Data processing system, method, equipment and medium

Through the collaborative cooperation between the cloud platform, main storage end and backup storage end, key management services are used to generate key encryption service data for the main encrypted volume, and backup to backup volumes according to business volume negotiation when data is updated, solving the problem of waste of data storage and backup resources on cloud platform and achieving flexible and efficient data management.

CN120498774APending Publication Date: 2025-08-15INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510641313.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the storage and backup methods of business data on the cloud platform are fixed, resulting in wasting of computing resources when the number of business access is unstable, affecting storage and backup efficiency and performance.

Method used

Through the collaborative cooperation between the cloud platform, main storage end and backup storage end, key management services are used to generate key encryption service data for the main encrypted volume, and the ciphertext is backed up to the backup encrypted volume according to the current business volume negotiation of the cloud host, realizing flexible storage and backup.

Benefits of technology

It realizes dynamic adjustment of storage and backup methods based on business volume, reduces resource waste, and improves the efficiency and performance of data storage and backup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498774A_ABST
    Figure CN120498774A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing system, method and device and a medium in the technical field of computers. According to the application, the cloud platform, the main storage end and the standby storage end are independent of each other and cooperate with each other, so that storage and backup of service data in the cloud host are realized; moreover, the cloud host in the cloud platform can utilize the key management service to encrypt the service data needing to be stored by the key generated by the main encryption volume, and stores the encrypted ciphertext to the main encryption volume, thereby achieving the encrypted storage of the service data. And when monitoring that data updating exists in the main encryption volume, the standby storage end backs up the ciphertext needing to be backed up in the main encryption volume to the standby encryption volume according to a backup mode negotiated with the main encryption volume for the current service volume of the cloud host, and storage and backup of related service data can be realized by adopting a proper backup mode according to the current service volume of the cloud host. Therefore, flexible storage and backup of the cloud platform data are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a data processing system, method, device and medium. Background Art

[0002] Currently, business data generated on cloud platforms is stored and backed up in a fixed manner. Since business access volume may be unstable, sometimes a large amount of data needs to be stored, and sometimes very little data needs to be stored. Therefore, fixed storage and backup methods may lead to a waste of computing resources and affect the efficiency and performance of data storage and backup.

[0003] Therefore, how to flexibly implement the storage and backup of cloud platform data is a problem that technical personnel in this field need to solve. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a data processing system, method, device and medium to flexibly implement the storage and backup of cloud platform data. The specific solution is as follows:

[0005] In a first aspect, the present application provides a data processing system, comprising: a cloud platform, a primary storage end, and a backup storage end;

[0006] The cloud platform includes at least one cloud host, which is used to: send an encrypted volume creation request to a primary storage end and a backup storage end;

[0007] The primary storage end is used to: create a primary encrypted volume in response to an encrypted volume creation request;

[0008] The backup storage end is used to: create a backup encrypted volume of the same size as the primary encrypted volume in response to the encrypted volume creation request;

[0009] The cloud host is also used to: mount the primary encrypted volume, encrypt the business data to be stored using the key generated by the key management service for the primary encrypted volume, and store the encrypted ciphertext in the primary encrypted volume;

[0010] The backup storage is used to: if data updates are detected in the primary encrypted volume, the backup storage will back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume according to the backup method negotiated with the primary encrypted volume based on the current business volume of the cloud host.

[0011] In a second aspect, the present application provides a data processing method, which is applied to any cloud host in a cloud platform, comprising:

[0012] Sending an encrypted volume creation request to the primary storage end and the backup storage end, so that the primary storage end responds to the encrypted volume creation request and creates a primary encrypted volume, and so that the backup storage end responds to the encrypted volume creation request and creates a backup encrypted volume of the same size as the primary encrypted volume;

[0013] Mount the primary encrypted volume, use the key generated by the key management service for the primary encrypted volume to encrypt the business data to be stored, and store the encrypted ciphertext in the primary encrypted volume. When the backup storage detects data updates in the primary encrypted volume, it will back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume according to the backup method negotiated with the primary encrypted volume based on the current business volume of the cloud host.

