A virtual machine protection system and method
By combining a virtual protection server and a proxy virtual machine, snapshots are created and data blocks are managed, solving the problem that existing virtual machine protection schemes cannot efficiently protect virtual machine data while ensuring stable operation, and achieving efficient data backup and recovery.
Patent Information
- Application Number
- CN202411878118.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-19
AI Technical Summary
Existing technologies cannot efficiently protect virtual machines related to computing, storage, and network resources within a cloud platform while ensuring their stable operation, thus failing to guarantee virtual machine data security.
A combination of virtual protection servers and proxy virtual machines is used to achieve data backup and recovery of virtual machines by creating snapshots, generating snapshot copy disks, reading and storing data blocks, and managing backup files.
It efficiently backs up and restores data for virtual machines in the cloud platform, ensuring the data security of virtual machines without affecting the stable operation of the cloud platform and virtual machines.
Smart Images

Figure CN119759500B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a virtual machine protection system and method. Background Technology
[0002] Enterprises typically employ cloud platforms to provide computing, storage, and network resources. These cloud platforms contain multiple virtual machines (VMs) that are associated with these resources. VMs are the most fundamental and crucial resource of a cloud platform. Each VM can perform almost all the functions of a physical computer. Therefore, during the operation of a cloud platform, it is essential to protect the VMs associated with these resources and ensure their data security.
[0003] Common virtual machine protection schemes in related technologies include: installing services or plugins within the cloud platform to protect virtual machines; installing applications on the virtual machine systems of the cloud platform to protect virtual machines; or using third-party tools to transfer virtual machine data to protect virtual machines. Installing services or plugins within the cloud platform is somewhat destructive and can affect the stability of the entire cloud platform. Installing applications on the virtual machine systems of the cloud platform requires login information such as usernames and passwords, which is inaccessible to virtual machines in sensitive departments and can easily corrupt the virtual machine state. If a large number of virtual machines need to be migrated, it will result in a huge workload. Using third-party tools to transfer virtual machine data requires encryption, compression, bandwidth control, congestion control, and performance tuning, which is quite difficult. The virtual machine protection schemes in these technologies cannot efficiently protect virtual machines related to computing, storage, and network resources within the cloud platform while ensuring the stable operation of the cloud platform and virtual machines, thus failing to guarantee the data security of virtual machines. Summary of the Invention
[0004] This invention provides a virtual machine protection system and method to address the problem that existing virtual machine protection schemes cannot efficiently protect virtual machines related to computing, storage, and network resources on a cloud platform while ensuring the stable operation of the cloud platform and virtual machines, thereby guaranteeing the data security of virtual machines.
[0005] According to one aspect of the present invention, a virtual machine protection system is provided, comprising: a virtual protection server, a cloud platform to be protected, and a backup cloud platform corresponding to the cloud platform to be protected;
[0006] The cloud platform to be protected is equipped with a first agent virtual machine and multiple source virtual machines to be protected, and the backup cloud platform is equipped with a second agent virtual machine.
[0007] When the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine. The first agent virtual machine reads the data in the snapshot copy disk sequentially according to a preset data volume, obtains multiple data blocks, and stores each data block and its data block information in the backup file corresponding to the source virtual machine in the virtual protection server. After determining that the storage process of each data block and its data block information is complete, the virtual protection server unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk.
[0008] When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and sends each data block and its data information from the backup file to the second agent virtual machine. The second agent virtual machine writes each data block from the backup file to the disk of the target virtual machine according to its data information. After determining that the writing process of each data block is complete, the virtual protection server remounts the disk of the target virtual machine to the target virtual machine.
[0009] According to another aspect of the present invention, a virtual machine protection method is provided, applied to the virtual machine protection system described in the embodiments of the present invention, comprising:
[0010] When the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine.
[0011] The first agent virtual machine reads the data in the snapshot copy disk sequentially according to the preset data volume to obtain multiple data blocks, and stores each data block and the data block information of each data block in the backup file corresponding to the source virtual machine in the virtual protection server;
[0012] After the virtual protection server completes the storage process of determining each data block and the data block information of each data block, it unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk.
[0013] When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and sends each data block and the data information of each data block in the backup file to the second agent virtual machine.
