System and method for providing data and application continuity in a computer system
Abstract
A system (100) for providing data continuity for one or more client systems (10), said system (100) comprising: a communication interface (130) configured to receive data from one or more client systems (10) ; a security infrastructure (400) configured to authorize a communication with the one or more of the client systems (10); a hardware infrastructure (140) comprising a replication engine (754) configured to create one or more virtual servers (620), and said one or more virtual servers (620) that are configured to store at least some of the received data of one or more customer systems (10); an application module (180) configured to execute one or more application programs corresponding to application programs running in the client system (10) on some of the data received from one of the client systems (10); and a portal (170) configured to provide access to one or more users associated with one or more client systems (10).

Term
2.5 yearsto projected expiry
Projected expiry 8 April 2029, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
12 claims: 2 independent, 10 dependent
- 1REIVINDICACIONES 1. Un sistema (100) para proporcionar continuidad de datos para uno o mas sistemas de clientes (10), dicho sistema (100) que comprende:una interfaz de comunicacion (130) configurada para recibir datos de uno o mas sistemas de clientes (10);una infraestructura de seguridad (400) configurada para autorizar una comunicacion con el uno o mas de los sistemas de clientes (10);una infraestructura de hardware (140) que comprende un motor de replicacion (754) configurado para crear uno o mas servidores virtuales (620), y dicho uno o mas servidores virtuales (620) que se configuran para almacenar al menos algunos de los datos recibidos de uno o mas sistemas de clientes (10);un modulo de aplicaciones (180) configurado para ejecutar uno o mas programas de aplicaciones correspondientes a programas de aplicaciones que se ejecutan en el sistema de cliente (10) sobre algunos de los datos recibidos de uno de los sistemas de clientes (10);y un portal (170) configurado para proporcionar acceso a uno o mas usuarios asociados con uno o mas sistemas de clientes (10).
- 2El sistema (100) segun la reivindicacion 1, que incluye ademas un mecanismo configurado para recibir entradas introducidas por el uno o mas usuarios en dicho portal (170) y para generar una configuracion de replicacion para dicha infraestructura de hardware (140) o dicho modulo de aplicaciones (180) correspondiente al sistema de cliente (10) asociado.
- 3El sistema (100) segun la reivindicacion 1, que incluye ademas una infraestructura de red (16) que comprende una o mas redes de clientes, cada una de dichas una o mas redes de clientes que comprenden una red privada configurada para el acceso por uno del uno o mas sistemas de clientes (10).
- 4El sistema (100) segun la reivindicacion 1, que incluye ademas una plataforma de control (700) que comprende uno o mas de un modulo de configuracion, un modulo de informe (720), un modulo de registro (730), un modulo de definicion de red (750), un modulo de definicion de servidor (760) y un modulo de definicion de archivo (770).
- 5El sistema (100) segun la reivindicacion 4, en donde dicho modulo de configuracion (700) incluye un mecanismo basado en reglas para generar una definicion de configuracion asociada con uno de los uno o mas sistemas de clientes (10), y un mecanismo basado en reglas que se configura para ser sensible a una o mas entradas del usuario asociado con el sistema de cliente (10).
- 6El sistema (100) segun la reivindicacion 5, en donde el portal (170) se configura para recibir dicha una o mas entradas del usuario y proporcionar dicha una o mas entradas a dicho modulo de configuracion.
- 7El sistema (100) segun la reivindicacion 1, en donde el portal (170) se configura para proporcionar un acceso de entidad a los servidores virtuales asociados con uno o mas de los sistemas de clientes, y dicho acceso que se basa en credenciales asociadas con dicha entidad.
- 8El sistema (100) segun la reivindicacion 7, en donde dicha entidad comprende una entidad socia y uno o mas de los sistemas de clientes (10) comprenden clientes de dicha entidad socia, y dicho portal (170) se configura para permitir que dicha entidad socia controle la configuracion de los servidores virtuales (620) asociados a dichos clientes.
- 9El sistema (100) segun la reivindicacion 8, que incluye ademas un modulo de aplicaciones, dicho modulo de aplicaciones que se configura para ejecutar uno o mas programas de aplicaciones sobre algunos de los datos recibidos de uno de los sistemas de clientes (10), y dicho o mas programas de aplicaciones correspondientes a programas de aplicaciones que se ejecutan en el sistema de cliente (10).
- 10El sistema (100) segun la reivindicacion 9, en donde dicho portal (170) se configura para permitir que dicho socio defina una configuracion de replicacion para dicha infraestructura de hardware (140) o dicho modulo de aplicaciones correspondiente al sistema de cliente (10) asociado.
- 11Un metodo para proporcionar continuidad de datos para uno o mas sistemas de clientes (10) a traves de un sistema de continuidad de datos (100), dicho metodo que comprende:recibir en el sistema de continuidad de datos (100) datos del uno o mas sistemas de clientes (10);proporcionar en el sistema de continuidad de datos (100) un motor de replicacion (754) configurado para crear uno o mas servidores virtuales (620), y dicho uno o mas servidores virtuales (620) que se configuran para almacenar al menos algunos de los datos recibidos del uno o mas sistemas de clientes (10);dicho metodo que se caracteriza por: ejecutar en el sistema de continuidad de datos (100) uno o mas programas de aplicaciones correspondientes a programas de aplicaciones que se ejecutan en el sistema de cliente (10) sobre algunos de los datos recibidos de uno de los sistemas de clientes (10).
- 12El metodo segun la reivindicacion 11, que incluye ademas el paso de almacenar los datos procesados por dicho uno o mas programas de aplicaciones.
