Data backup and recovery method and electronic equipment

By performing multiple backups and generating metadata in response to backup trigger events during the data backup and recovery process, data can be flexibly stored and recovered, solving the problems of lagging data protection and cumbersome operation in existing technologies, and achieving efficient and reliable data protection and recovery.

CN121387632AActive Publication Date: 2026-01-23INSPUR SUZHOU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202511950806.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-01-23
Estimated Expiration
2045-12-23

AI Technical Summary

Technical Problem

Existing data backup methods suffer from protection delays and cumbersome operations, making it difficult to meet the reliability and intelligence requirements of enterprises facing a surge in data volume and diversified business scenarios.

Method used

By responding to backup trigger events, the target data is backed up multiple times based on a preset backup strategy, generating backup data and metadata, which are then flexibly stored on a local or remote server. During the recovery phase, candidate version information is generated based on the backup metadata to accurately restore the target backup data.

Benefits of technology

It achieves a complete data protection closed loop from intelligent triggering and flexible storage to accurate recovery, improving the automation level of data protection and the reliability of recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121387632A_ABST
    Figure CN121387632A_ABST
Patent Text Reader

Abstract

The invention provides a data backup and recovery method and electronic equipment, which can be applied to the technical field of information. The data backup and recovery method comprises the following steps: in response to a detected backup trigger event, performing multiple times of backup on target data based on a preset backup strategy corresponding to the backup trigger event to obtain multiple pieces of backup data and backup metadata for respectively indexing the multiple pieces of backup data; storing the plurality of backup data in at least one of a local storage medium and a remote backup server, and storing the plurality of backup metadata in the remote backup server; in response to the detected backup recovery event, generating multiple pieces of candidate backup version information based on the multiple pieces of backup metadata; and in response to a recovery instruction for target backup version information in the multiple pieces of candidate backup version information, recovering target backup data corresponding to the target backup version information based on target backup metadata corresponding to the target backup version information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information technology, specifically to a data backup and recovery method and an electronic device. Background Technology

[0002] In the field of information technology, data backup is crucial for ensuring business continuity. However, existing data backup methods suffer from potential data loss risks, such as delayed protection and cumbersome operation.

[0003] As enterprise data volumes surge and business scenarios diversify, data protection needs become increasingly complex. Therefore, existing data backup methods are no longer sufficient to meet reliability and intelligence requirements, necessitating more timely and intelligent data protection measures. Summary of the Invention

[0004] In view of the above problems, this application provides a data backup and recovery method and electronic device to improve the reliability and flexibility of data backup.

[0005] According to a first aspect of this application, a data backup and recovery method is provided, comprising: in response to detecting a backup trigger event, performing multiple backups of target data based on a preset backup strategy corresponding to the backup trigger event to obtain multiple backup data and backup metadata for indexing the multiple backup data respectively; storing the multiple backup data in at least one of a local storage medium and a remote backup server, and storing the multiple backup metadata in the remote backup server; in response to detecting a backup recovery event, generating multiple candidate backup version information based on the multiple backup metadata; and in response to a recovery instruction for a target backup version information among the multiple candidate backup version information, recovering the target backup data corresponding to the target backup version information based on the target backup metadata corresponding to the target backup version information.

[0006] A second aspect of this application provides a data backup and recovery apparatus, comprising: a data backup module, configured to, in response to detecting a backup trigger event, perform multiple backups of target data based on a preset backup strategy corresponding to the backup trigger event, to obtain multiple backup data and backup metadata for indexing the multiple backup data respectively; a data storage module, configured to store the multiple backup data in at least one of a local storage medium and a remote backup server, and to store the multiple backup metadata in the remote backup server; a version generation module, configured to, in response to detecting a backup recovery event, generate multiple candidate backup version information based on the multiple backup metadata; and a data recovery module, configured to, in response to a recovery command for a target backup version information among the multiple candidate backup version information, recover the target backup data corresponding to the target backup version information based on the target backup metadata corresponding to the target backup version information.

[0007] A third aspect of this application provides an electronic device, a memory configured to store instructions, and a processor connected to the memory, the processor being configured to execute instructions to perform the following operations: in response to detecting a backup trigger event, performing multiple backups of target data based on a preset backup strategy corresponding to the backup trigger event, obtaining multiple backup data and backup metadata for indexing the multiple backup data respectively; storing the multiple backup data in at least one of a local storage medium and a remote backup server, and storing the multiple backup metadata in the remote backup server; in response to detecting a backup recovery event, generating multiple candidate backup version information based on the multiple backup metadata; and in response to a recovery instruction for a target backup version information among the multiple candidate backup version information, recovering the target backup data corresponding to the target backup version information based on the target backup metadata corresponding to the target backup version information.

[0008] A fourth aspect of this application also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.

[0009] In this embodiment, by responding to various backup trigger events and performing multiple backups of the target data according to a preset backup strategy, backup data and corresponding backup metadata are generated. The backup data is flexibly stored on local storage media or remote servers, and all backup metadata is centrally stored on remote servers. During the recovery phase, candidate version information is generated based on the backup metadata, and the target backup data is accurately restored according to the user's selection using the corresponding backup metadata. This achieves a complete data protection closed loop from intelligent triggering and flexible storage to accurate recovery, comprehensively improving the automation level of data protection and the reliability of recovery. Attached Figure Description

[0010] The above-mentioned contents, other objects, features and advantages of this application will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0011] Figure 1 This illustration schematically depicts an application scenario of a data backup and recovery method and an electronic device according to embodiments of this application.

[0012] Figure 2 A flowchart illustrating a data backup and recovery method according to an embodiment of this application is shown schematically;

[0013] Figure 3 A flowchart illustrating the deployment of a baseline backup strategy according to an embodiment of this application is shown schematically.

[0014] Figure 4 A flowchart illustrating a file backup triggering process according to an embodiment of this application is shown schematically.

[0015] Figure 5 This illustration schematically shows a flowchart of backup data storage to a local storage medium according to an embodiment of this application;

[0016] Figure 6 A flowchart illustrating the restoration of target backup data according to an embodiment of this application is shown schematically.

