Data control device and data control method

The data control device uses snapshots to efficiently restore volumes by determining the target restoration point, addressing the inefficiencies in existing cloud backup restoration methods.

JP7833583B2Active Publication Date: 2026-03-19HITACHI VANTARA LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2026-03-19

AI Technical Summary

Technical Problem

Existing data restoration methods from cloud backups, particularly incremental backups, require sequential retrieval and processing of multiple generations, leading to increased data transfer and processing time, without an efficient method for easy and appropriate volume restoration.

Method used

A data control device connected to a cloud system with an object store that backs up backup data as objects, utilizing snapshots to determine the target restoration point and restore volumes efficiently using the snapshot.

Benefits of technology

Enables easy and appropriate restoration of volumes by leveraging snapshots to streamline the data retrieval process, reducing the amount of data to be transferred and processing time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007833583000001
    Figure 0007833583000001
  • Figure 0007833583000002
    Figure 0007833583000002
  • Figure 0007833583000003
    Figure 0007833583000003
Patent Text Reader

Abstract

To easily and appropriately restore a volume.SOLUTION: In a storage system 10 is connected to a cloud system 20 for providing an object store through networks 13a and 13b, and performs backup of backup data having a predetermined volume as an object in the object store. The storage system 10 includes a processor 151, and the processor 151 is configured to determine whether or not the storage system 10 stores a snap shot relating to a volume at a first time point as a restore object, and to restore the volume at the first time point using the snap shot, when determining that it stores the snap shot.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technique for restoring a predetermined volume.

Background Art

[0002] In recent years, an operation mode called a hybrid cloud has emerged, which combines on-premises IT assets and public cloud services according to cost and usage. In storage, on-premises devices have high-speed I / O access but high bit costs and require prior capacity design. In contrast, cloud services have the characteristics that although performance is limited by distance and communication bandwidth, bit costs are low and capacity design is not required.

[0003] There is an object store service that stores data in object form in a typical service in cloud services and accesses it via a REST API. Since the object store can utilize almost unlimited capacity, prior capacity design is not required, and it is characterized by low bit costs compared to other cloud storage services.

[0004] As a method of using an object store, a method of using it as a backup of an on-premises storage device can be considered. For example, Patent Document 1 discloses a method of obtaining target data from the difference between a first and a second snapshot using snapshot technology, performing deduplication by comparing with transferred blocks, and transferring data including a plurality of deduplicated blocks as an object.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] When restoring data from the cloud, there are challenges such as the following: To restore data using incremental backups, it is necessary to retrieve each backup one by one, starting with the oldest generation, and then use that backup data to restore the data. This is because, when incremental backups are performed, data that has already been backed up is not included in other generations of backups.

[0007] In this way, if backups are continued, for example, by the 100th backup, 100 generations of data will have been accumulated. During restoration, these must be retrieved and restored sequentially, increasing the amount of data to be transferred, the amount of processing required for restoration, and the processing time. In contrast, Patent Document 1 does not disclose any method for restoring data.

[0008] This invention has been made in view of the above circumstances, and its purpose is to provide a technology that enables easy and appropriate restoration of a volume. [Means for solving the problem]

[0009] To achieve the above objective, a data control device relating to one perspective is connected via a network to a cloud system that provides an object store, and is a data control device that backs up backup data of a predetermined volume as an object to the object store, wherein the data control device includes a processor, and the processor determines whether the data control device has stored a snapshot related to the volume at a first point in time to be restored, and if it determines that it has stored the snapshot, it restores the volume at the first point in time using the snapshot. [Effects of the Invention]

[0010] According to the present invention, volumes can be easily and appropriately restored. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1 is an overall configuration diagram of the computer system according to the first embodiment. [Figure 2] Figure 2 is a diagram showing the configuration of the cloud system according to the first embodiment. [Figure 3] Figure 3 is a diagram showing the configuration of the I / O control program according to the first embodiment. [Figure 4] Figure 4 is a diagram showing the configuration of the storage management program according to the first embodiment. [Figure 5A] Figure 5A is a diagram illustrating the configuration of a logical volume according to the first embodiment. [Figure 5B] Figure 5B is a diagram illustrating the updating of a logical volume according to the first embodiment. [Figure 6] Figure 6 illustrates the acquisition of a snapshot of a logical volume according to the first embodiment. [Figure 7] Figure 7 is a diagram showing the configuration of the mapping table according to the first embodiment. [Figure 8A] Figure 8A shows the registration store screen according to the first embodiment. [Figure 8B] Figure 8B shows the new store registration screen according to the first embodiment. [Figure 9] Figure 9 is a flowchart of the object store registration process according to the first embodiment. [Figure 10] Figure 10 shows the backup schedule setting screen according to the first embodiment. [Figure 11] Figure 11 is a flowchart of the backup process according to the first embodiment. [Figure 12A] Figure 12A is a diagram illustrating the backup data in a full backup according to the first embodiment. [Figure 12B]FIG. 12B is a diagram for explaining backup data in the incremental backup according to the first embodiment. [Figure 12C] FIG. 12C is a diagram for explaining backup data in the differential backup according to the first embodiment. [Figure 13] FIG. 13 is a flowchart of object conversion and transmission processing according to the first embodiment. [Figure 14] FIG. 14 is a diagram for explaining stored data in the object store of the object storage system according to the first embodiment. [Figure 15] FIG. 15 is a configuration diagram of metadata according to the first embodiment. [Figure 16A] FIG. 16A is a first example of catalog data according to the first embodiment. [Figure 16B] FIG. 16B is a second example of catalog data according to the first embodiment. [Figure 17] FIG. 17 is a diagram showing a restore selection screen according to the first embodiment. <## [Figure 18] FIG. 18 is a flowchart of backup list acquisition processing according to the first embodiment. [Figure 19] FIG. 19 is a flowchart of restore processing according to the first embodiment. [Figure 20] FIG. 20 is a flowchart of backup data acquisition and restoration processing according to the first embodiment. <000#02> [Figure 21] FIG. 21 is a flowchart of object reception and conversion processing according to the first embodiment. [Figure 22A] FIG. 22A is a diagram for explaining a first specific example of restore processing according to the first embodiment. [Figure 22B] FIG. 22B is a diagram for explaining a second specific example of restore processing according to the first embodiment. [Figure 22C] [[ID=#]]FIG. 22C is a diagram for explaining a third specific example of restore processing according to the first embodiment. [Figure 22D]Figure 22D illustrates a fourth specific example of the restore process according to the first embodiment. [Figure 23] Figure 23 is a diagram showing the configuration of a catalog data table according to a modified example of the first embodiment. [Figure 24] Figure 24 shows the backup schedule setting screen according to the second embodiment. [Figure 25] Figure 25 is a flowchart of the backup process according to the second embodiment. [Figure 26] Figure 26 is a flowchart of the old backup set disposal process according to the second embodiment. [Modes for carrying out the invention]

[0012] Several embodiments will be described with reference to the drawings. Note that the embodiments described below are not intended to limit the invention as defined in the claims, and not all of the elements and combinations described in the embodiments are necessarily essential to the solution of the invention.

[0013] First, the computer system according to the first embodiment will be described.

[0014] Figure 1 is an overall configuration diagram of the computer system according to the first embodiment.

[0015] Computer system 1 includes, as an example of a data control device, a storage system 10, a cloud system 20, a group of servers 11, terminals 17a and 17b, etc.

[0016] Terminal 17b and the cloud system 20 are connected via a network. The server group 11 and the storage system 10 are connected via a storage network 12. The storage system 10 and the cloud system 20 are connected via a dedicated line 13a or an internet line 13b. In addition, the storage system 10 and terminal 17a are connected via a LAN (Local Area Network) 14. The storage system 10 and terminal 17a are connected to the cloud system 20 via the LAN 14 and a dedicated line 15a or an internet line 15b.

[0017] The cloud system 20 provides various services to the storage system 10 and the like. The cloud system 20 has an operation management system 18 that manages the operation of multiple storage systems, including the storage system 10. The operation management system 18 performs processing to manage the operation of the storage system 10.

[0018] Terminal 17b receives management instructions for the storage systems from an administrator who manages multiple storage systems 10, and sends the management instructions to the operation management system 18.

[0019] Terminal 17a receives operation instructions from the operator operating the storage system 10 and transmits the operation instructions to the storage system 10.

[0020] The server group 11 performs various processes by reading and writing I / O (Input / Output) to the logical volumes provided by the storage system 10.

[0021] The storage system 10 is a disk array device that provides, for example, data protection using RAID (Redundant Array of Independent (or Inexpensive) Disks) and data copying functions both inside and outside the storage system.

[0022] The storage system 10 comprises multiple redundant I / O control subsystems 150 (150a, 150b), a storage management subsystem 160, multiple host interfaces (I / F) 110a, 110b, network interfaces 120a, 120b, connection interfaces 131, 132, and multiple drives 140 (140-0, 140-1, ..., 140-n).

[0023] The host interfaces 110a and 110b communicate with the server group 11 via the storage network 12.

[0024] Network interfaces 120a and 120b communicate with the cloud system 20 regarding various cloud services via a dedicated line 13a or an internet connection 13b.

[0025] The connection interfaces 131 and 132 can connect to other storage systems 170 and 180 and communicate with the connected storage systems. For example, storage system 10 can control the logical volumes 171 and 172 provided by the connected storage system 170 as if they were its own logical volumes. Furthermore, storage system 10 can perform volume copying between itself and the connected storage system 180.

[0026] Drive 140 refers to physical storage devices such as SSDs (Solid State Drives) and HDDs (Hard Disk Drives).

[0027] The I / O control subsystem 150 configures one or more logical volumes based on the storage area of ​​the connected drive 140 and provides the logical volumes to the server group 11. Based on read / write I / O from the server group 11, the I / O control subsystem 150 issues read / write I / O to the drive 140 and executes I / O processing.

[0028] The I / O control subsystem 150 includes a processor 151 and a memory 152. The processor 151 executes various processes according to the program stored in the memory 152.

[0029] Memory 152 is, for example, RAM (RANDOM ACCESS MEMORY) and stores programs executed by processor 151 and necessary information. Memory 152 stores the I / O control program P150.

