Method and storage medium for storing and reading health data

By accurately classifying and hierarchically encrypting health data, combining intelligent data retrieval and flexible security control, the problems of health data management and privacy protection are solved, and efficient data retrieval and secure data utilization are achieved.

CN118886031BActive Publication Date: 2025-06-13XIAN DAZHIHUITONG TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411000198.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2025-06-13
Estimated Expiration
2044-07-24

AI Technical Summary

Technical Problem

The prior art is difficult to effectively classify and manage large amounts of health data, and there are shortcomings in privacy protection, data encryption, secure storage and access rights control, resulting in the risk of data breaches and unauthorized access.

Method used

By accurately classifying personal health data, developing a hierarchical encryption strategy based on privacy preference analysis, performing mixed storage and encryption, and through intelligent data retrieval and selective decryption, combining flexible security control and intelligent access permission management, we ensure the security and rational use of data.

Benefits of technology

It improves the efficiency of data retrieval, enhances the protection of personal privacy, reduces the risk of data leakage, ensures the security and rational use of data, prevents unauthorized access, and optimizes the use of storage resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118886031B_ABST
    Figure CN118886031B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data processing, and particularly to a method for storing and reading health data and a storage medium. The method includes the following steps: collecting personal health data of a target object to obtain physiological and biochemical health data and behavioral and lifestyle pattern data; performing privacy preference analysis on the target object based on the physiological and biochemical health data and the behavioral and lifestyle pattern data to obtain a privacy sensitivity data set; formulating a hierarchical encryption strategy for the physiological and biochemical health data and the behavioral and lifestyle pattern data according to the privacy sensitivity data set to obtain a hierarchical encryption strategy set; making a data shunting decision on the physiological and biochemical health data and the behavioral and lifestyle pattern data to obtain a data shunting strategy. The present invention improves the classification accuracy and effective management of health data, and also improves the efficiency of data retrieval.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly to a method for storing and reading health data and a storage medium. Background Art

[0002] In the current technical field of data processing, especially in the storage and reading of health data, there are some technical problems to be solved urgently. First of all, with the rapid increase in the amount of health data, how to effectively classify and manage these data has become a challenge. Personal health data usually includes various types, such as sleep data, physiological data, biochemical data, activity data, and nutritional data. These data need to be accurately classified and stored for subsequent access and analysis.

[0003] Secondly, privacy protection is an important issue in the storage and reading of health data. Health data often contains sensitive information. How to ensure data security while facilitating data retrieval and use is a difficult problem in existing technologies. Traditional data storage methods cannot fully consider the privacy sensitivity of data, resulting in a risk of data leakage.

[0004] Furthermore, the encryption and secure storage of data are also areas that need to be focused on. Existing encryption technologies cannot meet the growing security requirements. Especially in the aspect of multi-level data protection, how to formulate effective hierarchical encryption strategies to adapt to health data with different sensitivity levels is an important direction in technological development.

[0005] Finally, access control of data is also a key issue. With the increasing popularity of health data applications, different users have different access requirements for data. How to intelligently determine the access rights of users to health data according to their identities and needs is an important link to ensure the reasonable utilization and security protection of data. Existing technologies have deficiencies in access control and cannot achieve flexible and secure access management. Summary of the Invention

[0006] Based on this, it is necessary for the present invention to provide a method for storing and reading health data and a storage medium to solve at least one of the above technical problems.

[0007] To achieve the above object, a method for storing and reading health data includes the following steps:

[0008] Step S1: Obtain personal health data; classify the personal health data to obtain physiological and biochemical health data and behavioral and lifestyle pattern data;

[0009] Step S2: Perform privacy preference analysis on the target object based on physiological and biochemical health data and behavioral and lifestyle data to obtain a privacy sensitivity data set; formulate a hierarchical encryption policy for the physiological and biochemical health data and behavioral and lifestyle data according to the privacy sensitivity data set to obtain a hierarchical encryption policy set;

[0010] Step S3: Make a data shunting decision on the physiological and biochemical health data and behavioral and lifestyle data to obtain a data shunting strategy; perform hybrid storage and encryption on the physiological and biochemical health data and behavioral and lifestyle data according to the hierarchical encryption policy set and the data shunting strategy to obtain locally encrypted health data and cloud-encrypted health data;

[0011] Step S4: Obtain user query request data; perform authentication and parsing on the user query request data to obtain user identity characteristic data; determine the access permission of the query user according to the user identity characteristic data to obtain a data access permission result;

[0012] Step S5: Based on the locally encrypted health data and cloud-encrypted health data, perform intelligent data retrieval and selective decryption according to the data access permission result to obtain authorized health data, and feedback the authorized health data to the query user.

