Data backup system

The data backup system uses a controller to manage bridge power supply and secure data transfer through intermediate and backup storage, addressing vulnerabilities and enhancing security and ease of use.

JP2026516819APending Publication Date: 2026-05-26TF IND GMBH

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TF IND GMBH
Filing Date
2024-04-26
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing data backup systems lack robust protection against operation and are vulnerable to external attacks during data backup and recovery, necessitating improved security and ease of use.

Method used

A data backup system with a controller that manages power supply to bridges using MOSFET switches, ensuring secure data transfer through intermediate storage and backup storage, employing optical waveguides for communication, and implementing a locking mechanism to prevent simultaneous bridge activation.

Benefits of technology

The system provides enhanced security by preventing simultaneous bridge activation, minimizing external attacks, and ensuring secure data transfer and recovery, while maintaining ease of use and reducing the risk of malware damage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026516819000001_ABST
    Figure 2026516819000001_ABST
Patent Text Reader

Abstract

The present invention relates to a data backup system (1, 101) for backing up data from a data network (31). The data backup system (1, 101) includes backup storage (33), and further includes a first bridge (21), intermediate storage (32), and a second bridge (22). The data backup system (1, 101) and / or the first bridge (21) include a data backup system interface (221) for a first data communication connection (41) for directly or indirectly connecting the data network (31) and the first bridge (21) for data communication. The first bridge (21) and the intermediate storage (32) utilize the second data communication connection (42) to back up data. The intermediate storage (32) and the second bridge (22) are connected for data communication using a third data communication connection (43), and the second bridge (22) and the backup storage (33) are connected for data communication using a fourth data communication connection (44). The data backup system (1, 101) includes a controller (2, 102) configured to cut off the power supply to the first bridge (21) and the power supply to the second bridge (22) such that at least the power supply to the first bridge (21) or the power supply to the second bridge (22) is cut off.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a data backup system. The present invention further relates to a network system including the data backup system. The present invention further relates to a method of operating the network system.

Background Art

[0002] For example, in Non-Patent Document 1, a data backup system is disclosed.

[0003] Patent Document 1 discloses a device for limiting or interrupting current in an electric circuit and a control method therefor. This device includes a current interruption branch and a bridge branch. This bridge branch includes two bridge arms formed by four identical current rectifying branches. Two of the four current rectifying branches are connected in series, and the two formed bridge arms are connected in parallel. Both of the two bridge arms are connected in parallel to the current interruption branch, and the midpoints of the two bridge arms are separately connected to two points of this circuit. Each current rectifying branch includes at least one high-speed interruption switch and at least one bidirectional power semiconductor switch, which are connected in series with each other. This device can switch off bidirectional current.

[0004] Patent Document 2 discloses a backup device that enables removing a primary server from a network and connecting a secondary server regardless of the type of failure occurring in the network. This is achieved by providing means for interrupting the power supply to the primary server.

[0005] Patent Document 3 discloses a method of operating a bus system including a first network node (MASTER) and at least one second network node (SLAVE). Power is supplied to the at least one second network node (SLAVE), and a first line (BUS) and a second line (GND) are provided for communication between the first network node (MASTER) and the at least one second network node (SLAVE). Communication between the first network node (MASTER) and the at least one second network node (SLAVE) and power supply to the at least one second network node (SLAVE) are each performed via the first line (BUS) and are performed at different times from each other.

Prior Art Documents

Non-Patent Documents

[0006]

Non-Patent Document 1

Patent Documents

[0007]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0008] The present invention aims to embody a data backup system that is particularly well protected against operation, or to improve data backup in network systems. It is desirable to achieve ease of use and minimize the risk of external attacks during data backup and data recovery. [Means for solving the problem]

[0009] The above objectives are solved by a data backup system for a data network (a base network also known as a LAN (e.g., a corporate network)). This data backup system includes backup storage (in particular for storing data from the data network), and the data backup system further includes a first bridge (including a lock or flow gate), intermediate storage, and a second bridge. The data backup system and / or the first bridge includes a data backup system interface for a first data communication connection for direct or indirect data communication between the data network and the first bridge. The first bridge and the intermediate storage device are connected for data communication using a second data communication connection. The intermediate storage and the second bridge are connected for data communication using a third data communication connection. The second bridge and backup memory are connected for data communication using a fourth data communication connection. The data backup system includes a controller configured to shut off the power supply to the first bridge and the power supply to the second bridge, thereby (intentionally) shutting off the power supply to at least the first bridge or the second bridge.

