IP Library Granted Patent US 9,626,518
Granted Patent B2
US 9,626,518 · App. 14/966,406 · Granted Apr 18, 2017

Avoiding encryption in a deduplication storage

Inventor: Andrew Lynn Gardner (Oak City, UT)
Assignee: STORAGECRAFT TECHNOLOGY CORPORATION
G06F21/602G06F11/1453G06F11/1464G06F12/14G06F17/30097G06F17/30159G06F21/60G06F2201/845
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,626,518
App. No.
14/966,406
Granted
Apr 18, 2017
Kind
B2
Abstract

Avoiding encryption in a deduplication vault. In one example embodiment, a method may include analyzing an allocated plain text block stored in the source storage to determine if the block is already stored in the deduplication storage, in response to the block not being stored, encrypting the allocated plain text block and analyzing the encrypted block to determine if the encrypted block is already stored in the deduplication storage, analyzing a second allocated plain text block stored in the source storage to determine if the block is already stored in the deduplication storage, in response to the block already being stored, avoiding encryption of the second allocated plain text block by not encrypting the second allocated plain text block and instead associating the location of the second allocated plain text block in the source storage with the location of the duplicate block already stored.

Claims (52)

1. A method for avoiding encryption during a backup of a source storage into a deduplication storage, the method comprising:

analyzing an allocated plain text block stored in the source storage at a point in time to determine if the allocated plain text block is already stored in the deduplication storage;

in response to the allocated plain text block not being stored in the deduplication storage, encrypting the allocated plain text block and analyzing the encrypted block to determine if the encrypted block is already stored in the deduplication storage;

analyzing a second allocated plain text block stored in the source storage at the point in time to determine if the second allocated plain text block is already stored in the deduplication storage; and

in response to the second allocated plain text block already being stored in the deduplication storage, avoiding encryption of the second allocated plain text block by not encrypting the second allocated plain text block and instead associating the location of the second allocated plain text block in the source storage with the location of the duplicate block already stored in the deduplication storage.

2. The method as recited in claim 1 , further comprising reading, from the deduplication storage, and storing, in a restore storage, each allocated block that was stored in the source storage at the point in time in the same position as stored in the source storage at the point in time, wherein each encrypted allocated block is decrypted prior to being stored in the restore storage and each plain text allocated block is not decrypted prior to being stored in the restore storage.

3. The method as recited in claim 1 , further comprising seeding the deduplication storage with common plain text blocks prior to the point in time.

4. The method as recited in claim 1 , wherein the analyzing the allocated plain text block includes compressing the allocated plain text block.

5. The method as recited in claim 1 , wherein the analyzing the allocated plain text block includes:

hashing the allocated plain text block to produce a hash value;

determining if the hash value matches a hash value of any plain text block already stored in the deduplication storage; and

if the hash value matches any hash value of any plain text block already stored in the deduplication storage, determining that the allocated plain text block is already stored in the deduplication storage.

6. The method as recited in claim 5 , wherein hash values associated with plain text blocks stored in the deduplication storage are stored in a database or hash table.

7. The method as recited in claim 1 , wherein the analyzing the encrypted block includes:

hashing the encrypted block to produce a hash value;

determining if the hash value matches a hash value of any encrypted block already stored in the deduplication storage; and

if the hash value matches the hash value of any encrypted block already stored in the deduplication storage, determining that the encrypted block is already stored in the deduplication storage.

8. The method as recited in claim 7 , further comprising, in response to the encrypted block not being stored in the deduplication storage, storing the encrypted block in the deduplication storage which includes storing the hash value in a database or hash table such that the hash value is associated with the encrypted block.

9. The method as recited in claim 7 , wherein the encrypting the allocated plain text block includes encrypting the allocated plain text block using a user-chosen key.

10. One or more non-transitory computer-readable media storing one or more programs that, when executed, causes one or more processors to perform a method for avoiding encryption during a backup of a source storage into a deduplication storage, the method comprising:

analyzing an allocated plain text block stored in the source storage at a point in time to determine if the allocated plain text block is already stored in the deduplication storage;

in response to the allocated plain text block not being stored in the deduplication storage, encrypting the allocated plain text block and analyzing the encrypted block to determine if the encrypted block is already stored in the deduplication storage;

analyzing a second allocated plain text block stored in the source storage at the point in time to determine if the second allocated plain text block is already stored in the deduplication storage; and

in response to the second allocated plain text block already being stored in the deduplication storage, avoiding encryption of the second allocated plain text block by not encrypting the second allocated plain text block and instead associating the location of the second allocated plain text block in the source storage with the location of the duplicate block already stored in the deduplication storage.