[0013] Through the precise classification and effective management of personal health data, the present invention not only improves the efficiency of data retrieval, but also provides a solid foundation for data analysis and application. Secondly, through privacy preference analysis and the formulation of hierarchical encryption policies, the protection of personal privacy is strengthened, and the risk of data leakage is effectively reduced. In addition, through flexible security control and intelligent access permission control, the security and reasonable utilization of data are ensured, while unauthorized access is prevented. The present invention also ensures the accuracy of data use and meets the actual needs of users through intelligent data retrieval and selective decryption. Through historical access logs and storage resource monitoring, the dynamically adjusted storage strategy optimizes the use of storage resources, reduces data redundancy, and improves storage efficiency.

[0014] Preferably, the present invention also provides a computer-readable storage medium storing a storage and reading method for health data that can be loaded and executed by a processor as described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Other features, objectives, and advantages of the present invention will become more apparent by reading the detailed description of the non-limiting embodiments with reference to the following drawings:

[0016] Figure 1 The step flow diagram of the storage and reading method for health data according to an embodiment is shown.

[0017] Figure 2Shows the detailed step - by - step flowchart of step S2 of an embodiment.

[0018] Figure 3 Shows the detailed step - by - step flowchart of step S25 of an embodiment. Detailed implementation manners

[0019] The following clearly and completely describes the technical method of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those skilled in the art without creative work belong to the scope protected by the present invention.

[0020] In addition, the accompanying drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, so repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor methods and / or microcontroller methods.

[0021] It should be understood that although the terms "first", "second", etc. may be used here to describe each unit, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit can be called the second unit, and similarly the second unit can be called the first unit. The term "and / or" used here includes any and all combinations of one or more of the listed related items.

[0022] To achieve the above - mentioned purpose, please refer to Figures 1 to 3 , the present invention provides a method for storing and reading health data, including the following steps:

[0023] Step S1: Obtain personal health data; classify the personal health data to obtain physiological and biochemical health data and behavioral and lifestyle pattern data;

[0024] Step S2: Based on the physiological and biochemical health data and the behavioral and lifestyle pattern data, perform a privacy preference analysis on the target object to obtain a privacy sensitivity data set; formulate a hierarchical encryption strategy for the physiological and biochemical health data and the behavioral and lifestyle pattern data according to the privacy sensitivity data set to obtain a hierarchical encryption strategy set;

[0025] Step S3: Make a data shunting decision on the physiological and biochemical health data and the behavioral and lifestyle pattern data to obtain a data shunting strategy; perform hybrid storage and encryption on the physiological and biochemical health data and the behavioral and lifestyle pattern data according to the hierarchical encryption strategy set and the data shunting strategy to obtain locally encrypted health data and cloud-encrypted health data;

[0026] Step S4: Obtain the user query request data; perform authentication and parsing on the user query request data to obtain user identity characteristic data; determine the access permission of the query user according to the user identity characteristic data to obtain a data access permission result;

[0027] Step S5: Based on the locally encrypted health data and the cloud-encrypted health data, perform intelligent data retrieval and selective decryption according to the data access permission result to obtain authorized health data, and feedback the authorized health data to the query user.

[0028] Through the precise classification and effective management of personal health data, the present invention not only improves the efficiency of data retrieval, but also provides a solid foundation for data analysis and application. Secondly, through privacy preference analysis and the formulation of hierarchical encryption strategies, the protection of personal privacy is strengthened, and the risk of data leakage is effectively reduced. In addition, through flexible security control and intelligent access permission control, the security and reasonable utilization of data are ensured, while unauthorized access is prevented. The present invention also ensures the accuracy of data use and compliance with the actual needs of users through intelligent data retrieval and selective decryption. Through historical access logs and storage resource monitoring, the dynamically adjusted storage strategy optimizes the use of storage resources, reduces data redundancy, and improves storage efficiency.

[0029] In this embodiment, first, personal health data including sleep patterns, heart rate, and blood pressure is collected through a mobile health application or a wearable device. Subsequently, a data analysis tool is used to classify the data, generating physiological and biochemical health data and behavioral lifestyle pattern data. Next, a privacy preference analysis is performed on the classified data to identify the privacy sensitivity and create a privacy sensitivity data set. Based on this data set, a hierarchical encryption policy set is formulated to provide corresponding strength encryption protection for different levels of sensitive data. Through a data management tool, considering the user access pattern and local storage capacity, a data diversion strategy is formulated, and then the data is mixed-stored according to the hierarchical encryption policy set and the data diversion strategy. Part of the data is encrypted and stored in a secure area of the local device, such as the Android Keystore or the iOS Secure Enclave, and the rest is securely uploaded to a cloud storage service such as Amazon S3 or Google Cloud Storage, forming locally encrypted health data and cloud-encrypted health data. When the user initiates a query request, identity verification parsing is performed through an authentication mechanism (such as OAuth 2.0 or OpenID Connect), user identity characteristic data is extracted, and the data access permission is determined according to the permission control policy, obtaining a data access permission result. Based on this result, intelligent retrieval and selective decryption are performed on the encrypted data, and the authorized health data is fed back to the user through a secure protocol (such as HTTPS, SSL / TLS) to ensure data security. All sensitive operations in the whole process are logged in detail for security auditing and monitoring.

