Method, electronic device and computer program product for restoring data
By selecting a target time point in the storage system and determining the changes in the data system, the current data system is overwritten, solving the problem of long data recovery time under large data volumes and achieving efficient data recovery.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- EMC IP HLDG CO LLC
- Filing Date
- 2021-04-21
- Publication Date
- 2026-06-12
AI Technical Summary
During data recovery, existing technologies require a significant amount of time to retrieve the target data backup from the backup repository when dealing with large amounts of data.
Select a target time point in the storage system, determine the changes in the data system from that time point to the current time point, and overwrite the data system at the current time point based on these changes, thereby reducing the amount of data that needs to be retrieved for data recovery.
By reducing the amount of data retrieved, an efficient data recovery process was achieved, improving the efficiency of data recovery.
Smart Images

Figure CN115220956B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this disclosure relate to the field of data storage, and more specifically, to methods, electronic devices, and computer program products for data recovery. Background Technology
[0002] In the field of data storage, data recovery is a crucial issue. Data recovery refers to retrieving a target data backup from a backup repository to restore the current data in the storage system to that backup. When the target data backup is large, retrieving it from the backup repository can take a considerable amount of time. Summary of the Invention
[0003] In a first aspect of this disclosure, a method for recovering data is provided. The method includes selecting a target time point from multiple backup time points at a storage system. The method also includes determining changes in the data system within the storage system from the target time point to the current time point. Furthermore, the method includes overwriting the data system at the current time point based on these changes.
[0004] In a second aspect of this disclosure, an electronic device is provided. The electronic device includes a processor and a memory coupled to the processor, the memory having instructions stored therein, the instructions causing the device to perform actions when executed by the processor. The actions include selecting a target time point from a plurality of backup time points in a storage system. The actions also include determining changes in the data system within the storage system from the target time point to the current time point. Furthermore, the actions include overwriting the data system at the current time point based on the changes.
[0005] In a third aspect of this disclosure, a computer program product is provided, which is tangibly stored on a computer-readable medium and includes machine-executable instructions that, when executed, cause a machine to perform the method according to the first aspect.
[0006] In the embodiments of this disclosure, the data recovery scheme of this application can reduce the amount of data that needs to be retrieved to restore the current data system to the backup at the target time point based on the changes in the data system since the target time point, thereby achieving efficient data recovery.
[0007] The summary section is provided to present the chosen concepts in a simplified form, which will be further described in the detailed description below. The summary section is not intended to identify key or principal features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Attached Figure Description
[0008] The above and other objects, features and advantages of the embodiments of the present disclosure will become more apparent from the accompanying drawings, in which like reference numerals generally denote like parts.
[0009] Figure 1 A schematic diagram of an example environment in which embodiments of the present disclosure can be implemented is shown;
[0010] Figure 2 A flowchart illustrating an example method for recovering data according to some embodiments of this disclosure is shown;
[0011] Figure 3 A schematic diagram illustrating the process of determining changes in a data system by merging change logs according to some embodiments of the present disclosure is shown;
[0012] Figure 4 A schematic diagram illustrates a process for determining changes in a data system by comparing mirrors according to some embodiments of the present disclosure;
[0013] Figure 5 A schematic diagram illustrating the process of determining changes in a data system through comparisons of hash tables according to some embodiments of the present disclosure; and
[0014] Figure 6 A block diagram of an example computing device that can be used to implement embodiments of the present disclosure is shown. Detailed Implementation
[0015] The principles of embodiments of this disclosure will now be described with reference to several exemplary embodiments illustrated in the accompanying drawings. While preferred embodiments of this disclosure are shown in the drawings, it should be understood that these embodiments are described merely to enable those skilled in the art to better understand and implement the embodiments of this disclosure, and are not intended to limit the scope of this disclosure in any way.
[0016] The term "comprising" and its variations as used herein signify open inclusion, i.e., "including but not limited to". Unless otherwise stated, the term "or" means "and / or". The term "based on" means "at least partially based on". The terms "one example embodiment" and "some embodiments" mean "at least one example embodiment". The term "another embodiment" means "at least one additional embodiment". The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.
[0017] As mentioned above, when the amount of data to be backed up is large, retrieving the data backup directly from the backup repository can take a considerable amount of time. Therefore, a solution is needed that can reduce the time required to restore the data.
