Data backup and recovery method and electronic device
By performing multiple backups and generating metadata in response to backup trigger events during the data backup and recovery process, and flexibly storing the metadata on local or remote servers, the problem of lagging data protection and cumbersome operation in existing technologies is solved, and efficient and reliable data recovery is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-23
- Publication Date
- 2026-03-27
AI Technical Summary
Existing data backup methods suffer from protection delays and cumbersome operations, making it difficult to meet the reliability and intelligence requirements of enterprises facing a surge in data volume and diversified business scenarios.
By responding to backup trigger events, the target data is backed up multiple times based on a preset backup strategy, generating backup data and metadata, which are then flexibly stored on local or remote servers. During the recovery phase, candidate version information is generated based on the metadata to accurately restore the target backup data.
It achieves a complete data protection closed loop from intelligent triggering and flexible storage to accurate recovery, improving the automation level of data protection and the reliability of recovery.
Smart Images

Figure CN121387632B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information technology, in particular to a data backup and recovery method and an electronic device. BACKGROUND
[0002] In the field of information technology, data backup is the key to business continuity. However, the existing data backup method has potential data loss risks such as protection lag and cumbersome operation.
[0003] With the explosive growth of enterprise data and the diversification of business scenarios, data protection requirements are becoming more complex. Therefore, the existing data backup method has been difficult to meet the reliability and intelligence requirements, and there is an urgent need for more timely and intelligent data protection means. SUMMARY
[0004] In view of the above problems, the present application provides a data backup and recovery method and an electronic device to improve the reliability and flexibility of data backup.
[0005] According to a first aspect of the present application, a data backup and recovery method is provided, comprising: in response to detecting a backup trigger event, performing multiple backups on target data based on a pre-backup strategy corresponding to the backup trigger event, obtaining multiple backup data and backup metadata for indexing the multiple backup data respectively; storing the multiple backup data in at least one of a local storage medium and a remote backup server, and storing the multiple backup metadata in the remote backup server; in response to detecting a backup recovery event, generating multiple candidate backup version information based on the multiple backup metadata; and in response to a recovery instruction for target backup version information in the multiple candidate backup version information, restoring target backup data corresponding to the target backup version information based on target backup metadata corresponding to the target backup version information.
[0006] A second aspect of the present application provides a data backup and recovery device, comprising: a data backup module configured to, in response to detecting a backup trigger event, perform multiple backups on target data based on a pre-backup strategy corresponding to the backup trigger event, and obtain multiple backup data and backup metadata for indexing the multiple backup data respectively; a data storage module configured to store the multiple backup data in at least one of a local storage medium and a remote backup server, and store the multiple backup metadata in the remote backup server; a version generation module configured to, in response to detecting a backup recovery event, generate multiple candidate backup version information based on the multiple backup metadata; and a data recovery module configured to, in response to a recovery instruction for target backup version information in the multiple candidate backup version information, restore target backup data corresponding to the target backup version information based on target backup metadata corresponding to the target backup version information.
[0007] The third aspect of the present application provides an electronic device, a memory configured to store instructions; a processor connected with the memory, the processor being configured to execute the instructions to implement the following operations: in response to detecting a backup trigger event, performing multiple backups of target data based on a pre-backup strategy corresponding to the backup trigger event, to obtain multiple backup data and backup metadata for respectively indexing the multiple backup data; storing the multiple backup data in at least one of a local storage medium and a remote backup server, and storing the multiple backup metadata in the remote backup server; in response to detecting a backup recovery event, generating multiple candidate backup version information based on the multiple backup metadata; in response to a recovery instruction for target backup version information in the multiple candidate backup version information, recovering target backup data corresponding to the target backup version information based on target backup metadata corresponding to the target backup version information.
[0008] The fourth aspect of the present application further provides a computer readable storage medium having a computer program or instructions stored thereon, the computer program or instructions being executed by a processor to implement the steps of the above method.
[0009] In the embodiments of the present application, by responding to various backup trigger events and performing multiple backups of target data according to a pre-backup strategy, backup data and corresponding backup metadata are generated; by flexibly storing backup data in a local storage medium or a remote server and centrally storing all backup metadata in a remote server; in the recovery phase, candidate version information is generated based on backup metadata, and target backup data is accurately recovered according to user selection through corresponding backup metadata, a complete data protection closed loop from intelligent triggering, flexible storage to accurate recovery is realized, and the automation degree and recovery reliability of data protection are comprehensively improved. BRIEF DESCRIPTION OF DRAWINGS
[0010] The above and other objects, features and advantages of the present application will become more apparent from the following description of the embodiments of the present application taken with reference to the accompanying drawings, in which:
[0011] Figure 1 An application scenario diagram of the data backup and recovery method and the electronic device according to the embodiments of the present application is schematically shown;
[0012] Figure 2 A flowchart of the data backup and recovery method according to the embodiments of the present application is schematically shown;
[0013] Figure 3 A flowchart of the reference backup strategy deployment according to the embodiments of the present application is schematically shown;
[0014] Figure 4 A flowchart of the file backup triggering according to the embodiments of the present application is schematically shown;
[0015] Figure 5 A flowchart illustrating a process of storing backup data to a local storage medium according to an embodiment of the present application is schematically shown;
[0016] Figure 6 A flowchart illustrating a process of restoring target backup data according to an embodiment of the present application is schematically shown;
[0017] Figure 7 A flowchart illustrating a process of restoring system-level backup data according to an embodiment of the present application is schematically shown;
[0018] Figure 8 A flowchart illustrating a process of forcibly installing a backup client according to an embodiment of the present application is schematically shown;
[0019] Figure 9 A system architecture diagram of a data backup and restoration method according to an embodiment of the present application is schematically shown;
[0020] Figure 10 A structural block diagram of a data backup and restoration method device according to an embodiment of the present application is schematically shown;
[0021] Figure 11 A block diagram of an electronic device suitable for implementing a data backup and restoration method according to an embodiment of the present application is schematically shown. DETAILED DESCRIPTION
[0022] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. It should be understood, however, that the description which follows is merely exemplary and is not intended to limit the scope of the application. In the following detailed description of the embodiments of the present application, numerous specific details are set forth in order to provide a thorough understanding of the present application. However, it will be apparent to one skilled in the art that the present application can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring aspects of the present application.