[0010] In this disclosure, "bridge" may mean a switch. In this disclosure, "bridge" can be understood as connecting two segments at Layer 2 (Data Link Layer) of the OSI model in a computer network. In this disclosure, "bridge" may optionally mean a device configured to operate at the MAC sublayer or LLC sublayer. In this disclosure, "bridge" may mean a MAC bridge. In this disclosure, "bridge" may mean an LLC bridge. In this disclosure, "bridge" may mean a transparent bridge. In this disclosure, "bridge" may mean a source routing bridge. In this disclosure, "bridge" may mean a coupling element in a computer network. In this disclosure, "bridge" may mean a switch that ensures data packets known as "frames" reach their destination within a segment (broadcast domain). In this disclosure, "bridge" may generally mean a switch that performs forwarding based on information from the Data Link Layer (Layer 2) of the OSI model. In this disclosure, "bridge" may mean a bridging hub. In this disclosure, "bridge" may mean a switching hub. In this disclosure, "bridge" can mean a fiber optic LAN converter that can be used in the same way as a switch, in which case the fiber optic connection can be connected externally or internally (from the converter to the cache) via optical bridging.

[0011] In one advantageous embodiment of the present invention, the controller includes a first switch for interrupting the power supply to a first bridge by opening the first switch. In this disclosure, the first switch means, in particular, a MOSFET. In this disclosure, the first switch means, in particular, a switch that is open when no power supply is provided. In this disclosure, the first switch may mean a control board having a function comparable to a MOSFET and implementing additional control instances such as ICs.

[0012] The controller may include a bridge controller (e.g., a Raspberry Pi microcontroller), also known as a bridge device. This bridge controller controls a group of MOSFETs via their GPIO pins to supply voltage to the gates. When there is voltage at the gates, the source voltage (e.g., 5V) is switched, and the bridge or switch becomes active. Switching the bridge or switch creates a physical connection between all the lines connected to the bridge / switch. Intermediate storage / cache can be a storage device that receives and transfers data, provided that the appropriate bridge is switched.

[0013] In another advantageous embodiment of the present invention, the controller includes a second switch for interrupting the power supply to a second bridge by opening the second switch. In this disclosure, the second switch means, in particular, a MOSFET. In this disclosure, the second switch means, in particular, a switch that is open when no power is supplied. In this disclosure, the second switch may also mean a control board that includes a function comparable to that of a MOSFET and implements additional control instances such as ICs.

[0014] In this disclosure, interruption of power supply means, in particular, a physical interruption.

[0015] In another advantageous embodiment of the present invention, a bridge controller is provided to generate a first switch signal for closing a first switch and a second switch signal for closing a second switch. The controller includes a bridge controller. In another advantageous embodiment of the present invention, the data backup system includes a logic circuit having a first input for the first switch signal and a second input for the second switch signal. The logic circuit has a first output and a second output, configured such that the first switch signal is output to the first output unless the second switch signal is output at the second output, and the second switch signal is output to the second output if the second switch signal is input at the second input and the first switch signal is not output at the first output.

[0016] In this disclosure, the second data communication connection and / or the third data communication connection and / or the fourth data communication connection means a wired data communication connection. In this disclosure, a wired data communication connection means, in particular, a data communication connection in which “data carrier” signals are transmitted through a solid material.

[0017] In another advantageous embodiment of the present invention, the first data communication connection is configured as an optical waveguide, or includes an optical waveguide.

[0018] In another advantageous embodiment of the present invention, the second data communication connection is configured as an optical waveguide or includes an optical waveguide. In another advantageous embodiment of the present invention, the third data communication connection and / or the fourth data communication connection is configured as an optical waveguide or includes an optical waveguide.

[0019] In this disclosure, optical waveguide (OWG) means, for example, a fiber optic cable (OFC). In this disclosure, optical waveguide (OWG) means, for example, a cable and wire composed of optical waveguides and partially incorporating plug connectors for transmitting light. Light is guided, for example, through a quartz glass fiber or a plastic fiber (polymer optical fiber). These are often called fiber optic cables, which typically consist of multiple optical fibers bundled together and mechanically reinforced, or can be mechanically reinforced, to protect and stabilize each optical fiber. They can be single-mode or multimode.