[0014] The second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the data information of each data block in the backup file;
[0015] After the virtual protection server determines that the writing process of each data block is complete, it remounts the disk of the target virtual machine to the target virtual machine.
[0016] In the technical solution of this invention, when the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine. The first agent virtual machine reads the data in the snapshot copy disk sequentially according to a preset data volume, obtains multiple data blocks, and stores each data block and its data block information in the backup file corresponding to the source virtual machine in the virtual protection server. After determining that the storage process of each data block and its data block information is complete, the virtual protection server unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk. Then, when the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and stores each data block in the backup file. The data information of each data block is sent to the second agent virtual machine; the second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the data information of each data block in the backup file; after the virtual protection server determines that the writing process of each data block is complete, it remounts the disk of the target virtual machine to the target virtual machine. This solves the problem that virtual machine protection schemes in related technologies cannot efficiently protect virtual machines related to computing resources, storage resources and network resources in the cloud platform while ensuring the stable operation of the cloud platform and virtual machines, and ensure the data security of virtual machines. Based on the virtual protection server, the second agent virtual machine, and the second agent virtual machine, data backup and recovery of virtual machines related to computing resources, storage resources and network resources in the cloud platform can be performed efficiently, thereby protecting virtual machines related to computing resources, storage resources and network resources in the cloud platform, ensuring the data security of virtual machines, and not affecting the stable operation of the cloud platform and virtual machines.
[0017] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram of the structure of a virtual machine protection system provided in Embodiment 1 of the present invention.
[0020] Figure 2 This is a flowchart of a virtual machine protection method provided in Embodiment 2 of the present invention. Detailed Implementation
[0021] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0022] It should be noted that the terms "target," "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising," "including," and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0023] Example 1
[0024] Figure 1This is a schematic diagram of a virtual machine protection system provided in Embodiment 1 of the present invention. This embodiment is applicable to protecting virtual machines related to computing resources, storage resources, and network resources in a cloud platform, ensuring the data security of the virtual machines. Figure 1 As shown, the virtual machine protection system may specifically include: a virtual protection server 101, a cloud platform to be protected 102, and a backup cloud platform 103 corresponding to the cloud platform to be protected 102. Its structure and functions are described below.
[0025] The cloud platform to be protected 102 is equipped with a first agent virtual machine 1021 and multiple source virtual machines 1022 to be protected, while the backup cloud platform 103 is equipped with a second agent virtual machine 1031.
[0026] When the virtual protection server 101 receives a backup request corresponding to any source virtual machine 1022, it creates a snapshot of the source virtual machine 1022, obtains the snapshot disk information of the source virtual machine 1022, generates a snapshot copy disk of the source virtual machine 1022 based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine 1021. The first agent virtual machine 1021 reads the data in the snapshot copy disk sequentially according to a preset data volume, obtains multiple data blocks, and stores each data block and its data block information in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101. After determining that the storage process of each data block and its data block information is complete, the virtual protection server 101 unmounts the snapshot copy disk mounted to the first agent virtual machine 1021 and deletes the snapshot copy disk. Then, when the virtual protection server 101 receives a recovery request corresponding to the source virtual machine 1022, it creates a target virtual machine 1032 corresponding to the source virtual machine 1022 on the backup cloud platform 103 according to the backup file, mounts the disk of the target virtual machine 1032 to the second agent virtual machine 1031, and sends each data block and its data information from the backup file to the second agent virtual machine 1031. The second agent virtual machine 1031 writes each data block from the backup file to the disk of the target virtual machine 1032 according to the data information of each data block in the backup file. After determining that the writing process of each data block is complete, the virtual protection server 101 remounts the disk of the target virtual machine 1032 back to the target virtual machine 1032.
[0027] Optionally, the cloud platform 102 to be protected can be a cloud platform set up within an enterprise to provide computing, storage, and network resources. The cloud platform 102 contains multiple virtual machines related to these computing, storage, and network resources. During the operation of the cloud platform 102, it is necessary to protect the virtual machines related to these resources to ensure their data security. Each virtual machine related to computing, storage, and network resources in the cloud platform 102 is a source virtual machine 1022 to be protected.
