Implementation of Resilient Deterministic Encryption

The method addresses vulnerabilities in current deterministic encryption solutions by using a secret key to create a fully deterministic ciphertext string for data deduplication, ensuring enhanced security and efficiency.

JP7691190B2Active Publication Date: 2025-06-11INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023531627
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-07
Filing Date
2021-11-04
Publication Date
2025-06-11
Estimated Expiration
2041-11-04

Smart Images

  • Figure 0007691190000001
    Figure 0007691190000001
  • Figure 0007691190000002
    Figure 0007691190000002
  • Figure 0007691190000003
    Figure 0007691190000003
Patent Text Reader

Abstract

The computer-implemented method includes creating an initialization vector using the instance of plaintext and a secret key; encrypting the instance of plaintext using the initialization vector, the secret key, and the instance of plaintext; combining the initialization vector and the encrypted instance of plaintext to create a ciphertext string; and sending the ciphertext string to a storage device that performs deduplication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to data encryption, and in particular, this invention relates to implementing deterministic encryption of data to facilitate data deduplication.

[0002] Deterministic encryption is useful in data storage in that it allows duplicates of encrypted data to be identified and removed within such a data storage. Length Preserving Compression (LPC) is a concept that enables a storage system to perform data deduplication on data that has already been persistently encrypted at the host. However, current approaches to LPC implementation can result in systems that can be bypassed by known methods. Therefore, improved deterministic encryption solutions that avoid such bypasses are desired.

Summary of the Invention

[0003] A computer-implemented method according to one aspect comprises creating an initialization vector using an instance of plaintext and a secret key; encrypting the instance of plaintext using the initialization vector, the secret key, and the instance of plaintext; combining the initialization vector and the encrypted instance of plaintext to create a ciphertext string; and transmitting the ciphertext string to a storage device that performs deduplication.

[0004] According to another aspect, the initialization vector is added as metadata to the encrypted instance of plaintext.

[0005] According to another aspect, the initialization vector and the encrypted instance of plaintext are combined into a single data chunk that is parsed when a read operation is performed.

[0006] In this way, a fully deterministic ciphertext string can be created and stored for an instance of data. Since both the initialization vector and the instance of the encrypted plaintext are calculated using the secret key, security vulnerabilities are avoided.

[0007] According to another aspect, a computer program product for implementing resilient deterministic encryption comprises a computer-readable storage medium having program instructions embodied thereon. The computer-readable storage medium is not a transient signal per se. The program instructions are executable by a processor to cause the processor to perform a method having: a procedure for creating an initialization vector using an instance of plaintext and a secret key; a procedure for encrypting an instance of plaintext using the initialization vector, the secret key, and the instance of plaintext; a procedure for combining the initialization vector and the instance of the encrypted plaintext to create a ciphertext string; and a procedure for transmitting the ciphertext string to a storage device that performs deduplication.

[0008] According to another aspect, a system comprises a processor; and logic integrated with, executable by, or integrated with and executable by the processor, where the logic is configured to: create an initialization vector using an instance of plaintext and a secret key; encrypt an instance of plaintext using the initialization vector, the secret key, and the instance of plaintext; combine the initialization vector and the instance of the encrypted plaintext to create a ciphertext string; and transmit the ciphertext string to a storage device that performs deduplication.

[0009] According to another aspect, a computer-implemented method includes analyzing a plurality of ciphertext strings in a data storage, where each of the plurality of ciphertext strings is created by combining an initialization vector and an instance of encrypted plaintext, the instance of encrypted plaintext is encrypted using the initialization vector, a secret key, and an instance of plaintext, and the initialization vector is created using the instance of plaintext and the secret key; and removing one or more redundant ciphertext strings from the data storage based on the analyzing step.

[0010] Other aspects and embodiments of the invention will become apparent from the following detailed description, which, when interpreted in conjunction with the drawings, illustrate the principles of the invention by way of example.

Brief Description of the Drawings

[0011]

Figure 1

[0012]

Figure 2

[0013]

Figure 3

[0014]

Figure 4

[0015]

Figure 5

[0016]

Figure 6

[0017]

Figure 7

[0018] The following description is made for the purpose of illustrating the general principles of the present invention and is not meant to limit the concepts of the invention claimed herein. Further, the specific features described herein can be used in combination with other described features in each of various possible combinations and permutations.

[0019] Unless specifically defined otherwise herein, all terms are to be given their broadest possible interpretation including meanings suggested by the specification as well as meanings understood by those skilled in the art and / or as defined in dictionaries, treatises, etc.

[0020] It should also be noted that, as used in this specification and the appended claims, the singular forms "a", "an", and "the" include plural referents unless the context clearly dictates otherwise. The terms "comprises" and / or "comprising", when used in this specification, specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0021] The following description discloses several aspects of implementing resilient deterministic encryption.

[0022] In one general aspect, a computer-implemented method includes creating an initialization vector using a plaintext instance and a secret key; encrypting the plaintext instance using the initialization vector, the secret key, and the plaintext instance; combining the initialization vector and the encrypted plaintext instance to create a ciphertext string; and transmitting the ciphertext string to a storage device that performs deduplication.

[0023] In another general aspect, the initialization vector is added as metadata to the encrypted plaintext instance.

[0024] In another general aspect, the initialization vector and the encrypted plaintext instance are combined into a single data chunk that is parsed when a read operation is performed.

[0025] In this way, a fully deterministic ciphertext string can be created and stored for an instance of data, and since both the initialization vector and the encrypted plaintext instance are calculated with the secret key, security vulnerabilities are avoided.

[0026] In another general aspect, a computer program product for implementing resilient deterministic encryption includes a computer-readable storage medium having program instructions embodied thereon, the computer-readable storage medium not being a transient signal per se, and the program instructions being executable by a processor to cause the processor to perform a method having steps of creating an initialization vector using a plaintext instance and a secret key; encrypting the plaintext instance using the initialization vector, the secret key, and the plaintext instance; combining the initialization vector and the encrypted plaintext instance to create a ciphertext string; and transmitting the ciphertext string to a storage device that performs deduplication.

[0027] In another general aspect, the system comprises a processor; and logic integrated with or executable by the processor, where the logic creates an initialization vector using a plaintext instance and a private key; encrypts the plaintext instance using the initialization vector, the private key, and the plaintext instance; combines the initialization vector and the encrypted plaintext instance to create a ciphertext string; and is configured to transmit the ciphertext string to a storage device that performs deduplication.

[0028] In another general aspect, a computer-implemented method comprises analyzing a plurality of ciphertext strings in a data storage, where each of the plurality of ciphertext strings is created by combining an initialization vector and an encrypted plaintext instance, the encrypted plaintext instance is encrypted using the initialization vector, a private key, and the plaintext instance, and the initialization vector is created using the plaintext instance and the private key; and removing one or more redundant ciphertext strings from the data storage based on the analyzing.

[0029] Although the present disclosure includes a detailed description regarding cloud computing, it should be understood that the implementations of the teachings described herein are not limited to a cloud computing environment. Rather, aspects of the invention are capable of being implemented in conjunction with any other type of computing environment now known or later developed.

[0030] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources (such as networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models.

[0031] The characteristics are as follows.

[0032] On-demand self-service: Cloud consumers can provision computing capabilities, such as server time and network storage, automatically as needed, without the need for human interaction with the service provider.

[0033] Broad network access: This capability is available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (such as mobile phones, laptops, and PDAs (registered trademarks)).

