Image-Level Backup File Restoration With User Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing backup solutions lack efficient user authorization mechanisms for file-level restoration from image-level backups, leading to security concerns and administrative inefficiencies, as either all users can access data or administrators are burdened with manual restoration requests.

Innovation Solution

Implement a user authorization system that uses machine and user identifiers to control access to image-level backups, allowing authorized users to restore data directly through a self-service interface without administrator intervention, by matching identifiers and optionally using authentication cookies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If all users are granted access to restore files from image-level backups, then ease of operation is improved, but data security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements role-based access control where different user groups (students, faculty, administrators) are granted specific restoration permissions based on their needs and security clearances. This allows the system to be easy to operate for authorized users while maintaining data security through differentiated access levels.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an authorization intermediary layer that mediates between users and backup data. This intermediary verifies user credentials, checks restoration permissions, and controls access to image-level backups, thereby maintaining both ease of operation for legitimate users and data security through automated authorization checks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If administrators manually handle all restoration requests, then data security is improved, but administrative workload increases

Engineering Contradiction:
Improvedata securityVSAvoidadministrative workload
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent enables authorized users to independently initiate and complete file restoration operations from image-level backups through a self-service interface. Users can browse backup contents, select files for restoration, and complete the process without administrator intervention, significantly reducing administrative workload while maintaining security through pre-configured authorization rules.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authorization setup in advance, where administrators configure user permissions and access rights before users need to restore files. This preliminary configuration allows the system to automatically handle restoration requests according to pre-established security policies, reducing both administrative workload and maintaining data security.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If user authorization mechanisms are implemented, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal authorization framework that handles multiple user types (students, faculty, administrators) and various restoration scenarios through a single integrated system. This multi-functional authorization mechanism manages different permission levels and restoration contexts using unified principles, preventing excessive complexity while maintaining comprehensive data security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If self-service restoration is enabled, then administrative efficiency is improved, but access control complexity increases

Engineering Contradiction:
Improveadministrative efficiencyVSAvoidaccess control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary authorization configuration where administrators define user permissions and restoration policies in advance. This upfront setup creates a framework that automatically guides self-service restoration operations, allowing users to independently restore files while the system enforces access control rules, thereby improving administrative efficiency without requiring complex real-time access control decisions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250284594A1User authorization for file level restoration from image level backups
Publication Date: 2025.09.11 VEEAM SOFTWARE GROUP GMBH
  • US20250284594A1 patent drawing
  • US20250284594A1 patent drawing
  • US20250284594A1 patent drawing

AI summary

Embodiments provide systems, methods, and computer program products for enabling user authorization to perform a file level recovery from an image level backup of a virtual machine without the need for access control by an administrator. Specifically, embodiments enable an access control mechanism for controlling access to stored image level backups of a virtual machine. In an embodiment, the virtual machine includes a backup application user interface that can be used to send a restoration request to a backup server. The restoration request can include a machine identifier and a user identifier of the user logged onto the virtual machine. The backup server includes a backup application that determines whether or not the machine identifier contained in the restoration request can be matched to a machine identifier of a virtual machine present in one of the virtual machine backups stored on the backup server.