VM Encrypted Storage Deduplication via Guest Program Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data deduplication techniques are ineffective for encrypted data due to variations in cryptographic inputs, causing duplicate detection failures in encrypted storage environments, particularly within virtualized systems where hypervisors lack access to decrypted data.

Innovation Solution

A guest program, executed by a virtual machine, performs data comparisons and collaborates with the hypervisor to identify and deduplicate encrypted storage blocks without accessing decrypted versions, using cryptographic functions executed by hardware to maintain security and conceal decryption keys from the hypervisor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted using cryptographic functions with variations in cryptographic inputs, then security is improved, but data deduplication capability deteriorates because duplicate detection fails

Engineering Contradiction:
ImprovesecurityVSAvoiddata deduplication capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary component (deduplication module) that sits between the encrypted storage and the deduplication process. This intermediary has access to both the encrypted data and the plaintext versions, allowing it to perform deduplication on plaintext while maintaining encrypted storage. The intermediary resolves the contradiction by enabling deduplication without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data handling process into two distinct paths: one for encryption/security (handled by cryptographic module) and one for deduplication (handled by deduplication module). The data is processed differently for each function - encrypted for storage and decrypted for deduplication comparison. This segmentation allows both security and deduplication to coexist without interfering with each other.

Inventive Principle:
Principle #1Segmentation

2Productivity

If the hypervisor accesses decrypted data to perform deduplication, then data deduplication efficiency is improved, but security deteriorates because decryption keys become accessible to the hypervisor

Engineering Contradiction:
Improvedata deduplication efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a dedicated deduplication module as an intermediary that acts as a bridge between the encrypted storage system and the deduplication process. This module has special privileges to access plaintext data for comparison purposes while the hypervisor remains restricted to encrypted data only. The intermediary enables efficient deduplication operations without compromising the security model.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the deduplication function from the hypervisor and places it in a separate dedicated module. This extracted module is the only component with access to plaintext data for deduplication purposes. By separating the deduplication function from the hypervisor, the system achieves efficient deduplication while maintaining security boundaries - the hypervisor cannot access decryption keys.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If duplicate detection is performed on encrypted data, then security is maintained, but storage utilization deteriorates because duplicate copies cannot be identified and removed

Engineering Contradiction:
ImprovesecurityVSAvoidstorage utilization
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces a mediating deduplication module that can access both encrypted and plaintext versions of data. This intermediary performs duplicate detection on plaintext data, identifies redundant copies, and manages their removal or consolidation. The mediation enables effective deduplication while the underlying storage remains encrypted, resolving the contradiction between security and storage efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs deduplication operations before data is permanently stored in encrypted form. The system first decrypts incoming data, performs duplicate detection and removal in plaintext form, then encrypts and stores only the unique data. This preliminary action on plaintext data enables effective deduplication while maintaining security in the stored encrypted data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11061711B2Storage deduplication for virtual machines with encrypted storage
Publication Date: 2021.07.13 RED HAT INC
  • US11061711B2 patent drawing
  • US11061711B2 patent drawing
  • US11061711B2 patent drawing

AI summary

Technology for performing data deduplication on encrypted storage of a virtual machine. An example method may involve: analyzing, by a guest program, a first storage block of a first virtual machine and a second storage block of a second virtual machine, wherein the first virtual machine and the second virtual machine are managed by a hypervisor; comparing, by the guest program, data of the first storage block and data of the second storage block, wherein the data of the first storage block and the data of the second storage block are encrypted using different location dependent cryptographic input; determining, by the guest program in view of the comparing, that the first storage block and the second storage block are duplicate storage blocks; and providing, by the guest program, an indication of the duplicate storage blocks to the hypervisor to cause the duplicate storage blocks to reference a common storage location.