Backup system, backup device, backup method, backup device control method and program
The backup system enables reduced backup device count and increased availability by having multiple servers back up data among themselves and a single backup device take over processing, addressing the complexity and strain issues in existing systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- MITSUBISHI ELECTRIC CORP
- Filing Date
- 2022-04-08
- Publication Date
- 2026-04-24
AI Technical Summary
Existing backup systems for high reliability and availability systems face challenges in reducing the number of backup devices while maintaining system availability, as they often require one backup device per server, leading to increased complexity and potential network strain.
A backup system comprising multiple servers that backup data among themselves and a single backup device capable of taking over the processing of failed servers, with the backup device storing application programs for each server, allowing it to take over processing and data backup in case of failures.
This approach enhances system availability by reducing the number of backup devices required and minimizing network strain, while ensuring seamless continuity of processing and data backup operations.
Smart Images

Figure 0007851173000001 
Figure 0007851173000002 
Figure 0007851173000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a backup system, a backup device, a backup method, a control method for a backup device, and a program.
Background Art
[0002] In systems that require high reliability and high availability, in case an abnormality occurs in a server, the server is multiplexed or a backup of the data held by the server is taken. For example, in Patent Document 1, in order to suppress an increase in backup devices that becomes a problem when a backup device is provided individually for each server and data is backed up to the backup device, a method of backing up data of a plurality of servers with one backup device is described.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, according to the technique described in Patent Document 1, it is possible to reduce the number of backup devices when acquiring a backup of data, but the processing performed by the server cannot be continued, and there is a problem that the availability of the system is not considered.
[0005] The present disclosure has been made in view of the above, and an object thereof is to obtain a backup system that can suppress an increase in the number of devices constituting the system when comparing with the same multiplexing number while enhancing the availability of the system.
Means for Solving the Problems
[0006] To solve the aforementioned problems and achieve the objectives, the backup system relating to this disclosure comprises multiple servers, a backup device capable of substituting for the processing of the multiple servers, and taking over the processing of the server that fails if any of the multiple servers fail, and each of the multiple servers backs up the data it holds between servers. The backup device is normally connected to multiple servers and does not normally hold backup data for all of them. If an error occurs in any of the servers, the server that holds the backup data for the failed server sends the backup data to the backup device. The backup device uses the backup data sent by the server to take over the processing of the failed server, and then takes over the data backup processing that the failed server was performing. It is characterized by the following: [Effects of the Invention]
[0007] According to this disclosure, it is possible to enhance the availability of the system while suppressing the increase in the number of devices that make up the system when compared with the same number of redundancies. [Brief explanation of the drawing]
[0008] [Figure 1] Diagram showing an overview of the backup system according to Embodiment 1. [Figure 2] Figure 1 is a diagram illustrating the data backup method in the backup system shown. [Figure 3] A sequence diagram illustrating the data backup of the server shown in Figure 1. [Figure 4] This sequence diagram illustrates the operation of the backup system shown in Figure 1 when an anomaly is detected on the server. [Figure 5] Figure 1 shows a sequence diagram illustrating the backup process after a server failure occurs in the backup system. [Figure 6] Figure 1 shows the functional configuration of the server. [Figure 7] Flowchart illustrating the normal operation of the data transmission unit shown in Figure 6. [Figure 8] Figure 6 is a flowchart illustrating the normal operation of the data receiving unit. [Figure 9] Figure 6 is a flowchart illustrating the operation of the abnormality management unit's abnormality notification transmission process. [Figure 10] Flowchart for explaining the operation related to the reception of an abnormality notification by the abnormality management unit shown in FIG. 6 [Figure 11] Diagram showing the functional configuration of the backup device shown in FIG. 1 [Figure 12] Flowchart for explaining the operation of the backup device shown in FIG. 11 [Figure 13] Diagram showing a configuration example of a computer system that realizes the server and backup device of Embodiment 1 [Figure 14] Sequence diagram for explaining the data backup method according to Modified Example 1 of Embodiment 1 [Figure 15] Sequence diagram for explaining the data backup method according to Modified Example 2 of Embodiment 1 [Figure 16] Sequence diagram for explaining the data backup method according to Modified Example 3 of Embodiment 1 [Figure 17] Sequence diagram for explaining the data backup method according to Modified Example 4 of Embodiment 1 [Figure 18] Diagram showing the configuration of the backup system according to Embodiment 2
Embodiments for Carrying Out the Invention
[0009] Hereinafter, a backup system, a backup device, a backup method, a control method for the backup device, and a program according to embodiments of the present disclosure will be described in detail based on the drawings.
[0010] Embodiment 1. FIG. 1 is a diagram showing an overview of a backup system 3 according to Embodiment 1. The backup system 3 includes a plurality of servers 1A to 1C and a backup device 2. Hereinafter, when it is not necessary to distinguish each of the servers 1A to 1C, they are simply referred to as server 1.
[0011] Each of the plurality of servers 1 performs predetermined processing to realize the functions provided by the system constituted by the servers 1 by executing an application program. The plurality of servers 1 are devices to be backed up in the backup system 3. The server 1 is operated as the active system. As a term paired with the active system, the standby system is used here. The active system is a system that operates normally, and the standby system is a system that waits normally.
[0012] The plurality of servers 1 constitute, for example, a monitoring control system. Examples of the processing performed by each server 1 include collection of data to be monitored, data processing, display of a monitoring screen, generation of a command for the monitoring target, etc. The monitoring target includes, for example, trains, river water levels, traffic control systems, traffic volumes on expressways, facilities constituting social infrastructure, etc.
