Intermediate Device for Data Deduplication Confidentiality
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data deduplication methods in network storage systems face inefficiencies due to reduced inter-user deduplication efficiency and compromised confidentiality, particularly with convergent encryption, where malicious attacks can occur and network traffic observation reveals stored data, and existing solutions fail to optimize bandwidth and storage savings across users.
Innovation Solution
An intermediate device manages both intra-user and inter-user deduplication, creating and verifying data identifiers securely, ensuring only authorized access and transparent inter-user deduplication, with the intermediate device located strategically to maintain data confidentiality and optimize bandwidth and storage usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If convergent encryption is used to enable inter-user deduplication, then storage space is optimized, but data confidentiality is compromised and the system becomes vulnerable to malicious attacks
Solution Approach 1:
The patent introduces a trusted intermediate device that acts as a mediator between clients and the storage server. This intermediary performs deduplication operations on encrypted data without having the ability to decrypt it, using cryptographic techniques such as commutative encryption or homomorphic hashing. The intermediate device verifies data uniqueness and manages deduplication metadata while preserving client data confidentiality, thus resolving the contradiction between enabling inter-user deduplication and maintaining security.
2Reliability
If per-user encryption is used to ensure data confidentiality, then security is improved, but inter-user deduplication efficiency is reduced
Solution Approach 1:
The patent implements a universal deduplication mechanism that works across multiple users while maintaining per-user encryption. The system uses user-independent cryptographic operations (such as hashing or commutative encryption) that can be applied universally to encrypted data from different users, enabling the storage server to perform deduplication without needing to decrypt or know individual user encryption keys. This allows the same encryption scheme to serve both confidentiality and deduplication purposes simultaneously.
3Loss of energy
If deduplication is performed on the source side to save bandwidth, then transmission efficiency is improved, but storage optimization across users is reduced
Solution Approach 1:
The patent divides the deduplication function into two segments: source-side deduplication for immediate bandwidth savings, and server-side deduplication for long-term storage optimization. The source device performs initial deduplication to reduce transmission volume, while the storage server performs additional deduplication on received data to optimize overall storage utilization across all users. This segmented approach allows both bandwidth and storage efficiency to be improved without compromising either objective.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
The invention relates to a method for storing data in a computer system (SYS) including a plurality of first devices (PC1, PC2) storing data belonging to respective users (U1, U2), a second device (SS) capable of managing a backup of data from first devices, said backup including a step of deduplicating inter-user data, characterised in that an intermediate device (I) is inserted between the first devices (PC1, PC2) and the second device (SS), such as to initially perform an intra-user deduplication of the data to be backed up from first devices, and then to manage the inter-user deduplication in cooperation with the second device (SS).