Multi-role collaborative management architecture based on RBAC + HIS synchronization
Through the multi-role collaborative management architecture based on RBAC+HIS synchronization, the lack of dynamic adaptability and data security of permission management in the medical information field is solved, flexible permission configuration, secure transmission and efficient collaborative operation are achieved, and the robustness and user experience of the system are improved.
Patent Information
- Application Number
- CN202510861877.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-25
AI Technical Summary
The traditional RBAC-based permission management system has insufficient dynamic adaptability in the field of medical information, resulting in a long permission adjustment cycle and easy to cause data leakage risks. The collaborative operation efficiency of multiple terminals is low, and there is a risk of privacy leakage during data synchronization.
It adopts a multi-role collaborative management architecture based on RBAC+HIS synchronization, including role permission management module, data synchronization middleware, multi-terminal collaborative engine and permission audit center. Through dynamic rules engine, field-level encryption and distributed session management, flexible configuration of permissions, secure transmission and seamless collaboration are achieved.
Significantly shorten the permission adjustment cycle, improve data transmission security and collaborative operation efficiency, reduce the risk of data leakage, and ensure the system's business continuity and security in abnormal situations.
Smart Images

Figure CN120354459A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of collaborative management of medical permissions, and particularly to a multi-role collaborative management architecture based on RBAC+HIS synchronization. Background Art
[0002] In the field of medical informatization, traditional RBAC-based permission management systems generally suffer from insufficient dynamic adaptability. Static role configuration is difficult to cope with the complex organizational structures of multiple departments and wards in a hospital, resulting in a permission adjustment cycle of up to several weeks and an increased risk of medical data leakage due to manual configuration errors.
[0003] Although existing technologies have attempted to achieve data synchronization between HIS systems through API interfaces, they generally adopt a full-volume data push mode, which not only occupies a large amount of network bandwidth but also increases the risk of patient privacy leakage due to the lack of field-level encryption.
[0004] In addition, during multi-terminal collaborative operations, doctors need to repeatedly log in and authenticate between different systems, seriously affecting the diagnosis and treatment efficiency; traditional solutions also have obvious defects in permission auditing. Cross-system operation logs are isolated from each other, making it difficult to trace the source of data leakage. Therefore, a multi-role collaborative management architecture based on RBAC+HIS synchronization is proposed. Summary of the Invention
[0005] Aiming at the deficiencies of the prior art, the present invention provides a multi-role collaborative management architecture based on RBAC+HIS synchronization to solve the problems raised in the above background art.
[0006] To achieve the above object, the present invention provides the following technical solutions: A multi-role collaborative management architecture based on RBAC+HIS synchronization, including: A role permission management module that constructs a static role permission baseline based on the RBAC model and associates the real-time organizational structure data of the HIS system through a dynamic rule engine to generate a multi-level role permission tree; A data synchronization middleware that uses an API gateway to achieve one-way data push between the HIS system and the psychological assessment platform, including a field-level encryption unit and an incremental data verification unit, and supports the isolated transmission of patient medical records, doctor's orders, and assessment tasks by ward; A multi-terminal collaborative engine that realizes permission mapping between doctor workstations, mobile nursing terminals, and patient self-service terminals through distributed session management, and has a built-in conflict detection mechanism that triggers a secondary authentication process when cross-ward operations are detected; A permission auditing center that records role change logs and correlates them with the time stamps of HIS system operation logs to generate a three-dimensional audit report including operation traces, data flow directions, and risk levels; The emergency management module automatically switches to the role permission configuration cached locally when detecting anomalies in the HIS system, and performs permission downgrading according to the preset department priority rules; Among them, the role permission management module establishes a two-way mapping relationship through the ward code and the HIS system department code. The data synchronization middleware uses the AES-256 segmented encryption algorithm at the transport layer. The multi-terminal collaboration engine supports the intelligent switching between the WebSocket protocol and HTTP long polling; In the role permission management module, if there are compatibility issues in the data association between the RBAC model and the HIS system organizational structure, an intermediate adapter layer can be developed. This layer is responsible for parsing the JSON format data returned by the HIS and converting it into a permission configuration format recognizable by the RBAC model to ensure the effective integration of the static role permission baseline and the dynamic organizational structure data; By combining the RBAC model with the dynamic data of the HIS system, the role permission management module realizes the flexible configuration and real-time update of role permissions, enhancing the system's adaptability to complex medical environments. The data synchronization middleware adopts API gateway and field-level encryption technologies to ensure the security and integrity of patient data during transmission. At the same time, it supports isolated transmission by ward, improving the efficiency and accuracy of data processing. The multi-terminal collaboration engine realizes seamless collaboration among doctor, nurse, and patient terminals through distributed session management. The built-in conflict detection and secondary authentication mechanisms effectively prevent permission abuse and data leakage. The permission audit center provides a traceable audit basis for system security through detailed log records and correlation analysis. The addition of the emergency management module further enhances the system's robustness, ensuring that basic business operations can still be maintained when the HIS system is abnormal.