[0030] Preferably, step S1 includes the following steps:

[0031] Step S11: Collect electrooculogram signals of the target object to obtain enhanced eye movement data of the object;

[0032] Specifically, an eye tracker sensor can be selected and accurately placed on the key parts of the target object. Using wireless synchronization technologies such as Bluetooth or Wi-Fi, ensure that the data of all sensors can be transmitted to the central processing unit in real time, and finally obtain enhanced eye movement data of the object and enhanced skin physiological data of the object.

[0033] Step S12: Perform neuromorphic computing processing on the enhanced eye movement data of the object to obtain neurally encoded eye movement feature data of the object;

[0034] Specifically, object-enhanced eye movement data can be loaded, including but not limited to information on the frequency, amplitude, and direction of eye movements. Then, a neuromorphic computing model that simulates the human visual system is constructed, and deep learning algorithms such as convolutional neural networks (CNNs) or recurrent neural networks (RNNs) are used to extract features from the object-enhanced eye movement data. Through the backpropagation algorithm, the model is trained and optimized to improve its prediction accuracy and generalization ability. Finally, object neural coding eye movement feature data is generated.

[0035] Step S13: Perform multispectral dynamic skin resistance scanning on the target object to obtain object-enhanced skin physiological data, and perform terahertz spectral analysis on the object-enhanced skin physiological data to obtain object deep skin metabolic feature data;

[0036] Specifically, a terahertz time-domain spectrometer (THz-TDS) can be used to scan the skin of the target object. This device emits terahertz pulses with a frequency range of 0.1 - 10 THz and receives the reflected signals through a high-speed photoconductive antenna. During the acquisition process, the probe is placed at different skin locations of the target object, and 100 averages are collected at each position to improve the signal-to-noise ratio. The obtained time-domain data is converted into frequency-domain data through fast Fourier transform. Then, principal component analysis (PCA) and partial least squares regression (PLSR) algorithms are used to reduce the dimension and extract features from the spectral data. Finally, through a pre-trained deep neural network model, the extracted features are converted into specific skin metabolic indicators such as collagen content, water molecule dynamics, and subcutaneous fat distribution, thereby obtaining object deep skin metabolic feature data.

[0037] Step S14: Perform non-invasive physiological parameter acquisition on the target object to obtain object comprehensive physiological data;

[0038] Specifically, a multifunctional physiological monitor can be first worn by the target object, and this device integrates multiple sensors. Electrocardiogram signals are collected through dry electrodes with a sampling rate of 1000 Hz; respiratory signals use a resistive breathing belt with a sampling rate of 100 Hz; blood oxygen saturation is measured by a reflective pulse oximeter, and the data is updated once per second. At the same time, an infrared thermal imaging camera (resolution 320x240, temperature resolution 0.05°C) is used to scan the whole body of the target object once every 5 minutes. A microwave Doppler radar (operating frequency 24 GHz, sampling rate 100 Hz) is used to capture minute body movements. All data is transmitted to the central processing unit in real time through the Bluetooth 5.0 protocol. Data preprocessing includes median filtering to remove baseline drift, wavelet transform for denoising, and outlier detection and interpolation. Finally, all processed data is aligned according to the time stamp to form object comprehensive physiological data.

[0039] Step S15: Perform dynamic modeling analysis of the comprehensive physiological data of the subject to obtain the physiological rhythm prediction data of the subject;

[0040] Specifically, first, the fast Fourier transform (FFT) and continuous wavelet transform (CWT) can be used to perform time-frequency analysis on each physiological index in the comprehensive physiological data of the subject to identify significant periodic patterns. Then, nonlinear time series analysis methods, such as phase space reconstruction and recurrence quantification analysis (RQA), are adopted to extract the dynamic characteristics of the system. Next, a multi-scale entropy (MSE) model is constructed to quantify the complexity of physiological signals at different time scales. Based on these analyses, a deep learning model combining a long short-term memory network (LSTM) and an attention mechanism is designed. This model takes the physiological data of the past 72 hours as input and predicts the changes in physiological indexes in the next 24 hours. The model is trained using the Adam optimizer with a learning rate of 0.001, a batch size of 64, and 200 training epochs. Finally, the prediction results of the model are smoothed by the sliding window method to obtain the physiological rhythm prediction data of the subject.