[0017] Figure 7 A flowchart illustrating system-level backup data recovery according to an embodiment of this application is shown schematically;

[0018] Figure 8 A flowchart illustrating the forced installation of a backup client according to an embodiment of this application is shown schematically;

[0019] Figure 9 This illustration schematically shows a system architecture diagram of a data backup and recovery method according to an embodiment of this application;

[0020] Figure 10 This schematic diagram illustrates a structural block diagram of a data backup and recovery method apparatus according to an embodiment of this application;

[0021] Figure 11 A block diagram schematically illustrates an electronic device suitable for implementing a data backup and recovery method according to an embodiment of this application. Detailed Implementation

[0022] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely examples and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.

[0023] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0024] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0025] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0026] Embodiments of this application provide a data backup and recovery method and an electronic device.

[0027] Figure 1 The diagram illustrates an application scenario of the data backup and recovery method according to an embodiment of this application.

[0028] like Figure 1 As shown, application scenario 100 according to this embodiment includes an interaction scenario between a terminal device and a backup service system, specifically including a terminal device 101, a network 102, and a remote backup server 103. Network 102 is the communication medium between the terminal device 101 and the remote backup server 103. Network 102 can include various connection types, such as wired or wireless communication links or fiber optic cables.

[0029] It should be noted that, Figure 1 For illustrative purposes only, the number of terminal devices 101 and remote backup servers 103 is unlimited. In actual deployment, there can be any number of terminal devices 101, such as hundreds or thousands of various employee computers, R&D workstations, mobile office devices, etc. within an enterprise; similarly, the remote backup server 103 can be a cluster or distributed system composed of multiple servers to provide highly available and scalable service capabilities. The core of this architecture lies in the logical service provision and usage relationship, rather than the physical quantity correspondence.

[0030] In this application scenario, let's take the personal computers used by employees in a corporate office environment as an example. Terminal device 101 is the core device for users to perform daily tasks such as document editing and data processing, and various applications run on it.

[0031] As the central hub for enterprise data protection, remote backup server 103 is responsible for receiving, storing, and managing baseline backup policies issued by the security management server. These policies are pre-configured and generated by the security management server based on the attributes of terminal device 101, such as device type, storage capacity, and the user's role and data access permissions within the enterprise. When terminal device 101 detects a backup event triggered by a user or by a specific application file operation, it performs a backup of the target data being processed according to the corresponding backup policy, generating time-stamped backup data and its indexed backup metadata.

[0032] The generated backup data is stored locally on the terminal or uploaded to a remote backup server 103. Simultaneously, critical backup metadata is uploaded to the server for centralized management. When a user needs to recover data due to accidental deletion, file corruption, or system failure, the backup metadata can be retrieved from the remote backup server 103 to generate a list of recoverable versions. After the user selects the target version, the program locates and retrieves the backup data based on the corresponding backup metadata, ultimately completing the data restoration.

[0033] Through the aforementioned mechanism of intelligent sensing triggering on the terminal side, collaborative management of cloud policies, and centralized maintenance of backup metadata, automated and policy-based protection and convenient recovery of terminal business data are achieved, effectively ensuring the security of enterprise core data assets and business continuity without the need for full-time administrator intervention.

[0034] The following will be based on Figure 1 The described scene, through Figures 2-9 The data backup and recovery method of the disclosed embodiments will be described in detail.

[0035] Figure 2 A flowchart illustrating a data backup and recovery method according to an embodiment of this application is shown schematically.

[0036] like Figure 2 As shown, the data backup and recovery method of this embodiment includes operations S210 to S240.

[0037] In operation S210, in response to the detection of a backup trigger event, the target data is backed up multiple times based on the preset backup strategy corresponding to the backup trigger event, resulting in multiple backup data and backup metadata used to index the multiple backup data respectively.

[0038] In this embodiment, in response to the detection of a backup trigger event, a backup program set on the terminal can be used to perform multiple backups of the target data based on a preset backup strategy corresponding to the backup trigger event. When a backup trigger event is detected, the backup program deployed on the terminal is started. The backup program determines the scope of the target data to be protected and the backup rules according to the preset backup strategy bound to the backup trigger event. The target data is backed up according to the preset backup strategy, generating corresponding backup data and simultaneously creating backup metadata for describing and locating the backup data.

[0039] It should be noted that the terminal can be a user device running a backup program, such as a personal computer or mobile device; the backup program set up on the terminal can be a software module installed and running on the terminal device, responsible for performing data backup-related acquisition, processing, and transmission operations. The preset backup strategy can be a predefined backup execution rule that specifies how to perform backup operations when a specific triggering event occurs. The target data can be the selected data object that needs to be backed up and protected. The backup data can be a copy of the target data generated after backup processing. Backup metadata can be index information describing the attributes of the backup data, used to manage and retrieve the backup data.

[0040] In operation S220, multiple backup data are stored in at least one of local storage media and a remote backup server, and multiple backup metadata are stored in the remote backup server.

[0041] In this embodiment, the local storage medium can be a storage device inside the terminal device, such as a hard disk or a solid-state drive; the remote backup server can be an independent backup service device or cluster connected via a network, used to centrally store backup data and backup metadata.

[0042] In operation S230, in response to the detection of a backup recovery event, multiple candidate backup version information are generated based on multiple backup metadata.

[0043] In this embodiment, a backup recovery event refers to a specific condition or signal that triggers the data recovery process, such as a user-initiated recovery command, the system detecting data corruption or loss, or an automatic recovery process after the device completes system restoration. Backup metadata obtained from a remote backup server or local offline index file is parsed, and key features of the backup metadata are extracted, such as backup time, data size, integrity verification status, and association information with the backup strategy. Based on these key features, version entries that can be identified and selected by the user are constructed, such as a list of backup time points arranged in reverse chronological order, where each entry includes a version identifier or time identifier, a summary of the backup trigger reason, and a data status prompt.

[0044] In operation S240, in response to a recovery command for the target backup version information among multiple candidate backup version information, the target backup data corresponding to the target backup version information is recovered based on the target backup metadata corresponding to the target backup version information.

