Data backup system

EP4702487A1Pending Publication Date: 2026-03-04TF- IND GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-26
Publication Date
2026-03-04

AI Technical Summary

Technical Problem

Existing data backup systems are vulnerable to manipulation and third-party attacks, lacking effective measures for secure data protection and easy handling during backup and restoration processes in network systems.

Method used

A data backup system comprising a backup memory with two bridges and a buffer, where the power supply can be interrupted to secure data transmission, utilizing MOSFET switches controlled by a bridge control unit for secure data encryption and decryption, ensuring that both bridges cannot be switched simultaneously, thus preventing unauthorized access.

Benefits of technology

The system provides robust protection against manipulation and minimizes risks of third-party attacks by ensuring secure data transmission and storage, making it highly secure against malware and malicious code execution during backup and restoration processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024061635_31102024_PF_FP_ABST
    Figure EP2024061635_31102024_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a data backup system (1, 101) for data of a data network (31) to be backed up, the data backup system (1, 101) comprising a backup memory (33), the data backup system (1, 101) also comprising a first bridge (21), a cache (32), and a second bridge (22), the data backup system (1, 101) and / or the first bridge (21) comprising a data backup system interface (221) for a first data transmission connection (41) for directly or indirectly connecting the data network (31) and the first bridge (21) for data transmission, the first bridge (21) and the cache (32) being connected for data transmission by means of a second data transmission connection (42), the cache (32) and the second bridge (22) being connected for data transmission by means of a third data transmission connection (43), the second bridge (22) and the backup memory (33) being connected for data transmission by means of a fourth data transmission connection (44), the data backup system (1, 101) comprising a controller (2, 102) designed to interrupt a power supply for the first bridge (21) and to interrupt the power supply for the second bridge (22) in such a way that at least the power supply for the first bridge (21) or the power supply for the second bridge (22) is interrupted.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Data backup system

[0002] The invention relates to a data backup system. The invention also relates to a network system with a data backup system. The invention also relates to a method for operating a network system.

[0003] A data backup system is disclosed, for example, in the article Shon et al., “A robust and secure backup system for protecting malware”, dl.acm.org / doi / abs / 10.1145 / 3297280.3297424.

[0004] EP 2 953 150 B1 discloses a device for current limiting or current interruption of an electrical circuit and a control method therefor. The device comprises a current interruption branch and a bridge branch. The bridge branch comprises two bridge arms formed by four identical current commutation branches. Two branches of each of the four current commutation branches are connected in series, and the two formed bridge arms are then connected in parallel. The two bridge arms are both connected in parallel to the current interruption branch, and the midpoints of the two bridge arms are separately connected to two points of the electrical circuit. Each current commutation branch comprises at least one high-speed interruption switch and at least one bidirectional power semiconductor switch, both connected in series. The device can interrupt a bidirectional current.

[0005] DE 196 47 655 A1 discloses a backup device that allows a primary server to be disconnected from the network and a secondary server to be connected, regardless of the type of malfunction occurring in a network. This is achieved by providing means for interrupting the power supply to the primary server.

[0006] DE 10 2008 029 902 A1 discloses a method for operating a bus system comprising a first and at least one second network node (MASTER, SLAVE). A first and a second line (BUS, GND) are provided for supplying power to the at least one second network node (SLAVE) and for communication between the first and the at least one second network node (MASTER, SLAVE). Communication between the first and the at least one second network node (MASTER, SLAVE) and the power supply to the at least one second network node (SLAVE) are each effected via the first line (BUS) and are separated in time.

[0007] The object of the invention is to provide a data backup system that is particularly well protected against manipulation or to improve data backup in a network system. It is desirable to achieve simple handling and minimize the risk of external attacks during data backup and / or data recovery.