[0041] Step S16: Perform micro-sampling on the target subject using a nano-biosensor to obtain nano-level biochemical index data of the subject, and perform integrated monitoring on the target subject using an intelligent wearable device to obtain the all-weather activity trajectory data of the subject;

[0042] Specifically, microfluidic chip technology can be used for micro-sampling with a nano-biosensor. The chip is made of PDMS (polydimethylsiloxane) material and contains multiple microchannels and sampling chambers. Through capillary action and micro-pump drive, a small amount (about 100 nL) of sweat and sebum is extracted from the skin surface of the target subject. The sample is then introduced into the nano-biosensor array integrated on the chip. The array contains gold nanoparticle sensors modified with specific antibodies for detecting the concentration of electrolytes (such as sodium and potassium ions); carbon nanotube field-effect transistors for measuring glucose and lactate levels; and sensors for detecting hormone content, such as cortisol. The sensor signals are amplified and processed by the on-chip integrated circuit and finally transmitted through a wireless module to form nano-level biochemical index data of the subject. At the same time, an intelligent wearable device is equipped for the target subject, including a smart watch using a 9-axis inertial measurement unit (IMU) (sampling rate 100 Hz) and smart clothing integrated with flexible strain sensors. The IMU data is fused through the Kalman filter algorithm to achieve high-precision motion trajectory reconstruction. The strain sensor network on the clothing (32x32 grid, sampling rate 50 Hz) detects body posture through capacitance changes. All data is transmitted to a mobile device in real time via low-power Bluetooth (BLE5.0), and after data cleaning and feature extraction, the all-weather activity trajectory data of the subject is generated.

[0043] Step S17: Conduct non-contact sleep monitoring on the target object to obtain the object's full-cycle sleep quality data;

[0044] Specifically, a high-precision pressure-sensing mattress (sampling rate 100Hz), an infrared thermal imaging camera (resolution 640x480, frame rate 30fps), and an environmental sensor kit can be installed in the sleep environment. The pressure-sensing mattress uses a capacitive sensor array (64x128 grid) to capture body movements and breathing patterns. The infrared thermal imaging camera analyzes the change in body temperature distribution in real time through thermal image processing algorithms. The environmental sensor kit includes a thermometer (accuracy ±0.1°C), a hygrometer (accuracy ±2%RH), and a decibel meter (measurement range 30 - 130dB). All data is processed in real time by an edge computing device, and a convolutional neural network (CNN) model is applied to identify sleep stages, and a recurrent neural network (RNN) analyzes the change in sleep cycles. Finally, the sleep monitoring data forms the object's full-cycle sleep quality data.

[0045] Step S18: Perform class annotation and integration on the object's neural coding eye movement feature data, the object's deep skin metabolism feature data, the object's physiological rhythm prediction data, and the object's nano-level biochemical index data to obtain physiological and biochemical health data, and perform class annotation and integration on the object's all-weather activity trajectory data and the object's full-cycle sleep quality data to obtain behavioral and lifestyle pattern data.

[0046] Specifically, data preprocessing methods can be used to standardize and normalize various types of data. For time series data (such as physiological rhythm prediction data, activity trajectory data), the dynamic time warping (DTW) algorithm is applied for time alignment. Then, a multi-label classifier (such as ML-kNN or BP-MLL) is used to perform preliminary class annotation on the data, dividing the data into five categories: sleep, physiology, biochemistry, activity, and nutrition, and then classifying the five categories into physiological and biochemical health data and behavioral and lifestyle pattern data. Next, a hierarchical clustering algorithm (such as AGNES) is applied to subdivide the data within each major category, forming a multi-level data structure. To handle the complex relationships between data, a knowledge graph is constructed, and entity recognition and relationship extraction techniques are used to convert data points into nodes and edges in the graph. Subsequently, a graph neural network (such as Graph Convolutional Network) is used to perform deep learning on the knowledge graph to extract high-order features and implicit relationships. Finally, an ensemble learning method (such as Stacking) is used to combine the outputs of each model to generate the final classification result. The entire process is implemented through a distributed computing framework (such as Apache Spark) to achieve parallel processing and improve efficiency. The finally output physiological and biochemical health data and behavioral and lifestyle pattern data are stored in a hierarchical JSON format, and each data point contains the original value, the standardized value, the class label, and the associated information.

