IP Library Granted Patent US 9,811,550
Granted Patent B2
US 9,811,550 · App. 14/557,596 · Granted Nov 7, 2017

Security for multi-tenant deduplication datastore against other tenants

Inventors: Venkata Krishna Venu Gopala Rao Bezawada (Hyderabad, IN); Subrahmanya Sarma Yellapragada (Hyderabad, IN); Ramakrishna Maddali (Prakasam Dt, IN)
Assignee: CA, Inc.
G06F17/30371G06F17/3033G06F17/30156G06F21/6218G06F21/64G06F21/645H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,811,550
App. No.
14/557,596
Granted
Nov 7, 2017
Kind
B2
Abstract

A method comprises receiving a first user hash value associated with data of a first user of a deduplication system, and comparing the first user hash value with each of a plurality of hash values stored in a first user hash store of the deduplication system. When it is determined that the first user hash value does not match one of the plurality of hash values stored in the first user hash store, first user hash value may be compared to each of a plurality of hash values stored in a global user hash store of the deduplication system associated with a plurality of users. When it is determined that the first user hash value matches one of the plurality of hash values stored in the global user hash store, the method may further comprise deleting the data after receiving the data associated with the first user hash value.

Claims (52)

1. A method comprising:

receiving a first user hash value associated with data of a first user of a deduplication system, and

comparing the first user hash value with each of a plurality of hash values stored in a first user hash store of the deduplication system, the plurality of hash values stored in the first user hash store associated with the first user,

wherein when it is determined that the first user hash value matches one of the plurality of hash values stored in the first user hash store, sending a first user hash value identifier to the first user, and

wherein when it is determined that the first user hash value does not match one of the plurality of hash values stored in the first user hash store,

comparing the first user hash value to each of a plurality of hash values stored in a global user hash store of the deduplication system, the plurality of hash values stored in the global hash store associated with a plurality of users, and the plurality of users including the first user,

requesting the data associated with the first user hash value from the first user, and

receiving the requested data from the first user.

2. The method of claim 1 , wherein when it is determined that that the first user hash value matches one of the plurality of hash values stored in the global user hash store, the method further comprises

discarding the data after receiving the data associated with the first user hash value from the first user, and

storing the first user hash value in the first user hash store.

3. The method of claim 1 , wherein when it is determined that the first user hash value does not match one of the plurality of hash values stored in the global user hash store, the method further comprises:

generating a new data hash value to be associated with the data, and

storing the new data hash value.

4. The method of claim 3 , wherein the new data hash value is stored in the first user hash store and the global user hash store.

5. The method of claim 1 , wherein the first user hash value identifier is associated with a hash value of the plurality of hash values stored in the first user hash store that matches the received first user hash value.

6. The method of claim 1 , wherein comparing the first user hash value to each of the plurality of hash values stored in the global user hash store comprises comparing the first user hash value to a plurality of hash values stored in the global user hash store associated with a plurality of users not including the first user.

7. A system comprising:

a hash value receiving device configured to receive a first user hash value associated with data of a first user of a deduplication system, and

a first hash value comparing device configured to compare the first user hash value with each of a plurality of hash values stored in a first user hash store of the deduplication system, the plurality of hash values stored in the first user hash store associated with the first user, and

wherein when it is determined that the first user hash value does not match one of the plurality of hash values stored in the first user hash store, the system further comprises:

a second hash value comparing device configured to compare the first user hash value to each of a plurality of hash values stored in a global user hash store of the deduplication system, the plurality of hash values stored in the global hash store associated with a plurality of users, and the plurality of users including the first user, and

a data requesting device configured to request the data associated with the first user hash value from the first user, and

a data receiving device configured to receive the data from the first user.

8. The system of claim 7 , wherein when the second hash value comparing device determines that the first user hash value matches one of the plurality of hash values stored in the global user hash store, the data receiving device is further configured to

send a first user hash value identifier to the first user,

discard the data after the data associated with the first user hash value is received from the first user, and

store the first user hash value in the first user hash store.

9. The system of claim 7 , wherein when it is determined that the first user hash value does not match one of the plurality of hash values stored in the global user hash store, the system further comprises:

a hash value generating device configured to generate a new data hash value to be associated with the data, and

a storage device configured to store the new data hash value.

10. The system of claim 9 , wherein the new data hash value is stored in the first user hash store and the global user hash store.

11. The system of claim 7 , wherein the first user hash value identifier is associated with a hash value of the plurality of hash values stored in the first user hash store that matches the received first user hash value.

12. The method of claim 7 , wherein comparing the first user hash value to each of the plurality of hash values stored in the global user hash store comprises comparing the first user hash value to a plurality of hash values stored in the global user hash store associated with a plurality of users not including the first user.

13. A computer program product comprising:

a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code comprising:

computer readable program code configured to receive a first user hash value associated with data of a first user of a deduplication system, and

computer readable program code configured to compare the first user hash value with each of a plurality of hash values stored in a first user hash store of the deduplication system, the plurality of hash values stored in the first user hash store associated with the first user,

computer readable program code configured to, when it is determined that the first user hash value does not match one of the plurality of hash values stored in the first user hash store:

compare the first user hash value to each of a plurality of hash values stored in a global user hash store of the deduplication system, the plurality of hash values stored in the global hash store associated with a plurality of users, and the plurality of users including the first user,

request the data associated with the first user hash value from the first user, and

receive the data from the first user.

14. The computer program product of claim 13 , wherein when it is determined that that the first user hash value matches one of the plurality of hash values stored in the global user hash store, computer readable program code is further configured to

send a first user hash value identifier to the first user,

discard the data after the data associated with the first user hash value is received from the first user, and

store the first user hash value in the first user hash store.

15. The computer program product of claim 14 , wherein when it is determined that the first user hash value does not match one of the plurality of hash values stored in the global user hash store, computer readable program code is further configured to:

generate a new data hash value to be associated with the data, and

store the new data hash value.

16. The computer program product of claim 15 , wherein the new data hash value is stored in the first user hash store and the global user hash store.

17. The computer program product of claim 13 , wherein the first user hash value identifier is associated with a hash value of the plurality of hash values stored in the first user hash store that matches the received first user hash value.

18. The computer program product of claim 13 , wherein comparing the first user hash value to each of the plurality of hash values stored in the global user hash store comprises comparing the first user hash value to a plurality of hash values stored in the global user hash store associated with a plurality of users not including the first user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2014
From: BEZAWADA, VENKATA KRISHNA VENU GOPALA RAO; YELLAPRAGADA, SUBRAHMANYA SARMA; MADDALI, RAMAKRISHNA
To: CA, INC.
Reel/Frame 034301/0583 →
Continuity (1)
Related Publication 20160154839A1 · Jun 2, 2016