[0007] Preferably, the dynamic rule engine includes: A rule configuration interface that supports visual editing of permission inheritance rules based on the tree structure of the hospital organizational structure; A rule parser that converts the configured rules into executable scripts and performs real-time matching with the JSON format organizational data returned by the HIS system; A conflict resolution unit that arbitrates according to the preset medical service priority table when detecting conflicts between the RBAC baseline permissions and the HIS dynamic data; Regarding the specific implementation of the conflict resolution unit in the dynamic rule engine, when detecting conflicts between the RBAC baseline permissions and the HIS dynamic data, the system first reads the preset medical service priority table, which details the priority order of various medical services. Subsequently, the system matches in the priority table according to the type of medical service involved in the conflict and automatically selects the business rule with a higher priority as the arbitration basis to resolve the permission conflict and ensure the smooth progress of medical services; The dynamic rule engine realizes the flexible editing and efficient execution of the hospital organizational structure permission inheritance rules through the collaborative work of the rule configuration interface, the rule parser, and the conflict resolution unit. The tree structure visualization editing function of the rule configuration interface makes the adjustment of the permission inheritance rules intuitive and convenient, reducing the management cost. The rule parser converts the configured rules into executable scripts and performs real-time matching with the JSON format organizational data returned by the HIS system, ensuring the accuracy and timeliness of permission allocation. When the conflict resolution unit detects a conflict between the RBAC baseline permissions and the HIS dynamic data, it can arbitrate based on the preset medical service priority table, effectively avoiding the impact of permission conflicts on medical services and ensuring the efficiency and security of hospital operations.
[0008] Preferably, the field-level encryption unit includes: An encryption policy manager that dynamically selects the AES-256 or national secret SM4 algorithm according to the sensitivity level of patient data; A key distribution sub-module that pushes temporary session keys to each terminal through the hospital intranet security channel; An encryption performance optimizer that adopts a cache pre-encryption mechanism for frequently accessed fields; In the field-level encryption unit, the encryption policy manager automatically determines the sensitivity level of patient data according to the type of patient data (such as ID number, diagnosis information, etc.) through the built-in sensitivity level evaluation algorithm, and selects the AES-256 or national secret SM4 algorithm for encryption accordingly. The key distribution sub-module uses the existing VPN or encryption tunnel technology in the hospital to establish a secure channel, encrypts the generated temporary session keys, and pushes them to each terminal. The encryption performance optimizer analyzes the historical access records, identifies the frequently accessed fields, and performs pre-encryption processing on them when the system is idle and stores them in the local cache to reduce the computational burden of real-time encryption; The field-level encryption unit ensures the security of patient data at different sensitivity levels by dynamically selecting the encryption algorithm, which not only meets the compliance requirements but also takes into account the encryption efficiency. Distributing keys through the hospital intranet security channel effectively prevents the risk of key leakage during transmission. At the same time, the encryption performance optimizer significantly improves the encryption speed of frequently accessed fields through the cache pre-encryption mechanism, reduces system latency, and improves the user experience.
[0009] Preferably, the distributed session management includes: A session token generator that carries role identification, ward area code, and terminal type information in the JWT format; A session status monitor that real-time detects the session activity of each terminal and automatically logs off sessions that have been idle for more than the preset duration; A session migration component that supports seamless switching between different terminals by doctors while maintaining the continuity of the operation context; For the session token generator in distributed session management, the JWT (JSON Web Token) standard can be adopted to encode the role identifier, ward code (processed into a hash value through the SHA-256 algorithm to protect privacy), and terminal type (such as a unique identifier generated from the device MAC address and operating system version as the terminal fingerprint) into the Payload part of the JWT to ensure the secure transmission and parsing of information. The session status monitor polls each terminal session through a scheduled task, detects its last activity time, and automatically triggers the session logout logic when it exceeds a preset threshold (such as 30 minutes). The session migration component uses a distributed cache (such as Redis) to store the session context. When a doctor switches between different terminals, seamless switching is achieved by verifying the JWT and restoring the context data from the cache; The distributed session management mechanism realizes unified identity authentication and permission verification across terminals through session tokens in JWT format, ensuring the security and consistency of doctors' operations between different devices. The introduction of the session status monitor effectively manages the lifecycle of terminal sessions, avoids potential security risks brought by long-term idle sessions, and releases system resources at the same time. The support of the session migration component greatly improves doctors' work efficiency, allows them to freely switch between different devices without losing operation progress, and ensures the continuity and efficiency of medical services. Overall, this distributed session management solution not only enhances the security and stability of the system but also significantly improves the user experience, providing solid technical support for the multi-terminal collaborative work of the medical informatization system.
