US2021389893A1PendingUtilityA1

Deduplication of encrypted data within a remote data store

Assignee: NETAPP INCPriority: Apr 4, 2019Filed: Aug 30, 2021Published: Dec 16, 2021
Est. expiryApr 4, 2039(~12.7 yrs left)· nominal 20-yr term from priority
G06F 3/067G06F 3/0608H04L 9/0643H04L 9/0822H04L 9/0894H04L 9/3239G06F 3/0641G06F 16/9027G06F 21/602G06F 17/18G06F 16/215
64
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques are provided for deduplicating encrypted data. For example, a device has data to store in an encrypted state within a remote data store. A key is used to encrypt the data to create encrypted data. The data is hashed to create hashed data and the encrypted data is hashed to create hashed encrypted data. A probabilistic data structure of the data is generated. The key is encrypted based upon the data to create an encrypted key. The encrypted data is transmitted to the remote data store, along with metadata comprising the hashed data, the hashed encrypted data, the probabilistic data structure, and the encrypted key. The metadata may be used to implement deduplication for subsequent requests, to store data within the remote data store, with respect to the encrypted data.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving a request from a client device to store data within a remote data store, wherein the request comprises hashed data corresponding to a hash of the data;   in response to the hashed data matching stored hashed data within metadata maintained by the remote data store, requesting hashed encrypted data from the client device;   storing a reference for the client device to encrypted data stored within the remote data store based upon the hashed encrypted data matching stored hashed encrypted data within the metadata; and   transmitting an indication to the client device that the data has been deduplicated with respect to the encrypted data stored within the remote data store.   
     
     
         2 . The method of  claim 1 , comprising:
 incrementing a reference count maintained by the remote data store for the encrypted data to indicate that the data is deduplicated with respect to the encrypted data.   
     
     
         3 . The method of  claim 1 , wherein the reference for the client device to the encrypted data is stored within the remote data store in place of storing an encrypted version of the data. 
     
     
         4 . The method of  claim 1 , comprising:
 incrementing a reference count for the encrypted data to indicate that the client device is an owner of the encrypted data.   
     
     
         5 . The method of  claim 4 , wherein the reference count comprises a count corresponding to a number of owners of the encrypted data. 
     
     
         6 . The method of  claim 1 , comprising:
 transmitting the indication to the client device with an instruction to refrain from sending an encrypted version of the data to store within the remote data store because the encrypted version of the data is already stored as the encrypted data within the remote data store.   
     
     
         7 . The method of  claim 1 , comprising:
 in response to the hashed encrypted data not matching the stored hashed encrypted data within the metadata, transmitting a request to the client device to send an encrypted version of the data for storage within the remote data store.   
     
     
         8 . A non-transitory machine readable medium comprising instructions for performing a method, which when executed by a machine, causes the machine to:
 receive a request from a client device to store data within a remote data store, wherein the request comprises hashed data corresponding to a hash of the data;   in response to the hashed data matching stored hashed data within metadata maintained by the remote data store, request hashed encrypted data from the client device;   store a reference for the client device to encrypted data stored within the remote data store based upon the hashed encrypted data matching stored hashed encrypted data within the metadata; and   transmit an indication to the client device that the data has been deduplicated with respect to the encrypted data stored within the remote data store.   
     
     
         9 . The non-transitory machine readable medium of  claim 8 , wherein the instructions cause the machine to:
 increment a reference count maintained by the remote data store for the encrypted data to indicate that the data is deduplicated with respect to the encrypted data.   
     
     
         10 . The non-transitory machine readable medium of  claim 8 , wherein the reference for the client device to the encrypted data is stored within the remote data store in place of storing an encrypted version of the data. 
     
     
         11 . The non-transitory machine readable medium of  claim 8 , wherein the instructions cause the machine to:
 increment a reference count for the encrypted data to indicate that the client device is an owner of the encrypted data.   
     
     
         12 . The non-transitory machine readable medium of  claim 11 , wherein the reference count comprises a count corresponding to a number of owners of the encrypted data. 
     
     
         13 . The non-transitory machine readable medium of  claim 8 , wherein the instructions cause the machine to:
 transmit the indication to the client device with an instruction to refrain from sending an encrypted version of the data to store within the remote data store because the encrypted version of the data is already stored as the encrypted data within the remote data store.   
     
     
         14 . The non-transitory machine readable medium of  claim 8 , wherein the instructions cause the machine to:
 in response to the hashed encrypted data not matching the stored hashed encrypted data within the metadata, transmit a request to the client device to send an encrypted version of the data for storage within the remote data store.   
     
     
         15 . A computing device comprising:
 a memory comprising machine executable code for performing a method; and   a processor coupled to the memory, the processor configured to execute the machine executable code to cause the processor to:
 receive a request from a client device to store data within a remote data store, wherein the request comprises hashed data corresponding to a hash of the data; 
 in response to the hashed data matching stored hashed data within metadata maintained by the remote data store, request hashed encrypted data from the client device; 
 store a reference for the client device to encrypted data stored within the remote data store based upon the hashed encrypted data matching stored hashed encrypted data within the metadata; and 
 transmit an indication to the client device that the data has been deduplicated with respect to the encrypted data stored within the remote data store. 
   
     
     
         16 . The computing device of  claim 15 , wherein the machine executable code causes the processor to:
 in response to the hashed encrypted data not matching the stored hashed encrypted data within the metadata, transmit a request to the client device to send an encrypted version of the data for storage within the remote data store.   
     
     
         17 . The computing device of  claim 15 , wherein the machine executable code causes the processor to:
 increment a reference count maintained by the remote data store for the encrypted data to indicate that the data is deduplicated with respect to the encrypted data.   
     
     
         18 . The computing device of  claim 15 , wherein the reference for the client device to the encrypted data is stored within the remote data store in place of storing an encrypted version of the data. 
     
     
         19 . The computing device of  claim 15 , wherein the machine executable code causes the processor to:
 increment a reference count for the encrypted data to indicate that the client device is an owner of the encrypted data.   
     
     
         20 . The computing device of  claim 19 , wherein the reference count comprises a count corresponding to a number of owners of the encrypted data.

Join the waitlist — get patent alerts

Track US2021389893A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.