Medical shared data protection method and system using elliptic curve cryptosystem
By combining elliptic curve cryptography system, data compression and information hiding technology, a method for medical data protection was designed, which solved the shortcomings of traditional methods in data security and transmission efficiency, and realized the secure storage, efficient transmission and controllable sharing of medical data.
Patent Information
- Application Number
- CN202510244565.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-06-03
AI Technical Summary
The existing medical data protection methods have shortcomings in taking into account data security and transmission efficiency. Especially in the process of data sharing among medical institutions, traditional encryption methods are difficult to meet the needs of data compression, transmission efficiency and multi-party secure access at the same time.
An elliptic curve cryptography system is used to combine data compression and information hiding technology to design a medical shared data protection method. This method generates a shared key through the elliptic curve Diffie-Hellman key exchange protocol, compresses DICOM medical images using lossless compression algorithm, and embeds electronic medical record information into the encrypted image to realize secure storage, efficient transmission and controllable sharing of data.
This method not only ensures the security of medical data during transmission, but also realizes efficient compression and controllable access of data, meets the needs of secure data sharing among medical institutions and improves the operation efficiency of telemedicine platforms.
Smart Images

Figure CN120089301A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data content security in information security, and particularly relates to a method for protecting medical shared data using an elliptic curve cryptosystem. Background Art
[0002] With the rapid development of medical informatization, digital medical images and electronic medical records play an increasingly important role in modern medical systems. Frequent exchanges and sharing of various medical data are required among medical institutions to provide better diagnosis and treatment services. However, these medical data containing patients' sensitive information face serious security threats during transmission and storage. Especially in scenarios such as remote medical consultations, how to ensure the security of medical data and the protection of patients' privacy has become a key issue to be solved.
[0003] Currently, medical data protection mainly uses traditional symmetric encryption algorithms, which have disadvantages such as complex key management and large computational overhead. At the same time, medical data often needs to be securely transmitted between different institutions and ensure its integrity, which poses higher requirements for encryption technology. In addition, due to the large volume of medical image data itself, it is difficult for traditional encryption methods to balance data security and transmission efficiency simultaneously.
[0004] In the field of medical data protection, solutions based on public key cryptosystems have received extensive attention due to their superior security and flexible key management mechanisms. Especially, elliptic curve cryptography (ECC) shows unique advantages in medical data protection with its shorter key length and higher security strength. However, existing ECC-based solutions often only focus on a single encryption function and lack comprehensive consideration of practical requirements such as medical data compression, transmission efficiency, and multi-party secure access. To solve the above problems, a comprehensive solution that can not only ensure the security of medical data but also meet the efficient data sharing needs among medical institutions is required. This solution should make full use of the advantages of elliptic curve cryptography and consider the characteristics of medical data to achieve secure storage, efficient transmission, and controllable sharing of data. Summary of the Invention
[0005] The purpose of the present invention is to solve the problems existing in the prior art and provide a method for protecting medical shared data using an elliptic curve cryptosystem.
[0006] The specific technical solution adopted by the present invention is as follows:
[0007] In a first aspect, the present invention provides a method for protecting medical shared data using an elliptic curve cryptosystem, where the medical shared data includes DICOM medical images and electronic medical records, and the specific steps of the method are as follows:
[0008] S1: After all image owners, data embedders, and recipients participating in data sharing pass the identity authentication of the trusted certification center, the trusted certification center generates exclusive elliptic curve public-private key pairs consisting of private keys and public keys for each party.
[0009] S3: The image owner uses their own private key and the recipient's public key to generate a first shared key through the elliptic curve Diffie-Hellman key exchange protocol.
[0010] S6: The image owner separates the DICOM file into image data and metadata, and applies a lossless compression algorithm to the image data to obtain a compressed DICOM image.
[0011] S9: The image owner encrypts the compressed DICOM image using the first shared key to obtain an encrypted DICOM image.
[0012] S5: The data embedder uses their own private key and the recipient's public key to generate a second shared key, encrypts the electronic medical record information with it, embeds it into the encrypted DICOM image, and then sends it to the recipient.
[0013] S6: The recipient uses their private key and the public keys of the data embedder and the image owner to reconstruct the shared key to extract the embedded electronic medical record information, and reconstructs the original DICOM medical image through a lossless decompression algorithm.
[0014] As a preference of the first aspect above, in S1, the trusted certification center generates paired private keys and public keys for the image owner, data embedder, and recipient respectively based on the standard secp256r1 elliptic curve, stores the public keys in the database, and distributes the private keys to the image owner, data embedder, and recipient through a secure channel.
