Secure Data Slice Rebuilding in Dispersed Storage Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data storage systems face challenges with data integrity and security due to the failure of memory devices, especially those using physical movement technologies, and the inefficiencies of redundant array of independent discs (RAID) solutions, which increase maintenance demands and security risks with multiple copies of data.
Innovation Solution
A distributed storage system that employs error coding dispersal storage to partition and encode data into multiple slices, storing them across physically diverse locations, allowing for secure and reliable data retrieval and reconstruction even in the event of device failures, using a dispersed storage network with error correction and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored using RAID with multiple copies, then data availability is improved, but security risks and maintenance demands increase
Solution Approach 1:
The patent segments data into multiple slices and distributes them across different storage locations using error coding. Instead of creating complete copies like RAID, the system divides data into fragments (slices) that can be reconstructed from a threshold number of slices, reducing security risks while maintaining availability.
Solution Approach 2:
The patent introduces error coding as an intermediary mechanism between data storage and retrieval. The encoding process creates redundant information that enables data reconstruction without requiring direct access to complete data copies, thereby improving security while maintaining reliability.
2Reliability
If data is stored using RAID with multiple copies, then data availability is improved, but maintenance demands increase
Solution Approach 1:
By segmenting data into slices distributed across multiple locations with error coding, the system reduces maintenance complexity. When failures occur, the system can reconstruct data from remaining slices without requiring manual intervention or complex maintenance procedures associated with RAID.
Solution Approach 2:
The error coding mechanism enables the system to automatically reconstruct lost or corrupted data slices from remaining slices without external intervention. This self-healing capability reduces maintenance demands compared to RAID systems that require manual recovery procedures.
3Reliability
If data is partitioned and encoded into multiple slices stored across physically diverse locations, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent employs universal error coding algorithms that can be applied across different storage locations and devices. This multi-functional approach allows the same encoding/decoding mechanisms to handle various failure scenarios and storage configurations, managing complexity through standardization.
Solution Approach 2:
The system allows flexible adjustment of encoding parameters such as the number of slices, threshold for reconstruction, and error correction levels. These parameter changes enable the system to adapt to different storage configurations and reliability requirements without fundamental changes to the underlying architecture.
Data Source
AI summary
A method begins by a processing module identifying an encoded data slice to be rebuilt, selecting a decode threshold number of dispersed storage (DS) units of a storage set of DS units, generating a decode threshold number of key pairs, wherein a key pair of the decode threshold number of key pairs corresponds to a DS unit of the decode threshold number of DS units, and sending partial rebuilding requests to the decode threshold number of DS units, wherein a partial rebuilding request of the partial rebuilding requests includes the key pair. The method continues with the processing module receiving encrypted partial encoded data slices, wherein an encrypted partial encoded data slice received from the corresponding DS unit includes a multiple encryption, using the key pair, of a partial encoded data slice and decoding the encrypted partial encoded data slices to rebuild the encoded data slice.