[0047] The present invention realizes comprehensive health monitoring of the physiological and biochemical states of the target object by using a multimodal biosensor array, thereby providing a more comprehensive health status analysis. The application of microelectrophysiological signal acquisition technology makes the acquisition of eye movement and skin physiological data more accurate, enhancing the quality and depth of the data. Terahertz spectroscopy analysis technology deeply analyzes the metabolic characteristics of the deep layer of the skin, revealing more health information. Through physiological rhythm dynamic modeling and analysis technology, the physiological rhythm changes of the target object can be predicted, providing forward-looking guidance for health management. The use of nanobiosensors makes the sampling of biochemical indicators more refined, providing more accurate health data. The application of intelligent wearable devices records the all-day activity trajectory of the target object, providing data support for the analysis of activity habits and lifestyle. Non-contact sleep monitoring technology comprehensively evaluates the sleep quality of the target object. Intelligent gastrointestinal nutrition monitoring technology accurately monitors the nutrient absorption situation. Category annotation and integration technology effectively integrates various types of health data, forming a comprehensive and systematic personal health data. The comprehensive application of these technologies improves the personalization and effectiveness of health management.

[0048] Preferably, step S2 includes the following steps:

[0049] Step S21: Extract semantic tags from the physiological and biochemical health data and behavioral and lifestyle data to obtain a set of health data semantic tags;

[0050] Specifically, a text analysis module based on machine learning can be deployed, which is specifically used for processing and analyzing the classified personal health data. This module first receives the physiological and biochemical health data and behavioral and lifestyle data input in text form, such as sleep data and physiological data, and then uses natural language processing technology to perform word segmentation, decomposing the text into individual elements. Through part-of-speech tagging, the module identifies nouns and adjectives, which are used as candidate words for tag semantics. The module further uses ontologies and term libraries in the medical field to match and verify these candidate words. Then, a named entity recognition (NER) model is used to identify specific medical entities in the text, such as disease names or physiological indicators, and extract them as key semantic tags. Dependency syntactic analysis helps the system understand the semantic relationships between words, thereby refining the context and importance of the tags. Finally, all the extracted semantic tags are integrated into a set to obtain a set of health data semantic tags, which details the keywords and concepts associated with each health data category.

[0051] Step S22: Display the set of health data semantic tags and the preset privacy sensitivity options to the target object, and record the privacy sensitivity options selected by the target object to obtain a privacy sensitivity data set;

[0052] Specifically, a user-friendly interface can be developed and integrated into the health data recording software on the mobile terminal. This interface is designed to display the semantic tag set of health data and provide a set of preset privacy sensitivity options, such as "not sensitive", "moderately sensitive", and "highly sensitive". Through this interface, users can view the semantic tags of each health record and select the corresponding privacy sensitivity level by checking or using a slider. The software uses a database to store the user's selections, and each time the user makes a choice, the software will update the records in the database in real time. In this way, each tag is associated with the privacy sensitivity defined by the user, forming a privacy sensitivity data set.

[0053] Step S23: Perform corresponding sensitivity annotation on the physiological and biochemical health data and behavioral and lifestyle data according to the privacy sensitivity data set to obtain sensitivity-annotated health data;

[0054] Specifically, an automated script can be run at the software backend. This script reads the records in the privacy sensitivity data set and traverses the health data records in the database. The script will use a data marking tool to attach the corresponding label to each piece of health data according to the privacy sensitivity level selected by the user for each semantic tag. For example, if the user's sleep data is marked as "highly sensitive", the script will attach the label "high privacy" to this piece of data. In this way, each piece of health data will be given a clear privacy sensitivity annotation, thus forming a sensitivity-annotated health data set.

[0055] Step S24: Perform clustering of the same level on the sensitivity-annotated health data to obtain several groups of hierarchical health data;

[0056] Specifically, clustering algorithms such as k-means or hierarchical clustering can be used to process the sensitivity-annotated data set. The algorithm groups the data points according to the privacy sensitivity labels of the data, ensuring that the data in the same group has the same privacy level. For example, all data marked as "high privacy" will be clustered into the same group. The clustering results can be visually displayed to the user by the software, such as through a list or a chart, clearly showing the data grouping of different privacy levels. Finally, several groups of hierarchical health data are obtained.

[0057] Step S25: Develop a hierarchical encryption strategy for several groups of hierarchical health data to obtain a hierarchical encryption strategy set.

[0058] Specifically, for the specific implementation process of this embodiment, please refer to the sub-steps of Step S25.