[0015] As a preference of the first aspect above, in S2, after the image owner authenticates their identity at the trusted certification center, they obtain the recipient's public key pk r from the public key database of the certification center, and then use their own private key sk o and the recipient's public key pk r to obtain the point KO on the elliptic curve through dot multiplication operation. Finally, the x coordinate of the calculated point KO is processed through a key derivation function to obtain the first shared key, where the key derivation function uses the SHA-256 hash function.
[0016] As a preference of the first aspect above, in S3, the method for the image owner to apply a lossless compression algorithm to compress the image data using a lossless compression algorithm is as follows:
[0017] S31: The image owner divides the DICOM image into image blocks of size 16×16, and calculates the respective total embedding amounts of each image block under three different embedding strategies; the first embedding strategy embeds the entire 16×16 image block as a whole, the second embedding strategy further divides the 16×16 image block into 4 sub-image blocks of size 8×8 and embeds them separately, and the third embedding strategy further divides the 16×16 image block into 16 sub-image blocks of size 4×4 and embeds them separately;
[0018] S32: For each 16×16 image block, the image owner selects the embedding strategy with the largest embedding amount, compresses the MSBs of all embeddable pixels in the image block using the selected strategy with Huffman coding, and then rearranges the bit planes of the compressed image in the order from the LSB to the MSB, and fills all the compressed embedding space parts with random numbers to form a compressed image in the form of a binary stream.
[0019] Preferably, as in the first aspect above, the embedding spaces and the total capacity calculation methods under the three different embedding strategies are as follows:
[0020] For the first embedding strategy, the pixel at the center of the 16×16 image block is used as the reference pixel, and the remaining pixels are embeddable pixels. Compare from which MSB the first different bit starts between each embeddable pixel and the reference pixel, and use this MSB and all the previous MSBs as the embedding space. The sum of the embedding space sizes of all embeddable pixels is used as the total embedding amount of the first embedding strategy;
[0021] For the second embedding strategy, the 16×16 image block is split into 4 sub-image blocks of size 8×8. The pixel at the center of each sub-image block is used as the reference pixel, and the remaining pixels in the sub-image block are embeddable pixels. Compare from which MSB the first different bit starts between each embeddable pixel and the reference pixel in the same image block, and use this MSB and all the previous MSBs as the embedding space. The sum of the embedding space sizes of all embeddable pixels is used as the total embedding amount of the second embedding strategy;
[0022] For the third embedding strategy, the 16×16 image block is split into 16 sub-image blocks of size 4×4. The pixel at the center of each sub-image block is used as the reference pixel, and the remaining pixels in the sub-image block are embeddable pixels. Compare from which MSB the first different bit starts between each embeddable pixel and the reference pixel in the same image block, and use this MSB and all the previous MSBs as the embedding space. The sum of the embedding space sizes of all embeddable pixels is used as the total embedding amount of the third embedding strategy.
[0023] As a preference of the above first aspect, in step S4, the method for the image owner to encrypt the compressed DICOM image is as follows:
[0024] S41: The image owner inputs the calculated first shared key sk o into a random number generator to generate a random number matrix of the same size as the DICOM image;
[0025] S42: The image owner encrypts the random number matrix and the compressed DICOM image using a stream encryption algorithm to obtain an encrypted image in binary stream form, and converts the total embedding capacity of the compressed DICOM image into binary and writes it as an embedding marker into the header of the encrypted image, so that the data embedder can directly identify the available embedding space size.
[0026] As a preference of the above first aspect, in step S5, the method for the data embedder to embed the electronic medical record information into the encrypted image is as follows:
[0027] After the data embedder authenticates its identity at the trusted authentication center, it then uses its own private key sk h and the public key pk r of the receiving party to obtain a point KH on the elliptic curve through dot product operation. Finally, the x coordinate of the calculated point KH is processed through the key derivation function to obtain a second shared key, and the electronic medical record data is encrypted using the second shared key. Finally, according to the embedding marker in the header of the encrypted image, the encrypted medical record data is directly embedded into the available embedding space of the encrypted image.
[0028] As a preference of the above first aspect, in step S6, after receiving the encrypted DICOM image embedded with encrypted electronic medical record information, the receiving party needs to first authenticate its identity at the trusted authentication center, and then obtain the public keys pk o , pk h of the image owner and the data embedder respectively from the public key database of the authentication center, and use its own private key sk r to calculate the first shared key and the second shared key, and then restore the original DICOM image and the original electronic medical record data.
[0029] In a second aspect, the present invention provides a medical shared data protection system using an elliptic curve cryptosystem, which is used to implement the medical shared data protection method using an elliptic curve cryptosystem as described in any one of the above first aspects.