[0020] From a physical standpoint, in this disclosure, optical fiber means, for example, a dielectric waveguide. They consist of, for example, several concentric layers, with the optical core located, for example, in the center, and the optical core is surrounded, for example, by a cladding layer with a slightly lower refractive index and, for example, a further protective layer of plastic. Depending on the application, the diameter of the core can range, for example, from a few micrometers to 1 mm. Optical fibers are distinguished, for example, by the refractive index gradient between the core and the cladding layer (step-index or gradient-index optical fiber) and the number of propagation modes limited by the core diameter.

[0021] The above objectives can also be achieved by a network system including a data backup system, for example, a data backup system that includes one or more of the above features. This network system includes a data network and a first data communication connection between the data network and a first bridge that utilizes a data backup system interface.

[0022] The above object is further solved by a method of operating a network system together with a backup storage, particularly by a method of operating a network system including the above characteristics. This network system includes a first bridge (including a lock), an intermediate storage, and a second bridge. This network system includes a first data communication connection that connects the data network and the first bridge for data communication. The first bridge and the intermediate storage are connected using a second data communication connection of the network system for data communication. The intermediate storage and the second bridge are connected by a third data communication connection of the network system for data communication. And the second bridge and the backup storage are connected by a fourth data communication connection of the network system for data communication. Particularly, the data of the data network to be backed up is transferred from the data network to the intermediate storage.

[0023] In an advantageous embodiment of the present invention, the data to be backed up (from the data network) is configured to be stored in the backup storage in an encrypted form. In another advantageous embodiment of the present invention, the data to be backed up is encrypted in the intermediate storage, transferred from the intermediate storage to the backup storage in an encrypted form, and stored in the backup storage in an encrypted form.

[0024] In another advantageous embodiment of the present invention, the power supply to the second bridge is cut off. Then, the data to be backed up is transferred from the data network to the intermediate storage. Then, the power supply to the first bridge is cut off. Then, the power supply cut-off to the second bridge is released. Then, the data to be backed up is transferred from the intermediate storage to the backup storage and stored in the backup storage. In another advantageous embodiment of the present invention, the power supply to the second bridge is cut off.

[0025] In one advantageous embodiment of the present invention, the power supply to the second bridge is uncut in order to restore the data backed up using the backup storage. In another advantageous embodiment of the present invention, the backed-up data is transferred from the backup storage to the intermediate storage and decrypted as necessary. Subsequently, in another advantageous embodiment of the present invention, the power supply to the second bridge is cut off.

[0026] In one advantageous embodiment of the present invention, the power supply to the first bridge is released. In another advantageous embodiment of the present invention, protected data is transferred from intermediate storage to a data network. In this case, in another advantageous embodiment of the present invention, the power supply to the first bridge is cut off.

[0027] The two bridges, in conjunction with the intermediate storage, form a lock or implement a locking function. When the power supply to the second bridge is released, the power supply to the first bridge is also released, and when the power supply to the first bridge is released, the power supply to the second bridge is also released. This makes it impossible to switch both bridges simultaneously at any given time.

[0028] Furthermore, the circuit board can also prevent both locks, i.e., both bridges, from opening simultaneously in the event of a hardware failure.

[0029] Advantageously, the bridge controller (a bridge device that uses GPIO to control the appropriate bridge) is not connected by connectors to intermediate storage / cache or other modules. Instead, advantageously, the bridge controller operates independently, thereby completely preventing unwanted external access. Advantageously, switching times and other parameters can only be configured and edited by directly accessing the bridge controller.

[0030] The above measures ensure that it is not possible to switch both bridges at any point. A first locking phase and a second locking phase are distinguished. The first locking phase relates to the case where data from the data network (hereinafter also called "LAN") should be given to intermediate storage (hereinafter also called "cache"). In this case, the bridge controller (bridge device (manager)) turns on the first bridge so that it is powered. From this point on, the LAN is "connected" to the cache. This allows data to be transferred to the cache. This can continue until the bridge controller or bridge device turns off the first bridge again, that is, until the first bridge is disconnected from the power. From this point on, the data in the cache is analyzed. This means that malware is analyzed and finally encrypted (symmetric encryption).

