Site-Based Namespace Allocation for Secure Dispersed Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage systems face challenges in ensuring data security and reliability, particularly when replicating data across multiple locations, as it increases the risk of unauthorized access and can lead to data unrecoverability due to lopsided storage allocation and single-point failures.

Innovation Solution

A dispersed storage network (DSN) that uses error encoding techniques like Cauchy Reed-Solomon encoding to distribute data across multiple storage units, ensuring data can be recovered even with failures, without the need for redundant copies, and maintains security through secure encoding and decoding processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is replicated across multiple storage locations, then data availability is improved, but security risk increases due to multiple access points

Engineering Contradiction:
Improvedata availabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into multiple encoded slices distributed across different storage units. Each slice alone is insufficient to reconstruct the original data, providing both availability (data can be recovered from any sufficient subset of slices) and security (unauthorized access to individual slices does not reveal the complete data). This is achieved through information dispersal algorithms that encode data into multiple interdependent parts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encoding/decoding mechanism as an intermediary between the original data and its stored representations. The encoding process transforms data into encoded slices, and the decoding process reconstructs data only when sufficient slices are combined. This intermediary layer ensures that distributed storage provides availability while maintaining security, as the encoding scheme controls what can be recovered from stored slices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is stored in multiple locations, then redundancy is improved, but storage allocation becomes lopsided leading to single-point failures

Engineering Contradiction:
Improvedata redundancyVSAvoidstorage allocation balance
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent divides data into multiple encoded slices that are distributed across different storage units located at various sites. This segmentation ensures that no single storage unit holds a disproportionate amount of critical data, preventing lopsided allocation. The encoding scheme ensures that any sufficient subset of slices from any combination of storage units can reconstruct the original data, eliminating single-point failures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent assigns different encoded slices to different storage units based on their capabilities and locations. Each storage unit stores a specific portion of the encoded data tailored to its characteristics, creating a balanced distribution where each location contributes uniquely to the overall data redundancy without creating imbalances. This local optimization ensures stable and balanced storage allocation across the distributed system.

Inventive Principle:
Principle #3Local quality

3Device complexity

If simple replication is used for data storage, then implementation complexity is reduced, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvestorage system complexityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing data into multiple encoded slices instead of creating simple copies. While this increases the encoding complexity slightly, it dramatically improves security by ensuring that unauthorized access to any single slice or small subset of slices does not compromise the complete data. The segmented approach with encoding provides a practical balance between manageable complexity and enhanced security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encoding/decoding intermediary that transforms simple replication into secure distributed storage. The encoding process creates interdependent slices that require collaboration to reconstruct the original data, adding a layer of security without significantly complicating the overall storage architecture. This intermediary mechanism enables the system to achieve strong security properties while maintaining relatively simple operational procedures for data storage and retrieval.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9760440B2Site-based namespace allocation
Publication Date: 2017.09.12 PURE STORAGE INC
  • US9760440B2 patent drawing
  • US9760440B2 patent drawing
  • US9760440B2 patent drawing

AI summary

A distributed storage network (DSN) can include a DSN memory and a distributed storage (DS) managing unit in communication with the DSN memory. The DSN memory includes DS units physically located at different sites. The DS units store encoded data slices associated with a storage vault having a number of pillars and a read threshold. The number of pillars correspond to a number of encoded data slices generated from a particular segment of data, and the read threshold corresponds to subset of those encoded data slices required to reconstruct the particular segment of data. The DS managing unit assigns storage of particular encoded data slices to particular DS units based, at least in part, on a pillar associated with the encoded data slices and on the physical locations, e.g. the sites, at which the DS units are located.