🤖 AI Summary
To address high network overhead, excessive cloud-side computational burden, and elevated latency caused by secure deduplication in encrypted cloud storage, this paper proposes a source-end deduplication paradigm. It migrates duplicate detection and lightweight proof-of-ownership (PoW) computation to client-side edge trusted execution environments (TEEs), integrating content-defined encryption (CDE), distributed fingerprint indexing, and an edge-coordination protocol to establish a cloud-edge collaborative, locality-aware deduplication architecture. This work is the first to achieve PoW offloading within TEEs and secure ciphertext fingerprint comparison, thereby breaking the traditional security-performance trade-off inherent in source-end or server-side approaches. Experimental results demonstrate that, compared to state-of-the-art schemes, the proposed solution reduces upload traffic by 72%, decreases cloud-side computational overhead by 65%, cuts end-to-end latency by 58%, and resists ciphertext-deduplication inference and PoW side-channel attacks.
📝 Abstract
Currently, an increasing number of users and enterprises are storing their data in the cloud but do not fully trust cloud providers with their data in plaintext form. To address this concern, they encrypt their data before uploading it to the cloud. However, encryption with different keys means that even identical data will become different ciphertexts, making deduplication less effective. Encrypted deduplication avoids this issue by ensuring that identical data chunks generate the same ciphertext with content-based keys, enabling the cloud to efficiently identify and remove duplicates even in encrypted form. Current encrypted data deduplication work can be classified into two types: target-based and source-based. Target-based encrypted deduplication requires clients to upload all encrypted chunks (the basic unit of deduplication) to the cloud with high network bandwidth overhead. Source-based deduplication involves clients uploading fingerprints (hashes) of encrypted chunks for duplicate checking and only uploading unique encrypted chunks, which reduces network transfer but introduces high latency and potential side-channel attacks, which need to be mitigated by Proof of Ownership (PoW), and high computing overhead of the cloud. So, reducing the latency and the overheads of network and cloud while ensuring security has become a significant challenge for secure data deduplication in cloud storage. In response to this challenge, we present PM-Dedup, a novel secure source-based deduplication approach that relocates a portion of the deduplication checking process and PoW tasks from the cloud to the trusted execution environments (TEEs) in the client-side edge servers. We also propose various designs to enhance the security and efficiency of data deduplication.