[0013] The backup device 2 is operated as a standby system for the plurality of servers 1. One backup device 2 can replace the processing of the plurality of servers 1. Usually, in a system that requires high reliability and high availability, a standby system is often provided for each device. In this case, there is a problem that the number of devices becomes the number of servers 1 multiplied by the multiplexing factor, and the operation also becomes complicated. On the other hand, the backup device 2 according to Embodiment 1 functions as a standby system for the plurality of servers 1 with one device, so when compared with the same multiplexing factor, an increase in the number of devices can be suppressed. When an abnormality occurs in any of the plurality of servers 1, the backup device 2 takes over the processing of the server 1 in which the abnormality has occurred. Here, the abnormality referred to means a state in which it is difficult for the server 1 to continue normal processing, such as a failure of the server 1 or a failure of the communication path connected to the server 1.
[0014] For backup device 2 to take over the processing of the active server 1, it needs the application program that implements the functions of the target server 1, and the data that the target server 1 held. Backup device 2 stores the application programs that implement the functions of each of the multiple servers 1. When backup device 2 holds backup data for multiple servers 1, problems such as the disk capacity of backup device 2 being strained or the network load being concentrated may occur. In systems where the data of each server 1 is updated frequently, problems such as the disk capacity being strained and the network load being concentrated are more likely to occur. For this reason, in backup system 3, each of the multiple servers 1 backs up the data that each server 1 holds to other servers 1.
[0015] Here, we will explain backup between servers 1. In Figure 1, the data of server 1A is referred to as "Data A," and the application program that implements the functions of server 1A is referred to as "App A." Similarly, the data of server 1B is referred to as "Data B," and the application program that implements the functions of server 1B is referred to as "App B." The data of server 1C is referred to as "Data C," and the application program that implements the functions of server 1C is referred to as "App C." At this time, backup device 2 normally stores App A, App B, and App C.
[0016] In backup system 3, backup data is not stored in backup device 2, but rather backups are performed between servers 1A to 1C, with each server 1A to 1C holding backup data for the other servers 1. The backup method here is sufficient if data A, data B, and data C are each stored in two or more locations within servers 1A to 1C.
[0017] Figure 2 is an explanatory diagram of the data backup method in the backup system 3 shown in Figure 1. More specifically, in Embodiment 1, servers 1A to 1C perform data backup in a circular format. Here, a circular format is a data backup method in which each server 1 sends the data it holds to one of the multiple servers 1 such that the data movement path between the multiple servers 1 forms a circular path that goes around the multiple servers 1 and returns to its original location. The data movement path forms a circular path, and each server 1 transmits data in the same direction along the circular path. Specifically, server 1A sends data A to server 1C, server 1C sends data C to server 1B, and server 1B sends data B to server 1A. This forms a circular path that goes around servers 1A to 1C and returns to its original location.
[0018] Figure 3 is a sequence diagram illustrating the data backup of servers 1A to 1C shown in Figure 1. Server 1C sends data C to server 1B, server 1B sends data B to server 1A, and server 1A sends data A to server 1C. The same process is repeated. Note that the backup method shown here is just one example. For example, the direction in which servers 1A to 1C send data may be reversed. Also, regarding the timing of when each server 1 sends data, the order of data transmission shown in Figure 3 is just one example, and the order in which data is sent may be different, or multiple servers 1 may send data simultaneously. For simplicity, here, the data that each server 1 sends is expressed as "data A, data B, data C," but each server 1 can achieve data equivalence between its own data and the backup data held by the destination server 1 by sending only the difference between its own data and the backup data held by the destination server 1.
[0019] As explained above, under normal circumstances when no abnormality occurs in Server 1, Servers 1A to 1C are operational, and Backup Device 2 is in standby mode. At this time, each of Servers 1A to 1C sends its own data to the other Server 1, so each of Servers 1A to 1C holds both its own data and the backup data of the other Server 1. Since data backup is performed between Server 1, under normal circumstances, Backup Device 2 does not need to hold backup data for multiple Server 1s.
[0020] Figure 4 is a sequence diagram illustrating the operation when an abnormality is detected in server 1A in the backup system 3 shown in Figure 1. First, server 1A detects the abnormality (step S101). Server 1A sends an abnormality notification to the other servers 1B, 1C and backup device 2 (step S102).
[0021] Server 1C, which holds backup data for Server 1A where the anomaly occurred, sends data A to backup device 2 (step S103).
[0022] Backup device 2 saves data A (step S104). Backup device 2 also starts application A, which is an application that implements the functions of server 1A where the failure occurred (step S105). Backup device 2 takes over the processing of server 1A using data A (step S106).
[0023] Furthermore, backup device 2 also takes over the backup process that was being performed by server 1A when the malfunction occurred. Figure 5 is a sequence diagram illustrating the backup process after a malfunction occurs in server 1A in the backup system 3 shown in Figure 1.
[0024] After a malfunction occurs in server 1A and backup device 2 takes over the processing that server 1A was performing, backup device 2 sends data A to server 1C and receives data B from server 1B, just as server 1A did, and holds the backup data for server 1B. Server 1B sends data B to backup device 2 on behalf of server 1A. Server 1C receives data A from backup device 2 on behalf of server 1A.
[0025] The above describes the overview of the functions of backup system 3. Below, we will describe the detailed functional configuration and operation of each device.