[0014] In a third aspect, the present application provides an electronic device, comprising:

[0015] memory for storing computer programs;

[0016] A processor is used to execute the computer program to implement the aforementioned disclosed data processing method.

[0017] In a fourth aspect, the present application provides a non-volatile storage medium for storing a computer program, wherein the computer program implements the aforementioned disclosed data processing method when executed by a processor.

[0018] In a fifth aspect, the present application provides a computer program product, comprising a computer program / instruction, which implements the steps of the aforementioned disclosed data processing method when executed by a processor.

[0019] From the above scheme, it can be seen that the present application provides a data processing system, including: a cloud platform, a primary storage end and a backup storage end; the cloud platform includes at least one cloud host, and the cloud host is used to: send an encryption volume creation request to the primary storage end and the backup storage end; the primary storage end is used to: create a primary encryption volume in response to the encryption volume creation request; the backup storage end is used to: create a backup encryption volume of the same size as the primary encryption volume in response to the encryption volume creation request; the cloud host is also used to: mount the primary encryption volume, use the key generated for the primary encryption volume by the key management service to encrypt the business data to be stored, and store the encrypted ciphertext to the primary encryption volume; the backup storage end is used to: if it is detected that there is a data update in the primary encryption volume, then according to the backup method negotiated with the primary encryption volume for the current business volume of the cloud host, the ciphertext to be backed up in the primary encryption volume is backed up to the backup encryption volume.

[0020] It can be seen that the cloud platform, primary storage end and backup storage end in this application are independent of each other and work together to realize the storage and backup of business data in the cloud host; moreover, the cloud host in the cloud platform can use the key management service to generate the key for the primary encryption volume to encrypt the business data to be stored, and store the encrypted ciphertext in the primary encryption volume, thereby realizing the encrypted storage of business data; and when the backup storage end detects that there is a data update in the primary encryption volume, it backs up the ciphertext to be backed up in the primary encryption volume to the backup encryption volume in accordance with the backup method negotiated with the primary encryption volume for the current business volume of the cloud host. The appropriate backup method can be used according to the current business volume of the cloud host to realize the storage and backup of relevant business data, thereby realizing flexible storage and backup of cloud platform data.

[0021] Correspondingly, the data processing method, device and medium provided by this application also have the above-mentioned technical effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0023] Figure 1 A schematic diagram of a data processing system disclosed in this application;

[0024] Figure 2 A flow chart of a data backup method disclosed in this application;

[0025] Figure 3 This is a flow chart of another data backup method disclosed in this application;

[0026] Figure 4 A flow chart of a data processing method disclosed in this application;

[0027] Figure 5 A schematic diagram of an electronic device disclosed in this application;

[0028] Figure 6 A server structure diagram provided for this application;

[0029] Figure 7 This is a terminal structure diagram provided for this application. DETAILED DESCRIPTION

[0030] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments of this application, all other examples obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0031] At present, the business data generated on the cloud platform is stored and backed up in a fixed manner. Since the business access volume may be unstable, sometimes a large amount of data needs to be stored, and sometimes very little data needs to be stored. Therefore, the fixed storage and backup method may lead to a waste of computing resources, affecting the efficiency and performance of data storage and backup. To this end, the present application provides a data processing solution, in which the cloud host in the cloud platform can use the key generated by the key management service for the main encryption volume to encrypt the business data to be stored, and store the encrypted ciphertext to the main encryption volume, thereby realizing the encrypted storage of business data; and when the backup storage end detects that there is a data update in the main encryption volume, it backs up the ciphertext to be backed up in the main encryption volume to the backup encryption volume according to the backup method negotiated with the main encryption volume for the current business volume of the cloud host. The storage and backup of relevant business data can be realized by adopting an appropriate backup method according to the current business volume of the cloud host, thereby realizing the flexible storage and backup of cloud platform data.

