Server recovery method and server

A three-tier backup system for dialysis treatment data servers addresses vulnerabilities by enabling rapid recovery from hardware damage and cyberattacks, ensuring quick access to essential treatment information.

JP2026122690APending Publication Date: 2026-07-29NIPRO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
NIPRO CORP
Filing Date
2025-01-16
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Existing systems for managing dialysis treatment data are vulnerable to hardware damage and cyberattacks, leading to potential data loss and tampering, with insufficient methods for rapid server recovery.

Method used

A three-tier backup system comprising a first backup device for system data, a second backup device for network data, and a third backup device for secondary network data, enabling rapid initialization and data restoration of a server using system and data backup data from these devices.

Benefits of technology

Facilitates the rapid recovery of a server storing dialysis treatment data, minimizing data loss and ensuring quick access to critical information for ongoing treatments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026122690000001_ABST
    Figure 2026122690000001_ABST
Patent Text Reader

Abstract

To restore the server storing data related to dialysis treatment as quickly as possible. [Solution] A method for recovering a server that stores data related to dialysis treatment is provided. A first backup device, which is an external storage device for the server, stores system backup data of the server. A second backup device, which can communicate with the server via a network, stores data backup data of the server. A third backup device, which is an external storage device for the second backup device, stores data backup data of the second backup device. Based on the system backup data of the server stored in the first backup device, the server is initialized. Based on the data backup data of the server stored in the third backup device, at least a portion of the data related to dialysis treatment is restored on the initialized server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the recovery of a server that stores data related to dialysis treatment.

Background Art

[0002] Conventionally, for example, as described in Japanese Unexamined Patent Application Publication No. 2024-081324 (Patent Document 1), various data related to dialysis treatment may be managed by a device on a network.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

[0004] On the other hand, dialysis treatment is a coping therapy that is continuously performed for each patient, and information on past dialysis treatment can be used for subsequent dialysis treatment. For example, the real-time blood pressure fluctuations of a patient can be used to consider the necessity of using antihypertensive drugs. In addition, numerical values such as set values and / or the blood pressure of a patient in past dialysis treatment can be used to consider the ultrafiltration rate in the current dialysis treatment. Therefore, information related to dialysis treatment needs to be managed as data on hardware, managed by a server on a network, and appropriately referred to. However, conventionally, in a system that uses data related to dialysis treatment, when the server is down due to a cyberattack or the like, sufficient consideration has not been given to a technique for quickly recovering the server.

Summary of the Invention

Problems to be Solved by the Invention

[0005] This invention was conceived in view of the circumstances described herein, and its purpose is to provide a technology for the early recovery of a server that stores data related to dialysis treatment. [Means for solving the problem]

[0006] A server recovery method according to a certain aspect of this disclosure is a method for recovering a server that stores data relating to dialysis treatment, wherein a first backup device, which is an external storage device for the server, stores system backup data of the server; a second backup device, which is able to communicate with the server via a network, stores data backup data of the server; and a third backup device, which is an external storage device for the second backup device, stores data backup data of the second backup device; the method comprises the steps of: initializing the server based on the system backup data of the server stored in the first backup device; and restoring at least a portion of the data relating to dialysis treatment in the initialized server based on the data backup data of the server stored in the third backup device.

[0007] A server according to a certain aspect of this disclosure is a server constituting a medical system, comprising a processor and storage for storing data relating to dialysis treatment, the medical system comprising a first backup device which is an external storage device to the server, a second backup device which is able to communicate with the server via a network, and a third backup device which is an external storage device to the second backup device, the first backup device being configured to store system backup data of the server, the second backup device being configured to store data backup data of the server, and the third backup device being configured to store data backup data of the second backup device, the processor being configured to perform the steps of initializing the server based on the system backup data of the server stored in the first backup device, and restoring at least a portion of the data relating to dialysis treatment in the initialized server based on the data backup data of the server stored in the third backup device. [Effects of the Invention]

[0008] In accordance with certain aspects of this disclosure, a technology is provided for the early recovery of a server that stores data related to dialysis treatment. [Brief explanation of the drawing]

