Distributed storage and controllable sharing system based on signaling network threat stream data
By adopting distributed storage and smart contract management technologies in the threat flow data sharing system of the signaling network, the security and trust problems in the threat flow data sharing of the signaling network are solved, and the controllable, secure and efficient sharing of signaling data is achieved.
Patent Information
- Application Number
- CN202510165442.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art has security and trust issues in the sharing of threat stream data of signaling networks, especially potential vulnerabilities in identity authentication and malicious member management.
The distributed storage and controllable sharing system is adopted, and the controllable, safe and efficient sharing of signaling data is achieved through the data sharing module, the shared channel management module, the data management module, the identity management module, the alliance chain management module and the user management module. Specific measures include using hidden channels for identity authentication, using smart contracts to manage shared member rights, and ensuring the security and reliability of data through alliance chains and distributed ledger technology.
It realizes the secure, reliable and efficient sharing of threat flow data of the signaling network, enhances the security and trust of the system, and prevents malicious attacks and data leakage.
Smart Images

Figure CN120074831A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of mobile communication network data management systems, and specifically to a system capable of controllable, secure, and efficient sharing of signaling network threat flow data. The present invention also provides a usage method for this system. Background Art
[0002] With the booming development of China's informatization construction, the security of mobile communication networks has become increasingly important. The mobile communication network is the cornerstone of informatization, and in the mobile communication network, the signaling network is the control hub. The sharing and utilization of signaling network threat flow data between communication agencies contribute to enhancing the signaling network threat protection ability and improving the overall communication service level. However, due to the sensitivity of signaling data, how to share it in a controllable, secure, and efficient manner is an urgent problem to be solved currently.
[0003] After retrieval, Patent CN115378654A describes a network threat data desensitization sharing system, whose core is to solve the problem of the inability to protect the privacy of information providers in existing data sharing systems through identity authentication, data desensitization, and blockchain technology. The system includes modules such as shared member review, identity authentication, sensitive information security desensitization, and blockchain storage. Although this invention has made progress in data sharing and privacy protection, it still has some potential technical problems and deficiencies, which are overcome by the present invention.
[0004] In this patent, the identity authentication module sends identity credentials through a covert channel for authentication. This has some potential security problems. Especially when there may be vulnerabilities in the covert channel itself or malicious attackers can simulate identity credentials, it may lead to incomplete security of identity authentication. The present invention uses means such as zero-knowledge proof to ensure that the identity authentication process is more secure and reliable, preventing malicious attacks and identity forgery. To ensure that sensitive information can still be effectively used after desensitization and can be restored to the original data when necessary, thus providing more flexible application scenarios.
[0005] Despite the review and identity authentication process for shared members, if there are multiple members in the system, how to ensure trust among members and avoid data pollution introduced by malicious members is still a potential risk. This patent does not elaborate on how to prevent malicious members from forging or tampering with shared data. The present invention uses smart contracts to manage the permissions and access control of shared members, which can ensure that only verified members can read or upload data. At the same time, smart contracts can also automatically execute behavior monitoring of members to further guarantee the security of the system. Summary of the Invention
[0006] The present invention aims to solve the problems of the above-mentioned prior art. A distributed storage and controllable sharing system based on signaling network threat flow data is proposed. The technical solution of the present invention is as follows:
[0007] A distributed storage and controllable sharing system based on signaling network threat flow data, which includes a data sharing module, a shared channel management module, a data management module, an identity management module, a consortium blockchain management module, and a user management module. Among them, the data sharing module is used for signaling data sharing; the shared channel management module uses distributed ledger technology, dynamic configuration and permission management, real-time monitoring and intelligent contract management to achieve controllable sharing of signaling data; the data management module uses metadata management, fine-grained permission control, real-time monitoring and management, and audit log management methods to achieve efficient data management and secure sharing; the identity management module uses identity authentication and auditing, multi-factor authentication, identity information dynamic update encryption and privacy protection methods to protect user privacy information, verify user identity information, and ensure secure access; the consortium blockchain management module uses distributed ledger management, role and permission management, node registration and monitoring, and intelligent contract life cycle management methods to achieve system management; the user management module is used to maintain the basic information of users.