[0010] Preferably, the three-dimensional audit report generation method includes: A log collector that synchronously grabs the operation logs of the RBAC system and the business logs of the HIS system; A log correlation engine that establishes cross-system log correlation through the unique patient ID and operation timestamp; A visualization renderer that presents the audit results in the form of a timeline, heat map, and Sankey diagram; The log collector adopts multi-threaded concurrent technology to establish stable connections with the RBAC system and the HIS system respectively, and grabs log data in real-time. After receiving the logs, the log correlation engine first extracts the unique patient ID and operation timestamp, generates a unique correlation key using the hash algorithm, and then correlates the cross-system logs through this key. The visualization renderer uses a front-end chart library to dynamically generate a timeline, heat map, and Sankey diagram based on the audit result data and provides interactive functions for users to conduct in-depth analysis; Establishing cross-system log associations using a unique patient ID and operation timestamps effectively solves the problem of log fragmentation, enabling auditors to easily track all operation trajectories of a specific patient. The visualization renderer presents the audit results in the form of a timeline, heatmap, and Sankey diagram, not only intuitively showing the dynamic changes in audit data but also revealing potential risk points and operation hotspots in a graphical way, providing strong decision-making support for hospital management. This method not only improves audit efficiency but also enhances the usability and comprehensibility of audit results, helping the hospital better manage role permissions and ensure the security and compliance of medical data.
[0011] Preferably, the emergency management module includes: A local cache unit that stores role permission snapshots within the last 72 hours; A degradation policy library that pre-sets permission restriction schemes corresponding to different HIS failure levels; A recovery validator that automatically compares the consistency between the local cache and the latest HIS data after the HIS system is restored; After the HIS system is restored, the recovery validator automatically starts a data comparison task. First, it extracts the role permission snapshot data within the last 72 hours from the local cache unit, and then obtains the latest role permission data from the HIS system through the API interface. It uses a hash algorithm to perform integrity verification on the two sets of data and compares the permission configuration items item by item to ensure data consistency. If differences are found, it records the details of the differences and triggers an alarm mechanism to notify the administrator for manual intervention; The local cache unit stores role permission snapshots within the last 72 hours, ensuring that when the HIS system fails, the system can quickly switch to the local cache to maintain basic business operations and avoid business interruptions. The degradation policy library pre-sets permission restriction schemes corresponding to different HIS failure levels, enabling the system to flexibly adjust permissions according to the actual situation, ensuring both business continuity and avoiding the risk of permission abuse. The recovery validator automatically compares the consistency between the local cache and the latest HIS data after the HIS system is restored to ensure the accuracy of the data, providing strong guarantee for the safe and stable operation of the system. The design of this module not only improves the emergency response speed of the system but also greatly reduces business losses caused by system failures, providing a more reliable and efficient management tool for medical institutions.
[0012] Preferably, the tree structure visualization editing supports: Drag-and-drop node adjustment, which reflects changes in the permission inheritance relationship in real time; A batch rule import function that is compatible with the HL7 FHIR standard medical data format; A rule version controller that supports rollback and difference comparison of historical configurations; The system interface uses a 3D tree diagram based on WebGL for display, supports adjusting node positions by dragging with the mouse, and synchronizes permission inheritance relationship data with the backend in real time through WebSocket; the batch rule import function parses XML or JSON files in the HL7 FHIR standard and automatically maps them to the system permission model; the rule version controller uses the Git principle to maintain a version library in the background, records each configuration change, and supports version rollback and display of differences through interface buttons. First, the drag-and-drop node adjustment greatly improves the intuitiveness and efficiency of permission configuration. Managers can directly operate on the interface and see the changes in the permission inheritance relationship in real time, reducing the risk of system failures caused by configuration errors. Second, the batch rule import function is compatible with the HL7 FHIR standard medical data format, enabling the system to seamlessly connect to various medical information systems, achieving standardized and automated processing of permission data, and reducing the error rate of manual entry. Finally, the introduction of the rule version controller provides the ability of historical traceability and version rollback for permission management. Managers can easily view the details of each configuration change, quickly locate the root cause of problems, and restore to the previous stable state when necessary, thus ensuring the continuous and stable operation of the system.
[0013] Preferably, the dynamic selection mechanism includes: A sensitive field recognizer that matches preset fields of the patient's ID number and diagnostic information based on regular expressions; An algorithm negotiation component that negotiates with the terminal to determine the final encryption algorithm; An encryption performance monitor that automatically switches to a lightweight algorithm when the detected encryption delay exceeds the threshold During the negotiation process, the algorithm negotiation component can add a terminal performance evaluation step to recommend the optimal encryption algorithm according to the terminal's computing power. The encryption performance monitor can set multiple levels of thresholds. When the delay reaches different levels, it will sequentially switch to a lighter encryption algorithm to ensure the balance between data transmission efficiency and security; The dynamic selection mechanism has significant advantages in ensuring the secure transmission of patient data. Through the sensitive field recognizer, the system can accurately identify and encrypt key information, effectively preventing data leakage. The algorithm negotiation component enhances the flexibility and adaptability of the system and can dynamically adjust the encryption strategy according to the terminal performance, ensuring both the security of data transmission and avoiding unnecessary performance losses. The introduction of the encryption performance monitor enables the system to monitor and adjust the performance bottleneck in the encryption process in real time while ensuring security. When the detected encryption delay is too high, it automatically switches to a lightweight algorithm to ensure the smoothness of data transmission. This mechanism not only improves the overall operating efficiency of the system but also enhances the user experience, providing a solid security guarantee for medical informatization.
