A cloud data deduplication method supporting remote update

CN116226920BActive Publication Date: 2026-09-25HUAIYIN INSTITUTE OF TECHNOLOGY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310231375.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-10
Publication Date
2026-09-25
Estimated Expiration
2043-03-10

AI Technical Summary

Technical Problem

对于需要逐步更新大文件的应用程序而言,代价和开销都相当高

Benefits of technology

[0062](1)无需可信第三方参与即可实现云存储中加密数据的高效去重及远程敏感分区更新;其中,密钥传递采用加密算法进行,不需要可信第三方的辅助,简化了密钥传递的过程,同时保证了密钥在传递过程中的安全性;远程更新粒度为分区级,更新敏感分区时,直接从更新的密文块重新计算,部分解密分区密文,然后重新加密受影响的分区,不会影响其他路径。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116226920B_ABST
    Figure CN116226920B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a cloud data deduplication method supporting remote update, file partitioning is performed through context, whether the partition sensitivity reaches a threshold is determined, a single layer encryption is used for a non-sensitive partition which does not reach the threshold, and an outer layer encryption is added for a sensitive partition which reaches the threshold; the remote update granularity is a partition level, firstly, a user interacts with a CSS to obtain a key of each partition, and each partition is encrypted; if the user is an initial uploader, the key does not need to be obtained through interaction; then, connection of the partition keys is regarded as a new plaintext message, and the new plaintext message is encrypted; the process is repeated until a single partition finally contains the partition keys generated in the previous step, and the key of the last partition becomes a file key; when a sensitive partition is updated, the affected partition is directly recalculated from an updated ciphertext block, part of the partition ciphertext is decrypted, and then the affected partition is re-encrypted. The application can realize efficient deduplication and remote update of encrypted data in cloud storage without the participation of a trusted third party.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to cloud data deduplication methods, specifically to a cloud data deduplication method that supports remote updates. Background Technology

[0002] Statistics show that more than half of the data generated and stored on cloud servers is duplicated. Managing duplicate data is extremely costly, almost eight times that of the original data. Cloud service providers delete duplicate copies to improve storage utilization and reduce processing overhead. However, when users upload data to the cloud, they lose control of their data, posing a risk of cloud service providers leaking their private data.

[0003] To prevent data leaks, the traditional method is for users to encrypt data before uploading it. To achieve deduplication of encrypted data, the traditional method uses convergent encryption (CE). This means that the same content encrypted by different users will generate matching ciphertext, thus achieving deduplication. CE requires each user to hold a unique master key to encrypt their convergent key (CK), and then stores them in the cloud, so different users will store the same key for their copies.

[0004] To effectively manage the large number of keys involved in convergence encryption, Wen et al. proposed a Session-Key-based Convergent Key Management (SKC) and Convergent Key Sharing (CKS) scheme. This scheme manages the convergence keys for data using multi-user session keys and detects duplicates using data hash values. However, this scheme only supports block-level dynamic data updates; file-level data updates still incur significant overhead. Gang et al. proposed a dynamic deduplication scheme for cross-user duplicate data, requiring the participation of a key management server and a permission management server. It uses file-level keys to encrypt and store block-level keys, effectively reducing key redundancy, but it only supports block-level data updates; the file-level data update problem remains unresolved.

[0005] In summary, standalone CEs do not meet the requirements for data semantic security, are vulnerable to offline brute-force attacks that could steal the plaintext-ciphertext correspondence in the message space, and are unsuitable for scenarios with high security requirements. Meanwhile, as the user and data scale increases, the number of CKs will grow linearly, placing a heavy key management burden on cloud servers. Existing research focuses on static data, and even with the help of key management servers, it does not support efficient file updates. To modify a single bit, the data owner must download the entire ciphertext, decrypt it, update the data, re-encrypt it, and then upload the new ciphertext to the cloud. The computational and communication costs of all these operations are linearly related to the file size. For applications that need to incrementally update large files, the cost and overhead are quite high. Summary of the Invention

[0006] Purpose of the invention: The purpose of this invention is to propose a cloud data deduplication method that supports remote updates, which can support remote updates while ensuring the confidentiality of sensitive data and the security of transmission keys.