[0032] See Figure 1 , a data processing system includes: a cloud platform, a primary storage end and a backup storage end.

[0033] The cloud platform includes at least one cloud host, which is used to send an encrypted volume creation request to the primary storage end and the backup storage end. The encrypted volume creation request may specify the volume name, size, and the name of the storage end.

[0034] The primary storage end is used to: create a primary encrypted volume in response to an encrypted volume creation request.

[0035] The backup storage end is used to: in response to the encryption volume creation request, create a backup encryption volume of the same size as the primary encryption volume.

[0036] The cloud host is also used to mount the primary encrypted volume, encrypt the business data to be stored using the key generated by the key management service for the primary encrypted volume, and store the encrypted ciphertext in the primary encrypted volume. It should be noted that the cloud host is deployed with the key management service Barbican, which manages key generation, usage, and destruction. Therefore, the cloud host uses the key management service to dynamically update keys according to the key lifecycle.

[0037] The backup storage is used to: if data updates are detected in the primary encrypted volume, the backup storage will back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume according to the backup method negotiated with the primary encrypted volume based on the current business volume of the cloud host.

[0038] In this embodiment, the primary storage and backup storage include multiple storage controllers; furthermore, the primary and backup storage are geographically located as close as possible, thereby reducing backup duration and resource loss during the backup process. The primary storage utilizes a distributed block storage service to achieve decentralized data storage, improving data storage reliability and recoverability. In one embodiment, the cloud host is configured to: upon confirming that the block storage service is available, read the block storage service's configuration information, establish an interface communication connection with the primary encrypted volume based on the configuration information, and obtain the backup method for the primary encrypted volume through the interface communication connection.

[0039] To achieve consistency between the backup mode of the backup encrypted volume and the backup mode of the primary encrypted volume, the cloud host is used to: if the backup mode of the backup encrypted volume is inconsistent with the backup mode of the primary encrypted volume, notify the primary encrypted volume and the backup encrypted volume to negotiate the backup mode. The specific negotiation process can be: the cloud host sets the corresponding backup mode based on the current business volume, sends this backup mode to the primary encrypted volume, and after the primary encrypted volume obtains this backup mode, the primary encrypted volume synchronizes this backup mode to the backup encrypted volume. Among them, the correspondence between different business volumes and various backup modes can be preset and recorded as a table. The cloud host determines the backup mode corresponding to the current business volume by querying the table. For example: when the business volume is 100, the corresponding backup mode is synchronous backup + incremental backup; when the business volume is 100,000, the corresponding backup mode is backing up fixed-size data every T seconds + incremental backup. The backup storage end can synchronously back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in an incremental backup mode.

[0040] In one embodiment, the main storage end includes multiple storage controllers; accordingly, the cloud host is used to: collect performance indicators of each storage controller in real time, determine the overloaded storage controller by analyzing the performance indicators, and reduce the number of storage requests sent to the overloaded storage controller; accordingly, the overloaded storage controller is used to: forward the storage requests it receives to other storage controllers.

[0041] In one embodiment, the primary storage side implements a distributed block storage service based on multiple storage controllers. This distributed block storage service is a data storage architecture that distributes data across multiple independent nodes (i.e., storage controllers), each capable of independently processing data read and write requests. This architecture divides data into multiple equal-sized blocks and stores and manages them in units of blocks, providing a high-performance, high-availability, and scalable data storage solution. High performance is demonstrated by significantly improving data read and write speeds through parallel processing and data sharding, meeting the requirements of high-performance computing and data-intensive applications. It also offers low data transmission latency and supports simultaneous access by multiple clients, making it suitable for high-concurrency scenarios. High availability is demonstrated by ensuring data accessibility in the event of node failures through data redundancy mechanisms, improving data availability. Data replication and redundancy technologies are employed to ensure data reliability. Scalability is demonstrated by expanding storage capacity and performance by adding more nodes as data volumes grow, without the need for complex reconfiguration or migration. This supports horizontal expansion to meet growing data storage needs.

