IP Library Granted Patent US 10,387,213
Granted Patent B2
US 10,387,213 · App. 16/113,437 · Granted Aug 20, 2019

Dispersed storage network secure hierarchical file directory

Inventors: Wesley Leggette (Chicago, IL); Jason K. Resch (Chicago, IL)
Assignee: PURE STORAGE, INC.
G06F9/5083G06F9/5077G06F11/1008G06F11/1076G06F11/1092G06F11/1451G06F11/2058G06F11/2069G06F21/602G06F21/6218H04L63/0428H04L63/06H04L67/10H04L67/1017H04L67/1097G06F3/064G06F3/067G06F3/0619G06F2211/1028H03M13/09H03M13/1515H04L63/08H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,387,213
App. No.
16/113,437
Granted
Aug 20, 2019
Kind
B2
Abstract

A method includes creating a file directory entry in a directory file of a secure hierarchical file directory system for a file. The file directory entry includes a path name, an encryption access control list, and a source name. The file is encrypted with a key and the key is encrypted with each public key of user devices authorized to access the file. The encryption access control list includes identities of the set of user devices and the set of object content keys. The method further includes encrypting the directory file using a second key. The method further includes generating second object content keys based on the second key and public keys of second user devices authorized to access the directory file. The method further includes creating a next level directory file entry in a next higher directory file of the secure hierarchical file directory system for the directory file.

Claims (48)

1. A method for execution by a processing module to generate a secure hierarchical file directory system, the method comprises:

encrypting a directory file using a second key to produce an encrypted directory file of the secure hierarchical file directory system for a file, wherein the directory file includes a file directory entry having a path name for the file, an encryption access control list, and a source name of the file, wherein the file is encrypted with a key, wherein the key is encrypted with each public key of a set of user devices that is authorized to access the file to produce a set of object content keys, and wherein the encryption access control list includes identities of the set of user devices and the set of object content keys;

generating a second set of object content keys based on the second key and public keys of a second set of user devices authorized to access the directory file; and

creating a next level directory file entry in a next higher directory file of the secure hierarchical file directory system for the directory file, wherein the next level file directory entry includes a next level path name for the file directory, a second encryption access control list, and a second source name of the file directory, and wherein the second encryption access control list includes the second set of object content keys and identities of the second set of user devices, wherein the second set of user devices includes the set of user devices.

2. The method of claim 1 further comprises:

dispersed storage error encoding the encrypted file to produce a plurality of sets of encoded data slices.

3. The method of claim 2 further comprises:

generating a plurality of sets of slice names for the plurality of sets of encoded data slices based on the source name of the file.

4. The method of claim 3 further comprises:

sending, based on the plurality of sets of slice names, the plurality of sets of encoded data slices to storage units for storage therein.

5. The method of claim 1 further comprises:

dispersed storage error encoding the encrypted directory file to produce a set of encoded data slices.

6. The method of claim 5 further comprises:

generating a sets of slice names for the set of encoded data slices based on the source name of the directory file.

7. The method of claim 6 further comprises:

sending, based on the set of slice names, the set of encoded data slices to storage units for storage therein.

8. The method of claim 1 further comprises:

encrypting the next level directory file using a third key to produce a second encrypted directory file.

9. The method of claim 8 further comprises:

generating a third set of object content keys based on the third key and public keys of a third set of user devices authorized to access the next level directory file.

10. The method of claim 9 further comprises:

creating a subsequent next level directory file entry in a subsequent next higher directory file of the secure hierarchical file directory system for the next level directory file, wherein the subsequent next level file directory entry includes a subsequent next level path name for the next level file directory, a third encryption access control list, and a third source name of the next level file directory, and wherein the third encryption access control list includes identities of the third set of user devices and the third set of object content keys, wherein the third set of user devices includes the second set of user devices.

11. A dispersed storage (DS) module comprises:

a processing system including a processing module and a memory, wherein the processing system is configured to perform operations that include:

encrypting a directory file using a second key to produce an encrypted directory file of secure hierarchical file directory system for a file, wherein the directory file includes a file directory entry having a path name for the file, an encryption access control list, and a source name of the file, wherein the file is encrypted with a key, wherein the key is encrypted with each public key of a set of user devices that is authorized to access the file to produce a set of object content keys, and wherein the encryption access control list includes identities of the set of user devices and the set of object content keys;

generating a second set of object content keys based on the second key and public keys of a second set of user devices authorized to access the directory file; and

creating a next level directory file entry in a next higher directory file of the secure hierarchical file directory system for the directory file, wherein the next level file directory entry includes a next level path name for the file directory, a second encryption access control list, and a second source name of the file directory, and wherein the second encryption access control list includes the second set of object content keys and identities of the second set of user devices, wherein the second set of user devices includes the set of user devices.

12. The DS module of claim 11 , wherein the operations further include:

dispersed storage error encoding the encrypted file to produce a plurality of sets of encoded data slices.

13. The DS module of claim 12 , wherein the operations further include:

generating a plurality of sets of slice names for the plurality of sets of encoded data slices based on the source name of the file.

14. The DS module of claim 13 , wherein the operations further include:

sending, based on the plurality of sets of slice names, the plurality of sets of encoded data slices to storage units for storage therein.

15. The DS module of claim 11 , wherein the operations further include:

dispersed storage error encoding the encrypted directory file to produce a set of encoded data slices.

16. The DS module of claim 15 , wherein the operations further include:

generating a sets of slice names for the set of encoded data slices based on the source name of the directory file.

17. The DS module of claim 16 , wherein the operations further include:

sending, based on the set of slice names, the set of encoded data slices to storage units for storage therein.

18. The DS module of claim 11 , wherein the operations further include:

encrypting the next level directory file using a third key to produce a second encrypted directory file.

19. The DS module of claim 18 , wherein the operations further include:

generating a third set of object content keys based on the third key and public keys of a third set of user devices authorized to access the next level directory file.

20. A computer readable storage medium comprises:

at least one memory section that stores operational instructions that, when executed by a processing system of a dispersed storage network (DSN) that includes a processor and a memory, causes the processing system to perform operations that include:

encrypting a directory file using a second key to produce an encrypted directory file of a secure hierarchical file directory system for a file, wherein the directory file includes a file directory entry having a path name for the file, an encryption access control list, and a source name of the file, wherein the file is encrypted with a key, wherein the key is encrypted with each public key of a set of user devices that is authorized to access the file to produce a set of object content keys, and wherein the encryption access control list includes identities of the set of user devices and the set of object content keys;

generating a second set of object content keys based on the second key and public keys of a second set of user devices authorized to access the directory file; and

creating a next level directory file entry in a next higher directory file of the secure hierarchical file directory system for the directory file, wherein the next level file directory entry includes a next level path name for the file directory, a second encryption access control list, and a second source name of the file directory, and wherein the second encryption access control list includes the second set of object content keys and identities of the second set of user devices, wherein the second set of user devices includes the set of user devices.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: PURE STORAGE, INC.
Reel/Frame 049556/0288 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2018
From: CLEVERSAFE, INC.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 046948/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2018
From: LEGGETTE, WESLEY; RESCH, JASON K.
To: CLEVERSAFE, INC.
Reel/Frame 046713/0698 →
Continuity (5)
Continuation 15794865 · Oct 26, 2017
Continuation 13865641 · Apr 8, 2013
Continuation In Part 13707490 · Dec 6, 2012
Provisional Application 61569387 · Dec 12, 2011
Related Publication 20190012213A1 · Jan 10, 2019