[0007] Technical solution: This invention provides a cloud data deduplication method that supports remote updates, comprising:

[0008] (1) Initialize system parameters;

[0009] (2) The initial user stores the file based on the context. Partitioning;

[0010] (3) Initially encrypt the user partition, generate the partition transmission key ciphertext, generate the partition ciphertext label, generate the partition deduplication detection label, and send the uploaded information to the cloud storage server.

[0011] (4) The user initially encrypts the file, generates the file transmission key ciphertext, generates the file ciphertext tag, generates the file deduplication detection tag, and sends the upload information to the cloud storage server;

[0012] (5) The cloud storage server and the user execute the POW interaction protocol to ensure that the user actually holds the complete data corresponding to the tag he or she uploaded;

[0013] (6) The cloud storage server performs file-level duplicate data detection based on file deduplication detection tags;

[0014] If the file does not exist, the user is the initial uploader, uploads the data, and executes step (3); if the file already exists, the user is the subsequent uploader, does not need to upload again, and executes step (4).

[0015] (7) The cloud storage server performs partition-level duplicate data detection based on the partition deduplication detection tags;

[0016] If the partition already exists, it is a non-sensitive area and the user does not need to upload it again. The file-level encryption of this partition is performed in step (4). If the partition does not exist, it is a sensitive partition. The initial user performs double encryption on the sensitive partition and then uploads the partition information to the cloud storage server, i.e., performs step (3).

[0017] (8) Legitimate users download partition data and file data;

[0018] (9) A legitimate user updates a sensitive partition and updates files.

[0019] Further, step (1) includes:

[0020] Configure security parameters , It is the partition key length in bits;

[0021] Configure two numbers of order as large prime numbers Multiplication cyclic group and ,group The generator is Bilinear mapping ;

[0022] The order of the Elgamal encryption algorithm is defined as a large prime number. Multiplication cyclic group ,group The generator is ;

[0023] Configure three safe and collision-resistant hash functions , , and a SHA256 hash function. The list of legitimate users for the file is as follows: The list of valid users for the partition is as follows ;

[0024] The system generates master-public-private key pairs. And generate a unique identity for each user who joins the system. Cloud storage server publicly discloses system parameters. .

[0025] Further, step (2) includes:

[0026] The initial user stores the file based on the context. Partitioning, i.e. , For the first of the documents One partition, , For partitioned indexes, This represents the partition size.

[0027] Further, step (3) includes:

[0028] Generate partition key Initial user calculates the key for each partition. Used to encrypt data;

[0029] Encrypted partition data Initial users are randomly selected. Use partition key For partitions Encrypt and generate ciphertext. ;

[0030] Generate partition transmission key ciphertext Initial user calculation , These are used as the private and public keys for the Elgamal algorithm, respectively; randomly selected. Calculate the ciphertext for transmitting the key in the partition. ;

[0031] Generate partition ciphertext tags Initial users will encrypt partition data. As input, via Then generate partition ciphertext tags This is used to verify the consistency between the tag and the ciphertext;

[0032] Generate partition deduplication detection tags Initial user input parameters and partitions Output partition deduplication and label detection ,in yes A random number;

[0033] Upload data The initial user will ultimately identify the sensitive partition. Encrypted partition data , partition transmission of key ciphertext Partition encrypted tags Partition deduplication and tag detection Uploaded together to the cloud storage server, the cloud storage server will identify the identity. Save to Initial user save Identity identification and deduplication detection labels Used for downloading partition decryption.