[0018] According to embodiments of this disclosure, a target time point is selected from multiple backup time points at the storage system. In this approach, the changes in the data system within the storage system from the target time point to the current time point are determined. Based on these changes, the data system at the current time point is overwritten. In this manner, the amount of data required to restore the current data system to its backup state at the target time point can be reduced based on the changes in the data system since the target time point, thereby achieving efficient data recovery.
[0019] The following is for reference Figures 1 to 5 The present disclosure is provided to illustrate the basic principles and several exemplary embodiments. It should be understood that these exemplary embodiments are given only to enable those skilled in the art to better understand and implement the embodiments of the present disclosure, and are not intended to limit the scope of the disclosure in any way.
[0020] Figure 1 An example environment 100 in which embodiments of this disclosure can be implemented is shown. For example... Figure 1 As shown, environment 100 includes a storage system 110 and a backup repository 120. Storage system 110 may be main storage for storing user data. Backup repository 120 may be used to back up user data in storage system 110. Storage system 110 and backup repository 120 may utilize block-level or file-level data systems to store and manage user data. Backup repository 120 may include backups of the data system in storage system 110 at multiple backup points in time. Storage system 110 and backup repository 120 may be non-volatile storage devices. Storage system 110 and backup repository 120 may reside on different physical storage devices.
[0021] It should be understood that Figure 1 The environment 100 shown is merely exemplary and should not constitute any limitation on the functionality and scope of the implementation described in this disclosure.
[0022] Figure 2 A flowchart of an example method 200 for recovering data according to an embodiment of the present disclosure is shown. Method 200 can be implemented, for example, in... Figure 1 The example environment 100 shown is executed. It should be understood that method 200 may also include additional actions not shown and / or the actions shown may be omitted; the scope of this disclosure is not limited in this respect. The following is combined with… Figure 1 Let me describe method 200 in detail.
[0023] At box 210, a target time point is selected from multiple backup time points at storage system 110. Backup repository 120 may include multiple backups of the data system of storage system 110 at different backup time points. Storage system 110 can select a target time point from multiple backup time points according to user needs to restore the data system at the current time point to the data system at the target time point.
[0024] At box 220, determine the changes in the data system within storage system 110 from the target time point to the current time point. These changes can be file-level or block-level. Examples of file-level changes include file deletion, updates, additions, and renaming. Block-level changes can refer to the overwriting of data in a data block's fields. Various methods can be used to determine the changes in the data system between the target and current time points. The following will refer to... Figures 3-5 This describes in detail the process of determining the changes in the data system within storage system 110 from the target time point to the current time point.
[0025] In some embodiments, a change tracking program may be installed in the storage system 110 to track changes in the data system within the storage system 110 in real time. Figure 3 A schematic diagram illustrating a process for determining changes in a data system by merging change logs, according to some embodiments of this disclosure. Figure 3 Backups 311-315 (hereinafter collectively referred to as 310) of the data system at multiple backup points in backup repository 120 are shown. Backup 313, shown in gray, may be a backup of the data system at a target point in time. When data in storage system 110 is backed up, storage system 110 can record changes to the data system tracked between the previous backup and the current backup as a change log, for example, Figure 3 The change logs 322-326 (hereinafter collectively referred to as 320) are shown in the figure. As illustrated, change log 322 can be used to record changes to the data system tracked between the previous backup 311 and the current backup 312. Change log 320 can be stored in storage system 110. Storage system 110 can determine the changes to the data system between the target time point and the current time point by merging a set of change logs 330 between the target time point and the current time point. In this way, the changes to the data system between the target time point and the current time point can be determined using only the change logs stored in storage system 110, without needing to retrieve the backup at the target time point for comparison with the current data system.
[0026] In some embodiments, changes to the data system can be file-level changes. Change log 320 can record operations on files in the data system. For example, change log 324 can record that an update operation was performed on file A and a delete operation was performed on file B. Changes to the data system between a target time point and the current time point can refer to a list of operations on files in the data system between the target time point and the current time point. The list of file operations can be determined by merging a set of change logs 330.
[0027] In some embodiments, merging a set of change logs 330 may include merging update operations for the same file recorded in the set of change logs 330 prior to a deletion operation into a single deletion operation. For example, a first change log 324 records an update operation performed on file A, and a subsequent second change log 325 records a deletion operation performed on file A. In this case, when merging the first change log 324 and the second change log 325, the update operation and the deletion operation for file A can be merged into a single deletion operation for file A. Alternatively or additionally, merging a set of change logs 330 may include merging multiple update operations for the same file recorded in the set of change logs 330 into a single update operation. Alternatively or additionally, merging a set of change logs 330 may include merging multiple rename operations for the same file recorded in the set of change logs 330 into a single rename operation. Alternatively or additionally, a similar merging operation may be performed when recording changes to the data system between adjacent backups in the change log. In this way, duplicate information in the change logs 320 and the list of operations can be effectively reduced, thereby improving the efficiency of data recovery.