[0009] [Figure 1] This is a schematic diagram of a medical system according to one embodiment of the present disclosure. [Figure 2] This diagram schematically illustrates the system backup process for the management server 10. [Figure 3] This diagram schematically illustrates the backup process for the NAS server 40. [Figure 4] This diagram schematically shows the initialization process of the management server 10. [Figure 5] This diagram schematically illustrates the data recovery process on the management server 10. [Figure 6] This diagram shows the hardware configuration of the management server 10. [Figure 7] This diagram shows the hardware configuration of the NAS server 40. [Figure 8] This is a flowchart of the system backup process for management server 10. [Figure 9] This is a flowchart of the first backup process. [Figure 10] This is a flowchart of the second backup process. [Figure 11] This is a flowchart of the process for recovering management server 10. [Modes for carrying out the invention]

[0010] The embodiments of this disclosure will be described in detail below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated.

[0011] [System Configuration] Figure 1 is a schematic diagram of a medical system according to one embodiment of the present disclosure. As shown in Figure 1, the medical system includes a management server 10 located in a medical facility. The medical facility is, for example, a hospital or other facility where blood purification therapy is performed. The management server 10 is composed of a server that manages various data related to dialysis treatment, such as DiaCom® manufactured by Nipro Corporation.

[0012] A medical facility is equipped with one or more dialysis machines, as indicated by medical devices 31-33, and the management server 10 can transmit dialysis conditions to each dialysis machine. The management server 10 also stores data related to each patient's dialysis treatment (for example, treatment data for each dialysis treatment, such as the ultrafiltration rate, blood pressure, weight before and after treatment, findings, etc.). In a medical facility, medical personnel such as doctors can access the management server 10 to obtain patient information and, based on that information, determine the content of the patient's current dialysis treatment (ulcer removal rate, prescription of antihypertensive drugs, etc.).

[0013] The medical system of FIG. 1 further includes a storage device 20. The storage device 20 is a storage device for system backup, and is realized, for example, by a USB (Universal Serial Bus) type SSD (Solid State Drive). The storage device 20 constitutes an example of a first backup device.

[0014] The medical system of FIG. 1 further includes a NAS (Network Attached Storage) server 40. The NAS server 40 can communicate with the management server 10 via a network and functions as a storage device for data backup of the management server 10. The NAS server 40 constitutes an example of a second backup device.

[0015] The medical system of FIG. 1 further includes a storage device 50. It is a storage device for backup of the NAS server 40 and is realized, for example, by a USB type HDD (Hard Disk Drive). The storage device 50 constitutes an example of a third backup device.

[0016] [Backup] FIG. 2 is a diagram schematically showing a mode of system backup of the management server 10. FIG. 3 is a diagram schematically showing a mode of backup of the NAS server 40.

[0017] As shown in FIG. 2, in the medical system of the present embodiment, backup data of the system environment (OS (Operating System), applications, etc.) of the management server 10 is stored in the storage device 20 by the system backup of the management server 10. For system backup, in the management server 10, the CPU (Central Processing Unit) executes a backup application program such as DatacloningWizard (manufactured by Fujitsu) stored in an external HDD, generates backup image data, and stores the image data in the storage device 20. In one implementation example, the system backup of the management server 10 is performed immediately before the management server 10 starts operating in the medical system of FIG. 1.

[0018] In the medical system, during the operation of the management server 10, the storage device 20 may be disconnected from the management server 10. Thereby, even when the management server 10 is infected with a virus, the storage device 20 can be prevented from being infected with the virus.

[0019] In the medical system, a plurality of storage devices (storage device 20) for system backup may be prepared, and backup image data may be stored in each of the plurality of storage devices.

[0020] As shown in FIG. 3, in the medical system of the present embodiment, backup data of the NAS server 40 is stored in the storage device 50. More specifically, the NAS server 40 formats the storage device 50 and stores the data for data backup stored in the NAS server 40 in the storage device 50. As the data backup of the management server 10, the data backup of the management server 10 is performed on the NAS server 40 at regular intervals (for example, once a day), and thereby, the backup data of the management server 10 is stored in the NAS server 40 at regular intervals. In one implementation example, the NAS server 40 also stores the backup data stored in the NAS server 40 in the storage device 50 at the above-mentioned regular intervals.

