Intelligent medical monitoring data security management method based on edge block chain

By combining the edge blockchain multi-layer architecture with PUF and SM9 technologies, the problems of data management and security authentication in smart medical monitoring systems have been solved, efficient and secure medical data processing and instant health warnings have been achieved, and the development of smart healthcare has been promoted.

CN120639795APending Publication Date: 2025-09-12NANJING INST OF TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510752771.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing smart medical monitoring systems lack effective data management and security authentication, resulting in inefficient data processing, storage, and sharing, and inability to achieve instant analysis and rapid response.

Method used

It adopts a multi-layer architecture based on edge blockchain, including device authentication layer, data collection layer, edge processing layer, data storage layer and data sharing layer, combined with physical unclonable function (PUF) and SM9 cryptography technology to achieve dual authentication of medical terminal devices and manage data access and sharing through smart contracts.

Benefits of technology

It achieves efficient and secure processing of medical data, enhances system security, optimizes operational efficiency, and provides immediate health warnings and comprehensive medical services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639795A_ABST
    Figure CN120639795A_ABST
Patent Text Reader

Abstract

In order to solve the problem of lack of effective authentication and data security management of medical terminal equipment in the prior art, the invention provides a smart medical monitoring data management method based on an edge block chain, and the method comprises the steps: building a multi-layer block chain network fused with edge calculation; registering a medical monitoring terminal device, and obtaining an identity identifier of the medical monitoring terminal device; after the registered user completes identity authentication, the user is bound with the medical monitoring terminal equipment, and a binding identifier is stored; collecting physiological data of a user through medical monitoring terminal equipment; authenticating the medical monitoring terminal equipment; the successfully authenticated medical monitoring terminal equipment uses the session key to carry out communication and data exchange with the edge layer equipment; user physiological data analysis is carried out on the edge layer equipment; and the blockchain network participants perform the management steps of sharing, processing, analyzing and cross-chain operation of the physiological data through the blockchain network. According to the invention, the medical monitoring data can be managed efficiently, safely and flexibly, and the subsequent communication security is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of smart medical technology, and in particular to a method for securely managing smart medical monitoring data based on edge blockchain. Background Art

[0002] With growing healthcare awareness and technological advancements, smart medical monitoring has become a key area. It uses various medical monitoring devices to collect real-time patient physiological data, providing crucial support for early diagnosis and treatment. However, existing technologies still face numerous challenges in data processing, storage, and sharing. Existing smart medical monitoring systems lack effective authentication and data security management for medical terminal devices.

[0003] Blockchain technology, with its decentralized, tamper-proof, and highly secure nature, offers a new solution for medical data management. It ensures the integrity and privacy of medical data while improving the transparency and efficiency of data exchange. Furthermore, edge computing, as a distributed computing paradigm, reduces data transmission latency and improves response speed by processing data at the edge of the network. In the field of medical monitoring, edge computing enables real-time analysis and processing of patient data, providing patients with faster medical services. Summary of the Invention

[0004] In response to the shortcomings of the existing technology, the present invention provides a smart medical monitoring data security management method based on edge blockchain, which solves the problem of lack of effective management of medical data in the existing technology, utilizes the computing power of edge nodes to provide fast data access and processing services, and realizes more secure and efficient data processing and storage.

[0005] To achieve the above object, the present invention adopts the following technical solutions:

[0006] A method for securely managing smart medical monitoring data based on edge blockchain, comprising the following steps:

[0007] Build a multi-layer blockchain network integrating edge computing;

[0008] Register the medical monitoring terminal device and obtain the medical monitoring terminal device identity identifier;

[0009] After the registered user completes identity authentication, the user is bound to the registered medical monitoring terminal device and the binding identifier is stored; the user's physiological data is collected through the medical monitoring terminal device;

[0010] Authenticate the medical monitoring terminal device; the successfully authenticated medical monitoring terminal device uses the session key to communicate and exchange data with the edge layer device; analyze the user's physiological data on the edge layer device;

[0011] Participants in the blockchain network perform management steps for sharing, processing, analyzing and cross-chain operations of physiological data through the blockchain network.

