Cloud-edge collaborative repeated data deletion method, system and device and medium

By implementing cloud-edge collaboration data deduplication method in edge computing, using trusted authentication, hash computing and two-level indexing strategies, data blocks are typed and de-deleted at the edge or cloud, solving the problem of high encryption costs in the existing technology and achieving efficient data management and storage.

CN120030569AActive Publication Date: 2025-05-23SUN YAT SEN UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510103850.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-23
Estimated Expiration
2045-01-21

AI Technical Summary

Technical Problem

The existing secure deduplication scheme in edge computing has too high encryption costs when processing data, resulting in excessive communication and computing overhead.

Method used

The cloud-edge collaboration deduplication method is adopted to encrypt and decrypt communication through trusted authentication between the client and the edge server, as well as trusted authentication between the edge server and the cloud server, and to divide the data blocks into types using hash computing and two-level indexing strategies, and redelete operations on edge server or cloud server according to the type.

Benefits of technology

It reduces the management and storage overhead of encryption keys, reduces the pressure on cloud storage, improves the storage efficiency and data management capabilities of the system, reduces communication, encryption and storage costs, and achieves an efficient balance between system performance and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030569A_ABST
    Figure CN120030569A_ABST
Patent Text Reader

Abstract

The invention provides a cloud-side collaborative repeated data deletion method, system and device and a medium. The method comprises the following steps: executing credible authentication between a client and an edge server and between the edge server and a cloud server; performing communication encryption on the to-be-uploaded data and uploading the to-be-uploaded data; performing Hash calculation on the data blocks to obtain corresponding fingerprint information; according to the file label, the fingerprint information and a two-stage index strategy, performing type division on the data blocks; if the type is a hot block, executing edge deduplication; and if the type is a cold block, executing cloud deduplication. By creating the cloud security area and the edge security area, effective isolation of communication is realized, and the security of the communication process is guaranteed. And the shared key is obtained while trusted authentication is executed, so that the management and storage overhead of the key is reduced. Edge deduplication and cloud deduplication are realized through a two-stage index strategy, the pressure of cloud storage is reduced, and the storage efficiency and the data management capability of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of data storage and computer technology, and in particular to a cloud-edge collaborative deduplication data method, system, device and medium. Background Art

[0002] Edge computing is a distributed computing architecture in which data processing and applications run closer to the data's "edge" devices or local networks. The cloud-edge collaboration model aims to reduce the latency of data transmission to cloud servers for processing, improve the real-time nature of data processing, reduce the computing burden of cloud servers, and enhance data security and privacy protection.

[0003] On the other hand, secure deduplication is an attractive data redundancy reduction technology that stores only one copy of duplicate data and provides a link to the copy to the owner. At the same time, it also uses encryption to achieve data security, taking into account both data storage efficiency and security requirements.

[0004] Secure data deduplication in edge computing improves the cost-effectiveness and data security of cloud storage. However, existing solutions are built on expensive cryptographic operations, which lead to high communication and computational overheads. Summary of the invention

[0005] The present invention provides a cloud-edge collaborative deduplication method, system, device and medium to solve the problem that the encryption cost of existing secure deduplication solutions in edge computing is too high when processing data, resulting in excessive communication and computing overhead.

[0006] In order to solve the above technical problems, the technical solution adopted by the present invention is to provide a cloud-edge collaborative data deduplication method, including the steps of: respectively executing trusted authentication between the client and the edge server, and trusted authentication between the edge server and the cloud server; performing communication encryption on the uploaded data, obtaining the encrypted data and uploading it; wherein the encrypted data includes multiple data blocks of the file and the file tags corresponding to the file; after communication decryption of the uploaded encrypted data, performing hash calculation on each of the data blocks to obtain the fingerprint information corresponding to each of the data blocks; according to the file tag, the fingerprint information corresponding to each of the data blocks, and the two-level indexing strategy, the multiple data blocks are divided into types; if the type of the data block is a hot block, edge deduplication is performed on the data block; if the type of the data block is a cold block, cloud deduplication is performed on the data block.

[0007] In some embodiments, the method for trusted authentication between the client and the edge server includes the steps of: the edge server creates an edge security zone, and the edge security zone generates a first attestation report; wherein the first attestation report includes identity information and status measurement values ​​of the edge security zone; the edge security zone sends the first attestation report to an authentication unit, and the authentication unit verifies the first attestation report to obtain a first signature report; the authentication unit sends the first signature report to the client through the edge server, and the client verifies the first signature report to determine the credibility of the edge security zone.