11. A method for avoiding encryption during a backup of a source storage into a deduplication storage, the method comprising:

seeding the deduplication storage with common plain text blocks;

analyzing an allocated plain text block stored in the source storage at a point in time to determine if the allocated plain text block is already stored in the deduplication storage;

in response to the allocated plain text block not being stored in the deduplication storage, encrypting the allocated plain text block and analyzing the encrypted block to determine if the encrypted block is already stored in the deduplication storage;

analyzing a second allocated plain text block stored in the source storage at the point in time to determine if the second allocated plain text block is already stored in the deduplication storage; and

in response to the second allocated plain text block already being stored in the deduplication storage, avoiding encryption of the second allocated plain text block by not encrypting the second allocated plain text block and instead associating the location of the second allocated plain text block in the source storage with the location of the duplicate block already stored in the deduplication storage.

12. The method as recited in claim 11 , wherein the common plain text blocks include blocks that make up files of a standard operating system and/or files of a standard software application and/or blocks that have been designated by an administrator or user of the deduplication storage as common blocks.

13. The method as recited in claim 11 , wherein the seeding the deduplication storage includes:

identifying an encrypted block stored in the deduplication storage that corresponds to multiple source storages; and

replacing the encrypted block with a corresponding plain text block in the deduplication storage.

14. The method as recited in claim 11 , wherein the analyzing the allocated plain text block includes compressing the allocated plain text block.

15. The method as recited in claim 11 , wherein the analyzing the allocated plain text block includes:

hashing the allocated plain text block to produce a hash value;

determining if the hash value matches a hash value of any plain text block already stored in the deduplication storage; and

if the hash value matches any hash value of any plain text block already stored in the deduplication storage, determining that the allocated plain text block is already stored in the deduplication storage.

16. The method as recited in claim 15 , wherein hash values associated with plain text blocks stored in the deduplication storage are stored in a database or hash table.

17. The method as recited in claim 11 , wherein the analyzing the encrypted block includes:

hashing the encrypted block to produce a hash value;

determining if the hash value matches a hash value of any encrypted block already stored in the deduplication storage; and

if the hash value matches the hash value of any encrypted block already stored in the deduplication storage, determining that the encrypted block is already stored in the deduplication storage.

18. The method as recited in claim 17 , further comprising, in response to the encrypted block not being stored in the deduplication storage, storing the encrypted block in the deduplication storage which includes storing the hash value in a database or hash table such that the hash value is associated with the encrypted block.

19. The method as recited in claim 18 , wherein the encrypting the allocated plain text block includes encrypting the allocated plain text block using a user-chosen key.

20. One or more non-transitory computer-readable media storing one or more programs that, when executed, causes one or more processors to perform a method for avoiding encryption during a backup of a source storage into a deduplication storage, the method comprising:

seeding the deduplication storage with common plain text blocks;

analyzing an allocated plain text block stored in the source storage at a point in time to determine if the allocated plain text block is already stored in the deduplication storage;

in response to the allocated plain text block not being stored in the deduplication storage, encrypting the allocated plain text block and analyzing the encrypted block to determine if the encrypted block is already stored in the deduplication storage;

analyzing a second allocated plain text block stored in the source storage at the point in time to determine if the second allocated plain text block is already stored in the deduplication storage; and

in response to the second allocated plain text block already being stored in the deduplication storage, avoiding encryption of the second allocated plain text block by not encrypting the second allocated plain text block and instead associating the location of the second allocated plain text block in the source storage with the location of the duplicate block already stored in the deduplication storage.

Assignments (6)
CHANGE OF NAME Recorded Aug 16, 2024
From: STORAGECRAFT TECHNOLOGY CORPORATION
To: STORAGECRAFT TECHNOLOGY LLC
Reel/Frame 068660/0176 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2024
From: MONROE CAPITAL MANAGEMENT ADVISORS, LLC; ARCSTOR MIDCO LLC; ARCSERVE ACQUISITION COMPANY LLC; ARCSERVE (USA) LLC; STORAGECRAFT TECHNOLOGY, LLC
To: STORAGECRAFT, LLC
Reel/Frame 068660/0208 →
SECURITY INTEREST Recorded Mar 16, 2021
From: ARCSERVE (USA) LLC; STORAGECRAFT TECHNOLOGY LLC; ZETTA, LLC
To: MONROE CAPITAL MANAGEMENT ADVISORS, LLC, AS COLLATERAL AGENT
Reel/Frame 055603/0219 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT Recorded Mar 16, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: STORAGECRAFT TECHNOLOGY CORPORATION
Reel/Frame 055614/0607 →
SECURITY AGREEMENT Recorded Apr 18, 2016
From: STORAGECRAFT TECHNOLOGY CORPORATION
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 038449/0943 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2015
From: GARDNER, ANDREW LYNN
To: STORAGECRAFT TECHNOLOGY CORPORATION
Reel/Frame 037277/0274 →
Continuity (3)
Continuation 14618928 · Feb 10, 2015
Continuation 14493028 · Sep 22, 2014
Related Publication 20160098569A1 · Apr 7, 2016