Air-Gapped Backup Replication Using Metadata-Based Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods are vulnerable to ransomware attacks and require costly migration of data to a native format before backup, lacking efficient, scalable, and secure integration of backup data across systems.

Innovation Solution

A cloud-based air-gapped data storage management system that integrates proprietary backup copies directly into a destination system, utilizing supplemental metadata for streamlined integration and value-added services, while maintaining an air gap to prevent breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional data migration methods are used to move backup data between systems, then data can be transferred between different systems, but the process requires restoring data to native format first which increases complexity and time consumption

Engineering Contradiction:
Improvedata compatibilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates replica copies of backup data that preserve the original proprietary format and metadata structure. Instead of restoring to native format and re-backing up, the system copies the backup structure directly while maintaining format fidelity, thereby reducing complexity while achieving cross-system compatibility

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The destination system is pre-configured with parsers and integration tools that anticipate the source system's proprietary metadata format. By preparing the destination environment in advance with the appropriate parsing capabilities, the system eliminates the need for format conversion during the migration process

Inventive Principle:
Principle #10Preliminary action

2Productivity

If backup copies are integrated directly without restoration, then integration efficiency improves and source system performance is preserved, but the destination system must recognize and parse proprietary metadata formats

Engineering Contradiction:
Improveintegration speedVSAvoidmetadata parsing complexity
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The backup copies contain self-descriptive metadata that includes format identification, structure definitions, and parsing instructions. This self-service metadata allows the destination system's parser to automatically recognize and interpret the proprietary format without requiring manual configuration or complex detection algorithms

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a metadata layer that acts as an intermediary between the proprietary backup format and the destination system's native ecosystem. This metadata layer contains translation rules and structure definitions that enable the parser to bridge the format gap efficiently

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data is stored in a cloud-based air-gapped system, then security against ransomware attacks is improved, but the system must maintain connectivity capabilities for legitimate access

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the data protection function from the data access function. The air-gapped cloud storage provides secure, isolated storage that cannot be breached by ransomware, while separate authorized access mechanisms allow legitimate retrieval. This segmentation maintains both security and accessibility without compromise

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authorized intermediary access mechanism that bridges the air gap for legitimate operations. This controlled intermediary channel allows authenticated users to request and receive data from the isolated cloud storage without compromising the security barrier that protects against unauthorized ransomware attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If supplemental metadata is added to backup copies, then integration capability and value-added services improve, but the data storage requirements and processing overhead increase

Engineering Contradiction:
Improveintegration capabilityVSAvoiddata volume
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The supplemental metadata structure is designed as a universal framework that serves multiple functions: format identification, structure definition, parsing guidance, and value-added service enablement. This multi-functional metadata approach maximizes integration capability while minimizing the quantity of metadata required compared to separate structures for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12579041B2Cloud-based air-gapped data storage management system
Publication Date: 2026.03.17 COMMVAULT SYSTEMS INC
  • US12579041B2 patent drawing
  • US12579041B2 patent drawing
  • US12579041B2 patent drawing

AI summary

An illustrative cloud-based air-gapped data storage management (destination) system obtains authorized access to other (source) systems' backup copies, replicates those copies within the destination system, parses supplemental metadata included in the source backup copies, and integrates the replica copies into the destination system as though natively created there. Replica copies are integrated as backup copies without first restoring the source backup copies to a native data format. The source system lacks knowledge of or connectivity with the destination system, thus maintaining an “air gap” between the systems. The destination system preferably operates in a cloud computing environment. The destination system uses supplemental metadata from the replica copies to re-create or mimic the source's computing environment and to restore backed up data from the replica copies. The destination system also operates as an autonomous analytics engine, applying value-added services to backed up data pulled from source system(s).