Data backup method and device, data recovery method and device and electronic equipment
By obtaining and encrypting data based on backup policies during the data backup process and writing it to a disk-based backup storage pool, the problems of complex operation and maintenance, waste of space resources and data tampering in the existing technology are solved, and efficient and secure data backup and recovery are achieved.
Patent Information
- Application Number
- CN202510244057.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-30
AI Technical Summary
In the data backup process, the existing technology has the risks of data tampering complex operation and maintenance, wasted space resources, reading and writing performance bottlenecks, and data tampering risks caused by inability to be truly offline.
By obtaining the data to be backed up based on the backup policy in the server, encrypting the data using an encryption key, and sending the encrypted data to a backup storage pool built on disk for writing, the data document attributes are set to read-only to ensure the security and integrity of the data.
It improves the efficiency and maintainability of data backup, prevents illegal access and tampering of backup data by network attacks, and ensures the originality and consistency of backup data.
Smart Images

Figure CN120066860A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a data backup method, a data recovery method, a device, and an electronic device. Background Art
[0002] Backing up data is the basis for quickly restoring a production system after a cyber-attack, and the backed-up data contains real production data, whose security is crucial, and it is necessary to prevent the backed-up data from being deleted, tampered with, and leaked.
[0003] Traditional backup solutions use tapes for data backup. To achieve true offline data anti-tampering, the tapes need to be taken out of the tape library as soon as possible after the data is written to the tapes. This solution, on the one hand, leads to complex operation and maintenance, especially when the tapes are not full, there is also a waste of space resources; on the other hand, due to the read-write performance bottleneck of the tapes, it cannot meet the timeliness requirements of large-scale data backup. Based on these drawbacks, existing technologies usually use disks for data backup, but since disks cannot be truly offline, the data is extremely vulnerable to ransomware attacks and data tampering threats. Therefore, it is necessary to provide a new data backup method to ensure the security of the backed-up data. Summary of the Invention
[0004] This application provides a data backup method, a data recovery method, a device, and an electronic device, which can improve the efficiency and maintainability of data backup and prevent illegal access and tampering of the backed-up data by cyber-attacks.
[0005] In a first aspect, this application provides a data backup method, which is applied to a first server. The first server is communicatively connected to an application server cluster and a backup storage pool respectively. The method includes:
[0006] Obtaining data to be backed up from the application server cluster based on a backup policy;
[0007] Encrypting the data to be backed up based on an encryption key to obtain encrypted backup data;
[0008] Sending the encrypted backup data and a data write instruction to the backup storage pool. The data write instruction is used to instruct the backup storage pool to perform a write operation on the encrypted backup data, and then setting the document attribute of the encrypted backup data to read-only. The backup storage pool is built based on disks.
[0009] Further, the backup policy at least includes the target server identifier, the backup initiation time, the backup content information, and the backup execution frequency; obtaining the data to be backed up from the application server cluster based on the backup policy includes: determining the data range to be backed up based on the backup content information; formulating a data backup task based on the backup initiation time, the backup execution frequency, and the data range; and obtaining the data to be backed up from the target server based on the data backup task and the target server identifier.
[0010] Further, the method further includes: calculating a first checksum of the data to be backed up; after the backup storage pool receives the encrypted backup data, recording the first checksum and backup information in a backup log, where the backup information at least includes the backup retention duration, the backup address, and the backup directory.
[0011] Further, the method further includes: determining first backup data with an expired backup retention duration from the backup log; setting the document attribute of the first backup data to readable, and then performing a deletion operation on the first backup data.
[0012] In a second aspect, the present application provides a data recovery method, which is applied to a first server. The first server is communicatively connected to an application server cluster and a backup storage pool respectively. The method includes:
[0013] Obtaining the data to be recovered from the backup storage pool based on a recovery policy, where the backup storage pool is constructed based on a disk;
[0014] Decrypting the data to be recovered based on a decryption key to obtain decrypted recovery data;
[0015] Sending the decrypted recovery data to a target server in the application server cluster.