[0030] The storage management subsystem 160 performs various settings and monitoring operations for the storage system 10. The storage management subsystem 160 receives operator instructions from terminal 17a via LAN 14. The storage management subsystem 160 stores the storage management program P160, and performs various operations by executing the storage management program P160 using its internal processor. The storage management subsystem 160 also receives instructions from the operation management system 18 running on the cloud system 20 via a dedicated line 15a or internet line 15b, and performs operations according to the instructions. In the example in Figure 1, the storage management subsystem 160 is located inside the storage system 10, but the storage management subsystem 160 may be located outside the storage system 10, or a part of the storage management subsystem 160 may be run on the cloud system 20.

[0031] Next, I will explain Cloud System 20.

[0032] Figure 2 is a diagram showing the configuration of the cloud system according to the first embodiment.

[0033] The cloud system 200 is composed of multiple servers and provides various microservices such as data store services, computing services, and application services. The cloud system 200 includes a user authentication and access rights management system 210, a database system 220, an object storage system 230, and a management console system 290.

[0034] The User Authentication and Access Rights Management System 210 provides user authentication and access rights management services. The User Authentication and Access Rights Management System 210 issues access IDs and secret keys for each user utilizing various services, based on instructions from the service subscriber of the Cloud System 20. The User Authentication and Access Rights Management System 210 also defines permissions for access IDs and access permission policies for each service resource. The User Authentication and Access Rights Management System 210 controls user and service access.

[0035] The database system 220 provides SQL databases and NoSQL databases.

[0036] The object storage system 230 provides an object store that constitutes unlimited capacity storage that allows reading and writing of object sets using a REST API.

[0037] The management console system 290 provides console services for starting / stopping various services and displaying their usage status. For example, subscribers can use the console services of the management console system 290 to access the user authentication and access rights management system 210 to create user access IDs or check the usage capacity of the object store service.

[0038] Next, we will describe the I / O control program P150, which is stored in and executed in the I / O control subsystem 150 of the storage system 10.

[0039] Figure 3 is a diagram showing the configuration of the I / O control program according to the first embodiment.

[0040] The I / O control program P150 includes a physical volume control function P1510, a logical volume control function P1520, a point-in-time copy (snapshot acquisition) function P1530, a mapping difference extraction function P1531, a data transfer function P1532, an object metadata generation function P1533, a catalog generation function P1534, an object conversion function P1535, an API communication management function P1536, a restore planner P1537, a catalog acquisition function P1538, and an object metadata acquisition function P1539.

[0041] The physical volume control function P1510 controls multiple drives 140 and performs drive I / O control, including drive path and drive-specific fault handling.

[0042] The logical volume control function P1520 configures logical volumes through a capacity virtualization mechanism and performs host I / O control and data copying.

[0043] The Point-in-Time copy function P1530 ​​is a function that copies and saves a static image (called a snapshot) of a logical volume in cooperation with the logical volume control function P1520. The Point-in-Time copy function P1530 ​​also has a function to copy the saved snapshot back to the original volume.

[0044] The mapping difference extraction function P1531 retrieves the differences between the mapping data in the snapshot.

[0045] The data transfer function P1532 copies data between the memory and buffers of network interfaces 120a and 120b.

[0046] The object metadata generation function P1533 generates metadata (meta-information) that includes the correspondence between location information within an object and address information of blocks on a logical volume.

[0047] The catalog generation function P1534 creates catalog data (catalog information) that holds various information for each backup generation.

[0048] The object conversion function P1535 converts between binary data held within the storage system 10 and object data sent using the REST API.

[0049] The API communication management function P1536 performs communication processing with the cloud system 20 via the network interface 120 using a REST API, and also performs various recovery processes related to communication in the event of an error.

[0050] The restore planner P1537 references multiple catalog data and snapshots held by the storage system 10 to plan the procedure for restoring data from the cloud system 20.

[0051] The catalog retrieval function P1538 retrieves catalog data from the object store of cloud system 20 during volume restoration and interprets the contents of the retrieved catalog data.

[0052] The object metadata retrieval function P1539 retrieves metadata from the object store of cloud system 20 during restoration and interprets the contents of the retrieved metadata.

[0053] Next, we will describe the storage management program P160, which is stored in and executed in the storage management subsystem 160 of the storage system 10.

[0054] Figure 4 is a diagram showing the configuration of the storage management program according to the first embodiment.

[0055] The storage management program P160 includes GUI (Graphical User Interface) and CLI (Command Line Interface) components P1610, network communication management function P1620, status monitor P1630, logging function P1640, storage volume management function P1650, object store registration management function P1660, backup management function P1670, and restore management function P1680.

[0056] The GUI and CLI component P1610 provides a user interface that makes the management functions of the storage management program P160 available from terminals 17a, 17b, and the operation management system 18. The GUI and CLI component P1610 provides, for example, an object store registration screen and a backup settings screen.

[0057] The network communication management function P1620 manages the settings of the network interface 120 for connecting to the cloud system 20, and the network settings for connecting to LAN 14. For example, the network communication management function P1620 configures the IP address, netmask, gateway, etc., of the network interface 120.

[0058] The status monitor P1630 displays the hardware health of the storage system 10, the capacity usage and health of each logical volume and object store, as well as the progress of ongoing processes and I / O speed.

[0059] The P1640 logging function records logs of various processes. For example, the P1640 logging function records the start / end of backup processes and errors.

[0060] The storage volume management function P1650 configures and manages multiple drives 140, a storage pool composed of the storage areas of multiple drives 140, and logical volumes created from the storage area of ​​the storage pool. The storage pool will be described later using Figure 5A.

[0061] The object store registration and management function P1660 registers and manages information about the object store service of the cloud system 20 used by the storage system 10.

[0062] The backup management function P1670 manages the settings (backup settings) for backing up to the cloud system 20. The restore management function P1680 issues instructions to restore data backed up to the cloud system 20.

[0063] This section describes the configuration of logical volumes in storage system 10.

[0064] Figure 5A is a diagram illustrating the configuration of a logical volume according to the first embodiment.

[0065] In the storage system 10, a RAID group 300 is configured using multiple drives 140 to protect data using RAID. Data written to the RAID group 300 is distributed and stored across the multiple drives 140 after a predetermined calculation corresponding to, for example, RAID 5.

[0066] A RAID group 300 generally has a large capacity because it consists of multiple drives 140. Therefore, the storage system 10 defines a logical management mechanism called a storage pool 600 to manage the capacity of the RAID group 300. The storage pool 600 divides the storage area into multiple blocks of a predetermined block size, and each block is assigned a logical address (pool address) on the storage pool 600 for management. The storage pool 600 may consist of multiple RAID groups. Furthermore, the storage system 10 may have multiple storage pools.

[0067] Logical volume 500 is a virtual device configured with the capacity of storage pool 600, which is managed by capacity virtualization (Thin Provisioning) technology. Since logical volume 500 has no physical form, when a host writes data to logical volume 500, the storage system 10 temporarily stores the data in memory on the I / O control subsystem 150, then allocates a portion of the blocks in storage pool 600 to virtual blocks of logical volume 500, and stores the data in those blocks. The correspondence between the virtual blocks of logical volume 500 and the blocks on storage pool 600 is managed by a mapping table 400. The mapping table 400 is stored, for example, in memory within the storage management subsystem 160.

[0068] Figure 5A shows an example where three data units "A", "B", and "C" are sequentially written to virtual blocks 50, 51, and 52 in logical volume 500. In this example, as indicated by the dotted arrows in the figure, blocks 60, 61, and 62 are assigned to virtual blocks 50, 51, and 52, corresponding to pool addresses B00, B01, and B02 of storage pool 600, and the three data units are stored in blocks 60, 61, and 62. In this case, the correspondence between the addresses of virtual blocks 50, 51, and 52 in logical volume 500 and the pool addresses of blocks 60, 61, and 62 in storage pool 600 is recorded in the mapping table 400.

[0069] Next, we will explain the process by which the data on logical volume 500 is updated.

[0070] Figure 5B is a diagram illustrating the updating of a logical volume according to the first embodiment. Figure 5B shows an example in which a new data unit 40 "A'" is overwritten in the virtual block 50 of the logical volume 500 shown in Figure 5A by a host (for example, one of the servers in the server group 11).

[0071] When the storage system 10 receives a new data unit 40 for the virtual block 50 from the host, it allocates a new block 63 (pool address B03) in the storage pool 600 and writes the data unit to the allocated block 63. Next, the storage system 10 associates the pool address B03 of the newly allocated block 63 with the address of the virtual block 50 in the mapping table 400. Since the block 60 that was associated with the virtual block 50 is no longer referenced from anywhere, it is determined to be an unused block and will be reclaimed (made an empty block) and reused at the appropriate time by the storage volume management function P1650.

[0072] Next, we will explain how to take a snapshot of logical volume 500.

[0073] Figure 6 illustrates the acquisition of a snapshot of a logical volume according to the first embodiment. Figure 6 shows an example of acquiring snapshots at several points during the update process of the logical volume 500 shown in Figure 5A.

[0074] When a snapshot is taken at the point in time when logical volume 500 (P-VOL) is in the state shown in Figure 5A, the resulting snapshot will be snapshot 511 (SS01). Here, a snapshot is a virtual copy of the logical volume at a specific point in time.

[0075] Snapshot 511 indicates that the data units of logical volume 500 at the time shown in Figure 5A are "A", "B", and "C", and is created by copying the logical volume information from the mapping table 400. Specifically, snapshot 511 includes information on the correspondence between the addresses of virtual blocks 50, 51, and 52 and the pool addresses B00, B01, and B02 of blocks 60, 61, and 62 of storage pool 600. In this embodiment, the storage system 10 registers snapshot 511 in the mapping table 400.

[0076] Subsequently, the first data unit of logical volume 500 is rewritten from "A" to "A'", and when a snapshot is taken at that point, the snapshot taken becomes snapshot 512 (SS02). Snapshot 512 indicates that the data units of logical volume 500 at that point are "A'", "B", and "C", and is created by copying the information of logical volume 500 from the mapping table 400 at that point. Specifically, snapshot 512 includes information on the correspondence between the addresses of virtual blocks 50, 51, and 52 and the pool addresses B03, B01, and B02 of blocks 63, 61, and 62 in storage pool 600 where the data units "A'", "B", and "C" are stored. In this embodiment, the storage system 10 registers snapshot 512 in the mapping table 400.