[0008] In some embodiments, the method for trusted authentication between the edge server and the cloud server includes the following steps: the cloud server creates a cloud security zone and a key security zone, and multiple edge servers create corresponding multiple edge security zones; the key security zone verifies the credibility of the multiple edge security zones, and generates a shared key and multiple private keys; wherein the private key corresponds to the edge security zone one-to-one; the key security zone generates a second proof report; wherein the second proof report includes the fingerprint information of the shared key, the fingerprint information of the private key, and the identity information of the key security zone; the key security zone sends the second proof report to the authentication unit, the authentication unit verifies the second proof report, and obtains a second signature report; the authentication unit sends the second signature report to each edge server through the key security zone, the edge server verifies the second signature report, determines the credibility of the key security zone, and obtains the shared key and the corresponding private key.

[0009] In some embodiments, the classification of the multiple data blocks according to the file tag, the fingerprint information corresponding to each data block, and the two-level index strategy specifically includes: identifying the version type of the file corresponding to the data block according to the file tag corresponding to each data block; searching for the corresponding version type in the first-level index entry, and locating the corresponding second-level index table according to the version type; wherein the second-level index table includes a fingerprint information list, an address list, and a type list; querying the fingerprint information list according to the fingerprint information corresponding to the data block, and updating the type of the corresponding data block in the type list; classifying the type of the data block corresponding to the updated part in the type list as a hot block, and classifying the type of the data block corresponding to the unupdated part in the type list as a cold block.

[0010] In some embodiments, the edge deduplication method includes the following steps: the hot block includes a type one hot block and a type two hot block; if the data block is a type one hot block, the data block is encrypted and saved; if the data block is a type two hot block, the data block is deleted.

[0011] In some embodiments, the cloud-based deduplication method includes the steps of: sending the fingerprint information corresponding to the data block of type cold block; wherein the cold block includes type I cold block and type II cold block; performing a secondary comparison and judgment on the type of the data block based on the fingerprint information, and feeding back the secondary comparison and judgment result; if the type of the data block is type I cold block, encrypting the data block and uploading it for storage; if the type of the data block is type II cold block, no processing is performed.

[0012] In some embodiments, the subsequent steps are also included: sending the file tag corresponding to the file to be downloaded; finding the corresponding recipe information based on the file tag; obtaining multiple data blocks corresponding to the file based on the recipe information, and decrypting the multiple data blocks to reconstruct the file and download it.

[0013] The present invention also provides a cloud-edge collaborative data deduplication system, comprising: an authentication unit, used to respectively perform trusted authentication between a client and an edge server, and trusted authentication between the edge server and a cloud server; a client, used to perform communication encryption on data to be uploaded, obtain encrypted data and upload it; wherein the encrypted data includes multiple data blocks of a file and file tags corresponding to the file; an edge server, used to perform communication decryption on the uploaded encrypted data, perform hash calculation on each of the data blocks, and obtain fingerprint information corresponding to each of the data blocks; and further used to classify the multiple data blocks into types according to the file tags, the fingerprint information corresponding to each of the data blocks, and a two-level indexing strategy; and further used to perform edge deduplication on the data blocks of type hot blocks; and a cloud server, used to perform cloud deduplication on the data blocks of type cold blocks.

[0014] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned method when executing the computer program.

[0015] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method described above are implemented.

[0016] The beneficial effects of the present invention are as follows: the present invention discloses a cloud-edge collaborative deduplication method, system, device and medium, the method comprising the steps of: respectively executing trusted authentication between a client and an edge server, and trusted authentication between an edge server and a cloud server; performing communication encryption on the data to be uploaded, obtaining encrypted data and uploading it; wherein the encrypted data includes multiple data blocks of a file and a file tag corresponding to the file; after communication decryption of the uploaded encrypted data, performing hash calculation on each data block to obtain fingerprint information corresponding to each data block; dividing multiple data blocks into types according to the file tag, the fingerprint information corresponding to each data block, and a two-level indexing strategy; if the type of the data block is a hot block, performing edge deduplication on the data block; if the type of the data block is a cold block, performing cloud deduplication on the data block. The present application achieves effective isolation of communication and ensures the security of the communication process by creating a cloud security zone and an edge security zone. And obtaining a shared key while performing trusted authentication reduces the management and storage overhead of the key. Further, edge deduplication and cloud deduplication are achieved through a two-level indexing strategy, which not only reduces the pressure of cloud storage, but also improves the storage efficiency and data management capabilities of the entire system. This application not only improves data communication efficiency and storage efficiency, but also further reduces communication, encryption and storage costs, achieving an efficient balance between system performance and data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flowchart of the cloud-edge collaborative deduplication method of the present application;

[0018] Figure 2 It is a schematic diagram of the composition of the cloud-edge collaborative deduplication system of this application;