[0030] In a third aspect, the present invention provides a computer electronic device, which includes a memory and a processor;
[0031] The memory is used to store computer programs;
[0032] The processor is configured to, when executing the computer program, implement the medical shared data protection method using the elliptic curve cryptosystem as described in any one of the above first aspects.
[0033] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0034] The present invention proposes a medical data protection method based on the elliptic curve cryptosystem. By combining ECC with technologies such as data compression and information hiding, it realizes all-round protection of DICOM medical images and electronic medical records. This solution not only ensures the security of the data transmission process, but also realizes the efficient compression and controllable access of medical data, providing a feasible solution for secure data sharing among medical institutions. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 is a flowchart of the present invention;
[0036] Figure 2 is the effect diagram of DICOME image encryption and decryption;
[0037] Figure 3 are four DICOME test images;
[0038] Figure 4 are the effect diagrams of four DICOME image embedding strategies;
[0039] Figure 5 is a schematic diagram of a computer electronic device. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] For the convenience of those of ordinary skill in the art to understand and implement the present invention, the following further describes the present invention in detail with reference to the accompanying drawings. It should be understood that the embodiments described herein are only for explaining and illustrating the present invention, and are not used to limit the present invention.
[0041] The following further describes the specific implementation of the present invention in detail with reference to the accompanying drawings:
[0042] In a preferred embodiment of the present invention, a method for protecting medical shared data (including DICOM medical images and electronic medical records) using the elliptic curve cryptosystem is provided, which realizes the efficient compression and controllable access of medical data. As Figure 1 shown, the specific flowchart for implementing this method is as follows:
[0043] S1: After all image owners, data embedders, and receivers participating in data sharing pass the identity authentication of the trusted certification center, the trusted certification center generates elliptic curve public and private key pairs exclusive to each party, consisting of a private key and a public key.
[0044] It should be noted that the Trusted Authority (TA) is an authoritative and trustworthy third-party institution responsible for establishing and maintaining a trust system in the network environment. By issuing and managing digital certificates, the Trusted Authority provides a reliable trust foundation for network communication and ensures information security. The Trusted Authority can be selected according to actual needs.
[0045] In addition, it should be noted that the above image owner, data embedder, and recipient are defined according to their role functions in the medical data sharing process. Generally speaking, the image owner can be an institution that owns DICOM medical images, such as the primary hospital; the data embedder is a person or institution that embeds medical records such as diagnosis opinions and electronic medical records into encrypted data, such as a consultation expert; the recipient can be a person or institution that receives the encrypted medical data, such as the attending physician of the patient. The image owner, data embedder, and recipient can all participate in the entire process of the present invention through their respective clients.
[0046] In step S1 of this embodiment, the Trusted Authority generates paired private keys and public keys for the image owner, data embedder, and recipient respectively based on the standard secp256r1 elliptic curve, stores the public keys in the database, and distributes the private keys to the image owner, data embedder, and recipient through a secure channel. The specific method is as follows:
[0047] S11: For the standard secp256r1 elliptic curve E: y 2 =x 3 +ax + b mod p, the Trusted Authority selects a prime number p and a finite field F(p), and determines the base point G(x,y) and its order n, where a,b ∈ F(p). In this embodiment, the prime number p = 17, the elliptic curve parameters a = 2, b = 2, the base point G = (5,1), and n = 19 are selected.
[0048] S12: The medical institution, data embedder, and recipient submit institutional identification, institutional license certificates, and other certification materials to the certification center for identity authentication applications.
[0049] S13: After the certification center verifies the identity information of the three parties, it randomly generates private keys sk o , sk h , sk r ∈[1,n - 1], and calculates the corresponding public keys pk o =sk o ·G, pk h =sk h ·G, pk r =sk r ·G, and stores the public keys in the database.
[0050] S14: The certification center transmits the private keys sk o , sk h , sk r to the image owner, data embedder, and recipient respectively through a secure channel.
[0051] S2: The image owner uses its own private key and the recipient's public key to generate a first shared key through the elliptic curve Diffie-Hellman key exchange protocol.
[0052] In step S2 of this embodiment, the method for the image owner to generate a shared key through the elliptic curve Diffie-Hellman key exchange protocol is as follows:
[0053] S21: The image owner performs identity verification at the trusted certification center.
[0054] The trusted certification center can select the identity verification method for each participating party as needed, such as username and password authentication, hardware token authentication, digital certificate authentication, etc. The choice of identity verification method should be comprehensively considered based on specific security requirements, user convenience, system environment, and other factors. At the same time, to ensure the security and reliability of identity verification, it is recommended to adopt a strategy of combining multiple identity verification methods to provide multi-level security protection.