[0023] The terms used herein are merely used to describe specific embodiments and are not intended to limit the present application. The terms "include", "comprise", and the like used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0024] All terms used herein, including technical and scientific terms, have the same meanings as those generally understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having meanings consistent with the context of the present specification, and should not be interpreted in an idealized or excessively formal manner.
[0025] In the case of using expressions such as "at least one of A, B, and C", it generally should be interpreted to include any of A, B, or C individually, as well as a combination of A, B, and C, unless the context clearly suggests otherwise (e.g., "at least one of A, B, and C" can cover A only, B only, C only, as well as a combination of A, B, and C).
[0026] Embodiments of the present application provide a data backup and recovery method and an electronic device.
[0027] Figure 1 An application scenario diagram of a data backup and recovery method according to an embodiment of the present application is schematically shown.
[0028] As Figure 1 shown, the application scenario 100 according to this embodiment includes an interaction scenario of a terminal device and a backup service system, and can specifically include a terminal device 101, a network 102, and a remote backup server 103. The network 102 is a medium for communication between the terminal device 101 and the remote backup server 103. The network 102 can include various connection types, such as wired, wireless communication links, or optical fiber cables, etc.
[0029] It should be noted that Figure 1 is only schematic, and the number of entities of the terminal device 101 and the remote backup server 103 is not limited. In actual deployment, the terminal device 101 can be any number, such as hundreds or thousands of various types of employee computers, research and development workstations, mobile office devices, etc. in an enterprise; the remote backup server 103 can also be a cluster or distributed system composed of multiple servers to provide high availability and scalability. The core of this architecture is the logical service provision and use relationship, rather than the physical quantity correspondence.
[0030] In this application scenario, taking a personal computer used by an employee in an enterprise office environment as an example. The terminal device 101 is the core device for the user to perform daily work such as document editing and data processing, and various application programs run on it.
[0031] The remote backup server 103, as the hub of enterprise data protection, is responsible for receiving, storing, and managing the baseline backup policy issued from the security management server. The policy is generated by the security management server according to the attributes of the terminal device 101, such as device type, storage capacity, and the user's functional role and data access permission in the enterprise. When the terminal device 101 detects a backup event triggered by the user or triggered by a specific application file operation, it will perform backup on the target data being processed according to the corresponding backup policy, and generate backup data with a time identifier and its index backup metadata.
[0032] The generated backup data is stored locally on the terminal or uploaded to the remote backup server 103, while the key backup metadata is uploaded to the server for centralized management. When the user needs to restore data due to accidental deletion, file corruption or system failure, the backup metadata can be obtained from the remote backup server 103 to generate a list of recoverable versions. After the user selects the target version, the program locates and obtains the backup data according to the corresponding backup metadata, and finally completes the data restoration.
[0033] Through the above-mentioned mechanism of intelligent sensing trigger on the terminal side, cloud strategy collaborative management and centralized maintenance of backup metadata, the automatic, policy-based protection and convenient recovery of terminal business data are realized. Without the need for administrator intervention throughout the process, the security and business continuity of enterprise core data assets are effectively guaranteed.
[0034] The following will be based on Figure 1 The scenario described, through Figures 2-9 The data backup and recovery method of the disclosed embodiment is described in detail.
[0035] Figure 2 The flowchart of the data backup and recovery method according to the embodiment of the application is schematically shown.
[0036] As Figure 2 shown, the data backup and recovery method of this embodiment includes operations S210-S240.
[0037] In operation S210, in response to detecting a backup trigger event, the target data is backed up multiple times based on a pre-backup strategy corresponding to the backup trigger event, to obtain multiple backup data and backup metadata for indexing the multiple backup data respectively.
[0038] In the embodiment of the application, in response to detecting a backup trigger event, the backup program set on the terminal can be used to backup the target data multiple times based on a pre-backup strategy corresponding to the backup trigger event. When the backup trigger event is detected, the backup program deployed on the terminal is started. The backup program determines the target data range to be protected and the backup rules according to the pre-backup strategy bound to the backup trigger event. The target data is backed up according to the pre-backup strategy to generate corresponding backup data and create backup metadata for describing and locating the backup data.
[0039] It should be noted that the terminal can be a user device running a backup program, such as a personal computer, a mobile device; the backup program arranged in the terminal can be a software module installed and running on the terminal device, responsible for performing data backup related collection, processing and transmission operations. The pre-device backup strategy can be a pre-defined backup execution rule, which specifies how to perform the backup operation when a specific trigger event occurs. The target data can be a data object selected for backup protection. The backup data can be a copy data generated after the target data is backed up. The backup metadata can be index information describing the attributes of the backup data, used to implement management and retrieval of the backup data.
[0040] In operation S220, the plurality of backup data is stored in at least one of the local storage medium and the remote backup server, and the plurality of backup metadata is stored in the remote backup server.
[0041] In the embodiments of the present application, the local storage medium can be a storage device inside the terminal device, such as a hard disk, a solid state disk; the remote backup server can be an independent backup service device or cluster connected through a network, used for centralized storage of backup data and backup metadata.
[0042] In operation S230, in response to detecting a backup recovery event, a plurality of candidate backup version information is generated based on the plurality of backup metadata.
[0043] In the embodiments of the present application, the backup recovery event refers to a specific condition or signal that triggers the data recovery process, such as a user-initiated recovery instruction, system detection of data corruption or loss, or automatic recovery process after device completes system restore, parsing the backup metadata obtained from the remote backup server or local offline index file, extracting the key features of the backup metadata, such as backup time, data size, integrity check state and associated information with the backup strategy; constructing version entries that can be identified and selected by the user according to the key features, such as a backup time point list arranged in reverse order of time, wherein each entry contains version identification or time identification, backup trigger reason summary and data state prompt.
[0044] In operation S240, in response to a recovery instruction for target backup version information in the plurality of candidate backup version information, target backup data corresponding to the target backup version information is recovered based on target backup metadata corresponding to the target backup version information.
[0045] In the embodiments of the present application, based on a plurality of backup metadata stored in a remote backup server, version identification information contained in the backup metadata is extracted, and a candidate backup version information list containing a plurality of identifiable entries is generated after being sorted according to a preset rule and presented to a user for selection. When the user selects target backup version information and issues a recovery instruction, the storage location of the target backup data is determined through the corresponding target backup metadata, the target backup data is read from the storage location, and the target backup data is recovered to a specified path of the terminal according to the recovery configuration information in the target backup metadata.