[0019] Figure 3 It is a specific structural diagram of the cloud-edge collaborative deduplication system of this application;

[0020] Figure 4 It is a schematic diagram of the two-level indexing strategy in the cloud-edge collaborative deduplication method of the present application;

[0021] Figure 5 It is a schematic diagram of the structure of an electronic device according to an embodiment of the present application;

[0022] Figure 6 It is a schematic block diagram of an embodiment of a computer-readable storage medium of the present application. DETAILED DESCRIPTION

[0023] In order to facilitate the understanding of the present invention, the present invention is described in more detail below in conjunction with the accompanying drawings and specific embodiments. Preferred embodiments of the present invention are provided in the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described in this specification. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present invention more thorough and comprehensive.

[0024] It should be noted that, unless otherwise defined, all technical and scientific terms used in this specification have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used in this specification includes any and all combinations of one or more related listed items.

[0025] Figure 1 The implementation flow chart of the cloud-edge collaborative deduplication method provided by the present application is shown, including the following steps:

[0026] S1: Perform trusted authentication between the client and the edge server, and between the edge server and the cloud server.

[0027] S2: encrypt the data to be uploaded, obtain the encrypted data and upload it; wherein the encrypted data includes multiple data blocks of the file and a file tag corresponding to the file.

[0028] S3: After decrypting the uploaded encrypted data, perform hash calculation on each data block to obtain fingerprint information corresponding to each data block.

[0029] S4: Based on the file tag, the fingerprint information corresponding to each data block, and the two-level indexing strategy, multiple data blocks are classified into types.

[0030] S5: If the data block type is a hot block, edge deduplication is performed on the data block; if the data block type is a cold block, cloud deduplication is performed on the data block.

[0031] This application achieves effective isolation of communications and ensures the security of the communication process by creating a cloud security zone and an edge security zone. It also obtains shared keys while performing trusted authentication, reducing key management and storage overhead. Further edge deduplication and cloud deduplication are achieved through a two-level indexing strategy, which not only reduces the pressure on cloud storage, but also improves the storage efficiency and data management capabilities of the entire system. This application not only improves data communication efficiency and storage efficiency, but also further reduces communication, encryption and storage costs, achieving an efficient balance between system performance and data security.

[0032] Combine the following Figures 1 to 6, the present application is further described in detail with specific embodiments.

[0033] like Figure 1 As shown, the cloud-edge collaborative deduplication method provided in the embodiment of the present application is described in detail as follows:

[0034] S1: Perform trusted authentication between the client and the edge server, and between the edge server and the cloud server.

[0035] like Figure 2 As shown, the deduplication system of the present application includes a cloud server 1, multiple edge servers 2, and multiple clients 3. A cloud server 1 can communicate with multiple edge servers 2 respectively without interfering with each other; each edge server 2 can communicate with multiple clients 3 without interfering with each other.

[0036] Among them, the cloud server 1 is a physical device located in the center of the network with powerful computing and storage capabilities. It is responsible for scheduling the global storage of encrypted data and deduplication. The edge server 2 is distributed around the client 3, and it provides users with outsourced storage and computing services. The client 3 is the legal owner of the data. Each client 3 has specific access rights. The edge server 2 manages the access rights of each user based on these access rights.

[0037] Combination Figure 2 As shown, when the system of the present application is working, it first needs to be initialized, that is, trusted authentication is required between each part (such as between the client 3 and the edge server 2, or between the edge server 2 and the cloud server 1) to ensure the security of the communication process. The trusted authentication process is mainly completed by the authentication unit 4. In this embodiment, the authentication unit 4 specifically refers to the Intel Attestation Service Center (IAS).

[0038] Specific, combined Figure 3 As shown, the trusted authentication method between each client 3 and the edge server 2 includes the following steps:

[0039] The edge server 2 first creates the edge security zone 22 and calls the SGX (Software Guard Extensions, processor extension) code to enable the edge security zone 22 to generate a first certification report. The first certification report includes the identity information and state measurement value of the edge security zone 22, and the state measurement value is the fingerprint information in the edge security zone 22.

[0040] Further, the edge security zone 22 sends the first proof report to the authentication unit 4, and the authentication unit 4 verifies the authenticity of the first proof report and signs it to generate a first signature report 29. The authentication unit 4 returns the first signature report 29 to the edge server 2, and sends the first signature report 29 to the client 3 through the edge server 2. At the same time, the edge server 2 saves the first signature report 29 to the edge storage area 23.

[0041] After receiving the first signature report 29 , the client 3 uses the public key of the authentication unit 4 to verify the signature in the first signature report 29 , and further determines the credibility of the edge security zone 22 .

