Blockchain-based Medical Data Processing Method, Device, and Computer Equipment
By receiving data call requests from medical service nodes in the blockchain network and obtaining and storing data according to the medical data sharing protocol, data barriers and security issues in traditional medical data sharing are solved, and efficient and secure medical data processing and sharing are achieved.
Patent Information
- Application Number
- CN202210949645.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-09
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-08-09
AI Technical Summary
Traditional medical data sharing methods have data barriers, security issues, and the high throughput and query performance requirements of blockchain storage services are difficult to achieve, making it difficult to share data.
By receiving the data call request of the target medical service node in the blockchain network, the target medical data is obtained according to the pre-stored medical data sharing protocol, and the data is sent to the target medical service node, and the call information is on the chain to be stored.
The blockchain-based medical data processing optimization is realized. By introducing patient roles and expandable medical data sharing protocols, data barriers are solved, data processing efficiency is improved, and the authenticity and security of shared data are ensured.
Smart Images

Figure CN115396113B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technologies, and in particular, to a medical data processing method, apparatus, computer device, storage medium, and computer program product based on blockchain. Background Art
[0002] With the development of blockchain technology, the medical data sharing method based on blockchain has brought great help to the treatment and analysis of diseases. In traditional methods, data sharing is usually carried out for the existing data among medical institutions, which is not conducive to the introduction of new data for sharing. There are relatively large data barriers among medical institutions, resulting in difficulty in achieving true data sharing, difficulty in solving data security problems, and relatively strict requirements for storage services in the blockchain system. The storage service is required to have a high throughput and good query performance, making it difficult to implement blockchain data sharing. Summary of the Invention
[0003] Based on this, in view of the above technical problems, it is necessary to provide a medical data processing method, apparatus, computer device, storage medium, and computer program product based on blockchain that can solve the above problems.
[0004] In a first aspect, the present application provides a medical data processing method based on blockchain, the method including:
[0005] Receiving a data call request sent by a target medical service node in a blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores an association relationship pre-determined between a patient client corresponding to the target patient and the target medical service node;
[0006] Obtaining target medical data according to a medical data sharing protocol corresponding to the target patient pre-stored; the medical data sharing protocol is used to represent the sharing scope of the medical data of the target patient;
[0007] Sending the target medical data to the target medical service node, and storing the call information corresponding to the data call request on the blockchain.
[0008] In one embodiment, before the step of receiving a data call request sent by a target medical service node in the blockchain network, the method further includes:
[0009] Constructing a blockchain network including multiple medical service nodes based on blockchain network configuration parameters and data security parameters;
[0010] Receive the registration verification requests sent by each of the medical service nodes, and perform registration verification operations on each of the medical service nodes; the registration verification requests carry node verification parameters corresponding to the medical service nodes.
[0011] Receive the registration request sent by the patient client corresponding to the target patient, and perform a registration operation on the patient client; the registration request carries identity verification parameters corresponding to the patient client.
[0012] In one embodiment, call audit information for the medical data of each patient is stored in the blockchain network, and the call audit information is used to verify the call identity situation and data security situation when requesting to call the medical data of each patient; after the call audit is passed, the blockchain network obtains the medical data to be called through a preset database, and the preset database is used to store the medical data of each patient.
[0013] In one embodiment, the receiving the registration request sent by the patient client corresponding to the target patient and performing a registration operation on the patient client includes:
[0014] Generate patient identification information for the target patient according to the identity verification parameters corresponding to the patient client and send it to the patient client;
[0015] Correspondingly store the identity verification parameters and the patient identification information of the target patient.
[0016] In one embodiment, before the step of receiving a data call request sent by a target medical service node in the blockchain network, the method further includes:
[0017] Receive a medical visit association request sent by the target medical service node; the medical visit association request carries node verification parameters corresponding to the target medical service node and identity verification parameters corresponding to the patient client;
[0018] Based on the node verification parameters and the identity verification parameters, establish an association relationship between the patient client corresponding to the target patient and the target medical service node, and send association relationship record information to the target medical service node; both the patient client and the target medical service node have association key information.
[0019] In one embodiment, before the step of obtaining target medical data according to the medical data sharing protocol corresponding to the target patient stored in advance, the method further includes:
[0020] Receive the protocol chain - up request sent by the target medical service node; the protocol chain - up request carries a medical data sharing protocol, and the medical data sharing protocol is generated after passing the verification using the associated key information, in combination with the node verification parameters corresponding to the target medical service node, the identity verification parameters corresponding to the patient client, and the associated relationship record information.
[0021] Correspondingly store the medical data sharing protocol with the target patient corresponding to the patient client.
[0022] In one embodiment, the method further includes:
[0023] Receive the data upload request sent by the target medical service node, generate an upload address parameter and a timestamp information, and send them to the target medical service node.
[0024] Obtain the medical data upload information sent by the target medical service node; the medical data upload information is obtained by the target medical service node according to the upload address parameter, the timestamp information, and the target patient's medical treatment data combination.
[0025] Parse the medical data upload information, obtain the target patient's medical treatment data and store it.
[0026] Chain - up and store the upload information corresponding to the data upload request.