[0026] Figure 6 shows the functional configuration of servers 1A to 1C shown in Figure 1. Here, the configuration common to servers 1A to 1C is described, and therefore referred to as Server 1. Server 1 includes a data storage unit 10, a backup data storage unit 11, a data equivalence unit 12, an error management unit 13, and a backup data migration unit 14. The data equivalence unit 12 includes a data transmission unit 121 and a data reception unit 122. The error management unit 13 includes an error detection unit 131, an error notification transmission unit 132, and an error notification reception unit 133. Note that only the functions necessary to realize the functions of backup system 3 are shown here; in reality, Server 1 also has functions other than those shown in Figure 6.
[0027] The data storage unit 10 stores the data of Server 1 itself. For example, the data storage unit 10 of Server 1A stores data A, the data storage unit 10 of Server 1B stores data B, and the data storage unit 10 of Server 1C stores data C. The backup data storage unit 11 stores backup data of other Servers 1. For example, in the example shown in Figure 2, the backup data storage unit 11 of Server 1A stores data B, the backup data storage unit 11 of Server 1B stores data C, and the backup data storage unit 11 of Server 1C stores data A.
[0028] The data equivalence unit 12 performs equivalence processing to bridge the gap between the backup data and the data held by Server 1 itself. Specifically, the data transmission unit 121 of the data equivalence unit 12 transmits to another Server 1 the difference between the data stored in the data storage unit 10 and the data stored in the data storage unit 10 at the time of the previous data transmission, as backup data. The data reception unit 122 receives the backup data from the other Server 1 and stores the received backup data in the backup data storage unit 11. The backup data received here is the difference between the previous backup data stored in the backup data storage unit 11 and the data stored in the source Server 1 at the time of backup data transmission. Therefore, by reflecting the received backup data in the backup data storage unit 11, the data reception unit 122 can equivalentize the backup data stored in the backup data storage unit 11 with the data stored in the source Server 1 of the backup data.
[0029] The anomaly management unit 13 manages anomalies that occur in server 1 of the backup system 3. Specifically, the anomaly management unit 13 includes an anomaly detection unit 131 that detects anomalies in server 1 itself, an anomaly notification transmission unit 132 that sends an anomaly notification, which is information to inform other devices of the anomaly when the anomaly detection unit 131 detects an anomaly, and an anomaly notification receiving unit 133 that receives anomaly notifications to inform other servers 1 of anomalies. The anomaly notification includes, for example, information indicating that an anomaly has occurred and information indicating the source of the anomaly.
[0030] When the anomaly detection unit 131 detects an anomaly, the anomaly notification transmission unit 132 sends an anomaly notification to the other server 1 and the backup device 2. The anomaly notification receiving unit 133 receives the anomaly notification from the other server 1. When the anomaly notification receiving unit 133 receives an anomaly notification, it outputs the anomaly notification to the backup data migration unit 14.
[0031] When an abnormality notification is output from the abnormality notification receiving unit 133, the backup data migration unit 14 determines whether or not it holds backup data for the server 1 where the abnormality originated. If it holds backup data, it transmits the backup data stored in the backup data storage unit 11 to the backup device 2. If it does not hold backup data for the server 1 where the abnormality originated, the backup data migration unit 14 outputs an abnormality notification to the data equivalence unit 12.
[0032] If the backup data migration unit 14 outputs an error notification, the data equivalence unit 12 determines whether or not backup data had been sent to the server 1 where the error originated. If backup data had been sent to the server 1 where the error originated, the data equivalence unit 12 changes the destination of the backup data to the backup device 2.
[0033] Next, the operation of Server 1 will be explained. Under normal circumstances, when no abnormalities are detected, Server 1 periodically sends backup data to other Server 1s. Figure 7 is a flowchart illustrating the normal operation of the data transmission unit 121 shown in Figure 6. The data transmission unit 121 of Server 1 determines whether or not it is a predetermined backup timing (step S201). For example, the time interval for sending backup data can be predetermined, and the data transmission unit 121 can determine whether or not it is a backup timing based on whether or not a predetermined amount of time has elapsed since the last backup data was sent.
[0034] If it is a backup timing (step S201: Yes), the data transmission unit 121 generates backup data from the data stored in the data storage unit 10 and transmits the generated backup data (step S202). The backup data may be all the data stored in the data storage unit 10 at the time of the backup timing, or, as described above, it may be data showing the difference between the data stored in the data storage unit 10 at the time the previous backup data was transmitted and the data currently stored in the data storage unit 10. After transmitting the backup data, and if it is not a backup timing (step S201: No), the data transmission unit 121 repeats step S201.
[0035] Figure 8 is a flowchart illustrating the normal operation of the data receiving unit 122 shown in Figure 6. The data receiving unit 122 determines whether or not it has received backup data from another server 1 (step S203). If backup data is received (step S203: Yes), the data receiving unit 122 stores the received backup data in the backup data storage unit 11 (step S204). After storing the backup data in the backup data storage unit 11, and if no backup data has been received (step S203: No), the data receiving unit 122 repeats the process in step S203.
[0036] Figure 9 is a flowchart illustrating the operation of the abnormality management unit 13, as shown in Figure 6, regarding the transmission of abnormality notifications. The abnormality detection unit 131 of the abnormality management unit 13 checks whether an abnormality has occurred (step S301). The abnormality detection unit 131 determines whether an abnormality has occurred (step S302). If an abnormality has occurred (step S302: Yes), the abnormality notification transmission unit 132 sends an abnormality notification to other devices (step S303). Specifically, the abnormality notification transmission unit 132 sends an abnormality notification to other servers 1 and backup device 2. For example, if server 1 is server 1A, the abnormality notification transmission unit 132 of server 1A sends an abnormality notification to servers 1B, 1C and backup device 2. If no abnormality has occurred (step S302: No), the abnormality detection unit 131 repeats the process from step S301. The operation in Figure 9 is repeated.
