Data recovery method and apparatus, device, and computer-readable storage medium
Patent Information
- Application Number
- PCT/CN2025/136328
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-28
- Filing Date
- 2025-11-20
- Publication Date
- 2026-10-01
Smart Images

Figure CN2025136328_01102026_PF_FP_ABST
Abstract
Description
Data recovery methods, apparatus, equipment and computer-readable storage media
[0001] This application claims priority to Chinese Patent Application No. 202510391975.X, filed on March 28, 2025, entitled “Data Recovery Method, Apparatus, Device and Computer-Readable Storage Medium”, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of storage technology, and in particular to a data recovery method, apparatus, device, and computer-readable storage medium. Background Technology
[0003] A storage system contains multiple logical unit numbers (LUNs). A LUN is a logical storage space that maps to the physical storage space within the storage system. The data stored in the physical storage space is the same as the data stored in the LUN. If the data stored in a LUN is tampered with or infected by a virus, the data stored in the LUN becomes abnormal (i.e., the LUN experiences data anomaly), affecting user access to the data. Data recovery can be performed to restore the data stored in the LUN to its normal state.
[0004] Currently, data recovery can be achieved by periodically taking snapshots of any LUN in the storage system, obtaining snapshot data of the LUN at multiple snapshot points. If a data anomaly is detected in the LUN, a relatively safe snapshot point is selected from the LUN's historical snapshot points. Based on the snapshot data of the LUN at the relatively safe snapshot point, data recovery is performed on the LUN to restore it to its data state at that relatively safe snapshot point.
[0005] Because the above data recovery method performs data recovery at the LUN granularity, the data recovery processes for different LUNs are independent of each other. If different LUNs experience data anomalies at different times, it will cause different LUNs to be restored to the data state at different snapshot times (i.e., the data states of different LUNs are out of sync). However, when the data stored in different LUNs has dependencies, this recovery method will cause the dependent data to become out of sync in time, thereby breaking the dependency relationship and affecting user services. Summary of the Invention
[0006] This application provides a data recovery method, apparatus, device, and computer-readable storage medium. When recovering data from multiple logical storage spaces in a storage system, it can restore these multiple logical storage spaces to their data state at the same point in time, without disrupting the dependencies between the data stored in the multiple logical storage spaces, thus without affecting user services. The technical solution is as follows:
[0007] Firstly, a data recovery method is provided for recovering data from multiple logical storage spaces that are related in a storage system after data loss has occurred. The logical storage space is a virtualized storage space in the storage system.
[0008] The method includes: for multiple logical storage spaces with interrelationships in a storage system, if any logical storage space experiences a data anomaly (e.g., data loss), first, acquiring snapshot data from multiple snapshot groups at a target snapshot time point; then, performing data recovery on the multiple logical storage spaces based on the acquired snapshot data. The target snapshot time point is prior to the occurrence of the anomaly.
[0009] This method synchronizes the data states of multiple logical storage spaces by restoring them to the same snapshot time (rather than different time points) when a data anomaly occurs in one of these interconnected logical storage spaces. This establishes a connection between previously independent logical storage spaces at the data recovery point. For example, even if the data stored in these logical storage spaces is dependent (e.g., files from the same application), this data recovery method will not disrupt this dependency due to inconsistencies in the recovery time points of different logical storage spaces, thus avoiding impact on user business.
[0010] In one possible implementation, the aforementioned logical storage space can be a LUN or a file system, to meet different application scenarios.
[0011] In one possible implementation, the data stored in the aforementioned multiple logical storage spaces are dependent on each other. If a data anomaly occurs in one of the logical storage spaces, the data recovery method described above will not disrupt this dependency, thus preventing any impact on user services.
[0012] In one possible implementation, the aforementioned multiple logical storage spaces are located in the same protection group, and the method further includes: after each first duration, performing a consistent snapshot of the logical storage spaces in the protection group to obtain at least one snapshot group, the snapshot group including snapshot data of the multiple logical storage spaces in the protection group at the same snapshot time point; based on this, obtaining the snapshot data of the multiple logical storage spaces at the target snapshot time point includes: determining the target snapshot group from at least one snapshot group.
[0013] Based on the above possible implementation methods, it is possible to obtain the snapshot groups of the protection group at different snapshot time points, so as to determine the target snapshot group from these snapshot groups for data recovery of the protection group.
[0014] In one possible implementation, the target snapshot group is the net snapshot group whose snapshot time point is closest to the current time among at least one snapshot group, and the clean snapshot group is the snapshot group in the protection group when there are no data anomalies in the logical storage space; based on this, the above-mentioned taking a consistent snapshot of the logical storage space in the protection group every first time interval to obtain at least one snapshot group includes: taking an anomaly detection of the logical storage space in the protection group every first time interval, taking a consistent snapshot of the logical storage space in the protection group, and determining whether the snapshot group obtained by the current consistent snapshot is a clean snapshot group based on the detection result of the current anomaly detection.
[0015] Based on the above possible implementation methods, and based on the detection results of the protection group before the consistency snapshot, it is possible to accurately determine whether the consistency snapshot is a clean snapshot group. This allows for the subsequent selection of a target snapshot group from at least one accurate clean snapshot group to perform data recovery on the logical storage space in the protection group, so as to accurately recover the normal data (i.e., data without data anomalies) previously stored in the logical storage space.
[0016] In one possible implementation, determining whether the snapshot group obtained from the current consistency snapshot is a clean snapshot group based on the detection result of the current anomaly detection includes: if a data anomaly is detected in the logical storage space of the protection group, determining whether the snapshot group obtained from the current consistency snapshot is a clean snapshot group based on the detection result of the next anomaly detection.
[0017] Based on the above possible implementation methods, it is possible to avoid misjudging the clean status of the snapshot group obtained from this consistent snapshot, thereby avoiding false alarms caused by misjudgment.
[0018] In one possible implementation, determining whether the snapshot group obtained from the current consistency snapshot is a clean snapshot group based on the detection result of the next anomaly detection includes: if no data anomaly is detected in the logical storage space of the protection group in the next detection, the snapshot group obtained from the current consistency snapshot is determined to be a clean snapshot group.
[0019] Based on the above possible implementation methods, it is possible to avoid misjudging the cleanliness of the snapshot group obtained from this consistent snapshot, thereby avoiding false alarms caused by misjudgment.
[0020] In one possible implementation, determining whether the snapshot group obtained from the current consistency snapshot is a clean snapshot group based on the detection result of the next anomaly detection includes: if a data anomaly is detected in the logical storage space of the protection group in the next instance, determining whether the snapshot group obtained from the current consistency snapshot is a clean snapshot group based on the difference data between the snapshot group obtained from the current consistency snapshot and the snapshot group obtained from the next consistency snapshot.
[0021] Based on the above possible implementation methods, it is possible to further avoid misjudging the cleanliness of the snapshot group obtained from this consistent snapshot, thereby avoiding false alarms caused by misjudgment.
[0022] In one possible implementation, before taking a consistent snapshot of the logical storage space in the protection group after each first time interval to obtain at least one snapshot group, the method further includes: receiving a protection group creation instruction, which includes identifiers of multiple logical storage spaces; and creating a protection group based on the identifiers of the multiple logical storage spaces.
[0023] Based on the above possible implementation methods, users can issue protection group creation commands through terminal devices and specify the logical storage space in the protection group through the protection group creation command. Thus, during the protection group creation process, users can flexibly specify logical storage space for the protection group according to the needs of different businesses to meet different business scenarios.
[0024] In one possible implementation, if any one of the multiple logical storage spaces experiences a data anomaly, obtaining snapshot data of the multiple logical storage spaces at the target snapshot time point includes: if any of the aforementioned logical storage spaces experiences a data anomaly and a data recovery instruction is received, obtaining snapshot data of the multiple logical storage spaces at the target snapshot time point. The data recovery instruction instructs data recovery to be performed on the multiple logical storage spaces.
[0025] Based on the above possible implementation methods, users can issue data recovery commands through terminal devices to obtain snapshot data of multiple logical storage spaces at the target snapshot time point for data recovery, which can meet the user's data recovery needs.
[0026] Secondly, a data recovery method is provided, comprising: displaying a data recovery interface; and, in response to a selection operation of a data recovery component in the data recovery interface, sending a data recovery instruction to a data recovery device. The data recovery component corresponds to multiple logical storage spaces with an association in the storage system. If any one of these logical storage spaces experiences data anomalies, and these multiple logical storage spaces support data recovery based on snapshot data from the same snapshot time point, the data recovery component instructs data recovery to be performed on the multiple logical storage spaces.
[0027] This method enables one-click recovery of data stored in multiple logical storage spaces with a relationship. Specifically, the user triggers a data recovery command through the data recovery component, so that the data recovery device can perform data recovery on the multiple logical storage spaces based on the data recovery command. For the user, it realizes one-click recovery of data in multiple logical storage spaces with a relationship, which is simple and convenient to operate, saves data recovery time, and improves data recovery efficiency.
[0028] In one possible implementation, the aforementioned logical storage space is a LUN or a file system.
[0029] In one possible implementation, there are dependencies between the data stored in the aforementioned multiple logical storage spaces.
[0030] In one possible implementation, the aforementioned multiple logical storage spaces are located in the same protection group. Before displaying the data recovery interface, the method further includes sending a protection group creation instruction to the data recovery device, the protection group creation instruction including the identifiers of the multiple logical storage spaces.
[0031] Each possible implementation of the second aspect has a corresponding implementation in the first aspect, which can achieve the beneficial effects achieved by the corresponding implementation in the first aspect, and will not be elaborated here.
[0032] Thirdly, a data recovery apparatus is provided for performing the method provided in the first aspect or any alternative manner of the first aspect.
[0033] Fourthly, a data recovery apparatus is provided for performing the method provided in the second aspect or any alternative manner of the second aspect.
[0034] Fifthly, a computing device is provided, the computing device including a processor and a memory, the memory storing program code, the processor executing the program code, causing the computing device to perform a method as provided in the first aspect above or any alternative to the first aspect above.
[0035] In a sixth aspect, a computing device cluster is provided, the computing device cluster including a plurality of computing devices, each computing device including a processor and a memory, the memory storing program code, the processor of the plurality of computing devices being configured to execute the program code stored in the memory of the plurality of computing devices, such that the computing device cluster performs a method as provided in the first aspect above or any alternative embodiment of the first aspect above.
[0036] In a seventh aspect, a terminal device is provided, the terminal device including a processor and a memory, the memory storing program code, the processor executing the program code to cause the terminal device to perform a method as provided in the second aspect above or any alternative method of the second aspect above.
[0037] Eighthly, a computer-readable storage medium is provided, the storage medium storing at least one piece of program code, the program code being read by a processor to cause a computing device or a cluster of computing devices to perform the method provided as described in the first aspect or any alternative method of the first aspect.
[0038] A ninth aspect provides a computer-readable storage medium storing at least one piece of program code that is read by a processor to cause a terminal device to perform the method provided in the second aspect above or any alternative method of the second aspect above.
[0039] In a tenth aspect, a computer program product or computer program is provided, the computer program product or computer program including program code stored in a computer-readable storage medium, a processor reading the program code from the computer-readable storage medium, the processor executing the program code, causing a computing device or cluster of computing devices to perform the method provided in the first aspect or various optional implementations of the first aspect.
[0040] Eleventhly, a computer program product or computer program is provided, the computer program product or computer program including program code stored in a computer-readable storage medium, a processor reading the program code from the computer-readable storage medium, the processor executing the program code, causing a terminal device to perform the method provided in the second aspect or various optional implementations of the second aspect.