[0077] Subsequently, when the second data unit of logical volume 500 is overwritten from "B" to "B'", a new block 64 (pool address B04) in storage pool 600 is allocated through the operation shown in Figure 5B. The data unit "B'" is then written to the allocated block 64, and in the mapping table 400, the pool address B04 of the newly allocated block 64 is associated with the second address of virtual block 50.

[0078] According to snapshots 511 and 512, the correspondence between the virtual blocks corresponding to logical volume 500 at a past point in time when the snapshot was taken and the blocks in storage pool 600 can be identified. By obtaining data units from the identified blocks in storage pool 600, logical volume 500 at that point in time can be restored.

[0079] Next, we will explain mapping table 400.

[0080] Figure 7 is a diagram of the mapping table configuration according to the first embodiment. The mapping table in Figure 7 is the mapping table when logical volume 500 and snapshots 511 and 512 are in the state shown in Figure 6.

[0081] The mapping table 400 includes a column 401 showing the addresses (LBAs) of the virtual blocks of logical volume 500, a column 402 showing the pool addresses of the blocks in storage pool 600 corresponding to each virtual block of logical volume 500, and columns 403, 404, etc., corresponding to snapshots 511, 512 of logical volume 500.

[0082] In column 402, which corresponds to logical volume 500, the data units stored in logical volume 500 are "A'", "B'", and "C" as shown in Figure 6. Therefore, the pool addresses of the blocks in storage pool 600 where these data units are stored are B03, B04, B02, ....

[0083] Furthermore, column 403, which corresponds to the snapshot, corresponds to the state when the data units of logical volume 500 were "A", "B", and "C", and therefore stores the pool addresses of the blocks in storage pool 600 where these data units are stored: B00, B01, B02, ...

[0084] Furthermore, column 404, which corresponds to the snapshot, corresponds to the state when the data units of logical volume 500 were "A'", "B", and "C", and therefore stores the pool addresses of the blocks in storage pool 600 where these data units are stored: B03, B01, B02, ...

[0085] In this case, in the storage system 10, blocks of the storage pool 600 registered (referenced) in the mapping table 400 are not determined to be unused blocks, and the data units stored in those blocks are maintained in their stored state. Therefore, blocks B00 to B04 of the storage pool 600 referenced in the mapping table 400 are not determined to be unused blocks, and the data units "A", "B", "C", "A'", and "B'" in those blocks are maintained in their stored state.

[0086] Next, we will explain the backup process to the cloud system 20 using snapshots.

[0087] First, we will explain the screens related to registering the object store of the cloud system 20 in the storage system 10.

[0088] Figure 8A shows the registration store screen according to the first embodiment. The registration store screen D10 is provided to terminals 17a, 17b, etc. by the object store registration management function P1660 and the GUI and CLI component P1610.

[0089] The registration store screen D10 is the screen that is initially displayed on the requesting terminal, for example, when the storage system 10 receives a request to register a store.

[0090] The registered store screen D10 includes a registered store list display area D100, an add button D111, and a delete button D112.

[0091] The registered store list display area D100 is an area that displays a list of already registered object stores (object store list), and includes registered store selection areas D101, D102, etc., which allow users to select registered object stores.

[0092] The Add button D111 accepts instructions to add a new object store or to edit a selected object store. If the Add button D111 is pressed when no object store is selected in the Registered Store List display area D100, the storage system 10 displays the New Store Registration screen D20 (see Figure 8B). If the Add button D111 is pressed when an object store is selected in the Registered Store List display area D100, the storage system 10 displays a screen for editing the selected object store.

[0093] The delete button D112 accepts the deletion of the object store selected in the registered store list display area D100. When the delete button D112 is pressed, the storage system 10 performs the process of deleting the selected object store.

[0094] Figure 8B shows the new store registration screen according to the first embodiment.

[0095] The new store registration screen D20 includes a dropdown box D201, a Tag button D211, an OK button D212, and a Cancel button D213. The dropdown box D201 allows the user to select a cloud service available on the storage system 10.

[0096] When a cloud service is selected in the dropdown box D201, the storage system 10 displays setting areas that can be entered or selected according to the selected cloud service. For example, when an object store is selected in the dropdown box D201, the new store registration screen D20 displays the following setting areas: name setting area D207, region selection area D202, access ID input area D203, secret key input area D204, bucket name setting area D205, and encryption selection area D206.

[0097] The Name Setting Area D207 is where you specify the registration name for the object store to be created. This registration name is used, for example, when displaying it in the object store list. The Region Selection Area D202 is, for example, a dropdown box where you can select the region where the cloud service will be used. The Access ID Input Area D203 is where you enter the access ID required to access the object store to be registered. The Secret Key Input Area D204 is where you enter the secret key required to access the object store to be registered. The Bucket Name Setting Area D205 is where you specify the name of the bucket (bucket name) where backup data will be stored on the object store to be registered. The bucket name must be unique within the region. Therefore, if no name is specified, the storage system 10 generates a bucket name using unique information that does not overlap with other users, such as the manufacturing number or customer ID of the storage system 10. The Encryption Selection Area D206 is where you select the method for encrypting data in the object store to be registered.

[0098] The Tag button D211 is a button that accepts tags, which consist of a Name and a Value. When the Tag button D211 is pressed, a screen (not shown) for entering tags is displayed, and the button accepts the input of tags.

[0099] The OK button D212 is a button that accepts the instruction to register the object store set on the new store registration screen D20. When the OK button D212 is pressed, the storage system 10 performs the process of registering the object store set on the new store registration screen D20 (object store registration process: see Figure 9).

[0100] The Cancel button D213 accepts the cancellation of object store registration. If the Cancel button D213 is pressed, the storage system 10 terminates object store registration and closes the new store registration screen D20.

[0101] Next, we will explain the object store registration process.

[0102] Figure 9 is a flowchart of the object store registration process according to the first embodiment.

[0103] The object store registration process is performed by the object store registration management function P1660. When registering an object store, if the authentication information for the object store is incorrect or the object store is not granted appropriate access rights, all backup operations performed on this object store will fail, and the backup process will not be performed properly. To prevent such a situation, the storage system 10 performs an access test on the object store to be registered (referred to as the target object store in this explanation of the process) during the object store registration process.

[0104] In the object store registration process, first, the object store registration management function P1660 (more precisely, the processor of the storage management subsystem 160 that executes the storage management program P160) works in conjunction with the network communication management function P1620 to check whether the network settings (for example, the settings for the access ID and secret key for the target object store) that allow access to the cloud service selected on the new store registration screen D20 are appropriate in the I / O control subsystem 150 (S1100). If the network settings are not appropriate as a result (S1100: Not OK), the object store registration management function P1660 displays a message prompting a review of the settings based on the error code for the network settings (S1500) and terminates the process. An example of a message prompting a review of the settings is "The Access ID or Secret Key is incorrect. Please check it."

[0105] On the other hand, if the network settings are correct (S1100: OK), the object store registration management function P1660 works in conjunction with the I / O control program P150 to create a LIST command to check the viewing permissions for the target object store (S1110), and issues it to the object storage system 230 as a REST API (S1120). The LIST command is used to retrieve a list of objects in the object store.

[0106] Next, the object store registration management function P1660 checks the response to the LIST command (S1130).

[0107] If the response is an error (S1130:Error), the object store registration management function P1660 displays a message (S1500) instructing the user to review the object store's access permission settings based on the error code corresponding to this error.

[0108] If the response is not returned within a certain period of time and a timeout occurs (S1130: Time Out), the object store registration management function P1660 determines whether or not this is the first timeout (S1330). If it is the first timeout (S1330: Yes), the object store registration management function P1660 proceeds to step S1120 and issues the REST API again. On the other hand, if this is not the first timeout, i.e., if it is a repeat timeout (S1330: No), a network communication problem is suspected, so the object store registration management function P1660 displays a message to check the network status (S1600) and terminates processing.

[0109] If the response is normal (S1130: No Error), the object store registration management function P1660 works in conjunction with the I / O control program P150 to generate a PUT command to verify write permissions to the target object store (S1140) and issues it to the object storage system 230 as a REST API (S1150).

[0110] Next, the object store registration management function P1660 checks the response to the PUT command (S1160).

[0111] The processing based on the response check result in step S1160 is the same as the processing based on the response check result in step S1130 described above (S1360, S1500, S1600).

[0112] If the response is normal (S1160: No Error), the object store registration management function P1660 works in conjunction with the I / O control program P150 to generate a GET command to confirm read permission for the target object store (S1170) and issues it to the object storage system 230 as a REST API (S1180).

[0113] Next, the object store registration management function P1660 checks the response to the GET command (S1190).

[0114] The processing based on the response check result in step S1190 is the same as the processing based on the response check result in step S1130 described above (S1390, S1500, S1600).

[0115] If the response is normal (S1190: No Error), the object store registration management function P1660 works in conjunction with the I / O control program P150 to generate a DELETE command to confirm the deletion permission for the target object store (S1200), and issues it to the object storage system 230 as a REST API (S1210).

[0116] Next, the object store registration management function P1660 checks the response to the DELETE command (S1220).

[0117] The processing based on the response check result in step S1220 is the same as the processing based on the response check result in step S1130 described above (S1420, S1500, S1600).

[0118] If the response is normal (S1220: No Error), it means that the series of processes necessary for the normal use of the object store have been confirmed. Therefore, the object store registration management function P1660 registers the information of the new object store set on the new store registration screen D20 (S1230) and terminates the object store registration process.

[0119] Next, we will explain the backup schedule setting screen D30, which is used to set a schedule for backups using the registered object store.

[0120] Figure 10 shows the backup schedule setting screen according to the first embodiment. The backup schedule setting screen D30 is provided to terminals 17a, 17b, etc. by the object store registration management function P1660 and the GUI and CLI component P1610.

[0121] The backup schedule setting screen D30 includes the logical volume selection area D301, the object store selection area D302, the backup schedule setting area D303, and the backup method selection area D304.

