Hierarchical Vault Access Sharing Across DSN Memories

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dispersed storage networks face challenges in ensuring data integrity and security, particularly in maintaining data availability and access control across geographically distributed storage units, while also being resilient to storage unit failures and unauthorized access.

Innovation Solution

A dispersed storage network architecture that incorporates a managing unit for data management, an integrity processing unit for rebuilding corrupted data slices, and a dispersed storage error encoding scheme using Cauchy Reed-Solomon encoding, along with a hierarchical authorization approach for secure access control, ensures data integrity and security by distributing data across multiple storage units and managing access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is distributed across multiple storage units in a dispersed storage network, then data availability and resilience to storage unit failures are improved, but system complexity and difficulty of managing access control increase

Engineering Contradiction:
Improvedata availabilityVSAvoidaccess control management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments access control by creating hierarchical authorization levels (read, write, administrative privileges) that can be independently assigned to different user groups and storage units. This segmentation allows complex distributed access control to be managed through modular, manageable units rather than a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authorization mechanism that mediates between storage units and users. This intermediary layer handles the complexity of access control by automatically verifying credentials and enforcing authorization policies, simplifying the management interface while maintaining security across the distributed network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hierarchical authorization is implemented across multiple DSN memories, then access control security is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improveaccess control securityVSAvoidauthorization verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing hierarchical authorization relationships between DSN memories and pre-configuring access policies. This allows the system to quickly verify credentials against pre-computed authorization hierarchies rather than performing complex real-time analysis, significantly reducing verification time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If error correction encoding is used to maintain data integrity, then data reliability is improved, but storage space requirements and processing complexity increase

Engineering Contradiction:
Improvedata integrityVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies partial action by implementing error correction encoding only at necessary hierarchical levels and for critical data portions. Rather than applying full error correction uniformly across all data, the system selectively applies encoding based on data importance and location, reducing overall storage overhead while maintaining integrity for the most critical information.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10831381B2Hierarchies of credential and access control sharing between DSN memories
Publication Date: 2020.11.10 WORKDAY INC
  • US10831381B2 patent drawing
  • US10831381B2 patent drawing
  • US10831381B2 patent drawing

AI summary

A method includes detecting a change to one or more of: a credential of set of storage units supporting a logical storage vault and access control information for a user group affiliated with the logical storage vault. The method further includes, in response to the detecting, determining, whether the logical storage vault is in a relationship with another logical storage vault. When the logical storage vault is in the relationship, determining whether the logical storage vault is an originating vault or a subservient vault. When the logical storage vault is the originating vault, sending updated access control information to the second set of storage units regarding a change to the access control information. When the logical storage vault is the subservient vault, sending an updated credential of the set of storage units to the computing device regarding a change to the credential of the set of storage units.