IP Library › Granted Patent US 10,764,037
Granted Patent B2
US 10,764,037 · App. 15/536,986 · Granted Sep 1, 2020

Method and apparatus for duplicated data management in cloud computing

Inventor: Zheng Yan (Espoo, FI)
Assignee: Nokia Technologies Oy
H04L9/0825G06F11/1453G06F16/1756G06F21/602G06F21/6209H04L9/088H04L9/0847H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,764,037
App. No.
15/536,986
Granted
Sep 1, 2020
Kind
B2
Abstract

An approach is provided for managing data duplication in cloud computing. A method comprising, sending from a first device to a data center, data encrypted with a data encryption key for storing the encrypted data at the data center; encrypting the data encryption key according to an attribute-based encryption (ABE) scheme by using identity as an attribute in a deduplication policy for the data; issuing to a second device, a personalized secret attribute key which is derived from a public key of the second device according to the attribute-based encryption (ABE) scheme, wherein the personalized secret attribute key is to be used for decrypting the encrypted data encryption key at the second device, in combination with the policy.

Claims (29)

1. An apparatus comprising:

at least one processor; and

at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus to at least:

send, to a data center, data encrypted with a data encryption key for storing the encrypted data at the data center;

encrypt the data encryption key according to an attribute-based encryption scheme by using identity as an attribute in a deduplication policy for the data;

receive, from the data center, a public key associated with a device, wherein the public key is received in response to the device sending, to the data center, a request to store a duplicate of the encrypted data; and

issue, to the device, a personalized secret attribute key which is derived from the public key of the device according to the attribute-based encryption scheme, wherein the personalized secret attribute key is to be used for decrypting the encrypted data encryption key at the device, in combination with the deduplication policy.

2. An apparatus of claim 1 , wherein the apparatus is further caused to at least:

receive a deduplication notification from the data center, indicating that a duplication of the same data from the device is requested to be stored or has been stored at the data center, wherein the personalized secret attribute key is derived and issued in response to the receipt of the deduplication notification.

3. An apparatus of claim 2 , wherein the apparatus is further caused to at least:

inform the data center to deduplicate the same data from the device.

4. An apparatus of claim 1 , wherein the apparatus is further caused to at least:

send the encrypted data encryption key to the data center and/or the device.

5. An apparatus of claim 1 , wherein the apparatus is further caused to at least:

issue to another device, a personalized secret attribute key which is derived from a public key of the other device according to the attribute-based encryption scheme,

wherein the personalized secret attribute key issued to the other device is to be used for decrypting the encrypted data encryption key at the other device, in combination with the deduplication policy.

6. An apparatus of claim 1 , wherein the apparatus is further caused to at least:

set an access policy for the access to the data and sending the access policy to the data center.

7. An apparatus of claim 1 , wherein the apparatus is further caused to at least:

send to the data center, a request for deleting the data from the data center; and

continue a control of an encryption of the data encryption key and the issue of personalized secret attribute keys for decrypting the encrypted data encryption key.

8. An apparatus of claim 1 , wherein the apparatus is further caused to at least:

send to the data center a request for storing the data; and

receive from the data center an indication that there is no same data stored at the data center, wherein the data encrypted with the data encryption key is sent to the data center in response to the receipt of the indication.

9. A method comprising:

sending, by a first device and to a data center, data encrypted with a data encryption key for storing the encrypted data at the data center;

encrypting, by the first device, the data encryption key according to an attribute-based encryption scheme by using identity as an attribute in a deduplication policy for the data;

receiving, at the first device and from the data center, a public key associated with a second device, wherein the public key is received in response to the second device sending, to the data center, a request to store a duplicate of the encrypted data; and

issuing, by the first device and to the second device, a personalized secret attribute key which is derived from the public key of the second device according to the attribute-based encryption scheme, wherein the personalized secret attribute key is to be used for decrypting the encrypted data encryption key at the device, in combination with the deduplication policy.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2017
From: YAN, ZHENG
To: NOKIA CORPORATION
Reel/Frame 042733/0508 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2017
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 042733/0665 →
Continuity (1)
Related Publication 20170346625A1 · Nov 30, 2017
Cited By (2)
US 12,323,401 US 12,645,825