[0034] Further, step (4) includes:

[0035] Generate file key User calculation As the number of sensitive partitions contained in each group, if the number of partitions in the last group does not reach the required level... The number of partitions is then increased through reversible padding to ensure that encryption and decryption algorithms can function correctly; the partition key is then... The connection is treated as a new plaintext message. Apply again Encrypt the new partition as Repeat this process until the final partition key contains the key generated in the previous steps; the key for the last partition becomes the key for that file. ;

[0036] Encrypted files Initial users are randomly selected. Using a key For the file Encrypt and generate ciphertext. ;

[0037] Generate ciphertext for file transfer Initial user calculation , These are used as the private and public keys for the Elgamal algorithm, respectively; randomly selected. Calculate the encrypted key for file transmission , ;

[0038] Generate encrypted tags for files Initial users will encrypt files. As input, via Post-generated tags This is used to verify the consistency between the tag and the ciphertext;

[0039] Generate deduplication and tagging of files Initial user input parameters and documents Output file deduplication and tag detection ;

[0040] Upload data Initial user identification Encrypted files File deduplication detection tags File transfer key ciphertext and encrypted file tags Uploaded together to the cloud storage server, the cloud storage server will identify the identity. Save to Initial user save Identity identification and deduplication detection labels Used for downloading and decrypting files.

[0041] Further, step (5) includes:

[0042] Generate challenge information This is executed by the cloud storage server; the cloud storage server divides the stored encrypted data into fixed blocks, i.e. Randomly select several block information and extract the block location information. The challenge information is encrypted and authenticated. Send to the user;

[0043] Generate challenge evidence The task is executed by the user; after receiving the challenge information from the cloud storage server, the user first uses their private key. Decryption ; Calculate based on the obtained challenge information set And employs encrypted authentication The challenge evidence is returned to the cloud storage server;

[0044] Verify challenge information This is executed by the cloud storage server; after receiving the user's authentication information, the cloud storage server uses its own private key. The encrypted data block is computed in the same way, and the result is compared with... The comparison is performed; if they are equal, the user's identity is verified using Proof-of-Work (PoW). Add to the list of authorized users for the file Otherwise, the user's challenge fails.

[0045] Furthermore, in step (6), the cloud storage server will deduplicate and detect tags on the uploaded files. The deduplication tag is compared with that of an existing file. If they are equal, the file already exists; otherwise, the file does not exist.

[0046] In step (7), the cloud storage server will upload the partition deduplication detection tags. The deduplication check label is compared with an existing partition. If they are equal, the partition already exists and is a non-sensitive partition; if they are not equal, the partition does not exist and is a sensitive partition.

[0047] Further, step (8) includes:

[0048] Authorized users send download requests to the cloud storage server, and then submit their identity information. and encrypted tags The request is sent together to the cloud storage server; upon receiving the request, the cloud storage server first checks... Does the corresponding file exist? If it does, then further check the user's file. After confirming that the user is the owner of the data by checking if they are on the data's legitimate list, the key is encrypted. and encrypted data Return it to the user;

[0049] Authorized users of the partition interact with the cloud storage server to obtain the partition key ciphertext. Then decrypt to obtain the key. Finally, the partitioned data is obtained;

[0050] The legitimate user of the file interacts with the cloud storage server to obtain the file's encrypted key. Then decrypt to obtain the key. Finally, the file data is obtained.

[0051] Furthermore, the decryption of plaintext data in a partition by a legitimate user includes:

[0052] Get partition key Legitimate users, based on locally stored data right Decryption reveals the sensitive partition. The key, the decryption formula is ;

[0053] Decrypting data :pass Get partition ;

[0054] The plaintext data that a legitimate user can decrypt in a file includes:

[0055] Get file key : Based on locally saved data right Decrypt to obtain the file The key, the decryption formula is ;

[0056] Decrypting data :pass Get the file .

