Dispersed Storage Encoding for Secure Metadata and Data Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dispersed storage networks face challenges in securely storing and retrieving data across geographically diverse locations, particularly in maintaining data integrity and preventing unauthorized access, while also managing distributed task processing efficiently.

Innovation Solution

A distributed computing system that employs dispersed storage error encoding, secure encryption methods using per-vault and per-slice keys, and a network architecture with DST execution units for secure data storage and task processing, allowing for error correction and secure data retrieval without redundant copies, and enabling distributed task management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in a dispersed storage network across multiple locations, then data availability and reliability are improved, but data security and integrity become more difficult to maintain

Engineering Contradiction:
Improvedata availabilityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into multiple data slices that are dispersed across different storage locations. Each slice is encrypted with unique encryption keys, so that no single location contains the complete unencrypted data. This segmentation approach maintains reliability through distribution while preventing unauthorized access, as an attacker would need to compromise multiple locations and decrypt multiple slices to access the full data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security measures to different data slices stored at different locations. Each slice has its own encryption keys and security parameters tailored to its specific storage environment. This allows the system to optimize security for each location while maintaining overall data integrity, resolving the contradiction between distributed availability and centralized security control.

Inventive Principle:
Principle #3Local quality

2Reliability

If data is encrypted using per-vault and per-slice keys, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidencryption key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-generating and distributing encryption keys to appropriate storage locations before data is actually stored. The encryption key management infrastructure is set up in advance, creating a hierarchical key structure where master keys can derive slice-specific keys. This preliminary setup reduces the complexity of real-time key management while maintaining strong security through multiple encryption layers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary key management system that mediates between the data storage locations and the users. This intermediary layer handles the complex tasks of key generation, distribution, rotation, and revocation, shielding the actual storage system from key management complexity. The intermediary translates high-level security policies into low-level encryption operations, reducing overall system complexity while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If error correction schemes are implemented in dispersed storage, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing error correction only where needed based on the storage environment and data criticality. Not all data slices require the same level of error correction; the system can apply lighter error correction to less critical data and stronger correction to mission-critical data. This selective approach maintains data integrity for important information while minimizing the processing time overhead for less critical data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent utilizes parameter changes by adjusting error correction codes based on the specific storage conditions and data requirements. The system can dynamically change error correction parameters such as code strength, redundancy level, and correction algorithm selection. This allows optimization of the balance between data integrity and processing time by adapting error correction parameters to match the actual operational context rather than using a fixed, overly conservative approach.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11782789B2Encoding data and associated metadata in a storage network
Publication Date: 2023.10.10 PURE STORAGE INC
  • US11782789B2 patent drawing
  • US11782789B2 patent drawing
  • US11782789B2 patent drawing

AI summary

A storage network operates by: generating metadata for a data object; first disperse storage error encoding the metadata to produce a set of metadata slices, wherein the first disperse storage error encoding utilizes first dispersal parameters, the first dispersal parameters including a first decode threshold of 1; generating sets of first data slices via a second disperse storage error encoding of data segments associated with the data object, wherein the second disperse storage error encoding utilizes second dispersal parameters, the second dispersal parameters different from the first dispersal parameters and the second dispersal parameters including a second decode threshold greater than 1; producing an additional data segment associated with the data object wherein the additional data segment is different from the data segments and the metadata; and third disperse storage error encoding the additional data segment to produce a set of second data slices, wherein the third disperse storage error encoding utilizes the first dispersal parameters including the first decode threshold of 1.