[0028] Optionally, the first agent virtual machine 1021 is a virtual machine set up in the cloud platform 102 to be protected, specifically for working with the virtual protection server 101 to back up the source virtual machine 1022.
[0029] Optionally, the backup cloud platform 103 corresponding to the cloud platform to be protected 102 is a cloud platform used in conjunction with the virtual protection server 101 to perform data recovery on the source virtual machine 1022 based on the backup data of the source virtual machine 1022 in the cloud platform to be protected 102.
[0030] Optionally, the second agent virtual machine 1031 is a virtual machine set up in the backup cloud platform 103 specifically for working with the virtual protection server 101 to perform data recovery on the source virtual machine 1022.
[0031] Optionally, the virtual protection server 101 can be a server set up in an enterprise to perform data backup and data recovery on the source virtual machine 1022 in the cloud platform 102 to be protected, thereby protecting the virtual machines related to computing resources, storage resources and network resources in the cloud platform 102 to be protected and ensuring the data security of the virtual machines.
[0032] Optionally, the virtual protection server 101 can manage the cloud platform 102 to be protected and the backup cloud platform 103 through the Representational State Transfer (Restful) interface on the cloud platform to be protected and the backup cloud platform 103.
[0033] Optionally, the backup request corresponding to the source virtual machine 1022 can be a request to back up data on the source virtual machine 1022. The backup request corresponding to the source virtual machine 1022 can be sent by the target user via a terminal device. The target user can be a technical personnel managing the cloud platform 102 to be protected.
[0034] Optionally, backing up the source virtual machine 1022 can refer to copying the data from the disk of the source virtual machine 1022 to a backup file corresponding to the source virtual machine 1022 in the virtual protection server 101. The backup file corresponding to the source virtual machine 1022 can be a file set in the virtual protection server 101 for storing the data from the disk of the source virtual machine 1022.
[0035] Optionally, when the virtual protection server 101 receives a backup request corresponding to any one of the source virtual machines 1022, it creates a snapshot of the source virtual machine 1022, obtains the snapshot disk information of the source virtual machine 1022, and then generates a snapshot copy disk of the source virtual machine 1022 according to the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine 1021.
[0036] Optionally, creating a snapshot of the source virtual machine 1022 can refer to saving the state and data of the source virtual machine 1022 at the current moment. The state of the source virtual machine 1022 can include the power state of the source virtual machine 1022. The power state of the source virtual machine 1022 can be either powered on or powered off / suspended. The data of the source virtual machine 1022 can include data in the disk, memory, and other devices of the source virtual machine 1022. The snapshot disk information of the source virtual machine 1022 can refer to the saved data in the disk of the source virtual machine 1022. The snapshot disk information of the source virtual machine 1022 includes the virtual machine configuration information and disk information of the source virtual machine 1022. The virtual machine configuration information can be information related to the specifications of the source virtual machine 1022. The disk information can be the capacity and name of the disk in the source virtual machine 1022. The virtual protection server 101 can create a snapshot of the source virtual machine 1022 and obtain the snapshot disk information of the source virtual machine 1022 when it receives a backup request corresponding to any source virtual machine 1022.
[0037] Optionally, the snapshot copy disk of the source virtual machine 1022 is the same disk as the original disk of the source virtual machine 1022. The snapshot copy disk stores the saved data from the original disk of the source virtual machine 1022. The location of the data on the snapshot copy disk is the same as its location on the original disk of the source virtual machine 1022. The virtual protection server 101 can generate a snapshot copy disk of the source virtual machine 1022 based on its snapshot disk information and mount the snapshot copy disk to the first agent virtual machine 1021.
[0038] Optionally, after the first agent virtual machine 1021 is mounted to the snapshot copy disk, it can sequentially read the data in the snapshot copy disk according to a preset data volume to obtain multiple data blocks, and store each data block and its data block information in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101.
[0039] Optionally, the data block information includes: location information, size information, and hash value. The data block information can refer to the location information, size information, and hash value of the data block. The location information of the data block can refer to the location of the data block within the snapshot copy disk. The size information of the data block can refer to the amount of data in the data block. The hash value of the data block can be the hash value of the data block calculated according to a preset hash algorithm. The preset hash algorithm can be a pre-set algorithm used to calculate the hash value of the data block.
