Cloud hard disk backup method, device, computer equipment and storage medium

By using encrypted data volumes to encrypt the backup data during cloud hard disk backup and copying the encrypted data to the backup data volume, the problem that cloud hard disk backup data cannot be guaranteed in the transmission and storage process is solved, and data confidentiality and security are achieved.

CN119336548BActive Publication Date: 2025-05-16INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411864652.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-05-16
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

The prior art cannot effectively ensure the security of cloud hard disk backup data during transmission and storage, and there is a risk of data leakage and unauthorized access.

Method used

By obtaining the encrypted data volume, copying the data to be backed up into the encrypted data volume, and encrypting the data based on the encrypted information to obtain the encrypted backup data. Then, copy the encrypted backup data and encryption information in the encrypted data volume to the backup data volume to complete the encrypted backup of the cloud hard disk to be backed up.

Benefits of technology

Ensure the confidentiality of the data to be backed up during transmission and storage, prevent data breaches, and even if an attacker can access the backup data volume, he cannot directly read the encrypted backup data, thereby preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119336548B_ABST
    Figure CN119336548B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of computer technology, and discloses a cloud hard disk backup method, device, computer equipment and storage medium, the method comprising: obtaining the data to be backed up of the cloud hard disk to be backed up; obtaining an encrypted data volume, and copying the data to be backed up to the encrypted data volume, wherein the encrypted data volume contains encryption information, and the encrypted data volume is used to encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data; creating a backup data volume, and copying the encrypted backup data and encryption information in the encrypted data volume to the backup data volume. The problem that the related technology cannot guarantee the security of backup data during transmission and storage is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a cloud hard disk backup method, device, computer equipment and storage medium. Background Art

[0002] Cloud disk backup can help users protect precious data from accidental damage, deletion or loss. Users back up disks that store important data and quickly restore the data backed up to the cloud disk to the source disk in the event of cloud host disk failure, user accidental data deletion, or hacker attack to ensure the integrity of user data. The backup data in the cloud disk contains a large amount of user's sensitive information and core assets. Once the data is leaked or illegally accessed, it may cause serious economic losses and reputation damage. Therefore, it is necessary to ensure the security of the backup data in the cloud disk.

[0003] OpenStack is a cloud platform management project that has the basic functions of cloud disk backup, including cloud disk data storage and recovery. However, the security of backup data cannot be guaranteed during transmission and storage. Summary of the invention

[0004] In view of this, the present invention provides a cloud hard disk backup method, device, computer equipment and storage medium to solve the problem that the related technology cannot guarantee the security of backup data during the transmission and storage process.

[0005] In a first aspect, the present invention provides a cloud hard disk backup method, comprising:

[0006] Obtain the data to be backed up from the cloud hard disk to be backed up;

[0007] Acquire an encrypted data volume, copy the data to be backed up to the encrypted data volume, wherein the encrypted data volume contains encryption information, and the encrypted data volume is used to encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data;

[0008] Create a backup data volume, and copy the encrypted backup data and encryption information in the encrypted data volume to the backup data volume.

[0009] The cloud hard disk backup method provided in this embodiment obtains an encrypted data volume, copies the data to be backed up to the encrypted data volume, and the encrypted data volume encrypts the data to be backed up according to the encryption information to obtain and save the encrypted backup data; the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume to complete the encrypted backup of the cloud hard disk to be backed up. It can not only protect user data from the risk of accidental damage, deletion or loss, but also ensure the confidentiality of the data to be backed up during transmission and storage, prevent data leakage, and even if the attacker can access the backup data volume, he cannot directly read the encrypted data to be backed up in the backup data volume, thereby preventing unauthorized access. It solves the problem that the related technology cannot guarantee the security of backup data during transmission and storage.

[0010] In some optional implementations, obtaining the encrypted data volume includes:

[0011] Obtain the data volume list corresponding to the cloud hard disk to be backed up in the backup backend;

[0012] Determine whether there is a data volume in the data volume list whose capacity is the same as the backup size in the backup record and whose encryption type is the same as the encryption type information in the backup record. If so, use the data volume as an encrypted data volume, wherein the backup record is used to represent the backup information of the cloud hard disk to be backed up;

[0013] If it does not exist, use the first component to create a first empty data volume with the same capacity as the backup size in the backup record on the backup backend, format the first empty data volume using the encryption type information in the backup record, obtain an encrypted data volume and generate encryption information in the encrypted data volume.

[0014] In this embodiment, an encrypted data volume containing encryption information is obtained or created on the backup backend. During the process of backing up the backup cloud hard disk, the encrypted data volume can encrypt the backup data according to the encryption information, and obtain and save the encrypted backup data. This not only ensures the confidentiality of the backup data during transmission and storage, but also prevents attackers from directly reading the encrypted backup data even if they can obtain it, thereby preventing unauthorized access.

[0015] In some optional implementations, before determining whether there is a data volume in the data volume list with a capacity that is the same as the backup size in the backup record and an encryption type that is the same as the encryption type information in the backup record, the method further includes:

[0016] Obtain encryption algorithm configuration information, encryption operation information, encryption algorithm and key length;

[0017] Obtain encryption type information according to the encryption algorithm configuration information, the encryption operation information, the encryption algorithm, and the key length, wherein the encryption type information is used to generate encryption information in the encrypted data volume;

[0018] Get the backup name and backup size;

[0019] A backup record is created in the database that contains the encryption type information, the backup name, and the backup size.

[0020] In this embodiment, a backup record is created that includes encryption type information, backup name, and backup size. Subsequently, an encrypted data volume can be created based on the encryption type information in the backup record, and a backup data volume can be created based on the backup name and backup size in the backup record, thereby realizing encrypted backup of the backup cloud hard disk.

[0021] In some optional implementations, obtaining the data to be backed up of the cloud hard disk to be backed up includes:

[0022] Freeze the file system of the cloud hard disk to be backed up;

[0023] Creating a snapshot of the cloud hard disk to be backed up according to the first component, wherein the snapshot includes the data to be backed up;

[0024] A temporary cloud hard disk is generated based on the snapshot to restore the file system. The temporary cloud hard disk is used to temporarily store data to be backed up.

[0025] In some optional implementations, copying the data to be backed up to the encrypted data volume includes:

[0026] Mount the temporary cloud hard disk and encrypted data volume to the host machine;

[0027] Use the host machine to compare the temporary cloud hard disk and the encrypted data volume, determine the difference data, and use the difference data as the data to be backed up;

[0028] The data to be backed up is written to the encrypted data volume using the preset protocol framework of the host machine.

[0029] In this embodiment, the host machine compares the temporary cloud hard disk and the encrypted data volume to determine the difference data, and can perform full and incremental backup on the backup cloud host. The preset protocol framework of the host machine is used to write the backup data to the encrypted data volume in parallel, thereby improving data backup efficiency.

