Multi-Tenant Encrypted Data Deduplication With Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage systems face challenges in efficiently managing multi-tenancy datasets with end-to-end encryption while preventing deduplication, which can compromise data security and integrity.

Innovation Solution

Implementing a storage system that supports multi-tenancy with end-to-end encryption and prohibits deduplication between tenant datasets, using non-volatile solid state storage units and proactive data rebuilding mechanisms to ensure data security and availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of substance

If deduplication is enabled across multi-tenant datasets, then storage efficiency is improved, but data security and integrity are compromised

Engineering Contradiction:
Improvestorage efficiencyVSAvoiddata security and integrity
Core Design Contradiction:
Loss of substanceVSReliability

Solution Approach 1:

The patent segments the storage system into isolated tenant datasets, where each tenant's data is stored in separate namespaces. This segmentation prevents cross-tenant deduplication while allowing deduplication within each tenant's own data, thus maintaining both storage efficiency and data security/integrity by ensuring tenants cannot access or manipulate each other's deduplicated data blocks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different deduplication policies to different tenants locally. Each tenant can have their own deduplication enabled on their specific datasets while maintaining security boundaries. This local application of deduplication ensures storage efficiency is improved for each tenant without compromising the security and integrity of other tenants' data

Inventive Principle:
Principle #3Local quality

2Reliability

If end-to-end encryption is implemented, then data security is improved, but deduplication capability is reduced

Engineering Contradiction:
Improvedata securityVSAvoiddeduplication capability
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent performs deduplication operations on plaintext data blocks before encryption is applied. By conducting the deduplication comparison and identification in advance, the system can effectively duplicate data blocks across the same tenant's datasets while maintaining encryption for security. The encrypted blocks are then stored with their encryption keys managed separately, preserving both deduplication capability and end-to-end encryption security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12596816B2Performing deduplication on multi-tenancy dataset
Publication Date: 2026.04.07 PURE STORAGE INC
  • US12596816B2 patent drawing
  • US12596816B2 patent drawing
  • US12596816B2 patent drawing

AI summary

End-to-end encryption in a storage system with multi-tenancy, includes: performing deduplication on a first tenant dataset, the first tenant dataset including data encrypted using a first storage system encryption key; and performing deduplication on a second tenant dataset, the second tenant dataset including data encrypted using a second storage system encryption key, where deduplication is not performed between the first and second tenant datasets.