A medical scientific research data key variable encryption method and system

CN114896613BActive Publication Date: 2026-09-25PEKING UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210532084.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-09
Publication Date
2026-09-25
Estimated Expiration
2042-05-09

AI Technical Summary

Benefits of technology

[0024]1、本发明具有快速,安全,方便的特点,能实现对变量进行加密、解密、打乱等操作,以解决医学科研数据隐私数据的安全保密需求,同时保留密文的特征,支持将密文纳入研究作为分类区分。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114896613B_ABST
    Figure CN114896613B_ABST
Patent Text Reader

Abstract

The application relates to a medical scientific research data key variable encryption method and system, which comprises the following steps: reading a data row, obtaining all variables in the data row; randomly selecting the data row based on a fixed container, and then selecting variables to be encrypted and decrypted; and adopting multi-thread concurrent encryption and decryption on the selected variables. The application can solve the security and privacy protection demand of medical scientific research data, retain the characteristics of ciphertext, support the classification and differentiation of ciphertext, and can be applied in the technical field of medical data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of medical data processing technology, and in particular to a method and system for encrypting key variables in medical research data. Background Technology

[0002] Medical research data collection focuses on information related to human diseases or health issues. The data volume is large and the scope is extremely broad, including basic personal information, daily lifestyle behaviors, physical examinations, and various test results. Therefore, the confidentiality of critical and private information is the most critical ethical issue in the use of medical research data.

[0003] Currently, the simplest and most common method for handling this critical information is to directly delete these key variables, preventing their analysis and utilization. However, this simplistic approach also has its drawbacks. Medical research data typically requires repeated use or linking to more data points through these key quantities. Therefore, traditional methods cannot meet these requirements. Summary of the Invention

[0004] To address the aforementioned problems, the purpose of this invention is to provide a method and system for encrypting key variables in medical research data. This method can solve the security and confidentiality requirements of medical research data while preserving the characteristics of the ciphertext and supporting the inclusion of the ciphertext in research for classification and differentiation.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: an encryption method for key variables of medical research data, comprising: reading data rows and obtaining all variables in the data rows; randomly selecting data rows based on a fixed container, and then selecting variables to be encrypted or decrypted, and performing encryption and decryption on the selected variables using multi-threaded concurrent methods.

[0006] Furthermore, the data in the read data rows is in the format of csv, txt, dta, or sas7bdat.

[0007] Furthermore, the random selection of data rows based on a fixed container includes:

[0008] After data encryption begins, a portion of the data is read into a fixed-size memory-based container until the container is full.

[0009] Before reading each new line of data, a line of data is randomly selected from the current container and output to the target file, and then the read data is stored back into the container; each line of data written to the target file is randomly selected from the container.

[0010] Furthermore, in the process of encrypting and decrypting the selected variables using multi-threaded concurrency, a key needs to be set. The method for generating the key includes:

[0011] The application number entered by the user is mixed with a salt generated by the local operating system to generate the first intermediate text;

[0012] The first intermediate text is Base64 encoded to generate the second intermediate text;

[0013] The second intermediate text is hashed using MD5 to obtain the third intermediate text. The third intermediate text is then processed using HEX digest to convert the byte array to 16 bits, thus obtaining the key used for encryption and decryption operations.

[0014] Furthermore, the step of mixing the application number input by the user with a salt generated by the local operating system includes:

[0015] A seed file is generated on the local operating system. This seed file is bound to the operating system user. The content of the seed file is the salt used in the application number conversion process.

[0016] Furthermore, the encryption and decryption uses the AES-192 algorithm.

[0017] Furthermore, the step of encrypting and decrypting the selected variables using multi-threaded concurrent methods includes:

[0018] Two threads are started: the first thread reads data from the data row, and the second thread writes the encryption result to the data file.

[0019] Simultaneously, several third threads are started to perform concurrent encryption and decryption processing. These third threads extract variables from the input data line in parallel, encrypt and decrypt the selected variables, and then reassemble the encrypted and unencrypted variables into a data line. The combined data line is then sent to the second thread used for writing files. The second thread calls the operating system's append file interface to append the processed data line to the data file.