[0034] Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, and different physical and virtual resources are dynamically assigned and reassigned according to demand. Consumers generally have no control or knowledge over the exact location of the provided resources, but there is location independence in that it may be possible to specify location at a higher level of abstraction (such as country, state, or data center).

[0035] Rapid elasticity: This ability can provision quickly and elastically, and in some cases automatically, scale out urgently, and release quickly to scale in urgently. For consumers, in many cases, the available provisioning capabilities seem unlimited and can be purchased in any amount at any time.

[0036] Measured services: Cloud systems automatically control and optimize resource usage by leveraging measurement capabilities at an appropriate level of abstraction for service types (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both the provider and consumers of the services utilized.

[0037] The service model is as follows.

[0038] Software as a Service (SaaS): The ability provided to consumers is to use the provider's applications running on the cloud infrastructure. This application is accessible from various client devices through a client interface such as a web browser (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even the individual application capabilities, except for limited user-specific application configuration settings as a possible exception.

[0039] Platform as a Service (PaaS): The capabilities provided to consumers are to deploy applications created or acquired by consumers on a cloud infrastructure using programming languages and tools supported by the provider. Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, or storage, but control the deployed applications and, in some cases, the application hosting environment configuration.

[0040] Infrastructure as a Service (IaaS): The capabilities provided to consumers are to provision processing, storage, networks, and other basic computing resources, where consumers can deploy and run any software that can include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but control the operating systems, storage, deployed applications, and, in some cases, limited control over selected networking components (e.g., host firewalls).

[0041] The deployment models are as follows.

[0042] Private cloud: This cloud infrastructure operates only for a particular organization. It may be managed by that organization or a third party and may exist on-premises or off-premises.

[0043] Community cloud: This cloud infrastructure is shared by several organizations and supports a specific community with shared concerns (e.g., mission, security requirements, policies, and compliance considerations). It may be managed by those organizations or a third party and may exist on-premises or off-premises.

[0044] Public cloud: This cloud infrastructure is made available to the general public or large industry groups and is owned by an organization that sells cloud services.

[0045] Hybrid cloud: This cloud infrastructure is a composite of two or more clouds (private, community, or public), where the two or more clouds remain separate entities but are joined together by standard or proprietary technologies that enable data and application portability (e.g., cloud bursting for load distribution between clouds).

[0046] Cloud computing environments are service-oriented, emphasizing statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0047] Referring now to FIG. 1, an exemplary cloud computing environment 50 is shown. As shown, cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud consumers, such as, for example, a personal digital assistant (PDA) or cellular telephone 54A, desktop computer 54B, laptop computer 54C, and / or automotive computer system 54N, may communicate. Nodes 10 may communicate with one another. They may be physically or virtually grouped in one or more networks such as a private cloud, community cloud, public cloud, or hybrid cloud as described above herein, or combinations thereof (not shown). Thereby, cloud computing environment 50 can provide infrastructure, platform and / or software as services such that a cloud consumer need not maintain resources on a local computing device therefor. The types of computing devices 54A - N shown in FIG. 1 are intended only as examples, and it is understood that cloud computing nodes 10 and cloud computing environment 50 can communicate with any type of computerized device via any type of network and / or network addressable connection (e.g., using a web browser).

[0048] Referring now to FIG. 2, a set of functional abstractions provided by cloud computing environment 50 (FIG. 1) is shown. It should be pre - understood that the components, layers, and functions shown in FIG. 2 are intended only as examples and that aspects of the invention are not limited thereto. As shown, the following layers and corresponding functions are provided.

[0049] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include: mainframe 61; RISC (Reduced Instruction Set Computer) architecture-based server 62; server 63; blade server 64; storage device 65; and network and networking components 66. In some embodiments, the software components include network application server software 67 and database software 68.

[0050] The virtualization layer 70 provides an abstraction layer that can provide the following examples of virtual entities: virtual server 71; virtual storage 72; virtual network 73 including a virtual private network; virtual applications and operating systems 74; and virtual client 75.

[0051] In one example, the management layer 80 may provide the functions described below. Resource provisioning 81 provides for the dynamic procurement of computing resources and other resources utilized to perform tasks within a cloud computing environment. Metering and pricing 82 provides for cost tracking when resources are utilized within a cloud computing environment and for billing or invoicing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides for the verification of identification information for cloud consumers and tasks and for the protection of data and other resources. User portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides for the allocation and management of cloud computing resources such that required service levels are met. Service level agreement (SLA) planning and fulfillment 85 provides for the advance reservation and procurement of cloud computing resources where future requirements are anticipated to conform to the SLA.

[0052] The workload layer 90 provides examples of functions that can be utilized in a cloud computing environment. Examples of workloads and functions that can be provided from this layer include: mapping and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analysis processing 94; transaction processing 95; and data encryption 96.

[0053] Referring now to Figure 3, a schematic diagram of an example of a cloud computing node is shown. The cloud computing node 10 is merely an example of a suitable cloud computing node and is not intended to imply any limitation as to the use or functionality of the aspects of the present invention described herein. In any event, the cloud computing node 10 is capable of implementing and / or performing any of the functions described above.

[0054] The cloud computing node 10 includes a computer system / server 12, which operates in many other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, and / or configurations that may be suitable for use with the computer system / server 12 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, hand-held or laptop devices, multiprocessor systems, microprocessor-based systems, set top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments including any of the above systems or devices, and the like.

[0055] The computer system / server 12 may be described in the general context of computer system-executable instructions, such as program modules, being executed by a computer system. Generally, a program module may include routines, programs, objects, components, logic, data structures, etc., that perform particular tasks or implement particular abstract data types. The computer system / server 12 may be implemented in a distributed cloud computing environment where tasks are performed by remote processing devices linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media including memory storage devices.

[0056] As shown in FIG. 3, the computer system / server 12 within the cloud computing node 10 is illustrated in the form of a general-purpose computing device. The components of the computer system / server 12 may include, but are not limited to, one or more processors or processing units 16, a system memory 28, and a bus 18 that couples various system components including the system memory 28 to the processor 16.

[0057] The bus 18 represents one or more of any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures. By way of example and not limitation, such architectures include Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Enhanced ISA (EISA) bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0058] The computer system / server 12 typically includes various computer system-readable media. Such media can be any available media accessible by the computer system / server 12, including both volatile and non-volatile media, and both removable and non-removable media.

[0059] System memory 28 can include computer system-readable media in the form of volatile memory such as random access memory (RAM) 30 and / or cache memory 32. The computer system / server 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 34 can be provided for reading from and writing to a non-removable non-volatile magnetic medium (not shown, typically referred to as a “hard drive”). Although not shown, a magnetic disk drive for reading from and writing to a removable non-volatile magnetic disk (e.g., a “floppy disk”), and an optical disk drive for reading from or writing to a removable non-volatile optical disk such as a CD-ROM, DVD-ROM, or other optical media can be provided. In such cases, each can be connected to bus 18 by one or more data media interfaces. As further illustrated and described below, memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to implement the functionality of aspects of the present invention.

[0060] A program / utility 40 having a set of program modules (e.g., at least one) 42 may be stored in the memory 28, by way of example and not limitation, as well as an operating system, one or more application programs, other program modules, and program data. Similarly, each of the operating system, one or more application programs, other program modules, and program data or some combination thereof may include an implementation of a network environment. The program modules 42 generally implement the functions and / or methods of the aspects of the present invention described herein.