[0041] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods. Attached Figure Description
[0042] Figure 1 is a schematic diagram of the architecture of a data recovery system provided in an embodiment of this application;
[0043] Figure 2 is a flowchart illustrating a data protection method provided in an embodiment of this application;
[0044] Figure 3 is a flowchart illustrating another data protection method provided in an embodiment of this application;
[0045] Figure 4 is a flowchart illustrating a data recovery method provided in an embodiment of this application;
[0046] Figure 5 is a flowchart illustrating a data recovery method for ransomware protection provided in an embodiment of this application;
[0047] Figure 6 is a schematic diagram of a data recovery device provided in an embodiment of this application;
[0048] Figure 7 is a schematic diagram of a data recovery device provided in an embodiment of this application;
[0049] Figure 8 is a structural schematic diagram of a terminal device provided in an embodiment of this application;
[0050] Figure 9 is a schematic diagram of the structure of a computing device provided in an embodiment of this application. Detailed Implementation
[0051] To facilitate understanding of the specific implementation methods of this application, some of the terms used in these specific implementation methods are introduced as follows.
[0052] Ransomware, also known as ransomware, is a type of malware that threatens users with ransom by encrypting their data or locking their systems. Once infected, users will be unable to access or use their important data, leading to severe financial losses and business disruptions.
[0053] A snapshot is a usable copy of a specified data set. This copy includes a mirror image (or image) of the data set at the snapshot time. In other words, a snapshot is equivalent to a copy of the data set at a certain point in time.
[0054] The embodiments of this application will now be described in further detail with reference to the accompanying drawings.
[0055] Figure 1 is a schematic diagram of the architecture of a data recovery system provided in an embodiment of this application. As shown in Figure 1, the data recovery system includes an application server 101, a storage system 102, a terminal device 103, and a data recovery device 104. The application server 101 and the data recovery device 104 can both communicate with the storage system 102, and the terminal device 103 can communicate with the data recovery device 104.
[0056] Storage system 102 provides data storage services to target applications, which are applications that use storage system 102 to store data. Target applications include, but are not limited to, database systems, network file systems (NFS), cloud service platforms, or big data processing platforms. Storage system 102 supports at least one data storage format among file storage, object storage, and block storage. The types of storage system 102 include, but are not limited to, storage area network (SAN) systems, network attached storage (NAS) systems, backup storage systems, object storage systems, file storage systems, or block storage systems.
[0057] Application server 101 is a computer running the target application. A first user can access data in storage system 102 through the target application; the first user is the user of the target application. Application server 101 can be a physical machine or a virtual machine. Physical application servers include, but are not limited to, desktop computers, servers, laptops, and mobile devices.
[0058] For example, application server 101 sends a data access request to storage system 102 to instruct whether to read or write data from storage system 102. If the request is to read data, storage system 102 returns the data it requested to read to application server 101. If the request is to write data, storage system 102 stores the data it requested to write, thereby enabling access to storage system 102.
[0059] Storage system 102 includes multiple storage devices that provide physical storage space. Storage system 102 also includes multiple logical storage spaces, which are virtualized storage spaces within storage system 102. These logical storage spaces can be mapped to the physical storage space provided by the storage devices, and the data stored in the mapped physical storage space is the same as the data stored in the logical storage space.
[0060] Logical storage space is either a LUN or a file system. A LUN is a virtualized storage space, typically referring to a logical unit. A file system is a method and data structure used by the operating system to define files on storage devices or partitions. Application server 101's data access requests can specify the logical storage space to be accessed, and thus, through the data access request, it can access the specified logical storage space to read or write data within it.
[0061] During the operation of storage system 102, data anomalies may occur in the logical storage space. These anomalies include data corruption, infection, or loss. Corruption refers to the alteration of data stored in the logical storage space, which can manifest as modification, encryption, or deletion of data, or the writing of invalid data. Infection refers to the infection of data stored in the logical storage space by a virus, which can be ransomware or non-ransomware. Ransomware infection can manifest as encryption or data alteration, while non-ransomware infection can manifest as data alteration. Corruption of data in the logical storage space equates to logical storage space corruption, and infection of data in the logical storage space equates to logical storage space infection. Ransomware infection renders the logical storage space inaccessible, while corruption or non-ransomware infection does not necessarily render the logical storage space inaccessible.
[0062] Taking ransomware infection of logical storage space as an example, ransomware may be running on any node accessing storage system 102. During the access to storage system 102, the ransomware on that node can infiltrate storage system 102 and encrypt or tamper with the data stored in the logical storage space of storage system 102 to infect the logical storage space. This node can be a virtual machine, container, or any computing instance; for example, it can be application server 101 or other devices besides application server 101.
[0063] Multiple logical storage spaces in a data recovery system are interconnected. These interconnected logical storage spaces support data consistency protection and data consistency recovery. Data consistency protection includes consistency anomaly detection and consistency snapshots. Consistency anomaly detection involves performing anomaly checks on the multiple logical storage spaces at the same point in time (the detection time point) to detect data anomalies. Consistency snapshots involve taking snapshots of the multiple logical storage spaces at the same point in time (the snapshot time point). Data consistency recovery refers to restoring the multiple logical storage spaces to their data state at the same snapshot time point based on the snapshot data taken at the same snapshot time point.
[0064] This relationship can be represented by multiple logical storage spaces located in the same group; in other words, logical storage spaces within the same group are related. Here, "group" refers to a logical storage space group, encompassing multiple logical storage spaces within the storage system. Groups support data consistency protection and data consistency recovery. Data consistency protection supported by a group refers to performing consistency anomaly detection and consistency snapshots on the logical storage spaces within the group at the group level. Data consistency recovery supported by a group refers to performing data recovery on the logical storage spaces within the group at the group level. Therefore, this group is also called a protection group.
[0065] In other embodiments, the association may also be represented as multiple logical storage spaces being located in the same group, the same set, or under the same label. Here, the embodiments of this application do not limit the way the association is represented.
[0066] The data recovery system includes a detection system, which is a type of software used to protect the data consistency of multiple logical storage spaces (i.e., logical storage spaces in a protection group) that have a logical relationship. If any logical storage space in these multiple logical storage spaces experiences a data anomaly, the system will perform data consistency recovery on these multiple logical storage spaces.
[0067] In cases where the above-mentioned anomaly detection includes virus infection detection, the detection system is also called a virus detection system, anti-virus system, etc. For example, if the virus infection detection is ransomware infection detection, the detection system can be an anti-ransomware system. An anti-ransomware system is a type of anti-ransomware software used to protect the data stored in the storage system 102 from being harmed by ransomware.
[0068] Terminal device 103 is a client device running a detection system. Terminal device 103 may include, for example, a mobile phone, a personal computer (PC), a desktop computer, a laptop, a notebook computer, a wearable device, etc., but the type of terminal device 103 is not limited to these.
[0069] Data recovery device 104 is a computing device running a detection system. The detection system can run on a single computing device, in which case that computing device is also the data recovery device 104. Alternatively, the detection system can run in a cluster of computing devices comprising multiple computers, where each computing device in the cluster is a data recovery device 104. This computing device can be a server, and the computing device cluster can be a server cluster; the servers can be local servers or cloud servers.
[0070] Figure 1 illustrates an example of terminal device 103 and data recovery device 104 being deployed in storage system 102. In other embodiments, terminal device 103 and / or data recovery device 102 may also be deployed within storage system 102. Here, this application embodiment does not limit the deployment location of terminal device 103 and data recovery device 104.
[0071] The user using the client of the detection system is referred to as the second user. The second user can be the operation and maintenance personnel of the detection system or the storage system 102. Through the client of the detection system in the terminal device 103, the second user triggers the data recovery device 104 to establish the association relationship between multiple logical storage spaces of the storage system 102 (such as establishing a protection group). This allows the data recovery device 104 to perform data consistency protection on the multiple logical storage spaces with the association relationship. If a data anomaly is detected in any of the multiple logical storage spaces, the device can perform data consistency recovery on the multiple logical storage spaces.
[0072] In the data recovery system, the terminal device interacts with the data recovery device, triggering the data recovery device to establish associations between multiple logical storage spaces in the storage system. The data recovery device can then enable data protection functions for these associated logical storage spaces, facilitating subsequent data consistency protection and recovery. The following sections will first detail the processes of establishing associations, enabling data protection functions, and implementing data consistency protection, using Figures 2 and 3 as examples. Then, the data consistency recovery process will be detailed using Figure 4.
[0073] The methods for establishing relationships with different representations for multiple logical storage spaces are similar, as are the methods for enabling data protection functions for multiple logical storage spaces with different representations of relationships, and the processes for protecting data consistency for multiple logical storage spaces with different representations of relationships. The following sections, using Figures 2 and 3 as examples and taking the representation of the relationship as a protection group, will introduce the methods for establishing relationships, enabling data protection functions, and protecting data consistency.
[0074] Figure 2 is a flowchart illustrating a data protection method provided in an embodiment of this application. This method is applied to the data recovery system described above and includes the following steps.
[0075] 201. The terminal device sends a protection group creation instruction to the data recovery device. The protection group creation instruction includes the identifiers of multiple logical storage spaces in the storage system.
[0076] The terminal device and the data recovery device are respectively the terminal device 103 and the data recovery device 104 in the aforementioned data recovery system.
[0077] The protection group creation instruction instructs the creation of a protection group based on the identifiers of the multiple logical storage spaces. The identifier of a logical storage space is used to identify that logical storage space. The logical storage space allocated to the target application in the storage system is called the first logical storage space. There are multiple first logical storage spaces in the storage system. The multiple logical storage spaces used to establish the same protection group can be all the first logical storage spaces in the storage system, or they can be a subset of the first logical storage spaces.
[0078] Data stored in multiple logical storage spaces used to establish the same protection group may have dependencies. For example, business data for the same service within a target application may be dependent on each other, and this business data may be stored in different logical storage spaces within the storage system. Therefore, in some embodiments, a protection group is created by combining multiple logical storage spaces in the storage system used to store the same business data of the target application. This protection group is then used for data consistency protection and recovery, enabling data consistency protection and recovery for business data stored in different logical storage spaces within the same service. For instance, data recovery based on snapshot data from multiple logical storage spaces within the protection group at the same snapshot time point will not disrupt the dependency relationship due to inconsistencies in the recovery time points of different logical storage spaces, thus avoiding impact on user services.
[0079] There are several ways to trigger a protection group creation command. For example, it can be triggered via a command-line interface. For instance, a second user enters a protection group creation command in the command-line interface of a terminal device, performs a send operation to send the command, and the terminal device responds by sending the protection group creation command to the data recovery device.
[0080] For example, a protection group creation command can be triggered via a user interface. For instance, the detection system's client provides a creation interface, which is a human-computer interaction interface, such as a graphical user interface (GUI), used to create protection groups. The client runs on a terminal device. A second user triggers the terminal device to display the creation interface on the client. The second user performs operations to create the protection group, specifying multiple logical storage spaces within the protection group. The terminal device responds to this operation by sending a protection group creation command to the data recovery device.
[0081] 202. The data recovery device receives the protection group creation instruction and creates a protection group based on the identifiers of the multiple logical storage spaces.
[0082] Step 202 is used to establish an association between the multiple logical storage spaces.
[0083] The data recovery device obtains the identifiers of multiple logical storage spaces from the protection group creation command, generates a protection group identifier, and generates and stores the protection group information based on the identifiers of the multiple logical storage spaces and the protection group identifier to realize the creation of the protection group. This group information includes the identifiers of the multiple logical storage spaces and the protection group identifier. The protection group identifier is used to indicate the protection group and can be the name or number of the protection group.
