A method, apparatus, device, and storage medium for encrypting medical images
DICOM format-based encryption using unique identifiers and segment-specific keys addresses security issues in medical imaging data transmission and storage, enhancing patient information security through individualized encryption.
Patent Information
- Application Number
- CN202410234744.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-29
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-02-29
AI Technical Summary
Existing medical images are less secure during transmission and storage, and patient information is easily leaked.
The unique identifier generated by the DICOM format data generates a wheel key to encrypt the medical image data. The specific steps include obtaining the initial image data in the DICOM format, dividing it into several image segment data with a set number of image segment data, and generating a wheel key corresponding to the image segment data one by one based on the unique identifier, and finally generating the encrypted image data.
Effectively prevent unauthorized access and data leakage, improve the security of patient information, increase the difficulty of cracking through personalized encryption, and improve the security of data.
Smart Images

Figure CN118039084B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data encryption, and particularly to an encryption method, device, equipment and storage medium for medical images. Background Art
[0002] PACS (Picture Archiving and Communication System) is a system applied in the imaging departments of hospitals. Its main task is to store a large amount of various medical images (including images generated by equipment such as magnetic resonance, CT, ultrasound, various X-ray machines, various infrared devices, and microscopes) in a digital manner. When needed, it can be quickly retrieved for use under certain authorization, and some auxiliary diagnostic management functions are added. It plays an important role in transmitting data and organizing storage data among various imaging devices.
[0003] The transmission and storage of medical images in the PACS system are based on the DICOM (Digital Imaging and Communications in Medicine) standard. The DICOM standard defines the data format of medical images, patient information, device parameters, etc. This standard for transmission and storage greatly facilitates information exchange between different manufacturers.
[0004] However, there are problems of relatively low security and easy leakage of patient information in the process of transmitting and storing existing medical images. Summary of the Invention
[0005] In view of the above-mentioned problems, the present application is proposed to provide an encryption method, device, equipment and storage medium for medical images that can overcome or at least partially solve the problems, including:
[0006] An encryption method for medical images, including:
[0007] Obtain initial image data in DICOM format; wherein, the initial image data includes a unique identifier;
[0008] Divide the initial image data into several image segment data with a preset number of digits;
[0009] Generate round keys corresponding one-to-one to the image segment data according to the unique identifier;
[0010] Generate encrypted image data according to the image segment data and the round keys.
[0011] Preferably, the step of generating round keys corresponding one-to-one to the image segment data according to the unique identifier includes:
[0012] Generate an initial key according to the unique identifier;
[0013] Generate round keys corresponding one by one to the video segment data according to the initial key.
[0014] Preferably, the step of generating an initial key according to the unique identifier includes:
[0015] Perform a hashing process on the unique identifier to obtain the initial key.
[0016] Preferably, the step of generating round keys corresponding one by one to the video segment data according to the initial key includes:
[0017] Divide the initial key into a preset number of sub-keys;
[0018] Update the sub-keys respectively through a first arithmetic operation;
[0019] Update the sub-keys sequentially in a loop through a second arithmetic operation;
[0020] When the second arithmetic operation is completed, merge the updated sub-keys and the remaining sub-keys to obtain the round key.
[0021] Preferably, the step of updating the sub-keys respectively through a first arithmetic operation includes:
[0022] For each sub-key, perform an exclusive OR operation on the sub-key with a first parameter.
[0023] Preferably, the step of updating the sub-keys sequentially in a loop through a second arithmetic operation includes:
[0024] For the sub-key of the current round, perform a non-linear transformation and a linear transformation on the first sub-key to obtain an intermediate value;
[0025] Perform an exclusive OR operation on the intermediate value with a second parameter.
[0026] Preferably, the step of generating encrypted video data according to the video segment data and the round key includes:
[0027] Perform an encryption operation on the video segment data respectively with the round key corresponding to the video segment data to obtain encrypted segment data;
[0028] Merge all the encrypted segment data to obtain the encrypted video data.
