Point-to-point content distribution system for scientific data center
By building a layered and modular point-to-point content distribution system, embed access authorization proof documents for permission verification, the security and efficiency of traditional PCDN in scientific data centers are solved, and the secure and efficient distribution of scientific data is achieved.
Patent Information
- Application Number
- CN202510720925.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-18
AI Technical Summary
In the application of scientific data centers, traditional point-to-point content distribution network (PCDN) lacks the ability to manage and control multiple dimensions such as user identity, organizational attributes and usage purposes, and cannot meet the security needs of scientific data centers.
Build a point-to-point content distribution system for scientific data centers, through the layered modular structure of the user terminal layer, gateway adaptation layer and data source layer, combined with the point-to-point content distribution network layer, the deep integration of permission control and content distribution mechanism is realized, and access authorization proof documents are embedded for permission verification to ensure the security and efficiency of data transmission.
While maintaining distributed transmission efficiency, we ensure the security and efficient circulation of scientific data, follow the data usage rules of the scientific data center, and achieve the safe and efficient distribution of scientific data.
Smart Images

Figure CN120342767A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of scientific data sharing, and particularly to a peer-to-peer content distribution system for scientific data centers. Background Art
[0002] With the rapid growth of the scale of scientific data, traditional centralized distribution models face problems such as high cross-regional transmission delays and soaring bandwidth costs. The peer-to-peer content delivery network (PCDN) coordinates the storage and bandwidth resources of edge nodes to build a decentralized distribution service, which can effectively reduce the load on the central server and improve resource utilization, especially suitable for high-concurrency and large-bandwidth content transmission scenarios.
[0003] However, scientific data involves sensitive information such as national security and business secrets, and strict hierarchical and classified access control needs to be followed. Traditional PCDNs are mainly oriented to the distribution of public content, and their security mechanisms only support basic data verification, lacking the refined permission control capabilities in multiple dimensions such as user identity, institutional attributes, and usage purposes, and cannot meet the security requirements of scientific data centers. Therefore, how to achieve the secure and efficient distribution of scientific data under the PCDN architecture has become a technical problem that needs to be solved urgently. Summary of the Invention
[0004] In view of the above problems, embodiments of this application provide a peer-to-peer content distribution system for scientific data centers to overcome or at least partially solve the above problems.
[0005] Embodiments of this application disclose a peer-to-peer content distribution system for scientific data centers, and the system includes: A user terminal layer, including multiple user terminals. The user terminal sends a request for an access authorization certificate file to the gateway adaptation layer according to the user's data access request, and in the case of obtaining the access authorization certificate file and the seed file, sends a data acquisition request carrying the access authorization certificate file to the peer-to-peer content distribution network layer according to the seed file. The seed file contains information about the seed node storing the target data; A gateway adaptation layer, configured to obtain an access control rule from the data source layer in response to the request for the access authorization certificate file, and generate an access authorization certificate file and a seed file according to the access control rule. The access authorization certificate file is used to represent the access permission of the authorized user to the target data; A data source layer, including multiple scientific data centers, where the scientific data center is used to provide the access control rule to the gateway adaptation layer; The peer-to-peer content distribution network layer includes multiple seed nodes. The seed nodes perform permission verification based on the access authorization proof file in the data acquisition request, and when the permission verification is passed, send the shards of the target data accessed by the user to the user terminal. The seed nodes represent scientific data centers and / or other user terminals storing the target data.
[0006] Optionally, the gateway adaptation layer includes a proof generation and distribution module; The proof generation and distribution module is used to receive the access authorization proof file request, send a permission query request to the data source layer according to the access authorization proof file request, obtain the access control rules fed back by the data source layer; and generate an access authorization proof file according to the access control rules, and send the access authorization proof file to the user terminal.
[0007] Optionally, the gateway adaptation layer further includes a tracking service module and a seed generation and distribution module; The tracking service module is used to record the online status and cached data of each node, and the nodes include the multiple user terminals and the multiple scientific data centers; The seed generation and distribution module is used to generate a seed file according to the access control rules, as well as the online status and cached data of each node, and send the seed file to the user terminal.
