IP Library Granted Patent US 12,222,822
Granted Patent B2
US 12,222,822 · App. 18/526,419 · Granted Feb 11, 2025

Secure storage network and methods for use therewith

Inventors: Jason K. Resch (Warwick, RI); Wesley Leggette (Chicago, IL)
Assignee: Pure Storage, Inc.
G06F11/1464G06F3/0617G06F3/0619G06F3/0635G06F3/065G06F3/067G06F16/172G06F16/9535H04L63/10H04L67/1097G06F11/0709G06F11/0751G06F11/1076G06F11/2038G06F11/2048G06F11/2094G06F2201/80G06F2211/1028
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,222,822
App. No.
18/526,419
Granted
Feb 11, 2025
Kind
B2
Abstract

A storage network operates by: encoding a data segment into a set of encoded data slices, wherein a read threshold of encoded data slices of the set of encoded data slices is required to decode the data segment, wherein the read threshold has a value greater than one, and wherein the data segment has an associated security level; selecting a subset of the plurality of storage units based on the security level, wherein the subset includes at least the read threshold of storage units of the plurality of storage units, wherein each of the subset of the plurality of storage units has a connection security approach that corresponds to the security level; and communicating the set of encoded data slices to the subset of the plurality of storage units in accordance with the connection security approach associated with each of the subset of the plurality of storage units.

Claims (48)

1. A method for execution by one or more computing devices of a storage network having a plurality of storage units, the method comprises:

encoding a data segment into a set of encoded data slices, wherein a read threshold of encoded data slices of the set of encoded data slices is required to decode the data segment, wherein the read threshold has a value greater than one, and wherein the data segment has an associated security level;

selecting a subset of the plurality of storage units based on the security level, wherein the subset includes at least the read threshold of storage units of the plurality of storage units, wherein each of the subset of the plurality of storage units has a connection security approach that corresponds to the security level; and

communicating the set of encoded data slices to the subset of the plurality of storage units in accordance with the connection security approach associated with each of the subset of the plurality of storage units.

2. The method of claim 1 , wherein the connection security approach for one of the subset of the plurality of storage units includes a first key.

3. The method of claim 2 , wherein the connection security approach for another one of the subset of the plurality of storage units includes a second key.

4. The method of claim 1 , wherein the connection security approach for one of the subset of the plurality of storage units includes a first the connection security approach for another one of the subset of the plurality of storage units includes a second cipher employed.

5. The method of claim 1 , wherein the connection security approach for one of the subset of the plurality of storage units includes at least one of:

a transmission control protocol connection that is based on a user identifier and security credentials;

a transport layer security null cipher connection that is based on the user identifier and the security credentials; or

a transport layer security cipher connection that is based on the user identifier and the security credentials.

6. The method of claim 1 , wherein the security level includes one of:

a first level with no tampering protection and with no eavesdropping protection;

a second level with the tampering protection and with the no eavesdropping protection; or

a third level with the tampering protection and with eavesdropping protection.

7. The method of claim 1 wherein the security level is determined based on a corresponding proximity of each of the subset of the plurality of storage units from the one or more computing devices.

8. A processing unit for use in a storage network having a plurality of storage units, the processing unit comprising:

an interface;

memory; and

one or more processors operably coupled to the interface and the memory, wherein the one or more processors are operable to perform operations including:

encoding a data segment into a set of encoded data slices, wherein a read threshold of encoded data slices of the set of encoded data slices is required to decode the data segment, wherein the read threshold has a value greater than one, and wherein the data segment has an associated security level;

selecting a subset of the plurality of storage units based on the security level, wherein the subset includes at least the read threshold of storage units of the plurality of storage units, wherein each of the subset of the plurality of storage units has a connection security approach that corresponds to the security level; and

communicating the set of encoded data slices to the subset of the plurality of storage units in accordance with the connection security approach associated with each of the subset of the plurality of storage units.

9. The processing unit of claim 8 , wherein the connection security approach for one of the subset of the plurality of storage units includes a first key.

10. The processing unit of claim 9 , wherein the connection security approach for another one of the subset of the plurality of storage units includes a second key.

11. The processing unit of claim 8 , wherein the connection security approach for one of the subset of the plurality of storage units includes a first the connection security approach for another one of the subset of the plurality of storage units includes a second cipher employed.

12. The processing unit of claim 8 , wherein the connection security approach for one of the subset of the plurality of storage units includes at least one of:

a transmission control protocol connection that is based on a user identifier and security credentials;

a transport layer security null cipher connection that is based on the user identifier and the security credentials; or

a transport layer security cipher connection that is based on the user identifier and the security credentials.

13. The processing unit of claim 8 , wherein the security level includes one of:

a first level with no tampering protection and with no eavesdropping protection;

a second level with the tampering protection and with the no eavesdropping protection; or

a third level with the tampering protection and with eavesdropping protection.