Independent claims12
99 paragraphs, as filed
<b>DESCRIPTION</b>
System and method to provide continuity of data and applications in an information system
<b>Field of the Invention</b>
The present application refers to computer systems and, more particularly, to a system and methods to maintain the continuity of data and / or applications in a computer system for a business or a company.
<b>Background of the invention</b>
The uptime of computer systems and data infrastructure for a business is critical to the operation of the company. The same or even more important is the recovery of an economic crisis or system interruption. It has been estimated that at least 50% of a company's intellectual property resides in its email system.
Recovery systems that provide data continuity are known from publications US 2007/078982 A1, US 2008/016387 A1, US 2005/193245 A1, WO 01/14987 A2 and WO 2007/024478 A2, to name just a few few.
Consequently, there remains a need for improvements in the technique to maintain business data continuity.
<b>Brief Summary of the Invention</b>
The present invention is directed to a method and / or system to maintain the continuity of data and / or applications in an information system for a business or a company.
According to one aspect, a system is provided to provide data continuity for one or more client systems, the system comprises: a communication interface configured to receive data from one or more client systems; a security infrastructure configured to authorize communication with the one or more customer systems; a hardware infrastructure comprising a replication engine configured to create one or more virtual servers, and the one or more virtual servers that are configured to store at least some of the data received from the one or more client systems; an application module configured to execute one or more application programs corresponding to application programs running in the client system on some of the data received from one of the client systems; and a portal configured to provide access to one or more users associated with the one or more client systems.
A system for providing data continuity for a plurality of customer systems is also described herein, the system comprises: a communication interface configured to receive data from customer systems; a security infrastructure configured to authorize communication with customer systems; a hardware infrastructure comprising a replication engine configured to create one or more virtual servers, and the one or more virtual servers that are configured to store at least some of the data received from client systems; and a portal configured to provide entity access to virtual servers associated with one or more of the client systems, and access based on the credentials associated with that entity.
According to another aspect, a method is provided to provide data continuity for one or more customer systems through a data continuity system, the method comprises: receiving in the data continuity system, data from one or more data systems. customers; provide in the data continuity system a replication engine configured to create one or more virtual servers, and the one or more virtual servers that are configured to store at least some of the data received from the one or more client systems; said method characterized by: executing in the data continuity system one or more application programs corresponding to application programs that are executed in the client system on some of the data received from one of the client systems.
Other aspects and features of the present invention will become apparent to those skilled in the art upon review of the following description of the embodiments of the invention along with the accompanying figures.
<b>Brief description of the drawings</b>
Reference will now be made to the accompanying drawings which show, by way of example, embodiments of the apparatus and methods described herein, and how they can be carried out, and in which:
Fig. 1 schematically shows a system for maintaining business data continuity according to an embodiment of the present invention and in the context of an exemplary operating environment;
Fig. 2 shows in block diagram form an exemplary client system for the continuity system of data of Fig. 1;
Fig. 3 shows in block diagram form an Internet interface for the data continuity system of Fig. 1 according to an embodiment of the invention;
Fig. 4 shows in block diagram form a security infrastructure for the data continuity system of Fig. 1 according to an embodiment of the invention;
Fig. 5 shows in block diagram form an internal network structure for the data continuity system of Fig. 1 according to an embodiment of the invention;
Fig. 6 shows in block diagram form a hardware virtualization structure for the data continuity system of Fig. 1 according to an embodiment of the invention;
Fig. 7 shows in block diagram form a control platform for the data continuity system of Fig. 1 according to an embodiment of the invention;
Fig. 8 schematically shows a system for maintaining business data continuity and a control system and a management portal according to an embodiment of the present invention and in the context of an exemplary operating environment;
Fig. 9 is a screenshot of a window or login screen of the portal for the control system and the management portal of Fig. 8 according to an embodiment of the present invention;
Fig. 10 is a screenshot of a search or management window or screen for the control system and the management portal of Fig. 8 according to an embodiment of the invention;
Fig. 11 is a screenshot of a screen configured to manage / control a client associated with an entity configured in the control system and the management portal of Fig. 8 according to an embodiment of the present invention;
Fig. 12 is a screenshot of a screen configured to manage / search and access customer data for the control system and the management portal of Fig. 8 according to an embodiment of the invention;
Fig. 13 is a screenshot of a screen configured to access and control clients associated with an exemplary entity configured in the control system and the management portal of Fig. 8 according to an embodiment of the invention; Y
Fig. 14 is a screenshot of a screen configured to access and control the Preparation Evaluation tool for the control system and the management portal of Fig. 8 according to an embodiment of the invention;
Equal reference numbers indicate similar or corresponding elements in the drawings.
<b>Detailed description of the achievements</b>
First, reference is made to Fig. 1, which shows a system 100 according to an embodiment of the present invention and in the context of an exemplary operating environment comprising a plurality of customer systems, with a customer system that is represented in Fig. 1 and is indicated in general by reference 10. In the context of the present description, the system 100 comprises a system for configuring, storing and delivering data (eg, business data) and a control platform for maintaining and managing the data and / or applications to provide data continuity of business, as will be described in more detail below. In the present description, reference is made to system 100 as a system (and method) of data continuity and business applications, or, alternatively, data continuity system 100.
The data continuity system 100 comprises a network interconnection layer or infrastructure 120, a hardware layer or infrastructure 140, a software layer or infrastructure 160, an application module or components 180 and a file component or module. 190 . The exemplary client system 10 comprises client workstations 12, one or more servers 14, and a network structure 16. The functionality and operation of the data continuity system 100 are described in more detail below.
The network interconnection layer 120 includes a network communication interface indicated generally by reference 130. The network communication interface 130 is configured to provide communication with the client system 10 through the Internet 20 and / or through of a path or communication structure 30 of virtual private network (VPN) or wide area network (WAN). The network interconnection layer 120 and the network communication interface 130 are described in more detail.
