US2015169897A1PendingUtilityA1
Efficient and secure data storage utilizing a dispersed data storage system
Est. expiryApr 20, 2029(~2.7 yrs left)· nominal 20-yr term from priority
G06F 21/6218H04L 9/085G06F 3/067G06F 11/1076G06F 21/6227H04L 9/0618
48
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method of securely storing data to a dispersed data storage system is disclosed. A data segment is arranged along the columns or rows of an appropriately sized matrix. Data slices are then created based on either the columns or the rows so that no consecutive data is stored in a data slice. Each data slice is then stored in a separate storage node.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method operating on a computer, the method comprises:
applying an all-or-nothing transformation to a data segment to produce an all-or-nothing data segment; encoding, using an information dispersal algorithm, the all-or-nothing data segment to produce a set of encoded data slices; and generating a set of write command to write the set of encoded data slices to storage units of a dispersed storage network.
2 . The method of claim 1 wherein the applying an all-or-nothing transformation comprises:
generating an encryption key;
encrypting the data segment with said encryption key to produce an encrypted data segment;
calculating a digest corresponding to the encrypted data segment;
obfuscating the encryption key by exclusive ORing said encryption key with the digest to produce an obfuscated encryption key; and
packaging the obfuscated encryption key with the encrypted data segment to produce the all-or-nothing data segment.
3 . The method of claim 1 further comprises:
encrypting the data segment using a first block cipher prior to the applying of the all-or-nothing transformation.
4 . The method of claim 1 further comprises:
retrieving, by a second computer, at least a decode threshold number of encoded data slices of the set of encoded data slices from the storage units;
decoding, by the second computer using the information dispersal algorithm, the at least the decode threshold number of encoded data slices to recover the all-or-nothing data segment; and
reversing, by the second computer, the all-or-nothing transformation on the recovered all-or-nothing data segment to recover the data segment.
5 . The method of claim 1 further comprises:
retrieving at least a decode threshold number of encoded data slices of the set of encoded data slices from the storage units;
decoding, using the information dispersal algorithm, the at least the decode threshold number of encoded data slices to recover the all-or-nothing data segment; and
reversing the all-or-nothing transformation on the recovered all-or-nothing data segment to recover the data segment.
6 . The method of claim 5 , wherein the reversing the all-or-nothing transformation comprises:
separating the all-or-nothing data segment into an encrypted data segment and an obfuscated encryption key; calculating a digest based on the encrypted data segment; exclusive ORing the obfuscated encryption key with the digest to recover an encryption key; and decrypting the encrypted data segment using the encryption key to recover the data segment.
7 . A computer comprising:
a network port adapted to couple with a network and receive a data segment; and a processor coupled to the network port wherein the processor:
applies an all-or-nothing transformation to the data segment to produce an all-or-nothing data segment;
encodes, using an information dispersal algorithm, the all-or-nothing data segment to produce a set of encoded data slices; and
generates a set of write commands to write the set of encoded data slices to storage nodes of a dispersed storage network.
8 . The computer of claim 7 , wherein the processor further functions to apply the all-or-nothing transformation by:
generating an encryption key; encrypting said data segment with said encryption key to produce an encrypted data segment; calculating a digest corresponding to said encrypted data segment; obfuscating said encryption key by exclusive-ORing said encryption key with said digest to produce an obfuscated encryption key; and packaging said obfuscated encryption key with said encrypted data segment to produce the all-or-nothing encrypted data segment.
9 . The computer of claim 7 , wherein the processor further functions to:
encrypt the data segment using a first block cipher prior to the applying of the all-or-nothing transformation.
10 . The computer of claim 7 , wherein the processor further functions to:
retrieve, via the network port, at least a decode threshold number of encoded data slices of the set of encoded data slices from the storage nodes; decode, using the information dispersal algorithm, the at least the decode threshold number of encoded data slices to recover the all-or-nothing data segment; and reverse the all-or-nothing transformation on the recovered all-or-nothing data segment to recover the data segment.
11 . The computer of claim 10 , wherein the processor further functions to reverse the all-or-nothing transformation by:
separating the all-or-nothing data segment into an encrypted data segment and an obfuscated encryption key; calculating a digest based on the encrypted data segment; exclusive ORing the obfuscated encryption key with the digest to recover an encryption key; and decrypting the encrypted data segment using the encryption key to recover the data segment.Join the waitlist — get patent alerts
Track US2015169897A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.