[0045] In this embodiment, based on multiple backup metadata stored on a remote backup server, version identification information contained in the backup metadata is extracted, sorted according to preset rules, and a candidate backup version information list containing multiple identifiable entries is generated and presented to the user for selection. When the user selects the target backup version information and issues a recovery command, the storage location of the target backup data is determined through the corresponding target backup metadata, the target backup data is read from the storage location, and the target backup data is restored to the path specified on the terminal according to the recovery configuration information in the target backup metadata.

[0046] In this embodiment, by responding to various backup trigger events and performing multiple backups of the target data according to a preset backup strategy, backup data and corresponding backup metadata are generated. The backup data is flexibly stored on local storage media or remote servers, and all backup metadata is centrally stored on remote servers. During the recovery phase, candidate version information is generated based on the backup metadata, and the target backup data is accurately restored according to the user's selection using the corresponding backup metadata. This achieves a complete data protection closed loop from intelligent triggering and flexible storage to accurate recovery, comprehensively improving the automation level of data protection and the reliability of recovery.

[0047] The data backup and recovery methods, including operations S210 to S240, are described in detail below.

[0048] In this embodiment, the preset backup strategy corresponding to the backup trigger event in operation 210 can be determined as follows: when the backup trigger event is receiving an immediate backup instruction for the target data, the preset backup strategy is to immediately perform a backup operation on the target data after receiving the immediate backup instruction; when the backup trigger event is monitoring the operation status of a specified application process on a preset type file to switch from open to closed, and the terminal has not supplemented the baseline backup strategy, the preset backup strategy is to perform a backup operation on the preset type file according to the backup storage location and backup rules associated with the baseline backup strategy; when the backup trigger event is monitoring the operation status of a specified application process on a preset type file to switch from open to closed, and the terminal has supplemented the baseline backup strategy, the preset backup strategy is to perform a backup operation on the preset type file according to the backup storage location and backup rules associated with the supplemented baseline backup strategy; the baseline backup strategy is a default backup rule generated and issued by the security management server based on the device attribute information of the terminal and loaded on the terminal in read-only mode. The default backup rule includes a default backup storage root directory, a default data retention period, and a default compression and encryption algorithm. The security management server is a background service entity responsible for formulating and forcing the terminal to execute the baseline backup strategy.

[0049] In this embodiment, a backup program running on the terminal can supplement the baseline backup policy. The backup program can be a backup client, and the security management server can be a domain controller. The backup client is pushed and installed on the terminal through the domain controller, and the baseline backup policy is set for the corresponding backup client on the terminal through the group policy set by the domain controller. The group policy is centrally distributed to all terminals through the domain network by the domain controller, and the configuration management policy contained in the group policy is forcibly assigned. The domain controller is a core server based on Active Directory service, responsible for the centralized management of all terminals and user authentication and policy enforcement within the domain.

[0050] For example, the domain controller can formulate corresponding baseline backup policies based on the department or job function of the user corresponding to the terminal. The baseline backup policies include, but are not limited to, different backup policies for different file types, different backup time periods, and different data folders. The backup policies for different groups are converted into different group policies and imported into the terminal through the domain controller for activation.

[0051] It should be noted that the backup strategy established according to the organization's departments and division of responsibilities serves as the baseline backup strategy. For example, it can specify which folders and file types must be backed up, and the required backup time. For the backup needs of different end users within the same group, additional settings can be configured on the backup client interface based on the baseline backup strategy. For instance, folders, file types, and backup times outside the baseline backup strategy can all be set in the configuration interface.

[0052] It should be noted that users on the terminal are not allowed to modify the backup configuration already included in the baseline backup policy through the backup client. For example, users are not allowed to delete the policy that requires backup at a certain point in time. This point in time is the time point that the baseline backup policy determines when backup is required.

[0053] Figure 3 A flowchart illustrating the deployment of a baseline backup strategy according to an embodiment of this application is shown.

[0054] In the embodiments of this application, such as Figure 3 As shown, after the baseline backup policy deployment process begins, the domain controller checks whether the backup client is installed on the endpoint. If not, it automatically installs the backup client to the endpoint via domain push. After installation, the domain controller further checks whether the client configuration is complete; if not, it forcibly distributes the baseline backup policy through the domain policy and completes the configuration. After configuration, the backup client returns an acknowledgment signal, and the entire policy deployment process ends. The baseline backup policy deployment process ensures the unified, mandatory, and automated implementation of the baseline backup policy on endpoints within the enterprise.

[0055] In this embodiment, a one-time backup operation on a file or folder is performed by the user on the terminal. The file or folder being backed up may be outside the scope of the scheduled backup protection in the baseline backup strategy. A one-time, immediate backup is performed by directly right-clicking on the file or folder to be backed up and selecting the corresponding immediate backup option, without needing to configure a backup strategy in the backup software beforehand.

[0056] In this embodiment, the background service of the backup program monitors the processes of specific target programs, such as word processing software, spreadsheet software, office software, etc., as well as the specific types of documents that these target programs are editing and modifying, such as document formats, computer-aided design drawings, etc. When the target program completes the editing and modification operation of the specific type of document, it will save the file and then close the file. At the same time, the file changes from an open state to a closed state, indicating that the file has been closed after the relevant editing is completed. At this time, the background service of the backup program actively triggers the backup operation of the file.

[0057] Figure 4 A flowchart illustrating a file backup triggering method according to an embodiment of this application is shown schematically.

[0058] In the embodiments of this application, such as Figure 4 As shown, after the file backup triggering process begins, it continuously monitors specific file types and their associated editing program processes based on a specific file type whitelist. When a specific type of file that meets preset conditions is detected as being opened by a related program in the target file list, the status judgment phase begins. During the status judgment phase, if a specific type of file is detected as being open but not modified, the backup operation is not triggered; instead, monitoring of the file status continues. When it is detected that the target file has been edited and the user has saved and closed the file (i.e., the file status has changed from open to closed), it is determined that the file has been edited. A notification is sent to the backup client's background service to trigger the backup process. Upon receiving the notification, the backup client's background service immediately starts and performs a backup operation on the specific type of file that has been edited and closed. After the backup operation is completed, the entire file backup triggering process ends, achieving near real-time continuous data protection. This avoids the problems of high system resource consumption and user experience lag caused by frequent snapshots in traditional disk snapshot-based continuous data protection solutions.