[0027] In a second aspect, the present application also provides a blockchain - based medical data processing device, and the device includes:
[0028] A data call request receiving module, configured to receive a data call request sent by a target medical service node in a blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre - determined association relationship between the patient client corresponding to the target patient and the target medical service node.
[0029] A target medical data determining module, configured to obtain target medical data according to the pre - stored medical data sharing protocol corresponding to the target patient; the medical data sharing protocol is used to represent the sharing scope of the target patient's medical data.
[0030] A call information chain - up module, configured to send the target medical data to the target medical service node, and chain - up and store the call transaction information corresponding to the data call request.
[0031] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the above-mentioned blockchain-based medical data processing method are implemented.
[0032] In a fourth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the steps of the above-mentioned blockchain-based medical data processing method are implemented.
[0033] In a fifth aspect, the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned blockchain-based medical data processing method are implemented.
[0034] The above-mentioned blockchain-based medical data processing method, device, computer device, storage medium, and computer program product receive a data call request sent by a target medical service node in a blockchain network. The data call request is a request to call the medical data of a target patient. The blockchain network stores the association relationship pre-determined between the patient client corresponding to the target patient and the target medical service node. Then, according to the medical data sharing protocol corresponding to the target patient pre-stored, the target medical data is obtained. The medical data sharing protocol is used to represent the sharing scope of the medical data of the target patient. Furthermore, the target medical data is sent to the target medical service node, and the call information corresponding to the data call request is stored on the chain, realizing the optimization of blockchain-based medical data processing. By introducing the patient role and an extensible medical data sharing protocol, it provides support for adding new sharable data, solves the data barrier problem. By receiving the call request to obtain medical data and recording the corresponding information on the chain, data can be stored separately based on the decoupling of the system architecture, realizing the optimization of system performance, improving the data processing efficiency, and ensuring the authenticity and security of the shared data. Description of the Drawings
[0035] Figure 1 It is a schematic flowchart of a blockchain-based medical data processing method in an embodiment;
[0036] Figure 2 It is a schematic diagram of medical data interaction processing in an embodiment;
[0037] Figure 3 It is a schematic flowchart of a data upload step in an embodiment;
[0038] Figure 4 It is a schematic flowchart of another blockchain-based medical data processing method in an embodiment;
[0039] Figure 5 is a structural block diagram of a blockchain-based medical data processing device in an embodiment;
[0040] Figure 6 is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0041] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0042] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties; correspondingly, the present application also provides a corresponding user authorization entry for the user to choose to authorize or choose to refuse.
[0043] In one embodiment, as Figure 1 shown, a blockchain-based medical data processing method is provided. In this embodiment, the method is described by taking its application to a server as an example. It can be understood that the method can also be applied to a terminal, and can also be applied to a system including a terminal and a server, such as a data security sharing system, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0044] Step 101, receiving a data call request sent by a target medical service node in a blockchain network;
[0045] Among them, the data call request may be a request to call the medical data of a target patient; the blockchain network may store the association relationship predetermined between the patient client corresponding to the target patient and the target medical service node.
[0046] Among them, the blockchain network may be a consortium blockchain network. Since the consortium blockchain has an identity management mechanism, by adopting the consortium blockchain in the blockchain, identity permission control can be performed on medical institutions joining the network, such as adding authorized medical institutions to the network, so as to improve data security and system robustness, and at the same time retain the scalability of adding new medical institutions to the data security sharing system in the future.
[0047] As an example, the target medical service node can be the node corresponding to the authorized medical institution in the consortium blockchain network; the target patient can be the current patient seeking medical treatment at the medical institution corresponding to the target medical service node. For example, based on the medical treatment behavior of the current patient, the target medical service node can send a data call request for this current patient.
[0048] In practical applications, based on the medical treatment behavior of the target patient, the target medical service node corresponding to the medical institution where the patient seeks medical treatment can send a data call request through the blockchain network. Since the blockchain network can store the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node, such as the target patient and the medical institution have been bound through registered medical treatment, the target medical service node can then obtain the medical data of the target patient it requests to call through the blockchain network.
[0049] Specifically, the medical institution corresponding to the target medical service node can send a data call request to the data center of the data security sharing system to obtain the patient data corresponding to the target patient stored in the data center. For example, the target medical service node can generate a data request (i.e., a data call request), encrypt the data request and the medical treatment verification value with the session key of the data center, and then send the corresponding hash verification value together.
[0050] In one example, the patient data obtained based on the data call request can be the historical medical treatment data of the target patient. For example, during the medical treatment process of the target patient at the medical institution, the target patient can perform a registration operation for the current medical treatment behavior. If the target patient has already registered in the data security sharing system, the registration step can be skipped, and the medical institution can perform the registered medical treatment operation, such as uploading the medical treatment information of the target patient to the blockchain for evidence storage. Then, the patient client corresponding to the target patient and the target medical service node corresponding to the medical institution can generate a binding key, as well as generate a medical data sharing protocol and upload it to the blockchain. Furthermore, the target medical service node corresponding to the medical institution can upload the current medical treatment data to the data center, and the data center can upload the uploaded current medical treatment record (such as the transaction information for the current medical treatment event) to the blockchain network.