[0028] In some embodiments, changes to the data system can be at the data block level. Change log 320 can record changed fields within a data block of the data system. For example, change log 324 can record that field {64, 104857600} has changed, that is, the data in field {64, 104857600} has been overwritten. Changes to the data system between a target time point and the current time point can refer to a list of changed fields in the data system between the target time point and the current time point. The list of changed fields in the data system can be determined by merging a set of change logs 330. The list of changed fields can be determined by performing a union operation on the changed fields in a set of change logs 330. For example, a first change log 324 records the changed field A {64, 104857600}, and a subsequent second change log 325 records the changed field B {8, 104857600}. In this scenario, when merging the first change log 324 and the second change log 325, the changed field A {64, 104857600} and the changed field B {8, 104857600} can be merged into a single changed field {8, 104857600}. Additionally, a similar merging operation can be performed when recording changed fields in data blocks of the data system in change log 320. This effectively reduces duplicate information in the list of changed fields, thereby improving the efficiency of data recovery.
[0029] In some embodiments, built-in functions in the operating system can be used to determine changes to the data system without installing a change tracking program in the storage system 110. In some embodiments, the operating system's image generation function can be used to determine changes to the data system. Figure 4 A schematic diagram illustrates a process for determining changes in a data system by comparing mirror images according to some embodiments of this disclosure. Similarly, Figure 4 Backups 310 of the data system in backup repository 120 at multiple backup points in time are shown. Backup 313, shown in gray, may be a backup of the data system at a target point in time.
[0030] In some embodiments, when backing up the data system in storage system 110, an image of the data system at a specific point in time can be generated, for example... Figure 4The images 422-425 (hereinafter collectively referred to as 420) are shown in the diagram. Therefore, storage system 110 can store images 420 of the data system at different backup points in time. Image 423, shown in gray, can be the target image of the data system at the target point in time. To determine the changes in the data system from the target point in time to the current point in time, a temporary image 426 of the data system at the current point in time can be generated. By comparing the temporary image 426 of the data system at the current point in time with the image 423 of the data system at the target point in time, a list of fields that have changed in the data blocks of the data system between the target point in time and the current point in time can be determined. In this way, the changes in the data system between the target point in time and the current point in time can be determined using only the image 420 stored in storage system 110, without needing to retrieve the backup at the target point in time for comparison with the current data system.
[0031] In some embodiments, the hash table generation function of the operating system can be used to determine changes in the data system. Figure 5 A schematic diagram illustrates a process for determining changes in a data system by comparing hash tables according to some embodiments of this disclosure. Similarly, Figure 5 Backups 310 of the data system in backup repository 120 at multiple backup points in time are shown. Backup 313, shown in gray, may be a backup of the data system at a target point in time.
[0032] In some embodiments, when backing up the data system in storage system 110, a hash table of the data system at a corresponding point in time can be generated, for example... Figure 5 The hash tables 522-525 (hereinafter collectively referred to as 520) are shown below. Therefore, the storage system 110 can store hash tables 520 corresponding to the data system at different backup points in time. For example... Figure 5 As shown, a hash table can include a corresponding entry for each file in the data system. The hash table can have two attributes: a hash value generated based on the file data and the file path, and the file path string. A temporary hash table 526 for the data system at the current time point can be generated and compared with a target hash table 523 for the data system at the target time point to determine the changes in the data system from the target time point to the current time point.
[0033] In some embodiments, by comparing the temporary hash table 526 of the data system at the current time point with the target hash table 523 of the data system at the target time point, a list of operations on files in the data system between the target time point and the current time point can be determined. In some embodiments, files that have changed in the data system between the target time point and the current time point can be identified by comparing hash values in the hash tables, and the corresponding operations on the files can be determined. Since the generation of hash values is related to file data and file paths, files with the same hash value at the target time point and the current time point can be determined to be unchanged files. Furthermore, for entries of files that appear only in the target hash table 523, it can be determined that a deletion operation was performed on that file between the target time point and the current time point. For entries of files that appear only in the temporary hash table 526, it can be determined that the file was added between the target time point and the current time point. For entries of files that appear in both the temporary hash table 526 and the target hash table 523 but with different hash values, it can be determined that an update operation was performed on that file between the target time point and the current time point. In this way, the changes in the data system between the target time point and the current time point can be determined using only the hash table 520 stored in the storage system 110, without having to retrieve a backup from the target time point for comparison with the current data system.