[0014] Preferably, the JWT payload includes: Role encoding, adopting the hospital's unified identity authentication system standard; Ward hash value, generated by processing the original ward encoding through the SHA-256 algorithm; Terminal fingerprint, a unique identifier generated based on the device MAC address and operating system version; The role encoding directly maps to the existing role IDs in the hospital's unified identity authentication system to ensure consistency; when generating the ward hash value, the original ward encoding is input into the SHA-256 algorithm, and a hash value of a fixed length is output to protect data privacy; the terminal fingerprint generates a unique identifier by reading the device MAC address and operating system version information and combining specific algorithms to ensure the uniqueness tracking of the terminal; Designing the JWT payload to include role encoding, ward hash value, and terminal fingerprint significantly improves the security and manageability of the system. The role encoding adopts the hospital's unified standard, simplifies the permission management process, and ensures the consistency of cross-system roles; the ward hash value is generated through the SHA-256 algorithm, which not only protects the privacy of the original ward encoding but also enables quick verification without decryption, enhancing data security; the introduction of the terminal fingerprint enables the system to accurately identify and manage each connected device, effectively preventing the access of illegal devices and the risk of data leakage.
[0015] Preferably, the association process includes: Log normalization processing, unifying the log formats of different systems into JSON Schema; Event time alignment, using the NTP protocol for cross-system clock synchronization; Association rule engine, defining the log association path based on the medical business process diagram; In terms of log normalization processing, it can be further explained that a custom log parsing script is used to parse each system log line by line, identify key fields, and reorganize them according to the predefined JSON Schema template to ensure that all log items (such as operation type, timestamp, user ID, etc.) conform to the unified format. For event time alignment, the deployment location and configuration method of the NTP server can be specifically described to ensure that all system clocks are synchronized with the standard time source. The association rule engine can accurately match the key information in the log by writing XPath or JSONPath expressions based on the medical business process to achieve the automatic association of log items; The combination of log normalization, event time alignment, and the association rule engine can significantly improve the efficiency and accuracy of multi-system log management. Through log normalization, log data from different systems can be unified in format, facilitating subsequent analysis and processing. Event time alignment ensures the time accuracy of log records, avoiding analysis biases caused by clock differences. The association rule engine, based on the medical business process flowchart, precisely correlates relevant log items, providing strong support for audit tracking, problem troubleshooting, and business optimization.
[0016] In summary, compared with the prior art, the present invention provides a multi-role collaborative management architecture based on RBAC+HIS synchronization, having the following beneficial effects: By constructing a multi-role collaborative management architecture based on RBAC+HIS synchronization, the invention realizes the dynamic optimization and efficient collaboration of medical permission management, with significant benefits. This architecture utilizes the linkage between the role permission management module and the real-time organizational structure data of the HIS system, combines with the dynamic rule engine to generate a multi-level role permission tree, greatly shortening the permission adjustment cycle, reducing the risk of data leakage caused by manual configuration errors. At the same time, the two-way mapping of roles and department codes ensures the accuracy of permission allocation, improving hospital management efficiency. The data synchronization middleware adopts field-level encryption and incremental verification, combined with the transport layer encryption algorithm, to ensure the security of data transmission, avoiding bandwidth waste and privacy leakage in the full-volume push mode. The multi-terminal collaboration engine realizes permission mapping through distributed session management, with built-in conflict detection and secondary authentication processes, which not only ensures data security but also improves the operation convenience of doctors between different terminals, significantly improving the diagnosis and treatment efficiency. In addition, the three-dimensional audit report of the permission audit center provides a basis for tracing data leakage, and the emergency management module ensures business continuity in case of system anomalies, further strengthening the security and reliability of the medical system. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a schematic diagram of the multi-role collaborative management architecture based on RBAC+HIS synchronization of the invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The present invention provides a technical solution, a multi-role collaborative management architecture based on RBAC+HIS synchronization. Please refer to Figure 1 , including: A role permission management module, which constructs a static role permission baseline based on the RBAC model and correlates the real-time organizational structure data of the HIS system through a dynamic rule engine to generate a multi-level role permission tree. The data synchronization middleware uses an API gateway to achieve one-way data push between the HIS system and the psychological assessment platform. It includes a field-level encryption unit and an incremental data verification unit, and supports the isolated transmission of patient medical records, doctor's orders, and assessment tasks by ward area; The multi-terminal collaboration engine realizes the permission mapping of the doctor's workstation, mobile nursing terminal, and patient self-service terminal through distributed session management. It has a built-in conflict detection mechanism that triggers a secondary authentication process when cross-ward area operations are detected; The permission audit center records role change logs and correlates them with the HIS system operation logs by timestamp, generating a three-dimensional audit report including operation traces, data flow, and risk levels; The emergency management module, when detecting an abnormality in the HIS system, automatically switches to the locally cached role permission configuration and performs permission downgrading according to the preset department priority rules; Among them, the role permission management module establishes a two-way mapping relationship with the HIS system department code through the ward area code. The data synchronization middleware uses the AES-256 block encryption algorithm at the transport layer, and the multi-terminal collaboration engine supports the intelligent switching between the WebSocket protocol and HTTP long polling; In the role permission management module, if there are compatibility issues in the data association between the RBAC model and the HIS system organizational structure, a middle adapter layer can be developed. This layer is responsible for parsing the JSON format data returned by the HIS and converting it into a permission configuration format recognizable by the RBAC model to ensure the effective integration of the static role permission baseline and dynamic organizational structure data; The role permission management module realizes the flexible configuration and real-time update of role permissions by combining the RBAC model with the HIS system dynamic data, enhancing the system's adaptability to complex medical environments. The data synchronization middleware uses API gateway and field-level encryption technology to ensure the security and integrity of patient data during transmission. At the same time, it supports isolated transmission by ward area, improving the efficiency and accuracy of data processing. The multi-terminal collaboration engine realizes seamless collaboration among doctor, nurse, and patient terminals through distributed session management. The built-in conflict detection and secondary authentication mechanisms effectively prevent permission abuse and data leakage. The permission audit center provides a traceable audit basis for system security through detailed log records and correlation analysis. The addition of the emergency management module further enhances the system's robustness, ensuring that basic business operations can still be maintained when the HIS system is abnormal.