As shown in Fig. 1, the data continuity system 100 includes a portal indicated by reference 170. Portal 170 provides an Internet interface 20 and provides users, that is, subscribers or clients, access to certain applications and tools in the software layer 160. The data continuity system 100 also includes an internal network indicated by reference 150, which is described in more detail below with reference to Fig. 5. According to one embodiment, the internal network 150 comprises an infrastructure to provide / define a plurality of private customer or production networks. As will be described in more detail below, the internal network infrastructure 150 is used to configure a client private network ("production") for each client of system 100.
Reference is made below to Fig. 2, which shows the client system 10 in more detail. As described above, the client system 10 comprises one or more client workstations 210, client servers 220 and a client network 230. The client workstations comprise desktop computer systems, for example, stations Windows XP, which are residents in the client network 230. Client server 220 comprises one or more servers, including, for example, a mail server such as the Microsoft Exchange ™ system, database servers, such as MS SQL ™ servers, an Active Directory server or servers, a server or application servers such as MS GreatPlains ™ server or servers, and / or the File server, such as an MS Server 2003 ™ server or servers. Client network 230 is configured to provide a network configuration for client workstations 210 and client servers 220 through an Internet connection (ie, an Internet Service Provider or ISP of standard offer) and / or a routing device that connects Internet 20 to a local area network (LAN).
As shown in Fig. 2, each of the client servers 220 includes an agent or replication engine according to an embodiment of the invention and indicated generally by reference 222. According to one embodiment, replication engine 222 is run as a service under the operating system for server 220 and is configured to capture stored data and transfer captured data to replication servers running in the data continuity system of business 100 as described in more detail below with reference to Fig. 8. According to one embodiment, the replication engine 222 is interchangeable with multiple forms of software replication engines. According to one embodiment, the replication engine 222 is configured to work with multiple application formats, such as Mail systems, Databases, Applications and Files from various providers, such as Microsoft and Oracle. Commonly referred to as "client servers", these systems can be either physical or virtualized systems on the network.
In the context of the present description, the client workstations 210 are configured for the creation and retrieval of information (data). According to another aspect, client workstations 210 are configured to access portal 170 (Fig. 1) for data continuity system 100. In a known manner, client workstations 210 can be configured with Microsoft Windows XP ™, Linux ™, Macintosh ™ and other operating systems.
According to one embodiment, the client network 230 comprises a combination of network interconnection devices that are configured to provide an infrastructure layer to the client network 230 and also an interface or gateway to the network interconnection layer 120 (Fig. 1) of the data continuity system 100. Network interconnection devices comprise "routers, modems or access devices" and are configured / connected in a known manner to provide Internet connectivity and network communication capability between client workstations 210 and server devices client 230 and data continuity system 100. According to one embodiment, direct connectivity is provided between client system 10 (Fig. 1) and the data continuity system 100 by means of a router capable of standard WAN VPN as indicated by reference 32 in Fig. 1.
Reference is made below to Fig. 3. The Internet in a known manner comprises interconnected networks that extend across the globe and provide access to users connected to them with services and information available on both public servers and private servers. In the context of the present description, the communication interface 130 (Fig. 1) configured for the Internet provides the capacity for the client system 10 (Fig. 1) and other clients and / or remote servers access and transfer data directly to the data continuity system 100, as will be described in more detail below.
According to one embodiment and as shown in Fig. 1, the client workstations 12 are configured to remotely connect to the business continuity data system 100 through the Internet 20, as opposed to through the network of client 16, that is, WAN 30 and VPN router 32. According to another aspect, Internet 20 provides access to an Internet user 40 (Fig. 1), that is, a remote user, or a user without a system directly connected to the client network 16, who wishes to view or access the information hosted on the client server or servers 14.
Reference is made again to Fig. 3. According to another aspect, Internet 20 provides access to public servers, that is, servers on the Internet that are trying to exchange information with client servers 14 (Fig. 1) in some specific format. This generally takes the form of email, database inquiries or website searches. An email server comprises a typical example of such a server. According to another embodiment, the communication interface 130 (Fig. 1) is configured to send and receive information in multiple formats with publicly and externally hosted systems, such as email servers, websites and database systems, as indicated. by reference 50 in Fig. 1 and reference 310 in Fig. 3.
For example, such systems typically comprise desktop machines, agenda computers and / or mobile wireless communication devices or PDAs, which are configured to access data on client servers 14 through the Internet 20. According to this aspect, the servers coupled to the Internet are capable of sending and receiving communications in a wide variety of formats to the hosted servers and systems associated with the data continuity system 100, as represented by reference 320 in Fig. 3 .
According to another aspect, the data continuity system 100 includes a portal indicated by reference 170 in Fig. 1. Portal 170 is configured as a public portal or interface to provide publicly available access, that is, via Internet 20 , to certain private control and / or configuration functions in the data continuity system 100, as will be described in more detail below. According to one embodiment, portal 170 comprises a secure website, which has a secure website page available on the Internet, for example, with URL www.geminare.com. As will be described in more detail below, portal 170 and the secure web page mechanism provide access to authorized users and the ability to manage and control all their systems from any publicly available system 40 (Fig. 1), as will be described in more detail below with reference to Fig. 7.
