A blockchain-based method for secure data storage and verification

By leveraging blockchain technology's dynamic key generation, segmented hash value storage, and IoT positioning adjustments, combined with distributed storage, the problems of static key leakage and fine-grained data protection in existing encryption technologies are solved, achieving high security and flexible access control for medical data.

CN120150937BActive Publication Date: 2026-01-30QINGDAO HAICHUANG CHAIN DIGITAL TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510216085.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2026-01-30
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

Existing encryption technologies rely on static keys or a single algorithm, which are easily leaked and cannot achieve fine-grained data protection and dynamic access control, especially in the management of sensitive data in the medical field.

Method used

It adopts a blockchain-based dynamic key generation and update mechanism, combined with segmented hash value storage and homomorphic encryption technology, adjusts access permissions through IoT positioning and device status, and uses distributed storage technology to prevent data tampering and recovery.

Benefits of technology

It achieves dynamic encrypted security management of data, ensuring high security and reliability of data during storage, access and recovery, preventing timeout access risks, and improving the reliability and flexibility of data recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150937B_ABST
    Figure CN120150937B_ABST
Patent Text Reader

Abstract

This application relates to the field of data transmission technology, specifically disclosing a blockchain-based data security storage and verification method. The method involves collecting biometric data to generate a first dynamic key, which is used to encrypt first data and updated upon each access to ensure key timeliness. The first data is logically divided into multiple segments, generating segmented hash values ​​and storing them on the blockchain. Corresponding segments are dynamically loaded according to user permissions, and anonymous verification is achieved through homomorphic encryption. Based on IoT technology, combined with first positioning parameters and first status parameters, access permissions are dynamically adjusted, and a self-destruct flag is set to avoid timeout access risks. During the storage of data segments, distributed storage, dynamic security scoring, and path adjustment are employed. This invention not only solves the static problems in data storage and access control but also provides more flexible and reliable security guarantees in dynamic access scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data transmission technology, and more specifically, to a blockchain-based method for secure data storage and verification. Background Technology

[0002] With the rapid development of information technology, data storage and transmission have become core issues that cannot be ignored in modern society. Especially in fields such as healthcare and finance, data security and privacy protection have become critical issues that urgently need to be addressed. In recent years, blockchain technology, due to its decentralized, immutable, and transparent characteristics, has been increasingly applied to various data storage and verification scenarios. By encrypting and storing data and distributively recording it on the blockchain, blockchain can provide data integrity guarantees and effectively prevent the risks of data tampering and leakage. Furthermore, with the development of IoT technology, smart devices and sensors can provide real-time and accurate data support, which offers new possibilities for realizing intelligent data management and security verification based on the IoT.

[0003] However, despite the progress made in secure data storage, existing technologies still have many shortcomings. For example, while traditional encryption technologies can guarantee data confidentiality, they mostly rely on static keys or a single encryption algorithm, making them vulnerable to key leakage or cracking. Furthermore, existing encryption algorithms are mostly used for overall data encryption and cannot achieve fine-grained protection of data, particularly exhibiting significant deficiencies in the dynamic management and access control of sensitive data. Summary of the Invention

[0004] This application is made in order to solve the above-mentioned technical problems.

[0005] According to one aspect of this application, a blockchain-based data security storage and verification method is provided, comprising: collecting biometric features, generating a first dynamic key, the first dynamic key being used to encrypt first data and being updated upon each access to ensure key timeliness; logically dividing the first data into multiple segments, generating segmented hash values ​​and storing them on the blockchain; dynamically loading corresponding segments according to user permissions and achieving anonymous verification through homomorphic encryption technology; dynamically adjusting access permissions based on Internet of Things technology, combined with first positioning parameters and first state parameters, and setting a self-destruct flag to avoid the risk of timeout access; and ensuring the security and integrity of medical record data during storage, access, and recovery through distributed storage, dynamic security scoring, and path adjustment during the storage of data segments.

[0006] Furthermore, the generation of the first dynamic key includes: converting the biometric features into a digital representation; generating a random factor, which will participate in the encryption process together with the patient's biometric information; using an encryption algorithm to combine the biometric information and the random factor to generate a key, which serves as the first dynamic key; and binding the generated first dynamic key with the patient's basic information.

[0007] Furthermore, the first data is the patient's medical record data, including diagnostic information, treatment records, and imaging data.

[0008] Furthermore, dividing the first data into multiple segments logically includes: dividing the medical record data based on different data types, data importance, or access requirements; each segment corresponds to a logical unit and generates a unique identifier for it; each segment corresponds to different encrypted data, and for each segment, its hash value is generated to ensure data integrity and tamper-proofness.

[0009] Furthermore, the step of dynamically loading corresponding fragments based on user permissions includes: when each user accesses the system, they need to verify their identity through authentication; after verification, the user's permission information is loaded; according to the configured permission management policy, the user's identity is compared with the access permissions of the medical record data fragments; if the access permissions of a certain data fragment match the user's identity, then loading the data fragment is allowed; once the permissions are confirmed, the data fragments that the user has permission to access are dynamically loaded.