[0040] Optionally, the first agent virtual machine 1021 sequentially reads the data in the snapshot copy disk according to a preset data volume to obtain multiple data blocks, and stores each data block and its data block information in a backup file in the virtual protection server 101 corresponding to the source virtual machine 1022. This includes: the first agent virtual machine 1021 sequentially reading the data in the snapshot copy disk according to a preset data volume to obtain multiple data blocks; the first agent virtual machine 1021 determining the data block information of each data block; and the first agent virtual machine 1021 storing each data block and its data block information in a backup file in the virtual protection server 101 corresponding to the source virtual machine 1022.
[0041] Optionally, the preset data volume can be a pre-set data volume. The first agent virtual machine 1021 can sequentially read the preset data volume from the beginning of the data in the snapshot copy disk of the source virtual machine 1022 until the end of the data in the snapshot copy disk. Each preset data volume read constitutes a data block. The data blocks are arranged in the order they are read. The first data block read is placed first, and the last data block read is placed last.
[0042] Optionally, if the amount of data remaining is less than the preset data amount, the remaining data is read, and a data block is defined to obtain the last data block. The amount of data in the last data block is less than the preset data amount. If the amount of data remaining is equal to the preset data amount, the remaining data is read, and a data block is defined to obtain the last data block. The amount of data in the last data block is equal to the preset data amount.
[0043] Optionally, for each data block, the first agent virtual machine 1021 can detect the location and size of the data block to obtain the location and size information of the data block, calculate the hash value of the data block according to the preset hash algorithm, and thus determine the data block information, which includes: location information, size information and hash value.
[0044] Optionally, the first proxy virtual machine 1021 stores each of the data blocks and the data block information of each of the data blocks in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101, including: if the backup request is a full backup request, the first proxy virtual machine 1021 sequentially determines whether each of the data blocks is a non-empty data block, and stores the data block information of the non-empty data block and the non-empty data block in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101.
[0045] Optionally, a full backup request can refer to a backup request that requests the copying of all data from the disk of the source virtual machine 1022 to the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101. A non-empty data block can refer to a data block containing data that is not all zeros.
[0046] Optionally, determining whether each data block is a non-empty data block includes: performing the following operation for each data block: determining whether all data in the data block is 0; if yes, then determining that the data block is not a non-empty data block; if no, then determining that the data block is a non-empty data block. The first agent virtual machine 1021 stores each data block determined to be a non-empty data block and the data block information of each data block determined to be a non-empty data block in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101.
[0047] Optionally, the first agent virtual machine 1021 stores each of the data blocks and the data block information of each of the data blocks in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101, including: if the backup request is an incremental backup request, the first agent virtual machine 1021 detects whether each of the data blocks is a changed data block according to the hash value of each of the data blocks and the historical disk hash value list corresponding to the source virtual machine 1022, and stores the changed data block and the data block information of the changed data block in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101.
[0048] Optionally, an incremental backup request can refer to a backup request that requests the copying of data from the disk of the source virtual machine 1022 that has changed since the last data backup to the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101. The historical disk hash value list corresponding to the source virtual machine 1022 can be a list set in the first agent virtual machine 1021 for storing the hash values of each data block obtained during the last data backup of the source virtual machine 1022. The order of the hash values of each data block in the historical disk hash value list is the same as the order of the data blocks themselves. A changed data block can refer to a data block whose data has changed since the last data backup.
[0049] Optionally, based on the hash value of each data block and the historical disk hash value list corresponding to the source virtual machine 1022, the detection of whether each data block is a changed data block includes: for each data block, performing the following operation: determining whether the hash value of the data block is the same as the hash value of the data block in the historical disk hash value list corresponding to the source virtual machine 1022, where the data block is in the same sorted position as the data block; if yes, then the data block is determined not to be a changed data block; if no, then the data block is determined to be a changed data block. The first proxy virtual machine 1021 stores each data block determined to be a changed data block and the data block information of each data block determined to be a changed data block in the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101.
[0050] Optionally, after completing the process of storing each data block and its data block information into the backup file corresponding to the source virtual machine 1022 in the virtual protection server 101, the first agent virtual machine 1021 may send a first completion notification to the virtual protection server 101. The first completion notification may be pre-set information indicating that the first agent virtual machine 1021 has completed the process of storing the data blocks and their data block information into the corresponding backup file.