[0122] Logical volume selection area D301 is the area where you select the logical volume to be backed up. In the example in Figure 10, the logical volume VolB (16TB), indicated by volume number 7F, is selected as the backup target in logical volume selection area D301.

[0123] The object store selection area D302 is, for example, a dropdown box where you select the object store to be used as the backup destination for the logical volume. In the object store selection area D302, already registered object stores are displayed for selection using the screens shown in Figures 8A and 8B. In the example in Figure 10, the object store corresponding to "ams:std Backup" is selected.

[0124] The backup schedule setting area D303 is where you configure the backup schedule. In the backup schedule setting area D303, for example, a One shot button D3031 for setting up a one-time backup and a Periodically button D3032 for setting up periodic backups are displayed. If you select the One shot button D3031, you can specify whether to run the backup immediately or specify the start time. If you select the Periodically button D3032, you can specify the repetition interval (for example, daily, weekly, or monthly), the start time, the interval between runs, the number of runs, etc. In the example in Figure 10, periodic execution is selected as the backup schedule, and it is specified to run daily, every 30 minutes starting at 0:00 each day.

[0125] The backup method selection area D304 is where you configure the backup method. In the example in Figure 10, the selectable backup methods are Full Backup, which backs up the entire logical volume; Incremental Backup, which backs up only the difference in the logical volume since the last backup; and Differential Backup, which backs up the difference between the logical volume at the time of the most recent Full Backup and the current backup. In the example in Figure 10, Incremental Backup is selected.

[0126] The OK button D311 is a button that accepts the instruction to register the backup schedule set on the backup schedule setting screen D30. When the OK button D311 is pressed, the set backup schedule is registered in the scheduler of the storage management subsystem 160.

[0127] The Cancel button D312 accepts the instruction to discard the backup schedule set on the backup schedule setting screen D30. When the Cancel button D312 is pressed, the set backup schedule is discarded.

[0128] Multiple backup schedules can be created for a single logical volume. For example, a logical volume to be backed up could have a schedule for a full backup every Sunday at 0:00 and a schedule for incremental backups every Monday through Saturday at 0:00. In this case, the logical volume would be backed up using a combination of these schedules.

[0129] Next, we will explain the backup process.

[0130] Figure 11 is a flowchart of the backup process according to the first embodiment.

[0131] The backup process is performed by the backup management function P1670, which issues instructions to the I / O control program P150 based on the configured backup schedule. Information necessary for operation is shared between the backup management function P1670 and the I / O control program P150 as needed.

[0132] When the I / O control program P150 receives an operation instruction from the backup management function P1670, it uses the Point-in-Time copy function P1530 ​​to take a snapshot of the logical volume to be backed up (target logical volume) (S2100). Specifically, this is achieved by copying the mapping information (column information) of the target logical volume in the mapping table 400, as explained in Figures 6 and 7.

[0133] Next, the I / O control program P150 checks the configured backup method (S2110).

[0134] If a full backup is specified as the backup method (S2110: Full Backup), the I / O control program P150 specifies a dummy snapshot as the comparison snapshot for creating the backup data (S2121). A dummy snapshot is a snapshot in which all pool addresses are filled with 0 (NULL), which means an invalid value.

[0135] Furthermore, if incremental backup is specified as the backup method (S2110: Incremental Backup), the I / O control program P150 specifies the snapshot taken during the previous backup as the snapshot to be compared (S2122).

[0136] Furthermore, if differential backup is specified as the backup method (S2110: Differential Backup), the I / O control program P150 specifies the snapshot taken during the most recent full backup as the snapshot to be compared (S2123).

[0137] Note that if this is the first backup, there are no previous snapshots or snapshots taken during the most recent full backup. Therefore, even if incremental or differential backup is specified, a dummy snapshot will be specified as the comparison snapshot. Consequently, in this case, the incremental data for an incremental backup (incremental backup data) and the differential data for a differential backup will be the full data of the volume (full backup data).

[0138] After executing steps S2121, S2122, or S2123, the I / O control program P150 identifies the data to be backed up (backup data) using the mapping difference extraction function P1531 (S2130). Specifically, the mapping difference extraction function P1531 extracts the difference between the source snapshot and the backup target snapshot (basically the latest snapshot) by taking the exclusive OR of the pool addresses corresponding to each block number of the logical volume. If the result of the exclusive OR is 0, i.e., the pool addresses are the same, it indicates that the data in the block of that logical volume has not been changed and the data in that block is not to be backed up. If the result is non-zero (non-zero is treated as 1), i.e., the pool addresses are different, it indicates that the data in the block has been changed and the data in that block is the difference data to be backed up.

[0139] Next, the I / O control program P150 reads the data from the target blocks (multiple blocks identified as backup targets) from the storage pool 600 and stores it in the transfer memory (S2140) based on the extraction results of step S2130, in order to collect the data from multiple blocks (target blocks) identified as backup targets and form an object. If it is not possible to read everything at once due to resource constraints of the I / O control subsystem 150, the processing can be performed in batches of a certain size (e.g., 16MB).

[0140] Next, the I / O control program P150 determines the name (OBJ Key) of the object to be transmitted and stores information about the blocks contained in this object (e.g., whether or not it is compressed, its size, etc.) (S2150).

[0141] Next, the I / O control program P150, using the object conversion function P1535 and the API communication management function P1536, performs object (OBJ) conversion and transmission processing (see Figure 13) on the backup data, converting it into an object and sending it to the object store (S2160). Furthermore, asynchronously with the object conversion and transmission processing, the I / O control program P150 receives the reception result from the object store and checks whether the transfer was successful (S2161).

[0142] The I / O control program P150 determines whether all backup target data (differential data) has been transferred (S2170). If it determines that not all data has been transferred (S2170: No), it proceeds to step S2140 to execute the process of transferring the data that has not been transferred.

[0143] On the other hand, if all the data to be backed up has been transferred (S2170: Yes), the I / O control program P150 generates metadata about the data to be backed up (see Figure 15) and stores it in the transfer memory. Next, the I / O control program P150 uses the object conversion function P1535 and the API communication management function P1536 to perform object conversion and transmission processing on the metadata to store it as an object in the object store (S2190).

[0144] Next, the I / O control program P150 confirms that the metadata has been successfully transferred (S2200). If the successful transfer of metadata is confirmed, it indicates that the data to be backed up and its metadata have been stored in the object store. Therefore, the I / O control program P150 generates catalog data (Figures 16A and 16B) containing various information about the backup data to be referenced during restoration and stores it in the transfer memory (S2210).

[0145] Next, the I / O control program P150 performs object (OBJ) conversion and transmission processing (see Figure 13) on the catalog data, converting it into an object and sending it to the object store (S2220).

[0146] Next, the I / O control program P150 confirms that the catalog data has been successfully transferred (S2230).

[0147] Subsequently, the I / O control program P150 performs disposal processing for the snapshots used for backup. This is because if a snapshot is taken for each backup and left in the storage system 10, the number of snapshots would become enormous, and the amount of data stored in the storage system 10 would also become enormous. Therefore, the I / O control program P150 deletes older snapshots that exceed a predetermined number of generations of snapshots to be kept (e.g., 3) that have been pre-configured by the user in the storage system 10 (S2240). If differential backup is specified as the backup method, snapshots taken during the most recent full backup may be excluded from deletion. Snapshot deletion is performed by deleting the corresponding snapshot (column in the mapping table 400) from the mapping table 400. In this way, by deleting the snapshots, the blocks of the storage pool 600 that are no longer referenced from anywhere in the mapping table 400 are recovered by the I / O control program P150 and reused at the appropriate time, thereby appropriately restoring the capacity of the storage pool 600.

[0148] Next, the I / O control program P150 updates the management information (step S2250) and terminates the process.

[0149] According to the backup process described above, users can choose from full backup, incremental backup, or differential backup as the backup method.

[0150] Next, we will specifically explain the process of identifying backup data in steps S2110 to S2130 of the backup process.

[0151] Figure 12A is a diagram illustrating backup data in a full backup according to the first embodiment. Figure 12A shows an example of identifying backup data when the snapshot to be backed up is snapshot 1211A corresponding to logical volume 2100, and when it is determined in step S2110 that the backup method is a full backup.

[0152] In this case, step S2121 specifies a dummy snapshot corresponding to logical volume 2121A, i.e., snapshot 1201A, in which the pool addresses corresponding to all LBAs of the volume are NULL, as the comparison source snapshot. Next, in step S2130, the exclusive OR (XOR) operation is performed on snapshot 1201A and snapshot 1211A against the pool addresses corresponding to the same logical volume addresses (LBAs). Here, since each pool address of snapshot 1201A is 0, the exclusive OR operation results in 1 (non-zero), as shown in result 4130A, indicating that the data of all blocks is subject to backup. Therefore, backup data 2130A is identified as containing the data of all blocks of logical volume 2100 corresponding to snapshot 1211A.

[0153] Figure 12B is a diagram illustrating backup data in an incremental backup according to the first embodiment. Figure 12B shows an example of identifying backup data when the snapshot to be backed up is snapshot 1211A corresponding to logical volume 2100, and it is determined in step S2110 that the backup method is an incremental backup.

[0154] In this case, step S2122 specifies snapshot 1201B, the previous backup target corresponding to logical volume 2121B, as the comparison source snapshot. Next, in step S2130, the exclusive OR of snapshot 1201B and snapshot 1211A is taken with respect to the pool address corresponding to the address of the same logical volume. When the exclusive OR is taken, as shown in result 4130B, the LBA is 1 (not 0), indicating that only the data of block #1 is to be backed up. Therefore, the backup data 2130B is identified as the data of block #1 of logical volume 2100 corresponding to snapshot 1211A (in the example shown in the figure, "A'").

[0155] Figure 12C is a diagram illustrating backup data in differential backup according to the first embodiment. Figure 12C shows an example of identifying backup data when the backup method is determined to be differential backup in step S2110, in a case where the first (1st) snapshot to be backed up is snapshot 1211A corresponding to logical volume 2100, and the second (2nd) snapshot to be backed up is snapshot 1211C corresponding to logical volume 2101.

