Method for cloud platform data off-site backup
By establishing a transmission channel and setting up action groups between the cloud platform and the off-site backup center, and using floating points and trigger layers to form data isolation, the risks of data leakage and tampering in cloud platform data backup are resolved, and data security protection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-19
- Publication Date
- 2026-04-14
AI Technical Summary
In existing technologies, cloud platform data backups are subject to risks of data leakage and tampering, and lack effective protection measures.
By establishing a transmission channel between the cloud platform and the off-site backup center, setting up action groups to block unauthorized network access, and using floating points and trigger layers to form data isolation, the action groups follow the location of unauthorized networks to surround and move around, thus protecting the data.
It achieves effective isolation and protection of data, prevents unauthorized network access and tampering, and ensures data security.
Smart Images

Figure CN121173595B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data storage technology, and more specifically to a method for off-site data backup on a cloud platform. Background Technology
[0002] With the rapid development of the digital economy, enterprises' business operations, customer management, and production processes all heavily rely on data; for example, user information, transaction records, R&D data, and supply chain data. Data has evolved from an auxiliary tool to a core asset for enterprises, its value reflected in driving business decisions, improving operational efficiency, and building competitive barriers. To ensure data security, backups are necessary. However, backed-up data is easily accessible, leading to potential data leaks and the risk of data tampering, resulting in inadequate data protection. Summary of the Invention
[0003] The purpose of this invention is to provide a method for off-site data backup of cloud platforms to address the shortcomings in the prior art.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a method for off-site data backup of a cloud platform, comprising the following steps:
[0005] Identify the target backup center in a different location and deploy multiple action groups corresponding to the target backup center;
[0006] Identify the data in the cloud platform that needs to be backed up as the target data, establish a transmission channel between the cloud platform and the target backup center, and transfer the target data to the target backup center for storage;
[0007] When unauthorized network access to the target backup center is detected, action groups are activated to block such access, and multiple action groups are used to protect the data of the target backup center.
[0008] In a preferred embodiment, the step of deploying multiple action groups to the corresponding target backup center includes:
[0009] The storage space is determined according to the target backup center, and the space is divided within the storage space to obtain the target space;
[0010] A trigger layer is set outside the target space, which is formed by connecting multiple network nodes to each other, and a mapping relationship is established between the trigger layer and the target space.
[0011] Multiple fixed floating points are set up within the target space, and adjacent floating points are connected to each other;
[0012] Multiple action groups are set up within the target space, and the action groups are evenly bound to floating points within the target space. The multiple action groups are interconnected through the floating points.
[0013] Set distribution rules for multiple floating points, where the distribution rule is the uniformity of the distribution of action groups on the floating points.
[0014] In a preferred embodiment, the step of establishing the mapping relationship between the triggering layer and the target space includes:
[0015] Multiple network nodes are deployed outside the target space, and adjacent network nodes are interconnected to form a trigger layer.
[0016] Establish correspondences between multiple network nodes and the target space edge range to obtain the mapping relationship between the triggering layer and the target space.
[0017] In a preferred embodiment, the step of setting multiple fixed-location floating points within the target space, with adjacent floating points interconnected, includes:
[0018] Determine multiple storage locations within the target space;
[0019] At each storage location point, a storage package and a temporary point are set as floating points, and the storage package and the temporary point are bound together at each storage location point;
[0020] Connect temporary points between adjacent storage locations, and connect storage packets between temporary storage locations.
[0021] In a preferred embodiment, the step of interconnecting the plurality of action groups via datum points includes:
[0022] Multiple action groups are set up within the target space, and the action groups are evenly distributed within the target space according to the number of action groups.
[0023] Connect evenly distributed action groups to temporary points in their storage locations, and establish communication connections between multiple action groups through these temporary points.
[0024] In a preferred embodiment, the steps of determining the data to be backed up in the cloud platform as the target data, establishing a transmission channel between the cloud platform and the target backup center, and transmitting the target data to the target backup center for storage include:
[0025] Identify the data in the current cloud platform that needs to be backed up as the target data;
[0026] The target data is transmitted to the target backup center through the transmission channel. The target data is then divided in order and labeled with sequential encoding to obtain multiple sub-data.
[0027] Multiple sub-data are evenly distributed and stored one-to-one in storage packets in the target space, with the storage packets containing the multiple sub-data being evenly distributed between the action group and the action group.