[0008] Optionally, the seed generation and distribution module is used to generate a seed file according to the access control rules, as well as the online status and cached data of each node, and send the seed file to the user terminal, including: The seed generation and distribution module determines whether the target data joins the peer-to-peer content distribution network layer according to the access control rules, as well as the online status and cached data of each node; When the seed generation and distribution module determines that the target data does not join the peer-to-peer content distribution network layer, it caches the target data into the local cache of the neighboring node and generates a seed file to send to the user terminal; When the seed generation and distribution module determines that the target data joins the peer-to-peer content distribution network layer, it sends the historical seed file to the user terminal.
[0009] Optionally, the user terminal includes a data request module; The data request module is used to receive the user's data access request, generate the access authorization proof file request according to the user identity information and the identification information of the target data accessed in the data access request, and send the access authorization proof file request to the gateway adaptation layer.
[0010] Optionally, the user terminal includes a verification and storage module; The verification and storage module is used to receive the access authorization certificate file and the seed file, and perform permission verification according to the access authorization certificate file; The verification and storage module determines the seed node according to the seed file when the authority verification passes, and sends a point-to-point connection request to each seed node, and sends the data acquisition request to each seed node when a point-to-point connection is established with each seed node; The verification and storage module receives the data shard index table sent by the seed node, and sends a data download request to the seed node according to the data shard index table to obtain the target data shard, wherein the data shard index table represents information about the data shard held by the seed node.
[0011] Optionally, the user terminal includes a seed maintenance module; The seed maintenance module is used to manage the data sharding information stored in itself, maintain the integrity of the data sharding, and participate in the peer-to-peer content distribution network sharing.
[0012] Optionally, the data source layer includes a data management module; The data management module adopts a distributed storage architecture to store scientific data and provides functions for retrieving and reading the scientific data; wherein the scientific data is stored in the data management module in the form of digital objects.
[0013] Optionally, the data source layer includes a rights management module; The authority management module is used to determine access control rules according to users, data classifications and operation permissions, wherein the operation permissions represent data operation types, including read operations and write operations; and provide access control rules to the gateway adaptation layer when receiving the authority query request.
[0014] Optionally, the seed node performs permission verification according to the access authorization certificate file in the data acquisition request, including: The seed node extracts the hash value of the access authorization certificate file, and initiates an online verification request to the gateway adaptation layer to perform online verification on the correctness of the hash value of the access authorization certificate file, the validity of the digital signature of the access authorization certificate file, and the validity of the authorization terms; When the online verification is passed, the seed node sends the data shard index table it holds to the user terminal.
[0015] The embodiments of the present application include the following advantages: In the embodiment of the present application, the point-to-point content distribution system for a scientific data center consists of three physical layers, namely, the user terminal layer, the gateway adaptation layer, and the data source layer, and one logical layer, namely, the point-to-point content distribution network layer. The user terminal layer serves as the entry for users to access data. When a user initiates a data access request, it automatically activates the security verification process, obtains an access authorization certificate file from the gateway adaptation layer, and when performing data transmission, obtains the target data from the point-to-point content distribution network layer according to the access authorization certificate file, making each user terminal become a trusted node and authentication environment in the distributed network, ensuring that unauthorized data requests cannot enter the transmission channel. The gateway adaptation layer generates an access authorization certificate file in real time based on the access control rules of the data source layer to achieve dynamic verification and authorization of user permissions. The data source layer serves as a trusted data storage infrastructure and provides authoritative access control rules for the entire system. The point-to-point content distribution network layer embeds the permission verification of the access authorization certificate file in the point-to-point handshake process, so that the transmission of each target data shard is subject to dynamic permission checks. In this way, through this system, the data stream that freely spreads in the traditional point-to-point content distribution network is transformed into a directional distribution guaranteed by the authorization mechanism, while maintaining the distributed transmission efficiency, ensuring full compliance with the data usage rules of the original scientific data center, and thus realizing the secure and efficient circulation of scientific data under the point-to-point content distribution network architecture. Description of the Drawings
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the description of the embodiments of the present application. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.
[0017] Figure 1 It is a schematic diagram of a point-to-point content distribution system for a scientific data center provided by an embodiment of the present application; Figure 2 It is a schematic diagram of the working process of a point-to-point content distribution system for a scientific data center provided by an embodiment of the present application; Figure 3 It is a structural diagram of the functional modules of a point-to-point content distribution system for a scientific data center provided by an embodiment of the present application. Detailed Embodiments
[0018] To make the above objects, features, and advantages of the present application more obvious and understandable, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.