[0051] In another example, based on the data center, the data barriers between medical institutions can be broken, improving system efficiency while also ensuring high availability. The data center can be a data repository for storing medical data, and the data stored therein can be encrypted and digitally signed to ensure the authenticity and security of the stored data. Thus, a high-performance data repository can be used to store, query, and enter medical data, and the blockchain network stores the security information and identity information required for auditing and calling medical data. This can optimize system performance based on system architecture decoupling. For example, the blockchain network can store call audit information for the medical data of each patient. This call audit information can be used to verify the call identity and data security when requesting to call the medical data of each patient. After the call audit is passed by the blockchain network, the medical data to be called can be obtained through a preset database (such as a high-performance data repository), which is used to store the medical data of each patient.
[0052] Step 102: Obtain target medical data according to the medical data sharing protocol corresponding to the target patient pre-stored.
[0053] Among them, the medical data sharing protocol can be used to represent the sharing scope of the target patient's medical data. For example, the medical data sharing protocol can include patient identity information and the shareable scope information of the patient's medical data determined by the patient. This shareable scope information can be used to represent the callable data scope and the callable person scope, such as which data fields or information fields can be shared, the degree of shareability (including but not limited to whether it can be used by other medical institutions for diagnosis, whether it can be used by medical research institutions for research analysis, which medical institutions or medical research institutions it can be shared with, or not shared, de-identified shared, etc.).
[0054] In a specific implementation, for the received data call request, the target medical data for the data call request can be obtained according to the medical data sharing protocol corresponding to the target patient pre-stored in the blockchain network.
[0055] For example, the data center can call a smart contract according to the medical data sharing protocol uploaded by the target patient during the visit in the consortium blockchain, and then query the data that meets the requirements in the data call request, such as the EHR electronic medical record, as the target medical data.
[0056] Another example is that the data center can decrypt the data request. After verifying that the data request passes, it can parse the content of the data request, call the corresponding medical data sharing protocol (such as a smart contract) to obtain the corresponding electronic medical record.
[0057] In one example, by adopting blockchain technology as the technical framework for secure sharing of medical data, the tamper-proof feature of blockchain technology ensures the traceability of medical data. Based on the smart contract in the consortium blockchain, it can ensure that the data security sharing system stably executes automated data reading and writing operations, reduce the risks brought by malicious node operations, and make the parties involved open, transparent, and decentralized, achieving the effect of evidence collection and liability tracing.
[0058] Step 103: Send the target medical data to the target medical service node and store the call information corresponding to the data call request on the blockchain.
[0059] As an example, the call information can be transaction information for this request call event to achieve recording the corresponding transaction on the blockchain.
[0060] After determining the target medical data, the target medical data can be sent to the target medical service node, and the call information corresponding to the data call request can be stored on the blockchain. For example, the target medical service node can request corresponding data from the data center. After verifying the identity and the legitimacy of the request, the data center can transmit the data to the target medical service node and upload the transaction record corresponding to the request call to the blockchain.
[0061] In one example, the data center can encrypt the electronic medical record with a session key, generate a corresponding hash verification value and send it to the target medical service node together, and record the transaction record corresponding to the request call on the blockchain. Then, after the target medical service node receives the corresponding data and verifies that the hash value passes, it can obtain the electronic medical record of the target patient.
[0062] Compared with the traditional method, the technical solution of this embodiment can add the medical data supply chain (such as patients) to the system by introducing multiple roles in the data security sharing system, enabling patients to participate in the process of data security sharing through the patient client. Under the framework of the consortium blockchain, introducing the patient role is beneficial for different types of medical data (such as different sensitivities) and different medical institutions to have different data sharing strategies, and is also beneficial for new data to continuously emerge in the system while ensuring patient data security, rather than just sharing existing data.
[0063] Since the introduction of the patient role brings new data into the system, the throughput of the system also needs to meet certain requirements. In the technical solution of this embodiment, by introducing a cloud data center as a data lake, it can be used to store medical data, thus breaking the data barriers between medical institutions. And only key information is recorded in the consortium blockchain, which can improve the value of the block information in the consortium blockchain and reduce the input information rate and total amount required for the blockchain to go on-chain to an extremely low level. On the one hand, it is beneficial to save system overhead. On the other hand, when horizontally expanding the system, it can enable newly added nodes to efficiently reach a consensus, improving the system throughput and system efficiency.
[0064] In the above blockchain-based medical data processing method, by receiving a data call request sent by a target medical service node in the blockchain network, where the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node. Then, according to the medical data sharing protocol corresponding to the target patient stored in advance, the target medical data is obtained. The medical data sharing protocol is used to represent the sharing scope of the medical data of the target patient. Furthermore, the target medical data is sent to the target medical service node, and the call information corresponding to the data call request is stored on the chain, realizing the optimization of blockchain-based medical data processing. By introducing the patient role and an extensible medical data sharing protocol, it provides support for adding new sharable data, solves the data barrier problem. By receiving the call request to obtain medical data and recording the corresponding information on the chain, data can be separately stored based on the decoupling of the system architecture, realizing system performance optimization, improving data processing efficiency, and ensuring the authenticity and security of shared data.
[0065] In one embodiment, before the step of receiving the data call request sent by the target medical service node in the blockchain network, the following steps may further be included:
[0066] Based on the blockchain network configuration parameters and data security parameters, construct a blockchain network including multiple medical service nodes; receive the registration verification requests sent by each of the medical service nodes and perform the registration verification operations on each of the medical service nodes; the registration verification request carries the node verification parameters corresponding to the medical service node; receive the registration request sent by the patient client corresponding to the target patient and perform the registration operation on the patient client; the registration request carries the identity verification parameters corresponding to the patient client.
