Distributed Storage Coordination Using Encoded Slices for Secure Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional RAID systems face challenges with increasing disk failures, maintenance costs, data security, and vulnerability to natural disasters due to the need for redundant data copies, which can lead to data loss and unauthorized access.
Innovation Solution
A distributed storage network (DSN) with dispersed storage error encoding and decoding using Cauchy Reed-Solomon encoding, where data is split into encoded slices stored across multiple geographically diverse sites, allowing for data recovery even with multiple failures without redundant copies, and secure storage through encryption and secure access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundant data copies are stored in RAID systems, then data security is improved, but maintenance costs increase and unauthorized access risk increases
Solution Approach 1:
The patent segments data into multiple encoded slices distributed across different storage units. Instead of storing complete redundant copies like traditional RAID, the system divides data into fragments and stores them separately, allowing recovery from failures while reducing the overhead of full redundancy copies.
Solution Approach 2:
The patent uses Cauchy Reed-Solomon encoding to transform data into encoded slices with specific mathematical properties. This encoding scheme allows the system to achieve data security and fault tolerance through parameter-based encoding rather than simple copying, reducing storage overhead and maintenance complexity.
2Reliability
If multiple copies of data are stored, then data loss risk is reduced, but security vulnerabilities increase due to unauthorized access
Solution Approach 1:
By segmenting data into encoded slices distributed across multiple storage units, the system eliminates the security vulnerability of having complete data copies in multiple locations. Each storage unit holds only a fragment, making unauthorized access to complete data significantly more difficult while maintaining the ability to reconstruct data for authorized users.
Solution Approach 2:
The patent introduces an encoding scheme as an intermediary between the original data and stored slices. This mathematical transformation acts as a security layer, where data can only be recovered through the proper decoding process, preventing unauthorized reconstruction even if multiple slices are accessed.
3Productivity
If RAID devices are co-located for easy access, then operational efficiency is improved, but vulnerability to natural disasters increases
Solution Approach 1:
The system segments data across geographically distributed storage units rather than co-locating redundant copies. This segmentation allows operational efficiency to be maintained through distributed access while simultaneously protecting against site-specific disasters, as data fragments are stored in different physical locations.
4Quantity of substance
If more disks are added to RAID array to increase storage capacity, then storage capacity is improved, but disk failure probability increases
Solution Approach 1:
The patent changes the fundamental parameter of data protection from simple redundancy copying to mathematical encoding. This allows the system to efficiently utilize additional disks for storage capacity while maintaining a controlled failure threshold through the encoding scheme, where data can be recovered as long as a sufficient number of encoded slices are intact.
Data Source
AI summary
Apparatus and methods for use in coordinating distributed computing networks such as distributed storage networks. In an embodiment, a coordination unit establishes connections with managing units of the distributed computing networks. For example, the managing units can initiate the connections via connection messages. The coordination unit further transmits coordination messages to the managing units. The coordination messages can include update information and requests specifying information gathering tasks to be executed by the distributed computing networks. In an example, the coordination unit receives a response to a first coordination message from a first managing unit. The coordination unit transmits a second coordination message to a second managing unit, wherein the second coordination message includes information related to the information gathered by the first distributed computing network in response to the first coordination message.


