Distributed Storage Network Data Slicing and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage systems face challenges with data integrity and security due to the failure of physical movement-based memory devices, such as disc drives, and the inefficiencies and security risks associated with redundant array of independent discs (RAID) solutions, which increase maintenance demands and expose data to unauthorized access.

Innovation Solution

A distributed storage network (DSN) system that uses error coding dispersal storage to partition data into slices, which are then encoded and stored across multiple physically diverse locations, allowing for reliable and secure data retrieval and integrity verification, with a management unit overseeing data distribution, storage, and retrieval processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If physical movement-based memory devices (disc drives) are used for data storage, then storage capacity is provided, but system reliability deteriorates due to device failures

Engineering Contradiction:
Improvestorage capacityVSAvoidsystem reliability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent divides data into multiple data slices and distributes them across different storage locations in the dispersed storage network. This segmentation ensures that if one storage device fails, other slices remain intact, maintaining system reliability while preserving storage capacity through distributed redundancy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates multiple copies of data slices and stores them at different physical locations. This copying approach provides redundancy without requiring a single point of failure, thereby improving reliability while maintaining the ability to store large quantities of data across the network.

Inventive Principle:
Principle #26Copying

2Reliability

If redundant array of independent discs (RAID) is used to improve data integrity, then data reliability is improved, but device complexity and maintenance requirements increase

Engineering Contradiction:
Improvedata integrityVSAvoidmaintenance requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the redundancy management function from a centralized RAID controller and distributes it across the network. Each storage location independently stores data slices, eliminating the need for complex centralized RAID management while maintaining data integrity through distributed redundancy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The dispersed storage network enables self-managed redundancy where data is automatically distributed and replicated across multiple locations without requiring active RAID management. The system self-maintains data integrity through peer-to-peer storage architecture, reducing maintenance requirements.

Inventive Principle:
Principle #25Self-service

3Reliability

If redundant array of independent discs (RAID) is used for data protection, then data reliability is improved, but security risks increase due to unauthorized access

Engineering Contradiction:
Improvedata protectionVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into multiple slices distributed across different network locations, making it difficult for unauthorized access. Even if one location is compromised, the distributed nature of slices prevents complete data exposure, enhancing both protection and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security management component that acts as an intermediary between data storage and access requests. This mediator handles authentication and authorization, controlling who can access which data slices, thereby improving both data protection and security posture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11973828B2Acquiring security information in a vast storage network
Publication Date: 2024.04.30 PURE STORAGE INC
  • US11973828B2 patent drawing
  • US11973828B2 patent drawing
  • US11973828B2 patent drawing

AI summary

A storage network operates by: receiving a plurality of identifiers associated with a user including a user identifier and a group identifier; generating a plurality of key pairs associated with the plurality of user identifiers, the plurality of key pairs including a first key pair and a second key pair, the first key pair including a first public key and a first private key, and the second key pair including a second public key and a second private key; storing the plurality of key pairs; generating at least one request for a certificate; receiving at least one signed certificate in response to the at least one request; and accessing the storage network using the at least one signed certificate.