[0057] Further, step (9) includes:

[0058] Legitimate users will identify themselves. and partition encrypted tags The request is sent together to the cloud storage server; upon receiving the request, the cloud storage server checks... Check if the corresponding partition exists; if it does, further check the user's information. Is the user on the list of valid data? After the owner is determined, the partition will be transmitted with the key ciphertext. and partitioned data ciphertext Return it to the user;

[0059] Authorized users update sensitive partitions: The user determines the block key index to be updated locally. ; Receive ciphertext of all sensitive partition keys along this path from the cloud storage server and through key ciphertext Decrypt partitions one by one Generate a new key for the updated sensitive partition. Replace the old key at its parent node with the new key, re-encrypt the parent node, and repeat until all affected partitions along the root-to-leaf path are re-encrypted; finally, update the consistency check label of the affected sensitive partitions. and deduplication detection labels ;

[0060] When a legitimate user updates a file: the key of the last partition becomes the key of the new file when the final partition key contains the key updated in the previous steps. .

[0061] Beneficial effects: Compared with the prior art, the present invention has the following significant advantages:

[0062] (1) Efficient deduplication of encrypted data and remote sensitive partition updates in cloud storage can be achieved without the participation of a trusted third party; among them, the key transmission adopts an encryption algorithm, which does not require the assistance of a trusted third party, simplifying the key transmission process and ensuring the security of the key during the transmission process; the remote update granularity is partition level. When updating a sensitive partition, it directly recalculates from the updated ciphertext block, partially decrypts the partition ciphertext, and then re-encrypts the affected partition without affecting other paths.

[0063] (2) Double encryption of sensitive partitions can prevent unauthorized access to sensitive data.

[0064] (3) Detect whether different encrypted data come from the same plaintext content to ensure that the label does not leak any plaintext information. Attached Figure Description

[0065] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0066] Figure 1 This is a flowchart of the duplicate data detection process in an embodiment of this application;

[0067] Figure 2 This is a flowchart of the remote update process for sensitive partitions in an embodiment of this application;

[0068] Figure 3 This is an example of the file encryption process in the embodiments of this application ( );

[0069] Figure 4 This is an example of the file update process in the embodiments of this application ( ). Detailed Implementation

[0070] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the present invention.

[0071] The cloud data deduplication method supporting remote updates provided in this application involves two types of entities: a cloud storage server (CSS) and users. The CSS provides cloud storage and user deduplication services to multiple registered users. It not only offers pay-as-you-go storage services but also possesses powerful computing capabilities, enabling it to perform calculations on user data in the cloud and return the results. Users outsource their data to the CSS to save local storage space. For users, considering data security, they should avoid uploading plaintext data; to protect data privacy, the data must be encrypted before uploading to the CSS.

[0072] The cloud data deduplication method supporting remote updates provided in this application partitions files based on context and determines whether the partition sensitivity reaches a threshold. Partitions that do not reach the threshold are considered non-sensitive and are encrypted using a single layer of symmetric convergence encryption of the CSS stored data. Partitions that reach the threshold are considered sensitive and are encrypted with an additional outer layer. The remote update granularity is partition-level. First, the user interacts with the CSS to obtain the key for each partition and encrypts each partition. If the user is the initial uploader, no interaction is required to obtain the key. Then, the concatenation of these partition keys is treated as a new plaintext message and encrypted. This process is repeated until a single partition can ultimately contain the partition keys generated in the previous steps. The key of the last partition becomes the file key, such as... Figure 3 As shown. When updating a sensitive partition, the ciphertext is recalculated directly from the updated ciphertext block, partially decrypting the partition's ciphertext, and then the affected partition is re-encrypted, as shown. Figure 4 As shown.

[0073] The following is a detailed description of the cloud data deduplication method supporting remote updates provided in the embodiments of this application. The cloud data deduplication method includes four parts: data upload, duplicate data detection, data download and data update. The data upload part includes the following steps (1) to (5), the duplicate data detection part includes the following steps (6) to (7), the data download part includes step (8), and the data update part includes step (9).

[0074] A cloud data deduplication method that supports remote updates includes:

[0075] (1) Initialize system parameters;

[0076] Configure security parameters , It is the partition key length in bits;

[0077] Configure two numbers of order as large prime numbers Multiplication cyclic group and ,group The generator is Bilinear mapping ;

[0078] The order of the Elgamal encryption algorithm is defined as a large prime number. Multiplication cyclic group ,group The generator is ;

[0079] Configure three safe and collision-resistant hash functions , , and a SHA256 hash function The list of legitimate users for the file is as follows: The list of valid users for each partition is as follows ;

[0080] The system generates master-public-private key pairs. And generate a unique identity for each user who joins the system. CSS exposes system parameters .

