VM Encrypted Storage Deduplication via Guest Program Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data deduplication techniques are ineffective for encrypted data due to variations in cryptographic inputs, causing duplicate detection failures in encrypted storage environments, particularly within virtualized systems where hypervisors lack access to decrypted data.
Innovation Solution
A guest program, executed by a virtual machine, performs data comparisons and collaborates with the hypervisor to identify and deduplicate encrypted storage blocks without accessing decrypted versions, using cryptographic functions executed by hardware to maintain security and conceal decryption keys from the hypervisor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted using cryptographic functions with variations in cryptographic inputs, then security is improved, but data deduplication capability deteriorates because duplicate detection fails
Solution Approach 1:
The patent introduces an intermediary component (deduplication module) that sits between the encrypted storage and the deduplication process. This intermediary has access to both the encrypted data and the plaintext versions, allowing it to perform deduplication on plaintext while maintaining encrypted storage. The intermediary resolves the contradiction by enabling deduplication without compromising security.
Solution Approach 2:
The patent segments the data handling process into two distinct paths: one for encryption/security (handled by cryptographic module) and one for deduplication (handled by deduplication module). The data is processed differently for each function - encrypted for storage and decrypted for deduplication comparison. This segmentation allows both security and deduplication to coexist without interfering with each other.
2Productivity
If the hypervisor accesses decrypted data to perform deduplication, then data deduplication efficiency is improved, but security deteriorates because decryption keys become accessible to the hypervisor
Solution Approach 1:
The patent introduces a dedicated deduplication module as an intermediary that acts as a bridge between the encrypted storage system and the deduplication process. This module has special privileges to access plaintext data for comparison purposes while the hypervisor remains restricted to encrypted data only. The intermediary enables efficient deduplication operations without compromising the security model.
Solution Approach 2:
The patent extracts the deduplication function from the hypervisor and places it in a separate dedicated module. This extracted module is the only component with access to plaintext data for deduplication purposes. By separating the deduplication function from the hypervisor, the system achieves efficient deduplication while maintaining security boundaries - the hypervisor cannot access decryption keys.
3Reliability
If duplicate detection is performed on encrypted data, then security is maintained, but storage utilization deteriorates because duplicate copies cannot be identified and removed
Solution Approach 1:
The patent introduces a mediating deduplication module that can access both encrypted and plaintext versions of data. This intermediary performs duplicate detection on plaintext data, identifies redundant copies, and manages their removal or consolidation. The mediation enables effective deduplication while the underlying storage remains encrypted, resolving the contradiction between security and storage efficiency.
Solution Approach 2:
The patent performs deduplication operations before data is permanently stored in encrypted form. The system first decrypts incoming data, performs duplicate detection and removal in plaintext form, then encrypts and stores only the unique data. This preliminary action on plaintext data enables effective deduplication while maintaining security in the stored encrypted data.
Data Source
AI summary
Technology for performing data deduplication on encrypted storage of a virtual machine. An example method may involve: analyzing, by a guest program, a first storage block of a first virtual machine and a second storage block of a second virtual machine, wherein the first virtual machine and the second virtual machine are managed by a hypervisor; comparing, by the guest program, data of the first storage block and data of the second storage block, wherein the data of the first storage block and the data of the second storage block are encrypted using different location dependent cryptographic input; determining, by the guest program in view of the comparing, that the first storage block and the second storage block are duplicate storage blocks; and providing, by the guest program, an indication of the duplicate storage blocks to the hypervisor to cause the duplicate storage blocks to reference a common storage location.