[0037] Figure 10 is a flowchart illustrating the operation of the abnormality management unit 13 shown in Figure 6 regarding the reception of abnormality notifications. The abnormality notification receiving unit 133 checks whether or not there is an abnormality notification to receive (step S401). The abnormality notification receiving unit 133 determines whether or not there is an abnormality notification to receive (step S402). If there is no abnormality notification (step S402: No), the abnormality notification receiving unit 133 repeats the process from step S401.
[0038] If an abnormality notification is received (Step S402: Yes), the abnormality notification receiving unit 133 outputs the abnormality notification to the backup data migration unit 14, and the backup data migration unit 14 determines whether or not it holds backup data for the server 1 where the abnormality occurred (Step S403). If it holds backup data for the server 1 where the abnormality occurred (Step S403: Yes), the backup data migration unit 14 sends the backup data for the server 1 where the abnormality occurred to the backup device 2 (Step S404), and the process ends.
[0039] If backup data for server 1 where the anomaly occurred is not held (step S403: No), the backup data migration unit 14 outputs an anomaly notification to the data equivalence unit 12, and the data equivalence unit 12 determines whether or not backup data had been sent to server 1 where the anomaly occurred (step S405). If backup data had not been sent to server 1 where the anomaly occurred (step S405: No), the data equivalence unit 12 terminates processing. If backup data had been sent to server 1 where the anomaly occurred (step S405: Yes), the data equivalence unit 12 changes the destination of the backup data to backup device 2 (step S406) and terminates processing. The operation in Figure 10 is repeated.
[0040] Figure 11 shows the functional configuration of the backup device 2 shown in Figure 1. The backup device 2 includes an input processing unit 21, a switching control unit 22, a backup data storage unit 23, and an application program storage unit 24.
[0041] The input processing unit 21 is connected to multiple servers 1 and receives abnormality notifications from a server 1 where an abnormality has occurred, and receives backup data from a server 1 that holds backup data of the server 1 where the abnormality occurred. When the input processing unit 21 receives an abnormality notification, it outputs the received abnormality notification to the switching control unit 22. When the input processing unit 21 receives backup data, it stores the received backup data in the backup data storage unit 23.
[0042] When the input processing unit 21 outputs an abnormality notification, the switching control unit 22 performs a switching process to take over the processing of the abnormal server 1 based on the information in the abnormality notification that indicates the server 1 where the abnormality occurred. Specifically, the switching control unit 22 selects an application program from among the multiple application programs stored in the application program storage unit 24 that will implement the functions of the abnormal server 1, and reads and executes the selected application program. This allows the switching control unit 22 to start the application that will implement the functions of the abnormal server 1. At this time, the switching control unit 22 takes over the processing of the abnormal server 1 using the backup data of the abnormal server 1 stored in the backup data storage unit 23.
[0043] The backup data storage unit 23 does not normally hold backup data, but when the input processing unit 21 receives backup data from server 1, the received backup data is stored in the storage unit. In the backup system 3, if an abnormality occurs in any of the multiple servers 1, the other servers 1 that hold the backup data of the abnormal server 1 will send the backup data to the backup device 2. Therefore, the backup data storage unit 23 will store the backup data of the abnormal server 1 if an abnormality occurs in any of the multiple servers 1 in the backup system 3.
[0044] The application program storage unit 24 stores multiple application programs necessary to implement the functions of the server 1 to be backed up in the backup system 3. The application program storage unit 24 stores multiple application programs even during normal operation when no abnormalities occur. In the example shown in Figure 1, the application program storage unit 24 stores three application programs represented by App A, App B, and App C.
[0045] Next, the operation of the backup device 2 will be explained. Figure 12 is a flowchart for explaining the operation of the backup device 2 shown in Figure 11. The input processing unit 21 checks whether or not an abnormality notification has been received (step S501). Based on the check result, the input processing unit 21 determines whether or not an abnormality notification has been received (step S502). If there is no abnormality notification (step S502: No), the input processing unit 21 repeats the process from step S501. If there is an abnormality notification (step S502: Yes), the input processing unit 21 outputs the abnormality notification to the switching control unit 22 and determines whether or not backup data for the server 1 where the abnormality occurred has been received (step S503). If backup data has not been received (step S503: No), the input processing unit 21 repeats the process in step S503. If backup data has been received (step S503: Yes), the input processing unit 21 stores the received backup data in the backup data storage unit 23 (step S504).
[0046] Upon receiving the abnormality notification output by the input processing unit 21, the switching control unit 22 reads the backup data and application program of the server 1 where the abnormality occurred, based on the information in the abnormality notification indicating the server 1 where the abnormality occurred, and starts the application (step S505). Specifically, the switching control unit 22 reads the application program from the application program storage unit 24 and the backup data from the backup data storage unit 23. As a result, the backup device 2 can take over the processing of the server 1 where the abnormality occurred.
[0047] Next, the hardware configuration of the server 1 and backup device 2 in this embodiment will be described. The server 1 and backup device 2 in this embodiment are implemented, for example, by a computer system.
[0048] This section describes an example configuration of a computer system that implements Server 1 and Backup Device 2. Figure 13 shows an example configuration of a computer system that implements Server 1 and Backup Device 2 according to Embodiment 1. As shown in Figure 13, this computer system comprises a control unit 101, an input unit 102, a storage unit 103, a display unit 104, a communication unit 105, and an output unit 106, which are connected via a system bus 107.
