Data backup and recovery method and device, computing equipment and communication system
By generating data streams and storing them in parallel on a storage server and encrypting them, the problem of low data backup and recovery efficiency in the prior art is solved, and efficient data backup and recovery is achieved.
Patent Information
- Application Number
- CN202410358390.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-26
- Publication Date
- 2025-09-26
AI Technical Summary
Existing technologies require multiple read and write operations during data backup and recovery, occupying a large amount of local storage space, resulting in low efficiency and waste of resources.
The generated data stream is stored in parallel on the storage server and encrypted at the same time, avoiding local caching. The data is transmitted and encrypted in parallel in blocks during the transmission process.
It saves storage resources, reduces backup and recovery time, and improves data backup and recovery efficiency.
Smart Images

Figure CN120704941A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing, and in particular to a data backup and recovery method, apparatus, computing device, and communication system. Background Art
[0002] Currently, when backing up data, the data is first temporarily stored on a local storage medium. The data is then read from the local storage medium, signed to generate a signature file, and both the data and the signature file are stored on a remote storage server for backup. However, during the data backup process, multiple read and write operations are required, and a large amount of local storage space is consumed, resulting in low data backup efficiency and a waste of storage resources.
[0003] When restoring data, the data and signature file from the remote storage server are first temporarily downloaded to the local storage medium. The signature file is then read from the local storage medium to verify the downloaded data. However, during the data recovery process, multiple read and write operations are required. The signature file must be used to verify the data after the data download is complete, and this consumes a large amount of local storage space, resulting in low data recovery efficiency and a waste of storage resources. Summary of the Invention
[0004] This application provides a data backup and recovery method, apparatus, computing device, and communication system that improves the efficiency of data backup and data recovery and saves storage resources. The following describes the data backup method and data recovery method respectively.
[0005] In a first aspect, a data backup method is provided, comprising: generating a data stream and storing the data stream on a storage server; and, while storing the data stream on the storage server, encrypting payload data in the data stream to generate an encrypted file. Upon completion of data stream storage, the payload data in the data stream is also encrypted, and the encrypted file is stored on the storage server.
[0006] Compared to temporarily storing the data to be backed up on a disk first, then reading the data from the disk for encryption, and finally transferring the data and the encrypted file to the storage server for backup, the data backup method provided by the present application does not cache the data stream locally, but directly stores the data stream on the storage server, without occupying additional local storage space, thus saving storage resources. Moreover, during the above-mentioned process of storing the data stream on the storage server, the payload data in the data stream is encrypted until the data stream storage is completed. There is no need to wait for the data stream to be completely stored on the disk before encryption, nor is there any need to perform multiple read and write operations, which saves backup time and improves the efficiency of data backup.
[0007] In a possible implementation, generating a data stream and storing the data stream in a storage server includes: after generating the data stream, directly storing the data stream in the storage server without caching the data stream.
[0008] Directly transferring data streams from the local server to the storage server, rather than temporarily caching the data stream locally before transferring it, saves storage resources without occupying additional local storage space. This also reduces the time required to store the data stream and improves data backup efficiency.
[0009] In another possible implementation, storing the data stream in the storage server includes: dividing the payload data in the data stream into a plurality of data blocks; transmitting the plurality of data blocks in parallel, and storing the data stream in the storage server.
[0010] In another possible implementation, transmitting multiple data blocks in parallel and storing the data stream in a storage server includes: transmitting multiple data blocks in parallel and storing the data stream in multiple storage servers.
[0011] In another possible implementation, the method further includes: when a first data block among the multiple data blocks fails to be transmitted, retransmitting the first data block.
[0012] In this way, the data stream is divided into multiple data blocks for parallel transmission, improving data stream transmission efficiency. During the parallel transmission of multiple data blocks to at least one remote storage server, based on the data stream segmentation, if the transmission of the first data block among the multiple data blocks fails, the first data block can be any other data block in the multiple data blocks and can be retransmitted. This eliminates the need to restart the transmission of the entire data stream, saving data transmission time and further improving data backup efficiency.
[0013] In another possible implementation, the encrypted file includes a digest file and a signature file; encrypting the payload data in the data stream to obtain the encrypted file includes: encrypting the payload data in the data stream according to the digest algorithm to obtain the digest file; encrypting the digest file according to the signature algorithm to obtain the signature file, and the signature file includes ciphertext information of the digest file.
[0014] In another possible implementation, encrypting payload data in a data stream according to a digest algorithm to obtain a digest file includes: dividing the payload data in the data stream into multiple data blocks; and encrypting each of the multiple data blocks according to the digest algorithm to obtain a digest file, wherein the digest file includes a data block number of each data block and digest information of the data block indicated by the data block number.
[0015] When encrypting payload data in a data stream, in order to improve data security, each data block can be first encrypted according to a digest algorithm to obtain a digest file, and then the digest file can be encrypted according to a signature algorithm. Thus, an encrypted file is obtained after two encryptions, so that the encrypted file can be used for data verification during data recovery to ensure data security.
[0016] In another possible implementation, generating the data stream includes compressing the data to be backed up to obtain the data stream. Compressing the data is beneficial to saving storage space.
[0017] In a second aspect, a data recovery method is provided, comprising: obtaining a data stream and an encrypted file from a storage server, where the encrypted file is obtained by encrypting the data stream during data backup; and, while obtaining the data stream from the storage server, concurrently verifying the payload data in the data stream against the encrypted file. If the data stream passes the verification, the data stream is restored. If the data stream fails the verification, receiving the data stream is stopped.
[0018] Compared to temporarily downloading the data and encrypted files from the storage server to the local disk first, and then using the encrypted file to verify the data after the data is downloaded, the data recovery method provided by the present application directly obtains the data stream from the storage server, does not cache the data stream locally, does not need to occupy additional local storage space, and saves storage resources. In addition, in the above process of obtaining the data stream from the storage server, the encrypted file is used to verify the payload data in the data stream. If the verification fails, the data stream is stopped in time. There is no need to wait for the data stream to be completely downloaded to the local disk before verification, and there is no need to perform multiple read and write operations, which saves recovery time and improves the efficiency of data recovery.