[0034] Continue to refer to Figure 2 At box 230, the data system at the current point in time is overwritten based on changes. Storage system 110 can overwrite the data system at the current point in time based on changes to the data system between a target point in time and the current point in time. In some embodiments, changes to the data system can be a list of operations performed on files in the data system between the target point in time and the current point in time. For example, the list of operations could include a deletion operation on file A and an addition operation on file B.
[0035] In some embodiments, storage system 110 can retrieve file data corresponding to a list of operations from the backup of the data system at a target time point in backup repository 120. Storage system 110 can also overwrite the data system at the current time point by performing the reverse operation list on the data system at the current time point based on the file data. For example, storage system 110 can retrieve file data of file A from the backup of the data system at a target time point in backup repository 120 and perform the reverse operation corresponding to the deletion operation on file A on the data system at the current time point. In other words, storage system 110 can add the retrieved file data of file A to the data system at the current time point.
[0036] In some embodiments, depending on the type of operation, storage system 110 may not need to retrieve the file data corresponding to the list of operations from the backup of the data system at the target time point in the backup repository 120. Storage system 110 can overwrite the data system at the current time point by directly reversing the list of operations performed on the data system at the current time point. For example, for file B added between the target time point and the current time point, storage system 110 can directly perform a delete operation on the data system without retrieving any data from the backup repository. Therefore, by utilizing embodiments of this disclosure, the amount of data that needs to be retrieved for data recovery can be reduced, thereby improving the efficiency of data recovery.
[0037] In some embodiments, changes to the data system can be a list of fields that have changed in a data block of the data system between a target time point and the current time point. For example, the list of changed fields may include changed field A {64, 104857600} and changed field B {8, 104857600}. Storage system 110 can retrieve the list of changed fields from a backup of the data system at the target time point in backup repository 120. For example, storage system 110 can retrieve the data of field A {64, 104857600} and field B {8, 104857600} from the backup. Storage system 110 can also overwrite the list of changed fields in a data block of the data system at the current time point based on the retrieved data. For example, storage system 110 can overwrite the changed field A {64, 104857600} and field B {8, 104857600} in a data block of the data system at the current time point.
[0038] In this way, the amount of data that needs to be retrieved to restore the current data system to the backup at the target time point can be reduced based on the changes in the data system since the target time point, thereby achieving efficient data recovery.
[0039] Figure 6 A schematic block diagram of an example device 600 that can be used to implement embodiments of the present disclosure is shown. For example, device 600 can be used in, for example... Figure 1 The storage system shown is implemented at location 110. For example... Figure 6As shown, device 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to computer program instructions stored in read-only memory (ROM) 602 or loaded from storage unit 608 into random access memory (RAM) 603. RAM 603 may also store various programs and data required for the operation of device 600. CPU 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.
[0040] Multiple components in device 600 are connected to I / O interface 605, including: input unit 606, such as keyboard, mouse, etc.; output unit 607, such as various types of monitors, speakers, etc.; storage unit 608, such as disk, optical disk, etc.; and communication unit 609, such as network card, modem, wireless transceiver, etc. Communication unit 609 allows device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0041] The various processes and handling described above, such as method 200, can be executed by processing unit 601. For example, in some embodiments, method 200 can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed on device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by CPU 601, one or more actions of method 200 described above can be performed.
[0042] This disclosure can be a method, apparatus, system, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of this disclosure.
[0043] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), SRAM, portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0044] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0045] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.
[0046] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0047] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processing unit of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.
[0048] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.
[0049] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0050] The various embodiments of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or improvement of the technology in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A method for recovering data, the method comprising: A target time point is selected from multiple backup time points at a storage system, wherein the storage system includes a data system, and wherein the multiple backup time points correspond to multiple backups of the data system stored in a backup repository, wherein multiple operations are performed on files in the data system between the target time point and the current time point, the multiple operations including a first operation performed on a first file in the file and a second operation performed on the first file in the file, wherein the first operation precedes the second operation, and the second operation is a deletion operation; Determine a first set of change logs between the target time point and the current time point, with each change log recording changes in the data system between the corresponding backup time point and the previous backup time point; Determining changes to the files in the data system between the target time point and the current time point by merging the first set of change logs includes: generating a list of operations performed on the files in the data system between the target time point and the current time point by merging the first operation and the second operation into a second operation in response to determining that the first operation precedes the second operation, wherein the list of operations includes the second operation but not the first operation; Retrieve file data corresponding to the list of operations from one or more backups of the data system at the target time point in the backup repository; and Based on the file data, the data system at the current time point is overwritten by reversing the operation on the data system at the current time point.