[0020] An encryption system for key variables in medical research data includes: a data reading module for reading data rows and obtaining all variables in the data rows; and an encryption / decryption module for randomly selecting data rows based on a fixed container, selecting variables to be encrypted / decrypted, and performing encryption / decryption on the selected variables using multi-threaded concurrent methods.

[0021] A computer-readable storage medium storing one or more programs, the one or more programs including instructions that, when executed by a computing device, cause the computing device to perform any of the methods described above.

[0022] A computing device includes: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include instructions for performing any of the methods described above.

[0023] The present invention has the following advantages due to the adoption of the above technical solutions:

[0024] 1. This invention is fast, safe, and convenient. It can perform operations such as encryption, decryption, and scrambling on variables to solve the security and confidentiality requirements of medical research data privacy, while retaining the characteristics of the ciphertext and supporting the inclusion of the ciphertext in research for classification and differentiation.

[0025] 2. This invention addresses the massive volume of medical research data by achieving a fast, efficient, and memory-efficient encryption / decryption process.

[0026] 3. This invention provides protection for the confidentiality and security of scientific research data, and supports encryption and decryption operations for extremely large files, providing convenience for researchers who study medical research data. Attached Figure Description

[0027] Figure 1 This is a schematic diagram of a method for encrypting key variables of medical research data in one embodiment of the present invention;

[0028] Figure 2 This is a schematic diagram illustrating the generation of a key in one embodiment of the present invention;

[0029] Figure 3 This is a schematic diagram of a multi-threaded concurrent encryption / decryption process in one embodiment of the present invention. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the described embodiments of the present invention are within the scope of protection of the present invention.

[0031] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments according to this application. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0032] To better describe the technical solution of this invention, the relevant terms are defined and explained as follows:

[0033] "Plaintext" refers to text that the user inputs or specifies and that needs to be encrypted.

[0034] A "key" refers to the password text that a user inputs or specifies to participate in the encryption process.

[0035] "Ciphertext" refers to the text output after encryption.

[0036] "Encryption" refers to the process of processing plaintext and a key to obtain ciphertext.

[0037] "Decryption" refers to the process of processing ciphertext and key to obtain plaintext.

[0038] "Encryption and decryption" is an abbreviation for two-way encryption and decryption operations.

[0039] In one embodiment of the present invention, a method for encrypting key variables of medical research data is provided. This embodiment illustrates the method by applying it to a terminal. It is understood that the method can also be applied to a server, and to a system including both a terminal and a server, and implemented through interaction between the terminal and the server. In this embodiment, the encryption or decryption operation is illustrated using a symmetric-key cryptography algorithm. Medical research data is typically structured data. Processing medical research data characterized by large volume and numerous variables is necessary, such as... Figure 1 As shown, the method includes the following steps:

[0040] 1) Read the data row and retrieve all variables in the data row;

[0041] 2) Randomly select data rows based on a fixed container, and then select variables to be encrypted or decrypted. Use multi-threaded concurrent encryption and decryption for the selected variables.

[0042] When in use, the data processing is based on the sequential reading and processing of operating system files. The encryption and decryption process does not involve plaintext context data, thus supporting concurrent operations to improve processing efficiency.

[0043] In step 1) above, the data in the read rows is in CSV, TXT, DTA, or SASS7BDAT formats. For CSV and TXT data formats, the data is usually stored in the file as readable text. Simply configure the data format and delimiter before reading to read it successfully. Variable names for this type of data are generally written in the first line of the file, so usually only one line needs to be read to obtain all variables in the data file. Other data formats require calling a software library for reading. This invention implements a unified and efficient data reading interface that can quickly read data files of different formats selected by the user. After selecting a data file, the user can choose to encrypt or decrypt one or more variables.

[0044] In step 2) above, the method of randomly selecting data rows based on a fixed container includes the following steps:

[0045] 2.1.1) After data encryption begins, a portion of the data is read into a fixed-size memory-based container (which must be able to store at least two lines of data) until the container is full;

[0046] 2.1.2) Before reading each new line of data, first randomly select a line of data from the current container and output it to the target file, and then store the read data back into the container;

[0047] By repeating steps 2.1.1) and 2.1.2), each line of data written to the target file is randomly selected from the container, thus ensuring that the data in the target file has been shuffled.

