IP Library Granted Patent US 12,135,814
Granted Patent B2
US 12,135,814 · App. 18/334,559 · Granted Nov 5, 2024

Storage network with key sharing

Inventor: Jason K. Resch (Warwick, RI)
Assignee: Pure Storage, Inc.
G06F21/6227G06F3/0604G06F3/0644G06F3/067G06F8/65G06F11/10G06F11/1076G06F11/2089G06F12/1408G06F21/602G06F21/6218G06F21/64H04L9/085H04L9/0861G06F15/17331G06F16/27G06F2212/263G06F2221/2107H04L2209/24H04L2209/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,135,814
App. No.
18/334,559
Granted
Nov 5, 2024
Kind
B2
Abstract

A method includes encoding a data segment into a set of encoded data slices using erasure coding; storing, in storage units of a storage network, the set of encoded data slices, in accordance with a shared key-based encryption system (SKBES) having keys shared with the storage units; retrieving, at a periodic rate and in accordance with the SKBES, the set of encoded data slices from the storage units of the storage unit to verify whether individual slices of the set of encoded data slices have been corrupted. When one of the set of encoded data slices stored in one of the storage units has been corrupted, rebuilding the one of the set of encoded data slices by: retrieving the decode threshold number of other slices of the set of encoded data slices, in accordance with the SKBES; reconstructing the one of the set of encoded data slices based on the erasure encoding, to generate a reconstructed data slice; and storing, in accordance with the SKBES, the reconstructed data slice in the one of the storage units.

Claims (72)

1. A method comprises:

receiving a data segment;

encoding the data segment into a set of encoded data slices using dispersed error encoding, wherein the data segment is reconstructable from a decode threshold number of encoded data slices of the set of encoded data slices;

storing, in storage units of a storage network, the set of encoded data slices, in accordance with a shared key-based encryption system of the storage units having keys shared with the storage units, wherein sharing the keys with the storage units via the shared key-based encryption system includes sharing a first key between a first subset of the storage units and sharing a second key, that differs from the first key, between a second subset of the storage units that differs from the first subset of the storage units;

retrieving, in accordance with the shared key-based encryption system, the set of encoded data slices from the storage units of the storage unit to verify whether individual slices of the set of encoded data slices have been corrupted; and

when one of the set of encoded data slices stored in one of the storage units has been corrupted, rebuilding the one of the set of encoded data slices by:

retrieving the decode threshold number of other slices of the set of encoded data slices, in accordance with the shared key-based encryption system;

reconstructing the one of the set of encoded data slices based on the dispersed error encoding, to generate a reconstructed data slice; and

storing, in accordance with the shared key-based encryption system, the reconstructed data slice.

2. The method of claim 1 , further comprising:

identifying, by one storage unit of the storage units, a subset of other storage units of the storage network, wherein the one storage unit and the subset of other storage units comprise a set of storage units of the storage network that store the set of encoded data slices, wherein the set of encoded data slices are associated with a storage vault;

determining, by the one storage unit, that a number of available storage units in the set of storage units is greater than the decode threshold number based on an update status of the set of storage units; and

updating, by the one storage unit, respective software of the set of storage units including the respective software of the one storage unit itself, while maintaining availability of the decode threshold number of the storage units of the set of storage units to service access requests to the data segment encoded in the set of encoded data slices.

3. The method of claim 2 , wherein updating the respective software of the set of storage units is based on a status of a software update, and wherein the status of the software update includes one or more of a mandatory critical status, a mandatory non-critical status, and an optional status.

4. The method of claim 3 , wherein the update status includes one or more of available, unavailable, already updated, and not already updated.

5. The method of claim 2 , further comprising:

identifying, by the one storage unit, a plurality of storage vaults supported by the one storage unit, wherein the plurality of storage vaults includes the storage vault;

identifying, by the one storage unit, a plurality of subsets of other storage units of the storage network, wherein the plurality of subsets of other storage units includes the subset of other storage units, wherein the one storage unit and each of the plurality of subsets of other storage units comprise each of a plurality of sets of storage units that support one of the plurality of storage vaults, and wherein the plurality of sets of storage units includes the set of storage units; and

updating, by the one storage unit, the respective software of the set of storage units, including the respective software of the one storage unit itself, while maintaining availability of the decode threshold number of storage units of each set of storage units in the plurality of sets of storage units.