[0019] In another possible implementation, the encrypted file includes a digest file and a signature file. The digest file is obtained by encrypting the data stream according to the digest algorithm, and the signature file is obtained by encrypting the digest file according to the signature algorithm. The payload data in the data stream is verified according to the encrypted file, including: verifying the digest file according to the signature file; when the digest file passes the verification, verifying the payload data in the data stream according to the digest file.
[0020] In another possible implementation, verifying the payload data in the data stream according to the digest file includes: dividing the payload data in the data stream into multiple data blocks; generating a digest to be verified for each of the multiple data blocks according to a digest algorithm; and verifying the digest to be verified according to the digest file.
[0021] When verifying the payload data in the data stream, the digest file is first verified against the signature file, based on the encryption process that encrypts the encrypted file twice during data backup. If the digest file passes verification, each data block is then verified against the digest file. If each data block passes verification, the data stream passes verification, indicating that the data stream has not been illegally tampered with, ensuring data security and integrity.
[0022] In another possible implementation, when the data stream verification fails, stopping receiving the data stream includes: when any data block among the multiple data blocks fails verification, stopping receiving the data stream.
[0023] During the download process of a data stream from a storage server to a local server, the payload data in the data stream can be divided into multiple data blocks. If any of these blocks fails verification, indicating that the data stream has been illegally tampered with, the download of the data stream is promptly terminated, and the local server stops receiving the data stream. This eliminates the need to wait for all data in the data stream to be fully downloaded to the local server before verification. Performing data stream verification during the download process facilitates the timely detection of illegal data and the prompt termination of the download task. This saves time and improves data recovery efficiency.
[0024] In another possible implementation, restoring the data stream includes: decompressing the data stream to obtain restored data. The original data is restored by decompressing the data stream, so as to perform data processing and other services based on the original data.
[0025] In a third aspect, a data backup device is provided, comprising a communication module and an encryption module. After generating a data stream, the communication module is configured to store the data stream on a storage server. While the communication module is storing the data stream on the storage server, the encryption module is configured to concurrently encrypt the payload data in the data stream to generate an encrypted file. The communication module is further configured to store the encrypted file on the storage server.
[0026] In a possible implementation, when the communication module stores the data stream in the storage server, it is specifically configured to: not cache the data stream, but directly store the data stream in the storage server.
[0027] In another possible implementation, when the communication module stores the data stream in the storage server, it is specifically configured to: divide the payload data in the data stream into multiple data blocks; transmit the multiple data blocks in parallel, and store the data stream in the storage server.
[0028] In another possible implementation, when the communication module transmits multiple data blocks in parallel and stores the data stream in the storage server, it is specifically configured to: transmit multiple data blocks in parallel and store the data stream in multiple storage servers.
[0029] In another possible implementation, the communication module is further configured to: when a first data block among the multiple data blocks fails to be transmitted, retransmit the first data block.
[0030] In another possible implementation, the encrypted file includes a digest file and a signature file; the encryption module encrypts the payload data in the data stream to obtain the encrypted file, and is specifically used to: encrypt the payload data in the data stream according to the digest algorithm to obtain the digest file; encrypt the digest file according to the signature algorithm to obtain the signature file, and the signature file includes the ciphertext information of the digest file.
[0031] In another possible implementation, the encryption module encrypts the payload data in the data stream according to the digest algorithm to obtain the digest file, and is specifically used to: divide the payload data in the data stream into multiple data blocks; encrypt each of the multiple data blocks according to the digest algorithm to obtain the digest file, where the digest file includes a data block number of each data block and digest information of the data block indicated by the data block number.
[0032] In another possible implementation, the apparatus further includes a compression module configured to generate a data stream. When generating the data stream, the compression module is specifically configured to compress the data to be backed up to obtain the data stream.
[0033] In a fourth aspect, a data recovery device is provided, comprising a communication module, a verification module, and a recovery module. The communication module is configured to obtain a data stream and an encrypted file from a storage server, where the encrypted file is obtained by encrypting the data stream. While the communication module is obtaining the data stream from the storage server, the verification module is configured to concurrently verify the payload data in the data stream against the encrypted file. When the data stream passes verification by the verification module, the recovery module is configured to restore the data stream. When the data stream fails verification by the verification module, the communication module is configured to stop receiving the data stream.
[0034] In one possible implementation, the encrypted file includes a digest file and a signature file. The digest file is obtained by encrypting the data stream according to the digest algorithm, and the signature file is obtained by encrypting the digest file according to the signature algorithm. When the verification module verifies the payload data in the data stream according to the encrypted file, it is specifically used to: verify the digest file according to the signature file; when the digest file passes the verification, verify the payload data in the data stream according to the digest file.
[0035] In another possible implementation, when the verification module verifies the payload data in the data stream according to the summary file, it is specifically used to: divide the payload data in the data stream into multiple data blocks; generate a summary to be verified for each of the multiple data blocks according to the summary algorithm; and verify the summary to be verified according to the summary file.
[0036] In another possible implementation, when the data stream verification fails, the communication module stops receiving the data stream, which is specifically configured to: stop receiving the data stream when any data block among the multiple data blocks fails verification.
[0037] In another possible implementation, when the recovery module restores the data stream, it is specifically configured to: decompress the data stream to obtain the recovered data.
[0038] In a fifth aspect, a computing device is provided, comprising a memory and a processor, wherein the memory is configured to store a set of computer instructions; when the processor, as an execution device in the first aspect or any possible implementation of the first aspect, executes the set of computer instructions, the operating steps of the data backup method in the first aspect or any possible implementation of the first aspect are performed. Alternatively, when the processor, as an execution device in the second aspect or any possible implementation of the second aspect, executes the set of computer instructions, the operating steps of the data recovery method in the second aspect or any possible implementation of the second aspect are performed.
[0039] In a sixth aspect, a communication system is provided, comprising a computing device and a storage server, the storage server being configured to store backup data; the computing device comprising a processor and a memory, the memory being configured to store a set of computer instructions; when the processor, as an execution device in the first aspect or any possible implementation of the first aspect, executes the set of computer instructions, the operating steps of the data backup method in the first aspect or any possible implementation of the first aspect are performed. Alternatively, when the processor, as an execution device in the second aspect or any possible implementation of the second aspect, executes the set of computer instructions, the operating steps of the data recovery method in the second aspect or any possible implementation of the second aspect are performed.