[0048] In step 2) above, when encrypting and decrypting the selected variables using multi-threaded concurrency, a key needs to be set. For example... Figure 2 As shown, the key generation method includes the following steps:

[0049] 2.2.1) Mix the application number entered by the user with the salt generated by the local operating system to generate the first intermediate text 1;

[0050] 2.2.2) Encode the first intermediate text 1 using Base64 to generate the second intermediate text 2;

[0051] 2.2.3) Perform MD5 hashing on the second intermediate text 2 to obtain the third intermediate text 3. Perform HEX digest processing on the third intermediate text 3 and convert the byte array to 16 bits to obtain the key for encryption and decryption operations.

[0052] In step 2.2.1) above, to prevent the encrypted data from being cracked due to software and application number leakage, the user-input application number is mixed with a salt generated by the local operating system. Specifically, a seed file is generated on the local operating system and bound to the operating system user. The content of the seed file is the salt generated during the application number conversion process. Different random salts are generated by the software for different users, thus improving the security of the encrypted data.

[0053] In step 2.2.1) above, the length of the application number differs from the length of the key required in the encryption / decryption method. For example, in this embodiment, encryption and decryption are implemented using the AES-192 algorithm, which requires a 32-bit key. However, the application number is input by the user, and the user's input is generally not exactly 32 bits. If truncation or padding is used, changes in the user's output will not be fully reflected in the key used in the operation. Therefore, this invention uses the above method for key setting to generate the key for the AES encryption / decryption algorithm.

[0054] In step 2) above, to achieve the ability to process large files and high processing efficiency, a data pipeline architecture is adopted during the data file reading process. Data is encrypted, decrypted, and written to the file line by line. This eliminates the need to read all data into memory before processing, thus minimizing memory usage. As long as there is a continuous input of data, the invention can continuously output data. Furthermore, because the data encryption and decryption process consumes CPU resources and is time-consuming, this invention employs a multi-threaded processing method.

[0055] Among them, such as Figure 3 As shown, the method for encrypting and decrypting selected variables using multi-threaded concurrency includes the following steps:

[0056] 2.3.1) Start two threads: the first thread is used to read data from the data row, and the second thread is used to write the encryption result to the data file;

[0057] 2.3.2) Since data encryption and decryption are relatively time-consuming, several third threads are started simultaneously for concurrent encryption and decryption processing (depending on the system hardware configuration, the default is twice the number of CPU cores) to improve the data processing speed. Several third threads extract variables from the input data line in parallel, encrypt and decrypt the selected variables, and then reassemble the encrypted and unencrypted variables into a data line. The combined data line is sent to the second thread for writing to the file. The second thread calls the operating system's append write interface to append the processed data line to the data file.

[0058] In summary, this invention implements encryption and decryption processing through a data pipeline, providing users with single-line data encryption and decryption calculations, allowing for convenient and simple data encryption and decryption operations. Based on the architecture of processing encryption and decryption data line by line through the data pipeline, this invention also implements the function of shuffling the output data. It adopts a multi-threaded concurrent encryption and decryption method. Due to the uncertainty of multi-threaded operation, the order of output data lines is randomly shuffled. Combined with a method of randomly selecting data lines based on a fixed container, the data shuffling is achieved. This invention can ensure the confidentiality and security of medical research data, and also supports encryption and decryption operations on very large files, providing convenience for researchers studying medical research data.

[0059] This invention also has the following advantages: 1. It supports users inputting an application number that is easy for them to remember, which participates in data encryption and decryption operations, thus binding the application number and the encrypted data. The application number undergoes security operations such as salting and hashing during encryption and decryption. 2. A seed file is generated by the local operating system, binding it to the operating system. Even if the software is leaked, it cannot be used to decrypt the data, improving security. 3. Users can select one or more variables and perform encryption and decryption operations only on the selected variables. 4. A simple encryption / decryption calculator function is provided, which can generate corresponding encrypted or verification encrypted data for data and application number, facilitating researchers to view or encrypt individual data entries. 5. The software uses multi-threading during encryption and decryption operations, making file reading, encryption / decryption, and file writing asynchronous, fully utilizing the operating system's multi-threading resources, thus enabling efficient processing of massive amounts of data. 6. Data volume is statistically analyzed during encryption and decryption, providing a data processing progress display function. 7. Data shuffling is achieved by setting small containers, consuming only parameter-level space resources.

