Virtualized Data Storage Vaults on Dispersed Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed data storage networks face challenges in managing access and administration due to the lack of effective directory service software for virtual drives, and they often require physically disparate locations, which limits their applicability and flexibility in managing different user preferences for data storage and security.

Innovation Solution

A system that utilizes a network of slice servers to implement multiple dispersed data storage networks, where a subset of servers is associated with a user account to form a virtualized data storage vault, allowing flexible configuration of storage, encryption, compression, and integrity checks, along with access control, to manage access and storage efficiently across a dispersed data storage grid.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If data is stored in a single location, then storage simplicity is improved, but reliability and security deteriorate

Engineering Contradiction:
Improvestorage simplicityVSAvoiddata reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides data into multiple segments or slices and distributes them across multiple storage locations. This segmentation allows the system to maintain simple storage operations at each location while improving overall reliability, as the data can be reconstructed from a sufficient number of slices even if some storage locations fail.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a hierarchical structure where data is first divided into slices, then each slice is further encoded with error correction codes, and finally organized into vaults with access control layers. This nested structure provides multiple levels of protection while maintaining operational simplicity at each layer.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If backup copies are created and stored in separate locations, then reliability is improved, but security deteriorates

Engineering Contradiction:
Improvedata reliabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security and storage characteristics to different data slices. Each slice can be stored with different encryption keys and access controls, allowing the system to maintain reliability through distribution while mitigating security risks by ensuring that compromise of one location does not expose the entire dataset.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security parameters by requiring a threshold number of slices to reconstruct data. This means that even if backup copies exist in separate locations, an attacker must compromise a specific number of locations simultaneously, significantly increasing the security barrier while maintaining reliability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If RAID configurations are used to divide and replicate data, then performance and reliability are improved, but security remains compromised

Engineering Contradiction:
Improvedata reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces encryption and secret sharing mechanisms as intermediary layers between the data and storage locations. Instead of directly storing data slices as in traditional RAID, the system first encrypts and encodes the data, then distributes these protected slices. This intermediary layer maintains the performance and reliability benefits of distribution while adding security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If encryption is applied to protect data, then security is improved, but accessibility and operational simplicity deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent creates a unified access system that handles multiple functions through a single interface. The vault access mechanism universally manages encryption key distribution, slice reconstruction, and data retrieval operations, maintaining security while simplifying user interaction. Users interact with a single vault structure rather than managing individual encrypted slices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements automated key management and slice reconstruction processes that operate without user intervention. The vault structure automatically manages the complexity of encryption and decryption operations, selecting appropriate slices and keys based on access permissions, thereby maintaining security while preserving ease of operation for authorized users.

Inventive Principle:
Principle #25Self-service

5Adaptability or versatility

If multiple dispersed storage networks are implemented, then versatility and security are improved, but system complexity and management difficulty increase

Engineering Contradiction:
Improvestorage flexibilityVSAvoidsystem management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple dispersed storage networks under a unified vault management structure. Instead of managing separate systems, the vault abstraction layer combines multiple storage networks into a single manageable entity, allowing flexible data distribution across different networks while simplifying management through centralized control interfaces.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8190662B2Virtualized data storage vaults on a dispersed data storage network
Publication Date: 2012.05.29 PURE STORAGE INC
  • US8190662B2 patent drawing
  • US8190662B2 patent drawing
  • US8190662B2 patent drawing

AI summary

A slice server includes a network port, a central processing unit, and memory. The central processing unit (CPU) is operable to receive, via the network port, a request to access a virtual digital data storage vault. The CPU then determines whether the slice server supports the virtual digital data storage vault. When the slice server supports the virtual digital data storage vault, the CPU determines whether the request is valid. When the request is valid, the CPU executes the request to generate a response.