[0046] In the embodiments of the present application, by responding to various backup trigger events and performing multiple backups of target data according to a preset backup strategy, backup data and corresponding backup metadata are generated; by flexibly storing the backup data in a local storage medium or a remote server and centrally storing all the backup metadata in a remote server; in the recovery phase, candidate version information is generated based on the backup metadata, and target backup data is accurately recovered through the corresponding backup metadata according to user selection, a complete data protection closed loop from intelligent triggering, flexible storage to accurate recovery is realized, and the automation degree and recovery reliability of data protection are comprehensively improved.
[0047] The data backup and recovery method will be described in detail below including operations S210-S240.
[0048] In the embodiments of the present application, the preset backup strategy corresponding to the backup trigger event in the above operation 210 can be determined in the following manner: in the case that the backup trigger event is receiving an instant backup instruction for the target data, the preset backup strategy is to immediately perform a backup operation on the target data after receiving the instant backup instruction; in the case that the backup trigger event is monitoring that the operation state of a preset type file by a specified application program process is switched from open to close, and the terminal has not supplemented the baseline backup strategy, the preset backup strategy is to perform a backup operation on the preset type file according to the backup storage location and the backup rule associated with the baseline backup strategy; in the case that the backup trigger event is monitoring that the operation state of a preset type file by a specified application program process is switched from open to close, and the terminal has supplemented the baseline backup strategy, the preset backup strategy is to perform a backup operation on the preset type file according to the backup storage location and the backup rule associated with the supplemented baseline backup strategy; the baseline backup strategy is a default backup rule generated and issued by a security management server based on the device attribute information of the terminal and loaded on the terminal in a read-only manner, the default backup rule includes a default backup storage root directory, a default data retention period, and a default compression and encryption algorithm, and the security management server is a background service entity responsible for formulating and forcing the terminal to execute the baseline backup strategy.
[0049] In the embodiments of the present application, the reference backup strategy can be supplemented by a backup program running on the terminal. The backup program can be a backup client, and the security management server can be a domain controller. The backup client is pushed to the terminal by the domain controller, and the reference backup strategy is set for the corresponding backup client on the terminal by the group policy set by the domain controller. The group policy is centrally issued to all terminals by the domain controller through the domain network, and the configuration management policy contained in the group policy is forcibly distributed. The domain controller is based on active directory service, and is a core server responsible for centralized management of all terminals and user identity authentication and policy implementation in the domain.
[0050] For example, the domain controller formulates corresponding reference backup strategies according to the departments or work functions of the users corresponding to the terminals. The reference backup strategies include but are not limited to different backup strategies for different file types, different backup time periods, and different data folders. The backup strategies of different groups are converted into different group policies, and are imported into the terminal by the domain controller to take effect.
[0051] It should be noted that the backup strategies formulated according to the departments and divisions within an organization are used as reference backup strategies, such as the folders and file types that must be backed up, the backup time that must be performed, and the like. The backup needs of different terminal users within the same group can be set by the users themselves through the backup client interface based on the reference backup strategies, such as the folders, file types, and backup time outside the reference backup strategies, which can be set in the configuration interface.
[0052] It should be noted that the users on the terminal are not allowed to modify the backup configurations already contained in the reference backup strategies through the backup client, such as not being allowed to delete the strategy for backup at a certain time point, which is the time point determined by the reference backup strategy to be backed up.
[0053] Figure 3 A flowchart of the deployment of the reference backup strategy according to the embodiments of the present application is schematically shown.
[0054] In the embodiments of the present application, as shown in Figure 3 After the deployment process of the reference backup strategy starts, the domain controller checks whether the backup client has been installed on the terminal. If not, the backup client is automatically installed on the terminal by the domain push method. After installation is completed, the domain controller further checks whether the client configuration has been completed. If not, the configuration of the reference backup strategy is forcibly issued and completed by the domain policy. After the configuration is completed, the backup client returns an acknowledgement signal, and the entire strategy deployment process ends. The process of the deployment of the reference backup strategy ensures the uniformity, forced implementation, and automation of the reference backup strategy in the terminals within an enterprise.
[0055] In the embodiments of the present application, the one-time backup operation of the file or folder on the terminal by the user's self-operation can be outside the protection of the scheduled backup in the reference backup strategy. The one-time immediate backup is performed by directly clicking the right button on the file or folder to be backed up to select the corresponding immediate backup option, without setting the backup strategy on the backup software in advance.
[0056] In the embodiments of the present application, the specific target program processes, such as word processing software, spreadsheet software, office software, etc., and the specific type of documents edited and modified by these target programs, such as document formats, computer-aided design drawing files, etc., are monitored by the background service of the backup program. When the target program completes the editing and modification operation on the specific type of document, the file closing operation after saving the file will be performed, and the file state will be changed from open to closed, indicating that the file has been closed after editing. At this time, the background service of the backup program actively triggers the backup operation of the file.
[0057] Figure 4 The flowchart of the file backup triggering method according to the embodiments of the present application is schematically shown.
[0058] In the embodiments of the present application, as shown in Figure 4 After the file backup triggering flow starts, the specific file type and the editing program process associated with the specific file type are continuously monitored according to the specific file type whitelist. When a specific type of file that meets the preset condition is detected in the target file list and is in an open state by the related program, the state judgment stage is entered. In the state judgment stage, if it is detected that the specific type of file is in the open state but has not been modified, the backup operation is not triggered, but the monitoring of the file state is continued. When it is detected that the target file has completed the editing operation and the user performs the action of saving and closing the file, that is, the file state is switched from open to closed, it is determined that the file has completed the editing and modification. A notification is sent to the background service of the backup client to trigger the backup flow. After receiving the notification, the background service of the backup client starts immediately and performs the backup operation on the specific type of file that has completed the editing and closed. After the backup operation is completed, the entire file backup triggering flow is ended, realizing the near real-time continuous data protection and avoiding the problems of high system resource occupation and user experience lag caused by frequent snapshot in the traditional continuous data protection scheme based on disk snapshot.
[0059] It should be noted that this can realize the data file backup without time interval, achieve the effect of continuous data protection, and does not need to perform frequent snapshot operations on the disk as the traditional continuous data protection software, which occupies a large amount of system and disk resources and makes the user feel lag and affects the customer's use experience.
[0060] In the embodiments of the present application, for the application file closing event, backup is performed according to the baseline backup strategy when the baseline backup strategy is not supplemented, and backup is performed according to the supplemented strategy when the baseline backup strategy is supplemented. The baseline backup strategy is generated and distributed by the security management server based on the terminal device attributes, and contains the default backup storage root directory, the retention period, the compression and encryption algorithm, thereby realizing differentiated backup strategy execution based on different trigger scenarios, and ensuring the flexibility and compliance of the backup operation.