[0031] In the second locking phase, data can be transferred from the cache to the backup storage using a standardized, supported protocol (such as FTP / SMB / NFS) for the backup storage / backup server. Again, this is done only within the framework specified by the bridge controller / bridge device. All data or content transferred to the backup storage / backup server is encrypted without exception. This means that malicious code cannot damage main memory without knowing the key (used for encryption), because encrypted malicious code cannot be executed.

[0032] The options for bridge control / bridge device configuration are intentionally very limited. To ensure ease of use and minimize the risk of security incidents, only a switching schedule can be set. Furthermore, to avoid compromising system security without legitimate reason, the duration and / or number of time intervals are also limited. It is also possible to reverse the switching process and recover data. This also means that the number of end devices on the transmitting side is limited. Certain processes in the cache require computational power, which is time-dependent and also limits the number of end devices.

[0033] In addition to the normal operation of the backup function, the bridge device can also be set to restore mode. In this restore mode, data is periodically reloaded into intermediate storage and then transferred from there to the corresponding terminal devices on the LAN. Here, the locking principle is completely reversed. Only the intermediate storage is responsible for loading / encrypting the data and decrypting / analyzing it.

[0034] Further advantages and details will become clear by reading the description of the embodiments below. [Brief explanation of the drawing]

[0035] [Figure 1] This shows an embodiment of the network system. [Figure 2] This shows an embodiment of an alternative network system. [Figure 3] An embodiment of a logic circuit is shown. [Figure 4] Figure 1 shows an embodiment of how to operate a network system. [Figure 5] This document illustrates an embodiment of a modified method for operating a network system. [Modes for carrying out the invention]

[0036] Figure 1 shows an example of a network system 11 that includes a data network 31 and a data backup system 1 for the data network 31. The data backup system 1 includes backup storage 33 for storing data from the data network 31. The data backup system 1 further includes a bridge 21, intermediate storage 32, and bridge 22. The network system 11 includes a first data communication connection 41, which is particularly wired, for connecting the data network 31 to bridge 21 for data communication, and bridge 21 includes a data backup system interface 211 for implementing the data communication connection 41.

[0037] Bridge 21 and intermediate storage 32 are connected for data communication, particularly using a second data communication connection 42, which is wired. The second data communication connection 42 may be configured as an optical waveguide and may also include an optical waveguide. Intermediate storage 32 and bridge 22 are connected for data communication, particularly using a third data communication connection 43, which is wired. The third data communication connection 43 may be configured as an optical waveguide and may also include an optical waveguide. Bridge 22 and backup storage 33 are connected for data communication, particularly using a fourth data communication connection 44, which is wired. The fourth data communication connection 44 may be configured as an optical waveguide and may also include an optical waveguide.

[0038] No special technical requirements are needed for data networks (e.g., LAN networks) or backup storage. The operating systems of end devices within the data network 31 or LAN and backup storage 33 support only (network) sockets as defined in RFCs, for example.

[0039] The power of bridge 21 and bridge 22 is supplied by the voltage source 5.

[0040] The data backup system 1 includes a controller 2 configured to cut off the power supply to bridge 21 and to bridge 22, thereby cutting off the power supply to at least bridge 21 or bridge 22. For this purpose, the controller 2 includes a switch RLY1 configured as a MOSFET and a switch RLY2 configured as a MOSFET. Switch RLY1 is configured to cut off the power supply to bridge 21 by opening it and cutting off the line between bridge 21 and the voltage source 5, and switch RLY2 is configured to cut off the power supply to bridge 22 by opening it and cutting off the line between bridge 22 and the voltage source 5. The bridge controller 3 or bridge device (e.g., Raspberry Pi, microcontroller) controls switches RLY1 and RLY2, which are designed as MOSFETs, via the GPIO group of the bridge controller 3, and supplies them with gate voltages, which are here called switch signals. When a voltage is applied to the gate of each MOSFET, a voltage is applied to the bridge assigned to that MOSFET.

[0041] Figure 2 shows an example of an alternative network system 101 that includes controllers 102 configured in an alternating manner. This network system 101, in contrast to network system 1 in Figure 1, includes logic circuits 4, which are shown as an example in Figure 3.