[0016] Further, the recovery policy at least includes the data identification information of the data to be recovered, the indication information of the backup log corresponding to the data to be recovered, and the recovery initiation time; obtaining the data to be recovered from the backup storage pool based on the recovery policy includes: determining whether the backup retention duration of the data to be recovered is in an expired state based on the backup log; if not in an expired state, obtaining the data to be recovered from the backup storage pool based on the data identification information at the start of the recovery initiation time.
[0017] Further, before decrypting the data to be restored with the decryption key to obtain the decrypted and restored data, the following steps are also included: calculating a second check code of the data to be restored; obtaining a first check code corresponding to the data to be restored from the backup log corresponding to the data to be restored; if the second check code is inconsistent with the first check code, generating an indication message for prompting that the data has been tampered with; if the second check code is consistent with the first check code, performing the operation of decrypting the data to be restored with the decryption key to obtain the decrypted and restored data.
[0018] In a third aspect, the present application provides a data backup device configured in a first server, where the first server is respectively communicatively connected to an application server cluster and a backup storage pool. The device includes:
[0019] A data acquisition module, configured to acquire data to be backed up from the application server cluster based on a backup policy;
[0020] A data encryption module, configured to encrypt the data to be backed up with an encryption key to obtain encrypted backup data;
[0021] A data backup module, configured to send the encrypted backup data and a data write instruction to the backup storage pool. The data write instruction is used to instruct the backup storage pool to perform a write operation on the encrypted backup data, and then set the document attribute of the encrypted backup data to read-only. The backup storage pool is built based on disks.
[0022] In a fourth aspect, the present application provides a data recovery device configured in a first server, where the first server is respectively communicatively connected to an application server cluster and a backup storage pool. The device includes:
[0023] A data acquisition module, configured to acquire data to be restored from the backup storage pool based on a recovery policy. The backup storage pool is built based on disks;
[0024] A data decryption module, configured to decrypt the data to be restored with a decryption key to obtain decrypted and restored data;
[0025] A data recovery module, configured to send the decrypted and restored data to a target server in the application server cluster.
[0026] In a fifth aspect, the present application provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the method of any embodiment of the present application.
[0027] To solve the defects of the prior art in the background art, an embodiment of the present application provides a data backup method. Executing this method can bring the following beneficial effects: First, based on the backup policy, the present application obtains the data to be backed up from the application server cluster, and can comprehensively and accurately collect the data that needs to be backed up according to preset rules (such as the target server identifier, backup content information, backup initiation time, backup execution frequency, etc.), ensuring the integrity and pertinence of the source of the backup data and ensuring that important business data will not be missed. Then, the data to be backed up is encrypted using an encryption key to obtain encrypted backup data, effectively preventing the data from being illegally obtained and tampered with during transmission and storage. Moreover, the document attribute of the encrypted backup data is set to read-only, further preventing the data from being accidentally modified or deleted, ensuring the originality and consistency of the backup data, and providing a reliable guarantee for long-term data storage and recovery. Finally, the encrypted backup data and the data write instruction are sent to the backup storage pool built based on disks, so that the backup storage pool performs a write operation on the encrypted backup data and sets the document attribute. The present application can realize that the data does not need to be truly offline during the data backup process, can improve the efficiency and maintainability of data backup, and can prevent illegal access and tampering of the backup data by network attacks.
[0028] It should be noted that the above computer instructions can be stored in whole or in part on a computer-readable storage medium. Among them, the computer-readable storage medium can be packaged together with the processor of the data backup device and the data recovery device, or can be separately packaged from the processor of the data backup device and the data recovery device. The present application does not make any limitations in this regard.
[0029] For the descriptions of the second aspect, the third aspect,..., and the fifth aspect in the present application, reference can be made to the detailed description of the first aspect; and for the beneficial effects of the descriptions of the second aspect, the third aspect,..., and the fifth aspect, reference can be made to the analysis of the beneficial effects of the first aspect, which will not be elaborated here.