[0030] In some optional implementations, mounting the temporary cloud hard disk and the encrypted data volume to the host machine includes:

[0031] Determine whether the temporary cloud hard disk is an encrypted cloud hard disk;

[0032] If not, the temporary cloud hard disk is mounted to the host file directory of the host machine through the preset mount command;

[0033] If yes, the temporary cloud hard disk is decrypted using a preset decryption command, and the decrypted temporary cloud hard disk is mounted to the host file directory using a preset mount command;

[0034] The encrypted data volume is decrypted by a preset decryption command, and the decrypted encrypted data volume is mounted to the host file directory by a preset mount command.

[0035] In some optional implementations, creating a backup data volume, and copying the encrypted backup data and encryption information in the encrypted data volume to the backup data volume includes:

[0036] Obtain a backup name and a backup size from the backup record, create a second empty data volume with the same name and size as the backup on the backup backend, and use the second empty data volume as the backup data volume;

[0037] Unmount the encrypted data volume on the host machine;

[0038] Use the backup backend to establish a local replication relationship between the encrypted data volume and the backup data volume;

[0039] Based on the local replication relationship, the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume.

[0040] In this embodiment, a backup data volume is created on the backup backend, the encrypted data volume is unmounted on the host machine, and the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume using the local replication function of the backup backend, thereby improving data replication efficiency without occupying the available resources of the host machine.

[0041] In some optional implementations, creating a backup data volume, and copying the encrypted backup data and encryption information in the encrypted data volume to the backup data volume includes:

[0042] Obtain a backup name and a backup size from the backup record, create a second empty data volume with the same name and size as the backup on the backup backend, and use the second empty data volume as the backup data volume;

[0043] Mount the backup data volume to the host machine;

[0044] The encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume using the preset protocol framework of the host machine.

[0045] In this implementation, the encrypted backup data and the encrypted information in the encrypted data volume are written into the encrypted data volume in parallel by utilizing the preset protocol framework of the host machine, thereby improving data backup efficiency.

[0046] In some optional implementations, unmounting the encrypted data volume on the host machine includes:

[0047] Unmount the encrypted data volume from the host file directory using the preset unmount command;

[0048] Execute the data volume close command to close the encrypted data volume.

[0049] In some optional implementations, after writing the data to be backed up into the encrypted data volume, the method further includes:

[0050] Determine whether the temporary cloud hard disk is an encrypted cloud hard disk;

[0051] If not, the temporary cloud hard disk is uninstalled from the host file directory using the preset uninstall command;

[0052] If yes, the temporary cloud hard disk is uninstalled from the host file directory through a preset uninstall command, and a cloud hard disk close command is executed to close the temporary cloud hard disk.

[0053] In some optional embodiments, the method further comprises:

[0054] Before creating a snapshot of the cloud hard disk to be backed up according to the first component, modifying the status of the cloud hard disk to be backed up in the database to be in backup;

[0055] After creating a snapshot of the cloud hard disk to be backed up according to the first component, the state of the cloud hard disk to be backed up is modified to an available state in the database.

[0056] In this embodiment, before creating a snapshot of the cloud hard disk to be backed up, the status of the cloud hard disk to be backed up is changed to being backed up, to prevent the user from performing other operations on the cloud hard disk to be backed up during the backup process, which may cause the backup to fail. After creating the snapshot, the status of the cloud hard disk to be backed up is changed to available, and the cloud host can perform read and write operations on the cloud hard disk to be backed up, so that the encrypted backup process will not affect the normal production business of the cloud host.

[0057] In some optional implementations, after copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume, the method further includes:

[0058] When receiving the data recovery instruction and the key, the backup data volume is decrypted using the key, and the data to be recovered corresponding to the data recovery instruction is obtained from the decrypted backup data volume;

[0059] Determine the target cloud hard disk according to the data recovery instructions, and restore the data to be restored to the target cloud hard disk.

[0060] In this embodiment, data recovery instructions and keys are used to restore the data to be recovered to the target cloud hard disk, which not only provides data protection and recovery capabilities, ensuring that user data can be quickly restored in the event of loss, damage or accident, effectively ensuring the integrity of user data, but also ensures the confidentiality of backup data during transmission and storage, thereby enhancing data security.

[0061] In a second aspect, the present invention provides a cloud hard disk backup device, comprising:

[0062] A data acquisition module is used to acquire the data to be backed up from the cloud hard disk to be backed up;

[0063] A first backup module is used to obtain an encrypted data volume, copy the data to be backed up to the encrypted data volume, wherein the encrypted data volume contains encryption information, and the encrypted data volume is used to encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data;

[0064] The second backup module is used to create a backup data volume and copy the encrypted backup data and encryption information in the encrypted data volume to the backup data volume.

[0065] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the cloud hard disk backup method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0066] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the cloud hard disk backup method of the first aspect or any corresponding embodiment thereof.

[0067] In a fifth aspect, the present invention provides a computer program product, including computer instructions, which are used to enable a computer to execute the cloud hard disk backup method of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the related technologies, the drawings required for use in the specific embodiments or the related technical descriptions will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0069] Figure 1 is a flowchart of a cloud hard disk backup method according to an embodiment of the present invention;

[0070] Figure 2 is a diagram of a cloud hard disk encryption backup architecture according to an embodiment of the present invention;

[0071] Figure 3 is a flowchart of a cloud hard disk encryption backup method according to an embodiment of the present invention;

[0072] Figure 4 is a structural block diagram of a cloud hard disk backup device according to an embodiment of the present invention;

[0073] Figure 5 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0074] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0075] OpenStack is a cloud platform management project. OpenStack can provide software for the construction and management of public clouds, private clouds, and hybrid clouds. The primary task of OpenStack is to simplify the cloud deployment process and bring good scalability to it. OpenStack is composed of several major components, including Cinder, Nova, etc. Cinder is the OpenStack block storage service, adding persistent storage to virtual machines. Cinder provides an infrastructure for managing data volumes and interacting with OpenStack computing services. Cinder also activates the functions of managing volume snapshots and volume types. Nova is the core service of OpenStack, responsible for maintaining and managing computing resources in the cloud environment. Virtual machine lifecycle management is also implemented through Nova.

[0076] Although the OpenStack cloud platform has implemented the basic functions of cloud disk backup, it only has the ability to protect and restore cloud disk data. Backup data may be leaked during transmission and storage, and the security of backup data cannot be guaranteed.