[0042] Further, combined with Figure 2 , Figure 3 As shown, the method for trusted authentication between multiple edge servers 2 and a cloud server 1 includes the following steps:

[0043] The cloud server 1 first creates a cloud security zone 12 and a key security zone 11 , and each edge server 2 creates its own corresponding edge security zone 22 .

[0044] Furthermore, the credibility of multiple edge security zones 22 is verified respectively through the key security zone 11. The key security zone 11 generates high-security encryption keys (including shared keys and multiple private keys) with the help of random functions of the KDC (Key Distribution Center), such as AES (Advanced Encryption Standard) under the GCM mode (Galois counter mode), which provides data confidentiality and integrity. Among them, the private key corresponds to the edge security zone 22 one by one, that is, each edge security zone 22 corresponds to a unique private key.

[0045] Further, the key security zone 11 generates a second proof report. The second proof report includes the fingerprint information of the shared key, the fingerprint information of each private key, and the identity information of the key security zone 11. The key security zone 11 sends the second proof report to the authentication unit 4, and the authentication unit 4 verifies the authenticity of the second proof report and signs it to generate a second signature report 17. The authentication unit 4 returns the second signature report 17 to the key security zone 11, and sends the second signature report 17 to each edge server 2 through the key security zone 11. At the same time, the cloud server 1 saves the second signature report 17 to the cloud storage area 13.

[0046] After receiving the second signature report 17, each edge server 2 verifies the second signature report 17, determines the credibility of the key security zone 11, and obtains the shared key and the corresponding different private keys. Each edge server 2 saves the obtained shared key and private key to its own edge security zone 22 for subsequent use.

[0047] S2: encrypt the data to be uploaded, obtain the encrypted data and upload it; wherein the encrypted data includes multiple data blocks of the file and a file tag corresponding to the file.

[0048] Specific, combined Figure 2 As shown, this step is mainly completed by client 3.

[0049] When the client 3 needs to upload a file to the edge server 2 or the cloud server 1, the client 3 first needs to encrypt the data to be uploaded to avoid data leakage during the uploading process.

[0050] Among them, in this embodiment, the ECDH (Elliptic Curve Diffie-Hellman) protocol is used to generate a one-time session key to encrypt the communication of the uploaded data. The one-time session key calculation steps are not repeated here. By using the ECDH protocol, the client 3 and the edge server 2 can negotiate a common session key on an insecure channel to ensure the security of the communication process.

[0051] It should be noted that a file can be composed of multiple different data blocks. When we need to upload one of the files, we can choose to upload multiple data blocks of the file for subsequent duplicate checking and deletion. Among them, the file tag represents the specific version type of the file.

[0052] Furthermore, the encrypted data after communication encryption is uploaded to the corresponding edge server 2 to wait for further processing.

[0053] S3: After decrypting the uploaded encrypted data, perform hash calculation on each data block to obtain fingerprint information corresponding to each data block.

[0054] Specifically, Figure 3 As shown, this step is mainly completed by edge server 2.

[0055] The client 3 uploads the encrypted data to the edge server 2 through the file transfer interface 21, and transmits it to the edge security zone 22 of the edge server 2. The encryption and decryption module 24 of the edge security zone 22 uses the one-time session key generated in S2 to decrypt the encrypted data.

[0056] The decrypted data is further transmitted to the deduplication module 25, and the fingerprint information corresponding to each data block in the data is calculated by the hash calculation submodule 201, and the formula information 27 corresponding to the data is recorded, and the formula information 27 is stored in the edge storage area 23 for use in the subsequent download stage.

[0057] S4: Based on the file tag, the fingerprint information corresponding to each data block, and the two-level indexing strategy, multiple data blocks are classified into types.

[0058] Specifically, Figure 3 As shown, this step is mainly completed by edge server 2.

[0059] The fingerprint information corresponding to each data block calculated by the hash calculation submodule 201 in S3 is transmitted to the classification submodule 202 to classify each data block. In this application, the types of data blocks are divided into two categories, one is cold blocks (i.e., data that is not frequently used), and the other is hot blocks (i.e., data that is needed in the short term, or data that is frequently used in the long term).

[0060] In this embodiment, combined with Figure 4 As shown, the specific classification method includes the following steps:

[0061] According to the file tag corresponding to each data block, identify the version type of the file corresponding to the data block. Search the corresponding version type in the primary index entry, and locate the corresponding secondary index table according to the version type. The secondary index table includes a fingerprint information list, an address list, and a type list. According to the fingerprint information corresponding to the data block, query the fingerprint information list, and update the type of the corresponding data block in the type list. The type of the data block corresponding to the updated part in the type list is classified as a hot block, and the type of the data block corresponding to the unupdated part in the type list is classified as a cold block.