[0040] In a seventh aspect, a chip system is provided, comprising a logic circuit and a power supply circuit, wherein the power supply circuit supplies power to the logic circuit, and the logic circuit is configured to execute the operating steps of the data backup method in the first aspect or any possible implementation of the first aspect. Alternatively, the logic circuit is configured to execute the operating steps of the data recovery method in the second aspect or any possible implementation of the second aspect. In one possible design, the chip system further comprises a memory for storing program instructions and / or data.
[0041] In an eighth aspect, a computer-readable storage medium is provided, comprising: computer software instructions; when the computer software instructions are executed in a computing device, the computing device is caused to perform the steps of the data backup method in the first aspect or any possible implementation of the first aspect. Alternatively, the computing device is caused to perform the steps of the data recovery method in the second aspect or any possible implementation of the second aspect.
[0042] In a ninth aspect, a computer program product is provided. When the computer program product is executed on a computing device, the computer program product causes the computing device to perform the steps of the data backup method in the first aspect or any possible implementation of the first aspect. Alternatively, the computer program product causes the computing device to perform the steps of the data recovery method in the second aspect or any possible implementation of the second aspect.
[0043] The technical effects brought about by any design method in the third to ninth aspects can refer to the technical effects brought about by the first or second aspect, and will not be repeated here.
[0044] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 A flowchart of a data backup method provided by the prior art;
[0046] Figure 2 A flowchart of a data recovery method provided by the prior art;
[0047] Figure 3 A schematic diagram of the structure of a communication system provided in this application;
[0048] Figure 4 A flowchart of a data backup method provided in this application;
[0049] Figure 5 A schematic diagram of a transmission data flow provided by this application;
[0050] Figure 6 A timing diagram of a data backup method provided by this application;
[0051] Figure 7 A flowchart of a data recovery method provided in this application;
[0052] Figure 8 A timing diagram of a data recovery method provided by this application;
[0053] Figure 9 A schematic diagram of the structure of a data backup device provided in this application;
[0054] Figure 10 A schematic diagram of the structure of a data recovery device provided by this application;
[0055] Figure 11 A schematic diagram of the structure of a computing device provided in this application. DETAILED DESCRIPTION
[0056] With the development of big data technology, data has permeated every field and industry today. The development of fields like education, healthcare, finance, and energy, as well as the operation of equipment, industry, and industrial parks, all rely on the mining and utilization of massive amounts of data. The ever-increasing demand for data storage and the scale of data present significant challenges to data security.
[0057] Data backup is crucial to ensure data security and integrity, prevent data loss due to computing device failures or outages, and protect against data loss. Currently, digital signatures are used to protect data backups. During data recovery, the backup package is verified using the same signature. If verification passes, the original data can be restored.
[0058] The following introduces the implementation processes of the current data backup method and data recovery method respectively.
[0059] Figure 1 The following is a flow chart of a data backup method provided by the prior art. Figure 1 As shown, a compression tool is used on a local server to compress the data to be backed up to obtain a backup package (step 101). The backup package is stored on the local server's disk (step 102). The backup package on the disk is signed to obtain a signature file (step 103). The signature file is stored on the disk (step 104). The backup package and signature file are transmitted to a remote storage server (step 105).
[0060] Figure 2 The following is a flow chart of a data recovery method provided by the prior art. Figure 2 As shown, the backup package and signature file stored in the remote storage server are downloaded to the disk of the local server (step 201). The backup package is verified using the signature file on the local server (step 202). When the verification passes, the backup package is decompressed using a decompression tool on the local server to restore the original data (step 203).
[0061] However, both the data backup and data recovery processes require a significant amount of disk storage space, resulting in a waste of storage resources. Furthermore, data backups require waiting for the backup package to be stored on disk before encryption, and data recovery requires waiting for the backup package to be downloaded to disk before verification. These multiple read and write operations to the disk increase the time required for both data backup and recovery, resulting in lower efficiency.
[0062] In order to improve the efficiency of data backup and data recovery and save storage resources, the present application provides a data backup method and a data recovery method respectively.
[0063] The data backup method includes: generating a data stream and storing the data stream on a storage server; and, in parallel with storing the data stream on the storage server, encrypting the payload data in the data stream to obtain an encrypted file. Upon completion of the data stream storage, the payload data in the data stream is also encrypted, and the encrypted file is stored on the storage server.
[0064] Compared to temporarily storing the data to be backed up on a disk first, then reading the data from the disk for encryption, and finally transferring the data and the encrypted file to the storage server for backup, the data backup method provided by the present application does not cache the data stream locally, but directly stores the data stream on the storage server, without occupying additional local storage space, thus saving storage resources. Moreover, during the above-mentioned process of storing the data stream on the storage server, the payload data in the data stream is encrypted until the data stream storage is completed. There is no need to wait for the data stream to be completely stored on the disk before encryption, nor is there any need to perform multiple read and write operations, which saves backup time and improves the efficiency of data backup.
[0065] The data recovery method includes: obtaining a data stream and an encrypted file from a storage server, where the encrypted file is obtained by encrypting the data stream during data backup; and, while obtaining the data stream from the storage server, concurrently verifying the payload data in the data stream against the encrypted file. If the data stream passes the verification, the data stream is restored. If the data stream fails the verification, data stream reception is stopped.
[0066] Compared to temporarily downloading the data and encrypted files from the storage server to the local disk first, and then using the encrypted file to verify the data after the data is downloaded, the data recovery method provided by the present application directly obtains the data stream from the storage server, does not cache the data stream locally, does not need to occupy additional local storage space, and saves storage resources. In addition, in the above process of obtaining the data stream from the storage server, the encrypted file is used to verify the payload data in the data stream. If the verification fails, the data stream is stopped in time. There is no need to wait for the data stream to be completely downloaded to the local disk before verification, and there is no need to perform multiple read and write operations, which saves recovery time and improves the efficiency of data recovery.