[0077] Based on the above content, an embodiment of the present invention provides a cloud hard disk backup method. First, all the data to be backed up of the cloud hard disk to be backed up are copied to a temporary cloud hard disk; then the temporary cloud hard disk and the encrypted data volume are mounted on the host machine at the same time, and the data to be backed up are copied to the encrypted data volume by the host machine concurrently, and the encrypted data volume contains encryption information, and the encryption information is used to encrypt the data to be backed up; after the copy is completed, the encrypted data volume is uninstalled from the host machine; a backup volume is created in the backup backend, and all the data of the encrypted data volume is copied to the backup volume through the local copy function of the backup backend. The backup volume also contains encryption information, and the backup and encryption process of the cloud hard disk to be backed up is completed. Without affecting the production tasks of the cloud host, the cloud hard disk data is backed up and encrypted, which can not only ensure the confidentiality of the backup data during transmission and storage, and prevent data leakage, but also even if the attacker can access the cloud storage service, it cannot directly read the encrypted backup data, thereby preventing unauthorized access. In order to achieve the technical effect of protecting user data from the risk of accidental damage, deletion or loss, and ensuring the confidentiality of backup data during transmission and storage, and enhancing the security of user data.

[0078] According to an embodiment of the present invention, a cloud hard disk backup embodiment is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer device with data processing capabilities, such as a computer, a server, etc., and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0079] In this embodiment, a cloud hard disk backup method is provided. Figure 1 is a flow chart of a cloud hard disk backup method according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:

[0080] Step S101, obtaining the data to be backed up from the cloud hard disk to be backed up.

[0081] Specifically, Figure 1 As shown in the figure, OpenStack is used to manage cloud hosts and cloud hard disks. The Nova component in OpenStack is used to manage cloud hosts, and the Cinder component is used to manage cloud hard disks in the storage backend.

[0082] Determine the source cloud hard disk in the storage backend, the source cloud hard disk is the cloud hard disk that needs to be backed up. Use the source cloud hard disk as the cloud hard disk to be backed up. The present invention supports full backup and incremental backup of cloud hard disks. Obtain the data to be backed up of the cloud hard disk to be backed up. If it is a full backup, all the data in the cloud hard disk to be backed up will be used as the data to be backed up; if it is an incremental backup, the changed data in the cloud hard disk to be backed up compared to the previous backup will be used as the data to be backed up. In addition, the snapshot function of the backup backend can be used to copy all the data to be backed up of the cloud hard disk to be backed up to a temporary cloud hard disk, and the data to be backed up will be temporarily stored in the temporary cloud hard disk to ensure that the data reading and writing functions of the cloud hard disk to be backed up are not affected during the backup of the data to be backed up.

[0083] Step S102, obtaining an encrypted data volume, and copying the data to be backed up to the encrypted data volume, wherein the encrypted data volume contains encryption information, and the encrypted data volume is used to encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data.

[0084] Specifically, an encrypted data volume is obtained on the backup backend, such as an encrypted Base volume. If the backup backend already has an encrypted data volume associated with the cloud hard disk to be backed up, the encrypted data volume is used directly. If not, an empty data volume needs to be created on the backup backend, and then the encryption information is written into the empty data volume to obtain the encrypted data volume. The encrypted data volume contains encryption information, such as encryption algorithm, disk encryption technology, key length, encryption operation location, etc.

[0085] Copy the data to be backed up to the encrypted data volume. You can mount the cloud hard disk (such as a temporary cloud hard disk) storing the data to be backed up and the encrypted data volume to the same host machine, and use the host machine to copy the data to be backed up to the encrypted data volume. The encrypted data volume can encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data.

[0086] Step S103: create a backup data volume, and copy the encrypted backup data and encryption information in the encrypted data volume to the backup data volume.

[0087] Specifically, a backup data volume is created on the backup backend. Both the backup data volume and the encrypted data volume are on the backup backend. Therefore, the encrypted data volume can be unmounted from the host machine first, and then the encrypted backup data and encryption information in the encrypted data volume can be copied to the backup data volume using the local copy function of the backup backend. Alternatively, the backup data volume can also be mounted on the host machine, and the encrypted backup data and encryption information in the encrypted data volume can be copied to the backup data volume using the host machine. Finally, the temporary cloud hard disk is unmounted and deleted from the host machine, completing the backup and encryption process of the cloud hard disk to be backed up.

[0088] The cloud hard disk backup method provided in this embodiment obtains an encrypted data volume, copies the data to be backed up to the encrypted data volume, and the encrypted data volume encrypts the data to be backed up according to the encryption information to obtain and save the encrypted backup data; the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume to complete the encrypted backup of the cloud hard disk to be backed up. It can not only protect user data from the risk of accidental damage, deletion or loss, but also ensure the confidentiality of the data to be backed up during transmission and storage, prevent data leakage, and even if the attacker can access the backup data volume, he cannot directly read the encrypted data to be backed up in the backup data volume, thereby preventing unauthorized access. It solves the problem that the related technology cannot guarantee the security of backup data during transmission and storage.

[0089] In some optional implementations, obtaining the encrypted data volume includes:

[0090] Obtain the data volume list corresponding to the cloud hard disk to be backed up in the backup backend;

[0091] Determine whether there is a data volume in the data volume list whose capacity is the same as the backup size in the backup record and whose encryption type is the same as the encryption type information in the backup record. If so, use the data volume as an encrypted data volume, wherein the backup record is used to represent the backup information of the cloud hard disk to be backed up;

[0092] If it does not exist, use the first component to create a first empty data volume with the same capacity as the backup size in the backup record on the backup backend, format the first empty data volume using the encryption type information in the backup record, obtain an encrypted data volume and generate encryption information in the encrypted data volume.

[0093] Specifically, a base volume list, that is, a data volume list, associated with a source cloud hard disk is obtained on the backup backend. The source cloud hard disk is the cloud hard disk to be backed up.

[0094] Determine whether there is a data volume in the data volume list that was created recently, has the same capacity as the backup size in the backup record, and has the same encryption type as the encryption type information in the backup record. If it exists, it means that this is not the first time to create an encrypted backup of the source cloud hard disk. The data in the encrypted Base volume contains encryption information and the last backup data of the source cloud hard disk. The data volume is used as an encrypted data volume. The backup record is used to represent the backup information of the cloud hard disk to be backed up. The backup size in the backup record is the size of the cloud hard disk to be backed up, and the encryption information in the backup record contains the encryption type information of the backup to be created.

[0095] If the above data volume does not exist in the data volume list, it indicates that this is the first time to create an encrypted backup of the source cloud hard disk, and the encrypted data volume needs to be recreated. The first component is, for example, the Cinder component. Use the first component to create a first empty data volume with the same capacity as the backup size in the backup record on the backup backend. Format the first empty data volume using the cryptsetup luksFormat command according to the encryption type information in the backup record. The formatted first empty data volume contains encryption information, and the encrypted data volume is obtained.

[0096] In this embodiment, an encrypted data volume containing encryption information is obtained or created on the backup backend. During the process of backing up the backup cloud hard disk, the encrypted data volume can encrypt the backup data according to the encryption information, and obtain and save the encrypted backup data. This not only ensures the confidentiality of the backup data during transmission and storage, but also prevents attackers from directly reading the encrypted backup data even if they can obtain it, thereby preventing unauthorized access.