[0051] Optionally, after receiving the first completion prompt, the virtual protection server 101 may determine that the storage process for each data block and its data block information is complete. After determining that the storage process for each data block and its data block information is complete, the virtual protection server 101 unmounts the snapshot copy disk mounted to the first agent virtual machine 1021, thereby determining that the data backup process of the source virtual machine 1022 is complete.
[0052] Optionally, after determining that the data backup process of the source virtual machine 1022 is complete, the virtual protection server 101 sends a data backup completion notification to the target user's terminal device. The data backup completion notification may be pre-set information indicating the completion of the data backup process. The target user's terminal device may be any terminal device used by the target user.
[0053] Optionally, after the virtual protection server 101 unmounts the snapshot copy disk mounted to the first agent virtual machine 1021, it deletes the snapshot copy disk.
[0054] Optionally, the recovery request corresponding to the source virtual machine 1022 can be a request to recover data from the source virtual machine 1022. The recovery request corresponding to the source virtual machine 1022 can be sent by the target user through a terminal device. Recovering data from the source virtual machine 1022 can refer to creating a target virtual machine 1032 corresponding to the source virtual machine 1022 on the backup cloud platform, and storing the data from the disk of the source virtual machine 1022 in the backup file corresponding to the source virtual machine 1022 copied to the virtual protection server 101, into the disk of the target virtual machine 1032. The target virtual machine 1032 corresponding to the source virtual machine 1022 can be a virtual machine with the same specifications as the source virtual machine 1022. Alternatively, the target virtual machine 1032 corresponding to the source virtual machine 1022 can also be a virtual machine with specifications consistent with a user-defined virtual machine. A user-defined virtual machine can be a virtual machine specified by the target user.
[0055] Optionally, when the virtual protection server 101 receives a recovery request corresponding to the source virtual machine 1022, it creates a target virtual machine 1032 corresponding to the source virtual machine 1022 on the backup cloud platform 103 according to the backup file. This includes: when the virtual protection server 101 receives a recovery request corresponding to the source virtual machine 1022, it creates a target virtual machine 1032 corresponding to the source virtual machine 1022 on the backup cloud platform 103 according to the virtual machine configuration information and disk information in the backup file; wherein, the target virtual machine 1032 is a virtual machine with the same specifications as the source virtual machine 1022. The virtual protection server 101 can create a virtual machine with the same specifications as the source virtual machine 1022, i.e., the target virtual machine 1032 corresponding to the source virtual machine 1022, on the backup cloud platform 103 according to the virtual machine configuration information and disk information of the source virtual machine 1022 in the backup file.
[0056] Optionally, when the virtual protection server 101 receives a recovery request corresponding to the source virtual machine 1022, it creates a target virtual machine 1032 corresponding to the source virtual machine 1022 on the backup cloud platform 103 according to the backup file. This includes: when the virtual protection server 101 receives a recovery request corresponding to the source virtual machine 1022, it creates the target virtual machine 1032 corresponding to the source virtual machine 1022 on the backup cloud platform 103 according to the user-defined settings information corresponding to the source virtual machine 1022; wherein, the target virtual machine 1032 is a virtual machine with specifications consistent with the user-defined virtual machine. The user-defined settings information corresponding to the source virtual machine 1022 may be information related to the specifications of the user-defined virtual machine. The information related to the specifications of the user-defined virtual machine includes, but is not limited to, information describing the processor and disk of the user-defined virtual machine. The user-defined settings information corresponding to the source virtual machine 1022 may be stored in the backup file by the target user. Virtual protection server 101 can create a virtual machine with the same specifications as the user-defined virtual machine on backup cloud platform 103, i.e., target virtual machine 1032 corresponding to the source virtual machine 1022, based on user-defined settings information corresponding to the source virtual machine 1022. The disk of the user-defined virtual machine has the same specifications as the disk of the source virtual machine 1022.
[0057] Optionally, after creating a target virtual machine 1032 corresponding to the source virtual machine 1022, the virtual protection server 101 mounts the disk of the target virtual machine 1032 to the second agent virtual machine 1031 and sends each data block and its data information from the backup file to the second agent virtual machine 1031. Upon receiving the data blocks and their data information from the backup file, the second agent virtual machine 1031 writes each data block from the backup file to the disk of the target virtual machine 1032 according to the data information in the backup file.