14. The processing unit of claim 8 , wherein the security level is determined based on a corresponding proximity of each of the subset of the plurality of storage units from the processing unit.

15. A tangible computer readable storage medium for use in a storage network having a plurality of storage units, the tangible computer readable storage medium comprising:

at least one non-transitory memory section that stores operational instructions that, when executed by one or more processors of one or more computing devices of a storage network, causes the one or more computing devices to perform operations including:

encoding a data segment into a set of encoded data slices, wherein a read threshold of encoded data slices of the set of encoded data slices is required to decode the data segment, wherein the read threshold has a value greater than one, and wherein the data segment has an associated security level;

selecting a subset of the plurality of storage units based on the security level, wherein the subset includes at least the read threshold of storage units of the plurality of storage units, wherein each of the subset of the plurality of storage units has a connection security approach that corresponds to the security level; and

communicating the set of encoded data slices to the subset of the plurality of storage units in accordance with the connection security approach associated with each of the subset of the plurality of storage units.

16. The tangible computer readable storage medium of claim 15 , wherein the connection security approach for one of the subset of the plurality of storage units includes a first key.

17. The tangible computer readable storage medium of claim 16 , wherein the connection security approach for another one of the subset of the plurality of storage units includes a second key.

18. The tangible computer readable storage medium of claim 15 , wherein the connection security approach for one of the subset of the plurality of storage units includes a first the connection security approach for another one of the subset of the plurality of storage units includes a second cipher employed.

19. The tangible computer readable storage medium of claim 15 , wherein the connection security approach for one of the subset of the plurality of storage units includes at least one of:

a transmission control protocol connection that is based on a user identifier and security credentials;

a transport layer security null cipher connection that is based on the user identifier and the security credentials; or

a transport layer security cipher connection that is based on the user identifier and the security credentials.