Reference is made below to Fig. 4, which shows an embodiment of a security infrastructure 400. The security infrastructure 400 is configured in the network interconnection layer 120 (Fig. 1) and provides security functions that include, Incoming Internet access, firewall, security, remote access, spam prevention and virus filtering control systems for the business data continuity system 100 (Fig. 1). According to one embodiment, the security infrastructure 400 comprises a public network layer 410, a security layer infrastructure 420 and an authentication infrastructure 430. According to one embodiment, the public network layer 410 is implemented or configured using routing devices based on Cisco ™ brand hardware or equivalent. The security layer infrastructure 420 is implemented or configured using Intrusion Detection, Unwanted Email Filtering and Virus Control based hardware devices of the Cisco ™ brand or equivalent. According to one embodiment, the 430 authentication infrastructure is implemented or configured using a Cisco ™ hardware and software based authentication server or equivalent that is capable of communicating with a Microsoft Active Directory RADIUS ™ server or equivalent.
In operation, security infrastructure 400 provides multiple levels of hardware-based security, and comprises a rule-based hardware configuration to filter and authenticate all incoming traffic in data continuity system 100. According to one embodiment, all traffic incoming and outgoing that arrives through the Internet 20 or from an internal network 500 (Fig. 5) passes through the security hardware and the rules for passing or blocking the traffic are applied.
Referring again to Fig. 4, the public network infrastructure layer 410 is intended for inbound and outbound traffic over the Internet 20. The public network infrastructure layer 410 is configured to accept all incoming packets in the system. data continuity 100 and to transmit all packets outside the data continuity system 100. According to one embodiment, the public network infrastructure layer 410 is implemented in the form of a routing system comprising routing tables for Internet domains and is configured to define where the traffic should be transmitted. According to an additional aspect, the public network infrastructure layer 410 is implemented in a fault-tolerant configuration and provides a failover to a second device without any service interruption and controls a secondary backup Internet connection to handle the traffic.
As shown in Fig. 4, the traffic of the public network infrastructure layer 410 is passed or handled by the security layer infrastructure 420. The security layer infrastructure 420 is configured to provide border control and filtering of security. According to one embodiment, the security layer infrastructure 420 determines the traffic that is allowed to pass through the data continuity system 100 and traffic that is blocked or discarded that passes through the data continuity system 100, based to one or more rule adjustments. According to one embodiment, the security layer infrastructure 420 is implemented in the form of a "Router" or "Firewall" device and is configured to provide controls for intrusion detection, management and filtering of spam, and contention functions and virus removal. According to another aspect, the security layer infrastructure 420 is implemented in a redundant configuration to provide a failover to a secondary backup system without interruption. Once the traffic has been reviewed and allowed to pass through the security layer infrastructure 420, it is passed to the authentication infrastructure layer 430.
The authentication infrastructure layer 430 is configured to pass or route the traffic of the security layer infrastructure 420 based on a set of rules to a resource or module in the data continuity system 100 through the internal network 150 (Fig. 1). (The internal network 150 according to one embodiment is described in more detail below with reference to Fig. 5). The authentication infrastructure layer 430 can be implemented both in software and hardware. According to one embodiment, the authentication infrastructure layer 430 is configured to operate in conjunction with the security layer infrastructure 420 to control a network within the internal network 150 for traffic through a virtual network configuration table, ie VLAN According to another aspect, the authentication infrastructure layer 430 is configured to function as an "authentication server" for remote access to virtual machine (VM) 620 servers, which are described in more detail in continued with reference to Fig. 6.
According to another aspect, the authentication infrastructure layer 430 functions as a gateway between the security layer infrastructure 420 and the network definition 750 (Fig. 7) running on the control platform 700 (Fig. 7) as describe in more detail below. According to one embodiment, the authentication infrastructure layer 430 is configured to process remote users based on their current and active credentials that are stored on the control platform 700 (Fig. 7), the network definition module 750 (Fig. 7) and software application components 180 (Fig. 1). Authentication infrastructure layer 430 is configured to manage communication between the previous components and authenticates the communication to ensure that it is valid and appropriate, and then authorizes security layer infrastructure 420 to provide access to the appropriate private client network. in the internal network 150 in the data continuity system 100.
Reference is made below to Fig. 5, which shows the internal network or infrastructure 150 according to an embodiment of the invention. The internal network is indicated by reference 500 in Fig. 5 and according to one embodiment it comprises a shared network infrastructure 510 and a private network infrastructure 520. According to one embodiment, the shared network infrastructure 510 is implemented using a switch configuration network layer 2. Private network infrastructure 520 is implemented using a switch with network VLAN capability. The private network infrastructure 520 comprises a plurality of VLANs and, according to one embodiment, a private VLAN is configured for each client. In operation, the internal network 500 and the private VLANs provide the ability for a multitude of clients to run in the shared hardware infrastructure 140 (Fig. 1) and the network interconnection infrastructure 120 (Fig. 1), while maintaining complete security and separation between each client.
According to another aspect, the internal network 150 includes a management network. The management network runs on the same infrastructure and is configured to provide the data continuity system 100 with access and the ability to interact with each of the client networks and servers directly from a centralized location. According to one embodiment, the management network is configured as a VLAN and provides communication with each of the 520 client VLANs. However, to ensure security, each of the VLANs cannot communicate directly with the management VLAN.
Reference is made below to Fig. 6, which shows a hardware virtualization layer 600 according to an embodiment of the invention. The hardware virtualization layer 600 resides within the hardware infrastructure 140 (Fig. 1) of the system 100 and is configured according to an embodiment to provide the functionality to run a very large number of client environments and servers within virtualized instances. According to one embodiment, hardware virtualization layer 600 is configured to provide multiple levels of redundancy and flexibility when client servers or networks are deployed or modified.
According to one embodiment and as depicted in Fig. 6, the hardware virtualization layer 600 comprises a hardware virtualization control 610 and a hardware virtualization platform 620. The hardware virtualization control 610 is configured to manage the environments of client within a virtualized structure. According to one embodiment, the hardware virtualization layer 600 is configured to perform disk allocation and use, allocation and management of network interconnection and resource allocation, such as memory, CPU and other allocations.
