Distributed Credential Storage Using Encoded Authentication Slices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer storage systems face challenges with data integrity and security due to the failure of memory devices, especially those using physical movement technologies, and the inefficiencies and security risks associated with redundant array of independent discs (RAID) solutions.
Innovation Solution
A dispersed storage network (DSN) system that employs error coding dispersal storage functions to distribute data across multiple physically diverse locations, using a processing unit to partition data into slices, encode them, and store them across multiple DS units, ensuring data integrity and security through error correction and redundancy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in conventional memory devices or RAID systems, then storage capacity is achieved, but data integrity and security are compromised due to device failures and unauthorized access
Solution Approach 1:
The patent segments data into multiple distinct slices and stores them across different physically diverse locations in the dispersed storage network. This segmentation ensures that failure of any single storage device does not result in complete data loss, as the data is distributed and can be reconstructed from remaining slices.
Solution Approach 2:
The patent introduces an authentication credential as an intermediary mechanism that mediates access to stored data. The credential is stored separately from the data slices and must be presented to authorized access requests, providing an additional layer of security that prevents unauthorized access even if data slices are compromised.
2Reliability
If redundant storage systems like RAID are used, then data security is improved, but system complexity and vulnerability to unauthorized access increase
Solution Approach 1:
The patent simplifies the storage system by segmenting data into slices that are distributed across the network, eliminating the need for complex RAID configurations. Each slice is independently stored and can be independently accessed or recovered, reducing system complexity while maintaining security through distribution rather than redundancy.
Solution Approach 2:
The authentication credential acts as a simple intermediary that manages access control without adding complex storage redundancy. The credential verification process provides security through authentication rather than through complex redundant storage mechanisms, reducing overall system complexity.
3Reliability
If data is distributed across multiple locations, then data integrity is improved, but access management becomes more complex
Solution Approach 1:
The patent introduces an authentication credential as a centralized intermediary that simplifies access management across the distributed network. Instead of managing access controls at each distributed location, the single credential serves as a universal key that facilitates or denies access to authorized users, making access management easier despite data distribution.
Solution Approach 2:
The authentication credential serves multiple functions: it verifies user identity, authorizes access to data slices, and can be stored separately from the data itself. This multi-functionality simplifies access management by providing a single mechanism that handles various access control requirements across the distributed storage system.
Data Source
AI summary
A method for execution by a computing device of a storage network begins by obtaining a credential to be added to a local authentication list, where the credential authenticates, during a first time period, at least one of an access request and a requesting device, and where the local authentication list is stored in temporary memory of the computing device and is stored as a plurality of sets of encoded authentication slices in a set of storage units. The method continues by updating the local authentication list stored in the temporary memory to include a representation of the credential. The method continues by encoding the representation to produce a set of encoded authentication slices, where a decode threshold number of encoded authentication slices is needed to recover the representation. The method continues by sending the set of encoded authentication slices to the set of storage units for storage therein.


