DSN Master Key Storage for Multi-IDA Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud storage systems face challenges in ensuring data integrity and security due to varying levels of fault tolerance and security properties, particularly in dispersed storage networks where data is encoded and decoded across multiple storage units, leading to potential data loss and unauthorized access.

Innovation Solution

A dispersed storage network (DSN) architecture that employs error encoding and decoding using Cauchy Reed-Solomon encoding, with a managing unit and integrity processing unit to manage and rebuild encoded data slices, ensuring data integrity and security through multiple configuration error coding functions and secure storage of master key slices in a highest security IDA configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is dispersed and encoded across multiple storage units using error correction schemes, then data reliability and fault tolerance are improved, but security properties and confidentiality guarantees deteriorate

Engineering Contradiction:
Improvedata reliabilityVSAvoidsecurity properties
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into multiple encoded slices distributed across different storage units. Each slice contains only a portion of the encoded data, and no single slice or small subset can reveal the original information. This segmentation approach maintains reliability through distribution while improving security by ensuring that compromising a limited number of storage units does not expose the complete data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security configurations to different storage units or data sets within the dispersed storage system. By allowing local customization of encoding parameters and security levels, the system can optimize each storage location's security properties according to specific requirements, thereby improving overall security without sacrificing reliability.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If multiple IDA configurations are used simultaneously for different security levels, then security guarantees are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity guaranteesVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal dispersed storage system that can handle multiple IDA configurations through a single integrated architecture. The system uses a common encoding framework that supports different security levels and configurations, allowing the same infrastructure to serve multiple security requirements without requiring separate systems for each configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables dynamic selection and switching between different IDA configurations based on security requirements and storage conditions. The system can adaptively choose appropriate encoding schemes and security levels for different data sets or storage scenarios, managing complexity through flexible, context-aware configuration selection rather than static rigid structures.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10129023B2Enhancing security for multiple storage configurations
Publication Date: 2018.11.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10129023B2 patent drawing
  • US10129023B2 patent drawing
  • US10129023B2 patent drawing

AI summary

A method begins by a processing module identifying, for a DSN (Dispersed Storage Network) memory using multiple IDA (Information Dispersal Algorithms) configurations simultaneously, a first IDA configuration with a highest security level relative to each of the multiple IDA configurations. The method continues by generating at least one master key. The method continues by encoding the master key with a secure error coding function to produce master key slices according to the first IDA configuration. The method continues by storing the master key slices in the DSN memory using the first IDA configuration. The method continues by, when storing data with a second IDA configuration having a security level lower than the first IDA configuration, retrieving the master key slices, decoding the master key slices to obtain the master key and encrypting the data using the master key.