[0059] It should be noted that this allows for seamless data file backup, achieving continuous data protection. Unlike traditional continuous data protection software, it does not require frequent disk snapshots, which consume significant system and disk resources, causing lag and impacting the user experience.

[0060] In this embodiment, for application file closing events, backup is performed according to the baseline backup policy when no baseline backup policy has been supplemented, and according to the supplemented policy when a baseline backup policy has been supplemented. The baseline backup policy is generated and distributed by the security management server based on terminal device attributes, and includes the default backup storage root directory, retention period, compression and encryption algorithms. This enables differentiated backup policy execution based on different triggering scenarios, ensuring the flexibility and compliance of backup operations.

[0061] In this embodiment of the application, the above operation 220 may further include: sending multiple backup metadata to a remote backup server for storage, and setting backup time identifiers for the multiple backup metadata according to the sending time; determining the target storage location of multiple backup data according to the storage location selection information of the backup data; writing the multiple backup data to the local storage medium when the target storage location is a local storage medium; and encrypting the multiple backup data when the target storage location is a remote backup server, and sending the encrypted backup data to the remote backup server for storage.

[0062] Figure 5 A flowchart illustrating the process of storing backup data to a local storage medium according to an embodiment of this application is shown.

[0063] In the embodiments of this application, such as Figure 5 As shown, the backup data storage process begins after a backup trigger event, determining the backup data based on the selected backup content. It then checks whether the preset storage destination for the backup data includes the terminal's local storage media. If the preset storage destination does not include local storage media, the process directly proceeds to the backup to backup server branch, storing and managing the backup data on the backup server, after which the process stops.

[0064] If the preset storage target includes local storage media, the process further determines whether backup settings allow backup to local storage media. If the result is yes, the process proceeds to the "Write to Local Storage Media" branch, where backup data is written to the local storage media and encrypted during the backup process. Simultaneously, the "Backup to Backup Server" branch is executed. If the result is no, a message indicates that backup is not allowed to be stored on local storage media, and the local backup terminates, but the "Backup to Backup Server" branch continues. The backup data storage process stops after completing the corresponding branch operation.

[0065] In this embodiment, backup metadata is uniformly sent to a remote backup server for storage and a backup time identifier is set. At the same time, the storage location of the backup data is determined according to the storage location selection information: if local storage is selected, the backup data is written to the local storage medium; if remote storage is selected, the backup data is encrypted and sent to the remote backup server. This achieves centralized management and version identification of backup metadata, as well as flexible and secure storage of backup data, ensuring the reliability and confidentiality of backup data.

[0066] In this embodiment of the application, before determining the target storage location of multiple backup data based on the storage location selection information of the backup data, the method may further include: obtaining storage location selection information determined by the storage location selection operation input through the storage location selection interface of the terminal; or, obtaining the storage location selection information preset for the backup data in the preset backup strategy.

[0067] In this embodiment of the application, the storage location selection interface of the terminal backup program can be the storage location selection interface of the backup program running on the terminal. Before performing the backup operation, the backup program obtains the storage location selection information in one of the following two ways: one is to obtain the storage location selection information determined by the user after interactive operation through the storage location selection interface of the backup program; the other is to directly read the preset storage location selection information of the backup data from the preset backup strategy and use it as the basis for determining the target storage location.

[0068] For example, when starting the backup process, if the backup program uses a user-defined mode, it will present a graphical storage location selection interface, recording and retrieving the storage location selection information determined by the user's interactive operations such as path selection, drop-down menu selection, or manual input through this interface. If the policy execution mode is used, the backup program directly accesses the locally cached preset backup policy configuration file and parses the preset storage location selection information field for backup data. Regardless of the method of acquisition, this storage location selection information will ultimately serve as the basis for determining whether the backup data should be stored on local storage media or uploaded to a remote backup server.

[0069] In this embodiment, by obtaining storage location selection information input by the user or obtaining preset storage location selection information from a preset backup strategy, flexible configuration of storage location is achieved. This supports both user customization based on needs and automatic determination through preset strategies, thereby improving the convenience of backup operations and the consistency of strategy execution.

[0070] In this embodiment of the application, the above operation 230 may further include: when the backup recovery event is receiving a version viewing instruction for the target data, obtaining multiple backup metadata associated with the target data from the remote backup server; parsing the multiple backup metadata and extracting multiple backup time identifiers corresponding to the target data; and generating multiple candidate backup version information containing backup time identifiers.

[0071] In this embodiment of the application, when the backup recovery event is receiving a version viewing instruction for the target data, the backup client requests the remote backup server to obtain multiple backup metadata associated with the target data. After receiving the returned backup metadata, it performs parsing processing to extract multiple backup time identifiers contained therein, and generates multiple candidate backup version information containing complete time series information for the user to select based on these time identifiers.

[0072] For example, in the event that a version view instruction for the target data has not been received during a backup and recovery event, the backup client sends a metadata query request to the remote backup server via a secure communication protocol. This request carries a unique identifier for the target data. Upon receiving the request, the remote backup server retrieves all backup metadata records containing that identifier from its metadata database and returns them to the client. The backup client parses each of the retrieved backup metadata records, extracting precise backup time identifiers from specific fields, including the date and time of the backup operation. These time identifiers are then sorted and formatted to generate multiple candidate backup version information entries containing the backup time identifiers. These entries are presented in a list format on the client interface, with each version information entry including a readable time identifier and a corresponding version operation entry.

[0073] In this embodiment, by obtaining backup metadata associated with the target data from a remote backup server, parsing and extracting multiple backup time identifiers, and generating candidate backup version information containing backup time identifiers, a list of recoverable versions can be quickly generated based on centrally managed backup metadata. This provides users with a clear basis for version selection, improving the accuracy and efficiency of data recovery.