[0010] Furthermore, the dynamically adjusted access permissions include the following: Location and spatial management are achieved within the hospital using Beacon technology. When a patient or doctor enters a designated fenced area with a Beacon-enabled device, their identity is automatically identified through location information. Multiple Beacon beacons are deployed within the hospital to create a location matrix encompassing various treatment areas. The devices carried by patients and doctors periodically scan for nearby Beacon signals. Each Beacon beacon periodically broadcasts its unique identifier and signal strength. The specific location of the patient's or doctor's device is calculated using the received signal strength and the relative position of the Beacon beacon, combined with a triangulation algorithm. Finally, a configured virtual fence is used to determine whether the patient's or doctor's location meets the specified conditions.

[0011] Furthermore, the dynamic adjustment of access permissions also includes the following: Access permissions for medical record data will be dynamically adjusted based on the following two main factors: the relative positions of the patient and the doctor, and device status monitoring. The relative positions of the patient and the doctor include: viewing medical record data will only be allowed when the patient and the doctor are within the authorized treatment area; at the same time, the treatment area where the patient is located will be matched with the doctor's identity to ensure that only doctors with access permissions can obtain medical record data. Device status monitoring includes: the status of medical equipment also plays an important role in the access permissions for medical record data; if the equipment is faulty or offline, valid medical record data cannot be provided.

[0012] Furthermore, the distributed storage technology includes: storing the data fragments on multiple nodes or servers respectively; encrypting each data fragment to ensure that even if an attacker obtains part of the data fragment, they cannot recover the complete data; each data fragment has an independent encryption key, and the association information between different fragments is removed or hidden, thereby preventing the data from being easily reassembled.

[0013] Furthermore, automatically adjusting the storage path of data fragments includes: selecting an appropriate recovery path based on the security score of the data fragment and the security of the storage node; automatically adjusting the recovery path if the storage path of some data fragments is risky or abnormal; and extracting data fragments from different storage nodes in sequence during data recovery and splicing them together in a specific order to ensure the correctness and legality of data recovery.

[0014] Furthermore, the automatic adjustment of the storage path for data fragments also includes: during the data recovery process, periodically evaluating the security score of each storage node; if the security score of a storage node is lower than a preset threshold, the node is considered to be at risk, and the data recovery path needs to be adjusted; if the path is adjusted, fragments that originally depended on high-risk storage nodes need to be relocated, storage nodes are reassigned, and the recovery path score is updated; by assigning to safer nodes, it is ensured that the data recovery process does not recover from potentially dangerous nodes; during the data splicing process, a legality verification mechanism ensures that the recovered data meets the integrity requirements.

[0015] Compared to existing technologies, this application provides a blockchain-based data security storage and verification method. Through a dynamic key generation and update mechanism, combined with the generation and on-chain storage of segmented hash values, it proposes a method that can both ensure data encryption security and dynamically manage access permissions. By utilizing IoT technology and dynamic adjustments based on location and device status, it can not only control data access permissions in real time but also avoid the security risks of timed-out access. Furthermore, this invention combines distributed storage technology to achieve data fragmentation and irreversible reassembly, greatly improving the reliability and security of data recovery. Compared to existing technologies, this invention not only solves the static problems in data storage and access control but also provides more flexible and reliable security guarantees in dynamic access scenarios. Through multi-layered security mechanisms, it ensures high security and high availability of data during storage, access, and recovery. Attached Figure Description

[0016] The above and other objects, features, and advantages of this application will become more apparent from the more detailed description of the embodiments of this application in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the embodiments of this application to explain this application and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0017] Figure 1 This is a flowchart of a blockchain-based data security storage and verification method according to an embodiment of this application.

[0018] Figure 2 This is a flowchart of step S4 in the blockchain-based data security storage and verification method according to an embodiment of this application. Detailed Implementation

[0019] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0020] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0021] In the description of embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.

[0022] It is worth noting that all actions to acquire signals, information, or data in this application are carried out in compliance with the relevant data protection laws and policies of the country where the application is located, and with the authorization granted by the owner of the relevant device.

[0023] With the rapid development of information technology, data storage and transmission have become core issues that cannot be ignored in modern society. Especially in fields such as healthcare and finance, data security and privacy protection have become critical issues that urgently need to be addressed. In recent years, blockchain technology, due to its decentralized, immutable, and transparent characteristics, has been increasingly applied to various data storage and verification scenarios. By encrypting and storing data and distributively recording it on the blockchain, blockchain can provide data integrity guarantees and effectively prevent the risks of data tampering and leakage. Furthermore, with the development of IoT technology, smart devices and sensors can provide real-time and accurate data support, which offers new possibilities for realizing intelligent data management and security verification based on the IoT.