[0029] An encryption device for medical images, comprising:
[0030] A data acquisition module for acquiring initial image data in DICOM format; wherein, the initial image data includes a unique identifier;
[0031] A data segmentation module for dividing the initial image data into a plurality of image segment data with a preset number of digits;
[0032] A key generation module for generating round keys corresponding one-to-one to the image segment data according to the unique identifier;
[0033] A data encryption module for generating encrypted image data according to the image segment data and the round keys.
[0034] A computer device includes a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the encryption method described in any one of the above is implemented.
[0035] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the encryption method described in any one of the above is implemented.
[0036] The present application has the following advantages:
[0037] In the embodiments of the present application, in view of the problem of relatively low security in the transmission and storage of existing medical images, the present application provides a solution for encrypting medical image data through the identification information carried by DICOM format data, specifically: "acquiring initial image data in DICOM format; wherein, the initial image data includes a unique identifier; dividing the initial image data into a plurality of image segment data with a preset number of digits; generating round keys corresponding one-to-one to the image segment data according to the unique identifier; generating encrypted image data according to the image segment data and the round keys". By encrypting medical image data, unauthorized access and data leakage can be effectively prevented, and the security of patient information is improved; by using the unique identifier as the key to encrypt medical image data, personalized data encryption can be achieved, increasing the difficulty of cracking and further improving the security of patient information. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the technical solutions of the present application, the drawings required to be used in the description of the present application will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0039] Figure 1It is a flowchart of the steps of an encryption method for medical images provided by an embodiment of the present application;
[0040] Figure 2 It is a schematic flowchart of an encryption method for medical images provided by an embodiment of the present application;
[0041] Figure 3 It is a structural block diagram of an encryption device for medical images provided by an embodiment of the present application;
[0042] Figure 4 It is a schematic structural diagram of a computer device provided by an embodiment of the present application.
[0043] The reference signs in the accompanying drawings of the specification are as follows:
[0044] 12. Computer device; 14. External device; 16. Processing unit; 18. Bus; 20. Network adapter; 22. I / O interface; 24. Display; 28. Memory; 30. Random access memory; 32. Cache memory; 34. Storage system; 40. Program / utilities; 42. Program module. Detailed implementation manners
[0045] To make the objectives, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0046] Referring to Figure 1 , 2 , there is shown an encryption method for medical images provided by an embodiment of the present application, including:
[0047] S110. Obtain initial image data in DICOM format; wherein, the initial image data includes a unique identifier;
[0048] S120. Divide the initial image data into several image segment data with a preset number of bits;
[0049] S130. Generate round keys corresponding one-to-one to the image segment data according to the unique identifier;
[0050] S140. Generate encrypted image data according to the image segment data and the round keys.
[0051] In an embodiment of the present application, in view of the problem of relatively low security in the transmission and storage of existing medical images, the present application provides a solution for encrypting medical image data through the identification information carried by DICOM format data, specifically: "Obtain initial image data in DICOM format; wherein, the initial image data includes a unique identifier; divide the initial image data into several image segment data with a preset number of digits; generate round keys corresponding one-to-one to the image segment data according to the unique identifier; generate encrypted image data according to the image segment data and the round keys". By encrypting medical image data, unauthorized access and data leakage can be effectively prevented, and the security of patient information is improved; by using the unique identifier as the key to encrypt medical image data, personalized data encryption can be achieved, increasing the difficulty of cracking and further improving the security of patient information.
[0052] Next, a method for encrypting a medical image in this exemplary embodiment will be further described.
[0053] As described in step S110, obtain initial image data in DICOM format; wherein, the initial image data includes a unique identifier.
[0054] Obtain the initial image data in DICOM format from the receiving address of the PACS system (such as the receiving directory D:\ImagesNet created by the server), and search for the unique identifier in the initial image data.
