A medical data access control method based on dynamic trust evaluation and zero trust model
By employing a dynamic trust assessment and zero-trust model access control approach, the problem of lacking dynamic assessment and continuous monitoring in traditional medical data access control is solved. This approach enables fine-grained and differentiated access control, reduces the risk of unauthorized access and data leakage, and improves the security and controllability of medical data access.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHAOXING SECOND HOSPITAL
- Filing Date
- 2026-03-23
- Publication Date
- 2026-06-19
AI Technical Summary
Existing medical data access control methods rely on static permission management and traditional boundary security models, lacking dynamic trust assessment and continuous security monitoring. This makes it difficult to achieve fine-grained and differentiated access control based on the sensitivity level and access context of medical data, resulting in a high risk of unauthorized access and data leakage.
An access control method based on dynamic trust assessment and zero trust model is adopted. Through multi-factor authentication, real-time trust assessment and continuous monitoring, access permissions are dynamically allocated, access control policies are executed in abnormal situations, and a full-process access audit log is recorded to optimize the model.
It enables fine-grained and differentiated access control for medical data, reduces the risk of unauthorized access and data leakage, improves the security and controllability of the access process, and adapts to the dynamic needs of medical data in multiple scenarios.
Smart Images

Figure PQFADLBXGCSCUUEHXDNIAYIXHS36U1QAO05HUYEQ
Abstract
Description
Technical Field
[0001] This application relates to the field of medical data security and information access control, and in particular to a medical data access control method based on dynamic trust assessment and a zero-trust model. Background Technology
[0002] With the deep integration of information technology and the healthcare industry, new medical service models such as smart healthcare, internet hospitals, telemedicine, and mobile healthcare are constantly developing. Medical information systems are gradually shifting from traditional closed, in-hospital systems to open, multi-terminal, and multi-scenario application models. Against this backdrop, it is increasingly common for healthcare professionals to access medical data resources such as Hospital Information Systems (HIS), Electronic Medical Records (EMR), and medical imaging systems through various terminal devices such as mobile phones, tablets, and laptops. The scope and application scenarios of medical data access are constantly expanding. However, with the increased mobility of medical data, its data security risks also increase. How to achieve efficient and convenient data access while ensuring medical data security has become a crucial technical issue in the current construction of smart healthcare.
[0003] Most existing medical data access control technologies are built on traditional network boundary security models, typically employing a "trusted internal network, untrusted external network" security approach. This involves controlling user access through firewalls, access control lists, and static permission management. In this model, the system authenticates users upon initial login and pre-configures access permissions based on user roles. Once authentication is successful, users can access relevant data resources within their authorized scope. However, with the widespread adoption of mobile office and telemedicine applications for healthcare workers, medical data access scenarios are characterized by diversified terminals, complex access environments, and dynamically changing access behaviors. Traditional access control methods based on static permission allocation are ill-suited to dynamic security needs. Once a user gains access, the lack of a continuous verification mechanism can easily lead to abuse of permissions and unauthorized access, thereby increasing the risk of medical data leakage.
[0004] Furthermore, existing medical data access control methods typically only perform authentication at the initial stage of access, lacking continuous monitoring and dynamic evaluation mechanisms throughout the access process. In practical applications, user access behavior can be influenced by various factors such as endpoint security status, changes in the network environment, or malicious attacks. For example, endpoint devices may have system vulnerabilities or malware, and user access behavior may exhibit abnormal access frequency, abnormal access periods, or unauthorized downloads. If the system cannot monitor these changes in real time and conduct dynamic risk assessments, it will be difficult to identify potential security threats in a timely manner, and thus unable to effectively defend against advanced persistent attacks (APT attacks) or hidden threats such as malicious operations by insiders.
[0005] Meanwhile, medical data is highly sensitive and valuable, often involving important data resources such as patient privacy, medical records, medical images, and genetic information. Different types of medical data vary significantly in terms of sensitivity and security requirements, but existing access control mechanisms typically employ coarse-grained permission divisions, making it difficult to differentiate management based on the sensitivity level and specific access scenarios of the medical data. For example, using a uniform permission control strategy for highly sensitive data such as electronic medical records, imaging data, or genetic data may lead to insufficient security protection; conversely, excessively restricting access may affect the efficiency of medical staff, thereby impacting the quality of medical services. Therefore, achieving a balance between security and operational efficiency is a significant challenge in medical data security management.
[0006] Furthermore, traditional medical data security protection systems largely rely on post-incident traceability mechanisms such as log auditing, which locate the source of the problem through log analysis after a data breach or abnormal access incident occurs. However, this model often only provides remediation after a security incident, making it difficult to promptly block abnormal access behavior, which can easily lead to the expansion of data breaches and even irreparable losses. Meanwhile, with the implementation of the "Personal Information Protection Law of the People's Republic of China," the "Data Security Law," and related medical data security management regulations, higher requirements have been placed on the security management of the medical data access process, necessitating the achievement of full-process controllability, auditability, and traceability of data access behavior.