[0067] The data backup method and data recovery method provided by this application are described in detail below with reference to the accompanying drawings.
[0068] Figure 3 This is a schematic diagram of the structure of a communication system provided by this application. Figure 3As shown, the communication system 300 includes a local server 310 and a storage server 320. The local server 310 and the storage server 320 can be connected through a switch. The local server 310 and the storage server 320 interact with each other to achieve data backup and recovery.
[0069] The local server 310 may be a computing device including a memory 311 and a processor 312 .
[0070] The memory 311 may be used to store data to be backed up, including but not limited to business data, application data, and operating system (OS) running data.
[0071] Business data can be data closely related to business processing generated by an enterprise or organization when operating its core business. Businesses can involve various fields such as education, healthcare, finance, and e-commerce. For example, when counting e-commerce orders, business data may include customer information, transaction records, and order details. This application does not restrict the type of business data.
[0072] Application data can be data generated, processed and stored by application software during its operation. It can include text, pictures and videos, etc. It can also include log files, temporary files and cached data automatically generated by the application software.
[0073] OS operation data can be the data generated and processed by the OS when managing hardware devices and software resources. It can include operation status information (such as CPU usage, memory allocation, and network connection status), device driver data, file system data, log files, OS configuration data, and user account and permission data.
[0074] In order to ensure the security of the data stored in the memory 311 and prevent data loss due to security threats such as illegal tampering, virus intrusion or malware attack, it is necessary to back up the data regularly and restore the data according to usage requirements. The processor 312 can serve as the operation center and control center of the local server 310 to implement data backup or data recovery. For example, the processor 312 includes a central processing unit (CPU). During data backup, the CPU is responsible for data compression, signing and data packet uploading. During data recovery, the CPU is responsible for data packet downloading, signature verification and decompression of data packets to restore the original data. The specific implementation method of data backup can refer to the content described in subsequent steps 410 to 430. The specific implementation method of data recovery can refer to the content described in subsequent steps 710 to 730.
[0075] Storage server 320 is configured to receive data requiring backup from processor 312 and persistently store the backup data (e.g., backup data 1, backup data 2, ..., backup data N). Storage server 320 may be a remote storage server, including but not limited to a cloud storage server and Network Attached Storage (NAS). As the amount of stored data continues to increase, NAS can expand storage capacity according to user needs without interrupting storage services.
[0076] This application does not limit the number of the local servers 310 and storage servers 320. The number of each type of server can be one, or there can be two or more servers sharing different responsibilities and cooperating with each other to implement various functions of the server.
[0077] Next, combine Figures 4 to 8 , the data backup method and data recovery method provided in this application are described in detail respectively.
[0078] First, the data backup method provided by this application is introduced. Figure 4 A flow chart of a data backup method provided in this application, mainly based on Figure 3 For example, the processor encrypts the data stream when storing it in the storage server to achieve data backup. Figure 4 As shown, the data recovery method may include the following steps.
[0079] Step 410: Generate a data stream and store the data stream in a storage server.
[0080] After exporting the data to be backed up from the storage device using a data export tool, the data can be compressed to create a data package (e.g., pkg.tar) to save storage space on the storage server. The data package to be stored is then streamed, generating a data stream. The data stream message can include a header (e.g., an Ethernet frame header and an IP header) and payload data.
[0081] In order to save storage resources, after the data stream is generated, it is not cached locally. Instead, the data stream can be directly transmitted from the local server to a remote storage server. In this way, the data stream is directly stored in the storage server, and the data stream is persistently saved in the storage server to achieve data backup and prevent data loss.
[0082] In some embodiments, to improve data stream transmission efficiency, the payload data in the data stream is first divided into multiple data chunks. For example, a fixed chunk length (e.g., 2MB) is configured, and the payload data is divided into multiple data chunks according to the chunk length. The multiple data chunks are then transmitted in parallel, and the data stream is stored on a storage server. Figure 5 A schematic diagram of a transmission data flow provided by this application, such as Figure 5 As shown in (a) of Figure 1, the payload data in the data stream is first divided on the local server into multiple data blocks, including data block 1, data block 2, ..., data block N, which are temporarily stored in the local buffer. The multiple data blocks are then transmitted in parallel to the remote storage server to achieve data stream storage.
[0083] The embodiment of the present application does not limit the number of remote storage servers. Multiple data blocks can be transmitted to multiple remote storage servers in parallel. Figure 5 As shown in (b), after the payload data is divided, multiple data blocks are generated. These blocks are transmitted in parallel to multiple remote servers. For example, block 1 is transmitted to remote storage server 1, block 2 to remote storage server 2, and so on. Finally, block N is also transmitted to remote storage server 1. The remote servers then synchronize the different data blocks, improving data backup efficiency.
[0084] During the aforementioned parallel transmission of multiple data blocks to at least one remote storage server, the data stream is segmented. If the transmission of the first data block among the multiple data blocks fails, the first data block, which can be any other data block among the multiple data blocks, can be retransmitted. This eliminates the need to restart the transmission of the entire data stream, saving data transmission time and improving data backup efficiency.
[0085] Step 420: In the process of storing the data stream in the storage server, encrypt the payload data in the data stream in parallel to obtain an encrypted file.
[0086] During the process of storing the data stream on the storage server—that is, transferring the data stream from the local server to the storage server—encryption of the payload data in the data stream begins, resulting in an encrypted file. It can be considered that storing the data stream on the storage server and encrypting the payload data in the data stream are performed in parallel. Thus, rather than caching the data stream locally, the data stream is directly transferred from the local server to the storage server. During this process, the payload data in the data stream remains encrypted, eliminating the need to wait for all data in the data stream to be transferred before encryption begins. This reduces data backup time and improves backup efficiency.
[0087] In some embodiments, the encrypted file obtained by encrypting the payload data in the data stream may include a digest file and a signature file. To encrypt the payload data in the data stream, the payload data in the data stream may be first encrypted according to a digest algorithm to obtain a digest file. The digest file is then encrypted according to a signature algorithm to obtain a signature file. The embodiments of the present application do not limit the types of digest algorithms and signature algorithms. Digest algorithms include but are not limited to message digest algorithms (Message-Digest Algorithm 5, MD5) and secure hash algorithms (Security Hash Algorithm 1, SHA1), and signature algorithms include but are not limited to hash-based message authentication codes (Hash-based Message Authentication Code, HMAC), and the like.