6. The method of claim 5 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another one of the plurality of storage vaults, wherein the decode threshold number of the storage units is needed to reconstruct other data encoded in the other encoded data slices, further comprising:

determining, by the one storage unit, that another number of available storage units in the another set of storage units is equal to the decode threshold number of the storage units; and

determining, by the one storage unit, to update the respective software of the another set of storage units later in response to determining the another number of available storage units is equal to the decode threshold number of the storage units.

7. The method of claim 5 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another storage vault, wherein another decode threshold number of storage units is needed to reconstruct other data encoded in other encoded data slices, and wherein the another decode threshold number of storage units is different from the decode threshold number of the storage units, further comprising:

determining, by the one storage unit, that another number of available storage units in the another set of storage units is greater than the another decode threshold number of storage units.

8. The method of claim 7 , further comprising:

determining a priority for each of the plurality of storage vaults, wherein a first one of the plurality of storage vaults corresponding the set of storage units has a first priority, and wherein a second one of the plurality of storage vaults corresponding to the another set of storage units has a second priority.

9. The method of claim 1 , wherein sharing the keys with the storage units via the shared key-based encryption system includes sharing a first key between a first pair of the storage units and sharing a second key between a second pair of the storage units that differs from the first pair.

10. A system comprising:

a communications interface;

a memory; and

a computer processor;

wherein the memory includes instructions for causing the computer processor to perform operations that include:

receiving a data segment;

encoding the data segment into a set of encoded data slices using dispersed error encoding, wherein the data segment is reconstructable from a decode threshold number of encoded data slices of the set of encoded data slices;

storing, in storage units of a storage network, the set of encoded data slices, in accordance with a shared key-based encryption system of the storage units having keys shared with the storage units, wherein sharing the keys with the storage units via the shared key-based encryption system includes sharing a first key between a first subset of the storage units and sharing a second key, that differs from the first key, between a second subset of the storage units that differs from the first subset of the storage units;

retrieving, in accordance with the shared key-based encryption system, the set of encoded data slices from the storage units of the storage unit to verify whether individual slices of the set of encoded data slices have been corrupted; and

when one of the set of encoded data slices stored in one of the storage units has been corrupted, rebuilding the one of the set of encoded data slices by:

retrieving the decode threshold number of other slices of the set of encoded data slices, in accordance with the shared key-based encryption system;

reconstructing the one of the set of encoded data slices based on the dispersed error encoding, to generate a reconstructed data slice; and

storing, in accordance with the shared key-based encryption system, the reconstructed data slice.

11. The system of claim 10 , wherein the operations further comprise:

identifying, by one storage unit of the storage units, a subset of other storage units of the storage network, wherein the one storage unit and the subset of other storage units comprise a set of storage units of the storage network that store the set of encoded data slices, wherein the set of encoded data slices are associated with a storage vault;

determining, by the one storage unit, that a number of available storage units in the set of storage units is greater than the decode threshold number based on an update status of the set of storage units; and

updating, by the one storage unit, respective software of the set of storage units including the respective software of the one storage unit itself, while maintaining availability of the decode threshold number of the storage units of the set of storage units to service access requests to the data segment encoded in the set of encoded data slices.

12. The system of claim 11 , wherein updating the respective software of the set of storage units is based on a status of a software update, and wherein the status of the software update includes one or more of a mandatory critical status, a mandatory non-critical status, and an optional status.

13. The system of claim 12 , wherein the update status includes one or more of available, unavailable, already updated, and not already updated.