According to one embodiment, the hardware virtualization control 610 is configured to manage the allocation of resources in the hardware virtualization platform 620. The resources for allocation include disk, memory and CPU storage and have a direct relationship with the control of the instances of virtualized environments. According to one embodiment, the hardware virtualization platform 620 is configured to have direct control over the hardware resources such as disk, memory and CPU (without taking into account their configuration), it is <sup>say the hardware virtualization platform </sup>620 <sup>includes the mechanism responsible in the system of </sup>100 data continuity to communicate with the hardware layer.
According to one embodiment, the hardware virtualization control 610 is implemented with IBM xSeries servers and a VMWare Virtual Center, or any hardware platform capable of natively supporting virtualized instances and the corresponding software or platform designed to run a massive number of virtual machines (VM) in a single device (that is, "a physical box"). According to one embodiment, hardware virtualization platform 620 is implemented using IBM xSeries Servers and VMWare ESX Server Software. According to one embodiment, hardware virtualization layer 600 is configured to support approximately 4000 clients configured with hardware resources. The particular details of the implementation will be within the understanding of an expert in the art.
Reference is made below to Fig. 7, which shows a control platform according to an embodiment of the invention and indicated generally by reference 700. As will be described in more detail below, the control platform 700 is configured according to an embodiment to provide the following functions for the data continuity system 100: an interface function, a definition function, a control function, a function report, a registration function and an alert function. According to one embodiment, control platform 700 provides an interface for customers and the ability to call customers directly. hardware and software components within the data continuity system 100 based on user requests. According to another embodiment, the control platform 700 includes a rule-based mechanism, which allows a user to configure a data continuity process by conducting a "Preparation Evaluation" survey or audit.
The functionality and features associated with the control platform 700 are summarized in Table I as shown below:
<img file="ES2711348T3_D0001.tif" />
The references in Table I correspond to references or similar elements in Fig. 7.
As shown in Fig. 7, the control platform 700 comprises the following modules; a customer preparation evaluation audit module 710, a data report module 720, a registration and audit module 730, a contact definition module 740, a network definition module 750, a server definition module 760, a file definition module 770 and a support enablement module 780. According to one embodiment, the aspects of the control platform 700 are implemented and configured in the form of a user interface that is accessed through portal 170 (Fig. 1). A user interface and a configuration according to an embodiment are described in more detail below with reference to Figs. 9 to 14.
According to one embodiment, the client evaluation and audit evaluation module 710 is configured as a line tool that collects information from the server and the client network using, for example, a survey form or interactive questionnaire that is presented to the user. through portal 170. Control platform 700 includes one or more processes that process the collected data and generate a server and network configuration for the user. According to one embodiment, the client audit and access preparation evaluation is accessed through a web browser (for example, MS Internet Explorer) on line in portal 170.
The data report module 720 is configured for data collection and customer report. According to one embodiment, the data report module 720 comprises a storage and search engine 722, an interpretation and analysis engine 724, a recording and file engine 726 and a display and report engine 728. The storage and search engine 722 is configured to provide live or instant feedback on the status of the replication data for a client within the data continuity system 100, for example, through the interface in portal 170 (Fig. . one). According to another aspect, the storage and search engine 722 is configured to allow a user to search for both current and historical data, that is, data that has been processed over time, for example, data replicated for the MS Exchange server during the last 12 hours are 12345 GB.
The interpretation and analysis engine 724 is configured with a set of intelligent business rules that are designed to interpret the replication data that has been stored, that is, archived, and report the status of the data to the end user's client . According to one embodiment, the interpretation and analysis engine 724 is configured to interpret the business rules through calculations that are designed to compare the data that is in the primary server or servers of clients 14 (Fig. 1) with the servers of Replication running on hardware virtualization layer 140 (Fig. 1). An exemplary report may include: "The MS Exchange server is fine and 100% in sync with the primary server."
The recording and archiving engine 726 is configured to record the results generated by the interpretation and analysis engine 724, which can be very important for customers and compares that require documented validations that the services were functioning correctly for specific periods of time. According to one embodiment, the recording and file engine 726 is sensitive to a request through the storage and search engine 722. An exemplary data output from the 726 file and recording engine may comprise: "The MS Exchange server is fine and 100% in sync on December 31, 2007 with the primary server."
The 728 display and report engine is configured to provide an immediate visual representation to the client about the status of its replication servers. According to one embodiment, the display engine 728 is sensitive to the interpretation engine 724 and shows a green, yellow or red indicator for each replica server. For example, a green indicator, for example, a "green light", indicates that the MS Exchange server replica server is in sync with client production server 14 (Fig. 1).
The registration module and auditona 730 is configured for the collection and monitoring of auditone data. According to one embodiment, the registration and audit module 730 comprises an auditory registration engine 732 and an action monitoring engine 734.
Auditone registration engine 732 is configured to record and record all actions with portal 170 for data continuity system 100. It will be appreciated that this provides a system process compatible with SaaS (Software as a Service). According to one aspect, the recorded data / actions include changes in contact data, server data, control systems and audits. The exemplary data generated by the audit registry engine 732 can take the following form: "Administrator Geminare Admin, registered in this account on January 15, 2008 at 3:33 pm and updated address information."
The 734 action monitoring engine is configured to provide a SaaS-compatible system ("Software as a Service") and documentation concerning the status of server systems on hardware virtualization platform 620 (Fig. 6) at specific times . According to one embodiment, all changes of the server states are monitored and recorded in an action log. According to another aspect, the action monitoring engine 734 is configured to provide intelligent processing of the server status information in order to inform the users of the server and any corrective action to be taken. The exemplary data generated by the 734 action monitoring engine can take the as follows: "The status of the MS Exchange server was changed from Paused to Replication at 3:34 pm on January 13, 2008 by the user Geminare Admin."