[0030] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understandable through the following description.
[0031] It can be understood that before using the technical solutions disclosed in the embodiments of the present application, the types, usage scopes, and usage scenarios of the personal information involved in the present application should be informed to users and the authorization of the users should be obtained in an appropriate manner in accordance with relevant laws and regulations. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0033] Figure 1 It is a networking schematic diagram of a communication system provided by an embodiment of the present application;
[0034] Figure 2 It is a flowchart of a data backup method provided by an embodiment of the present application;
[0035] Figure 3 It is a flowchart of a data recovery method provided by an embodiment of the present application;
[0036] Figure 4 It is a structural schematic diagram of a data backup device provided by an embodiment of the present application;
[0037] Figure 5 It is a structural schematic diagram of a data recovery device provided by an embodiment of the present application;
[0038] Figure 6 It is a block diagram of an electronic device used to implement a data backup method and a data recovery method in the embodiments of the present application. Specific Embodiments
[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some, rather than all, of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.
[0040] It should be noted that the terms "first", "second", "target", and "original" in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include", "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.
[0041] Before introducing the embodiments of the present application, the communication system of the present application will be introduced below. Figure 1 It is a networking schematic diagram of a communication system provided for an embodiment of the present application, as Figure 1 shown. The communication system at least includes a first server 110, a cryptographic machine 120, an application server cluster 130, and a backup storage pool 140. Among them, the first server is communicatively connected to the application server cluster, the backup storage pool, and the cryptographic machine respectively; the first server refers to a server used to manage backup components (including the application server cluster and the backup storage pool) and schedule backup tasks; the cryptographic machine is responsible for generating or storing a unique encryption key; the application server hosts business applications, including databases and file applications, etc.; the backup storage pool is a highly reliable, high-performance, and scalable storage cluster built based on disks, which can be a distributed cluster or a centralized disk unit.
[0042] Figure 2 It is a flowchart of a data backup method provided for an embodiment of the present application. This embodiment is applicable to the scenario of backing up application data in an application server using a backup storage pool built based on disks. A data backup method provided in this embodiment can be executed by a data backup device provided in an embodiment of the present application. The device can be implemented in software and / or hardware and integrated in an electronic device that executes this method. This method is applied to the first server.
[0043] See Figure 2 , the method of this embodiment includes but is not limited to the following steps:
[0044] S210. Obtain data to be backed up from the application server cluster based on a backup policy.
[0045] Among them, the application server cluster may refer to combining multiple application servers through specific technologies and architectures to form an organic whole to jointly provide application services for users. The backup policy may refer to a plan formulated for backing up application data in the application server cluster. The backup policy may at least include a target server identifier, a backup initiation time, backup content information, and a backup execution frequency. The data to be backed up may refer to the application data of which specific application server or servers in the application server cluster, for example: database files, application program configuration files, log files, user data, etc.
[0046] Specifically, obtaining the data to be backed up from the application server cluster based on the backup policy includes: determining the data range to be backed up based on the backup content information; formulating a data backup task based on the backup initiation time, the backup execution frequency, and the data range; and obtaining the data to be backed up from the target server based on the data backup task and the target server identifier.
[0047] In the embodiment of the present application, the first server determines the data range to be backed up according to the backup content information in the backup policy, which may include database files, application configuration files, log files, user data, etc. For different types of data, corresponding acquisition methods and tools are determined. For example, for a database, the built-in backup tool of the database or a third-party database backup software can be used; for a file system, a file copy tool or a Network File System (NFS) protocol, etc. can be used. The first server starts a backup task at a specified time according to the set backup initiation time and backup execution frequency. If it is a scheduled backup, the task scheduling tool of the operating system (such as Cron for Linux or Task Scheduler for Windows) can be used to trigger the backup script or program. According to the target server identifier in the backup policy, the location of the target server to be backed up in the cluster is determined. The first server starts to obtain the data to be backed up from the target server in the application server cluster according to the backup content information.