[0008] Further, the data sharing module includes a data upload module, a data download module, a data retrieval module, and an integrity verification module. Among them,
[0009] The data upload module is used to provide a data upload function, allowing users with sharing qualifications to upload local data to the system;
[0010] The data download module is used to allow legitimate users to download shared data from the system, provide download interfaces and interfaces, ensure data security and integrity, generate a log after successful download, and record the downloader ID and time;
[0011] The data retrieval module is used to support data retrieval by ID or keyword, generate an access log after successful access, and record the visitor ID and time;
[0012] The integrity verification module is used to provide a data integrity verification function to ensure that the data has not been tampered with during the upload, download, and storage processes.
[0013] Further, the shared channel management module includes a create channel module, a channel management module, a channel configuration information viewing module, a channel data viewing module, and a channel intelligent contract management module; among them,
[0014] The create channel module is used for users to create multiple independent data channels;
[0015] The channel management module is used for users to dynamically adjust the sharing scope and configuration information of channels, and flexibly modify members and consensus rules;
[0016] The channel configuration information viewing module is used to view the consensus algorithm, participating nodes, and block production policy configuration information of channels in real time, and comprehensively manage the operating status of channels;
[0017] The channel shared data viewing module is used to view the block data and transaction records in the channel to understand the data sharing situation;
[0018] The smart contract management module is used for the deployment, upgrade, and management of smart contracts to ensure the consistency and effectiveness of smart contracts within the channel, customize smart contracts, and implement personalized business logics.
[0019] Furthermore, the data management module includes a basic information management module, an access policy management module, a sharing status management module, and an access log module. Among them,
[0020] The basic information management module is used to maintain the metadata of data, including name, type, keywords, and description, to ensure data integrity and traceability;
[0021] The access policy management module is used to support the customization of data access policies, allowing users to precisely control data access permissions to ensure data security and compliance;
[0022] The sharing status management module is used for users to view and adjust the sharing status of data in real time, monitor the scope and objects of data sharing, and ensure the effectiveness and security of sharing;
[0023] The access log module is used to record detailed logs of all data access activities, helping users audit and analyze data usage, detect abnormal activities, and enhance data protection.
[0024] Furthermore, the identity management module includes an identity registration module, an identity authentication module, an identity update module, and an identity information management module. Among them,
[0025] The identity registration module is used for users to submit real and legal identity materials for registration. After review, the system generates an identity certificate for users, which is used for identity authentication without revealing privacy;
[0026] The identity authentication module is used to authenticate the registered identity certificate. The system confirms the user's identity to ensure that only authorized users can perform operations;
[0027] The identity update module is used to update identity information. Users submit new identity materials, and after passing the review, the system updates the identity certificate and user information;
[0028] The identity information management module is used to manage the identity materials of users for system security, preventing information leakage and unauthorized access.
[0029] Further, the consortium blockchain management module includes a public channel management module, an organization management module, a node management module, and a smart contract management module; among them,
[0030] The public channel management module is used for administrators to create and adjust public channels, define participating organizations, consensus algorithms, and block production strategies to record and share information about organizations and data sharing channels;
[0031] The organization management module is used for administrators to add, delete, or update the organization information participating in the consortium blockchain, and assign roles and permissions to ensure the legal participation and effective cooperation of organizations;
[0032] The node management module is used to manage the nodes in the consortium blockchain, including node registration, configuration, and monitoring to maintain the high availability and reliability of the chain;
[0033] The smart contract management module is used to deploy and manage smart contracts in public channels, including contract installation, instantiation, and version control to ensure the automation of business logic and the controllability of data sharing.
[0034] Further, the user management module includes a registration and login module, a role management module, an organization management module, and an information management module, among which,
[0035] The registration and login module is used for users to create accounts to access the sharing platform, but the registered accounts only provide basic access permissions and do not include the permissions to upload or download data;
[0036] The role management module is used for the system to distinguish between two roles: ordinary users and administrators. Ordinary users can upload and download data, while administrators manage user permissions and system data access;
[0037] The organization management module is used to support multi-level organizational structures, such as network operators, government agencies, etc. Organization administrators are responsible for member management, including permission and role adjustment;
[0038] The information management module is used for users to securely modify personal information, such as user names and passwords, on the system page.
