数据与计算发展前沿 ›› 2026, Vol. 8 ›› Issue (3): 40-50.

doi: 10.11871/jfdc.issn.2096-742X.2026.03.004

• 专刊:第二十一届全国科学计算与信息化会议征文 • 上一篇    下一篇

面向高能物理计算平台的无认证文件共享设计与实现

欧歌1(),刘子凯1,2,毕玉江1,石京燕1,*()   

  1. 1 中国科学院高能物理研究所北京 100049
    2 郑州大学河南 郑州 450001
  • 收稿日期:2025-10-15 出版日期:2026-06-20 发布日期:2026-06-18
  • 通讯作者: 石京燕
  • 作者简介:欧歌,中国科学院高能物理研究所,高级工程师,主要研究方向为数据库技术应用、数据处理工作流。
    本文承担工作为系统设计、安全策略的实现。
    OU Ge, is a senior engineer at the Institute of High Energy Physics, Chinese Academy of Sciences. Her primary research interests include database technology applications and data processing workflows.
    In this paper, she is mainly responsible for system design and implementation of security strategies.
    E-mail: oug@ihep.ac.cn|石京燕,中国科学院高能物理研究所,研究员,主要研究方向为高性能计算、虚拟化技术。
    本文中负责方向指导、INK平台。
    SHI Jingyan, Research Professor at the Institute of High Energy Physics, Chinese Academy of Sciences. Her research focuses on high performance computing and virtualization technology.
    In this paper, she provided research guidance and was in charge of the INK platform for this paper.
    E-mail: shijy@ihep.ac.cn
  • 基金资助:
    国家重点研发计划(2023YFC2206404)

Design and Implementation of Authentication-Free File Sharing for the High-Energy Physics Computing Platforms

OU Ge1(),LIU Zikai1,2,BI Yujiang1,SHI Jingyan1,*()   

  1. 1 Institute of High Energy Physics, Chinese Academy of Sciences, Beijing 100049, China
    2 Zhengzhou University, Henan, Zhengzhou 450001, China
  • Received:2025-10-15 Online:2026-06-20 Published:2026-06-18
  • Contact: SHI Jingyan

摘要:

【目的】针对计算平台与交互式分析工作台的文件共享需求,设计无认证文件共享机制,以便捷的公共链接方式,实现文件即时安全分享。 【方法】基于INK全域认证体系,使用Linux UGO权限模型与元数据管理构建权限控制逻辑,采用XRootD框架屏蔽底层异构分布式存储差异,通过多维度安全机制保障数据传输与访问安全,最终形成精准管控的无认证文件共享方案。 【结果】已成功部署于INK交互式分析工作台,支持安全、快速生成公共链接完成数据分享;采用XRootD框架的文件下载速度较单服务器普通下载仅下降3.2%,在分布式存储场景下具备优异的数据访问性能。 【结论】全域认证、异构存储适配及精细化权限管控能力,为跨平台分布式环境下的文件共享提供了完整且高效的解决方案。

关键词: 文件共享, 计算平台, 交互式分析, 安全策略

Abstract:

[Objective] To meet the file sharing needs in the computational platform and interactive analysis workbench, this paper designs an authentication-free mechanism for instant, secure sharing via public links. [Methods] Leveraging the INK global authentication framework, permission control logic is implemented using the Linux UGO permission model in conjunction with metadata management. The XRootD framework is employed to abstract underlying differences in heterogeneous distributed storage systems. Multi-dimensional security mechanisms are integrated to safeguard data transmission and access, culminating in a precisely controlled authentication-free file-sharing paradigm. [Results] The mechanism has been successfully deployed on INK workbench, allowing secure, fast public link generation for sharing. XRootD downloads are only 3.2% slower than ordinary downloads from a single-server, with strong performance in distributed storage. [Conclusions] Global authentication, heterogeneous storage adaptation, and fine-grained controls deliver a complete, efficient solution for cross-platform distributed file sharing.

Key words: file sharing, computing platform, interactive analysis, security strategy