[0048] Furthermore, before obtaining the data to be backed up, it is also necessary to check the backup environment and establish a connection. For example: Ensure that the backup storage pool (such as a tape library, disk array, etc.) is in a normal state and has sufficient storage space to accommodate the data to be backed up. Check whether the backup software is correctly installed and can run normally, and whether the relevant configuration parameters are correct. Another example: Use appropriate network tools and protocols to establish a secure and stable connection between the first server and the application server cluster to ensure that data can be transmitted smoothly. According to the target server identifier, configure the authentication information such as the Internet Protocol Address (IP address), port number, username, password, etc. required for the connection.
[0049] S220. Encrypt the data to be backed up based on the encryption key to obtain encrypted backup data.
[0050] In the embodiment of the present application, during the data backup process, in order to ensure the security of the backup data and prevent the data from being stolen or tampered with during transmission or storage, the first server calls a cryptographic machine to obtain an encryption key and encrypts the data to be backed up based on the encryption key, thereby obtaining encrypted backup data. Among them, the encryption algorithms used by the cryptographic machine can include symmetric encryption algorithms (such as: Advanced Encryption Standard (AES), Data Encryption Standard (DES), etc.) and asymmetric encryption algorithms (such as: Digital Signature Algorithm (RSA), etc.).
[0051] Taking the AES algorithm as an example, the data to be backed up is divided into blocks according to the block size specified by the AES algorithm (such as 128 bits). Then, using the selected encryption key, through a series of encryption rounds, each block of data is encrypted. During the encryption process, operations such as byte substitution, row shifting, and column mixing may be involved, and finally each block of plaintext data is converted into a ciphertext data block, and these ciphertext data blocks are combined to form the encrypted backup data.
[0052] Furthermore, before encryption, appropriate preprocessing needs to be performed on the data to be backed up. The preprocessing operations can include standardizing the data format to ensure that the data is encrypted in a unified format, facilitating subsequent decryption and recovery operations. For example, converting different types of files into a standard binary format. In addition, it may also be necessary to perform integrity verification on the data, such as calculating the hash value of the data, in order to verify whether the data is complete after encryption and decryption.
[0053] S230. Send the encrypted backup data and the data write instruction to the backup storage pool. The data write instruction is used to instruct the backup storage pool to perform a write operation on the encrypted backup data, and then set the document attribute of the encrypted backup data to read-only.
[0054] Among them, the backup storage pool is built based on disks. The disks can be hard disk drives (HDDs), solid state drives (SSDs), or other forms, which are not specifically limited in this embodiment.
[0055] In the embodiment of the present application, after the encrypted backup data is generated, the first server needs to store the encrypted backup data in the backup storage pool. During the data transmission process, corresponding security measures can be taken, such as using a secure network transmission protocol, to ensure the security of the encrypted backup data during transmission and prevent the data from being intercepted or tampered with midway. After receiving the encrypted backup data and the data write instruction, the backup storage pool writes the encrypted backup data and sets the document attribute of the encrypted backup data to read-only after the write is completed, preventing the data from being modified and deleted. If there is an intrusion into the server to illegally access the backup data, the data obtained is encrypted, which can achieve anti-leakage; if the intrusion server attempts to modify or delete the file, since the file attribute is read-only, the modification and deletion actions cannot succeed, which can achieve anti-tampering.