[0021] The frequency of data backups for the management server 10 and the NAS server 40 does not need to be the same. However, if they are the same, the backup data stored in the NAS server 40 can be backed up more reliably by the storage device 50. In particular, if both data backups for the management server 10 and the NAS server 40 are performed at predetermined intervals (for example, every day), it is preferable to configure the NAS server 40 backup to be performed after the data backup of the management server 10. For example, the data backup for the management server 10 may start at 10 p.m. every day, and the backup for the NAS server 40 may start at 11 p.m. every day.

[0022] In one implementation example, the file system of the storage device 50 may be that of a different operating system than the file system of the NAS server 40. More specifically, in a medical system, the file systems of the management server 10, storage device 20, and NAS server 40 are Windows® file systems such as NTFS, while the file system of the storage device 50 is a Linux® file system such as EXT4. Since the NAS server 40 is backed up regularly, it is preferable that the storage device 50 is always connected to the NAS server 40. In this case, if the NAS server 40 is infected with a virus, it is conceivable that not only the data in the NAS server 40 but also the data in the storage device 50 may be overwritten. On the other hand, if the file system of the storage device 50 is a different file system from Windows, the possibility of the data in the storage device 50 being overwritten due to a virus infection can be kept low.

[0023] [restoration] Figure 4 is a schematic diagram illustrating the initialization process of the management server 10. Figure 5 is a schematic diagram illustrating the data restoration process on the management server 10.

[0024] As shown in Figure 4, when the management server 10 is initialized, the storage device 20 is connected to the management server 10. The management server 10 is initialized using the data stored in the storage device 20 during the system backup, thereby restoring the system environment on the management server 10.

[0025] As shown in Figure 5, when restoring data from the management server 10, the storage device 50 is connected to the management server 10. The management server 10 uses the backup data stored in the storage device 50 during the NAS server 40 backup to restore the data stored within the management server 10 (treatment data, shared folders, etc.).

[0026] The management server 10 recovers when its system environment is restored and the data it stored is restored.

[0027] In one implementation example, to initialize the management server 10 and restore data on the management server 10, the CPU 11 executes a recovery application program, such as DatacloningWizard (manufactured by Fujitsu), which is stored on an external HDD.

[0028] [Hardware configuration of management server 10] Figure 6 shows the hardware configuration of the management server 10.

[0029] As shown in Figure 6, the management server 10 includes a CPU 11, an input / output interface (I / F) 12, a communication I / F 13, and storage 14. The storage 14 includes a program area 14A and a data area 14B.

[0030] The CPU 11 is configured to execute programs stored nonvolatilically in the program area 14A, or programs stored in an external storage device. Various parameters used when the program is executed, as well as various data such as patient information, are stored nonvolatilically in the data area 14B.

[0031] Various devices such as input devices (keyboard, mouse, etc.) and displays can be connected to the input / output interface 12. The CPU 11 can acquire information input from the input devices via the input / output interface 12 and display a screen on the display.

[0032] Communication I / F13 allows CPU11 to communicate with external devices. [Hardware configuration of NAS server 40] Figure 7 shows the hardware configuration of the NAS server 40.

[0033] As shown in Figure 7, the NAS server 40 includes a CPU 41, an input / output interface 42, a communication interface 43, and storage 44. The storage 44 includes a program area 44A and a data area 44B.

[0034] The CPU 41 is configured to execute programs stored nonvolatilically in the program area 44A, or programs stored in an external storage device. Various parameters used when the program is executed, as well as various data such as patient information, are stored nonvolatilically in the data area 44B.

[0035] Various devices such as input devices and displays can be connected to the input / output interface 42. The CPU 41 can acquire information input from the input device via the input / output interface 42 and display a screen on the display.

[0036] Communication I / F43 allows CPU41 to communicate with external devices. [Process Flow] Next, referring to Figures 8 to 11, the processes performed during backup and recovery of the management server 10 will be described.

[0037] <System Backup> Figure 8 is a flowchart of the system backup process of the management server 10. In one implementation example, the process in Figure 8 is performed immediately before the management server 10 starts up, and is achieved by the CPU 11 executing a given program (a program for the system backup application). This is performed while the management server 10 is connected to an external HDD and a storage device 20 that have a disk containing the given program installed.