[0084] For steps 201 to 202 above, the second user can specify the logical storage space in the protection group through the protection group creation command. Thus, during the protection group creation process, the second user can flexibly specify the logical storage space for the protection group according to the needs of different businesses to meet different business scenarios.
[0085] Steps 201 to 202 described above are based on the example of a terminal device triggering a data recovery device to create a protection group. In other embodiments, the data recovery device can automatically create one or more protection groups for the storage system without being triggered by the terminal device. For example, the data recovery device can create protection groups for multiple logical storage spaces in the storage system that have dependencies on the data stored therein. In this case, steps 201 to 202 do not need to be executed.
[0086] 203. The data recovery device enables the data protection function for this protection group.
[0087] In this step 203, data protection is enabled for multiple logical storage spaces that are related. Data protection refers to the function of protecting and restoring data consistency of a protection group. When the data protection function is used to address a data anomaly such as ransomware infection, it is also called an anti-ransomware protection function. Of course, if the data protection function is used to address other data anomalies, it may have other names. Here, the specific name of the data protection function in this embodiment is not limited.
[0088] In some embodiments, the data protection function is enabled by default. After the protection group is created, the data recovery device automatically enables the data protection function for the protection group.
[0089] In other embodiments, after the protection group is created, the terminal device triggers the data recovery device to enable the data protection function for the protection group. For example, the terminal device sends a function activation command to the data recovery device, wherein the function activation command indicates that the data protection function for the protection group is enabled. The function activation command includes the identifier of the protection group. After receiving the function activation command, the data recovery device enables the data protection function for the protection group. There are various ways to trigger the function activation command. For example, it can be triggered through a command-line interface or through a configuration interface in the client. Here, this application embodiment does not limit the triggering method of the function activation command.
[0090] After enabling data protection for the protection group, the data recovery device can perform data consistency protection for the protection group through the following step 204, that is, perform data consistency protection for multiple logical storage spaces with related relationships.
[0091] 204. The data recovery device acquires at least one snapshot group of the protection group, each snapshot group including snapshot data of multiple logical storage spaces in the protection group at the same snapshot time point.
[0092] Each snapshot group corresponds to a snapshot time point, and different snapshot groups correspond to different snapshot time points. A snapshot group includes snapshot data of all logical storage spaces in the protection group corresponding to the snapshot time point. The snapshot time point is the moment (i.e., the point in time) at which a consistent snapshot is taken of multiple logical storage spaces in the protection group.
[0093] In some embodiments, the data recovery device performs a consistent snapshot of the logical storage space in the protection group every first period of time, resulting in at least one snapshot group. Each snapshot group is the result of one consistent snapshot; that is, one snapshot group is obtained for each pair of logical storage spaces in the protection group. For example, after enabling data protection for the protection group, the data recovery device performs a consistent snapshot of the logical storage space, obtaining one snapshot group. After the first period of time, it performs another consistent snapshot of the logical storage space, obtaining a new snapshot group, and so on. As the number of consistent snapshots increases, the number of snapshot groups increases.
[0094] The first duration is the time interval between two consecutive consistent snapshots. The first duration can be set flexibly. For example, the first duration can be 20 minutes, or it can be greater or less than 20 minutes. Here, the embodiments of this application do not limit the first duration.
[0095] Alternatively, the data recovery device performs an anomaly detection on the logical storage space within the protection group every first set of time intervals, and takes a consistency snapshot of the logical storage space within the protection group. Based on the result of this anomaly detection, it determines whether the snapshot group obtained from this consistency snapshot is a clean snapshot group. This ensures that if data anomalies occur in the logical storage space within the protection group later, the data recovery device can perform data recovery based on the clean snapshot group. A clean snapshot group is the snapshot group of the logical storage space within the protection group when no data anomalies occur.
[0096] For example, the data recovery device can perform at least one round of data protection (i.e., data consistency protection) on the protection group. During each round of data protection, an anomaly detection and a consistency snapshot are performed on the logical storage space in the protection group. If a data anomaly is detected in any logical storage space in the protection group during a certain round, the data consistency protection for the protection group is terminated. The process will now be described in conjunction with steps A1 to A4 below.
[0097] Step A1: During the i-th round of data protection, the data recovery device performs anomaly detection on multiple logical storage spaces in the protection group and obtains the i-th detection result, where i is an integer greater than 0.
[0098] The anomaly detection is used to detect whether data anomalies occur in the logical storage spaces within the protection group. The i-th detection result is the result of anomaly detection performed on the protection group during the i-th round of data protection. The i-th detection result indicates whether data anomalies occur in the logical storage spaces within the protection group. In some embodiments, the i-th detection result includes the detection results of multiple logical storage spaces. The detection result of one logical storage space indicates whether data anomalies occur in that logical storage space. If any logical storage space in the protection group has data anomalies, then the i-th detection result indicates that data anomalies occur in the logical storage spaces within the protection group. If none of the logical storage spaces in the protection group have data anomalies, then the i-th detection result indicates that no data anomalies occur in the logical storage spaces within the protection group. The moment when anomaly detection is performed on the protection group during the i-th round of data protection is called the i-th detection time point. The i-th detection result corresponds to the i-th detection time point. The i-th detection result and the i-th detection time point indicate whether data anomalies occur in the logical storage spaces within the protection group at the i-th detection time point. Correspondingly, the i-th detection time point and the detection result of the logical storage space indicate whether data anomalies occur in the logical storage spaces at the i-th detection time point.
[0099] Taking data anomalies, including ransomware infection of logical storage space, as an example, anomaly detection includes ransomware infection detection on the logical storage space within the protection group. Ransomware infection detection is used to determine whether the logical storage space within the protection group has been infected by ransomware. In this case, anomaly detection for multiple logical storage spaces within the protection group includes:
[0100] The data recovery device performs ransomware infection detection on each logical storage space within the protection group based on the characteristic data of that logical storage space. The characteristic data indicates the input / output (I / O) characteristics of the logical storage space, including the characteristics of I / O operations performed on that logical storage space, and the frequency of these I / O operations. Examples of I / O operations include read, write, or delete operations.
[0101] For example, for any logical storage space in the protection group, the data recovery device collects data on the IO characteristics of that logical storage space during the current time period to obtain its feature data. The collected feature data is preprocessed, and the processed feature data can be recognized by an artificial intelligence (AI) model. The preprocessed feature data of each logical storage space in the protection group is input into the AI model. For any logical storage space, the AI model performs ransomware infection detection based on the feature data of that logical storage space and outputs the detection result. At this point, the detection result indicates whether the logical storage space has been infected by ransomware (i.e., whether data anomalies have occurred). Based on the detection results of each logical storage space in the protection group, the data recovery device generates the i-th detection result. At this point, the i-th detection result indicates whether the logical storage space in that protection group has been infected by ransomware (i.e., whether data anomalies have occurred).
[0102] The types of AI models include, but are not limited to, machine learning models, deep learning models, and neural network models. The AI model is trained based on feature data from multiple logical storage spaces over a historical period, and on whether these logical storage spaces were infected during that period. The logical storage spaces used to train the AI model can be the same as or different from the logical storage spaces in the protection group.
[0103] Taking data anomalies, such as logical storage space being infected or contaminated by non-ransomware, as an example, similar or other methods can be used to detect anomalies in the logical storage space of the protection group. Here, the embodiments of this application do not limit the method of anomaly detection, as long as it can detect whether data anomalies have occurred in the logical storage space of the protection group.
[0104] Step A2: After obtaining the i-th detection result, the data recovery device performs a consistency snapshot on multiple logical storage spaces in the protection group to obtain the i-th snapshot group.
[0105] The i-th snapshot group is the snapshot group established for the protection group during the i-th round of data protection. It is the i-th snapshot group among at least one snapshot group of the protection group. The i-th snapshot group includes snapshot data of multiple logical storage spaces in the protection group at the i-th snapshot time point.
[0106] The data recovery device takes a snapshot of each logical storage space in the protection group at the current moment, obtains the snapshot data of each logical storage space, and combines the snapshot data of each logical storage space into the i-th snapshot group. The current moment is taken as the snapshot time point of the i-th snapshot group (called the i-th snapshot time point). Therefore, the i-th snapshot group is the snapshot group of the protection group at the i-th snapshot time point. The i-th snapshot time point is later than the i-th detection time point.
[0107] The data recovery device can also store the i-th snapshot group for later retrieval. The storage method for the i-th snapshot group can be, for example, persistent storage. The data recovery device can store the i-th snapshot group and its descriptive information together. For example, the data recovery device stores (e.g., persistently stores) the snapshot information of the i-th snapshot group, which includes the i-th snapshot group and its descriptive information. This descriptive information describes the i-th snapshot group and includes, but is not limited to, information about the time point of the i-th snapshot.
[0108] Snapshot groups can be in several states, including clean and polluted states. A clean state refers to the state of a snapshot group when there are no data anomalies in the logical storage space, while a polluted state refers to the state of a snapshot group when there are data anomalies in the logical storage space. Snapshot groups in a clean state are called clean snapshot groups, and those in a polluted state are called polluted snapshot groups. Polluted snapshot groups are snapshot groups that exist when there are data anomalies in the logical storage space of the protection group.
[0109] After obtaining the i-th snapshot group, the data recovery device can determine whether the i-th snapshot group is a clean snapshot group based on the i-th detection result (that is, based on the detection result of this anomaly detection, determine whether the snapshot group obtained by this consistency snapshot is a clean snapshot group). The determination method is as follows: steps A3 and A4.
[0110] Step A3: If the result of the i-th detection indicates that there is no data abnormality in the logical storage space of the protection group, the data recovery device will determine the i-th snapshot group as a clean snapshot group.
[0111] If the result of the i-th detection indicates that there is no data anomaly in the logical storage space of the protection group, it means that there is no data anomaly in the logical storage space of the protection group at the i-th detection time point. Since the i-th snapshot time point is the next moment after the i-th detection time point, the logical storage space of the protection group is also likely not to have data anomaly at the i-th snapshot time point. Therefore, the data recovery device will determine the i-th snapshot group as a clean snapshot group.
[0112] In some embodiments, the data recovery device establishes a mapping relationship between the i-th snapshot group and a clean identifier to determine the i-th snapshot group as a clean snapshot group, wherein the mapping relationship indicates that the i-th snapshot group is a clean snapshot group and the clean identifier indicates a clean status.
[0113] Data recovery devices can also record this mapping relationship in the form of a table. Alternatively, the mapping relationship can be recorded in a log. For example, after performing the operation of identifying the i-th snapshot group as a clean snapshot group (referred to as the first operation), the data recovery device generates an operation log for the first operation. This operation log includes the identifier of the i-th snapshot group and a clean identifier to indicate the first operation.
[0114] If the result of the i-th detection indicates that there is no data anomaly in the logical storage space of the protection group, the data recovery device determines the i-th snapshot group as a clean snapshot group, the i-th round of data protection ends, and after the second duration, the (i+1)-th round of data protection begins. At this time, the (i+1)-th round of data protection is the same as steps A1 to A3 above. The second duration is the time interval between adjacent rounds of detection. The second duration and the first duration can be the same or different. The second duration can be flexibly set, and this embodiment does not limit the second duration.
[0115] Step A4: If the i-th detection result indicates that there is a data anomaly in the logical storage space of the protection group, the data recovery device will identify the i-th snapshot group as the contaminated snapshot group.
[0116] If the i-th detection result indicates that the logical storage space in the protection group has data anomalies, it means that the logical storage space in the protection group has data anomalies at the i-th detection time point. The i-th snapshot time point is the next moment after the i-th detection time point. The logical storage space in the protection group will also have data anomalies at the i+1-th snapshot time point. Then the data recovery device will identify the i-th snapshot group as the contaminated snapshot group.