[0056] In one embodiment, the data to be backed up obtained from the application server is transmitted to the backup storage pool through the network. During the transmission process, technologies such as data verification and encryption can be adopted to ensure the integrity and accuracy of the data. For large-scale data backup, incremental backup or differential backup methods can be considered to only transmit and store the data that has changed compared with the previous backup, so as to improve the backup efficiency and reduce the storage space occupation. Therefore, the data backup method of this application further includes: calculating the message authentication code (MAC) of the data to be backed up, denoted as the first verification code; after the backup storage pool receives the encrypted backup data, recording the first verification code and the backup information in the backup log, and the backup information at least includes the backup retention duration, the backup address, and the backup directory. The backup log can also include information such as the backup start time, the backup end time, the amount of data backed up, and whether there is an error. The backup log can be used for subsequent backup management and troubleshooting.
[0057] In one embodiment, the first server periodically cancels the read-only feature of the expired backup data in batches according to the backup retention period, so that the files can be deleted and the storage space can be recycled. Therefore, the data backup method of this application further includes: determining the first backup data whose backup retention duration is in an invalid state from the backup log; setting the document attribute of the first backup data to be readable, and then performing a delete operation on the first backup data.
[0058] The technical solution provided in this embodiment obtains the data to be backed up from the application server cluster based on the backup policy; encrypts the data to be backed up using the encryption key to obtain the encrypted backup data; sends the encrypted backup data and the data write instruction to the backup storage pool, where the data write instruction is used to instruct the backup storage pool to perform a write operation on the encrypted backup data, and then sets the document attribute of the encrypted backup data to read-only. This application first obtains the data to be backed up from the application server cluster based on the backup policy, and can comprehensively and accurately collect the data that needs to be backed up according to preset rules (such as the target server identifier, backup content information, backup initiation time, backup execution frequency, etc.), ensuring the integrity and pertinence of the backup data source and ensuring that important business data is not missed; then, uses the encryption key to encrypt the data to be backed up to obtain the encrypted backup data, effectively preventing the data from being illegally obtained and tampered with during transmission and storage; and, sets the document attribute of the encrypted backup data to read-only, further preventing the data from being accidentally modified or deleted, ensuring the originality and consistency of the backup data, and providing a reliable guarantee for long-term data storage and recovery. Finally, sends the encrypted backup data and the data write instruction to the backup storage pool built based on disks, so that the backup storage pool performs a write operation on the encrypted backup data and sets the document attribute. This application can achieve that the data does not need to be truly offline during the data backup process, can improve the efficiency and maintainability of data backup, and can prevent illegal access and tampering of the backup data by network attacks.
[0059] Figure 3 FIG. is a schematic flowchart of a data recovery method provided in an embodiment of the present application. This embodiment is applicable to a scenario where the application data in the application server is recovered by a backup storage pool built based on disks. A data recovery method provided in this embodiment can be executed by a data recovery device provided in an embodiment of the present application. The device can be implemented in a software and / or hardware manner and integrated in an electronic device that executes this method. This method is applied to a first server, and the first server is communicatively connected to the application server cluster.
[0060] See Figure 3 , the method of this embodiment includes but is not limited to the following steps:
[0061] S310. Obtain the data to be recovered from the backup storage pool based on the recovery policy.
[0062] Among them, the backup storage pool is built based on disks, and the disks can be HDDs, SSDs or other forms, which are not specifically limited in this embodiment. The recovery policy at least includes the data identification information of the data to be recovered, the indication information of the backup log corresponding to the data to be recovered, and the recovery initiation time. Among them, the data identification information can be a backup timestamp, a data unique identifier, etc.
[0063] Specifically, obtaining the data to be restored from the backup storage pool based on the restoration policy includes: querying the backup retention duration of the data to be restored based on the backup log, and determining whether the backup retention duration is in an invalid state; if it is not in an invalid state, at the start of the restoration initiation time, retrieving the data to be restored from the backup storage pool based on the data identification information.
[0064] S320. Decrypting the data to be restored using the decryption key to obtain the decrypted restored data.
