IP Library Granted Patent US 11,895,098
Granted Patent B2
US 11,895,098 · App. 17/937,286 · Granted Feb 6, 2024

Storing encrypted chunksets of data in a vast storage network

Inventors: Andrew D. Baptist (Mt. Pleasant, WI); Greg R. Dhuse (Chicago, IL); Wesley B. Leggette (Chicago, IL); Jason K. Resch (Warwick, RI)
Assignee: Pure Storage, Inc.
H04L63/0428G06F3/064G06F3/067G06F3/0619H04L9/085H04L9/0825H04L9/0894H04L67/10H04L67/1097G06F11/1076G06F2211/1028H03M13/1515H04L2463/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,895,098
App. No.
17/937,286
Granted
Feb 6, 2024
Kind
B2
Abstract

A method for execution by one or more processing modules of one or more computing devices begins by encoding data using a dispersed storage error encoding function to produce a plurality of sets of encoded data slices arranged into a plurality of chunksets of encoded data slices. The method continues by selecting a set of storage units for storing the plurality of chunksets and assigning a distributed computing task to each storage unit of the set of storage units. The method then continues by generating a unique key set for each storage unit of the storage units, encrypting each chunkset of encoded data slices with a corresponding one of the unique key sets to produce a plurality of encrypted chunksets and sending an encrypted chunkset of the plurality of encrypted chunksets and an indication of a corresponding distributed computing task to each storage unit of the set of storage units for storage of the encrypted chunksets and execution of the distributed computing task.

Claims (59)

1. A method for execution by one or more processing modules of one or more computing devices, the method comprises:

encoding data using a dispersed storage error encoding function to produce a plurality of sets of encoded data slices, wherein the encoded data slices of the plurality of sets of encoded data slices are arranged into a plurality of chunksets of encoded data slices;

selecting a set of storage units for storing the plurality of chunksets;

assigning a distributed computing task to each storage unit of the set of storage units;

generating a unique key set for each storage unit of the storage units;

encrypting each chunkset of encoded data slices with a corresponding one of the unique key sets to produce a plurality of encrypted chunksets; and

sending an encrypted chunkset of the plurality of encrypted chunksets and an indication of a corresponding distributed computing task to each storage unit of the set of storage units for storage of the encrypted chunksets and execution of the distributed computing task.

2. The method of claim 1 , wherein the distributed computing task includes one or more partial tasks.

3. The method of claim 2 , wherein the selecting a set of storage units for storing the plurality of chunksets is based on at least one of: an assigned partial task for a corresponding storage unit, information regarding the corresponding storage unit, information regarding key generation and a pseudo random function.

4. The method of claim 1 , wherein the indication of the distributed computing task for a storage unit of the set of storage units comprises at least one of:

an indication that the distributed computing task was used to generate a corresponding unique key set; and

an indication as to how the distributed computing task was used to generate the corresponding unique key set.

5. The method of claim 1 , wherein the sending the indication of the distributed computing task to a storage unit of the set of storage units comprises:

sending a corresponding partial task to the storage unit.

6. The method of claim 1 , wherein the generating a unique key set for each storage unit of the storage units comprises:

generating a unique key for each storage unit of the set of storage units that is used to encrypt a corresponding chunkset of encrypted slices.

7. The method of claim 1 , wherein the generating a unique key set for each storage unit of the storage units comprises:

generating a unique key for each storage unit of the set of storage units that is used to encrypt one or more slices of the corresponding chunkset of encrypted slices.

8. The method of claim 1 , wherein the generating a unique key set for each storage unit of the storage units comprises:

identifying an assigned partial task for the one of the storage units; and

performing a deterministic mathematical function on bits of the assigned partial task to create a value.

9. The method of claim 1 , wherein the generating a unique key set for each storage unit of the storage units comprises:

determining a public key of a public/private key pair for the one of the storage units; and

using the public key to generate the unique key set.