[0008] The above object is achieved by a data backup system for a data network (basic network, also known as LAN (e.g. company network), wherein the data backup system comprises a backup memory (in particular for storing data of the data network), wherein the data backup system further comprises a (lock comprising a) first bridge, a buffer and a second bridge, wherein the data backup system and / or the first bridge comprises a data backup system interface for a first data transmission connection for the indirect or direct data connection of the data network and the first bridge, wherein the first bridge and the buffer are connected for data technology by means of a second data transmission connection, wherein the buffer and the second bridge are connected for data technology by means of a third data transmission connection,wherein the second bridge and the backup memory are connected for data purposes by means of a fourth data transmission connection, wherein the data backup system comprises a controller configured to interrupt a power supply for the first bridge and to interrupt a power supply for the second bridge such that (during normal operation) at least the power supply for the first bridge or the power supply for the second bridge is interrupted.

[0009] A bridge within the meaning of this disclosure can be a switch. A bridge within the meaning of this disclosure can be understood as connecting two segments in a computer network at the level of Layer 2 (data link layer) of the OSI model. A bridge within the meaning of this disclosure can optionally be designed to operate on the MAC sublayer or the LLC sublayer. A bridge within the meaning of this disclosure can be a MAC bridge. A bridge within the meaning of this disclosure can be an LLC bridge. A bridge within the meaning of this disclosure can be a transparent bridge. A bridge within the meaning of this disclosure can be a source routing bridge. A bridge within the meaning of this disclosure can be a coupling element in computer networks. A bridge within the meaning of this disclosure can be a switch that ensures that the data packets, so-called "frames," reach their destination within a segment (broadcast domain).A bridge within the meaning of this disclosure can be a switch, which generally refers to a multiport bridge (or an active network device) that forwards frames based on information from the data link layer (layer 2) of the OSI model. A bridge within the meaning of this disclosure can be a bridging hub. A bridge within the meaning of this disclosure can be a switching hub. A bridge within the meaning of this disclosure can be a fiber optic LAN converter, which can be used in the same way as the switch, and can connect to an external fiber optic connection or an internal fiber optic connection (converter to cache) via light bridging. In an advantageous embodiment of the invention, the controller has a first switch for interrupting the power supply for the first bridge by opening the first switch. A first switch within the meaning of this disclosure is, in particular, a MOSFET.A first switch within the meaning of this disclosure is, in particular, a switch that is open in the de-energized state. A first switch within the meaning of this disclosure can also be a control board that has a function comparable to a MOSFET, but has additional control instances implemented, such as an IC.

[0010] The control system can include a bridge controller, also called a bridge appliance (e.g., Raspberry Pi, microcontroller, etc.). This bridge controller controls the MOSFETs via their GPIOs and supplies them with voltage at the GATE. If voltage is applied to the GATE, the source voltage (e.g., 5V) is switched, activating the bridge or switch. Switching the bridge or switch creates a physical connection between all connected lines on the bridge / switch. The cache can be a memory that accepts data and forwards it, provided the appropriate bridge is connected.

[0011] In a further advantageous embodiment of the invention, the controller has a second switch for interrupting the power supply to the second bridge by opening the second switch. A second switch within the meaning of this disclosure is, in particular, a MOSFET. A second switch within the meaning of this disclosure is, in particular, a switch that is open in the de-energized state. A second switch within the meaning of this disclosure can also be a control board that has a function comparable to a MOSFET, but has additional control instances implemented, such as an IC.

[0012] The interruption of a power supply within the meaning of this disclosure is, in particular, a physical interruption. In a further advantageous embodiment of the invention, the bridge controller is provided for generating a first switch signal for closing the first switch and for generating a second switch signal for closing the second switch, wherein the controller comprises the bridge controller.In a further advantageous embodiment of the invention, it is provided that the data backup system comprises a logic circuit with a first input for the first switch signal and a second input for the second switch signal, wherein the logic circuit comprises a first output and a second output and is designed such that the first switch signal is output at the first output if the second switch signal is not output at the second output and that the second switch signal is output at the second output if the second switch signal is applied to the second input and the first switch signal is not output at the first output.

