发明名称 Method for data privacy in a fixed content distributed data storage
摘要 An archival storage cluster of preferably symmetric nodes includes a data privacy scheme that implements key management through secret sharing. In one embodiment, the protection scheme is implemented at install time. At install, an encryption key is generated, split, and the constituent pieces written to respective archive nodes. The key is not written to a drive to ensure that it cannot be stolen or otherwise compromised. Due to the secret sharing scheme, any t of the n nodes must be present before the cluster can mount the drives. Thus, to un-share the secret, a process runs before the cluster comes up. It contacts as many nodes as possible to attempt to reach a sufficient t value. Once it does, the process un-shares the secret and mounts the drives locally. Given bidirectional communication, this mount occurs more or less at the same time on all t nodes. Once the drives are mounted, the cluster can continue to boot as normal.
申请公布号 US2008285759(A1) 申请公布日期 2008.11.20
申请号 US20080116274 申请日期 2008.05.07
申请人 发明人 SHAW DAVID M.
分类号 H04L9/08 主分类号 H04L9/08
代理机构 代理人
主权项
地址