[0055] S22: After the identity verification is passed, the image owner obtains the recipient's public key pk r .
[0056] S23: The image owner uses its own private key sk o and the recipient's public key pk r , and calculates the point KO on the elliptic curve through dot product operation KO = sk o ·pk r = sk o ·(sk r ·G).
[0057] S24: The x coordinate KO of the point KO x is processed through the key derivation function KDF to obtain the first shared key sk' o = KDF(KO x ), where KDF is the SHA-256 hash function.
[0058] S3: The image owner separates the DICOM file into image data and metadata, and applies a lossless compression algorithm to the image data for compression to obtain the compressed DICOM image.
[0059] In an embodiment of the present invention, a DICOM medical image with a size of 512×512 and a depth of 16 - bit is selected as the original image data for compression.
[0060] In step S3 of this embodiment, the method for the image owner to compress the DICOM image using a lossless compression algorithm is as follows:
[0061] S31: The image owner divides the DICOM image into image blocks of size 16×16. For each image block, the image owner tries 3 different strategies to calculate the total embedding amount of the current block, so as to find the embedding strategy with the largest total embedding amount for each image block. The difference between the 3 strategies lies in whether the image block needs to be divided. The first embedding strategy embeds the entire 16×16 - sized image block as a whole. The second embedding strategy further splits the 16×16 - sized image block into 4 sub - image blocks of size 8×8 and then embeds them separately. The third embedding strategy further splits the 16×16 - sized image block into 16 sub - image blocks of size 4×4 and then embeds them separately.
[0062] In this embodiment, the embedding space and the total capacity calculation methods under the 3 different embedding strategies are as follows:
[0063] Strategy 1: The pixel at the center of the 16×16 - sized image block is used as the reference pixel, and the remaining pixels are embeddable pixels. Compare which bit of the most significant bit (MSB) the embeddable pixel starts to be different from the reference pixel, and use this bit of the MSB and all the previous MSBs as the embedding space. The sum of the embedding space sizes of all embeddable pixels is used as the total embedding amount of the first embedding strategy (that is, the embedding space size of each embeddable pixel is the number of the same MSB bits between the embeddable pixel and the reference pixel plus 1). In this embodiment, since there are 4 pixels at the center of the 16×16 - sized image block, the pixel at the upper left corner of these 4 pixels can be selected as the center pixel, that is, the coordinate of the reference pixel in each image block is (8, 8).
[0064] Strategy 2: Split the 16×16 image block into 4 sub-image blocks of 8×8. Take the pixel at the center of each sub-image block as the reference pixel, and the remaining pixels in the sub-image block as embeddable pixels. Compare from which most significant bit (MSB) the embeddable pixel in each sub-image block is different from the reference pixel in the same image block, and take this MSB and all the previous MSBs as the embedding space (that is, the embedding space size of each embeddable pixel is the number of the same MSBs between the embeddable pixel and the reference pixel plus 1). Take the sum of the embedding space sizes of all embeddable pixels in the 4 sub-image blocks of 8×8 as the total embedding amount of the second embedding strategy. In this embodiment, since there are also 4 pixels at the center of the 8×8 image block, the pixel at the upper left corner among these 4 pixels can be selected as the central pixel, that is, the coordinate of the reference pixel in each image block is (4, 4).
[0065] Strategy 3: Split the 16×16 image block into 16 sub-image blocks of 4×4. Take the pixel at the center of each sub-image block as the reference pixel, and the remaining pixels in the sub-image block as embeddable pixels. Compare from which most significant bit (MSB) the embeddable pixel in each sub-image block is different from the reference pixel in the same image block, and take this MSB and all the previous MSBs as the embedding space (that is, the embedding space size of each embeddable pixel is the number of the same MSBs between the embeddable pixel and the reference pixel plus 1). Take the sum of the embedding space sizes of all embeddable pixels in the 16 sub-image blocks of 4×4 as the total embedding amount of the third embedding strategy. In this embodiment, since there are also 4 pixels at the center of the 4×4 image block, the pixel at the upper left corner among these 4 pixels can be selected as the central pixel, that is, the coordinate of the reference pixel in each image block is (2, 2).
[0066] It should be noted that in the above Strategy 2 and Strategy 3, since there is a reference pixel inside each sub-image block, for the remaining embeddable pixels in each sub-image block except the reference pixel, the embedding space needs to be determined based on the reference pixel of this sub-image block itself, rather than based on the reference pixels of other sub-image blocks.