[0013] The second data transmission connection and / or the third data transmission connection and / or the fourth data transmission connection within the meaning of this disclosure are non-wireless data transmission connections. Non-wireless data transmission connections within the meaning of this disclosure are, in particular, data transmission connections in which the signals carrying the data are transmitted in a solid state.

[0014] In a further advantageous embodiment of the invention, it is provided that the first data transmission connection is designed as an optical fiber or comprises an optical fiber.

[0015] In a further advantageous embodiment of the invention, it is provided that the second data transmission connection is designed as an optical fiber or comprises an optical fiber. In a further advantageous embodiment of the invention, it is provided that the third data transmission connection and / or the fourth data transmission connection is designed as an optical fiber or comprises an optical fiber. Optical fibers (OFC) within the meaning of this disclosure are, for example, fiber optic cables (FOC). Optical fibers (OFC) within the meaning of this disclosure are, for example, cables and lines consisting of optical fibers and partially pre-assembled with connectors for transmitting light. The light is guided, for example, in fibers made of quartz glass or plastic (polymer optical fiber).They are often also referred to as fiber optic cables, where they typically combine several optical fibers, which are also mechanically reinforced to protect and stabilize the individual fibers. They can be single-mode or multimode.

[0016] From a physical perspective, optical waveguides within the meaning of this disclosure are, for example, dielectric waveguides. They are constructed, for example, from concentric layers, with the light-guiding core located at the center, surrounded, for example, by a cladding with a somewhat lower refractive index and, for example, by additional protective layers made of plastic. Depending on the application, the core has a diameter of, for example, a few micrometers to over a millimeter. Optical waveguides are differentiated, for example, according to the refractive index distribution between core and cladding (step-index or graded-index fibers) and the number of propagable vibration modes, which is limited by the core diameter.

[0017] The aforementioned object is further achieved by a network system, wherein the network system comprises a data backup system, for example a data backup system with one or more of the aforementioned features, and wherein the network system comprises a data network and the first data transmission connection between the data network and the first bridge by means of the data backup system interface. The aforementioned object is further achieved by a method for operating a network system with a backup memory, in particular by a method for operating a network system with the aforementioned features, wherein the network system comprises a (gate comprising a) first bridge, a buffer, and a second bridge, wherein the network system comprises a first data transmission connection for the data connection of / the data network and the first bridge,wherein the first bridge and the buffer are connected for data purposes by means of a second data transmission connection of the network system, wherein the buffer and the second bridge are connected for data purposes by means of a third data transmission connection of the network system, and wherein the second bridge and the backup memory are connected for data purposes by means of a fourth data transmission connection of the network system, wherein it is provided in particular that data of the data network to be backed up is transmitted from the data network to the buffer.

[0018] In an advantageous embodiment of the invention, data to be backed up (of the data network, yes) is stored in encrypted form on the backup memory. In a further advantageous embodiment of the invention, data to be backed up is encrypted in the buffer memory, transferred from the buffer memory to the backup memory, and stored in encrypted form on the backup memory.

[0019] In a further advantageous embodiment of the invention, the power supply to the second bridge is interrupted, wherein data to be backed up is then transferred from the data network to the buffer memory, wherein the power supply to the first bridge is then interrupted, wherein the interruption in the power supply to the second bridge is then lifted, wherein the data to be backed up is then transferred from the buffer memory to the backup memory and stored in the backup memory. In a further advantageous embodiment of the invention, the power supply to the second bridge is then interrupted. In order to restore data backed up using the backup memory, an advantageous embodiment of the invention provides that the interruption in the power supply to the second bridge is lifted.In a further advantageous embodiment of the invention, the secured data is transferred from the backup memory to the buffer and, if necessary, decrypted. In a further advantageous embodiment of the invention, the power supply to the second bridge is subsequently interrupted.

[0020] In an advantageous embodiment of the invention, the interruption of the power supply to the first bridge is removed. In a further advantageous embodiment of the invention, the saved data is transferred from the buffer to the data network. In a further advantageous embodiment of the invention, the power supply to the first bridge is subsequently interrupted.