[0007] Regarding the aforementioned technologies, the inventors believe that existing medical data access control methods rely on static permission management and traditional boundary security models, lacking the ability to dynamically assess trust and continuously monitor user identity, terminal environment, and access behavior. They are unable to achieve fine-grained and differentiated access control based on the sensitivity level of medical data and access context, thus failing to effectively prevent unauthorized access and data leakage risks. Summary of the Invention
[0008] To address the technical problems of existing medical data access control methods that rely on static permission management and traditional boundary security models, lack dynamic trust assessment and continuous security monitoring capabilities, and are unable to achieve fine-grained access control based on the sensitivity level and access context of medical data, thus leading to a high risk of unauthorized access and data leakage, this application provides a medical data access control method based on dynamic trust assessment and a zero-trust model.
[0009] This application provides a medical data access control method based on dynamic trust assessment and a zero-trust model, which adopts the following technical solution: Firstly, a medical data access control method based on dynamic trust assessment and a zero-trust model includes the following steps: S1. Receive a medical data access request initiated by the user through the terminal, and obtain the identity authentication information and access request information submitted by the user; S2. Perform multi-factor authentication on the user, wherein the multi-factor authentication includes at least identity information authentication, biometric authentication, device feature authentication, and access scenario authentication. S3. After successful identity authentication, the system collects access terminal environment information, user access behavior information, and access context information in real time, and performs dynamic trust assessment based on the collected information to obtain the user's real-time trust value. S4. Dynamically allocate medical data access permissions based on the real-time trust value, user identity and responsibility information, and access data sensitivity level information; S5. During the user's data access process, the access behavior is monitored in real time, and the access permissions are dynamically adjusted according to the dynamically updated real-time trust value. S6. When the real-time trust value is detected to be lower than the preset threshold or the access behavior is abnormal, the access control policy is executed to restrict or block the abnormal access behavior. S7. After the access is completed, record the full access process audit log, and optimize and update the dynamic trust assessment model and access control policy based on the audit log.
[0010] By adopting the above technical solution, when a user initiates a medical data access request, the system conducts strict identity verification of the access subject through a multi-factor authentication mechanism. It can comprehensively consider multiple dimensions of information such as user identity information, biometric information, terminal device characteristics, and access scenario to ensure the authenticity and legitimacy of the access subject's identity. After identity authentication is passed, the system further collects access terminal environment information, user access behavior information, and access context information in real time, and calculates the user's real-time trust value through a dynamic trust assessment model to achieve continuous assessment of the access subject's security status. Based on this real-time trust value, combined with the user's responsibilities and roles and the sensitivity level of the medical data, the system can dynamically allocate corresponding data access permissions to achieve fine-grained and differentiated medical data access control. Meanwhile, during data access, the system continuously monitors user access behavior and dynamically adjusts access permissions based on real-time updated trust values. When a user's trust value decreases or abnormal access behavior is detected, the system can promptly trigger access control policies to restrict or block access to abnormal behavior, thereby effectively preventing unauthorized access and potential data leakage risks. By recording audit logs of the entire access process, the system can achieve traceable management of medical data access behavior and continuously optimize the dynamic trust assessment model and access control policies using audit data, enabling the system to have self-learning and self-optimization capabilities.
[0011] Optionally, the access terminal environment information includes terminal hardware information, operating system status, security configuration status, and network environment information, which are used to detect whether the terminal has vulnerabilities, malicious software, or unauthorized permission modifications.
[0012] By adopting the above technical solution, the system can comprehensively detect and evaluate the security status of the terminal used by the user when accessing medical data. By analyzing the terminal hardware information, operating system status, security configuration, and network environment information, it can promptly identify whether the terminal has security risks such as system vulnerabilities, malicious software, or unauthorized modification. Thus, the terminal security status is incorporated into the dynamic trust assessment basis during the access control process, improving the terminal security during medical data access and effectively reducing the risk of data leakage caused by insecure terminals.
[0013] Optionally, the user access behavior information includes access time period, access frequency, access data type, data download behavior, and operation behavior trajectory, and anomaly detection of user behavior is performed by establishing a baseline model of normal user behavior.
[0014] By adopting the above technical solutions, the system can establish a baseline model of normal user behavior, continuously analyze access time periods, access frequency, access data types, and operation behavior trajectories, thereby identifying abnormal access behaviors and conducting risk assessments, improving the ability to identify unauthorized access and abnormal data operations, and enhancing the level of security protection during medical data access.
[0015] Optionally, the access context information includes access time, access location, access device, access purpose, and access data sensitivity level information, which are used to determine whether the access behavior conforms to preset access rules.
[0016] By adopting the above technical solutions, the system can comprehensively consider contextual information such as access time, access location, access device, and access purpose to perform scenario-based rule matching and rationality judgment on user access behavior, thereby identifying abnormal requests that do not conform to access rules and improving the accuracy and security of medical data access control.
[0017] Optionally, the real-time trust value is obtained by weighting the terminal environment security score, user behavior compliance score, and access context compliance score, and the user trust level is divided into high trust level, medium trust level, and low trust level according to the real-time trust value.