[0067] As an example, the blockchain network configuration parameters may include a list of trusted institutions, block generation parameters, server node parameters, and network communication parameters; the data security parameters may include public keys, prime group information, and hash functions. For example, the security parameters (i.e., data security parameters) of the key sharing algorithm can be determined by the blockchain network administrator and the data security parameters can be uploaded to the blockchain.
[0068] In practical applications, a consortium blockchain network (i.e., the blockchain network) can be pre-constructed. To enable those skilled in the art to better understand the above steps, the following will be combined with Figure 2 an example to exemplarily illustrate the embodiments of the present application. However, it should be understood that the embodiments of the present application are not limited thereto. As Figure 2 shown, when initializing the consortium blockchain network, the blockchain network administrator can initialize the blockchain network configuration to establish the network, and can share the corresponding blockchain network configuration parameters and policies with all applicants of the system. Furthermore, the server nodes (i.e., multiple medical service nodes) and client nodes of each medical institution can be added to the consortium chain network.
[0069] In an alternative embodiment, the medical institution may include a hospital, and may also include institutions such as physical examination centers and medical research institutions that can join the data security sharing system and have service nodes and client nodes. There is no specific limitation in this embodiment.
[0070] In an example, for each medical institution, it can perform key registration. As Figure 2 shown, the medical service node corresponding to the medical institution can associate its own UID (User Identification) and private key, and then send the hash value to the blockchain network administrator. Furthermore, the blockchain network administrator can calculate node proof information for the private key of the medical institution as the key. Among them, the proof information can correspond to a private key, and each medical institution can register multiple keys.
[0071] For example, the medical service node corresponding to the medical institution can generate a random number as its own private key, and can use the hash value obtained by splicing the UID and the private key as the medical treatment verification value (i.e., the registration verification request carries the node verification parameters corresponding to the medical service node) and send it to the blockchain network administrator. The blockchain network administrator can select a random number and splice it with the received medical treatment verification value to calculate a hash value, and then add the product of the administrator's private key and the public key of the medical institution to obtain the node proof information and retain it for future use.
[0072] In this embodiment, a blockchain network including multiple medical service nodes is constructed based on blockchain network configuration parameters and data security parameters. Then, registration verification requests sent by each medical service node are received, registration verification operations for each medical service node are performed, and a registration request sent by a patient client corresponding to a target patient is received, and a registration operation for the patient client is performed. The identity management mechanism of the consortium blockchain can be used to control network joining objects, improving data security.
[0073] In one embodiment, the receiving the registration request sent by the patient client corresponding to the target patient and performing the registration operation on the patient client may include the following steps:
[0074] Generate patient identification information for the target patient according to the identity verification parameters corresponding to the patient client and send it to the patient client; store the identity verification parameters in correspondence with the patient identification information of the target patient.
[0075] In practical applications, the patient client can generate a corresponding identity verification value (i.e., identity verification parameter) in response to patient input information, send the identity verification value to the blockchain network administrator. Then, the blockchain network administrator can generate a receiving label (i.e., patient identification information) based on the received identity verification value and send it to the patient client, and can also store the received identity verification value and the generated receiving label in correspondence in the data center.
[0076] In one example, for each visiting patient, patient client registration can be performed. For example, Figure 2 as shown, in response to the patient registration operation, the patient client can send the hashed value of the processed patient UID to the blockchain network administrator. Then, the blockchain network administrator can store the hashed value in the data center and return a personal card. The patient client can generate a set of verification parameters locally based on the received personal card.
[0077] For example, the patient client can generate a random number as the registration random number according to the input UID and user password, and can generate an identity verification value according to the hashed value obtained by concatenating the registration random number and the UID, and send the identity verification value to the blockchain network administrator. Then, the blockchain network administrator can generate a random number, generate a receiving label according to the hashed value obtained by the random number and the received identity verification value, store the received identity verification value and the generated receiving label in the data center together, and return the receiving label to the patient client. Further, the patient client can generate a random number as the key, and can generate an identity verification card quadruple according to the key, UID, user password, registration random number, and receiving label and store it locally.
[0078] In another example, taking the identity information of patient j as an example,
[0079] Authentication value = hash(Registration random number || Patient UID)
[0080] Receiving tag = hash(Authentication value || Administrator random number)
[0081] Authentication card quadruple (B j , C j , D j , E j )
[0082] wherein, H pw = hash(Patient UID || Patient password); B j = H pw ⊕ Registration random number; The patient client corresponding to patient j generates a random number S for the second time j , C j = hash(Patient UID || Patient password || Registration random number) ⊕ S j ; D j = hash(Registration random number || S j ) ⊕ Receiving tag; E j = hash(Registration random number || S j ) || Receiving tag.