[0019] In order to achieve the secure distribution and efficient transmission of scientific data, the present application proposes the following technical concept: realizing the deep integration of the permission control and content distribution mechanism through a hierarchical modular structure, constructing a hierarchical architecture system of "three physical layers and one virtual layer", dividing the digital networking infrastructure into three physical layers: the user terminal layer, the gateway adaptation layer, and the data source layer, and one logical layer: the peer-to-peer content distribution network layer, to achieve the deep integration of the permission control mechanism and the content distribution network. While retaining the advantages of the peer-to-peer (P2P) transmission efficiency in this system, the security policy of the scientific data center is implemented throughout the entire data life cycle through access authorization proof files, fundamentally solving the architectural contradiction between the distributed network and the centralized security management.
[0020] Refer to Figure 1 as shown Figure 1 is a schematic diagram of a peer-to-peer content distribution system for a scientific data center provided by an embodiment of the present application. As Figure 1 shown, the peer-to-peer content distribution system for a scientific data center specifically includes: The user terminal layer includes multiple user terminals. The user terminal sends an access authorization proof file request to the gateway adaptation layer according to the user's data access request, and in the case of obtaining the access authorization proof file and the seed file, sends a data acquisition request carrying the access authorization proof file to the peer-to-peer content distribution network layer according to the seed file. The seed file contains information about the seed node storing the target data; The gateway adaptation layer is used to respond to the access authorization proof file request, obtain the access control rules from the data source layer, and generate an access authorization proof file and a seed file according to the access control rules. The access authorization proof file is used to represent the access permission of the authorized user to the target data; The data source layer includes multiple scientific data centers, and the scientific data centers are used to provide access control rules to the gateway adaptation layer; The peer-to-peer content distribution network layer includes multiple seed nodes. The seed nodes perform permission verification according to the access authorization proof file in the data acquisition request, and in the case of passing the permission verification, send the shards of the target data accessed by the user to the user terminal. The seed nodes represent the scientific data centers storing the target data and / or other user terminals.
[0021] In the embodiments of the present application, the user terminal serves as the only entry for users to access data, undertaking the data transceiver function of the traditional network interface, and also having the functions of managing access authorization certificate files and executing access rules. When a user (requestor) initiates a data access request, the user terminal automatically activates the security verification process and sends an access authorization certificate file request to the gateway adaptation layer to obtain an access authorization certificate file and a seed file; wherein, the user terminal communicates with the gateway adaptation layer through a standardized protocol (for example, the enhanced peer-to-peer (P2P) protocol). When data is transmitted, the target data is obtained from the peer-to-peer content distribution network layer according to the access authorization certificate file, making each user terminal a trusted node and authentication environment in the distributed network, ensuring that unauthorized data requests cannot enter the transmission channel. Thus, the system deeply embeds the security verification function into the data transmission process of the user terminal.
[0022] The gateway adaptation layer serves as the security control center of the system and communicates with the data source layer through a standardized protocol (for example, the Digital Object Interface Protocol (DOIP)). After receiving the access authorization certificate file request from the user terminal, the gateway adaptation layer obtains access control rules from each scientific data center in the data source layer, where the access control rules can be understood as the access rights of users to the scientific data in the scientific data centers. In some embodiments, generating an access authorization certificate file according to the access control rules includes: the gateway adaptation layer digitally signs the access control rules to obtain an immutable access authorization certificate file. In some embodiments, generating a seed file according to the access control rules includes: the gateway adaptation layer determines candidate nodes caching the target data (data accessed by users), and selects nodes with access rights for the user from the candidate nodes as seed nodes according to the access control rules, and generates a seed file according to the information of the seed nodes.
[0023] The data source layer includes multiple scientific data centers. The data source layer serves as a trusted data storage infrastructure and provides authoritative access control rules for the entire system. Specifically, the scientific data centers maintain a complete digital object identification system and a fine-grained access control list at this layer, and provide real-time access control rules (permission verification services) to the gateway adaptation layer through a standard interface; moreover, an encrypted channel is established between the data source layer and the gateway adaptation layer to ensure the confidentiality and integrity of the transmission of access control rules, preventing the access control rules from being tampered with or leaked during the transmission process.
