Dispersed Storage Network Data Access Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer networks face challenges in ensuring data integrity and security when using dispersed storage systems, particularly in handling error-encoded data across multiple storage units, as they are prone to data loss and unauthorized access.

Innovation Solution

A dispersed storage network (DSN) with a managing unit, integrity processing unit, and computing devices that utilize error encoding and decoding functions like Cauchy Reed-Solomon encoding to distribute data across multiple storage units, ensuring data integrity and security through redundancy and secure access tracking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is dispersed across multiple storage units, then data security and fault tolerance are improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into multiple encoded slices and disperses them across different storage units. Each slice is independently stored, and the system can reconstruct the original data from any sufficient subset of slices, achieving both security and fault tolerance through segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encoding mechanism (error correction codes) that transforms original data into encoded slices before storage. This intermediary layer enables the system to tolerate losses and unauthorized access while maintaining data integrity, managing the complexity of dispersed storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If error correction encoding is applied to data, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies error correction encoding to data before dispersal and storage. By performing the encoding action in advance, the system ensures data integrity is built into the stored slices, eliminating the need for complex real-time verification during retrieval and reducing overall processing time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If data is encoded and dispersed across geographically distributed storage units, then fault tolerance is improved, but access tracking complexity increases

Engineering Contradiction:
Improvefault toleranceVSAvoidaccess tracking complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements access tracking mechanisms that monitor and record access patterns to dispersed slices. This feedback system enables the network to detect unauthorized access attempts and track legitimate operations across geographically distributed storage units, managing the complexity of monitoring dispersed data.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10114696B2Tracking data access in a dispersed storage network
Publication Date: 2018.10.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10114696B2 patent drawing
  • US10114696B2 patent drawing
  • US10114696B2 patent drawing

AI summary

A method for execution by a dispersed storage and task (DST) processing unit that includes a processor includes receiving an access request from a requesting entity via a network indicating an original data object. At least one read request is generated for transmission to at least one storage unit indicating a plurality of encoded original data slices associated with the original data object. A regenerated original data object is generated by utilizing a decoding scheme on the plurality of encoded original data slice. A transformed data object is generated for transmission to the requesting entity via the network by utilizing a transformation function on the first regenerated original data object based on an entity identifier associated with the requesting entity.