[0061] The computer system / server 12 may also communicate with one or more external devices 14, such as a keyboard, a pointing device, a display 24, etc., one or more devices that enable a user to interact with the computer system / server 12, and / or any device that enables the computer system / server 12 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may occur via an input / output (I / O) interface 22. Further, the computer system / server 12 can communicate with one or more networks, such as a local area network (LAN), a general wide area network (WAN), and / or a public network (e.g., the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with other components of the computer system / server 12 via a bus 18. Although not shown, it should be understood that other hardware and / or software components may be used in combination with the computer system / server 12. By way of example and not limitation, these include microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archive storage systems, etc.

[0062] Referring now to FIG. 4, a storage system 400 is shown by one embodiment. Note that some of the elements shown in FIG. 4 may be implemented as hardware and / or software according to various embodiments. The storage system 400 may include a storage system manager 412 for communicating with a plurality of media on at least one upper storage tier 402 and at least one lower storage tier 406. The upper storage tier 402 may preferably include one or more random access and / or direct access media 404 such as a hard disk in a hard disk drive (HDD), non-volatile memory (NVM), solid state memory of a solid state drive (SSD), flash memory, SSD arrays, flash memory arrays, etc., and / or other things described herein or known in the art. The lower storage tier 406 may preferably include one or more lower performance storage media 408, which may include sequential access media such as magnetic tape of a tape drive and / or optical media, low access HDDs, low access SSDs, etc., and / or other things described herein or known in the art. One or more additional storage tiers 416 may include any combination of storage memory media as desired by the designer of the system 400. Also, either the upper storage tier 402 and / or the lower storage tier 406 may include some combination of storage devices and / or storage media.

[0063] The storage system manager 412 may communicate with the storage media 404, 408 on the upper storage tier 402 and the lower storage tier 406, and a network 410 such as a storage area network (SAN) as shown in FIG. 4, or any other suitable network type. The storage system manager 412 may also communicate with one or more host systems (not shown) through a host interface 414, which may or may not be part of the storage system manager 412. The storage system manager 412 and / or any other optional components of the storage system 400 may be implemented in hardware and / or software, and a processor (not shown) such as a central processing unit (CPU), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc. may be used to execute commands of a type known in the art. Of course, any configured storage system may be used, as will be apparent to those skilled in the art upon reading this description.

[0064] In more embodiments, storage system 400 may include any number of data storage tiers, each storage tier may include the same or different storage memory media. For example, each data storage tier may include the same type of storage memory media such as HDD, SSD, sequential access media (tape in a tape drive, optical disk in an optical disk drive, etc.), direct access media (CD-ROM, DVD-ROM, etc.), or any combination of media storage types. In one such configuration, upper storage tier 402 may include most of the SSD storage media for storing data in a high-performance storage environment, and the remaining storage tiers including lower storage tier 406 and additional storage tier 416 may include any combination of SSD, HDD, tape drive, etc. for storing data in a lower-performance storage environment. Thus, data that is accessed more frequently, has a higher priority, or needs to be accessed more urgently, etc. may be stored in upper storage tier 402, while on the other hand, data that does not have any of these attributes may be stored in additional storage tier 416 including lower storage tier 406. Of course, those skilled in the art, upon reading this description, may devise many other combinations of storage media types and implement them in different storage schemes according to the embodiments presented herein.

[0065] According to some embodiments, a storage system (such as 400) may include logic configured to receive a request and open a data set, logic configured to determine whether the requested data set is stored in a lower storage tier 406 of a hierarchical data storage system 400 as a plurality of related parts, logic configured to move each related part of the requested data set to an upper storage tier 402 of the hierarchical data storage system 400, and logic configured to assemble the requested data set from the related parts on the upper storage tier 402 of the hierarchical data storage system 400.

[0066] Of course, this logic may be implemented in accordance with various aspects as a method on any device and / or system, or as a computer program product.

[0067] Referring now to FIG. 5, a flowchart of a method 500 is shown in one aspect. Method 500 may be implemented in accordance with the present invention, among other aspects, in any of the environments shown in FIGS. 1-4. Of course, as will be understood by those skilled in the art upon reading this description, method 500 may include more or fewer operations than specifically recited in FIG. 5.

[0068] Each of the steps of method 500 may be performed by any suitable component of the operating environment. For example, in various aspects, method 500 may be performed partially or entirely by one or more servers, computers, or any other device having one or more processors incorporated therein. A processor implemented in hardware and / or software and preferably having at least one hardware component (e.g., a processing circuit, chip, and / or module) may be utilized on any device to perform one or more steps of method 500. Exemplary processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), combinations thereof, or any other suitable computing device known in the art. Additional exemplary components include one or more coprocessors or accelerators, which may or may not be on the same chip, or may or may not be packaged on the same substrate or module as the CPU.

[0069] As shown in FIG. 5, method 500 may begin with operation 502, where an initialization vector (IV) is created using an instance of data and a private key. In one aspect, the instance of data may include data to be encrypted. In another aspect, the instance of data may include a plaintext instance.

[0070] Furthermore, in one aspect, an instance of data may be compressed and the IV may be calculated based on the compressed data instance. In another aspect, the secret key may include information about the data used for encryption that is not published (e.g., held by the entity performing the encryption of the data instance). In yet another aspect, the secret key may also be known as a private key.

[0071] Furthermore, in one aspect, the IV may be all or a subset of a keyed hash. For example, the keyed hash may result from applying a cryptographic hash function to a secret key and plaintext. In another example, the hash function may be applied to the secret key and plaintext in any order (e.g., first to the secret key then to the plaintext, or first to the plaintext then to the secret key). In yet another example, the hash function may map the secret key and plaintext to a fixed-size hash value that constitutes the keyed hash. In one aspect, the hash function may include a Secure Hash Algorithm - 256 (SHA-256) cryptographic hash function such as SHA2-256 or SHA3-256.

[0072] Still further, in one aspect, the IV may include the calculation of a keyed hash message authentication code / hash-based message authentication code (HMAC) involving a hashing key and plaintext. In another aspect, the hashing key may be the same as the secret key used to encrypt the data, or may be associated with that secret key by key derivation (e.g., the hashing key may be derived from the secret key, or the secret key may be derived from the hashing key), and the keyed hash may be calculated by using cryptographic hashing, or by using an encryption algorithm, or by using a combination of hashing and encryption.

[0073] For example, a keyed hash may be determined by encrypting a hash of the plaintext with a hash encryption key. The hash encryption key is one type of hashing key and may thus be the same as the secret key used to encrypt data or may be related to that secret key by key derivation. When using a hash encryption key, the encryption algorithm used may be as simple as the electronic codebook (ECB) mode of the Advanced Encryption Standard (AES) encryption algorithm that uses a 128-bit key (i.e., ECB-AES-128). In another aspect, the hashing key may be generated independently of the secret key, in which case it may be necessary to keep it so that it can be used together with the secret key to perform further encryption with the same key to enable data deduplication. The independently generated hashing key may contribute to the uniqueness of the IV. The independently generated hashing key may also need to be kept when it is necessary to check the IV when comparing the ciphertext created by using the IV with the resulting plaintext during decryption.

[0074] Also, method 500 may proceed to operation 504, where an instance of data is encrypted using the IV, the secret key, and the instance of data. In one aspect, as a result of encrypting the instance of data, an encrypted instance of data (e.g., a ciphertext, etc.) is obtained. In another aspect, encrypting the instance of data may include applying an encryption mode (e.g., an encryption algorithm) to the instance of data using the IV and the secret key.