[0117] Data recovery equipment can establish a mapping relationship between the i-th snapshot group and a contamination identifier to identify the i-th snapshot group as a contaminated snapshot group. This mapping relationship indicates that the i-th snapshot group is a contaminated snapshot group, and the contamination identifier indicates the contamination status. The data recovery equipment can also record this mapping relationship in a table format. Alternatively, it can record this mapping relationship in a log. For example, after performing the operation of identifying the i-th snapshot group as a contaminated snapshot group (referred to as the second operation), the data recovery equipment generates an operation log for the second operation. This operation log includes the identifier of the i-th snapshot group and the contamination identifier to indicate the second operation.
[0118] If the result of the i-th detection indicates that there is a data anomaly in the logical storage space of the protection group, the data recovery device will identify the i-th snapshot group as a contaminated snapshot group, end the detection of the protection group, and will not enter the i+1-th round of data protection process.
[0119] If the i-th snapshot group is identified as a contaminated snapshot group, the data recovery device sends a first alarm message to the terminal device. This first alarm message indicates that a data anomaly occurred in the logical storage space of the protection group at detection time point i, thus alerting the terminal device. Upon receiving the first alarm message, the terminal device provides a second alarm message to the second user, enabling the second user to perform data recovery on the protection group after receiving the second alarm message. The data recovery process can be referenced from the flow chart of the data recovery method shown in Figure 4.
[0120] To facilitate understanding of the process shown in steps A1 to A3 above, taking a first duration of 20 minutes as an example, the process is explained as follows.
[0121] After detecting that a protection group has enabled data protection, the data recovery device performs the first anomaly detection on the protection group, creating a snapshot group S1 at snapshot time t1. If the detection result indicates that there is no data anomaly in the logical storage space of the protection group, snapshot group S1 is a clean snapshot group, and the first round of data protection ends. After 20 minutes, the device performs a second anomaly detection on the protection group, creating a snapshot group S2 at snapshot time t2. If the detection result indicates that there is data anomaly in the logical storage space of the protection group, snapshot group S2 is a contaminated snapshot group, and the second round of data protection ends, thus ending the data protection for the protection group.
[0122] The above description uses the example of the data recovery device establishing the i-th snapshot group for the protection group after obtaining the i-th detection result. In other embodiments, after obtaining the i-th detection result, if the i-th detection result indicates that there is no data abnormality in the logical storage space of the protection group, the data recovery device establishes the i-th snapshot group for the protection group; if the i-th detection result indicates that there is data abnormality in the logical storage space of the protection group, the data recovery device does not establish the i-th snapshot group for the protection group, and the data protection of the protection group ends.
[0123] In some embodiments, the detection result of this detection (such as the i-th detection result) may be inaccurate. If data abnormality is detected in the logical storage space of the protection group, the snapshot group obtained by this consistency snapshot (such as the i-th snapshot group) may be mistakenly identified as a polluted snapshot group, thereby triggering a false alarm (such as mistakenly sending the first alarm information).
[0124] To avoid triggering false alarms, in some embodiments, if a data anomaly is detected in the logical storage space of the protection group, the data recovery device determines whether the snapshot group obtained from the current consistency snapshot is a clean snapshot group based on the detection result of the next anomaly detection. Next, referring to Figure 3, this implementation method will be described, which includes the following steps B1 to B6.
[0125] Step B1: During the i-th round of data protection, the data recovery device performs anomaly detection on multiple logical storage spaces in the protection group and obtains the i-th detection result, where i is an integer greater than 0.
[0126] Step B1 can be performed after the data protection function is enabled for the protection group. Step B1 is similar to step A1 above, and will not be described again in this embodiment of the application.
[0127] Step B2: After obtaining the i-th detection result, the data recovery device performs a consistency snapshot on multiple logical storage spaces in the protection group to obtain the i-th snapshot group.
[0128] Step B2 is similar to step A2 above, and will not be described again in this embodiment of the application.
[0129] After obtaining the i-th snapshot group, based on the i-th detection result, determine whether the i-th snapshot group is a clean snapshot group, as shown in steps B3 and B4 below.
[0130] Step B3: If the result of the i-th detection indicates that there is no data anomaly in the logical storage space of the protection group, the data recovery device will determine the i-th snapshot group as a clean snapshot group.
[0131] Step B3 is similar to step A3 above, and will not be described again in this embodiment of the application.
[0132] If the result of the i-th detection indicates that there is no data anomaly in the logical storage space of the protection group, the data recovery device determines the i-th snapshot group as a clean snapshot group, the i-th round of data protection ends, and after the first duration, the i+1-th round of data protection begins. In this case, the i+1-th round of data protection is the same as steps B1 to B3 above.
[0133] Step B4: If the i-th detection result indicates that there is a data anomaly in the logical storage space of the protection group, the data recovery device will identify the i-th snapshot group as a suspicious snapshot group.
[0134] Among them, a suspicious snapshot group is a snapshot group within the protection group whose logical storage space is suspected of exhibiting data anomalies. A suspicious snapshot group is a snapshot group in a suspicious state, meaning the snapshot group's state when its logical storage space is suspected of exhibiting data anomalies. In this case, the snapshot group can be in various states, including suspicious, clean, and contaminated.
[0135] Since the result of the i-th detection is not necessarily accurate, if the result of the i-th detection indicates that there is a data anomaly in the logical storage space in the protection group, there may not be a data anomaly in the logical storage space in the protection group at the i-th detection time point. Therefore, it is first determined that there is a suspected data anomaly in the logical storage space in the protection group at the i-th detection time point, and the i-th snapshot group is identified as a suspicious snapshot group. Subsequently, based on the detection results in the (i+1)-th round of data protection, it is determined whether the suspicious snapshot group is a clean snapshot group (that is, if a data anomaly is detected in the logical storage space in the protection group this time, based on the detection results of the next anomaly detection, it is determined whether the snapshot group obtained by this consistency snapshot is a clean snapshot group). The determination method is as follows in step B6 below.
[0136] Data recovery equipment can establish a mapping relationship between the i-th snapshot group and a suspicious identifier to identify the i-th snapshot group as a suspicious snapshot group. This mapping relationship indicates that the i-th snapshot group is a suspicious snapshot group, and the suspicious identifier indicates a suspicious status. The data recovery equipment can also record this mapping relationship in a table format. Alternatively, it can record this mapping relationship in a log. For example, after performing the operation of identifying the i-th snapshot group as a suspicious snapshot group (referred to as the third operation), the data recovery equipment generates an operation log for the third operation. This operation log includes the identifier of the i-th snapshot group and the suspicious identifier to indicate the third operation.
[0137] In some embodiments, if the i-th snapshot group is determined to be a suspicious snapshot group, the data recovery device sends a second alarm message to the terminal device. The second alarm message indicates that the logical storage space in the protection group is suspected of having data anomalies at detection time point i, thereby alerting the terminal device. The terminal device receives the second alarm message and provides it to a second user so that the second user can decide whether to perform data recovery on the protection group based on the second alarm message. The data recovery process can be referred to the flow chart of the data recovery method shown in Figure 4. Sending the second alarm message is an optional step. In some embodiments, if the i-th detection result indicates that the logical storage space in the protection group has data anomalies, the data recovery device may not send the second alarm message to the terminal device.
[0138] Steps B1 to B4 above constitute the i-th round of data protection process. In step B4, if the i-th detection result indicates that there is a data anomaly in the logical storage space of the protection group, the data recovery device will identify the i-th snapshot group as a suspicious snapshot group, and the i-th round of data protection will end. After the second duration, the i+1-th round of data protection process will begin. In this case, the i+1-th round of data protection process includes the following steps B5 to B6.
[0139] Step B5: During the (i+1)th round of data protection, the data recovery device performs anomaly detection on multiple logical storage spaces in the protection group and obtains the (i+1)th detection result. After obtaining the (i)th detection result, it performs a consistency snapshot on multiple logical storage spaces in the protection group and obtains the (i+1)th snapshot group.
[0140] In this context, the moment when the (i+1)th round of data protection process performs anomaly detection on the protection group is called the (i+1)th detection time point. The (i+1)th detection time point is later than the (i)th snapshot time point. The snapshot time point of the (i+1)th snapshot group is called the (i+1)th snapshot time point, which is later than the (i+1)th detection time point. The (i+1)th snapshot group is the snapshot group established for the protection group during the (i)th round of data protection, and it is the (i+1)th snapshot group among at least one snapshot group of the protection group. The (i+1)th snapshot group includes snapshot data of multiple logical storage spaces in the protection group at the (i+1)th snapshot time point. Relative to the (i)th detection result, the (i+1)th detection result is the detection result of the next anomaly detection; relative to the (i)th snapshot group, the (i+1)th snapshot group is the snapshot group obtained by the next consistent snapshot.
[0141] Step B5 is the same as steps A1 and A2 above, and will not be described again in this embodiment of the application.
[0142] Step B6: Based on the (i+1)th detection result, the data recovery device determines whether the suspicious snapshot group is a clean snapshot group.
[0143] The suspicious snapshot group is the i-th snapshot group. Next, in conjunction with the situation indicated by the i+1 detection results in (1) and (2) below, this step B6 will be described in detail.
[0144] (1) The result of the (i+1)th test indicates that there is no data abnormality in the logical storage space of the protection group.
[0145] If the (i+1)th detection result indicates that there is no data anomaly in the logical storage space of the protection group, that is, there is no data anomaly in the logical storage space of the protection group at the (i+1)th detection time point, then there is also no data anomaly in the logical storage space of the protection group at the time points before the (i+1)th detection time point. If the (i)th detection result is inaccurate, then the data recovery device determines the suspicious snapshot group (i.e., the (i)th snapshot group) as a clean snapshot group.
[0146] The data recovery device can switch the i-th snapshot group from a suspicious state to a clean state, thereby identifying the suspicious snapshot group as a clean snapshot group. The state switching method, for example, involves modifying the suspicious identifier in the mapping relationship between the i-th snapshot group and the suspicious identifier through a table, to change the state of the i-th snapshot group from a suspicious snapshot group to a clean snapshot group. If the mapping relationship is recorded in the operation log of the first operation, an operation log for the fourth operation is generated. This operation log includes the identifier of the i-th snapshot group and the suspicious identifier to indicate the fourth operation. The fourth operation includes, if the (i+1)-th detection result indicates that there is no data anomaly in the logical storage space of the protected group, identifying the i-th snapshot group as a clean snapshot group.
[0147] If the (i+1)th detection result indicates that there is no data anomaly in the logical storage space of the protection group, the data storage device will also determine the (i+1)th snapshot group as a clean snapshot group. For example, the data recovery device establishes a mapping relationship between the (i+1)th snapshot group and the clean state to determine the (i+1)th snapshot group as a clean snapshot group. This process is the same as establishing the mapping relationship between the (i)th snapshot group and the clean state, and will not be described in detail here.
[0148] The above process means that if the (i+1)th detection result indicates that there is no data anomaly in the logical storage space of the protection group, the data recovery device will determine both the i-th snapshot group and the (i+1)-th snapshot group as clean snapshot groups. If both the (i+1)-th snapshot group and the (i+2)-th snapshot group are clean snapshot groups, after the second duration, the (i+2)-th round of data protection process begins. In this case, the (i+2)-th round of data protection process is the same as steps B1 to B3 above.
[0149] (2) The (i+1)th detection result indicates that there is a data anomaly in the logical storage space of the protection group.