[0156] In this case, in step S2123 during the first backup, snapshot 1201B, the snapshot to be backed up in the previous backup corresponding to logical volume 2121B, is specified as the comparison source snapshot. Then, in step S2130, the exclusive OR of snapshot 1201B and snapshot 1211A is taken with respect to the pool address corresponding to the address of the same logical volume. When the exclusive OR is taken, the result is 1 (not 0), as shown in result 4130C, indicating that only the data of block #1 of LBA is to be backed up. Therefore, the backup data 2130C is identified as the data of block #1 of logical volume 2100 corresponding to snapshot 1211A (in the example shown in the figure, "A'").

[0157] Furthermore, in step S2123 during the second backup, snapshot 1201B, the snapshot to be backed up in the previous full backup corresponding to logical volume 2121B, is specified as the comparison source snapshot. Then, in step S2130, the exclusive OR of snapshot 1201B and snapshot 1211C is taken with respect to the pool address corresponding to the address of the same logical volume. After taking the exclusive OR, as shown in result 4130D, the LBA is 1 (not 0), indicating that the data in blocks #1 and #2 is the data to be backed up. Therefore, the backup data 2130D is identified as the data in blocks #1 and #2 of logical volume 2101 corresponding to snapshot 1211C (in the example shown in the figure, "A'" and "B'"). According to the differential backup, the second backup data includes cumulative changes between the logical volume at the time of the previous full backup, such as the data "A'" that was included in the first backup data.

[0158] Next, the object conversion and transmission processes (S2160, S2190, S2220) will be explained.

[0159] Figure 13 is a flowchart of the object conversion and transmission process according to the first embodiment.

[0160] In the object conversion and transmission process, the storage system 10 converts the data to be processed, which is stored in binary format, into text format and sends it via a REST API using the HTTP protocol.

[0161] The I / O control program P150, using its object conversion function P1535, encodes the data to be processed, stored in the transfer memory, into text data, for example, according to BASE64 (S3100). Next, the I / O control program P150 calculates an MD5 hash value from the encoded data to protect the data (S3110). Then, the I / O control program P150 creates authentication information by performing a predetermined calculation using the access ID and secret key from the object store's registration information (S3120). Next, the API communication management function P1536 of the I / O control program P150 constructs object data using the created MD5 hash value and authentication information, as well as the transmission date and time, size information, etc., as the HTTP header, and the encoded text data as the HTTP body (S3130). Finally, it stores the object data in the object store via REST API communication using a PUT or POST command (S3140). As a result, an object of the data to be processed is stored in the object store.

[0162] Next, we will describe the data stored in the object store of the object storage system 230.

[0163] Figure 14 is a diagram illustrating the data stored in the object store of the object storage system according to the first embodiment.

[0164] The object storage system 230 is configured with an object store 231. The object store 231 is configured with one or more buckets 2310, 2320.

[0165] Bucket 2310 stores backup data for storage system 10. In the example in Figure 14, bucket 2310 stores catalog data C23 for the first generation backup of logical volume number 0x7f, catalog data C24 for the second generation backup, metadata M23 referenced by catalog data C23, one or more backup data 2311, 2312, ... referenced by metadata M23, metadata M24 referenced by catalog data C24, and one or more backup data 2411, 2412, ... referenced by metadata M24.

[0166] Bucket 2310 also stores data related to the backup of logical volume number 0x90, including catalog data C25, metadata M25, backup data 2511, etc.

[0167] Bucket 2320 is, for example, a bucket that stores backup data from another storage system that has registered the same authentication information.

[0168] Next, I will explain metadata.

[0169] Figure 15 is a diagram illustrating the metadata configuration according to the first embodiment. Figure 15 corresponds to the metadata M24 shown in Figure 14.

[0170] Metadata M24 is stored in the object store with a unique object key associated with the name of the metadata object. The object key is composed of a combination of elements such as the product number of storage system 10, the volume number, and the backup generation number. In this example, the object key for metadata M24 is VSP56342-v7f-s02.meta.

[0171] Metadata M24 includes the bitmap size T1510, the bitmap T1511, and one or more data object keys (T1520, T1530, T1540, etc.) and block length pairs (T1521, T1531, T1541, etc.).

[0172] The bitmap size T1510 stores the size of the bitmap to be stored in bitmap T1511.

[0173] Bitmap T1511 stores a bitmap indicating the location (storage position) of blocks in the logical volume included in the backup data. Specifically, the bitmap of bitmap T1511 is the result of the exclusive OR operation between the comparison snapshots used when extracting the data to be backed up, and indicates whether or not the backup data contains the data of that block in block number order. In this embodiment, if the data of a block is included, the bit corresponding to the block is set to 1, and if it is not included, the bit corresponding to the block is set to 0. For example, in the example in Figure 15, the bitmap of bitmap T1511 is "110011...", so it indicates that the backup data contains the data of blocks with bit numbers #1, #2, #5, #6, ..., where the bit is "1", and does not contain the data of blocks with bit numbers #3, #4, where the bit is "0".

[0174] The data object keys (T1520, T1530, T1540, etc.) store object keys that indicate the object containing the backup data. In this embodiment, when transferring backup data as objects in a single backup, the data is processed as separate objects, for example, by dividing it into sections of a certain size. Therefore, there may be multiple objects containing backup data, and therefore multiple data object keys that indicate these objects.

[0175] The block length (T1521, T1531, T1541, etc.) stores the data length (block size) of each block in the portion of the backup data contained in the object. This block length is used to determine where one block ends in the backup data. In the example in Figure 15, the backup data is stored uncompressed, so the block lengths are all the same. However, if the blocks are compressed before storage, the block lengths of each compressed block will be listed.

[0176] Next, let's discuss catalog data. Catalog data is created during backup and stores various information that is referenced during restoration. Information stored in catalog data includes, for example, the logical volume of the backup source, the capacity required for restoration, the object key for accessing the backup data, and the parent-child relationships of the backup data catalog.

[0177] Figure 16A is a first example of catalog data according to the first embodiment, and Figure 16B is a second example of catalog data according to the first embodiment. Figure 16A is catalog data created during the second backup of the logical volume and corresponds to catalog data C24 in Figure 14, and Figure 16B is catalog data created during the first backup of the logical volume and corresponds to catalog data C23 in Figure 14.

[0178] The catalog data C24 is stored in the object store with the object key VSP56342-v7f-s02.catalog associated with it.

[0179] Catalog data C24 stores the device product number T1610, backup volume number T1611, volume usage / provisioning size T1612, snapshot generation number T1613, snapshot acquisition date and time T1614, metadata object key T1615, and parent catalog object key T1616.

[0180] The device product number T1610 stores the device product number of storage system 10. The backup volume number T1611 stores the volume number that identifies the logical volume to be backed up. The volume usage / provisioning size T1612 stores the provisioning size (allocated capacity) and usage size of the logical volume to be backed up. The snapshot generation number T1613 stores the generation number of the snapshot corresponding to the catalog data. The snapshot acquisition date and time T1614 stores the acquisition date and time of the snapshot corresponding to the catalog data. The metadata object key T1615 stores the object key that indicates the object that stores the metadata corresponding to the catalog data. The parent catalog object key T1616 stores the object key of the catalog data object at the time of backup of the parent generation (previous generation). This object key allows the generation relationship (parent-child relationship) between backups of the same volume to be identified.

[0181] According to catalog data C24, it is catalog data related to the backup of a logical volume with volume number 0x7f in storage system 10 with device product number VSP56342, and it can be seen that the logical volume will become 16TB when restored. It can also be seen that the snapshot has generation number 2 and was taken on April 28, 2021 at 21:00:17, and that to access the backup data, one should refer to the metadata object with object key VSP56342-v7f-s02.meta. Furthermore, it can be seen that there is a catalog data object with object key VSP56342-v7f-s02.catalog, which is the catalog data (parent catalog data) corresponding to the previous generation (parent generation) snapshot. Note that if parent catalog data exists, it means that when restoring the logical volume to be backed up, it is necessary to perform the restore based on the parent catalog data before performing the restore based on this catalog data.

[0182] Catalog data C23 is stored in the object store with the object key VSP56342-v7f-s01.catalog associated with it.

[0183] Catalog data C23 stores the device product number T1710, backup volume number T1711, volume usage / provisioning size T1712, snapshot generation number T1713, snapshot acquisition date and time T1714, metadata object key T1715, and parent catalog object key T1716. Each field stores the same information as the field of the same name in catalog data C24.

[0184] According to catalog data C23, it is a backup catalog data for the same logical volume on storage system 10 as catalog data C24. The snapshot has generation number 1 and was taken on April 28, 2021 at 18:00:14. To access the backup data, one should refer to the metadata object with object key VSP56342-v7f-s01.meta. Since the object key for the parent catalog data does not exist, it means that the parent catalog does not exist, i.e., this is the first snapshot, and therefore, it can be restored based on this catalog data.

[0185] Next, we will explain the restore process for restoring logical volumes.

[0186] First, we will explain the restore selection screen used to select various settings for the restore process in storage system 10.

[0187] Figure 17 shows the restore selection screen according to the first embodiment. The restore selection screen D40 is provided to terminals 17a, 17b, etc. by the GUI and CLI component P1610 and the restore management function P1680 of the storage management program P160.

[0188] The restore selection screen D40 includes the object store selection area D401, the restore volume selection area D402, the backup version selection area D403, the restore destination selection area D404, the Restore button D411, and the Cancel button D412.

[0189] The object store selection area D401 is, for example, a dropdown box where you select the object store containing the backup of the logical volume to be restored. In the object store selection area D401, already registered object stores are displayed for selection using the screens shown in Figures 8A and 8B. In the example in Figure 17, the object store corresponding to "ams:std Backup" is selected.

[0190] The restore volume selection area D402 displays the volumes to be restored as selectable options. The restore volume selection area D402 also displays information about the volumes in the object store selected in the object store selection area D401 where backup data is stored. The list of volumes in the object store where backup data is stored and the backup data itself, which is to be displayed in the restore volume selection area D402 and the backup version selection area D403, is obtained in advance. The backup list acquisition process for obtaining this list of volumes and backup data will be described later.