[0042] Figure 4 shows an example of how to operate the network system 11 or 111. It is distinguished between the idle phase shown in Figure 4(a), the backup phase including the first and second locking phases shown in Figure 4(b), and the data recovery (restore) phase including the second and first locking phases shown in Figure 4(c).

[0043] In the idle phase as shown in Figure 4(a), it is ensured that GPIO1 and GPIO2 do not output switch signals. That is, in step S1, GPIO1 is set to logic zero (GPIO1=0), and in step S2, GPIO2 is set to logic zero (GPIO2=0). In this case, both switches RLY1 and RLY2 are open, and the power supply to bridges 21 and 22 (via voltage source 5) is cut off. Here, power supply is used as a synonym for current supply, and voltage source is used as a synonym for current source.

[0044] If data backup is desired (comparison query in step S3, i.e., "backup"), the backup phase begins from the first locking phase, as shown in Figure 4(b). In step S11, GPIO2 is set to logical zero (GPIO2=0), and in step S12, GPIO1 is set to logical one (GPIO1=1). Then, in step S13, the data to be backed up from the data network 31 is transferred to the intermediate storage / cache 32 via the bridge 21. The data to be backed up is transferred until the termination condition ("termination" comparison) in step S14 is met. This termination condition may mean that all the data to be backed up has been transferred to the intermediate storage 32. However, it may also mean that a certain amount of time has passed or that a certain amount of data has been reached.

[0045] If the termination condition in step S14 is met, power to bridge 21 is cut off in step S15 by logically setting GPIO1 to zero (GPIO1=0). This cuts off power to bridge 21, and bridge 21 turns off. Then, in step S16, bridge 22 is turned on, i.e., power is supplied to bridge 22, by logically setting GPIO2 to 1 (GPIO2=1). Then, in step S17, the data stored in intermediate storage 32 is analyzed to see if it contains malware, encrypted, and the encrypted data is transferred from intermediate storage 32 to backup storage 33 via bridge 22. Alternatively, encryption and malware checks can be performed before step S16, so that in step S17, only encrypted data is transferred from intermediate storage 32 to backup storage 33 via bridge 22. If the query in step S18 (comparison query in step S18 "Complete?") reveals that not all data to be backed up has been transferred from data network 31, the steps starting from step S11 are repeated. Otherwise, network systems 11, 111 return to the idle phase according to Figure 4(a).

[0046] When restoring backup data stored in an encrypted form in the backup storage 33 on the data network 31, the network system 11 or 111 enters the data restoration phase (restore) starting from the second locking phase, according to Figure 4(c). To do this, first, in step S21, power to the bridge 21 is cut off by setting GPIO1 to logical zero (GPIO1=0). Then, in step S22, power is supplied to the bridge 22 by setting GPIO2 to logical 1 (GPIO2=1). In step S23, the encrypted backup data is transferred from the backup storage 33 to the intermediate storage 32, and the data transferred to the intermediate storage 32 is decrypted. Then, in step S24, GPIO2 is set to logical zero (GPIO2=0), that is, power to the bridge 22 is cut off. Then, in step S25, GPIO1 is set to logical 1 (GPIO1=1), that is, power to the bridge 21 is released. In the subsequent step S26, the data to be restored is transferred from the intermediate storage 32 to the data network 31 via the bridge 21. This transfer can be performed in a single transfer process as described above, or it can be performed in batches, i.e., divided into several transfer processes.

[0047] Steps S11 and S12, and steps S24 and S25, form a first locking stage. Steps S15 and S16, and steps S21 and S22, form a second locking stage.

[0048] The procedures disclosed here provide a high level of security for backup data (i.e., data in backup storage 33). To further strengthen protection of backup data from destruction, the following potential attacks must be addressed.

[0049] - Wait until Bridge 21 switches over - This attack exploits an unknown "superexploit" to target Linux systems (caches) and insert malicious code that bypasses encryption. - Wait until bridge 22 switches over. - Allows access to data in backup storage and enables deletion / overwriting of files.

[0050] This attack scenario describes only a theoretical model and is practically impossible at present. Compared to the effort required to attack the current system, this attack scenario would require a very large effort from the attacker because the attacker would need to overcome the first and second locking stages. Therefore, while the risk of attacking main memory / backup memory is not impossible, the likelihood of it occurring is very low because, in most cases, the rewards would not be proportional to the time, computation, and economic resources required.