[0049] In Figure 13, the control unit 101 is, for example, a CPU (Central Processing Unit). The control unit 101 executes a computer program that describes each process performed by the server 1 and backup device 2 in this embodiment. The input unit 102 consists of, for example, a keyboard and mouse, and is used by the user of the computer system to input various information. The storage unit 103 includes various types of memory such as RAM (Random Access Memory) and ROM (Read Only Memory), and storage devices such as a hard disk, and stores the program that the control unit 101 should execute, necessary data obtained in the process of processing, etc. The storage unit 103 is also used as a temporary storage area for programs. The display unit 104 consists of an LCD (Liquid Crystal Display) or the like, and displays various screens to the user of the computer system. The communication unit 105 is a communication circuit that performs communication processing. The communication unit 105 may consist of multiple communication circuits corresponding to multiple communication methods. The output unit 106 is an output interface that outputs data to external devices such as a printer and an external storage device.
[0050] Note that Figure 13 is an example, and the configuration of the computer system is not limited to the example shown in Figure 13. For example, the computer system does not have to have an output unit 106. Also, not all of the multiple computer systems that implement Server 1 and Backup Device 2 have to be the computer systems shown in Figure 13. For example, some computer systems do not have to have at least one of the display unit 104, output unit 106, and input unit 102 shown in Figure 13.
[0051] Here, we will describe an example of the operation of the computer system until the computer program describing the processing of Server 1 and Backup Device 2 of this embodiment becomes executable. In a computer system with the above configuration, for example, a computer program is installed in the storage unit 103 from a CD-ROM or DVD-ROM set in a CD (Compact Disc)-ROM drive or DVD (Digital Versatile Disc)-ROM drive (not shown). When the computer program is executed, the computer program read from the storage unit 103 is stored in the area that becomes the main memory of the storage unit 103. In this state, the control unit 101 executes the processing of Server 1 or Backup Device 2 of this embodiment according to the computer program stored in the storage unit 103.
[0052] In the above explanation, a program describing the processing in server 1 and backup device 2 is provided using a CD-ROM or DVD-ROM as the recording medium. However, the system is not limited to this, and depending on the configuration of the computer system, the capacity of the program to be provided, a computer program provided via a transmission medium such as the Internet via the communication unit 105 may also be used.
[0053] The program of this embodiment causes the computer to take over the processing of the abnormal server 1 to the backup device 2 by executing the following steps: when an abnormality occurs in any of the multiple servers 1 to be backed up, launch an application program to implement the functions of the abnormal server 1; acquire backup data of the abnormal server 1; and execute the application program using the acquired backup data.
[0054] The data storage unit 10 and backup data storage unit 11 shown in Figure 6 are part of the storage unit 103 shown in Figure 13. The data equivalence unit 12, error management unit 13, and backup data migration unit 14 shown in Figure 6 are implemented using the control unit 101 and communication unit 105 shown in Figure 13. The input processing unit 21 shown in Figure 11 is implemented using the control unit 101 and communication unit 105 shown in Figure 13. The switching control unit 22 shown in Figure 11 is implemented using the control unit 101 shown in Figure 13. The backup data storage unit 23 and application program storage unit 24 shown in Figure 11 are part of the storage unit 103 shown in Figure 13.
[0055] Note that the functional separation of each device shown in Figures 6 and 11 is just one example, and the functional separation of each device is not limited to the example shown in Figures 6 and 11, as long as the backup system 3 can perform the operations described above.
[0056] <Example 1> In Embodiment 1 described above, an example was shown in which a backup system 3 having three servers 1A to 1C performs data backup in a circular manner. However, the number of servers 1 in the backup system 3 is not limited to three. The backup system 3 only needs to have two or more servers 1. In Modification 1, an example of a method for performing data backup in a backup system 3 having four servers 1A to 1D will be described.
[0057] Figure 14 is a sequence diagram illustrating a data backup method according to Modification 1 of Embodiment 1. In Modification 1, all four servers 1A to 1D of the backup system 3 perform data backup in a circular manner. Specifically, server 1D sends data D to server 1C, server 1C sends data C to server 1B, server 1B sends data B to server A, and server 1A sends data A to server D. Each server 1 repeats the above data backup operation.
[0058] <Modification 2> In Embodiment 1 and Modification 1 described above, an example was shown in which a backup system 3 having three or four servers 1 performs data backup in a circular format. However, the data backup method does not have to be circular. It is sufficient to ensure that the data of each server 1 is held on two or more servers 1.
[0059] Figure 15 is a sequence diagram illustrating a data backup method according to Modification 2 of Embodiment 1. In Modification 2, data backups are performed between pairs of servers 1A to 1D. In the example shown in Figure 15, data backups are performed between servers 1A and 1B, and also between servers 1C and 1D. Specifically, server 1A sends data A to server 1B, and server 1B sends data B to server 1A. Server 1C sends data C to server 1D, and server 1D sends data D to server 1C. As a result, the data from each server 1 is held on two servers 1.
[0060] <Variation 3> Embodiment 1 described above describes an example in which three servers 1 perform data backup in a circular format, Modification 1 describes an example in which four servers 1 perform data backup in a circular format, and Modification 2 describes an example in which four servers 1 perform data backup in a mutual format. Modification 3 describes an example in which five servers 1 perform data backup in a circular format.
[0061] Figure 16 is a sequence diagram illustrating a data backup method according to Modification 3 of Embodiment 1. Even when there are five servers 1, the cyclic data backup method is the same as when there are three or four servers 1.