[0067] S32: For each 16×16 image block, the image owner selects the strategy with the largest embedding amount and marks the current image block with the strategy. In this embodiment, the marks of the three strategies are (00, 01, 11) respectively, and each image block finally has only 1 strategy mark. After all image blocks are marked with strategy marks, the image owner compresses the MSBs of all embeddable pixels in the image block using Huffman coding according to the embedding strategy corresponding to the strategy mark, and rearranges the bit planes of the compressed image in the order from the least significant bit (LSB) to the most significant bit (MSB), while filling all the compressed embedding space parts with random numbers to form a compressed image in the form of a binary stream.
[0068] In this embodiment, the depth of each embeddable pixel is 16-bit. After comparing the MSBs, there are a total of 17 cases, indicating from which MSB the embeddable pixel and the reference pixel start to be different. After counting the available MSB frequencies of all embeddable pixels, the huffmandict function provided by MATLAB is used to generate a Huffman table, and the obtained Huffman labels are used to replace the redundant MSBs of each embeddable pixel. Finally, the image owner marks the compressed image according to the strategy of all blocks, and arranges the complete Huffman table, the Huffman labels of all embeddable pixels, the remaining LSBs of all embeddable pixels, and all complete reference pixels from the 16th bit plane to the 1st bit plane of the image.
[0069] It should be noted that during the process of rearranging the bit planes, the bit planes should be arranged one by one in the order from LSB to MSB. After one bit plane is arranged, the next bit plane is arranged, forming a compressed image in the form of a binary stream. Moreover, the lowest LSB is arranged at the end and arranged in the order from back to front. Therefore, the binary stream header of the compressed DICOM image is actually random numbers, and this part can be used to embed electronic medical record information.
[0070] S4: The image owner uses the first shared key sk′ o to encrypt the compressed DICOM image to obtain an encrypted DICOM image.
[0071] In step S4 of this embodiment, the method for the image owner to encrypt the compressed DICOM image is as follows:
[0072] S41: The image owner puts the calculated first shared key sk′ o into a random number generator to generate a random number matrix with the same size as the DICOM image.
[0073] S42: The image owner uses a stream encryption algorithm to encrypt the random number matrix and the compressed DICOM image to obtain an encrypted image in the form of a binary stream, and converts the total embedding capacity of the compressed DICOM image into binary and writes it as an embedding mark into the header of the encrypted image, so that the data embedder can directly identify the available embedding space size.
[0074] Since the binary stream header of the compressed DICOM image is actually random numbers, in order to facilitate accurately identifying the total embedding capacity of the compressed DICOM image subsequently, a space of log 2 16*M*N bits can be set in the header to record the embedding mark. Since the total embedding capacity of the compressed DICOM image cannot exceed log2 16 * M * N. Therefore, after converting the total embedding capacity into binary, add 0s in front to make it up to the length of log 2 16 * M * N, and then record it as a direct embedding marker. Subsequently, the data embedder can directly read this log 2 16 * M * N bits of binary data and convert it into the total embedding capacity. In the embodiment of the present invention, since the size of the DICOM image is 512 * 512, after the image owner uses the exclusive OR operation on the compressed image and the random number matrix to obtain the encrypted image, the log 2 16 * 512 * 512 = 22 bits can be used to mark the length of the available redundant space of the bit plane of the first (MSB) of the encrypted image.
[0075] S5: The data embedder uses its own private key and the public key of the recipient to generate a second shared key, encrypts the electronic medical record information, embeds it into the encrypted DICOM image, and then sends it to the recipient.
[0076] In step S5 of this embodiment, the method for the data embedder to embed the electronic medical record information into the encrypted image is as follows:
[0077] S51: The data embedder performs identity verification at the trusted authentication center. As mentioned before, the identity verification method of the trusted authentication center can also be selected according to actual needs.
[0078] S52: After passing the verification, the data embedder obtains the public key pk r of the recipient from the public key database of the authentication center, and uses the private key sk h to calculate the point KH on the elliptic curve through dot product operation, KH = sk h · pk r = sk h · (sk r · G).
[0079] S53: The data embedder processes the x - coordinate KO x of the point KH through the key derivation function KDF (SHA - 256 hash function) to obtain the second shared key sk′ h = KDF(KO x ), and encrypts the electronic medical record data using the second shared key sk′ h . It should be noted that the form of the electronic medical record data can be diverse. For example, the QR code link of the electronic medical record data or the image of the electronic medical record data can be selected.
[0080] S54: The data embedder directly embeds the encrypted medical record data into the available embedding space of the encrypted image according to the embedding marker in the encrypted image header.