The contact definition module 740 is configured to provide notification to the responsible parties. According to one embodiment, the contact definition module 740 comprises an authorization control engine 742 and an alert control engine 744.
According to one embodiment, the authorization control engine 742 is configured to capture data for users who have access and / or authorization to control and / or manage replication servers 620 (Fig. 6). This provides a mechanism to ensure that only authorized users have the ability to manipulate the control states of server systems. The exemplary data generated by the authorization control engine 742 can take the following form: "Administrator # 1 has access to the start and stop status of the MS Exchange server."
According to one embodiment, the alert control engine 744 is configured to work together with the authorization control engine 742 to provide the data continuity system 100 with the ability to alert and notify the appropriate users of changes in system status. . The exemplary data generated by the 744 alert control engine can take the following form: "Administrator # 1 is accessible at geminareadmin@geminare.org and via SMS at 416-555-1212".
The network definition module 750 is configured to provide remote access and network configuration functions. According to one embodiment, the network definition module 750 comprises a remote access engine 752 and a server control engine 754.
According to one embodiment, the remote access engine 752 is configured to connect the client network 16 (Fig. 1) to the data continuity system 100 in order to provide remote access. The required controls, access information, authentication and configuration are defined according to the client preparation evaluation audit 710 (as described above) and are used by the remote access engine 752 to configure the connection. Exemplary connection data includes IPSec IP, Encryption Key and Layer Information.
According to one embodiment, the replication engine 754 is configured to replicate active data from the connected client network 16 (Fig. 1) to the replication server or servers in hardware layer 140 (Fig. 1), for example, in time real using block level replication techniques. According to one embodiment, the replication parameters are defined in the network definitions module 750 and comprise compression types, timing and locations, for example, "Compression 2: 1", "Transfer data only after 9 pm" and "Transfer to location c: / spool".
The server definition module 760 is configured to define, that is, create, replication servers in the hardware virtualization platform 620 (Fig. 6) in the hardware infrastructure 140 (Fig. 1) according to a server definition. The replication server or servers are configured to replicate or duplicate the corresponding servers 14 in the client system 10 (Fig. 1). According to one embodiment, the server definition module 760 comprises a server creation engine 762, a server validation engine 764 and a server control engine 766.
According to one embodiment, the server creation engine 762 is configured to create a replication server or servers in the hardware virtualization platform 620, based on a server definition that is created or generated by the evaluation preparation auditory. client 710 (Fig. 7) as described above. An exemplary server definition generated by the 710 client preparation evaluation audit can take the following form: "MS Exchange running 2003, on a Windows 2003 server with 5GB of RAM, 2x50GB hard drives."
According to one embodiment, the server validation engine 764 is configured to take the information that was entered in the server definition module 760 (server creation engine 762) and process the information through one or more defined configuration rules . The operation of the server validation engine 764 serves to ensure that a valid and appropriate server creation is performed for the hardware virtualization platform 620. According to one embodiment, the server validation engine 764 seeks the matching of the configuration, version and configuration information of the server with predefined configuration data to ensure that a match is made within reasonable variations.
According to one embodiment, the server control engine 766 starts up a control system for each of the replication servers after the server creation (762) and server validation (764) operations are performed. According to one embodiment, the control system is configured to allow the replication process to pause, start, stop, create an image, rebuild, execute in a failover state, failover, etc. It will be appreciated that the control system provides a mechanism for a customer to control their system after creation. An exemplary control system configuration comprises: the MS Exchange server is configured for the Pause, Replication or Failover status.
The file definition module 770 is configured to provide a mechanism for defining file control systems. According to one embodiment, the file definition module 770 comprises a file creation engine 772 and a file storage engine 774.
According to one embodiment, the 772 file creation engine is configured to generate an archiving process to automatically archive data outside the active system (ie, replication servers) for an archiving system. The archiving process is based on the file definition, which according to an embodiment is based on the data entered and / or generated by the client preparation evaluation auditone module 710 (described above). According to one embodiment, the archiving process defines a level of information and a time line in which the data that is balanced or factored against the data management capacity of the system must be archived. An exemplary archiving process includes all data on the MS Exchange 001 server to be archived in the database backup if it has more than 30 days.
According to one embodiment, the file storage engine 774 is configured to define a policy or retention and control process for the archived data. According to one embodiment, the retention and control policy is based on the information of the client preparation evaluation auditone module 710 and defines how long the archived data should be kept and how much data should be maintained. According to one embodiment, portal 170 (Fig. 1) includes a component configured to allow a user to directly recover data from file storage.
The support enablement module 780 is configured to provide an automatic support system for a customer. According to one embodiment, once the server data and preferences have been entered through the client preparation evaluation audit module 710, the support enablement module 780 is configured to provide a support platform for users of the customer test and solve the problems of your system configured in the data continuity system 100. According to one embodiment, the support enablement module 780 comprises a capacity enablement motor 782 and a capacity control motor 784.
According to one embodiment, the capacity enablement engine 782 is configured to allow an administrator to define the level of and access to the integrated tools for each user account. An exemplary definition for automatic user support comprises: the user is able to test and see if the VPN network is connected by sending ICMP packets through a VPN tunnel to the replication servers in the data continuity system 100 as defined in the definition of preparation evaluation network.
According to one embodiment, the capacity control engine 784 is configured to allow a user to perform their own tests without assistance through the portal interface 170 (Fig. 1). The tests defined by the 782 capacity enablement engine can vary from VPN-based tests, to service tests and network responses. According to one aspect, the tests can be anything from VPN, services or network responses, and are executed in real time based on the definition in the capacity enablement engine 782. According to one embodiment, the system is configured with a Virtual NOC tab 905 (Fig. 9) to provide an interface for the 782 capacity enablement engine.