[0097] In some optional implementations, before determining whether there is a data volume in the data volume list with a capacity that is the same as the backup size in the backup record and an encryption type that is the same as the encryption type information in the backup record, the method further includes:

[0098] Obtain encryption algorithm configuration information, encryption operation information, encryption algorithm and key length;

[0099] Obtain encryption type information according to the encryption algorithm configuration information, the encryption operation information, the encryption algorithm, and the key length, wherein the encryption type information is used to generate encryption information in the encrypted data volume;

[0100] Get the backup name and backup size;

[0101] A backup record is created in the database that contains the encryption type information, the backup name, and the backup size.

[0102] Specifically, when performing encrypted backup of the backup cloud hard disk, the encryption type information of the backup must first be specified. The encryption type information is used to generate encryption information in the encrypted data volume. The encryption type information consists of four configuration parameters: provider, control location, encryption algorithm, and key length. The provider is the encryption algorithm configuration information, which refers to the software library, service, or hardware module that implements the encryption algorithm. For example, LUKS (Linux Unified Key Setup, a standard for Linux hard disk encryption) is a commonly used disk encryption technology. By providing a standard disk format, it not only promotes compatibility between distributions, but also provides secure management of multiple user passwords. LUKS stores all necessary setting information in the partition information header, allowing users to seamlessly transfer or migrate their data. The control location is the encryption operation information, which refers to the context or environment in which the encryption operation occurs. The default control location is the front end, and its corresponding service is the Nova component. The encryption algorithm is the core of the encryption process. It defines how to encrypt and decrypt data, such as aes-xts-plain64, where aes is the encryption algorithm, xts is the encryption mode, and plain64 is the initialization vector mode of the encryption mode. The key length is the number of bits of the key used in the encryption algorithm. Longer keys generally provide greater security. Key lengths are generally 128 or 256 bits.

[0103] Get the backup name and backup size. The backup name is set according to actual needs. The backup size is the same as the size of the cloud hard disk to be backed up. Create a backup record in the database that contains the encryption type information, backup name, and backup size. In addition, the backup record can also include: backup status, source cloud hard disk ID (Identity document, identity identification) and other information. The backup status can be: creating, idle, or in use.

[0104] In the cloud hard disk encryption backup method of this embodiment, the user only needs to specify the backup name, encryption type and backup backend. The operation is simple and has strong usability. It does not require additional hardware and software costs and has low production costs.

[0105] In this embodiment, a backup record is created that includes encryption type information, backup name, and backup size. Subsequently, an encrypted data volume can be created based on the encryption type information in the backup record, and a backup data volume can be created based on the backup name and backup size in the backup record, thereby realizing encrypted backup of the backup cloud hard disk.

[0106] In some optional implementations, obtaining the data to be backed up of the cloud hard disk to be backed up includes:

[0107] Freeze the file system of the cloud hard disk to be backed up;

[0108] Creating a snapshot of the cloud hard disk to be backed up according to the first component, wherein the snapshot includes the data to be backed up;

[0109] A temporary cloud hard disk is generated based on the snapshot to restore the file system. The temporary cloud hard disk is used to temporarily store data to be backed up.

[0110] Specifically, this embodiment is used to create a temporary cloud hard disk. First, the file system of the source cloud hard disk, ie, the cloud hard disk to be backed up, is frozen to prevent the cloud host from performing read and write operations on the cloud hard disk to be backed up.

[0111] The first component is, for example, the Cinder component. Create a snapshot of the cloud hard disk to be backed up at the current moment based on the first component. Create a snapshot of the cloud hard disk to be backed up based on the first component. For example, you can directly use the snapshot as a temporary cloud hard disk; or create an empty cloud hard disk, write the data in the snapshot to the empty cloud hard disk and use it as a temporary cloud hard disk. Since the cloud hard disk to be backed up and the temporary cloud hard disk are located in the same storage backend, all data on the cloud hard disk to be backed up is copied to the temporary cloud hard disk through the local replication function of the storage backend. Figure 2 As shown in the figure, a snapshot of the source cloud hard disk is created in the storage backend, and a temporary cloud hard disk is created based on the snapshot. After the temporary cloud hard disk is created, the file system of the source cloud hard disk is restored, and the cloud host can read and write to the backup cloud hard disk. The subsequent encrypted backup process is completed by the temporary cloud hard disk, which will not affect the normal production business of the cloud host.

[0112] In some optional implementations, copying the data to be backed up to the encrypted data volume includes:

[0113] Mount the temporary cloud hard disk and encrypted data volume to the host machine;

[0114] Use the host machine to compare the temporary cloud hard disk and the encrypted data volume, determine the difference data, and use the difference data as the data to be backed up;

[0115] The data to be backed up is written to the encrypted data volume using the preset protocol framework of the host machine.

[0116] Specifically, this embodiment uses the host machine to perform data transmission between the temporary cloud hard disk and the encrypted data volume. The temporary cloud hard disk and the encrypted data volume are mounted on the host machine.

[0117] After the temporary cloud hard disk and the encrypted data volume are mounted to the host, the user data in the temporary cloud hard disk and the encrypted data volume are compared. If this is not the first time to perform encrypted backup of the backup cloud hard disk, the incremental data in the temporary cloud hard disk is read and the incremental data is used as differential data. If this is the first time to perform encrypted backup of the backup cloud hard disk, the full data in the temporary cloud hard disk is read and the full data is used as differential data.

[0118] The preset protocol framework of the host machine, for example, the coroutine framework of the eventlet library. Use the preset protocol framework of the host machine to concurrently write the data to be backed up into the encrypted data volume. After the temporary cloud hard disk data is copied to the encrypted data volume, except for the encryption information in the encrypted data volume, the other data in the encrypted data volume is completely consistent with the data in the temporary cloud hard disk and the source cloud hard disk. Figure 2 As shown in the figure, the data of the temporary cloud hard disk is copied to the encrypted Base volume of the backup backend.

[0119] In this embodiment, the host machine compares the temporary cloud hard disk and the encrypted data volume to determine the difference data, and can perform full and incremental backup on the backup cloud host. The preset protocol framework of the host machine is used to write the backup data to the encrypted data volume in parallel, thereby improving data backup efficiency.

[0120] In some optional implementations, mounting the temporary cloud hard disk and the encrypted data volume to the host machine includes:

[0121] Determine whether the temporary cloud hard disk is an encrypted cloud hard disk;

[0122] If not, the temporary cloud hard disk is mounted to the host file directory of the host machine through the preset mount command;

[0123] If yes, the temporary cloud hard disk is decrypted using a preset decryption command, and the decrypted temporary cloud hard disk is mounted to the host file directory using a preset mount command;

[0124] The encrypted data volume is decrypted by a preset decryption command, and the decrypted encrypted data volume is mounted to the host file directory by a preset mount command.

