Key Sharing in a Distributed Storage Network
A method includes encoding a data segment into a set of encoded data slices using erasure coding; storing, in storage units of a storage network, the set of encoded data slices, in accordance with a shared key-based encryption system (SKBES) having keys shared with the storage units; retrieving, at a periodic rate and in accordance with the SKBES, the set of encoded data slices from the storage units of the storage unit to verify whether individual slices of the set of encoded data slices have been corrupted. When one of the set of encoded data slices stored in one of the storage units has been corrupted, rebuilding the one of the set of encoded data slices by: retrieving the decode threshold number of other slices of the set of encoded data slices, in accordance with the SKBES; reconstructing the one of the set of encoded data slices based on the erasure encoding, to generate a reconstructed data slice; and storing, in accordance with the SKBES, the reconstructed data slice in the one of the storage units.
1 . A method comprises:
storing, in storage units of a storage network, a set of encoded data slices in accordance with a shared key-based encryption system that includes sharing a first key among a first subset of the storage units and sharing a second key, that differs from the first key, among a second subset of the storage units that differs from the first subset of the storage units;
retrieving, in accordance with the shared key-based encryption system, the set of encoded data slices from one or more of the storage units of the storage network to verify whether individual slices of the set of encoded data slices have been corrupted; and
when one of the set of encoded data slices stored in the one or more of the storage units has been corrupted, rebuilding the one of the set of encoded data slices by:
retrieving a decode threshold number of other slices of the set of encoded data slices, in accordance with the shared key-based encryption system;
reconstructing the one of the set of encoded data slices based on a dispersed error encoding, to generate a reconstructed data slice; and
storing, in accordance with the shared key-based encryption system, the reconstructed data slice.
2 . The method of claim 1 , further comprising:
identifying a subset of other storage units of the storage network, wherein the one or more storage units and the subset of other storage units comprise a set of storage units of the storage network that store the set of encoded data slices, wherein the set of encoded data slices are associated with a storage vault;
determining that a number of available storage units in the set of storage units is greater than the decode threshold number based on an update status of the set of storage units; and
updating respective software of the set of storage units including the respective software of the one or more storage units, while maintaining availability of the decode threshold number of the storage units of the set of storage units to service access requests for the set of encoded data slices.
3 . The method of claim 2 , wherein updating the respective software of the set of storage units is based on a status of a software update, and wherein the status of the software update includes one or more of a mandatory critical status, a mandatory non-critical status, and an optional status.
4 . The method of claim 3 , wherein the update status includes one or more of available, unavailable, already updated, and not already updated.
5 . The method of claim 2 , further comprising:
identifying a plurality of storage vaults supported by the one or more storage units, wherein the plurality of storage vaults includes the storage vault;
identifying a plurality of subsets of other storage units of the storage network, wherein the plurality of subsets of other storage units includes the subset of other storage units, wherein the one or more storage units and each of the plurality of subsets of other storage units comprise each of a plurality of sets of storage units that support one of the plurality of storage vaults, and wherein the plurality of sets of storage units includes the set of storage units; and
updating the respective software of the set of storage units, including the respective software of the one or more storage units, while maintaining availability of the decode threshold number of storage units of each set of storage units in the plurality of sets of storage units.
6 . The method of claim 5 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another one of the plurality of storage vaults, wherein the decode threshold number of the storage units is needed to reconstruct other data encoded in the other encoded data slices, further comprising:
determining that another number of available storage units in the another set of storage units is equal to the decode threshold number of the storage units; and
determining to update the respective software of the another set of storage units later in response to determining the another number of available storage units is equal to the decode threshold number of the storage units.
7 . The method of claim 5 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another storage vault, wherein another decode threshold number of storage units is needed to reconstruct other data encoded in other encoded data slices, and wherein the another decode threshold number of storage units is different from the decode threshold number of the storage units, further comprising:
determining another number of available storage units in the another set of storage units is greater than the another decode threshold number of storage units.
8 . The method of claim 7 , further comprising:
determining a priority for each of the plurality of storage vaults, wherein a first one of the plurality of storage vaults corresponding the set of storage units has a first priority.
