Balancing storage efficiency and data confidentiality with tunable encrypted deduplication
Jingwei Li, Zuoru Yang, Yanjing Ren, Patrick P. C. Lee, Xiaosong Zhang
Abstract
Conventional encrypted deduplication approaches retain the deduplication capability on duplicate chunks after encryption by always deriving the key for encryption/decryption from the chunk content, but such a deterministic nature causes information leakage due to frequency analysis. We present TED, a tunable encrypted deduplication primitive that provides a tunable mechanism for balancing the tradeoff between storage efficiency and data confidentiality. The core idea of TED is that its key derivation is based on not only the chunk content but also the number of duplicate chunk copies, such that duplicate chunks are encrypted by distinct keys in a controlled manner. In particular, TED allows users to configure a storage blowup factor, under which the information leakage quantified by an information-theoretic measure is minimized for any input workload. We implement an encrypted deduplication prototype TEDStore to realize TED in networked environments. Evaluation on real-world file system snapshots shows that TED effectively balances the trade-off between storage efficiency and data confidentiality, with small performance overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 269285a5-005b-4e10-a857-333cddc7737fCited by top-tier papers6
- Accelerating Encrypted Deduplication via SGXYanjing Ren, Jingwei Li, Zuoru Yang, Patrick P. C. Lee et al.USENIX ATC 2021 · 50 citations
- Secure and Lightweight Deduplicated Storage via Shielded Deduplication-Before-EncryptionZuoru Yang, Jingwei Li, Patrick P. C. LeeUSENIX ATC 2022 · 46 citations
- Light-Dedup: A Light-weight Inline Deduplication Framework for Non-Volatile Memory File SystemsJiansheng Qiu, Yanqi Pan, Wen Xia, Xiaojia Huang et al.USENIX ATC 2023 · 20 citations
- SimEnc: A High-Performance Similarity-Preserving Encryption Approach for Deduplication of Encrypted Docker ImagesTong Sun, Bowen Jiang, Borui Li, Jiamei Lv et al.USENIX ATC 2024 · 10 citations
- FeatureSpy: Detecting Learning-Content Attacks via Feature Inspection in Secure Deduplicated StorageJingwei Li, Yanjing Ren, Patrick P. C. Lee, Yuyu Wang et al.INFOCOM 2023 · 7 citations
Builds on2
Related papers
- Revisiting Frequency Analysis against Encrypted Deduplication via Statistical DistributionJingwei Li, Guoli Wei, Jiacheng Liang, Yanjing Ren et al.INFOCOM 2022 · 8 citations
- Breaking and Fixing Content-Defined ChunkingKien Tuong Truong, Simon-Philipp Merz, Matteo Scarlata, Felix Günther et al.CCS 2025
- TiDedup: A New Distributed Deduplication Architecture for CephMyoungwon Oh, Sungmin Lee, Samuel Just, Youngjin Yu et al.USENIX ATC 2023 · 23 citations
- Physical vs. Logical Indexing with IDEA: Inverted Deduplication-Aware IndexAsaf Levi, Philip Shilane, Sarai Sheinvald, Gala YadgarFAST 2024 · 7 citations
- Pancake: Frequency Smoothing for Encrypted Data StoresPaul Grubbs, Anurag Khandelwal, Marie-Sarah Lacharité, Lloyd Brown et al.USENIX Security 2020