[0074] In this embodiment of the application, the operation 240 described above, which restores the target backup data corresponding to the target backup version information based on the target backup metadata, may further include: in response to a recovery command for the target version information, if the target backup metadata corresponding to the target backup version information is stored on a remote backup server, obtaining the target backup metadata corresponding to the target backup version information from the remote backup server; determining the storage location of the target backup data and reading the target backup data based on the obtained target backup metadata; and restoring the read target backup data to a specified local path or the original path of the target data based on the target backup metadata.

[0075] In this embodiment, the backup client is integrated into the right-click menu of the file manager, which displays the historical versions of the selected file or folder. Users can select the desired version to restore to the local machine or other specified paths.

[0076] In this embodiment, the local storage medium does not include backup metadata generated during backup. During off-site data restoration away from the organizational network environment, the external network interface of the backup environment can be used, or with the administrator's approval, the backup metadata can be exported and downloaded through a web interface. The backup metadata related to the data backup in the local storage medium is exported to the local storage medium, and then the backup data on the local storage medium is restored through the backup client on the terminal. The restoration process also involves using the user's domain certificate to decrypt the encrypted backup data. This decryption process is transparent to the user.

[0077] Figure 6 A flowchart illustrating the restoration of target backup data according to an embodiment of this application is shown.

[0078] In the embodiments of this application, such as Figure 6As shown, the target backup data restoration process begins with a restoration trigger event. Based on the target backup version information selected by the user, it determines whether the backup data to be restored originates from local storage media. If it is not local storage media, the process redirects to the backup server or media management server to retrieve the data. If it is indeed local storage media, the process further verifies whether the local storage media, such as external hard drives, CD burners, or tape drives, is correctly connected and ready. If the local storage media is not ready, the user is prompted to prepare a valid local storage media, and the target backup data restoration process is suspended. If the local storage media is ready, the encrypted backup data is read from the local storage media, and the data structure and encryption parameters are parsed based on the backup metadata obtained from the backup server or exported locally. The user's domain certificate is then used to complete transparent decryption, and the data is restored to the target location according to the original path recorded in the backup metadata or the path specified by the user. During the target backup restoration process, the status of the local storage media and the integrity of the backup data are continuously monitored. If an anomaly is detected, the process is paused, and the user is prompted to intervene. The target backup data restoration process ends after all data has been restored and passed verification.

[0079] In this embodiment, by obtaining the target backup metadata corresponding to the target backup version information from the remote backup server, determining the storage location of the backup data based on the backup metadata, reading the data, and restoring the data to the specified local path or the original path, the accurate location and recovery of backup data based on centrally managed backup metadata is achieved, ensuring the reliability and path accuracy of the data recovery process.

[0080] In this embodiment, a system restore identifier is created; when the terminal's operating system is first started after being restored from a system image, the system restore identifier is detected; in response to the detection of the system restore identifier and the backup recovery event, multiple candidate backup version information of the target data is generated; after receiving a recovery confirmation instruction or a recovery cancellation instruction for the multiple candidate backup version information, the system restore identifier is cleared.

[0081] In this embodiment, before backing up the operating system image, the backup client marks the system backup process, such as writing a key value to the registry, creating a specific file, or leaving a corresponding record in a file. When the terminal experiences disk failure or other damage to the original storage medium, and after restoring using the operating system backup image, the backup client service, upon startup with the operating system, determines that the operating system is in a newly restored state through corresponding markers. When the user logs into the operating system through a domain environment or completes identity verification through other means, the backup client service automatically launches the user interface.

[0082] The user is prompted to restore the backed-up file-level data. Depending on their situation—for example, if the operating system corruption wasn't caused by a damaged terminal disk, but rather by a crash on the C drive while data exists on other hard drives—the user only needs to restore files in the C drive, such as the user folder, desktop, and My Documents. The user can select the data to restore and the corresponding version, such as the latest or a version from a previous point in time, before proceeding with the data restoration. Alternatively, the user can choose not to restore any data and exit directly. Any choice made by the user will cause the backup client to clear the backup identifier from the restored operating system to prevent the restore interface from popping up again when the user logs into the operating system later.

[0083] Figure 7 A flowchart illustrating system-level backup data recovery according to an embodiment of this application is shown schematically.

[0084] In the embodiments of this application, such as Figure 7 As shown, the system-level backup data recovery process begins with the user logging into a terminal that has already completed an operating system restore. After the operating system boots up, the terminal's built-in backup client service runs automatically and checks for the existence of a pre-created system restore identifier. Restore identifiers may exist in various forms, such as writing specific key values ​​to the system registry, creating marker files in the file system, or leaving corresponding records in configuration files.

[0085] If a system restore flag is detected, the backup client automatically starts and provides the user with several optional actions. These actions typically include selectively restoring backed-up file-level data; for example, the user can choose to restore only the data in the affected user folders, desktop, and document directory on the system drive, or they can choose to restore the full backup. Alternatively, the user can choose not to restore any data and exit the interface directly. After the user makes a selection, the backup client service clears the operating system restore flag, effectively preventing the restore interface from being triggered again when the user logs back into the system, ensuring the one-time nature and deterministic nature of the recovery process.

[0086] If the user chooses to restore data, the backup client will perform the data recovery operation based on the backup version selected by the user, such as the latest version or a version at a specific point in time, and will simultaneously clear the restore flag after the data recovery operation is completed; if the user chooses not to restore, the backup client will directly clear the flag and end the process.

[0087] In this embodiment, a system restore identifier is created and detected during the first startup after system image restoration. When the identifier is detected and a backup recovery event is detected, candidate backup version information is generated. The identifier is cleared after receiving a recovery confirmation or cancellation instruction. This realizes the automatic triggering and status management of the backup recovery process in the system restore scenario, ensuring the timely recovery of user data and the integrity of the process after system recovery.

[0088] In this embodiment of the application, in response to detecting a system restore identifier and a backup recovery event, generating multiple candidate backup version information of the target data may further include: when the backup recovery event is the receipt of a backup recovery instruction for the target data, determining a preset time range based on the time when the operating system is restored through a system image as the target time period; obtaining multiple backup metadata created within the target time period and associated with the terminal from a remote backup server; parsing the multiple backup metadata to generate multiple candidate backup version information of the target data.