The module or component layer of software applications is indicated by reference 180 in Fig. 1 and according to an embodiment of the invention comprises the applications that run directly on the virtualized server instances in the hardware virtualization platform 620 ( Fig. 6). The application components typically comprise mail server applications, database server applications, file server applications and / or directory servers. Exemplary application components include Microsoft Exchange server, Microsoft SQL server and Microsoft IIS server. According to another aspect, the software application component module 180 is configured to process incoming data once it has passed through all the security and operational layers in the data continuity system 100, that is, data that has been replicated through the data continuity system 100, as described above. According to another aspect, the application components represent the actual applications of the server that are processing the data for the users and are also typically responsible for distributing the data. According to another aspect, the hardware virtualization platform 620 (Fig. 6) is configured to run multiple instances of the application component or components. According to one embodiment, the data continuity system 100 does not replicate the application layer within the server environment, only the data used by this layer and, therefore, the software application component layer 180 is used in the delivery of the information of the client servers 14 (Fig. 1) and the replication servers 620 (Fig. 6) in the hardware infrastructure layer 140 (Fig. 1). According to another embodiment, the application component module 180 includes a data replication engine 182 or an application failover control engine 184 in order to provide the ability to "exchange" a replication engine.
The archive component module is indicated by reference 190 in Fig. 1 and, according to one embodiment, is configured to archive data from the data continuity system 100 to a separate system (not shown). For example, once the data has been collected, processed (for example, replicated) and used within the data continuity system 100, it may need to be archived outside in a separate system, for example, based on the criteria that are defined according to the client preparation evaluation auditone module 710 (Fig.
<b>7) </b>as described above. According to one embodiment, the archive component module 190 comprises a hardware and software platform that is responsible for directly archiving the data outside the system live on a separate hardware, software or cloud storage platform for long-term storage. According to one embodiment, the file component module 190 is implemented with a hardware component that uses a SANTM storage device, or another type of shared storage environment device or hardware platform, and a software component comprising the software. ArcServe ™ file or other type of backup / archive software solution. According to one embodiment, the file module 190 is enabled for duplication and backup of the entire existing environment configured for the user, or enabled for duplication or copying of only the data within the environment for archiving purposes. According to another aspect, the file module 190 is configured to copy data in a live and "hot" state from one physical system to the next for an "internal" high availability capability. It will be appreciated that by providing the ability to create images of an entire environment configured for a user (and duplicate it in real time), the data continuity system 100 is capable of creating accurate and duplicate compatible files from client environments in a secure and secure environment. auditable According to another aspect, the archiving process can be audited and / or managed through the portal interface 170 (Fig. 1). According to another embodiment, the archiving process can be audited and / or managed through the portal interface 170 (Fig. 1).
Reference is made below to Figs. 8 to 14, which show a system according to an embodiment of the present invention configured for a management platform of multiple tenants and multiple moments. The system is generally indicated by reference 810 in Fig. 8. The system 810 comprises a control system and a management portal 812, and a network interconnection layer 820, a hardware layer 830 and a software layer 840 implemented, for example, as described above. The 810 system interacts with one or more networks of 802 clients, individually indicated by the references 802a, 802b, 802c ... 802x, through the network interconnection layer 820. The 802 client networks may comprise individual clients or subscribers of the 810 system services and / or clients of an entity or partner that provides / manages the 810 system services. For example, the 802a client network may comprise an individual client, while the 802b and 802c client networks comprise the clients of a partner associated with the 810 system. According to one embodiment, the control system and the management portal 812 are configured to allow an unlimited number of partners to manage an unlimited number of 802 client networks (eg, clients) at the same time without having any impact between them. According to one aspect, a corresponding client network 852 is created (for example, "hosted version"), indicated individually by references 852a, 852b, 852c ... 852x (linked through the 820 network interconnection layer) and an API interface is added / configured in the 810 control and management portal. The configuration allows partners or entities to view / manage their respective customer facilities privately at the same time (for example, based on the security layers and mechanisms described above), for example, from a single screen, as will be described in more detail below.
Reference is made below to Fig. 9, which is a screenshot of an administrator login screen indicated in general by reference 900. The login screen 900 is accessed from a tab or link Control Panel 901. According to one embodiment, the login screen 900 is configured to recognize user access and configure access controls according to privileges, credentials, security and / or actions assigned or authorized for the particular user. For example, the login screen 900 is configured to recognize "Administrators" 902, "Partners Lfderes" 904, "Partners" 906 and "Customers" 908. For the exemplary login represented in Fig. 9, the login screen 900 is configured for an administrator login, and the administrator is identified by a User Name field 910, an Email Address field 912 and a Company Name field 914, and a 920 Session Close button.
As shown in Fig. 9, the user interface for login 900 and other screens include other common or configurable menu items, such as a Main Screen link 930, a Servers Screen link 932, a link 934 Preparation Evaluation Screen, a 936 Accounting and Billing Screen link and a 938 Contact Screen link. The user interface also includes a Member Portal tab 903 and a Virtual NOC tab 905 as shown in Fig. 9.
Reference is made below to Fig. 10, which is a screenshot of a Members Search screen indicated in general by reference 1000. The Members Search Screen 1000 is configured to search for partners (eg partners assets or other similar entities) in the 800 system. Search controls / parameters include the “From” and “Up to” 1010 fields, a “Company Name” field 1012, a “Last Name” field 1014, a “First Name” field 1016 and a “Email Address” field ”1018. According to one embodiment, the search results are displayed in a“ Search Results ”window indicated in general by reference 1020. According to another aspect, each of the search partners is shown with a button or control “Manage” 1030 active. According to one embodiment, the Manage 1030 button is configured to allow an entity, for example, an administrator with the required privileges, to impersonate the selected partner.