[0019] Please refer to Figure 1 , the dynamic rule engine includes: A rule configuration interface that supports visual editing of permission inheritance rules based on the tree structure of the hospital organizational structure; A rule parser that converts the configured rules into executable scripts and performs real-time matching with the data organized in JSON format returned by the HIS system; A conflict resolution unit that arbitrates based on a preset medical service priority table when detecting conflicts between RBAC baseline permissions and HIS dynamic data; For the specific implementation of the conflict resolution unit in the dynamic rule engine, when detecting conflicts between RBAC baseline permissions and HIS dynamic data, the system first reads the preset medical service priority table, which details the priority order of various medical services. Subsequently, based on the type of medical service involved in the conflict, the system matches in the priority table and automatically selects the business rule with a higher priority as the arbitration basis to resolve the permission conflict and ensure the smooth progress of medical services; Through the collaborative work of the rule configuration interface, rule parser, and conflict resolution unit, the dynamic rule engine realizes the flexible editing and efficient execution of the hospital organizational structure permission inheritance rules. The tree structure visualization editing function of the rule configuration interface makes the adjustment of permission inheritance rules intuitive and convenient, reducing management costs. The rule parser converts the configured rules into executable scripts and performs real-time matching with the data organized in JSON format returned by the HIS system to ensure the accuracy and timeliness of permission allocation. When detecting conflicts between RBAC baseline permissions and HIS dynamic data, the conflict resolution unit can arbitrate based on a preset medical service priority table, effectively avoiding the impact of permission conflicts on medical services and ensuring the high efficiency and security of hospital operations.
[0020] Please refer to Figure 1 , the field-level encryption unit includes: An encryption policy manager that dynamically selects the AES-256 or national cipher SM4 algorithm according to the sensitivity level of patient data; A key distribution sub-module that pushes temporary session keys to each terminal through the hospital's intranet secure channel; An encryption performance optimizer that adopts a cache pre-encryption mechanism for frequently accessed fields; In the field-level encryption unit, the encryption policy manager automatically determines the sensitivity level of patient data based on the type of patient data (such as ID number, diagnosis information, etc.) through a built-in sensitivity level evaluation algorithm and selects the AES-256 or national cipher SM4 algorithm for encryption accordingly. The key distribution sub-module uses the hospital's existing VPN or encrypted tunnel technology to establish a secure channel and pushes the generated temporary session keys to each terminal after encryption. The encryption performance optimizer analyzes historical access records to identify frequently accessed fields and pre-encrypts them during system idle time and stores them in the local cache to reduce the computational burden of real-time encryption; The field-level encryption unit ensures the security of patient data at different sensitivity levels by dynamically selecting encryption algorithms, which not only meets compliance requirements but also takes into account encryption efficiency. It distributes keys through the hospital intranet security channel, effectively preventing the risk of key leakage during transmission. At the same time, the encryption performance optimizer significantly improves the encryption speed of frequently accessed fields through a cache pre-encryption mechanism, reduces system latency, and enhances the user experience.
