Data offline protection method and system, electronic device and storage medium

By employing server backup data and network isolation strategies in the offline backup system, the management challenges caused by brand differences in existing technologies have been resolved, achieving unified management and cost reduction.

CN121560640APending Publication Date: 2026-02-24THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411783515.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2026-02-24

AI Technical Summary

Technical Problem

Existing offline backup systems cannot achieve unified management due to differences in brand, architecture, and equipment type, resulting in high costs and difficulties in unified equipment management, inter-system service calls, and function integration.

Method used

The system employs server backup and network isolation strategies. By using the first, second, and third network isolation strategies to perform data transmission and isolation within set time periods, it ensures offline data protection and allows data recovery when needed.

Benefits of technology

It eliminates brand differences between different manufacturers, enables unified management of backup servers, reduces equipment costs, and improves the security and reliability of data backup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121560640A_ABST
    Figure CN121560640A_ABST
Patent Text Reader

Abstract

The invention discloses a data offline protection method and system. The method comprises the steps that a first server backs up target data from a data source end according to a preset first network isolation strategy, and the target data serve as first backup data; at least one second server backs up the first backup data from the first server according to a preset second network isolation strategy to serve as second backup data, and the second server is in a physical isolation state after backup; wherein the first network is configured in a way that the first server only opens the data transmission with the data source end in a first set time period, and closes the data transmission with the data source end after the first backup data is backed up; the second network isolation strategy is configured to enable the second server to only open the data transmission with the first server in a second set time period, and close the data transmission with the first server after the second backup data is backed up. Unified management, calling of services among systems and function integration can be achieved, and the equipment cost is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of this disclosure relate to methods and systems for protecting data offline, electronic devices, and storage media. Background Technology

[0002] To ensure business continuity and data integrity, and to prevent accidental deletion or malicious alteration, current financial infrastructure requires both online data integrity and offline backup and protection. Offline data protection systems, as the foundational infrastructure, provide the technical support for emergency data recovery.

[0003] Dedicated offline backup systems typically use backup software and offline media for data protection. To meet security and diverse business needs, offline backup systems inherently exhibit heterogeneous architectures and brand diversity. The configurations of different types of equipment from various brands also differ significantly, resulting in high costs and making unified management impossible. Summary of the Invention

[0004] At least one embodiment of this disclosure provides a data offline protection method, the method comprising: a first server backing up target data from a data source according to a preset first network isolation strategy, as first backup data; at least one second server backing up the first backup data from the first server according to a preset second network isolation strategy, as second backup data, and the second server being physically isolated after backup; wherein the first network isolation strategy is configured to: enable the first server to only enable data transmission with the data source during a first set time period, and disable data transmission with the data source after the first backup data is backed up; the second network isolation strategy is configured to: enable the second server to only enable data transmission with the first server during a second set time period, and disable data transmission with the first server after the second backup data is backed up.

[0005] For example, according to at least one embodiment of the data offline protection method of this disclosure, the method further includes: releasing the physical isolation state of the second server; at least one third server backing up second backup data from the second server according to a preset third network isolation strategy, as third backup data, and after the backup, the third server is in a physical isolation state; wherein, the third network isolation strategy is configured to enable the third server to only enable data transmission with the second server during a third set time period, and to close the data transmission with the second server after the third backup data is backed up.

[0006] For example, according to at least one embodiment of the data offline protection method of this disclosure, the method further includes: a first server responding to a recovery request for target data, enabling data transmission with the data source end, and transmitting first backup data for the target data to the data source end to restore the target data, wherein the recovery request includes a data generation timestamp and number of the target data, and the first server searching for the corresponding first backup data based on the data generation timestamp and number and sending it to the data source end.

[0007] For example, according to at least one embodiment of the data offline protection method of this disclosure, the method further includes: releasing the physical isolation state of the second server; in response to a recovery request for the target data, the second server initiates data transmission with the first server, and transmits second backup data for the target data to the data source via the first server to restore the target data; or, initiates data transmission with the data source, and transmits second backup data for the target data to the data source to restore the target data; wherein the recovery request includes a data generation timestamp and number of the target data, and the second server searches for the corresponding second backup data based on the data generation timestamp and number.

[0008] For example, according to at least one embodiment of the data offline protection method of this disclosure, the method further includes: releasing the physical isolation state of the third server; in response to a recovery request for the target data, the third server initiates data transmission with the second server, and transmits third backup data for the target data to the data source end via the second server and the first server to restore the target data; or, initiates data transmission with the data source end, and transmits third backup data for the target data to the data source end to restore the target data; wherein the recovery request includes the data generation timestamp and number of the target data, and the third server searches for the corresponding third backup data based on the data generation timestamp and number.

[0009] For example, according to at least one embodiment of the data offline protection method of this disclosure, the first server backs up target data from the data source end according to a preset first network isolation strategy, including: pre-isolating other ports except the data transmission port that transmits data with the data source end through a first layer firewall; during a first set time period, opening the second layer firewall with the data source end, transmitting the target data from the data source end to the local machine through the data transmission port according to the setting rules of the second layer firewall, packaging the target data to generate first backup data, and storing a first backup log that records the backup process; and closing the second layer firewall with the data source end after the first backup data is backed up.

[0010] For example, according to at least one embodiment of the data offline protection method of this disclosure, the second server backs up the first backup data from the first server according to a preset second network isolation strategy, and after the backup, the second server is in a physically isolated state, including: isolating other ports except the data transmission port that transmits data with the first server through a first-layer firewall in advance; during a second set time period, opening the second-layer firewall with the first server, obtaining the first backup log from the first server according to the setting rules of the second-layer firewall, and determining whether the target data has been packaged to generate the first backup data based on the first backup log; if the determination result is yes, transmitting the first backup data to the local machine through the data transmission port as the second backup data, and storing the second backup log recording the backup process; after the second backup data is backed up, closing the second-layer firewall with the first server and performing a shutdown operation.

[0011] For example, according to at least one embodiment of the data offline protection method of this disclosure, the method further includes: detecting a first backup log or a second backup log, determining whether an abnormality occurs during the data backup process, and if an abnormality occurs, re-backing up the data.