[0024] The peer-to-peer content distribution network layer, as the capability aggregation of the first three physical architectures (user terminal layer, gateway adaptation layer, data source layer), constructs a weighted distribution overlay network (i.e., the network distributes data according to access permissions / rules). Specifically, the peer-to-peer content distribution network layer extends the BitTorrent protocol stack and embeds an access authorization proof file verification link in the standard P2P handshake process, so that the transmission of each target data shard is subject to dynamic permission checks. Before providing data services, the seed nodes in the peer-to-peer content distribution network layer must verify the validity of the access authorization proof file of the requester through the gateway adaptation layer. Only when the verification passes, the target data shards accessed by the user are sent to the user terminal.
[0025] Adopting the technical solution of the embodiment of the present application, the system transforms the freely propagated data stream in the traditional peer-to-peer content distribution network into a directional distribution guaranteed by an authorization mechanism. While maintaining the distributed transmission efficiency, it ensures full compliance with the data usage rules of the original scientific data center, thus realizing the safe and efficient circulation of scientific data under the peer-to-peer content distribution network architecture.
[0026] Combined with the above embodiments, in one implementation, the embodiment of the present application also provides a peer-to-peer content distribution system for a scientific data center. In this system, the user terminal includes a data request module; The data request module is used to receive the user's data access request, generate the access authorization proof file request according to the user identity information and the identification information of the target data accessed in the data access request, and send the access authorization proof file request to the gateway adaptation layer.
[0027] In the embodiment of the present application, the access authorization proof file request is generated according to the user identity information and the identification information of the target data accessed, realizing the binding relationship verification between the user identity and the target data, so as to ensure that the request subject has the access qualification.
[0028] Among them, the user identity information associates the user identity with the permission subject. The user identity information adopts a composite structure, integrating the institutional identifier of the scientific data center and the user characteristic value; the identification information of the target data adopts the digital network standard coding specification, including the type prefix and hash suffix of the scientific data digital object (i.e., the target data), ensuring that each target data has a unique traceable identity identifier in the peer-to-peer content distribution network.
[0029] The access authorization proof file request is a request message that conforms to the DOIP standard. When the data request module is used to receive the user's data access request, a request message that conforms to the DOIP standard is constructed according to the user identity information and the identification information of the target data in the data access request.
[0030] By adopting the technical solution implemented in this application, when a user initiates a data access request, the user terminal can automatically activate the security verification process through the data request module, obtain the access authorization certificate document from the gateway adaptation layer, and verify the binding relationship between the user identity and the target data to ensure that the requesting subject is eligible for access.
[0031] The following four parts respectively describe the user terminal layer, gateway adaptation layer, data source layer, and peer-to-peer content distribution network layer in the peer-to-peer content distribution system for scientific data centers.
[0032] (1) User terminal layer: In combination with the above embodiments, in one implementation, the embodiment of the present application further provides a peer-to-peer content distribution system for a scientific data center, in which the user terminal includes a verification and storage module; The verification and storage module is used to receive the access authorization certificate file and the seed file, and perform permission verification according to the access authorization certificate file; The verification and storage module determines the seed node according to the seed file when the authority verification passes, and sends a point-to-point connection request to each seed node, and sends the data acquisition request to each seed node when a point-to-point connection is established with each seed node; The verification and storage module receives the data shard index table sent by the seed node, and sends a data download request to the seed node according to the data shard index table to obtain the target data shard, wherein the data shard index table represents information about the data shard held by the seed node.
[0033] In an embodiment of the present application, the verification and storage module caches the received access authorization certificate file, and before requesting to obtain target data from the peer-to-peer content distribution network layer each time, the verification and storage module performs local pre-verification based on the access authorization certificate file (i.e., it verifies the validity of the access authorization certificate file itself) to ensure that each data access is subject to an authorization check.
[0034] Before data transmission (P2P handshake phase), the user terminal sends a point-to-point connection request (i.e., a P2P connection request) to the seed node indicated in the seed file through the verification and storage module. At this time, the user terminal executes the key access authorization certificate file verification handshake protocol through the verification and storage module. After establishing a connection with each seed node, a data acquisition request (carrying an access authorization certificate file) is sent to each seed node.