20. The tangible computer readable storage medium of claim 15 , wherein the security level is determined based on a corresponding proximity of each of the subset of the plurality of storage units from the one or more computing devices.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 065775/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2023
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 065749/0849 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2023
From: RESCH, JASON K.; LEGGETTE, WESLEY
To: CLEVERSAFE, INC.
Reel/Frame 065735/0061 →
Continuity (11)
Continuation 17453370 · Nov 3, 2021
Continuation 16910522 · Jun 24, 2020
Continuation 16185573 · Nov 9, 2018
Continuation 14315775 · Jun 26, 2014
Continuation 12886389 · Sep 20, 2010
Continuation In Part 12080042 · Mar 31, 2008
Continuation In Part 11973542 · Oct 9, 2007
Continuation In Part 11403391 · Apr 13, 2006
Continuation In Part 11241555 · Sep 30, 2005
Provisional Application 61264297 · Nov 25, 2009
Related Publication 20240095131A1 · Mar 21, 2024
References Cited (136)
US 4092732A · Ouchi · 1978 [cited by applicant]
US 5454101A · Mackay · 1995 [cited by applicant]
US 5485474A · Rabin · 1996 [cited by applicant]
US 5581690A · Ellis et al. · 1996 [cited by applicant]
US 5774643A · Lubbers · 1998 [cited by applicant]
US 5802364A · Senator · 1998 [cited by applicant]
US 5809285A · Hilland · 1998 [cited by applicant]
US 5832000A · Lin · 1998 [cited by applicant]
US 5890156A · Rekieta · 1999 [cited by applicant]
US 5987622A · Lo Verso · 1999 [cited by applicant]
US 5991414A · Garay · 1999 [cited by applicant]
US 6012159A · Fischer · 2000 [cited by applicant]
US 6058454A · Gerlach · 2000 [cited by applicant]
US 6128277A · Bruck · 2000 [cited by applicant]
US 6175571B1 · Haddock · 2001 [cited by applicant]
US 6192472B1 · Garay · 2001 [cited by applicant]
US 6256688B1 · Suetaka · 2001 [cited by applicant]
US 6272658B1 · Steele · 2001 [cited by applicant]
US 6301604B1 · Nojima · 2001 [cited by applicant]
US 6356949B1 · Katsandres · 2002 [cited by applicant]
US 6366995B1 · Nikolaevich · 2002 [cited by applicant]
US 6374336B1 · Peters · 2002 [cited by applicant]
US 6415373B1 · Peters · 2002 [cited by applicant]
US 6418539B1 · Walker · 2002 [cited by applicant]
US 6449688B1 · Peters · 2002 [cited by applicant]
US 6502194B1 · Berman · 2002 [cited by applicant]
US 6553511B1 · DeKoning · 2003 [cited by applicant]
US 6567948B2 · Steele · 2003 [cited by applicant]
US 6571282B1 · Bowman-Amuah · 2003 [cited by applicant]
US 6609223B1 · Wolfgang · 2003 [cited by applicant]
US 6718361B1 · Basani · 2004 [cited by applicant]
US 6728922B1 · Sundaram · 2004 [cited by applicant]
US 6760808B2 · Peters · 2004 [cited by applicant]
US 6785768B2 · Peters · 2004 [cited by applicant]
US 6785783B2 · Buckland · 2004 [cited by applicant]
US 6826711B2 · Moulton · 2004 [cited by applicant]
US 6879596B1 · Dooply · 2005 [cited by applicant]
US 6971096B1 · Ankireddipally · 2005 [cited by applicant]
US 7003688B1 · Pittelkow · 2006 [cited by applicant]
US 7024451B2 · Jorgenson · 2006 [cited by applicant]
US 7024609B2 · Wolfgang · 2006 [cited by applicant]
US 7080101B1 · Watson · 2006 [cited by applicant]
US 7103824B2 · Halford · 2006 [cited by applicant]
US 7103915B2 · Redlich · 2006 [cited by applicant]
US 7111115B2 · Peters · 2006 [cited by applicant]
US 7140044B2 · Redlich · 2006 [cited by applicant]
US 7146461B1 · Kiselev et al. · 2006 [cited by applicant]
US 7146644B2 · Redlich · 2006 [cited by applicant]
US 7171493B2 · Shu · 2007 [cited by applicant]
US 7222133B1 · Raipurkar · 2007 [cited by applicant]
US 7240236B2 · Cutts · 2007 [cited by applicant]
US 7272613B2 · Sim · 2007 [cited by applicant]
US 7278067B1 · Coatney et al. · 2007 [cited by applicant]
US 7506155B1 · Stewart · 2009 [cited by applicant]
US 7636724B2 · De La Torre · 2009 [cited by applicant]
US 7721157B2 · Spitz · 2010 [cited by applicant]
US 8117155B2 · Chen · 2012 [cited by applicant]
US 8396895B2 · Miloushev · 2013 [cited by applicant]
US 8418233B1 · Hughes · 2013 [cited by applicant]
US 20020062422A1 · Butterworth · 2002 [cited by applicant]
US 20020166079A1 · Ulrich · 2002 [cited by applicant]
US 20030018927A1 · Gadir · 2003 [cited by applicant]
US 20030037261A1 · Meffert · 2003 [cited by applicant]
US 20030065617A1 · Watkins · 2003 [cited by applicant]
US 20030084020A1 · Shu · 2003 [cited by applicant]
US 20030120723A1 · Bright · 2003 [cited by applicant]
US 20030120949A1 · Redlich · 2003 [cited by applicant]
US 20030233455A1 · Leber · 2003 [cited by applicant]
US 20040024963A1 · Talagala · 2004 [cited by applicant]
US 20040117718A1 · Manasse · 2004 [cited by applicant]
US 20040122917A1 · Menon · 2004 [cited by applicant]
US 20040215998A1 · Buxton · 2004 [cited by applicant]
US 20040228493A1 · Ma · 2004 [cited by applicant]
US 20050050383A1 · Horn · 2005 [cited by applicant]
US 20050100022A1 · Ramprashad · 2005 [cited by applicant]
US 20050114594A1 · Corbett · 2005 [cited by applicant]
US 20050125593A1 · Karpoff · 2005 [cited by applicant]
US 20050131993A1 · Fatula · 2005 [cited by applicant]
US 20050132070A1 · Redlich · 2005 [cited by applicant]
US 20050144382A1 · Schmisseur · 2005 [cited by applicant]