[0059] The present invention enhances the retrievability of data through precise semantic tag extraction. Personalized privacy preference recognition ensures that data protection measures can meet the actual needs of users. By presenting preset privacy sensitivity options and recording user selections, personalized recognition of user privacy preferences is achieved. Data sensitivity annotation clearly differentiates the privacy levels of data, providing a basis for hierarchical encryption and strengthening privacy protection. Efficient data clustering by the same-level clustering method simplifies the complexity of data management and improves data processing efficiency. By taking corresponding encryption measures according to the sensitivity level of data, the flexibility and pertinence of data security protection are realized, ensuring the security of key data. The formulation of the hierarchical encryption strategy optimizes data security, effectively preventing data leakage or unauthorized access and enhancing the overall data security.

[0060] Preferably, step S25 includes the following steps:

[0061] Step S251: Collect network security event logs of the local terminal to obtain local historical security event data;

[0062] Specifically, a Security Information and Event Management (SIEM) system on the local terminal can be configured to collect network security event logs. This system captures events indicating security threats by monitoring network traffic and system activities. For example, SIEM agents are deployed at various key nodes in the local network to collect logs such as login attempts, data access, and system change events. These logs are then transmitted to a central SIEM server, and parsing tools running on the server convert logs in different formats into a unified format for easy analysis, finally obtaining local historical security event data.

[0063] Step S252: Collect network security event logs of a preset health data cloud storage platform to obtain cloud historical security event data;

[0064] Specifically, the log service of the cloud storage platform can be configured to collect and store security event information. Use log management tools provided by the cloud platform, such as Amazon CloudWatch or Google Cloud Logging, to monitor and record all security-related events in the cloud environment. These tools can track API calls, data access requests, and configuration change events and export the event logs to a secure repository, finally obtaining cloud historical security event data.

[0065] Step S253: Conduct statistics on the frequency distribution of various types of health data attacks on the local historical security event data to obtain local health data attack frequency distribution data;

[0066] Specifically, data analysis tools can be used to process and analyze local historical security event data. Specifically, run a data analysis tool query to filter out security events related to health data, such as unauthorized access attempts or data breach incidents. Then, use statistical analysis software, such as the Pandas library in R or Python, to classify these events and calculate the occurrence frequency of each type of event. In this way, the frequency distribution of attacks on local health data can be obtained, identifying the data types or time periods that are most frequently attacked, and finally obtaining the frequency distribution data of attacks on local health data.

[0067] Step S254: Conduct statistics on the frequency distribution of various types of health data attacks on the cloud historical security event data to obtain the frequency distribution data of attacks on cloud health data;

[0068] Specifically, data analysis software, such as the data analysis library in Python or professional business intelligence (BI) tools, can be used to perform statistical analysis on the cloud historical security event data. By writing scripts to identify and classify security events related to health data, such as data breaches, unauthorized access attempts, or malware attacks. The script will perform the following operations: Filter the logs to identify specific types of health data events. Classify the events, such as grouping by event type, timestamp, or data category affected. Calculate the event frequency for each category to determine which types of health data are more frequently targeted. After the analysis is completed, generate the frequency distribution data of attacks on cloud health data.

[0069] Step S255: Develop a hierarchical encryption strategy for several groups of hierarchical health data based on the frequency distribution data of attacks on local health data and the frequency distribution data of attacks on cloud health data to obtain a set of hierarchical encryption strategies.

[0070] Specifically, for the specific implementation process of this embodiment, please refer to the sub-steps of Step S255.

[0071] The present invention comprehensively collects and analyzes local and cloud network security event logs, achieving a comprehensive understanding and assessment of health data security threats, and providing a solid data foundation for formulating effective data protection measures. This enhanced data security analysis ability, combined with an accurate attack frequency assessment, enables the present invention to customize and design appropriate hierarchical encryption strategies for health data with different sensitivity levels, thereby realizing the differentiation and personalization of data protection. In addition, the present invention optimizes resource allocation, focuses on protecting data that is more vulnerable to attack or contains higher privacy sensitivity, improves preventive security measures, and quickly strengthens the response mechanism after identifying high-risk data, enhancing the response speed to security threats. Through hierarchical encryption, the present invention ensures the integrity and availability of data, reducing the risk of data loss or damage even when security events occur.

[0072] Preferably, step S255 includes the following steps:

[0073] Step S2551: Conduct a statistical count of the data categories for a set of hierarchical health data to obtain the quantity of single-group health data categories and the data of health data category names;

[0074] Specifically, the category labels of the data can first be extracted from the hierarchical health dataset by executing an SQL query statement. For example, use "SELECT category FROM health_data" to retrieve the "category" field from the data table named "health_data", which contains category labels such as "sleep data" and "physiological data". The dataset returned by the query is then imported into the Pandas library in Python for processing. Using the value_counts() function of Pandas, count these category labels to statistically count the number of occurrences of each category label in the dataset. Immediately afterwards, by accessing the index attribute of the obtained frequency sequence, all unique category names can be collected to create a list containing all categories. Finally, the quantity of single-group health data categories and the data of health data category names are obtained.