[0058] Optionally, the second proxy virtual machine 1031 writes each data block in the backup file to the disk of the target virtual machine 1032 according to the data information of each data block in the backup file. This includes: the second proxy virtual machine 1031 writes each data block in the backup file to the disk of the target virtual machine 1032 according to the location and size information of each data block. For each data block, the second proxy virtual machine 1031 can write the data block to the disk of the target virtual machine 1032 according to the location and size information in the data block's data information, so that the position of the data block in the disk of the target virtual machine 1032 corresponding to the source virtual machine 1022 is the same as the position of the data block in the disk of the source virtual machine 1022.
[0059] Optionally, after completing the process of writing each data block from the backup file to the disk of the target virtual machine 1032, the second agent virtual machine 1031 may send a second completion message to the virtual protection server 101. The second completion message may be pre-set information indicating that the second agent virtual machine 1031 has completed the process of writing each data block from the backup file to the disk of the target virtual machine 1032.
[0060] Optionally, after receiving the second completion notification, the virtual protection server 101 can determine that the writing process of each data block is complete. After determining that the writing process of each data block is complete, the virtual protection server 101 remounts the disk of the target virtual machine 1032 to the target virtual machine 1032, and determines that the data recovery process of the source virtual machine 1022 is complete.
[0061] Optionally, after determining that the data recovery process of the source virtual machine 1022 is complete, the virtual protection server 101 sends a data recovery completion notification to the target user's terminal device. The data recovery completion notification may be pre-set information indicating the completion of the data recovery process.
[0062] Optionally, the virtual machine protection system further includes a user interaction module, used to provide data related to the virtual protection server, the cloud platform to be protected, or the backup cloud platform to the target user through a user interaction page.
[0063] Optionally, the user interaction module can be an electronic device used to provide data related to the virtual protection server 101, the cloud platform to be protected 102, or the backup cloud platform 103 to a target user. The user interaction page can be a page set in the user interaction module for user interaction. The data related to the virtual protection server 101, the cloud platform to be protected 102, or the backup cloud platform 103 includes, but is not limited to, data related to users, licenses, permissions, logs, historical records, and rules of the virtual protection server 101, the cloud platform to be protected 102, or the backup cloud platform 103.
[0064] In the technical solution of this invention, when the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine. The first agent virtual machine reads the data in the snapshot copy disk sequentially according to a preset data volume, obtains multiple data blocks, and stores each data block and its data block information in the backup file corresponding to the source virtual machine in the virtual protection server. After determining that the storage process of each data block and its data block information is complete, the virtual protection server unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk. Then, when the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and stores each data block in the backup file. The data information of each data block is sent to the second agent virtual machine; the second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the data information of each data block in the backup file; after the virtual protection server determines that the writing process of each data block is complete, it remounts the disk of the target virtual machine to the target virtual machine. This solves the problem that virtual machine protection schemes in related technologies cannot efficiently protect virtual machines related to computing resources, storage resources and network resources in the cloud platform while ensuring the stable operation of the cloud platform and virtual machines, and ensure the data security of virtual machines. Based on the virtual protection server, the second agent virtual machine, and the second agent virtual machine, data backup and recovery of virtual machines related to computing resources, storage resources and network resources in the cloud platform can be performed efficiently, thereby protecting virtual machines related to computing resources, storage resources and network resources in the cloud platform, ensuring the data security of virtual machines, and not affecting the stable operation of the cloud platform and virtual machines.
[0065] Example 2
[0066] Figure 2 This is a flowchart illustrating a virtual machine protection method provided in Embodiment 2 of the present invention. This method can be executed by the virtual machine protection system provided in the above embodiments of the present invention. Figure 2 As shown, the method in this embodiment specifically includes:
[0067] Step 201: When the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine.
[0068] Step 202: The first agent virtual machine reads the data in the snapshot copy disk sequentially according to the preset data volume to obtain multiple data blocks, and stores each data block and its data block information in the backup file corresponding to the source virtual machine in the virtual protection server.
[0069] Optionally, the data block information includes: location information, size information, and hash value.