9 . The method of claim 8 , wherein a second one of the plurality of storage vaults corresponding to the another set of storage units has a second priority.
10 . The method of claim 1 , wherein sharing the keys with the storage units via the shared key-based encryption system includes sharing a first key between a first pair of the storage units and sharing a second key between a second pair of the storage units that differs from the first pair.
11 . A system comprising:
a communications interface;
a memory; and
a computer processor;
wherein the memory includes instructions for causing the computer processor to perform operations that include:
storing, in storage units of a storage network, a set of encoded data slices in accordance with a shared key-based encryption system that includes sharing a first key among a first subset of the storage units and sharing a second key, that differs from the first key, among a second subset of the storage units that differs from the first subset of the storage units;
retrieving, in accordance with the shared key-based encryption system, the set of encoded data slices from one or more of the storage units of the storage network to verify whether individual slices of the set of encoded data slices have been corrupted; and
when one of the set of encoded data slices stored in the one or more of the storage units has been corrupted, rebuilding the one of the set of encoded data slices by:
retrieving a decode threshold number of other slices of the set of encoded data slices, in accordance with the shared key-based encryption system;
reconstructing the one of the set of encoded data slices based on a dispersed error encoding, to generate a reconstructed data slice; and
storing, in accordance with the shared key-based encryption system, the reconstructed data slice.
12 . The system of claim 11 , wherein the operations further comprise:
identifying a subset of other storage units of the storage network, wherein the one or more storage units and the subset of other storage units comprise a set of storage units of the storage network that store the set of encoded data slices, wherein the set of encoded data slices are associated with a storage vault;
determining that a number of available storage units in the set of storage units is greater than the decode threshold number based on an update status of the set of storage units; and
updating respective software of the set of storage units including the respective software of the one or more storage units, while maintaining availability of the decode threshold number of the storage units of the set of storage units to service access requests for the set of encoded data slices.
13 . The system of claim 12 , wherein updating the respective software of the set of storage units is based on a status of a software update, and wherein the status of the software update includes one or more of a mandatory critical status, a mandatory non-critical status, and an optional status.
14 . The system of claim 13 , wherein the update status includes one or more of available, unavailable, already updated, and not already updated.
15 . The system of claim 12 , wherein the operations further comprise:
identifying a plurality of storage vaults supported by the one or more storage units, wherein the plurality of storage vaults includes the storage vault;
identifying a plurality of subsets of other storage units of the storage network, wherein the plurality of subsets of other storage units includes the subset of other storage units, wherein the one or more storage units and each of the plurality of subsets of other storage units comprise each of a plurality of sets of storage units that support one of the plurality of storage vaults, and wherein the plurality of sets of storage units includes the set of storage units; and
updating the respective software of the set of storage units, including the respective software of the one or more storage units, while maintaining availability of the decode threshold number of storage units of each set of storage units in the plurality of sets of storage units.
16 . The system of claim 15 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another one of the plurality of storage vaults, wherein the decode threshold number of the storage units is needed to reconstruct other data encoded in the other encoded data slices, wherein the operations further comprise:
determining that another number of available storage units in the another set of storage units is equal to the decode threshold number of the storage units; and
determining to update the respective software of the another set of storage units later in response to determining the another number of available storage units is equal to the decode threshold number of the storage units.
17 . The system of claim 15 , wherein another set of storage units of the plurality of sets of storage units stores other encoded data slices associated with another storage vault, wherein another decode threshold number of storage units is needed to reconstruct other data encoded in other encoded data slices, and wherein the another decode threshold number of storage units is different from the decode threshold number of the storage units, wherein the operations further comprise:
determining another number of available storage units in the another set of storage units is greater than the another decode threshold number of storage units.
18 . The system of claim 17 , wherein the operations further comprise:
determining a priority for each of the plurality of storage vaults, wherein a first one of the plurality of storage vaults corresponding the set of storage units has a first priority.
19 . The system of claim 18 , wherein a second one of the plurality of storage vaults corresponding to the another set of storage units has a second priority.
20 . The system of claim 11 , wherein sharing the keys with the storage units via the shared key-based encryption system includes sharing a first key between a first pair of the storage units and sharing a second key between a second pair of the storage units that differs from the first pair.