Secure Backup Recovery from Ransomware Using Air-Gapped Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security techniques, such as data replication and snapshots, are costly and inefficient in dealing with ransomware attacks, as they either reproduce the ransomware or require significant disk space and management overhead, and there is no guarantee of recovering corrupted data.

Innovation Solution

A method and system using isolated, disconnected storage nodes to store backup images, monitored by application programming interfaces (APIs) to detect ransomware attacks, allowing for retrieval of a recent backup image for system recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data replication is used to protect against ransomware attacks, then data availability is improved, but the system reproduces ransomware and increases device complexity

Engineering Contradiction:
Improvedata availabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides backup storage into multiple disconnected storage nodes that are isolated from the network. Each node stores portions of backup images, creating segmented backup architecture that prevents ransomware propagation while maintaining data availability for recovery.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention extracts backup images from the networked storage system and stores them in disconnected storage nodes that are isolated from the network. This separation removes backup data from the attack surface, preventing ransomware from encrypting backup copies while preserving recovery capability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If traditional snapshots are used for backup, then data recovery capability is improved, but significant disk space and management overhead are required

Engineering Contradiction:
Improvedata recovery capabilityVSAvoiddisk space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system merges multiple backup images into a single consolidated backup image stored across disconnected storage nodes. This consolidation reduces the total storage requirement compared to maintaining multiple separate snapshot copies, while still enabling recovery to any previous state.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Instead of creating full duplicate snapshots of entire systems, the invention creates selective copies of only the necessary backup images and stores them in disconnected storage. This selective copying approach reduces disk space requirements while maintaining recovery capability for critical data.

Inventive Principle:
Principle #26Copying

3Speed

If networked storage is used for backups, then access speed is improved, but security against ransomware is worsened

Engineering Contradiction:
Improveaccess speedVSAvoidransomware vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by continuously updating backup images in disconnected storage nodes before ransomware attacks occur. These pre-prepared backup images are ready for immediate retrieval and system recovery, eliminating the need for fast access to networked storage during an attack when speed is critical.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4181001B1Secure data backup and recovery from cyberattacks
Publication Date: 2025.07.02 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP4181001B1 patent drawingFigure 1
  • EP4181001B1 patent drawingFigure 2
  • EP4181001B1 patent drawingFigure 3

AI summary

Aspects of the present disclosure provide systems, methods, and computer-readable storage media that support providing secure backup and recovery of files from edge devices during ransomware attacks or other cyberattacks. Secure data, such as medical records, may be stored at one or more networked storage nodes and backup images (e.g., snapshots) may be stored at a disconnected storage node (e.g., an air-gapped storage node) that is isolated from the networked storage nodes. Application programming interface (API) calls may be managed and monitored to detect an alarm state (e.g., a ransomware attack), and based on the alarm state, storage and retrieval from the networked storage nodes may be stopped. Additionally, a recent backup image from the disconnected storage node may be retrieved for use in performing system recovery operations.