针对高能同步辐射光源(HEPS)科学数据管理和开放共享面临的问题,论述了科学数据策略研究对同步辐射大科学装置这类公共实验平台的必要性和重要性.依据国内外光源类装置科学数据策略的研究进展,分析了我国同步辐射大科学装置数据策略研究的现状,重点阐述高能同步辐射光源数据策略研究包含的内容,总结策略研究中遇到的问题并提出相关思考.最后,系统介绍了数据策略研究取得的阶段性进展以及在高能同步辐射光源的应用情况,并对高能同步辐射光源未来的科学数据策略提出了展望.
高能物理科学数据是用于研究物质的基本构成以及宇宙起源基础研究的重要资源。利用网络、计算、存储等基础设施可以提供包括数据汇交、数据共享、数据处理等高能物理科学数据服务,研究探讨高能物理科学数据的服务与应用具有重要意义。本文阐述国家高能物理科学数据中心支持的包括宇宙线观测、空间科学、粒子物理和材料科学领域的数据应用模式以及所采用的技术手段和方法,并通过典型服务案例介绍国内高能物理科学数据服务与应用。
科研基础平台是国家科技创新的基础性、战略性平台。近10年来,我国科研基础平台在科学观测水平、制造工艺水平、数据获取水平、开放共享水平、科学管理水平、开发利用水平方面取得了跨越式发展,高水平支撑我国科技创新活动。展望未来,新的科研范式变革正在悄然到来,新兴科研信息化基础平台不仅支撑重大科技基础设施和野外台站朝着更大规模、更精确、更先进的方向发展,其本身还将对科研范式变革起到重要的推动作用,成为重大科技突破的“加速器”与“倍增器”,成为我国跻身创新型国家前列和迈进世界科技强国的关键支撑。
[目的]利用SDN架构网络实现对高能物理数据传输路径选择的优化,提升高能物理合作单位之间数据传输效率.[方法]采用面向服务的网络性能测量框架perfSONAR、基于GRE的虚拟网络技术以及基于SDN的控制技术来实现提出的目标.[结果]提出一种面向高能物理网格环境网络性能测量与性能优化方法,首先采用SDN技术及虚拟网络技术在高能物理网格环境中构建基于SDN架构的高能物理数据共享虚拟专用网,然后采用面向服务的网络性能测量框架perfSONAR设计并实现面向高能物理网格环境网络性能监测及可视化平台,基于网络性能探测的结果,结合本文提出的最优路径计算方法选择出高能物理网格环境中两个节点之间的最优数据共享路径.[结论]测试结果表明本文的方法能提升高能物理网格环境中数据共享的效率,能够为高能物理网格环境中节点间数据高速、稳定传输提供可靠的保障.
[目的]高能同步辐射光源(HEPS)是我国"十三五"期间优先建设的、为国家的重大战略需求和前沿基础科学研究提供技术支撑平台的国家重大科技基础设施,开展超高空间分辨、时间分辨、能量分辨的高通量同步辐射实验.其一期建设的十五条光束线实验站,预计平均每天产生200TB的原始实验数据,峰值可达每天500TB.这些实验数据需要得到存储、共享,并能够进行准确实时的处理与分析.[方法]科学数据处理平台包括基础设施、科学软件、网络、计算、存储、公共信息服务等系统.[结果]该平台将为HEPS设施、科研人员、工程技术人员以及用户提供包括设数据传输、数据存储、数据分析、数据共享、科研协同等在内的网络、计算、存储等基础设施能力,以及提供科学软件、通用软件、通用信息系统和网络信息安全服务等.
High energy physics mainly studies elementary particles and the interactions among them through various types of experiments, which yield a tremendous amount of data every day. Also the high energy physics experiments are regional-crossing. How to transfer experimental data reliably and efficiently in real time from the on-site detector to a data center for processing and analysis is one of the most important research topics for each experiment. After considering the requirements from different experiments, this paper introduces a general purpose data transfer system, which meets the needs of various high energy physics experiments through the way of interface definition and configuration files. The sys-tem provides the following functions:multipath source data scanning, data transferring, system information sharing, sys-tem configuration, log management and performance monitoring. At present, the system has been used by the experiment of Jiangmen Underground Neutrino Observatory to transfer the data of photomultiplier tube measurements. The good per-formance of real operation shows the that system satisfies the experiment’s requirements.