[0042] It can be seen that the cloud platform, primary storage end and backup storage end in this embodiment are independent of each other and work together to realize the storage and backup of business data in the cloud host; moreover, the cloud host in the cloud platform can use the key generated by the key management service for the primary encrypted volume to encrypt the business data to be stored, and store the encrypted ciphertext in the primary encrypted volume, thereby realizing the encrypted storage of business data; and when the backup storage end detects that there is a data update in the primary encrypted volume, it backs up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in accordance with the backup method negotiated with the primary encrypted volume for the current business volume of the cloud host. The appropriate backup method can be used according to the current business volume of the cloud host to realize the storage and backup of relevant business data, thereby realizing the flexible storage and backup of cloud platform data.

[0043] See Figure 2 and Figure 3 , a data backup process may include:

[0044] A1: Modify the Cinder driver in the OpenStack cloud host and read the OpenStack Cinder configuration file to obtain the configuration information of the primary storage and backup storage (including IP address, password, and other information).

[0045] A2: Modify the Cinder driver interface so that it connects to the primary storage interface to establish communication between the Cinder driver and the primary storage. The Cinder driver obtains primary storage information (including the number of nodes and backup mode) and analyzes the information.

[0046] A3: Based on the parsed information, the server confirms whether the primary storage supports synchronous replication and creates a primary volume on the primary storage and a backup volume on the backup storage. Specifically, the server specifies the name, size, and storage pool of the primary volume in the rest request parameters for creating the primary volume; and the name, size, and storage pool of the backup volume in the rest request parameters for creating the backup volume. Both the primary and backup volumes can be encrypted.

[0047] A4: Mount the primary storage to the cloud host as a data disk and enable synchronous replication between the primary storage and the backup storage.

[0048] The cloud host can access the backup methods supported by both primary and backup storage through the storage command-line interface. This solution enables real-time backup of data generated by the OpenStack cloud host and also introduces dynamic encryption and key management within the cloud platform, ensuring data remains encrypted during transmission and storage.

[0049] Step A1 may specifically include: modifying the cinder driver status in the OpenStack cloud host to be available, so as to ensure that the cinder driver status is available; and reading the OpenStack cinder configuration file to obtain configuration information of the primary storage and the backup storage.

[0050] The cloud platform deploys the following components: Barbican, OpenStack's key management service for generating, storing, and managing encryption keys; Cinder Volume Encryption, which encrypts Cinder volumes using keys managed by Barbican; and Nova Instance Encryption, which encrypts the disks of virtual machine instances. The integration of Barbican and Cinder provides end-to-end encryption support for virtual machine disks. Barbican manages key management, Cinder encrypts and decrypts volumes, and Nova mounts encrypted volumes to virtual machines. The entire process is transparent to users while ensuring data security and compliance. Real-time encryption and robust key management ensure data security during transmission and storage.

[0051] OpenStack is an open-source cloud computing management platform project designed to provide software solutions for the construction and management of public and private clouds. It delivers Infrastructure as a Service (IaaS) capabilities through a series of interrelated services. The cinder driver is OpenStack's block storage service, providing storage resources for OpenStack's compute modules. Nova is an OpenStack component that provides a cloud computing network controller and supports a wide range of virtual machine technologies. Barbican is the key management service in OpenStack, providing powerful encryption and key management capabilities for cloud environments. By integrating with other OpenStack services, Barbican can meet the encryption requirements of virtual machines, storage, and images, while supporting multi-tenant isolation and compliance auditing.

[0052] It should be noted that dynamic encryption and key management in cloud hosts can include:

[0053] 1. Install and configure the Barbican service.

[0054] 2. Create a key: Generate an encryption key through the Barbican API to create an AES-256 symmetric key.

[0055] 3. Create an encrypted volume type in Cinder and associate it with the key in Barbican.

