Deduplication and Encryption Grouping for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data management systems face challenges in efficiently managing increasing data storage requirements while ensuring data security, as conventional deduplication and encryption methods either compromise data integrity or security due to key leakage or inefficient data identification.

Innovation Solution

Implementing deduplication and encryption at the source by creating unique deduplication groups with specific encryption methods and keys, using symmetric or public key encryption, and assigning unique signature computation and block computation methods to each group for enhanced security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If conventional deduplication is performed before encryption, then data storage space is reduced, but data security is compromised due to key leakage risks

Engineering Contradiction:
Improvedata storage spaceVSAvoiddata security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system segments data into multiple deduplication groups, where each group is encrypted with a unique encryption key. This segmentation approach allows deduplication to be performed within groups while maintaining security isolation between groups, thus reducing storage space without compromising overall data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different encryption keys are assigned to different deduplication groups, creating local quality variations in security parameters. This allows the system to optimize storage efficiency within each group while maintaining differentiated security levels, preventing key leakage from affecting the entire dataset.

Inventive Principle:
Principle #3Local quality

2Productivity

If convergent encryption is used to identify common data, then data identification efficiency is improved, but data security is compromised as common data can be identified without decryption

Engineering Contradiction:
Improvedata identification efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system changes the encryption parameter (encryption key) based on the deduplication group to which data belongs. By using group-specific encryption keys rather than a universal key, the system maintains the ability to efficiently identify common data within groups while preventing unauthorized identification of encrypted data across different groups.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If key-based encryption is used for data security, then data protection is improved, but system security is compromised if the key is leaked

Engineering Contradiction:
Improvedata protectionVSAvoidkey leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides data into multiple deduplication groups, each protected by a separate encryption key. This segmentation means that if one key is leaked, only the corresponding deduplication group is compromised, while other groups remain secure, thereby limiting the impact of key leakage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each deduplication group is assigned unique encryption parameters (key and signature computation method), creating localized security zones. This ensures that security compromise in one area does not propagate to other areas, reducing the overall harmful impact of potential key leakage.

Inventive Principle:
Principle #3Local quality

4Reliability

If data is encrypted before storage, then data security is maintained, but storage efficiency is reduced due to inability to deduplicate encrypted data

Engineering Contradiction:
Improvedata securityVSAvoidstorage efficiency
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs deduplication identification before final encryption by using group-specific parameters to identify common data patterns. This preliminary identification allows the system to mark deduplicated data without fully encrypting it, enabling both security and storage efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses differentiated encryption parameters (keys and signature methods) for different deduplication groups, which allows efficient identification and deduplication of common data within groups while maintaining security through group-specific encryption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9086819B2System and method for combining deduplication and encryption of data
Publication Date: 2015.07.21 VAULTIZE TECH
  • US9086819B2 patent drawing
  • US9086819B2 patent drawing
  • US9086819B2 patent drawing

AI summary

The embodiments herein relate to data management and, more particularly, to global deduplication and encryption of data in data management systems. The user equipments (UE) are grouped under certain deduplication groups based on certain parameters such as rate of data exchange, frequency of data exchange, social closeness, work closeness, similarity of data and interests and so on, between those UEs. Further, specific deduplication and encryption parameters such as encryption method, encryption key, signature computation method, block computation method and so on are assigned to each group. Further, deduplication and encryption of data in each group is performed using the deduplication and encryption modes and parameters assigned to each group. The deduplication and encryption of data is performed in at least one of the UEs and/or a server. Further, the parameters used for deduplication and encryption are stored in specific databases and are encrypted for better security.