IP Library Granted Patent US 12,499,060
Granted Patent B2
US 12,499,060 · App. 18/218,780 · Granted Dec 16, 2025

Securely storing secure packages in a storage network

Inventors: Gary W. Grube (Barrington Hills, IL); Timothy W. Markison (Mesa, AZ)
Assignee: Pure Storage, Inc.
G06F12/1408G06F11/1004G06F11/1076H04L9/085H04L9/0894H04L9/14H04L9/3239H04L9/3263H04L63/061H04L67/06H04L67/1097H04L67/306G06F2212/1052H04L1/0041H04L1/0045H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,060
App. No.
18/218,780
Granted
Dec 16, 2025
Kind
B2
Abstract

A method for execution by a computing device of a storage network includes appending at least a decode threshold number of encoded key slices of a set of encoded key slices to at least some encrypted data segments of a plurality of encrypted data segments to produce secure packages. The method further includes error encoding, in accordance with error encoding parameters, the secure packages to produce sets of encoded data slices, where a first secure package of the secure packages is dispersed storage error encoded using an error encoding function of the error encoding parameters to produce a first set of encoded data slices of the sets of encoded data slices. The method further includes outputting the sets of encoded data slices for storage in memory of the storage network.

Claims (39)

1 . A method for execution by one or more computing devices of a storage network comprises:

appending at least a decode threshold number of encoded key slices of a set of encoded key slices to at least some encrypted data segments of a plurality of encrypted data segments to produce secure packages such that no individual encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices of the set of encoded key slices, wherein the encrypted data segments are not encoded encrypted data segments;

error encoding, in accordance with error encoding parameters, the secure packages to produce sets of encoded data slices, wherein a first secure package of the secure packages is dispersed storage error encoded using an error encoding function of the error encoding parameters to produce a first set of encoded data slices of the sets of encoded data slices; and

outputting the sets of encoded data slices for storage in memory of the storage network.

2 . The method of claim 1 further comprises:

error encoding an encryption key to produce the set of encoded key slices.

3 . The method of claim 2 , wherein the error encoding the encryption key is performed in accordance with the error encoding parameters.

4 . The method of claim 2 , wherein the error encoding the encryption key is performed in accordance with second error encoding parameters.

5 . The method of claim 4 , wherein the error encoding parameters comprises:

a first pillar width; and

a first decode threshold.

6 . The method of claim 5 , wherein the second error encoding parameters comprises:

a second pillar width; and

a second decode threshold.

7 . The method of claim 1 , wherein the appending the at least a decode threshold number of encoded key slices of the set of encoded key slices to the at least some encrypted data segments is based on an appending approach.

8 . The method of claim 7 , wherein the appending approach is a random sequence.

9 . The method of claim 7 , wherein the appending approach is a pseudo random sequence.

10 . The method of claim 7 , wherein the appending approach is a function.

11 . The method of claim 7 , wherein the appending approach comprises appending rules such that no individual encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices of a set of encoded key slices of the sets of encoded key slices.

12 . A computing device of a storage network, the computing device comprises:

memory;

an interface; and

a processing module operably coupled to the memory and the interface, wherein the processing module is operable to:

append at least a decode threshold number of encoded key slices of a set of encoded key slices to at least some encrypted data segments of a plurality of encrypted data segments to produce secure packages such that no individual encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices of the set of encoded key slices, wherein the encrypted data segments are not encoded encrypted data segments;

error encode, in accordance with error encoding parameters, the secure packages to produce sets of encoded data slices, wherein a first secure package of the secure packages is dispersed storage error encoded using an error encoding function of the error encoding parameters to produce a first set of encoded data slices of the sets of encoded data slices; and

output, via the interface, the sets of encoded data slices for storage in memory of the storage network.

13 . The computing device of claim 12 , wherein the processing module is further operable to:

error encoding an encryption key to produce the set of encoded key slices.

14 . The computing device of claim 13 , wherein the error encoding the encryption key is performed in accordance with the error encoding parameters.

15 . The computing device of claim 13 , wherein the error encoding the encryption key is performed in accordance with second error encoding parameters.

16 . The computing device of claim 15 , wherein the error encoding parameters comprise:

a first pillar width; and

a first decode threshold.

17 . The computing device of claim 16 , wherein the second error encoding parameters comprise:

a second pillar width; and

a second decode threshold.

18 . The computing device of claim 12 , wherein the appending the at least a decode threshold number of encoded key slices of the set of encoded key slices to the at least some encrypted data segments is based on an appending approach.

19 . The computing device of claim 18 , wherein the appending approach is a function.