[0012] At least one embodiment of this disclosure provides a data offline protection system, comprising: a first server configured to back up target data from a data source according to a preset first network isolation strategy, as first backup data; and at least one second server configured to back up the first backup data from the first server according to a preset second network isolation strategy, as second backup data, and to place the second server in a physically isolated state after backup; wherein the first network isolation strategy is configured to enable data transmission between the first server and the data source only during a first set time period, and to disable data transmission between the first server and the data source after the first backup data is backed up; and the second network isolation strategy is configured to enable data transmission between the second server and the first server only during a second set time period, and to disable data transmission between the second server and the first server after the second backup data is backed up.

[0013] For example, according to at least one embodiment of the data offline protection system of this disclosure, the system further includes: at least one third server configured to back up second backup data from a second server that has been physically isolated, according to a preset third network isolation policy, as third backup data, and to put the third server in a physically isolated state after the backup; wherein the third network isolation policy is configured to enable the third server to only enable data transmission with the second server during a third set time period, and to close data transmission with the second server after the third backup data is backed up.

[0014] For example, in a data offline protection system according to at least one embodiment of the present disclosure, a first server is further configured to, in response to a recovery request for target data, enable data transmission with the data source end and transmit first backup data for the target data to the data source end to restore the target data, wherein the recovery request includes a data generation timestamp and number of the target data, and the first server searches for the corresponding first backup data based on the data generation timestamp and number.

[0015] For example, in a data offline protection system according to at least one embodiment of this disclosure, the second server is further configured to release the physical isolation state of the second server; in response to a recovery request for target data, to initiate data transmission with the first server, and to transmit second backup data for the target data to the data source via the first server to restore the target data; or, to initiate data transmission with the data source, and to transmit second backup data for the target data to the data source to restore the target data; wherein the recovery request includes a data generation timestamp and number of the target data, and the second server searches for the corresponding second backup data based on the data generation timestamp and number.

[0016] For example, in a data offline protection system according to at least one embodiment of the present disclosure, the third server is further configured to release the physical isolation state of the third server; in response to a recovery request for target data, data transmission between the second server and the first server is initiated, and third backup data for the target data is transmitted to the data source end via the second server and the first server to restore the target data; or, data transmission between the data source end and the data source end is initiated, and third backup data for the target data is transmitted to the data source end to restore the target data; wherein the recovery request includes the data generation timestamp and number of the target data, and the third server searches for the corresponding third backup data based on the data generation timestamp and number.

[0017] For example, in the data offline protection system according to at least one embodiment of the present disclosure, the first server is further configured to pre-isolate other ports except the data transmission port for data transmission with the data source end through a first-layer firewall; during a first set time period, the second-layer firewall with the data source end is turned on, and the target data of the data source end is transmitted to the local machine through the data transmission port according to the setting rules of the second-layer firewall, and the target data is packaged to generate first backup data, and a first backup log recording the backup process is stored; after the first backup data is backed up, the second-layer firewall with the data source end is turned off.

[0018] For example, in the data offline protection system according to at least one embodiment of this disclosure, the second server is further configured to pre-isolate other ports besides the data transmission port that transmits data with the first server through a first-layer firewall; during a second set time period, the second-layer firewall with the first server is turned on, the first backup log is obtained from the first server according to the configuration rules of the second-layer firewall, and it is determined based on the first backup log whether the target data has been packaged to generate the first backup data; if the determination result is yes, the first backup data is transmitted to the local machine through the data transmission port as the second backup data, and the second backup log recording the backup process is stored; after the second backup data is backed up, the second-layer firewall with the first server is turned off, and a shutdown operation is performed.

[0019] For example, in the data offline protection system according to at least one embodiment of the present disclosure, the first server is further configured to detect the first backup log, determine whether an abnormality occurs during the data backup process, and if an abnormality occurs, then back up the data again; or, the second server is further configured to detect the second backup log, determine whether an abnormality occurs during the data backup process, and if an abnormality occurs, then back up the data again.

[0020] At least one embodiment of this disclosure provides an electronic device, including: one or more processors; and a memory storing one or more computer program modules; wherein the one or more computer program modules are configured to be executed by the one or more processors to implement a method provided according to at least one embodiment of this disclosure.

[0021] At least one embodiment of this disclosure provides a computer-readable storage medium for storing non-transitory computer-readable instructions, wherein the non-transitory computer-readable instructions, when executed by one or more processors, implement a method provided according to at least one embodiment of this disclosure.

[0022] Compared to existing offline backup systems, the data offline protection scheme of this disclosure can be managed uniformly and at a lower cost. Attached Figure Description

[0023] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments of this disclosure will be briefly described below. Clearly, the drawings described below only relate to some embodiments of this disclosure and are not intended to limit the scope of this disclosure.

[0024] Figure 1 A block diagram of a data offline protection system according to at least one embodiment of the present disclosure is shown;

[0025] Figure 2 A schematic flowchart of a data offline protection method according to at least one embodiment of the present disclosure is shown;

[0026] Figure 3 A flowchart illustrating an exemplary offline data backup process according to at least one embodiment of the present disclosure is shown;

[0027] Figure 4 A schematic flowchart of an exemplary data recovery process according to at least one embodiment of the present disclosure is shown;

[0028] Figure 5 A schematic diagram of an electronic device according to at least one embodiment of the present disclosure is shown;

[0029] Figure 6 A schematic diagram of a computer-readable storage medium according to at least one embodiment of the present disclosure is shown. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.

[0031] Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms “first,” “second,” and similar terms used in this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, terms such as “comprising” or “including” mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as “connected” or “linked” are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as “upper,” “lower,” “left,” and “right” are used only to indicate relative positional relationships, which may change accordingly when the absolute position of the described objects changes.

[0032] Note that the examples described below are merely specific examples and are not intended to limit the embodiments of this disclosure to the specific shapes, hardware, connections, operations, values, conditions, data, sequences, etc., shown and described. Those skilled in the art can utilize the concepts of this disclosure to construct further embodiments not mentioned herein by reading this specification.

[0033] The terminology used in this disclosure is that which is currently widely used in the art in consideration of the functionality of this disclosure; however, these terms may vary depending on the intent, precedent, or new technology of those skilled in the art. Furthermore, specific terms may be chosen by the applicant, and in such cases, their detailed meanings will be described in the detailed description of this disclosure. Therefore, the terminology used in this specification should not be construed as simple names, but rather based on the meaning of the terms and the overall description of this disclosure.