[0065] In the embodiment of the present application, the first server calls the cryptographic machine to obtain the decryption key, and decrypts the data to be restored based on the decryption key, thereby obtaining the decrypted restored data. Among them, the decryption algorithm and mode correspond to the encryption algorithm and mode used during encryption. Taking the AES algorithm as an example, the decryption process is the inverse operation of the encryption process. According to the steps specified by the algorithm, such as byte reverse substitution, reverse row shift, inverse column mixing, etc., the ciphertext data block is processed, and the ciphertext is gradually converted into plaintext. During the processing, it is necessary to operate according to the data block sequence and mode requirements during encryption to ensure the accuracy of decryption.
[0066] Optionally, the data to be restored may have been processed in a specific data format before encryption. Before decryption, it is necessary to ensure that the data format meets the requirements of the decryption algorithm. For example, some encryption algorithms require the data to be processed with a specific byte length or data structure. If the data format does not match, the decryption process may go wrong. Therefore, before decryption, it is necessary to check the data format and perform necessary conversions to enable it to smoothly enter the decryption process.
[0067] Furthermore, before decrypting the data to be restored using the decryption key to obtain the decrypted restored data, it further includes: calculating the MAC of the data to be restored, denoted as the second check code; obtaining the first check code corresponding to the data to be restored from the backup log corresponding to the data to be restored; if the second check code and the first check code are inconsistent, indicating that the data has been contaminated and a security alarm needs to be issued, then generating an indication message for prompting that the data has been tampered with; if the second check code and the first check code are consistent, indicating that the data has not been tampered with, then performing the operation of this step S320.
[0068] S330. Sending the decrypted restored data to the target server in the application server cluster.
[0069] In an embodiment of the present application, the first server uses a network communication protocol, such as the Transmission Control Protocol / Internet Protocol (TCP / IP), to establish a reliable network connection with the target server. During the connection establishment process, authentication and authorization operations may be required to ensure that only legitimate data senders can communicate with the target server. For example, a certificate-based authentication method is adopted, and the sender and the target server confirm each other's identities by exchanging digital certificates. After the connection is established, the first server selects an appropriate transmission protocol to send the decrypted and restored data to the target server in the application server cluster according to the data volume of the decrypted and restored data, the network condition, and the transmission performance requirements.
[0070] The technical solution provided in this embodiment obtains the data to be restored from the backup storage pool based on the restoration policy; decrypts the data to be restored based on the decryption key to obtain the decrypted and restored data; and sends the decrypted and restored data to the target server in the application server cluster. This application obtains the data to be restored from the backup storage pool based on the restoration policy, and accurately and quickly locates the data to be restored according to preset rules (such as the data identification information of the data to be restored, the indication information of the backup log corresponding to the data to be restored, and the restoration initiation time). The data to be restored is decrypted using the decryption key to restore the encrypted data to an available plaintext form, and finally the decrypted and restored data is sent to the target server in the application server cluster, enabling the data to return to the business system and resume its normal use in the business process, meeting the real-time requirements of the business for data. This application can achieve that the data does not need to be truly offline during the data backup process, can improve the efficiency and maintainability of data backup, and can prevent illegal access and tampering of the backup data by network attacks.
[0071] Figure 4 It is a schematic structural diagram of a data backup device provided in an embodiment of the present application, as Figure 4 shown. The device 400 is configured on the first server, and the first server is respectively communicatively connected to the application server cluster and the backup storage pool. It may include:
[0072] A data acquisition module 410, configured to acquire the data to be backed up from the application server cluster based on the backup policy;
[0073] A data encryption module 420, configured to encrypt the data to be backed up based on the encryption key to obtain the encrypted backup data;
[0074] A data backup module 430 is used to send the encrypted backup data and a data write instruction to the backup storage pool. The data write instruction is used to instruct the backup storage pool to perform a write operation on the encrypted backup data, and then set the document attribute of the encrypted backup data to read-only. The backup storage pool is built based on disks.
[0075] In one embodiment, the backup policy at least includes a target server identifier, a backup initiation time, backup content information, and a backup execution frequency.
