Deduplication of encrypted data within a remote data store
Abstract
Techniques are provided for deduplicating encrypted data. For example, a device has data to store in an encrypted state within a remote data store. A key is used to encrypt the data to create encrypted data. The data is hashed to create hashed data and the encrypted data is hashed to create hashed encrypted data. A probabilistic data structure of the data is generated. The key is encrypted based upon the data to create an encrypted key. The encrypted data is transmitted to the remote data store, along with metadata comprising the hashed data, the hashed encrypted data, the probabilistic data structure, and the encrypted key. The metadata may be used to implement deduplication for subsequent requests, to store data within the remote data store, with respect to the encrypted data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving a request from a client device to store data within a remote data store, wherein the request comprises hashed data corresponding to a hash of the data; in response to the hashed data matching stored hashed data within metadata maintained by the remote data store, requesting hashed encrypted data from the client device; storing a reference for the client device to encrypted data stored within the remote data store based upon the hashed encrypted data matching stored hashed encrypted data within the metadata; and transmitting an indication to the client device that the data has been deduplicated with respect to the encrypted data stored within the remote data store.
2 . The method of claim 1 , comprising:
incrementing a reference count maintained by the remote data store for the encrypted data to indicate that the data is deduplicated with respect to the encrypted data.
3 . The method of claim 1 , wherein the reference for the client device to the encrypted data is stored within the remote data store in place of storing an encrypted version of the data.
4 . The method of claim 1 , comprising:
incrementing a reference count for the encrypted data to indicate that the client device is an owner of the encrypted data.
5 . The method of claim 4 , wherein the reference count comprises a count corresponding to a number of owners of the encrypted data.
6 . The method of claim 1 , comprising:
transmitting the indication to the client device with an instruction to refrain from sending an encrypted version of the data to store within the remote data store because the encrypted version of the data is already stored as the encrypted data within the remote data store.
7 . The method of claim 1 , comprising:
in response to the hashed encrypted data not matching the stored hashed encrypted data within the metadata, transmitting a request to the client device to send an encrypted version of the data for storage within the remote data store.
8 . A non-transitory machine readable medium comprising instructions for performing a method, which when executed by a machine, causes the machine to:
receive a request from a client device to store data within a remote data store, wherein the request comprises hashed data corresponding to a hash of the data; in response to the hashed data matching stored hashed data within metadata maintained by the remote data store, request hashed encrypted data from the client device; store a reference for the client device to encrypted data stored within the remote data store based upon the hashed encrypted data matching stored hashed encrypted data within the metadata; and transmit an indication to the client device that the data has been deduplicated with respect to the encrypted data stored within the remote data store.
9 . The non-transitory machine readable medium of claim 8 , wherein the instructions cause the machine to:
increment a reference count maintained by the remote data store for the encrypted data to indicate that the data is deduplicated with respect to the encrypted data.
10 . The non-transitory machine readable medium of claim 8 , wherein the reference for the client device to the encrypted data is stored within the remote data store in place of storing an encrypted version of the data.
11 . The non-transitory machine readable medium of claim 8 , wherein the instructions cause the machine to:
increment a reference count for the encrypted data to indicate that the client device is an owner of the encrypted data.
12 . The non-transitory machine readable medium of claim 11 , wherein the reference count comprises a count corresponding to a number of owners of the encrypted data.
13 . The non-transitory machine readable medium of claim 8 , wherein the instructions cause the machine to:
transmit the indication to the client device with an instruction to refrain from sending an encrypted version of the data to store within the remote data store because the encrypted version of the data is already stored as the encrypted data within the remote data store.
14 . The non-transitory machine readable medium of claim 8 , wherein the instructions cause the machine to:
in response to the hashed encrypted data not matching the stored hashed encrypted data within the metadata, transmit a request to the client device to send an encrypted version of the data for storage within the remote data store.
15 . A computing device comprising:
a memory comprising machine executable code for performing a method; and a processor coupled to the memory, the processor configured to execute the machine executable code to cause the processor to:
receive a request from a client device to store data within a remote data store, wherein the request comprises hashed data corresponding to a hash of the data;
in response to the hashed data matching stored hashed data within metadata maintained by the remote data store, request hashed encrypted data from the client device;
store a reference for the client device to encrypted data stored within the remote data store based upon the hashed encrypted data matching stored hashed encrypted data within the metadata; and
transmit an indication to the client device that the data has been deduplicated with respect to the encrypted data stored within the remote data store.
16 . The computing device of claim 15 , wherein the machine executable code causes the processor to:
in response to the hashed encrypted data not matching the stored hashed encrypted data within the metadata, transmit a request to the client device to send an encrypted version of the data for storage within the remote data store.
17 . The computing device of claim 15 , wherein the machine executable code causes the processor to:
increment a reference count maintained by the remote data store for the encrypted data to indicate that the data is deduplicated with respect to the encrypted data.
18 . The computing device of claim 15 , wherein the reference for the client device to the encrypted data is stored within the remote data store in place of storing an encrypted version of the data.
19 . The computing device of claim 15 , wherein the machine executable code causes the processor to:
increment a reference count for the encrypted data to indicate that the client device is an owner of the encrypted data.
20 . The computing device of claim 19 , wherein the reference count comprises a count corresponding to a number of owners of the encrypted data.Join the waitlist — get patent alerts
Track US2021389893A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.