Temporary Credential Enrollment for Anonymous DSN Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dispersed storage networks face challenges in maintaining data integrity and security across geographically distributed storage units, particularly in scenarios where multiple storage unit failures occur, as they lack efficient error correction mechanisms and secure access management.

Innovation Solution

The implementation of a dispersed storage network with an integrity processing unit that uses error encoding techniques like Cauchy Reed-Solomon encoding to distribute data into encoded slices, which are then stored across multiple storage units, allowing for data recovery even with failures, and a managing unit for secure access and billing management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If data is distributed across multiple storage units without error encoding, then storage simplicity is improved, but data reliability deteriorates when storage unit failures occur

Engineering Contradiction:
Improvestorage system simplicityVSAvoiddata recovery capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides data into multiple encoded slices and distributes them across different storage units. This segmentation allows the system to store data in distributed form while maintaining the ability to reconstruct the original data from any sufficient subset of slices, thus resolving the contradiction between distribution simplicity and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies error encoding to data before distribution, creating redundant encoded slices in advance. This preliminary encoding action ensures that even if some storage units fail, the original data can be recovered from the remaining slices, thereby improving reliability without compromising the distributed storage structure.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional authentication is used for access management, then security is improved, but ease of operation deteriorates due to complex authentication requirements

Engineering Contradiction:
Improveaccess securityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a managing unit as an intermediary that handles authentication and authorization. This intermediary component centralizes security management, allowing simple client-side access operations while maintaining strong security through the managing unit's credential verification and access control policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service authentication mechanisms where users can obtain temporary credentials and manage their own access rights through automated processes. This reduces the operational burden on both users and administrators while maintaining security through programmatic credential management.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If anonymous access is allowed, then ease of operation is improved, but data security deteriorates

Engineering Contradiction:
Improveaccess convenienceVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access credentials that are temporary and context-specific. Anonymous users receive time-limited or purpose-limited credentials that automatically expire or become invalid after use, allowing convenient anonymous access while maintaining security through the temporary nature of the credentials.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of access credentials by making them temporary rather than permanent. This parameter change allows anonymous access for specific purposes or time periods while automatically revoking access afterward, thus balancing ease of operation with security requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10241697B2Temporary enrollment in anonymously obtained credentials
Publication Date: 2019.03.26 WORKDAY INC
  • US10241697B2 patent drawing
  • US10241697B2 patent drawing
  • US10241697B2 patent drawing

AI summary

A method begins by receiving, by an authenticated device of a dispersed storage network (DSN), an access request from a requesting device. The method continues by determining, by the authenticated device, whether the requesting device is affiliated with an anonymous user or an authenticated user. When the requesting device is affiliated with the anonymous user, the method continues by determining, by the authenticated device, status of the anonymous user. When the status of the anonymous user is of minimal threat to the DSN, the method continues by granting, by the authenticated device, temporary credentials and temporary access privileges to the anonymous user for use by the requesting device. The method continues by processing, by the authenticated device, the access request in accordance with the temporary credentials and the temporary access privileges.