Auditing a transaction in a dispersed storage network
Abstract
A method for auditing transactions within a dispersed storage network (DSN) begins by identifying a set of audit objects for a transaction of the transactions. The method continues by determining sets of slice names for the set of audit objects based on information regarding the transaction. The method continues by generating sets of read requests regarding sets of encoded data slices based on the sets of slice names. The method continues by sending the sets of read requests to a set of storage units of the DSN. In response to the sets of read requests, the method continues by receiving and decoding a decode threshold number of encoded data slices of each of the sets of encoded data slices to recover the set of audit objects and analyzing the set of audit objects for DSN operational compliance.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for auditing transactions within a dispersed storage network (DSN), the method comprises:
for a transaction of the transactions, identifying, by a device of the DSN, a set of audit objects, wherein an audit object of the set of audit objects includes at least one record regarding the transaction, wherein the set of audit objects is dispersed storage error encoded to produce sets of encoded data slices; determining, by the device, sets of slice names for the set of audit objects based on information regarding the transaction, wherein each slice name of the sets of slice name includes a pillar number section and a common object section, the pillar number section contains a unique pillar number for a corresponding encoded data slice of the sets of slice names, the common object section contains audit object identifying information, wherein the common object section includes an audit vault identifier section and an audit object identifier section, wherein the audit object identifier section includes at least some of: a device identifier section, a timestamp section, a target identifier section, a source identifier section, a sequence number section, and a transaction type identifier section; generating, by the device, sets of read requests regarding the sets of encoded data slices based on the sets of slice names; sending, by the device, the sets of read requests to a set of storage units of the DSN; in response to the sets of read requests, receiving and decoding, by the device, a decode threshold number of encoded data slices of each of the sets of encoded data slices to recover the set of audit objects; and analyzing, by the device, the set of audit objects for DSN operational compliance.
2 . The method of claim 1 further comprises:
selecting the transaction based on one or more of:
identity of a device involved in the transaction;
a transaction type; and
a pseudo random selection process.
3 . The method of claim 1 , wherein the identifying the set of audit objects comprises:
when the transaction is regarding a data access request, identifying the set of audit objects based on encoding parameters associated with data of the data access request, wherein the set of audit objects includes a first subset of audit objects from a device of the transaction to storage units of the transaction and a second subset of audit objects from the storage units to the device.
4 . The method of claim 3 , wherein the analyzing the set of audit objects comprises:
determining that the first subset of audit objects includes a first appropriate number of audit objects; determining that the second subset of audit objects includes a second appropriate number of audit objects; when the first and second subsets of audit objects include the first and second appropriate numbers, respectively, determining whether records of audit objects of the first subset of audit objects correlate with records of audit objects of the second subset of audit objects; and when the records of audit objects of the first subset of audit objects correlate with the records of audit objects of the second subset of audit objects, indicating that the transaction passed an audit.
5 . The method of claim 4 further comprises:
when the records of audit objects of the first subset of audit objects do not correlate with the records of audit objects of the second subset of audit objects, determining whether non-correlation is due to obtaining less than the second appropriate number of audit objects of the second subset of audit objects;
when the non-correlation is due to obtaining less than the second appropriate number of audit objects of the second subset of audit objects, determining whether a follow-up audit object exists, wherein the follow-up audit object includes one or more records regarding one or more of: rebuilding, storage unit service report, storage unit off-line report, and storage unit failure report;
when the follow-up audit object exists, indicating that the transaction passed the audit; and
when the follow-up audit object does not exist, indicating that the transaction failed the audit.
6 . The method of claim 4 further comprises:
when one of the records of audit objects of the first subset of audit objects does not correlate with a corresponding record of the records of audit objects of the second subset of audit objects, indicating that the transaction failed the audit.
7 . The method of claim 3 , wherein the data access request includes one of:
a write operation; a read operation; a list request; and a status report.
