Deduplication and Encryption Grouping for Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data management systems face challenges in efficiently managing increasing data storage requirements while ensuring data security, as conventional deduplication and encryption methods either compromise data integrity or security due to key leakage or inefficient data identification.
Innovation Solution
Implementing deduplication and encryption at the source by creating unique deduplication groups with specific encryption methods and keys, using symmetric or public key encryption, and assigning unique signature computation and block computation methods to each group for enhanced security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If conventional deduplication is performed before encryption, then data storage space is reduced, but data security is compromised due to key leakage risks
Solution Approach 1:
The system segments data into multiple deduplication groups, where each group is encrypted with a unique encryption key. This segmentation approach allows deduplication to be performed within groups while maintaining security isolation between groups, thus reducing storage space without compromising overall data security.
Solution Approach 2:
Different encryption keys are assigned to different deduplication groups, creating local quality variations in security parameters. This allows the system to optimize storage efficiency within each group while maintaining differentiated security levels, preventing key leakage from affecting the entire dataset.
2Productivity
If convergent encryption is used to identify common data, then data identification efficiency is improved, but data security is compromised as common data can be identified without decryption
Solution Approach 1:
The system changes the encryption parameter (encryption key) based on the deduplication group to which data belongs. By using group-specific encryption keys rather than a universal key, the system maintains the ability to efficiently identify common data within groups while preventing unauthorized identification of encrypted data across different groups.
3Reliability
If key-based encryption is used for data security, then data protection is improved, but system security is compromised if the key is leaked
Solution Approach 1:
The system divides data into multiple deduplication groups, each protected by a separate encryption key. This segmentation means that if one key is leaked, only the corresponding deduplication group is compromised, while other groups remain secure, thereby limiting the impact of key leakage.
Solution Approach 2:
Each deduplication group is assigned unique encryption parameters (key and signature computation method), creating localized security zones. This ensures that security compromise in one area does not propagate to other areas, reducing the overall harmful impact of potential key leakage.
4Reliability
If data is encrypted before storage, then data security is maintained, but storage efficiency is reduced due to inability to deduplicate encrypted data
Solution Approach 1:
The system performs deduplication identification before final encryption by using group-specific parameters to identify common data patterns. This preliminary identification allows the system to mark deduplicated data without fully encrypting it, enabling both security and storage efficiency.
Solution Approach 2:
The system uses differentiated encryption parameters (keys and signature methods) for different deduplication groups, which allows efficient identification and deduplication of common data within groups while maintaining security through group-specific encryption.
Data Source
AI summary
The embodiments herein relate to data management and, more particularly, to global deduplication and encryption of data in data management systems. The user equipments (UE) are grouped under certain deduplication groups based on certain parameters such as rate of data exchange, frequency of data exchange, social closeness, work closeness, similarity of data and interests and so on, between those UEs. Further, specific deduplication and encryption parameters such as encryption method, encryption key, signature computation method, block computation method and so on are assigned to each group. Further, deduplication and encryption of data in each group is performed using the deduplication and encryption modes and parameters assigned to each group. The deduplication and encryption of data is performed in at least one of the UEs and/or a server. Further, the parameters used for deduplication and encryption are stored in specific databases and are encrypted for better security.


