A highly secure cloud-based data sharing host
By employing technologies such as multi-level identity authentication, encrypted transmission, access control, and real-time detection, the security and reliability issues of cloud-based data sharing hosts have been resolved, achieving high security and stability for end-to-end protection and cross-platform data sharing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XUZHOU XINCHEN TECHNOLOGY CO LTD
- Filing Date
- 2026-05-09
- Publication Date
- 2026-07-31
AI Technical Summary
Existing cloud-based data sharing hosts lack multi-dimensional identity verification mechanisms, which can easily lead to data theft, tampering, and unauthorized access. Furthermore, they lack real-time anomaly detection and end-to-end protection, making it difficult to meet the high-security and high-reliability data sharing requirements.
It employs multi-level identity authentication, end-to-end encrypted transmission, fine-grained permission isolation, distributed storage, real-time anomaly detection, end-to-end encrypted log auditing, and multi-cloud protocol compatibility to build a highly secure cloud-based data sharing host.
It achieves end-to-end security protection, resists identity forgery, data theft and unauthorized access, ensures data storage reliability, supports cross-platform sharing, reduces security risks and improves the convenience of operation and maintenance management.
Smart Images

Figure CN122496264A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud data sharing, specifically to a highly secure cloud data sharing host. Background Technology
[0002] In the current era of comprehensive digital transformation, cloud computing, hybrid cloud architecture, and remote collaborative work have become deeply integrated into the daily operations of various industries. Cloud data sharing has become the mainstream method of information interaction across organizations, regions, and terminals. As the core hardware carrier for data storage, transmission, scheduling, and sharing, cloud data sharing hosts are widely deployed in highly sensitive scenarios such as government, finance, enterprises, and healthcare. Their security, stability, and compatibility directly determine the efficiency of data flow and the continuity of business operations. With the continuous increase in data value, risks such as external network attacks, internal unauthorized operations, data leakage, and loss are becoming increasingly prominent, making the market demand for highly secure and reliable cloud data sharing hosts increasingly urgent.
[0003] Currently, traditional cloud-based data sharing hosts on the market have significant shortcomings in security design and functional adaptation. Most products rely solely on simple account and password verification, lacking multi-dimensional identity verification mechanisms, making them vulnerable to brute-force attacks, identity forgery, and device misuse. Data transmission and storage depend only on basic encryption methods, lacking end-to-end protection and integrity verification, making them susceptible to data theft, tampering, and loss. Access control is often rudimentary, failing to implement user domain isolation and fine-grained permission division, easily leading to unauthorized access and data leaks. Furthermore, existing hosts generally lack real-time anomaly detection and proactive emergency blocking capabilities, failing to quickly block intrusions or abnormal behavior; log auditing is incomplete, unencrypted, and inconsistent in timing, making post-incident traceability difficult. In addition, some hosts have single interface protocols, poor compatibility with multiple cloud platforms, and lack distributed storage and redundant backup mechanisms, making them prone to single points of failure and service interruptions, failing to meet the actual usage requirements of cloud data sharing in high-security, high-reliability scenarios. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention provides a highly secure cloud-based data sharing host, solving the problems of lacking multi-dimensional identity verification mechanisms, being prone to data theft, tampering and loss, and unauthorized access and data leakage.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a highly secure cloud-based data sharing host, comprising a core control unit, an identity authentication unit, an encrypted transmission unit, a permission isolation unit, a distributed storage unit, an anomaly detection unit, a log auditing unit, an emergency locking unit, a clock synchronization unit, and an interface adaptation unit; the identity authentication unit performs multi-level verification of user identity and then sends the verification result to the core control unit; the core control unit calls the encrypted transmission unit to perform AES-256 encryption on the shared data, and after user domain isolation is completed by the permission isolation unit, the data is written to the distributed storage unit; the anomaly detection unit collects host operation indicators in real time, and triggers the emergency locking unit when the indicators exceed the threshold; the log auditing unit records the entire operation behavior; the interface adaptation unit is compatible with private cloud and public cloud protocols; and the clock synchronization unit ensures that the system operation and log timing are consistent.
[0006] Preferably, the identity authentication unit includes an account verification subunit, a biometric subunit, a dynamic password subunit, and a device fingerprint subunit; The account verification subunit uses a local encrypted database to store account information, the biometric subunit supports face and fingerprint recognition, the dynamic password subunit updates every T=30s, and the device fingerprint subunit is bound to the terminal hardware information. A shared connection can only be established after all four verifications are passed.