[0061] In the embodiments of the present application, the operation 220 can further include: sending the plurality of backup metadata to the remote backup server for storage, and setting backup time identifiers of the plurality of backup metadata according to sending time; determining target storage locations of the plurality of backup data according to the storage location selection information of the backup data; in the case that the target storage location is the local storage medium, writing the plurality of backup data to the local storage medium; in the case that the target storage location is the remote backup server, encrypting the plurality of backup data, and sending the encrypted backup data to the remote backup server for storage.
[0062] Figure 5 A flowchart of storing backup data to a local storage medium according to the embodiments of the present application is schematically shown.
[0063] In the embodiments of the present application, as shown in Figure 5 The backup data storage flow starts after a backup trigger event, and the backup data is determined according to the content of the backup selection. It is judged whether the preset storage target of the backup data includes the local storage medium of the terminal. If the preset storage target does not include the local storage medium, the flow directly enters the branch of backup to the backup server, and the backup data is stored and managed in the backup server, and then the flow stops.
[0064] If the preset storage target includes the local storage medium, it is further judged whether the backup setting allows backup to the local storage medium. When the judgment result is yes, the flow enters the branch of writing to the local storage medium, and the backup data is written to the local storage medium, and the data is encrypted during the backup process, and the branch of backup to the backup server is also executed in parallel; when the judgment result is no, it is prompted that backup is not allowed to be stored to the local storage medium, and the local backup is terminated, but the branch of backup to the backup server is continued. The backup data storage flow stops after the corresponding branch operation is completed.
[0065] In the embodiments of the present application, the backup metadata is sent to the remote backup server for storage and the backup time point identifier is set, and the storage location of the backup data is determined according to the storage location selection information; if local storage is selected, the backup data is written into the local storage medium, and if remote storage is selected, the backup data is sent to the remote backup server after being encrypted, thereby realizing centralized management and version identification of the backup metadata, flexible and secure storage of the backup data, and ensuring the reliability and confidentiality of the backup data.
[0066] In the embodiments of the present application, before the target storage locations of the plurality of backup data are determined according to the storage location selection information, the storage location selection operation input through the storage location selection interface of the terminal can be further acquired to determine the storage location selection information; or the storage location selection information preset for the backup data in the pre-backup strategy can be acquired.
[0067] In the embodiments of the present application, the storage location selection interface of the terminal backup program can be a storage location selection interface of the backup program running on the terminal. Before performing the backup operation, the backup program can acquire the storage location selection information in one of the following two ways: one is to acquire the storage location selection information determined by the user after interactive operation through the storage location selection interface of the backup program; the other is to directly read the storage location selection information preset for the backup data from the pre-backup strategy and use it as the basis for determining the target storage location.
[0068] For example, when the backup program starts the backup process, if the user-defined mode is adopted, a graphical storage location selection interface is presented, and the storage location selection information determined by the user through interactive operations such as path checking, drop-down menu selection or manual input through the interface is recorded and acquired. If the strategy execution mode is adopted, the backup program directly accesses the pre-backup strategy configuration file cached locally, and parses the storage location selection information field preset for the backup data in the pre-backup strategy configuration file. Regardless of the way of acquisition, the storage location selection information will ultimately serve as the basis for determining whether the backup data should be stored in the local storage medium or uploaded to the remote backup server.
[0069] In the embodiments of the present application, the storage location selection information input by the user or preset in the pre-backup strategy is acquired, thereby realizing flexible configuration of the storage location, supporting user-defined according to requirements and automatic determination through the preset strategy, and improving the convenience of the backup operation and the consistency of the strategy execution.
[0070] In the embodiments of the present application, the operation 230 can further include: in the case that the backup recovery event is receiving a version viewing instruction for the target data, obtaining, from the remote backup server, backup metadata associated with the target data; parsing the backup metadata to extract backup time point identifiers corresponding to the target data; and generating candidate backup version information containing the backup time point identifiers.
[0071] In the embodiments of the present application, in the case that the backup recovery event is receiving a version viewing instruction for the target data, the backup client requests the remote backup server to obtain backup metadata associated with the target data, and after receiving the returned backup metadata, parses the backup metadata to extract backup time point identifiers contained therein, and generates candidate backup version information containing complete time sequence information based on the time point identifiers for the user to select.
[0072] For example, in the case that the backup recovery event is receiving a version viewing instruction for the target data, the backup client sends a metadata query request to the remote backup server through a secure communication protocol, and the request carries a unique identifier of the target data; after receiving the request, the remote backup server retrieves all backup metadata records containing the identifier from its metadata database and returns them to the client. The backup client parses the obtained backup metadata one by one, extracts accurate backup time point identifiers from a specific field of the backup metadata, including date and time information of the backup operation; sorts and formats the time point identifiers, generates candidate backup version information containing the backup time point identifiers, and presents the information in the form of a list on the client interface, each version information entry containing readable time identifiers and corresponding version operation portals.
[0073] In the embodiments of the present application, by obtaining backup metadata associated with the target data from the remote backup server, parsing and extracting backup time point identifiers, and generating candidate backup version information containing the backup time point identifiers, a version list that can be recovered is quickly generated based on centrally managed backup metadata, clear version selection basis is provided for the user, and the accuracy and operation efficiency of data recovery are improved.
[0074] In the embodiment of the present application, the operation 240 of restoring the target backup data corresponding to the target backup version information based on the target backup metadata corresponding to the target backup version information can further include: in response to a restoration instruction for the target version information, obtaining the target backup metadata corresponding to the target backup version information from the remote backup server if the target backup metadata corresponding to the target backup version information is stored in the remote backup server; determining the storage location of the target backup data and reading the target backup data according to the obtained target backup metadata; and restoring the read target backup data to a specified local path or the original path of the target data according to the target backup metadata.
[0075] In the embodiment of the present application, the backup client integrated into the right-click menu of the file manager is used to display the historical versions of the selected file or folder in the backup client program interface, and the user can select the required version to restore to the local or other specified path.
[0076] In the embodiment of the present application, the backup metadata generated by the backup is not included in the local storage medium, and in the off-site data restoration process away from the organization network environment, the backup environment can use the external network interface, or in the case of approval by the administrator, the backup metadata can be exported and downloaded through the web interface. The backup metadata related to the backup of the data in the local storage medium is exported to the local storage medium, and then the backup client on the terminal is used to restore the backup data on the local storage medium. The restoration process also involves using the user's domain certificate to decrypt the encrypted backup data, and the decryption process is transparent to the user.
