Dispersed Storage Network Access Information Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer storage systems face issues with data integrity and security due to the failure of memory devices, particularly those using physical movement technologies, which can lead to data loss and unauthorized access, especially as the amount of data grows and maintenance demands increase.
Innovation Solution
A distributed storage network (DSN) system that employs error coding dispersal storage to partition and encode data into multiple slices, storing them across physically diverse locations, allowing for reliable and secure data retrieval even in the event of device failures, and includes a storage integrity processing unit for verification and rebuilding of corrupted slices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data is stored in conventional memory devices with physical movement, then storage capacity is achieved, but data integrity deteriorates due to device failures and bit corruption
Solution Approach 1:
The patent divides data into multiple data segments and further partitions each segment into multiple slices, which are then distributed across different storage devices. This segmentation ensures that failure of individual devices does not result in complete data loss, as sufficient slices from remaining devices can be used to reconstruct the original data through error correction coding.
Solution Approach 2:
The patent transforms data into a different parameter state through error correction coding, converting k data slices into n encoded slices (where n > k). This parameter transformation allows the system to tolerate up to (n-k) slice failures while maintaining data integrity, effectively changing the reliability parameter of the storage system.
2Reliability
If multiple redundant disc drives are used to replicate data, then data integrity is improved, but device complexity and maintenance demands increase
Solution Approach 1:
The patent creates encoded copies of data segments through error correction coding, where each data segment is transformed into multiple encoded slices distributed across different devices. Unlike simple replication, these encoded copies allow for more flexible recovery, as any sufficient combination of slices can reconstruct the original data, reducing the need for exact duplicate copies and simplifying maintenance.
Solution Approach 2:
The patent introduces a new dimension of redundancy through error correction coding, moving beyond simple spatial replication. By encoding data across multiple dimensions (different devices, different slices per device), the system achieves higher reliability with potentially fewer total storage units, thereby reducing overall system complexity and maintenance burden.
3Ease of operation
If access information is stored centrally, then ease of operation is maintained, but security deteriorates due to unauthorized access risks
Solution Approach 1:
The patent divides access information into multiple encoded slices and distributes them across different storage devices, similar to how data itself is segmented. This segmentation of access credentials ensures that no single device contains complete access information, thereby preventing unauthorized access even if individual devices are compromised, while still allowing legitimate access when sufficient slices are combined.
Solution Approach 2:
The patent introduces an intermediary error correction coding layer between the access information and the storage devices. This intermediary encoding mechanism transforms access credentials into distributed encoded slices, adding a security layer that requires successful decoding of sufficient slices to retrieve original access information, thereby mitigating unauthorized access risks while maintaining operational ease.
Data Source
AI summary
A method begins by a processing module applying a share encoding function on data to produce a plurality of encoded shares and generating a plurality of random numbers. The method continues with the processing module obtaining a set of personalized authenticating values regarding user access to the data and generating a plurality of hidden passwords based on the set of personalized authenticating values. The method continues with the processing module generating an encryption key based on a corresponding one of the plurality of hidden passwords and a corresponding one of the plurality of random numbers and encrypting the encoded share utilizing the encryption key to produce an encrypted share for each encoded share of the plurality of encoded shares. The method continues with the processing module facilitating storage of the plurality of random numbers and each of the encrypted shares.