[0125] Specifically, this embodiment is used to mount a temporary cloud hard disk and an encrypted data volume to a host machine. When a temporary cloud hard disk is created, all data in the cloud hard disk to be backed up, including encrypted data, will be copied to the temporary cloud hard disk. Therefore, if the source cloud hard disk is an encrypted cloud hard disk, the temporary cloud hard disk is also an encrypted cloud hard disk.

[0126] Determine whether the temporary cloud hard disk is an encrypted cloud hard disk. If the temporary cloud hard disk is an encrypted cloud hard disk, it needs to be decrypted before mounting it to the host. The preset decryption command is for example: cryptsetup luksOpen command, and the preset mount command is for example: mount command. Decrypt and open the temporary cloud hard disk through the preset decryption command, and then mount the decrypted temporary cloud hard disk to the host file directory through the preset mount command; if the temporary cloud hard disk is a normal cloud hard disk, not an encrypted cloud hard disk, directly mount the temporary cloud hard disk to the host file directory or host mount point directory of the host through the preset mount command.

[0127] The encrypted data volume is decrypted by a preset decryption command, and then the decrypted encrypted data volume is mounted to a host file directory or a host mount point directory by a preset mount command.

[0128] In some optional implementations, creating a backup data volume, and copying the encrypted backup data and encryption information in the encrypted data volume to the backup data volume includes:

[0129] Obtain a backup name and a backup size from the backup record, create a second empty data volume with the same name and size as the backup on the backup backend, and use the second empty data volume as the backup data volume;

[0130] Unmount the encrypted data volume on the host machine;

[0131] Use the backup backend to establish a local replication relationship between the encrypted data volume and the backup data volume;

[0132] Based on the local replication relationship, the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume.

[0133] Specifically, the backup name and backup size are obtained from the backup record. The backup name is set according to actual needs, and the backup size is the same as the size of the cloud hard disk to be backed up.

[0134] A second empty data volume with the same name and size as the backup is created on the backup backend, and the second empty data volume is used as the backup data volume.

[0135] After the backup data volume is created, since both the encrypted data volume and the backup data volume are on the backup backend, you can use the local replication function of the backup backend to replicate data. In order to facilitate the use of the local replication function of the backup backend, you need to first uninstall the encrypted data volume on the host.

[0136] Use the backup backend to establish a local replication relationship between the encrypted data volume and the backup data volume. Based on the local replication relationship, all encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume. After the copy is completed, the backup data volume is the encrypted backup volume of the source cloud hard disk. Figure 2 As shown in the figure, on the backup backend, the data in the encrypted Base volume is copied to the encrypted backup volume through local replication.

[0137] In this embodiment, a backup data volume is created on the backup backend, the encrypted data volume is unmounted on the host machine, and the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume using the local replication function of the backup backend, thereby improving data replication efficiency without occupying the available resources of the host machine.

[0138] In some optional implementations, creating a backup data volume, and copying the encrypted backup data and encryption information in the encrypted data volume to the backup data volume includes:

[0139] Obtain a backup name and a backup size from the backup record, create a second empty data volume with the same name and size as the backup on the backup backend, and use the second empty data volume as the backup data volume;

[0140] Mount the backup data volume to the host machine;

[0141] The encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume using the preset protocol framework of the host machine.

[0142] Specifically, the backup name and backup size are obtained from the backup record. The backup name is set according to actual needs, and the backup size is the same as the size of the cloud hard disk to be backed up.

[0143] A second empty data volume with the same name and size as the backup is created on the backup backend, and the second empty data volume is used as the backup data volume.

[0144] The host's preset protocol framework is, for example, the coroutine framework of the eventlet library. Because the host's preset protocol framework can be used to copy data concurrently, data copying efficiency is higher. Therefore, the host's preset protocol framework can be used for data copying. In order to facilitate the use of the host's preset protocol framework, the backup data volume needs to be mounted on the host first.

[0145] Using the preset protocol framework of the host machine, the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume concurrently. After the copy is completed, the backup data volume is the encrypted backup volume of the source cloud hard disk. Except for the encryption information in the backup data volume, the other data in the backup data volume is completely consistent with the data in the temporary cloud hard disk and the source cloud hard disk.

[0146] In this implementation, the encrypted backup data and the encrypted information in the encrypted data volume are written into the encrypted data volume in parallel by utilizing the preset protocol framework of the host machine, thereby improving data backup efficiency.

[0147] In some optional implementations, unmounting the encrypted data volume on the host machine includes:

[0148] Unmount the encrypted data volume from the host file directory using the preset unmount command;

[0149] Execute the data volume close command to close the encrypted data volume.

[0150] Specifically, the preset uninstallation command is, for example, the umount command. The data volume closing command is, for example, the cryptsetupluksClose command.

[0151] After the backup data of the temporary cloud hard disk is copied to the encrypted data volume, the encrypted data volume is unmounted from the host file directory through the preset unmount command, and the data volume close command is executed to close the encrypted data volume, thereby completing the unmounting of the encrypted data volume.

[0152] It should be noted that after completing the encrypted backup of the cloud hard disk to be backed up, the encrypted data volume will not be deleted. The encrypted data volume will be used to copy the user incremental data when the encrypted backup of the cloud hard disk to be backed up is performed next time.

[0153] In some optional implementations, after writing the data to be backed up into the encrypted data volume, the method further includes:

[0154] Determine whether the temporary cloud hard disk is an encrypted cloud hard disk;

[0155] If not, the temporary cloud hard disk is uninstalled from the host file directory using the preset uninstall command;

[0156] If yes, the temporary cloud hard disk is uninstalled from the host file directory through a preset uninstall command, and a cloud hard disk close command is executed to close the temporary cloud hard disk.

[0157] Specifically, when the host machine uninstalls the temporary cloud hard disk, it is also necessary to determine whether the temporary cloud hard disk is an encrypted cloud hard disk. If the temporary cloud hard disk is an encrypted cloud hard disk, it needs to be decrypted first.

[0158] The preset uninstallation command is, for example, the umount command. The cloud disk closing command is, for example, the cryptsetup luksClose command.

[0159] If the temporary cloud disk is not an encrypted cloud disk, directly uninstall the temporary cloud disk from the host file directory using the preset uninstall command. After the temporary cloud disk is uninstalled from the host, delete the temporary cloud disk.

[0160] If the temporary cloud hard disk is an encrypted cloud hard disk, first use the preset uninstall command to uninstall the temporary cloud hard disk from the host file directory, and execute the cloud hard disk shutdown command to close the temporary cloud hard disk. After the temporary cloud hard disk is uninstalled from the host, delete the temporary cloud hard disk.