[0038] Referring to Figure 8, in step S10, the CPU 11 starts the system backup application program. More specifically, in response to the external HDD being connected to the management server 10 via the input / output I / F 12, the CPU 11 starts the system backup application program stored on the disk in the external HDD.

[0039] In step S12, the CPU 11 executes a system backup application, which stores the system backup data for the management server 10 in the storage device 20.

[0040] <Data Backup> In this specification, storing backup data from the management server 10 in the NAS server 40 is referred to as "first backup," and storing backup data from the NAS server 40 in the storage device 50 is referred to as "second backup."

[0041] (First backup) Figure 9 is a flowchart of the first backup process. In one implementation example, the process in Figure 9 is achieved by the CPU 11 executing an application program for data backup.

[0042] Referring to Figure 9, in step S20, the CPU 11 retrieves the data backup settings. The data backup settings include a first backup setting and a second backup setting. Each of the first and second backup settings includes the scope of data to be backed up, the frequency to be performed, and the start timing for each of the first and second backups. For example, the first backup setting includes "start daily at 10 p.m." as the backup frequency and start timing, and the second backup setting includes "start daily at 11 p.m." as the backup frequency and start timing.

[0043] In step S20, the user uses an input device to enter data backup settings into the data backup application. The CPU 11 then retrieves these data backup settings.

[0044] In step S22, CPU 11 sends the second backup settings obtained in step S20 to NAS server 40.

[0045] In step S24, the CPU 11 determines whether the backup start time specified in the first backup setting has arrived. The CPU 11 repeats the control in step S24 until it determines that the start time has arrived (NO in step S24), and when it determines that the start time has arrived (YES in step S24), it proceeds to step S26.

[0046] In step S26, the CPU 11 performs the first backup. This stores the data within the range specified in the first backup configuration on the NAS server 40. After that, the CPU 11 returns control to step S24. This repeats the first backup at the frequency (period) specified in the first backup configuration.

[0047] Furthermore, the start timing can be determined by means other than a predetermined frequency. For example, the start timing may be determined when a user inputs a command to start a backup to the management server 10 or the NAS server 40, or when the management server 10 stores more than a certain amount of data to be backed up.

[0048] (Second backup) Figure 10 is a flowchart of the second backup process. In one implementation example, the process in Figure 10 is achieved by the CPU 41 executing an application program for data backup.

[0049] Referring to Figure 10, in step S30, CPU 41 acquires the second backup setting. The second backup setting is sent from CPU 11 to CPU 41 in step S22.

[0050] In step S32, the CPU 41 determines whether the backup start timing specified in the second backup setting has arrived. The CPU 41 repeats the control in step S32 until it determines that the start timing has arrived (NO in step S32), and when it determines that the start timing has arrived (YES in step S32), it proceeds to step S34.

[0051] In step S34, the CPU 41 performs a second backup. This stores data within the range specified in the second backup settings into the storage device 50. After that, the CPU 41 returns control to step S34. This repeats the second backup at the frequency (period) specified in the second backup settings.

[0052] Furthermore, the start timing can be determined by means other than a predetermined frequency. For example, the start timing may be determined to have arrived after a certain amount of time has elapsed since the start of the first backup. In other words, the NAS server 40 may be configured to start the second backup in accordance with the timing of the first backup.

[0053] In one implementation example, data is stored on the NAS server 40 using a Windows file system, and on the storage device 50 using a Linux file system. In the second backup, the data in the Windows file system is converted to data in the Linux file system before being stored on the storage device 50.

[0054] <Recovery> Figure 11 is a flowchart of the process for recovering the management server 10. In one implementation example, the process in Figure 11 is performed when recovery of the management server 10 is required due to a virus infection or hardware failure, etc., and is achieved by the CPU 11 executing a given program (a recovery application program), and is performed when the management server 10 is connected to an external HDD and storage device 50 with a disk containing the given program installed. In another implementation example, the process in Figure 11 may be started when the external HDD with the disk installed is connected to the management server 10.