[0055] Files in DICOM format usually include pixel data, unique identifiers, patient information, device information, and image acquisition parameters. Pixel data is the actual pixel data of the image, which can be various types of medical images such as CT, MRI, and X-ray. The unique identifier is metadata used to uniquely identify the image, such as SOP UID (Service-Object Pair Unique Identifier), which is used to ensure that each image is uniquely identifiable globally. Patient information includes personal information such as the patient's name, gender, date of birth, and some specific medical information, such as patient ID and other identification information, which is used to associate the image with the patient's medical records. Device information includes detailed information about the medical device that generated the image, such as the manufacturer, model, and serial number of the device. Image acquisition parameters describe how the image was acquired, including scan time, scan parameters, exposure duration, and the technology used, which helps to understand the image data and perform subsequent processing on it.
[0056] As described in step S120, divide the initial image data into several image segment data with a preset number of digits.
[0057] Determine the number of bits of each image segment data in advance according to the requirements of the encryption algorithm. For example, if the encryption algorithm used is for 128-bit data blocks, the preset number of bits is 128 bits; if the encryption algorithm used is for 256-bit data blocks, the preset number of bits is 256 bits.
[0058] Divide the initial image data into consecutive segments according to the preset number of bits. If the total number of bits of the initial image data is not an integer multiple of the preset number of bits, padding data can be added at the end of the file to ensure that the last data block also meets the bit requirement.
[0059] In this way, the initial image data can be converted into a format suitable for encryption algorithm processing. Each image segment data can be independently used with the corresponding round key in the encryption process, thus ensuring the security of the entire medical image data.
[0060] As described in step S130, generate round keys corresponding one by one to the image segment data according to the unique identifier.
[0061] Generate an initial key according to the unique identifier. Specifically, process the unique identifier through arithmetic operations to obtain the initial key. As an example, perform an encryption algorithm process (such as a hash function) on the unique identifier to generate an initial key, and this initial key will be used as the basis for generating round keys.
[0062] Generate round keys corresponding one by one to the image segment data according to the initial key. Specifically, perform multiple rounds of processing on the initial key through arithmetic operations to obtain a series of different round keys. It is necessary to ensure that the number of generated round keys is equal to the number of image segment data, and the number of bits of the round keys is equal to the number of bits of the image segment data. As an example, perform multiple rounds of different transformation or arithmetic operations (such as circular shift, substitution, mixing, etc.) on the initial key to generate a series of round keys that correspond one by one to the image segment data.
[0063] In a specific implementation, the number of image segment data is 16, and the number of bits is 128 bits. Apply a hash function, such as SHA-128, to the unique identifier to obtain a 128-bit initial key. Perform 16 rounds of transformation on the initial key. Each round of transformation is to perform a specific rotation and substitution on the initial key. For example, in the first round, shift the initial key to the left by a preset number of bits, and in the second round, perform a numerical substitution operation on the result by the preset number of bits, and so on, to obtain round keys corresponding one by one to the image segment data.
[0064] In this way, it can be ensured that each initial image data has its unique encryption key, realizing the personalization of data encryption, increasing the difficulty of cracking, and each image segment data in the initial image data also has its unique round key, greatly enhancing the complexity and security of the entire encryption process.
[0065] As described in step S140, according to the image segment data and the round key, encrypted image data is generated.
[0066] A suitable encryption algorithm is preselected. The encryption algorithm needs to match the algorithm used to generate the round key before. For example, if the round key is generated based on the SM4 algorithm, then the SM4 algorithm is also used for encryption in this step. If the round key is generated based on the AES algorithm, then the AES algorithm is also used for encryption in this step.
[0067] For each image segment data, it is encrypted using its corresponding round key through the selected encryption algorithm. Repeat the above process until all image segment data are encrypted by their corresponding round keys. Finally, all the encrypted image segment data are combined to form the final encrypted image data.
[0068] In a specific example, the number of the image segment data is 16, the number of bits is 128 bits, the number of the round keys is 16, and the number of bits is 128 bits. The SM4 encryption algorithm is selected for encryption. For the first image segment data, SM4 encryption is performed using the first round key. For the second image segment data, SM4 encryption is performed using the second round key. Repeat this process until all 16 image segment data are encrypted by their corresponding round keys. The encrypted image segment data are combined in order to form a complete encrypted image data.