[0083] The public key of patient j is S j ·H,
[0084] Auxiliary verification value = hash(Registration random number || S j || Administrator random number)
[0085] According to the timestamp V1,
[0086] N1 = hash(Administrator random number || Authentication value || V1) + S j · Institutional public key (such as S j ·S k ·H)
[0087] N bq = hash(Receiving tag || Authentication value)
[0088] 〈N1 N bq V1〉
[0089] Data center verification:
[0090] Receiving tag || Authentication value || V1 = N1 - Institutional private key · Patient public key (such as S k ·S j·H) In this embodiment, by generating patient identification information for the target patient based on the authentication parameters corresponding to the patient client and sending it to the patient client, and then storing the authentication parameters and the patient identification information of the target patient in correspondence, the patient role can be introduced while ensuring patient data security, providing data support for subsequent data sharing.
[0091] In one embodiment, before the step of receiving the data call request sent by the target medical service node in the blockchain network, the following steps may further be included:
[0092] Receiving the medical visit association request sent by the target medical service node; the medical visit association request carries the node authentication parameters corresponding to the target medical service node and the authentication parameters corresponding to the patient client; based on the node authentication parameters and the authentication parameters, establishing an association relationship between the patient client corresponding to the target patient and the target medical service node, and sending the association relationship record information to the target medical service node; both the patient client and the target medical service node have association key information.
[0093] In practical applications, when a patient visits a medical institution, the medical service node corresponding to the medical institution can send a medical visit association request based on the information provided by the patient client. The medical visit association request may carry the node authentication parameters (such as a visit authentication value) corresponding to the target medical service node and the authentication parameters (such as an authentication value) corresponding to the patient client. Then, the blockchain network administrator can establish an association relationship (such as association proof information) between the patient client corresponding to the target patient and the target medical service node according to the node authentication parameters and the authentication parameters. Furthermore, the association relationship record information (such as association proof information and authentication value) can be stored in the data center and sent to the medical service node corresponding to the medical institution.
[0094] In one example, after the patient client registration is completed, a patient visit binding operation can be performed, such as Figure 2 As shown, if the patient information of the target patient already exists in the data security sharing system, the patient visit binding step can be entered, and the patient information and the medical institution information can be bound and stored in the data center.
[0095] For example, when a patient visits a medical institution, the medical service node corresponding to the medical institution can send the visit verification value and identity verification value provided by the patient client (i.e., the node verification parameters corresponding to the target medical service node and the identity verification parameters corresponding to the patient client carried in the visit association request) and the public key to the blockchain network administrator. Then, the blockchain network administrator can select a random number and calculate the association proof information (i.e., the association relationship record information) based on the received public key, visit verification value, random number, and administrator's private key. Furthermore, the association proof information and identity verification value can be stored in the data center and returned to the medical service node corresponding to the medical institution.
[0096] In a specific implementation, a binding key (i.e., association key information) can be generated for the patient client and the medical service node. The medical institution corresponding to the medical service node can be a medical institution that is not a first-time visit and has been registered in the blockchain network. Thus, when the patient needs a health diagnosis in the future, the patient's identity can be authenticated.
[0097] In another example, as Figure 2 shown, the UID and password input by the patient client can be verified through the local identity verification card quadruple, and an auxiliary verification value can be generated by using the received tag, identity verification value, timestamp, patient's private key, and the public key of the medical institution. The hash value of the received tag generated by the auxiliary verification value and the identity verification value are associated and sent to the medical service node corresponding to the medical institution together with the timestamp.
[0098] The medical service node corresponding to the medical institution can quickly parse out the identity verification value from the received auxiliary verification value through the cyclic group information of the blockchain network, and then verify the received hash value. After the verification passes, the medical service node can select a random number as the temporary key with the patient and send the exclusive OR value of the temporary key and the received tag. At the same time, the binding key can be calculated locally, and the key sharing verification value can be generated based on the visit verification value, binding key, and timestamp and sent together. The patient client can calculate the temporary key through the received exclusive OR value and restore the binding key based on the temporary key, identity verification value, visit verification value, and received tag.
[0099] In this embodiment, by receiving the visit association request sent by the target medical service node, and then based on the node verification parameters and identity verification parameters, the association relationship between the patient client corresponding to the target patient and the target medical service node is established, and the association relationship record information is sent to the target medical service node, which helps to authenticate the patient's identity during the patient's subsequent health diagnosis.
[0100] In one embodiment, before the step of obtaining the target medical data according to the medical data sharing protocol corresponding to the target patient pre-stored, the following steps may further be included:
[0101] Receive a protocol on-chain request sent by the target medical service node; the protocol on-chain request carries a medical data sharing protocol, which is generated by combining the node verification parameters corresponding to the target medical service node, the identity verification parameters corresponding to the patient client, and the associated relationship record information after passing the verification using the associated key information; store the medical data sharing protocol corresponding to the target patient corresponding to the patient client.
[0102] In practical applications, based on the established binding key, the medical service node corresponding to the medical institution and the patient client can put the medical data sharing protocol on the chain (i.e., send a protocol on-chain request). This medical data sharing protocol can include information on the shareable scope of patient medical data and patient identity information, and then the medical data sharing protocol can be stored corresponding to the target patient corresponding to the patient client.