[0150] If the (i+1)th detection result indicates that there is a data anomaly in the logical storage space of the protection group, that is, if there is a data anomaly in the logical storage space of the protection group at the (i+1)th detection time point, then there may also be a data anomaly in the logical storage space of the protection group at the (i)th snapshot time point before the (i+1)th detection time point. The (i)th detection result is likely to be accurate, and the data recovery device determines the suspicious snapshot group (i.e. the (i)th snapshot group) as a contaminated snapshot group.
[0151] If the (i+1)th detection result indicates that there is a data anomaly in the logical storage space of the protection group, the storage device will also identify the (i+1)th snapshot group as a contaminated snapshot group. For example, a mapping relationship between the (i+1)th snapshot group and the contaminated snapshot group can be established to identify the (i+1)th snapshot group as a contaminated snapshot group. This process is similar to the process of establishing the mapping relationship between the (i)th snapshot group and the contaminated snapshot group described above.
[0152] The above process means that if both the (i+1)th and (i+2)th detection results indicate that there is a data anomaly in the logical storage space of the protection group, the data recovery device will identify both the (i)th snapshot group and the (i+1)th snapshot group as contaminated snapshot groups.
[0153] If both the i-th snapshot group and the (i+1)-th snapshot group are contaminated snapshot groups, the data recovery device sends a first alarm message to the terminal device so that the second user can perform data recovery on the protected group based on the alarm message. The data recovery process can be referenced from the flow chart of the data recovery method shown in Figure 4.
[0154] For the i-th round of data protection, if a data anomaly is detected in the logical storage space in this round, the detection result of the next anomaly detection (such as the i+1 detection result) may be inaccurate. If a data anomaly is detected in the logical storage space of the protection group in the next round, the snapshot group obtained from the current consistency snapshot (such as the i-th snapshot group) and the snapshot group obtained from the next consistency snapshot (such as the i+1 snapshot group) may be mistakenly identified as the contaminated snapshot group, thereby triggering a false alarm.
[0155] To avoid triggering false alarms, in some embodiments, if a data anomaly is detected in the logical storage space this time, and a data anomaly is detected in the logical storage space of the protection group next time, the data recovery device determines whether the snapshot group obtained by the current consistency snapshot is a clean snapshot group based on the difference data between the snapshot group obtained by the current consistency snapshot and the snapshot group obtained by the next consistency snapshot.
[0156] For example, if the i-th detection result indicates that there is a data anomaly in the logical storage space of the protection group, and the i+1-th detection result indicates that there is a data anomaly in the logical storage space of the protection group, the i-th snapshot group is determined to be a clean snapshot group based on the difference data between the i+1-th snapshot group and the i-th snapshot group.
[0157] For example, a data recovery device compares the (i+1)th snapshot group with the i-th snapshot group to obtain difference data between the (i+1)th snapshot group and the i-th snapshot group. This difference data allows for in-depth analysis of the data state of the logical storage space at the (i+1)th snapshot time point. The difference data indicates the discrepancies between the (i+1)th snapshot group and the i-th snapshot group, including the differences in the data stored in each logical storage space within the protection group. The differences in the data stored in a logical storage space between the (i+1)th snapshot group and the i-th snapshot group include data added, removed, modified, and encrypted in the i+1th snapshot group relative to the data stored in the i-th snapshot group.
[0158] Based on this difference data, the data recovery device determines whether the logical storage space in the protection group has experienced data anomalies at snapshot time i+1. If it is determined that the logical storage space in the protection group has not experienced data anomalies at snapshot time i+1, then both snapshot group i and snapshot group i+1 are designated as clean snapshot groups; if it is determined that the logical storage space in the protection group has experienced data anomalies at snapshot time i+1, then both snapshot group i and snapshot group i+1 are designated as contaminated snapshot groups.
[0159] In this case, if both the i-th snapshot group and the (i+1)-th snapshot group are determined to be clean snapshot groups, after the second duration, the (i+2)-th round of data protection process begins. This (i+2)-th round of data protection process is the same as steps B1 to B3 described above. If both the i-th snapshot group and the (i+1)-th snapshot group are determined to be contaminated snapshot groups, data protection for the protected groups ends, and the (i+2)-th round of data protection process does not begin. If both the i-th snapshot group and the (i+1)-th snapshot group are determined to be contaminated snapshot groups, a first alarm message can be sent to the terminal device so that the second user can perform data recovery for the protected groups based on the alarm message. The data recovery process can be referred to the flow of the data recovery method shown in Figure 4.
[0160] The above method determines whether the (i+1)th snapshot group and the ith snapshot group are clean snapshot groups based on the difference between the (i+1)th snapshot group and the ith snapshot group. This makes the determination of clean snapshot groups more accurate, so that the data in the protection group can be restored to a safe state based on the accurate clean snapshot group. It can also further avoid misjudging the clean status of the ith snapshot group, thereby avoiding false alarms caused by such misjudgment.
[0161] To facilitate understanding of the process shown in steps B1 to B6 above, taking a second duration of 20 minutes as an example, the process is explained as follows.
[0162] After detecting that a protection group has enabled data protection, the data recovery device performs the first anomaly detection on the protection group, creating a snapshot group S1 at snapshot time t1. If no data anomalies are detected in the protection group in the first detection, snapshot group S1 is a clean snapshot group, and the first round of data protection ends. After 20 minutes, the device performs the second anomaly detection on the protection group, creating a snapshot group S2 at snapshot time t2. If data anomalies are detected in the logical storage space of the protection group in the second detection, snapshot group S2 is a suspicious snapshot group, and the second round of data protection ends. After 20 minutes, the device performs the third anomaly detection on the protection group, creating a snapshot group S3 at snapshot time t3. If no data anomalies are detected in the logical storage space of the protection group in the third detection, the status of snapshot group S2 is switched from suspicious to clean, snapshot group S3 is determined to be a clean snapshot group, and the third round of data protection ends. After 20 minutes, a fourth anomaly check is performed on the snapshot group, establishing snapshot group S4 at snapshot time t4. Snapshot group S4 may be a clean snapshot group or a suspicious snapshot group, and so on. If a data anomaly is detected in the logical storage space of the protection group for the third time, the status of snapshot group S2 is switched from suspicious to polluted, snapshot group 3 is identified as a polluted snapshot group, the third round of data protection ends, the data protection for the protection group ends, and a fourth anomaly check is not performed on the snapshot group.
[0163] After establishing any snapshot group (such as the i-th snapshot group or the i+1-th snapshot group) for the protection group, the data recovery device stores the group information of the snapshot group (such as persistent storage). After obtaining multiple snapshot groups of the protection group, when the total number of multiple snapshot groups exceeds a certain threshold, the data recovery device can also delete at least one clean snapshot group that was established earliest among these multiple snapshot groups to release the storage space occupied by at least one clean snapshot group and improve the utilization rate of storage space.
[0164] In some embodiments, after determining that any snapshot group of the protection group is a clean snapshot group, the data recovery device can store the snapshot information of the snapshot group into the memory of the data recovery device so that the clean snapshot group can be quickly retrieved from the memory during subsequent data recovery, thereby speeding up the data recovery process and improving the data recovery efficiency.
[0165] The above-mentioned determination of the i-th snapshot group as a clean snapshot group, a suspicious snapshot group, or a contaminated snapshot group means that the i-th snapshot time point is determined as a safe time point, a suspicious time point, or a contaminated time point, so that the subsequent data recovery device can select a clean snapshot group from the clean snapshot group of the protection group at the historical safe time point for data recovery of the protection group.
[0166] The above description illustrates the process in each round of data protection by using the example of different detection and snapshot times for the protection group. In other embodiments, the detection and snapshot times for the protection group can be the same in the same round of data protection. For example, in the i-th detection process, anomaly detection and snapshots are performed on the logical storage space in the protection group at the same time, so that the i-th detection time and the i+1-th detection time are the same.
[0167] The method provided in this application embodiment performs anomaly detection on the protection group during each round of data protection and creates a snapshot group for the protection group. Thus, after at least one round of data protection, the data recovery device can obtain at least one snapshot group of the protection group so that when data anomalies occur in the logical storage space of the protection group, a clean snapshot group can be selected from at least one snapshot group for data recovery.
[0168] As shown in Figures 2 and 3 above, for multiple logical storage spaces with an association in the storage system, after enabling data protection for these multiple logical storage spaces, the data recovery device periodically acquires snapshot data of these multiple logical storage spaces (as in step 204 above). If a data anomaly occurs in one of these multiple logical storage spaces, a second user can trigger the data recovery device to perform data consistency recovery on these multiple logical storage spaces through a terminal device. Next, this implementation method will be described in conjunction with Figure 4.
[0169] Figure 4 is a flowchart illustrating a data recovery method provided in an embodiment of this application. The method is applied to the data recovery system described above and includes the following steps.
[0170] 401. For multiple logical storage spaces that are related in a storage system, if any of the multiple logical storage spaces experiences a data anomaly, the data recovery device obtains the snapshot data of the multiple logical storage spaces at a target snapshot time point, where the target snapshot time point is before the anomaly occurs.
[0171] Taking multiple logical storage spaces with a relationship located in the same protection group as an example, before step 401, the data recovery device obtains at least one snapshot group of the protection group by performing step 204 above. The at least one snapshot group includes at least one clean snapshot group. In step 401, the data recovery device determines the target snapshot group from the at least one snapshot group. The target snapshot group is the net snapshot group among the at least one snapshot group whose snapshot time point is closest to the current time. The snapshot time point of the target snapshot group is the target snapshot time point.
[0172] For example, if the i-th snapshot group in the at least one snapshot group is a contaminated snapshot group, it means that at least one logical storage space in the protection group has a data anomaly, and the data recovery device determines the target snapshot group from at least one snapshot group in the protection group.
[0173] In other embodiments, if any of the plurality of logical storage spaces experiences data anomalies and a data recovery instruction is received, the data recovery device acquires snapshot data of the plurality of logical storage spaces at the target snapshot time point. This implementation will now be described in conjunction with steps C1 to C3 below.
[0174] Step C1: The terminal device displays a data recovery interface, which includes a data recovery component. The data recovery component corresponds to multiple logical storage spaces that are related in the storage system. If any of the multiple logical storage spaces experiences a data anomaly, the multiple logical storage spaces support data recovery based on snapshot data of the multiple logical storage spaces at the same snapshot time point. The data recovery component instructs the multiple logical storage spaces to perform data recovery.
[0175] The data recovery interface is a human-computer interaction interface provided by the detection system's client. Taking multiple logical storage spaces with a relationship located in the same protection group as an example, the data recovery interface includes protection group options and data recovery components corresponding to that protection group. Each protection group option represents that protection group, and each protection group option corresponds to a data recovery component. When there are multiple protection groups in the storage system, the data recovery interface includes multiple protection group options and a data recovery component corresponding to each protection group option. Different protection group options represent different protection groups.
[0176] If a data anomaly is detected in any logical storage space within the protection group, the second user performs an operation on the client side of the terminal device to open the data recovery interface, and the terminal device responds by displaying the data recovery interface.
[0177] The second user may discover that the logical storage space has a data anomaly by having the terminal device provide the second user with a first alarm message or a second alarm message, thereby indicating that the logical storage space has a data anomaly. Of course, there may be other ways to discover the anomaly. Here, this application embodiment does not limit the way the second user discovers that the logical storage space has a data anomaly.
[0178] In other embodiments, after acquiring at least one snapshot group of the protection group, the data recovery device can send the status information of this at least one snapshot group to the terminal device. The status information of each snapshot group includes an identifier for the snapshot group and a status identifier for the snapshot group, which is one of a clean identifier, a suspicious identifier, or a contaminated identifier. Based on this at least one snapshot group, the terminal device displays the status of each snapshot group within the at least one snapshot group in a status interface associated with the protection group, so that a second user can be aware of the status of each snapshot group. Here, the status interface is an interface provided by the client of the detection system.