[0021] Please refer to Figure 1 , the distributed session management includes: A session token generator that carries role identification, ward code, and terminal type information in the JWT format; A session status monitor that real-time detects the activity of each terminal session and automatically logs out sessions that have been idle for more than a preset duration; A session migration component that supports seamless switching of doctors between different terminals while maintaining the continuity of the operation context; For the session token generator in the distributed session management, the JWT (JSON Web Token) standard can be adopted to encode the role identification, ward code (processed into a hash value through the SHA-256 algorithm to protect privacy), and terminal type (such as a unique identifier generated from the device MAC address and operating system version as the terminal fingerprint) into the Payload part of the JWT to ensure the secure transmission and parsing of information. The session status monitor polls each terminal session through a scheduled task to detect its last activity time, and automatically triggers the session logout logic when it exceeds the preset threshold (such as 30 minutes). The session migration component uses a distributed cache (such as Redis) to store the session context. When a doctor switches between different terminals, it realizes seamless switching by verifying the JWT and restoring the context data from the cache; The distributed session management mechanism realizes unified identity authentication and permission verification across terminals through session tokens in the JWT format, ensuring the security and consistency of doctors' operations between different devices. The introduction of the session status monitor effectively manages the lifecycle of terminal sessions, avoids potential security risks brought by long-term idle sessions, and releases system resources at the same time. The support of the session migration component greatly improves doctors' work efficiency, allows them to freely switch between different devices without losing the operation progress, and ensures the continuity and efficiency of medical services. Overall, this distributed session management solution not only enhances the security and stability of the system but also significantly improves the user experience, providing solid technical support for the multi-terminal collaborative work of the medical informatization system.
[0022] Please refer to Figure 1 , the three-dimensional audit report generation method includes: A log collector that synchronously captures RBAC system operation logs and HIS system business logs; Log correlation engine, which establishes cross-system log correlation through unique patient IDs and operation timestamps; Visualization renderer, which presents audit results in the form of a timeline, heatmap, and Sankey diagram; The log collector uses multi-threaded concurrent technology to establish stable connections with the RBAC system and HIS system respectively, and captures log data in real time. After receiving the logs, the log correlation engine first extracts the unique patient ID and operation timestamp, generates a unique correlation key using the hash algorithm, and then correlates the cross-system logs through this key. The visualization renderer uses a front-end chart library to dynamically generate a timeline, heatmap, and Sankey diagram based on the audit result data, and provides interactive functions for users to conduct in-depth analysis; Establishing cross-system log correlation using unique patient IDs and operation timestamps effectively solves the problem of log fragmentation, enabling auditors to easily track all operation trajectories of specific patients. The visualization renderer presents audit results in the form of a timeline, heatmap, and Sankey diagram, not only intuitively showing the dynamic changes in audit data, but also revealing potential risk points and operation hotspots in a graphical way, providing strong decision-making support for hospital management. This method not only improves audit efficiency, but also enhances the usability and understandability of audit results, helping the hospital better manage role permissions and ensure the security and compliance of medical data.
[0023] Please refer to Figure 1 , the emergency management module includes: Local cache unit, which stores role permission snapshots within the last 72 hours; Degradation policy library, which pre-sets permission limit schemes corresponding to different HIS failure levels; Recovery validator, which automatically compares the consistency between the local cache and the latest HIS data after the HIS system is restored; After the HIS system is restored, the recovery validator automatically starts a data comparison task. First, it extracts the role permission snapshot data within the last 72 hours from the local cache unit, then obtains the latest role permission data from the HIS system through the API interface, uses the hash algorithm to perform integrity verification on the two sets of data, and compares the permission configuration items item by item to ensure data consistency. If differences are found, the details of the differences are recorded and the alarm mechanism is triggered to notify the administrator for manual intervention; The local cache unit stores the role permission snapshots within the most recent 72 hours, ensuring that when the HIS system fails, the system can quickly switch to the local cache to maintain basic business operations, avoid business interruptions. The degradation policy library has preset permission restriction schemes corresponding to different HIS failure levels, enabling the system to flexibly adjust permissions according to the actual situation, which not only guarantees business continuity but also avoids the risk of permission abuse. The recovery validator automatically compares the consistency between the local cache and the latest HIS data after the HIS system is restored, ensuring the accuracy of the data and providing strong guarantee for the safe and stable operation of the system. The design of this module not only improves the emergency response speed of the system but also greatly reduces the business losses caused by system failures, providing a more reliable and efficient management tool for medical institutions.
[0024] Please refer to Figure 1 , tree structure visual editing support: Drag-and-drop node adjustment, which reflects the changes in the permission inheritance relationship in real time; Batch rule import function, compatible with the HL7 FHIR standard medical data format; Rule version controller, supporting rollback and difference comparison of historical configurations; The system interface uses a 3D tree diagram based on WebGL for display, supporting the adjustment of node positions by dragging the mouse, and synchronizing the permission inheritance relationship data with the backend in real time through WebSocket; the batch rule import function automatically maps to the system permission model by parsing XML or JSON files in the HL7 FHIR standard; the rule version controller uses the Git principle to maintain a version library in the background, records each configuration change, and supports version rollback and difference comparison display through interface buttons; First of all, the drag-and-drop node adjustment greatly improves the intuitiveness and efficiency of permission configuration. Managers can directly operate on the interface and see the changes in the permission inheritance relationship in real time, reducing the risk of system failures caused by configuration errors. Secondly, the batch rule import function is compatible with the HL7 FHIR standard medical data format, enabling the system to seamlessly connect to various medical information systems, realizing the standardization and automated processing of permission data, and reducing the error rate of manual input. Finally, the introduction of the rule version controller provides the ability of historical traceability and version rollback for permission management. Managers can easily view the details of each configuration change, quickly locate the root cause of problems, and restore to the previous stable state when necessary, thus ensuring the continuous and stable operation of the system.