[0077] Figure 6 The flowchart of the target backup data restoration according to the embodiment of the present application is schematically shown.
[0078] In the embodiment of the present application, as Figure 6As shown, the target backup data restoration process begins with a restoration trigger event. Based on the target backup version information selected by the user, it determines whether the backup data to be restored originates from local storage media. If it is not local storage media, the process redirects to the backup server or media management server to retrieve the data. If it is indeed local storage media, the process further verifies whether the local storage media, such as external hard drives, CD burners, or tape drives, is correctly connected and ready. If the local storage media is not ready, the user is prompted to prepare a valid local storage media, and the target backup data restoration process is suspended. If the local storage media is ready, the encrypted backup data is read from the local storage media, and the data structure and encryption parameters are parsed based on the backup metadata obtained from the backup server or exported locally. The user's domain certificate is then used to complete transparent decryption, and the data is restored to the target location according to the original path recorded in the backup metadata or the path specified by the user. During the target backup restoration process, the status of the local storage media and the integrity of the backup data are continuously monitored. If an anomaly is detected, the process is paused, and the user is prompted to intervene. The target backup data restoration process ends after all data has been restored and passed verification.
[0079] In this embodiment, by obtaining the target backup metadata corresponding to the target backup version information from the remote backup server, determining the storage location of the backup data based on the backup metadata, reading the data, and restoring the data to the specified local path or the original path, the accurate location and recovery of backup data based on centrally managed backup metadata is achieved, ensuring the reliability and path accuracy of the data recovery process.
[0080] In this embodiment, a system restore identifier is created; when the terminal's operating system is first started after being restored from a system image, the system restore identifier is detected; in response to the detection of the system restore identifier and the backup recovery event, multiple candidate backup version information of the target data is generated; after receiving a recovery confirmation instruction or a recovery cancellation instruction for the multiple candidate backup version information, the system restore identifier is cleared.
[0081] In this embodiment, before backing up the operating system image, the backup client marks the system backup process, such as writing a key value to the registry, creating a specific file, or leaving a corresponding record in a file. When the terminal experiences disk failure or other damage to the original storage medium, and after restoring using the operating system backup image, the backup client service, upon startup with the operating system, determines that the operating system is in a newly restored state through corresponding markers. When the user logs into the operating system through a domain environment or completes identity verification through other means, the backup client service automatically launches the user interface.
[0082] The user is prompted to restore the backed-up file-level data. According to the user's situation, if the operating system is not damaged due to terminal disk damage and is restored, but the operating system of the C disk is crashed and the data of other hard disks exists, only the file data of the user folder, desktop, and my documents in the C disk needs to be restored. The user selects the data to be restored and the corresponding version, such as the latest version or a version at a certain time point, and then performs data restoration. The user can also choose not to restore the data and directly exit. Any selection of the user will cause the backup client to clear the backup identifier in the restored operating system, so as to avoid the restoration interface from being popped up again when the user logs in to the operating system subsequently.
[0083] Figure 7 A flowchart of system-level backup data restoration according to an embodiment of the present application is schematically shown.
[0084] In the embodiment of the present application, as shown in Figure 7 the system-level backup data restoration flow starts when the user logs in to a terminal in which the operating system has been restored. After the operating system is started, the backup client service built in the terminal is automatically run, and whether a pre-created system restoration identifier exists is checked. The restoration identifier can exist in various forms, such as writing a specific key value in the registry of the system, creating a marker file in the file system, or leaving a corresponding record in the configuration file.
[0085] If the system restoration identifier is detected, the backup client is automatically started and provides the user with multiple selectable operation items. The selectable operation items usually include selective restoration of the backed-up file-level data, for example, the user can select to restore only the data in the affected user folder, desktop, and document directory of the system disk, or can select to restore the complete backup version. Meanwhile, the user can also select not to perform any data restoration and directly exit the interface according to actual needs. After the user performs the selection operation, the backup client service will execute the clearing of the system restoration identifier, thereby effectively avoiding the restoration interface from being triggered again when the user logs in to the system subsequently, and ensuring the one-time nature and certainty of the restoration flow.
[0086] If the user selects to perform data restoration, the backup client will perform data restoration according to the backup version selected by the user, such as the latest version or a version at a certain time point, and synchronously clear the restoration identifier after the data restoration operation is completed; if the user selects not to restore, the backup client directly clears the identifier and ends the flow.
[0087] In the embodiment of the present application, by creating the system restoration identifier, detecting the identifier when the system image is restored and started for the first time, generating the candidate backup version information when the identifier and the backup restoration event are detected, and clearing the identifier after receiving the restoration confirmation or cancellation instruction, the automatic triggering and state management of the backup restoration flow in the system restoration scenario are realized, and the timely restoration of the user data after the system is restored and the completeness of the flow are ensured.
[0088] In the embodiments of the present application, in response to detecting the system restoration identifier and the backup recovery event, generating the multiple candidate backup version information of the target data can further include: in the case that the backup recovery event is receiving a backup recovery instruction for the target data, determining a preset time range based on the time when the operating system is restored by the system image as a target time period; obtaining, from the remote backup server, multiple backup metadata created within the target time period and associated with the terminal; and parsing the multiple backup metadata to generate the multiple candidate backup version information of the target data.
[0089] In the embodiments of the present application, when the backup recovery process is triggered after the system is restored, the backup client first takes the time when the system image restoration is completed as a time reference point, and extends a preset time window forward and backward as a target time period. A query request is initiated to the remote backup server to obtain all backup metadata related to the terminal generated within the target time period. By parsing the backup metadata, the backup time, file information, version identifier and other key contents contained therein are extracted to construct and present a candidate backup version list containing multiple historical versions for user selection.
[0090] For example, when the user logs in to the terminal that has just completed operating system restoration and triggers the data recovery instruction, the backup client automatically reads the system restoration event log to obtain the time T when the operating system image restoration is completed. The target time period is dynamically determined according to the preset strategy (such as default setting of T-24 hours to T time) based on the time T. A query request is sent to the remote backup server through a secure channel, and the request parameters in the query request include the terminal device identifier and the target time range of the terminal device identifier. The remote backup server retrieves all backup metadata records generated by the terminal device backup client within the target time period in the backup metadata database, and returns the result set to the backup client.