[0089] In this embodiment, when the backup and recovery process is triggered after system restoration, the backup client first uses the moment the system image restoration is completed as the time reference point, and extends forward and backward by a preset time window as the target time period. It then sends a query request to the remote backup server to obtain all terminal-related backup metadata generated within the target time period. By parsing and processing the backup metadata, it extracts key information such as backup time, file information, and version identifiers, constructing and presenting a candidate backup version list containing multiple historical versions for the user to choose from.

[0090] For example, when a user logs into a terminal that has just completed an operating system restore and triggers a data recovery command, the backup client automatically reads the system restore event log to obtain the time T when the operating system image restore was completed. Based on time T, and according to a preset strategy (e.g., the default setting is T-24 hours to time T), the target time period is dynamically determined. A query request is sent to the remote backup server through a secure channel. The query request parameters include the terminal device identifier and the target time range for that terminal device. The remote backup server retrieves all backup metadata records generated by the backup client on that terminal device within the target time period from its backup metadata database and returns the result set to the backup client.

[0091] After receiving the backup metadata set, the backup client executes a parsing engine to perform structured processing on the metadata set. First, it filters out records that match the target data type the user needs to restore. Then, it extracts information such as the backup timestamp, data integrity check value, storage location index, and associated backup policy identifier from each record. Based on this information, it generates a candidate backup version information list arranged in reverse chronological order. This list includes version time, data status information, and a recovery operation entry point. Users can intuitively understand the multiple historical states of the target data before system restoration through the candidate backup version information list and select a specific version to restore.

[0092] In this embodiment, by determining a target time period based on the system image restoration time, obtaining backup metadata related to the terminal within that time period from the remote backup server, and parsing to generate candidate backup version information, intelligent filtering and presentation of backup versions for relevant time periods are achieved in system recovery scenarios, thereby improving the targeting and timeliness of data recovery.

[0093] In this embodiment, the data backup status of the terminal is monitored according to the network security policy component of the terminal; if it is determined that the data backup status does not meet the preset backup requirements, the network access permissions or function usage permissions of the terminal are restricted by the network security policy component until the data backup status is restored to meet the preset backup requirements.

[0094] In this embodiment, monitoring of data backup status is achieved through the following technical means: The network security policy component obtains configuration and runtime information related to the data backup function by accessing the terminal's system interface. For example, it checks whether there is an activated backup task plan that conforms to a preset policy, verifies whether the local or remote storage path used for backup operations is accessible, or confirms that the timestamp of the most recent successful backup operation is within the allowed time window. If any of the above checks fails to meet the threshold or condition set by the preset backup requirements, the data backup status is determined to be unacceptable. The network security policy component triggers the access control module to strategically block the terminal's network connection or restrict specific system functions. The network security policy component continuously monitors the above checks, and automatically removes the relevant restrictions when all checks meet the preset rules.

[0095] In this embodiment, the installation status of the backup program can also be monitored according to the network security policy component of the terminal; if it is determined that the backup program is not installed, the network access permissions or function usage permissions of the terminal can be restricted through the network security policy component until the backup program is installed and running.

[0096] In this embodiment, the network security policy component includes internet behavior management software and a security assistant. To prevent the inability to back up and protect user data due to the lack of a backup client on the terminal, the backup client program is added to the monitoring list of the organization's internal security assistant or user internet behavior management software. This requires the terminal to have the backup client installed before accessing the organization's intranet or performing any operations. If the backup client is not installed, the security assistant or user internet behavior management software will guide the user to install it, thereby achieving full coverage of data backup.

[0097] Figure 8 A flowchart illustrating the forced installation of a backup client according to an embodiment of this application is shown.

[0098] In the embodiments of this application, such as Figure 8 As shown, the process of forcibly installing the backup client begins with a compliance check by the internet access management software when a terminal accesses the organization's intranet. The compliance check first determines whether the terminal device has the specified backup client program installed. If the check indicates that the terminal has the backup client installed, the internet access management software allows the terminal to access the organization's intranet, and the process ends normally.

[0099] If the check reveals that the backup client is not installed on the terminal, the internet behavior management software will immediately send a clear installation reminder to the user, prompting them to complete the installation of the backup client to meet organizational security policy requirements. The software monitors whether the user completes the backup client installation within the specified response time.

[0100] If the user completes the installation of the backup client after receiving the notification, the Internet access management software will allow the terminal to access the organization's intranet after verifying the installation's validity. Conversely, if the user fails to complete the installation within the required time, the Internet access management software will enforce access control policies and deny the terminal access to the organization's intranet. Regardless of whether access is ultimately allowed, the forced installation check process ends after performing the corresponding operations.

[0101] In this embodiment, the data backup status of the terminal is monitored by a network security policy component. When the data backup status is detected to be inconsistent with the preset backup requirements, the network access or function usage permissions of the terminal are restricted. This realizes the mandatory deployment and execution guarantee of the backup policy, ensures that the terminal device meets the data protection requirements, and improves the overall compliance of enterprise data security.

[0102] In this embodiment, when backing up target data based on a preset backup strategy, the system resource status of the terminal is evaluated. Based on the evaluation results and a predetermined resource scheduling strategy, multiple concurrent or consecutive backup tasks are queued or their priorities adjusted to control the peak system resource usage of the backup tasks. The predetermined resource scheduling strategy includes assigning higher priority to backup tasks triggered by immediate backup commands than to backup tasks triggered by timed strategies; and / or, delaying the execution of non-urgent backup tasks when system resource usage exceeds a threshold.

[0103] In this embodiment, when the backup client performs a backup task, it monitors key system resource indicators such as CPU utilization, memory usage, and disk I / O in real time. Based on the monitoring data and the preset resource scheduling strategy, it dynamically sorts and prioritizes backup tasks that are initiated simultaneously or queued continuously, placing user-initiated instant backup tasks before scheduled backup tasks, and automatically suspending non-critical backup tasks when the system resource load exceeds a safety threshold.