[0021] The two bridges, in conjunction with the buffer, form a gate or implement a gate functionality. The power supply to the first bridge is interrupted when the power supply interruption to the second bridge is removed, and the power supply to the second bridge is interrupted when the power supply interruption to the first bridge is removed. This ensures that both bridges cannot be switched on at any time.

[0022] A circuit board can prevent both gates, i.e. both bridges, from opening simultaneously, even in the event of hardware defects.

[0023] The bridge controller (a bridge appliance that controls matching bridges with its GPIOs) is advantageously not connected to the buffer / cache or any other module by any connector. Rather, the bridge controller is advantageously designed to run independently, particularly to completely prevent unwanted external access. It is advantageously designed so that switching times, etc., can only be set and edited through direct access to the bridge controller.

[0024] The measures listed ensure that both bridges cannot be switched at any time. A distinction is made between a first gate phase and a second gate phase. The phase referred to as the first gate phase concerns the case in which data from the data network (hereinafter also referred to as LAN) is to be fed to the buffer (hereinafter also referred to as cache). In this case, the bridge controller (bridge appliance (manager)) switches on the first bridge in such a way that the first bridge is supplied with power. From this point on, the LAN is "through-connected" to the cache. This allows data to be transferred to the cache. This can continue until the bridge controller or bridge appliance switches the first bridge off again, i.e., the first bridge is disconnected from the power supply. From this point on, a thorough analysis of the data in the cache takes place. This meansThey are analyzed for malware and finally encrypted (symmetric encryption methods).

[0025] In a second gateway phase, the data can be transferred from the cache to the backup storage using a standardized and supported protocol of the backup storage / backup server (e.g., FTP / SMB / NFS). This, too, only occurs within the framework defined by the bridge controller / bridge appliance. All data or content transferred to the backup storage / backup server is encrypted without exception. This means that no malicious code can cause damage to the main memory without knowledge of the encryption key, since encrypted malicious code is not executable.

[0026] The configuration options for the bridge controller / bridge appliance are deliberately very limited. For ease of use and to minimize the risk of security incidents, only schedules for switching are possible. The duration and / or number of time intervals are also advantageously limited to avoid unnecessary compromises of system security. Furthermore, it is possible to reverse the switching process to restore data. This also means that the number of transmitting devices is limited. Certain processes in the cache also require computing capacity, which is dependent on time and, in this case, also limits the number of devices.

[0027] In addition to normal operation for backup, the Bridge appliance can also be put into restore mode. In this mode, data is loaded intermittently into the buffer / cache and from there transported to the appropriate end device via the LAN (). The gateway principle is completely inverted here. The buffer / cache is solely responsible for loading, encrypting, decrypting, and analyzing data.

[0028] Further advantages and details are revealed in the following description of exemplary embodiments. These show:

[0029] Fig. 1 shows an embodiment of a network system,

[0030] Fig. 2 shows an embodiment of an alternative network system,

[0031] Fig. 3 shows an embodiment of a logic circuit,

[0032] Fig. 4 shows an embodiment of a method for operating a network system according to Fig. 1, and

[0033] Fig. 5 shows an embodiment of a modified method for operating a network system.

[0034] Fig. 1 shows an embodiment of a network system 11 with a data network 31 and with a data backup system 1 for the data network 31, wherein the data backup system 1 comprises a backup memory 33 for storing data of the data network 31. The data backup system 1 also comprises a bridge 21, a buffer 32 and a bridge 22. The network system 11 comprises a first, in particular non-wireless, data transmission connection 41 for the data-technical connection of the data network 31 to the bridge 21, wherein the bridge 21 comprises a data backup system interface 211 for implementing the data transmission connection 41.