[0028] In a preferred embodiment, the step of activating action groups to block unauthorized network access to the target backup center when unauthorized network access exists, and protecting the data of the target backup center through multiple action groups, includes:
[0029] An authorized network is set for the target backup center. When the authorized network accesses the target backup center, the sub-data in the floating point is sorted and combined according to the encoding to obtain the target data and provided to the authorized network.
[0030] When there is unauthorized network access to the target backup center, the trigger layer is accessed first. The trigger layer determines the edge space range of the accessed target space, and activates a preset number of action groups within the edge space range to gather and obtain the counter-action group.
[0031] The countermeasures team surrounds the unauthorized network and tracks its movement based on its access location until it leaves the target backup center.
[0032] During the process of the countermeasures group surrounding the unauthorized network, the action groups other than the countermeasures group are adjusted to be evenly distributed. At the same time, the sub-data in the floating points that the countermeasures group moves through are temporarily transferred to floating points other than the floating points that the countermeasures group passes through. After the countermeasures group passes through, the sub-data is transferred back, thus completing the data protection of the target backup center.
[0033] In a preferred embodiment, the step of surrounding the unauthorized network by an adversarial action group, which tracks and moves the unauthorized network based on its access location until the unauthorized network leaves the target backup center, includes:
[0034] When the adversarial action group moves to the edge space range of the target space to be visited, the sub-data in the edge space range of the target space to be visited is transferred to a floating point outside the adversarial action group. The adversarial action group consists of multiple clustered and interconnected action groups.
[0035] The countermeasures team surrounds the unauthorized network, monitors its access location in real time, and moves accordingly based on the access location of the unauthorized network.
[0036] Until the unauthorized network leaves the target backup center.
[0037] The technical effects and advantages provided by the present invention in the above technical solution are as follows:
[0038] This invention stores data through floating points and isolates the data by using storage packets and temporary points, preventing unauthorized networks from accessing the target data. It has good data isolation, prevents the target data from being acquired or tampered with, and can protect the data. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.
[0040] Figure 1 This is a flowchart of the method of the present invention.
[0041] Figure 2 This is the target space logic diagram of the present invention. Detailed Implementation
[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0043] Example 1, please refer to Figure 1 As shown, the off-site data backup method for cloud platforms described in this embodiment includes the following steps:
[0044] S1. Determine the target backup center in a different location (this target backup center is Alibaba Cloud's block storage EBS, which can provide low-latency, high-performance block-level storage for cloud servers, etc.), and deploy multiple action groups corresponding to the target backup center.
[0045] S2. Determine the data that needs to be backed up in the cloud platform as the target data, establish a transmission channel between the cloud platform and the target backup center, and transfer the target data to the target backup center for storage;
[0046] S3. When there is unauthorized network access to the target backup center, activate the action group to block the unauthorized network access, and protect the data of the target backup center through multiple action groups;
[0047] As described in steps S1-S3 above, the movement of the action group is achieved through connections between temporary points. The connection channels built between temporary points support the movement of the action group, thereby enabling the action group to always follow the access location of the unauthorized network and always surround the unauthorized network, preventing the unauthorized network from breaking through the encirclement and blocking of the action group. This can block and isolate the unauthorized network from accessing floating points outside the action group, protect the storage security of external sub-data, and has a good data protection effect.
[0048] In one embodiment, see Figure 2 As shown, step S1, which involves deploying multiple action groups to the corresponding target backup center, includes:
[0049] S11. Determine the storage space corresponding to the target backup center, and divide the space within the storage space to obtain the target space;
[0050] S12. Set up a trigger layer outside the target space, wherein the trigger layer is obtained by interconnecting multiple network nodes, and establish a mapping relationship between the trigger layer and the target space;
[0051] S13. Set up multiple floating points with fixed storage locations within the target space, and connect adjacent floating points to each other;
[0052] S14. Set up multiple action groups in the target space, and bind the action groups evenly to the floating points in the target space (bind but not connected, set a blank position on the floating point, the blank position is used as a temporary point, a data storage position, and the data storage position is used as a storage package), and connect the multiple action groups to each other through the floating points.
[0053] S15. Set distribution rules for multiple floating points, where the distribution rule is the uniformity of the distribution of action groups on the floating points;
[0054] In one embodiment, step S12, which establishes the mapping relationship between the triggering layer and the target space, includes:
[0055] S121. Multiple network nodes are deployed outside the target space, and adjacent network nodes are interconnected to form a trigger layer.