[0039] Further, the system architecture is developed using a front-end and back-end separation framework. The front-end uses the Vue.js framework to build the interface framework and combines the ElementUI and Echarts frameworks for interface design and implementation. The back-end is mainly implemented based on the Java language and developed using the Springboot framework.
[0040] The advantages and beneficial effects of the present invention are as follows:
[0041] 1. Security: The security of the software system proposed by the present invention is reflected in two aspects. For signaling data, the security is reflected in that the data can be stably stored in the system and will not be tampered with or stolen due to malicious attack behaviors. For data sharers, the security is reflected in protecting the privacy of the sharers and their organizations, while strictly controlling data access permissions. Only authorized users and system components can access the shared data, preventing the abuse or leakage of data.
[0042] 2. Reliability: The software system proposed by the present invention ensures that the failure of a small number of nodes in the blockchain network and the storage cluster will not affect the entire system. The system can normally complete the secure sharing of signaling data, and can timely repair the faulty nodes and ensure their synchronization status with normal nodes.
[0043] 3. Efficiency: The software system proposed by the present invention introduces the distributed storage system IPFS to implement a distributed data storage model for indexing off-chain data, improving the data access efficiency.
[0044] 4. Maintainability: The software system proposed by the present invention is developed using the front-end and back-end separation method. In terms of later maintenance and requirement expansion, this architecture is more friendly to developers and is easier to add or modify functions.
[0045] The innovative modules of the present invention are mainly reflected in the following aspects:
[0046] 1. Shared member review module:
[0047] This module reviews multiple users who apply to join the sharing center to ensure that only eligible members can participate in data sharing. Through this process, the qualifications of shared members can be effectively managed, preventing unqualified members from abusing or leaking data.
[0048] 2. Shared member identity authentication module:
[0049] This module uses a covert channel to send identity credentials and perform identity authentication. By processing identity credentials in this covert channel manner, the risk of leakage during the identity authentication process is avoided, ensuring that the authentication process is more secure and private. Description of the Drawings
[0050] Figure 1 is the overall functional structure diagram of the system of the preferred embodiment provided by the present invention;
[0051] Figure 2 is the system architecture diagram of the present invention;
[0052] Figure 3It is the data upload timing diagram of the present invention;
[0053] Figure 4 It is the data download timing diagram of the present invention;
[0054] Figure 5 It is the identity authentication model timing diagram of the present invention;
[0055] Figure 6 It is the ER diagram of shared data operation of the present invention;
[0056] Figure 7 It is the diagram of the shared data display page of the present invention;
[0057] Figure 8 It is the diagram of the data upload page of the present invention;
[0058] Figure 9 It is the diagram of the channel management page of the present invention;
[0059] Figure 10 It is the shared channel block diagram of the present invention;
[0060] Figure 11 It is the diagram of the shared data element information management of the present invention;
[0061] Figure 12 It is the diagram of the authentication request processing of the present invention;
[0062] Figure 13 It is the diagram of the consortium chain management page of the present invention;
[0063] Figure 14 It is the diagram of the consortium chain transaction throughput test of the present invention. Specific implementation manners
[0064] Next, the technical solutions in the embodiments of the present invention will be clearly and detailedly described in conjunction with the accompanying drawings in the embodiments of the present invention. The described embodiments are only a part of the embodiments of the present invention.
[0065] The technical solution for the present invention to solve the above technical problems is:
[0066] Embodiment 1
[0067] This embodiment provides a distributed storage and controllable sharing system based on signaling network threat flow data. This system is based on the B / S architecture and includes a browser and a server. The server part includes an application server and a database server. This system runs under the Windows 11 operating system and uses IDEA as the development tool. The backend is developed using Java 11 (using the Spring Boot framework), C++, and Go languages, and the frontend uses the JavaScript language and the Vue.js framework. The database server uses MySQL 8.0. The system integrates Hyperledger Fabric 2.2 as the consortium chain technology, IPFS 0.4.6 as the storage system, and Docker 20.10.8 as the containerization technology. The system realizes user login and access through the HTTPS and RPC protocols, effectively managing the distributed storage and controllable sharing system based on signaling network threat flow data.
