IP Library Granted Patent US 11,567,702
Granted Patent B1
US 11,567,702 · App. 17/301,470 · Granted Jan 31, 2023

Resolving detected access anomalies in a vast storage network

Inventor: Jason K. Resch (Chicago, IL)
Assignee: PURE STORAGE, INC.
G06F3/0659G06F3/064G06F3/0619G06F3/0647G06F3/0653G06F3/0689G06F11/1076
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,567,702
App. No.
17/301,470
Granted
Jan 31, 2023
Kind
B1
Abstract

A method for execution by a computing device of a dispersed storage network includes obtaining resource information for a subset of storage units of a storage unit pool. W available storage units of the storage unit pool are identified in response to receiving a store data request. W choose S combinations of selecting S number of storage units of the W available storage units are identified. A plurality of rating levels is calculated based on the resource information, where each of the plurality of rating levels are assigned to a corresponding combination of the W choose S combinations. One combination of the W choose S combinations is selected based on the plurality of rating levels. Storage of data of the store data request is facilitated utilizing the S number of storage units of the selected one combination.

Claims (48)

1. A method for execution by a computing device that includes a processor, the method comprising:

receiving an access request associated with a data object stored as dispersed storage encoded data slices in at least one storage unit of a storage system, wherein the access request includes a request to access a data segment, and wherein the data segment was dispersed storage error encoded to produce a set of encoded data slices for storage in a set of storage units;

detecting an access anomaly associated with the access request, the access anomaly corresponding to a requestor that generated the access request, the access anomaly having one of a plurality of anomaly types;

denying the access request in response to detecting the access anomaly;

generating, based on the one of the plurality of anomaly types, an anomaly detection indicator identifying the requestor; and

sending the anomaly detection indicator to other devices of the storage system.

2. The method of claim 1 , wherein the access request is received from a requestor and wherein the method further comprises:

queueing the access request for processing in response to detecting the access anomaly;

initiating a secondary authentication process with the requestor;

receiving a secondary authentication response from the requestor; and

processing the access request when the secondary authentication response is favorable.

3. The method of claim 2 , wherein queuing the access request includes:

storing the access request in a local memory; and

associating the access request with at least one other queued access request, wherein the at least one other queued access request includes a request for a same encoded data slice.

4. The method of claim 3 , wherein processing the access request includes:

extracting the at least one other queued access request associated with the access request;

processing the access request and the at least one other queued access request in a sequence in accordance with a request type of the access request; and

wherein the access request and the at least one other queued access request include a write request, a commit request, and a finalize request of a three-phase storage process.

5. The method of claim 1 , wherein the access request is received via a dispersed storage and task (DST) processing unit that received the access request from a requestor corresponding to the access request.

6. The method of claim 1 , wherein detecting the access anomaly includes detecting an unfavorable access pattern.

7. The method of claim 1 , wherein detecting the access anomaly includes receiving a second anomaly detection indicator from another storage unit.

8. The method of claim 1 , wherein sending the anomaly detection indicator to the other devices includes generating the anomaly detection indicator to include the access request, and an identifier of a requestor corresponding to the access request.

9. The method of claim 1 , wherein another storage unit receives another access request associated with a requestor corresponding to the access request and queues the another access request in response to receiving the anomaly detection indicator.

10. A processing system of a storage unit comprises:

at least one processor;

a memory that stores operational instructions that, when executed by the at least one processor, cause the processing system to perform operations that include:

receiving an access request associated with a data object stored as dispersed storage encoded data slices in at least one storage unit of a storage system, wherein the access request includes a request to access a data segment, and wherein the data segment was dispersed storage error encoded to produce a set of encoded data slices for storage in a set of storage units;

detecting an access anomaly associated with the access request, the access anomaly corresponding to a requestor that generated the access request, the access anomaly having one of a plurality of anomaly types;

denying the access request in response to detecting the access anomaly;

generating, based on the one of the plurality of anomaly types, an anomaly detection indicator identifying the requestor; and

sending the anomaly detection indicator to other devices of the storage system.

11. The processing system of claim 10 , wherein the access request is received from a requestor and wherein the operations further include:

queueing the access request for processing in response to detecting the access anomaly;

initiating a secondary authentication process with the requestor;

receiving a secondary authentication response from the requestor; and

processing the access request when the secondary authentication response is favorable.

12. The processing system of claim 11 , wherein queuing the access request includes:

storing the access request in a local memory; and

associating the access request with at least one other queued access request, wherein the at least one other queued access request includes a request for a same encoded data slice.

13. The processing system of claim 12 , wherein processing the access request includes:

extracting the at least one other queued access request associated with the access request;

processing the access request and the at least one other queued access request in a sequence in accordance with a request type of the access request; and

wherein the access request and the at least one other queued access request include a write request, a commit request, and a finalize request of a three-phase storage process.

14. The processing system of claim 10 , wherein the access request is received via a dispersed storage and task (DST) processing unit that received the access request from a requestor corresponding to the access request.

15. The processing system of claim 10 , wherein detecting the access anomaly includes detecting an unfavorable access pattern.

16. The processing system of claim 10 , wherein detecting the access anomaly includes receiving a second anomaly detection indicator from another storage unit.

17. The processing system of claim 10 , wherein sending the anomaly detection indicator to the other devices includes generating the anomaly detection indicator to include the access request, and an identifier of a requestor corresponding to the access request.

18. The processing system of claim 10 , wherein another storage unit receives another access request associated with a requestor corresponding to the access request and queues the another access request in response to receiving the anomaly detection indicator.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 055828/0136 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2021
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 055830/0358 →
Continuity (5)
Continuation 16554939 · Aug 29, 2019
Continuation 15841863 · Dec 14, 2017
Continuation In Part 15837705 · Dec 11, 2017
Continuation In Part 15006735 · Jan 26, 2016
Provisional Application 62140861 · Mar 31, 2015