[0007] Preferably, the encrypted transmission unit includes a data encryption subunit, a key management subunit, and a transmission verification subunit; The data encryption subunit performs block encryption on the shared file, with a block size of S=4MB. The key management subunit uses an asymmetric RSA algorithm to protect the symmetric key, and the transmission verification subunit uses CRC32 verification to ensure that the data has not been tampered with.
[0008] Preferably, the permission isolation unit includes a role division subunit, an access control subunit, and a domain isolation subunit; The role division sub-unit is divided into three levels of permissions: administrator, ordinary user, and visitor. The access control sub-unit implements policies based on the RBAC model. The domain isolation sub-unit divides different user data into independent logical domains, and cross-domain access is prohibited.
[0009] Preferably, the distributed storage unit includes a data sharding subunit, a redundancy backup subunit, and an addressing and locating subunit; The data sharding subunit splits the file into primary shards and redundant shards at a ratio of 1:3. The redundant backup subunit supports multi-replica storage across nodes, with the number of replicas N≥3. The addressing and positioning subunit achieves fast shard location through hash index.
[0010] Preferably, the anomaly detection unit includes a traffic monitoring subunit, a behavior analysis subunit, and an intrusion identification subunit; The traffic monitoring subunit monitors incoming and outgoing bandwidth in real time, the behavior analysis subunit establishes a model of normal user behavior, and the intrusion identification subunit matches attack behaviors based on a feature database.
[0011] Preferably, the emergency locking unit includes a connection disconnection subunit, a data freezing subunit, and an alarm push subunit; The disconnection subunit forcibly closes abnormal sessions, the data freeze subunit locks storage files, and the alarm push subunit notifies the administrator via local audio-visual and remote message notifications.
[0012] Preferably, the log auditing unit includes an operation recording subunit, a log encryption subunit, and a traceability query subunit; The operation record subunit collects four types of information: time, user, operation object, and result. The log encryption subunit uses the SM4 algorithm to protect the logs. The traceability query subunit supports fast retrieval based on conditions.
[0013] Preferably, the clock synchronization unit adopts the PTP protocol, which supports automatic synchronization between master and slave nodes, ensuring consistency between logs and operation timing.
[0014] Preferably, the interface adaptation unit includes a private cloud interface subunit, a public cloud interface subunit, and a protocol conversion subunit, and is compatible with HTTP, HTTPS, WebDAV, and S3 protocols, supporting cross-platform data sharing.
[0015] This invention provides a highly secure cloud-based data sharing host. It offers the following advantages: 1. This invention constructs a multi-level identity authentication, end-to-end encrypted transmission, and fine-grained permission isolation system to achieve end-to-end security protection from user access and data transmission to storage access. It effectively resists security threats such as identity forgery, data theft, illegal tampering, and unauthorized access, significantly improving the overall security of cloud data sharing. At the same time, it adopts a distributed storage and redundant backup design to ensure data storage reliability and avoid data loss caused by single point of failure. This allows cloud data sharing to have stronger security protection capabilities and data stability while flowing efficiently.
[0016] 2. This invention integrates real-time anomaly detection, rapid emergency locking, and end-to-end encrypted log auditing functions. It can promptly identify and block abnormal operations and intrusion behaviors, reduce losses caused by security risks, and enable traceability and verification of operational behaviors. With multi-cloud protocol compatible interfaces and a precise clock synchronization mechanism, it not only meets the data sharing needs of cross-platform and cross-cloud environments, but also ensures the consistency of system operation and log timing, taking into account the security, compatibility, and convenience of operation and maintenance management of cloud data sharing. Attached Figure Description
[0017] Figure 1 This is a system diagram of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Example: Please see the appendix Figure 1 This invention provides a highly secure cloud-based data sharing host, comprising a core control unit, an identity authentication unit, an encrypted transmission unit, a permission isolation unit, a distributed storage unit, an anomaly detection unit, a log auditing unit, an emergency locking unit, a clock synchronization unit, and an interface adaptation unit. All units are interconnected via an internal high-speed bus and are uniformly scheduled by the core control unit to collaboratively complete the entire process of security control, including user access, data transmission, storage management, security monitoring, emergency response, and audit traceability.
[0020] When an external user initiates a data sharing, file upload, file download, or permission operation request through a terminal device, the identity authentication unit first performs multi-level identity verification. The identity authentication unit includes an account verification subunit, a biometrics subunit, a dynamic password subunit, and a device fingerprint subunit. The account verification subunit stores account information in a local encrypted database, and passwords are encrypted using a salted hash method to prevent plaintext leakage and database breach / credential stuffing attacks. The biometrics subunit supports face liveness detection and fingerprint feature comparison, effectively resisting forged biometric attacks. The dynamic password subunit updates its passwords every T=30 seconds using a time synchronization mechanism to prevent replay attacks. The device fingerprint subunit collects hardware information such as the terminal's CPU serial number, hard drive identifier, and network card MAC address to generate a unique device fingerprint, allowing only pre-bound devices to access the system. After all four verifications pass, the identity authentication unit sends a verification pass signal to the core control unit, allowing the establishment of a data sharing connection; if any verification fails, the system immediately denies access and records the abnormal behavior.