[0018] By adopting the above technical solution, the system can form a real-time user trust value by weighting the terminal environment security score, user behavior compliance score, and access context compliance score, and classify different trust levels accordingly. This enables a quantitative assessment of user access risks, provides a reliable basis for dynamic access control, and improves the security and flexibility of medical data access control.
[0019] Optionally, the medical data is divided into multiple levels according to sensitivity, including ordinary data, generally sensitive data, highly sensitive data and extremely sensitive data, and different access control policies are configured for different data levels.
[0020] By adopting the above technical solutions, hierarchical management is implemented based on the sensitivity level of medical data, and differentiated access control policies are configured for different levels of data. This achieves key protection for highly sensitive medical data while also taking into account the access efficiency of ordinary data, thereby improving the refinement and rationality of medical data security management.
[0021] Optionally, the dynamic allocation of access permissions includes determining the range of data a user can access, operation permissions, and access duration based on the user's trust level, user identity and responsibilities, and the sensitivity level of the accessed data.
[0022] By adopting the above technical solutions, and combining user trust levels, identity responsibilities, and data sensitivity levels, the scope of data that users can access, operation permissions, and access duration can be dynamically controlled, thereby achieving refined permission management. This ensures the security of medical data while avoiding the impact on medical business efficiency due to excessive permission restrictions.
[0023] Optionally, when abnormal user access behavior is detected, differentiated access control policies are implemented according to the degree of abnormality, including restricting access permissions, triggering security alerts, or blocking access requests. During the process of users accessing medical data, the data transmission process is encrypted, and a secure transmission protocol is used to protect the data to prevent it from being stolen or tampered with during transmission.
[0024] By adopting the above technical solutions, differentiated control measures can be implemented according to the degree of risk when abnormal access behavior is detected, such as restricting permissions, triggering alarms, or blocking access. At the same time, the data transmission process is encrypted and protected through a secure transmission protocol, thereby effectively preventing data from being stolen or tampered with, and further improving the overall security of medical data access.
[0025] Second aspect. A medical data access control system based on dynamic trust assessment and a zero-trust model, characterized in that it includes: The identity authentication module is used to perform multi-factor authentication for users; The dynamic trust assessment module is used to collect terminal environment information, user behavior information, and access context information, and calculate the user's real-time trust value. The fine-grained access control module is used to dynamically allocate access permissions based on the user's real-time trust value, user identity and responsibilities, and data sensitivity level. The real-time monitoring module is used to monitor access behavior and update trust assessment results in real time during the user's access to medical data. The exception handling module is used to implement access restrictions or access blocking when abnormal access behavior is detected. The log auditing module is used to record the entire access process log and optimize and update the dynamic trust assessment model.
[0026] By adopting the above technical solution, a medical data access control system based on dynamic trust assessment and a zero-trust model was constructed. Through the collaborative work of multiple functional modules, the system achieves full-process security control over medical data access. The system first performs multi-factor authentication on users through the identity authentication module to ensure the authenticity and legitimacy of the access subject's identity. Subsequently, the dynamic trust assessment module comprehensively analyzes terminal environment information, user access behavior, and access context information to calculate the user's trust value in real time, thereby dynamically assessing the user's current access risk. On this basis, the fine-grained access control module dynamically allocates access permissions according to the user's trust level, identity and responsibilities, and the sensitivity level of medical data, realizing differentiated and refined access control. At the same time, the real-time monitoring module continuously monitors access behavior during the user's access to medical data and dynamically updates the trust assessment results. When abnormal access behavior is detected, the exception handling module can promptly implement access restrictions or access blocking measures to effectively prevent unauthorized access and data leakage risks. In addition, the log auditing module records and analyzes the entire access process to achieve traceable management of access behavior and continuously optimizes the dynamic trust assessment model and access control strategies to improve the overall security protection capability of the system.
[0027] Thirdly, a computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is run on the processor, it causes the processor to perform the method described in any one of claims 1 to 9.
[0028] By adopting the above technical solution, the processor can execute the medical data access control method to realize medical data security access control based on dynamic trust assessment and zero trust model, thereby improving the system's ability to identify and protect against abnormal access behavior.
[0029] In summary, this application includes at least one of the following beneficial technical effects: By introducing a multi-factor authentication mechanism, the user's identity, terminal device, and access scenario are comprehensively verified, thereby improving the reliability of the access subject's identity authentication and reducing the risk of unauthorized access from the source. By constructing a dynamic trust assessment mechanism, terminal environment information, user access behavior and access context are analyzed in real time to form a real-time user trust value, thereby realizing continuous assessment of the security status of the access subject. By combining user trust levels, identity responsibilities, and medical data sensitivity levels to implement fine-grained access control, differentiated and dynamic data access management can be achieved, ensuring data security while also taking into account the efficiency of medical business access. By monitoring user access behavior in real time and implementing permission restrictions, alerts, or access blocking measures when abnormal behavior is detected, unauthorized access and potential data leakage risks can be prevented in a timely manner. By recording audit logs of the entire process of accessing medical data and continuously optimizing the trust assessment model and access control policies based on the audit data, the system is equipped with self-learning and self-adaptive capabilities, thereby further improving the level of medical data security management. Attached Figure Description
[0030] Figure 1 This is a flowchart of the steps in an embodiment of this application. Detailed Implementation
[0031] The following is in conjunction with the appendix Figure 1 This application will be described in further detail.