[0075] Additionally, in one aspect, the encryption mode may include an encryption mode that depends on a nonce such as an IV or CBC, PCBC, CFB, OFB, OCB, CTR, CCM, or GCM. For example, a counter-based encryption mode (e.g., CTR, GCM, etc.) may combine the IV with any counter value to create a first value. That first value can then be incremented to create a count stream of the required length. Next, a block cipher encryption (e.g., Advanced Encryption Standard (AES) encryption, etc.) may be performed on that count stream using a secret key to create an encryption stream. This instance of data may then be combined with the encryption stream (e.g., using an exclusive OR (XOR) operation) to create an encrypted instance of the data.

[0076] Furthermore, in one aspect, the encryption mode may include the Galois / Counter Mode (GCM) encryption mode. For example, the GCM encryption mode may determine the number of blocks within an instance of data. The number of blocks may be combined with the IV to create a first value. Next, a block cipher encryption (e.g., Advanced Encryption Standard (AES) encryption, etc.) may be performed on the first value using a secret key to create a second value. This instance of data may then be combined with the second value (e.g., using an XOR operation) to create an encrypted instance of the data.

[0077] Still further, in one aspect, the encryption mode may include using an IV with the cipher block chaining message authentication code (CCM) encryption mode. In another aspect, the length of the keyed hash may be compared to the required IV length for the encryption mode used to encrypt an instance of data.

[0078] For example, in response to determining that the length of the keyed hash is equal to the minimum IV length required for the encryption mode (in order to sufficiently ignore the possibility of hash collisions), the keyed hash may be used as the IV to perform encryption utilizing the encryption mode. In another example, in response to determining that the length of the keyed hash is greater than the required IV length for the encryption mode, a predetermined subset of the keyed hash (e.g., the first byte thereof for a predetermined length, etc.) may be used to perform encryption utilizing the encryption mode.

[0079] Also, in one aspect, an instance of data may be compressed before being encrypted. Also, in another aspect, an instance of encrypted data may include an instance of ciphertext (e.g., encrypted text that is the result of applying an encryption algorithm to plaintext, etc.).

[0080] Furthermore, method 500 may proceed to operation 506, where the IV and the instance of encrypted data are combined to create a ciphertext string. In one aspect, the IV may be concatenated to the instance of encrypted data to create the ciphertext string. In another aspect, the IV may be added to the instance of encrypted data as metadata. In yet another aspect, the IV and the instance of encrypted data may be combined into a single data chunk that is parsed when the read operation is performed.

[0081] Furthermore, in one aspect, length-preserving compression (LPC) may be implemented using an instance of encrypted data and an IV. For example, to create an instance of encrypted and compressed data, an instance of the data may be compressed before being encrypted. In another example, to create a ciphertext string having the same length as the length of the instance of the original data before compression, a length value indicating the length of the instance of the encrypted and compressed data, the instance of the encrypted and compressed data, and a zero-padding field (a highly compressible and easily detectable pattern such as all zeros) may be concatenated in any predetermined (or self-describing) order.

[0082] Also, in one aspect, LPC may be extended to enable deduplication. For example, to create an instance of encrypted and compressed data, an instance of the data may be compressed before being encrypted. In another example, to create a ciphertext string having the same length as the length of the instance of the original data before compression, an IV (created using the instance of the compressed data and a secret key), a MAC (created using the instance of the compressed data and a secret key), a length value indicating the length of the instance of the encrypted and compressed data, and / or a zero-padding field may be appended to the instance of the encrypted and compressed data.

[0083] Further, method 500 may proceed to operation 508, where the ciphertext string is sent to a storage device that performs deduplication. In one aspect, the storage device may include a database, a distributed storage system, a cloud computing environment, etc. In another example, the ciphertext string may be sent to one or more users, one or more devices, one or more remote storage systems, etc. via one or more networks. Further, data deduplication may be performed within the storage device.

[0084] In this way, a fully deterministic ciphertext string may be created and stored for an instance of data. If a first instance of data is identical to a second instance of data and a first key is identical to a second key, the first ciphertext string created for the first instance of data using the first key may be identical to the second ciphertext string created for the second instance of data using the second key in terms of using the above technique. In this regard, this ciphertext string is fully deterministic. As a result, duplicate ciphertext strings can be identified and removed within the hardware storage, thereby increasing the available storage space within the hardware storage, improving the effective storage capacity and performance of the hardware storage, while maintaining the security of the stored data through robust encryption.

[0085] More specifically, since both the IV and the instance of encrypted data are calculated with a secret key, security vulnerabilities are avoided.

[0086] Referring now to FIG. 6, a flowchart of a method 600 for performing data deduplication is shown in one aspect. The method 600 may be implemented by the present invention in various aspects, particularly in any of the environments shown in FIGS. 1 through 4. Of course, as would be understood by those skilled in the art upon reading this description, more or fewer operations may be included in the method 600 compared to what is specifically described in FIG. 6.

[0087] Each of the steps of method 600 may be performed by any suitable component of the operating environment. For example, in various ways, method 600 may be performed partially or entirely by one or more servers, computers, or some other device having one or more processors internally. It may be implemented in hardware and / or software, and a processor having at least one hardware component, such as a processing circuit, chip, and / or module, may be utilized in any device to perform one or more steps of method 600. Exemplary processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), combinations thereof, or any other suitable computing device known in the art. Additional exemplary components include one or more coprocessors or accelerators, which may or may not be on the same chip as the CPU, may or may not be packaged on the same substrate or module.

[0088] As shown in FIG. 6, method 600 may begin with operation 602, where a plurality of ciphertext strings in data storage are analyzed. In one aspect, the data storage may include a database, a distributed storage system, a cloud computing environment, etc. In another aspect, the analysis may include comparing a single ciphertext string in the data storage with other ciphertext strings in the data storage to determine whether there are any matches (e.g., duplicates) in the data storage. If so, one of the two instances may be replaced by a pointer to the duplicate instance that implements data deduplication.

[0089] In yet another aspect, each of the plurality of ciphertext strings may be created by combining an IV and an instance of encrypted data. In another aspect, an instance of encrypted data may be encrypted using an IV, a secret key, and an instance of data. In yet another aspect, the IV may be created using an instance of data and a secret key.

[0090] Further, in one aspect, a portion of a single ciphertext string may be compared to a portion of other ciphertext strings within a data storage. For example, the ciphertext string may include an IV concatenated to an instance of encrypted data. In another example, the IV may have a predetermined size, be extracted from the ciphertext string, and be compared to other IVs extracted from other stored ciphertext strings.

[0091] Further, method 600 may proceed to operation 604, where one or more redundant ciphertext strings are removed from the data storage based on the analysis. In one aspect, in response to determining that one or more matches / duplicates have been found for a given ciphertext string within the data storage, one or more instances of the given ciphertext string are removed (e.g., deleted, transferred, etc.) from the data storage and replaced with a pointer to the remaining instance(s). In another aspect, duplicate ciphertext strings may be removed from the data storage such that a single instance of the ciphertext string remains in the data storage.

[0092] As a result, deduplication can be performed within the data storage, thereby maximizing the effective amount of storage space available within the data storage, and thereby improving the storage capacity of the data storage.