[0012] To optimize the above technical solutions, specific measures taken also include:

[0013] Furthermore, the architecture of the multi-layer blockchain network includes a device authentication layer, a data acquisition layer, an edge processing layer, a data storage layer, and a data sharing layer;

[0014] The device authentication layer is used for authentication of medical terminal devices;

[0015] The data collection layer is used for the medical monitoring terminal device to collect the user's physiological data, add a time stamp to each physiological data and perform encryption and signature;

[0016] The edge processing layer is a family medical center that is used to deploy smart contracts and analyze collected physiological data;

[0017] The data storage layer is used to store processed user physiological data;

[0018] The data sharing layer is used to share data between medical institutions and between doctors and patients;

[0019] The construction of a multi-layer blockchain network integrating edge computing is specifically as follows: each layer of the blockchain network is constructed, including:

[0020] At the device authentication layer, medical monitoring terminal devices are combined into a device authentication layer blockchain network to verify the identity and compliance of medical terminal devices, and the results are written into the blockchain;

[0021] Build an edge blockchain network at the edge processing layer, use edge computing capabilities to analyze and process data, and monitor the status of edge layer devices in real time;

[0022] At the data storage layer, medical institution servers form a blockchain network to conduct decentralized data management and classify and store data;

[0023] At the data sharing layer, medical device manufacturers, regulators, and third-party service providers establish blockchain networks to manage data access rights, sharing agreements, and compliance. Through smart contracts and permission management mechanisms, they ensure that only authorized users and regulators can access user physiological data.

[0024] Furthermore, the registered medical monitoring terminal device is specifically:

[0025] Generate a pair of public and private keys for each medical monitoring terminal device, and register the public key of the medical monitoring terminal device on the blockchain as the identity of the medical monitoring terminal device. The specific steps are as follows:

[0026] The medical monitoring terminal device is embedded with a PUF circuit for generating a Challenge-Response pair.

[0027] When a medical monitoring terminal device is used for the first time, it will be registered on the blockchain network and the device information will be stored;

[0028] Through the device interface, input the challenge value Challenge to the PUF circuit and obtain the response value Response;

[0029] Use the response value as a basis and combine it with other device information, including serial number and model, to generate a device identifier;

[0030] Hash the device identifier using a hash function to obtain a hash value of fixed length;

[0031] Using the identity-based public key encryption mechanism SM9, the hash value of the device identity identifier is used as input to obtain the device's unique SM9 private key SK and the corresponding public key PK, and the public-private key pair is distributed to registered medical monitoring terminal devices.

[0032] Furthermore, the user is bound to the registered medical monitoring terminal device specifically as follows:

[0033] Receive identification information provided by the user;

[0034] Use encryption algorithms to encrypt user identity information;

[0035] The user initiates an identity authentication request by entering a password or verifying biometrics;

[0036] Decrypt and verify the user's identity based on the identity authentication information provided by the user;

[0037] After the user identity is successfully authenticated, the user identity is bound to the device identity identifier;

[0038] Combining the user's encrypted identity information with the SM9 public key PK and response value Response of the medical monitoring terminal device, a hash function is used to generate a unique binding identifier l, and the hash summary H(l) of the binding identifier is recorded on the blockchain.

[0039] Furthermore, when the medical monitoring terminal device is connected to the blockchain network, the medical monitoring terminal device is authenticated, and the authentication participants also include the authentication center CA and the blockchain proxy server BPS.

[0040] Furthermore, the authentication of the medical monitoring terminal device is specifically as follows:

[0041] Medical monitoring terminal equipment E - Send device identity information to the certification authority CA User identity information And the first authentication request Request1, the formula is as follows:

[0042]

[0043] in, Indicates medical monitoring terminal equipment E - Message sent to the certification authority CA, text1 indicates the device identity information User identity information and the plaintext of the message consisting of the first authentication request Request1, Indicates that the medical monitoring terminal device signs text1. Express text1 is encrypted with CA's public key PK; || represents a message concatenation operator;

[0044] The authentication center CA decrypts the message sent to it by the medical monitoring terminal device Confirm the identity information of the medical monitoring terminal device, and if it is legal, respond to the first authentication request Request1. The authentication center CA queries the blockchain proxy server BPS for the medical monitoring terminal device E - The challenge value Challenge corresponding to the registration is stamped with the first timestamp T1 and encrypted together with the second authentication request Request2 and sent to the blockchain proxy server BPS. It is expressed as follows:

[0045]

[0046] in, M 2(CA→BPS) Indicates the message sent by the certification center CA to the blockchain proxy server BPS, and text2 indicates the device identity information The plain text of the message consisting of the second authentication request Request2 and the first timestamp T1, Express text2 is encrypted with the public key PK of BPS, Indicates that CA signs text2 with its private key;

[0047] The blockchain proxy server BPS decrypts the message M sent to it by the certification center CA 2(CA→BPS) If the first timestamp T1 is fresh, query the medical monitoring terminal device E- The challenge value Challenge during registration is stamped with the second timestamp T2. The rule for judging whether the timestamp is fresh is that the time interval between the current timestamp and the previous timestamp is less than the threshold;

[0048] Encrypt the message Sent to the certification authority CA, where M 3(BPS→CA) Indicates the message sent by BPS to CA. Express text3, T2 uses medical monitoring terminal equipment E - Public key PK encryption; Indicates that BPS uses the private key SK to sign text3, and text3 is represented by the challenge value Channel and device identity information and user identity information The composed message plaintext;