[0034] This disclosure uses flowcharts to illustrate the operations performed by a system according to embodiments of this disclosure. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, various steps can be processed in reverse order or simultaneously, as needed. Furthermore, other operations can be added to these processes, or one or more steps can be removed from them.

[0035] As mentioned in the background above, existing offline backup systems cannot provide users with a unified usage style and interface due to differences in brands, architectures, and equipment types. They cannot achieve unified management of devices, call services between systems, or integrate functions. Furthermore, the system costs are high, with both initial purchase and subsequent expansion costs being substantial.

[0036] At least one embodiment of this disclosure provides a data offline protection method, apparatus, electronic device, and storage medium. By employing server backup data and network isolation strategies, data offline protection is achieved, shielding the brand differences between different manufacturers. This enables unified management, inter-system service calls, and function integration. Moreover, the server cost is much lower than that of a dedicated offline backup system, thus greatly reducing equipment costs.

[0037] Figure 1 A block diagram of a data offline protection system 1000 according to at least one embodiment of the present disclosure is shown. Figure 1 As shown, system 1000 mainly includes a data source server 100 (e.g., a data source of the type such as database 101, object storage 102, and log file 103, collectively referred to as "data source 100" below), a first server 110, and at least one second server 120. The data source 100 and servers 110 and 120 can be implemented as one or more computing devices, which at least include a processor, memory, and other components typically found in general-purpose computers to perform functions such as computing, storage, communication, and control. It should be understood that although... Figure 1 Only three different types of data sources are shown, but the number of data sources can be more or less. Furthermore, although... Figure 1The diagram only shows one data source server 100, one first server 110, and one second server 120, but the number of these servers can be increased according to the actual application scenario and requirements.

[0038] In this embodiment of the disclosure, target data stored on the data source 100 can be backed up to a server. For example, target data in database 101 can be backed up to a first server 110, thereby storing first backup data 111 as a first copy of the target data in the first server 110. Subsequently, the first backup data 111 of the first server 110 can also be backed up to a second server 120, thereby storing second backup data 121 as a second copy of the target data in the second server 120.

[0039] In some embodiments of this disclosure, the first server 110 and the second server 120 can be local storage servers. By storing data locally, financial infrastructure organizations can have complete control, avoiding privacy and security risks associated with online data storage. Furthermore, backing up the target data to at least two servers, such as the first server 110 and the second server 120, not only preserves multiple copies of the target data but also enhances the backup security of the source data due to offline data protection, while reducing storage costs.

[0040] like Figure 1 As shown, system 1000 may further include a third server 130, which can be network-connected to the second server 120 to back up the second backup data in the second server 120 as the third backup data. This ensures effective protection of the target data even in extreme circumstances. Of course, there can be multiple third servers; this embodiment does not limit the number.

[0041] like Figure 1 As shown, each server is configured with its own network isolation policy. For example, the first server 110 is configured with a first network isolation policy 113, and the second server 120 is configured with a second network isolation policy 123. The network isolation policy is mainly used to isolate each server from access to other networks. It also includes a scheduled backup task. After each server completes its scheduled backup task, the data is "cold-stored" offline according to the network isolation policy, thus completely isolating each server from the network. Similarly, in some embodiments, the system 1000 also includes at least one third server 130, which is also configured with a third network isolation policy. After the third server completes its scheduled backup task, it also achieves network isolation. Moreover, these network isolation policies can be implemented using existing conventional commands (such as Linux system commands), as detailed later.

[0042] Thus, the solution proposed in this disclosure, while achieving offline data protection, provides users with a unified usage style and interface due to the relatively simple type of servers. This facilitates unified management of all backup servers, inter-system service calls, and function integration. Moreover, the costs of purchasing servers and subsequent expansion are controllable, effectively reducing costs.

[0043] Figure 2 A flowchart of a data offline protection method 200 according to some embodiments of the present disclosure is shown. Method 200 can be performed by, for example... Figure 1 The method is implemented by the system 1000 shown. Alternatively, the method 200 may also be implemented by other entities besides the system 1000. It should be understood that the method 200 may also include additional steps not shown and / or the steps shown may be omitted, and the scope of this disclosure is not limited in this respect.

[0044] In step S230, the first server 110 backs up the target data from the data source 100 according to a preset first network isolation strategy 113, as the first backup data 111. The first network isolation strategy 113 is configured to enable the first server 110 to only enable data transmission with the data source 100 during a first set time period, and to disable data transmission with the data source 100 after the first backup data 111 is backed up.

[0045] For example, in some embodiments of this disclosure, the first server 110 backs up the backup data from the data source end according to a preset first network isolation strategy 113, including: pre-isolating other ports except the data transmission port that transmits data with the data source end 100 through a first layer firewall; during a first set time period (e.g., a set time period every day, a set time period every week, or every hour or every minute), opening the second layer firewall (limited port) with the data source end 100, transmitting the target data from the data source end to the local machine through the data transmission port according to the setting rules of the second layer firewall, packaging the target data to generate the first backup data 111, storing the first backup log recording the backup process; and closing the second layer firewall (limited port) with the data source end 100 after the first backup data 111 is backed up.

[0046] For example, in one example, the first server 110 performs offline backup according to a script (e.g., Linux system instruction programming) that implements the first network isolation policy 121. Specifically, a data transmission port to the data source 100 is pre-opened through a network firewall (an example of a first-layer firewall) (necessary maintenance ports can also be opened), while other ports are closed, thus ensuring network security to a certain extent. After opening the data transmission port through the first-layer firewall, the data source 100 and the first server 110 still cannot transmit data because the first server 110 also has a second-layer firewall (limited ports). This second-layer firewall controls the flow of network packets through predetermined configuration rules. A packet filtering firewall (an example of a second-layer firewall) between the first server 110 and the data source 100 also needs to be enabled before the target data from the data source 100 can be retrieved through the data transmission port.

[0047] The second-layer firewall, for example, uses iptables, a packet-filtering firewall in Linux systems that manages network packets. It opens or closes specific ports by configuring rules, such as allowing or blocking packets from specific IP addresses or IP address ranges. When the second-layer firewall is off, all packets are dropped; when it is on, packets that match the configured rules are allowed to pass, while those that do not are dropped. This is merely an example; other feasible firewalls can be used, as long as they possess similar packet-filtering functionality. This disclosure does not limit the scope of such firewalls.