[0062] by Figure 4 Take the data in the table as an example (blue represents new content and red represents modified content) to further explain the above process. First, fill the type list in the secondary index table with "cold blocks". Assuming that the file tag of the current data block identifies that the version type of the file corresponding to the current data block is Linux, then Figure 4 The corresponding version type (ie, Linux version type) is searched in the first-level index entry in , and the corresponding second-level index table (ie, the second-level index table of Linux) is located according to the version type.

[0063] If the fingerprint information corresponding to the current data block is A, and the same fingerprint information (A) is found in the fingerprint information list in the secondary index table of Linux, the type in the type list corresponding to the fingerprint information (A) is modified to "hot block"; if the fingerprint information corresponding to the current data block is D (already exists in the secondary index table), the same applies.

[0064] If the fingerprint information corresponding to the current data block is B, and the same fingerprint information is not found in the fingerprint information list in the secondary index table of Linux, the fingerprint information B is added to the secondary index table of Linux, and its corresponding type is filled in as "hot block".

[0065] If the fingerprint information of all data blocks has been queried, and there are still two unqueried fingerprint information (C and E) in the Linux secondary index table, the type of the data block corresponding to the fingerprint information (C and E) is classified as "cold block" and remains unchanged.

[0066] If the file tag of the current data block is used to identify the version type of the file corresponding to the current data block as FSL, and Figure 4 If the corresponding version type (i.e., FSL version type) is not found in the first-level index entry in the table, the FSL version type is added to the first-level index entry, and a corresponding second-level index table (i.e., FSL's second-level index table) is newly created based on the FSL version type. If the fingerprint information corresponding to the current data block is F, the fingerprint information F is added to the fingerprint information list in the newly created FSL second-level index table, and its corresponding type is filled in as "hot block".

[0067] Classifying the data blocks by type can effectively improve storage efficiency, make the storage of useful data more convenient, and save the storage space of other duplicate or invalid data in the edge server 2.

[0068] S5: If the data block type is a hot block, edge deduplication is performed on the data block; if the data block type is a cold block, cloud deduplication is performed on the data block.

[0069] Among them, hot blocks include Class I hot blocks and Class II hot blocks; cold blocks include Class I cold blocks and Class II cold blocks. Class I hot blocks refer to newly uploaded non-duplicate data blocks, and Class II hot blocks refer to duplicate data blocks. Class I cold blocks refer to data blocks that are not stored in cloud server 1, and Class II cold blocks refer to data blocks that have been stored in cloud server 1.

[0070] In this embodiment, the edge deduplication method includes the following steps: if the data block type is a first-class hot block, encrypting and saving the data block; if the data block type is a second-class hot block, deleting the data block.

[0071] Specifically, then Figure 4For example, combined with the analysis content in S4, it can be known that the data blocks with fingerprint information A and D are of type II hot blocks, the data blocks with fingerprint information B and F are of type I hot blocks, and the data blocks with fingerprint information C and E are of type cold blocks.

[0072] Further, the uploaded data block of type 1 hot block is encrypted by the private key of the edge server 2 and saved in the edge data block storage module 28 of the edge storage area 23. The uploaded data block of type 2 hot block is directly deleted. The uploaded data block of type 2 cold block is saved in the data communication buffer submodule 203 in the buffer module 26 of the edge security area 22 for further processing.

[0073] Further, combined with Figure 3 As shown, in this embodiment, the cloud deduplication method includes the steps of:

[0074] First, the fingerprint information corresponding to the data block of the cold block type is sent to the cloud security zone 12 in the cloud server 1 through the data communication buffer submodule 203 in the edge server 2, and a query is performed in the security index table 14 according to the corresponding fingerprint information.

[0075] If the same fingerprint information is found in the security index table 14, it means that the type of the data block is a second-class cold block. If the same fingerprint information is not found in the security index table 14, a further search is performed in the global index table 15 in the cloud storage area 13; if the same fingerprint information is found in the global index table 15, it means that the type of the data block is a second-class cold block; if the same fingerprint information is still not found in the global index table 15, it means that the type of the data block is a first-class cold block.

[0076] Further, the query result is fed back to the edge server 2. According to the result, the data communication buffer submodule 203 encrypts the data block of the type of cold block stored therein by the shared key, and uploads it to the cloud data block storage module 16 of the cloud storage area 13 in the cloud server 1 for storage. The shared key is the same key shared by all, so it can be directly saved without further decryption.