[0056] 4. Create an encrypted volume: Use the encrypted volume type to create an encrypted volume on the primary storage side.

[0057] 5. Mount the encrypted volume to the virtual machine in the cloud platform. Cinder obtains the key from Barbican and passes the key to Nova. Nova uses the key for the virtual machine to access the relevant data.

[0058] In addition, Barbican can also be used to manage the key lifecycle, such as changing keys, destroying keys, etc.

[0059] For the primary storage side, the following functions can also be implemented:

[0060] Data collection: Performance indicators such as read and write IOPS are collected from storage nodes. Data such as CPU, memory, disk I / O, and network bandwidth can also be included.

[0061] Data analysis: Based on the collected performance indicators, identify load imbalance issues, that is, whether some nodes are overloaded and some nodes are relatively idle.

[0062] Decision making: Develop a load balancing strategy based on the analysis results, for example, temporarily not sending tasks to overloaded nodes.

[0063] Monitoring feedback: Continuously monitor the performance indicators of each node to optimize the load balancing strategy.

[0064] In one example, the primary storage side also has the following advantages:

[0065] High availability: Data is stored in multiple nodes. Even if a node fails, the failed node can forward the storage requests it receives to other nodes, and the requests can still be processed normally by other nodes.

[0066] Efficient backup: Data is stored in shards across different nodes, preventing a single node from becoming a performance bottleneck. Incremental backups only back up changed data, reducing backup time and storage space.

[0067] Elastic expansion: Storage nodes can be dynamically increased or decreased according to demand to adapt to changing storage needs; data distribution can be dynamically adjusted to optimize system performance.

[0068] In this embodiment, the purpose of real-time data backup in the OpenStack cloud host is achieved by utilizing the synchronous replication function of the storage cluster; the backup and recovery mechanism based on distributed storage, by distributing data on multiple nodes, can not only improve the efficiency of backup, but also quickly restore data from other nodes when a node fails.

[0069] The following introduces a data processing method provided in an embodiment of the present application. The data processing method described below can be referenced with other embodiments described in this document.

[0070] See also Figure 4 As shown, the embodiment of the present application discloses a data processing method, which is applied to any cloud host in a cloud platform, including:

[0071] S401. Send an encrypted volume creation request to the primary storage end and the backup storage end, so that the primary storage end responds to the encrypted volume creation request and creates a primary encrypted volume, and so that the backup storage end responds to the encrypted volume creation request and creates a backup encrypted volume of the same size as the primary encrypted volume.

[0072] S402. Mount the primary encrypted volume, use the key generated by the key management service for the primary encrypted volume to encrypt the business data to be stored, and store the encrypted ciphertext in the primary encrypted volume. When the backup storage end detects that there is data update in the primary encrypted volume, it will back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume according to the backup method negotiated with the primary encrypted volume based on the current business volume of the cloud host.

[0073] In one embodiment, the cloud host is configured to: if the block storage service is confirmed to be available, read the configuration information of the block storage service, establish an interface communication connection with the primary encrypted volume according to the configuration information, and obtain the backup method of the primary encrypted volume through the interface communication connection.

[0074] In one embodiment, the cloud host is configured to: if the backup mode of the backup encrypted volume is inconsistent with the backup mode of the primary encrypted volume, notify the primary encrypted volume and the backup encrypted volume to negotiate the backup mode.

[0075] In one embodiment, the cloud host is configured to dynamically update the key according to the life cycle of the key using a key management service.

[0076] In one embodiment, the main storage end includes multiple storage controllers; accordingly, the cloud host is used to: collect performance indicators of each storage controller in real time, determine the overloaded storage controller by analyzing the performance indicators, and reduce the number of storage requests sent to the overloaded storage controller; accordingly, the overloaded storage controller is used to: forward the storage requests it receives to other storage controllers.

[0077] In one embodiment, the primary storage end constructs a distributed block storage service based on multiple storage controllers.