[0051] The Main SafeStorage (HSS), a part of the intermediate storage, achieves the basic purpose of protection against ransomware. However, this can lead to various challenges, such as the possibility of the HSS reaching its processing limits. - The amount of data during the initialization phase exceeds the acceptable processing time. - The system's processing load exceeds the data capacity for a 24-hour cycle (or a shorter cycle).

[0052] Using parallel HSSs is inefficient because, while technically only one valid configuration is needed, such configurations require different HSSs. Smart Restore can encounter problems with netboot image provisioning because it requires specifying multiple PXE servers on the network via DHCP.

[0053] System performance is a limiting factor in each of the above items. This is especially true when evaluating the anti-malware software integrated into SafeStorage. Also, in the case of smart recovery, unique assignment must be possible. Therefore, it is advantageous to have only one main SafeStorage (HSS). This acts as a central management point for client configuration, remembers the network infrastructure, and thereby also implements smart recovery (data recovery). In the case of smart recovery, the locking process is reversed, so there is no decrease in speed. If the process is reversed and a netboot image is provided, malware analysis is not required.

[0054] In designing another advantageous system, the use of LMU (Performance Module Support) ensures improved performance. The principle is illustrated in Figure 5. In Figure 5, reference numbers 53, 54, and 55 represent client networks such as the data network 32. HSS 50 works in conjunction with LMUs 51 and 52 to replace the intermediate storage 32 (also called cache or cache memory). Authentication by LMUs 51 and 52 is enabled using the same method as the main system, or the same method as the main SafeStorage (HSS) to which reference number 50 is assigned. A locking procedure with a bridge device controller, i.e., bridge control, is also incorporated. This enables a complete locking procedure. Equivalent malware analysis by equivalent software components is performed in the LMU.

[0055] The differences between HSS and LMU may stem from their respective areas of responsibility. For example, smart restore, i.e., data recovery, might be performed solely by the HSS, with the LMU not involved in this process. The client database used for authentication might also be handled within a synchronization loop. This occurs when the HSS and LMU are physically connected on the network, for example, through an internal communication circuit (connected by bridge 22 / switch on the left side of Figure 5).

[0056] The following configuration information may be required for an LMU: - (Fixed) IPv4 address and / or domain - Switching time for bridged equipment in the locking system - LMU login data in HSS for synchronizing client authentication data

[0057] The LMU is 1U tall and has no screen. Configuration is sent via a web panel (separately for bridge control / bridge device and intermediate storage / cache). In the initial configuration, the client records which LMU (domain / IPv4) should be used for initial synchronization, and whether this LMU will be integrated into the network long-term or used only for initial data processing. The HSS's IPv4 / domain is also recorded for recovery (applied if the recovery stage does not support PXE boot).

[0058] To ensure higher data transfer rates during the initialization phase, LMUs are issued to customers as standard, because all data across the entire network needs to be initially transferred to backup storage. The number of initialization LMUs used varies depending on the amount of data being processed. Once the initial processing is complete, the LMUs are removed and used for initialization at the next customer's site. Alternatively, SafeStorage can make LMUs available to the network long-term using common business models (lease / purchase / indirect sale), and this can also be done retroactively.

[0059] The need for additional LMUs justifies scaling up further, particularly for the following reasons: - More clients using our services, - Shorten the backup cycle, or - Increase in data stream [Explanation of Symbols]

[0060] 1. 101 Data Backup System 2, 102 controllers 3 Bridge Controller 4. Logic Circuits 5 Power supply 11, 111 Network Systems RLY1 Switch / MOSFET RLY2 Switch / MOSFET 21 Bridge / Switch 22 Bridge / Switch 31 Data Networks 32 Intermediate Storage / Cache 33 Backup Storage 41. First data communication connection (e.g., wired) between the first bridge and the data network. 42. Second (wired) data communication connection (between the first bridge and intermediate storage) 43. A third (wired) data communication connection (between the intermediate storage and the second bridge) 44. A fourth (wired) data communication connection (between the second bridge and backup storage) 50 HSS 51 LMU1 / Power Module Support 52 LMU2 / Power Module Support 53 Client System 1 54 Client System 2 55 Client System 3 211 Data Backup System Interface S1, S2, S11, S12, S13, S15, S16, S17, S21, S22, S23, S24, S25, S26 Step S3, S4, S14, S18 Inquiry