[0048] As mentioned above, setting up a first-layer firewall can protect the internal network from external network threats and ensure that internal information is not leaked to external attackers. Setting up a second-layer firewall allows for isolation protection to the data source as needed. Protection is enabled when data transmission is required and immediately disabled after transmission is complete, thus working in conjunction with the first-layer firewall for network security protection.

[0049] In step S250, at least one second server 120 backs up the first backup data 111 from the first server 110 according to a preset second network isolation strategy 123, as the second backup data 121, and after the backup, the second server 120 is placed in a physically isolated state. The second network isolation strategy 123 is configured to allow the second server 120 to only enable data transmission with the first server 110 during a second set time period, and to disable data transmission with the first server 110 after the second backup data 121 is backed up.

[0050] For example, in some embodiments of this disclosure, the second server 120 backs up the first backup data 111 from the first server 110 according to a preset second network isolation strategy 123, and after the backup, the second server 120 is placed in a physically isolated state, including: pre-isolating ports other than the data transmission port that transmits data with the first server 110 through a first-layer firewall; opening the second-layer firewall with the first server 110 during a second set time period, obtaining the first backup log from the first server 110 according to the settings rules of the second-layer firewall, and determining whether the target data has been packaged to generate the first backup data based on the first backup log; if the determination result is yes, then transmitting the first backup data 111 to the local machine through the data transmission port as the second backup data 121, and storing the second backup log recording the backup process; after the second backup data 121 is backed up, closing the second-layer firewall with the first server, and performing a shutdown operation. When determining whether the first backup data has been packaged based on the first backup log, the keywords in the transmission log can be detected. If "error" or "failed" appears, it is determined that there is a problem with the transmission; otherwise, it is considered that the packaging is complete.

[0051] For example, in one instance, the second server 120 executes the offline backup function according to the script (e.g., Linux system instruction programming) that implements the second network isolation strategy 123. Specifically, a data transmission port (and necessary maintenance ports) to the first server 110 are pre-opened through the network firewall, while other ports are closed, thus ensuring network security to a certain extent. After the data transmission port is opened, the packet filtering firewall (restricted port) configured on the second server 120 also needs to be enabled. Only according to the packet filtering firewall's configuration rules can the first backup data from the first server 110 be retrieved through the data transmission port. After retrieving the first backup data, the packet filtering firewall's restricted port is closed, and the data is "cold-saved." Therefore, at least two copies of the data are saved, improving redundancy. Moreover, by shutting down the second server 120 and implementing network isolation, the backup security of the backed-up data is ensured, preventing ransomware intrusion and guaranteeing business continuity. The packet filtering firewall's configuration rules are similar to those described above and will not be repeated here.

[0052] like Figure 2 As shown, for example, in some embodiments of this disclosure, the data offline protection method 200 further includes step S270.

[0053] In step S270, at least one third server 130 backs up the second backup data 121 from the second server 120, which is in a state of physical isolation, according to a preset third network isolation policy, as the third backup data, and after the backup, the third server 130 is put into a state of physical isolation.

[0054] The third network isolation strategy is configured as follows: the third server only enables data transmission with the second server during the third set time period, and shuts down data transmission with the second server after the third backup data is backed up.

[0055] For example, in some embodiments of this disclosure, the third server 130 backs up the second backup data 121 from the second server 120 according to a preset third network isolation strategy, and after the backup, the third server 130 is in a physically isolated state, including: pre-isolating other ports except the data transmission port that transmits data with the second server 120 through the first layer firewall, opening the second layer firewall during a third set time period, transmitting the second backup data 121 to the local machine as the third backup data, and storing a third backup log that records the backup process; after the third backup data is backed up, closing the second layer firewall and performing a shutdown operation.

[0056] For example, in one scenario, a third server 130 opens a data transmission port (and necessary maintenance ports) to the second server 120 through a network firewall, while closing all other ports, thus ensuring network security to a certain extent. After the data transmission port is opened, the ports restricted by the packet filtering firewall also need to be opened. Only according to the packet filtering firewall's configuration rules can the second backup data from the second server 120 be retrieved through the data transmission port. After retrieving the second backup data, the ports restricted by the packet filtering firewall are closed, and the data is "cold-saved." Generally, after the preceding server completes the retrieval, it sends a success flag. Subsequent servers only perform data retrieval operations on the preceding server after receiving the success flag, avoiding conflicts when retrieving data from the preceding server.

[0057] Thus, the solution disclosed herein allows for the selection of an appropriate number of server hardware devices based on actual needs, enabling autonomous management and maintenance, thereby reducing long-term operating costs. Furthermore, local server data backup primarily relies on local area networks or internal networks for data transmission, eliminating the need for significant network bandwidth consumption and reducing network costs. Additionally, by deploying a unified data backup solution, centralized management of all backup servers is possible, facilitating resource allocation optimization. Under unified management, cross-server data replication and synchronization are possible, ensuring data integrity and consistency. This facilitates rapid data recovery in the event of a disaster, minimizing business interruption time.

[0058] In this embodiment, the offline data protection system 1000 also has a task monitoring function, which can monitor the operation of the entire system in real time, including the operation of scheduled backup tasks. In the event of an anomaly or malfunction, the system will issue an early warning, reducing potential security risks and ensuring the stable operation of the system.

[0059] For example, in some embodiments of this disclosure, method 200 further includes: detecting a first backup log, a second backup log, or a third backup log, determining whether an abnormality occurs during the backup data process, and if an abnormality occurs, issuing an alarm and re-backing up the data.

[0060] It's important to note that backup logs generally include data transfer logs and error logs. Data transfer logs primarily record detailed information about the scheduled backup task execution process, including file transfer progress, speed, and quantity. This information is usually output in verbose mode and stored in a specifically named log. Error logs mainly record errors and exceptions encountered during the scheduled backup task execution. This information is crucial for diagnosing and resolving problems in the task. Specific contents of the error log may include: error codes and messages, the filename and path of the file that caused the error, the error type, and suggested solutions.