[0077] Furthermore, when downloading the file, the application also includes the following steps:

[0078] refer to Figure 3 , the client 3 sends the file tag corresponding to the file to be downloaded to the edge server 2. The edge server 2 searches the edge storage area 23 for the recipe information 27 of the corresponding file according to the file tag. The recipe information 27 records the data block composition content of the corresponding file, that is, which data blocks the file is specifically composed of.

[0079] Further, according to the recipe information 27, multiple data blocks corresponding to the file are searched and obtained from the edge server 2 or the cloud server 1, and the multiple data blocks are decrypted by the data recovery buffer submodule 204 of the edge server 2 to reconstruct the file. The client 3 can further download the file from the edge server 2.

[0080] Corresponding to the cloud-edge collaborative deduplication method of the above embodiment, the embodiment of the present application also provides a cloud-edge collaborative deduplication system. For the sake of ease of explanation, only the parts related to the embodiment of the present application are shown.

[0081] like Figure 2 , Figure 3 As shown, the cloud-edge collaborative data deduplication system includes:

[0082] The authentication unit 4 is used to perform trusted authentication between the client 3 and the edge server 2, and trusted authentication between the edge server 2 and the cloud server 1.

[0083] The client 3 is used to encrypt the data to be uploaded, obtain the encrypted data and upload it; wherein the encrypted data includes multiple data blocks of the file and the file tag corresponding to the file.

[0084] Edge server 2 is used to perform hash calculation on each data block after decrypting the uploaded encrypted data to obtain fingerprint information corresponding to each data block; it is also used to classify multiple data blocks into types according to file tags, fingerprint information corresponding to each data block, and a two-level indexing strategy; it is also used to perform edge deduplication on data blocks of type hot blocks.

[0085] The cloud server 1 is used to perform cloud deduplication on data blocks of the cold block type.

[0086] It should be noted that other technical features in the above-mentioned cloud-edge collaborative data deduplication system are the same as the features disclosed in the above-mentioned embodiment methods. Please refer to the description in the above-mentioned corresponding method embodiments and will not be repeated here.

[0087] Based on the same inventive concept, the present application also provides an electronic device, which includes a processor, a memory and a communication circuit, and the processor is connected to the memory and the communication circuit respectively; wherein the communication circuit is used for communication connection, the memory is used to store a computer program, and the processor is used to execute the computer program to implement the above-mentioned cloud-edge collaborative deduplication method.

[0088] See also Figure 5 The electronic device described in the embodiment of the present application may specifically include a processor 210 and a memory 220. The memory 220 is coupled to the processor 210.

[0089] The processor 210 is used to control the operation of the electronic device. The processor 210 may also be referred to as a CPU (Central Processing Unit). The processor 210 may be an integrated circuit chip having the ability to process signals. The processor 210 may also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. A general-purpose processor may be a microprocessor or the processor 210 may also be any conventional processor, etc.

[0090] The memory 220 is used to store computer programs, and may be a RAM, a ROM, or other types of storage terminals. Specifically, the memory 220 may include one or more computer-readable storage media, which may be non-transitory or transient. The memory 220 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage terminals, flash memory storage terminals. In some embodiments, the non-transitory computer-readable storage medium in the memory 220 is used to store at least one program code.

[0091] The processor 210 is used to execute the computer program stored in the memory 220 to implement the methods described in the various method embodiments of the present application.

[0092] In some embodiments, the electronic device may further include: a peripheral terminal interface 230 and at least one peripheral terminal. The processor 210, the memory 220 and the peripheral terminal interface 230 may be connected via a bus or a signal line. Each peripheral terminal may be connected to the peripheral terminal interface 230 via a bus, a signal line or a circuit board. Specifically, the peripheral terminal includes: at least one of a radio frequency circuit 240, a display screen 250, an audio circuit 260 and a power supply 270.

[0093] The peripheral terminal interface 230 may be used to connect at least one peripheral terminal related to I / O (Input / output) to the processor 210 and the memory 220. In some embodiments, the processor 210, the memory 220, and the peripheral terminal interface 230 are integrated on the same chip or circuit board; in some other implementations, any one or two of the processor 210, the memory 220, and the peripheral terminal interface 230 may be implemented on a separate chip or circuit board, which is not limited in this embodiment.

[0094] The radio frequency circuit 240 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 240 communicates with the communication network and other Internet of Things devices through electromagnetic signals, and the radio frequency circuit 240 is the communication circuit of the electronic device. The radio frequency circuit 240 converts electrical signals into electromagnetic signals for transmission, or converts the received electromagnetic signals into electrical signals. Optionally, the radio frequency circuit 240 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a subscriber identity module card, and so on. The radio frequency circuit 240 can communicate with other terminals through at least one wireless communication protocol. The wireless communication protocol includes but is not limited to: the World Wide Web, a metropolitan area network, an intranet, generations of mobile communication networks (2G, 3G, 4G, and 5G), a wireless local area network, and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 240 may further include a circuit related to NFC (Near Field Communication), which is not limited in this application.