[0062] Server 1E sends data E to Server 1D, Server 1D sends data D to Server 1C, Server 1C sends data C to Server 1B, Server 1B sends data B to Server 1A, and Server 1A sends data A to Server 1E.
[0063] <Modification 4> In Embodiment 1 and Modifications 1-3 described above, examples of performing data backup using either a circular format or a reciprocal format were explained, but both circular and reciprocal formats may be used in combination. Modification 4 describes a method in which five servers 1 perform data backup using both a circular format and a reciprocal format.
[0064] Figure 17 is a sequence diagram illustrating a data backup method according to Modification 4 of Embodiment 1. Servers 1A and 1B perform data backup in a reciprocal format, while servers 1C to 1E perform data backup in a circular format.
[0065] Server 1A sends data A to Server 1B, and Server 1B sends data B to Server 1A. Server 1E sends data E to Server 1D, Server 1D sends data D to Server 1C, and Server 1C sends data C to Server 1E.
[0066] In variations 1 to 4, the operation of each server 1 is the same as in Embodiment 1, except that the destination of the backup data changes, so a detailed explanation is omitted. The operation of the backup device 2 is also the same as in Embodiment 1.
[0067] It should be noted that, as with Embodiment 1, the backup methods shown in Modifications 1 to 4 are just examples. For example, in the case of Server 1 performing data backup in a circular format, the direction in which each Server 1 transmits data may be reversed. Also, in the case of Server 1 performing data backup in a circular format, the destination of the data transmitted by each Server 1 is just an example; it is sufficient that a circular path is formed in which the data movement path between multiple Servers 1 completes a full cycle and returns to its original location. Furthermore, regarding the timing of when each Server 1 transmits data, the illustrated order of data transmission is just an example; the order in which data is transmitted may differ, and multiple Servers 1 may transmit data simultaneously. Here, for simplicity, the data transmitted by each Server 1 is expressed as "Data A, Data B, Data C, Data D, Data E," but each Server 1 can achieve data equivalence between its own data and the backup data held by the destination Server 1 by transmitting only the difference between the data it holds and the backup data held by the destination Server 1.
[0068] As described above, according to Embodiment 1, the backup system 3 comprises a plurality of servers 1, which are the active system operating under normal conditions, and a backup device 2, which is the standby system operating under normal conditions. A single backup device 2 can replace the processing of multiple servers 1, and if an abnormality occurs in any of the multiple servers 1, it takes over the processing of the server 1 that has experienced the abnormality. Since a single backup device 2 can replace the processing of multiple servers 1, there is no need to provide a backup device 2 for each server 1, and the number of backup devices 2 can be made less than the number of servers 1. Therefore, while increasing the availability of the system, it is possible to suppress the increase in the number of devices constituting the backup system 3 when compared with the same number of redundancies.
[0069] Furthermore, according to Embodiment 1, each of the multiple servers 1 can back up the data it holds among the multiple servers 1. Therefore, the backup device 2 does not need to hold backup data for the multiple servers 1 when no abnormalities occur. If an abnormality occurs in any of the multiple servers 1, the server 1 that holds the backup data of the abnormal server 1 sends the backup data to the backup device 2. This allows the backup device 2 to take over the processing of the abnormal server 1 using the backup data sent by the server 1.
[0070] Furthermore, the backup device 2 according to Embodiment 1 normally stores multiple application programs for realizing the functions of each of the multiple servers 1. Therefore, if an abnormality occurs in any of the multiple servers 1, the application program for realizing the function of the abnormal server 1 can be started immediately. Consequently, it is possible to shorten the time it takes for the backup device 2 to take over the processing of the abnormal server 1.
[0071] Furthermore, regarding the method of performing data backup between multiple servers 1, it is sufficient that the data of one server 1 is stored in multiple servers 1. For example, a circular backup method can be used. Backup system 3 can perform circular data backup between at least some of the multiple servers 1 included in backup system 3. In the circular backup method, each of the multiple servers 1 sends the data it holds to one of the multiple servers 1 such that the data movement path between the multiple servers 1 forms a circular path that returns to the original server after completing a loop. This creates a circular data movement path between the multiple servers 1, and each server 1 sends its own data to an adjacent server 1 in the circular data movement path. The circular backup method has the advantage of being highly versatile because it does not require consideration of the number of devices, making it applicable to systems with diverse configurations.
[0072] Furthermore, in Embodiment 1, if an abnormality occurs in any of the multiple servers 1 and the backup device 2 takes over the processing of the abnormal server 1, it can also take over the data backup processing that the abnormal server 1 was performing. Specifically, when the backup device 2 takes over the processing of server 1A, it can send its own data, data A, to server 1C on behalf of server 1A, and store data B received from server 1B. In other words, after taking over the processing of server 1A, the backup device 2 will have the functions of the data storage unit 10, backup data storage unit 11, and data equivalence unit 12 shown in Figure 6. As a result, the backup system 3 will be able to continue data backup even after an abnormality occurs in any of the multiple servers 1.
[0073] Embodiment 2. Figure 18 shows the configuration of backup system 3-1 according to Embodiment 2. Although Embodiment 1 described a backup system 3 having one backup device 2, multiple backup devices 2 may be prepared.
[0074] Backup system 3-1 comprises servers 1A to 1C and backup devices 2A and 2B. The following description will primarily focus on the differences from Embodiment 1, omitting detailed explanations of aspects similar to Embodiment 1. Furthermore, in the following description, when it is not necessary to distinguish between backup devices 2A and 2B, they may simply be referred to as backup device 2.