[0069] In this way, the initial image data is converted into an encrypted format, which can effectively prevent data leakage even when transmitted in an insecure network or in the hands of unauthorized personnel, protecting the privacy of patients and the security of image data. At the same time, the encryption speed of the file is relatively fast and the storage efficiency is relatively high.
[0070] In an embodiment of the present application, the specific process of "generating an initial key according to the unique identifier" can be further described in combination with the following description.
[0071] Perform a hashing process on the unique identifier to obtain the initial key.
[0072] In an embodiment of the present application, the specific process of "generating round keys corresponding to the image segment data one by one according to the initial key" can be further described in combination with the following description.
[0073] Divide the initial key into a preset number of sub-keys;
[0074] Update the sub-keys respectively through a first operation; specifically, for each sub-key, perform an exclusive OR operation on the sub-key with a first parameter; wherein, the first parameter is a value related to the image acquisition parameter, which is obtained by hashing the scanning time;
[0075] Update the sub-keys sequentially in a loop through a second operation; specifically, for the sub-key in the current round, perform a non-linear transformation and a linear transformation on the first sub-key to obtain an intermediate value; wherein, the non-linear transformation is S-box substitution, that is, each byte in the data block is mapped to another byte through a predefined S-box; the linear transformation is row shift, that is, the data block is divided into several parts and circularly shifted; and perform an exclusive OR operation on the intermediate value with a second parameter; wherein, the second parameter is a value related to the date and time, which is obtained by hashing the current date and the current time;
[0076] When the second operation is completed, merge the updated sub-keys and the remaining sub-keys to obtain a round key.
[0077] In a specific implementation, given an initial key (K), divide K into 4 sub-keys: K_0, K_1, K_2, K_3. First, update the 4 sub-keys respectively: perform an exclusive OR operation on the 4 sub-keys with a first parameter (F1) respectively to obtain the updated 4 sub-keys: K_0 = K_0 ⊕ FK_0, K_1 = K_1 ⊕ FK_1, K_2 = K_2 ⊕ FK_2, K_3 = K_3 ⊕ FK_3. Then update the 4 sub-keys sequentially in a loop: for each round (i) of update, obtain an intermediate value (T) by applying a non-linear transformation function and a linear transformation function to the sub-key (K_i) in the i-th round, and perform an exclusive OR operation on T with a second parameter (F2_i) to obtain the updated sub-key: K_i = T ⊕ CK_i, where F2_i is the value of the second parameter in the i-th round, and finally use K_i and the complete key composed of other sub-keys as the round key in the i-th round.
[0078] In an embodiment of the present application, the encryption method further includes:
[0079] Store the encrypted image data.
[0080] Optionally, store the encrypted data dispersedly at multiple different addresses, and only by collecting all necessary shards can the complete medical image data be decrypted. In this way, even if an attacker obtains some data fragments, they cannot reconstruct the complete image information, thereby increasing the difficulty of data leakage.
[0081] For the apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the related parts, please refer to the description of the method embodiments.
[0082] Referring to Figure 3 , there is shown an encryption apparatus for medical images provided by an embodiment of the present application, including:
[0083] A data acquisition module 210, configured to acquire initial image data in DICOM format; wherein, the initial image data includes a unique identifier;
[0084] A data segmentation module 220, configured to divide the initial image data into a plurality of image segment data with a preset number of digits;
[0085] A key generation module 230, configured to generate round keys corresponding one-to-one to the image segment data according to the unique identifier;
[0086] A data encryption module 240, configured to generate encrypted image data according to the image segment data and the round keys.
[0087] In an embodiment of the present application, the key generation module 230 includes:
[0088] An initial key generation module, configured to generate an initial key according to the unique identifier;
[0089] A multi-round key generation module, configured to generate round keys corresponding one-to-one to the image segment data according to the initial key.
[0090] In an embodiment of the present application, the initial key generation module includes:
[0091] A unique identifier hashing module, configured to perform hashing processing on the unique identifier to obtain an initial key.