[0095] The display screen 250 is used to display a UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 250 is a touch display screen, the display screen 250 also has the ability to collect touch signals on or above the surface of the display screen 250. The touch signals can be input to the processor 210 for processing as control signals. At this time, the display screen 250 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 250, which is set on the front panel of the electronic device; in other embodiments, there may be at least two display screens 250, which are respectively set on different surfaces of the electronic device or in a folded design; in other embodiments, the display screen 250 may be a flexible display screen, which is set on the curved surface or the folding surface of the electronic device. Even, the display screen 250 can also be set into an irregular non-rectangular shape, that is, a special-shaped screen. The display screen 250 can be prepared from materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).

[0096] The audio circuit 260 may include a microphone and a speaker. The microphone is used to collect sound waves from the operator and the environment, and convert the sound waves into electrical signals and input them into the processor 210 for processing, or input them into the radio frequency circuit 240 to achieve voice communication. For the purpose of stereo acquisition or noise reduction, there may be multiple microphones, which are respectively arranged in different parts of the electronic device. The microphone may also be an array microphone or an omnidirectional acquisition microphone. The speaker is used to convert the electrical signal from the processor 210 or the radio frequency circuit 240 into sound waves. The speaker may be a traditional film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into sound waves inaudible to humans for purposes such as ranging. In some embodiments, the audio circuit 260 may also include a headphone jack.

[0097] The power supply 270 is used to power various components in the electronic device. The power supply 270 can be an alternating current, a direct current, a disposable battery, or a rechargeable battery. When the power supply 270 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery that is charged through a wired line, and a wireless rechargeable battery is a battery that is charged through a wireless coil. The rechargeable battery can also be used to support fast charging technology.

[0098] For a detailed description of the functions and execution processes of each functional module or component in the electronic device embodiment of the present application, reference can be made to the description in the above-mentioned method embodiments of the present application, which will not be repeated here.

[0099] In the several embodiments provided in the present application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the various embodiments of the electronic devices described above are only schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0100] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0101] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0102] Based on the same inventive concept, the present application also provides a computer-readable storage medium storing a computer program, which can be executed by a processor to implement the above-mentioned cloud-edge collaborative deduplication method.

[0103] See also Figure 6 , if the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium 300. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including several instructions / computer programs to enable an IoT device (which can be a personal computer, server, or network terminal, etc.) or a processor (processor) to perform all or part of the steps of each implementation method of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks or optical disks, and electronic terminals such as computers, mobile phones, laptops, tablet computers, cameras, etc. having the above-mentioned storage media.

[0104] The description of the execution process of the program data in the computer-readable storage medium can refer to the description in the above-mentioned method embodiments of the present application, and will not be repeated here.

[0105] It can be seen that the present invention discloses a cloud-edge collaborative deduplication method, system, device and medium, the method comprising the steps of: performing trusted authentication between a client and an edge server, and trusted authentication between an edge server and a cloud server respectively; encrypting the data to be uploaded, obtaining encrypted data and uploading it; wherein the encrypted data includes multiple data blocks of a file and a file tag corresponding to the file; after decrypting the uploaded encrypted data, performing hash calculation on each data block to obtain fingerprint information corresponding to each data block; dividing multiple data blocks into types according to the file tag, the fingerprint information corresponding to each data block, and a two-level indexing strategy; if the type of the data block is a hot block, edge deduplication is performed on the data block; if the type of the data block is a cold block, cloud deduplication is performed on the data block. The present application achieves effective isolation of communication and ensures the security of the communication process by creating a cloud security zone and an edge security zone. And obtains a shared key while performing trusted authentication, reducing the management and storage overhead of the key. Further, edge deduplication and cloud deduplication are achieved through a two-level indexing strategy, which not only reduces the pressure of cloud storage, but also improves the storage efficiency and data management capabilities of the entire system. This application not only improves data communication efficiency and storage efficiency, but also further reduces communication, encryption and storage costs, achieving an efficient balance between system performance and data security.

[0106] The above are only embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structural transformations made using the contents of the present invention's specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A cloud-edge collaborative deduplication method, characterized in that: Includes steps: Performing trusted authentication between the client and the edge server, and trusted authentication between the edge server and the cloud server respectively; Performing communication encryption on the data to be uploaded, obtaining the encrypted data and uploading it; wherein the encrypted data includes a plurality of data blocks of the file and a file tag corresponding to the file; After the uploaded encrypted data is decrypted, a hash calculation is performed on each data block to obtain fingerprint information corresponding to each data block; Classify the multiple data blocks into types according to the file tag, the fingerprint information corresponding to each data block, and the two-level indexing strategy; If the type of the data block is a hot block, edge deduplication is performed on the data block; if the type of the data block is a cold block, cloud deduplication is performed on the data block.