[0093] Referring now to FIG. 7, a flowchart of a method 700 for performing data decryption is shown in one aspect. Method 700 may be performed by the present invention in various aspects, particularly in any of the environments shown in FIGS. 1 - 4. Of course, as would be understood by one of ordinary skill in the art upon reading this description, method 700 may include more or fewer operations compared to those specifically described in FIG. 7.

[0094] Each of the steps of method 700 may be performed by any suitable component of the operating environment. For example, in various aspects, method 700 may be performed partially or entirely by one or more servers, computers, or some other device having one or more processors internally. A processor (e.g., a processing circuit, chip, and / or module) implemented in hardware and / or software and preferably having at least one hardware component may be utilized in any device to perform one or more steps of method 700. Exemplary processors include, but are not limited to, a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), combinations thereof, or any other suitable computing device known in the art. Additional exemplary components include one or more coprocessors or accelerators that may or may not be on the same chip as the CPU, may or may not be packaged on the same substrate or module.

[0095] As shown in FIG. 7, method 700 may begin with operation 702, where a ciphertext string is received. In one aspect, the ciphertext string may be obtained from a data storage (e.g., a database, a distributed storage system, a cloud computing environment, etc.).

[0096] Furthermore, method 700 may proceed to operation 704, where the ciphertext string is decrypted using the private key. In one aspect, if the ciphertext string includes a MAC, the MAC may be checked to determine if it is valid. In another aspect, if the MAC is invalid, the ciphertext may be decrypted using the private key.

[0097] In another aspect, the ciphertext string may be created by combining an IV and an instance of encrypted data. In another aspect, an instance of encrypted data may be encrypted using an IV, a private key, and an instance of data. In yet another aspect, the IV may be created using an instance of data and a private key.

[0098] Furthermore, in one aspect, decrypting the ciphertext string may yield a first IV and an instance of data. In another aspect, decrypting the ciphertext string may include decrypting the IV within the ciphertext using the private key and the IV.

[0099] Still further, in one aspect, decrypting the ciphertext string may include reversing the steps used by the encryption mode to encrypt the instance of data. In another embodiment, the first two steps in decrypting a sector may include parsing the ciphertext string to detect whether the ciphertext string includes a zero-padded field of sufficient length at a known location (e.g., the first or last field) in the sector. Depending on the predetermined order of the fields, if present, the zero-padding may be detectable before the rest of the sector is parsed. In another aspect, a second IV may be calculated using an instance of data and a private key.

[0100] Also, in one aspect, the first IV may be compared to a second IV to determine whether the ciphertext string has been modified. For example, if the first IV matches the second IV, it may be determined that the ciphertext string has not been modified after it was created. In another example, if the first IV does not match the second IV, it may be determined that the ciphertext string has been corrupted or modified after it was created.

[0101] Resilient Deterministic Encryption

[0102] Length Preserving Compression (LPC) is a concept with promise as a method for enabling a storage system to perform data deduplication on data that has already been persistently encrypted at the host when appropriately extended. However, an overly simplistic approach to LPC implementation can result in a system that is easily broken by known attacks. Accordingly, a deterministic encryption solution is provided that improves two other types of deterministic encryption that are vulnerable to such attacks. This solution can be considered a derivative of convergent encryption.

[0103] Current implementations are not secure against certain attacks. For example, a highly fixed form filled with a limited number of inputs can then create a limited number of IVs (along with their associated ciphertexts) that can all be generated by an attacker and compared to the IVs (or full ciphertexts) created by convergent encryption. If a match exists, the plaintext can be determined.

[0104] Conceptually similar encryption concepts (although different in implementation) have also been referred to as convergent encryption. This implementation requires a simple hash of the plaintext to be used instead as the IV for counter mode-based encryption (e.g., counter (CTR) encryption, Galois / counter mode (GCM) encryption, etc.). This concept is also a form of deterministic encryption that is vulnerable to attacks.

[0105] Accordingly, a method is provided that enables convergent encryption without having the vulnerabilities to the attacks described above. This method uses a keyed hash as the IV. This keyed hash can be a hash calculated over the data and the hashing key, an HMAC calculated based on the data and the hashing key, or an encryption of a simple cryptographic hash of the plaintext data (e.g., using electronic codebook (ECB) encryption, etc.). The hashing key may have a key derivation relationship with the key used to encrypt the host data, or may be generated independently thereof. The keyed hash, or a subset of it, is then used as the IV during encryption. This IV will typically (e.g., in the case of LPC) be transmitted along with the resulting ciphertext.

[0106] By including in the calculation of the keyed hash (used as the IV) a hashing key with high entropy independent of the host data, both the IV and the resulting ciphertext are cryptographically created with a secret key not possessed by the attacker, thus this implementation eliminates the above vulnerabilities. This new implementation is called resilient deterministic encryption (RDE).

[0107] Encryption

[0108] To encrypt the plaintext P using RDE with the secret key Kd, one exemplary embodiment may include creating a keyed hash (e.g., based on Kd), and then using that keyed hash as the initialization vector (IV) for an encryption mode that uses both the IV and Kd.

[0109] In one aspect, Kd may be associated with a specific tenant as part of a secure multi-tenant resolution means. In another aspect, Kd may be associated with a subset of users and / or applications (e.g., human resources, funds, etc.) within the operations of a given tenant.

[0110] The generation of one type of keyed hash Hk is described below.

[0111] Hk = hash(Kd || P)

[0112] Examples of suitable cryptographic "hash" functions can be SHA2-256, SHA3-256, or another standardized cryptographic hash. The generation of the encryption result CX is described below.

[0113] CX = encrypt_data(Kd, Hk, P)

[0114] The "encrypt_data" function may be CTR(key, IV, plaintext) encryption, GCM if a message authentication code (MAC) is to be created and appended, or another cryptographic mode that requires an IV or nonce.

[0115] If the "hash" function output is larger than the IV that the required or selected encryption mode will accept, a subset of the hash may be used. For example, the IV may be set to the first 12 (or 16 if required) bytes of a 32-byte SHA-256 output. CX obtained as a result of the counter mode includes the IV concatenated with the ciphertext of P. When an authenticated encryption mode such as GCM is used, CX also includes a trailing MAC (e.g., GCM-MAC). In either case, CX is longer than the encrypted P (e.g., by at least the IV and possibly also the MAC).

[0116] Storage / Transmission

[0117] After generating the encryption result CX, CX is transmitted or stored. CX is completely deterministic for any given combination of the secret key (Kd) and the plaintext (P) as it is constructed, which allows different ciphertext strings (CX) created from different instances of the same plaintext to be non-overlapping.

[0118] Decryption

[0119] The decryption of the encryption result CX using the initialization vector IV and the secret key Kd for obtaining the plaintext P is described below.

[0120] decrypt_data(Kd,CX) => IV and P

[0121] In one aspect, when an authenticated mode such as GCM is used for encryption, the values of IV and P are simply passed or trusted as valid in response to determining that the integrated MAC is valid.

[0122] In another aspect, the IV may be used to confirm that nothing in the encryption result CX has been modified. More specifically, given the secret key Kd and the plaintext P, the receiver / reader of the encryption result CX can calculate a keyed hash of the secret key Kd and the plaintext P (e.g., hash(Kd||P)) and verify whether it matches the received IV. If the calculated hash matches the IV, the integrity of the encryption result CX can be confirmed.

[0123] In the case where the encryption mode used is not authenticated (e.g., standard CTR or CBC), this integrity check can be calculated based on the plaintext and function as one type of MAC applied before encryption, which is secure when an appropriate encryption mode is used.