20 . The computing device of claim 18 , wherein the appending approach comprises appending rules such that no individual encrypted data segment of the at least some of the encrypted data segments includes the at least the decode threshold number of encoded key slices of a set of encoded key slices of the sets of encoded key slices.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2023
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 064270/0637 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: GRUBE, GARY W.; MARKISON, TIMOTHY W.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064207/0372 →
Continuity (8)
Continuation 17197807 · Mar 10, 2021
Continuation 16040786 · Jul 20, 2018
Continuation In Part 15799943 · Oct 31, 2017
Continuation In Part 15345262 · Nov 7, 2016
Continuation 14499570 · Sep 29, 2014
Continuation 13686827 · Nov 27, 2012
Provisional Application 61564200 · Nov 28, 2011
Related Publication 20230359570A1 · Nov 9, 2023
References Cited (106)
US 4092732A · Ouchi · 1978 [cited by applicant]
US 5454101A · Mackay · 1995 [cited by applicant]
US 5485474A · Rabin · 1996 [cited by applicant]
US 5764767A · Beimel · 1998 [cited by applicant]
US 5774643A · Lubbers · 1998 [cited by applicant]
US 5802364A · Senator · 1998 [cited by applicant]
US 5809285A · Hilland · 1998 [cited by applicant]
US 5890156A · Rekieta · 1999 [cited by applicant]
US 5987622A · Lo Verso · 1999 [cited by applicant]
US 5991414A · Garay · 1999 [cited by applicant]
US 6012159A · Fischer · 2000 [cited by applicant]
US 6058454A · Gerlach · 2000 [cited by applicant]
US 6128277A · Bruck · 2000 [cited by applicant]
US 6175571B1 · Haddock · 2001 [cited by applicant]
US 6192472B1 · Garay · 2001 [cited by applicant]
US 6256688B1 · Suetaka · 2001 [cited by applicant]
US 6272658B1 · Steele · 2001 [cited by applicant]
US 6301604B1 · Nojima · 2001 [cited by applicant]
US 6356949B1 · Katsandres · 2002 [cited by applicant]
US 6366995B1 · Nikolaevich · 2002 [cited by applicant]
US 6374336B1 · Peters · 2002 [cited by applicant]
US 6415373B1 · Peters · 2002 [cited by applicant]
US 6418539B1 · Walker · 2002 [cited by applicant]
US 6449688B1 · Peters · 2002 [cited by applicant]
US 6567948B2 · Steele · 2003 [cited by applicant]
US 6571282B1 · Bowman-Amuah · 2003 [cited by applicant]
US 6609223B1 · Wolfgang · 2003 [cited by applicant]
US 6718361B1 · Basani · 2004 [cited by applicant]
US 6760808B2 · Peters · 2004 [cited by applicant]
US 6785768B2 · Peters · 2004 [cited by applicant]
US 6785783B2 · Buckland · 2004 [cited by applicant]
US 6826711B2 · Moulton · 2004 [cited by applicant]
US 6879596B1 · Dooply · 2005 [cited by applicant]
US 7003688B1 · Pittelkow · 2006 [cited by applicant]
US 7024451B2 · Jorgenson · 2006 [cited by applicant]
US 7024609B2 · Wolfgang · 2006 [cited by applicant]
US 7080101B1 · Watson · 2006 [cited by applicant]
US 7103824B2 · Halford · 2006 [cited by applicant]
US 7103915B2 · Redlich · 2006 [cited by applicant]
US 7111115B2 · Peters · 2006 [cited by applicant]
US 7140044B2 · Redlich · 2006 [cited by applicant]
US 7146644B2 · Redlich · 2006 [cited by applicant]
US 7171493B2 · Shu · 2007 [cited by applicant]
US 7222133B1 · Raipurkar · 2007 [cited by applicant]
US 7240236B2 · Cutts · 2007 [cited by applicant]
US 7272613B2 · Sim · 2007 [cited by applicant]
US 7636724B2 · De La Torre · 2009 [cited by applicant]
US 8458233B2 · Gladwin · 2013 [cited by applicant]
US 8848906B2 · Grube · 2014 [cited by applicant]
US 20020062422A1 · Butterworth · 2002 [cited by applicant]
US 20020166079A1 · Ulrich · 2002 [cited by applicant]
US 20030018927A1 · Gadir · 2003 [cited by applicant]
US 20030037261A1 · Meffert · 2003 [cited by applicant]
US 20030065617A1 · Watkins · 2003 [cited by applicant]
US 20030084020A1 · Shu · 2003 [cited by applicant]
US 20040024963A1 · Talagala · 2004 [cited by applicant]
US 20040122917A1 · Menon · 2004 [cited by applicant]
US 20040215998A1 · Buxton · 2004 [cited by applicant]
US 20040228493A1 · Ma · 2004 [cited by applicant]
US 20050100022A1 · Ramprashad · 2005 [cited by applicant]
US 20050114594A1 · Corbett · 2005 [cited by applicant]
US 20050125593A1 · Karpoff · 2005 [cited by applicant]
US 20050131993A1 · Fatula, Jr. · 2005 [cited by applicant]
US 20050132070A1 · Redlich · 2005 [cited by applicant]