[0024] However, despite the progress made in secure data storage, existing technologies still have many shortcomings. For example, while traditional encryption technologies can guarantee data confidentiality, they mostly rely on static keys or a single encryption algorithm, making them vulnerable to key leakage or cracking. Furthermore, existing encryption algorithms are mostly used for overall data encryption and cannot achieve fine-grained protection of data, particularly exhibiting significant deficiencies in the dynamic management and access control of sensitive data.

[0025] Our invention proposes a method that ensures both data encryption security and dynamic access control through a dynamic key generation and update mechanism, combined with segmented hash value generation and on-chain storage. By leveraging IoT technology and dynamic adjustments based on location and device status, it not only enables real-time control of data access permissions but also avoids the security risks of timeout access. Furthermore, by incorporating distributed storage technology to achieve data fragmentation and irreversible reassembly, this invention significantly improves the reliability and security of data recovery. Compared to existing technologies, this invention not only solves static problems in data storage and access control but also provides more flexible and reliable security guarantees in dynamic access scenarios. Through multi-layered security mechanisms, it ensures high security and high availability of data during storage, access, and recovery.

[0026] Figure 1 This is a flowchart of a blockchain-based data security storage and verification method according to an embodiment of this application. Figure 1 As shown, the blockchain-based data security storage and verification method according to an embodiment of this application includes the following steps:

[0027] S1: Collect biometric data and generate a first dynamic key. This first dynamic key is used to encrypt the first data, i.e., the patient's medical record, and is updated on each access to ensure key timeliness. S2: Logically divide the first data into multiple segments, generate segmented hash values, and store them on the blockchain. Dynamically load the corresponding segments according to user permissions and achieve anonymous verification through homomorphic encryption technology. S3: Based on IoT technology, combined with the first location parameter (patient / doctor location) and the first status parameter (device status), dynamically adjust access permissions and set a self-destruct flag to avoid the risk of timeout access. S4: During the storage of data segments, ensure the security and integrity of medical record data during storage, access, and recovery through distributed storage, dynamic security scoring, and path adjustment.

[0028] In this embodiment, step S1 is used to generate a first dynamic key by collecting and processing the patient's biometrics, and to encrypt and store the patient's medical record data to ensure the security, integrity, and verifiability of the data. This process not only provides high security for subsequent data access, but also ensures the timeliness of the key by dynamically updating it each time access is accessed, thereby effectively preventing the risk of key theft or leakage.

[0029] Specifically, when a patient first arrives at a medical institution for treatment, their biometric data is collected through medical devices or applications. Biometric data refers to biological information that can uniquely identify a patient, such as fingerprints, iris scans, facial images, finger veins, voice, and DNA. This information is typically highly unique and difficult to forge, making it ideal for generating secure keys.

[0030] For example, hospitals can collect patients' biometrics in the following ways:

[0031] The fingerprint scanner is used to collect the patient's fingerprints, and the unique fingerprint features are extracted using image processing algorithms; the iris scanner is used to collect the patient's iris images, and the unique patterns of the patient's iris are extracted using image recognition technology, etc.

[0032] After biometric data is collected, it undergoes preprocessing to remove noise and extract stable and unique feature information. This feature information will serve as the basis for subsequent encryption operations.

[0033] Furthermore, based on the collected patient biometric data, an encryption algorithm will be used to generate a first dynamic key. The generation of the dynamic key relies on encryption techniques, combining biometrics and a random factor to produce a unique and difficult-to-copy key. This key will be updated with each patient visit to ensure its validity and security.

[0034] For example, the process of generating a dynamic key is as follows:

[0035] First, the patient's biometric information is converted into a digital representation. Taking fingerprints as an example, specific ridges, lines, and feature points are extracted using fingerprint recognition technology to form a set of feature vectors. To increase the complexity of the key, a random factor is generated. This factor participates in the encryption process along with the patient's biometric information, thereby increasing the unpredictability of the key.

[0036] Using encryption algorithms, such as the symmetric encryption algorithm (AES) or the hash algorithm (SHA-256), biometric information and random factors are combined to generate a key.

[0037] The generated first dynamic key will be bound to the patient's basic information (such as name, ID, etc.) and stored in a secure database.

[0038] Optionally, to prevent security risks arising from the long-term validity of keys, a timed update mechanism is designed. The key will be regenerated each time a patient visits, ensuring its timeliness.

[0039] Next, the generated first dynamic key is used to encrypt the patient's medical record data. The patient's medical record data includes, but is not limited to:

[0040] Diagnostic information, including the patient's medical history, diagnostic results, examination reports, etc.;

[0041] Treatment records, including treatment methods, medication use, surgical records, etc.;

[0042] Imaging data, including X-rays, CT scans, MRI images, etc.