[0049] The certification center CA decrypts the message M sent to it by BPS 3(BPS→CA) If the second timestamp T2 is fresh, the signature verification is passed, and the medical monitoring terminal device E - If the identity information query is legal, then the third timestamp T3 is added, text3 is signed and encrypted and forwarded. Send a message For medical monitoring terminal equipment E _ ,At this point, BPS and CA have completed mutual authentication; Indicates that the authentication center CA sends a certificate to the medical monitoring terminal device E _ Messages sent; Indicates that CA encrypts with its own public key PK text3,T3; Indicates that CA signs text3 with its own private key SK;

[0050] Medical monitoring terminal equipment E - Decrypt the message sent by the certification authority CA If the third timestamp T3 is fresh, the challenge value Channel is used to calculate its own response value Response; then the user identity information, device identity information, challenge value Channel, and response value Response are combined for calculation, the calculation result is stamped with the fourth timestamp T4 and signed, and then the message is encrypted and sent. To the blockchain proxy server BPS, where Indicates medical monitoring terminal equipment E - Message sent to the blockchain proxy server BPS, Indicates that the blockchain proxy server BPS uses its own public key PK to text4 is encrypted, text4 represents the hash value and the fourth timestamp T4, H(·) represents a hash function;

[0051] Blockchain proxy server BPS decrypts data from medical monitoring terminal device E - News If the fourth timestamp T4 is fresh, use the medical monitoring terminal device E - The public key of the signature is used to verify the signature; if the verification is successful, text4 is used to match the binding identifier l. If the match is successful, the comprehensive verification is passed and BPS sends the message For medical monitoring terminal equipment E - , and authorized medical monitoring terminal equipment E - Perform subsequent operations; Cert is the certificate, text5 is the authentication information, obtained by XORing success and l. is the XOR symbol, Indicates that BPS sends data to device E. - The message sent, success is the plain text indicating successful verification, Indicates medical monitoring terminal equipment E - Encrypt (Cert, text5) with your own public key PK;

[0052] Medical monitoring terminal equipment E _ Decrypt and verify the message from the blockchain proxy server BPS, verify If success is obtained, the authentication is successful.

[0053] Furthermore, the successfully authenticated medical monitoring terminal device uses the session key to communicate and exchange data with the edge layer device as follows:

[0054] The Ath medical monitoring terminal device selects the data to be sent, selects a random value k, and generates a renewable session key S. The medical monitoring terminal device uses the session key S to encrypt the data M to be sent, generating a data ciphertext C;

[0055] The Ath medical monitoring terminal device uses its SM9 private key SK A Sign the data to be sent and get the signature SIG A ;

[0056] Use the SM9 public key of the Bth edge layer device receiving the data to encrypt the session key S and obtain the encrypted session key C S , the medical monitoring terminal device will ciphertext C, signature SIGA , encrypted session key C S and binding identifier 1 are sent to the edge layer device;

[0057] In the next encryption session, update the random value k and obtain a new session key S′;

[0058] The Bth edge layer device receives the ciphertext C and signature SIG from the Ath medical monitoring terminal device. A , encrypted session key C S and binding identifier l;

[0059] Edge layer devices use the SM9 public key PK of the medical monitoring terminal device A Verify the signature;

[0060] If the signature verification is successful, the edge layer device uses the received binding identifier l to calculate its hash value H(l) to verify the source of the data and the identity of the medical monitoring terminal device. Otherwise, the communication is rejected and the process is exited;

[0061] If the medical monitoring terminal device does not exist after binding identity verification, the edge layer device refuses to communicate and exits the process. Otherwise, the edge layer device uses its own SM9 private key SK B The encrypted session key C S Decrypt to obtain the session key S;

[0062] The edge layer device uses the session key S to decrypt the ciphertext C and restore the original data;

[0063] Edge layer devices confirm the integrity and origin of the data and complete the communication process.

[0064] Furthermore, the edge processing layer uses machine learning algorithms to analyze the collected user physiological data to identify health trends and potential health problems;

[0065] Health warnings are automatically triggered through smart contracts, and when analysis results indicate that the user may be at health risk, the user and relevant medical institutions are automatically notified.

[0066] Furthermore, the participants of the blockchain network include users, family medical centers, medical institution servers, medical institutions, medical equipment manufacturers, regulatory agencies and third-party service providers;

[0067] Medical institutions, medical device manufacturers, regulatory agencies, and third-party service providers manage data access rights and sharing agreements through the blockchain network. Participants in the blockchain network can access authorized user physiological data for the next step of specific treatment, related research, insurance reimbursement, and equipment updates.