[0091] After the backup client receives the backup metadata set, the metadata set is structured by the parsing engine. First, records matching the target data type currently to be restored by the user are filtered out, and then backup timestamps, data integrity check values, storage location indexes and associated backup policy identifiers are extracted from each record. Based on this information, a candidate backup version information list arranged in reverse chronological order is generated, which includes version time, data status prompt and recovery operation portal. The user can intuitively understand the multiple historical states of the target data before the system restoration through the candidate backup version information list, and select a specific version for recovery.
[0092] In the embodiments of the present application, the target time period is determined based on the system image restoration time, the backup metadata related to the terminal in the time period is obtained from the remote backup server, and the candidate backup version information is generated by parsing, so as to realize intelligent filtering and presenting of the backup version in the related time period in the system recovery scenario, and improve the pertinence and timeliness of data recovery.
[0093] In the embodiments of the present application, the data backup state of the terminal is monitored according to the network security policy component of the terminal; and in the case that the data backup state does not meet the preset backup requirement, the network access right or the function use right of the terminal is limited by the network security policy component until the data backup state recovers to meet the preset backup requirement.
[0094] In the embodiments of the present application, the monitoring of the data backup state is implemented by the following technical means: the network security policy component accesses the system interface of the terminal to obtain the configuration and runtime information related to the data backup function, such as checking whether there is an activated backup task plan meeting the preset policy, verifying whether the local or remote storage path for the backup operation is accessible, or confirming whether the time stamp of the last successful backup operation is within the allowed time window. If any of the above checking items does not meet the threshold value or condition set by the preset backup requirement, it is determined that the data backup state does not meet the requirement. The network security policy component triggers the access control module to implement policy-based blocking of the network connection of the terminal or to limit the specific system function. The network security policy component continuously monitors the above checking items, and when all the checking items meet the preset rule, the related limitation is automatically cancelled.
[0095] In the embodiments of the present application, the installation state of the backup program can also be monitored according to the network security policy component of the terminal; in the case that the backup program is not installed, the network access right or the function use right of the terminal is limited by the network security policy component until the backup program is installed and runs.
[0096] In the embodiments of the present application, the network security policy component includes the Internet behavior management software and the security assistant. In order to avoid that the terminal does not install the backup client and cannot protect the user data, the backup client program is added to the monitoring list of the organization internal security assistant or the user Internet behavior management software, and the terminal must install the backup client before accessing the organization internal network or operating, and in the case that the backup client is not installed, the user is guided to install the backup client by the security assistant or the user Internet behavior management software, so as to achieve the purpose of fully covering the data backup range.
[0097] Figure 8 A flowchart of forcibly installing a backup client according to the embodiments of the present application is schematically shown.
[0098] In the embodiments of the present application, as shown in Figure 8 The flow of forcibly installing the backup client starts from the compliance check of the online behavior management software when the terminal accesses the intranet of the organization. The compliance check first determines whether the terminal device has installed the specified backup client program. If the check result is that the terminal has installed the backup client, the online behavior management software allows the terminal to access the intranet of the organization, and the flow ends normally.
[0099] If the check finds that the terminal has not installed the backup client, the online behavior management software will immediately send a clear installation reminder to the user, prompting the user to complete the installation of the backup client to meet the requirements of the organization's security policy. It is monitored whether the user completes the installation operation of the backup client within the specified response time.
[0100] If the user completes the installation of the backup client after receiving the reminder, the online behavior management software will allow the terminal to access the intranet of the organization after verifying the validity of the installation. Otherwise, if the user fails to complete the installation within the required time, the online behavior management software will execute the access control policy and deny the terminal to access the intranet of the organization. Whether the access is finally allowed or not, the forced installation check flow ends after the corresponding operation is performed.
[0101] In the embodiments of the present application, the data backup state of the terminal is monitored through the network security policy component, and when it is detected that the data backup state does not meet the pre-device backup requirements, the network access or function use permission of the terminal is limited, the forced deployment and execution guarantee of the backup policy is realized, the terminal device is ensured to meet the data protection requirements, and the overall compliance of enterprise data security is improved.
[0102] In the embodiments of the present application, when the target data is backed up based on the pre-device backup policy, the system resource state of the terminal is evaluated; according to the evaluation result and the predetermined resource scheduling policy, a plurality of backup tasks in parallel or in series are queued or priority adjusted to control the peak of system resource occupation of the backup tasks. The predetermined resource scheduling policy includes giving the backup task triggered by the instant backup instruction higher priority than the backup task triggered by the timing strategy; and / or delaying the execution of non-urgent backup tasks when the system resource occupation exceeds a threshold.
[0103] In the embodiments of the present application, when the backup client executes the backup task, it monitors the central processor utilization, memory occupation, disk input and output and other key system resource indicators of the terminal in real time; according to the monitoring data and the preset resource scheduling policy, the backup tasks initiated simultaneously or queued continuously are dynamically sorted and priority adjusted, the instant backup task triggered by the user is executed before the timing backup task, and the non-critical backup task is automatically suspended when the system resource load exceeds the safety threshold.
[0104] For example, the backup client built-in resource monitoring module continuously collects real-time resource data of the terminal, including CPU usage, available memory capacity, disk queue length and network bandwidth occupancy. When multiple backup tasks are triggered concurrently, intelligent scheduling is performed according to the predetermined resource scheduling strategy. First, the task type is identified, and the highest priority is assigned to the backup task triggered by the instant backup instruction to ensure that it immediately enters the execution queue. For regular tasks triggered by a timing strategy, dynamic queuing is performed according to the set time tolerance. At the same time, the system resource occupancy is compared with the preset threshold in real time. Once resource overload is detected, the execution of all non-urgent backup tasks is suspended, and their state is set to delayed execution, until the system resources recover to a safe level, and then the tasks can be rescheduled, thereby achieving the balance between backup efficiency and system performance by dynamically scheduling backup tasks, prioritizing instant backup and delaying non-critical tasks during system high load.
[0105] Figure 9 A system architecture diagram of a data backup and recovery method according to an embodiment of the present application is schematically shown.