[0060] In one embodiment of the present invention, an encryption system for key variables of medical research data is provided, comprising:

[0061] The data reading module reads data rows and retrieves all variables within those rows.

[0062] The encryption / decryption module randomly selects data rows from a fixed container, and then selects the variables to be encrypted / decrypted. The selected variables are then encrypted / decrypted concurrently using multi-threading.

[0063] In the above embodiments, the data in the data reading module is in the format of csv, txt, dta, sas7bdat.

[0064] In the above embodiments, in the encryption / decryption module, randomly selecting a data row based on a fixed container includes:

[0065] The container model reads a portion of the data into a fixed-size, memory-based container after data encryption begins, until the container is full.

[0066] The selection module first randomly selects a line of data from the current container and outputs it to the target file before reading a new line of data, and then stores the read data back into the container; each line of data written to the target file is randomly selected from the container.

[0067] In the above embodiments, during the encryption / decryption module's multi-threaded concurrent encryption / decryption of the selected variables, a key needs to be set. The key includes:

[0068] The first processing module mixes the application number input by the user with the salt generated by the local operating system to generate the first intermediate text;

[0069] The second processing module performs Base64 encoding on the first intermediate text to generate the second intermediate text.

[0070] The third processing module performs MD5 hashing on the second intermediate text to obtain the third intermediate text, performs HEX digest processing on the third intermediate text, and converts the byte array to 16 bits to obtain the key used for encryption and decryption operations.

[0071] In the above embodiments, in the first processing module, the application number input by the user is mixed with the salt generated by the local operating system. Specifically, a seed file is generated in the local operating system, which is bound to the operating system user. The content of the seed file is the salt in the application number conversion process.

[0072] In the above embodiments, encryption and decryption are implemented using the AES-192 algorithm.

[0073] In the above embodiments, the encryption / decryption module further includes using multi-threaded concurrent encryption / decryption of the selected variables:

[0074] The read / write module starts two threads: the first thread reads data from the data row, and the second thread writes the encrypted result to the data file.

[0075] The parallel processing module simultaneously starts several third threads to perform concurrent encryption and decryption processing. These third threads extract variables from the input data line in parallel, encrypt and decrypt the selected variables, and then reassemble the encrypted and unencrypted variables into a data line. The combined data line is then sent to the second thread for writing to the file. The second thread calls the operating system's append write interface to append the processed data line to the data file.

[0076] The system provided in this embodiment is used to execute the above-described method embodiments. For specific processes and details, please refer to the above embodiments, which will not be repeated here.

[0077] A schematic diagram of a computing device structure is provided in one embodiment of the present invention. This computing device can be a terminal, and may include: a processor, a communication interface, memory, a display screen, and an input device. The processor, communication interface, and memory communicate with each other via a communication bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. When the computer programs are executed by the processor, they implement an encryption method. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface is used for wired or wireless communication with external terminals. Wireless communication can be achieved through Wi-Fi, a management network, NFC (Near Field Communication), or other technologies. The display screen can be a liquid crystal display (LCD) or an e-ink display. The input device can be a touch layer covering the display screen, or buttons, a trackball, or a touchpad mounted on the casing of the computing device, or an external keyboard, touchpad, or mouse. The processor can invoke logical instructions in memory to execute the following methods: read data rows and obtain all variables in the data rows; randomly select data rows based on fixed containers, and then select variables to be encrypted or decrypted; and perform encryption and decryption on the selected variables concurrently using multiple threads.

[0078] Furthermore, the logical instructions in the aforementioned memory can be implemented as software functional units and sold or used as independent products, and can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0079] Those skilled in the art will understand that the structure of the above-described computing device is only a partial structure related to the solution of this application and does not constitute a limitation on the computing device to which the solution of this application is applied. A specific computing device may include more or fewer components, or combine certain components, or have different component arrangements.