2. The cloud-edge collaborative data deduplication method according to claim 1, characterized in that: The method for trusted authentication between the client and the edge server comprises the steps of: The edge server creates an edge security zone, and the edge security zone generates a first certification report; wherein the first certification report includes identity information and state measurement values ​​of the edge security zone; The edge security zone sends the first certification report to the authentication unit, and the authentication unit verifies the first certification report to obtain a first signature report; The authentication unit sends the first signature report to the client through the edge server, and the client verifies the first signature report to determine the credibility of the edge security zone.

3. The cloud-edge collaborative data deduplication method according to claim 1, characterized in that: The method for trusted authentication between the edge server and the cloud server comprises the steps of: The cloud server creates a cloud security zone and a key security zone, and the plurality of edge servers create corresponding plurality of edge security zones; The key security zone verifies the credibility of the plurality of edge security zones and generates a shared key and a plurality of private keys; wherein the private keys correspond one to one with the edge security zones; The key security zone generates a second certification report; wherein the second certification report includes the fingerprint information of the shared key, the fingerprint information of the private key, and the identity information of the key security zone; The key security zone sends the second certification report to the authentication unit, and the authentication unit verifies the second certification report to obtain a second signature report; The authentication unit sends the second signature report to each edge server through the key security zone, and the edge server verifies the second signature report, determines the credibility of the key security zone, and obtains the shared key and the corresponding private key.

4. The cloud-edge collaborative data deduplication method according to claim 1, characterized in that: The dividing of the multiple data blocks into types according to the file tag, the fingerprint information corresponding to each data block, and the two-level indexing strategy specifically includes: According to the file tag corresponding to each data block, identifying the version type of the file corresponding to the data block; Searching for the corresponding version type in the primary index entry, and locating the corresponding secondary index table according to the version type; wherein the secondary index table includes a fingerprint information list, an address list, and a type list; According to the fingerprint information corresponding to the data block, query the fingerprint information list, and update the type of the corresponding data block in the type list; The types of the data blocks corresponding to the updated parts in the type list are classified as hot blocks, and the types of the data blocks corresponding to the unupdated parts in the type list are classified as cold blocks.

5. The cloud-edge collaborative data deduplication method according to claim 1, characterized in that: The edge deduplication method comprises the steps of: The heat blocks include a first type of heat block and a second type of heat block; If the type of the data block is a type of hot block, encrypting and saving the data block; If the type of the data block is a second-class hot block, the data block is deleted.

6. The cloud-edge collaborative data deduplication method according to claim 1, characterized in that: The cloud deduplication method comprises the following steps: Sending the fingerprint information corresponding to the data block of the cold block type; wherein the cold block includes a first type cold block and a second type cold block; According to the fingerprint information, a secondary comparison is performed on the type of the data block, and the secondary comparison result is fed back; If the data block is a cold block, encrypt the data block and save it after uploading; If the data block is a type II cold block, no processing is performed.

7. The cloud-edge collaborative data deduplication method according to claim 1, characterized in that: Also includes next steps: Sending the file tag corresponding to the file to be downloaded; According to the file tag, find the corresponding recipe information; According to the recipe information, a plurality of data blocks corresponding to the file are obtained, and the plurality of data blocks are decrypted to reconstruct and download the file.

8. A cloud-edge collaborative data deduplication system, characterized in that: include: an authentication unit, used to respectively perform trusted authentication between the client and the edge server, and trusted authentication between the edge server and the cloud server; The client is used to encrypt the data to be uploaded, obtain the encrypted data and upload it; wherein the encrypted data includes multiple data blocks of the file and the file tag corresponding to the file; The edge server is used to perform hash calculation on each data block after decrypting the uploaded encrypted data, so as to obtain fingerprint information corresponding to each data block; it is also used to classify the multiple data blocks into types according to the file tag, the fingerprint information corresponding to each data block, and the two-level indexing strategy; it is also used to perform edge deduplication on the data blocks of the hot block type; The cloud server is used to perform cloud deduplication on the data blocks of the cold block type.

9. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Saving type duplicated data deleting method in cloud storage system

    CN104932841A

  • Workload optimized data deduplication using ghost fingerprints

    CN109416681A

  • Cloud edge-end longitudinal fusion de-duplication storage system, method, equipment and medium

    CN117539389A

  • Asynchronous semi-inline deduplication

    US10001942B1