[0070] Optionally, the first agent virtual machine sequentially reads data from the snapshot copy disk according to a preset data volume to obtain multiple data blocks, and stores each data block and its data block information in a backup file corresponding to the source virtual machine in the virtual protection server. This includes: the first agent virtual machine sequentially reading data from the snapshot copy disk according to a preset data volume to obtain multiple data blocks; the first agent virtual machine determining the data block information of each data block; and the first agent virtual machine storing each data block and its data block information in a backup file corresponding to the source virtual machine in the virtual protection server.
[0071] Optionally, the first agent virtual machine stores each of the data blocks and the data block information of each of the data blocks into a backup file in the virtual protection server corresponding to the source virtual machine, including: if the backup request is a full backup request, the first agent virtual machine sequentially determines whether each of the data blocks is a non-empty data block, and stores the data block information of the non-empty data block and the non-empty data block into a backup file in the virtual protection server corresponding to the source virtual machine.
[0072] Optionally, the first agent virtual machine stores each of the data blocks and the data block information of each of the data blocks in a backup file corresponding to the source virtual machine in the virtual protection server, including: if the backup request is an incremental backup request, the first agent virtual machine detects whether each of the data blocks is a changed data block according to the hash value of each of the data blocks and the historical disk hash value list corresponding to the source virtual machine, and stores the changed data block and the data block information of the changed data block in the backup file corresponding to the source virtual machine in the virtual protection server.
[0073] Step 203: After the virtual protection server completes the process of determining the storage of each data block and the data block information of each data block, it unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk.
[0074] Step 204: When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and sends each data block and its data information in the backup file to the second agent virtual machine.
[0075] Optionally, when the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file. This includes: when the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the virtual machine configuration information and disk information in the backup file; wherein, the target virtual machine is a virtual machine with the same specifications as the source virtual machine.
[0076] Optionally, when the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file. This includes: when the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the user-defined settings information corresponding to the source virtual machine; wherein, the target virtual machine is a virtual machine with the same specifications as the user-defined virtual machine.
[0077] Step 205: The second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the data information of each data block in the backup file.
[0078] Optionally, the second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the data information of each data block in the backup file, including: the second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the location information and size information of each data block.
[0079] Step 206: After the virtual protection server determines that the writing process of each data block is complete, it remounts the disk of the target virtual machine to the target virtual machine.
[0080] In the technical solution of this invention, when the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine. The first agent virtual machine reads the data in the snapshot copy disk sequentially according to a preset data volume, obtains multiple data blocks, and stores each data block and its data block information in the backup file corresponding to the source virtual machine in the virtual protection server. After determining that the storage process of each data block and its data block information is complete, the virtual protection server unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk. Then, when the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and stores each data block in the backup file. The data information of each data block is sent to the second agent virtual machine; the second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the data information of each data block in the backup file; after the virtual protection server determines that the writing process of each data block is complete, it remounts the disk of the target virtual machine to the target virtual machine. This solves the problem that virtual machine protection schemes in related technologies cannot efficiently protect virtual machines related to computing resources, storage resources and network resources in the cloud platform while ensuring the stable operation of the cloud platform and virtual machines, and ensure the data security of virtual machines. Based on the virtual protection server, the second agent virtual machine, and the second agent virtual machine, data backup and recovery of virtual machines related to computing resources, storage resources and network resources in the cloud platform can be performed efficiently, thereby protecting virtual machines related to computing resources, storage resources and network resources in the cloud platform, ensuring the data security of virtual machines, and not affecting the stable operation of the cloud platform and virtual machines.
[0081] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0082] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A virtual machine protection system, characterized in that, include: Virtual protection server, cloud platform to be protected, and backup cloud platform corresponding to the cloud platform to be protected; The cloud platform to be protected is equipped with a first agent virtual machine and multiple source virtual machines to be protected, and the backup cloud platform is equipped with a second agent virtual machine. When the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine. The first agent virtual machine reads the data in the snapshot copy disk sequentially according to a preset data volume, obtains multiple data blocks, and stores each data block and its data block information in the backup file corresponding to the source virtual machine in the virtual protection server. After determining that the storage process of each data block and its data block information is complete, the virtual protection server unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk. When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and sends each data block and its data information from the backup file to the second agent virtual machine. The second agent virtual machine writes each data block from the backup file to the disk of the target virtual machine according to its data information. After determining that the writing process of each data block is complete, the virtual protection server remounts the disk of the target virtual machine to the target virtual machine.