[0035] After receiving a data acquisition request, the seed node verifies the access authorization certificate file in the data acquisition request. If the verification is passed, the seed node sends a data shard index table to the user terminal. After passing the verification and receiving the data shard index table through the storage module, the user terminal starts data transmission, sends a data download request to the seed node according to the data shard index table, and obtains the target data shard.
[0036] By adopting the technical solution of the embodiment of the present application, the user terminal executes the peer-to-peer handshake node and the data transmission phase through the verification and storage module, and embeds the access authorization certificate file permission verification into the data acquisition process, so that the transmission of each target data shard is subject to dynamic permission checking.
[0037] Combined with the above embodiments, in one implementation, the embodiment of the present application further provides a peer-to-peer content distribution system for a scientific data center. In this system, the user terminal includes a seed maintenance module. Specifically, the seed maintenance module is used to manage the data shard information stored by itself, maintain the integrity of the data shards, and participate in the peer-to-peer content distribution network sharing.
[0038] In the embodiment of the present application, after obtaining the target data, the user terminal can be used as a new seed node and added to the peer-to-peer content distribution network layer. Therefore, when the user terminal further includes a seed maintenance module, the user terminal can manage the data shard information stored by itself through the seed maintenance module and maintain the integrity of the data shards (that is, perform shard integrity verification), so as to participate in the peer-to-peer content distribution network sharing.
[0039] In some embodiments, the user terminal includes three modules: a data request module, a verification and storage module, and a seed maintenance module. These three modules together constitute the security proxy of the user terminal. During the data access process, they can automatically activate the security verification process according to the user's data access request, obtain the access authorization certificate file from the gateway adaptation layer, and obtain the target data from the peer-to-peer content distribution network layer according to the access authorization certificate file, making each user terminal a trusted node and authentication environment in the distributed network, and ensuring that unauthorized data requests cannot enter the transmission channel.
[0040] (2) Gateway adaptation layer: Combined with the above embodiments, in one implementation, the embodiment of the present application further provides a peer-to-peer content distribution system for a scientific data center. In this system, the gateway adaptation layer includes a certificate generation and distribution module; The proof generation and distribution module is configured to receive the access authorization proof file request, send a permission query request to the data source layer according to the access authorization proof file request, and obtain the access control rules fed back by the data source layer; and generate an access authorization proof file according to the access control rules, and send the access authorization proof file to the user terminal.
[0041] In the embodiment of the present application, the gateway adaptation layer is docked with the data source through the proof generation and distribution module, obtains the access control rules from each scientific data center of the data source, generates the corresponding proof file by parsing the access control rules, and finally sends the generated access authorization proof file to the user terminal through the DOIP message.
[0042] Combined with the above embodiments, in one implementation manner, the embodiment of the present application further provides a point-to-point content distribution system for scientific data centers. In this system, the gateway adaptation layer further includes a tracking service module and a seed generation and distribution module; The tracking service module is configured to record the online status and cached data of each node, and the nodes include the plurality of user terminals and the plurality of scientific data centers; The seed generation and distribution module is configured to generate a seed file according to the access control rules, as well as the online status and cached data of each node, and send the seed file to the user terminal.
[0043] In the embodiment of the present application, the gateway adaptation layer maintains the dynamic node topology through the tracking service module (Tracker service module), that is, records the online status and cached data of each node (the data holding situation of the node). When the user terminal requests an access authorization proof file, the seed generation and distribution module can obtain the online status and cached data of each node from the tracking service module to determine the candidate nodes caching the target data, and then select the nodes that the user has access rights from the candidate nodes as seed nodes according to the access control rules, and generate a seed file according to the information of the seed nodes.
[0044] Further, the seed generation and distribution module is configured to generate a seed file according to the access control rules, as well as the online status and cached data of each node, and send the seed file to the user terminal, including: Step B-1: The seed generation and distribution module determines whether the target data is added to the peer-to-peer content distribution network layer according to the access control rules, as well as the online status and cached data of each node; Step B-2: When the seed generation and distribution module determines that the target data has not been added to the peer-to-peer content distribution network layer, it caches the target data in the local cache of the neighboring node and generates a seed file to send to the user terminal. Step B-3: When the seed generation and distribution module determines that the target data has been added to the peer-to-peer content distribution network layer, it sends the historical seed file to the user terminal.