[0068] Furthermore, the method further comprises:

[0069] Users and medical professionals view data analysis results and health trends through data visualization tools;

[0070] User-defined data reports allow users to choose the method and content of data display based on their needs.

[0071] The beneficial effects of the present invention are as follows: the present invention designs a smart medical monitoring data management method based on edge blockchain, which realizes efficient and secure processing of medical data by integrating a multi-layer blockchain architecture with edge computing technology. Utilizing physical unclonable functions (PUF) and SM9 cryptography technology, dual authentication is provided for device and user identity, enhancing the security of the system. Smart contracts are deployed to automate data sharing and compliance checks, improve operational efficiency, conduct in-depth analysis of user data, and provide timely warnings of health risks. This method not only optimizes the medical data management process, but also provides patients with comprehensive and continuous medical services, promoting the development of the smart medical field. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] Figure 1 is a flow chart of the present invention;

[0073] Figure 2 This is a diagram of the multi-layer blockchain architecture of the present invention. DETAILED DESCRIPTION

[0074] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0075] Example 1

[0076] This invention proposes a smart medical monitoring data security management method based on edge blockchain. The process of this method is as follows: Figure 1 As shown, the following steps are included:

[0077] Step 1: Build a multi-layer blockchain network integrating edge computing; the architecture of the multi-layer blockchain network includes device authentication layer, data collection layer, edge processing layer, data storage layer and data sharing layer; Figure 2 shown.

[0078] The device authentication layer is used to authenticate medical terminal devices; verify the identity and compliance of the device, and ensure that only authenticated devices can connect to the system and upload data.

[0079] The data collection layer is used by medical monitoring terminal devices to collect user physiological data, and blockchain technology is used to ensure the integrity and non-repudiation of data collection, and each physiological data is timestamped and encrypted.

[0080] The edge processing layer is a family medical center that is used to deploy smart contracts and analyze collected physiological data;

[0081] The data storage layer is used to store processed user physiological data; all processed data are stored on the blockchain, ensuring the data's immutability and transparency.

[0082] The data sharing layer is used to share data between medical institutions and between doctors and patients;

[0083] The construction of a multi-layer blockchain network integrating edge computing is specifically as follows: each layer of the blockchain network is constructed, including:

[0084] At the device authentication layer, medical monitoring terminal devices are combined into a device authentication layer blockchain network to verify the identity and compliance of medical terminal devices, and the results are written into the blockchain;

[0085] Build an edge blockchain network at the edge processing layer, use edge computing capabilities to analyze and process data, and monitor the status of edge layer devices in real time;

[0086] At the data storage layer, medical institution servers form a blockchain network to conduct decentralized data management and classify and store data;

[0087] At the data sharing layer, medical device manufacturers, regulators, and third-party service providers establish blockchain networks to manage data access rights, sharing agreements, and compliance. Through smart contracts and permission management mechanisms, they ensure that only authorized users and regulators can access user physiological data.

[0088] Step 2: Register the medical monitoring terminal device and obtain the medical monitoring terminal device identity identifier; the specific steps for registering the medical monitoring terminal device are:

[0089] Generate a pair of public and private keys for each medical monitoring terminal device, and register the public key of the medical monitoring terminal device on the blockchain as the identity of the medical monitoring terminal device. The specific steps are as follows:

[0090] The medical monitoring terminal device is embedded with a PUF (physically unclonable functions) circuit for generating a challenge-response pair.

[0091] When a medical monitoring terminal device is used for the first time, it will be registered on the blockchain network and the device information will be stored;

[0092] Through the device interface, input the challenge value Challenge to the PUF circuit and obtain the response value Response;

[0093] Use the response value as a basis and combine it with other device information, including serial number and model, to generate a device identifier;

[0094] Hash the device identifier using a hash function (such as SHA-256) to obtain a hash value of fixed length;

[0095] Using the identity-based public key encryption mechanism SM9, the hash value of the device identity identifier is used as input to obtain the device's unique SM9 private key SK and the corresponding public key PK, and the public-private key pair is distributed to registered medical monitoring terminal devices.

[0096] Step 3: After the registered user completes identity authentication, the user is bound to the registered medical monitoring terminal device and the binding identifier is stored; the user's physiological data is collected through the medical monitoring terminal device; the user is bound to the registered medical monitoring terminal device in the following specific steps:

[0097] Receive identification information provided by the user;

[0098] Use encryption algorithms to encrypt user identity information;

[0099] The user initiates an identity authentication request by entering a password or verifying biometrics;

[0100] Decrypt and verify the user's identity based on the identity authentication information provided by the user;

[0101] After the user identity is successfully authenticated, the user identity is bound to the device identity identifier;

[0102] Combining the user's encrypted identity information with the SM9 public key PK and response value Response of the medical monitoring terminal device, a hash function is used to generate a unique binding identifier l, and the hash summary H(l) of the binding identifier is recorded on the blockchain.