[0068] As Figure 2 shown, in the architecture of the distributed storage and controllable sharing system for signaling network threat flow data, the presentation layer implements a user-friendly operation interface through the Vue.js, ElementUI, and Echarts frameworks, supporting functions such as data sharing, channel management, data management, identity management, consortium chain management, and user management. The interaction layer uses the HTTPS and RPC protocols to achieve front-end and back-end communication. The service layer is the core of the system, developed using Spring Boot and the Java language, interacting with the Hyperledger Fabric consortium chain through the Go language, Shell scripts, Docker, and Fabric-sdk-java, supporting channel management, block parsing, and chain code deployment. This layer also integrates IPFS for data storage, implementing identity management based on zero-knowledge proofs, access control based on attribute-based encryption, and data retrieval algorithms based on searchable encryption. User management is based on the RBAC model, with permission control combined with the characteristics of the consortium chain. The infrastructure layer includes IPFS, Hyperledger Fabric, MySQL, and Redis, where IPFS stores encrypted data, the consortium chain stores encrypted data indexes and authentication materials, MySQL manages user accounts and log information, and Redis improves data access speed. The system also includes an additional monitoring module that records service operations and smart contract executions in the form of logs to assist users in system analysis and decision-making.
[0069] The following is a detailed explanation of some of the above arrangements:
[0070] 1) Spring Boot background technology framework
[0071] Spring Boot is a new framework provided by the Pivotal team, designed to simplify the initial setup and development process of new Spring applications. The framework uses a specific way of configuration, so that developers no longer need to define boilerplate configurations. In this way, Spring Boot aims to become a leader in the booming field of rapid application development.
[0072] 2) Vue front-end technology framework
[0073] Vue is a progressive framework for building data-driven web interfaces. The goal of Vue.js is to achieve reactive data binding and composable view components through the simplest possible API. It is not only easy to get started with, but also convenient to integrate with third-party libraries or existing projects. On the other hand, when used in combination with single-file components and libraries supported by the Vue ecosystem, Vue is also fully capable of powering complex single-page applications.
[0074] 3) Docker
[0075] Docker is an open-source containerization platform that allows developers to package an application and its dependencies into lightweight, portable containers, and then run them on any machine that supports Docker. This containerization technology helps simplify configuration, ensure application consistency across different environments, and improve resource utilization. Docker containers run on a shared operating system and are more efficient than traditional virtual machines. It supports automated deployment, and through Docker Hub and other registries, it is convenient to share and manage container images.
[0076] 4) Hyperledger Fabric blockchain platform
[0077] Hyperledger Fabric is an open-source enterprise-level blockchain platform designed for enterprise applications, supporting a modular and scalable architecture. It allows components such as consensus and membership services to be customized as needed, supports private transactions and confidential contracts, thus protecting the privacy of transaction data. The unique feature of Fabric is its channel function, which allows a subset of participants in a blockchain network to interact privately, achieving data isolation and confidentiality. In addition, it does not rely on cryptocurrency mining and is a permissioned network, suitable for use in industries such as finance, supply chain, and others that require high levels of auditing and performance.
[0078] 5) RBAC (Role-Based Access Control)
[0079] RBAC (Role-Based Access Control) is a widely used access control mechanism that assigns access permissions to system resources based on the roles of users. In this model, permissions are not directly assigned to individual users but to roles, and then users obtain these permissions by being assigned to these roles. This approach simplifies permission management because roles can be defined according to the responsibilities and positions of the organization. Managers only need to manage roles and the assignment of users to roles, rather than each individual user's permissions, which greatly improves management efficiency and reduces the risk of misconfiguration. RBAC is particularly suitable for environments with complex permission requirements and a large number of users.
