Dispersed Storage Network Authentication via Slice Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage systems face challenges with data integrity and security due to the failure of physical movement-based memory devices, such as disc drives, which can lead to data loss and increased maintenance needs, and RAID systems suffer from efficiency and security issues with multiple disc failures and redundant data copies.

Innovation Solution

A dispersed storage network (DSN) system that uses error-coded data slices distributed across multiple physically diverse locations, allowing for reliable and secure data storage and retrieval through error correction and redundancy, managed by a distributed storage protocol that includes data partitioning, error encoding, and secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical movement-based memory devices (disc drives) are used for data storage, then data can be stored and accessed, but data integrity and security deteriorate due to device failure and bit level corruption

Engineering Contradiction:
Improvedata integrityVSAvoiddevice failure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides data into multiple data slices and distributes them across multiple disc drives in a dispersed storage network. This segmentation ensures that no single drive holds all data, so failure of one drive does not result in complete data loss. The data can be reconstructed from a threshold number of slices, maintaining data integrity even with device failures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates multiple copies of data slices and distributes them across multiple disc drives. Instead of storing complete redundant copies (RAID), it stores fragmented copies that can be reassembled. This allows the system to tolerate drive failures while maintaining data availability and integrity through error correction and reconstruction algorithms.

Inventive Principle:
Principle #26Copying

2Reliability

If RAID systems with multiple disc drives are used for redundancy, then data protection against disc failure is improved, but system efficiency and security deteriorate due to overhead and multiple copies

Engineering Contradiction:
Improvedata protectionVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments data into slices and distributes them across multiple drives with different security clearances. This allows the system to maintain data protection while improving efficiency by only requiring access to a threshold number of drives rather than all drives in the array. The segmented approach reduces the overhead associated with traditional RAID systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent assigns different security clearances to different disc drives, creating local quality variations in the storage system. Hot data with higher access requirements is stored on drives with higher clearances, while cold data is stored on drives with lower clearances. This optimization improves system efficiency by matching storage resources to data requirements while maintaining overall data protection.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple disc drives are used for data redundancy, then fault tolerance is improved, but security deteriorates due to increased attack surface and unauthorized access risk

Engineering Contradiction:
Improvefault toleranceVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by assigning different security clearances to different disc drives. Each drive has a specific clearance level, and data reconstruction requires slices from drives meeting a minimum clearance threshold. This creates a security gradient where not all drives are equally accessible, reducing the attack surface while maintaining fault tolerance through the distributed slice architecture.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a security intermediary mechanism where the dispersed storage network controller verifies clearance levels before allowing data reconstruction. This intermediary layer mediates between the distributed drives and access requests, ensuring that unauthorized access is prevented even if multiple drives are compromised, while still allowing legitimate reconstruction from sufficient slices.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If data is distributed across multiple locations with error correction, then data security and fault tolerance are improved, but device complexity increases due to error encoding and authentication protocols

Engineering Contradiction:
Improvedata securityVSAvoiderror encoding
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal dispersed storage protocol that handles multiple functions including error encoding, security verification, and data reconstruction through a single standardized interface. This multi-functional approach reduces device complexity by providing a unified method for managing distributed storage operations, eliminating the need for separate complex systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes in the form of adjustable clearance thresholds and slice distribution parameters to control the balance between security and complexity. By modifying these parameters, the system can adapt to different security requirements without fundamentally changing the underlying error encoding mechanisms, thus managing complexity while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9077734B2Authentication of devices of a dispersed storage network
Publication Date: 2015.07.07 PURE STORAGE INC
  • US9077734B2 patent drawing
  • US9077734B2 patent drawing
  • US9077734B2 patent drawing

AI summary

A method begins by a first processing module generating a dispersed storage network (DSN) authentication request frame that includes authenticating data and an authenticating code, wherein the authenticating code references a valid authenticating process. The method continues with the first processing module transmitting the DSN authentication request frame to a second processing module. The method continues with the second processing module determining whether the second processing module includes the valid authentication process referenced by the authentication code. When the second processing module includes the valid authentication process, processing, by the second processing module, the authenticating data in accordance with the valid authentication process to produce processed authenticating data. The method continues with the second processing module generating a DSN authentication response frame that includes the processed authenticating data and transmitting the DSN authentication response frame to the first processing module.