[0124] Additional aspect

[0125] In one aspect, the order of hash calculation can be adjusted. For example, the generation of the keyed hash Hk using an alternating order is described below.

[0126] Hk = hash(P||Kd)

[0127] Generally, the secret key Kd and the plaintext P may be put into the hash function in any order.

[0128] In another aspect, the keyed hash may be calculated by encrypting the hash. For example, an additional key Kh may be derived from the secret key Kd. The keyed hash Hk may then be calculated by the following process.

[0129] encrypt_hash(Kh,hash(P))

[0130] Here, "encrypt_hash" may include the Electronic Codebook (ECB) Advanced Encryption Standard (AES).

[0131] For example, it is ECB_AES_128_encrypt(key,hash(P)).

[0132] In another aspect, the additional key Kh may be generated independently of the secret key Kd, and both the secret key Kd and the additional key Kh must be retained to enable decryption of the encryption result CX.

[0133] In one aspect, a method for deterministic encryption of data comprises the steps of creating an encrypted hash of the data (in the form of a keyed hash) and adopting the encrypted hash (or a subset thereof) as an IV for encrypting the data. In another aspect, the hashing key is used to create the IV, and the encryption keys used to encrypt the host data are distinct from each other.

[0134] Furthermore, in one aspect, the lengths of the encrypted IV and hash are adjusted by utilizing the first part of the encrypted hash as the IV. In another aspect, the IV and the data are decrypted, the hash of the decrypted data is determined, and the hash is compared with the IV to ensure that the data has not been modified.

[0135] The present invention may be a system, method, and / or computer program product at any conceivable technical detail level of integration. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions to cause a processor to implement aspects of the present invention.

[0136] The computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer-readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, punch cards, mechanically encoded devices such as a raised structure in a groove having instructions recorded thereon, and any suitable combination of the foregoing. The computer-readable storage medium should not be construed as being a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire.

[0137] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices or to an external computer or external storage device via a network, such as, for example, the Internet, a local area network, a wide area network, and / or a wireless network. The network may comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage on a computer-readable storage medium in each computing / processing device.

[0138] The computer-readable program instructions for carrying out the operations of the present invention may be in any combination of assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, where the one or more programming languages include object-oriented programming languages such as Smalltalk® and C++, and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partly on the user's computer as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, for example, an electronic circuit including a programmable logic circuit, a field programmable gate array (FPGA), a programmable logic array (PLA), a hardware accelerator, or a coprocessor may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit to perform aspects of the present invention.

[0139] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0140] These computer-readable program instructions may be provided to a computer processor or other programmable data processing apparatus to produce a machine, such that the instructions executed via the computer processor or other programmable data processing apparatus create means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable storage medium containing the instructions comprises a manufacture including instructions for implementing the aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0141] Alternatively, the computer-readable program instructions may be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0142] Flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various aspects of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions that include one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur in a different order than that noted in the drawings. For example, two blocks shown in succession may, in fact, be accomplished as substantially one step, may be executed at the same time, in a substantially simultaneous, partially or fully temporally overlapping manner, or the blocks may be executed in the reverse order depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, can be implemented by a dedicated hardware-based system that performs the specified functions or operations or by a combination of dedicated hardware and computer instructions.

[0143] Furthermore, systems in various aspects may include a processor and logic integrated with and / or executable by the processor, the logic being configured to perform one or more of the processing steps described herein. By integrated, it means that the logic is embedded as hardware logic such as an application specific integrated circuit (ASIC), field programmable gate array (FPGA), etc. in the processor. Executable by the processor means that the logic is either hardware logic, software logic such as firmware, a part of an operating system, a part of an application program, etc., or some combination of hardware and software logic that is accessible by the processor and configured to cause the processor to perform some function when executed by the processor. As is known in the art, software logic can be stored in local and / or remote memory of any memory type. Any processor known in the art such as a software processor module, and / or a hardware processor such as an ASIC, FPGA, central processing unit (CPU), integrated circuit (IC), graphics processing unit (GPU), etc. can also be used. Additional exemplary processors include one or more coprocessors or accelerators that may or may not be on the same chip as the CPU, may or may not be packaged on the same substrate or module.

[0144] It will be apparent that the various features of the systems and / or methods described above may be combined in any manner, thereby creating multiple combinations from the descriptions shown above.

[0145] Furthermore, it will be understood that aspects of the present invention may be provided in the form of services deployed on behalf of customers to provide services on demand.

[0146] Although the description of various aspects of the present invention has been presented for purposes of illustration, it is not intended to be exhaustive or to limit the invention to the disclosed aspects. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the described aspects. The terms used herein have been selected to best explain the principles of the aspects, the practical application, or the technical improvements found in the marketplace, or to enable others of ordinary skill in the art to understand the aspects disclosed herein 。 [Item 1] Creating an initialization vector using a plaintext instance and a private key; Encrypting the plaintext instance using the initialization vector, the private key, and the plaintext instance; Combining the initialization vector and the encrypted plaintext instance to create a ciphertext string; and Sending the ciphertext string to a storage device that performs deduplication A computer-implemented method comprising. [Item 2] The computer-implemented method according to Item 1, wherein the initialization vector is added as metadata to the encrypted plaintext instance. [Item 3] The computer-implemented method according to Item 1, wherein the initialization vector and the encrypted plaintext instance are combined into a single data chunk that is parsed when performing a read operation. [Item 4] The computer-implemented method according to Item 1, wherein the plaintext instance is compressed and the initialization vector is created based on the compressed plaintext instance. [Item 5] The computer-implemented method according to Item 1, wherein the initialization vector includes a keyed hash resulting from applying a hash function across the private key and the plaintext instance in a known order. [Item 6] The computer-implemented method according to Item 1, wherein a key for hashing is associated with the private key by key derivation and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing. [Item 7] The computer-implemented method according to Item 1, wherein a key for hashing is generated independently of the private key and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing. [Item 8] The computer-implemented method according to Item 1, wherein the step of encrypting the plaintext instance includes applying an encryption mode to the plaintext instance using the initialization vector and the private key. [Item 9] The length of the initialization vector is compared to the required initialization vector length for the encryption mode used to encrypt the plaintext instance, In response to determining that the length of the initialization vector is less than or equal to the required initialization vector length for the encryption mode, the initialization vector is used to perform encryption utilizing the encryption mode. In response to determining that the length of the initialization vector is greater than the required initialization vector length for the encryption mode, a subset of the initialization vector is used to perform encryption utilizing the encryption mode. The computer-implemented method according to item 1. [Item 10] The computer-implemented method according to item 1, wherein the instance of the plaintext is compressed before being encrypted. [Item 11] The computer-implemented method according to item 1, wherein, to create the ciphertext string, the initialization vector is concatenated to an instance of the encrypted plaintext. [Item 12] A computer-readable storage medium having program instructions embodied thereon, the computer-readable storage medium itself not being a transient signal, the program instructions causing a processor to, create an initialization vector using an instance of plaintext and a secret key by the processor; encrypt the instance of the plaintext using the initialization vector, the secret key, and the instance of the plaintext by the processor; combine the initialization vector and the instance of the encrypted plaintext to create a ciphertext string by the processor; and send the ciphertext string to a storage device that performs deduplication by the processor A computer program product for implementing resilient deterministic encryption, executable by the processor to cause the processor to perform a method having these steps. [Item 13] The computer program product according to item 12, wherein the initialization vector is added as metadata to the instance of the encrypted plaintext. [Item 14] The computer program product according to item 12, wherein the initialization vector and the instance of the encrypted plaintext are combined into a single data chunk that is parsed upon performing a read operation. [Item 15] The computer program product according to item 12, wherein the instance of the plaintext is compressed and the initialization vector is created based on the compressed instance of the plaintext. [Item 16] The computer program product according to item 12, wherein the initialization vector includes an authenticated hash resulting from applying a hash function first to the secret key and then to an instance of the plaintext. [Item 17] The computer program product according to item 12, wherein the initialization vector includes an authenticated hash resulting from applying a hash function over the secret key and the instance of the plaintext in a known order. [Item 18] The computer program product according to item 12, wherein a key for hashing is associated with the secret key by key derivation, and the initialization vector includes an authenticated hash calculated using an encryption algorithm and the key for hashing. [Item 19] The computer program product according to item 12, wherein a key for hashing is generated independently of the secret key, and the initialization vector includes an authenticated hash calculated using an encryption algorithm and the key for hashing. [Item 20] The computer program product according to item 12, wherein the procedure for encrypting an instance of the plaintext has a procedure of applying an encryption mode to the instance of the plaintext using the initialization vector and the secret key. [Item 21] The length of the initialization vector is compared with the required initialization vector length for the encryption mode used to encrypt the instance of the plaintext, in response to determining that the length of the initialization vector is less than or equal to the required initialization vector length for the encryption mode, the initialization vector is used to perform encryption using the encryption mode, in response to determining that the length of the initialization vector is greater than the required initialization vector length for the encryption mode, a subset of the initialization vector is used to perform encryption using the encryption mode The computer program product according to item 12. [Item 22] The computer program product according to item 12, wherein the instance of the plaintext is compressed before being encrypted. [Item 23] The computer program product according to item 12, wherein the initialization vector is concatenated to the encrypted instance of the plaintext to create the ciphertext string. [Item 24] A processor; and Logic integrated with the processor and executable by the processor, or integrated with and executable by the processor, where the logic is creating an initialization vector using an instance of plaintext and a private key; encrypting the instance of plaintext using the initialization vector, the private key, and the instance of plaintext; combining the initialization vector and the encrypted instance of plaintext to create a ciphertext string; sending the ciphertext string to a storage device that performs deduplication configured to A system comprising. [Item 25] analyzing a plurality of ciphertext strings in data storage, where each of the plurality of ciphertext strings is created by combining an initialization vector and an instance of encrypted plaintext, the instance of encrypted plaintext is encrypted using the initialization vector, a private key, and an instance of plaintext, the initialization vector is created using the instance of plaintext and the private key; and removing one or more redundant ciphertext strings from the data storage based on the analyzing step A computer-implemented method comprising.