[0080] The advantages of the distributed storage and controllable sharing system architecture based on signaling network threat flow data are summarized as follows:
[0081] 1) The performance of the system platform is improved. Based on the SpringBoot and Vue frameworks, both of which have the characteristics of openness and stability, it can accelerate the development and expansion of the system, and has the advantages of simple and convenient maintenance and upgrade, low cost, data security, real-time synchronization, etc.;
[0082] 2) Easy maintainability: The software system proposed in the present invention is developed using the method of separating the front and back ends. In terms of later maintenance and requirement expansion, this architecture is more friendly to developers, and it is very easy to add or modify functions;
[0083] 3) The HTTPS and RPC protocols are adopted to ensure the security and efficiency of front-end and back-end communication, and to guarantee the integrity and confidentiality of data during transmission;
[0084] 4) Interact with Hyperledger Fabric through Fabric-sdk-java, support multi-channel technology, block parsing and chain code deployment, and realize the trusted sharing and management of data;
[0085] 5) Implement identity management based on zero-knowledge proof, access control based on attribute-based encryption, and data retrieval algorithms based on searchable encryption, enhancing the security of the system and data privacy protection;
[0086] 6) Use IPFS for distributed storage to ensure the high availability and reliability of data, and at the same time reduce the risk of single-point failure caused by centralized storage;
[0087] 7) Use Docker for containerized deployment to ensure the consistency of applications in different environments, and improve the portability and resource utilization rate of the system;
[0088] 8) Through the role-based access control model, combined with zero-knowledge proof and the characteristics of the consortium blockchain, fine-grained permission control is achieved, ensuring the security and compliance of the system;
[0089] The functions of the distributed storage and controllable sharing system based on signaling network threat flow data are generally described as follows:
[0090] As Figure 1 shown, the distributed storage and controllable sharing system based on signaling network threat flow data includes: a data sharing module, a shared channel management module, a data management module, an identity management module, a consortium blockchain management module, and a user management module. Among them, the data sharing module is used for signaling data sharing, including a data upload module, a data retrieval module, and an integrity verification module; the shared channel management module is used for controllable sharing of signaling data, including a channel creation module, a channel management module, a channel configuration information viewing module, a channel data viewing module, and a channel smart contract management module; the data management module is used for efficient data management and secure sharing, including a basic information management module, an access policy management module, a sharing status management module, and an access log module; the identity management module is used to protect user privacy information, verify user identity information, and ensure secure access, including an identity registration module, an identity verification module, an identity update module, and an identity information management module; the consortium blockchain management module is used for system management, including a public channel management module, an organization management module, a node management module, and a smart contract management module; the user management module is used to maintain the basic information of users, including a registration and login module, a role management module, an organization management module, and an information management module.
[0091] 1. Data Sharing Module
[0092] 1) Data Upload Module: Provides a data upload function that allows users with sharing qualifications to upload local data to the system. The system supports various file formats and sizes, provides an upload interface and real-time upload progress feedback. The encrypted transmission of data during the upload process ensures security.
[0093] 2) Data Download Module: Allows legitimate users to download shared data from the system, provides a download interface and interface, and ensures data security and integrity. A log is generated after successful download, recording the downloader ID and time.
[0094] 3) Data Retrieval Module: Supports data retrieval by ID or keyword. An access log is generated after successful access, recording the visitor ID and time.
[0095] 4) Integrity Verification Module: Provides a data integrity verification function to ensure that the data has not been tampered with during upload, download, and storage.
[0096] 2. Shared Channel Management Module
[0097] 1) Create channel module: Users can create multiple independent data channels to meet different data sharing and access requirements, ensuring data security and privacy.
[0098] 2) Channel management module: Users can dynamically adjust the sharing scope and configuration information of channels, flexibly modify members and consensus rules to adapt to changes in business requirements.
[0099] 3) Channel configuration information viewing module: The system provides a visual interface where users can view configuration information such as the consensus algorithm, participating nodes, and block production strategy of channels in real time, comprehensively managing the operating status of channels.
[0100] 4) Channel shared data viewing module: Each channel is an independent blockchain, and users can view block data and transaction records in the channel to understand the data sharing situation.
[0101] 5) Smart contract management module: The system supports the deployment, upgrade, and management of smart contracts, ensuring the consistency and effectiveness of smart contracts within channels. Users can customize smart contracts to implement personalized business logic.
[0102] 3. Data management module
[0103] 1) Basic information management module: Users can maintain the metadata of data, such as name, type, keywords, and description, ensuring data integrity and traceability.