[0179] In other embodiments, the status information of any snapshot group also includes the snapshot time point of the snapshot group. The data recovery interface may display the snapshot time points of each clean snapshot group in the at least one snapshot group, so that a second user can select the snapshot time point of a clean snapshot group to perform data recovery on the protected group.
[0180] Step C2: In response to the selection operation of the data recovery component, the terminal device sends a data recovery instruction to the data recovery device, which instructs the multiple logical storage spaces to perform data recovery.
[0181] Taking the example of multiple logical storage spaces located in the same protection group, the data recovery command instructs that data recovery be performed on that protection group. The data recovery command includes the identifier of the protection group. This selection can be done by clicking the data recovery component or by selecting the data recovery component via voice command.
[0182] The second user selects the data recovery component corresponding to the protection group in the data recovery interface. The terminal device responds to the selection operation, generates a data recovery command, and sends the data recovery command to the data recovery device.
[0183] In data recovery at the LUN (Legion Unit) granularity, different LUNs may have some snapshot time points that are the same, and some LUNs may have different snapshot time points, resulting in a large number of snapshot time points for different LUNs. When recovering data from different dependent LUNs, users need to select a relatively safe snapshot time point that corresponds to the same snapshot time point for different LUNs from a large number of snapshot time points, and then perform data recovery on different LUNs based on the snapshot data at the selected snapshot time point. Selecting a relatively safe snapshot time point that corresponds to the same snapshot time point for different LUNs requires a significant amount of time from the large number of snapshot time points, increases user intervention in the data recovery process, complicates the data recovery process, increases the data recovery time, and reduces data recovery efficiency.
[0184] In this embodiment, the user triggers a data recovery command through the data recovery component, so that the data recovery device can perform data recovery on multiple logical storage spaces with dependencies based on the data recovery command. For the user, this achieves one-click recovery of data in multiple logical storage spaces with dependencies, without the need for the user to select a snapshot time point for data recovery, reducing user intervention, making the operation simple and convenient, saving data recovery time, and improving data recovery efficiency.
[0185] In other embodiments, the data recovery instruction further includes a target snapshot time point to instruct data recovery of the plurality of logical storage spaces based on snapshot data of the plurality of logical storage spaces at the target snapshot time point. The target snapshot time point may be specified by a second user.
[0186] For example, when the snapshot time points of each clean snapshot group in at least one snapshot group of the protection group are displayed in the data recovery interface, the second user selects the snapshot time point of any clean snapshot group and the data recovery component corresponding to the protection group. In response to these two selection operations, the terminal device generates a data recovery instruction based on the snapshot time point of the clean snapshot group as the target snapshot time point and the identifier of the protection group, and sends the data recovery instruction to the data recovery device. At this time, the data recovery instruction includes the target snapshot time point and the identifier of the protection group.
[0187] Compared to data recovery methods using LUN as the granularity, where users spend a significant amount of time selecting a relatively safe snapshot time point, the clean snapshot group (i.e., snapshot data from multiple logical storage spaces) in this embodiment corresponds to a single snapshot time point. This allows users to more easily select the target snapshot time point, reduces user intervention, simplifies and facilitates operation, saves data recovery time, and improves data recovery efficiency.
[0188] The above description uses triggering data recovery commands through a data recovery interface as an example. In other embodiments, the second user can trigger data recovery commands through the command-line interface of the terminal device. Here, this application does not limit the triggering method of data recovery commands.
[0189] Step C3: The data recovery device receives the data recovery instruction and obtains the snapshot data of the multiple logical storage spaces at the target snapshot time point.
[0190] Taking a protection group as an example where multiple logical storage spaces with a relationship are located therein, the data recovery device determines the target snapshot group from at least one snapshot group in the protection group. For instance, if the data recovery instruction does not include a target snapshot time point, the data recovery device determines the clean snapshot group among the at least one snapshot groups whose snapshot time point is closest to the current time as the target snapshot group. For example, for this protection group, the snapshot groups currently obtained by the data recovery device include snapshot groups S1, S2, and S3, where snapshot groups S1 and S2 are clean snapshot groups, and S3 is a contaminated snapshot group. Since the snapshot time point of snapshot group S2 is later than that of snapshot group S1, snapshot group S2 is the clean snapshot group closest to the current time, that is, the latest snapshot group before the data anomaly occurred in the logical storage space within the protection group. Therefore, snapshot group S2 is selected as the target snapshot group.
[0191] If the data recovery instruction includes a target snapshot time point, the data recovery device identifies the clean snapshot group corresponding to the target snapshot time point in at least one snapshot group as the target snapshot group. Specifying a target snapshot time point in the data recovery instruction allows for data recovery of the protected group based on the clean snapshot group at the specified target snapshot time point, thus meeting the needs of a second user.
[0192] Upon receiving a data recovery instruction from the terminal device, the above-mentioned method acquires snapshot data of the multiple logical storage spaces at the target snapshot time point, so as to perform data recovery on the multiple logical storage spaces based on the snapshot data of the multiple logical storage spaces at the target snapshot time point (as described in step 402 below), thereby meeting the data recovery needs of the second user.
[0193] 402. The data recovery device performs data recovery on the multiple logical storage spaces based on the snapshot data at the target snapshot time point.
[0194] Taking multiple related logical storage spaces located in a protection group as an example, for any logical storage space in the protection group, the data recovery device performs data recovery on that logical storage space based on the snapshot data of that logical storage space in the target snapshot group, so as to restore the data stored in that logical storage space to the data state at the target snapshot time point. In a similar manner, the data recovery device can restore the data stored in each logical storage space in the protection group to their respective data state at the target snapshot time point, thereby achieving data consistency recovery at the protection group level.
[0195] After data recovery of the protection group, the data recovery device can continue to protect the data of the protection group and obtain a new snapshot group of the protection group, which can be used when the protection group is recovered again based on the new snapshot group.
[0196] In the event of a data anomaly in any of a plurality of logical storage spaces with an association relationship, the above describes the data recovery process for these logical storage spaces, assuming they are located in a protection group. In other embodiments, when the association relationship between these logical storage spaces is represented in other ways, data recovery can also be performed on these logical storage spaces in other ways, and will not be elaborated upon here.
[0197] The method provided in this application synchronizes the data states of multiple logical storage spaces by restoring them to the same snapshot time (rather than different time points) when a data anomaly occurs in one of the multiple logical storage spaces with a relationship. This achieves the beneficial effect of establishing a relationship between the originally independent logical storage spaces at the data recovery time point. For example, even if the data stored in these multiple logical storage spaces has a dependency relationship, this data recovery method will not destroy the dependency relationship due to the inconsistent recovery time points of different logical storage spaces, thus not affecting user services. Furthermore, since the target snapshot time point is before the anomaly occurs, restoring all the multiple logical storage spaces to the data state at the target snapshot time point can restore them to their pre-anomaly data state, achieving the effect of data recovery. When multiple logical storage spaces with a relationship are located in the same protection group, data consistency recovery at the protection group granularity is also achieved, thereby restoring the data of multiple logical storage spaces in the storage system at one time, which can improve the efficiency of data recovery.
[0198] The embodiments shown in Figures 2 and 4 above can be combined into an embodiment of a data recovery method. For example, steps 201 to 204 can be executed first, followed by steps 401 to 402. Next, taking multiple logical storage spaces with related relationships located in the same protection group, the logical storage space being a LUN, and the detection system being an anti-ransomware system as an example, the flow of this data recovery method will be described with reference to Figure 5. This method is applied to a data recovery system, which includes an anti-ransomware system and a client for the anti-ransomware system. The anti-ransomware system includes a configuration module, an IO detection module, a ransomware detection module, and a snapshot module. The client includes a GUI. The method includes the following steps.
[0199] 1. The configuration module creates a protection group, adds all LUNs of the same service corresponding to the target application in the storage system to the protection group, turns on the anti-ransomware switch for the protection group, and synchronizes the on / off status of each LUN in the protection group, so that the anti-ransomware system can perform concurrent detection on each LUN.
[0200] This service refers to Oracle database services or other types of services. Enabling ransomware protection for this protection group enables data protection for the group. The LUN object refers to the LUN within the protection group. Synchronizing the on / off states of each LUN object enables data protection for each LUN in the protection group. Performing concurrent detection on each LUN object means concurrently detecting ransomware infection on each LUN in the protection group.
[0201] In this embodiment, the configuration module is located in the anti-ransomware system as an example. In other embodiments, the configuration module may also be located on the client side of the anti-ransomware system, and the second user triggers the configuration module to execute this step 1, such as the relevant descriptions in steps 201 to 203 above.
[0202] 2. After detecting the switch configuration of the protection group, the IO module learns that the anti-ransomware switch has been turned on for the protection group. It then collects the IO characteristics of all LUNs in the protection group to achieve IO characteristic collection for all LUNs in the protection group. The method of collecting IO characteristics is, for example, to sample the IO characteristics of each LUN's read and write data rows to obtain the characteristic data for each LUN.
[0203] 3. The IO module vectorizes the collected feature data and sends the vectorized feature data to the ransomware detection module. The ransomware detection module performs threat detection based on the AI module and the quantized feature data.
[0204] Among them, threat detection, namely ransomware infection detection, is used to detect whether the protected group is infected with ransomware. The feature data of each LUN is input into the AI model, and the AI model performs threat detection on each LUN based on the feature data of each LUN, so as to achieve concurrent detection of LUNs in the protected group.
[0205] 4. The ransomware detection module sends the threat detection results to the snapshot module. The snapshot module concurrently checks whether any LUN in the protection group is infected with ransomware based on the detection results. After concurrently detecting that any LUN in the protection group is infected with ransomware (i.e., a virus is detected), the snapshot module performs a consistent group snapshot for the protection group members and triggers an alarm.
[0206] Triggering an alarm can involve sending a first alarm message or a second alarm message to the client, and the client can then display the received first alarm message or second alarm message on the GUI interface.
[0207] 5. If no ransomware infection is detected in the protection group, the snapshot module performs a consistent group snapshot for the protection group members to obtain a snapshot group of the protection group. The snapshot group is used as clean data (i.e., a clean snapshot group), and the clean data is saved.
[0208] Steps 2-5 above constitute one cycle, which is one round of data protection for the protection group. If no infected LUN is detected in the protection group during one cycle (i.e., no infection of the protection group is detected), the next cycle begins after the first duration. This continues until an infection of the protection group is detected in a certain cycle. The snapshot group obtained in that cycle is designated as a contaminated snapshot group or a suspicious snapshot group. If it is designated as a suspicious snapshot group, the next cycle begins. The detection results in the next cycle determine whether the suspicious snapshot group is a contaminated snapshot group, and so on. The cycle ends when a snapshot group in a certain cycle is determined to be a contaminated snapshot group.
[0209] 6. If, during a loop, any LUN in the protection group is detected to be infected by ransomware (i.e., data anomalies occur), the user can perform data consistency recovery on the protection group based on the historical clean data of that protection group through the GUI (such as a data recovery interface). The data consistency recovery process can be referred to the method flow shown in Figure 4 above.
[0210] The above describes the process of establishing a protection group, protecting data, and restoring data consistency, using a single protection group as an example. Multiple protection groups can be created for the storage system in a similar manner, and similar data protection and data consistency restoration can be performed on each protection group. This will not be elaborated further here.
[0211] The methods of the embodiments of this application have been described above. The apparatus of the embodiments of this application will be described below with reference to Figures 6 to 9.