[0078] In one embodiment, the backup storage end is used to synchronously back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in an incremental backup manner.

[0079] Among them, for more specific working processes of each module and unit in this embodiment, reference can be made to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.

[0080] It can be seen that this embodiment provides a data processing device. In this solution, the cloud host in the cloud platform can use the key generated by the key management service for the primary encryption volume to encrypt the business data to be stored, and store the encrypted ciphertext in the primary encryption volume, thereby realizing the encrypted storage of the business data; and when the backup storage end detects that there is a data update in the primary encryption volume, it backs up the ciphertext to be backed up in the primary encryption volume to the backup encryption volume in accordance with the backup method negotiated with the primary encryption volume for the current business volume of the cloud host. The appropriate backup method can be used according to the current business volume of the cloud host to realize the storage and backup of relevant business data, thereby realizing the flexible storage and backup of cloud platform data.

[0081] The following describes an electronic device provided in an embodiment of the present application. The electronic device described below can be cross-referenced with other embodiments described herein. The electronic device in this embodiment can be the cloud host or storage controller described in the previous embodiment.

[0082] See also Figure 5As shown, the embodiment of the present application discloses an electronic device, including:

[0083] Memory 501, used for storing computer programs;

[0084] The processor 502 is configured to execute the computer program to implement the method disclosed in any of the above embodiments.

[0085] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: sending an encrypted volume creation request to the primary storage end and the backup storage end, so that the primary storage end responds to the encrypted volume creation request and creates a primary encrypted volume, so that the backup storage end responds to the encrypted volume creation request and creates a backup encrypted volume of the same size as the primary encrypted volume; mounting the primary encrypted volume, using the key generated for the primary encrypted volume by the key management service to encrypt the business data to be stored, and storing the encrypted ciphertext in the primary encrypted volume, so that when the backup storage end detects that there is a data update in the primary encrypted volume, it backs up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in accordance with the backup method negotiated with the primary encrypted volume for the current business volume of the cloud host.

[0086] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: if it is confirmed that the block storage service is available, configuration information of the block storage service is read, an interface communication connection is established with the primary encrypted volume according to the configuration information, and a backup method of the primary encrypted volume is obtained through the interface communication connection.

[0087] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: if the backup mode of the backup encrypted volume is inconsistent with the backup mode of the primary encrypted volume, the primary encrypted volume and the backup encrypted volume are notified to negotiate the backup mode.

[0088] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: dynamically updating the key according to the life cycle of the key by using the key management service.

[0089] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: collect the performance indicators of each storage controller in the main storage end in real time, determine the overloaded storage controller by analyzing the performance indicators, and reduce the number of storage requests sent to the overloaded storage controller.

[0090] In this embodiment, when the processor executes the computer program stored in the memory, it may specifically implement the following steps: forwarding the storage request received by the processor to other storage controllers.

[0091] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: synchronously backing up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in an incremental backup manner.

[0092] Furthermore, the embodiment of the present application also provides an electronic device. The electronic device can be Figure 6 The server shown can also be Figure 7 Terminal shown. Figure 6 and Figure 7 Each of the diagrams is a structural diagram of an electronic device according to an exemplary embodiment, and the contents in the diagrams cannot be considered as any limitation on the scope of use of the present application.

[0093] Figure 6 This is a schematic diagram of the structure of a server provided in an embodiment of the present application. The server may specifically include: at least one processor, at least one memory, a power supply, a communication interface, an input / output interface, and a communication bus. The memory is used to store a computer program, which is loaded and executed by the processor to implement the relevant steps of the data processing disclosed in any of the aforementioned embodiments.

[0094] In this embodiment, the power supply is used to provide operating voltage for each hardware device on the server; the communication interface can create a data transmission channel between the server and external devices. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface is used to obtain external input data or output data to the outside world. The specific interface type can be selected according to specific application needs and is not specifically limited here.