[0104] 2) Access policy management module: Supports customizing data access policies, allowing users to precisely control data access permissions to ensure data security and compliance.
[0105] 3) Sharing status management module: Users can view and adjust the sharing status of data in real time, monitor the scope and objects of data sharing, ensuring the effectiveness and security of sharing.
[0106] 4) Access log module: The system records detailed logs of all data access activities, helping users audit and analyze data usage, detect abnormal activities, and enhance data protection.
[0107] 4. Identity management module
[0108] 1) Identity registration module: Users need to submit real and legal identity materials for registration. After verification, the system generates an identity certificate for users for identity verification without revealing privacy.
[0109] 2) Identity verification module: Users verify their identities through the registered identity certificate, and the system confirms the user's identity to ensure that only authorized users can perform operations.
[0110] 3) Identity Update Module: Allows users to update their identity information. Users submit new identity materials, and after passing the review, the system updates the identity certificate and user information.
[0111] 4) Identity Information Management Module: The system securely manages users' identity materials to prevent information leakage and unauthorized access.
[0112] 5. Consortium Blockchain Management Module
[0113] 1) Public Channel Management Module: Administrators can create and adjust public channels, define participating organizations, consensus algorithms, and block production strategies to record and share information about organizations and data sharing channels.
[0114] 2) Organization Management Module: Allows administrators to add, delete, or update the information of organizations participating in the consortium blockchain, and assign roles and permissions to ensure the legal participation and effective cooperation of organizations.
[0115] 3) Node Management Module: Manages the nodes in the consortium blockchain, including node registration, configuration, and monitoring, to maintain the high availability and reliability of the chain.
[0116] 4) Smart Contract Management Module: Deploys and manages smart contracts in public channels, including contract installation, instantiation, and version control, to ensure the automation of business logic and the controllability of data sharing.
[0117] 6. User Management Module
[0118] 1) Registration and Login Module: Users can create accounts to access the sharing platform, but the registered accounts only provide basic access permissions and do not include the permissions to upload or download data.
[0119] 2) Role Management Module: The system differentiates between two roles: ordinary users and administrators. Ordinary users can upload and download data, while administrators manage user permissions and system data access.
[0120] 3) Organization Management Module: Supports multi-level organizational structures, such as network operators, government agencies, etc. Organization administrators are responsible for member management, including permission and role adjustment.
[0121] 4) Information Management Module: Users can securely modify their personal information, such as user names and passwords, on the system page.
[0122] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions.
[0123] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising said element.
[0124] The above embodiments should be understood as being only for illustrative purposes of the present invention and not for limiting the scope of protection of the present invention. After reading the content described in the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.
Claims
1. A distributed storage and controllable sharing system for threat flow data based on a signaling network, characterized in that: It includes a data sharing module, a shared channel management module, a data management module, an identity management module, an alliance chain management module and a user management module, wherein the data sharing module is used for signaling data sharing; the shared channel management module adopts distributed ledger technology, dynamic configuration and authority management, real-time monitoring and smart contract management to realize controllable sharing of signaling data; the data management module adopts metadata management, fine-grained authority control, real-time monitoring and management, and audit log management methods to realize efficient data management and secure sharing; the identity management module adopts identity authentication and auditing, multiple identity authentication, dynamic update encryption and privacy protection methods of identity information to protect user privacy information, verify user identity information, and ensure secure access; the alliance chain management module adopts distributed ledger management, role and authority management, node registration and monitoring, and smart contract lifecycle management methods to realize system management; the user management module is used to maintain basic user information.
2. According to claim 1, a distributed storage and controllable sharing system based on signaling network threat flow data is characterized in that: The data sharing module includes a data upload module, a data download module, a data retrieval module and an integrity check module, wherein: The data upload module is used to provide a data upload function, allowing users with sharing qualifications to upload local data to the system; The data download module is used to allow legitimate users to download shared data from the system, provide a download interface and screen, ensure data security and integrity, and generate a log after a successful download to record the downloader ID and time; The data retrieval module is used to support data retrieval by ID or keyword, and generate access logs after successful access, recording the visitor ID and time; The integrity check module is used to provide a data integrity check function to ensure that the data has not been tampered with during the upload, download and storage process.