[0025] Please refer to Figure 1 , the dynamic selection mechanism includes: Sensitive field recognizer, presetting fields for matching patient ID numbers and diagnostic information based on regular expressions; Algorithm negotiation component, negotiating with the terminal to determine the final encryption algorithm; Encryption performance monitor that automatically switches to a lightweight algorithm when the detected encryption delay exceeds the threshold During the negotiation process, the algorithm negotiation component can add a terminal performance evaluation step to recommend the optimal encryption algorithm based on the terminal's computing power. The encryption performance monitor can set multiple levels of thresholds. When the delay reaches different levels, it will sequentially switch to a more lightweight encryption algorithm to ensure the balance between data transmission efficiency and security; The dynamic selection mechanism has significant advantages in ensuring the secure transmission of patient data. Through the sensitive field identifier, the system can accurately identify and encrypt key information, effectively preventing data leakage. The algorithm negotiation component enhances the flexibility and adaptability of the system and can dynamically adjust the encryption policy according to the terminal performance, ensuring both the security of data transmission and avoiding unnecessary performance losses. The introduction of the encryption performance monitor enables the system to monitor and adjust the performance bottleneck in the encryption process in real time while ensuring security. When the detected encryption delay is too high, it automatically switches to a lightweight algorithm to ensure the smoothness of data transmission. This mechanism not only improves the overall operation efficiency of the system but also enhances the user experience, providing a solid security guarantee for medical informatization.
[0026] Please refer to Figure 1 , the JWT payload contains: Role code, adopting the hospital's unified identity authentication system standard; Ward hash value, generated by processing the original ward code through the SHA-256 algorithm; Terminal fingerprint, a unique identifier generated based on the device's MAC address and operating system version; The role code directly maps to the existing role ID in the hospital's unified identity authentication system to ensure consistency; when generating the ward hash value, the original ward code is input into the SHA-256 algorithm, and a hash value of a fixed length is output to protect data privacy; the terminal fingerprint generates a unique identifier by reading the device's MAC address and operating system version information and combining a specific algorithm to ensure the unique tracking of the terminal; Designing the JWT payload to contain the role code, ward hash value, and terminal fingerprint significantly improves the security and manageability of the system. The role code adopts the hospital's unified standard, simplifying the permission management process and ensuring the consistency of cross-system roles; the ward hash value is generated through the SHA-256 algorithm, protecting the privacy of the original ward code and enabling quick verification without decryption, enhancing data security; the introduction of the terminal fingerprint enables the system to accurately identify and manage each connected device, effectively preventing the access of illegal devices and the risk of data leakage.
[0027] Please refer to Figure 1 , the association process includes: Log normalization to unify the log formats of different systems into JSON Schema; Event time alignment, using the NTP protocol for cross-system clock synchronization; Association rule engine, defining log association paths based on the medical business process flow chart; Regarding log normalization, it can be further explained that a custom log parsing script is used to parse each line of the system logs, identify key fields, and reorganize them according to the predefined JSON Schema template to ensure that all log entries (such as operation type, timestamp, user ID, etc.) conform to a unified format. For event time alignment, the deployment location and configuration method of the NTP server can be specifically described to ensure that all system clocks are synchronized with the standard time source. The association rule engine can precisely match the key information in the logs by writing XPath or JSONPath expressions based on the medical business process to achieve automatic association of log entries; The combination of log normalization, event time alignment, and the association rule engine can significantly improve the efficiency and accuracy of multi-system log management. Through log normalization, the log data of different systems is unified in format, facilitating subsequent analysis and processing; event time alignment ensures the time accuracy of log records and avoids analysis deviations caused by clock differences; while the association rule engine, based on the medical business process flow chart, precisely associates relevant log entries, providing strong support for audit tracking, problem troubleshooting, and business optimization; Efficiency improvement: The role permission configuration time is reduced from 30 minutes per time to 5 minutes per time, and the department data synchronization efficiency is increased by 80%; The time-consuming for the release of group physical examination tasks is reduced by 70% (configurable within 1 hour for a group of 1,000 people); Data consistency: The cross-terminal data synchronization error rate is reduced from 15% to 0.5%, and the matching accuracy of the prescription association evaluation task is ≥98%; Enhanced security: Through ward binding and field-level encryption (AES-256), zero leakage of patient data is achieved; The risk of incorrect permission operations is reduced by 90% (compared with traditional static RBAC).
[0028] User experience optimization: The doctor's workbench integrates HIS and psychological CT functions, and the operation path is shortened by 50%; Only the tasks bound to the ward are displayed on the nurse's Pad, and the interface complexity is reduced by 60%.
[0029] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device.