[0095] In addition, the memory as a carrier for resource storage can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon include operating system, computer programs and data, etc. The storage method can be temporary storage or permanent storage.

[0096] The operating system is used to manage and control the hardware devices and computer programs on the server, enabling the processor to operate and process data in the memory. It can be Windows Server, NetWare, Unix, Linux, etc. In addition to computer programs capable of performing the data processing methods disclosed in any of the aforementioned embodiments, computer programs can also include computer programs capable of performing other specific tasks. Data can include data such as application update information and other data such as application developer information.

[0097] Figure 7This is a schematic diagram of the structure of a terminal provided in an embodiment of the present application. The terminal may specifically include but is not limited to a smartphone, tablet computer, laptop computer or desktop computer.

[0098] Generally, the terminal in this embodiment includes: a processor and a memory.

[0099] The processor may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor may be implemented in at least one of the following hardware forms: a DSP (Digital Signal Processing), an FPGA (Field-Programmable Gate Array), or a PLA (Programmable Logic Array). The processor may also include a main processor and a coprocessor. The main processor is used to process data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing content required to be displayed on the display. In some embodiments, the processor may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning.

[0100] The memory may include one or more computer non-volatile storage media, which may be non-transitory. The memory may also include high-speed random access memory, and non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory is used to store at least the following computer program, wherein, after the computer program is loaded and executed by the processor, it can implement the relevant steps in the data processing method performed by the terminal side disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory may also include an operating system and data, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system may include Windows, Unix, Linux, etc. The data may include but is not limited to update information of the application.

[0101] In some embodiments, the terminal may further include a display screen, an input and output interface, a communication interface, a sensor, a power supply, and a communication bus.

[0102] Those skilled in the art will understand that Figure 7The structure shown in the figure does not constitute a limitation to the terminal, and may include more or fewer components than shown in the figure.

[0103] A non-volatile storage medium provided in an embodiment of the present application is introduced below. The non-volatile storage medium described below can be referenced with other embodiments described herein.

[0104] A non-volatile storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the data processing method disclosed in the aforementioned embodiment. The non-volatile storage medium is a computer-readable non-volatile storage medium that, as a carrier for resource storage, may be a read-only memory, random access memory, a magnetic disk, or an optical disk. The resources stored thereon include an operating system, a computer program, and data, and the storage method may be either temporary or permanent.

[0105] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, it can specifically implement the following steps: sending an encrypted volume creation request to the primary storage end and the backup storage end, so that the primary storage end responds to the encrypted volume creation request and creates a primary encrypted volume, so that the backup storage end responds to the encrypted volume creation request and creates a backup encrypted volume of the same size as the primary encrypted volume; mounting the primary encrypted volume, using the key generated by the key management service for the primary encrypted volume to encrypt the business data to be stored, and storing the encrypted ciphertext in the primary encrypted volume, so that when the backup storage end detects that there is a data update in the primary encrypted volume, it backs up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in accordance with the backup method negotiated with the primary encrypted volume for the current business volume of the cloud host.

[0106] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: if it is confirmed that the block storage service is available, configuration information of the block storage service is read, an interface communication connection is established with the primary encrypted volume according to the configuration information, and a backup method of the primary encrypted volume is obtained through the interface communication connection.

[0107] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps can be specifically implemented: if the backup mode of the backup encrypted volume is inconsistent with the backup mode of the primary encrypted volume, the primary encrypted volume and the backup encrypted volume are notified to negotiate the backup mode.

[0108] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: dynamically updating the key according to the life cycle of the key by using the key management service.

[0109] In this embodiment, when the processor executes a computer program stored in a non-volatile storage medium, it can specifically implement the following steps: collect performance indicators of each storage controller in the main storage end in real time, determine the overloaded storage controller by analyzing the performance indicators, and reduce the number of storage requests sent to the overloaded storage controller.

[0110] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, it may specifically implement the following steps: forwarding the storage request received by the processor to other storage controllers.