[0191] The backup version selection area D403 displays the backup data for the volume to be restored, making it available for selection. The backup version selection area D403 displays the backup data for the volume selected in the restore volume selection area D402 from the backup data stored in the datastore. In the example in Figure 17, logical volume #7F is selected in the restore volume selection area D402, so only the backup data for logical volume #7F is displayed in the backup version selection area D403.

[0192] The restore destination selection area D404 is where you select the volume to which you want to restore the logical volume. The restore destination selection area D404 includes the original volume selection button D4041 and the new volume selection button D4042.

[0193] The Original Volume Selection button D4041 accepts the instruction to select the original volume as the restore destination. The New Volume Selection button D4042 accepts the instruction to select a new volume as the restore destination. When the New Volume Selection button D4042 is selected, storage pools that can create a new volume are displayed as selectable. For example, in the example in Figure 17, the New Volume Selection button D4042 is selected in the restore destination selection area D404, and storage pools that can create a new volume are displayed, with storage pool B selected. Note that the storage management program P160 may display storage pools that do not have sufficient capacity to restore the selected logical volume as unavailable.

[0194] The Restore button D411 is a button that accepts the instruction to execute the restore set on the restore selection screen D40. When the Restore button D411 is pressed, the storage management function P180 causes the I / O control program P150 to execute the restore process (see Figure 19).

[0195] The Cancel button D412 accepts the instruction to discard the restore selected on the Restore Selection screen D40. When the Cancel button D412 is pressed, the selected restore is discarded.

[0196] Next, we will explain the process of obtaining the backup list.

[0197] Figure 18 is a flowchart of the backup list acquisition process according to the first embodiment. The backup list acquisition process is the process of acquiring a list of backup data to be used for displaying the restore selection screen D40 in Figure 17.

[0198] Prior to displaying the restore selection screen D40, the storage management program P160 retrieves the date and time when the previous backup data list was created (S5100). The date and time when the previous backup data list was created is registered in the storage system 10 at that time.

[0199] Next, the storage management program P160 works in conjunction with the I / O control program P150 to generate a LIST command (S5110) to retrieve a list of catalog data in the object store. Specifically, the storage management program P160 generates a command to retrieve all object keys that end with ".catalog," indicating that they are catalog data.

[0200] Next, the storage management program P160 issues a LIST command to the object storage system 230 via the API communication management function P1536 and obtains the result of the LIST command (S5120).

[0201] Next, the storage management program P160 determines whether there is any new catalog data that was not included in the previously acquired list (S5130). If no new catalog data exists as a result (S5130: No), it means that the previously acquired backup data list is up-to-date, and the storage management program P160 terminates processing.

[0202] On the other hand, if new catalog data exists (S5130: Yes), the storage management program P160 creates a GET command to retrieve the various information contained in one of the new catalog data (S5140). Then, the storage management program P160 issues a GET command to the object storage system 230 through the API communication management function P1536 and retrieves the result of the GET command (S5150).

[0203] Next, the storage management program P160 determines whether or not it has obtained information about all new catalog data (S5160). If it determines that it has not obtained information about all new catalog data (S5160: No), it proceeds to step S5140.

[0204] On the other hand, if it determines that it has obtained information about all new catalog data (S5160: Yes), the storage management program P160 identifies the backup data based on all the catalog data, updates the list of backup data, registers the updated date as the creation date (S5170), and terminates the process.

[0205] In this embodiment, the logical volume can be restored even if the storage system to which the logical volume is restored is different from the storage system from which the logical volume was backed up. Specifically, by registering the object store in the destination storage system in the same way as the one registered in the backed-up storage system, using the screens shown in Figures 8A and 8B, the backup data of the logical volume backed up on the other storage system can be selected as the restore target using the restore selection screen D40 in Figure 17, and the restore can be performed. In this case, since the original logical volume does not exist in the destination storage system, the original volume specification button D4041 is displayed as unavailable in the restore destination selection area D404 of the restore selection screen D40 in Figure 17.

[0206] Next, we will explain the restore process.

[0207] Figure 19 is a flowchart of the restore process according to the first embodiment.

[0208] The restore process is executed by the storage management program P160 when the Restore button D411 is pressed on the restore selection screen D40. During the restore process, if the snapshot used to create the backup data remains on the storage system 10, the data from that snapshot is used; otherwise, the backup data is retrieved from the object store and restored.

[0209] First, the I / O control program P150 retrieves catalog data corresponding to the backup data selected for restoration (S6100).

[0210] Next, the I / O control program P150 refers to the logical volume number and snapshot generation number included in the catalog data and determines whether its own storage system 10 (self-storage system), which is the restore destination, is the same as the storage system that backed up the logical volume to be restored (step S6105).

[0211] As a result, if it is determined that the local storage system and the backup source storage device are not the same (S6105: No), the I / O control program P150 proceeds to step S6120.

[0212] On the other hand, if it is determined that the local storage system and the backup source storage device are the same (S6105: Yes), the I / O control program P150 determines whether a snapshot of the logical volume corresponding to the acquired catalog data is available on the local storage system 10 (S6110).

[0213] Here, if a snapshot of the logical volume corresponding to the catalog data is available on the local storage system 10, that is, if a snapshot exists and is available (S6110: Yes), it means that the backup data used for restoration remains in the storage system 10 as a snapshot. Therefore, the I / O control program P150 uses this snapshot to restore the data to the logical volume at the restoration destination (S6121) and proceeds to step S6140. Specifically, the contents (columns) of the snapshot in the mapping table 400 are added to the mapping table 400 as mapping information (columns) of the logical volume at the restoration destination. This process does not read or write data on the volume, so it can be completed quickly.

[0214] On the other hand, if a snapshot of the logical volume corresponding to the catalog data is not available (S6110: No), the I / O control program P150 proceeds to step S6120 because it needs to retrieve backup data from the object store of the cloud system 20.

[0215] In step S6120, the I / O control program P150 adds the catalog data to be processed to the processing list managed by the restore planner P1537.

[0216] Next, the I / O control program P150 refers to the parent catalog object key T1616 of the catalog data to check whether a backup of the previous generation (parent generation) exists (S6130).

[0217] As a result, if a parent generation backup exists (S6130: Yes), it is necessary to restore based on the parent generation backup data first. Therefore, the I / O control program P150 retrieves the parent generation catalog data using the parent catalog object key (S6141) and proceeds to step S6105. This executes the processes shown in steps S6105 to S6130. In this way, the processing list is filled with catalog data of backups to be restored in generational order, from the last catalog data to the next, such as parent → child → grandchild.

[0218] In subsequent steps (S6140 to S6170), data restoration is performed using each of the catalog data registered in the processing list.

[0219] During this data recovery process, the I / O control program P150 checks whether catalog data exists in the processing list (S6140).

[0220] As a result, if catalog data exists in the processing list (S6140: Yes), the I / O control program P150 refers to the catalog data at the end of the processing list, i.e., the catalog data of the earliest generation, and obtains the object key of the metadata (S6150).

[0221] Next, the I / O control program P150 retrieves the metadata object corresponding to the object key from the object store 231, retrieves backup data based on the metadata, and performs a backup data retrieval and restore process (see Figure 20) using the backup data to restore to the volume at that generation (point in time) (S6160).

[0222] Next, the I / O control program P150 removes the catalog data of the generation processed in the backup data acquisition and restoration process from the processing list (S6170), and proceeds to step S6140. As a result, the restore is performed using each catalog data registered in the processing list.

[0223] On the other hand, if the catalog data is not present in the processing list (S6140: No), it indicates that the restore is complete, and the I / O control program P150 terminates the process.

[0224] Next, we will explain the process of obtaining and restoring backup data.

[0225] Figure 20 is a flowchart of the backup data acquisition and restoration process according to the first embodiment. The backup data acquisition and restoration process involves interpreting the backup data acquired based on metadata and writing it to the restore destination volume.

[0226] The I / O control program P150 retrieves an object from the object store for metadata based on the object key of the metadata stored in the catalog (for example, the object key of metadata object key T1615 in Figure 16A), and performs an object reception and conversion process (see Figure 21) to convert the object into binary format (S7100).

[0227] Next, the I / O control program P150 extracts a bitmap from the acquired metadata (S7110). Then, the I / O control program P150 obtains the object key of the next object to be processed (referred to as the target object) from the metadata (S7120), retrieves the object corresponding to the object key from the object store 231, and performs an object reception and conversion process (see Figure 21) to convert the object into binary format (S7130).

[0228] Next, the I / O control program P150 advances the next bit to be referenced (reference bit) in the bitmap obtained in step S7110 (S7140) and determines whether the reference bit is "1" or not (S7150).

[0229] As a result, if the reference bit is "1" (S7150: Yes), it means that the data obtained from the target object (partial backup data) contains data from the block with the block number corresponding to the reference bit. Therefore, the I / O control program P150 writes the data from that block contained in the target object to the block with the corresponding block number in the restore destination volume (S7160).

[0230] On the other hand, if the reference bit is not "1", i.e., "0" (S7150; No), it means that the data obtained from the target object does not contain block data for the block number corresponding to the reference bit, so the I / O control program P150 does nothing and proceeds to step S7170.

[0231] In step S7170, the I / O control program P150 advances the block number of the write destination on the restore destination volume by one (S7170) and refers to the next block of the partial backup data (S7180).

[0232] Next, the I / O control program P150 determines whether it is the end of the data contained in the partial backup data, that is, whether the next block exists (S7190).

[0233] As a result, if this is not the end of the partial backup data, that is, if the partial backup data obtained from the target object contains the next block (S7190: No), it indicates that there is still data to be restored in the partial backup data. Therefore, the I / O control program P150 proceeds to S7140 and further executes the processing steps S7140 to S7190 for the partial backup data.

[0234] On the other hand, if the reference block does not exist in the partial backup data and it is the end of the data included in the partial backup data (S7190: Yes), the I / O control program P150 determines whether the reference bit is the end of the bitmap (S7200).

[0235] As a result, if the reference bit is not at the end of the bitmap (S7200: No), it means that the next partial backup data exists in another object, so the I / O control program P150 proceeds to step S7120 and performs the processing in steps S7140 to S7190 for the next partial backup data.