[0045] In the embodiments of the present application, the neighboring node is one or more nodes of the peer-to-peer content distribution network that are closest to the scientific data center storing the target data. For the target data that has not been added to the peer-to-peer content distribution network layer, the gateway adaptation layer caches the complete target data in the local cache of the neighboring node through the seed generation and distribution module, and at this time, a seed file (conforming to the Bit Torrent protocol) is generated. For the target data that has already been added to the peer-to-peer content distribution network layer, the historical generated seed file is directly sent to the user terminal.
[0046] In some embodiments, the gateway adaptation layer includes three modules: the proof generation and distribution module, the tracking service module, and the seed generation and distribution module. As a bridge connecting the user terminal and the data source layer, the gateway adaptation layer maintains the dynamic node topology through these three modules, and generates a seed file according to the dynamic node topology and access control rules, realizing the seamless integration of the security policy and the distribution network.
[0047] (3) Data source layer: Combined with the above embodiments, in an implementation manner, the embodiments of the present application further provide a peer-to-peer content distribution system for a scientific data center. In this system, the data source layer includes a data management module; The data management module uses a distributed storage architecture to store scientific data and provides functions for retrieving and reading the scientific data; wherein, the scientific data is stored in the data management module in the form of digital objects.
[0048] In the embodiments of the present application, the data management module distributes and stores scientific data in the form of data objects, maintaining a complete digital object identification system and a fine-grained access control list. When retrieving and reading scientific data, the corresponding data can be directly located according to the identification information of the target data (i.e., the digital object identifier), realizing fast data retrieval and data reading operations.
[0049] Furthermore, the data source layer includes a permission management module; the permission management module is used to determine access control rules based on users, data classifications and operation permissions, the operation permissions characterize data operation types, and the data operation types include read operations and write operations; and when the permission query request is received, provide access control rules to the gateway adaptation layer.
[0050] In the embodiment of the present application, different users have operation rights over scientific data. The permission management module defines access control rules through multiple dimensions such as users, data classifications, and operation rights, thereby achieving fine-grained maintenance of access control rules and providing authoritative access control rules (policy benchmarks) for the system.
[0051] By adopting the technical solution of the embodiment of the present application, the scientific data center constitutes the authoritative data source of the system through the data management module and the authority management module, so as to provide a reliable data foundation and policy benchmark for the system.
[0052] (4) Peer-to-peer content distribution network layer: In combination with the above embodiments, in one implementation, the embodiment of the present application further provides a peer-to-peer content distribution system for a scientific data center, in which the seed node performs authority verification according to the access authorization certificate file in the data acquisition request, including: Step C-1: The seed node extracts the hash value of the access authorization certificate file, and initiates an online verification request to the gateway adaptation layer to perform online verification on the correctness of the hash value of the access authorization certificate file, the validity of the digital signature of the access authorization certificate file, and the validity of the authorization terms; Step C-2: When the online verification is passed, the seed node sends the data shard index table it holds to the user terminal.
[0053] In an embodiment of the present application, after establishing a connection with the seed node, the user terminal sends a data acquisition request carrying an access authorization certificate file to the seed node. After receiving the data acquisition request, the seed node parses the data acquisition request, extracts the hash value of the access authorization certificate file, and initiates an online verification request to the gateway adaptation layer to ensure that the transmission of each target data shard is subject to dynamic permission checks.
[0054] The following is an example embodiment to illustrate the point-to-point content distribution system for scientific data centers provided by the present application. Figure 2 and Figure 3 As shown, Figure 2 is a schematic diagram of a workflow of a point-to-point content distribution system for a scientific data center provided in an embodiment of the present application. Figure 3It is a functional module structure diagram of a point-to-point content distribution system for a scientific data center provided by an embodiment of the present application. Specifically, the point-to-point content distribution system for a scientific data center includes a user terminal layer, a gateway adaptation layer, a data source layer, and a point-to-point content distribution network layer.