US 20050144514A1 · Ulrich et al. · 2005 [cited by applicant]
US 20050195735A1 · Brady · 2005 [cited by applicant]
US 20050223272A1 · Yasuhara · 2005 [cited by applicant]
US 20050229069A1 · Hassner · 2005 [cited by applicant]
US 20050283645A1 · Turner · 2005 [cited by applicant]
US 20060047907A1 · Shiga · 2006 [cited by applicant]
US 20060136448A1 · Cialini · 2006 [cited by applicant]
US 20060156059A1 · Kitamura · 2006 [cited by applicant]
US 20060224603A1 · Correll, Jr. · 2006 [cited by applicant]
US 20070050686A1 · Keeton · 2007 [cited by applicant]
US 20070079081A1 · Gladwin · 2007 [cited by applicant]
US 20070079082A1 · Gladwin · 2007 [cited by applicant]
US 20070079083A1 · Gladwin · 2007 [cited by applicant]
US 20070088970A1 · Buxton · 2007 [cited by applicant]
US 20070140494A1 · Kumoluyi · 2007 [cited by applicant]
US 20070143359A1 · Uppala · 2007 [cited by applicant]
US 20070150481A1 · Song · 2007 [cited by applicant]
US 20070150965A1 · Redlich · 2007 [cited by applicant]
US 20070174192A1 · Gladwin · 2007 [cited by applicant]
US 20070021425A1 · Spitz et al. · 2007 [cited by applicant]
US 20070214285A1 · Au · 2007 [cited by applicant]
US 20070234110A1 · Soran · 2007 [cited by applicant]
US 20070282868A1 · Wanigasekara-Mohotti · 2007 [cited by applicant]
US 20070283167A1 · Venters, II · 2007 [cited by applicant]
US 20080096526A1 · Miettinen · 2008 [cited by applicant]
US 20080183975A1 · Foster · 2008 [cited by applicant]
US 20080244030A1 · Leitheiser · 2008 [cited by applicant]
US 20090094251A1 · Gladwin · 2009 [cited by applicant]
US 20090094318A1 · Gladwin · 2009 [cited by applicant]
US 20100023524A1 · Gladwin · 2010 [cited by applicant]
US 20100269008A1 · Leggette · 2010 [cited by examiner]
US 20100036578A1 · Lohn · 2010 [cited by applicant]
US 20110264905A1 · Ovsiannikov · 2011 [cited by applicant]
US 20120042162A1 · Anglin · 2012 [cited by applicant]
EP 1191442A2 · 2002 [cited by applicant]
WO 2007103533A1 · 2007 [cited by applicant]
Chung; An Automatic Data Segmentation Method for 3D Measured Data Points; National Taiwan University; pp. 1-8; 1998. [cited by applicant]
European Patent Office; Extended European Search Report; Jul. 19, 2012; 7 pages. [cited by applicant]
European Patent Office; Extended European Search Report; EP Application No. 09727284.3; Oct. 29, 2015; 8 pgs. [cited by applicant]
Harrison; Lightweight Directory Access Protocol (LDAP): Authentication Methods and Security Mechanisms; IETF Network Working Group; RFC 4513; Jun. 2006; pp. 1-32. [cited by applicant]
Kubiatowicz, et al.; OceanStore: An Architecture for Global-Scale Persistent Storage; Proceedings of the Ninth International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS 20… [cited by applicant]
Legg; Lightweight Directory Access Protocol (LDAP): Syntaxes and Matching Rules; IETF Network Working Group; RFC 4517; Jun. 2006; pp. 1-50. [cited by applicant]
Plank, T1: Erasure Codes for Storage Applications; FAST2005, 4th Usenix Conference on File Storage Technologies; Dec. 13-16, 2005; pp. 1-74. [cited by applicant]
Rabin; Efficient Dispersal of Information for Security, Load Balancing, and Fault Tolerance; Journal of the Association for Computer Machinery; vol. 36, No. 2; Apr. 1989; pp. 335-348. [cited by applicant]
Satran, et al.; Internet Small Computer Systems Interface (ISCSI); IETF Network Working Group; RFC 3720; Apr. 2004; pp. 1-257. [cited by applicant]
Sciberras; Lightweight Directory Access Protocol (LDAP): Schema for User Applications; IETF Network Working Group; RFC 4519; Jun. 2006; pp. 1-33. [cited by applicant]
Sermersheim; Lightweight Directory Access Protocol (LDAP): The Protocol; IETF Network Working Group; RFC 4511; Jun. 2006; pp. 1-68. [cited by applicant]
Shamir; How to Share a Secret; Communications of the ACM; vol. 22, No. 11; Nov. 1979; pp. 612-613. [cited by applicant]
Smith; Lightweight Directory Access Protocol (LDAP): Uniform Resource Locator; IETF Network Working Group; RFC 4516; Jun. 2006; pp. 1-15. [cited by applicant]
Smith; Lightweight Directory Access Protocol (LDAP): String Representation of Search Filters; IETF Network Working Group; RFC 4515; Jun. 2006; pp. 1-12. [cited by applicant]
Wildi; Java iSCSi Initiator; Master Thesis; Department of Computer and Information Science, University of Konstanz; Feb. 2007; 60 pgs. [cited by applicant]
Xin, et al.; Evaluation of Distributed Recovery in Large-Scale Storage Systems; 13th IEEE International Symposium on High Performance Distributed Computing; Jun. 2004; pp. 172-181. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Directory Information Models; IETF Network Working Group; RFC 4512; Jun. 2006; pp. 1-49. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Internationalized String Preparation; IETF Network Working Group; RFC 4518; Jun. 2006; pp. 1-14. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): String Representation of Distinguished Names; IETF Network Working Group; RFC 4514; Jun. 2006; pp. 1-15. [cited by applicant]
Zeilenga; Lightweight Directory Access Protocol (LDAP): Technical Specification Road Map; IETF Network Working Group; RFC 4510; Jun. 2006; pp. 1-8. [cited by applicant]
Cited By (1)
US 12,339,937