Enhancing Data Security and Efficiency: A Hybrid Cloud Approach to Secure Authorized Deduplication
K. Suresh Kumar, Preethi S T, P. Mahalakshmi, S Hariharasudhan · 2024
As cloud services grow, data deduplication has become crucial for reducing storage costs and improving resource utilization by eliminating duplicate data. However, maintaining data security and user privacy in deduplication-enabled environments remains a significant challenge due to increasing risks of unauthorized access and data breaches. To address this, convergent encryption has been proposed, allowing data encryption before outsourcing while supporting deduplication. This paper introduces a hybrid cloud approach for secure authorized deduplication, combining public and private clouds to optimize efficiency, data integrity, and confidentiality. Our solution uses a dual-layer authentication and encryption mechanism, where key generation is tied to user privileges and file ownership. The control plane is managed by the private cloud, handling sensitive metadata and keys, while the public cloud stores deduplicated data to ensure cost efficiency. We further introduce differential user privileges in duplicate checks, a feature lacking in traditional systems. To validate our approach, we developed a prototype and conducted testbed experiments. The results show substantial reductions in storage overhead and latency, with minimal performance impact. Security analysis confirms that our scheme meets the required security guarantees, providing a scalable and efficient solution for cloud deduplication while addressing privacy and performance concerns.