[0061] During the execution of tasks by System 1000, these logs are monitored. Anomalies are identified by recognizing keywords such as "fail," "error," and "broken," triggering an alarm and ensuring the integrity of the backup data by retransmitting the data. Specifically, upon detecting an anomaly, the backup task is interrupted. This can involve retransmitting all target data, or generating a retransmission command based on information such as the current data offset, allowing backup processing to resume from the point of interruption.

[0062] For example, the system 1000 in this embodiment supports breakpoint resumption of various data sources, such as relational databases, non-relational databases, object storage, and log files. For instance, when performing a data backup task, the timestamp, task number, and data offset of the data transmission can be periodically persisted to a designated storage space in the system. When the backup task fails, the data backup task can be resumed by reading and parsing the latest data offset of the saved timestamp. The specific processing logic for resuming the data backup task from the breakpoint for different types of data sources is as follows:

[0063] 1. Relational Database: Parse the latest offset (e.g., represented by DB_offset_B) corresponding to each backup task number, combine the SQL statement generated before each backup task failed (before the timestamp) with the latest offset DB_offset_B to generate a new SQL statement, and the data backup task executes the new SQL statement to achieve breakpoint resume;

[0064] 2. Non-relational databases (HBase, Hive, etc.): The processing logic can be referenced from relational databases. Specifically, Hive is a Hadoop-based data warehouse that uses HDFS for data storage and translates SQL statements into MapReduce jobs. It is specifically designed for processing and analyzing large-scale datasets. Since Hive supports standard SQL statements, it can be processed similarly to relational databases. HBase is a distributed, column-oriented NoSQL database that runs on top of HDFS. While HBase does not support standard SQL, it provides HBase Query Language (HQL), a SQL-like query language used for querying, updating, and deleting data in HBase. Therefore, it can also be processed like a relational database.

[0065] 3. Log Files: Parse the latest offset (e.g., represented by FS_offset_B) corresponding to each task number, and combine the file read range before each backup task failed with the latest offset FS_offset_B to generate a new file read range. Resume download from breakpoints by reading data within this new file read range.

[0066] The above describes the implementation solutions for resuming interrupted data transfers from various data sources, including relational databases, non-relational databases, and log files. For different types of data sources, System 1000 can resume the backup operation from the point of data transmission interruption, resulting in higher job efficiency.

[0067] Figure 3 A flowchart illustrating an exemplary offline data backup process according to at least one embodiment of the present disclosure is shown. Figure 3 In the example, the overall implementation uses two servers, namely the first server 110 and the second server 120, to back up the data respectively.

[0068] In summary, the first server 110 backs up data from the data source 100. The data to be backed up in the data source 100 can include different types of content such as databases, object storage, and / or log files. The first server 110 pulls the backup data to its local machine as the first backup data according to the scheduled backup task. Then, the second server 120 pulls the first backup data from the first server 110 again as the second backup data. After the retrieval is complete, the second server 120 performs a shutdown operation, "cold saving" the data.

[0069] Regarding network isolation strategies, on the one hand, the first server 110 closes all ports except for the transmission port to the data source server and necessary maintenance ports. Similarly, the second server 120 closes all ports except for the data transmission port to the first server 110 and necessary maintenance ports, ensuring network security. On the other hand, after data is backed up from the data source 100 to the first server 110, the first server 110 closes the connection between the two, such as closing the iptables port, and packages the backup data. The second server 120 also closes its connection with the first server 110 after pulling data, such as closing the iptables port, and shuts down. Through the shutdown of the second server 120 and network isolation operations, the backup security of the saved data can be achieved, preventing ransomware intrusion and ensuring business continuity.

[0070] The following is for reference. Figure 3 Please provide a detailed description of the specific content of this example.

[0071] Step S301: The first server 110 periodically opens the port restricted by the packet filtering firewall to pull data for backup.

[0072] First, server 110 checks if there are any incomplete data transfer processes (e.g., initiated by the rsync command in Linux). If so, it returns and waits for the current data transfer to complete. If there are no incomplete data transfer processes, it first unblocks the packet filtering firewall (e.g., configured using the iptables program in Linux) between server 110 and source data server 100. This firewall is disabled by default (discarding all received packets), and it is enabled when the scheduled backup task starts to prepare for the specific target data transfer.

[0073] The data transfer process uses the rsync command in the Linux system to pull data to the local machine, for example, by executing the following command:

[0074] "nohup rsync-avzh--delete--progress source data server IP: / source data path / / local backup data path / > / rsync_$data.log2> / fail_rsync_$date.log",

[0075] Furthermore, data transfer logs during the data retrieval process are written to a log file named "rsync_$date.log" by date, and error messages are written to a file named "fail_rsync_$date.log" by date for subsequent monitoring.

[0076] Step S302: The first server 110 packages the data and closes the ports restricted by the packet filtering firewall.

[0077] First server 110 checks if there are any incomplete packaging processes (e.g., initiated by the tar command on a Linux system). If so, it returns and waits for the packaging to complete. If there are no incomplete data packaging processes, it disables the packet filtering firewall of first server 110 (e.g., configured using the iptables program on a Linux system) and re-enables it when there is a need for data transmission later, ensuring the network security of first server 110.

[0078] The data packaging process uses the Linux system command `tar` to package the backed-up data, for example, by executing the following command:

[0079] "nohup tar -cvf / backupdata.tar / local backup data path / > / tar_$date.log 2> / fail_tar_$date.log",

[0080] Once the packaging is complete, a completion log is recorded. The packaging log is written to a log file named "tar_$date.log" by date, and the error log is written to a file named "fail_tar_$date.log" by date for subsequent monitoring.

[0081] Step S303: The second server 120 is powered on at regular intervals and the firewall port is opened to back up the data pulled by the first server 110.

[0082] The second server 120 first unblocks the packet filtering firewall (such as the iptables program configuration of a Linux system) of the first server 110 by using out-of-band scheduled power-on (for example, the server has a remote control module (also called an out-of-band management system) through which the server can be scheduled to power on and off). This firewall is off by default and is turned on when the scheduled backup task starts to prepare for data transmission.

[0083] The second server 120 retrieves the logs from the first server 110 showing the completion of the tar command packaging process for Linux system data. If the logs indicate that packaging is complete, then the data retrieval process will begin from the first server 110.