[0104] For example, the backup client has a built-in resource monitoring module that continuously collects real-time resource data from the terminal, including CPU utilization, available memory capacity, disk queue length, and network bandwidth usage. When multiple backup tasks are triggered concurrently, they are intelligently sorted according to a predetermined resource scheduling strategy. First, the task type is identified, and backup tasks triggered by immediate backup commands are assigned the highest priority to ensure they immediately enter the execution queue. For regular tasks triggered by timed policies, they are dynamically queued according to their set time tolerance. At the same time, the system resource usage is compared with the preset threshold in real time. Once resource overload is detected, the execution of all non-urgent backup tasks is immediately suspended, and their status is set to delayed until the system resources recover to a safe level before they can be rescheduled. This achieves a balance between backup efficiency and system performance by dynamically scheduling backup tasks, prioritizing immediate backups and delaying non-critical tasks when the system is under high load.

[0105] Figure 9 A schematic diagram illustrating the system architecture of a data backup and recovery method according to an embodiment of this application is provided.

[0106] In the embodiments of this application, such as Figure 9 As shown in the diagram, 1-8 respectively identify the wide area network (WAN), remote backup server, remote storage media, local storage media, client 1, local storage media, client 2, and client 3 that connect the system architecture. The data backup and recovery system architecture consists of the WAN, the organizational intranet (composed of client 1, local storage media, client 2, and client 3), and various entities deployed at different network layers. The WAN houses the remote backup server and its associated remote storage media. This server acts as a centralized backup management node, responsible for receiving and storing backup metadata from various terminals and providing cross-network backup data storage and recovery services when needed. The organizational intranet constitutes the enterprise's local network environment, connecting multiple terminal clients and local storage media.

[0107] Specifically, the organization's intranet contains at least three client terminals (Client 1, Client 2, and Client 3), each with a backup program installed, capable of performing local data backup and recovery operations. These clients can choose to write backup data to local storage media directly connected to them, or upload backup data to a remote backup server for centralized storage via the organization's intranet and wide area network. Simultaneously, backup metadata generated by each client during the backup process must be sent to the remote backup server for unified management and maintenance.

[0108] In recovery scenarios, clients can access a remote backup server via the organization's intranet to obtain the required backup metadata version. Following the metadata's guidance, they can then read the corresponding backup data from local or remote storage media to complete data restoration. This system architecture supports both distributed, localized, rapid backup and recovery, and centralized cloud data management and cross-network disaster recovery capabilities, achieving flexibility in backup storage location, uniformity in metadata management, and controllability in the recovery process. Through hierarchical network design and resource distribution, the overall architecture ensures backup efficiency while also considering data security, ease of management, and system scalability.

[0109] Based on the above data backup and recovery methods, this application also provides a data backup and recovery method apparatus. The following will be combined with... Figure 10 The device is described in detail.

[0110] Figure 10 A schematic block diagram of a data backup and recovery method apparatus according to an embodiment of this application is shown.

[0111] like Figure 10 As shown, the data backup and recovery method apparatus 1000 of this embodiment includes a data backup module 1010, a data storage module 1020, a version generation module 1030, and a data recovery module 1040.

[0112] The data backup module 1010 is used to respond to the detection of a backup trigger event, and based on a preset backup strategy corresponding to the backup trigger event, to perform multiple backups of the target data, resulting in multiple backup data and backup metadata for indexing the multiple backup data respectively. In one embodiment, the data backup module 1010 can be used to perform the operation S210 described above, which will not be repeated here.

[0113] The data storage module 1020 is used to store multiple backup data in at least one of a local storage medium and a remote backup server, and to store multiple backup metadata in the remote backup server. In one embodiment, the data storage module 1020 can be used to perform the operation S220 described above, which will not be repeated here.

[0114] The version generation module 1030 is used to generate multiple candidate backup version information based on multiple backup metadata in response to the detection of a backup recovery event. In one embodiment, the version generation module 1030 can be used to perform the operation S230 described above, which will not be repeated here.

[0115] The data recovery module 1040 is used to respond to a recovery command for a target backup version information among multiple candidate backup version information, and to recover the target backup data corresponding to the target backup version information based on the target backup metadata corresponding to the target backup version information. In one embodiment, the data recovery module 1040 can be used to perform the operation S240 described above, which will not be repeated here.

[0116] According to embodiments of this application, any multiple modules among the data backup module 1010, data storage module 1020, version generation module 1030, and data recovery module 1040 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this application, at least one of the data backup module 1010, data storage module 1020, version generation module 1030, and data recovery module 1040 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the data backup module 1010, data storage module 1020, version generation module 1030, and data recovery module 1040 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.

[0117] Figure 11 A block diagram schematically illustrates an electronic device suitable for implementing a data backup and recovery method according to an embodiment of this application.

[0118] like Figure 11 As shown, an electronic device 1100 according to an embodiment of this application includes a processor 1101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1102 or a program loaded from a storage portion 1108 into a random access memory (RAM) 1103. The processor 1101 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1101 may also include onboard memory for caching purposes. The processor 1101 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.

[0119] RAM 1103 stores various programs and data required for the operation of electronic device 1100. Processor 1101, ROM 1102, and RAM 1103 are interconnected via bus 1104. Processor 1101 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 1102 and / or RAM 1103. It should be noted that programs may also be stored in one or more memories other than ROM 1102 and RAM 1103. Processor 1101 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in one or more memories.

[0120] According to embodiments of this application, the electronic device 1100 may further include an input / output (I / O) interface 1105, which is also connected to a bus 1104. The electronic device 1100 may also include one or more of the following components connected to the input / output (I / O) interface 1105: an input section 1106 including a keyboard, mouse, etc.; an output section 1107 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1108 including a hard disk, etc.; and a communication section 1109 including a network interface card such as a LAN card, modem, etc. The communication section 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to the input / output (I / O) interface 1105 as needed. A removable medium 1111, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1110 as needed so that computer programs read from it can be installed into the storage section 1108 as needed.

[0121] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.

[0122] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM1102 and / or RAM1103 and / or one or more memories other than ROM1102 and RAM1103 described above.