[0081] S6: The recipient uses its private key and the public keys of the data embedder and the image owner to reconstruct the shared key to extract the embedded EMR information, and reconstructs the original DICOM medical image through a lossless decompression algorithm.
[0082] In step S6 of this embodiment, the method for the recipient to use its private key and the public keys of the data embedder and the image owner to reconstruct the shared key to extract the embedded EMR information and reconstruct the original DICOM medical image through a lossless decompression algorithm is as follows:
[0083] S61: The recipient conducts identity authentication at the trusted certification center. As mentioned before, the identity authentication method of the trusted certification center can also be selected according to actual needs.
[0084] S62: After the identity authentication is passed, the recipient obtains the public key pk o of the image owner and the public key pk h of the data embedder from the public key database of the certification center, and uses its own private key sk r to calculate the points KO and KH on the elliptic curve corresponding to the two shared keys respectively, and then calculates the first shared key sk′ o and the second shared key sk′ h through dot product operation. The calculation of the first shared key sk′ o and the second shared key sk′ h is still generated through the elliptic curve Diffie-Hellman key exchange protocol using the recipient's own private key and the public keys of the image owner and the data embedder. The specific method is as mentioned before and will not be elaborated here.
[0085] S63: The recipient can restore the original DICOM image and the original EMR data by using the first shared key sk′ o and the second shared key sk′ h . This restoration process is the reverse process of the aforementioned steps S2 to S5, and can be achieved by performing the corresponding reverse operations, which will not be elaborated here.
[0086] The method described in S1 - S6 of the present invention can be applied to a remote consultation platform for multiple medical institutions to safely share and transmit patients' medical images and diagnosis and treatment records. First, each medical institution obtains its exclusive public - private key pair through a trusted third - party certification authority and stores the public key in the certification center. Secondly, the image owner (such as the primary diagnosis hospital) performs prediction - based lossless compression on DICOM medical images and uses elliptic curve encryption technology to protect the compressed data. Subsequently, the consultation expert generates a shared key using the recipient's public key and their own private key, and embeds medical records such as diagnosis opinions and electronic medical records into the encrypted data. Finally, the recipient (such as the patient's attending physician) reconstructs the shared key through their own private key and the public keys of the image owner and the data embedder to achieve lossless reconstruction of medical images and extraction of medical records. The present invention realizes hierarchical authorization access while ensuring the integrity of medical images, not only supports secure data sharing during multi - party consultations, but also protects patient privacy. At the same time, the present invention uses lossless compression technology to reduce data transmission overhead and improve the operating efficiency of the remote medical platform. In addition, the hierarchical authorization mechanism of the present invention ensures that medical staff at different levels can only access medical data within their authority, effectively preventing the leakage of sensitive information and is applicable to cross - institutional remote medical cooperation scenarios.
[0087] To further demonstrate the technical effects of the present invention, the following gives the specific application results of the method shown in S1 - S6 above in actual cases.
[0088] Embodiment
[0089] This embodiment conducts experiments based on the method shown in S1 - S6 above. The specific implementation steps are as described above and will not be elaborated here. Only the experimental results are shown below.
[0090] i. Performance analysis
[0091] Figure 2 Taking a DICOME image as an example, the corresponding results after embedding the confidential QR code are given. Among them Figure 2 (a) is the link QR code image of the electronic medical record to be embedded (where part of the QR code area is blurred due to privacy concerns), (b) is the original DICOME image, (c) is the encrypted DICOME image, (d) is the encrypted DICOME image after embedding the QR code image, and (e) and (f) are the losslessly extracted link QR code image and the restored DICOME image respectively. Obviously, the encrypted image does not retain any useful information in the plain - text image, and the encrypted image containing confidential information does not expose any QR code information, which makes it impossible for attackers to crack any useful information. In addition, Figure 3Four exemplary DICOM test images are shown. After selecting the strategy with the largest embedding amount for these four DICOM test images according to the aforementioned step S3, the distribution of the optimal strategy labels (BestStrategy Distribution) of all 16*16 image blocks at different rows (Block Row) and columns (Block Column) in the images is as Figure 4 shown ( Figure 4 The color bar of Figure 4 is continuous, but the actually used strategy labels are only three discrete values: 1, 2, and 3).
[0092] In addition, to show the effect comparison between the present invention and other existing data protection methods, Table 1 shows the comparison of the embedding amounts between the present invention and some of the latest similar methods. It can be seen that the embedding amount of the present invention is far better than that of other methods.