[0030] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A multi-role collaborative management architecture based on RBAC+HIS synchronization, characterized in that It includes: A role permission management module that constructs a static role permission baseline based on the RBAC model and generates a multi-level role permission tree by associating real-time organizational structure data of the HIS system through a dynamic rule engine; A data synchronization middleware that uses an API gateway to achieve one-way data push between the HIS system and the psychological assessment platform, including a field-level encryption unit and an incremental data verification unit, and supports the isolated transmission of patient medical records, doctor's orders, and assessment tasks by ward; A multi-terminal collaboration engine that realizes permission mapping for doctor workstations, mobile nursing terminals, and patient self-service terminals through distributed session management, with a built-in conflict detection mechanism that triggers a secondary authentication process when cross-ward operations are detected; A permission audit center that records role change logs and correlates them with the HIS system operation logs by timestamp to generate a three-dimensional audit report including operation traces, data flow, and risk levels; An emergency management module that automatically switches to the locally cached role permission configuration when an abnormality in the HIS system is detected and performs permission downgrading according to the preset department priority rules; Among them, the role permission management module establishes a two-way mapping relationship with the HIS system department code through the ward code. The data synchronization middleware uses the AES-256 segmented encryption algorithm at the transport layer, and the multi-terminal collaboration engine supports the intelligent switching between the WebSocket protocol and HTTP long polling.
2. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 1, characterized in that The dynamic rule engine includes: A rule configuration interface that supports visual editing of permission inheritance rules based on the tree structure of the hospital organizational structure; A rule parser that converts the configured rules into executable scripts and performs real-time matching with the JSON format organizational data returned by the HIS system; A conflict resolution unit that arbitrates according to the preset medical business priority table when a conflict between the RBAC baseline permission and the HIS dynamic data is detected.
3. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 1, characterized in that, The field-level encryption unit includes: An encryption policy manager that dynamically selects the AES-256 or national secret SM4 algorithm according to the sensitivity level of patient data; A key distribution sub-module that pushes temporary session keys to each terminal through the hospital intranet security channel; An encryption performance optimizer that uses a cache pre-encryption mechanism for frequently accessed fields.
4. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 1, characterized in that, The distributed session management includes: A session token generator that uses the JWT format to carry role identification, ward code, and terminal type information; A session status monitor that real-time detects the session activity of each terminal and automatically logs off sessions that have been idle for more than the preset duration; A session migration component that supports maintaining the continuity of the operation context when a doctor seamlessly switches between different terminals.
5. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 1, characterized in that, The method for generating the three-dimensional audit report includes: A log collector that synchronously captures the RBAC system operation logs and the HIS system business logs; A log correlation engine that establishes cross-system log correlation through the unique patient ID and operation timestamp; A visualization renderer that presents the audit results in the form of a timeline, heat map, and Sankey diagram.
6. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 1, characterized in that The emergency management module includes: A local cache unit that stores role permission snapshots within the last 72 hours; A downgrading policy library that pre-sets permission limitation schemes corresponding to different HIS failure levels; Recovery validator, which automatically compares the consistency between the local cache and the latest HIS data after the HIS system is restored.
7. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 2, characterized in that, The tree structure visualization editing support includes: Drag-and-drop node adjustment, which reflects the changes in the permission inheritance relationship in real time; Batch rule import function, which is compatible with the HL7 FHIR standard medical data format; Rule version controller, which supports rollback and difference comparison of historical configurations.
8. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 3, characterized in that The dynamic selection mechanism includes: Sensitive field recognizer, which presets fields for matching patient ID numbers and diagnosis information based on regular expressions; Algorithm negotiation component, which negotiates with the terminal to determine the final encryption algorithm; Encryption performance monitor, which automatically switches to a lightweight algorithm when the detected encryption delay exceeds the threshold.
9. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 4, wherein The JWT payload contains: Role code, which adopts the hospital's unified identity authentication system standard; Ward hash value, which is generated by processing the original ward code through the SHA-256 algorithm; Terminal fingerprint, which is a unique identifier generated based on the device MAC address and operating system version.
10. The multi-role collaborative management architecture based on RBAC+HIS synchronization according to claim 5, characterized in that, The association process includes: Log normalization processing, which unifies the log formats of different systems into JSON Schema; Event time alignment, which uses the NTP protocol for cross-system clock synchronization; Association rule engine, which defines the log association path based on the medical business flow chart.
Citation Information
Patent Citations
Authority control method and device, storage medium and computer program product
CN119066673A
New-generation medical equipment integration engine
CN119807249A
AI optimal storage system having automatic storage function and capable of being connected with hospital HIS system
CN119829666A
Intelligent integrated disinfection supply management system
CN120069392A
Tracing code-based drug management method and system
CN120072239A
Cited By
Management system data caching and batch synchronization method and system based on multi-level cache
CN120723845A
VTE intelligent monitoring system supporting multi-role requirements
CN121506359A
Role-based knowledge base authority management and data access control method and system
CN121723500A
Multi-terminal role separation intelligent service platform for full scene of hospital
CN122417343A