[0080] In one embodiment of the present invention, a computer program product is provided, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions, when the program instructions are executed by a computer, the computer can execute the methods provided in the above method embodiments, such as: reading a data row and obtaining all variables in the data row; randomly selecting a data row based on a fixed container, and then selecting variables to be encrypted or decrypted, and performing encryption and decryption on the selected variables using multi-threaded concurrent methods.

[0081] In one embodiment of the present invention, a non-transitory computer-readable storage medium is provided, which stores server instructions that cause a computer to execute the methods provided in the above embodiments, such as: reading a data row and obtaining all variables in the data row; randomly selecting a data row based on a fixed container, and then selecting variables to be encrypted or decrypted, and performing encryption and decryption on the selected variables using multi-threaded concurrent methods.

[0082] The computer-readable storage medium provided in the above embodiments has a similar implementation principle and technical effect to the above method embodiments, and will not be described again here.

[0083] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0084] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0085] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0086] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for encrypting key variables in medical research data, characterized in that, include: Read the data row and retrieve all variables in the data row; The system randomly selects data rows from a fixed container, and then selects variables to be encrypted or decrypted. The selected variables are then encrypted or decrypted concurrently using multiple threads. The method of randomly selecting data rows based on a fixed container includes: After data encryption begins, a portion of the data is read into a fixed-size memory-based container until the container is full. Before reading each new line of data, a line of data is randomly selected from the current container and output to the target file, and then the read data is stored back into the container; each line of data written to the target file is randomly selected from the container. The method of encrypting and decrypting the selected variables using multi-threaded concurrent processing includes: Two threads are started: the first thread reads data from the data row, and the second thread writes the encryption result to the data file. Simultaneously, several third threads are started to perform concurrent encryption and decryption processing. These third threads extract variables from the input data line in parallel, encrypt and decrypt the selected variables, and then reassemble the encrypted and unencrypted variables into a data line. The combined data line is then sent to the second thread used for writing files. The second thread calls the operating system's append file interface to append the processed data line to the data file.

2. The encryption method for key variables in medical research data as described in claim 1, characterized in that, The data in the read data rows are in the formats of csv, txt, dta, and sas7bdat.

3. The encryption method for key variables in medical research data as described in claim 1, characterized in that, In the process of encrypting and decrypting the selected variables using multi-threaded concurrency, a key needs to be set. The key generation method includes: The application number entered by the user is mixed with a salt generated by the local operating system to generate the first intermediate text; The first intermediate text is Base64 encoded to generate the second intermediate text; The second intermediate text is hashed using MD5 to obtain the third intermediate text. The third intermediate text is then processed using HEX digest to convert the byte array to 16 bits, thus obtaining the key used for encryption and decryption operations.

4. The encryption method for key variables in medical research data as described in claim 3, characterized in that, The step of mixing the user-input application number with a salt generated by the local operating system includes: A seed file is generated on the local operating system. This seed file is bound to the operating system user. The content of the seed file is the salt used in the application number conversion process.

5. The encryption method for key variables in medical research data as described in claim 1, characterized in that, The encryption and decryption uses the AES-192 algorithm.

6. An encryption system for key variables in medical research data, used to implement the encryption method for key variables in medical research data as described in any one of claims 1-5, characterized in that, include: The data reading module reads data rows and retrieves all variables within those rows. The encryption / decryption module randomly selects data rows from a fixed container, and then selects the variables to be encrypted / decrypted. The selected variables are then encrypted / decrypted concurrently using multi-threading.

7. A computer-readable storage medium for storing one or more programs, characterized in that, The one or more programs include instructions that, when executed by a computing device, cause the computing device to perform any of the methods described in claims 1 to 5.

8. A computing device, characterized in that, include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs including instructions for performing any of the methods described in claims 1 to 5.

Citation Information

Patent Citations

  • Image verification code protection method and system based on SGX

    CN106228076A

  • Data processing method, device and equipment, medium and program product

    CN113014604A