[0092] In an embodiment of the present application, the multi-round key generation module includes:
[0093] An initial key partitioning module, configured to partition the initial key into a preset number of sub-keys;
[0094] A first sub-key update module, configured to update the sub-keys respectively through a first arithmetic operation;
[0095] A second sub-key update module, configured to update the sub-keys sequentially in a loop through a second arithmetic operation;
[0096] A sub-key merging module, configured to, when the second arithmetic operation is completed, merge the updated sub-keys and the remaining sub-keys to obtain round keys.
[0097] In one embodiment of the present application, the first sub-key update module includes:
[0098] The first sub-key XOR module is configured to perform an XOR operation on each of the first sub-keys using a first parameter.
[0099] In one embodiment of the present application, the second sub-key update module includes:
[0100] The key second transformation module is configured to perform a non-linear transformation and a linear transformation on the first sub-key of the current round to obtain an intermediate value.
[0101] The intermediate value second XOR module is configured to perform an XOR operation on the intermediate value using a second parameter.
[0102] In one embodiment of the present application, the data encryption module 240 includes:
[0103] The initial segment encryption module is configured to perform an encryption operation on the video segment data respectively using the round keys corresponding to the video segment data to obtain encrypted segment data.
[0104] The encrypted segment merging module is configured to merge all the encrypted segment data to obtain encrypted video data.
[0105] Refer to Figure 4 , which shows a computer device of the present application. The computer device 12 is presented in the form of a general computing device. The computer device 12 includes: one or more processors or processing units 16, a memory 28, and a bus 18 connecting different system components (including the memory 28 and the processing unit 16).
[0106] The bus 18 can be one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any bus structure in a variety of bus structures. For example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0107] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.
[0108] Memory 28 may include computer system readable media in the form of volatile memory, such as random access memory 30 and / or cache memory 32. The computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 34 may be used for reading and writing on a non-removable, non-volatile magnetic medium (commonly referred to as a "hard disk drive"). Although Figure 4 not shown, a disk drive for reading and writing on a removable non-volatile disk (such as a "floppy disk") and an optical disk drive for reading and writing on a removable non-volatile optical disk (such as a CD-ROM, DVD-ROM or other optical medium) may be provided. In these cases, each drive may be connected to the bus 18 through one or more data media interfaces. The memory may include at least one program product having a set (such as at least one) of program modules 42 configured to perform the functions of the embodiments of the present application.
[0109] The program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in the memory. Such program modules 42 include an operating system, one or more application programs, other program modules 42, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules 42 generally perform the functions and / or methods in the embodiments described in the present application.
[0110] The computer device 12 may also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, a camera, etc.), and may also communicate with one or more devices that enable an operator to interact with the computer device 12, and / or communicate with any device that enables the computer device 12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication may be carried out through the I / O interface 22. And, the computer device 12 may also communicate with one or more networks (such as a local area network (LAN)), a wide area network (WAN), and / or a public network (such as the Internet) through the network adapter 20. As Figure 4 shown, the network adapter 20 communicates with other modules of the computer device 12 through the bus 18. It should be understood that although Figure 4 not shown, other hardware and / or software modules may be used in combination with the computer device 12, including but not limited to: microcode, device drivers, redundant processing unit 16, external disk drive arrays, RAID systems, tape drives, and data backup storage systems 34, etc.
[0111] The processing unit 16 executes various functional applications and data processing by running the programs stored in the memory 28, such as implementing the medical image encryption method provided by any embodiment of the present application.
[0112] That is, when the above processing unit 16 executes the above program, it can achieve: obtaining initial image data in DICOM format; wherein, the initial image data includes a unique identifier; dividing the initial image data into several image segment data with a preset number of bits; generating a round key corresponding to the image segment data one by one according to the unique identifier; and generating encrypted image data according to the image segment data and the round key.
[0113] In an embodiment of the present application, there is also provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the encryption method for medical images provided in any embodiment of the present application.
[0114] That is, when the program is executed by a processor, it can achieve: obtaining initial image data in DICOM format; wherein, the initial image data includes a unique identifier; dividing the initial image data into several image segment data with a preset number of bits; generating a round key corresponding to the image segment data one by one according to the unique identifier; and generating encrypted image data according to the image segment data and the round key.
