IP Library Granted Patent US 12,007,891
Granted Patent B2
US 12,007,891 · App. 17/582,524 · Granted Jun 11, 2024

Storage deduplication for containers with encrypted storage

Inventor: Michael Tsirkin (Haifa, IL)
Assignee: Red Hat, Inc.
G06F12/0646G06F9/44594G06F9/45558G06F12/1408G06F2009/45579G06F2009/45583G06F2212/1044G06F2212/151G06F2212/657
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,007,891
App. No.
17/582,524
Granted
Jun 11, 2024
Kind
B2
Abstract

Technology for enabling a kernel to perform data deduplication on encrypted storage of a container. An example method may involve: enabling, by a kernel, a guest program of a container to access a first storage block of a first container and a second storage block of a second container; receiving, by the kernel from the guest program, an indication that the first storage block and the second storage block are duplicate storage blocks; and updating the first storage block or the second storage block to cause the duplicate storage blocks to reference a common storage location.

Claims (37)

1. A method comprising:

enabling, by a kernel, a guest program of a container to access a first storage block of a first container and a second storage block of a second container;

providing, by the kernel, to the guest program, a set of one or more candidate storage blocks;

receiving, by the kernel, from the guest program, an indication that the first storage block and the second storage block are identified, among the set of one or more candidate storage blocks, as duplicate storage blocks; and

updating the first storage block or the second storage block to cause the duplicate storage blocks to reference a common storage location.

2. The method of claim 1 , wherein the duplicate storage blocks comprise encrypted data that is accessible to the guest program of the container in a decrypted form and is inaccessible to the kernel in the decrypted form.

3. The method of claim 1 , wherein the duplicate storage blocks correspond to duplicate pages in physical memory of one or more host machines, the method further comprising removing at least one of the duplicate pages from the physical memory by updating and freeing the at least one of the duplicate pages.

4. The method of claim 1 , further comprising activating the guest program in response to detecting that a quantity of available physical data storage is below a threshold value.

5. The method of claim 1 , further comprising deactivating the guest program in response to detecting that a quantity of available physical data storage is above a threshold value.

6. The method of claim 1 , wherein the duplicate storage blocks comprise equivalent data that is encrypted with different location dependent cryptographic input when stored in a storage device.

7. The method of claim 6 , wherein the different location dependent cryptographic input corresponds to different host physical addresses for the first and second storage blocks.

8. The method of claim 1 , wherein the first storage block and the second storage block comprise data that is decrypted by a hardware device using one or more cryptographic keys that are inaccessible to the kernel, wherein the one or more cryptographic keys comprise a cryptographic key that is based on a common cryptographic input that is shared by multiple containers and a location dependent cryptographic input.

9. The method of claim 1 , wherein the container that executes the guest program is the first container, and wherein the first container and the second container share a common cryptographic input for decrypting data of the first storage block and data of the second storage block.

10. The method of claim 1 , wherein the container that executes the guest program is a third container, and wherein the first container, the second container, and the third container share a common cryptographic input for decrypting data of the first storage block and data of the second storage block.

11. The method of claim 1 , wherein enabling the guest program comprises:

activating, by the kernel, a third container that executes the guest program; and

configuring the third container to access memory of the first container and memory of the second container.

12. The method of claim 1 , further comprising

selecting, by the kernel, a set of candidate storage blocks in view of a heuristic that uses modification times of storage blocks, wherein the set of candidate storage blocks comprises identification data of the first storage block of the first container and identification data of the second storage block of the second container.

13. The method of claim 1 , wherein receiving the indication that the first storage block and the second storage block are duplicate storage blocks is in view of the guest program making a system call to the kernel, wherein the system call indicates one or more guest physical addresses of the duplicate storage blocks.

14. The method of claim 1 , wherein updating the duplicate storage blocks comprises the kernel or host operating system updating the second storage block to reference a physical storage location of the first storage block.

15. A system comprising:

a memory; and

a processing device communicably coupled to the memory, the processing device to:

enable, by a kernel, a guest program of a container to access a first storage block of a first container and a second storage block of a second container;

provide, by the kernel, to the guest program, a set of one or more candidate storage blocks;

receive, by the kernel, from the guest program, an indication that the first storage block and the second storage block are identified, among the set of one or more candidate storage blocks, as duplicate storage blocks; and

update the first storage block or the second storage block to cause the duplicate storage blocks to reference a common storage location.

16. The system of claim 15 , wherein the duplicate storage blocks comprise encrypted data that is accessible to the guest program of the container in a decrypted form and is inaccessible to the kernel in the decrypted form.

17. The system of claim 15 , wherein the duplicate storage blocks correspond to duplicate pages in physical memory of one or more host machines, and wherein the processing device is further to remove at least one of the duplicate pages from the physical memory by updating and freeing the at least one of the duplicate pages.

18. A non-transitory machine-readable storage medium storing instructions which, when executed, cause a processing device to perform operations comprising:

enabling, by a kernel, a guest program of a container to access a first memory page of a first container and a second memory page of a second container;

providing, by the kernel, to the guest program, a set of one or more candidate storage blocks;

receiving, by the kernel, from the guest program, an indication that the first memory page and the second memory page are identified, among the set of one or more candidate storage blocks, as duplicate memory pages; and

updating the first storage block or the second storage block to cause the duplicate memory pages to reference a common storage location in a physical memory device.

19. The non-transitory machine-readable storage medium of claim 18 , wherein the duplicate memory pages comprise encrypted data that is accessible to the guest program of the container in a decrypted form and is inaccessible to the kernel in the decrypted form.

20. The non-transitory machine-readable storage medium of claim 18 , further comprising activating the guest program in response to detecting that a quantity of available physical memory is below a threshold value.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2022
From: TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 059196/0064 →
Continuity (2)
Continuation 16585154 · Sep 27, 2019
Related Publication 20220147450A1 · May 12, 2022