US 20050144382A1 · Schmisseur · 2005 [cited by applicant]
US 20050229069A1 · Hassner · 2005 [cited by applicant]
US 20060047907A1 · Shiga · 2006 [cited by applicant]
US 20060136448A1 · Cialini · 2006 [cited by applicant]
US 20060156059A1 · Kitamura · 2006 [cited by applicant]
US 20060224603A1 · Correll, Jr. · 2006 [cited by applicant]
US 20070079081A1 · Gladwin · 2007 [cited by applicant]
US 20070079082A1 · Gladwin · 2007 [cited by applicant]
US 20070079083A1 · Gladwin · 2007 [cited by applicant]
US 20070088970A1 · Buxton · 2007 [cited by applicant]
US 20070174192A1 · Gladwin · 2007 [cited by applicant]
US 20070214285A1 · Au · 2007 [cited by applicant]
US 20070234110A1 · Soran · 2007 [cited by applicant]
US 20070283167A1 · Venters · 2007 [cited by applicant]
US 20090094251A1 · Gladwin · 2009 [cited by applicant]
US 20090094318A1 · Gladwin · 2009 [cited by applicant]
US 20090323970A1 · Cerruti · 2009 [cited by applicant]
US 20100023524A1 · Gladwin · 2010 [cited by applicant]
US 20100169391A1 · Baptist · 2010 [cited by examiner]
US 20100268938A1 · Resch · 2010 [cited by examiner]
US 20100268966A1 · Leggette et al. · 2010 [cited by applicant]
US 20110126295A1 · Resch · 2011 [cited by applicant]
US 20110286594A1 · Resch · 2011 [cited by applicant]
US 20120243687A1 · Li et al. · 2012 [cited by applicant]
Chung; An Automatic Data Segmentation Method for 3D Measured Data Points; National Taiwan University, pp. 1-8; 1998. [cited by applicant]
Harrison; Lightweight Directory Access Protocol (LDAP): Authentication Methods and Security Mechanisms; IETF Network Working Group; RFC 4513; Jun. 2006; pp. 1-32. [cited by applicant]
Kubiatowicz, et al.; OceanStore: An Architecture for Global-Scale Persistent Storage; Proceedings of the Ninth International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 20… [cited by applicant]
Legg; Lightweight Directory Access Protocol (LDAP): Syntaxes and Matching Rules; IETF Network Working Group; RFC 4517; Jun. 2006; pp. 1-50. [cited by applicant]
Plank, T1: Erasure Codes for Storage Applications; FAST2005, 4th Usenix Conference on File Storage Technologies; Dec. 13-16, 2005; pp. 1-74. [cited by applicant]
Rabin; Efficient Dispersal of Information for Security, Load Balancing, and Fault Tolerance; Journal of the Association for Computer Machinery; vol. 36, No. 2; Apr. 1989; pp. 335-348. [cited by applicant]
Satran, et al.; Internet Small Computer Systems Interface (iSCSI); IETF Network Working Group; RFC 3720; Apr. 2004; pp. 1-257. [cited by applicant]
Sciberras; Lightweight Directory Access Protocol (LDAP): Schema for User Applications; IETF Network Working Group; RFC 4519; Jun. 2006; pp. 1-33. [cited by applicant]
Sermersheim; Lightweight Directory Access Protocol (LDAP): The Protocol; IETF Network Working Group; RFC 4511; Jun. 2006; pp. 1-68. [cited by applicant]
Shamir; How to Share a Secret; Communications of the ACM; vol. 22, No. 11; Nov. 1979; pp. 612-613. [cited by applicant]
Smith; Lightweight Directory Access Protocol (LDAP): Uniform Resource Locator; IETF Network Working Group; RFC 4516; Jun. 2006; pp. 1-15. [cited by applicant]
Smith; Lightweight Directory Access Protocol (LDAP): String Representation of Search Filters; IETF Network Working Group; RFC 4515; Jun. 2006; pp. 1-12. [cited by applicant]
Wildi; Java iSCSi Initiator; Master Thesis; Department of Computer and Information Science, University of Konstanz; Feb. 2007; 60 pgs. [cited by applicant]
Xin, et al.; Evaluation of Distributed Recovery in Large-Scale Storage Systems; 13th IEEE International Symposium on High Performance Distributed Computing; Jun. 2004; pp. 172-181. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Directory Information Models; IETF Network Working Group; RFC 4512; Jun. 2006; pp. 1-49. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Internationalized String Preparation; IETF Network Working Group; RFC 4518; Jun. 2006; pp. 1-14. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): String Representation of Distinguished Names; IETF Network Working Group; RFC 4514; Jun. 2006; pp. 1-15. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Technical Specification Road Map; IETF Network Working Group; RFC 4510; Jun. 2006; pp. 1-8. [cited by applicant]