Reference is made below to Fig. 11, which is a screenshot of an exemplary Manage Partner screen indicated generally by reference 1100. According to this example, the administrator logs in (as indicated by reference 1102) and is configured to impersonate a Partner, for example, "Geminare Incorporated", (as indicated by reference 1104). According to one embodiment, the Manage Partner 1100 screen is configured with an "Open Preparation Evaluations" 1110 field and a "View" 1112 button to view the open preparation evaluations. According to one embodiment, the Manage Partner 1100 screen includes a "News and Events" 1120 window that is configured to display events associated with the partner. The control system 810 is configured to display / provide access to data associated with the selected partner (for example, the partner through which it is impersonated in this example). According to another aspect, the active fields or buttons indicated generally by reference 1122 are provided and configured to display additional information or details associated with an event.
Reference is made below to Fig. 12, which is a screenshot of an exemplary Partner Search screen and is generally indicated by reference 1200. The Partner Search 1200 screen includes a search results window. 1220 (for example, corresponding to 1020 in Fig. 10 as described above). The 1200 Members Search screen is configured to allow a partner to search and access their entire customer base. As shown, the search results window 1220 is configured with a display that shows a list of customers (for example, customer networks) associated with the Partner. As shown in Fig. 12, each of the listings includes an active “Manage” 1222 button. This allows the partner to control the configuration and / or the settings for each of the clients. As also shown in Fig. 12, the Main Menu button 930 has been activated and is configured with a Start Button 930a, a Change Details button 930b and a Change Password button 930c. The status of the partner (for example, Geminare Incorporated) through which the administrator impersonates is indicated by the boxes or fields 1102 and 1104.
Reference is made below to Fig. 13, which is a screenshot of a Server Control screen indicated generally by reference 1300. The Server Control screen 1300 is shown in response to the Servers 932 button that is displayed. click and provide a 1310 list of control systems (eg servers) for customers associated with the partner. According to one embodiment, the Server Control screen 1300 is configured with the control buttons 1312, 1314 to access and / or control the features and / or functions associated with the hardware / software (for example, the server) for a client. According to this aspect, the Server Control screen 1300 provides the ability for a partner (or an entity that is ultimately passed through the partner) to access control systems and functions throughout the entire customer base associated with the partner.
Reference is made below to Fig. 14, which is a screenshot of a Preparation Evaluation control screen indicated generally by reference 1400. The Preparation Evaluation 1400 control screen is shown in response to the button of Preparation Evaluations 932 which is clicked and provides a 1410 listing of the preparation evaluation for each of the clients associated with the partner. According to one embodiment, the Preparation Evaluation 1400 control screen is configured with an Edit 1412 control button and a respective Revision 1414 control button. Using the control buttons of Edition 1412 and Revision 1414, the partner (or other authorized user) can access / control the functions associated with the preparation evaluation tool, for example, as described above.
The functionality and features associated with the control system and the management portal 810 (Fig. 8) and / or the screens or windows of the user interface (Fig. 9 to 14) for the control system and the portal manage 810 as described above and according to the embodiments can be implemented in the form of one or more software objects, components, or computer programs or program modules on the server and / or client machines. In addition, at least some of all or all software objects, components or modules can be encoded in read-only processing units and / or non-volatile storage media in the mobile communication device, the server and / or others. components or modules represented in the drawings. The specific implementation details of the software objects and / or program modules will be within the knowledge and understanding of a person skilled in the art.
The present invention can be embodied in other specific ways. Certain adaptations and modifications of the invention will be obvious to those skilled in the art. Therefore, the embodiments discussed at this time are considered to be illustrative and not restrictive, the scope of the invention being indicated by the appended claims rather than by the preceding description, and all changes that remain within the meaning of the claims are It intends, therefore, to be encompassed within them.
1 sheet
Sheet 1
22 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 99367 | United States of America | – | |
| 9936708 | United States of America | A | |
| 2009000454 | Canada | W |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| US2009254642A1 | United States of America | A1 | |
| CA2720082A1 | Canada | A1 | |
| WO2009124390A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2266253A1 | European Patent Office (EPO) | A1 | |
| US2011106756A1 | United States of America | A1 | |
| US2011270949A1 | United States of America | A1 | |
| US8135838B2 | United States of America | B2 | |
| US2012198023A1 | United States of America | A1 | |
| EP2266253A4 | European Patent Office (EPO) | A4 | |
| US9002786B2 | United States of America | B2 | |
| US2015180961A1 | United States of America | A1 | |
| US9674268B2 | United States of America | B2 | |
| US2017272510A1 | United States of America | A1 | |
| US9860310B2 | United States of America | B2 | |
| CA2720082C | Canada | C | |
| US10110667B2 | United States of America | B2 | |
| EP2266253B1 | European Patent Office (EPO) | B1 | |
| US2019037009A1 | United States of America | A1 | |
| ES2711348T3This record | Spain | T3 | |
| US11070612B2 | United States of America | B2 | |
| US2021352135A1 | United States of America | A1 | |
| US11575736B2 | United States of America | B2 |
Numbers
- Publication
- 2711348
- Application
- 9729259
Titles2
- Spanish
- Sistema y método para proporcionar continuidad de datos y aplicaciones en un sistema informático
- English
- System and method to provide continuity of data and applications in a computer system
Classification
- CPC, 6
- H04L63/10
- H04L67/1095
- H04L67/1097
- H04L69/40
- H04L51/23
- H04L67/10
- IPC, 6
- H04L12 24
- G06F11 07
- H04L29 14
- H04L29 08
- H10D62 13
- H04L69 40