Dispersed Storage Addressing for Reliable and Secure Data Slices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer storage systems face challenges with data integrity and security due to the failure of memory devices, particularly those using physical movement technologies, which can lead to data loss and increased maintenance demands, as well as security risks from redundant data replication.
Innovation Solution
A distributed storage system that uses error-coded data slices stored across multiple physically diverse locations, allowing for reliable and secure data retrieval and integrity verification, with a dispersed storage network that includes a processing unit for error encoding and decoding, and a managing unit for data distribution and security parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in redundant copies across multiple storage devices, then data reliability is improved, but security risks increase due to unauthorized access possibilities
Solution Approach 1:
The patent divides data into multiple segments or slices and distributes them across different storage devices. Each segment alone is insufficient to reconstruct the original data, providing both redundancy for reliability and security against unauthorized access. This is achieved through techniques like erasure coding where data is split into k segments and any m segments can be used to reconstruct the original, with k > m.
Solution Approach 2:
The patent introduces cryptographic intermediaries such as secret sharing schemes and homomorphic encryption to mediate between data storage and retrieval. These intermediaries allow data to be stored in encrypted form across multiple devices, where only authorized combinations of segments can be decrypted, thus maintaining security while achieving reliability through distribution.
2Object-affected harmful factors
If data is dispersed across multiple physically diverse locations, then security against unauthorized access is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal distributed storage framework that can operate across diverse physical locations using standardized protocols and interfaces. The system provides multi-functional capabilities including data slicing, encryption, error correction, and retrieval coordination through a unified architecture, reducing the perceived complexity for users while maintaining security through physical dispersion.
Solution Approach 2:
The patent incorporates feedback mechanisms where the distributed storage system continuously monitors the status, availability, and security of data segments across multiple locations. This feedback enables automatic reconciliation, error detection, and security verification, reducing the operational complexity of managing dispersed data while maintaining high security standards through continuous validation.
3Quantity of substance
If conventional memory devices with physical movement are used, then storage capacity is achieved, but data integrity deteriorates due to device failure
Solution Approach 1:
The patent applies error correction codes and redundancy mechanisms beforehand during the data encoding phase. Before data is stored in conventional memory devices that are prone to physical failure, the system adds corrective information and distributes redundant segments across multiple devices. This cushioning ensures that even if some devices fail due to physical movement issues, the original data integrity is preserved through the pre-built error correction capabilities.
Data Source
AI summary
A method begins by a dispersed storage (DS) processing module obtaining a plurality of data objects for storage in a dispersed storage network (DSN) and determining one or more common data object aspects of a data object of the plurality of data objects. The method continues with the DS processing module disperse storage error encoding at least a portion of the data object to produce a set of encoded data slices and generating a set of DSN addresses for the set of encoded data slices, wherein each of the set of DSN addresses includes a field referencing the one or more common data object aspects. The method continues with the DS processing module outputting the set of encoded data slices for storage in the DSN based on the set of DSN addresses.