10. A computing device of a storage network comprises:

a first module, when operable within the computing device, causes the computing device to:

encode data using a dispersed storage error encoding function to produce a plurality of sets of encoded data slices, wherein the encoded data slices of the plurality of sets of encoded data slices are arranged into chunksets of encoded data slices;

select a set of storage units for the chunksets of slices; and

assign one or more distributed computing tasks to each storage unit of the set of storage units;

a second module, when operable within the computing device, causes the computing device to:

generate a unique key set for each storage unit of the set of storage units based on at least one of: an assigned partial task for a corresponding storage unit, information regarding the storage unit, information regarding key generation and a pseudo random function; and

encrypt a chunkset of the chunksets of slices with a corresponding one of the unique key sets to produce an encrypted chunkset; and

a third module, when operable within the computing device, causes the computing device to:

send the encrypted chunkset and an indication of a corresponding distributed computing task to the storage unit for storage of the encrypted chunkset and execution of the distributed computing task on the encrypted chunkset.

11. The computing device of claim 10 , wherein the indication of the distributed computing task for the storage unit comprises at least one of:

an indication that the distributed computing task was used to generate a corresponding unique key set; and

an indication as to how the distributed computing task was used to generate the corresponding unique key set.

12. The computing device of claim 10 , wherein the third module functions to send the indication of the distributed computing task to the storage unit by:

sending a corresponding an assigned partial task to the storage unit.

13. The computing device of claim 10 , wherein the second module functions to generate a unique key set for each storage unit of the set of storage units by:

generating a unique key that is used to encrypt a corresponding chunkset of encrypted slices.

14. The computing device of claim 10 , wherein the second module functions to generate a unique key set for each storage unit of the set of storage units by:

generating multiple unique keys, wherein each of the multiple unique keys is used to encrypt a corresponding chunkset of encrypted slices.

15. The computing device of claim 10 , wherein the second module functions to generate a unique key set for each storage unit of the set of storage units by:

identifying an assigned partial task for a corresponding storage unit; and

performing a deterministic mathematical function on bits of the assigned partial task to create a value.

16. The computing device of claim 10 , wherein the second module functions to generate a unique key set for each storage unit of the set of storage units by:

determining a public key of a public/private key pair for a corresponding storage unit; and

utilizing the public key to generate the unique key set.

17. A method for execution by one or more processing modules of one or more computing devices of a storage network, the method comprises:

encoding data using a dispersed storage error encoding function to produce a plurality of sets of encoded data slices, wherein the encoded data slices of the plurality of sets of encoded data slices are arranged into a plurality of chunksets of encoded data slices;

selecting a set of storage units for storing the plurality of chunksets;

generating a unique key set for each storage unit of the set of storage units;

encrypting each chunkset of encoded data slices using a corresponding one of the unique key sets to produce a plurality of encrypted chunksets; and

sending an encrypted chunkset of the plurality of encrypted chunksets to each storage unit of the set of storage units.

18. The method of claim 17 , further comprising:

sending an indication of a corresponding one or more distributed computing tasks to each storage unit of the set of storage units.

19. The method of claim 18 , wherein the one or more distributed computing tasks includes a partial task.

20. The method of claim 19 , wherein the unique key is generated based on the partial task.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2022
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 061594/0852 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2022
From: BAPTIST, ANDREW D.; DHUSE, GREG R.; LEGGETTE, WESLEY B.; RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 061282/0564 →
Continuity (8)
Continuation 16858839 · Apr 27, 2020
Continuation 15824433 · Nov 28, 2017
Continuation In Part 15418164 · Jan 27, 2017
Continuation 13917017 · Jun 13, 2013
Continuation In Part 13707428 · Dec 6, 2012
Provisional Application 61679007 · Aug 2, 2012
Provisional Application 61569387 · Dec 12, 2011
Related Publication 20230025990A1 · Jan 26, 2023