[0035] The bridge 21 and the buffer 32 are connected for data transmission via a second, in particular non-wireless, data transmission connection 42. The second data transmission connection 42 can be configured as an optical fiber or comprise an optical fiber. The buffer 32 and the bridge 22 are connected for data transmission via a third, in particular non-wireless, data transmission connection 43. The third data transmission connection 43 can be configured as an optical fiber or comprise an optical fiber.

[0036] The bridge 22 and the backup memory 33 are connected for data purposes via a fourth, in particular non-wireless, data transmission connection 44. The fourth data transmission connection 44 can be configured as an optical fiber or comprise an optical fiber.

[0037] No special technical requirements are required for the data network (e.g., LAN network) or backup storage. The operating system of end devices in the data network 31 or LAN and the backup storage 33, for example, only supports the (network) sockets defined in RFCs.

[0038] The voltage supply of Bridge 21 and the voltage supply of Bridge 22 is provided by a voltage source 5.

[0039] The data backup system 1 comprises a controller 2 configured to interrupt a power supply for the bridge 21 and to interrupt the power supply for the bridge 22 such that at least the power supply for the bridge 21 or the power supply for the bridge 22 is interrupted. For this purpose, the controller 2 comprises a switch RLY1 configured as a MOSFET for interrupting the power supply for the bridge 21 by opening the switch RLY1, so that the line between the bridge 21 and the power source 5 is interrupted, as well as a switch RLY2 configured as a MOSFET for interrupting the power supply for the bridge 22 by opening the switch RLY2, so that the line between the bridge 22 and the power source 5 is interrupted. A bridge controller 3 or bridge appliance (e.g. Raspberry, microcontroller, etc.) controls the MOSFET switches RLY1 and RLY2 via the GPIOs of bridge controller 3 and supplies them with voltage at the GATE—referred to here as the switch signal. If voltage is present at the GATE of the respective MOSFET, this means that the bridge assigned to that MOSFET is supplied with voltage.

[0040] Fig. 2 shows an embodiment of an alternative network system 101 with an alternatively designed controller 102, wherein the network system 101, in a modification of the network system 1 according to Fig. 1, comprises a logic circuit 4 shown by way of example in Fig. 3.

[0041] Fig. 4 describes an embodiment of a method for operating the network system 11 or 111. In this case, a distinction is made between the idle phase described in Fig. 4 (a), the backup phase described in Fig. 4 (b) with a first lock phase and a second lock phase, and the data recovery phase (restore) described in Fig. 4 (c) with the second lock phase and the first lock phase.

[0042] During the idle phase shown in Fig. 4 (a), it is ensured that GPIO1 and GPIO2 do not output any switch signals. This means that in step S1, GPIO1 is set to logic zero (GPIO1 = 0), and in step S2, GPIO2 is set to logic zero (GPIO2 = 0). In this case, both switches RLY1 and RLY2 are open, and the power supply (via voltage source 5) is interrupted for bridge 21 and bridge 22. "Voltage supply" is used here as a synonym for power supply, and "voltage source" is used as a synonym for current source.

[0043] If a data backup is desired (see query in step S3 or "backup?"), the backup phase is started with the first gate phase, as described in Fig. 4 (b). In step S11, GPIO2 is logically set to zero (GPIO2 = 0) and in step S12, GPIO1 is logically set to 1 (GPIO1 = 1). Then, in step S13, data to be backed up from the data network 31 is transferred via the bridge 21 to the buffer / cache 32. The data to be backed up is transferred until a termination condition in step S14 (see "terminate?") is met. This termination condition can mean that all data to be backed up has been transferred to the buffer 32. However, it can also mean that a certain time has been exceeded or a certain amount of data has been reached.