高能物理(也称粒子物理)研究一直处于物质科学的最前沿,大科学装置往往是物理基础研究和满足国家战略需求的国之重器,为基础及应用研究提供了重要的平台.大科学装置产生的数据是一座极为重要的科学金矿,而科学数据的开放与共享是科学数据效益最大化的必要条件.前沿物理大科学装置包括面向特定学科的专用研究类装置和服务于多学科交叉前沿的公共服务平台类装置,两类装置科学数据构成大体一致,均包括实验数据、模拟数据以及文档、成果和专利等数据,但在数据主权和共享机制上则存在较大差别.专用研究装置和数据采用合作组模式,合作组有国内外科学家共同参与组成,并在合作组框架下实现科学数据共享和利用.公共服务平台类大科学装置数据管理和共享则仍然没有相应的管理规定和规范,需要结合我国科学数据管理办法和领域特点,进一步开展相关研究、探索和实践.科学数据的开放共享应遵循“尽量共享、不得已才受限”的原则,推动科学数据的效能最大化,并在经费保障、技术研发和人才队伍等方面给予支持.
针对当前单一SSID无线网络中存在的安全问题,即用户得到认证授权后能随时随地接入到无线网络中,造成身份不同的用户对无线网络的使用,如带宽、访问控制(ACL)等相同,提出了基于802.1X+VLAN技术的用户分组接入方案,并结合freeradius技术实现了该用户接入方案.通过对该方案进行部署,测试证明了该方案对不同身份的用户访问同一个SSID无线网络具有不同的访问策略,从而有效提高了无线网络的安全性,简化了无线网络的管理.
eduroam (education roaming,) is a secure, world-wide roaming wireless access service developed for international research and education community. Its purpose is to set up a wireless LAN roaming infrastructure for the authorized users to facilitate the wireless access freely and securely among the member institutions.eduroam uses IEEE 802.1x protocol and RADIUS protocol for wireless network access authentication. In this paper, theeduroam architecture and authentication processes are analyzed;eduroam has been deployed in IHEP network environment, and the practice verifies the practicability of the account authentication and certificate authentication; in addition, NT hash encryption algorithm for LDAP storage of password is proposed for the authentication processes. Analysis shows that the method simplifies the deployment and improves the efficiency of authenticate and security of the system.
提出了一种适用于MANET网络的基于队列长度的逐跳AC自适应机制(QLACSA)。QLACSA机制的设计目标是解决EDCA在MANET网络中不同长度的业务流间的不公平竞争问题,为时延敏感的业务流提供可靠的端到端时延保证。QLACSA机制作用于MAC层,对时延敏感的业务流,将其全局时延需求合理地划分成逐跳的期望时延,根据数据包的实际时延状况,执行逐跳的AC重估,并在AC的选择过程中综合考虑数据包的延迟状态、本地时延需求和队列的排队情况,以保证各数据包能在QoS要求的端到端时延要求内到达目的节点。QLACSA还采用了整流策略,通过主动丢包实现"优胜劣汰",将已经过期或有可能过期的数据包丢弃,从而降低可能的信道资源浪费,为具有更高传输成功率的数据包提供更多的传输机会。仿真结果表明,QLACSA机制在满足端到端时延需求的同时,将路径较长的业务流吞吐量提高了211%~245%左右。
高能物理研究组成物质的基本粒子及其相互作用规律,是物理学研究中的最前沿。当今,高能物理实验规模一般都很大,需要成百上千的科学家参加。高能物理实验的周期比较长,从实验设计到目标的实现通常会经历十几年甚至几十年的时间。实验产生的海量实验数据,需要借助先进的计算机技术来处理和分析,实验的需求也助推了计算机信息技术的不断发展。近年来,我国物理学家在以我为主的高能物理实验中取得了令人瞩目的成绩,其中包括北京正负电子对撞
The requirements of computing and storage for High Energy physics experiments are growing rapidly with the expansion of the scale of experiments, the forthcoming completion of Chinese Spallation Neutron Source(CSNS) has also higher requirements for computing system. The new computing pattern, cloud computing, can make IT resources configuration flexible and management centralized. So from the research and practice aspects, firstly, the application status of cloud computing science in High Energy Physics Experiments are introduced in this paper. Secondly, the special requirements of CSNS are discussed further. Thirdly, the design and practice of cloud computing platform based on OpenStack are mainly demonstrated from the aspects of cloud computing system framework, storage system, application of OpenStack, etc. Finally, some future prospects of CSNS cloud computing system are summarized in the ending of this paper.
