IP Library Granted Patent US 11,606,386
Granted Patent B2
US 11,606,386 · App. 17/686,690 · Granted Mar 14, 2023

Secure restore

Inventors: Ratmir Timashev (Baar, CH); Anton Gostev (Saint-Petersburg, RU)
Assignee: VEEAM SOFTWARE AG
H04L63/145G06F11/1464G06F11/1469G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,606,386
App. No.
17/686,690
Granted
Mar 14, 2023
Kind
B2
Abstract

Disclosed herein are system, method, and computer program product embodiments for restoring an electronic device. An embodiment operates by receiving a request for restoring a portion of data from a point of time onto the electronic device. Thereafter, the portion of data is scanned for a virus. Based on the detection of the virus, a determination is made on whether to proceed with restoring the electronic device with the portion of data. If the determination is made to proceed with the restoring of the electronic device, the portion of data is subsequently transmitted to the electronic device. The portion of data is stored in a backup repository remote from the electronic device.

Claims (75)

1. A computer-implemented method for restoring an electronic device, comprising:

receiving, at a mount server, a first request for restoring a first portion of data onto the electronic device, wherein the first portion of data is stored in a backup repository remote from the electronic device;

in response to receiving the first request, creating, at the mount server, a custom folder comprising a pointer to a volume in the backup repository, wherein the volume comprises the first portion of data;

scanning, at the mount server using the pointer to the volume, the first portion of data for a virus;

detecting, at the mount server, the virus in the first portion of data based on the scanning of the first portion of data;

determining, at the mount server, whether to proceed with restoring the electronic device with the first portion of data based on the detecting the virus in the first portion of data; and

transmitting, by the mount server, the first portion of data to the electronic device based on the determining of whether to proceed with restoring the electronic device with the first portion of data.

2. The computer-implemented method of claim 1 , further comprising:

receiving, at the mount server, a second request for restoring a second portion of data onto the electronic device based on the determining of whether to proceed with restoring the electronic device with the first portion of data, wherein the second request and the second portion of data are different from the first request and the first portion of data, respectively, and wherein the second portion of data is stored in a second backup repository remote from the electronic device;

scanning, at the mount server, the second portion of data for the virus;

detecting, at the mount server, the virus in the second portion of data based on the scanning of the second portion of data;

determining, at the mount server, whether to proceed with restoring the electronic device with the second portion of data based on the detecting of the virus in the second portion of data; and

transmitting, by the mount server, the second portion of data to the electronic device based on the determining of whether to proceed with restoring the electronic device with the second portion of data.

3. The computer-implemented method of claim 1 , wherein the transmitting further comprises:

transmitting the first portion of data to the electronic device based on the electronic device being on a different network than the mount server or the electronic device being associated with a different security group than the mount server.

4. The computer-implemented method of claim 1 , further comprising:

checking the first portion of data for the virus,

wherein the checking is performed prior to the receiving of the first request, and

wherein the checking is performed by an administrator of the electronic device and the first request is received from a user of the electronic device.

5. The computer-implemented method of claim 1 , wherein the determining whether to proceed with restoring the electronic device with the first portion of data further comprises:

determining, at the mount server, that the electronic device can be restored in a safe mode;

disabling, by the mount server, an adapter connecting the electronic device to a network based on the determining that the electronic device can be restored in the safe mode.

6. The computer-implemented method of claim 5 , wherein the disabling the adapter connecting the electronic device to the network further comprises:

disabling, by the mount server, the adapter prior to the transmitting of the first portion of data to the electronic device.

7. The computer-implemented method of claim 5 , wherein the determining that the electronic device can be restored in the safe mode further comprises:

determining that restoring the electronic device with the first portion of data is associated with a virtual disk.

8. A system, comprising:

a memory; and

at least one processor coupled to the memory and configured to:

receive a first request for restoring a first portion of data onto an electronic device, wherein the first portion of data is stored in a backup repository remote from the electronic device;

in response to receiving the first request, create a custom folder comprising a pointer to a volume in the backup repository, wherein the volume comprises the first portion of data;

scan, using the pointer to the volume, the first portion of data for a virus;

detect the virus in the first portion of data;

determine whether to proceed with restoring the electronic device with the first portion of data based on the detection of the virus in the first portion of data; and

transmit the first portion of data to the electronic device based on the determining of whether to proceed with restoring the electronic device with the first portion of data.