[0044] If the termination condition in step S14 is met, the power supply to the bridge 21 is interrupted by setting GPIO1 to logical zero in step S15 (GPIO1 = 0). This interrupts the power supply to the bridge 21 and switches the bridge 21 off. Subsequently, in step S16, the bridge 22 is switched on or supplied with power by setting GPIO2 to logical 1 (GPIO2 = 1). Then, in step S17, the data stored in the buffer 32 is analyzed for malware and encrypted, and the encrypted data is transferred from the buffer 32 to the backup memory 33 by means of the bridge 22. Alternatively, the encryption and checking for malware can take place before step S16, so that in step S17 only the encrypted data is transferred from the buffer 32 to the backup memory 33 by means of the bridge 22.If the query in step S18 reveals that not all of the data to be backed up from the data network 31 has been transferred (compare the query in step S18 "complete?"), the steps are executed again, beginning with step S11. Otherwise, the network system 11, 111 returns to the idle phase as shown in Fig. 4 (a). If backed up data, which is stored encrypted in the backup memory 33, is to be restored to the data network 31, the network system 11 or 111 transitions to the data restoration phase (restore), beginning with the second lock phase as shown in Fig. 4 (c). For this purpose, it is first ensured in step S21 that the power supply for the bridge 21 is interrupted by setting GPIO1 to logical zero (GPIO1 = 0). Then, the bridge 22 is supplied with power in step S22 by setting GPIO2 to logical 1 (GPIO2 = 1).The encrypted saved data is then transferred from the backup memory 33 to the buffer memory 32 in step S23, and the data transferred to the buffer memory 32 is decrypted. Subsequently, in step S24, GPIO2 is set to logical zero (GPIO2 = 0), i.e., the power supply for the bridge 22 is interrupted. Subsequently, in step S25, GPIO1 is set to logical 1 (GPIO1 = 1), i.e., the power supply interruption for the bridge 21 is lifted. This is followed by a step S26 in which the data to be restored is transferred from the buffer memory 32 to the data network 31 by means of the bridge 21. The transfer can take place in one transfer process as described, or alternatively, in bursts, i.e., divided into several transfer processes.

[0045] Steps S11 and S12, as well as steps S24 and S25, constitute a first lock phase. Steps S15 and S16, as well as steps S21 and S22, constitute a second lock phase.

[0046] The disclosed approach provides a high degree of security for the backup data (i.e., the data in backup memory 33). To further protect the backup data from destruction, the following attack potential must be addressed:

[0047] • Waiting for Bridge 21 to switch.

[0048] • Exploit the Linux system (cache) using an unknown "super exploit" and place malicious code past the encryption.

[0049] Wait for Bridge 22 to switch on. Access data in the backup storage and delete / overwrite files.

[0050] This attack vector only describes a theoretical model and is currently virtually impossible in practice. Compared to the effort required to attack current systems, this attack vector represents a significantly increased effort for the attacker, as the attacker must overcome the first and second gate phases. Thus, the risk of an attack on main memory / backup memory is not actually impossible, but nevertheless very unlikely, as in most cases it is disproportionate to the time / computing / financial resources.

[0051] The HSS (Main SafeStorage), which is part of the cache, achieves the basic goals of ransomware protection. However, several additional challenges arise that can push the HSS (Main SafeStorage) to its processing limits:

[0052] • The amount of data in the initialization phase exceeds an acceptable processing time.

[0053] • The processing volume in systems exceeds the capacity of the data in the 24h cycle (or even shorter cycles).

[0054] • Using parallel HSSs is inefficient, as such a configuration requires multiple HSSs, even though technically only one valid configuration is required. Smart Restoration can cause problems when deploying netboot images, as more than one PXE server within a network would be required via DHCP.

[0055] The system's performance is a limitation in each of the aforementioned points. This particularly applies to the evaluation by the anti-malware software integrated into SafeStorage. Furthermore, unambiguous assignment should be possible in the case of smart restoration. Therefore, it is advantageous to provide only one main SafeStorage (HSS), which assumes the central management point for client configurations, stores the network infrastructure, and thus also implements smart restoration (data recovery). Since the gateway process is reversed in the case of smart restoration, there is no loss of speed. Malware analysis is eliminated when reversing the process and providing the netboot images.