[0032] This application discloses a medical data access control method based on dynamic trust assessment and a zero-trust model. (Refer to...) Figure 1 It includes the following steps: S1. Receive a medical data access request initiated by the user through the terminal, and obtain the identity authentication information and access request information submitted by the user; S2. Perform multi-factor authentication on the user, wherein the multi-factor authentication includes at least identity information authentication, biometric authentication, device feature authentication, and access scenario authentication. S3. After successful identity authentication, the system collects access terminal environment information, user access behavior information, and access context information in real time, and performs dynamic trust assessment based on the collected information to obtain the user's real-time trust value. S4. Dynamically allocate medical data access permissions based on the real-time trust value, user identity and responsibility information, and access data sensitivity level information; S5. During the user's data access process, the access behavior is monitored in real time, and the access permissions are dynamically adjusted according to the dynamically updated real-time trust value. S6. When the real-time trust value is detected to be lower than the preset threshold or the access behavior is abnormal, the access control policy is executed to restrict or block the abnormal access behavior. S7. After the access is completed, record the full access process audit log, and optimize and update the dynamic trust assessment model and access control policy based on the audit log; By implementing the above steps, the medical data access control mechanism based on dynamic trust assessment and zero trust model is constructed, transforming the medical data access process from the traditional static permission management mode to a dynamic and continuously trustworthy access control mode. When a user initiates an access request, the system uses a multi-factor authentication mechanism to verify the identity of the accessing entity from multiple dimensions, ensuring the legitimacy and security of the user's identity and terminal device. After successful authentication, the system dynamically assesses the user's security status by collecting terminal environment information, user access behavior information, and access context information in real time, and generates a real-time trust value. This provides a quantitative basis for access permission allocation. The system can dynamically allocate access permissions based on the user's identity and responsibilities, real-time trust level, and the sensitivity level of medical data, achieving fine-grained and differentiated access control for medical data. During user access, the system monitors access behavior in real time and continuously updates the trust assessment results. Once a decrease in the trust value or abnormal access behavior is detected, the system can promptly implement access restrictions or access blocking measures, effectively preventing unauthorized access and potential data leakage risks. In addition, by recording audit logs of the entire medical data access process and using audit data to continuously optimize the dynamic trust assessment model and access control strategies, the system possesses self-learning and adaptive capabilities, improving the security, reliability, and intelligence level of medical data access control. Example 1
[0033] This application discloses a medical data access control method based on dynamic trust assessment and a zero-trust model. This method can be deployed in a hospital information system platform, such as a hospital information system (HIS), electronic medical record system (EMR), medical imaging system (PACS), or regional medical information platform, to perform security control on the process of medical staff, managers, and authorized third parties accessing medical data.
[0034] Reference Figure 1 The method described in this embodiment includes the following steps: S1. Receive a medical data access request initiated by the user through the terminal, and obtain the identity authentication information and access request information submitted by the user; Users can access the medical information system through internal hospital terminals or remote terminals, such as doctor workstations, mobile nursing terminals, tablets, or telemedicine terminals. When a user initiates an access request to the medical data platform through a terminal, the system first receives the user's request and obtains the user's authentication information and access request information. The authentication information may include username, account, and password information, while the access request information may include the data type requested, the type of access operation, and the purpose of access.
[0035] S2. Perform multi-factor authentication on the user, wherein the multi-factor authentication includes at least identity information authentication, biometric authentication, device feature authentication, and access scenario authentication. The system verifies user identity through multi-factor authentication. Identity verification can be performed using account passwords or identity tokens; biometric authentication can employ fingerprint, facial, or iris recognition; device authentication identifies legitimate access by checking device MAC addresses, fingerprints, or certificate information; and access scenario authentication determines if the user's current environment conforms to preset rules, such as whether they are within a hospital's authorized network or a legitimate access area. Only when all authentication conditions are met will the system allow the user to proceed with the subsequent access process.
[0036] S3. After successful identity authentication, the system collects access terminal environment information, user access behavior information, and access context information in real time, and performs dynamic trust assessment based on the collected information to obtain the user's real-time trust value. The system continuously collects security-related information during user access to medical data. This includes terminal environment information such as terminal hardware information, operating system status, security configuration status, and current network environment information, used to determine if the terminal has vulnerabilities, malicious programs, or unauthorized modifications. User access behavior information can include access time period, access frequency, access data type, data download behavior, and operation behavior trajectory, and anomaly detection is performed by establishing a baseline model of normal user behavior. Access context information may include access time, access location, access device type, access purpose, and the sensitivity level of the accessed medical data; The system performs a comprehensive analysis of the above multi-dimensional information and calculates the user's real-time trust value according to a preset evaluation model.