[0084] Use the Linux system's rsync command to pull data to your local machine, for example, by executing the following command:

[0085] "nohup rsync-avzh--delete--progress Backup_1_IP: / source_data_path / / local_backup_data_path / > / rsync_$data.log 2> / fail_$date.log",

[0086] Data transfer logs during the data retrieval process are written to a log file named "rsync_$date.log" by date, and error logs are written to a file named "fail_rsync_$date.log" by date for subsequent monitoring.

[0087] Step S304: The second server 120 disables the packet filtering firewall and shuts down.

[0088] After the second server 120 finishes pulling data from the first server 110, it disables the packet filtering firewall and shuts down. Once the server is shut down, it is disconnected from the network and power, thus achieving offline data backup.

[0089] It should be noted that when backing up data on each server, it is necessary to monitor the results of the data backup script.

[0090] Since the first server 110 and the second server 120 have a large number of running scripts and run regularly, a monitoring system (such as Zabbix) is used to filter keywords (e.g., fail, error, broken) in the data transmission log (rsyc_$data.log) and error log (fail_rsync_$date.log, fail_tar_$date.log). If any abnormalities are detected, an alarm is triggered and the issues are addressed. The integrity of the backup data is ensured through operations such as retransmission (or resuming interrupted transmission).

[0091] As described above, the first server 110 and the second server 120 isolate unused ports, including all known network segments and all ports, through a network firewall. The first server 110 uses a packet filtering firewall to only open port 22 for rsync transmission to the data source server 100, and the second server 120 also uses a packet filtering firewall to only open port 22 for rsync transmission to the first server 110. Therefore, through network firewall isolation, packet filtering firewall (iptables) isolation, server shutdown, and other operations, offline data backup is achieved, improving data security and preventing ransomware attacks.

[0092] In addition, offline data backup is performed using standard Linux operating system commands, which eliminates the brand differences between various backup software, backup appliances, and offline media, greatly reducing maintenance difficulty and improving maintenance efficiency.

[0093] Moreover, offline backup via servers significantly reduces the procurement and expansion costs of offline backup equipment, thereby lowering data center operating costs.

[0094] The process of offline data backup was described above. The process of using backup data to restore target data will be described below.

[0095] For example, in some embodiments of this disclosure, if the target data at the data source end is lost or tampered with, the target data can be recovered through the first server 110. Specifically, the first server 110, in response to a recovery request for the target data, initiates data transmission with the data source end 100 and transmits first backup data for the target data to the data source end 100 to recover the target data. The recovery request includes the data generation timestamp and number of the target data. The first server 110 locates the corresponding first backup data based on the data generation timestamp and number and sends it to the data source end 100.

[0096] For example, in some embodiments of this disclosure, if the data on the first server 110 is tampered with or destroyed, the target data can be recovered through the second server 120. Specifically, this includes: releasing the physical isolation state of the second server 120; in response to a recovery request for the target data, the second server 120 transmits second backup data for the target data to the data source 100 via the first server 110 to recover the target data, or, enabling data transmission with the data source 100 and transmitting the second backup data for the target data to the data source 100 to recover the target data; the second server locates the corresponding second backup data based on the data generation timestamp and number and sends it to the first server 110 for forwarding to the data source 100; or directly sending it to the data source 100.

[0097] For example, in some embodiments of this disclosure, when the data of the first server 110 and the second server 120 is tampered with or destroyed, the target data can also be recovered through the third server 130. Specifically, this includes: releasing the physical isolation state of the third server 130; in response to a recovery request for the target data, the third server 130 transmits third backup data for the target data to the data source 100 via the second server 120 and the first server 130 to recover the target data; or, enabling data transmission with the data source 100 and transmitting the third backup data for the target data to the data source to recover the target data. The third server 130 locates the corresponding third backup data based on the data generation timestamp and number and sends it to the second server 120, which then forwards it to the data source 100 via the first server 110; or it sends it directly to the data source 100.

[0098] For example, in one scenario, to remove the physical isolation of the servers in the event of data recovery, a power-on command can be sent to the remote control module on each server. The remote control module, responding to the command, controls the corresponding server to power on. This allows each server to receive data recovery requests and perform the appropriate operations. Alternatively, the servers involved in the backup can establish a network connection with the data source. When data recovery is needed, the backup data can be directly transmitted through the data transmission ports of each server and the data source.

[0099] Figure 4 A schematic flowchart illustrating an exemplary data recovery process according to at least one embodiment of the present disclosure is shown. The data recovery process can be performed by, for example... Figure 1 The data recovery process can be implemented using the data source 100 and the first server 110 shown, or it can be implemented in conjunction with a second server 120 or a third server 130 (not shown). Alternatively, it can be implemented by other entities. It should be understood that the data recovery process may also include additional steps not shown and / or the steps shown may be omitted, and the scope of this disclosure is not limited in this respect.

[0100] Data source 100 may send a recovery request for target data A to first server 110 (S410). It should be understood that target data A is merely an example of data to be recovered, and first server 110 can recover any target data that has already been backed up. Upon receiving the recovery request, first server 110 may, based on the request, determine the first backup data A1 stored on first server 110 corresponding to target data A (S420). Then, first server 110 sends the first backup data A1 to data source 100 (S430). After receiving the first backup data A1, data source 100 recovers target data A (S440) and sends a notification instruction to first server 110 indicating that the recovery of target data A is complete (S450).

[0101] In certain extreme cases, such as when the first backup data in the first server 110 is tampered with or attacked, it is necessary to use the second backup data A2 in the second server 120 to restore the target data A. In such cases, the following process is performed.

[0102] Data source 100 can send a recovery request for target data A to first server 110 (S410). First server 110 then forwards the received recovery request to second server 120 (S411). Upon receiving the recovery request, second server 120 can determine, based on the request, the second backup data A2 corresponding to target data A stored on second server 120 (S412). Then, second server 120 sends the second backup data A2 to first server 110 (S413), and first server 110 forwards the received second backup data A2 to data source 100 (S414). After receiving the second backup data A2, data source 100 restores target data A (S440) and sends a notification instruction to first server 110 indicating that the restoration of target data A is complete (S450). First server 110 sends the received notification instruction to second server 120 (S415).

[0103] It should be noted that the above application scenarios are merely illustrative to illustrate one or more aspects of this disclosure in specific scenarios, but these aspects are not essential and various modifications can be made to the application scenario.

