IP Library Granted Patent US 12,360,944
Granted Patent B2
US 12,360,944 · App. 18/515,343 · Granted Jul 15, 2025

Cloud-based secure operation of a recovery storage manager

Inventors: Abhinaw Kumar (Rangareddy, IN); Sanjay Harakhchand Kripalani (Morganville, NJ); Sachin Dattatraya Dhorage (Pune, IN); Satya Narayan Mohanty (Masjid Banda, IN)
Assignee: Commvault Systems, Inc.
G06F16/122G06F11/1464G06F11/1469G06F2201/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,360,944
App. No.
18/515,343
Granted
Jul 15, 2025
Kind
B2
Abstract

A secure data storage management “recovery system” operates in a cloud computing environment that is apart from a source system and source data being protected. A “recovery manager” in the cloud computing environment is responsible for restoring secondary copies that were generated by the source system. The recovery manager gains knowledge (metadata) about the secondary copies by restoring, for its own use, a management database of, and backed up by, the source system. The recovery manager initiates out-of-place restores of the secondary copies to “recovery clients” in the recovery cloud. The recovery system restores, to the recovery cloud, secondary copies from any cloud platform and/or from non-cloud data centers, including secondary copies stored locally, off-cloud by the source system. The recovery manager comprises new features that enforce its isolation from the source system and they act to protect the integrity of the secondary copies generated by the source system.

Claims (54)

1. A system comprising:

a first computing device comprising one or more first hardware processors and non-transitory computer-readable memory comprising computer programming instructions, which, when executed by the one or more first hardware processors, configure the first computing device to perform operations of a recovery manager, wherein the first computing device operates in a cloud computing environment;

wherein a second computing device that comprises one or more second hardware processors and non-transitory computer-readable memory comprising computer programming instructions, which, when executed by the one or more second hardware processors, configure the second computing device to perform operations of a storage manager,

wherein the storage manager previously managed backup operations that generated a first plurality of secondary copies of primary data,

wherein the primary data was generated by a first plurality of client computing devices that are registered as clients of the storage manager,

wherein the backup operations stored the first plurality of secondary copies in one or more data storage resources of the cloud computing environment, and

wherein the second computing device and the first plurality of client computing devices operate outside the cloud computing environment; and

wherein the operations of the recovery manager comprise:

causing information previously backed up from a first management database of the storage manager to be restored to a second management database of the recovery manager, wherein the first management database comprises first information about a first secondary copy among the first plurality of secondary copies, and wherein the first information is included in the second management database;

configuring a recovery client on a compute resource of the cloud computing environment that is distinct from the first computing device, wherein the recovery client is registered as a client of the recovery manager;

configuring a media agent on a compute resource of the cloud computing environment that is distinct from the first computing device, to access, and to prevent changing a write setting at, the one or more data storage resources that store the first plurality of secondary copies;

managing a restore operation of the first secondary copy, wherein the restore operation comprises the media agent: restoring the first secondary copy in a backup format into restored data in a primary data format, and storing the restored data in a data storage resource of the cloud computing environment; and

configuring the recovery client to consume the restored data.

2. The system of claim 1 , wherein the operations of the recovery manager further comprise: preventing any of the first plurality of client computing devices, which are registered as clients of the storage manager, from registering as a client of the recovery manager.

3. The system of claim 1 , wherein the operations of the recovery manager further comprise: preventing the recovery manager from accessing any of the first plurality of client computing devices.

4. The system of claim 1 , wherein the media agent is further configured to prevent the media agent from receiving data from any of the first plurality of client computing devices.

5. The system of claim 1 , wherein the restore operation managed by the recovery manager occurs concurrently with a first backup operation of at least some of the primary data generated by the first plurality of client computing devices, wherein the first backup operation is managed by the storage manager.

6. The system of claim 5 , wherein the first backup operation managed by the storage manager uses a second media agent that is distinct from the media agent; and wherein the media agent is further configured to reject requests to establish a backup pipeline with any of the first plurality of client computing devices that are registered as clients of the storage manager.

7. The system of claim 1 , wherein the one or more data storage resources that store the first plurality of secondary copies comprise write-once read-many (WORM) storage technology, and wherein the write setting that the media agent is prevented from changing comprises a release of a WORM hold on the first secondary copy.

8. The system of claim 1 , wherein the operations of the storage manager further comprise: causing a secondary copy of the first management database to be generated and stored in a storage resource of the cloud computing environment, wherein the second management database comprises information restored from the secondary copy of the first management database.