高能物理实验规模不断扩大,计算和存储需求不断增长,即将建成的中国散裂中子源(ChineseSpallation Neutron Source,CSNS)对物理实验计算环境同样有较高要求.进入云计算时代,资源的灵活配置和集中管理不仅降低了硬件成本还大大提高了资源利用率.本文首先介绍了云计算技术的在高能物理实验中的应用现状,然后介绍中国科学院高能物理研究所东莞分部目前所建设的中国散裂中子源对于计算环境的的具体需求,接下来从基础运维、统一认证、存储系统、OpenStack、资源监控五个方面详细阐述了基于OpenStack的云计算环境的设计和实践,以及如何利用其实现对CSNS计算资源的弹性管理,最后对CSNS云计算环境的现状进行了总结并提出了对未来的展望.
With the rapid growth of cloud computing, it is quite a common phenomenon for private users getting considerable amount of free network disk storage space. In order to provide users with a safe personal documents network storage space, this paper proposes a solution to build IHEP personal cloud platform (namely IHEPBox) based on the open source software ownCloud. As a typical three-tier load balance web application, IHEPBox supports all aspects of operations from users management to the plug, the file sharing and storage. All information such as user information, user’s shared files, plug-in application status and IHEPBox cache to accelerate file access is stored in the IHEPBox back-end database, where a user is configured to use storage space dynamically based on the user directory structure to open the basic data isolation and multi-tenant mode. Meanwhile, IHEPBox builds a storage abstraction layer by using CIFS, NFS, GFS2 and Gluster to connect the storage space to the server. And then IHEPBox uses ldap database (AD domain) and WebDAV protocol to connect private cloud storage servers with clients to realize real-time synchronization of data documents.
随着教育与科研的国际化潮流日趋增长,高校和科研机构之间的国际交流与合作也日益增多,各单位互派访问学者也越加常态化,访问学者在到访机构往往都有网络接入的需求.依照传统流程,访问学者需要向到访机构的网络管理部门主动提出网络接入申请,经相关部门确认身份后,办理网络接入手续,获得临时网络访问账号.这些临时账号从申请到后续维护,直至最后的注销,每个阶段都需要投入相当的成本.
We report an improved measurement of the neutrino mixing angle θ_(13) from the Daya Bay Reactor Neutrino Experiment. We exclude a zero value for sin~2 θ_(13) with a significance of 7.7 standard deviations. Electron antineutrinos from six reactors of 2.9 GW_(th) were detected in six antineutrino detectors deployed in two near (flux-weighted baselines of 470 m and 576 m) and one far (1648 m) underground experimental halls. Using 139 days of data, 28909 (205308) electron antineutrino candidates were detected at the far hall (near halls). The ratio of the observed to the expected number of antineutrinos assuming no oscillations at the far hall is 0.944±0.007(stat.)±0.003(syst.). An analysis of the relative rates in six detectors finds sin~2 θ_(13) =0.089±0.010(stat.)±0.005(syst.) in a three-neutrino framework.
针对BitTorrent系统中的节点剥削行为,提出一种流模型论证剥削行为对系统性能的影响,通过该模型得到“剥削容忍阈值”,当系统中剥削节点的比例超过该阈值时,系统可能“死亡”.为避免系统“死亡”,提出一种基于加密的间接激励机制.在该机制中,节点必须经过一段时间的供种才能够获取密钥,还原下载的文件,同时该机制还能够根据节点的供种贡献对其下载行为进行奖励.实验结果证明:BitTorrent系统中节点不会因其供种行为获得任何奖励,无法达到抑制剥削行为的效果;引入所提出的机制后,供种节点的下载效率是原BitTorrent系统的2~3倍.
With the development of network applications,flexibility and wieldy is becoming more and more important for network users.Based on the analysis of the needs of campus wireless network,This article design and analysis the deployment mechanism,register system and protection system of wireless network.Built a wireless network system base on IHEP network environment,realization the always and everywhere access the network in the IHEP campus area.
With the increased complexity of the network environment today,how to ensure the availability and reliability for the network and applications is becoming the most important issue to the network managers.Campus network monitoring system can give us real-time information showing the objective status for the network and applications and so that is very helpful for improving the network system management.Based on the design and implementation of our IHEP campus network monitor system,this paper introduces the functions,architecture and implementation technologies of campus network monitoring system.