[0055] Among them, the user terminal layer includes multiple user terminals. Each user terminal includes a data request module, a verification and storage module, and a seed maintenance module. These three modules together constitute the security proxy of the user terminal. During the data access process, through these three modules, the security verification process can be automatically activated according to the user's data access request, and an access authorization certificate file can be obtained from the gateway adaptation layer, making each user terminal a trusted node and authentication environment in the distributed network, ensuring that unauthorized data requests cannot enter the transmission channel.
[0056] As a bridge connecting the user terminal layer and the data source layer, the gateway adaptation layer includes a certificate generation and distribution module, a tracking service module, and a seed generation and distribution module. Through these three modules, the maintenance of the dynamic node topology is realized, and a seed file is generated according to the dynamic node topology and access control rules, realizing the seamless integration of the security policy and the distribution network.
[0057] The data source layer includes multiple scientific data centers. Each scientific data center uses a distributed storage architecture to store scientific data through a data management module and provides functions for retrieving and reading scientific data; and determines access control rules through a permission management module and provides access control rules to the gateway adaptation layer when receiving a permission query request.
[0058] Specifically, the content distribution process of the point-to-point content distribution system for a scientific data center is as follows: Step 1: The data request module of the user terminal receives the user's data access request, generates an access authorization certificate file request according to the user identity information and the identification information of the target data to be accessed in the data access request, and sends the access authorization certificate file request to the gateway adaptation layer.
[0059] Step 2: The gateway adaptation layer receives the access authorization certificate file request through the certificate generation and distribution module and sends a permission query request to the permission management module of the scientific data center according to the access authorization certificate file request.
[0060] Step 3: The permission management module of the scientific data center receives the permission query request and provides the access control rules to the gateway adaptation layer.
[0061] Step 4: The gateway adaptation layer generates an access authorization certificate file according to the access control rules through the manifest generation and distribution module, and sends the access authorization certificate file to the user terminal; and generates a seed file according to the access control rules, the online status of each node and the cache data (recorded by the tracking service module) through the seed generation and distribution module, and sends the seed file to the user terminal.
[0062] Step 5: The user terminal receives the access authorization certificate file and the seed file through the verification and storage module, and sends a data acquisition request carrying the access authorization certificate file to the peer-to-peer content distribution network layer according to the seed file.
[0063] Specifically, the verification and storage module performs permission verification based on the access authorization certificate file. If the permission verification passes, the seed node is determined according to the seed file, and a point-to-point connection request is sent to each seed node. When a point-to-point connection is established with each seed node, a data acquisition request is sent to each seed node.
[0064] Step 6: The seed node in the peer-to-peer content distribution network layer performs permission verification based on the access authorization certificate file in the data acquisition request, and if the permission verification passes, sends the target data shard accessed by the user to the user terminal.
[0065] Specifically, the seed node extracts the hash value of the access authorization certificate file, and initiates an online verification request to the gateway adaptation layer to verify online the correctness of the hash value of the access authorization certificate file, the validity of the digital signature of the access authorization certificate file, and the timeliness of the authorization terms; if the online verification passes, the data shard index table held by itself is sent to the user terminal; thereby, the verification and storage module of the user terminal receives the data shard index table sent by the seed node, and sends a data download request to the seed node according to the data shard index table to obtain the target data shard.
[0066] Through the above implementation process, the system transforms the data flow that propagates freely in the traditional point-to-point content distribution network into a targeted distribution guaranteed by the authorization mechanism. While maintaining the efficiency of distributed transmission, it ensures that the data usage rules of the original scientific data center are fully followed, thereby realizing the safe and efficient circulation of scientific data under the point-to-point content distribution network architecture.
[0067] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0068] Embodiments of the present application are described with reference to the flowcharts and / or block diagrams of systems according to embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a device for implementing the functions specified in multiple blocks.
[0069] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or the functions specified in multiple blocks. These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, such that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or the functions specified in multiple blocks.
[0070] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.
[0071] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or terminal device comprising said element.