[0075] Step S2552: Based on the local health data attack frequency distribution data and the cloud health data attack frequency distribution data, conduct a comprehensive calculation of the attack frequency to obtain the attack frequency data for various types of data;

[0076] Specifically, the attack frequency of various types of health data can be calculated by combining the local health data attack frequency distribution data and the cloud health data attack frequency distribution data. These two sets of data are merged through data fusion technology. Then, use data analysis software such as Excel, R, or Python to calculate the comprehensive attack frequency of each type of health data, and finally obtain the attack frequency data for various types of data. This includes calculating the total number, average value, or weighted average of attack events.

[0077] Step S2553: If it is indicated in the quantity of single-group health data categories that there is only one category of health data in the corresponding set of hierarchical health data, extract the single-category attack frequency from the attack frequency data for various types of data according to the health data category name data to obtain the single-group attack frequency data;

[0078] Specifically, if the number of single-group health data categories indicates that there is only one category of health data in the corresponding group of hierarchical health data, a data screening tool such as the WHERE clause of SQL or the Pandas library in Python can be used to select the attack frequency data related to this single category. For example, if a group of hierarchical health data only contains the "blood pressure" category, all attack event records related to this data are screened out. Then, the screened data is counted and summarized to obtain the attack frequency data for this single category, that is, the single-group attacked frequency data.

[0079] Step S2554: If the number of single-group health data categories indicates that there are at least two or more categories of health data in the corresponding group of hierarchical health data, the multi-category attack frequency accumulation calculation is performed on the attacked frequency data of each category according to the health data category name data to obtain the single-group attacked frequency data;

[0080] Specifically, if the number of single-group health data categories indicates that there are at least two or more categories of health data in the corresponding group of hierarchical health data, a data analysis tool such as Excel or Python can be used to process the categories of single-group health data and the corresponding attack frequency data. By loading the attacked frequency data of each category into a worksheet or DataFrame, the attack frequencies of at least two categories are summarized and calculated. For example, in Python, the Pandas library can be used to perform a groupby operation on the DataFrame and apply the sum function to accumulate the attack frequencies of each category. This will generate a new data set containing each health data category and its total number of attacks, that is, the single-group attacked frequency data.

[0081] Step S2555: Extract the privacy sensitivity level for a group of hierarchical health data to obtain the privacy sensitivity level data;

[0082] Specifically, the preset privacy sensitivity level of each group of hierarchical health data can be directly retrieved from the data management system. If the data is stored in a relational database, an SQL query such as SELECT sensitivity_level FROM health_data_group is executed to extract the level information from the table health_data_group that stores the grouped health data and its privacy levels. The result returned by this query is the privacy sensitivity level of the data group.

[0083] Step S2556: If the single-group attack frequency data is greater than or equal to the preset attack frequency threshold data, and the privacy sensitivity level data is the highest-level privacy sensitivity or medium-level privacy sensitivity, then perform secure homomorphic encryption on the corresponding group of hierarchical health data to obtain a secure encryption policy; otherwise, perform lightweight lattice cryptography encryption on the corresponding group of hierarchical health data to obtain a lightweight encryption policy.

[0084] Specifically, it can be determined whether the single-group attack frequency data is greater than or equal to the preset attack frequency threshold. This can be done through a simple comparison operation, such as using a conditional statement in Python to check the frequency data. Then, check the privacy sensitivity level data to determine whether it is the highest-level or medium-level privacy sensitivity. If both conditions are met, use a secure homomorphic encryption library, such as Microsoft's SEAL library, to encrypt the data, thus obtaining a secure encryption policy. If the conditions are not met, then adopt a lightweight lattice cryptography encryption scheme, such as using an open-source lattice cryptography library to encrypt the data. The encryption process will be carried out according to the specific guidelines of the selected encryption scheme to ensure that the data is encrypted in a secure manner to resist potential attacks, thus obtaining a lightweight encryption policy.

[0085] Step S2557: Execute Step S2551 - Step S2556 on each group of hierarchical health data, that is, obtain a hierarchical encryption policy set, where the hierarchical encryption policy set contains several hierarchical encryption policies, and each hierarchical encryption policy corresponds to a group of hierarchical health data.

[0086] Specifically, the operations of Step S2551 to S2556 can be repeated for each group of data. This includes the statistics of data categories, the cumulative calculation of attack frequencies, the extraction of privacy sensitivity levels, and the application of appropriate encryption policies according to the evaluation results. The encryption policy for each group of data will be determined based on its specific attack frequency and privacy sensitivity level. After completing these operations, a hierarchical encryption policy set will be formed, where each policy details the encryption method and parameters for the corresponding group of data. This policy set can be manually organized into a document or automatically generate a report using a script.