[0111] In this embodiment, when the processor executes the computer program stored in the non-volatile storage medium, the following steps may be specifically implemented: synchronously backing up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in an incremental backup manner.

[0112] A computer program product provided in an embodiment of the present application is introduced below. The computer program product described below can be referenced with other embodiments described herein.

[0113] A computer program product comprises a computer program / instruction, which implements the steps of the aforementioned data processing method when executed by a processor.

[0114] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0115] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of non-volatile storage medium known in the art.

[0116] This document uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.

Claims

1. A data processing system, characterized in that: include: Cloud platform, primary storage, and backup storage; The cloud platform includes at least one cloud host, and the cloud host is used to: send an encrypted volume creation request to the primary storage end and the backup storage end; The primary storage end is used to: create a primary encrypted volume in response to the encrypted volume creation request; The backup storage end is used to: create a backup encrypted volume of the same size as the primary encrypted volume in response to the encrypted volume creation request; The cloud host is further configured to: mount the primary encrypted volume, encrypt the business data to be stored using the key generated for the primary encrypted volume by the key management service, and store the encrypted ciphertext in the primary encrypted volume; The backup storage end is used to: if it is detected that there is data update in the primary encrypted volume, then back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume according to the backup method negotiated with the primary encrypted volume for the current business volume of the cloud host.

2. The system according to claim 1, wherein: The cloud host is used to: if it is confirmed that the block storage service is available, read the configuration information of the block storage service, establish an interface communication connection with the primary encrypted volume according to the configuration information, and obtain the backup method of the primary encrypted volume through the interface communication connection.

3. The system according to claim 1, wherein: The cloud host is used to: if the backup mode of the backup encrypted volume is inconsistent with the backup mode of the primary encrypted volume, notify the primary encrypted volume and the backup encrypted volume to negotiate the backup mode.

4. The system according to claim 1, wherein: The cloud host is used to dynamically update the key according to the life cycle of the key by using the key management service.

5. The system according to any one of claims 1 to 4, characterized in that The main storage end includes multiple storage controllers; Accordingly, the cloud host is configured to: collect performance indicators of each storage controller in real time, determine an overloaded storage controller by analyzing the performance indicators, and reduce the number of storage requests sent to the overloaded storage controller; Accordingly, the overloaded storage controller is configured to forward the storage requests received by itself to other storage controllers.

6. The system according to claim 5, characterized in that The primary storage end constructs a distributed block storage service based on the multiple storage controllers.

7. The system according to claim 1, wherein: The backup storage end is used to synchronously back up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in an incremental backup manner.

8. A data processing method, characterized in that: Applicable to any cloud host in the cloud platform, including: Sending an encrypted volume creation request to a primary storage end and a backup storage end, so that the primary storage end creates a primary encrypted volume in response to the encrypted volume creation request, and so that the backup storage end creates a backup encrypted volume of the same size as the primary encrypted volume in response to the encrypted volume creation request; Mount the primary encrypted volume, encrypt the business data to be stored using the key generated for the primary encrypted volume by the key management service, and store the encrypted ciphertext in the primary encrypted volume. When the backup storage end detects that there is data update in the primary encrypted volume, it backs up the ciphertext to be backed up in the primary encrypted volume to the backup encrypted volume in accordance with the backup method negotiated with the primary encrypted volume for the current business volume of the cloud host.

9. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to execute the computer program to implement the method according to claim 8.

10. A non-volatile storage medium, characterized in that: Used to store a computer program, wherein the computer program implements the method according to claim 8 when executed by a processor.

Citation Information

Patent Citations

  • Big data disaster recovery management method and device, equipment and storage medium

    CN117349083A

  • Cluster disaster recovery method, device, equipment and medium

    CN117724901A

  • Data backup method and device based on hyper-fusion mechanism and medium

    CN118312359A

  • Cloud hard disk backup method and device, computer equipment and storage medium

    CN119336548A

  • Encryption intermediary for volume creation

    US10867052B1