[0236] On the other hand, if the reference bit is at the end of the bitmap (S7200: Yes), it means that writing to all the data in the backup data is complete, so the I / O control program P150 terminates processing.

[0237] Next, we will explain the object reception and conversion process.

[0238] Figure 21 is a flowchart of the object reception and conversion process according to the first embodiment.

[0239] Object reception and conversion processing involves retrieving the target data object (target object) from the object store and converting the retrieved object into binary data.

[0240] When the I / O control program P150 obtains the object key that indicates the object of the target data (S8100), it identifies the access ID and secret key of the target object store from the registration information of the object store (information registered as shown in Figure 8B), and uses the access ID and secret key to perform a predetermined calculation and create authentication information (S8110).

[0241] Next, the I / O control program P150, using the API communication management function P1536, configures a GET command with authentication information, transmission date and time, etc. as HTTP headers (S8120), and requests the target object from the object store via REST API communication (S8130).

[0242] The I / O control program P150 receives a response containing an object from the object store (S8200), checks the received data using MD5 to verify that there are no errors in the data (S8210). If there are no errors in the data, the I / O control program P150 decodes the received data, for example, using BASE64, converts it to binary data (S8220), copies the converted binary data to a memory area for data storage (buffer memory) (S8230), and terminates processing.

[0243] Next, we will explain a specific example of the restore process using Figures 22A to 22D.

[0244] Here, in Figures 22A to 22D, we will explain an example where snapshots SS01, SS02, and SS03 are taken in the storage system 10, and when each snapshot is taken, incremental backups are performed so that backup data BA01 corresponding to snapshot SS01, backup data BA02 corresponding to snapshot SS02, and backup data BA03 corresponding to snapshot SS03 are stored in bucket 2310 of object store 231.

[0245] For example, if snapshot SS01 is defined as data units "A", "B", and "C", snapshot SS02 as data units "A'", "B", and "C", and snapshot SS03 as data units "A'", "B'", and "C'", then backup data BA01 will be defined as data units "A", "B", and "C", backup data BA02 as data unit "A'", and backup data BA03 as data units "B'" and "C'".

[0246] First, let me explain the first specific example.

[0247] Figure 22A is a diagram illustrating a first specific example of the restore process according to the first embodiment.

[0248] Figure 22A shows an example in storage system 10 where snapshot SS01 has been deleted, and snapshots SS02 and SS03 exist, and the volume corresponding to the third generation snapshot SS03 is selected as the restore target and restored to volume R00.

[0249] In this example, by executing the restore process shown in Figure 19, the I / O control program P150 obtains catalog data corresponding to the backup data BA03 at the time of the restore target (S6100), and uses this catalog data to check whether a snapshot SS03 for the volume to be restored in the storage system 10 is available. In this example, the I / O control program P150 determines that snapshot SS03 is available (S6110: Yes). As a result, the I / O control program P150 restores volume R00 based on snapshot SS03 (P1: S6121). In this example, since no other catalogs are registered in the processing list (S6140: No), the I / O control program P150 completes the restore process.

[0250] This process allows for the rapid restoration of a volume corresponding to the third generation snapshot to volume R00 of storage system 10 without retrieving backup data from the datastore. Furthermore, if there are charges associated with retrieving data from the object store, this process reduces the amount of data retrieved from the object store, thereby lowering data retrieval costs.

[0251] Next, I will explain the second specific example.

[0252] Figure 22B illustrates a second specific example of the restore process according to the first embodiment.

[0253] Figure 22B shows an example in storage system 10 where snapshots SS01 and SS02 have been deleted, and snapshot SS03 exists, and the volume corresponding to the second generation snapshot SS02 is selected as the restore target and restored to volume R00.

[0254] In this example, by executing the restore process shown in Figure 19, the I / O control program P150 obtains catalog data corresponding to the backup data BA02 at the time of the restore target (S6100), and uses this catalog data to check whether a snapshot SS02 for the volume to be restored in the storage system 10 is available. In this example, the I / O control program P150 determines that snapshot SS02 is not available (S6110: No), and adds the catalog data corresponding to backup data BA02 to the processing list. Next, since backup data BA02 has a parent generation backup data BA01 (S6130: Yes), the I / O control program P150 obtains the catalog data for backup data BA01 and checks the corresponding snapshot. As a result, since the corresponding snapshot SS01 does not exist, the I / O control program P150 adds the catalog data for backup data BA01 to the processing list. Subsequently, since the processing list contains catalog data for backup data BA01 and backup data BA02, the I / O control program P150 executes the processes in steps S6150 to S6170, performing process P2 to restore volume R00 to its first-generation state using the catalog data and metadata for backup data BA01, and then performing process P3 to restore volume R00 to its second-generation state using the catalog data and metadata for backup data BA02.

[0255] This process allows the volume corresponding to the second generation snapshot to be restored to volume R00 of storage system 10.

[0256] Next, I will explain the third specific example.

[0257] Figure 22C illustrates a third specific example of the restore process according to the first embodiment.

[0258] Figure 22C shows an example where a volume corresponding to the third-generation snapshot SS03 is restored to volume R01 on a storage system 10' that is different from storage system 10, which does not have a snapshot of the volume to be restored.

[0259] In this example, since no snapshots exist in the storage system 10', the I / O control program P150 adds the catalog data of backup data BA03, BA02, and BA01 to the processing list by executing the restore process shown in Figure 19 (S6120). As a result, the I / O control program P150 executes the processes in steps S6150 to S6170, performing process P4 to restore volume R00 to the first generation state using the catalog data and metadata for backup data BA0, then performing process P5 to restore volume R00 to the second generation state using the catalog data and metadata for backup data BA02, and then performing process P6 to restore volume R00 to the third generation state using the catalog data and metadata for backup data BA03.

[0260] This process stores the metadata and catalog data of the backup data in the object store along with the backup data itself. Since this data can be used, even storage systems that have not been backed up can have their desired volumes properly restored.

[0261] Next, I will explain the fourth specific example.

[0262] Figure 22D illustrates a fourth specific example of the restore process according to the first embodiment.

[0263] Figure 22D shows an example of restoring the volume corresponding to the third generation snapshot SS03 to volume R00 in storage system 10, where snapshot SS01 has been deleted, and snapshots SS02 and SS03 exist, but snapshot SS03 is unavailable for some reason.

[0264] In this example, by executing the restore process shown in Figure 19, the I / O control program P150 finds that the snapshot SS03 corresponding to the backup data BA03 is unavailable, and therefore adds the catalog data of backup data BA03 to the processing list (S6120). Next, the I / O control program P150 finds that the parent generation backup data BA02 exists and obtains the catalog corresponding to backup data BA02 (S6141). Since the storage system 10 has the snapshot SS02 corresponding to backup data BA02 available, the I / O control program P150 restores volume R00 to the second generation state by restoring snapshot SS02 to volume R00 (P7:S6121). Subsequently, the I / O control program P150 executes the processes in steps S6150 to S6170 to perform process P8, which restores volume R00 to the third generation state using the catalog data and metadata for backup data BA03.

[0265] This process allows the storage system 10 to use snapshots of previous generations of the volume to be restored (second-point-of-life snapshots) that are stored in the storage system 10, even if they do not contain a snapshot of the volume to be restored. If a snapshot of a previous generation of the volume (second-point-of-life snapshot) is stored in that generation, that snapshot can be used, and subsequent backup data (subsequent incremental data) can be retrieved from the datastore. This eliminates the need to retrieve all generations of backup data from the datastore and restore the volume to be restored appropriately and quickly. Furthermore, if there are charges for retrieving data from the object store, the amount of data retrieved from the object store can be reduced, thereby lowering the data retrieval cost.

[0266] Next, a modified example of the computer system according to the first embodiment will be described.

[0267] In the first embodiment of the computer system 1, all backup data objects, metadata related to the backup data, and catalog data were stored in the object store 231 of the object storage system 230. However, for example, the catalog data may be stored and managed as a catalog data table in the database system 220 of the cloud system 20.

[0268] Figure 23 is a diagram showing the configuration of a catalog data table according to a modified example of the first embodiment.

[0269] The catalog data table T1000 stores records (entries) for each catalog. Each record in the catalog data table T1000 includes the following fields: key T1001, device product number T1002, backup volume number T1003, volume usage / provisioning size T1004, snapshot generation number T1005, snapshot acquisition date and time T1006, metadata object key T1007, and parent catalog key T1008.

[0270] In the key T1001, an identification name (key) of the catalog data is stored. In the device product number T1002, the device product number of the storage system 10 is stored. In the backup volume number T1003, a volume number for identifying the logical volume to be backed up is stored. In the Volume usage / provisioning size T1004, the provisioning size (allocated capacity) and the used size of the logical volume to be backed up are stored. In the Snapshot generation number T1005, the generation number of the snapshot corresponding to the catalog data is stored. In the Snapshot acquisition date and time T100, the acquisition date and time of the snapshot corresponding to the catalog data are stored. In the metadata object key T1007, an object key indicating the object that is checking the metadata corresponding to the catalog data is stored. In the parent catalog key T1008, an identification name (key) indicating the catalog data at the time of backup of the parent generation (the immediately preceding generation) is stored.

[0271] In this catalog data table T1000, the object-form catalog data shown in FIGS. 16A and 16B are managed as records respectively.

[0272] In the storage system according to the modified example, instead of performing the process shown in FIG. 18 as the backup list acquisition process, a plurality of catalog data may be acquired by issuing a NoSQL command once to the database system 220. For this reason, the backup list acquisition process can be performed quickly. Also, in the storage system according to the modified example, in the backup process and the restore process, it is not necessary to perform the process of performing object conversion or inverse conversion for the catalog data.

[0273] Next, the computer system according to the second embodiment will be described.

[0274] The computer system according to the second embodiment does not directly configure the backup method, but automatically selects either a full backup or an incremental backup, taking into account the costs associated with the object store service or the time required for restoration. In the second embodiment, the differences from the first embodiment will be described in detail, and redundant descriptions may be omitted.

[0275] Figure 24 shows the backup schedule setting screen according to the second embodiment.