[0161] In some optional embodiments, the method further comprises:

[0162] Before creating a snapshot of the cloud hard disk to be backed up according to the first component, modifying the status of the cloud hard disk to be backed up in the database to be in backup;

[0163] After creating a snapshot of the cloud hard disk to be backed up according to the first component, the state of the cloud hard disk to be backed up is modified to an available state in the database.

[0164] Specifically, before creating a snapshot of the cloud hard disk to be backed up according to the first component, the file system of the source cloud hard disk, i.e., the cloud hard disk to be backed up, is frozen, and the cloud hard disk status is changed from being in use to being backed up in the database to prevent the user from performing other operations on the cloud hard disk to be backed up during the backup process.

[0165] After creating a snapshot of the cloud hard disk to be backed up, or after the temporary cloud hard disk is created, restore the file system of the cloud hard disk to be backed up, change the status of the cloud hard disk to be backed up to available in the database, and the cloud host can read and write to the cloud hard disk to be backed up. The subsequent encrypted backup process is completed by the temporary cloud hard disk, which will not affect the normal production business of the cloud host.

[0166] In this embodiment, before creating a snapshot of the cloud hard disk to be backed up, the status of the cloud hard disk to be backed up is changed to being backed up, to prevent the user from performing other operations on the cloud hard disk to be backed up during the backup process, which may cause the backup to fail. After creating the snapshot, the status of the cloud hard disk to be backed up is changed to available, and the cloud host can perform read and write operations on the cloud hard disk to be backed up, so that the encrypted backup process will not affect the normal production business of the cloud host.

[0167] In some optional implementations, after copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume, the method further includes:

[0168] When receiving the data recovery instruction and the key, the backup data volume is decrypted using the key, and the data to be recovered corresponding to the data recovery instruction is obtained from the decrypted backup data volume;

[0169] Determine the target cloud hard disk according to the data recovery instructions, and restore the data to be restored to the target cloud hard disk.

[0170] Specifically, after the encrypted backup data and encryption information in the encrypted data volume are copied to the backup data volume, the encrypted backup of the cloud hard disk to be backed up is completed. The status of the backup data volume in the database is changed from being created to being available, and the user can now use the backup data volume to restore data. For example: the user sends a data recovery instruction and a key to the backup backend, and the user uses the data recovery instruction to specify the data to be restored, i.e., the data to be restored, and the location to which the data needs to be restored, such as the target cloud hard disk. The backup backend uses the key to decrypt the backup data volume, and obtains the data to be restored corresponding to the data recovery instruction from the decrypted backup data volume; determines the target cloud hard disk according to the data recovery instruction, and restores the data to be restored to the target cloud hard disk.

[0171] In this embodiment, data recovery instructions and keys are used to restore the data to be recovered to the target cloud hard disk, which not only provides data protection and recovery capabilities, ensuring that user data can be quickly restored in the event of loss, damage or accident, effectively ensuring the integrity of user data, but also ensures the confidentiality of backup data during transmission and storage, thereby enhancing data security.

[0172] In some optional implementations, a custom policy may be set to implement automatic backup of the cloud hard disk, and the specific process may include steps A1 to A4.

[0173] Step A1: After creating a cloud hard disk, determine the cloud hard disk that needs to be automatically backed up.

[0174] Specifically, the user selects the type of cloud hard disk through the OpenStack Cinder component according to the user's needs, creates the cloud hard disk to be used, and determines the cloud hard disk to be automatically backed up in the created cloud hard disk.

[0175] Step A2: Create a customized backup strategy based on business needs.

[0176] Specifically, the basic operation types provided by the policy module are used to create a custom backup policy, set the property information of the backup policy, and enable the backup policy. The backup policy is saved in an independent data table that is expanded and added based on the OpenStack database. Users can perform basic data operations on the custom backup policy, where the basic data operation types include creation, deletion, modification, query, association, enabling, and disabling. The backup policy of the cloud hard disk is a service resource type provided by the data service class component that expands the business based on the OpenStack open source business framework.

[0177] Step A3: associate the created backup policy with the cloud hard disk that needs to be automatically backed up, and store the association relationship information in the corresponding association relationship data table in the database.

[0178] Specifically, the relationship between the backup strategy and the cloud hard disk is a one-to-many relationship, that is, one backup strategy can be associated with multiple cloud hard disks, and one cloud hard disk can only be associated with one backup strategy. The attribute information of the backup strategy includes the backup strategy ID, name, status, cycle (daily, weekly or monthly), time point (specified moment), and ownership information. The association relationship information includes the cloud hard disk ID, backup strategy ID, and ownership information. For example: Cloud hard disk A and cloud hard disk B are both associated with the backup strategy created in step A2. At this time, two association relationships between the cloud hard disk and the backup strategy will be generated, recording cloud hard disk A and cloud hard disk B (recording cloud hard disk ID, backup strategy ID, ownership information, etc.), and stored in the corresponding association relationship data table in the database.

[0179] Step A4, create an automatic backup script, the automatic backup script is used to scan the association information in the association data table according to the backup strategy, and use the cloud hard disk backup method in steps S101 to S103 and other embodiments to automatically back up the cloud hard disk that is determined to be automatically backed up, and generate its corresponding backup data volume.

[0180] Specifically, the automatic backup script will scan the association information recorded in the association data table according to the defined backup strategy, and use the cloud hard disk backup method in steps S101 to S103 and other embodiments to automatically back up the cloud hard disk that is determined to be automatically backed up at the period and time point specified in the backup strategy of the cloud hard disk, and generate its corresponding backup data volume.

[0181] In this embodiment, a customized backup strategy service is added to realize automatic backup of a specified cloud hard disk based on a specified time point and a specified strategy. This method greatly reduces the risk of data security storage. At the same time, it is more user-friendly and convenient to operate, thereby improving the user experience.

[0182] In some optional embodiments, Figure 3 is a flow chart of a cloud hard disk encryption backup method according to an embodiment of the present invention. The method can also solve the problem that the related technology cannot ensure the security of backup data during the transmission and storage process of backup data, such as Figure 3 As shown, the method comprises the following steps:

[0183] Specify the encryption type; modify the source cloud hard disk status; create a backup record in the database; create a temporary cloud hard disk; determine whether the source cloud hard disk is encrypted. If so, the host machine decrypts and mounts the temporary cloud hard disk. If not, the host machine mounts the temporary cloud hard disk; determine whether there is an encrypted Base volume. If not, create a Base volume, encrypt and format the Base volume, and the host machine decrypts and mounts the Base volume. If yes, the host machine decrypts and mounts the Base volume; copy data from the temporary cloud hard disk to the Base volume; unmount the Base volume from the host; create a backup volume; copy data from the Base volume to the backup volume; unmount and delete the temporary cloud hard disk; update the source cloud hard disk and backup status.