[0081] (2) The initial user stores the file based on the context. Partitioning, i.e. , For the first of the documents One partition, , For partitioned indexes, This represents the partition size.

[0082] (3) Initially encrypt the user partition, generate the partition transmission key ciphertext, generate the partition ciphertext tag, generate the partition deduplication detection tag, and send the uploaded information to CSS; specifically including:

[0083] Generate partition key Initial user calculates the key for each partition. Used to encrypt data;

[0084] Encrypted partition data Initial users are randomly selected. Use partition key For partitions Encrypt and generate ciphertext. ,in For the group Generators;

[0085] Generate partition transmission key ciphertext Initial user calculation , These are used as the private and public keys for the Elgamal algorithm, respectively; randomly selected. Calculate the ciphertext for transmitting the key in the partition. ,in For the group generator, For the group The order;

[0086] Generate partition ciphertext tags Initial users will encrypt partition data. As input, via Then generate partition ciphertext tags This is used to verify the consistency between the tag and the ciphertext;

[0087] Generate partition deduplication detection tags Initial user input parameters and partitions Output partition deduplication and label detection ,in yes A random number;

[0088] Upload data The initial user will ultimately identify the sensitive partition. Encrypted partition data , partition transmission of key ciphertext Partition encrypted tags Partition deduplication and tag detection Upload it together to CSS, and CSS will identify it. Save to Initial user save Identity identification and deduplication detection labels Used for downloading partition decryption.

[0089] (4) Initially, the user encrypts the file, generates the file transfer key ciphertext, generates the file ciphertext tag, generates the file deduplication detection tag, and sends the upload information to CSS; specifically including:

[0090] Generate file key User calculation (in For partition size, The partition key length (in bits) is used to determine the number of sensitive partitions contained in each block. If the last block does not reach the required number of partitions... The number of partitions is then increased through reversible padding to ensure that encryption and decryption algorithms can function correctly; then the partition key is... The connection is treated as a new plaintext message. ,For example (by (For example); apply again Encrypt the new partition as Repeat this process until the final partition key contains the key generated in the previous steps; the key for the last partition becomes the key for that file. .like Figure 3 As shown, with For example, For partitioned encrypted text, For the partition key, Treated as a new plaintext message, encrypted using a partitioning method. Encrypting partitions, the final partition key can contain the keys from previous steps; the key for the last partition is the file key. Through file encryption Encrypt the file.

[0091] Encrypted files Initial users are randomly selected. Using a key For the file Encrypt and generate ciphertext. ,in For the group Generators;

[0092] Generate ciphertext for file transfer Initial user calculation , These are used as the private and public keys for the Elgamal algorithm, respectively; randomly selected. Calculate the encrypted key for file transmission , ,in For the group generator, For the group The order;

[0093] Generate encrypted tags for files Initial users will encrypt files. As input, via Post-generated tags This is used to verify the consistency between the tag and the ciphertext;

[0094] Generate deduplication and tagging of files Initial user input parameters and documents Output file deduplication and tag detection ;

[0095] Upload data Initial user identification Encrypted files File deduplication detection tags File transfer key ciphertext and encrypted file tags Upload it together to CSS, and CSS will identify it. Save to Initial user save Identity identification and deduplication detection labels Used for downloading and decrypting files.

[0096] (5) CSS and the user execute the POW interaction protocol to ensure that the user actually holds complete data corresponding to the tags they uploaded; specifically including:

[0097] Generate challenge information This is executed by CSS; CSS divides the stored encrypted data into fixed chunks, i.e. Randomly select several block information and extract the block location information. The challenge information is encrypted and authenticated. Send to the user;

[0098] Generate challenge evidence This is executed by the user; after receiving the CSS challenge information, the user first uses their private key... Decryption ; Calculate based on the obtained challenge information set And employs encrypted authentication Return the challenge evidence to CSS;

[0099] Verify challenge information Executed by CSS; after receiving the user's authentication information, CSS uses its own private key. The encrypted data block is computed in the same way, and the result is compared with... The comparison is performed; if they are equal, the user's identity is verified using Proof-of-Work (PoW). Add to the list of authorized users for the file Otherwise, the user's challenge fails.