[0021] After receiving a valid authentication signal, the core control unit invokes the encryption transmission unit to encrypt and transmit the shared data. The encryption transmission unit includes a data encryption subunit, a key management subunit, and a transmission verification subunit. The data encryption subunit uses the AES-256 encryption algorithm to encrypt the shared file in blocks of size S=4MB, balancing encryption strength and processing efficiency. The key management subunit uses the RSA asymmetric algorithm to encrypt, securely distribute, and periodically update the symmetric key, ensuring that the key is never transmitted in plaintext over the network. The transmission verification subunit verifies the integrity of the encrypted data using CRC32 checksum. The data receiver performs real-time verification, and if tampering, packet loss, or unauthorized insertion is detected, a retransmission mechanism is immediately initiated to ensure that the transmission process is tamper-proof and unlost.
[0022] Encrypted data is then managed and isolated by a permission isolation unit. This unit comprises a role-based subunit, an access control subunit, and a domain isolation subunit. The role-based subunit categorizes users into three levels of permissions: administrators, regular users, and visitors. Administrators have full permissions for system configuration, permission allocation, and log auditing. Regular users can upload, download, and edit their own data. Visitors have only read-only permissions for specified files and cannot modify, delete, or forward them. The access control subunit performs access policy matching and permission verification based on the RBAC model, blocking unauthorized operations in real time. The domain isolation subunit divides data from different users, departments, and projects into independent logical domains, with hard isolation between domains to prohibit cross-domain access and unauthorized data retrieval.
[0023] Legitimate data, after being isolated by permissions, is written to the distributed storage unit. The distributed storage unit includes a data sharding subunit, a redundancy backup subunit, and an addressing and positioning subunit. The data sharding subunit splits files into primary and redundant shards at a 1:3 ratio to improve data fault tolerance. The redundancy backup subunit uses multi-replica storage across physical nodes, with N≥3 replicas, to avoid data loss due to single-point failures. The addressing and positioning subunit establishes a mapping relationship between shards and storage nodes through a consistent hash index, enabling fast shard location, parallel read / write, and efficient access.
[0024] During host operation, the anomaly detection unit collects operational metrics in real time and performs security monitoring. The anomaly detection unit includes a traffic monitoring subunit, a behavior analysis subunit, and an intrusion detection subunit. The traffic monitoring subunit monitors inbound and outbound bandwidth, concurrent connections, and request frequency in real time, issuing warnings for sudden traffic spikes and high-frequency scanning. The behavior analysis subunit establishes a normal behavior model based on user history, marking abnormal behaviors such as logins from different locations, batch downloads, and high-frequency deletions in real time. The intrusion detection subunit has a built-in attack signature database that can identify intrusion behaviors such as brute-force attacks, SQL injection, XSS attacks, and unauthorized access. When operational metrics exceed preset security thresholds, the anomaly detection unit immediately triggers an emergency locking unit. The emergency locking unit includes a connection disconnection subunit, a data freeze subunit, and an alarm push subunit. The connection disconnection subunit forcibly closes abnormal sessions and disconnects unauthorized connections. The data freeze subunit performs read-only locking on potentially compromised files to prevent unauthorized copying, modification, or deletion. The alarm push subunit simultaneously notifies the administrator via local audio-visual alarms and SMS, email, and remote messaging.
[0025] The log auditing unit records and encrypts all system operations. It includes an operation recording subunit, a log encryption subunit, and a traceability query subunit. The operation recording subunit collects four types of information: operation time, user, object, and result, covering all operations such as login, upload, download, deletion, authorization, and configuration modification. The log encryption subunit uses the SM4 national cryptographic algorithm to encrypt log files, preventing tampering, forgery, or deletion. The traceability query subunit supports multi-condition searches based on time range, user account, operation type, file name, etc., enabling security auditing and post-event traceability. The clock synchronization unit uses the PTP precise time protocol to automatically synchronize the clocks of the host master-slave nodes, storage nodes, and business nodes, ensuring that all operations are consistent with the log recording timeline without deviation.