[0043] The encrypted medical records will be stored and verified using blockchain technology. Due to the immutable nature of blockchain, patient medical records cannot be arbitrarily altered after storage, thus ensuring data integrity and reliability.

[0044] The timeliness of the key is one of the keys to ensuring security. To prevent security risks caused by the long-term use of keys, this invention designs a dynamic update mechanism:

[0045] Each time a patient accesses the healthcare system, a new initial dynamic key is generated. This new key is still based on the patient's biometric information, but it is generated in conjunction with a new random factor, thus ensuring that the key used each time is unique.

[0046] Key updates can be triggered in the following scenarios: for example, new keys will be automatically generated at regular intervals; when a patient visits for the first time, a brand new key will be generated based on biometrics; if unauthorized access or abnormal operation is detected, the key will be automatically updated and the user will be notified; if the patient changes healthcare providers or requests a key update with higher security, key revocation and replacement operations are supported.

[0047] For example, suppose patient A visits the hospital for the first time and submits fingerprint information for authentication. The hospital's medical information system will perform the following operations:

[0048] The fingerprint information of patient A is collected and fingerprint features are extracted; combined with randomly generated factors, a biometric encryption algorithm is used to generate the first dynamic key for patient A; patient A's medical record data (including diagnostic records, treatment information, etc.) is divided into segments, and each segment is encrypted using the dynamic key; each encrypted data segment generates a hash value and is uploaded to the blockchain network for storage to ensure data security and immutability; each time patient A accesses the data in the future, a new dynamic key will be generated to ensure data security.

[0049] As can be seen, by collecting biometric data and generating a dynamic key during a patient's first visit, this invention effectively safeguards the security and privacy of patient medical record data. The dynamic key update mechanism further ensures the timeliness of data during long-term storage and access, providing a high level of security for subsequent access to and verification of patient information. This process not only complies with data protection regulations but also effectively prevents the risk of external attacks or internal leaks.

[0050] In this embodiment, step S2 is used to logically divide the data encrypted in step S1 into multiple fragments and generate a hash value for each fragment for on-chain storage. This effectively manages different parts of the medical data while ensuring data integrity and privacy during access.

[0051] Furthermore, step S2 introduces homomorphic encryption, which allows verification to be performed without exposing the original data content, thus enabling anonymization of the data verification process. Based on different user permissions, corresponding fragments are dynamically loaded and verified using homomorphic encryption, ensuring that only authorized users can access the relevant data.

[0052] Specifically, after a patient's initial visit and the completion of encrypted data storage, S2's primary task is to logically divide the encrypted medical record data into multiple segments. These segments can be based on different data types, data importance, or access requirements. For example, a patient's medical record may contain diagnostic information, treatment records, medication usage, examination reports, and imaging data. This information can be divided in several ways:

[0053] Data can be categorized based on data type, such as "personal information," "diagnosis information," "treatment records," and "imaging data." It can also be categorized based on access needs, as different doctors or staff may require access to different types of information. For more efficient data storage and access, data can be divided into categories such as "urgent medical information," "long-term medical history," and "imaging examination reports." Some data (such as patient medical history or drug allergy information) may be sensitive and require additional protection measures. This type of data can be segmented separately and encrypted with more stringent encryption strategies.

[0054] Each segment corresponds to a logical unit and is assigned a unique identifier. For example, a treatment record might be divided into "treatment plan segments" and "treatment effect segments," each corresponding to different encrypted data and having a corresponding hash value during storage.

[0055] For each data segment, a hash value is generated to ensure data integrity and tamper resistance. The hash value is a fixed-length "fingerprint" obtained by hashing the data segment. Even if the data content changes slightly, the hash value will change drastically, making it easier to detect whether data tampering has occurred.

[0056] The process of generating segmented hash values ​​is as follows:

[0057] For each logically divided data segment, the system uses a cryptographic hash algorithm (such as SHA-256) to calculate its hash value. The hash algorithm can transform an input (i.e., a data segment) of arbitrary size into a fixed-size output (i.e., a hash value), ensuring data consistency and integrity.

[0058] The generated hash value will be stored using blockchain technology. Due to the immutability of the blockchain, the hash value stored on the blockchain will permanently record the "fingerprint" of the data fragment. Any attempt to tamper with or alter the data will result in a hash value mismatch, thus exposing the data change.

[0059] Each hash value and its corresponding fragment information (such as fragment identifiers) are uploaded to the blockchain network as part of a blockchain transaction. This operation not only improves storage security but also ensures the sharing and verification capabilities of the distributed ledger.

[0060] Through smart contract mechanisms, data operations under specific conditions are executed automatically, such as automatically verifying patient identity, automatically checking data integrity, and automatically updating access records. Each time a data segment is modified or updated, the smart contract triggers the relevant operation, ensuring that each modification leaves an immutable record on the blockchain.