[0184] In this embodiment, not only can user data be protected from the risk of accidental damage, deletion or loss, and data protection and recovery capabilities can be provided, but the confidentiality of backup data during transmission and storage is also guaranteed, preventing unauthorized access, thereby further enhancing the security of user data.

[0185] In this embodiment, a cloud hard disk backup device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0186] This embodiment provides a cloud hard disk backup device, such as Figure 4 As shown, including:

[0187] The data acquisition module 401 is used to acquire the data to be backed up from the cloud hard disk to be backed up;

[0188] The first backup module 402 is used to obtain an encrypted data volume and copy the data to be backed up to the encrypted data volume, wherein the encrypted data volume contains encryption information, and the encrypted data volume is used to encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data;

[0189] The second backup module 403 is used to create a backup data volume, and copy the encrypted backup data and encryption information in the encrypted data volume to the backup data volume.

[0190] In some optional implementations, the first backup module 402 includes:

[0191] An acquisition unit, used to acquire a list of data volumes corresponding to the cloud hard disk to be backed up in the backup backend;

[0192] a judgment unit, used to judge whether there is a data volume in the data volume list with a capacity having the same size as the backup size in the backup record and an encryption type having the same encryption type information as the backup record, and if so, use the data volume as an encrypted data volume, wherein the backup record is used to represent the backup information of the cloud hard disk to be backed up;

[0193] The first creation unit is used to create a first empty data volume with the same capacity as the backup size in the backup record at the backup backend using the first component if it does not exist, format the first empty data volume using the encryption type information in the backup record, obtain the encrypted data volume and generate encryption information in the encrypted data volume.

[0194] In some optional embodiments, the device further comprises:

[0195] The first acquisition module is used to obtain encryption algorithm configuration information, encryption operation information, encryption algorithm and key length;

[0196] A obtaining module, used to obtain encryption type information according to encryption algorithm configuration information, encryption operation information, encryption algorithm and key length, wherein the encryption type information is used to generate encryption information in the encrypted data volume;

[0197] The second acquisition module is used to obtain the backup name and backup size;

[0198] The creation module is used to create a backup record in the database containing encryption type information, backup name, and backup size.

[0199] In some optional implementations, the data acquisition module 401 includes:

[0200] A freezing unit, used to freeze the file system of the cloud hard disk to be backed up;

[0201] A second creation unit, configured to create a snapshot of the cloud hard disk to be backed up according to the first component, wherein the snapshot includes the data to be backed up;

[0202] The recovery unit is used to generate a temporary cloud hard disk according to the snapshot and recover the file system, wherein the temporary cloud hard disk is used to temporarily store data to be backed up.

[0203] In some optional implementations, the first backup module 402 includes:

[0204] The first mounting unit is used to mount the temporary cloud hard disk and the encrypted data volume to the host machine;

[0205] A determination unit, used to compare the temporary cloud hard disk and the encrypted data volume using the host machine, determine differential data, and use the differential data as data to be backed up;

[0206] The writing unit is used to write the data to be backed up into the encrypted data volume by using the preset protocol framework of the host machine.

[0207] In some optional embodiments, the first mounting unit includes:

[0208] The first judgment submodule is used to judge whether the temporary cloud hard disk is an encrypted cloud hard disk;

[0209] The first mounting submodule is used to mount the temporary cloud hard disk to the host file directory of the host machine through a preset mounting command if not;

[0210] The second mounting submodule is used for, if yes, decrypting the temporary cloud hard disk by a preset decryption command, and mounting the decrypted temporary cloud hard disk to the host file directory by a preset mounting command;

[0211] The third mounting submodule is used to decrypt the encrypted data volume through a preset decryption command, and mount the decrypted encrypted data volume to a host file directory through a preset mounting command.

[0212] In some optional implementations, the second backup module 403 includes:

[0213] A third creation unit is used to obtain a backup name and a backup size from the backup record, and create a second empty data volume with the same name and size as the backup name on the backup backend, and use the second empty data volume as the backup data volume;

[0214] An unloading unit, used for unloading the encrypted data volume on the host machine;

[0215] An establishing unit, used for establishing a local replication relationship between the encrypted data volume and the backup data volume by using a backup backend;

[0216] The first replication unit is used to replicate the encrypted backup data and encryption information in the encrypted data volume to the backup data volume based on the local replication relationship.

[0217] In some optional implementations, the second backup module 403 includes:

[0218] a fourth creation unit, configured to obtain a backup name and a backup size from the backup record, and create a second empty data volume having the same name and size as the backup name on the backup backend, and use the second empty data volume as the backup data volume;

[0219] The second mounting unit is used to mount the backup data volume to the host machine;

[0220] The second copying unit is used to copy the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume by using the preset protocol framework of the host machine.

[0221] In some optional embodiments, the unloading unit includes:

[0222] A first uninstallation submodule, used to uninstall the encrypted data volume from the host file directory through a preset uninstallation command;

[0223] The close submodule is used to execute the data volume close command and close the encrypted data volume.

[0224] In some optional implementations, the first backup module 402 further includes:

[0225] The second judgment submodule is used to judge whether the temporary cloud hard disk is an encrypted cloud hard disk;

[0226] The second uninstallation submodule is used to uninstall the temporary cloud hard disk from the host file directory through a preset uninstallation command if not;

[0227] The third uninstallation submodule is used to, if yes, uninstall the temporary cloud hard disk from the host file directory through a preset uninstallation command, and execute a cloud hard disk closing command to close the temporary cloud hard disk.

[0228] In some optional implementations, the data acquisition module 401 further includes:

[0229] A first state modifying unit, configured to modify the state of the cloud hard disk to be backed up to being backed up in the database before creating a snapshot of the cloud hard disk to be backed up according to the first component;

[0230] The second state modifying unit is used to modify the state of the cloud hard disk to be backed up to an available state in the database after creating a snapshot of the cloud hard disk to be backed up according to the first component.

[0231] In some optional embodiments, the device further comprises:

[0232] A decryption module is used to decrypt the backup data volume using the key when receiving the data recovery instruction and the key, and obtain the data to be recovered corresponding to the data recovery instruction from the decrypted backup data volume;

[0233] The recovery module is used to determine the target cloud hard disk according to the data recovery instruction and restore the data to be recovered to the target cloud hard disk.

[0234] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0235] The cloud hard disk backup device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0236] The embodiment of the present invention also provides a computer device having the above Figure 4 The cloud hard disk backup device is shown.

[0237] See also Figure 5 , Figure 5 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 5As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 5 A processor 10 is taken as an example.

[0238] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include an integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0239] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.

[0240] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0241] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0242] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0243] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0244] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0245] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined in this application.