9. The system of claim 1 , wherein the operations of the recovery manager further comprise:

receiving a request for information about a first backup operation managed by the storage manager; and

based on determining that the second management database comprises the information about the first backup operation, responding to the request.

10. The system of claim 1 , wherein the operations of the recovery manager further comprise: receiving administrative inputs; and

based on determining that the administrative inputs would enable the recovery manager to manage backup operations of primary data generated by the first plurality of client computing devices, rejecting the administrative inputs.

11. The system of claim 1 , wherein the operations of the recovery manager further comprise: receiving administrative inputs from an administrator who is authorized to administer preferences for backup operations at the storage manager; and

based on determining that the administrative inputs would enable the recovery manager to manage backup operations of primary data generated by the first plurality of client computing devices, rejecting the administrative inputs.

12. A system comprising:

a first computing device comprising one or more first hardware processors and non-transitory computer-readable memory comprising computer programming instructions, which, when executed by the one or more first hardware processors, configure the first computing device to perform operations of a recovery manager, wherein the first computing device operates in a cloud computing environment;

wherein a second computing device that comprises one or more second hardware processors and non-transitory computer-readable memory comprising computer programming instructions, which, when executed by the one or more second hardware processors, configure the second computing device to perform operations of a storage manager,

wherein previously, the storage manager managed backup operations that generated a first plurality of secondary copies of primary data,

wherein the primary data was generated by a first plurality of client computing devices that are registered as clients of the storage manager,

wherein the backup operations stored the first plurality of secondary copies in one or more data storage resources outside the cloud computing environment, and

wherein the second computing device and the first plurality of client computing devices operate outside the cloud computing environment; and

wherein the operations of the recovery manager comprise:

causing information previously backed up from a first management database of the storage manager to be restored to a second management database of the recovery manager, wherein the first management database comprises first information about a first secondary copy among the first plurality of secondary copies, and wherein the first information is included in the second management database,

configuring a recovery client on a compute resource of the cloud computing environment that is distinct from the first computing device, wherein the recovery client is registered as a client of the recovery manager,

managing a restore operation of the first secondary copy, wherein the restore operation converts the first secondary copy from a backup format to restored data in a primary data format, and stores the restored data in a data storage resource of the cloud computing environment,

configuring the recovery client to consume the restored data, and

rejecting a request from any of the first plurality of client computing devices, which are registered as clients of the storage manager, to register as a client of the recovery manager.

13. The system of claim 12 , wherein the operations of the recovery manager further comprise: configuring a first media agent on a compute resource of the cloud computing environment that is distinct from the first computing device, to: access the first secondary copy in the one or more data storage resources that store the first plurality of secondary copies, restore the first secondary copy, and store the restored data in the cloud computing environment.

14. The system of claim 13 , wherein the one or more data storage resources that store the first plurality of secondary copies comprise write-once read-many (WORM) storage technology, and wherein the first media agent is configured to prevent the first media agent from changing a release of a WORM hold on the first secondary copy.

15. The system of claim 13 , wherein the restore operation managed by the recovery manager occurs concurrently with a first backup operation of at least some of the primary data generated by the first plurality of client computing devices, wherein the first backup operation is managed by the storage manager and uses a second media agent that is distinct from the first media agent; and

wherein the first media agent is configured to reject requests to establish a backup pipeline with any of the first plurality of client computing devices that are registered as clients of the storage manager.

16. The system of claim 12 , wherein the operations of the recovery manager further comprise: preventing the recovery manager from accessing any of the first plurality of client computing devices.

17. The system of claim 12 , wherein the operations of the recovery manager further comprise:

receiving a request for information about a first backup operation managed by the storage manager; and

based on determining that the second management database comprises the information about the first backup operation, responding to the request.

18. The system of claim 12 , wherein the operations of the recovery manager further comprise: receiving administrative inputs; and

based on determining that the administrative inputs would enable the recovery manager to manage backup operations of primary data generated by the first plurality of client computing devices, rejecting the administrative inputs.

19. The system of claim 12 , wherein the operations of the recovery manager further comprise: receiving administrative inputs from an administrator who is authorized to administer preferences for backup operations at the storage manager; and

rejecting at least one administrative input that would enable the recovery manager to manage backup operations of primary data generated by the first plurality of client computing devices.

20. The system of claim 12 , wherein the operations of the recovery manager further comprise: receiving administrative inputs from an administrator who is authorized to register clients at the storage manager, and

rejecting at least one administrative input that would enable the recovery manager to register any of the first plurality of client computing devices as a client of the recovery manager.