[0104] At least some embodiments of this disclosure also provide an electronic device. Figure 5 A schematic diagram of an electronic device 500 according to at least one embodiment of the present disclosure is shown.

[0105] like Figure 5 As shown, the electronic device 500 includes one or more processors 510 and a memory 520. The memory 520 includes one or more computer program modules 521. The one or more computer program modules 521 are stored in the memory 520 and configured to be executed by the processor 510. These computer program modules 521 include instructions for performing a data offline protection method 200 and its additional aspects according to at least one embodiment of the present disclosure. When executed by the processor 510, they can perform one or more steps of the data offline protection method 200 and its additional aspects according to at least one embodiment of the present disclosure. The memory 520 and the processor 510 can be interconnected via a bus system and / or other forms of connection mechanisms (not shown). For example, the bus can be a Peripheral Component Interconnect Standard (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0106] For example, processor 510 may be a central processing unit (CPU), a digital signal processor (DSP), or other processing unit with data processing and / or program execution capabilities, such as a field-programmable gate array (FPGA). Processor 510 may be a general-purpose processor or a special-purpose processor, capable of controlling other components in electronic device 500 to perform desired functions.

[0107] Exemplarily, memory 520 may include any combination of one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), USB memory, flash memory, etc. One or more computer program modules 521 may be stored on the computer-readable storage medium, and processor 510 may execute one or more computer program modules 521 to implement various functions of electronic device 500. The computer program modules include multiple computer-executable instructions. Various application programs and various data, as well as various data used and / or generated by the application programs, may also be stored in the computer-readable storage medium.

[0108] For example, electronic device 500 may also include input devices such as touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, and gyroscopes; output devices such as liquid crystal displays, speakers, and vibrators; storage devices such as magnetic tapes and hard disks (HDDs or SDDs); and communication devices such as network interface cards like LAN cards and modems. The communication devices allow electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data and perform communication processing via networks such as the Internet. A drive is connected to the I / O interface as needed. Removable storage media, such as disks, optical disks, magneto-optical disks, and semiconductor memories, are installed on the drive as needed so that computer programs read from them can be installed into the storage device as required.

[0109] For example, the electronic device 500 may further include a peripheral interface (not shown in the figure). This peripheral interface can be of various types, such as a USB interface, a Lightning interface, etc. The communication device can communicate wirelessly with networks and other devices, such as the Internet, intranets and / or wireless networks such as cellular telephone networks, wireless local area networks (LANs) and / or metropolitan area networks (MANs). Wireless communication can use any of a variety of communication standards, protocols, and technologies, including but not limited to Global System for Mobile Communications (GSM), Enhanced Data GSM Environment (EDGE), Wideband Code Division Multiple Access (W-CDMA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Bluetooth, Wi-Fi (e.g., based on IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, and / or IEEE 802.11n standards), Voice over Internet Protocol (VoIP), Wi-MAX, protocols for email, instant messaging, and / or Short Message Service (SMS), or any other suitable communication protocol.

[0110] The electronic device 500 may be, for example, a system-on-a-chip (SOC) or a device including the SOC. For instance, it can be any device such as a mobile phone, tablet computer, laptop computer, e-reader, game console, television, digital photo frame, navigator, home appliance, communication base station, industrial controller, server, etc., or any combination of data processing devices and hardware. The embodiments of this disclosure do not limit this. The specific functions and technical effects of the electronic device 500 can be found in the foregoing description of the data offline protection method 200 and its additional aspects according to at least one embodiment of this disclosure, and will not be repeated here.

[0111] Figure 6 A schematic diagram of a computer-readable storage medium 600 according to at least one embodiment of the present disclosure is shown.

[0112] like Figure 6 As shown, a non-transitory computer instruction 610 is stored on a computer-readable storage medium 600, which, when executed by a processor, performs one or more steps of the data offline protection method 200 and its additional aspects as described above.

[0113] For example, when the program code is read by a computer, the computer can execute the program code stored in the computer storage medium to perform one or more steps to implement, for example, the data offline protection method 200 and its additional aspects according to at least one embodiment of the present disclosure.

[0114] For example, the computer-readable medium may include a memory card of a smartphone, a storage component of a tablet computer, a hard disk of a personal computer, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), portable compact disc read-only memory (CD-ROM), flash memory, and other computer-readable media or any combination thereof.

[0115] At least some of the embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other.

[0116] It should be noted that, in this document, relational terms such as "first," "second," etc., are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.

[0117] The following points should be noted regarding this disclosure:

[0118] (1) The accompanying drawings of the embodiments of this disclosure only involve the structures involved in the embodiments of this disclosure. Other structures can be referred to the general design.

[0119] (2) Where there is no conflict, the embodiments of this disclosure and the features in the embodiments can be combined with each other to obtain new embodiments.

[0120] The above description is merely an exemplary embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure, which is determined by the appended claims.

Claims

1. A method for protecting data offline, the method comprising: The first server backs up the target data from the data source according to the preset first network isolation strategy, and uses it as the first backup data; At least one second server backs up the first backup data from the first server according to a preset second network isolation policy, and uses it as the second backup data, and after the backup, the second server is in a physically isolated state. The first network isolation policy is configured such that the first server only enables data transmission with the data source during a first set time period, and disables data transmission with the data source after the first backup data is backed up. The second network isolation policy is configured to enable the second server to only transmit data with the first server during a second set time period, and to disable data transmission with the first server after the second backup data is backed up.

2. The method according to claim 1, wherein, The method further includes: Release the physical isolation status of the second server; At least one third server backs up the second backup data from the second server according to a preset third network isolation policy, and uses it as the third backup data, and after the backup, the third server is in a physically isolated state. The third network isolation strategy is configured such that the third server only enables data transmission with the second server during a third set time period, and closes data transmission with the second server after the third backup data is backed up.

3. The method according to claim 1, wherein, The method further includes: In response to a recovery request for the target data, the first server initiates data transmission with the data source and transmits first backup data for the target data to the data source to restore the target data. The recovery request includes the data generation timestamp and number of the target data, and the first server searches for the corresponding first backup data based on the data generation timestamp and number.

