Randomized Data Transforms for Secure Dispersed Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage solutions, such as RAID systems, face challenges in providing effective and efficient data continuity, security, and adaptability to various storage standards, especially with increased risks of multiple disk failures and unauthorized access due to replication of data across multiple sites.

Innovation Solution

A distributed data storage system that uses a dispersed data storage network with error encoding and dispersal algorithms, along with encryption and transposition techniques, to securely store and retrieve data across multiple physically diverse locations, ensuring data integrity and security through redundancy and secure encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is replicated across multiple storage sites, then data availability and continuity are improved, but security risks and vulnerability to unauthorized access increase

Engineering Contradiction:
Improvedata availabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into multiple slices and distributes them across different storage sites. Instead of replicating complete data copies, each site holds only a portion, making it impossible for unauthorized access at any single site to compromise the entire dataset. This resolves the contradiction by maintaining availability through distribution while preventing unauthorized access through fragmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encryption as an intermediary layer between the data and storage sites. Data is encrypted before being sliced and distributed, and only authorized systems with the proper decryption keys can reconstruct and access the original data. This intermediary protection mechanism maintains data availability while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If data is dispersed across multiple locations, then security against unauthorized access is improved, but system complexity and difficulty of data management increase

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidsystem management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal data management system that handles multiple functions through a single interface: data slicing, encryption, distribution, reconstruction, and decryption. This multi-functional approach simplifies management complexity by providing unified tools that work across all dispersed locations, rather than requiring separate management mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes in the form of encryption keys and slicing parameters to control data access and management. By changing these parameters dynamically, the system can securely disperse data across multiple locations while maintaining manageable complexity through standardized parameter-based control mechanisms.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If traditional RAID systems are used, then data storage efficiency is maintained, but adaptability to different storage standards and devices is limited

Engineering Contradiction:
Improvestorage efficiencyVSAvoidstorage standard compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal data storage system that can adapt to different storage standards and devices through its abstraction layer. The data slicing and encryption mechanisms work independently of the underlying storage hardware, allowing the same system to operate efficiently across various storage standards while maintaining high storage efficiency through optimized data distribution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11991280B2Randomized transforms in a dispersed data storage system
Publication Date: 2024.05.21 PURE STORAGE INC
  • US11991280B2 patent drawing
  • US11991280B2 patent drawing
  • US11991280B2 patent drawing

AI summary

A method for execution by one or more modules of one or more processors of a storage network includes receiving a data object for storage, segmenting the data object into a plurality of data segments and determining a level of security and a level of performance for the plurality of data segments. The method continues by determining whether one or more data segments of the plurality of data segments is to be transformed using an all-or-nothing transformation and in response to a determination to transform one or more data segments of the plurality of data segments, transforming a data segment of the plurality of data segments to produce a transformed data segment. The method continues by dispersed error encoding the transformed data segment to produce a set of encoded data slices and transmitting the set of encoded data slices to a set of storage units of the storage network.