IP Library Granted Patent US 12,204,798
Granted Patent B2
US 12,204,798 · App. 18/502,320 · Granted Jan 21, 2025

Access anomaly notification in a storage network

Inventor: Jason K. Resch (Warwick, RI)
Assignee: Pure Storage, Inc.
G06F3/0659G06F3/061G06F3/0619G06F3/064G06F3/0647G06F3/0653G06F3/067G06F3/0689G06F11/1076
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,798
App. No.
18/502,320
Granted
Jan 21, 2025
Kind
B2
Abstract

A processing system operates by: detecting an access anomaly associated with an access request from a requestor for a set of encoded data slices, the access anomaly having an unfavorable access pattern, wherein the set of encoded data slices is dispersed storage error encoded and stored in at least one storage unit of the storage network; denying the access request in response to detecting the access anomaly; generating, based on the unfavorable access pattern, an anomaly detection indicator identifying the requestor; and sending the anomaly detection indicator to other devices of the storage network.

Claims (44)

1. A method for execution by a computing device that includes a processor, the method comprising:

detecting an access anomaly associated with an access request from a requestor for a set of encoded data slices, the access anomaly having an unfavorable access pattern, wherein the set of encoded data slices is dispersed storage error encoded and stored in at least one storage unit of a storage network;

denying the access request in response to detecting the access anomaly;

generating, based on the unfavorable access pattern, an anomaly detection indicator identifying the requestor; and

sending the anomaly detection indicator to other devices of the storage network.

2. The method of claim 1 , wherein the method further comprises:

initiating a secondary authentication process with the requestor;

receiving a secondary authentication response from the requestor; and

processing the access request when the secondary authentication response is favorable.

3. The method of claim 1 , wherein the method further comprises:

storing the access request in a local memory; and

associating the access request with at least one other access request, wherein the at least one other access request includes a request for the set of encoded data slices.

4. The method of claim 3 , wherein processing the access request includes:

extracting the at least one other access request associated with the access request; and

processing the access request and the at least one other access request in a sequence in accordance with a request type of the access request.

5. The method of claim 4 , wherein the access request and the at least one other access request include a write request, a commit request, and a finalize request of a three-phase storage process.

6. The method of claim 1 , wherein the access request is received via a dispersed storage and task (DST) processing unit that received the access request from the requestor.

7. The method of claim 1 , wherein detecting the unfavorable access pattern corresponds to one of a plurality of anomaly types.

8. The method of claim 1 , wherein detecting the access anomaly includes receiving a second anomaly detection indicator from another storage unit.

9. The method of claim 1 , wherein the anomaly detection indicator includes the access request.

10. The method of claim 1 , wherein another storage unit receives another access request associated with the requestor corresponding to the access request and queues the another access request in response to receiving the anomaly detection indicator.

11. A processing system of a storage network comprises:

at least one processor;

a memory that stores operational instructions that, when executed by the at least one processor, cause the processing system to perform operations that include:

detecting an access anomaly associated with an access request from a requestor for a set of encoded data slices, the access anomaly having an unfavorable access pattern, wherein the set of encoded data slices is dispersed storage error encoded and stored in at least one storage unit of the storage network;

denying the access request in response to detecting the access anomaly;

generating, based on the unfavorable access pattern, an anomaly detection indicator identifying the requestor; and

sending the anomaly detection indicator to other devices of the storage network.

12. The processing system of claim 11 , wherein the operations further include:

initiating a secondary authentication process with the requestor;

receiving a secondary authentication response from the requestor; and

processing the access request when the secondary authentication response is favorable.

13. The processing system of claim 11 , wherein the operations further include:

storing the access request in a local memory; and

associating the access request with at least one other access request, wherein the at least one other access request includes a request for the set of encoded data slices.

14. The processing system of claim 13 , wherein processing the access request includes:

extracting the at least one other access request associated with the access request; and

processing the access request and the at least one other access request in a sequence in accordance with a request type of the access request.

15. The processing system of claim 14 , wherein the access request and the at least one other access request include a write request, a commit request, and a finalize request of a three-phase storage process.

16. The processing system of claim 11 , wherein the access request is received via a dispersed storage and task (DST) processing unit that received the access request from the requestor.

17. The processing system of claim 11 , wherein detecting the unfavorable access pattern corresponds to one of a plurality of anomaly types.

18. The processing system of claim 11 , wherein detecting the access anomaly includes receiving a second anomaly detection indicator from another storage unit.