[0056] In an advantageous further embodiment of the system, additional performance is ensured through the use of LMUs (performance module supports). The principle is illustrated in Fig. 5, where reference numerals 53, 54, and 55 denote client networks, such as the data network 32. The HSS 50, in conjunction with the LMUs 51 and 52, replaces the described intermediate memory 32 (also referred to as cache memory), enabling authentication methods with the LMUs 51 and 52 according to the same method as the main system or main SafeStorage (HSS) designated by reference numeral 50. The backdoor process, including the bridge appliance controller, i.e., the bridge control system, is also integrated. This enables a complete backdoor process. An equivalent analysis of malware with equivalent software components takes place on the LMUs.

[0057] The differences between HSSs and LMUs can arise from their responsibilities. Smart restoring, or the restoring of data, for example, takes place only at the HSS, although it may be stipulated that LMUs are not involved in the process. The client database used for authentication may be synchronized in synchronization loops. This occurs, for example, via the internal communication circuit, provided the HSS and an LMU are physically connected in a network (in Fig. 5: connected via Bridge 22 / switch on the left).

[0058] It may be required that an LMU requires the following configuration information:

[0059] • (Fixed) IPv4 address and / or domain

[0060] Bridge appliance switching times of the gateway system • Login data of an LMU on the HSS for synchronizing the client authorization data

[0061] The LMU is 1U high and has no screen. The settings are transmitted via a web panel (bridge control / bridge appliance and cache are separate). During the initial configuration, the client is informed which LMU (domain / IPv4) it should use for initial synchronization and whether this LMU is integrated into the network long-term or is only used for initial data processing. The IPv4 / domain of the HSS is also noted for restoration (applies to restoration levels that do not correspond to PXE boot).

[0062] To ensure higher data transfer rates during the initialization phase, since all data from the entire network must be transferred to backup storage at the beginning, LMUs are issued to the customer by default. The number of initialization LMUs used depends on the amount of data to be processed. Once the initial processing is complete, the LMUs are removed and used for initialization by the next customer. Alternatively, SafeStorage can make the LMUs available to the network long-term using its well-known business models (leasing / purchase / indirect sales). This can also be done retroactively.

[0063] A new scaling for the need for additional LMUs can be achieved in particular by

[0064] • the use of more clients,

[0065] • a shorter backup cycle, or an increasing data flow.

[0066] 1 , 101 Data backup system

[0067] 2, 102 Control

[0068] 3 Bridge control

[0069] 4 Logic circuit

[0070] 5 Voltage source

[0071] 11 , 111 Network system

[0072] RLY1 switch / MOSFET

[0073] RLY2 switch / MOSFET

[0074] 21 Bridge / Switch

[0075] 22 Bridge / Switch

[0076] 31 Data network

[0077] 32 Cache

[0078] 33 backup storage

[0079] 41 first (e.g. non-wireless) data transmission connection (between the first bridge and the data network)

[0080] 42 second (non-wireless) data transmission connection (between the first bridge and the buffer)

[0081] 43 third (non-wireless) data transmission connection (between the buffer and the second bridge)

[0082] 44 fourth (non-wireless) data transmission connection (between the second bridge and the backup storage)

[0083] 50 HSS

[0084] 51 LMU1 / Power Module Support

[0085] 52 LMU2 / Power Module Support 53 Client System 1

[0086] 54 Client System 2

[0087] 55 Client System 3

[0088] 211 Data backup system interface S1 , S2, S11 ,

[0089] S12, S13, S15,

[0090] S16, S17, S21 ,

[0091] S22, S23, S24,

[0092] S25, S26 Step S3, S4, S14,

[0093] S18 query

Claims

Patent claims 1. A data backup system (1, 101) for data to be backed up in a data network (31), wherein the data backup system (1, 101) comprises a backup memory (33), wherein the data backup system (1, 101) further comprises a first bridge (21), a buffer (32), and a second bridge (22), wherein the data backup system (1, 101) and / or the first bridge (21) comprises a data backup system interface (221) for a first data transmission connection (41) for the data connection of the data network (31) and the first bridge (21), wherein the first bridge (21) and the buffer (32) are connected for data purposes by means of a second data transmission connection (42), wherein the buffer (32) and the second bridge (22) are connected for data purposes by means of a third data transmission connection (43),wherein the second bridge (22) and the backup memory (33) are connected for data purposes by means of a fourth data transmission connection (44), wherein the data backup system (1, 101) comprises a controller (2, 102) configured to interrupt a power supply for the first bridge (21) and to interrupt the power supply for the second bridge (22) in such a way that at least the power supply for the first bridge (21) or the power supply for the second bridge (22) is interrupted.