[0088] When encrypting the payload data in a data stream using a digest algorithm, encryption can be performed using an encrypted data block approach. The payload data in the data stream is divided into multiple data blocks according to a configured block length, and each of the multiple data blocks is encrypted using the digest algorithm to generate a digest file.
[0089] For example, during a transmission process of multiple data blocks from a local server to a storage server, a first data block among the multiple data blocks is encrypted using a digest algorithm. After the encryption of the first data block is completed, a second data block among the multiple data blocks is encrypted using the digest algorithm. Similarly, the encryption using the digest algorithm may be performed over the multiple data blocks until each of the multiple data blocks is encrypted.
[0090] In some embodiments, the summary file includes the data block number of each data block and the summary information of the data block indicated by the data block number. The data block number of each data block is unique, and the summary information is also unique. Optionally, the summary file may also include the block length and the index of each data block.
[0091] For example, Table 1 is a schematic structural diagram of a digest file (pkg.tar.digest) provided in an embodiment of the present application. As shown in Table 1, the index (index), data block number (chunk ID) and digest information (digest) of each data block correspond to each other.
[0092] Table 1
[0093]
[0094] As shown in Table 1, the payload data in the data stream is divided into N data blocks, each numbered as data block 1, data block 2, ..., data block N. Taking data block 1 as an example, the index corresponding to data block 1 is 1. The data content indicated by data block 1 is encrypted using the digest algorithm, and the digest information corresponding to data block 1 is fb62c93567b65914...
[0095] After obtaining the above digest file, the digest file is encrypted according to the signature algorithm to obtain a signature file. The signature file includes the ciphertext information of the digest file. The ciphertext information of each digest file is unique.
[0096] For example, Table 2 is a schematic structural diagram of a signature file (pkg.tar.digest.sign) provided in an embodiment of the present application. As shown in Table 2, the digest file name (digestName) corresponds to the ciphertext information (signature) of the digest file.
[0097] Table 2
[0098]
[0099] As shown in Table 2, the digest file is the digest file indicated by pkg.tar.digest. The digest file is encrypted using the HMAC algorithm, and the ciphertext information obtained is HMAC:fe5e1055b3afca798364f474... and COMMON:TVZTJBYIHR7]:BHQA[_5...
[0100] In addition, the above Tables 1 and 2 illustrate the storage form of the corresponding relationship in the storage server in the form of tables, and are not limitations on the storage form of the corresponding relationship in the storage server. Of course, the storage form of the corresponding relationship in the storage server can also be stored in other forms, and this embodiment does not limit this.
[0101] Step 430: Store the encrypted file in a storage server.
[0102] After all data in the data stream is transferred from the local server to the storage server, the data stream is stored. Since the payload data in the data stream remains encrypted during storage on the storage server, all data in the data stream is also encrypted upon completion of data storage. The resulting encrypted file is also stored on the storage server, allowing for data verification during data recovery, ensuring data security and integrity.
[0103] It can be seen that the files stored in the storage server include data streams (pkg.tar) and encrypted files, wherein the encrypted files may include a digest file (pkg.tar.digest) and a signature file (pkg.tar.digest.sign).
[0104] The data backup method described in the above embodiment will be understood with reference to the accompanying drawings. Figure 6 A timing diagram of a data backup method provided by this application, such as Figure 6 As shown, a data export and compression module and an encryption module are run on a local server, and a remote storage server includes a storage module for storing data streams and encrypted files. The modules interact with each other to implement data backup. The data backup method may include the following steps:
[0105] Step 610: Export the data to be backed up, compress the data to be backed up, and generate a data stream.
[0106] Step 620: Transmit the data stream from the local server to the remote storage server to implement data stream storage. The implementation of steps 610 to 620 can refer to the relevant description of step 410 in the above embodiment.
[0107] Step 630: Encrypt the payload data in the data stream to obtain an encrypted file, which includes a digest file and a signature file. The implementation of step 630 can refer to the relevant description of step 420 in the above embodiment.
[0108] Here, the above step 620 and the above step 630 are performed in parallel.
[0109] Herein, step 630 may include the following steps 631 to 634 .
[0110] Step 631: Divide the payload data in the data stream into multiple data blocks according to the configured block length.
[0111] Step 632: Encrypt each data block in the plurality of data blocks according to the digest algorithm.
[0112] Step 633: Record the data block number of each data block in the multiple data blocks and the summary information of the data block indicated by the data block number to obtain a summary file.
[0113] Step 634: Encrypt the digest file according to the signature algorithm to obtain a signature file.
[0114] Step 640: Transmit the digest file and the signature file to the remote storage server to implement storage of the encrypted file. The implementation of step 640 can refer to the relevant description of step 430 in the above embodiment.
[0115] The data backup method provided according to the above steps is compared to first temporarily storing the data to be backed up on the disk, then reading the data on the disk for encryption, and finally transferring the data and the encrypted file to the storage server for backup. The data backup method provided by the present application does not cache the data stream locally, but directly stores the data stream on the storage server, without occupying additional local storage space, thus saving storage resources. Moreover, in the above process of storing the data stream on the storage server, the payload data in the data stream is encrypted until the data stream storage is completed. There is no need to wait for the data stream to be completely stored on the disk before encryption, nor is there any need to perform multiple read and write operations, which saves backup time and improves the efficiency of data backup.
[0116] Next, the data recovery method provided by this application is introduced. Figure 7 A flow chart of a data recovery method provided by this application, mainly based on Figure 3 For example, the processor verifies the data stream when obtaining the data stream from the storage server to achieve data recovery. Figure 7 As shown, the data recovery method may include the following steps.
[0117] Step 710: Obtain data stream and encrypted file from the storage server.
[0118] Because the data stream obtained by compressing the data to be backed up and the encrypted file obtained by encrypting the data stream are already stored on the storage server during data backup, the data stream and encrypted file from the storage server can be downloaded to the local server. For example, downloading the data stream and the encrypted file can be performed in parallel. Alternatively, if the storage capacity of the encrypted file is much smaller than that of the data stream, the data stream can be downloaded after the encrypted file is downloaded. In this manner, the data stream and encrypted file are obtained from the storage server.