[0103] In one example, as Figure 2 shown, the patient client can encrypt the authentication value associated with the visit verification value according to the shared binding key (i.e., the associated key information) and send it to the medical service node, and can also send the corresponding binding key verification value. Then the medical service node can calculate the binding key verification value locally. After determining that the locally calculated verification value is consistent with the received binding key verification value, it can decrypt through the binding key. Furthermore, the medical service node can generate a customized medical data sharing protocol, such as generating a medical data sharing protocol according to patient requirements, data type, data sensitivity, request institution type, etc., and can write the authentication value, visit verification value, and associated proof information into the medical data sharing protocol and upload it to the blockchain.
[0104] In an alternative embodiment, by signing a medical data sharing agreement between the patient and the medical institution, the patient's recognition of privacy security can be increased, making the patient more willing to incorporate medical data into the data security sharing system. Based on the customized agreement, the shareable scope information consented by the patient can be determined, such as which fields can be shared, the degree of sharing (e.g., can be used by other medical institutions for diagnosis, can be used by medical research institutions for research analysis, or not shared, de-identified shared, etc.). The medical data sharing agreement can be written into the blockchain as a mapping relationship with the real data. When calling the chain code in the blockchain to read data from the database, the chain code can query the medical data sharing agreement according to the identity of the caller to issue a call to the legal fields. In this embodiment, by receiving the protocol on-chain request sent by the target medical service node, and then generated in combination with the node verification parameters corresponding to the target medical service node, the identity verification parameters corresponding to the patient client, and the associated relationship record information, and then storing the medical data sharing agreement corresponding to the target patient corresponding to the patient client, it is possible to support the addition of more new shareable data to the system based on the introduction of an extensible medical data sharing agreement, enabling the patient to participate in the data security sharing process.
[0105] In one embodiment, as Figure 3 shown, the following steps may further be included:
[0106] Step 301, receive the data upload request sent by the target medical service node, generate an upload address parameter and a timestamp information, and send them to the target medical service node;
[0107] In a specific implementation, the target medical service node may request to upload data to the data center, such as sending a data upload request. Then, the data center may return an available URL and a request upload timestamp (i.e., the upload address parameter and the timestamp information) to the target medical service node for the data upload request.
[0108] Step 302, obtain the medical data upload information sent by the target medical service node; the medical data upload information is obtained by the target medical service node combining the upload address parameter, the timestamp information, and the medical treatment data of the target patient;
[0109] In practical applications, the target medical service node may encrypt the EHR electronic medical record (i.e., the medical data upload information) with the session key of the data center and send it to the data center, and may also send the upload verification value together.
[0110] For example, an EHR electronic medical record can be obtained by combining a patient authentication value, a medical institution visit authentication value, medical data (i.e., visit data), and an upload timestamp. Furthermore, the electronic medical record can be encrypted with a session key from the data center and sent, along with the upload authentication value of the electronic medical record.
[0111] Step 303: Parse the medical data upload information to obtain the visit data of the target patient and store it.
[0112] Step 304: Store the upload information corresponding to the data upload request on the blockchain.
[0113] In a specific implementation, the upload information (such as transaction information for this upload event) recorded on the blockchain supernode can be used. Through the structure of the data chain, the upload information can be packaged into a block. Then, the newly generated block data can be verified according to the consensus algorithm in the blockchain sharing protocol. Furthermore, the upload information can be distributed to each node for storage, and each node has a complete information copy of the block to complete the corresponding transaction record on the blockchain.
[0114] In one example, after decryption and successful verification, the data center can store the parsed medical data in a database and can also record the upload transaction of the corresponding URL on the blockchain. For example, the data center can decrypt the EHR electronic medical record, verify the legality of the upload authentication value and the electronic medical record, store the medical data in the corresponding URL, and perform transaction recording on the blockchain. For example, the medical service node can record the combined authentication value, visit authentication value, timestamp, and signature on the blockchain.
[0115] In another example, the technical solution of this embodiment only uses the encryption and decryption processes of digital signatures and asymmetric cryptography in a small number of steps. By using simple methods such as random numbers, hash functions, and exclusive OR operations, the security and reliability of the steps are ensured, and the system efficiency can be effectively improved.
[0116] In this embodiment, by receiving a data upload request sent by a target medical service node, generating an upload address parameter and a timestamp information and sending them to the target medical service node, then obtaining the medical data upload information sent by the target medical service node, further parsing the medical data upload information to obtain the visit data of the target patient and storing it, and storing the upload information corresponding to the data upload request on the blockchain, new sharable data can be provided, and the corresponding transaction records are recorded on the blockchain, ensuring the authenticity and security of the shared data.
[0117] In one embodiment, as Figure 4 shown, a flowchart of another blockchain-based medical data processing method is provided. In this embodiment, the method includes the following steps:
[0118] In step 401, a blockchain network including multiple medical service nodes is constructed based on blockchain network configuration parameters and data security parameters. In step 402, registration verification requests sent by each medical service node are received, and registration verification operations for each medical service node are performed; the registration verification requests carry node verification parameters corresponding to the medical service nodes. In step 403, a registration request sent by a patient client corresponding to a target patient is received, and a registration operation for the patient client is performed; the registration request carries identity verification parameters corresponding to the patient client. In step 404, a medical treatment association request sent by a target medical service node is received; the medical treatment association request carries node verification parameters corresponding to the target medical service node and identity verification parameters corresponding to the patient client. In step 405, based on the node verification parameters and the identity verification parameters, an association relationship between the patient client corresponding to the target patient and the target medical service node is established, and the association relationship record information is sent to the target medical service node. In step 406, a protocol on-chain request sent by the target medical service node is received; the protocol on-chain request carries a medical data sharing protocol, and the medical data sharing protocol is generated after passing verification using associated key information, in combination with the node verification parameters corresponding to the target medical service node, the identity verification parameters corresponding to the patient client, and the association relationship record information. In step 407, the medical data sharing protocol is stored corresponding to the target patient corresponding to the patient client. It should be noted that the specific limitations of the above steps can be referred to the specific limitations of a blockchain-based medical data processing method described above, and will not be elaborated here.