4. The method according to claim 1, wherein, The method further includes: Release the physical isolation status of the second server; In response to a recovery request for the target data, the second server initiates data transmission with the first server, and the first server transmits second backup data for the target data to the data source to restore the target data; or, it initiates data transmission with the data source and transmits second backup data for the target data to the data source to restore the target data. The recovery request includes the data generation timestamp and number of the target data, and the second server searches for the corresponding second backup data based on the data generation timestamp and number.

5. The method according to claim 2, wherein, The method further includes: Release the physical isolation status of the third server; In response to a recovery request for the target data, the third server initiates data transmission with the second server, and transmits third backup data for the target data to the data source via the second server and the first server to restore the target data; or, it initiates data transmission with the data source and transmits third backup data for the target data to the data source to restore the target data. The recovery request includes the data generation timestamp and number of the target data, and the third server searches for the corresponding third backup data based on the data generation timestamp and number.

6. The method according to any one of claims 1 to 5, wherein, The first server backs up the target data from the data source according to a preset first network isolation policy, including: All ports except the data transmission port that transmits data to the data source are pre-isolated by a first-layer firewall; During the first set time period, the second layer firewall of the data source is enabled, and the target data of the data source is transmitted to the local machine through the data transmission port according to the setting rules of the second layer firewall. The target data is packaged to generate the first backup data, and the first backup log recording the backup process is stored. After the first backup data is backed up, the second layer firewall between the data source and the data source is turned off.

7. The method according to claim 6, wherein, The second server backs up the first backup data from the first server according to a preset second network isolation policy, and after the backup, the second server is placed in a physically isolated state, including: The ports other than the data transmission port that transmits data with the first server are isolated in advance through the first-layer firewall; During the second set time period, the second layer firewall of the first server is enabled, the first backup log is obtained from the first server according to the configuration rules of the second layer firewall, and it is determined whether the target data has been packaged to generate the first backup data based on the first backup log; If the determination result is yes, the first backup data is transmitted to the local machine through the data transmission port as the second backup data, and the second backup log recording the backup process is stored. After the second backup data is backed up, disable the second layer firewall between the server and the first server, and then shut down the server.

8. The method according to claim 6 or 7, wherein, The method further includes: Check the first or second backup log to determine if any abnormality occurred during the data backup process. If an abnormality occurred, re-back up the data.

9. A data offline protection system, the system comprising: The first server is configured to back up the target data from the data source according to a preset first network isolation policy, and serve as the first backup data. At least one second server is configured to back up the first backup data from the first server according to a preset second network isolation policy, and to use the backup data as the second backup data, and to put the second server in a physically isolated state after the backup. The first network isolation policy is configured such that the first server only enables data transmission with the data source during a first set time period, and disables data transmission with the data source after the first backup data is backed up. The second network isolation policy is configured to enable the second server to only transmit data with the first server during a second set time period, and to disable data transmission with the first server after the second backup data is backed up.

10. The system according to claim 9, wherein, The system also includes: At least one third server is configured to back up the second backup data from the second server after the physical isolation state has been lifted, according to a preset third network isolation policy, as the third backup data, and after the backup, the third server is put into a physical isolation state. The third network isolation strategy is configured such that the third server only enables data transmission with the second server during a third set time period, and closes data transmission with the second server after the third backup data is backed up.

11. The system according to claim 9, wherein, The first server is further configured to, in response to a recovery request for the target data, initiate data transmission with the data source and transmit first backup data for the target data to the data source to restore the target data. The recovery request includes the data generation timestamp and number of the target data, and the first server searches for the corresponding first backup data based on the data generation timestamp and number.

12. The system according to claim 9, wherein, The second server is also configured to release the physical isolation state of the second server; In response to a recovery request for the target data, data transmission with the first server is initiated, and the target data is restored by transmitting second backup data for the target data to the data source via the first server. Alternatively, data transmission with the data source can be initiated, and a second backup of the target data can be transmitted to the data source to restore the target data; The recovery request includes the data generation timestamp and number of the target data, and the second server searches for the corresponding second backup data based on the data generation timestamp and number.

13. The system according to claim 10, wherein, The third server is further configured to release the physical isolation state of the third server; in response to a recovery request for the target data, to enable data transmission with the second server, and to transmit third backup data for the target data to the data source via the second server and the first server to restore the target data; Alternatively, data transmission with the data source can be initiated, and third backup data for the target data can be transmitted to the data source to restore the target data; The recovery request includes the data generation timestamp and number of the target data, and the third server searches for the corresponding third backup data based on the data generation timestamp and number.

14. The system according to any one of claims 9 to 13, wherein, The first server is also configured to pre-isolate other ports except the data transmission port that transmits data with the data source through a first-layer firewall; during the first set time period, the second-layer firewall of the data source is enabled, and the target data of the data source is transmitted to the local machine through the data transmission port according to the setting rules of the second-layer firewall, and the target data is packaged to generate first backup data, and a first backup log recording the backup process is stored. After the first backup data is backed up, the second layer firewall between the data source and the data source is turned off.

15. The system according to claim 14, wherein, The second server is also configured to pre-isolate other ports, except for the data transmission port that transmits data with the first server, through a first-layer firewall; During the second set time period, the second layer firewall of the first server is enabled, the first backup log is obtained from the first server according to the configuration rules of the second layer firewall, and it is determined whether the target data has been packaged to generate the first backup data based on the first backup log; If the determination result is yes, the first backup data is transmitted to the local machine through the data transmission port as the second backup data, and the second backup log recording the backup process is stored. After the second backup data is backed up, disable the second layer firewall between the server and the first server, and then shut down the server.

16. The system according to claim 14 or 15, wherein, The first server is also configured to detect the first backup log, determine whether any abnormality occurred during the data backup process, and if an abnormality occurred, re-backup the data; or, The second server is also configured to detect the second backup log, determine whether any abnormality occurs during the data backup process, and if an abnormality occurs, then re-back up the data.

17. An electronic device comprising: One or more processors; Memory, which stores one or more computer program modules. The one or more computer program modules are configured to be executed by the one or more processors to implement the method according to any one of claims 1-8.

18. A computer-readable storage medium for storing non-transitory computer-readable instructions, wherein, When a non-transitory computer-readable instruction is executed by one or more processors, it is used to implement the method according to any one of claims 1-8.