[0103] Step 4: Authenticate the medical monitoring terminal device. The successfully authenticated medical monitoring terminal device uses the session key to communicate and exchange data with the edge layer device. The edge layer device analyzes the user's physiological data. When the medical monitoring terminal device is connected to the blockchain network, the medical monitoring terminal device is authenticated. The authentication participants also include the authentication center CA and the blockchain proxy server BPS.

[0104] The specific certification of medical monitoring terminal equipment is as follows:

[0105] Medical monitoring terminal equipment E _ Send device identity information to the certification authority CA User identity information And the first authentication request Request1, the formula is as follows:

[0106]

[0107] in, Indicates medical monitoring terminal equipment E - Message sent to the certification authority CA, text1 indicates the device identity information User identity information and the plaintext of the message consisting of the first authentication request Request1, Indicates that the medical monitoring terminal device signs text1. Express text1 is encrypted with CA's public key PK; || represents a message concatenation operator;

[0108] The authentication center CA decrypts the message sent to it by the medical monitoring terminal device Confirm the identity information of the medical monitoring terminal device, and if it is legal, respond to the first authentication request Request1. The authentication center CA queries the blockchain proxy server BPS for the medical monitoring terminal device E - The challenge value Challenge corresponding to the registration is stamped with the first timestamp T1 and encrypted together with the second authentication request Request2 and sent to the blockchain proxy server BPS. It is expressed as follows:

[0109]

[0110] in, M 2(CA→BPS) Indicates the message sent by the certification center CA to the blockchain proxy server BPS, and text2 indicates the device identity information The plain text of the message consisting of the second authentication request Request2 and the first timestamp T1, Express text2 is encrypted with the public key PK of BPS, Indicates that CA signs text2 with its private key;

[0111] The blockchain proxy server BPS decrypts the message M sent to it by the certification center CA 2(CA→BPS) If the first timestamp T1 is fresh, query the medical monitoring terminal device E -The challenge value Challenge during registration is stamped with the second timestamp T2. The rule for judging whether the timestamp is fresh is that the time interval between the current timestamp and the previous timestamp is less than the threshold;

[0112] Encrypt the message Sent to the certification authority CA, where M 3(BPS→CA) Indicates the message sent by BPS to CA. Express text3, T2 uses medical monitoring terminal equipment E - Public key PK encryption; Indicates that BPS uses the private key SK to sign text3, and text3 is represented by the challenge value Channel and device identity information and user identity information The composed message plaintext;

[0113] The certification center CA decrypts the message M sent to it by BPS 3(BPS→CA) If the second timestamp T2 is fresh, the signature verification is passed, and the medical monitoring terminal device E - If the identity information query is legal, then the third timestamp T3 is added, text3 is signed and encrypted and forwarded. Send a message For medical monitoring terminal equipment E - ,At this point, BPS and CA have completed mutual authentication; Indicates that the authentication center CA sends a certificate to the medical monitoring terminal device E - Messages sent; Indicates that CA encrypts with its own public key PK text3,T3; Indicates that CA signs text3 with its own private key SK;

[0114] Medical monitoring terminal equipment E - Decrypt the message sent by the certification authority CA If the third timestamp T3 is fresh, the challenge value Channel is used to calculate its own response value Response; then the user identity information, device identity information, challenge value Challenge, and response value Response are combined for calculation, the calculation result is stamped with the fourth timestamp T4 and signed, and then the message is encrypted and sent To the blockchain proxy server BPS, where Indicates medical monitoring terminal equipment E - Message sent to the blockchain proxy server BPS, Indicates that the blockchain proxy server BPS uses its own public key PK to text4 is encrypted, text4 represents the hash value and the fourth timestamp T4, H(·) represents a hash function;

[0115] Blockchain proxy server BPS decrypts data from medical monitoring terminal device E - News If the fourth timestamp T4 is fresh, use the medical monitoring terminal device E - The public key of the signature is used to verify the signature; if the verification is successful, text4 is used to match the binding identifier l. If the match is successful, the comprehensive verification is passed and BPS sends the message For medical monitoring terminal equipment E - , and authorized medical monitoring terminal equipment E - Perform subsequent operations; Cert is the certificate, text5 is the authentication information, obtained by XORing success and l. is the XOR symbol, Indicates that BPS sends data to device E. - The message sent, success is the plain text indicating successful verification, Indicates medical monitoring terminal equipment E - Encrypt (Cert, text5) with your own public key PK;

[0116] Medical monitoring terminal equipment E - Decrypt and verify the message from the blockchain proxy server BPS, verify If success is obtained, the authentication is successful.

