Dispersed Storage Network Access Policy Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dispersed storage systems face challenges in maintaining data integrity and availability across multiple storage units, particularly in scenarios where a significant number of storage units fail, and they lack efficient mechanisms for secure, long-term data storage and retrieval without redundant copies.

Innovation Solution

A dispersed storage network (DSN) is implemented, utilizing a managing unit, integrity processing unit, and computing devices with error encoding and decoding capabilities, employing Cauchy Reed-Solomon encoding to distribute data across multiple storage units, ensuring data recovery even with failures, and managing access policies for secure and efficient data storage and retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is distributed across multiple storage units without redundant copies, then storage efficiency is improved, but data reliability deteriorates when storage units fail

Engineering Contradiction:
Improvestorage efficiencyVSAvoiddata reliability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments data into multiple slices and distributes them across different storage units. Each slice is a portion of the original data, and the segmentation allows efficient storage while maintaining the ability to reconstruct the full data set from any sufficient subset of slices, thus resolving the contradiction between storage efficiency and data reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs error correction codes that transform data parameters by adding redundant information in an encoded form. This parameter change allows the system to tolerate storage unit failures while maintaining storage efficiency, as the redundant information is integrated into the data structure rather than being separate copies.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If error correction codes are used to maintain data integrity, then data reliability is improved, but processing complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses error correction coding which creates encoded copies of data segments. These codes are mathematical transformations that allow reconstruction of original data even when some segments are lost or corrupted, providing data integrity while using systematic processing algorithms that manage complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces traditional mechanical redundancy (physical backup copies) with mathematical error correction mechanisms. This substitution uses algebraic and cryptographic operations instead of physical duplication, maintaining data integrity while reducing the overhead associated with managing multiple complete copies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If access policies are updated frequently to maintain security, then security is improved, but system performance deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication and authorization checks where access policies are evaluated before data access operations. By performing security verification in advance and caching policy decisions, the system maintains strong security while avoiding repeated policy evaluation overhead during actual data access, thus preserving system performance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10237281B2Access policy updates in a dispersed storage network
Publication Date: 2019.03.19 PURE STORAGE INC
  • US10237281B2 patent drawing
  • US10237281B2 patent drawing
  • US10237281B2 patent drawing

AI summary

A method for execution in a dispersed storage network operates to determine one or more slice names of one or more slices and determine whether to establish a new access policy corresponding to the one or more slices. When the new access policy is to be established, the method determines a timestamp; determines a new access policy; and sends the new access policy and the timestamp to one or more storage units that store the one or more slices.