Dispersed Storage Network Data Encryption and Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer storage systems face challenges with data integrity and security due to the failure of memory devices, particularly those using physical movement technologies, such as disc drives, which can lead to data loss and increased maintenance demands, and RAID systems face inefficiencies and security risks with multiple copies of data.

Innovation Solution

A distributed storage network (DSN) system that uses error coding dispersal storage to partition data into slices, storing them across multiple geographically diverse locations, ensuring data integrity and security through redundancy without the need for multiple copies, and includes a management unit for data distribution, retrieval, and integrity verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple copies of data are stored for redundancy, then data reliability is improved, but storage efficiency deteriorates and security risks increase

Engineering Contradiction:
Improvedata reliabilityVSAvoidstorage efficiency
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent divides data into multiple slices and distributes them across different storage locations. Instead of storing complete copies of data, the system segments data into portions that can be reconstructed from a threshold number of slices, thereby improving storage efficiency while maintaining reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms data from a redundant copy-based representation to an encoded slice-based representation. By changing the parameter of data representation from full copies to encoded fragments, the system achieves both reliability and storage efficiency

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple copies of data are stored for redundancy, then data reliability is improved, but security deteriorates due to increased access points

Engineering Contradiction:
Improvedata reliabilityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By segmenting data into encrypted slices distributed across multiple locations, the patent reduces security risks. Each slice alone is useless without the decryption key and threshold number of slices, thereby maintaining reliability while improving security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encryption keys as an intermediary layer between the data and access points. The keys control access to the sliced data, ensuring that even if multiple locations are accessed, the data remains secure without the proper authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If disc drives with physical movement are used for storage, then storage capacity is improved, but data integrity deteriorates due to bit level corruption

Engineering Contradiction:
Improvestorage capacityVSAvoiddata integrity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent applies error correction encoding to data slices before storage. This preliminary action prepares the data to withstand potential corruption during storage and retrieval, maintaining data integrity even when using physical movement-based storage devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By incorporating error correction codes and redundancy in the sliced data representation, the patent creates a cushion against data corruption. This beforehand protection ensures that even if some slices are corrupted during storage, the original data can be reconstructed

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS8848906B2Encrypting data for storage in a dispersed storage network
Publication Date: 2014.09.30 PURE STORAGE INC
  • US8848906B2 patent drawing
  • US8848906B2 patent drawing
  • US8848906B2 patent drawing

AI summary

A method begins by a dispersed storage (DS) processing module encrypting a plurality of data segments of the data using a plurality of encryption keys to produce a plurality of encrypted data segments and generating a plurality of deterministic values from the plurality of encrypted data segments. The method continues with the DS processing module establishing a data intermingling pattern and generating a plurality of masked keys by selecting one or more of the plurality of deterministic values in accordance with the data intermingling pattern and performing a masking function on the plurality of encryption keys and the selected one or more of the plurality of deterministic values. The method continues with the DS processing module appending the plurality of masked keys to the plurality of encrypted data segments to produce a plurality of secure data packages and outputting the plurality of secure data packages.