[0093] Table 1 Comparison results between the present invention and other methods
[0094]
[0095] For the specific methods [1] and [2] in the above comparison, please refer to the following literature:
[0096] [1] Dzwonkowski, M. and Czaplewski, B., 2022. “Reversible data hiding in encrypted DICOM images using sorted binary sequences of pixels.” Signal Processing, 199, p. 108621.
[0097] [2] Panchikkil, S., Manikandan, V.M., Pratim Roy, P., Wang, S. and Zhang, Y., 2024. “An adaptive block-wise prediction error-based (AdaBPE) reversible data hiding in encrypted images for medical image transmission.” CAAI Transactions on Intelligence Technology.
[0098] Similarly, based on the same inventive concept, the present invention provides a computer program product, including computer programs / instructions, which, when executed by a processor, can implement the medical shared data protection method using the elliptic curve cryptosystem as described above. This computer program product can be a system in the form of software, that is, corresponding to a medical shared data protection system using the elliptic curve cryptosystem.
[0099] In addition, when the logical instructions in the above-mentioned memory are implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention.
[0100] Thus, based on the same inventive concept, the present invention provides a computer-readable storage medium corresponding to a medical shared data protection method using the elliptic curve cryptosystem. A computer program is stored on the storage medium, and when the computer program is executed by a processor, it can implement the medical shared data protection method using the elliptic curve cryptosystem as described above.
[0101] Thus, based on the same inventive concept, as Figure 5 shown, the present invention further provides a computer electronic device corresponding to a medical shared data protection method using the elliptic curve cryptosystem provided in the above embodiment. It includes a memory and a processor;
[0102] The memory is used to store computer programs;
[0103] The processor is used to, when executing the computer program, be able to implement the medical shared data protection method using the elliptic curve cryptosystem as described above.
[0104] Specifically, in the computer-readable storage media of the above three embodiments, the stored computer programs are executed by a processor, and the steps of S1 to S4 described above can be executed.
[0105] It can be understood that the above storage medium can include a random access memory (RAM), and can also include a non-volatile memory (NVM), such as at least one disk memory. At the same time, the storage medium can also be various media such as a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc that can store program codes.
[0106] It can be understood that the above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0107] In addition, it should be noted that those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the above-described system can refer to the corresponding process in the foregoing method embodiments, and will not be elaborated herein. In the various embodiments provided in the present application, the division of steps or modules in the system and method is only a logical function division, and there may be other division methods in actual implementation. For example, multiple modules or steps can be combined or integrated together, and a module or step can also be split.
[0108] The above-described embodiments are only a preferred solution of the present invention, but they are not intended to limit the present invention. Those of ordinary skill in the relevant art can still make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, all technical solutions obtained by adopting equivalent replacement or equivalent transformation fall within the protection scope of the present invention.
Claims
1. A method for protecting medical shared data using elliptic curve cryptography, wherein the medical shared data includes DICOM medical images and electronic medical records, characterized in that: The specific steps of this method are as follows: S1: After all image owners, data embedders, and recipients participating in data sharing have passed identity authentication by a trusted authentication center, the trusted authentication center will generate an elliptic curve public-private key pair consisting of a private key and a public key for each party; S2: The image owner uses his own private key and the recipient's public key to generate a first shared key through the elliptic curve Diffie-Hellman key exchange protocol; S3: The image owner separates the DICOM file into image data and metadata, and compresses the image data using a lossless compression algorithm to obtain a compressed DICOM image; S4: The image owner encrypts the compressed DICOM image using the first shared key to obtain an encrypted DICOM image; S5: The data embedder uses its own private key and the recipient's public key to generate a second shared key, which is used to encrypt the electronic medical record information and then embed it into the encrypted DICOM image, which is then sent to the recipient; S6: The receiver uses its private key and the public keys of the data embedder and the image owner to reconstruct the shared key to extract the embedded electronic medical record information and reconstruct the original DICOM medical image through a lossless decompression algorithm.
2. A method for protecting medical shared data using elliptic curve cryptography according to claim 1, characterized in that: In S1, the trusted authentication center generates pairs of private keys and public keys for the image owner, data embedder and recipient respectively based on the standard secp256r1 elliptic curve, and stores the public keys in the database, while the private keys are distributed to the image owner, data embedder and recipient through a secure channel.
3. A method for protecting medical shared data using elliptic curve cryptography according to claim 2, characterized in that: In S2, after the image owner authenticates his identity at the trusted authentication center, he obtains the recipient's public key pk from the public key database of the authentication center. r , and then use its own private key sk o and the recipient's public key pk r The point KO on the elliptic curve is obtained by point multiplication operation, and finally the x coordinate of the calculated point KO is processed by a key derivation function to obtain the first shared key, wherein the key derivation function adopts the SHA-256 hash function.