[0061] Furthermore, to ensure efficient data access and prevent unauthorized users from accessing sensitive data, this invention dynamically loads relevant segments from patient medical records based on different user roles and permissions. Here, user access control is determined based on their identity and access needs. For example, doctor A may only have permission to view the patient's "diagnosis information" segment, while doctor B may need to view multiple data segments, including "treatment records."

[0062] For example, the dynamic loading process can be divided into the following steps:

[0063] When a user accesses the system, they must first verify their identity through authentication (such as entering a username and password, biometric identification, etc.). After successful verification, the user's permission information is loaded.

[0064] Based on the configured permission management policy, the user's identity is compared with the access permissions of the medical record data fragments. If the access permissions of a data fragment match the user's identity, loading of that data fragment is permitted.

[0065] Once permissions are confirmed, the data segments that the user is authorized to access are dynamically loaded. If the user's permissions allow viewing multiple segments, the encrypted data for those segments is loaded.

[0066] To further protect patient privacy, step S2 also uses homomorphic encryption to achieve anonymous verification. With homomorphic encryption, operations can be performed on encrypted data without decryption, ensuring that the original information is not exposed even when the data is stored on a server. In other words, only authorized users can verify the authenticity of the data without seeing its plaintext content.

[0067] Homomorphic encryption can perform the following operations in this process:

[0068] The patient's medical record data was encrypted using a dynamic key in step S1. At this point, the encrypted data is stored in a database or blockchain. When a user requests access to the medical record data, the system does not directly decrypt the data, but instead uses homomorphic encryption to calculate and verify the encrypted data. For example, the system can verify whether a data segment meets certain conditions (such as verifying whether a patient has a certain disease) without decrypting the specific content of the data segment. Through homomorphic encryption, the verification operation can be performed while the data remains encrypted. This ensures that even if a user can verify the correctness of the data, they will not directly see the data itself, thus achieving anonymous verification. With the support of homomorphic encryption, it is possible to verify whether a user has permission to access a specific medical record segment without disclosing the patient's medical record information. For example, when Doctor A requests to view "diagnosis information," the system uses encryption verification to ensure that Doctor A indeed has permission to view that segment.

[0069] For example, suppose patient A's medical record contains the following data segments: a diagnostic information segment, including the patient's initial diagnosis and medical history; a treatment record segment, including the patient's treatment plan and completed treatment steps; and an imaging data segment, including the patient's X-ray or CT scan results. Depending on user permissions, doctor B can access the "treatment record" and "imaging data," while doctor A can only view the "diagnostic information." When doctor A requests to view the medical record, the system checks whether the "diagnostic information" segment can be loaded based on permissions. If the permissions are valid, the system verifies the data's legitimacy using homomorphic encryption technology, without needing to decrypt and display the data.

[0070] As can be seen, by logically dividing patient medical record data into multiple segments and storing them using segmented hashing, this step not only effectively improves data access efficiency but also achieves anonymous verification of encrypted data through homomorphic encryption technology. This mechanism ensures the protection of patient privacy while enabling flexible access management and security verification within medical institutions.

[0071] In this embodiment, step S3 further enhances data access security and prevents unauthorized timeout access by dynamically controlling data access permissions through IoT technology, positioning parameters, and device status parameters. By combining these parameters, it is possible to adjust in real time which users and devices can access certain data segments, and trigger a "self-destruct" mechanism under certain conditions to reduce the risk of data leakage and timeout access.

[0072] Specifically, the positioning scheme based on the hospital's electronic fence system establishes a positioning matrix for the treatment space within the hospital using Beacon beacons, enabling real-time monitoring of the locations of patients and doctors. When patients and doctors enter authorized treatment areas, the system automatically activates their digital identity credentials, thereby dynamically adjusting access permissions to ensure that data access is only authorized at appropriate times, locations, and device conditions.

[0073] In this invention, a hospital electronic fence (also called a virtual fence) uses Beacon technology to achieve location and space management within the hospital. A Beacon is a low-power, low-cost, wireless Bluetooth sensor device capable of location tracking within a specific range. When a patient or doctor enters the designated fenced area carrying a Beacon-enabled device, their identity is automatically identified through location information, which then determines whether to grant access to medical record data.

[0074] The hospital deploys multiple Beacon beacons to create a location matrix encompassing various treatment areas (such as wards, operating rooms, and examination rooms). Each Beacon beacon can send a specific signal and transmit its location information wirelessly to the hospital's central server. This server can collect data from all beacons in real time and calculate the relative position of devices (such as patients or doctors) with respect to these beacons.

[0075] The system determines whether the patient and doctor are within an authorized treatment area based on their location, and decides whether to grant them access to medical records based on this information. For example, the patient must be in a designated ward and the doctor must be within an authorized work area to unlock access to medical records.

