Distributed Storage Coordination Using Encoded Slices for Secure Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional RAID systems face challenges with increasing disk failures, maintenance costs, data security, and vulnerability to natural disasters due to the need for redundant data copies, which can lead to data loss and unauthorized access.

Innovation Solution

A distributed storage network (DSN) with dispersed storage error encoding and decoding using Cauchy Reed-Solomon encoding, where data is split into encoded slices stored across multiple geographically diverse sites, allowing for data recovery even with multiple failures without redundant copies, and secure storage through encryption and secure access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundant data copies are stored in RAID systems, then data security is improved, but maintenance costs increase and unauthorized access risk increases

Engineering Contradiction:
Improvedata securityVSAvoidmaintenance costs
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments data into multiple encoded slices distributed across different storage units. Instead of storing complete redundant copies like traditional RAID, the system divides data into fragments and stores them separately, allowing recovery from failures while reducing the overhead of full redundancy copies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses Cauchy Reed-Solomon encoding to transform data into encoded slices with specific mathematical properties. This encoding scheme allows the system to achieve data security and fault tolerance through parameter-based encoding rather than simple copying, reducing storage overhead and maintenance complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple copies of data are stored, then data loss risk is reduced, but security vulnerabilities increase due to unauthorized access

Engineering Contradiction:
Improvedata loss preventionVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By segmenting data into encoded slices distributed across multiple storage units, the system eliminates the security vulnerability of having complete data copies in multiple locations. Each storage unit holds only a fragment, making unauthorized access to complete data significantly more difficult while maintaining the ability to reconstruct data for authorized users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encoding scheme as an intermediary between the original data and stored slices. This mathematical transformation acts as a security layer, where data can only be recovered through the proper decoding process, preventing unauthorized reconstruction even if multiple slices are accessed.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If RAID devices are co-located for easy access, then operational efficiency is improved, but vulnerability to natural disasters increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidnatural disaster vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system segments data across geographically distributed storage units rather than co-locating redundant copies. This segmentation allows operational efficiency to be maintained through distributed access while simultaneously protecting against site-specific disasters, as data fragments are stored in different physical locations.

Inventive Principle:
Principle #1Segmentation

4Quantity of substance

If more disks are added to RAID array to increase storage capacity, then storage capacity is improved, but disk failure probability increases

Engineering Contradiction:
Improvestorage capacityVSAvoiddisk failure probability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent changes the fundamental parameter of data protection from simple redundancy copying to mathematical encoding. This allows the system to efficiently utilize additional disks for storage capacity while maintaining a controlled failure threshold through the encoding scheme, where data can be recovered as long as a sufficient number of encoded slices are intact.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240248632A1Coordination of Distributed Storage Networks
Publication Date: 2024.07.25 PURE STORAGE INC
  • US20240248632A1 patent drawing
  • US20240248632A1 patent drawing
  • US20240248632A1 patent drawing

AI summary

Apparatus and methods for use in coordinating distributed computing networks such as distributed storage networks. In an embodiment, a coordination unit establishes connections with managing units of the distributed computing networks. For example, the managing units can initiate the connections via connection messages. The coordination unit further transmits coordination messages to the managing units. The coordination messages can include update information and requests specifying information gathering tasks to be executed by the distributed computing networks. In an example, the coordination unit receives a response to a first coordination message from a first managing unit. The coordination unit transmits a second coordination message to a second managing unit, wherein the second coordination message includes information related to the information gathered by the first distributed computing network in response to the first coordination message.