[0276] The backup schedule setting screen D31, compared to the schedule setting screen D30 of the first embodiment shown in Figure 10, includes a backup policy setting area D305 and a deletion policy setting area D306 instead of the backup method selection area D304.

[0277] The backup policy setting area D305 is where you select the backup policy. The backup policy setting area D305 includes a time-based selection button D3051 for selecting a time-based method for choosing between full backups or incremental backups, a cost-based selection button D3052 for selecting a method based on restore costs, and a threshold setting area D3053 for setting the thresholds used for selection.

[0278] When the time-based selection button D3051 is selected, a backup method is used in which, with the full backup time set to 1.0, a new full backup is performed if the total time of the full backup and incremental backup exceeds a threshold (the threshold in setting area D3053), and an incremental backup is performed otherwise. This backup method is suitable when you want to keep the backup time or restore time below a certain level.

[0279] If the cost-based selection button D3052 is selected, and assuming the estimated restore cost for a full backup is 1.0, a new full backup will be performed if the total estimated restore cost of a full backup and an incremental backup exceeds a threshold (the threshold in setting area D3053). Otherwise, an incremental backup will be performed. This backup method is suitable when you want to keep the restore cost below a certain level.

[0280] The deletion policy setting area D306 is where you select the policy for handling the deletion of old backup datasets. Here, "old backup datasets" refers to the backup data set consisting of previous full backups and incremental backups when a new full backup is taken.

[0281] The deletion policy setting area 306 includes a "Delete Old Backup Dataset" button D3061 and a "Archive Old Backup Dataset" button D3062. If the "Delete Old Backup Dataset" button D3061 is selected, the storage system 10 deletes the old backup dataset. If the "Archive Old Backup Dataset" button D3062 is selected, the storage system 10 moves the old backup dataset to the archive tier of the object store.

[0282] Next, the backup process using the storage system according to the second embodiment will be described.

[0283] Figure 25 is a flowchart of the backup process according to the second embodiment. Note that parts similar to those in the backup process according to the first embodiment shown in Figure 11 are denoted by the same reference numerals, and redundant explanations may be omitted.

[0284] When the I / O control program P150 receives an operation command from the backup management function P1670, it uses the Point-in-Time copy function P1530 ​​to take a snapshot of the logical volume to be backed up (target logical volume) (S2100).

[0285] Next, the I / O control program P150 checks the configured backup policy (S2101).

[0286] If the backup policy specifies a time-based backup (S2101: Time-based), the I / O control program P150 calculates the Ratio by dividing the total backup time by the time taken for the previous full backup (S2102), and proceeds to step S2104.

[0287] On the other hand, if the backup policy specifies a cost-based approach for restoration (S2101: Cost-based), the I / O control program P150 calculates a Ratio by dividing the maximum restore cost, i.e., the cost of restoring the full backup and all previous incremental backups, by the estimated restore cost of the previous full backup (S2103), and proceeds to step S2104.

[0288] In step S2104, the I / O control program P150 determines whether the Ratio exceeds a set threshold. If the Ratio exceeds the threshold (S2104: Yes), the I / O control program P150 sets the backup method to full backup (S2105). If the Ratio does not exceed the threshold (S2104: No), the backup method is set to incremental backup (S2106).

[0289] Next, the I / O control program P150 executes the processes in steps S2110 to S2230.

[0290] Next, the I / O control program P150 calculates the backup time required for this time (S2231). The backup time required for this time can be obtained by measuring the time required from step S2130 to S2230 in advance.

[0291] Next, the I / O control program P150 acquires the capacity of the object store consumed this time and the number of objects transferred (S2232), and calculates the cost required for restoration based on the capacity and the number of objects (S2233). Specifically, the I / O control program P150 obtains the transfer cost by multiplying the capacity of the consumed object store by the transfer capacity unit price, obtains the request cost by multiplying the number of transferred objects by the request unit price, and calculates the cost by summing these. If other charges occur by the cloud service provider, they may also be considered.

[0292] Next, the I / O control program P150 updates the total backup time by adding the backup time required for this time to the total backup time until the previous time, and updates the maximum restoration cost by adding the calculated cost to the maximum restoration cost (S2234). Also, if this is a full backup, the I / O control program P150 updates the full backup time and the full restoration cost (S2235). The subsequent processing is the same as the backup processing shown in FIG. 11.

[0293] Next, the old backup set disposal process by the storage system according to the second embodiment will be described.

[0294] FIG. 26 is a flowchart of the old backup set disposal process according to the second embodiment. The old backup set disposal process is executed in cooperation with the backup management function P1670 of the I / O control program P150 and the storage management program P160, for example, when a full backup is performed in the backup process shown in FIG. 25.

[0295] The backup management function P1670 acquires catalog data (catalog data set) for past backup data in the same manner as in Figure 18 (S9100). Next, the backup management function P1670 traces the parent generations sequentially from the catalog data for the previous backup, identifying the backup group whose parent is the previous full backup as the backup group to be disposed of, which is to be deleted or archived (S9110), and passes the catalog data of the backup group to be disposed of and the object key of this catalog data to the I / O control program P150.

[0296] Next, the I / O control program P150 refers to each catalog data passed to it and obtains the object key of the metadata object corresponding to the backup data corresponding to each catalog data (S9120). Then, the I / O control program P150 uses the obtained object key to obtain the metadata and obtains one or more object keys (object key group) of one or more objects of the backup data stored in the metadata (S9130). Through the above process, the set of catalog data, metadata, and backup data to be disposed of can be identified.

[0297] Next, the I / O control program P150 checks the deletion policy setting (S9140). If the deletion policy is set to delete (S9140: Delete), it uses the acquired object keys to delete the corresponding metadata and backup data objects from the object store 231 (S9200), deletes the corresponding catalog data from the object store 231 (S9210), and then terminates the process.

[0298] On the other hand, if the deletion policy is set to Archive (S9140: Archive), the I / O control program P150 uses the acquired object keys to move the corresponding metadata and backup data objects to the archive layer of object store 231 (S9300), and then rewrites the object keys of the metadata for each catalog data to point to the metadata objects in the archive layer (S9310) so that it is clear that this data has been moved to the archive layer, and then terminates the process.

[0299] According to the above process, old backup sets stored in the object store can be disposed of appropriately.

[0300] It should be noted that the present invention is not limited to the embodiments described above, and can be implemented with appropriate modifications without departing from the spirit of the invention.

[0301] For example, in the above embodiment, some or all of the processing performed by the processor may be performed by hardware circuits. Also, the program in the above embodiment may be installed from a program source. The program source may be a program distribution server or a storage medium (e.g., a portable storage medium). [Explanation of Symbols]

[0302] 1…Computer system, 10…Storage system, 20…Cloud system, 150…I / O control subsystem, 151…Processor, 160…Storage management subsystem, 230…Object storage system, 231…Object store

Claims

1. It connects to a cloud system that provides object storage via the network. A data control device that backs up backup data of a predetermined volume having multiple data as objects to the object store, The data control device comprises a processor, The aforementioned processor, When backing up the data on the aforementioned predetermined volume, With respect to the data to be backed up, the system generates backup data which is the difference between the backup data and other data stored in the object store, and catalog information which includes the identification information of the predetermined volume and the identification information of the other data used as the comparison source for the backup data. The backup data and the catalog information are objectified and stored in the object store. When restoring the aforementioned backed-up volume, Based on the catalog information, the object to be used for restoration is identified and read from the object store, and the predetermined volume is restored. Data control device.

2. Further generating metadata for the data to be backed up, which includes difference information indicating whether there is a difference between it and the other data and whether there is data in the backup data, and storing it in the object store, When restoring the backed-up predetermined volume, the predetermined volume is restored based on the catalog information and the metadata. The data control device according to claim 1.

3. When restoring the aforementioned backed-up volume, Based on the comparison source data of the catalog information, identify the object to be used for restoration. The data control device according to claim 1.

4. The processor of the aforementioned data control device is Selectively use multiple backup methods from the following: full backup using dummy data as the other data, incremental backup using the previously backed-up data as the other data, and differential backup using predetermined data as the other data multiple times. The data control device according to claim 3.

5. The catalog information for the incremental backup and the differential backup includes identification information for the source data, while the catalog information for the full backup does not include identification information for the source data. The process of identifying objects to be used for restoration based on the source data of the catalog information is carried out until the identification information of the source data of the catalog information is no longer available. Characterized by The data control device according to claim 4.

6. The aforementioned processor, The aforementioned data is a snapshot, For the volume to be restored, it is possible to specify the snapshot generation for the restoration. Based on the specified generation, the catalog information, and the metadata difference information, the backup data to be used for the restore and the data within it are selected. The data control device according to claim 2.

7. The aforementioned processor, The system accepts the specification of the volume to be restored. The system retrieves catalog information related to the volume to be restored from the object store, and displays a selectable generation of the volume to be restored based on the catalog information. The data control device according to claim 6.

8. The aforementioned processor, The backup method is selected based on backup time or backup cost. The data control device according to claim 4.

9. The aforementioned processor, The system receives an instruction to register an object store for storing backups of the aforementioned volume. The system determines whether access is possible by actually accessing the object store that has been instructed to do so. If it is determined that the object store is accessible, the object store is registered as an object store for storing backups of the volume. The data control device according to claim 1.

10. A data control method by a data control device that connects to a cloud system providing an object store via a network and backs up backup data of a predetermined volume having multiple data as objects to the object store, The data control device is When backing up the data on the aforementioned predetermined volume, With respect to the data to be backed up, the system generates backup data which is the difference between the backup data and other data stored in the object store, and catalog information which includes the identification information of the predetermined volume and the identification information of the other data used as the comparison source for the backup data. The backup data and the catalog information are objectified and stored in the object store. When restoring the aforementioned backed-up volume, Based on the catalog information, the object to be used for restoration is identified and read from the object store, and the predetermined volume is restored. Data control method.

Citation Information

Patent Citations

  • Data compression technology and data storage technology

    JP2009533731A

  • Computer system and method for managing hierarchy of journal

    JP2010079526A

  • Method and system for executing increment SQL server database backup

    JP2012146301A

  • A distributed backup system that determines the access destination based on multiple performance metrics.

    JP2015529861A

  • Data restoration using block disk presentations

    US20170329543A1