2. The method of claim 1, wherein each change log records one or more of the plurality of operations on the file in the data system between the corresponding backup time point and the previous backup time point, the plurality of operations including at least one of renaming, adding, and updating operations; and The determination of the changes to the files in the data system between the target time point and the current time point by merging the first set of change logs includes determining a list of operations on the files in the data system based on merging multiple renaming operations of the second file in the files recorded in the first set of change logs into a single renaming operation.
3. The method of claim 1, wherein each change log records the changed fields in the data block of the data system between the corresponding backup time point and the previous backup time point; and wherein determining the changes to the file in the data system between the target time point and the current time point by merging the first set of change logs comprises: The list of changed fields in the data system is determined by performing a union operation on the changed fields in the first set of change logs.
4. The method according to claim 3, further comprising: Retrieve data of the list of changed fields from one or more of the multiple backups of the data system at the target time point in the backup repository; as well as Based on the data, overwrite the list of changed fields in the data block of the data system at the current time point.
5. The method according to claim 1, further comprising: Determine the mirror image of the data system at the current point in time; By comparing the mirror image of the data system at the current time point with the mirror image of the data system at the target time point, a list of fields that have changed in the data blocks of the data system between the target time point and the current time point is determined.
6. An electronic device, comprising: processor; as well as A memory coupled to the processor, the memory having instructions stored therein, the instructions causing the device to perform actions when executed by the processor, the actions including: A target time point is selected from multiple backup time points at a storage system, wherein the storage system includes a data system, and wherein the multiple backup time points correspond to multiple backups of the data system stored in a backup repository, wherein multiple operations are performed on files in the data system between the target time point and the current time point, the multiple operations including a first operation performed on a first file in the file and a second operation performed on the first file in the file, wherein the first operation precedes the second operation, and the second operation is a deletion operation; Determine a first set of change logs between the target time point and the current time point, with each change log recording changes in the data system between the corresponding backup time point and the previous backup time point; Determining changes to the files in the data system between the target time point and the current time point by merging the first set of change logs includes: generating a list of operations performed on the files in the data system between the target time point and the current time point by merging the first operation and the second operation into a second operation in response to determining that the first operation precedes the second operation, wherein the list of operations includes the second operation but not the first operation; Retrieve file data corresponding to the list of operations from one or more backups of the data system at the target time point in the backup repository; and Based on the file data, the data system at the current time point is overwritten by reversing the operation on the data system at the current time point.
7. The device of claim 6, wherein each change log records one or more of the plurality of operations on the file in the data system between the corresponding backup time point and the previous backup time point, the one or more operations including at least one of renaming, adding, and updating operations; and The determination of the changes to the files in the data system between the target time point and the current time point by merging the first set of change logs includes determining a list of operations on the files in the data system based on merging multiple renaming operations of the second file in the files recorded in the first set of change logs into a single renaming operation.
8. The device of claim 6, wherein each change log records the changed fields in the data block of the data system between the corresponding backup time point and the previous backup time point; and wherein determining the changes to the file in the data system between the target time point and the current time point by merging the first set of change logs comprises: The list of changed fields in the data system is determined by performing a union operation on the changed fields in the first set of change logs.
9. The device according to claim 8, wherein the action further comprises: Retrieve data of the list of changed fields from one or more of the multiple backups of the data system at the target time point in the backup repository; as well as Based on the data, overwrite the list of changed fields in the data block of the data system at the current time point.
10. The device according to claim 6, wherein the action further includes: Determine the mirror image of the data system at the current point in time; By comparing the mirror image of the data system at the current time point with the mirror image of the data system at the target time point, a list of fields that have changed in the data blocks of the data system between the target time point and the current time point is determined.
11. A computer program product tangibly stored on a computer-readable medium and comprising machine-executable instructions that, when executed, cause a machine to perform the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method and device for restoring virtual machine
CN103034566A
Terminal information operating method and device and mobile terminal
CN104077053A
Database recovery method and system
CN104715041A
Data recovery method and device
CN106599006A
Data monitoring method and device
CN111290927A