[0026] The interface adaptation unit is designed to be compatible with multiple cloud platforms and multiple transmission protocols. The interface adaptation unit includes a private cloud interface subunit, a public cloud interface subunit, and a protocol conversion subunit. It is compatible with mainstream transmission protocols such as HTTP, HTTPS, WebDAV, and S3, and supports connection to private cloud, public cloud, and hybrid cloud environments. It enables secure data sharing across multiple terminals and platforms, including Windows, Linux, macOS, and mobile devices. During cross-cloud and cross-platform transmission, it maintains security mechanisms such as identity authentication, encrypted transmission, permission isolation, anomaly detection, and log auditing without degradation.
[0027] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A highly secure cloud-based data sharing host, characterized in that, It includes a core control unit, an identity authentication unit, an encrypted transmission unit, an access control unit, a distributed storage unit, an anomaly detection unit, a log auditing unit, an emergency locking unit, a clock synchronization unit, and an interface adaptation unit; After the identity authentication unit completes multi-level verification of the user's identity, it sends the verification result to the core control unit. The core control unit calls the encryption transmission unit to perform AES-256 encryption on the shared data, and after the permission isolation unit completes user domain isolation, it writes it to the distributed storage unit. The anomaly detection unit collects the host's operating indicators in real time, and triggers the emergency locking unit when the indicators exceed the threshold. The log auditing unit records all operational behaviors throughout the process; The interface adaptation unit is compatible with both private cloud and public cloud protocols; the clock synchronization unit ensures that the system operation and log timing are consistent.
2. The high-security cloud data sharing host according to claim 1, characterized in that, The identity authentication unit includes an account verification subunit, a biometric subunit, a dynamic password subunit, and a device fingerprint subunit; The account verification subunit uses a local encrypted database to store account information, the biometric subunit supports face and fingerprint recognition, the dynamic password subunit updates every T=30s, and the device fingerprint subunit is bound to the terminal hardware information. A shared connection can only be established after all four verifications are passed.
3. The high-security cloud data sharing host according to claim 1, characterized in that, The encrypted transmission unit includes a data encryption subunit, a key management subunit, and a transmission verification subunit; The data encryption subunit performs block encryption on the shared file, with a block size of S=4MB. The key management subunit uses an asymmetric RSA algorithm to protect the symmetric key, and the transmission verification subunit uses CRC32 verification to ensure that the data has not been tampered with.
4. A highly secure cloud-based data sharing host according to claim 1, characterized in that, The permission isolation unit includes a role division subunit, an access control subunit, and a domain isolation subunit; The role division sub-unit is divided into three levels of permissions: administrator, ordinary user, and visitor. The access control sub-unit implements policies based on the RBAC model. The domain isolation sub-unit divides different user data into independent logical domains, and cross-domain access is prohibited.
5. A highly secure cloud-based data sharing host according to claim 1, characterized in that, The distributed storage unit includes a data sharding subunit, a redundancy backup subunit, and an addressing and positioning subunit; The data sharding subunit splits the file into primary shards and redundant shards at a ratio of 1:
3. The redundant backup subunit supports multi-replica storage across nodes, with the number of replicas N≥3. The addressing and positioning subunit achieves fast shard location through hash index.
6. A highly secure cloud-based data sharing host according to claim 1, characterized in that, The anomaly detection unit includes a traffic monitoring subunit, a behavior analysis subunit, and an intrusion identification subunit; The traffic monitoring subunit monitors incoming and outgoing bandwidth in real time, the behavior analysis subunit establishes a model of normal user behavior, and the intrusion identification subunit matches attack behaviors based on a feature database.
7. A highly secure cloud-based data sharing host according to claim 1, characterized in that, The emergency locking unit includes a connection disconnection subunit, a data freeze subunit, and an alarm push subunit; The disconnection subunit forcibly closes abnormal sessions, the data freeze subunit locks storage files, and the alarm push subunit notifies the administrator via local audio-visual and remote message notifications.
8. A highly secure cloud-based data sharing host according to claim 1, characterized in that, The log auditing unit includes an operation recording subunit, a log encryption subunit, and a traceability query subunit; The operation record subunit collects four types of information: time, user, operation object, and result. The log encryption subunit uses the SM4 algorithm to protect the logs. The traceability query subunit supports fast retrieval based on conditions.
9. A highly secure cloud-based data sharing host according to claim 1, characterized in that, The clock synchronization unit adopts the PTP protocol, which supports automatic synchronization between master and slave nodes, ensuring consistency between logs and operation timing.
10. A highly secure cloud-based data sharing host according to claim 1, characterized in that, The interface adaptation unit includes a private cloud interface subunit, a public cloud interface subunit, and a protocol conversion subunit, and is compatible with HTTP, HTTPS, WebDAV, and S3 protocols, supporting cross-platform data sharing.