[0055] Referring to Figure 11, in step S40, the CPU 11 starts the recovery application program in response to instructions from the user. More specifically, in response to the external HDD being connected to the management server 10 via the input / output I / F 12, the CPU 11 starts the recovery application program stored on the disk within the external HDD.

[0056] In step S42, the CPU 11 initializes the management server 10. This restores the system environment on the management server 10.

[0057] In step S44, the CPU 11 launches an application (such as "Linux File Systems for Windows by Paragon Software" from Paragon Software Inc.) to decrypt the files stored in the storage device 50, in response to instructions from the user.

[0058] In step S46, the CPU 11 uses the data stored in the storage device 50 to restore the data on the management server 10. As a result, the management server 10 recovers.

[0059] In one implementation example, data is stored in a Windows file system on the management server 10, storage device 20, and NAS server 40, while data is stored in a Linux file system on storage device 50. The CPU 11 uses the file reader application launched in step S44 to decode the data stored in storage device 50, and processes the decoded data on a recovery application to recover it on the management server 10. After that, the CPU 11 terminates the process shown in Figure 11. Note that if data is also stored in a Windows file system on storage device 50, step S44 may be omitted.

[0060] In one implementation example, the NAS server 40 stores the treatment data for each day as data backup data for the management server 10, and the storage device 50 stores the treatment data for each day as data backup data for the NAS server 40. If the data from one and two days prior is corrupted on the NAS server 40, but the data from three days prior is backed up successfully, then similarly, even if the data from one and two days prior is corrupted on the storage device 50, the data from three days prior is backed up successfully. In the medical system, when the management server 10 is restored, the storage device 20 is used for system recovery and the storage device 50 is used for data recovery, allowing the management server 10 to be restored to its state from three days prior in a short time. That is, in step S46, at least a portion of the dialysis treatment data stored on the management server 10 is restored.

[0061] In a medical system, if data in the management server 10 is corrupted, attempting to initialize the management server 10 and restore the data through user input without using storage devices 20 and 50 would require several days. On the other hand, if storage devices 20 and 50 are used to initialize the management server 10 and restore the data, the management server 10 can be restored in a few hours.

[0062] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of this disclosure is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. Furthermore, each technology in the embodiments is intended to be practiced individually or, as far as possible, in combination with other technologies in the embodiments. [Explanation of Symbols]

[0063] 10 management servers, 20, 50 storage devices, 31, 32, 33 medical devices, 40 NAS servers.

Claims

1. A method for recovering a server that stores data related to dialysis treatment, The first backup device, which is an external storage device for the server, stores the system backup data of the server. A second backup device, which can communicate with the aforementioned server via a network, stores the data backup data of the aforementioned server. The third backup device, which is an external storage device for the second backup device, stores the data backup data of the second backup device. A step of initializing the server based on the system backup data of the server stored in the first backup device, A server recovery method comprising the step of restoring at least a portion of the data relating to the dialysis treatment on the initialized server based on the data backup of the server stored in the third backup device.

2. The server recovery method according to claim 1, wherein the file system of the third backup device is a file system of an operating system different from the operating system of the server's file system.

3. The second backup device stores the data backup data of the server at predetermined intervals. The server recovery method according to claim 1 or claim 2, further comprising the step of storing the data backup data of the second backup device in the third backup device at predetermined intervals.

4. The server recovery method according to claim 3, wherein, after storing the data backup data of the server in the second backup device at predetermined intervals, the data backup data of the second backup device is stored in the third backup device.

5. A server that constitutes a medical system, Processor and Includes storage for storing data related to dialysis treatment, The aforementioned medical system, A first backup device which is an external storage device for the server, A second backup device that can communicate with the aforementioned server via a network, The system includes a third backup device which is an external storage device for the second backup device, The first backup device is configured to store system backup data of the server, The second backup device is configured to store data backup data for the server, The third backup device is configured to store the data backup data of the second backup device. The aforementioned processor, A step of initializing the server based on the system backup data of the server stored in the first backup device, A server configured to perform the steps of: restoring at least a portion of the data relating to the dialysis treatment in the initialized server based on the data backup of the server stored in the third backup device.