Assignments (2)
SUPPLEMENTAL CONFIRMATORY GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Apr 16, 2025
From: COMMVAULT SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 070864/0344 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2023
From: KUMAR, ABHINAW; KRIPALANI, SANIAY HARAKHCHAND; DHORAGE, SACHIN DATTATRAYA; MOHANTY, SATYA NARAYAN
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 065727/0379 →
Continuity (2)
Provisional Application 63596636 · Nov 7, 2023
Related Publication 20250147925A1 · May 8, 2025
References Cited (44)
US 7035880B1 · Crescenti et al. · 2006 [cited by applicant]
US 7107298B2 · Prahlad et al. · 2006 [cited by applicant]
US 7246207B2 · Kottomtharayil et al. · 2007 [cited by applicant]
US 7315923B2 · Retnamma et al. · 2008 [cited by applicant]
US 7343453B2 · Prahlad et al. · 2008 [cited by applicant]
US 7395282B1 · Crescenti et al. · 2008 [cited by applicant]
US 7529782B2 · Prahlad et al. · 2009 [cited by applicant]
US 7617262B2 · Prahlad et al. · 2009 [cited by applicant]
US 7734669B2 · Kottomtharayil et al. · 2010 [cited by applicant]
US 7747579B2 · Prahlad et al. · 2010 [cited by applicant]
US 8156086B2 · Lu et al. · 2012 [cited by applicant]
US 8170995B2 · Prahlad et al. · 2012 [cited by applicant]
US 8230195B2 · Amarendran et al. · 2012 [cited by applicant]
US 8285681B2 · Prahlad et al. · 2012 [cited by applicant]
US 8307177B2 · Prahlad et al. · 2012 [cited by applicant]
US 8364652B2 · Vijayan et al. · 2013 [cited by applicant]
US 8578120B2 · Attarde et al. · 2013 [cited by applicant]
US 8954446B2 · Vijayan Retnamma et al. · 2015 [cited by applicant]
US 9020900B2 · Vijayan Retnamma et al. · 2015 [cited by applicant]
US 9098495B2 · Gokhale · 2015 [cited by applicant]
US 9239687B2 · Vijayan et al. · 2016 [cited by applicant]
US 9444811B2 · Nara et al. · 2016 [cited by applicant]
US 9633033B2 · Vijayan et al. · 2017 [cited by applicant]
US 10228962B2 · Dornemann et al. · 2019 [cited by applicant]
US 10255143B2 · Vijayan et al. · 2019 [cited by applicant]
US 10592145B2 · Bedadala et al. · 2020 [cited by applicant]
US 10684924B2 · Kilaru et al. · 2020 [cited by applicant]
US 10878084B1 · Voss · 2020 [cited by examiner]
US 11341230B1 · Ponnuswamy · 2022 [cited by examiner]
US 11966362B1 · Katuri · 2024 [cited by examiner]
US 11977455B1 · Ehrlich · 2024 [cited by examiner]
US 20060224846A1 · Amarendran et al. · 2006 [cited by applicant]
US 20160350391A1 · Vijayan et al. · 2016 [cited by applicant]
US 20170235647A1 · Kilaru et al. · 2017 [cited by applicant]
US 20190108341A1 · Bedhapudi et al. · 2019 [cited by applicant]
US 20210286684A1 · Nara · 2021 [cited by applicant]
US 20220012134A1 · Chatterjee et al. · 2022 [cited by applicant]
US 20230032714A1 · Pandit · 2023 [cited by examiner]
US 20240272989A1 · Sharma · 2024 [cited by examiner]
Google Cloud Regions and Zones, accessed on https://cloud.google.com/compute/docs/regions-zones/, Apr. 26, 2019, available on https://web.archive.org/web/20190415102759/cloud.google.com/compute/docs/regions-zones/, Dec.… [cited by applicant]
Margaret Rouse, “Definition of Availability Zones”, TechTarget, accessed on searchaws.techtarget.com/definition/availability-zones, Apr. 26, 2019, available on https://web.archive.org/web/20180911194556/https://searchaw… [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing, National Institute of Standards and Technology”, U.S. Department of Commerce. Special publication 800-145, accessed on https://nvlpubs.nist.gov/nistpubs/legacy/sp/ni… [cited by applicant]
Wikipedia, Cloud Computing, en.wikipedia.org/wiki/Cloud_computing, accessed on Apr. 26, 2019, 13 Pages. [cited by applicant]
Watts et al. “SaaS vs PaaS vs IaaS: What's The Difference & How to Choose”, BMC Blogs, BMC Software, Inc., accessed on https://www.bmc.com/blogs/saas-vs-paas-vs-iaas-whats-the-difference-and-how-to-choose/, Jun. 15, 201… [cited by applicant]