[0037] S4. Dynamically allocate medical data access permissions based on the real-time trust value, user identity and responsibility information, and access data sensitivity level information; In this embodiment, medical data is divided into multiple levels according to sensitivity, such as ordinary data, generally sensitive data, highly sensitive data, and extremely highly sensitive data. Among them: Ordinary data may include general statistical information; Sensitive data may generally include basic patient information; Highly sensitive data may include electronic medical records and medical imaging data; Highly sensitive data can include genetic data and data on the diagnosis and treatment of major diseases; The system dynamically determines user access permissions based on user trust level, user responsibilities and roles, and data sensitivity level. For example, it determines the range of data a user can access, the permissions to perform operations, and the time range during which access is allowed.
[0038] S5. During the user's data access process, the access behavior is monitored in real time, and the access permissions are dynamically adjusted according to the dynamically updated real-time trust value. The system continuously monitors user behavior during access to medical data, such as abnormal access frequency, abnormal data download behavior, or cross-permission access behavior. When the system detects a change in user behavior indicating a risk, it will recalculate the user's trust value and dynamically adjust access permissions, such as reducing access permissions or restricting the scope of access.
[0039] S6. When the real-time trust value is detected to be lower than the preset threshold or the access behavior is abnormal, the access control policy is executed to restrict or block the abnormal access behavior. When the system detects that a user's real-time trust value is lower than a preset security threshold, or detects abnormal access behavior, it can implement differentiated control strategies based on the degree of abnormal risk, such as: Restrict access to certain areas for minor abnormal behavior; Trigger security alerts and log security incidents for medium-risk behaviors; For high-risk behaviors, directly block access requests and terminate the session; Meanwhile, during the user's access to medical data, the system encrypts and protects the data transmission process through secure transmission protocols (such as HTTPS or TLS) to prevent the data from being stolen or tampered with during transmission.
[0040] S7. After the access is completed, record the full access process audit log, and optimize and update the dynamic trust assessment model and access control policy based on the audit log; After a user's access ends, the system records the entire access process information in the security audit log, such as user identity information, access time, access data type, operation behavior, and access results. By analyzing historical access logs, the system can continuously optimize the dynamic trust assessment model and access control policies, thereby improving the system's ability to identify and protect against abnormal access behavior.
[0041] Through the above steps, this embodiment can construct a medical data access control mechanism based on the zero-trust security concept, realize continuous identity verification, dynamic trust assessment and fine-grained permission control in the medical data access process, thereby effectively improving the security and controllability of the medical data access process.
[0042] This technical solution is based on the core zero-trust concept of "never trust, always verify," combined with dynamic trust assessment technology. It is divided into five modules to achieve closed-loop management of "identity verification - dynamic assessment - access control - real-time management - continuous optimization." We construct a five-layer architecture consisting of "identity authentication layer, dynamic trust assessment layer, fine-grained access control layer, real-time monitoring layer, and log auditing and optimization layer." With "identity as the root, data as the foundation, and security shifted left" as the core, we break through the traditional boundary protection logic and penetrate security control into the entire access process. This achieves the security protection goal of "access is verification, dynamic permission adjustment, and anomaly blocking," adapting to the multi-scenario access needs of medical data while balancing security and efficiency. Core module implementation: 1. Identity Authentication Layer: Employing a multi-factor authentication mechanism, abandoning the single password authentication mode, it combines "identity information (account password) + biometrics (fingerprint, face) + device characteristics (device ID, MAC address) + scenario characteristics (working hours, access location)" for multi-dimensional identity verification to ensure the authenticity and validity of the accessing user's identity. Simultaneously, unique identifiers are assigned to different entities such as medical staff, third-party maintenance personnel, and patients, binding their responsibilities, permissions, and access scope to achieve a one-to-one correspondence between identity and permissions, laying the foundation for subsequent dynamic evaluation.
[0043] 2. Dynamic Trust Assessment Layer: A dynamic trust assessment model is designed to collect three core assessment indicators in real time. The Analytic Hierarchy Process (AHP) and fuzzy comprehensive evaluation method are used to calculate the user's real-time trust value, enabling continuous trust assessment of the accessing entity. Details are as follows: (1) Terminal environment assessment: Real-time collection of data such as hardware information, system status, security configuration (such as patch update status, antivirus software running status), and network environment (such as IP address, network type) of the access terminal to detect whether the terminal has security risks such as vulnerabilities, malicious software, root privilege cracking, etc., and to quantify the terminal environment security score; (2) User behavior assessment: Establish a baseline of normal behavior for medical staff (such as access time, access data type, access frequency, and operation behavior), collect user access behavior data in real time, compare with the behavior baseline, detect whether there are abnormal behaviors (such as downloading a large amount of data outside of working hours, accessing sensitive data unrelated to responsibilities, and abnormal login from other locations), and quantify user behavior compliance score. (3) Access Context Assessment: Real-time collection of access context information, including access time, access location, access device, access purpose, data sensitivity level, etc., to determine whether the context complies with preset rules (e.g., remote diagnosis and treatment only allows access to the corresponding patient data in designated medical locations and on designated terminals), and quantify the context compliance score; (4) Trust value calculation and level classification: The scores of the above three items are weighted and calculated to obtain the user's real-time trust value, and divided into three levels: "high trust (≥80 points), medium trust (60-79 points), and low trust (<60 points)". The trust value is updated in real time and dynamically adjusted according to the changes in the evaluation indicators, so as to realize the dynamic perception of the trust status of the access subject.