[0075] Each of the multiple backup devices 2 is capable of substituting for the processing of the multiple servers 1 of the backup system 3-1. Each of the multiple backup devices 2 stores multiple application programs, App A, App B, and App C, which are applications for realizing the functions of servers 1A to 1C.
[0076] For example, the backup devices 2 have a predetermined order in which they will operate in the event of a failure in server 1. The backup device 2 that operates earliest is referred to as the first backup device, and the backup device 2 that operates after the first backup device is referred to as the second backup device. Here, backup device 2A is the first backup device, and backup device 2B is the second backup device. In this case, backup device 2A, which is the first backup device, operates in the same way as backup device 2 according to Embodiment 1, and if a failure occurs in any of the multiple servers 1, it takes over the functions of the server 1 that has failed. Backup device 2B, which is the second backup device, operates in the same way as backup device 2 according to Embodiment 1 when backup device 2A, which is the first backup device, is operating, and if a failure occurs in any of the multiple servers 1 and backup device 2A that are operating, it takes over the functions of the server or backup device 2A that has failed.
[0077] For example, consider a scenario where servers 1A to 1C are running, and an abnormality occurs in server 1A. In this case, backup device 2A takes over the processing of server 1A. In this case, servers 1B, 1C, and backup device 2A are running. Backup device 2A starts application A, retrieves backup data of server 1A from server 1C, and takes over the processing of server 1A. As explained in Embodiment 1, backup device 2A can also take over the data backup processing that server 1A was performing.
[0078] As described above, if a malfunction occurs in any of the operating devices while servers 1B, 1C, and backup device 2A are running, backup device 2B will activate. For example, if a malfunction occurs in server 1B, backup device 2B will start application B, retrieve backup data from server 1B from backup device 2A, and take over the processing of server 1B. Backup device 2B can also take over the data backup processing that server 1B was performing.
[0079] Furthermore, if a malfunction occurs in backup device 2A while servers 1B, 1C, and backup device 2A are operational, backup device 2B will take over the processing of backup device 2A. Specifically, backup device 2B will launch application A, retrieve data A (which is the backup data for backup device 2A) from server 1C, and take over the processing of backup device 2A.
[0080] As described above, according to Embodiment 2, the backup system 3-1 includes a plurality of backup devices 2A, 2B, and the plurality of backup devices 2 include a first backup device that takes over the processing of the server 1 that has failed when an abnormality occurs in any of the plurality of servers 1, and a second backup device that takes over the processing of the server 1 that has failed or the first backup device when an abnormality occurs in either the operating server 1 or the first backup device while the first backup device is operating. This makes it possible to increase the availability of the system while suppressing an increase in the number of devices that make up the system when compared with the same number of redundancies, similar to Embodiment 1. Furthermore, even if another abnormality occurs in the backup system 3-1 after the backup device 2 has started operating but before the server 1 that has failed has recovered, it is possible to continue the operation of the system.
[0081] In this case, the first backup device, backup device 2A, after operating in place of the server 1 that has malfunctioned, may have the functions of an error management unit 13 and a backup data migration unit 14, in addition to the functions of the data storage unit 10, backup data storage unit 11, and data equivalence unit 12 shown in Figure 6.
[0082] The configurations shown in the embodiments described above are merely examples of the content of this disclosure and can be combined with other known technologies, and parts of the configuration can be omitted or modified without departing from the gist of this disclosure.
[0083] For example, Embodiment 1 describes an example where there is one backup device 2, and Embodiment 2 describes an example where there are two backup devices 2, but there may be three or more backup devices 2. If three backup devices 2 are provided for three servers 1, the number of devices will be the same as the conventional configuration in which a backup system is provided for each device, but while the number of multiplexing devices in the conventional configuration is 2, in the above configuration with three backup devices 2, the number of multiplexing devices for each server 1 will be 4. When comparing with the same number of multiplexing devices, it is possible to suppress the increase in the number of devices, and when comparing with the same number of devices, it is possible to increase the number of multiplexing devices. [Explanation of symbols]
[0084] 1,1A~1E Server, 2,2A,2B Backup device, 3,3-1 Backup system, 10 Data storage unit, 11 Backup data storage unit, 12 Data equivalence unit, 13 Anomaly management unit, 14 Backup data migration unit, 21 Input processing unit, 22 Switching control unit, 23 Backup data storage unit, 24 Application program storage unit, 101 Control unit, 102 Input unit, 103 Storage unit, 104 Display unit, 105 Communication unit, 106 Output unit, 107 System bus, 121 Data transmission unit, 122 Data reception unit, 131 Anomaly detection unit, 132 Anomaly notification transmission unit, 133 Anomaly notification reception unit.
Claims
1. Multiple servers, A backup device capable of substituting for the processing of multiple servers, and which takes over the processing of the server that has failed if any of the servers fails, Equipped with, Each of the multiple servers backs up the data it holds between the servers. The backup device is normally connected to multiple servers and does not normally hold backup data for multiple servers. If an abnormality occurs in any of the aforementioned servers, The server holding the backup data of the server where the abnormality occurred transmits the backup data to the backup device. The backup system is characterized in that the backup device, using the backup data transmitted by the server, takes over the processing of the server that has experienced an abnormality, and then takes over the data backup processing that the server that has experienced an abnormality was performing.
2. The backup system according to claim 1, characterized in that each of the multiple servers performs data backup in a circular format, transmitting the data it holds to one of the multiple servers, such that the data movement path between the multiple servers forms a circular path that returns to the original location after completing a full circuit of the multiple servers.