4. A method for protecting medical shared data using elliptic curve cryptography according to claim 3, characterized in that: In S3, the method in which the image owner uses a lossless compression algorithm to compress the image data is as follows: S31: The image owner divides the DICOM image into image blocks of 16×16 size, and calculates the total embedding amount corresponding to each image block under three different embedding strategies; the first embedding strategy embeds the image block of 16×16 size as a whole, the second embedding strategy further splits the image block of 16×16 size into 4 sub-image blocks of 8×8 size and then embeds them separately, and the third embedding strategy further splits the image block of 16×16 size into 16 sub-image blocks of 4×4 size and then embeds them separately; S32: For each 16×16 image block, the image owner selects the embedding strategy with the largest embedding amount, and uses the strategy selected by Huffman coding to compress the MSB of all embeddable pixels in the image block, and then rearranges the bit planes of the compressed image in order from LSB to MSB, and fills the compressed embedding space with random numbers to form a compressed image in the form of a binary stream.
5. A method for protecting medical shared data using elliptic curve cryptography according to claim 4, characterized in that: The calculation methods of embedding space and total capacity under three different embedding strategies are as follows: The first embedding strategy uses the pixel at the center of the 16×16 image block as the reference pixel, and the remaining pixels as embeddable pixels. It compares which MSB each embeddable pixel starts with and the reference pixel, and uses this MSB and all previous MSBs as the embedding space. The sum of the embedding space sizes of all embeddable pixels is taken as the total embedding amount of the first embedding strategy. The second embedding strategy splits the 16×16 image block into four 8×8 sub-image blocks, takes the pixel at the center of each sub-image block as the reference pixel, and the remaining pixels in the sub-image block as the embeddable pixels. Compare which MSB each embeddable pixel starts to differ from the reference pixel in the same image block, and take this MSB and all the previous MSBs as the embedding space. The sum of the embedding space sizes of all embeddable pixels is taken as the total embedding amount of the second embedding strategy. The third embedding strategy splits the 16×16 image block into 16 4×4 sub-image blocks, takes the pixel at the center of each sub-image block as the reference pixel, and the remaining pixels in the sub-image block as the embeddable pixels. Each embeddable pixel is compared with the reference pixel in the same image block to see which MSB starts to differ, and uses this MSB and all previous MSBs as the embedding space. The sum of the embedding space sizes of all embeddable pixels is taken as the total embedding amount of the third embedding strategy.
6. A method for protecting medical shared data using elliptic curve cryptography according to claim 1, characterized in that: In S4, the method in which the image owner encrypts the compressed DICOM image is as follows: S41: The image owner calculates the first shared key sk o Input the random number generator to generate a random number matrix with the same size as the DICOM image; S42: The image owner uses a stream encryption algorithm to encrypt the random number matrix and the compressed DICOM image to obtain an encrypted image in the form of a binary stream, and converts the total embedding capacity of the compressed DICOM image into binary and writes it into the header of the encrypted image as an embedding mark, so that the data embedder can directly identify the available embedding space size.
7. A method for protecting medical shared data using elliptic curve cryptography according to claim 5, characterized in that: In S5, the method by which the data embedder embeds the electronic medical record information into the encrypted image is as follows: After the data embedder authenticates the identity of the trusted authentication center, he uses his own private key sk h and the recipient's public key pk r The point KH on the elliptic curve is obtained by point multiplication operation, and finally the x coordinate of the calculated point KH is processed by the key derivation function to obtain the second shared key, and the second shared key is used to encrypt the electronic medical record data. Finally, the encrypted medical record data is directly embedded into the available embedding space of the encrypted image according to the embedding mark in the encrypted image header.
8. A method for protecting medical shared data using elliptic curve cryptography according to claim 6, characterized in that: In S6, after receiving the encrypted DICOM image embedded with the encrypted electronic medical record information, the receiver must first authenticate the identity of the trusted authentication center and obtain the public keys pk of the image owner and the data embedder from the public key database of the authentication center. o ,pk h , and use its own private key sk r The first shared key and the second shared key are calculated, and then the original DICOM image and the original electronic medical record data are restored.
9. A medical shared data protection system using elliptic curve cryptography, characterized in that: Used to implement the medical shared data protection method using the elliptic curve cryptography system as described in any one of claims 1 to 8.
10. A computer electronic device, characterized in that: including memory and processor; The memory is used to store computer programs; The processor is used to implement the medical shared data protection method using the elliptic curve cryptography system as described in any one of claims 1 to 8 when executing the computer program.