[0119] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps or stages in other steps.
[0120] Based on the same inventive concept, an embodiment of the present application further provides a blockchain-based medical data processing device for implementing the above-mentioned blockchain-based medical data processing method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the blockchain-based medical data processing device provided below can refer to the limitations on the blockchain-based medical data processing method in the above text, and will not be repeated here.
[0121] In one embodiment, as Figure 5 shown, a blockchain-based medical data processing device is provided, including:
[0122] A data call request receiving module 501, configured to receive a data call request sent by a target medical service node in a blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node;
[0123] A target medical data determining module 502, configured to obtain target medical data according to the medical data sharing protocol corresponding to the target patient pre-stored; the medical data sharing protocol is used to characterize the sharing scope of the medical data of the target patient;
[0124] A call information on-chain module 503, configured to send the target medical data to the target medical service node and store the call information corresponding to the data call request on the chain.
[0125] In one embodiment, the device further includes:
[0126] A blockchain network construction module, configured to construct a blockchain network including multiple medical service nodes based on blockchain network configuration parameters and data security parameters;
[0127] A node registration module, configured to receive the registration verification requests sent by each medical service node and perform registration verification operations on each medical service node; the registration verification request carries the node verification parameters corresponding to the medical service node;
[0128] A client registration module, configured to receive the registration request sent by the patient client corresponding to the target patient and perform a registration operation on the patient client; the registration request carries the identity verification parameters corresponding to the patient client.
[0129] In one embodiment, call review information for the medical data of each patient is stored in the blockchain network. The call review information is used to verify the call identity situation and data security situation when requesting to call the medical data of each patient. After the call review is passed, the blockchain network obtains the medical data to be called through a preset database, and the preset database is used to store the medical data of each patient.
[0130] In one embodiment, the client registration module includes:
[0131] A patient identification information generation sub-module, configured to generate patient identification information for the target patient according to the authentication parameters corresponding to the patient client and send it to the patient client;
[0132] A corresponding storage sub-module, configured to store the authentication parameters and the patient identification information of the target patient in a corresponding manner.
[0133] In one embodiment, the device further includes:
[0134] A medical visit association request receiving module, configured to receive a medical visit association request sent by the target medical service node; the medical visit association request carries node verification parameters corresponding to the target medical service node and authentication parameters corresponding to the patient client;
[0135] An association relationship establishment module, configured to establish an association relationship between the patient client corresponding to the target patient and the target medical service node based on the node verification parameters and the authentication parameters, and send association relationship record information to the target medical service node; both the patient client and the target medical service node have association key information.
[0136] In one embodiment, the device further includes:
[0137] A protocol on-chain request receiving module, configured to receive a protocol on-chain request sent by the target medical service node; the protocol on-chain request carries a medical data sharing protocol, and the medical data sharing protocol is generated after being verified through the association key information and combined with the node verification parameters corresponding to the target medical service node, the authentication parameters corresponding to the patient client, and the association relationship record information;
[0138] A protocol corresponding storage module, configured to store the medical data sharing protocol and the target patient corresponding to the patient client in a corresponding manner.
[0139] In one embodiment, the device further includes:
[0140] A data upload request receiving module, configured to receive a data upload request sent by the target medical service node, generate an upload address parameter and a timestamp information, and send them to the target medical service node;
[0141] An upload information acquisition module, configured to acquire medical data upload information sent by the target medical service node; the medical data upload information is obtained by the target medical service node according to the upload address parameter, the timestamp information, and the medical treatment data of the target patient;
[0142] An analysis module, configured to analyze the medical data upload information, obtain the medical treatment data of the target patient, and store it;
[0143] A blockchain storage module, configured to store the upload information corresponding to the data upload request on the blockchain.
[0144] Each module in the above blockchain-based medical data processing device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0145] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 6 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store blockchain-based medical data processing data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a blockchain-based medical data processing method.
[0146] Those skilled in the art can understand that Figure 6 the structure shown in
[0147] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0148] Receive a data call request sent by a target medical service node in the blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node;
[0149] Obtain target medical data according to the pre-stored medical data sharing protocol corresponding to the target patient; the medical data sharing protocol is used to represent the sharing scope of the medical data of the target patient;
[0150] Send the target medical data to the target medical service node, and store the call information corresponding to the data call request on the chain.
[0151] In one embodiment, when the processor executes the computer program, it also implements the steps of the blockchain-based medical data processing method in the above-mentioned other embodiments.
[0152] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0153] Receive a data call request sent by a target medical service node in the blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node;
[0154] Obtain target medical data according to the pre-stored medical data sharing protocol corresponding to the target patient; the medical data sharing protocol is used to represent the sharing scope of the medical data of the target patient;
[0155] Send the target medical data to the target medical service node, and store the call information corresponding to the data call request on the chain.