[0100] (6) CSS performs file-level duplicate data detection based on file deduplication detection tags;

[0101] Initial users will identify themselves. Deduplication tag detection After uploading to CSS, CSS compares the existing file to remove duplicate tags and calculates... Is it valid?

[0102] like CSS determines that the file does not exist and returns [false]. The user is the initial uploader, uploads data, and executes step (3).

[0103] like The CSS determines that the file already exists and returns [a value]. The user is the subsequent uploader and does not need to upload again. POW verification is required, so step (4) is executed.

[0104] (7) CSS performs partition-level duplicate data detection based on partition deduplication tags;

[0105] When CSS determines that the file does not exist, it further performs a partition-level check to see if any partitions partially exist. CSS compares the deduplication tags for existing partitions on the cloud server and calculates... and Are they equal?

[0106] If it exists , making If the result is positive, it means the partition already exists and is a non-sensitive area; return [the value]. No user needs to upload again; single-layer encryption is performed, that is, file-level encryption of step (4) is performed on this partition.

[0107] If it exists , making If the result is negative, it means the partition does not exist and is a sensitive partition; return a negative value. The initial user performs double encryption on the sensitive partition and then uploads the partition information to CSS, i.e., executes step (3).

[0108] The duplicate data detection process is as follows: Figure 1 As shown.

[0109] (8) Legitimate users download partition data and file data; specifically including:

[0110] A legitimate user sends a download request to CSS, and then sends their identity identifier. and encrypted tags Send it along with the CSS; after receiving the request, the CSS first checks... Does the corresponding file exist? If it does, then further check the user's file. After confirming that the user is the owner of the data by checking if they are on the data's legitimate list, the key is encrypted. and encrypted data Return it to the user;

[0111] Authorized users of the partition interact with CSS to obtain the partition key ciphertext. Then decrypt to obtain the key. Finally, the partitioned data is obtained:

[0112] Get partition key Legitimate users, based on locally stored data right Decryption reveals the sensitive partition. The key, the decryption formula is ;

[0113] Decrypting data :pass Get partition .

[0114] The legitimate user of the file interacts with CSS to obtain the encrypted file key. Then decrypt to obtain the key. Finally, the file data is obtained:

[0115] Get file key : Based on locally saved data right Decrypt to obtain the file The key, the decryption formula is ;

[0116] Decrypting data :pass Get the file .

[0117] (9) Legitimate users update sensitive partitions and update files; specifically including:

[0118] Legitimate users will identify themselves. and partition encrypted tags Send it along with the CSS; after receiving the request, the CSS performs an inspection. Check if the corresponding partition exists; if it does, further check the user's information. Is the user on the list of valid data? After the owner is determined, the partition will be transmitted with the key ciphertext. and partitioned data ciphertext Return it to the user;

[0119] Authorized users update sensitive partitions: The user determines the block key index to be updated locally. ; Receive ciphertext of all sensitive partition keys along this path from CSS and through key ciphertext Decrypt partitions one by one Generate a new key for the updated sensitive partition. Replace the old key at its parent node with the new key, re-encrypt the parent node, and repeat until all affected partitions along the root-to-leaf path are re-encrypted; finally, update the consistency check label of the affected sensitive partitions. and deduplication detection labels The process for remotely updating sensitive partitions is as follows: Figure 2 As shown.

[0120] When a legitimate user updates a file: the key of the last partition becomes the key of the new file when the final partition key contains the key updated in the previous steps. .like Figure 4 As shown in the figure, For example, Updated to Only all affected partitions along the root-to-leaf path are updated. Once the final partition key is able to contain the keys updated in the previous steps, the key of the last partition becomes the new file key. .