19. The processing system of claim 11 , wherein the anomaly detection indicator includes the access request.

20. The processing system of claim 11 , wherein another storage unit receives another access request associated with the requestor corresponding to the access request and queues the another access request in response to receiving the anomaly detection indicator.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2023
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 065492/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2023
From: RESCH, JASON K.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 065477/0988 →
Continuity (8)
Continuation 18149363 · Jan 3, 2023
Continuation 17301470 · Apr 5, 2021
Continuation 16554939 · Aug 29, 2019
Continuation 15841863 · Dec 14, 2017
Continuation In Part 15837705 · Dec 11, 2017
Continuation In Part 15006735 · Jan 26, 2016
Provisional Application 62140861 · Mar 31, 2015
Related Publication 20240069813A1 · Feb 29, 2024
References Cited (120)
US 4092732A · Ouchi · 1978 [cited by applicant]
US 5454101A · Mackay · 1995 [cited by applicant]
US 5485474A · Rabin · 1996 [cited by applicant]
US 5774643A · Lubbers · 1998 [cited by applicant]
US 5802364A · Senator · 1998 [cited by applicant]
US 5809285A · Hilland · 1998 [cited by applicant]
US 5890156A · Rekieta · 1999 [cited by applicant]
US 5987622A · Lo Verso · 1999 [cited by applicant]
US 5991414A · Garay · 1999 [cited by applicant]
US 6012159A · Fischer · 2000 [cited by applicant]
US 6058454A · Gerlach · 2000 [cited by applicant]
US 6128277A · Bruck · 2000 [cited by applicant]
US 6175571B1 · Haddock · 2001 [cited by applicant]
US 6192472B1 · Garay · 2001 [cited by applicant]
US 6256688B1 · Suetaka · 2001 [cited by applicant]
US 6272658B1 · Steele · 2001 [cited by applicant]
US 6301604B1 · Nojima · 2001 [cited by applicant]
US 6356949B1 · Katsandres · 2002 [cited by applicant]
US 6366995B1 · Nikolaevich · 2002 [cited by applicant]
US 6374336B1 · Peters · 2002 [cited by applicant]
US 6415373B1 · Peters · 2002 [cited by applicant]
US 6418539B1 · Walker · 2002 [cited by applicant]
US 6449688B1 · Peters · 2002 [cited by applicant]
US 6567948B2 · Steele · 2003 [cited by applicant]
US 6571282B1 · Bowman-Amuah · 2003 [cited by applicant]
US 6609223B1 · Wolfgang · 2003 [cited by applicant]
US 6718361B1 · Basani · 2004 [cited by applicant]
US 6760808B2 · Peters · 2004 [cited by applicant]
US 6785768B2 · Peters · 2004 [cited by applicant]
US 6785783B2 · Buckland · 2004 [cited by applicant]
US 6826711B2 · Moulton · 2004 [cited by applicant]
US 6879596B1 · Dooply · 2005 [cited by applicant]
US 7003688B1 · Pittelkow · 2006 [cited by applicant]
US 7024451B2 · Jorgenson · 2006 [cited by applicant]
US 7024609B2 · Wolfgang · 2006 [cited by applicant]
US 7080101B1 · Watson · 2006 [cited by applicant]
US 7103824B2 · Halford · 2006 [cited by applicant]
US 7103915B2 · Redlich · 2006 [cited by applicant]
US 7111115B2 · Peters · 2006 [cited by applicant]
US 7140044B2 · Redlich · 2006 [cited by applicant]
US 7146644B2 · Redlich · 2006 [cited by applicant]
US 7171493B2 · Shu · 2007 [cited by applicant]
US 7222133B1 · Raipurkar · 2007 [cited by applicant]
US 7240236B2 · Cutts · 2007 [cited by applicant]
US 7272613B2 · Sim · 2007 [cited by applicant]
US 7406653B2 · Ide · 2008 [cited by applicant]
US 7636724B2 · De La Torre · 2009 [cited by applicant]
US 7793138B2 · Rastogi · 2010 [cited by examiner]
US 8386840B2 · Stougie · 2013 [cited by applicant]
US 8572736B2 · Lin · 2013 [cited by examiner]
US 9083789B2 · Dicke · 2015 [cited by applicant]
US 9465837B1 · Ross · 2016 [cited by applicant]
US 9632872B2 · Dhuse · 2017 [cited by applicant]
US 9735967B2 · Leggette · 2017 [cited by applicant]
US 10114887B1 · Cheng · 2018 [cited by applicant]
US 10180809B2 · Fetik · 2019 [cited by applicant]
US 10713374B2 · Algie · 2020 [cited by applicant]
US 11204836B1 · Resch · 2021 [cited by applicant]
US 11276287B2 · Oppenheimer · 2022 [cited by examiner]
US 20020062422A1 · Butterworth · 2002 [cited by applicant]
US 20020166079A1 · Ulrich · 2002 [cited by applicant]
US 20030018927A1 · Gadir · 2003 [cited by applicant]
US 20030037261A1 · Meffert · 2003 [cited by applicant]
US 20030065617A1 · Watkins · 2003 [cited by applicant]
US 20030084020A1 · Shu · 2003 [cited by applicant]
US 20040024963A1 · Talagala · 2004 [cited by applicant]
US 20040122917A1 · Menon · 2004 [cited by applicant]
US 20040215998A1 · Buxton · 2004 [cited by applicant]
US 20040228493A1 · Ma · 2004 [cited by applicant]
US 20050100022A1 · Ramprashad · 2005 [cited by applicant]
US 20050114594A1 · Corbett · 2005 [cited by applicant]
