Dispersed Storage Network Data Encryption and Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer storage systems face challenges with data integrity and security due to the failure of memory devices, particularly those using physical movement technologies, such as disc drives, which can lead to data loss and increased maintenance demands, and RAID systems face inefficiencies and security risks with multiple copies of data.
Innovation Solution
A distributed storage network (DSN) system that uses error coding dispersal storage to partition data into slices, storing them across multiple geographically diverse locations, ensuring data integrity and security through redundancy without the need for multiple copies, and includes a management unit for data distribution, retrieval, and integrity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple copies of data are stored for redundancy, then data reliability is improved, but storage efficiency deteriorates and security risks increase
Solution Approach 1:
The patent divides data into multiple slices and distributes them across different storage locations. Instead of storing complete copies of data, the system segments data into portions that can be reconstructed from a threshold number of slices, thereby improving storage efficiency while maintaining reliability
Solution Approach 2:
The patent transforms data from a redundant copy-based representation to an encoded slice-based representation. By changing the parameter of data representation from full copies to encoded fragments, the system achieves both reliability and storage efficiency
2Reliability
If multiple copies of data are stored for redundancy, then data reliability is improved, but security deteriorates due to increased access points
Solution Approach 1:
By segmenting data into encrypted slices distributed across multiple locations, the patent reduces security risks. Each slice alone is useless without the decryption key and threshold number of slices, thereby maintaining reliability while improving security
Solution Approach 2:
The patent introduces encryption keys as an intermediary layer between the data and access points. The keys control access to the sliced data, ensuring that even if multiple locations are accessed, the data remains secure without the proper authentication
3Quantity of substance
If disc drives with physical movement are used for storage, then storage capacity is improved, but data integrity deteriorates due to bit level corruption
Solution Approach 1:
The patent applies error correction encoding to data slices before storage. This preliminary action prepares the data to withstand potential corruption during storage and retrieval, maintaining data integrity even when using physical movement-based storage devices
Solution Approach 2:
By incorporating error correction codes and redundancy in the sliced data representation, the patent creates a cushion against data corruption. This beforehand protection ensures that even if some slices are corrupted during storage, the original data can be reconstructed
Data Source
AI summary
A method begins by a dispersed storage (DS) processing module encrypting a plurality of data segments of the data using a plurality of encryption keys to produce a plurality of encrypted data segments and generating a plurality of deterministic values from the plurality of encrypted data segments. The method continues with the DS processing module establishing a data intermingling pattern and generating a plurality of masked keys by selecting one or more of the plurality of deterministic values in accordance with the data intermingling pattern and performing a masking function on the plurality of encryption keys and the selected one or more of the plurality of deterministic values. The method continues with the DS processing module appending the plurality of masked keys to the plurality of encrypted data segments to produce a plurality of secure data packages and outputting the plurality of secure data packages.


