Dual-Layer Encryption for Secure Crypto-Erasing of Deduplicated Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional storage systems face challenges in securely erasing deduplicated data, as existing crypto-erase techniques do not effectively manage the encryption keys for both data chunks and storage objects, leading to potential security vulnerabilities and inefficiencies in storage space utilization.
Innovation Solution
The implementation of a dual encryption module system, where each data chunk is encrypted with a unique first encryption key and each storage object is encrypted with a unique second encryption key, with the second key capable of encrypting the first key, allowing for secure crypto-erasure by deleting the storage object encryption key, thereby rendering the data chunks undecipherable.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data deduplication is implemented to increase storage efficiency, then storage space utilization is improved, but data security is worsened because existing crypto-erase techniques cannot effectively manage encryption keys for both data chunks and storage objects
Solution Approach 1:
The patent segments the encryption key management into two distinct layers: data chunk encryption keys (unique to each chunk) and storage object encryption keys (unique to each storage object). This segmentation allows independent control and management of encryption keys at different hierarchical levels, resolving the contradiction by enabling both deduplication efficiency and security through structured key organization
Solution Approach 2:
The patent implements a nested encryption structure where storage object encryption keys encrypt data chunk encryption keys. This nested approach allows the system to maintain multiple layers of encryption simultaneously, enabling deduplication at the storage object level while preserving security at the data chunk level through hierarchical key management
2Reliability
If conventional crypto-erase techniques are used to erase deduplicated data, then data security is improved, but storage efficiency is worsened because duplicate data cannot be effectively managed with existing key management approaches
Solution Approach 1:
By segmenting encryption keys into chunk-level and object-level keys, the patent enables selective crypto-erasure at the storage object level without affecting other storage objects. This segmentation allows efficient storage utilization through deduplication while maintaining security through targeted key management and erasure capabilities
Solution Approach 2:
The nested encryption structure allows storage object encryption keys to control access to multiple data chunk encryption keys. This nesting enables efficient crypto-erasure by deleting a single storage object key, which automatically renders all associated data chunks undecipherable, thereby improving both security and storage efficiency
3Reliability
If unique encryption keys are assigned to each data chunk to enhance security, then data security is improved, but key management complexity is worsened
Solution Approach 1:
The patent reduces key management complexity by nesting storage object encryption keys that encrypt multiple data chunk encryption keys. This hierarchical structure allows the system to maintain unique encryption for each data chunk while simplifying management through fewer top-level keys that can control multiple chunks, thereby resolving the contradiction between security and management complexity
Data Source
AI summary
Methods that can crypto-erase deduplicated data are disclosed herein. One method includes encrypting, by a processor, each data chunk on a storage device with a unique first encryption key that is different from each other first encryption key and encrypting each storage object on the storage device with a unique second encryption key that is different from each first encryption key and each other second encryption key in which each second encryption key encrypts a first encryption key for a data chunk. Apparatus, systems, and computer program products that can include, perform, and/or implement the methods are also disclosed herein.