[0076] Beacon beacons do not rely on traditional GPS positioning systems, but instead use Bluetooth Low Energy (BLE) technology for indoor positioning. Specifically, the positioning process can be divided into the following steps:

[0077] Patients and doctors carry devices (such as smartphones or wearable devices) that periodically scan for nearby Beacon signals;

[0078] Each Beacon periodically broadcasts its unique identifier (ID) and signal strength (RSS I);

[0079] By combining the received signal strength and the relative position of the Beacon with a triangulation algorithm, the specific location of the patient or doctor's device can be calculated. The calculation can be as follows:

[0080]

[0081] Where Dis is the distance from the device to the beacon, R is the signal strength received by the device, n is the signal propagation attenuation factor, and RSSI is the signal strength.

[0082] The system uses configured virtual fences to determine if the patient's and doctor's locations meet certain criteria. For example, patient devices must be in authorized wards, and doctor devices must be in operating rooms or treatment rooms. If a patient or doctor is in an unauthorized area, data access permissions will be immediately revoked or prohibited to ensure the security of medical record data.

[0083] Furthermore, based on the real-time positioning system, access permissions for medical record data will be dynamically adjusted according to the following two main factors: the relative positions of the patient and the doctor, and equipment status monitoring. Specifically:

[0084] The relative positions of the patient and the doctor:

[0085] Access to patient medical records is only permitted when the patient and doctor are within the authorized treatment area. For example, a doctor must be in the ward and close to the patient to view the patient's medical records, preventing unauthorized access.

[0086] At the same time, the patient's treatment area is matched with the doctor's identity to ensure that only doctors with access permissions can obtain medical record data.

[0087] Equipment status monitoring:

[0088] The status of medical equipment (such as CT scanners, imaging equipment, and monitors) also plays a crucial role in accessing medical record data. If the equipment malfunctions or goes offline, valid medical record data cannot be provided, and the system will automatically block access to the data at that time.

[0089] For example, when a patient is undergoing a CT scan, the doctor can only view the patient's image data if the CT equipment is functioning properly; if the equipment malfunctions, the doctor will not be able to obtain the relevant data.

[0090] This method ensures that data is accessed only by authorized personnel and devices within the authorized area, thereby guaranteeing the security of medical record data.

[0091] To prevent medical record data from remaining in an undestroyed state for extended periods, potentially leading to timeout access risks, this invention employs a self-destruct tagging mechanism. The self-destruct tagging ensures strict time control for each access to medical record data; if the set access time is exceeded, access permissions are automatically revoked, and the relevant data is encrypted.

[0092] Specifically, each time access to medical record data is authorized, a temporary access token is generated for that access. The token contains information such as the start time, validity period, and access target of the access authorization. This token will also embed a self-destruct time, meaning that if the user does not perform any further operations within the set time period, the token will be automatically destroyed.

[0093] During the access to medical record data, the access status of the medical record is monitored in real time and each user operation is recorded. Specifically, a timeout threshold is set. If the medical record data is not accessed or the operation exceeds the preset time (e.g., 30 minutes or 1 hour) during the authorized access period, a self-destruct mechanism will be triggered.

[0094] Once the timeout period expires, access to the medical record data will be immediately revoked, and the temporary access marker will be deleted. At the same time, the medical record data will be re-encrypted using an encryption algorithm, and the original data will be rendered unrecoverable to prevent unauthorized recovery.

[0095] In the embodiments of this application, such as Figure 2 As shown, step S4 includes the following operational steps:

[0096] S4.1: To ensure the security of medical record data during storage, distributed storage technology is adopted to store medical record data divided into multiple data segments in different physical locations, avoiding single points of failure and security risks caused by centralized storage.

[0097] Specifically, these data fragments are stored on multiple nodes or servers. For example, a patient's medical record data is cut into five fragments, each stored in a different geographical location.

[0098] Each data segment is encrypted to ensure that even if an attacker obtains partial data segments, they cannot recover the complete data. Each data segment has an independent encryption key, and the association information between different segments is removed or hidden, thereby preventing the data from being easily reconstructed. This can be represented as:

[0099]

[0100] Where i = 1, 2, 3, ..., m, D i Let E represent the encryption operation, and D' be the i-th data segment. i For the original data fragment, K i The encryption key for each data segment, This is an XOR operation, where m is the number of data segments.

[0101] It should be noted that after the data fragments are encrypted, a strategy of removing or hiding related information is adopted during storage to ensure that even if the data fragments are obtained, they cannot be reassembled or cracked.

[0102] S4.2: Perform security scoring and storage path adjustment.

[0103] The security score of each data segment is calculated based on multiple factors (such as access frequency, device status, access anomalies, etc.), and the storage path is dynamically adjusted based on the security score to ensure the security of medical record data storage.

[0104] The security score is calculated based on multiple indicators, including the frequency of access, warnings of abnormal behavior, and the security status of the device. Through weighted calculation, these factors are comprehensively evaluated to obtain the security score of the medical record data.

[0105] Based on security scores, the storage path of data fragments is automatically adjusted. For example, if a data fragment has a low security score, it may be migrated to a more secure storage node to reduce the potential risk of leakage.