[0044] 3. Fine-grained access control layer: Based on the zero-trust principle of least privilege, and combined with dynamic trust assessment results and the sensitivity level of medical data, it achieves adaptive and refined access control. (1) Data sensitivity classification: Medical data is divided into four levels: Level 1 (ordinary data, such as public medical science popularization), Level 2 (generally sensitive data, such as ordinary outpatient records), Level 3 (highly sensitive data, such as electronic medical records and imaging data), and Level 4 (extremely sensitive data, such as gene data and infectious disease medical records). Different access control strategies are set for different levels of data. (2) Dynamic permission allocation: Based on the user's trust level, identity and responsibilities, access scenario and data sensitivity level, dynamic access permissions are allocated: users with high trust level can access highly sensitive data within their corresponding responsibilities, and access permissions are not restricted by location or device (adapted to remote diagnosis and treatment); users with medium trust level can only access generally sensitive data and below, and need to verify the purpose of access; users with low trust level are directly blocked from access and an alarm is triggered. (3) Access behavior control: Differentiated control rules are set for different access scenarios. For example, in the mobile office scenario for medical staff, the terminal is restricted to accessing only the patient data required for diagnosis and treatment on the same day and batch downloading is prohibited. In the remote diagnosis and treatment scenario, only the specified terminal and the specified IP address are allowed to access the corresponding patient data, and screenshots and forwarding are prohibited during the access process. This achieves refined control of access behavior and balances data security and diagnosis and treatment efficiency.
[0045] 4. Real-time Monitoring and Blocking Layer: Monitors the entire user access process in real time, connecting to the dynamic trust assessment layer and fine-grained access control layer. When the following situations are detected, corresponding control actions are immediately triggered: (1) When the trust value drops to a low trust level, or when there are serious security risks in the terminal environment, obvious abnormalities in user behavior, or when the access context does not conform to the preset rules, the access request will be blocked immediately and the user's access rights will be frozen. (2) When a minor anomaly occurs (such as the trust value dropping to the medium trust level or the terminal having a minor vulnerability), an alarm message is sent to the administrator and the accessing user, requiring the user to fix the terminal vulnerability in a timely manner and standardize the access behavior, while restricting their access permission level. (3) Monitor the data transmission process in real time and use encrypted transmission technology (SSL / TLS) to prevent data from being stolen or tampered with during transmission, ensure the security of medical data transmission, and adapt to the needs of remote diagnosis and treatment data transmission.
[0046] 5. Log Auditing and Optimization Layer: Records all user access data throughout the entire process, including identity authentication information, terminal environment data, user behavior data, trust assessment results, access permission allocation, abnormal events and handling results, etc., forming a complete audit log. It supports log querying, statistics and traceability, and meets regulatory compliance requirements. At the same time, based on the audit log data, machine learning algorithms are used to continuously optimize the user behavior baseline, trust assessment indicator weights and access control rules, improve the accuracy of dynamic trust assessment and the adaptability of access control, realize the system's self-optimization and iteration, and adapt to the dynamic changes in medical scenarios.
[0047] The method implementation steps of the technical solution in this application are clear and the entire process is closed-loop. The specific process is as follows: Step S1: Access Request Initiation -- Users (medical staff, third-party personnel, etc.) initiate medical data access requests through terminals (mobile phones, tablets, computers), and submit identity authentication information (account password, biometrics) and access requirements (data type of access, access purpose), adapting to multi-terminal access scenarios such as mobile office and remote diagnosis and treatment; Step S2: Multi-factor authentication -- The authentication layer verifies the user's submitted identity information from multiple dimensions. If the verification fails, access is blocked and an authentication failure message is returned. If the verification passes, proceed to the next step and record the identity authentication log. Step S3: Dynamic Trust Assessment Initialization -- The dynamic trust assessment layer collects terminal environment, user behavior initial data and access context information in real time, completes the initial trust value calculation, divides the initial trust level, and provides a basis for permission allocation; Step S4: Fine-grained permission allocation -- The fine-grained access control layer dynamically allocates access permissions (including the scope of accessible data, operation permissions, and access duration) based on the initial trust level, user identity and responsibilities, access purpose, and sensitivity level of the accessed data, and pushes the permission information to the user terminal. Step S5: Data Access and Real-time Monitoring -- Users access data within their assigned permissions. The real-time monitoring layer synchronously collects real-time data on the terminal environment, user behavior, and access context, dynamically updates the trust value, and monitors whether the access behavior complies with the control rules. Step S6: Anomaly Detection and Handling -- Determine if the real-time trust value is abnormal and if the access behavior is in violation: ① No anomaly (trust value remains at a medium-high level, access behavior is compliant), allow the user to continue accessing, continuously collect data and update the trust value; ② Minor anomaly (trust value drops to medium trust level, minor violation exists), trigger an alarm, restrict access permissions, and require the user to rectify; ③ Severe anomaly (trust value drops to low trust level, serious violation or attack behavior exists), immediately block access, freeze user permissions, and notify the administrator for handling; Step S7: Access End and Log Recording -- After the user completes the access, the system revoks the access permission, records the entire access process data, forms an audit log, archives and stores it, and supports subsequent querying and tracing; Step S8: Model Optimization -- Based on audit log data, the machine learning module continuously optimizes the user behavior baseline, trust assessment indicator weights, and access control rules to improve system performance and enter the next round of access control closed loop; Step S9: Compliance Audit (Regular) -- Administrators periodically query audit logs, conduct compliance audits, identify security risks, ensure that medical data access complies with relevant regulations, generate audit reports, and support further system optimization; The core logic of the process is to achieve closed-loop management of the entire access process, with "identity verification - dynamic evaluation - access control - real-time monitoring - optimization and iteration" as the core. This breaks the traditional static control model, adapts to the access needs of multiple medical scenarios, balances security and efficiency, and meets regulatory compliance requirements.