[0106] In the embodiment of the present application, as shown in Figure 9 Fig. 1-8 respectively identify the wide area network, remote backup server, remote storage medium, local storage medium, client 1, local storage medium, client 2, client 3 connected to the system architecture. The data backup and recovery system architecture is composed of a wide area network, an intranet (composed of client 1, local storage medium, client 2, client 3) and various entities deployed in different network levels. The remote backup server and the remote storage medium associated therewith are deployed on the wide area network. The server serves as a centralized backup management node, responsible for receiving and storing backup metadata from various terminals, and providing cross-network backup data storage and recovery services when needed. The intranet constitutes the local network environment of the enterprise, in which multiple terminal clients and local storage media are connected.
[0107] Specifically, the intranet includes at least three client terminals (client 1, client 2 and client 3), each of which is installed with a backup program and can perform local data backup and recovery operations. These clients can choose to write backup data to the local storage medium directly connected to themselves, or upload backup data to the remote backup server for centralized storage through the intranet and the wide area network. At the same time, the backup metadata generated by each client during the backup process needs to be sent to the remote backup server for unified management and maintenance.
[0108] In the recovery scenario, the client can access the remote backup server through the intranet to obtain the backup metadata of the required version, and then read the corresponding backup data from the local storage medium or the remote storage medium according to the metadata guidance, to complete the data recovery. The system architecture supports both distributed local rapid backup and recovery and centralized cloud data management and cross-network disaster recovery capability, realizes the flexibility of backup storage location, the uniformity of metadata management, and the controllability of the recovery process. The overall architecture realizes the data security, management convenience and system scalability through hierarchical network design and resource distribution, while ensuring the backup efficiency.
[0109] Based on the above data backup and recovery method, the application further provides a data backup and recovery method device. The following will be combined with Figure 10 The device is described in detail.
[0110] Figure 10 The structure block diagram of the data backup and recovery method device according to the embodiment of the application is schematically shown.
[0111] As Figure 10 shown, the data backup and recovery method device 1000 of the embodiment includes a data backup module 1010, a data storage module 1020, a version generation module 1030 and a data recovery module 1040.
[0112] The data backup module 1010 is configured to, in response to detecting a backup trigger event, perform multiple backups on target data based on a pre-backup strategy corresponding to the backup trigger event, to obtain multiple backup data and backup metadata for respectively indexing the multiple backup data. In an embodiment, the data backup module 1010 can be configured to perform the operation S210 described above, and details are not repeated here.
[0113] The data storage module 1020 is configured to store the multiple backup data in at least one of a local storage medium and a remote backup server, and store the multiple backup metadata in the remote backup server. In an embodiment, the data storage module 1020 can be configured to perform the operation S220 described above, and details are not repeated here.
[0114] The version generation module 1030 is configured to, in response to detecting a backup recovery event, generate multiple candidate backup version information based on the multiple backup metadata. In an embodiment, the version generation module 1030 can be configured to perform the operation S230 described above, and details are not repeated here.
[0115] The data recovery module 1040 is configured to, in response to a recovery instruction for target backup version information from the plurality of candidate backup version information, recover target backup data corresponding to the target backup version information based on target backup metadata corresponding to the target backup version information. In an embodiment, the data recovery module 1040 can be configured to perform operation S240 described above, and details are not repeated here.
[0116] According to an embodiment of the present application, any of the data backup module 1010, the data storage module 1020, the version generation module 1030 and the data recovery module 1040 can be combined in one module, or any of them can be split into multiple modules. Alternatively, at least part of the function of one or more of these modules can be combined with at least part of the function of other modules, and implemented in one module. According to an embodiment of the present application, at least one of the data backup module 1010, the data storage module 1020, the version generation module 1030 and the data recovery module 1040 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on board, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging a circuit, etc. hardware or firmware, or any one of software, hardware and firmware or a suitable combination of any of them. Alternatively, at least one of the data backup module 1010, the data storage module 1020, the version generation module 1030 and the data recovery module 1040 can be at least partially implemented as a computer program module which can perform corresponding functions when executed.
[0117] Figure 11 A block diagram of an electronic device suitable for implementing the data backup and recovery method according to an embodiment of the present application is schematically shown.
[0118] As shown in Figure 11 The electronic device 1100 according to an embodiment of the present application includes a processor 1101 which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1102 or loaded from a storage portion 1108 into a random access memory (RAM) 1103. The processor 1101 can include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor and / or a related chipset, and / or a special-purpose microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 1101 can also include an on-board memory for cache use. The processor 1101 can include a single processing unit or multiple processing units for performing different actions of the method processes according to an embodiment of the present application.
[0119] In the RAM 1103, various programs and data required for the operation of the electronic device 1100 are stored. The processor 1101, the ROM 1102, and the RAM 1103 are connected to each other via the bus 1104. The processor 1101 performs various operations of the method processes according to the embodiments of the present application by executing the programs in the ROM 1102 and / or the RAM 1103. It should be noted that the programs can also be stored in one or more memories other than the ROM 1102 and the RAM 1103. The processor 1101 can also perform various operations of the method processes according to the embodiments of the present application by executing the programs stored in the one or more memories.
[0120] According to the embodiments of the present application, the electronic device 1100 can further include an input / output (I / O) interface 1105, which is also connected to the bus 1104. The electronic device 1100 can further include one or more of the following components connected to the input / output (I / O) interface 1105: an input part 1106 including a keyboard, a mouse, etc.; an output part 1107 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage part 1108 including a hard disk, etc.; and a communication part 1109 including a network interface card such as a LAN card, a modem, etc. The communication part 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to the input / output (I / O) interface 1105 as necessary. A removable medium 1111 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the drive 1110 as necessary, so that a computer program read out therefrom is installed in the storage part 1108 as necessary.
[0121] The present application also provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments, or can exist separately without being assembled into the device / apparatus / system. The above computer readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present application.
[0122] According to an embodiment of the present application, the computer readable storage medium can be a non-transitory computer readable storage medium, for example, can include but not limited to: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In this application, a computer readable storage medium can be any tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present application, the computer readable storage medium can include one or more of the above-described ROM 1102 and / or RAM 1103 and / or a memory other than the ROM 1102 and the RAM 1103.
[0123] Embodiments of the present application also include a computer program product, which includes a computer program containing program codes for executing the methods shown in the flowcharts. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the methods provided by the embodiments of the present application.
[0124] The above-described functions defined in the system / device / apparatus of the embodiments of the present application are performed when the computer program is executed by the processor 1101. According to an embodiment of the present application, the above-described system, device, module, unit, etc. can be implemented by computer program modules.