[0072] The above provides a detailed introduction to a point-to-point content distribution system for a scientific data center provided by the present application. Specific examples are used in this text to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A peer-to-peer content distribution system for scientific data centers, characterized in that, Comprising: A user terminal layer, including a plurality of user terminals. The user terminal sends a request for an access authorization certificate file to the gateway adaptation layer according to the user's data access request, and, when obtaining the access authorization certificate file and the seed file, sends a data acquisition request carrying the access authorization certificate file to the peer-to-peer content distribution network layer according to the seed file. The seed file contains information about seed nodes storing target data; A gateway adaptation layer, which is used to, in response to the request for the access authorization certificate file, obtain an access control rule from the data source layer and generate an access authorization certificate file and a seed file according to the access control rule. The access authorization certificate file is used to represent the access right of an authorized user to the target data; A data source layer, including a plurality of scientific data centers, which are used to provide access control rules to the gateway adaptation layer; A peer-to-peer content distribution network layer, including a plurality of seed nodes. The seed nodes perform permission verification according to the access authorization certificate file in the data acquisition request, and, when the permission verification is passed, send shards of the target data accessed by the user to the user terminal. The seed nodes represent scientific data centers storing the target data and / or other user terminals.
2. The system according to claim 1, characterized in that, The gateway adaptation layer includes a certificate generation and distribution module; The certificate generation and distribution module is used to receive the request for the access authorization certificate file, send a permission query request to the data source layer according to the request for the access authorization certificate file, obtain the access control rule fed back by the data source layer; and generate an access authorization certificate file according to the access control rule and send the access authorization certificate file to the user terminal.
3. The system according to claim 1 or 2, wherein The gateway adaptation layer further includes a tracking service module and a seed generation and distribution module; The tracking service module is used to record the online status and cached data of each node. The nodes include the plurality of user terminals and the plurality of scientific data centers; The seed generation and distribution module is used to generate a seed file according to the access control rule, as well as the online status and cached data of each node, and send the seed file to the user terminal.
4. The system according to claim 3, wherein The seed generation and distribution module is used to generate a seed file according to the access control rule, as well as the online status and cached data of each node, and send the seed file to the user terminal, including: The seed generation and distribution module determines whether the target data is added to the peer-to-peer content distribution network layer according to the access control rule, as well as the online status and cached data of each node; When the seed generation and distribution module determines that the target data is not added to the peer-to-peer content distribution network layer, it caches the target data in the local cache of an adjacent node and generates a seed file to send to the user terminal; When the seed generation and distribution module determines that the target data is added to the peer-to-peer content distribution network layer, it sends the historical seed file to the user terminal.
5. The system according to claim 1, wherein The user terminal includes a data request module; The data request module is used to receive a user's data access request, generate the access authorization certificate file request according to the user identity information and identification information of the target data to be accessed in the data access request, and send the access authorization certificate file request to the gateway adaptation layer.
6. The system according to claim 1 or 5, characterized in that, The user terminal includes a verification and storage module; The verification and storage module is used to receive the access authorization certificate file and the seed file, and perform permission verification according to the access authorization certificate file; The verification and storage module determines the seed node according to the seed file when the authority verification passes, and sends a point-to-point connection request to each seed node, and sends the data acquisition request to each seed node when a point-to-point connection is established with each seed node; The verification and storage module receives the data shard index table sent by the seed node, and sends a data download request to the seed node according to the data shard index table to obtain the target data shard, wherein the data shard index table represents information about the data shard held by the seed node.
7. The system according to claim 1, wherein The user terminal includes a seed maintenance module; The seed maintenance module is used to manage the data sharding information stored in itself, maintain the integrity of the data sharding, and participate in the peer-to-peer content distribution network sharing.
8. The system according to claim 1, wherein The data source layer includes a data management module; The data management module adopts a distributed storage architecture to store scientific data and provides functions for retrieving and reading the scientific data; wherein the scientific data is stored in the data management module in the form of digital objects.
9. The system according to claim 2, wherein The data source layer includes a rights management module; The authority management module is used to determine access control rules according to users, data classifications and operation permissions, wherein the operation permissions represent data operation types, and the data operation types include read operations and write operations; and provide access control rules to the gateway adaptation layer when receiving the authority query request.
10. The system according to any one of claims 1-9, characterized in that, The seed node performs permission verification according to the access authorization certificate file in the data acquisition request, including: The seed node extracts the hash value of the access authorization certificate file, and initiates an online verification request to the gateway adaptation layer to perform online verification on the correctness of the hash value of the access authorization certificate file, the validity of the digital signature of the access authorization certificate file, and the validity of the authorization terms; When the online verification is passed, the seed node sends the data shard index table it holds to the user terminal.