IP Library › Granted Patent US 12,524,546
Granted Patent B2
US 12,524,546 · App. 17/583,172 · Granted Jan 13, 2026

Secure data backup and recovery from cyberattacks

Inventors: Andrew Truscott (Spring, TX); Teresa Sheausan Tung (Tustin, CA); Brandon Winful (Fannin, TX); Mallikarjun Bepeta (Toronto, CA)
Assignee: Accenture Global Solutions Limited
G06F21/568G06F3/0619G06F3/065G06F3/067G06F21/561G06F2221/033G16H10/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,546
App. No.
17/583,172
Granted
Jan 13, 2026
Kind
B2
Abstract

Aspects of the present disclosure provide systems, methods, and computer-readable storage media that support providing secure backup and recovery of files from edge devices during ransomware attacks or other cyberattacks. Secure data, such as medical records, may be stored at one or more networked storage nodes and backup images (e.g., snapshots) may be stored at a disconnected storage node (e.g., an air-gapped storage node) that is isolated from the networked storage nodes. Application programming interface (API) calls may be managed and monitored to detect an alarm state (e.g., a ransomware attack), and based on the alarm state, storage and retrieval from the networked storage nodes may be stopped. Additionally, a recent backup image from the disconnected storage node may be retrieved for use in performing system recovery operations.

Claims (56)

1 . A method for providing secure backup and recovery of files during ransomware attacks or other cyberattacks, the method comprising:

storing, by one or more processors, received data at one or more storage nodes coupled via a network to create a data backup at the one or more storage nodes;

storing, by the one or more processors, duplicated images of the data backup as backup images at a disconnected storage node that is isolated from the network;

initiating, by the one or more processors, an alarm state to indicate detection of target activity including a plurality of sequences of activities, wherein the target activity is associated with a ransomware attack indicated by deviation in pattern of at least one application programming interface (API) call, and wherein the alarm state corresponds to the data backup;

issuing, by the one or more processors, one or more application programming interface API calls to the disconnected storage node after detection of the ransomware attack;

prohibiting, by the one or more processors, access to the data backup at the one or more storage nodes based on the alarm state;

initiating, by the one or more processors, storage of recovered data at one or more other storage nodes coupled via the network to create a second data backup at the one or more other storage nodes by building new edge nodes to restore a most recent backup image, the new edge nodes being an air gap cluster;

providing the most recent backup image to the new edge nodes;

receiving the most recent backup image from the disconnected storage node; and

performing, by the one or more processors, one or more system recovery operations of a central system based on the recent backup image, wherein the new edge nodes are put into production based on the retrieved backup image to restore the central system.

2 . The method of claim 1 , further comprising detecting, by the one or more processors, the target activity based on monitoring API calls to store or retrieve data from the data backup, API calls to store or retrieve the backup images from the disconnected storage node, or a combination thereof.

3 . The method of claim 2 , wherein the target activity comprises an expired API call or a particular sequence of API calls that correspond to the ransomware attack.

4 . The method of claim 1 , further comprising prohibiting, by the one or more processors, access to the data backup at the one or more storage nodes based on the alarm state.

5 . The method of claim 1 , wherein the one or more API calls comprise industry standard API calls.

6 . The method of claim 1 , wherein the disconnected storage node comprises an on-premises storage node that is isolated from the network or a cloud-based storage node that is disconnected from the network.

7 . The method of claim 1 , further comprising:

receiving, by the one or more processors after receipt of the recent backup image, additional backup data from the disconnected storage node; and

performing, by the one or more processors, one or more additional system recovery operations based on the additional backup data.

8 . The method of claim 1 , further comprising:

generating, by the one or more processors, one or more logs of system activity during the alarm state; and

providing, by the one or more processors, the one or more logs for analysis after termination of the alarm state.

9 . The method of claim 1 , wherein the received data comprises electronic health record/electronic medical record (EHR/EMR) data.

10 . The method of claim 1 , wherein the most recent backup image includes read images and write images representing images of system information, files, or data read from the central system and images of system information, files, or data write by the central system for performing system backups of the central system.

11 . A system for providing secure backup and recovery of files during ransomware attacks or other cyberattacks, the system comprising:

a memory; and

one or more processors communicatively coupled to the memory, the one or more processors configured to:

initiate storage of received data at one or more storage nodes coupled via a network to create a data backup at the one or more storage nodes;

initiate storage of duplicated images of the data backup as backup images at a disconnected storage node that is isolated from the network;

detect, target activity includes a plurality of sequences of activities, to initiate an alarm state corresponding to the data backup, wherein the target activity is associated with a ransomware attack indicated by deviation in pattern of at least one application programming interface (API) call;

issue one or more API calls to the disconnected storage node after detection of the ransomware attack;

prohibit, access to the data backup at the one or more storage nodes based on the alarm state, and

initiate, storage of recovered data at one or more other storage nodes coupled via the network to create a second data backup at the one or more other storage nodes by building new edge nodes to restore a most recent backup image, the new edge nodes being an air gap cluster;

provide, the most recent backup image to the new edge nodes; and

perform one or more system recovery operations of a central system based on the most recent backup image received from the disconnected storage node, wherein the new edge nodes are put into production based on the retrieved backup image to restore the central system.