2. The virtual machine protection system according to claim 1, characterized in that, Also includes: The user interaction module is used to provide data related to the virtual protection server, the cloud platform to be protected, or the backup cloud platform to the target user through a user interaction page.
3. A virtual machine protection method, applied to the virtual machine protection system as described in claim 1, characterized in that, include: When the virtual protection server receives a backup request corresponding to any source virtual machine, it creates a snapshot of the source virtual machine, obtains the snapshot disk information of the source virtual machine, generates a snapshot copy disk of the source virtual machine based on the snapshot disk information, and mounts the snapshot copy disk to the first agent virtual machine. The first agent virtual machine reads the data in the snapshot copy disk sequentially according to the preset data volume to obtain multiple data blocks, and stores each data block and the data block information of each data block in the backup file corresponding to the source virtual machine in the virtual protection server; After the virtual protection server completes the storage process of determining each data block and the data block information of each data block, it unmounts the snapshot copy disk mounted to the first agent virtual machine and deletes the snapshot copy disk. When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the backup file, mounts the disk of the target virtual machine to the second agent virtual machine, and sends each data block and the data information of each data block in the backup file to the second agent virtual machine. The second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine according to the data information of each data block in the backup file; After the virtual protection server determines that the writing process of each data block is complete, it remounts the disk of the target virtual machine to the target virtual machine.
4. The virtual machine protection method according to claim 3, characterized in that, The data block information includes: location information, size information, and hash value.
5. The virtual machine protection method according to claim 4, characterized in that, The first agent virtual machine sequentially reads the data from the snapshot copy disk according to a preset data volume, obtaining multiple data blocks. Each data block and its data block information are then stored in a backup file corresponding to the source virtual machine on the virtual protection server, including: The first agent virtual machine reads the data in the snapshot copy disk sequentially according to a preset data volume to obtain multiple data blocks; The first agent virtual machine determines the data block information of each data block; The first agent virtual machine stores each data block and its data block information into a backup file in the virtual protection server corresponding to the source virtual machine.
6. The virtual machine protection method according to claim 5, characterized in that, The first agent virtual machine stores each of the data blocks and the data block information of each data block into a backup file corresponding to the source virtual machine in the virtual protection server, including: If the backup request is a full backup request, the first agent virtual machine sequentially determines whether each data block is a non-empty data block, and stores the data block information of the non-empty data blocks and the non-empty data blocks in the backup file corresponding to the source virtual machine in the virtual protection server.
7. The virtual machine protection method according to claim 5, characterized in that, The first agent virtual machine stores each of the data blocks and the data block information of each data block into a backup file corresponding to the source virtual machine in the virtual protection server, including: If the backup request is an incremental backup request, the first agent virtual machine detects whether each data block is a changed data block based on the hash value of each data block and the historical disk hash value list corresponding to the source virtual machine, and stores the changed data block and the data block information of the changed data block in the backup file corresponding to the source virtual machine in the virtual protection server.
8. The virtual machine protection method according to claim 3, characterized in that, When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform based on the backup file, including: When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the virtual machine configuration information and disk information in the backup file; wherein, the target virtual machine is a virtual machine with the same specifications as the source virtual machine.
9. The virtual machine protection method according to claim 3, characterized in that, When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform based on the backup file, including: When the virtual protection server receives a recovery request corresponding to the source virtual machine, it creates a target virtual machine corresponding to the source virtual machine on the backup cloud platform according to the user-defined settings information corresponding to the source virtual machine; wherein, the target virtual machine is a virtual machine with the same specifications as the user-defined virtual machine.
10. The virtual machine protection method according to claim 3, characterized in that, The second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine based on the data information of each data block in the backup file, including: The second agent virtual machine writes each data block in the backup file to the disk of the target virtual machine based on the location and size information of each data block.
Citation Information
Patent Citations
System and method for realizing cross-cloud rapid recovery of virtual machine based on cloud platform volume
CN112506616A
Virtual machine migration system and method
CN113515343A