Dual-Layer Encryption for Secure Crypto-Erasing of Deduplicated Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage systems face challenges in securely erasing deduplicated data, as existing crypto-erase techniques do not effectively manage the encryption keys for both data chunks and storage objects, leading to potential security vulnerabilities and inefficiencies in storage space utilization.

Innovation Solution

The implementation of a dual encryption module system, where each data chunk is encrypted with a unique first encryption key and each storage object is encrypted with a unique second encryption key, with the second key capable of encrypting the first key, allowing for secure crypto-erasure by deleting the storage object encryption key, thereby rendering the data chunks undecipherable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data deduplication is implemented to increase storage efficiency, then storage space utilization is improved, but data security is worsened because existing crypto-erase techniques cannot effectively manage encryption keys for both data chunks and storage objects

Engineering Contradiction:
Improvestorage space utilizationVSAvoiddata security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the encryption key management into two distinct layers: data chunk encryption keys (unique to each chunk) and storage object encryption keys (unique to each storage object). This segmentation allows independent control and management of encryption keys at different hierarchical levels, resolving the contradiction by enabling both deduplication efficiency and security through structured key organization

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested encryption structure where storage object encryption keys encrypt data chunk encryption keys. This nested approach allows the system to maintain multiple layers of encryption simultaneously, enabling deduplication at the storage object level while preserving security at the data chunk level through hierarchical key management

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If conventional crypto-erase techniques are used to erase deduplicated data, then data security is improved, but storage efficiency is worsened because duplicate data cannot be effectively managed with existing key management approaches

Engineering Contradiction:
Improvedata securityVSAvoidstorage efficiency
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

By segmenting encryption keys into chunk-level and object-level keys, the patent enables selective crypto-erasure at the storage object level without affecting other storage objects. This segmentation allows efficient storage utilization through deduplication while maintaining security through targeted key management and erasure capabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The nested encryption structure allows storage object encryption keys to control access to multiple data chunk encryption keys. This nesting enables efficient crypto-erasure by deleting a single storage object key, which automatically renders all associated data chunks undecipherable, thereby improving both security and storage efficiency

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If unique encryption keys are assigned to each data chunk to enhance security, then data security is improved, but key management complexity is worsened

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces key management complexity by nesting storage object encryption keys that encrypt multiple data chunk encryption keys. This hierarchical structure allows the system to maintain unique encryption for each data chunk while simplifying management through fewer top-level keys that can control multiple chunks, thereby resolving the contradiction between security and management complexity

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11386048B2Apparatus, systems, and methods for crypto-erasing deduplicated data
Publication Date: 2022.07.12 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11386048B2 patent drawing
  • US11386048B2 patent drawing
  • US11386048B2 patent drawing

AI summary

Methods that can crypto-erase deduplicated data are disclosed herein. One method includes encrypting, by a processor, each data chunk on a storage device with a unique first encryption key that is different from each other first encryption key and encrypting each storage object on the storage device with a unique second encryption key that is different from each first encryption key and each other second encryption key in which each second encryption key encrypts a first encryption key for a data chunk. Apparatus, systems, and computer program products that can include, perform, and/or implement the methods are also disclosed herein.