[0121] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A cloud data deduplication method supporting remote updates, characterized in that, include: (1) Initialize system parameters; (2) The initial user stores the file based on the context. Partitioning; If the file does not exist, the user is the initial uploader, uploads the data, and executes step (3); if the file already exists, the user is the subsequent uploader, does not need to upload again, and executes step (4). If the partition already exists, it is a non-sensitive area and the user does not need to upload it again. The file-level encryption of this partition is performed in step (4). If the partition does not exist, it is a sensitive partition. The initial user performs double encryption on the sensitive partition and then uploads the partition information to the cloud storage server, i.e., performs step (3). (3) Initially encrypt the user partition, generate the partition transmission key ciphertext, generate the partition ciphertext label, generate the partition deduplication detection label, and send the uploaded information to the cloud storage server. (4) The user initially encrypts the file, generates the file transmission key ciphertext, generates the file ciphertext tag, generates the file deduplication detection tag, and sends the upload information to the cloud storage server; (5) The cloud storage server and the user execute the POW interaction protocol to ensure that the user actually holds the complete data corresponding to the tag he or she uploaded; (6) The cloud storage server performs file-level duplicate data detection based on file deduplication detection tags; (7) The cloud storage server performs partition-level duplicate data detection based on the partition deduplication detection tags; (8) Legitimate users download partition data and file data; (9) A legitimate user updates a sensitive partition and updates files; Step (1) includes: Configure security parameters , It is the partition key length in bits; Configure two numbers of order as large prime numbers Multiplication cyclic group and ,group The generator is Bilinear mapping ; The order of the Elgamal encryption algorithm is defined as a large prime number. Multiplication cyclic group ,group The generator is ; Configure three safe and collision-resistant hash functions , , and a SHA256 hash function. The list of legitimate users for the file is as follows: The list of valid users for the partition is as follows ; The system generates master-public-private key pairs. And generate a unique identity for each user who joins the system. Cloud storage server publicly discloses system parameters. ; Step (2) includes: The initial user stores the file based on the context. Partitioning, i.e. , For the first of the documents One partition, , For partitioned indexes, This refers to the partition size; Step (3) includes: Generate partition key Initial user calculates the key for each partition. Used to encrypt data; Encrypted partition data Initial users are randomly selected. Use partition key For partitions Encrypt and generate ciphertext. ; Generate partition transmission key ciphertext Initial user calculation , These are used as the private and public keys for the Elgamal algorithm, respectively; randomly selected. Calculate the ciphertext for transmitting the key in the partition. ; Generate partition ciphertext tags Initial users will encrypt partition data. As input, via Then generate partition ciphertext tags This is used to verify the consistency between the tag and the ciphertext; Generate partition deduplication detection tags Initial user input parameters and partitions Output partition deduplication and label detection ,in yes A random number; Upload data The initial user will ultimately identify the sensitive partition. Encrypted partition data , partition transmission of key ciphertext Partition encrypted tags Partition deduplication and tag detection Uploaded together to the cloud storage server, the cloud storage server will identify the identity. Save to Initial user save Identity identification and deduplication detection labels Used for downloading partition decryption; Step (4) includes: Generate file key User calculation As the number of sensitive partitions contained in each group, if the number of partitions in the last group does not reach the required value... The number of partitions is then increased through reversible padding to ensure that encryption and decryption algorithms can function correctly; the partition key is then... The connection is treated as a new plaintext message. Apply again Encrypt the new partition as Repeatedly group, concatenate, treat as new plaintext messages, and apply the partition key again. The encryption process continues until the final partition key contains the key generated in the previous steps; the key for the last partition becomes the key for that file. ; Encrypted files Initial users are randomly selected. Using a key For the file Encrypt and generate ciphertext. ; Generate ciphertext for file transfer Initial user calculation , These are used as the private and public keys for the Elgamal algorithm, respectively; randomly selected. Calculate the encrypted key for file transmission , ; Generate encrypted tags for files Initial users will encrypt files. As input, via Post-generated tags This is used to verify the consistency between the tag and the ciphertext; Generate deduplication and tagging of files Initial user input parameters and documents Output file deduplication and tag detection ; Upload data Initial user identification Encrypted files File deduplication detection tags File transfer key ciphertext and encrypted file tags Uploaded together to the cloud storage server, the cloud storage server will identify the identity. Save to Initial user save Identity identification and deduplication detection labels Used for downloading and decrypting files; Step (5) includes: Generate challenge information This is executed by the cloud storage server; the cloud storage server divides the stored encrypted data into fixed blocks, i.e. Randomly select several blocks and then... Location information The challenge information is encrypted and authenticated. Send to the user; Generate challenge evidence The task is executed by the user; after receiving the challenge information from the cloud storage server, the user first uses their private key. Decryption ; Calculate based on the obtained challenge information set And employs encrypted authentication The challenge evidence will be returned to the cloud storage server; Verify challenge information This is executed by the cloud storage server; after receiving the user's authentication information, the cloud storage server uses its own private key. The encrypted data block is computed in the same way, and the result is compared with... The comparison is performed; if they are equal, the user's identity is verified using Proof-of-Work (PoW). Add to the list of authorized users for the file Otherwise, the user's challenge fails. In step (6), the cloud storage server will detect duplicate tags on the uploaded files. The deduplication tag is compared with that of an existing file. If they are equal, the file already exists; otherwise, the file does not exist. In step (7), the cloud storage server will upload the partition deduplication detection tags. The deduplication check label is compared with the existing partition deduplication check label. If they are equal, the partition already exists and is a non-sensitive partition; if they are not equal, the partition does not exist and is a sensitive partition. Step (9) includes: Legitimate users will identify themselves. and partition encrypted tags The request is sent together to the cloud storage server; upon receiving the request, the cloud storage server checks... Check if the corresponding partition exists; if it does, further check the user's information. Is the user on the list of valid data? After the owner is determined, the partition will be transmitted with the key ciphertext. and partitioned data ciphertext Return it to the user; Authorized users update sensitive partitions: The user determines the block key index to be updated locally. Receive ciphertext of all sensitive partition keys along the root-to-leaf path from the cloud storage server. and through key ciphertext Decrypt partitions one by one Generate a new key for the updated sensitive partition. Replace the old key at its parent node with the new key, re-encrypt the parent node, and repeat until all affected partitions along the root-to-leaf path are re-encrypted; finally, update the consistency check label of the affected sensitive partitions. and deduplication detection labels ; When a legitimate user updates a file: the key of the last partition becomes the key of the new file when the final partition key contains the key updated in the previous steps. .