[0123] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the methods provided in the embodiments of this application.

[0124] When the computer program is executed by the processor 1101, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0125] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 1109, and / or installed from the removable medium 1111. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0126] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1109, and / or installed from the removable medium 1111. When the computer program is executed by the processor 1101, it performs the functions defined in the system of this application embodiment. According to the embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0127] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0128] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0129] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.

[0130] The embodiments of this application have been described above. However, these embodiments are merely illustrative and not intended to limit the scope of this application. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of this application, those skilled in the art can make various substitutions and modifications, all of which should fall within the scope of this application.

Claims

1. A data backup and recovery method, characterized in that, Applied to a terminal, the method includes: In response to the detection of a backup trigger event, the target data is backed up multiple times based on a preset backup strategy corresponding to the backup trigger event, resulting in multiple backup data and backup metadata for indexing the multiple backup data respectively. The plurality of backup data are stored in at least one of a local storage medium and a remote backup server, and the plurality of backup metadata are stored in the remote backup server; In response to the detection of a backup recovery event, multiple candidate backup version information are generated based on the multiple backup metadata. In response to a recovery command for a target backup version among the plurality of candidate backup version information, target backup data corresponding to the target backup version information is recovered based on the target backup metadata corresponding to the target backup version information.

2. The method according to claim 1, characterized in that, The preset backup strategy corresponding to the backup trigger event is determined in the following manner: When the backup trigger event is receiving an immediate backup instruction for the target data, the preset backup strategy is to immediately perform a backup operation on the target data after receiving the immediate backup instruction. When the backup trigger event is that the operation status of a specified application process on a preset type of file changes from open to closed, and the terminal does not supplement the baseline backup strategy, the preset backup strategy is to perform backup operations on the preset type of file according to the backup storage location and backup rules associated with the baseline backup strategy. When the backup trigger event is that the operation status of a specified application process on a preset type of file is switched from open to closed, and the terminal has supplemented the baseline backup strategy, the preset backup strategy is to perform backup operations on the preset type of file according to the backup storage location and backup rules associated with the supplemented baseline backup strategy. The baseline backup policy is a default backup rule generated and issued by the security management server based on the device attribute information of the terminal and loaded on the terminal in read-only mode. The default backup rule includes the default backup storage root directory, the default data retention period, and the default compression and encryption algorithm. The security management server is a background service entity responsible for formulating and forcing the terminal to execute the baseline backup policy.

3. The method according to claim 1, characterized in that, The step of storing the plurality of backup data in at least one of a local storage medium and a remote backup server, and storing the plurality of backup metadata in the remote backup server, includes: The multiple backup metadata are sent to the remote backup server for storage, and the backup time identifier of the multiple backup metadata is set according to the sending time; Based on the storage location selection information of the backup data, the target storage location of the multiple backup data is determined; If the target storage location is the local storage medium, the plurality of backup data are written to the local storage medium; If the target storage location is the remote backup server, the multiple backup data are encrypted, and the encrypted backup data is sent to the remote backup server for storage.

4. The method according to claim 3, characterized in that, Before determining the target storage location of the plurality of backup data based on the storage location selection information of the backup data, the method further includes: Obtain the storage location selection information determined by inputting a storage location selection operation through the storage location selection interface of the terminal; or, Obtain the storage location selection information preset for the backup data in the preset backup strategy.

5. The method according to claim 1, characterized in that, In response to detecting a backup recovery event, generating multiple candidate backup version information based on the multiple backup metadata includes: In the event that the backup recovery event is receiving a version viewing instruction for the target data, multiple backup metadata associated with the target data are obtained from the remote backup server; Parse the multiple backup metadata and extract multiple backup time identifiers corresponding to the target data; Generate multiple candidate backup version information containing the backup time identifier.

6. The method according to claim 1, characterized in that, Based on the target backup metadata corresponding to the target backup version information, restoring the target backup data corresponding to the target backup version information includes: In response to a recovery command for the target version information, if the target backup metadata corresponding to the target backup version information is stored on the remote backup server, the target backup metadata corresponding to the target backup version information is obtained from the remote backup server. Based on the acquired target backup metadata, determine the storage location of the target backup data and read the target backup data; Based on the target backup metadata, the read target backup data is restored to the specified local path or the original path of the target data.

7. The method according to claim 1, characterized in that, The method further includes: Create a system restore identifier; When the operating system of the terminal is booted for the first time after being restored from a system image, the system restore identifier is detected; In response to the detection of the system restore identifier and backup recovery event, multiple candidate backup version information of the target data is generated; Upon receiving a recovery confirmation instruction or a recovery cancellation instruction for the multiple candidate backup version information, the system restore identifier is cleared.

8. The method according to claim 7, characterized in that, In response to detecting the system restore identifier and backup recovery event, the generation of multiple candidate backup version information for the target data includes: When the backup and restore event is the receipt of a backup and restore instruction for the target data, a preset time range based on the time when the operating system is restored through the system image is determined as the target time period; Obtain multiple backup metadata created within the target time period and associated with the terminal from the remote backup server; The multiple backup metadata are parsed to generate multiple candidate backup version information for the target data.

9. The method according to claim 1, characterized in that, The method further includes: The data backup status of the terminal is monitored according to the network security policy component of the terminal; If it is determined that the data backup status does not meet the preset backup requirements, the network access permissions or function usage permissions of the terminal are restricted by the network security policy component until the data backup status is restored to meet the preset backup requirements.

10. An electronic device, characterized in that, include: One or more processors; Memory, used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the data backup and recovery method as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Converting backup copies of objects created using a first backup program to backup copies created using a second backup program

    CN101772758A

  • File control method and device, file recovery method and device and storage medium

    CN110888758A

  • Data backup and recovery method, electronic equipment and computer readable storage medium

    CN111045857A

  • Memory controller and method of operating the same

    CN112463436A

  • Data backup method, data export method, data recovery method, data backup device, data export device, data recovery device, equipment and medium

    CN116955006A

Cited By

  • Multi-node cooperative hot backup recovery method and device, equipment and storage medium

    CN122220153A