[0115] One or more arbitrary combinations of computer-readable media can be adopted. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be an electrical, magnetic, optical, electromagnetic, infrared or semiconductor system, device or component, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device or component.
[0116] The computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate or transmit a program for use by or in combination with an instruction execution system, device or component.
[0117] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the operator's computer, partially on the operator's computer, executed as an independent software package, partially on the operator's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the operator's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet). Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0118] Although the preferred embodiments of the embodiments of this application have been described, once those skilled in the art learn the basic creative concepts, additional changes and modifications can be made to these embodiments. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of this application.
[0119] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or terminal device comprising the said element.
[0120] The above has provided a detailed introduction to a medical image encryption method, device, equipment and storage medium provided by this application. Specific examples are used in this text to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for encrypting medical images, which is applied to a Picture Archiving and Communication System (PACS), characterized in that, Comprising: Obtain initial image data in DICOM format; wherein, the initial image data includes a unique identifier; Divide the initial image data into a plurality of image segment data with a preset number of digits; Generate round keys corresponding one-to-one with the image segment data according to the unique identifier; wherein, the round keys corresponding to different image segment data are different; the step of generating round keys corresponding one-to-one with the image segment data according to the unique identifier includes: generating an initial key according to the unique identifier; generating round keys corresponding one-to-one with the image segment data according to the initial key; the step of generating round keys corresponding one-to-one with the image segment data according to the initial key includes: dividing the initial key into a preset number of sub-keys; respectively updating the sub-keys through a first operation; sequentially and circularly updating the sub-keys through a second operation; when the second operation is completed, merging the updated sub-keys and the remaining sub-keys to obtain a round key; Generate encrypted image data according to the image segment data and the round key.
2. The encryption method according to claim 1, wherein The step of generating an initial key according to the unique identifier includes: Performing a hashing process on the unique identifier to obtain an initial key.
3. The encryption method according to claim 1, wherein The step of respectively updating the sub-keys through a first operation includes: For each sub-key, performing an exclusive OR operation on the sub-key with a first parameter.
4. The encryption method according to claim 1, wherein The step of sequentially and circularly updating the sub-keys through a second operation includes: For the sub-key of the current round, performing a non-linear transformation and a linear transformation on a first sub-key to obtain an intermediate value; Performing an exclusive OR operation on the intermediate value with a second parameter.
5. The encryption method according to claim 1, characterized in that, The step of generating encrypted image data according to the image segment data and the round key includes: Performing an encryption operation on the image segment data respectively with the round key corresponding to the image segment data to obtain encrypted segment data; Merging all the encrypted segment data to obtain encrypted image data.
6. An encryption device for medical images, applied to a Picture Archiving and Communication System (PACS), characterized in that, Comprising: A data acquisition module, configured to obtain initial image data in DICOM format; wherein, the initial image data includes a unique identifier; A data segmentation module, configured to divide the initial image data into a plurality of image segment data with a preset number of digits; A key generation module, configured to generate round keys corresponding one by one to the video segment data according to the unique identifier; wherein, the round keys corresponding to different video segment data are different from each other; the step of generating round keys corresponding one by one to the video segment data according to the unique identifier includes: generating an initial key according to the unique identifier; generating round keys corresponding one by one to the video segment data according to the initial key; the step of generating round keys corresponding one by one to the video segment data according to the initial key includes: dividing the initial key into a preset number of sub-keys; respectively updating the sub-keys through a first operation; sequentially and circularly updating the sub-keys through a second operation; when the second operation is completed, merging the updated sub-keys and the remaining sub-keys to obtain a round key; A data encryption module, configured to generate encrypted video data according to the video segment data and the round key.
7. A computer device, characterized in that, It includes a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the encryption method according to any one of claims 1-5 is implemented.
8. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, the encryption method according to any one of claims 1-5 is implemented.
Citation Information
Patent Citations
Double mapping method for on-chain representation and off-chain security edge storage of medical image
CN114372294A
Safety processing and transmission method based on DICOM file, client and server
CN115664694A