9. The system of claim 8 , wherein the at least one processor is further configured to:

receive a second request for restoring a second portion of data onto the electronic device based on the determining of whether to proceed with restoring the electronic device with the first portion of data, wherein the second request and the second portion of data are different from the first request and the first portion of data, respectively, and wherein the second portion of data is stored in a second backup repository remote from the electronic device;

scan the second portion of data for the virus;

detect the virus in the second portion of data;

determine whether to proceed with restoring the electronic device with the second portion of data based on the detection of the virus in the second portion of data; and

transmit the second portion of data to the electronic device based on the determining of whether to proceed with restoring the electronic device with the second portion of data.

10. The system of claim 8 , wherein to transmit the first portion of data to the electronic device, the at least one processor is further configured to:

transmit the first portion of data to the electronic device based on the electronic device being on a different network than the system or the electronic device being associated with a different security group than the system.

11. The system of claim 8 , wherein the at least one processor is further configured to:

check the first portion of data for the virus,

wherein the checking is performed prior to the receiving of the first request, and

wherein the checking is performed by an administrator of the electronic device and the first request is received from a user of the electronic device.

12. The system of claim 8 , wherein to determine whether to proceed with restoring the electronic device with the first portion of data, the at least one processor is further configured to:

determine that the electronic device can be restored in a safe mode;

disable an adapter connecting the electronic device to a network based on the determination that the electronic device can be restored in the safe mode.

13. The system of claim 12 ; wherein to disable the adapter connecting the electronic device to the network, the at least one processor is further configured to:

disable the adapter prior to the first portion of data being transmitted to the electronic device.

14. The system of claim 12 , wherein to determine that the electronic device can be restored in the safe mode, the at least one processor is further configured to:

determine that restoring the electronic device with the first portion of data is associated with a virtual disk.

15. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

receiving a first request for restoring a first portion of data onto an electronic device, wherein the first portion of data is stored in a backup repository remote from the electronic device;

in response to receiving the first request, creating a custom folder comprising a pointer to a volume in the backup repository, wherein the volume comprises the first portion of data;

scanning, using the pointer to the volume, the first portion of data for a virus;

detecting the virus in the first portion of data;

determining whether to proceed with restoring the electronic device with the first portion of data based on the detecting the virus in the first portion of data; and

transmitting the first portion of data to the electronic device based on the determining of whether to proceed with restoring the electronic device with the first portion of data.

16. The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise:

receiving a second request for restoring a second portion of data onto the electronic device based on the determining of whether to proceed with restoring the electronic device with the first portion of data, wherein the second request and the second portion of data are different from the first request and the first portion of data, respectively, and wherein the second portion of data is stored in a second backup repository remote from the electronic device;

scanning the second portion of data for the virus;

detecting the virus in the second portion of data;

determining whether to proceed with restoring the electronic device with the second portion of data based on the detecting of the virus in the second portion of data; and

transmitting the second portion of data to the electronic device based on the determining of whether to proceed with restoring the electronic device with the second portion of data.

17. The non-transitory computer-readable medium of claim 15 , wherein the transmitting further comprises:

transmitting the first portion of data to the electronic device based on the electronic device being on a different network than the at least one computing device or the electronic device being associated with a different security group than the at least one computing device.

18. The non-transitory computer-readable medium of claim 15 , wherein the determining whether to proceed with restoring the electronic device with the first portion of data further comprises:

determining that the electronic device can be restored in a safe mode;

disabling an adapter connecting the electronic device to a network based on the determining that the electronic device can be restored in the safe mode.

19. The non-transitory computer-readable medium of claim 18 , wherein the disabling the adapter connecting the electronic device to the network further comprises: disabling the adapter prior to the transmitting of the first portion of data to the electronic device.

20. The non-transitory computer-readable medium of claim 19 , wherein the determining that the electronic device can be restored in the safe mode further comprises:

determining that restoring the electronic device with the first portion of data is associated with a virtual disk.

Assignments (4)
CHANGE OF NAME Recorded May 21, 2026
From: VEEAM SOFTWARE GMBH
To: VEEAM SOFTWARE GROUP GMBH
Reel/Frame 075623/0835 →
ENTITY CONVERSION Recorded May 20, 2026
From: VEEAM SOFTWARE AG
To: VEEAM SOFTWARE GMBH
Reel/Frame 075583/0744 →
PATENT SECURITY AGREEMENT Recorded May 3, 2024
From: VEEAM SOFTWARE GROUP GMBH (F/K/A VEEAM SOFTWARE AG)
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067309/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2022
From: TIMASHEV, RATMIR; GOSTEV, ANTON
To: VEEAM SOFTWARE AG
Reel/Frame 059171/0127 →
Continuity (2)
Continuation 16585819 · Sep 27, 2019
Related Publication 20220191218A1 · Jun 16, 2022