[0117] The successfully authenticated medical monitoring terminal device uses the session key to communicate and exchange data with the edge layer device as follows:

[0118] The Ath medical monitoring terminal device selects the data to be sent, selects a random value k, and generates a renewable session key S. The medical monitoring terminal device uses the session key S to encrypt the data M to be sent, generating a data ciphertext C;

[0119] The Ath medical monitoring terminal device uses its SM9 private key SK A Sign the data to be sent and get the signature SIG A ;

[0120] Use the SM9 public key of the Bth edge layer device receiving the data to encrypt the session key S and obtain the encrypted session key C S , the medical monitoring terminal device will ciphertext C, signature SIG A , encrypted session key C Sand binding identifier 1 are sent to the edge layer device;

[0121] In the next encryption session, update the random value k and obtain a new session key S′;

[0122] The Bth edge layer device receives the ciphertext C and signature SIG from the Ath medical monitoring terminal device. A , encrypted session key C S and binding identifier l;

[0123] Edge layer devices use the SM9 public key PK of the medical monitoring terminal device A Verify the signature; the edge layer device is located in the edge processing layer;

[0124] If the signature verification is successful, the edge layer device uses the received binding identifier l to calculate its hash value H(l) to verify the source of the data and the identity of the medical monitoring terminal device. Otherwise, the communication is rejected and the process is exited;

[0125] If the medical monitoring terminal device does not exist after binding identity verification, the edge layer device refuses to communicate and exits the process. Otherwise, the edge layer device uses its own SM9 private key SK B The encrypted session key C S Decrypt to obtain the session key S;

[0126] The edge layer device uses the session key S to decrypt the ciphertext C and restore the original data;

[0127] Edge layer devices confirm the integrity and origin of the data and complete the communication process.

[0128] The edge processing layer uses machine learning algorithms to analyze the collected user physiological data to identify health trends and potential health problems;

[0129] Health warnings are automatically triggered through smart contracts, and when analysis results indicate that the user may be at health risk, the user and relevant medical institutions are automatically notified.

[0130] Step 5: Participants in the blockchain network share, process, analyze, and manage cross-chain operations of physiological data through the blockchain network. Participants in the blockchain network include users, family medical centers, medical institution servers, medical institutions, medical device manufacturers, regulatory agencies, and third-party service providers.

[0131] Medical institutions, medical device manufacturers, regulatory agencies and third-party service providers manage data access rights and sharing agreements through the blockchain network. Participants in the blockchain network can access authorized user physiological data for the next step of specific treatment, related research, insurance reimbursement and equipment updates to provide comprehensive and continuous medical services.

[0132] The present invention also provides data visualization tools to enable users and medical professionals to intuitively understand data analysis results and health trends.

[0133] The present invention also supports user-defined data reports, allowing users to select the method and content of data display according to their own needs.

[0134] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0135] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions based on the principles of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, various improvements and modifications that do not depart from the principles of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A smart medical monitoring data security management method based on edge blockchain, characterized in that: The following steps are involved: Build a multi-layer blockchain network integrating edge computing; Register the medical monitoring terminal device and obtain the medical monitoring terminal device identity identifier; After the registered user completes identity authentication, the user is bound to the registered medical monitoring terminal device and the binding identifier is stored; Collect user physiological data through medical monitoring terminal equipment; Authenticate the medical monitoring terminal device; the successfully authenticated medical monitoring terminal device uses the session key to communicate and exchange data with the edge layer device; Analyze user physiological data on edge devices; Participants in the blockchain network perform management steps for sharing, processing, analyzing and cross-chain operations of physiological data through the blockchain network.

2. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 1, characterized in that: The architecture of the multi-layer blockchain network includes a device authentication layer, a data collection layer, an edge processing layer, a data storage layer, and a data sharing layer; The device authentication layer is used for authentication of medical terminal devices; The data collection layer is used for the medical monitoring terminal device to collect the user's physiological data, add a time stamp to each physiological data and perform encryption and signature; The edge processing layer is a family medical center that is used to deploy smart contracts and analyze collected physiological data; The data storage layer is used to store processed user physiological data; The data sharing layer is used to share data between medical institutions and between doctors and patients; The construction of a multi-layer blockchain network integrating edge computing is specifically as follows: each layer of the blockchain network is constructed, including: At the device authentication layer, medical monitoring terminal devices are combined into a device authentication layer blockchain network to verify the identity and compliance of medical terminal devices, and the results are written into the blockchain; Build an edge blockchain network at the edge processing layer, use edge computing capabilities to analyze and process data, and monitor the status of edge layer devices in real time; At the data storage layer, medical institution servers form a blockchain network to conduct decentralized data management and classify and store data; At the data sharing layer, medical device manufacturers, regulators, and third-party service providers establish blockchain networks to manage data access rights, sharing agreements, and compliance. Through smart contracts and permission management mechanisms, they ensure that only authorized users and regulators can access user physiological data.

3. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 1, characterized in that: The registered medical monitoring terminal device is specifically: Generate a pair of public and private keys for each medical monitoring terminal device, and register the public key of the medical monitoring terminal device on the blockchain as the identity of the medical monitoring terminal device. The specific steps are as follows: The medical monitoring terminal device is embedded with a PUF circuit for generating a Challenge-Response pair. When a medical monitoring terminal device is used for the first time, it will be registered on the blockchain network and the device information will be stored; Through the device interface, input the challenge value Challenge to the PUF circuit and obtain the response value Response; Use the response value as a basis and combine it with other device information, including serial number and model, to generate a device identifier; Hash the device identifier using a hash function to obtain a hash value of fixed length; Using the identity-based public key encryption mechanism SM9, the hash value of the device identity identifier is used as input to obtain the device's unique SM9 private key SK and the corresponding public key PK, and the public-private key pair is distributed to registered medical monitoring terminal devices.

4. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 1, characterized in that: The user is bound to the registered medical monitoring terminal device specifically as follows: Receive identification information provided by the user; Use encryption algorithms to encrypt user identity information; The user initiates an identity authentication request by entering a password or verifying biometrics; Decrypt and verify the user's identity based on the identity authentication information provided by the user; After the user identity is successfully authenticated, the user identity is bound to the device identity identifier; Combining the user's encrypted identity information with the SM9 public key PK and response value Response of the medical monitoring terminal device, a hash function is used to generate a unique binding identifier l, and the hash summary H(l) of the binding identifier is recorded on the blockchain.

5. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 1, wherein: When the medical monitoring terminal device is connected to the blockchain network, the medical monitoring terminal device is authenticated, and the authentication participants also include the authentication center CA and the blockchain proxy server BPS.

6. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 5, characterized in that: The authentication of the medical monitoring terminal device is specifically as follows: Medical monitoring terminal equipment E - Send device identity information Info to the certification center CA E_ , User identity information Info U_ And the first authentication request Request1, the formula is as follows: Where text1 = Info E_ ||Info U_ ||Request1,M 1(E_→CA) Indicates medical monitoring terminal equipment E - Message sent to the certification center CA, text1 represents the device identity information Info E- , User identity information Info U- and the plaintext of the message consisting of the first authentication request Request1, Indicates that the medical monitoring terminal device signs text1. Express text1 is encrypted with CA's public key PK; || represents a message concatenation operator; The authentication center CA decrypts the message M sent to it by the medical monitoring terminal device 1(E_→CA) , confirm the identity information of the medical monitoring terminal device, and if it is legal, respond to the first authentication request Request1. The authentication center CA queries the blockchain proxy server BPS for the medical monitoring terminal device E - The challenge value Challenge corresponding to the registration is stamped with the first timestamp T1 and encrypted together with the second authentication request Request2 and sent to the blockchain proxy server BPS. It is expressed as follows: Where text2 = Info E- ||Request2||T1;M 2(CA→BPS) Indicates the message sent by the certification center CA to the blockchain proxy server BPS, and text2 indicates the device identity information Info E- , the message plaintext consisting of the second authentication request Request2 and the first timestamp T1, Express text2 is encrypted with the public key PK of BPS, Indicates that CA signs text2 with its private key; The blockchain proxy server BPS decrypts the message M sent to it by the certification center CA 2(CA→BPS) If the first timestamp T1 is fresh, query the medical monitoring terminal device E - The challenge value Challenge during registration is stamped with the second timestamp T2. The rule for judging whether the timestamp is fresh is that the time interval between the current timestamp and the previous timestamp is less than the threshold; The encrypted message M 3(BPS→CA) : Sent to the certification authority CA, where text3 = Channel||Info E_ ||Info U_ ;M 3(BPS→CA) Indicates the message sent by BPS to CA. Express text3, T2 uses medical monitoring terminal equipment E - Public key PK encryption; Indicates that BPS uses the private key SK to sign text3, and text3 is represented by the challenge value Channel and the device identity information Info E- and user identity information Info U- The composed message plaintext; The certification center CA decrypts the message M sent to it by BPS 3(BPS→CA) If the second timestamp T2 is fresh, the signature verification is passed, and the medical monitoring terminal device E _ If the identity information query is legal, then the third timestamp T3 is added, text3 is signed and encrypted and forwarded, text3 = Channel||Info E- ||Info U- , send message M 4(CA→E-) : For medical monitoring terminal equipment E - At this time, BPS and CA have completed mutual authentication; M 4(CA→E-) Indicates that the authentication center CA sends a certificate to the medical monitoring terminal device E - Messages sent; Indicates that CA encrypts with its own public key PK Indicates that CA signs text3 with its own private key SK; Medical monitoring terminal equipment E - Decrypt the message M sent by the certification center CA 4(CA→E-) If the third timestamp T3 is fresh, the challenge value Channel is used to calculate its own response value Response; then the user identity information, device identity information, challenge value Challenge, and response value Response are combined for calculation, the calculation result is stamped with the fourth timestamp T4 and signed, and then the message M is encrypted and sent. 5(E-→BPS) : To the blockchain proxy server BPS, where text4 = H(Info U ||Info E- ||Challenge||Response)||T4;M 5(E-→BPS) Indicates medical monitoring terminal equipment E - Message sent to the blockchain proxy server BPS, Indicates that the blockchain proxy server BPS uses its own public key PK to Encryption, text4 represents the hash value H (Info U ||Info E- ||Challenge||Response) and a fourth timestamp T4, where H(·) represents a hash function; Blockchain proxy server BPS decrypts data from medical monitoring terminal device E - Message from M 5(E-→BPS) If the fourth timestamp T4 is fresh, use the medical monitoring terminal device E - The public key of the signature is used to verify the signature; if the verification is successful, text4 is used to match the binding identifier l. If the match is successful, the comprehensive verification is passed and BPS sends the message M 6(BPS→E-) : For medical monitoring terminal equipment E - , and authorized medical monitoring terminal equipment E - Perform subsequent operations; Cert is the certificate, text5 is the authentication information, obtained by XORing success and l. Is the XOR symbol, M 6(BPS→E-) Indicates that BPS sends data to device E. - The message sent, success is the plain text indicating successful verification, Indicates medical monitoring terminal equipment E - Encrypt (Cert, text5) with your own public key PK; Medical monitoring terminal equipment E - Decrypt and verify the message from the blockchain proxy server BPS, verify If success is obtained, the authentication is successful.

7. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 1, characterized in that: The successfully authenticated medical monitoring terminal device uses the session key to communicate and exchange data with the edge layer device as follows: The Ath medical monitoring terminal device selects the data to be sent, selects a random value k, and generates a renewable session key S. The medical monitoring terminal device uses the session key S to encrypt the data M to be sent, generating a data ciphertext C; The Ath medical monitoring terminal device uses its SM9 private key SK A Sign the data to be sent and get the signature SIG A ; Use the SM9 public key of the Bth edge layer device receiving the data to encrypt the session key S and obtain the encrypted session key C S , the medical monitoring terminal device will ciphertext C, signature SIG A , encrypted session key C S and binding identifier 1 are sent to the edge layer device; In the next encryption session, update the random value k and obtain a new session key S′; The Bth edge layer device receives the ciphertext C and signature SIG from the Ath medical monitoring terminal device. A , encrypted session key C S and binding identifier l; Edge layer devices use the SM9 public key PK of the medical monitoring terminal device A Verify the signature; If the signature verification is successful, the edge layer device uses the received binding identifier l to calculate its hash value H(l) to verify the source of the data and the identity of the medical monitoring terminal device. Otherwise, the communication is rejected and the process is exited; If the medical monitoring terminal device does not exist after binding identity verification, the edge layer device refuses to communicate and exits the process. Otherwise, the edge layer device uses its own SM9 private key SK B The encrypted session key C S Decrypt to obtain the session key S; The edge layer device uses the session key S to decrypt the ciphertext C and restore the original data; Edge layer devices confirm the integrity and origin of the data and complete the communication process.

8. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 2, characterized in that: The edge processing layer uses machine learning algorithms to analyze the collected user physiological data to identify health trends and potential health problems; Health warnings are automatically triggered through smart contracts, and when analysis results indicate that the user may be at health risk, the user and relevant medical institutions are automatically notified.

9. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 1, characterized in that: Participants in the blockchain network include users, family medical centers, medical institution servers, medical institutions, medical device manufacturers, regulatory agencies, and third-party service providers; Medical institutions, medical device manufacturers, regulatory agencies, and third-party service providers manage data access rights and sharing agreements through the blockchain network. Participants in the blockchain network can access authorized user physiological data for the next step of specific treatment, related research, insurance reimbursement, and equipment updates.

10. The method for secure management of smart medical monitoring data based on edge blockchain according to claim 1, wherein: The method further comprises: Users and medical professionals view data analysis results and health trends through data visualization tools; User-defined data reports allow users to choose the method and content of data display based on their needs.

Citation Information

Cited By

  • Medical security data security management method and device based on block chain

    CN122317103A