[0056] S122. Establish the correspondence between multiple network nodes and the target space edge range respectively, and obtain the mapping relationship between the trigger layer and the target space.
[0057] In one embodiment, step S13, which involves setting multiple fixed-location floating points within the target space and connecting adjacent floating points to each other, includes:
[0058] S131. Determine multiple storage location points within the target space;
[0059] S132. At each storage location point, a storage package and a temporary point are set as floating points. The storage package and the temporary point at each storage location point are bound together (here it is bound, not connected. There is no information exchange capability between the temporary point and the storage package. Here, the temporary point is a network node and the cloud storage space divided by the storage package).
[0060] S133. Connect temporary points on adjacent storage locations to each other, and connect storage packets on temporary storage locations to each other.
[0061] In one embodiment, step S14, in which the plurality of action groups are interconnected via dangling points, includes:
[0062] S141. Set up multiple action groups (action groups are virtual machines) in the target space, and distribute the action groups evenly in the target space according to the number of action groups.
[0063] S142. Connect the evenly distributed action groups with the temporary points in their storage locations, and establish communication connections between multiple action groups through the temporary points.
[0064] As described in steps S11-S15 above, the cloud platform is used to store enterprise data for a recent period. To ensure data security and ease of use, some historical data needs to be stored and backed up off-site. This ensures data security without affecting normal use by enterprise personnel. First, the target backup center is determined, which is the cloud storage space provided by Alibaba Cloud. Then, the storage space used for data storage is determined as the target space. Multiple network nodes are set up outside the target space, and these adjacent network nodes are connected to wrap the target space. A correspondence is established between the network nodes and the corresponding edge space of the target space. For example, the network nodes are evenly distributed outside the target space. Therefore, according to the number of network nodes and the correspondence between the network nodes and the target space, a corresponding edge range of the target space is allocated to each network node. Establishing the correspondence between them yields the mapping relationship between the trigger layer and the target space. In this way, if there is unauthorized network access, it will access the network nodes involved. Through the network nodes, it can be known that the unauthorized network accessed the corresponding edge space range of the target space. Subsequently, the action group within the target space can react. There is a connection between the network node and the action group within the corresponding edge space range of the target space, enabling the activation of the action group.
[0065] Subsequently, multiple floating points are set up within the target space to store sub-data. A floating point is a combination of a storage packet and a temporary point. The storage packet and the temporary point are bound together but do not communicate; therefore, the storage packet cannot be accessed through the temporary point. These temporary points act as shields for the storage packets. The action group can establish connections with these temporary points, access unauthorized networks, and move accordingly. The action group acts as a shield for the storage packets. Then, temporary points at adjacent storage locations are interconnected, and storage packets at adjacent storage locations are connected. The storage packets are used to store sub-data. The connections between storage packets facilitate the temporary transfer of sub-data during subsequent data protection processes, preventing access by unauthorized networks.
[0066] Distribution rules are set for multiple floating points. These rules define the uniformity of action groups' distribution across these floating points. After unauthorized network access and the activation of action groups, the distribution of action groups within the target space becomes partially uneven. A global adjustment then moves the action groups within the target space to the edge of the target space where action groups are enabled, re-dividing the global uniformity. There is no specific density; the action groups are simply evenly distributed. The floating points containing sub-data and action groups are evenly distributed. For example, there may be ten floating points storing sub-data and ten floating points binding action groups. The floating points corresponding to sub-data and action groups can be different or within the same floating point. Sub-data is stored in storage packets, and action groups and temporary points... The interconnected and evenly distributed network links allow for rapid activation of surrounding action groups in the event of unauthorized network access, resulting in better response capabilities. Furthermore, it provides comprehensive protection against unauthorized networks across all target locations, eliminating blind spots. Action group movement is achieved through connections between temporary points, enabling them to move in uninterrupted cycles and continuously surround the unauthorized network, preventing it from breaking through. This also blocks and isolates unauthorized network access to floating points outside the action group, protecting the storage security of external sub-data and providing strong data protection.