8 . A computer readable storage device comprises:
a first memory section for storing operational instructions that, when executed by a computing device, causes the computing device to audit transactions within a dispersed storage network (DSN) by:
for a transaction of the transactions, identifying, a set of audit objects, wherein an audit object of the set of audit objects includes at least one record regarding the transaction, wherein the set of audit objects is dispersed storage error encoded to produce sets of encoded data slices;
a second memory section for storing operational instructions that, when executed by the computing device, causes the computing device to:
determine sets of slice names for the set of audit objects based on information regarding the transaction, wherein each slice name of the sets of slice name includes a pillar number section and a common object section, the pillar number section contains a unique pillar number for a corresponding encoded data slice of the sets of slice names, the common object section contains audit object identifying information, wherein the common object section includes an audit vault identifier section and an audit object identifier section, wherein the audit object identifier section includes at least some of: a device identifier section, a timestamp section, a target identifier section, a source identifier section, a sequence number section, and a transaction type identifier section;
a third memory section for storing operational instructions that, when executed by the computing device, causes the computing device to:
generate sets of read requests regarding set of encoded data slices based on the sets of slice names; and
send the sets of read requests to a set of storage units of the DSN;
a fourth memory section for storing operational instructions that, when executed by the computing device, causes the computing device to:
in response to the sets of read requests, receiving and decoding, a decode threshold number of encoded data slices of each of the sets of encoded data slices to recover the set of audit objects; and
a fifth memory section for storing operational instructions that, when executed by the computing device, causes the computing device to:
analyze the set of audit objects for DSN operational compliance.
9 . The computer readable storage device of claim 8 further comprises:
a sixth memory section for storing operational instructions that, when executed by the computing device, causes the computing device to:
select the transaction based on one or more of:
identity of a device involved in the transaction;
a transaction type; and
a pseudo random selection process.
10 . The computer readable storage device of claim 8 , wherein the first memory section stores further operational instructions that, when executed by the computing device, causes the computing device to identify the set of audit objects by:
when the transaction is regarding a data access request, identify the set of audit objects based on encoding parameters associated with data of the data access request, wherein the set of audit objects includes a first subset of audit objects from a device of the transaction to storage units of the transaction and a second subset of audit objects from the storage units to the device.
11 . The computer readable storage device of claim 10 , wherein the fifth memory section stores further operational instructions that, when executed by the computing device, causes the computing device to analyze the set of audit objects by:
determining that the first subset of audit objects includes a first appropriate number of audit objects; determining that the second subset of audit objects includes a second appropriate number of audit objects; when the first and second subsets of audit objects include the first and second appropriate numbers, respectively, determining whether records of audit objects of the first subset of audit objects correlate with records of audit objects of the second subset of audit objects; and when the records of audit objects of the first subset of audit objects correlate with the records of audit objects of the second subset of audit objects, indicating that the transaction passed an audit.
12 . The computer readable storage device of claim 11 , wherein the fifth memory section stores further operational instructions that, when executed by the computing device, causes the computing device to:
when the records of audit objects of the first subset of audit objects do not correlate with the records of audit objects of the second subset of audit objects, determine whether non-correlation is due to obtaining less than the second appropriate number of audit objects of the second subset of audit objects is received; when the non-correlation is due to obtaining less than the second appropriate number of audit objects of the second subset of audit objects is received, determine whether a follow-up audit object exists, wherein the follow-up audit object includes one or more records regarding one or more of: rebuilding, storage unit service report, storage unit off-line report, and storage unit failure report; when the follow-up audit object exists, indicate that the transaction passed the audit; and when the follow-up audit object does not exist, indicate that the transaction failed the audit.
13 . The computer readable storage device of claim 11 , wherein the fifth memory section stores further operational instructions that, when executed by the computing device, causes the computing device to:
when one of the records of audit objects of the first subset of audit objects does not correlate with a corresponding record of the records of audit objects of the second subset of audit objects, indicate that the transaction failed the audit.
14 . The computer readable storage device of claim 10 , wherein the data access request includes one of:
a write operation; a read operation; a list request; and a status report.Join the waitlist — get patent alerts
Track US2017192684A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.