Dual Deduplication in multi-client setting and its applications

Hadi Sehat · 2023

With the ever growing access and use of internet, large amounts of data is being generated and used by devices and consumers all over the world. This data is normally stored in centralized storage systems, referred to as Cloud Storage Provides (CSPs). In order to cope with the rapid growth of data and storage requirements, and provide efficient service to multiple users around the globe, CSPs use different techniques to reduce the footprint of the data. These techniques can be categorized in two main categories, namely compression and deduplication. The latter, deduplication, is the main focus of this thesis. Deduplication reduces the footprint of the data, by removing identical chunks of the data between multiple files. In other words, it works based on redundancy in chunks between different files. Generalized Deduplication (GD) is a novel approach that expands deduplication, enabling removal of similar chunks, significantly improving the performance of the CSPs. However, in both these techniques, the cloud needs access to raw data to perform effective deduplication, which puts the privacy of the users at risk by leaking potentially sensitive information. In order to mitigate this risk, the users may wish to hide their sensitive information by using encryption. While encryption provides privacy for the data, it hinders the deduplication potential, making it an undesirable approach in many use cases. In this thesis, we tackle this problem by introducing an innovative technique to provide privacy and deduplication in a multi-user CSP environment. The proposed technique, called Dual Deduplication (DD) performs a set of lightweight transformations in the users, aiming to achieve privacy by altering the data. These transformations are semi-controlled by the CSP using a set of introductions sent to the client. We show that using this technique, we achieve information-theoretic privacy for the data of the users, while maintaining the possibility of effective deduplication in the CSP. In fact, we show that we achieve a level of privacy that is stronger than current encryption techniques, while allowing the CSP to reduce the footprint of the data to 68% of the size of the original data. In addition to storing the data, the CSPs have other functionalities, such as file sharing and data recovery. In this thesis, we investigate the affect of DD on two functionalities of a CSP, 1)secure file sharing, and 2) differential privacy. We show that using DD, and tweaking it with using cryptographic methods, namely Message Authenticated Code (MAC), and symmetric encryption, a system using DD is able to provide cloud-assisted secure file sharing between two or more users. We show that our method achieves this goal with negligible point-to-point (P2P) transmission overhead, and preserving the deduplication potential on the cloud. We also show that DD can be used to provide differential privacy for sensitive data, such as energy consumption values in a smart grid environment, while allowing the CSP that stores the consumption values to deduplicate data. In both cases, we show that our method not only does not hinder the functionalities of the CSP, but also improving the performance of such systems by reducing the footprint of the stored data.

Read the paper · More papers on PaperTik