Claims

1. creating an initialization vector using a plaintext instance and a secret key; encrypting the plaintext instance using the initialization vector, the secret key, and the plaintext instance; combining the initialization vector and the encrypted plaintext instance to create a ciphertext string; and comparing the ciphertext strings in a data storage and, if a matching or duplicate ciphertext string is found, sending the ciphertext string to a storage device that performs deduplication comprising a computer-implemented method, wherein the initialization vector includes an authenticated hash resulting from applying a hash function over the secret key and the plaintext instance in a predefined order.

2. creating an initialization vector using a plaintext instance and a secret key; encrypting the plaintext instance using the initialization vector, the secret key, and the plaintext instance; combining the initialization vector and the encrypted plaintext instance to create a ciphertext string; and comparing the ciphertext strings in a data storage and, if a matching or duplicate ciphertext string is found, sending the ciphertext string to a storage device that performs deduplication comprising a computer-implemented method, wherein a key for hashing is associated with the secret key by key derivation, and the initialization vector includes an authenticated hash calculated using an encryption algorithm and the key for hashing.

3. creating an initialization vector using a plaintext instance and a secret key; encrypting the plaintext instance using the initialization vector, the secret key, and the plaintext instance; combining the initialization vector and the encrypted plaintext instance to create a ciphertext string; and comparing the ciphertext strings in a data storage and, if a matching or duplicate ciphertext string is found, sending the ciphertext string to a storage device that performs deduplication comprising A computer-implemented method in which a key for hashing is generated independently of the secret key, and the initialization vector includes an encrypted hash calculated using an encryption algorithm and the key for hashing.

4. The computer-implemented method according to any one of claims 1 to 3, wherein the initialization vector is added as metadata to an instance of the encrypted plaintext.

5. The computer-implemented method according to any one of claims 1 to 4, wherein the initialization vector and the instance of the encrypted plaintext are combined into a single data chunk that is parsed when performing a read operation.

6. The computer-implemented method according to any one of claims 1 to 5, wherein the instance of the plaintext is compressed and the initialization vector is created based on the compressed instance of the plaintext.

7. The computer-implemented method according to any one of claims 1 to 6, wherein the step of encrypting the instance of the plaintext includes applying an encryption mode to the instance of the plaintext using the initialization vector and the secret key.

8. The length of the initialization vector is compared to the required initialization vector length for the encryption mode used to encrypt the instance of the plaintext, in response to determining that the length of the initialization vector is less than or equal to the required initialization vector length for the encryption mode, the initialization vector is used to perform encryption using the encryption mode, in response to determining that the length of the initialization vector is greater than the required initialization vector length for the encryption mode, a subset of the initialization vector is used to perform encryption using the encryption mode The computer-implemented method according to any one of claims 1 to 7.