[0106] It should be noted that, to ensure data integrity and prevent data tampering, this invention utilizes blockchain technology to verify each access to medical record data. The decentralized and immutable nature of blockchain guarantees the security and transparency of access records.

[0107] S4.3: After data access is completed, generate a recovery path to ensure that the data can be reassembled according to a valid path when recovery is required.

[0108] By using path combination algorithms, the security of data during the recovery process can be ensured, preventing unauthorized access or tampering of data.

[0109] In this embodiment of the application, the selection of the recovery path includes:

[0110] Based on the security scores of data fragments and the security of storage nodes, an appropriate recovery path is selected. If the storage paths of certain data fragments are risky or abnormal, the recovery path is automatically adjusted to avoid data recovery from potentially dangerous nodes. During data recovery, data fragments are extracted sequentially from different storage nodes and assembled in a specific order to ensure the correctness and legality of the data recovery.

[0111] Specifically, the security score of a storage node is calculated by weighting factors such as the node's physical security, network security, and access control policies. The higher the score, the stronger the security of the storage node.

[0112] Based on the security scores of data fragments and storage nodes, a recovery path score is calculated:

[0113]

[0114] Where j(i) is the storage node where the i data segments are located. Assess the security of data segments. Assess the security of storage nodes.

[0115] During data recovery, the security score of each storage node is periodically assessed. If a storage node's security score falls below a preset threshold, that node is considered at risk, and the data recovery path needs to be adjusted.

[0116] If the recovery path is adjusted, fragments that originally relied on high-risk storage nodes need to be relocated, storage nodes reassigned, and recovery path scores updated. By assigning them to safer nodes, the data recovery process is ensured not to recover from potentially dangerous nodes.

[0117] Furthermore, the data recovery process is specifically divided into the process of extracting data fragments from each storage node and splicing them together in the correct order. The recovery order and legality verification are crucial to the correctness of the final recovery.

[0118] During data recovery, data fragments are extracted from different storage nodes sequentially in a preset order to ensure data integrity. The security of each storage node is verified during fragment extraction; if a node is insecure or access is abnormal, a new secure node is automatically selected, and the recovery path is adjusted. During data recovery, data is assembled according to the order of the storage fragments. The assembly order must strictly adhere to the original order; any change in the fragment order will lead to data recovery failure or data inconsistency. During data assembly, a validity verification mechanism ensures that the recovered data meets integrity requirements. Verification methods include: verifying the hash value of the data to ensure that the hash value of the assembled data matches the original data hash value; and using methods such as checksums and digital signatures to verify data integrity.

[0119] In addition, each data segment is verified during data recovery to ensure data integrity and prevent data from being tampered with or leaked during the recovery process.

[0120] In summary, the blockchain-based data security storage and verification method based on the embodiments of this application has been clarified. It proposes a method that can both ensure data encryption security and dynamically manage access permissions through a dynamic key generation and update mechanism combined with the generation and on-chain storage of segmented hash values. By utilizing IoT technology and dynamic adjustments based on location and device status, it can not only control data access permissions in real time but also avoid the security risks of timed-out access. Furthermore, this invention combines distributed storage technology to achieve data fragmentation and irreversible reassembly, greatly improving the reliability and security of data recovery. Compared with existing technologies, this invention not only solves the static problems in data storage and access control but also provides more flexible and reliable security guarantees in dynamic access scenarios. Through multi-layered security mechanisms, it ensures high security and high availability of data during storage, access, and recovery.

[0121] As described above, the blockchain-based data security storage and verification method according to the embodiments of this application can be implemented in various wireless terminals, such as servers with blockchain-based data security storage and verification algorithms. In one possible implementation, the blockchain-based data security storage and verification method according to the embodiments of this application can be integrated into the wireless terminal as a software module and / or hardware module. For example, the blockchain-based data security storage and verification method can be a software module in the operating system of the wireless terminal, or it can be an application developed for the wireless terminal; of course, the blockchain-based data security storage and verification method can also be one of many hardware modules of the wireless terminal.

[0122] Alternatively, in another example, the blockchain-based data security storage and verification method and the wireless terminal can also be separate devices, and the blockchain-based data security storage and verification method can be connected to the wireless terminal via wired and / or wireless networks, and transmit interactive information in accordance with an agreed data format.

[0123] Those skilled in the art will understand that the specific operations of each step in the above-described blockchain-based data security storage and verification method have been referenced above. Figures 1 to 2 The description of the blockchain-based data security storage and verification method is detailed here, and therefore, its repeated description will be omitted.

[0124] Various implementations of this disclosure have been described above. The foregoing description is exemplary and not exhaustive. Furthermore, it is not limited to the disclosed implementations, and many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is chosen to best explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the various embodiments disclosed herein.