14. The system of claim 11 , wherein the operations further comprise:

identifying, by the one storage unit, a plurality of storage vaults supported by the one storage unit, wherein the plurality of storage vaults includes the storage vault;

identifying, by the one storage unit, a plurality of subsets of other storage units of the storage network, wherein the plurality of subsets of other storage units includes the subset of other storage units, wherein the one storage unit and each of the plurality of subsets of other storage units comprise each of a plurality of sets of storage units that support one of the plurality of storage vaults, and wherein the plurality of sets of storage units includes the set of storage units; and

updating, by the one storage unit, the respective software of the set of storage units, including the respective software of the one storage unit itself, while maintaining availability of the decode threshold number of storage units of each set of storage units in the plurality of sets of storage units.

15. The system of claim 14 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another one of the plurality of storage vaults, wherein the decode threshold number of the storage units is needed to reconstruct other data encoded in the other encoded data slices, further comprising:

determining, by the one storage unit, that another number of available storage units in the another set of storage units is equal to the decode threshold number of the storage units; and

determining, by the one storage unit, to update the respective software of the another set of storage units later in response to determining the another number of available storage units is equal to the decode threshold number of the storage units.

16. The system of claim 14 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another storage vault, wherein another decode threshold number of storage units is needed to reconstruct other data encoded in other encoded data slices, and wherein the another decode threshold number of storage units is different from the decode threshold number of the storage units, further comprising:

determining, by the one storage unit, that another number of available storage units in the another set of storage units is greater than the another decode threshold number of storage units.

17. The system of claim 16 , wherein the operations further comprise:

determining a priority for each of the plurality of storage vaults, wherein a first one of the plurality of storage vaults corresponding the set of storage units has a first priority, and wherein a second one of the plurality of storage vaults corresponding to the another set of storage units has a second priority.

18. The system of claim 17 , wherein the operations further comprise:

updating, by the one storage unit the respective software of the another set of storage units while maintaining availability of the another decode threshold number of storage units of the another set of storage units, wherein the set of storage units is updated before the another set of storage units in response to the first priority being greater than the second priority.

19. A system comprises:

means for receiving a data segment;

means for encoding the data segment into a set of encoded data slices using dispersed error encoding, wherein the data segment is reconstructable from a decode threshold number of encoded data slices of the set of encoded data slices;

means for storing, in storage units of a storage network, the set of encoded data slices, in accordance with a shared key-based encryption system of the storage units having keys shared with the storage units;

means for retrieving, in accordance with the shared key-based encryption system, the set of encoded data slices from the storage units of the storage unit to verify whether individual slices of the set of encoded data slices have been corrupted; and

means for when one of the set of encoded data slices stored in one of the storage units has been corrupted, rebuilding the one of the set of encoded data slices by:

retrieving the decode threshold number of other slices of the set of encoded data slices, in accordance with the shared key-based encryption system;

reconstructing the one of the set of encoded data slices based on the dispersed error encoding, to generate a reconstructed data slice; and

storing, in accordance with the shared key-based encryption system, the reconstructed data slice.

20. The system of claim 19 , further comprising:

means for identifying, by one storage unit of the storage units, a subset of other storage units of the storage network, wherein the one storage unit and the subset of other storage units comprise a set of storage units of the storage network that store the set of encoded data slices, wherein the set of encoded data slices are associated with a storage vault;

means for determining, by the one storage unit, that a number of available storage units in the set of storage units is greater than the decode threshold number based on an update status of the set of storage units; and

means for updating, by the one storage unit, respective software of the set of storage units including the respective software of the one storage unit itself, while maintaining availability of the decode threshold number of the storage units of the set of storage units to service access requests to the data segment encoded in the set of encoded data slices.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2023
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 064023/0604 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064006/0473 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: RESCH, JASON K.
To: CLEVERSAFE, INC.
Reel/Frame 063958/0885 →
Continuity (8)
Continuation 16782374 · Feb 5, 2020
Continuation In Part 16574793 · Sep 18, 2019
Continuation In Part 16410419 · May 13, 2019
Continuation 13464015 · May 4, 2012
Continuation 12551145 · Aug 31, 2009
Continuation In Part 12426727 · Apr 20, 2009
Provisional Application 61493820 · Jun 6, 2011
Related Publication 20230325526A1 · Oct 12, 2023