[0067] In one embodiment, step S2, which involves determining the data to be backed up in the cloud platform as the target data, establishing a transmission channel between the cloud platform and the target backup center, and transmitting the target data to the target backup center for storage, includes:
[0068] S21. Determine the data that needs to be backed up in the current cloud platform as the target data;
[0069] S22. Transmit the target data to the target backup center through the transmission channel, divide the target data in order and mark the order encoding to obtain multiple sub-data;
[0070] S23. Distribute multiple sub-data evenly and store them one-to-one in storage packets in the target space. The storage packets containing the multiple sub-data are evenly distributed with the action group.
[0071] As described in steps S21-S23 above, after the target backup center is set up, the data that needs to be backed up off-site in the current cloud platform is determined as the target data. The target data is then transferred to the target backup center. According to the order of the target data, which can be the time order of data generation or the logical order of data, the data volume is divided into multiple data. The multiple data are sequentially encoded to obtain multiple sub-data. The multiple sub-data are evenly distributed and stored one-to-one in the storage package in the target space. The storage packages containing the multiple sub-data are evenly distributed between the action group and the action group.
[0072] In one embodiment, step S3, which involves activating action groups to block unauthorized network access to the target backup center when unauthorized network access exists, and protecting the target backup center's data through multiple action groups, includes:
[0073] S31. Set an authorized network for the target backup center. When the authorized network accesses the target backup center, sort and combine the sub-data in the floating point according to the code to obtain the target data and provide it to the authorized network.
[0074] S32. When there is unauthorized network access to the target backup center, the trigger layer will be accessed first. The trigger layer will determine the edge space range of the accessed target space. A preset number of action groups within the edge space range of the target space will be activated to gather and form an adversarial action group. (The preset number here is the number of action groups required in advance. The specific action groups selected are based on the distance of the action groups from the actual edge space range of the target space. If there are action groups with the same distance, one or more of them will be selected randomly. The purpose is to quickly form groups of action groups that reach the preset number. The grouping behavior is to connect the selected action groups.)
[0075] S33. The countermeasures team surrounds the unauthorized network and tracks its movement based on its access location until the unauthorized network leaves the target backup center.
[0076] S34. During the process of the countermeasures group surrounding the unauthorized network, the action groups other than the countermeasures group are adjusted to be evenly distributed. At the same time, the sub-data in the floating points through which the countermeasures group moves is temporarily transferred to floating points other than the floating points through which the countermeasures group moves. After the countermeasures group passes, the sub-data is transferred back to complete the data protection of the target backup center.
[0077] In one embodiment, step S33, which involves surrounding the unauthorized network with an adversarial action group, and tracking the unauthorized network's movement based on its access location until the unauthorized network leaves the target backup center, includes:
[0078] S331. When the adversarial action group moves to the edge space range of the target space to be visited, the sub-data in the edge space range of the target space to be visited is transferred to a floating point outside the adversarial action group. The adversarial action group consists of multiple clustered and interconnected action groups.
[0079] S332. Surround the unauthorized network through the countermeasures team, monitor the access location of the unauthorized network in real time through the countermeasures team, and move according to the access location of the unauthorized network.
[0080] S333, until the unauthorized network is removed from the target backup center.
[0081] As described in steps S31-S34 above, an authorized network is noted for the target backup center. This authorized network is an enterprise network port. When the authorized network accesses the target backup center, the triggering layer will not react because it is an authorized network. The sub-data in the storage packet in the floating point is sorted and combined according to the encoding to obtain the target data, which is then provided to the authorized network for access and viewing. The sub-data is encoded during storage, and the encoding order is also sequential. Therefore, the target data is obtained by combining the sub-data according to the encoding order. When an unauthorized network accesses the target backup center, the triggering layer is accessed first. The target space edge range of the unauthorized network access is determined based on the triggered network node. Then, an action group for the target space edge range is activated as an anti-action group based on the location of the unauthorized network access. The action group is located at a temporary point and is isolated from the storage packet. Therefore, the action group can surround the location of the unauthorized network access to form an isolated space. The interior of the location space surrounded by the anti-action group for the unauthorized network access is after the sub-data has been transferred. Since the access location of the unauthorized network may change, the access position of the unauthorized network is controlled by the anti-action group. Real-time monitoring is implemented by binding all action groups within the adversarial action group to the unauthorized network, enabling them to follow it. Therefore, the adversarial action group tracks the unauthorized network's access location and moves accordingly, always maintaining a state of surrounding the unauthorized network. This isolates the storage space formed between the adversarial action groups from external floating points. The action groups within the adversarial action group are interconnected; each action group is a virtual machine accessible to the unauthorized network. Data is stored through floating points, and data isolation is achieved through storage packets and temporary points, preventing the unauthorized network from accessing the target data. This provides good data isolation and protection.