[0048] The significant achievements of the technical solution in this application are as follows: The method specifically addresses the technical pain points of traditional medical data access control, combining a zero-trust model with dynamic trust assessment technology, and is adapted to scenarios such as mobile office work and remote diagnosis and treatment for medical staff. It achieves significant results in data security protection, access efficiency, compliance, and scalability, as detailed below: 1. Significantly enhanced security protection capabilities, effectively preventing internal leaks and external attacks: Through continuous dynamic trust assessment and real-time monitoring throughout the entire process, it breaks through the limitations of traditional boundary protection, realizing "verification upon access and blocking upon anomalies." It can detect terminal environment vulnerabilities, abnormal user behavior, and external attack behaviors in real time, blocking abnormal access in advance, transforming "post-event tracing" into "in-process blocking and pre-event prevention." This significantly reduces the incidence of internal data leaks (such as unauthorized access and unauthorized downloads) and external attacks (such as APT attacks and malicious intrusions). Tests show that the abnormal access blocking rate is ≥99%, and the risk of data leaks is reduced by more than 95%, effectively protecting patient privacy and medical data security, and solving the inherent defects of traditional defense models. 2. Achieve refined and adaptive access control, balancing data security and treatment efficiency: Based on the sensitivity classification of medical data and dynamic trust assessment results, differentiated and fine-grained permission allocation is achieved. Access permissions can be dynamically adjusted according to the access scenario and user trust level. This avoids the problem of "over-control affecting the efficiency of mobile office and remote diagnosis and treatment for medical staff" and solves the dilemma of "insufficient control leading to security vulnerabilities". It adapts to the multi-scenario access needs of medical data, ensuring that medical staff can carry out diagnosis and treatment work efficiently within the scope of compliance and improving the efficiency of diagnosis and treatment service connection. After pilot application, the efficiency of remote access for medical staff has increased by more than 40%, while no data security violations have occurred, achieving a balance between security and efficiency. 3. Compliant with regulations and achieves compliant management: The entire access process is recorded and audited, supporting log query, statistics and traceability. It can accurately locate abnormal access behavior and responsible parties, fully complying with the requirements of relevant laws and regulations such as the Personal Information Protection Law and the Medical Data Security Guidelines for medical data security management. This avoids the risk of penalties faced by hospitals due to data security violations, while improving the standardization of hospital data security management and helping hospitals achieve compliant development in the process of digital and intelligent transformation. 4. Strong adaptability and scalability: This method adopts a modular architecture design, which can flexibly adapt to various medical data access scenarios such as mobile office work for medical staff, remote diagnosis and treatment, and clinical research. It supports flexible expansion of terminal types (mobile phones, tablets, computers, medical devices) and user subjects (medical staff, third-party operation and maintenance, patients). At the same time, through machine learning, the model can achieve self-optimization, and can dynamically optimize evaluation indicators and control rules according to changes in medical data security needs, attack methods, and policy adjustments. It does not require large-scale system transformation, reduces the cost of hospital data security upgrades, adapts to the long-term development needs of smart healthcare, and can be widely applied to medical data security management scenarios in hospitals and medical research institutions at all levels. It has broad application prospects and can promote the deep integration of the zero trust concept and medical digitalization, reshaping a new paradigm for medical data security protection. 5. Reduce management costs and improve management efficiency: Automated processes such as identity authentication, dynamic trust assessment, and anomaly blocking reduce manual intervention and lower the labor costs of hospital data security management. At the same time, through audit logs and model self-optimization, it helps administrators accurately identify security risks, improves data security management efficiency, and solves the problems of "low efficiency and easy omission" in traditional manual control. It helps hospitals achieve automated and intelligent upgrades in data security management and provides security guarantees for the high-quality development of hospitals. 6. Protecting the value of medical data assets: Through refined, end-to-end security management, the integrity, confidentiality, and availability of medical data are effectively protected, avoiding medical disputes, research losses, and reputational damage caused by data leaks or tampering. This fully leverages the core asset value of medical data in precision diagnosis, clinical research, and public health decision-making, promoting the high-quality development of smart healthcare. It also aligns with the national smart healthcare development strategy and medical data security management requirements, possessing significant social benefits and application value. It can be widely promoted and applied, providing technical support and practical reference for data security protection in the medical industry.