[0212] Figure 6 is a schematic diagram of a data recovery device provided in an embodiment of this application. The device 600 shown in Figure 6 can be a data recovery device or a component of a data recovery device in the preceding embodiments, used to execute the method steps performed by the data recovery device in the data recovery method and / or data protection method provided in the embodiments of this application. As shown in Figure 6, the device 600 includes:
[0213] The acquisition module 601 is used to acquire snapshot data of multiple logical storage spaces that are related in the storage system at a target snapshot time point if any logical storage space in the multiple logical storage spaces has a data anomaly. The target snapshot time point is before the anomaly occurs.
[0214] Recovery module 602 is used to recover data from multiple logical storage spaces based on snapshot data.
[0215] Alternatively, the logical storage space can be a logical unit number (LUN) or a file system.
[0216] Optionally, the data stored in the aforementioned multiple logical storage spaces have dependencies on each other.
[0217] Optionally, the aforementioned multiple logical storage spaces are located in the same protection group, and the device 600 further includes:
[0218] The snapshot module is used to take a consistent snapshot of the logical storage space in the protection group every first time interval, so as to obtain at least one snapshot group. The snapshot group includes snapshot data of multiple logical storage spaces in the protection group at the same snapshot time point.
[0219] Acquisition module 601 is used to determine a target snapshot group from at least one snapshot group.
[0220] Optionally, the target snapshot group is the net snapshot group among at least one snapshot group whose snapshot time point is closest to the current time, and the clean snapshot group is the snapshot group in the protection group where no data anomalies have occurred in the logical storage space; the snapshot module is used for:
[0221] The detection unit is used to perform an anomaly detection on the logical storage space in the protection group every first time interval;
[0222] The snapshot unit is used to take a consistent snapshot of the logical storage space in the protection group.
[0223] The determination unit is used to determine whether the snapshot group obtained from this consistency snapshot is a clean snapshot group based on the detection results of this anomaly detection.
[0224] Optionally, the determining unit is used to determine whether the snapshot group obtained by the current consistency snapshot is a clean snapshot group based on the detection result of the next anomaly detection if data anomaly is detected in the logical storage space of the protection group this time.
[0225] Optionally, the determining unit is used to determine the snapshot group obtained from this consistency snapshot as a clean snapshot group if no data anomalies are detected in the logical storage space of the protection group in the next detection.
[0226] Optionally, the determining unit is used to determine whether the snapshot group obtained in the current consistency snapshot is a clean snapshot group based on the difference data between the snapshot group obtained in the current consistency snapshot and the snapshot group obtained in the next consistency snapshot if a data anomaly is detected in the logical storage space of the protection group in the next detection.
[0227] Optionally, the device 600 further includes:
[0228] The receiving module is used to receive protection group creation instructions, which include identifiers of multiple logical storage spaces;
[0229] Create a module to create protection groups based on the identifiers of multiple logical storage spaces.
[0230] Optionally, the acquisition module 601 is used to acquire snapshot data of multiple logical storage spaces at the target snapshot time point if any logical storage space experiences data abnormality and a data recovery instruction is received, and the data recovery instruction instructs the multiple logical storage spaces to perform data recovery.
[0231] It should be understood that device 600 corresponds to the terminal device in the above method embodiments. Each module in device 600 and the other operations and / or functions described above are for implementing various steps and methods performed by the terminal device in the above method embodiments. Specific details can be found in the above method embodiments, and for simplicity, they will not be repeated here. The beneficial effects achieved by device 600 can be found in the above method embodiments, and will not be repeated here.
[0232] Figure 7 is a schematic diagram of a data recovery device provided in an embodiment of this application. The device 700 shown in Figure 7 can be a terminal device or a component in a terminal device in the preceding embodiments, used to execute the method steps performed by the terminal device in the data recovery method and / or data protection method provided in the embodiments of this application. As shown in Figure 7, the device 700 includes:
[0233] Display module 701 is used to display a data recovery interface, wherein the data recovery interface includes a data recovery component, which corresponds to multiple logical storage spaces that are related in the storage system. If any one of the multiple logical storage spaces experiences a data anomaly, the multiple logical storage spaces support data recovery based on snapshot data of the multiple logical storage spaces at the same snapshot time point. The data recovery component indicates that data recovery should be performed on the multiple logical storage spaces.
[0234] The sending module 702 is used to send a data recovery command to the data recovery device in response to the selection operation of the data recovery component. The data recovery command performs data recovery on multiple logical storage spaces.
[0235] Optionally, the logical storage space can be a logical unit number (LUN) or a file system.
[0236] Optionally, there may be dependencies between the data stored in multiple logical storage spaces.
[0237] Optionally, the sending module 702 is also used to send a protection group creation instruction to the data recovery device, the protection group creation instruction including the identifiers of multiple logical storage spaces.
[0238] It should be understood that device 700 corresponds to the data recovery device in the above method embodiments. Each module in device 700 and the other operations and / or functions described above are for implementing various steps and methods of the data recovery device in the above method embodiments. Specific details can be found in the above method embodiments, and for simplicity, they will not be repeated here. The beneficial effects achieved by device 700 can be referred to in the above method embodiments, and will not be repeated here.
[0239] It should be understood that when performing data recovery, the above-described division of functional modules in device 600 or 700 is merely an example. In practical applications, the functions described above can be assigned to different functional modules as needed. That is, the internal structure of device 600 or 700 can be divided into different functional modules to complete all or part of the functions described above. Furthermore, the device 600 or 700 provided in the above embodiments and the above method embodiments belong to the same concept, and their specific implementation process is detailed in the above method embodiments, which will not be repeated here.
[0240] Figure 8 is a structural schematic diagram of a terminal device provided in an embodiment of this application. Figure 8 is a structural block diagram of a terminal device according to an exemplary embodiment. As shown in Figure 8, the terminal device 800 can be a smartphone, tablet computer, laptop computer, or desktop computer, etc. The terminal device 800 may also be referred to as a user device, portable terminal, laptop terminal, desktop terminal, or other names.
[0241] Typically, terminal device 800 includes a processor 801 and a memory 802.
[0242] Processor 801 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. Processor 904 may be implemented using at least one of the following hardware forms: digital signal processing (DSP), field-programmable gate array (FPGA), programmable logic array (PLA), and application-specific integrated circuit (ASIC). Processor 901 may also include a main processor and a coprocessor. The main processor, also known as the central processing unit (CPU), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, processor 904 may integrate a graphics processing unit (GPU), which is responsible for rendering and drawing the content required to be displayed on the screen. In some embodiments, processor 904 may also include an artificial intelligence (AI) processor, which is used to handle computational operations related to machine learning, such as a neural network processing unit (NPU) or a tensor processing unit (TPU), but the type of AI processor is not limited to these.
[0243] The memory 802 can be a non-transitory memory, which can be volatile memory or non-volatile memory, or a combination of both. Volatile memory is, for example, random access memory (RAM). Non-volatile memory can be, for example, read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD).
[0244] The memory 802 stores executable program code, and the processor 801 reads and executes the executable program code, so that the terminal device 1000 implements the method steps executed by the terminal device in the above-described method embodiments.
[0245] In some embodiments, the terminal device 800 may also optionally include a peripheral device interface 803 and at least one peripheral device. The processor 801, memory 802, and peripheral device interface 803 can be connected via a bus or signal line. Each peripheral device can be connected to the peripheral device interface 803 via a bus, signal line, or circuit board. Specifically, the peripheral device includes at least one of the following: a radio frequency circuit 804, a touch display screen 805, a camera assembly 806, an audio circuit 807, and a power supply 808.
[0246] Peripheral device interface 803 can be used to connect at least one input / output (I / O) related peripheral device to processor 801 and memory 802. In some embodiments, processor 801, memory 802 and peripheral device interface 803 are integrated on the same chip or circuit board; in some other embodiments, any one or two of processor 801, memory 802 and peripheral device interface 803 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.
[0247] The radio frequency (RF) circuit 804 is used to receive and transmit radio frequency (RF) signals, also known as electromagnetic signals. The RF circuit 804 communicates with communication networks and other communication devices via electromagnetic signals. The RF circuit 804 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals back into electrical signals. Optionally, the RF circuit 804 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, etc. The RF circuit 804 can communicate with other terminals through at least one wireless communication protocol. This wireless communication protocol includes, but is not limited to: metropolitan area networks (MANs), various generations of mobile communication networks (2G, 3G, 4G, and 5G), wireless local area networks (WLANs), and / or wireless fidelity (WiFi) networks. In some embodiments, the RF circuit 804 may also include circuitry related to near-field communication (NFC), which is not limited in this application embodiment.
[0248] Display screen 805 is used to display a user interface (UI). The UI may include graphics, text, icons, videos, and any combination thereof. When display screen 805 is a touch display screen, it also has the ability to collect touch signals on or above its surface. These touch signals can be input as control signals to processor 801 for processing. In this case, display screen 805 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 805, which serves as the front panel of the terminal device 800; in other embodiments, there may be at least two display screens, respectively disposed on different surfaces of the terminal device 800 or in a folded design; in some embodiments, display screen 805 may be a flexible display screen, disposed on a curved or folded surface of the terminal device 800. Furthermore, display screen 805 may be configured as a non-rectangular irregular shape, i.e., a non-rectangular screen. Display screen 805 may be made of materials such as liquid crystal display (LCD) or organic light-emitting diode (OLED).
[0249] The camera assembly 806 is used to acquire images or videos. Optionally, the camera assembly 806 includes a front-facing camera and a rear-facing camera. Typically, the front-facing camera is located on the front panel of the terminal, and the rear-facing camera is located on the back of the terminal. In some embodiments, there are at least two rear-facing cameras, which are any one of a main camera, a depth-sensing camera, a wide-angle camera, and a telephoto camera, to achieve background blurring by fusion of the main camera and the depth-sensing camera, panoramic shooting by fusion of the main camera and the wide-angle camera, virtual reality (VR) shooting, or other fusion shooting functions. In some embodiments, the camera assembly 806 may also include a flash. The flash can be a single-color temperature flash or a dual-color temperature flash. A dual-color temperature flash refers to a combination of a warm-light flash and a cool-light flash, which can be used for light compensation at different color temperatures.
[0250] The audio circuit 807 may include a microphone and a speaker. The microphone is used to collect sound waves from the user and the environment, converting the sound waves into electrical signals that are input to the processor 801 for processing, or input to the radio frequency circuit 804 for voice communication. For stereo sound acquisition or noise reduction purposes, multiple microphones may be used, each located at a different part of the terminal device 800. The microphone may also be an array microphone or an omnidirectional microphone. The speaker is used to convert the electrical signals from the processor 801 or the radio frequency circuit 804 into sound waves. The speaker may be a conventional diaphragm speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can convert electrical signals not only into audible sound waves but also into inaudible sound waves for purposes such as distance measurement. In some embodiments, the audio circuit 807 may also include a headphone jack.
[0251] Power supply 808 is used to supply power to the various components in terminal device 800. Power supply 808 can be AC power, DC power, a disposable battery, or a rechargeable battery. When power supply 808 includes a rechargeable battery, the rechargeable battery can support wired charging or wireless charging. The rechargeable battery can also be used to support fast charging technology.
[0252] In some embodiments, the terminal device 800 further includes one or more sensors 810. The one or more sensors 810 include, but are not limited to, an acceleration sensor 811, a gyroscope sensor 812, a pressure sensor 813, an optical sensor 814, and a proximity sensor 815.