US 20050125593A1 · Karpoff · 2005 [cited by applicant]
US 20050131993A1 · Fatula · 2005 [cited by applicant]
US 20050132070A1 · Redlich · 2005 [cited by applicant]
US 20050144382A1 · Schmisseur · 2005 [cited by applicant]
US 20050229069A1 · Hassner · 2005 [cited by applicant]
US 20060047907A1 · Shiga · 2006 [cited by applicant]
US 20060136448A1 · Cialini · 2006 [cited by applicant]
US 20060156059A1 · Kitamura · 2006 [cited by applicant]
US 20060224603A1 · Correll, Jr. · 2006 [cited by applicant]
US 20060277184A1 · Faitelson et al. · 2006 [cited by applicant]
US 20070079081A1 · Gladwin · 2007 [cited by applicant]
US 20070079082A1 · Gladwin · 2007 [cited by applicant]
US 20070079083A1 · Gladwin · 2007 [cited by applicant]
US 20070088970A1 · Buxton · 2007 [cited by applicant]
US 20070174192A1 · Gladwin · 2007 [cited by applicant]
US 20070214285A1 · Au · 2007 [cited by applicant]
US 20070234110A1 · Soran · 2007 [cited by applicant]
US 20070283167A1 · Venters, III · 2007 [cited by applicant]
US 20090094251A1 · Gladwin · 2009 [cited by applicant]
US 20090094318A1 · Gladwin · 2009 [cited by applicant]
US 20100023524A1 · Gladwin · 2010 [cited by applicant]
US 20110107185A1 · Grube · 2011 [cited by applicant]
US 20110126060A1 · Grube · 2011 [cited by applicant]
US 20130232503A1 · Volvovski · 2013 [cited by applicant]
US 20130346563A1 · Huang · 2013 [cited by applicant]
US 20140279104A1 · Grube · 2014 [cited by applicant]
US 20140281417A1 · Peters · 2014 [cited by applicant]
US 20140351300A1 · Uppu · 2014 [cited by applicant]
US 20140379714A1 · Hankins · 2014 [cited by examiner]
US 20150355957A1 · Steiner · 2015 [cited by examiner]
US 20190190844A1 · Resch · 2019 [cited by applicant]
Chung; An Automatic Data Segmentation Method for 3D Measured Data Points; National Taiwan University; pp. 1-8; 1998. [cited by applicant]
Harrison; Lightweight Directory Access Protocol (LDAP): Authentication Methods and Security Mechanisms; IETF Network Working Group; RFC 4513; Jun. 2006; pp. 1-32. [cited by applicant]
Kubiatowicz, et al.; OceanStore: An Architecture for Global-Scale Persistent Storage; Proceedings of the Ninth International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 20… [cited by applicant]
Legg; Lightweight Directory Access Protocol (LDAP): Syntaxes and Matching Rules; IETF Network Working Group; RFC 4517; Jun. 2006; pp. 1-50. [cited by applicant]
Plank, T1: Erasure Codes for Storage Applications; FAST2005, 4th Usenix Conference on File Storage Technologies; Dec. 13-16, 2005; pp. 1-74. [cited by applicant]
Rabin; Efficient Dispersal of Information for Security, Load Balancing, and Fault Tolerance; Journal of the Association for Computer Machinery; vol. 36, No. 2; Apr. 1989; pp. 335-348. [cited by applicant]
Satran, et al.; Internet Small Computer Systems Interface (iSCSI); IETF Network Working Group; RFC 3720; Apr. 2004; pp. 1-257. [cited by applicant]
Sciberras; Lightweight Directory Access Protocol (LDAP): Schema for User Applications; IETF Network Working Group; RFC 4519; Jun. 2006; pp. 1-33. [cited by applicant]
Sermersheim; Lightweight Directory Access Protocol (LDAP): The Protocol; IETF Network Working Group; RFC 4511; Jun. 2006; pp. 1-68. [cited by applicant]
Shamir; How to Share a Secret; Communications of the ACM; vol. 22, No. 11; Nov. 1979; pp. 612-613. [cited by applicant]
Smith; Lightweight Directory Access Protocol (LDAP): Uniform Resource Locator; IETF Network Working Group; RFC 4516; Jun. 2006; pp. 1-15. [cited by applicant]
Smith; Lightweight Directory Access Protocol (LDAP): String Representation of Search Filters; IETF Network Working Group; RFC 4515; Jun. 2006; pp. 1-12. [cited by applicant]
Wildi; Java iSCSi Initiator; Master Thesis; Department of Computer and Information Science, University of Konstanz; Feb. 2007; 60 pgs. [cited by applicant]
Xin, et al.; Evaluation of Distributed Recovery in Large-Scale Storage Systems; 13th IEEE International Symposium on High Performance Distributed Computing; Jun. 2004; pp. 172-181. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Directory Information Models; IETF Network Working Group; RFC 4512; Jun. 2006; pp. 1-49. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Internationalized String Preparation; IETF Network Working Group; RFC 4518; Jun. 2006; pp. 1-14. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): String Representation of Distinguished Names; IETF Network Working Group; RFC 4514; Jun. 2006; pp. 1-15. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Technical Specification Road Map; IETF Network Working Group; RFC 4510; Jun. 2006; pp. 1-8. [cited by applicant]