Claims

1. A data backup system (1, 101) for backing up data from a data network (31), The aforementioned data backup system (1, 101) includes backup storage (33), The data backup system (1, 101) further includes a first bridge (21), intermediate storage (32), and a second bridge (22), The data backup system (1, 101) and / or the first bridge (21) includes a data backup system interface (221) for a first data communication connection (41) for connecting the data network (31) and the first bridge (21) for data communication. The first bridge (21) and the intermediate storage (32) are connected for data communication using a second data communication connection (42). The intermediate storage (32) and the second bridge (22) are connected for data communication using a third data communication connection (43). The second bridge (22) and the backup storage (33) are connected for data communication using a fourth data communication connection (44). The data backup system (1, 101) includes a controller (2, 102) configured to interrupt the power supply to the first bridge (21) and the power supply to the second bridge (22) so as to interrupt at least the power supply to the first bridge (21) or the power supply to the second bridge (22). Data backup system (1, 101).

2. The controller (2, 102) includes a first switch (RLY1) which, when opened, cuts off the power supply to the first bridge (21). The data backup system (1, 101) according to claim 1.

3. The controller (2, 102) includes a second switch (RLY2) which, when opened, cuts off the power supply to the second bridge (22). A data backup system according to claim 1 or 2 (1, 101).

4. The controller (2, 102) includes a bridge controller (3) that generates a first switch signal for closing the first switch (RLY1) and a second switch signal for closing the second switch (RLY2). The data backup system (1, 101) according to claim 3.

5. The data backup system (101) and / or the controller (102) includes a logic circuit (4) which includes a first input for the first switch signal and a second input for the second switch signal. The logic circuit (4) includes a first output and a second output, The logic circuit (4) is The first switch signal is output at the first output only when the first switch signal is input to the first input and the second switch signal is not output to the second output, and / or The second switch signal is output at the second output only when the second switch signal is input to the second input and the first switch signal is not output at the first output. It is configured so that this happens. The data backup system (101) according to claim 4.

6. The second data communication connection (42) is configured as an optical waveguide, or includes an optical waveguide. A data backup system according to any one of claims 1 to 5 (1, 101).

7. The third data communication connection (43) and / or the fourth data communication connection (44) are configured as optical waveguides, or include optical waveguides. A data backup system according to any one of claims 1 to 6 (1, 101).

8. A data backup system (1, 101) according to any one of claims 1 to 7, The aforementioned data network (31) and, The first data communication connection (41) between the data network (31) and the first bridge (21) that utilizes the data backup system interface (211), Network systems including (11, 111).

9. A method for operating a network system (11, 111) using backup storage (33), and in particular, a method for operating a network system (11, 111) as described in claim 8, The aforementioned network system (11, 111) includes a first bridge (21), intermediate storage (32), and a second bridge (22), The network system (11, 111) includes a first data communication connection (41) for connecting a data network (31) and the first bridge (21) for data communication. The first bridge (21) and the intermediate storage (32) are connected for data communication using the second data communication connection (42) of the network system (11, 111). The intermediate storage (32) and the second bridge (22) are connected for data communication using the third data communication connection (43) of the network system (11, 111). The second bridge (22) and the backup storage (33) are connected for data communication using the fourth data communication connection (44) of the network system (11, 111). method.

10. The data from the data network (31) to be backed up is stored in the backup storage (33) in an encrypted form. The method according to claim 9.

11. The data from the data network (31) to be backed up is encrypted in the intermediate storage (32), transferred from the intermediate storage (32) to the backup storage (33) in an encrypted form, and stored in the backup storage (33) in an encrypted form. The method according to claim 9.

12. The power supply to the second bridge (22) is cut off, Subsequently, the data to be backed up in the data network (31) is transferred from the data network to the intermediate storage (32). Subsequently, the power supply to the first bridge (21) is cut off. Subsequently, the interruption of the power supply to the second bridge (22) is released. Subsequently, the data of the data network (31) to be backed up is transferred from the intermediate storage (32) to the backup storage (33) and stored in the backup storage (33). The method according to any one of claims 9 to 11.

13. After the transfer and storage of the data of the data network (31) to be backed up, the power supply to the second bridge (22) is cut off. The method according to claim 12.