×

Restricted data zones for backup servers

  • US 10,095,587 B1
  • Filed: 12/23/2011
  • Issued: 10/09/2018
  • Est. Priority Date: 12/23/2011
  • Status: Active Grant
First Claim
Patent Images

1. A backup and recovery server, comprising:

  • a storage device providing backup resources;

    a first communication interface for displaying information to and receiving configuration from a top-level administrator of the backup and recovery server;

    a second communication interface for displaying information to and receiving configuration from a tenant administrator associated with a tenant of the backup and recovery server, wherein the tenant comprises a company or organization that is under a different administrative control from that of other tenants; and

    a processor coupled to the storage device and configured to;

    cause the first communication interface to display to the top-level administrator available backup resources of the storage device, wherein the available backup resources are portions of the backup resources that are available to be allocated to one or more restricted data zones;

    receive from the first communication interface configurations from the top-level administrator, wherein the configurations from the top-level administrator comprise external configurations of a restricted data zone associated with the tenant, wherein the external configurations specify portions of the backup resources to be allocated to the restricted data zone associated with the tenant;

    store in the storage device data representing the external configurations of the restricted data zone associated with the tenant, such that the backup resources allocated to the restricted data zone associated with the tenant can no longer be allocated to another restricted data zone;

    cause the second communication interface to display to the tenant administrator only the backup resources allocated to the restricted data zone associated with the tenant, and hide available backup resources and backup resources allocated to other restricted data zones such that the tenant administrator is unaware of the available backup resources and the backup resources allocated to other restricted data zones and is unaware of other tenants sharing the storage device;

    receive from the second communication interface configurations from the tenant administrator, wherein the configurations from the tenant administrator comprise internal configurations of the restricted data zone associated with the tenant, wherein the internal configurations of the restricted data zone do not include adding backup resources to the restricted data zone associated with the tenant, and wherein the internal configurations comprise configurations that specify portions of the backup resources allocated to the restricted data zone associated with the tenant to be allocated to users associated with the tenant;

    provide backup and recovery services to the users associated with the tenant using the backup resources allocated to the restricted data zone associated with the tenant based on the configurations from the tenant administrator;

    segregate the backup and recovery services provided to the users associated with the tenant from backup and recovery services provided to other tenants associated with restricted data zones that are different from the restricted data zone associated with the tenant; and

    after receiving the external configurations of the restricted data zone associated with the tenant, permit the top-level administrator to modify via the first communication interface the external configurations of the restricted data zone associated with the tenant, but restrict the top-level administrator from internal operations of the restricted data zone associated with the tenant, including restricting the top-level administrator from viewing and modifying the internal configurations of the restricted data zone and restricting the top-level administrator from viewing and modifying backup data backed up by the backup and recovery services provided to the users associated with the tenant, wherein the top-level administrator was previously allowed full access to the backup resources allocated to the restricted data zone prior to their allocation.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×