[0049] The implementation principle of a medical data access control method based on dynamic trust assessment and a zero-trust model in this application is as follows: By constructing an access control mechanism centered on "continuous verification and dynamic trust," when a user initiates a medical data access request, the system first verifies the identity of the access subject through multi-factor authentication. After successful authentication, it continuously collects information on the access terminal environment, user access behavior, and access context. The system then uses a dynamic trust assessment model to comprehensively analyze and quantify the user's current security status to obtain a real-time trust value. The system then dynamically allocates the user's accessible data range, operation permissions, and access duration based on the user's identity, responsibilities, and the sensitivity level of the medical data, achieving fine-grained access control. During the user's access process, the system continuously updates the user's trust value by monitoring access behavior in real time. When a decrease in the trust value or abnormal access behavior is detected, the system immediately executes the access control policy to restrict or block access permissions to prevent unauthorized access and potential data leakage risks. Simultaneously, a complete audit log is recorded after the access ends, and the trust assessment model and access control policy are optimized by analyzing historical access data, enabling the system to have continuous learning and adaptive capabilities, achieving continuous trust, dynamic controllability, and security protection during the medical data access process.
[0050] The above are all preferred embodiments of this application, and are not intended to limit the scope of protection of this application. Therefore, all equivalent changes made in accordance with the structure, shape and principle of this application should be covered within the scope of protection of this application.
Claims
1. A medical data access control method based on dynamic trust assessment and a zero-trust model, characterized in that, Includes the following steps: S1. Receive a medical data access request initiated by the user through the terminal, and obtain the identity authentication information and access request information submitted by the user; S2. Perform multi-factor authentication on the user, wherein the multi-factor authentication includes at least identity information authentication, biometric authentication, device feature authentication, and access scenario authentication. S3. After successful identity authentication, the system collects access terminal environment information, user access behavior information, and access context information in real time, and performs dynamic trust assessment based on the collected information to obtain the user's real-time trust value. S4. Dynamically allocate medical data access permissions based on the real-time trust value, user identity and responsibility information, and access data sensitivity level information; S5. During the user's data access process, the access behavior is monitored in real time, and the access permissions are dynamically adjusted according to the dynamically updated real-time trust value. S6. When the real-time trust value is detected to be lower than the preset threshold or the access behavior is abnormal, the access control policy is executed to restrict or block the abnormal access behavior. S7. After the access is completed, record the full access process audit log, and optimize and update the dynamic trust assessment model and access control policy based on the audit log.
2. The medical data access control method based on dynamic trust assessment and zero-trust model according to claim 1, characterized in that: The access terminal environment information includes terminal hardware information, operating system status, security configuration status, and network environment information, which is used to detect whether the terminal has vulnerabilities, malicious software, or unauthorized modifications.
3. The method according to claim 1, characterized in that: The user access behavior information includes access time period, access frequency, access data type, data download behavior, and operation behavior trajectory, and anomaly detection of user behavior is performed by establishing a baseline model of normal user behavior.
4. The method according to claim 1, characterized in that: The access context information includes access time, access location, access device, access purpose, and access data sensitivity level information, which is used to determine whether the access behavior conforms to the preset access rules.
5. The method according to claim 1, characterized in that: The real-time trust value is obtained by weighting the terminal environment security score, user behavior compliance score, and access context compliance score, and the user trust level is divided into high trust level, medium trust level, and low trust level according to the real-time trust value.
6. The method according to claim 1, characterized in that: The medical data is divided into multiple levels according to sensitivity, including ordinary data, generally sensitive data, highly sensitive data, and extremely sensitive data, and different access control policies are configured for different data levels.
7. The method according to claim 1, characterized in that: The dynamic allocation of access permissions includes determining the range of data a user can access, operation permissions, and access duration based on the user's trust level, user identity and responsibilities, and the sensitivity level of the accessed data.
8. The method according to claim 1, characterized in that: When abnormal user access behavior is detected, differentiated access control policies are implemented according to the degree of abnormality, including restricting access permissions, triggering security alerts, or blocking access requests. During the process of users accessing medical data, the data transmission process is encrypted, and a secure transmission protocol is used to protect the data to prevent it from being stolen or tampered with during transmission.
9. A medical data access control system based on dynamic trust assessment and a zero-trust model, characterized in that, include: The identity authentication module is used to perform multi-factor authentication for users; The dynamic trust assessment module is used to collect terminal environment information, user behavior information, and access context information, and calculate the user's real-time trust value. The fine-grained access control module is used to dynamically allocate access permissions based on the user's real-time trust value, user identity and responsibilities, and data sensitivity level. The real-time monitoring module is used to monitor access behavior and update trust assessment results in real time during the user's access to medical data. The exception handling module is used to implement access restrictions or access blocking when abnormal access behavior is detected. The log auditing module is used to record the entire access process log and optimize and update the dynamic trust assessment model.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is run on the processor, it causes the processor to perform the method described in any one of claims 1 to 9.