IP Library Granted Patent US 11,734,196
Granted Patent B1
US 11,734,196 · App. 17/197,807 · Granted Aug 22, 2023

Decrypting secure packages in a storage network

Inventors: Gary W. Grube (Barrington Hills, IL); Timothy W. Markison (Mesa, AZ)
Assignee: PURE STORAGE, INC.
G06F12/1408G06F11/1004G06F11/1076H04L9/085H04L9/0894H04L9/14H04L9/3239H04L9/3263H04L63/061H04L67/06H04L67/1097H04L67/306G06F2212/1052H04L1/0041H04L1/0045H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,734,196
App. No.
17/197,807
Granted
Aug 22, 2023
Kind
B1
Abstract

A method for execution by a computing device of a storage network includes dispersed storage error decoding a plurality of sets of encoded data slices to recover a plurality of secure packages, where the plurality of secure packages include a plurality of encrypted data segments and a plurality of sets of encoded key slices, and where encoded key slices are appended to the encrypted data segments in accordance with an appending approach. The method includes splitting the plurality of secure packages into the plurality of encrypted data segments and the plurality of sets of encoded key slices. The method includes decoding the at least the decode threshold number of each set of the plurality of sets of encoded key slices to recover a plurality of encryption keys. The method includes decrypting the plurality of encrypted data segments using the plurality of encryption keys to recover the data segments.

Claims (41)

1. A method for execution by a computing device of a storage network comprises:

dispersed storage error decoding, by the computing device, a plurality of sets of encoded data slices to recover a plurality of secure packages, wherein the plurality of secure packages include a plurality of encrypted data segments and a plurality of sets of encoded key slices, wherein at least a decode threshold number of encoded key slices of a set of encoded key slices of the plurality of sets of encoded key slices are appended to at least some of the encrypted data segments in accordance with an appending approach to produce a secure package of the plurality of secure packages, and wherein the encrypted data segments were not dispersed storage error encoded prior to the appending the at least a decode threshold number of encoded key slices to the at least some of the encrypted data segments;

splitting, by the computing device, the plurality of secure packages into the plurality of encrypted data segments and the plurality of sets of encoded key slices;

dispersed storage error decoding, by the computing device, the plurality of sets of encoded key slices to recover a plurality of encryption keys; and

decrypting, by the computing device, the plurality of encrypted data segments using the plurality of encryption keys to recover data segments.

2. The method of claim 1 further comprises:

de-segmenting, by the computing device, at least some of the data segments to recover a data object.

3. The method of claim 1 further comprises:

obtaining the plurality of sets of encoded data slices from storage units of the storage network.

4. The method of claim 1 , wherein the appending approach includes:

appending, by the computing device, an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices.

5. The method of claim 1 , wherein the appending approach includes:

appending, by the computing device, an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a pseudo random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices.

6. The method of claim 1 , wherein the appending approach includes:

appending, by the computing device, an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments according to a function, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices.

7. The method of claim 1 wherein the plurality of encryption keys were dispersed storage error encoded into the plurality of sets of encoded key slices using a key dispersed storage error encoding function.

8. The method of claim 7 , wherein the secure packages were dispersed storage error encoded into the plurality of sets of encoded data slices using a dispersed storage error encoding function.

9. The method of claim 8 , wherein the key dispersed storage error encoding function has a first pillar width, a first decode threshold, and a first error encoding function, and the dispersed storage error encoding function has a second pillar width, a second decode threshold, and a second error encoding function.

10. The method of claim 1 , wherein a data segment of the data segments was encrypted using an encryption key of the plurality of encryption keys to produce an encrypted data segment of the encrypted data segments.

11. A computing device of a storage network, the computing device comprises:

an interface;

memory; and

a processing module operably coupled to the memory and the interface, wherein the processing module is operable to:

dispersed storage error decode a plurality of sets of encoded data slices to recover a plurality of secure packages, wherein the plurality of secure packages include a plurality of encrypted data segments and a plurality of sets of encoded key slices, wherein at least a decode threshold number of encoded key slices of a set of encoded key slices of the plurality of sets of encoded key slices are appended to at least some of the encrypted data segments in accordance with an appending approach to produce a secure package of the plurality of secure packages, and wherein the encrypted data segments were not dispersed storage error encoded prior to the appending the at least a decode threshold number of encoded key slices to the at least some of the encrypted data segments;

split the plurality of secure packages into the plurality of encrypted data segments and the plurality of sets of encoded key slices;

dispersed storage error decode the at least the decode threshold number of each set of the plurality of sets of encoded key slices to recover a plurality of encryption keys; and

decrypt the plurality of encrypted data segments using the plurality of encryption keys to recover data segments.

12. The computing device of claim 11 , wherein the processing module is further operable to:

de-segment at least some of the data segments to recover a data object.

13. The computing device of claim 11 , wherein the processing module is further operable to:

receive, via the interface, the plurality of sets of encoded data slices from storage units of the storage network.

14. The computing device of claim 11 , wherein the processing module is further operable to perform the appending approach by:

appending an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices.

15. The computing device of claim 11 , wherein the processing module is further operable to perform the appending approach by:

appending an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments in a pseudo random sequence, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices.

16. The computing device of claim 11 , wherein the processing module is further operable to perform the appending approach by:

appending an encoded key slice of the at least the decode threshold number of encoded key slices to the at least some of the encrypted data segments according to a function, wherein no one encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices.

17. The computing device of claim 11 , wherein the plurality of encryption keys were dispersed storage error encoded into the plurality of sets of encoded key slices using a key dispersed storage error encoding function.

18. The computing device of claim 17 , wherein the secure packages were dispersed storage error encoded into the plurality of sets of encoded data slices using a dispersed storage error encoding function.

19. The computing device of claim 18 , wherein the key dispersed storage error encoding function has a first pillar width, a first decode threshold, and a first error encoding function, and the dispersed storage error encoding function has a second pillar width, a second decode threshold, and a second error encoding function.

20. The computing device of claim 11 , wherein the processing module is further operable to encrypt a data segment of the data segments using an encryption key of the plurality of encryption keys to produce an encrypted data segment of the encrypted data segments.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2021
From: GRUBE, GARY W.; MARKISON, TIMOTHY W.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 055570/0097 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 055575/0001 →
Continuity (6)
Continuation 16040786 · Jul 20, 2018
Continuation In Part 15799943 · Oct 31, 2017
Continuation In Part 15345262 · Nov 7, 2016
Continuation 14499570 · Sep 29, 2014
Continuation 13686827 · Nov 27, 2012
Provisional Application 61564200 · Nov 28, 2011