[0119] In some embodiments, in order to improve the download efficiency of the data stream, similar to the data transmission method described in the above step 410 during data backup, the payload data in the data stream is first divided into multiple data blocks; then the multiple data blocks are downloaded in parallel, and the data stream is stored in a local server.
[0120] Step 720: In the process of obtaining the data stream from the storage server, verify the payload data in the data stream according to the encrypted file in parallel.
[0121] During the process of acquiring the data stream from the storage server, i.e., downloading the data stream from the remote server to the local server, the payload data in the data stream is verified against the encrypted file. It can be considered that downloading the data stream to the local server and verifying the payload data in the data stream are performed in parallel. Thus, the data stream is downloaded directly from the storage server to the local server without caching it locally. During the data stream download process, the payload data in the data stream is verified without having to wait until all the data in the data stream has been downloaded before performing verification. This saves data recovery time and improves data recovery efficiency.
[0122] In some embodiments, the encrypted file obtained from the storage server may include a digest file (pkg.tar.digest) and a signature file (pkg.tar.digest.sign). The digest file may be obtained by encrypting the data stream according to the digest algorithm during data backup, and the signature file may be obtained by encrypting the digest file according to the signature algorithm during data backup.
[0123] The payload data in the data stream is verified against the encrypted file. This can be done by first verifying the digest file against the signature file. If the digest file passes verification, the payload data in the data stream is then verified against the digest file. If the digest file fails verification, the data stream from the storage server is immediately stopped.
[0124] In some embodiments, when verifying the summary file based on the signature file, the same signature algorithm as that used during data backup is used to generate a signature to be verified for the summary file. The signature to be verified for the summary file is verified based on the ciphertext information (signature) of the summary file included in the signature file. For example, it can be determined whether the summary file has passed the verification by comparing the signature to be verified and the ciphertext information. If the comparison results are the same, it indicates that the data stream downloaded during data recovery and the data stream transmitted during data backup are consistent, the data stream has not been illegally tampered with, and the summary file has passed the verification. If the comparison results are different, it indicates that the data stream downloaded during data recovery and the data stream transmitted during data backup are inconsistent, the data stream is likely to have been illegally tampered with, and the summary file has failed the verification.
[0125] If the digest file passes verification, the payload data in the data stream can be verified using a data block verification method. The payload data in the data stream is divided into multiple data blocks according to the configured block length. The same digest algorithm used during data backup is used to generate a digest to be verified for each of the multiple data blocks. The digest for each data block is verified based on the digest information (digest) of the data block indicated by each data block ID (chunk ID) included in the digest file.
[0126] For example, when downloading multiple data blocks from a storage server to a local server, the digest to be verified of the first data block can be compared with the digest information of the first data block. If the comparison results are the same, the first data block passes verification. The digest to be verified of the second data block is then compared with the digest information of the second data block. If the comparison results are the same, the second data block passes verification. The comparison is repeated over multiple data blocks until each of the multiple data blocks passes verification, and the data stream passes verification.
[0127] Step 730: When the data stream passes the verification, the data stream is restored; when the data stream fails the verification, the data stream is stopped from being received.
[0128] After all data in the data stream is downloaded from the storage server to the local server, the data stream is acquired. During the process of acquiring the data stream from the storage server, the payload data in the data stream is verified. When data stream acquisition is complete, if the data stream passes verification, such as if the payload data in the data stream is divided into multiple data blocks and each of the multiple data blocks passes verification, the data stream is restored and decompressed to obtain the recovered data, thus achieving data recovery.
[0129] When downloading a data stream from a remote server to a local server, if the payload data in the data stream fails verification—for example, if any of multiple data blocks fails verification, indicating that the data stream has likely been illegally tampered with—then the download of the data stream is promptly terminated, and the local server stops receiving the data stream from the storage server. This eliminates the need to wait for all data in the data stream to be fully downloaded before verification. Performing data stream verification during the download process facilitates timely detection of illegal data and termination of the download task. This reduces data recovery time and improves data recovery efficiency.
[0130] The data recovery method described in the above embodiment will be understood with reference to the accompanying drawings. Figure 8 A timing diagram of a data recovery method provided by this application, such as Figure 8 As shown, a data recovery module, a data decompression and import module, and a verification module are run on a local server. The remote storage server includes a storage module for storing data streams and encrypted files. The modules interact with each other to achieve data recovery. The data recovery method may include the following steps:
[0131] Step 810: Start the data recovery task and download the data stream and encrypted file (including the signature file and the digest file) in the storage server to the local server. The implementation of step 810 can refer to the relevant description of step 710 in the above embodiment.
[0132] Step 820: Verify the payload data in the data stream according to the encrypted file. The implementation of step 820 can refer to the relevant description of step 720 in the above embodiment.
[0133] Here, the above step 810 and the above step 820 are performed in parallel.
[0134] Among them, step 820 may include the following steps 821 to 823.
[0135] Step 821: Verify the digest file against the signature file. If the digest file fails verification, proceed to step 822. Otherwise, proceed to step 823.
[0136] Step 822: When the summary file fails to pass the verification, the download data stream is terminated.
[0137] Step 823: When the summary file passes verification, the payload data in the data stream is verified according to the summary file.
[0138] Among them, step 823 may include the following steps 823.a to 823.c.
[0139] Step 823.a: Divide the payload data in the data stream into multiple data blocks according to the block length configured during data backup.
[0140] Step 823.b: Generate a digest to be verified for each data block in the multiple data blocks according to the digest algorithm.
[0141] Step 823.c: Verify the digest of each data block against the digest information of each data block in the digest file. If any of the multiple data blocks fails verification, data stream verification has failed, and step 830 is executed. If all of the multiple data blocks pass verification, data stream verification has succeeded, and step 840 is executed.
[0142] Step 830: If any data block among the multiple data blocks fails to pass verification, the download data stream is terminated, that is, the local server stops receiving the data stream sent from the storage server.