2. The cloud data deduplication method according to claim 1, characterized in that, Step (8) includes: Authorized users send download requests to the cloud storage server, and then submit their identity information. and encrypted tags The request is sent together to the cloud storage server; upon receiving the request, the cloud storage server first checks... Does the corresponding file exist? If it does, then further check the user's file. After confirming that the user is the owner of the data by checking if they are on the data's legitimate list, the key is encrypted. and encrypted data Return it to the user; Authorized users of the partition interact with the cloud storage server to obtain the partition key ciphertext. Then decrypt to obtain the key. Finally, the partitioned data is obtained; The legitimate user of the file interacts with the cloud storage server to obtain the file's encrypted key. Then decrypt to obtain the key. Finally, the file data is obtained.

3. The cloud data deduplication method according to claim 2, characterized in that, The partition's plaintext data that a legitimate user can decrypt includes: Get partition key Legitimate users, based on locally stored data right Decryption yields the partition. The key, the decryption formula is ; Decrypting data :pass Get partition ; The plaintext data that a legitimate user can decrypt in a file includes: Get file key : Based on locally saved data right Decrypt to obtain the file The key, the decryption formula is ; Decrypting data :pass Get the file .

Citation Information

Patent Citations

  • Cloud data deduplication method for double-layer encryption sensitive partition

    CN115550005A