Intermediate Device for Data Deduplication Confidentiality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data deduplication methods in network storage systems face inefficiencies due to reduced inter-user deduplication efficiency and compromised confidentiality, particularly with convergent encryption, where malicious attacks can occur and network traffic observation reveals stored data, and existing solutions fail to optimize bandwidth and storage savings across users.

Innovation Solution

An intermediate device manages both intra-user and inter-user deduplication, creating and verifying data identifiers securely, ensuring only authorized access and transparent inter-user deduplication, with the intermediate device located strategically to maintain data confidentiality and optimize bandwidth and storage usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If convergent encryption is used to enable inter-user deduplication, then storage space is optimized, but data confidentiality is compromised and the system becomes vulnerable to malicious attacks

Engineering Contradiction:
Improvestorage spaceVSAvoiddata confidentiality
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces a trusted intermediate device that acts as a mediator between clients and the storage server. This intermediary performs deduplication operations on encrypted data without having the ability to decrypt it, using cryptographic techniques such as commutative encryption or homomorphic hashing. The intermediate device verifies data uniqueness and manages deduplication metadata while preserving client data confidentiality, thus resolving the contradiction between enabling inter-user deduplication and maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If per-user encryption is used to ensure data confidentiality, then security is improved, but inter-user deduplication efficiency is reduced

Engineering Contradiction:
Improvedata confidentialityVSAvoiddeduplication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a universal deduplication mechanism that works across multiple users while maintaining per-user encryption. The system uses user-independent cryptographic operations (such as hashing or commutative encryption) that can be applied universally to encrypted data from different users, enabling the storage server to perform deduplication without needing to decrypt or know individual user encryption keys. This allows the same encryption scheme to serve both confidentiality and deduplication purposes simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of energy

If deduplication is performed on the source side to save bandwidth, then transmission efficiency is improved, but storage optimization across users is reduced

Engineering Contradiction:
ImprovebandwidthVSAvoidstorage space
Core Design Contradiction:
Loss of energyVSQuantity of substance

Solution Approach 1:

The patent divides the deduplication function into two segments: source-side deduplication for immediate bandwidth savings, and server-side deduplication for long-term storage optimization. The source device performs initial deduplication to reduce transmission volume, while the storage server performs additional deduplication on received data to optimize overall storage utilization across all users. This segmented approach allows both bandwidth and storage efficiency to be improved without compromising either objective.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2979222B1Method for storing data in a computer system performing data deduplication
Publication Date: 2019.10.09 ORANGE SA
  • EP2979222B1 patent drawingFigure 1~2
  • EP2979222B1 patent drawingFigure 3~4
  • EP2979222B1 patent drawingFigure 5

AI summary

The invention relates to a method for storing data in a computer system (SYS) including a plurality of first devices (PC1, PC2) storing data belonging to respective users (U1, U2), a second device (SS) capable of managing a backup of data from first devices, said backup including a step of deduplicating inter-user data, characterised in that an intermediate device (I) is inserted between the first devices (PC1, PC2) and the second device (SS), such as to initially perform an intra-user deduplication of the data to be backed up from first devices, and then to manage the inter-user deduplication in cooperation with the second device (SS).