[0143] Step 840: When the data stream passes verification, the data stream is restored. When restoring the data stream, the data stream can be decompressed to obtain the restored data. The implementation of steps 830 to 840 can refer to the relevant description of step 730 in the above embodiment.
[0144] The data recovery method provided by the above steps is compared to temporarily downloading the data and encrypted files from the storage server to the local disk first, and then using the encrypted files to verify the data after the data download is complete. The data recovery method provided by the present application directly obtains the data stream from the storage server, does not cache the data stream locally, does not need to occupy additional local storage space, and saves storage resources. In addition, in the above process of obtaining the data stream from the storage server, the encrypted file is used to verify the payload data in the data stream. If the verification fails, the data stream is stopped in time. There is no need to wait for the data stream to be completely downloaded to the local disk before verification, and there is no need to perform multiple read and write operations, which saves recovery time and improves the efficiency of data recovery.
[0145] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. It is understandable that in order to implement the above functions, the computing device includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0146] Combined with the above Figures 3 to 8 , respectively describe in detail the data backup method and data recovery method provided by the embodiment of the present application, and then combine Figure 9 and Figure 10 , respectively describe the data backup device and data recovery device provided according to the embodiments of the present application.
[0147] Figure 9 This is a schematic diagram of the structure of a data backup device provided by the present application. These data backup devices can be used to implement the functions of the processor in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment.
[0148] like Figure 9 As shown, the data backup device 900 includes a communication module 910 and an encryption module 920 .
[0149] The communication module 910 is used to store the data stream to the storage server. For example, the communication module 910 is used to perform Figure 4 Step 410.
[0150] In the process of the communication module 910 storing the data stream to the storage server, the encryption module 920 is used to execute in parallel the encryption of the payload data in the data stream to obtain an encrypted file. Figure 4 Step 420.
[0151] The communication module 910 is also used to store the encrypted file in the storage server. Figure 4 Step 430.
[0152] Optionally, when the communication module 910 stores the data stream in the storage server, it is specifically configured to: not cache the data stream, but directly store the data stream in the storage server.
[0153] Optionally, when the communication module 910 stores the data stream in the storage server, it is specifically used to: divide the payload data in the data stream into multiple data blocks; transmit the multiple data blocks in parallel, and store the data stream in the storage server.
[0154] Optionally, when the communication module 910 transmits multiple data blocks in parallel and stores the data stream in a storage server, it is specifically used to: transmit multiple data blocks in parallel and store the data stream in multiple storage servers.
[0155] Optionally, the communication module 910 is further specifically configured to: when a first data block among multiple data blocks fails to be transmitted, retransmit the first data block.
[0156] Optionally, the encrypted file includes a digest file and a signature file; the encryption module 920 encrypts the payload data in the data stream to obtain the encrypted file, which is specifically used to: encrypt the payload data in the data stream according to the digest algorithm to obtain the digest file; encrypt the digest file according to the signature algorithm to obtain the signature file, and the signature file includes the ciphertext information of the digest file.
[0157] Optionally, the encryption module 920 encrypts the payload data in the data stream according to the digest algorithm to obtain a digest file, which is specifically used to: divide the payload data in the data stream into multiple data blocks; encrypt each data block in the multiple data blocks according to the digest algorithm to obtain a digest file, wherein the digest file includes the data block number of each data block and the summary information of the data block indicated by the data block number.
[0158] Optionally, the data backup device 900 further includes a compression module 930 .
[0159] The compression module 930 is used to generate a data stream. Optionally, when generating the data stream, the compression module 930 is specifically used to compress the data to be backed up to obtain the data stream.
[0160] Figure 10This is a schematic diagram of the structure of a data recovery device provided by the present application. These data recovery devices can be used to implement the functions of the processor in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment.
[0161] like Figure 10 As shown, the data recovery device 1000 includes a communication module 1010 , a verification module 1020 and a recovery module 1030 .
[0162] The communication module 1010 is used to obtain the data stream and the encrypted file from the storage server. The encrypted file is obtained by encrypting the data stream. For example, the communication module 1010 is used to execute Figure 7 Step 710.
[0163] In the process of the communication module 1010 acquiring the data stream from the storage server, the verification module 1020 is used to perform the verification of the payload data in the data stream according to the encrypted file in parallel. Figure 7 Step 720.
[0164] When the data stream passes the verification of the verification module 1020, the recovery module 1030 is used to restore the data stream. When the data stream fails to pass the verification of the verification module 1020, the communication module 1010 is used to stop receiving the data stream. For example, the communication module 1010 is used to perform Figure 7 Step 730.
[0165] Optionally, the encrypted file includes a digest file and a signature file. The digest file is obtained by encrypting the data stream according to the digest algorithm, and the signature file is obtained by encrypting the digest file according to the signature algorithm. When the verification module 1020 verifies the payload data in the data stream according to the encrypted file, it is specifically used to: verify the digest file according to the signature file; when the digest file passes the verification, verify the payload data in the data stream according to the digest file.
[0166] Optionally, when verifying the payload data in the data stream according to the summary file, the verification module 1020 is specifically used to: divide the payload data in the data stream into multiple data blocks; generate a summary to be verified for each of the multiple data blocks according to the summary algorithm; and verify the summary to be verified according to the summary file.
[0167] Optionally, when the data stream verification fails, the communication module 1010 stops receiving the data stream, which is specifically used to: stop receiving the data stream when any data block among the multiple data blocks fails to be verified.
[0168] Optionally, when restoring the data stream, the recovery module 1030 is specifically configured to: decompress the data stream to obtain the restored data.
[0169] It should be understood that the data backup device 900 and the data recovery device 1000 according to the embodiment of the present application may correspond to the method described in the embodiment of the present application, and the above and other operations and / or functions of each unit in the data backup device 900 are to achieve Figure 4 The corresponding processes of each method in the data recovery device 1000 and the above and other operations and / or functions of each unit are to achieve Figure 7 For the sake of brevity, the corresponding processes of each method in are not repeated here.
[0170] Figure 11 This is a schematic diagram of the structure of a computing device provided by this application. Figure 11 As shown, computing device 1100 includes a processor 1110, a bus 1120, a memory 1130, a memory unit 1150 (also referred to as a main memory unit), and a communication interface 1140. Processor 1110, memory 1130, memory unit 1150, and communication interface 1140 are connected via bus 1120.