3. The aforementioned backup device is Multiple application programs for implementing the respective functions of the multiple servers are stored in the system from the start. The backup system according to claim 1 or 2, characterized in that, if an abnormality occurs in any of the multiple servers, an application program for realizing the function of the server that has experienced the abnormality is launched.
4. The backup device comprises multiple such devices, Multiple backup devices, If an abnormality occurs in any of the multiple servers, a first backup device takes over the processing of the server that experienced the abnormality, When the first backup device is operating, if an abnormality occurs in either the operating server or the first backup device, a second backup device takes over the processing of the server or the first backup device that experienced the abnormality. The backup system according to claim 1 or 2, characterized by including the following:
5. Multiple servers, A backup device that is normally connected to multiple servers and capable of substituting for the processing of multiple servers, normally holds multiple application programs to realize the functions of each of the multiple servers, and normally does not hold backup data of the multiple servers, Equipped with, Each of the multiple servers backs up the data it holds between the servers. If an abnormality occurs in any of the aforementioned servers, The backup device starts the application program that it normally maintains and, using the backup data received from the server that holds the backup data of the server that has experienced an abnormality, takes over the processing of the server that has experienced an abnormality. A backup system characterized by the following features.
6. A storage unit that stores multiple application programs to implement the functions of multiple servers that are in operation under normal circumstances, An input processing unit that receives an abnormality notification sent by the server where the abnormality occurred when an abnormality occurs in any of the multiple servers, In response to the aforementioned abnormality notification, the switching control unit activates an application program stored in the storage unit that implements the function of the server where the abnormality occurred, thereby taking over the processing of the server where the abnormality occurred. Equipped with, It is a backup system capable of substituting for the processing of multiple of the aforementioned servers, Normally, multiple servers are connected, and normally, backup data for multiple servers is not stored, and the backup data is maintained between the servers. The input processing unit receives the backup data sent by the server holding the backup data of the server where the abnormality occurred in response to the abnormality notification. A backup device characterized by taking over the processing of the server that has experienced an abnormality, using the backup data received from the server, and then taking over the data backup processing that the server that has experienced an abnormality was performing.
7. Each of the multiple servers backs up the data it holds between the servers. A backup device capable of substituting for the processing of multiple servers is normally connected to multiple servers, and normally does not hold backup data for multiple servers. If an abnormality occurs in any of the aforementioned servers, The server holding the backup data of the server where the abnormality occurred transmits the backup data to the backup device. The backup method is characterized in that the backup device, using the backup data transmitted by the server, takes over the processing of the server that has experienced an abnormality, and then takes over the data backup processing that the server that has experienced an abnormality was performing.
8. The backup method according to claim 7, characterized in that each of the multiple servers performs data backup in a circular format, transmitting the data it holds to one of the multiple servers, such that the data movement path between the multiple servers forms a circular path that returns to the original location after going through all of the multiple servers.
9. The aforementioned backup device is Multiple application programs for implementing the respective functions of the multiple servers are stored in the system from the start. The backup method according to claim 7 or 8, characterized in that, if an abnormality occurs in any of the multiple servers, an application program for realizing the function of the server that has experienced the abnormality is launched.
10. If an abnormality occurs in any of the multiple backup devices, the first backup device will take over the processing of the server where the abnormality occurred. The backup method according to claim 7 or 8, characterized in that, when the first backup device is in operation, the second backup device among the plurality of backup devices takes over the processing of the server or the first backup device that is malfunctioning if a malfunction occurs in either the server or the first backup device that is in operation.
11. In a backup device that is normally on standby, It stores multiple application programs to implement the functions of each of the multiple servers that are in operation under normal circumstances. The backup device is normally connected to multiple servers and normally does not store backup data for multiple servers. The aforementioned backup data is maintained between the servers, The steps include receiving an abnormality notification sent by the server that experienced the abnormality when an abnormality occurs in any of the multiple servers, The steps include: receiving the backup data sent by a server that holds the backup data of the server where the abnormality occurred, in response to the abnormality notification; In response to the aforementioned anomaly notification, the application program that implements the function of the server where the anomaly occurred is launched from among the multiple application programs, and the processing of the server where the anomaly occurred is taken over using the backup data received from the server. After taking over the processing of the aforementioned server, the step is to take over the data backup process that the server that experienced the abnormality was performing, A method for controlling a backup device, characterized by including the following:
12. Multiple servers that are part of the active system operating under normal conditions and computers that are normally connected to them, Multiple application programs for implementing the respective functions of the multiple servers are stored, Under normal circumstances, backup data from multiple of the aforementioned servers is not stored. The aforementioned backup data is maintained between the servers, The steps include receiving an abnormality notification sent by the server that experienced the abnormality when an abnormality occurs in any of the multiple servers, The steps include: receiving the backup data sent by a server that holds the backup data of the server where the abnormality occurred, in response to the abnormality notification; In response to the aforementioned anomaly notification, the application program that implements the function of the server where the anomaly occurred is launched from among the multiple application programs, and the processing of the server where the anomaly occurred is taken over using the backup data received from the server. After taking over the processing of the aforementioned server, the next step is to take over the data backup process that was being performed by the server where the error occurred. A program characterized by causing the execution of a specific action.
Citation Information
Patent Citations
Multicontroller system
JP1995334382A
Data synchronization system, method, and program
JP2008276281A
Data backup system and data backup control method
JP2009211635A
Management system
JP2019134350A