[0082] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for off-site data backup on a cloud platform, characterized in that, Includes the following steps: Identify the target backup center in a different location and deploy multiple action groups corresponding to the target backup center; The steps of deploying multiple action groups to the corresponding target backup center include: The storage space is determined according to the target backup center, and the space is divided within the storage space to obtain the target space; A trigger layer is set outside the target space, which is formed by connecting multiple network nodes to each other, and a mapping relationship is established between the trigger layer and the target space. The step of setting up multiple fixed-location floating points within the target space, with adjacent floating points interconnected, includes: Determine multiple storage locations within the target space; At each storage location point, a storage package and a temporary point are set as floating points, and the storage package and the temporary point are bound together at each storage location point; Connect temporary points between adjacent storage locations, and connect storage packets between temporary storage locations; Multiple action groups are set up within the target space, and the action groups are evenly bound to floating points within the target space. The multiple action groups are interconnected through the floating points. Set distribution rules for multiple floating points, where the distribution rule is the uniformity of the distribution of action groups on the floating points; Identify the data in the cloud platform that needs to be backed up as the target data, establish a transmission channel between the cloud platform and the target backup center, and transfer the target data to the target backup center for storage; When unauthorized network access to the target backup center is detected, an action group is activated to block the unauthorized network access. This involves multiple action groups protecting the data at the target backup center, including: An authorized network is set for the target backup center. When the authorized network accesses the target backup center, the sub-data in the floating point is sorted and combined according to the encoding to obtain the target data and provided to the authorized network. When there is unauthorized network access to the target backup center, the trigger layer is accessed first. The trigger layer determines the edge space range of the accessed target space, and activates a preset number of action groups within the edge space range to gather and obtain the counter-action group. The countermeasures team surrounds the unauthorized network, tracks its movement based on its access location, and continues until the unauthorized network escapes the target backup center. This includes the following steps: When the adversarial action group moves to the edge space of the target space being accessed, the sub-data in the edge space of the target space being accessed is transferred to a floating point outside the adversarial action group. The adversarial action group consists of multiple clustered and interconnected action groups. Through the action groups, the location of unauthorized network access can be surrounded to form an isolated space. The countermeasures team surrounds the unauthorized network, monitors its access location in real time, and moves accordingly based on the access location of the unauthorized network. Until the unauthorized network leaves the target backup center; During the process of the countermeasures group surrounding the unauthorized network, the action groups other than the countermeasures group are adjusted to be evenly distributed. At the same time, the sub-data in the floating points that the countermeasures group moves through are temporarily transferred to floating points other than the floating points that the countermeasures group passes through. After the countermeasures group passes through, the sub-data is transferred back, thus completing the data protection of the target backup center.
2. The cloud platform data off-site backup method according to claim 1, characterized in that, The step of establishing the mapping relationship between the triggering layer and the target space includes: Multiple network nodes are deployed outside the target space, and adjacent network nodes are interconnected to form a trigger layer. Establish correspondences between multiple network nodes and the target space edge range to obtain the mapping relationship between the triggering layer and the target space.
3. The cloud platform data off-site backup method according to claim 1, characterized in that, The steps of connecting the multiple action groups to each other via floating points include: Multiple action groups are set up within the target space, and the action groups are evenly distributed within the target space according to the number of action groups. Connect evenly distributed action groups to temporary points in their storage locations, and establish communication connections between multiple action groups through these temporary points.
4. The cloud platform data off-site backup method according to claim 1, characterized in that, The steps of determining the data that needs to be backed up in the cloud platform as the target data, establishing a transmission channel between the cloud platform and the target backup center, and transmitting the target data to the target backup center for storage include: Identify the data in the current cloud platform that needs to be backed up as the target data; The target data is transmitted to the target backup center through the transmission channel. The target data is then divided in order and labeled with sequential encoding to obtain multiple sub-data. Multiple sub-data are evenly distributed and stored one-to-one in storage packets in the target space, with the storage packets containing the multiple sub-data being evenly distributed between the action group and the action group.
Citation Information
Patent Citations
Traditional Chinese medicine traceability data processing method based on artificial intelligence
CN120013556A
Patient information statistical system and method for emergency department
CN120893083A
Intelligent property risk management and control foundation setting system
CN121118105A