3. According to claim 1, a distributed storage and controllable sharing system based on signaling network threat flow data is characterized in that: The shared channel management module includes a channel creation module, a channel management module, a channel configuration information viewing module, a channel data viewing module and a channel smart contract management module; wherein, The channel creation module is used for the user to create multiple independent data channels; The channel management module is used by users to dynamically adjust the sharing scope and configuration information of the channel, and flexibly modify members and consensus rules; The channel configuration information viewing module is used to view the channel's consensus algorithm, participating nodes, and block generation strategy configuration information in real time, and comprehensively manage the channel's operating status; The channel shared data viewing module is used to view the block data and transaction records in the channel to understand the data sharing situation; The smart contract management module is used for the deployment, upgrading and management of smart contracts, ensuring the consistency and validity of smart contracts within the channel, customizing smart contracts and implementing personalized business logic.
4. According to claim 1, a distributed storage and controllable sharing system based on signaling network threat flow data is characterized in that: The data management module includes a basic information management module, an access policy management module, a shared status management module and an access log module, wherein: The basic information management module is used to maintain the metadata of the data, including name, type, keywords and description, to ensure data integrity and traceability; The access policy management module is used to support custom data access policies, allowing users to accurately control data access rights to ensure data security and compliance; The sharing status management module is used for users to view and adjust the sharing status of data in real time, monitor the scope and objects of data sharing, and ensure the effectiveness and security of sharing; The access log module is used to record detailed logs of all data access activities, helping users audit and analyze data usage, detect abnormal activities, and enhance data protection.
5. According to claim 1, a distributed storage and controllable sharing system based on signaling network threat flow data is characterized in that: The identity management module includes an identity registration module, an identity authentication module, an identity update module, and an identity information management module; wherein, The identity registration module is used for users to submit real and legal identity materials for registration. After review, the system generates an identity certificate for the user, which is used for identity verification without leaking privacy; The identity verification module is used to verify the identity of the registered identity certificate, and the system confirms the user's identity to ensure that only authorized users can perform operations; The identity update module is used to update identity information. The user submits new identity materials, and the system updates the identity certificate and user information after review; The identity information management module is used to manage the user's identity information in a system-safe manner to prevent information leakage and unauthorized access.
6. The distributed storage and controllable sharing system based on signaling network threat flow data according to claim 1 is characterized in that: The alliance chain management module includes a public channel management module, an organization management module, a node management module and a smart contract management module; wherein, The public channel management module is used by administrators to create and adjust public channels, define participating organizations, consensus algorithms, and block generation strategies, and record and share information about organizations and data sharing channels; The organization management module is used by administrators to add, delete or update the organization information participating in the alliance chain, and assign roles and permissions to ensure the legal participation and effective collaboration of the organization; The node management module is used to manage the nodes in the alliance chain, including node registration, configuration and monitoring, to maintain the high availability and reliability of the chain; The smart contract management module is used to deploy and manage smart contracts in public channels, including contract installation, instantiation and version control, to ensure the automation of business logic and controllability of data sharing.
7. The distributed storage and controllable sharing system based on signaling network threat flow data according to claim 1 is characterized in that: The user management module includes a registration and login module, a role management module, an organization management module and an information management module, wherein: The registration and login module is used by users to create accounts to access the sharing platform, but the registered account only provides basic access rights, not including the right to upload or download data; The role management module is used to distinguish between two roles in the system: ordinary users and administrators. Ordinary users can upload and download data, while administrators manage user permissions and system data access; The organization management module is used to support multi-level organizational structures, such as network operators, government agencies, etc. The organization administrator is responsible for member management, including authority and role adjustment; The information management module is used for users to safely modify personal information, such as user name and password, on the system page.
8. The distributed storage and controllable sharing system based on signaling network threat flow data according to claim 1 is characterized in that: The system architecture is developed using a front-end and back-end separation framework. The front-end uses the Vue.js framework to build the interface framework, and combines the ElementUI and Echarts frameworks for interface design and implementation. The back-end is mainly implemented based on the Java language and developed using the Springboot framework.