12 . The system of claim 11 , wherein the one or more processors are further configured to detect the target activity based on monitored API calls to store or retrieve data from the data backup, monitored API calls to store or retrieve the backup images from the disconnected storage node, or a combination thereof.

13 . The system of claim 12 , wherein the target activity comprises an expired API call or a particular sequence of API calls that correspond to the ransomware attack.

14 . The system of claim 11 , wherein the one or more API calls comprise industry standard API calls.

15 . The system of claim 11 , wherein the disconnected storage node comprises an on-premises storage node that is isolated from the network or a cloud-based storage node that is disconnected from the network.

16 . The system of claim 11 , wherein the received data comprises electronic health record/electronic medical record (EHR/EMR) data.

17 . A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations for providing secure backup and recovery of files during ransomware attacks or other cyberattacks, the operations comprising:

storing received data at one or more storage nodes coupled via a network to create a data backup at the one or more storage nodes;

storing duplicated images of the data backup as backup images at a disconnected storage node that is isolated from the network;

detecting, target activity including a plurality of sequences of activities, and initiating an alarm state corresponding to the data backup wherein the target activity is associated with a ransomware attack indicated by deviation in pattern of at least one application programming interface (API) call;

issuing one or more API calls to the disconnected storage node after detection of the ransomware attack;

prohibiting, access to the data backup at the one or more storage nodes based on the alarm state, and

initiating, storage of recovered data at one or more other storage nodes coupled via the network to create a second data backup at the one or more other storage nodes by building new edge nodes to restore a most recent backup image, the new edge nodes being an air gap cluster;

providing the most recent backup image to the new edge nodes;

receiving from the disconnected storage node the most recent backup image; and

performing one or more system recovery operations of a central system based on the recent backup image, wherein the new edge nodes are put into production based on the retrieved backup image to restore the central system.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the operations further comprise:

receiving, after receipt of the recent backup image, additional backup data from the disconnected storage node; and

performing one or more additional system recovery operations based on the additional backup data.

19 . The non-transitory computer-readable storage medium of claim 17 , wherein the operations further comprise:

generating one or more logs of system activity during the alarm state; and

providing the one or more logs for analysis after termination of the alarm state.

20 . The non-transitory computer-readable storage medium of claim 17 , wherein the most recent backup image includes read images and write images representing images of system information, files, or data read from the central system and images of system information, files, or data write by the central system for performing system backups of the central system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2022
From: TRUSCOTT, ANDREW; TUNG, TERESA SHEAUSAN; WINFUL, BRANDON; BEPETA, MALLIKARJUN
To: ACCENTURE GLOBAL SOLUTIONS LIMITED
Reel/Frame 060747/0900 →
Continuity (2)
Provisional Application 63278028 · Nov 10, 2021
Related Publication 20230141909A1 · May 11, 2023
References Cited (31)
US 8868979B1 · Zhang · 2014 [cited by examiner]
US 10503610B1 · Shemer · 2019 [cited by examiner]
US 10581897B1 · Natanzon · 2020 [cited by examiner]
US 10983877B1 · Hoffman · 2021 [cited by examiner]
US 12354043B2 · Saxe · 2025 [cited by examiner]
US 20160277374A1 · Reid · 2016 [cited by examiner]
US 20160371500A1 · Huang · 2016 [cited by examiner]
US 20170270293A1 · Gu · 2017 [cited by examiner]
US 20180034835A1 · Iwanir · 2018 [cited by examiner]
US 20180181761A1 · Sinha · 2018 [cited by examiner]
US 20190108340A1 · Bedhapudi · 2019 [cited by examiner]
US 20190121978A1 · Kraemer · 2019 [cited by examiner]
US 20190155695A1 · Protasov · 2019 [cited by examiner]
US 20190228148A1 · Pohl · 2019 [cited by examiner]
US 20200099699A1 · Saad · 2020 [cited by examiner]
US 20200213361A1 · Du · 2020 [cited by examiner]
US 20200236121A1 · Spurlock · 2020 [cited by examiner]
US 20200336508A1 · Srivastava · 2020 [cited by examiner]
US 20210067423A1 · Newman · 2021 [cited by examiner]
US 20210264028A1 · Genc · 2021 [cited by examiner]
US 20220027471A1 · Levy · 2022 [cited by examiner]
US 20220244858A1 · Grunwald · 2022 [cited by examiner]
US 20220292187A1 · Bhagi · 2022 [cited by examiner]
US 20220350887A1 · Kahn · 2022 [cited by examiner]
US 20220368613A1 · Darji · 2022 [cited by examiner]
US 20230018773A1 · Sudevalayam · 2023 [cited by examiner]
US 20230078476A1 · Venkatachalam · 2023 [cited by examiner]
US 20230393859A1 · Adogla · 2023 [cited by examiner]
IT 202000028874A1 · 2020 [cited by examiner]
European Patent Office, Communication, Extended European Search Report issued for European Patent Application No. 22206288.7, dated Apr. 4, 2023, 10 pages. [cited by applicant]
Gonzalez, D. et al. “Detection and Prevention of Crypto-Ransomware,” IEEE 8th Annual Ubiquitous Computing, Electronics and Mobile Communication Conference (UEMCON), Oct. 2017, 7 pages. [cited by applicant]