[0156] In one embodiment, when the computer program is executed by a processor, it also implements the steps of the blockchain-based medical data processing method in the above-mentioned other embodiments.
[0157] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the following steps are implemented:
[0158] Receive a data call request sent by a target medical service node in the blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node;
[0159] Obtain target medical data according to the pre-stored medical data sharing protocol corresponding to the target patient; the medical data sharing protocol is used to characterize the sharing scope of the medical data of the target patient.
[0160] Send the target medical data to the target medical service node, and store the call information corresponding to the data call request on the blockchain.
[0161] In one embodiment, when the computer program is executed by a processor, it also implements the steps of the blockchain-based medical data processing method in the above-mentioned other embodiments.
[0162] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAMs), magnetoresistive random access memories (MRAMs), ferroelectric random access memories (FRAMs), phase change memories (PCMs), graphene memories, etc. Volatile memories can include random access memories (RAMs) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include blockchain-based distributed databases, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.
[0163] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0164] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A blockchain-based medical data processing method, characterized in that The method includes: Receiving a data call request sent by a target medical service node in a blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node; the medical service nodes in the blockchain network are used to generate a medical data sharing protocol according to patient requirements, data types, data sensitivity, and request institution types, and write the authentication value, visit authentication value, and association proof information into the medical data sharing protocol and upload it to the blockchain; Obtaining target medical data according to the pre-stored medical data sharing protocol corresponding to the target patient; the medical data sharing protocol is used to represent the sharing scope of the medical data of the target patient; Sending the target medical data to the target medical service node and storing the call information corresponding to the data call request on the blockchain.
2. The method according to claim 1, wherein Before the step of receiving the data call request sent by the target medical service node in the blockchain network, the method further includes: Based on the blockchain network configuration parameters and data security parameters, constructing a blockchain network including multiple medical service nodes; Receiving the registration verification requests sent by each of the medical service nodes and performing registration verification operations on each of the medical service nodes; the registration verification requests carry the node verification parameters corresponding to the medical service nodes; Receiving the registration request sent by the patient client corresponding to the target patient and performing a registration operation on the patient client; the registration request carries the authentication parameters corresponding to the patient client.
3. The method according to claim 1, wherein The blockchain network stores call review information for the medical data of each patient, and the call review information is used to verify the call identity situation and data security situation when requesting to call the medical data of each patient; after the call review is passed, the blockchain network obtains the medical data to be called through a preset database, and the preset database is used to store the medical data of each patient.
4. The method according to claim 2, characterized in that The step of receiving the registration request sent by the patient client corresponding to the target patient and performing a registration operation on the patient client includes: Generating patient identification information for the target patient according to the authentication parameters corresponding to the patient client and sending it to the patient client; Correspondingly storing the authentication parameters and the patient identification information of the target patient.
5. The method according to claim 1, wherein Before the step of receiving the data call request sent by the target medical service node in the blockchain network, the method further includes: Receiving a visit association request sent by the target medical service node; the visit association request carries the node verification parameters corresponding to the target medical service node and the authentication parameters corresponding to the patient client; Based on the node verification parameters and the authentication parameters, establishing an association relationship between the patient client corresponding to the target patient and the target medical service node, and sending the association relationship record information to the target medical service node; both the patient client and the target medical service node have association key information.
6. The method according to claim 4, characterized in that, Before the step of obtaining target medical data according to the pre-stored medical data sharing protocol corresponding to the target patient, the method further includes: Receiving a protocol on-chain request sent by the target medical service node; the protocol on-chain request carries a medical data sharing protocol, which is generated by combining the node verification parameters corresponding to the target medical service node, the identity verification parameters corresponding to the patient client, and the association relationship record information after passing verification using associated key information. Correspondingly storing the medical data sharing protocol with the target patient corresponding to the patient client.
7. The method according to claim 1, characterized in that The method further includes: Receiving a data upload request sent by the target medical service node, generating an upload address parameter and a timestamp information and sending them to the target medical service node; Obtaining medical data upload information sent by the target medical service node; the medical data upload information is obtained by the target medical service node combining the upload address parameter, the timestamp information, and the medical treatment data of the target patient. Parsing the medical data upload information to obtain the medical treatment data of the target patient and storing it; Storing the upload information corresponding to the data upload request on the chain.
8. A medical data processing device based on blockchain, characterized in that, The apparatus includes: A data call request receiving module, configured to receive a data call request sent by a target medical service node in a blockchain network; the data call request is a request to call the medical data of a target patient, and the blockchain network stores the pre-determined association relationship between the patient client corresponding to the target patient and the target medical service node; the medical service nodes in the blockchain network are used to generate a medical data sharing protocol according to patient requirements, data types, data sensitivity, and request institution types, and write the identity verification value, medical treatment verification value, and association proof information into the medical data sharing protocol and upload it to the blockchain. A target medical data determination module, configured to obtain target medical data according to the pre-stored medical data sharing protocol corresponding to the target patient; the medical data sharing protocol is used to represent the sharing scope of the medical data of the target patient. A call information on-chain module, configured to send the target medical data to the target medical service node and store the call information corresponding to the data call request on the chain.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
KR20210041719A