9. A step of creating an initialization vector using an instance of plaintext and a secret key; A step of encrypting the instance of the plaintext using the initialization vector, the secret key, and the instance of the plaintext; A step of combining the initialization vector and the instance of the encrypted plaintext to create a ciphertext string; and Comparing ciphertext strings within a data storage and transmitting the ciphertext strings to a storage device that performs deduplication when a matching or duplicate ciphertext string is found comprising the length of the initialization vector is compared to the required initialization vector length for the encryption mode used to encrypt the instance of the plaintext, in response to determining that the length of the initialization vector is less than or equal to the required initialization vector length for the encryption mode, the initialization vector is used to perform encryption utilizing the encryption mode, in response to determining that the length of the initialization vector is greater than the required initialization vector length for the encryption mode, a subset of the initialization vector is used to perform encryption utilizing the encryption mode A computer-implemented method. **Claim 10** The computer-implemented method according to any one of claims 1 to 9, wherein the instance of the plaintext is compressed before being encrypted. **Claim 11** The computer-implemented method according to any one of claims 1 to 10, wherein the initialization vector is concatenated to the encrypted instance of the plaintext to create the ciphertext string. **Claim 12** A program for implementing resilient deterministic encryption, the program causing a processor to create an initialization vector using an instance of a plaintext and a secret key; encrypt the instance of the plaintext using the initialization vector, the secret key, and the instance of the plaintext; combine the initialization vector and the encrypted instance of the plaintext to create a ciphertext string; and compare ciphertext strings within a data storage and transmit the ciphertext strings to a storage device that performs deduplication when a matching or duplicate ciphertext string is found A program for causing execution, wherein the initialization vector includes a keyed hash resulting from applying a hash function over the secret key and the instance of the plaintext in a predefined order. **Claim 13** A program for implementing resilient deterministic encryption, the program causing a processor to create an initialization vector using an instance of a plaintext and a secret key; A procedure for encrypting an instance of the plaintext by using the initialization vector, the secret key, and the instance of the plaintext; A procedure for creating a ciphertext string by combining the initialization vector and the instance of the encrypted plaintext; and A procedure for comparing ciphertext strings in a data storage, and transmitting the ciphertext string to a storage device that performs deduplication when a matching or duplicate ciphertext string is found A program for causing the execution of: A program in which a key for hashing is associated with the secret key by key derivation, and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing. **Claim 14**: A program for implementing resilient deterministic encryption, causing a processor to A procedure for creating an initialization vector by using an instance of the plaintext and a secret key; A procedure for encrypting an instance of the plaintext by using the initialization vector, the secret key, and the instance of the plaintext; A procedure for creating a ciphertext string by combining the initialization vector and the instance of the encrypted plaintext; and A procedure for comparing ciphertext strings in a data storage, and transmitting the ciphertext string to a storage device that performs deduplication when a matching or duplicate ciphertext string is found A program for causing the execution of: A program in which a key for hashing is generated independently of the secret key, and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing. **Claim 15**: A program for implementing resilient deterministic encryption, causing a processor to A procedure for creating an initialization vector by using an instance of the plaintext and a secret key; A procedure for encrypting an instance of the plaintext by using the initialization vector, the secret key, and the instance of the plaintext; A procedure for creating a ciphertext string by combining the initialization vector and the instance of the encrypted plaintext; and A procedure for comparing ciphertext strings in a data storage, and transmitting the ciphertext string to a storage device that performs deduplication when a matching or duplicate ciphertext string is found A program for causing the execution of: The length of the initialization vector is compared to the required initialization vector length for the encryption mode used to encrypt the instance of the plaintext, in response to determining that the length of the initialization vector is less than or equal to the required initialization vector length for the encryption mode, the initialization vector is used to perform encryption utilizing the encryption mode, in response to determining that the length of the initialization vector is greater than the required initialization vector length for the encryption mode, a subset of the initialization vector is used to perform encryption utilizing the encryption mode, a program. **Claim 16** A processor; and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor, where the logic creates an initialization vector using an instance of plaintext and a secret key; encrypts the instance of the plaintext using the initialization vector, the secret key, and the instance of the plaintext; combines the initialization vector and the encrypted instance of the plaintext to create a ciphertext string; compares ciphertext strings in a data storage and, if a matching or duplicate ciphertext string is found, transmits the ciphertext string to a storage device that performs deduplication is configured to A system comprising wherein the initialization vector includes a keyed hash resulting from applying a hash function over the secret key and the instance of the plaintext in a predefined order. **Claim 17** A processor; and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor, where the logic creates an initialization vector using an instance of plaintext and a secret key; encrypts the instance of the plaintext using the initialization vector, the secret key, and the instance of the plaintext; combines the initialization vector and the encrypted instance of the plaintext to create a ciphertext string; Compare the ciphertext strings in the data storage and, if a matching or duplicate ciphertext string is found, send the ciphertext string to a storage device that performs deduplication configured as A system comprising A system in which a key for hashing is associated with the secret key by key derivation, and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing

18. A processor; and Logic integrated with the processor, executable by the processor, or integrated with and executable by the processor, where the logic Create an initialization vector using an instance of plaintext and a secret key; Encrypt the instance of the plaintext using the initialization vector, the secret key, and the instance of the plaintext; Combine the initialization vector and the encrypted instance of the plaintext to create a ciphertext string; Compare the ciphertext strings in the data storage and, if a matching or duplicate ciphertext string is found, send the ciphertext string to a storage device that performs deduplication configured as A system comprising A system in which a key for hashing is generated independently of the secret key, and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing

19. A processor; and Logic integrated with the processor, executable by the processor, or integrated with and executable by the processor, where the logic Create an initialization vector using an instance of plaintext and a secret key; Encrypt the instance of the plaintext using the initialization vector, the secret key, and the instance of the plaintext; Combine the initialization vector and the encrypted instance of the plaintext to create a ciphertext string; Compare the ciphertext strings in the data storage and, if a matching or duplicate ciphertext string is found, send the ciphertext string to a storage device that performs deduplication configured as A system comprising The length of the initialization vector is compared with the required initialization vector length for the encryption mode used to encrypt the instance of the plaintext, in response to determining that the length of the initialization vector is less than or equal to the required initialization vector length for the encryption mode, the initialization vector is used to perform encryption utilizing the encryption mode, in response to determining that the length of the initialization vector is greater than the required initialization vector length for the encryption mode, a subset of the initialization vector is used to perform encryption utilizing the encryption mode, a system. **Claim 20** Analyzing a plurality of ciphertext strings in a data storage, where each of the plurality of ciphertext strings is created by combining an initialization vector and an instance of an encrypted plaintext, the instance of the encrypted plaintext is encrypted using the initialization vector, a secret key, and an instance of the plaintext, the initialization vector is created using the instance of the plaintext and the secret key; and removing one or more redundant ciphertext strings from the data storage based on the analyzing step comprising, the initialization vector includes a keyed hash resulting from applying a hash function over the secret key and the instance of the plaintext in a predefined order, a computer-implemented method. **Claim 21** Analyzing a plurality of ciphertext strings in a data storage, where each of the plurality of ciphertext strings is created by combining an initialization vector and an instance of an encrypted plaintext, the instance of the encrypted plaintext is encrypted using the initialization vector, a secret key, and an instance of the plaintext, the initialization vector is created using the instance of the plaintext and the secret key; and removing one or more redundant ciphertext strings from the data storage based on the analyzing step comprising, a key for hashing is associated with the secret key by key derivation, and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing, a computer-implemented method. Step 22 of analyzing a plurality of ciphertext strings in a data storage, where each of the plurality of ciphertext strings is created by combining an initialization vector and an instance of encrypted plaintext, the instance of the encrypted plaintext is encrypted using the initialization vector, a secret key, and an instance of plaintext, the initialization vector is created using the instance of plaintext and the secret key; and removing one or more redundant ciphertext strings from the data storage based on the analyzing step comprising A computer-implemented method, wherein a key for hashing is generated independently of the secret key, and the initialization vector includes a keyed hash calculated using an encryption algorithm and the key for hashing. Step 23 of analyzing a plurality of ciphertext strings in a data storage, where each of the plurality of ciphertext strings is created by combining an initialization vector and an instance of encrypted plaintext, the instance of the encrypted plaintext is encrypted using the initialization vector, a secret key, and an instance of plaintext, the initialization vector is created using the instance of plaintext and the secret key; and removing one or more redundant ciphertext strings from the data storage based on the analyzing step comprising the length of the initialization vector is compared to the required initialization vector length for the encryption mode used to encrypt the instance of plaintext, in response to determining that the length of the initialization vector is less than or equal to the required initialization vector length for the encryption mode, the initialization vector is used to perform encryption using the encryption mode, in response to determining that the length of the initialization vector is greater than the required initialization vector length for the encryption mode, a subset of the initialization vector is used to perform encryption using the encryption mode.

Citation Information

Patent Citations

  • Information processing apparatus, tamper resistant device, encryption processing method and computer program

    JP2007158967A

  • Method and device for encryption chained mode

    JP2010140026A

  • Ciphering device and deciphering device for stream cipher, ciphering method and deciphering method for stream cipher, and program

    JP2011130340A

  • Application-generated encryption keys for data deduplication

    JP2020521369A

  • Secure initialization vector generation

    US20180176014A1