[0171] It should be understood that in this embodiment, the processor 1110 may be a CPU, but may also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0172] The communication interface 1140 is used to implement communication between the computing device 1100 and an external device or component. In this embodiment, the communication interface 1140 can also be used to exchange data with a storage server.
[0173] The bus 1120 may include a path for transmitting information between the aforementioned components (e.g., the processor 1110, the memory unit 1150, and the storage 1130). In addition to the data bus, the bus 1120 may also include a power bus, a control bus, and a status signal bus. However, for the sake of clarity, various buses are labeled as bus 1120 in the figure. The bus 1120 may be a Peripheral Component Interconnect Express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc.
[0174] As an example, computing device 1100 may include multiple processors. The processor may be a multi-core (multi-CPU) processor. A processor herein may refer to one or more devices, circuits, and / or computing units for processing data (e.g., computer program instructions). Processor 1110 may encrypt the data stream while storing it on a storage server to implement data backup. Alternatively, the data stream may be verified while being retrieved from the storage server to implement data recovery.
[0175] It is worth mentioning that Figure 11 In the example, the computing device 1100 includes a processor 1110 and a memory 1130. Here, the processor 1110 and the memory 1130 are respectively used to indicate a type of device or equipment. In a specific embodiment, the number of each type of device or equipment can be determined according to business requirements.
[0176] Memory unit 1150 may be used to store data streams and encrypted files, etc., corresponding to the above-mentioned method embodiments. Memory unit 1150 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0177] The memory 1130 is used to store data streams and encrypted files, etc., and can be a solid-state drive or a mechanical hard drive.
[0178] It should be understood that the computing device 1100 according to this embodiment may correspond to the data backup device 900 in this embodiment, and may correspond to the device that performs the Figure 4 The corresponding subjects in the data backup device 900, and the above and other operations and / or functions of each module are respectively to achieve Figure 4 Alternatively, the computing device 1100 may correspond to the data recovery device 1000 in this embodiment, and may correspond to the execution according to Figure 7 The corresponding subjects in the data recovery device 1000, and the above and other operations and / or functions of the modules are respectively to achieve Figure 7 For the sake of brevity, the corresponding process will not be described here.
[0179] The method steps in this embodiment can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a computer device. Of course, the processor and storage medium can also exist as discrete components in a network device or a terminal device.
[0180] The present application also provides a chip system, which includes a processor for implementing the functions of the data processing unit in the above method. In one possible design, the chip system also includes a memory for storing program instructions and / or data. The chip system can be composed of a chip alone or can include a chip and other discrete devices.
[0181] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the process or function described in the embodiments of the present application is performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instruction can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD).
[0182] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A data backup method, characterized in that: The method comprises: generating a data stream, and storing the data stream in a storage server; In the process of storing the data stream in the storage server, encrypting the payload data in the data stream in parallel to obtain an encrypted file; The encrypted file is stored in the storage server.
2. The method according to claim 1, characterized in that Generating a data stream and storing the data stream in a storage server, including: After the data stream is generated, the data stream is not cached but directly stored in the storage server.
3. The method according to claim 1 or 2, characterized in that Storing the data stream in a storage server includes: Dividing the payload data in the data stream into a plurality of data blocks; The multiple data blocks are transmitted in parallel, and the data stream is stored in the storage server.
4. The method according to any one of claims 1 to 3, characterized in that The encrypted file includes a digest file and a signature file; and the step of encrypting the payload data in the data stream to obtain the encrypted file includes: Encrypt the payload data in the data stream according to a digest algorithm to obtain the digest file; The digest file is encrypted according to a signature algorithm to obtain the signature file, where the signature file includes ciphertext information of the digest file.
5. The method according to claim 4, characterized in that Encrypting the payload data in the data stream according to a digest algorithm to obtain the digest file includes: Dividing the payload data in the data stream into a plurality of data blocks; Each data block in the plurality of data blocks is encrypted according to the digest algorithm to obtain the digest file, wherein the digest file includes a data block number of each data block and digest information of the data block indicated by the data block number.
6. The method according to any one of claims 1 to 5, characterized in that Generate data streams, including: The data to be backed up is compressed to obtain the data stream.
7. A data recovery method, characterized in that: The method comprises: Obtaining a data stream and an encrypted file from a storage server, wherein the encrypted file is obtained by encrypting the data stream; In the process of obtaining the data stream from the storage server, performing verification of the payload data in the data stream according to the encrypted file in parallel; When the data stream passes the verification, restoring the data stream; When the data stream verification fails, the receiving of the data stream is stopped.
8. The method according to claim 7, characterized in that The encrypted file includes a digest file and a signature file, wherein the digest file is obtained by encrypting the data stream according to the digest algorithm, and the signature file is obtained by encrypting the digest file according to the signature algorithm; Verifying the payload data in the data stream according to the encrypted file includes: Verifying the digest file according to the signature file; When the summary file passes the verification, the payload data in the data stream is verified according to the summary file.
9. The method according to claim 8, characterized in that Verifying the payload data in the data stream according to the digest file includes: Dividing the payload data in the data stream into a plurality of data blocks; generating a digest to be verified for each data block in the plurality of data blocks according to the digest algorithm; The digest to be verified is verified according to the digest file.
10. The method according to any one of claims 7 to 9, characterized in that Restoring the data stream includes: The data stream is decompressed to obtain restored data.
11. A computing device, characterized in that The computing device includes a memory and a processor, the memory is used to store a set of computer instructions; when the processor in the computing device executes the set of computer instructions, the operating steps of the method described in any one of claims 1 to 6 are performed; or, the operating steps of the method described in any one of claims 7 to 10 are performed.
12. A communication system, characterized in that: The communication system includes a computing device and a storage server, the storage server is used to store backup data, the computing device includes a memory and a processor, the memory is used to store a set of computer instructions; when the processor executes the set of computer instructions, the operating steps of the method described in any one of claims 1 to 6 are executed; or, the operating steps of the method described in any one of claims 7 to 10 are executed.