Temporary Credential Enrollment for Anonymous DSN Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current dispersed storage networks face challenges in maintaining data integrity and security across geographically distributed storage units, particularly in scenarios where multiple storage unit failures occur, as they lack efficient error correction mechanisms and secure access management.
Innovation Solution
The implementation of a dispersed storage network with an integrity processing unit that uses error encoding techniques like Cauchy Reed-Solomon encoding to distribute data into encoded slices, which are then stored across multiple storage units, allowing for data recovery even with failures, and a managing unit for secure access and billing management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If data is distributed across multiple storage units without error encoding, then storage simplicity is improved, but data reliability deteriorates when storage unit failures occur
Solution Approach 1:
The patent divides data into multiple encoded slices and distributes them across different storage units. This segmentation allows the system to store data in distributed form while maintaining the ability to reconstruct the original data from any sufficient subset of slices, thus resolving the contradiction between distribution simplicity and reliability.
Solution Approach 2:
The patent applies error encoding to data before distribution, creating redundant encoded slices in advance. This preliminary encoding action ensures that even if some storage units fail, the original data can be recovered from the remaining slices, thereby improving reliability without compromising the distributed storage structure.
2Reliability
If traditional authentication is used for access management, then security is improved, but ease of operation deteriorates due to complex authentication requirements
Solution Approach 1:
The patent introduces a managing unit as an intermediary that handles authentication and authorization. This intermediary component centralizes security management, allowing simple client-side access operations while maintaining strong security through the managing unit's credential verification and access control policies.
Solution Approach 2:
The system implements self-service authentication mechanisms where users can obtain temporary credentials and manage their own access rights through automated processes. This reduces the operational burden on both users and administrators while maintaining security through programmatic credential management.
3Ease of operation
If anonymous access is allowed, then ease of operation is improved, but data security deteriorates
Solution Approach 1:
The patent implements dynamic access credentials that are temporary and context-specific. Anonymous users receive time-limited or purpose-limited credentials that automatically expire or become invalid after use, allowing convenient anonymous access while maintaining security through the temporary nature of the credentials.
Solution Approach 2:
The system changes the parameters of access credentials by making them temporary rather than permanent. This parameter change allows anonymous access for specific purposes or time periods while automatically revoking access afterward, thus balancing ease of operation with security requirements.
Data Source
AI summary
A method begins by receiving, by an authenticated device of a dispersed storage network (DSN), an access request from a requesting device. The method continues by determining, by the authenticated device, whether the requesting device is affiliated with an anonymous user or an authenticated user. When the requesting device is affiliated with the anonymous user, the method continues by determining, by the authenticated device, status of the anonymous user. When the status of the anonymous user is of minimal threat to the DSN, the method continues by granting, by the authenticated device, temporary credentials and temporary access privileges to the anonymous user for use by the requesting device. The method continues by processing, by the authenticated device, the access request in accordance with the temporary credentials and the temporary access privileges.


