Backup System Data Protection Area Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing backup systems are vulnerable to destruction of service (DeOS) type attacks, where backup data can become infected, and even if uninfected, manual checks are required to determine restore points, leading to increased time for restoration, and existing technologies fail to ensure restoration when backup software is infected with viruses.

Innovation Solution

A backup system with a storage system and backup server configuration that includes a ledger for managing backup images, a data volume for storing accessed data, a backup image volume for multiple time points, a primary usage volume for the oldest backup, a ledger volume for managing backups, and an access volume with internal volume IDs, allowing sequential storage and association of backup images in a data protection area, preventing data destruction or falsification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If backup data is stored in a conventional backup system, then backup functionality is provided, but the backup data can be infected by DeOS type attacks or viruses, making restoration impossible

Engineering Contradiction:
Improvebackup data integrityVSAvoidvirus infection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The storage system is divided into multiple independent storage destinations (first storage destination and second storage destination). Backup images are segmented and stored across these separate destinations, so that if one destination is infected, the other remains intact and can be used for restoration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A storage controller acts as an intermediary between the backup server and storage destinations. It manages the distribution of backup images to multiple storage destinations and controls access, preventing direct access that could lead to infection while ensuring data integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual checking of backup data is performed to determine restore points, then uninfected backup data can be identified, but the time required for restoration increases dramatically

Engineering Contradiction:
Improverestore point accuracyVSAvoidrestoration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary distribution of backup images to multiple storage destinations with different storage periods. This pre-arranged structure allows the storage controller to quickly identify valid restore points without manual checking, as the distributed architecture inherently provides multiple candidate restore points that can be evaluated automatically.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If backup software is allowed to access storage system to operate, then backup functionality is provided, but the backup software itself can be infected with viruses, destroying all backup images

Engineering Contradiction:
Improvebackup operationVSAvoidsoftware infection
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the backup infrastructure into multiple independent storage destinations, each storing copies of backup images. This segmentation ensures that even if the backup software is infected and destroys backup images in one storage destination, other storage destinations remain intact and can be used for restoration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11556428B2Backup system including a data protection area and a read-only volume used by a controller to read a copy of backup data from the data protection area
Publication Date: 2023.01.17 HITACHI VANTARA LTD
  • US11556428B2 patent drawing
  • US11556428B2 patent drawing
  • US11556428B2 patent drawing

AI summary

Provided is a backup system including a storage system and a backup server, in which the backup server includes a ledger for managing a copy number and a backup acquisition date and time for each backup image, a data volume that stores data accessed by a business server, a backup image volume that stores a plurality of backup images at different time points of the data volume, an access volume having a volume ID for accessing the backup image from the backup server, and a data protection area including at least one volume having an internal volume ID instead of the volume ID for accessing from the backup server are configured in the storage system, and the backup image stored in the data protection area and the access volume are associated, and the backup image in the data protection area is provided to the backup server.