[0253] Accelerometer 811 can detect the magnitude of acceleration along the three coordinate axes of a coordinate system established by terminal device 800. For example, accelerometer 811 can be used to detect the components of gravitational acceleration along the three coordinate axes. Processor 801 can control touchscreen display 805 to display the user interface in landscape or portrait view based on the gravitational acceleration signal acquired by accelerometer 811. Accelerometer 811 can also be used for games or for acquiring user motion data.
[0254] The gyroscope sensor 812 can detect the orientation and rotation angle of the terminal device 800. The gyroscope sensor 812, in conjunction with the accelerometer sensor 811, can collect 3D motion data from the user on the terminal device 800. Based on the data collected by the gyroscope sensor 812, the processor 801 can perform the following functions: motion sensing (e.g., changing the UI based on the user's tilt), image stabilization during shooting, game control, and inertial navigation.
[0255] The pressure sensor 813 can be disposed on the side bezel of the terminal device 800 and / or on the lower layer of the touch display screen 805. When the pressure sensor 813 is disposed on the side bezel of the terminal device 800, it can detect the user's grip signal on the terminal device 800, and the processor 801 can perform left / right hand recognition or quick operation based on the grip signal collected by the pressure sensor 813. When the pressure sensor 813 is disposed on the lower layer of the touch display screen 805, the processor 801 can control the operable controls on the UI interface based on the user's pressure operation on the touch display screen 805. The operable controls include at least one of button controls, scroll bar controls, icon controls, and menu controls.
[0256] An optical sensor 814 is used to collect ambient light intensity. In one embodiment, the processor 801 can control the display brightness of the touch screen 805 based on the ambient light intensity collected by the optical sensor 814. Specifically, when the ambient light intensity is high, the display brightness of the touch screen 805 is increased; when the ambient light intensity is low, the display brightness of the touch screen 805 is decreased. In another embodiment, the processor 801 can also dynamically adjust the shooting parameters of the camera assembly 806 based on the ambient light intensity collected by the optical sensor 814.
[0257] A proximity sensor 815, also known as a distance sensor, is typically located on the front panel of a terminal device 800. The proximity sensor 815 is used to detect the distance between the user and the front of the terminal device 800. In one embodiment, when the proximity sensor 815 detects that the distance between the user and the front of the terminal device 800 is gradually decreasing, the processor 801 controls the touchscreen display 805 to switch from a screen-on state to a screen-off state; when the proximity sensor 815 detects that the distance between the user and the front of the terminal device 800 is gradually increasing, the processor 801 controls the touchscreen display 805 to switch from a screen-off state to a screen-on state.
[0258] Those skilled in the art will understand that the structure shown in FIG8 does not constitute a limitation on the terminal device 800, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.
[0259] Figure 9 is a schematic diagram of a computing device provided in an embodiment of this application. The computing shown in Figure 9 can be used to realize any function of the data recovery device in any of the above methods.
[0260] As shown in Figure 9, the computing device 900 includes a bus 902, a processor 904, a memory 906, and a communication interface 908. The processor 904, memory 906, and communication interface 908 communicate with each other via the bus 902. The bus 902 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be classified as an address bus, data bus, control bus, etc. For ease of illustration, only one line is used in Figure 9, but this does not indicate that there is only one bus or one type of bus. The bus 902 can include a path for transmitting information between various components of the computing device 900 (e.g., memory 906, processor 904, communication interface 908). The implementation of the processor 904 is similar to that of the processor 801; therefore, the implementation of the processor 904 will not be described in detail here.
[0261] The implementation of memory 906 is similar to that of memory 802 described above, and the implementation of processor 904 is similar to that of processor 801 described above. Therefore, the implementations of memory 802 and processor 904 will not be described again in this embodiment. Memory 906 stores executable program code, and processor 904 reads and executes this executable program code, enabling computing device 900 to implement the method steps performed by the data recovery device in the various method embodiments described above.
[0262] The communication interface 908 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between the computing device 900 and other devices or communication networks.
[0263] This application also provides a computing device cluster, which includes multiple computing devices, each including a processor and a memory. For example, each computing device is the computing device shown in Figure 9. These multiple computing devices can be communicatively connected. The processors of these multiple computing devices are used to execute program code stored in the memory of the multiple computing devices, so that the computing device cluster executes the method steps performed by the data recovery device in each method embodiment.
[0264] In an exemplary embodiment, a computer-readable storage medium is also provided, such as a memory including program code, which can be executed by a processor in a terminal device to perform the method steps performed by the terminal device in the various method embodiments described above.
[0265] In an exemplary embodiment, a computer-readable storage medium is also provided, such as a memory including program code that can be executed by a processor in a computing device or computing cluster to perform the method steps performed by the data recovery device in the various method embodiments described above.
[0266] The computer-readable storage media provided above are non-transitory computer-readable storage media, such as read-only memory (ROM), random access memory (RAM), compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage devices.
[0267] This application also provides a computer program product or computer program, which includes program code stored in a computer-readable storage medium. The processor of the terminal device reads the program code from the computer-readable storage medium and executes the program code, causing the terminal device to perform the method steps executed by the terminal device in the above-described method embodiments.
[0268] This application also provides a computer program product or computer program, which includes program code stored in a computer-readable storage medium. The processor of a computing device or computing device cluster reads the program code from the computer-readable storage medium and executes the program code, causing the computing device or computing device cluster to perform the method steps performed by the data recovery device in the above-described method embodiments.
[0269] In the description of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. The "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" means one or more, and "multiple" means two or more. The terms "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply differences.
[0270] In this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0271] It should be noted that all information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in this application have been authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the instructions involved in this application were all obtained under full authorization.
[0272] All of the above-mentioned optional technical solutions can be combined in any way to form optional embodiments of this disclosure, and will not be described in detail here.
[0273] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A data recovery method, characterized in that, The method includes: For multiple logical storage spaces that are related in a storage system, if any logical storage space in the multiple logical storage spaces experiences a data anomaly, the snapshot data of the multiple logical storage spaces at a target snapshot time point is obtained, where the target snapshot time point is before the anomaly occurs. Data recovery is performed on the multiple logical storage spaces based on the snapshot data.
2. The method according to claim 1, characterized in that, The logical storage space is a logical unit number (LUN) or a file system.
3. The method according to claim 1, characterized in that, The data stored in the multiple logical storage spaces are dependent on each other.
4. The method according to any one of claims 1-3, characterized in that, The method further includes: (The multiple logical storage spaces are located in the same protection group) After each first duration, a consistent snapshot is taken of the logical storage space in the protection group to obtain at least one snapshot group. The snapshot group includes snapshot data of the multiple logical storage spaces in the protection group at the same snapshot time point. The step of obtaining snapshot data of the plurality of logical storage spaces at the target snapshot time point includes: The target snapshot group is determined from the at least one snapshot group.
5. The method according to claim 4, characterized in that, The target snapshot group is the net snapshot group among the at least one snapshot group whose snapshot time point is closest to the current time, and the clean snapshot group is the snapshot group in the protection group when there are no data anomalies in the logical storage space; Every first time interval, a consistency snapshot is taken of the logical storage space in the protection group to obtain at least one snapshot group, including: After each first time interval, an anomaly detection is performed on the logical storage space in the protection group, and a consistency snapshot is taken of the logical storage space in the protection group. Based on the detection result of this anomaly detection, it is determined whether the snapshot group obtained by this consistency snapshot is the clean snapshot group.
6. The method according to claim 5, characterized in that, The determination of whether the snapshot group obtained from this consistent snapshot is the clean snapshot group based on the detection results of this anomaly detection includes: If a data anomaly is detected in the logical storage space of the protection group, the snapshot group obtained from the current consistency snapshot is determined to be the clean snapshot group based on the detection result of the next anomaly detection.
7. The method according to any one of claims 1-3 or 5-6, characterized in that, If any of the plurality of logical storage spaces experiences a data anomaly, obtaining the snapshot data of the plurality of logical storage spaces at the target snapshot time point includes: If any of the logical storage spaces experiences a data anomaly and a data recovery instruction is received, snapshot data of the multiple logical storage spaces at the target snapshot time point is obtained, and the data recovery instruction instructs the multiple logical storage spaces to perform data recovery.
8. A data recovery method, characterized in that, The method includes: The data recovery interface is displayed, which includes a data recovery component. The data recovery component corresponds to multiple logical storage spaces that are associated with each other in the storage system. If any of the multiple logical storage spaces experiences a data anomaly, the multiple logical storage spaces support data recovery based on snapshot data of the multiple logical storage spaces at the same snapshot time point. The data recovery component indicates that data recovery should be performed on the multiple logical storage spaces. In response to the selection operation of the data recovery component, a data recovery instruction is sent to the data recovery device, the data recovery instruction performing data recovery on the plurality of logical storage spaces.
9. The method according to claim 8, characterized in that, The logical storage space is a logical unit number (LUN) or a file system.
10. The method according to claim 8, characterized in that, The data stored in the multiple logical storage spaces are dependent on each other.
11. The method according to any one of claims 8-10, characterized in that, The method further includes the following steps before the data recovery interface is displayed, provided that the multiple logical storage spaces are located in the same protection group: Send a protection group creation instruction to the data recovery device, the protection group creation instruction including the identifiers of the plurality of logical storage spaces.
12. A data recovery device, characterized in that, The device includes: The acquisition module is used to acquire snapshot data of multiple logical storage spaces that are related in the storage system at a target snapshot time point if any of the multiple logical storage spaces has a data anomaly. The target snapshot time point is before the anomaly occurs. The recovery module is used to recover data from the multiple logical storage spaces based on the snapshot data.
13. The apparatus according to claim 12, characterized in that, The logical storage space is a logical unit number (LUN) or a file system.
14. The apparatus according to claim 12, characterized in that, The data stored in the multiple logical storage spaces are dependent on each other.
15. The apparatus according to any one of claims 12-14, characterized in that, The plurality of logical storage spaces are located in the same protection group, and the device further includes: The snapshot module is used to take a consistent snapshot of the logical storage space in the protection group after each first time interval, so as to obtain at least one snapshot group. The snapshot group includes snapshot data of the multiple logical storage spaces in the protection group at the same snapshot time point. The acquisition module is used to determine the target snapshot group from the at least one snapshot group.
16. The apparatus according to claim 15, characterized in that, The target snapshot group is the net snapshot group among the at least one snapshot group whose snapshot time point is closest to the current time, and the clean snapshot group is the snapshot group in the protection group when there are no data anomalies in the logical storage space; The snapshot module includes: The detection unit is used to perform an anomaly detection on the logical storage space in the protection group once every first time interval; A snapshot unit is used to perform a consistent snapshot of the logical storage space in the protection group; The determining unit is used to determine, based on the detection results of this anomaly detection, whether the snapshot group obtained from this consistency snapshot is the clean snapshot group.
17. The apparatus according to any one of claims 12-14 or 15-16, characterized in that, The acquisition module is used for: If any of the logical storage spaces experiences a data anomaly and a data recovery instruction is received, snapshot data of the multiple logical storage spaces at the target snapshot time point is obtained, and the data recovery instruction instructs the multiple logical storage spaces to perform data recovery.
18. A data recovery device, characterized in that, The device includes: The display module is used to display a data recovery interface, wherein the data recovery interface includes a data recovery component, which corresponds to multiple logical storage spaces that are associated with each other in the storage system. If any of the multiple logical storage spaces experiences a data anomaly, the multiple logical storage spaces support data recovery based on snapshot data of the multiple logical storage spaces at the same snapshot time point. The data recovery component indicates that data recovery should be performed on the multiple logical storage spaces. The sending module is configured to send a data recovery instruction to the data recovery device in response to a selection operation of the data recovery component, the data recovery instruction performing data recovery on the plurality of logical storage spaces.