IP Library Granted Patent US 11,194,672
Granted Patent B1
US 11,194,672 · App. 16/910,522 · Granted Dec 7, 2021

Storage network with connection security and methods for use therewith

Inventors: Jason K. Resch (Chicago, IL); Wesley Leggette (Chicago, IL)
Assignee: PURE STORAGE, INC.
G06F11/1464G06F3/065G06F3/067G06F3/0617G06F3/0619G06F3/0635G06F16/172G06F16/9535H04L63/10H04L67/1097G06F11/0709G06F11/0751G06F11/1076G06F11/2038G06F11/2048G06F11/2094G06F2201/80G06F2211/1028
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,194,672
App. No.
16/910,522
Granted
Dec 7, 2021
Kind
B1
Abstract

A method begins with a processing module selecting one of a plurality of dispersed storage (DS) processing modules for facilitating access to a dispersed storage network (DSN) memory. The method continues with the processing module sending a DSN memory access request to the one of the plurality of DS processing modules. The method continues with the processing module selecting another one of the plurality of DS processing modules when no response is received within a given time frame or when the response to the access request does not include an access indication. The method continues with the processing module sending the DSN memory access request to the another one of the plurality of DS processing modules.

Claims (60)

1. A method for execution by one or more computing devices of a storage network (SN), the method comprises:

receiving a write request corresponding to a data segment of a data object to be stored in the SN, wherein the SN has a plurality of storage units;

encoding the data segment into a set of encoded data slices, wherein a decode threshold number of encoded data slices of the set of encoded data slices is required to decode the data segment, wherein the decode threshold number is greater than one;

determining from a plurality of connection security levels, a connection security level corresponding to the write request;

selecting a subset of the plurality of storage units based on the connection security level, wherein the subset includes at least the decode threshold number of storage units of the plurality of storage units;

determining, based on the connection security level, a connection security approach corresponding to each of the subset of the plurality of storage units; and

communicating the set of encoded data slices to the subset of the plurality of storage units in accordance with the connection security approach corresponding to each of the subset of the plurality of storage units.

2. The method of claim 1 , wherein one of the plurality of connection security levels includes a first key employed for one of the subset of the plurality of storage units.

3. The method of claim 2 , wherein another one of the plurality of connection security levels includes a second key employed for another one of the subset of the plurality of storage units.

4. The method of claim 1 , wherein the plurality of connection security levels includes a first cipher employed for one of the subset of the plurality of storage units and a second cipher employed for another of the subset of the plurality of storage units.

5. The method of claim 1 , wherein the plurality of connection security levels includes at least one of:

a transmission control protocol connection that is based on a user identifier and security credentials;

a transport layer security null cipher connection that is based on the user identifier and the security credentials; or

a transport layer security cipher connection that is based on the user identifier and the security credentials.

6. The method of claim 1 , wherein the plurality of connection security levels includes one of:

a first level with no tampering protection and with no eavesdropping protection;

a second level with the tampering protection and with the no eavesdropping protection; and

a third level with the tampering protection and with eavesdropping protection.

7. The method of claim 1 wherein the connection security level is determined for the subset of the plurality of storage units based on a corresponding proximity of each of the subset of the plurality of storage units from the one or more computing devices.

8. A processing unit for use in a storage network comprises:

an interface;

memory; and

a processing module operably coupled to the interface and the memory, wherein the processing module is operable to perform operations including:

receiving a write request corresponding to a data segment of a data object to be stored in the SN, wherein the SN has a plurality of storage units;

encoding the data segment into a set of encoded data slices, wherein a decode threshold number of encoded data slices of the set of encoded data slices is required to decode the data segment, wherein the decode threshold number is greater than one;

determining from a plurality of connection security levels, a connection security level corresponding to the write request;

selecting a subset of the plurality of storage units based on the connection security level, wherein the subset includes at least the decode threshold number of storage units of the plurality of storage units;

determining, based on the connection security level, a connection security approach corresponding to each of the subset of the plurality of storage units; and

communicating the set of encoded data slices to the subset of the plurality of storage units in accordance with the connection security approach corresponding to each of the subset of the plurality of storage units.

9. The processing unit of claim 8 , wherein one of the plurality of connection security levels includes a first key employed for one of the subset of the plurality of storage units.

10. The processing unit of claim 9 , wherein another one of the plurality of connection security levels includes a second key employed for another one of the subset of the plurality of storage units.

11. The processing unit of claim 8 , wherein the plurality of connection security levels includes a first cipher employed for one of the subset of the plurality of storage units and a second cipher employed for another of the subset of the plurality of storage units.

12. The processing unit of claim 8 , wherein the plurality of connection security levels includes at least one of:

a transmission control protocol connection that is based on a user identifier and security credentials;

a transport layer security null cipher connection that is based on the user identifier and the security credentials; or

a transport layer security cipher connection that is based on the user identifier and the security credentials.

13. The processing unit of claim 8 , wherein the plurality of connection security levels includes one of:

a first level with no tampering protection and with no eavesdropping protection;

a second level with the tampering protection and with the no eavesdropping protection; and

a third level with the tampering protection and with eavesdropping protection.

14. The processing unit of claim 8 , wherein the connection security level is determined for the subset of the plurality of storage units based on a corresponding proximity of each of the subset of the plurality of storage units from one or more computing devices.

15. A tangible computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by one or more processing modules of one or more computing devices of a storage network, causes the one or more computing devices to perform operations including:

receiving a write request corresponding to a data segment of a data object to be stored in the SN, wherein the SN has a plurality of storage units;

encoding the data segment into a set of encoded data slices, wherein a decode threshold number of encoded data slices of the set of encoded data slices is required to decode the data segment, wherein the decode threshold number is greater than one;

determining from a plurality of connection security levels, a connection security level corresponding to the write request;

selecting a subset of the plurality of storage units based on the connection security level, wherein the subset includes at least the decode threshold number of storage units of the plurality of storage units;

determining, based on the connection security level, a connection security approach corresponding to each of the subset of the plurality of storage units; and

communicating the set of encoded data slices to the subset of the plurality of storage units in accordance with the connection security approach corresponding to each of the subset of the plurality of storage units.

16. The tangible computer readable storage medium of claim 15 , wherein one of the plurality of connection security levels includes a first key employed for one of the subset of the plurality of storage units.

17. The tangible computer readable storage medium of claim 15 , wherein the plurality of connection security levels includes a first cipher employed for one of the subset of the plurality of storage units and a second cipher employed for another of the subset of the plurality of storage units.

18. The tangible computer readable storage medium of claim 15 , wherein the plurality of connection security levels includes at least one of:

a transmission control protocol connection that is based on a user identifier and security credentials;

a transport layer security null cipher connection that is based on the user identifier and the security credentials; or

a transport layer security cipher connection that is based on the user identifier and the security credentials.

19. The tangible computer readable storage medium of claim 15 , wherein the plurality of connection security levels includes one of:

a first level with no tampering protection and with no eavesdropping protection;

a second level with the tampering protection and with the no eavesdropping protection; and

a third level with the tampering protection and with eavesdropping protection.

20. The tangible computer readable storage medium of claim 15 , wherein the connection security level is determined for the subset of the plurality of storage units based on a corresponding proximity of each of the subset of the plurality of storage units from the one or more computing devices.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2020
From: RESCH, JASON K.; LEGGETTE, WESLEY
To: CLEVERSAFE, INC.
Reel/Frame 053028/0671 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2020
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 053033/0327 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 053033/0389 →