[0076] Further, the above data acquisition module 410 can specifically be used to: determine a data range to be backed up based on the backup content information; formulate a data backup task based on the backup initiation time, the backup execution frequency, and the data range; and acquire the data to be backed up from the target server based on the data backup task and the target server identifier.
[0077] Further, the above data backup device may further include: an information recording module.
[0078] The information recording module is used to calculate a first checksum of the data to be backed up; after the backup storage pool receives the encrypted backup data, record the first checksum and backup information in a backup log. The backup information at least includes a backup retention period, a backup address, and a backup directory.
[0079] Further, the above data backup device may further include: a data deletion module.
[0080] The data deletion module is used to determine first backup data whose backup retention period is in an invalid state from the backup log; set the document attribute of the first backup data to readable, and then perform a deletion operation on the first backup data.
[0081] The data backup device provided in this embodiment can be applied to the data backup method provided in any of the above embodiments, and has corresponding functions and beneficial effects.
[0082] Figure 5 As shown in the structural schematic diagram of a data recovery device provided in an embodiment of the present application, Figure 5 The device 500 is configured in a first server. The first server is communicatively connected to an application server cluster and a backup storage pool respectively, and may include:
[0083] A data acquisition module 510 is used to acquire data to be restored from the backup storage pool based on a restoration policy. The backup storage pool is built based on disks.
[0084] A data decryption module 520 is configured to decrypt the data to be restored based on a decryption key to obtain decrypted and restored data;
[0085] A data restoration module 530 is configured to send the decrypted and restored data to a target server in the application server cluster.
[0086] In one embodiment, the restoration policy at least includes data identification information of the data to be restored, indication information of a backup log corresponding to the data to be restored, and a restoration initiation time;
[0087] Furthermore, the above data acquisition module 510 may specifically be configured to: determine whether a backup retention duration of the data to be restored is in an invalid state based on the backup log; if it is not in an invalid state, obtain the data to be restored from the backup storage pool based on the data identification information at the start of the restoration initiation time.
[0088] Furthermore, the above data decryption module 520 may specifically be configured to: calculate a second check code of the data to be restored before decrypting the data to be restored based on the decryption key to obtain decrypted and restored data; obtain a first check code corresponding to the data to be restored from the backup log corresponding to the data to be restored; if the second check code and the first check code are inconsistent, generate an indication message for prompting that the data has been tampered with; if the second check code and the first check code are consistent, perform the operation of decrypting the data to be restored based on the decryption key to obtain decrypted and restored data.
[0089] The data restoration apparatus provided in this embodiment can be applied to the data restoration method provided in any of the above embodiments, and has corresponding functions and beneficial effects.
[0090] Figure 6 It is a block diagram of an electronic device for implementing a data backup method and a data restoration method according to an embodiment of the present application. The electronic device 10 is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described herein and / or claimed.
[0091] Such as Figure 6As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0092] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0093] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the data backup method and the data recovery method.
[0094] In some embodiments, the data backup method and the data recovery method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data backup method and the data recovery method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the data backup method and the data recovery method by any other appropriate means (e.g., by means of firmware).
[0095] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0096] The computer programs for implementing the methods of this application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs may execute entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0097] In the context of this application, a computer-readable storage medium may be a tangible medium that can contain, or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium may be a machine-readable signal medium. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0098] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0099] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0100] The computing system can include a client and a server. The client and the server are generally far apart from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0101] Note that the above is only a preferred embodiment of the present application and the applied technical principles. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present application. For example, those skilled in the art can use various forms of processes shown above, reorder, add, or delete steps; the steps described in the present application can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present application can be achieved, which is not limited herein.
[0102] The above specific embodiments do not constitute a limitation on the protection scope of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of this application shall be included within the protection scope of this application.