Claims

1. A cloud hard disk backup method, characterized in that: The method comprises: Obtain the data to be backed up from the cloud hard disk to be backed up; Acquire an encrypted data volume, and copy the data to be backed up to the encrypted data volume, wherein the encrypted data volume contains encryption information, and the encrypted data volume is used to encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data; The copying of the data to be backed up to the encrypted data volume comprises: mounting a temporary cloud hard disk and the encrypted data volume on a host machine, wherein the temporary cloud hard disk is generated according to a snapshot of the cloud hard disk to be backed up; using the host machine to compare the temporary cloud hard disk and the encrypted data volume, determine differential data, and use the differential data as the data to be backed up; using a preset protocol framework of the host machine to write the data to be backed up into the encrypted data volume; Creating a backup data volume, and copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume; The creating of a backup data volume and copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume include: obtaining a backup name and a backup size from a backup record, creating a second empty data volume with a name identical to the backup name and a size identical to the backup size in a backup backend, and using the second empty data volume as the backup data volume, wherein the backup record includes the backup name and the backup size; unmounting the encrypted data volume on the host machine; establishing a local replication relationship between the encrypted data volume and the backup data volume by using the backup backend; and based on the local replication relationship, copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume.

2. The method according to claim 1, characterized in that The step of obtaining the encrypted data volume includes: Obtaining a list of data volumes corresponding to the cloud hard disk to be backed up on the backup backend; Determine whether there is a data volume in the data volume list whose capacity is the same as the backup size in the backup record and whose encryption type is the same as the encryption type information in the backup record; if so, use the data volume as the encrypted data volume, wherein the backup record is used to represent the backup information of the cloud hard disk to be backed up; If it does not exist, use the first component to create a first empty data volume with the same capacity as the backup size in the backup record in the backup backend, format the first empty data volume using the encryption type information in the backup record, obtain the encrypted data volume and generate the encryption information in the encrypted data volume.

3. The method according to claim 2, characterized in that Before determining whether there is a data volume in the data volume list having a capacity that is the same as the backup size in the backup record and an encryption type that is the same as the encryption type information in the backup record, the method further includes: Obtain encryption algorithm configuration information, encryption operation information, encryption algorithm and key length; Obtaining encryption type information according to the encryption algorithm configuration information, the encryption operation information, the encryption algorithm, and the key length, wherein the encryption type information is used to generate the encryption information in the encrypted data volume; Get the backup name and backup size; The backup record including the encryption type information, the backup name, and the backup size is created in a database.

4. The method according to claim 3, characterized in that The step of obtaining the data to be backed up of the cloud hard disk to be backed up includes: Freeze the file system of the cloud hard disk to be backed up; Creating a snapshot of the cloud hard disk to be backed up according to the first component, wherein the snapshot includes the data to be backed up; A temporary cloud hard disk is generated according to the snapshot, and the file system is restored, wherein the temporary cloud hard disk is used to temporarily store the data to be backed up.

5. The method according to claim 4, characterized in that The step of mounting the temporary cloud hard disk and the encrypted data volume on the host machine includes: Determine whether the temporary cloud hard disk is an encrypted cloud hard disk; If not, the temporary cloud hard disk is mounted to the host file directory of the host machine through a preset mount command; If yes, decrypt the temporary cloud hard disk using a preset decryption command, and mount the decrypted temporary cloud hard disk to the host file directory using the preset mount command; The encrypted data volume is decrypted by the preset decryption command, and the decrypted encrypted data volume is mounted to the host file directory by the preset mounting command.

6. The method according to claim 4, characterized in that The step of creating a backup data volume and copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume includes: Acquire the backup name and the backup size from the backup record, create a second empty data volume with the same name and the same size as the backup name on the backup backend, and use the second empty data volume as the backup data volume; Mounting the backup data volume to the host machine; The encrypted backup data and the encryption information in the encrypted data volume are copied to the backup data volume by using the preset protocol framework of the host machine.

7. The method according to claim 4, characterized in that Unmounting the encrypted data volume on the host machine includes: Uninstalling the encrypted data volume from the host file directory using a preset uninstall command; Execute a data volume closing command to close the encrypted data volume.

8. The method according to claim 4, characterized in that After writing the data to be backed up into the encrypted data volume, the method further includes: Determine whether the temporary cloud hard disk is an encrypted cloud hard disk; If not, uninstall the temporary cloud hard disk from the host file directory using a preset uninstall command; If yes, the temporary cloud hard disk is uninstalled from the host file directory through the preset uninstall command, and the cloud hard disk close command is executed to close the temporary cloud hard disk.

9. The method according to claim 4, characterized in that The method further comprises: Before creating the snapshot of the cloud hard disk to be backed up according to the first component, modifying the status of the cloud hard disk to be backed up in the database to be in backup; After creating the snapshot of the cloud hard disk to be backed up according to the first component, modifying the status of the cloud hard disk to be backed up to an available status in the database.

10. The method according to claim 1, characterized in that After copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume, the method further includes: When receiving the data recovery instruction and the key, decrypting the backup data volume using the key, and obtaining the to-be-recovered data corresponding to the data recovery instruction from the decrypted backup data volume; A target cloud hard disk is determined according to the data recovery instruction, and the data to be recovered is recovered to the target cloud hard disk.

11. A cloud hard disk backup device, characterized in that: The device comprises: A data acquisition module is used to acquire the data to be backed up from the cloud hard disk to be backed up; A first backup module, used to obtain an encrypted data volume, and copy the data to be backed up to the encrypted data volume, wherein the encrypted data volume contains encryption information, and the encrypted data volume is used to encrypt the data to be backed up according to the encryption information, and obtain and save the encrypted backup data; The first backup module includes: a first mounting unit, used to mount a temporary cloud hard disk and the encrypted data volume to a host machine, wherein the temporary cloud hard disk is generated according to a snapshot of the cloud hard disk to be backed up; a determining unit, used to compare the temporary cloud hard disk and the encrypted data volume using the host machine, determine difference data, and use the difference data as the data to be backed up; a writing unit, used to write the data to be backed up into the encrypted data volume using a preset protocol framework of the host machine; A second backup module, used for creating a backup data volume, and copying the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume; The second backup module includes: a third creation unit, used to obtain a backup name and a backup size from a backup record, and create a second empty data volume with a name identical to the backup name and a size identical to the backup size on a backup backend, and use the second empty data volume as the backup data volume, wherein the backup record includes the backup name and the backup size; an unloading unit, used to unload the encrypted data volume on the host machine; an establishment unit, used to establish a local replication relationship between the encrypted data volume and the backup data volume using the backup backend; and a first replication unit, used to copy the encrypted backup data and the encryption information in the encrypted data volume to the backup data volume based on the local replication relationship.

12. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the cloud hard disk backup method according to any one of claims 1 to 10 by executing the computer instructions.

13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the cloud hard disk backup method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Method and system for managing cloud disk

    CN116383870A