Claims

1.A blockchain-based data security storage and verification method, characterized in that, Comprise: Collecting biometric features, generating a first dynamic key, which is used to encrypt the first data and is updated at each access, ensuring the timeliness of the key; Divide the first data into multiple segments according to the logic, generate segment hash values and store them on the chain; According to the user's authority, the corresponding segment is dynamically loaded, and anonymous verification is realized through homomorphic encryption technology; Based on Internet of Things technology, combined with the first positioning parameter and the first state parameter, dynamically adjust the access authority, and set the self-destruction mark to avoid the risk of timeout access; In the storage process of data segments, through distributed storage, dynamic security scoring and path adjustment, the security and integrity of medical record data in the storage, access and recovery process are ensured; The dynamic adjustment of access authority includes the following contents: Realize positioning and space management in the hospital through Beacon signal technology, when the patient or doctor carries the device supporting Beacon into the set fence area, the identity will be automatically identified through the positioning information; Deploy multiple Beacon signals inside the hospital to create a positioning matrix containing various diagnosis and treatment areas; The device carried by the patient and the doctor will periodically scan the nearby Beacon signal; Each Beacon signal will periodically broadcast its unique identifier and signal strength; Through the received signal strength and the relative position of the Beacon signal, combined with the triangulation algorithm, the specific position of the patient or doctor device is calculated; And judge whether the position of the patient and the doctor meets the conditions through the configured virtual fence; The dynamic adjustment of access authority also includes the following contents: The access authority of medical record data will be dynamically adjusted according to the following two main factors, including the relative position of the patient and the doctor and the device state monitoring; The relative position of the patient and the doctor includes: Only when the patient and the doctor are located in the authorized diagnosis and treatment area, the medical record data can be viewed; At the same time, the diagnosis and treatment area where the patient is located will be matched with the identity of the doctor, ensuring that only the doctor with access authority can obtain the medical record data; The device state monitoring includes: The state of the medical device also plays an important role in the access authority of the medical record data. If the device fails or is offline, it cannot provide effective medical record data; The distributed storage technology includes: Store the data segments on multiple nodes or servers respectively; Each data segment is encrypted to ensure that even if the attacker obtains part of the data segment, the complete data cannot be recovered; Each data segment has an independent encryption key, and the association information between different segments is removed or hidden, so as to prevent the data from being easily recombined; Automatic adjustment of the storage path of the data segment includes: Based on the security score of the data segment and the security of the storage node, select the appropriate recovery path: If there is risk or exception in the storage path of some data segments, the recovery path is automatically adjusted; When recovering data, extract data segments from different storage nodes in turn and splice them according to a specific order to ensure the correctness and legality of data recovery; Automatic adjustment of the storage path of the data segment also includes: In the process of data recovery, the security score of each storage node is evaluated regularly. If the security score of a certain storage node is lower than the preset threshold, the node is considered to be at risk, and the data recovery path needs to be adjusted. If the path is adjusted, the fragments that originally rely on the high-risk storage node need to be relocated, reallocated to storage nodes, and the recovery path score is updated. By allocating to safer nodes, the data recovery process is ensured not to recover from potentially dangerous nodes. In the data splicing process, the legality verification mechanism ensures that the recovered data meets the integrity requirements. 2.The blockchain-based data security storage and verification method of claim 1, wherein, The generation of the first dynamic key includes: Converting the biological characteristics into a digital representation; Generating a random factor that will participate in the encryption process along with the patient's biological characteristic information; Combining the biological characteristic information and the random factor using an encryption algorithm to generate a key as the first dynamic key; The generated first dynamic key will be bound to the patient's basic information. 3.The blockchain-based data security storage and verification method of claim 2, wherein, The first data is the patient's medical record data, including diagnosis information, treatment records, and image data. 4.The blockchain-based data security storage and verification method of claim 1, wherein, Dividing the first data into multiple fragments according to logic includes: Dividing the medical record data based on different data types, data importance, or access requirements; Each fragment corresponds to a logical unit and generates a unique identifier for it; Each fragment corresponds to different encrypted data, and for each divided data fragment, its hash value is generated to ensure data integrity and tamper resistance. 5.The blockchain-based data security storage and verification method of claim 1, wherein, According to the user's authority, the corresponding fragment is dynamically loaded, including: Each user needs to verify their identity when accessing the system; After verification, load the user's permission information; According to the configured permission management policy, compare the user's identity with the access permissions of the medical record data fragments. If the access permissions of a certain data fragment match the user's identity, the data fragment is allowed to be loaded. Once the permissions are confirmed, the data fragments that the user has access to are dynamically loaded.

Citation Information

Patent Citations

  • Mobile office data security access system based on encrypted mirror image transmission

    CN118433704A

  • Data sending method, data receiving method, system and device and storage medium

    CN118694545A

  • Secure storage method and device for console game data and computer equipment

    CN119203177A

  • Data security sharing method and system

    CN119483909A