2. Data backup system (1, 101) according to claim 1, characterized in that the controller (2, 102) has a first switch (RLY1) for interrupting the voltage supply for the first bridge (21) by opening the first switch (RLY1).

3. Data backup system (1, 101) according to claim 1 or 2, characterized in that the controller (2, 102) has a second switch (RLY2) for interrupting the voltage supply for the second bridge (22) by opening the second switch (RLY2).

4. Data backup system (1, 101) according to claim 3, characterized in that the controller (2, 102) has a bridge controller (3) for generating a first switch signal for closing the first switch (RLY1) and for generating a second switch signal for closing the second switch (RLY2).

5. Data backup system (101) according to claim 4, characterized in that the data backup system (101) and / or the controller (102) comprises a logic circuit (4) with a first input for the first switch signal and a second input for the second switch signal, wherein the logic circuit (4) comprises a first output and a second output and is designed such that • that the first switch signal is output at the first output, but only if the first switch signal is applied to the first input and the second switch signal is not output at the second output, and / or • that the second switch signal is output at the second output, but only if the second switch signal is applied to the second input and the first switch signal is not output at the first output.

6. Data backup system (1, 101) according to one of the preceding claims, characterized in that the second data transmission connection (42) is designed as an optical fiber or comprises an optical fiber.

7. Data backup system (1, 101) according to one of the preceding claims, characterized in that the third data transmission connection (43) and / or the fourth data transmission connection (44) is designed as an optical fiber or comprises an optical fiber.

8. Network system (11, 111), characterized in that it comprises a data backup system (1, 101) according to one of the preceding claims, a data network (31) and the first data transmission connection (41) between the data network (31) and the first bridge (21) by means of the data backup system interface (211).

9. A method for operating a network system (11, 111) with a backup memory (33), in particular a method for operating a network system (11, 111) according to claim 8, wherein the network system (11, 111) comprises a first bridge (21), a buffer (32) and a second bridge (22), wherein the network system (11, 111) comprises a first data transmission connection (41) for data-technically connecting a data network (31) and the first bridge (21), wherein the first bridge (21) and the buffer (32) are data-technically connected by means of a second data transmission connection (42) of the network system (11, 111), wherein the buffer (32) and the second bridge (22) are data-technically connected by means of a third data transmission connection (43) of the network system (11, 111), and wherein the second bridge (22) and the backup memory (33) are connected to each other by means of a fourth data transmission connection (44) of the network system (11,111 ) are connected., 10. The method according to claim 9, characterized in that data of the data network (31) to be backed up is stored in encrypted form in the backup memory (33).

11. Method according to claim 9, characterized in that data of the data network (31) to be secured are encrypted in the buffer (32), transmitted in encrypted form from the buffer (32) to the backup memory (33) and stored in encrypted form in the backup memory (33).

12. The method according to claim 9, 10 and 11, characterized in that the power supply for the second bridge (22) is interrupted, wherein data of the data network (31) to be backed up is then transferred from the data network to the buffer memory (32), wherein the power supply for the first bridge (21) is then interrupted, wherein the interruption of the power supply for the second bridge (22) is then lifted, wherein the data of the data network (31) to be backed up is then transferred from the buffer memory (32) to the backup memory (33) and stored in the backup memory (33).

13. The method according to claim 12, characterized in that the voltage supply for the second bridge (22) is subsequently interrupted.