[0125] In one embodiment, the computer program can rely on tangible storage media such as optical storage media, magnetic storage media, etc. In another embodiment, the computer program can also be transmitted, distributed, and downloaded in the form of a signal on a network medium. The computer program containing program codes can be transmitted by any appropriate network medium, including but not limited to wireless, wired, etc., or any suitable combination of the foregoing.
[0126] In such an embodiment, the computer program can be downloaded and installed from the network by the communication part 1109, and / or installed from the detachable medium 1111. When the computer program is executed by the processor 1101, the above-described functions defined in the system of the embodiments of the present application are performed. According to an embodiment of the present application, the above-described system, device, apparatus, module, unit, etc. can be implemented by computer program modules.
[0127] According to embodiments of the present application, program code for implementing the computer programs provided by embodiments of the present application can be written in any combination of one or more programming languages, and can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The programming language includes, but is not limited to, such languages as Java, C++, python, "C" language, or the like. The program code can execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the remote computing device, or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider.
[0128] The computer program instructions can also be loaded onto a computer or other programmable information processing apparatus to cause a series of operations to be performed on the computer or other programmable information processing apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable information processing apparatus implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0129] Those skilled in the art will understand that features recited in the various embodiments of the present application can be combined and / or integrated in a variety of ways, even if such combinations or integrations are not expressly noted in the present application. In particular, features recited in the various embodiments of the present application can be combined and / or integrated in ways that do not depart from the spirit and scope of the present application. All such combinations and / or integrations are within the scope of the present application.
[0130] The embodiments of the present application are described above. However, these embodiments are merely for illustration purposes, and are not intended to limit the scope of the present application. Although the embodiments are described separately above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Those skilled in the art can make various substitutions and modifications without departing from the scope of the present application, and these substitutions and modifications shall fall within the scope of the present application.
Claims
1. A data backup and recovery method, characterized in that, Applied to a terminal, the method includes: In response to the detection of a backup trigger event, the target data is backed up multiple times based on a preset backup strategy corresponding to the backup trigger event, resulting in multiple backup data and backup metadata for indexing the multiple backup data respectively. The plurality of backup data are stored in at least one of a local storage medium and a remote backup server, and the plurality of backup metadata are stored in the remote backup server; In response to the detection of a backup recovery event, multiple candidate backup version information are generated based on multiple backup metadata. In response to a recovery command for a target backup version information among the plurality of candidate backup version information, target backup data corresponding to the target backup version information is recovered based on the target backup metadata corresponding to the target backup version information; Create a system restore identifier; When the operating system of the terminal is booted for the first time after being restored from a system image, the system restore identifier is detected; When the backup and restore event is the receipt of a backup and restore instruction for the target data, a preset time range based on the time when the operating system is restored through the system image is determined as the target time period; Obtain multiple backup metadata created within the target time period and associated with the terminal from the remote backup server; Parse multiple backup metadata entries to generate multiple candidate backup version information for the target data; Upon receiving a recovery confirmation instruction or a recovery cancellation instruction for the multiple candidate backup version information, the system restore identifier is cleared.
2. The method according to claim 1, characterized in that, The preset backup strategy corresponding to the backup trigger event is determined in the following manner: When the backup trigger event is receiving an immediate backup instruction for the target data, the preset backup strategy is to immediately perform a backup operation on the target data after receiving the immediate backup instruction. When the backup trigger event is that the operation status of a specified application process on a preset type of file changes from open to closed, and the terminal does not supplement the baseline backup strategy, the preset backup strategy is to perform backup operations on the preset type of file according to the backup storage location and backup rules associated with the baseline backup strategy. When the backup trigger event is that the operation status of a specified application process on a preset type of file is switched from open to closed, and the terminal has supplemented the baseline backup strategy, the preset backup strategy is to perform backup operations on the preset type of file according to the backup storage location and backup rules associated with the supplemented baseline backup strategy. The baseline backup policy is a default backup rule generated and issued by the security management server based on the device attribute information of the terminal and loaded on the terminal in read-only mode. The default backup rule includes the default backup storage root directory, the default data retention period, and the default compression and encryption algorithm. The security management server is a background service entity responsible for formulating and forcing the terminal to execute the baseline backup policy.
3. The method according to claim 1, characterized in that, The step of storing the plurality of backup data in at least one of a local storage medium and a remote backup server, and storing the plurality of backup metadata in the remote backup server, includes: Multiple backup metadata are sent to the remote backup server for storage, and backup time identifiers for multiple backup metadata are set according to the sending time; Based on the storage location selection information of the backup data, the target storage location of the multiple backup data is determined; If the target storage location is the local storage medium, the plurality of backup data are written to the local storage medium; If the target storage location is the remote backup server, the multiple backup data are encrypted, and the encrypted backup data is sent to the remote backup server for storage.
4. The method according to claim 3, characterized in that, Before determining the target storage location of the plurality of backup data based on the storage location selection information of the backup data, the method further includes: Obtain the storage location selection information determined by inputting a storage location selection operation through the storage location selection interface of the terminal; or, Obtain the storage location selection information preset for the backup data in the preset backup strategy.
5. The method according to claim 1, characterized in that, In response to detecting a backup recovery event, generating multiple candidate backup version information based on multiple backup metadata includes: In the event that the backup recovery event is receiving a version viewing instruction for the target data, multiple backup metadata associated with the target data are obtained from the remote backup server; Parse multiple backup metadata entries and extract multiple backup time identifiers corresponding to the target data; Generate multiple candidate backup version information containing the backup time identifier.
6. The method according to claim 1, characterized in that, Based on the target backup metadata corresponding to the target backup version information, restoring the target backup data corresponding to the target backup version information includes: In response to a recovery command for the target backup version information, if the target backup metadata corresponding to the target backup version information is stored on the remote backup server, the target backup metadata corresponding to the target backup version information is obtained from the remote backup server. Based on the acquired target backup metadata, determine the storage location of the target backup data and read the target backup data; Based on the target backup metadata, the read target backup data is restored to the specified local path or the original path of the target data.
7. The method according to claim 1, characterized in that, The method further includes: The data backup status of the terminal is monitored according to the network security policy component of the terminal; If it is determined that the data backup status does not meet the preset backup requirements, the network access permissions or function usage permissions of the terminal are restricted by the network security policy component until the data backup status is restored to meet the preset backup requirements.
8. An electronic device, characterized in that, include: One or more processors; Memory, used to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the data backup and recovery method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Financial product data backup method and device and electronic equipment
CN117632586A
Efficient backup, search and restore
US20160292043A1