Claims
1. A data backup method, characterized in that: Applied to a first server, the first server is respectively in communication connection with an application server cluster and a backup storage pool, the method comprising: Acquiring data to be backed up from the application server cluster based on a backup strategy; Encrypting the data to be backed up based on an encryption key to obtain encrypted backup data; The encrypted backup data and a data write instruction are sent to the backup storage pool, the data write instruction is used to instruct the backup storage pool to perform a write operation on the encrypted backup data, and then the document attribute of the encrypted backup data is set to read-only, and the backup storage pool is built based on a disk.
2. The data backup method according to claim 1, characterized in that: The backup strategy at least includes the target server identification, backup initiation time, backup content information and backup execution frequency; The obtaining the data to be backed up from the application server cluster based on the backup strategy includes: Determine the data range to be backed up based on the backup content information; Formulate a data backup task based on the backup initiation time, the backup execution frequency and the data range; The data to be backed up is obtained from the target server based on the data backup task and the target server identifier.
3. The data backup method according to claim 1, characterized in that: The method further comprises: Calculating a first check code of the data to be backed up; After the backup storage pool receives the encrypted backup data, the first verification code and backup information are recorded in a backup log, where the backup information at least includes a backup retention period, a backup address, and a backup directory.
4. The data backup method according to claim 3, characterized in that: The method further comprises: Determine, from the backup log, first backup data whose backup retention time is in an invalid state; The document attribute of the first backup data is set to be readable, and then a deletion operation is performed on the first backup data.
5. A data recovery method, characterized in that: Applied to a first server, the first server is respectively in communication connection with an application server cluster and a backup storage pool, the method comprising: Acquiring the data to be restored from the backup storage pool based on the restoration strategy, wherein the backup storage pool is constructed based on a disk; Decrypting the data to be recovered based on the decryption key to obtain decrypted recovery data; The decrypted recovery data is sent to a target server in the application server cluster.
6. The data recovery method according to claim 5, characterized in that: The recovery strategy includes at least data identification information of the data to be recovered, indication information of the backup log corresponding to the data to be recovered, and the recovery initiation time; The obtaining the data to be restored from the backup storage pool based on the restoration strategy includes: Determining whether the backup retention time of the data to be restored is in an invalid state based on the backup log; If it is not in an invalid state, then when the recovery initiation time starts, the data to be recovered is obtained from the backup storage pool based on the data identification information.
7. The data recovery method according to claim 5, characterized in that: Before decrypting the data to be recovered based on the decryption key to obtain the decrypted recovery data, the method further includes: Calculating a second check code of the data to be restored; Obtaining a first verification code corresponding to the data to be restored from a backup log corresponding to the data to be restored; If the second verification code is inconsistent with the first verification code, generating an indication message for prompting that the data has been tampered with; If the second verification code is consistent with the first verification code, the operation of decrypting the data to be recovered based on the decryption key to obtain the decrypted recovery data is performed.
8. A data backup device, characterized in that: The device is configured on a first server, the first server is respectively connected to the application server cluster and the backup storage pool for communication, and the device includes: A data acquisition module, used to acquire the data to be backed up from the application server cluster based on a backup strategy; A data encryption module, used for encrypting the data to be backed up based on an encryption key to obtain encrypted backup data; A data backup module is used to send the encrypted backup data and data write instructions to the backup storage pool, the data write instructions are used to instruct the backup storage pool to perform a write operation on the encrypted backup data, and then set the document attribute of the encrypted backup data to read-only, and the backup storage pool is built based on a disk.
9. A data recovery device, characterized in that: The device is configured on a first server, the first server is respectively connected to the application server cluster and the backup storage pool for communication, and the device includes: A data acquisition module, used for acquiring the data to be restored from the backup storage pool based on the restoration strategy, wherein the backup storage pool is constructed based on a disk; A data decryption module, used to decrypt the data to be recovered based on a decryption key to obtain decrypted recovery data; The data recovery module is used to send the decrypted recovery data to a target server in the application server cluster.
10. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; Wherein, the memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the data backup method as described in any one of claims 1 to 4, or enables the at least one processor to execute the data recovery method as described in any one of claims 5 to 7.