[0087] Through precise data classification and statistics, the present invention provides detailed basic information for hierarchical health data, ensuring the accuracy of security assessment and encryption policies. Through comprehensive security threat assessment, the attack frequencies of local and cloud data are comprehensively analyzed, providing support for formulating encryption policies based on actual needs. The flexible attack frequency data processing ability, by adopting corresponding single or multi-category attack frequency processing methods for health data with different category quantities, ensures the pertinence and effectiveness of encryption policies. At the same time, the present invention deeply considers privacy sensitivity. By extracting privacy sensitivity level data, it ensures that the most sensitive data is protected at the highest level. For data facing high risks and high privacy sensitivities, the present invention adopts advanced secure homomorphic encryption technology to provide top-level data protection. For other data, lightweight lattice cryptography is used to achieve a balance between security and performance. The execution of step S2557 formulates a set of systematic and standardized encryption policy sets for all hierarchical health data, improving the adaptability and comprehensiveness of data protection. In addition, detailed data classification and encryption policy records strengthen compliance and auditing capabilities.

[0088] Preferably, step S3 includes the following steps:

[0089] Step S31: Collect the historical access logs of health data for the target object to obtain historical access log data;

[0090] Specifically, the log management system on the local terminal can be configured to automatically collect and store the historical access records of health data. This involves system log configuration to ensure that all relevant access events are recorded. For example, the syslog or rsyslog service in the Linux system can be used to monitor the logs of access files. In addition, if the health data is stored in a database, the auditing function of the database can be utilized to capture all data access activities. The collected log data will be saved in a log file or a database table, and finally, historical access log data is obtained.

[0091] Step S32: Statistically analyze the access frequencies of various types of health data for the historical access log data to obtain a dataset of category health data access frequencies, where the dataset of category health data access frequencies contains several category health data access frequency data, and each category health data access frequency data corresponds to a type of category health data;

[0092] Specifically, log analysis tools such as ELK Stack (Elasticsearch, Logstash, Kibana) or Graylog can be used to parse log files and extract access frequency information. Logstash is responsible for processing and transforming log data, Elasticsearch performs data indexing, and Kibana is used for data visualization. By writing Logstash filtering rules, access events for different categories of health data can be filtered out and these events can be counted. This will generate a dataset containing the access frequencies of different categories of health data.

[0093] Step S33: Sort the dataset of access frequencies of category health data in descending order to obtain a sorted list of access frequencies of category health data;

[0094] Specifically, data analysis tools such as the Pandas library in Python can be used to sort the dataset of access frequencies of category health data in descending order. First, load the data into a Pandas DataFrame, and then use the sort_values() function to sort the access frequencies, with the parameter set to ascending=False to achieve descending order. The sorted dataset will clearly show which categories of health data are accessed most frequently, and finally obtain a sorted list of access frequencies of category health data.

[0095] Step S34: Dynamically monitor the storage resources of the local terminal to obtain the available storage capacity data of the terminal;

[0096] Specifically, it can be achieved through the storage APIs provided by the operating system. On Android devices, use the StorageManager class to query the total storage capacity and available space, access the information of each storage volume through the getStorageVolume() method, and call getAvailableBytes() to obtain the available storage space in bytes. On iOS devices, use the NSFileManager class in the Foundation framework and its availableDiskSpace property to obtain the current storage space, and the return value is of the NSNumber type, also in bytes. A monitoring application or script can be created to periodically use these APIs to check and record the storage space data, and finally obtain the available storage capacity data of the terminal, and store the results in a database or file to achieve historical data tracking and analysis. It is also possible to use the file system APIs of cross-platform mobile development frameworks such as Flutter or React Native to implement cross-platform storage monitoring functions and integrate this function into the health data management application.

[0097] Step S35: Based on the historical access log data and the available storage capacity data of the terminal, make a data shunting decision on the physiological and biochemical health data and the behavioral and lifestyle data according to the list of sorted access frequencies of the category health data, and obtain a data shunting strategy;

[0098] Specifically, for the specific implementation process of this embodiment, please refer to the sub-steps of Step S35.

[0099] Step S36: According to the hierarchical encryption policy set and the data shunting strategy, perform hybrid storage and encryption on the physiological and biochemical health data and the behavioral and lifestyle data to obtain locally encrypted health data and cloud-encrypted health data.

[0100] Specifically, according to the established hierarchical encryption policy and data shunting strategy, a scripting language such as Python can be used, combined with an encryption library (such as cryptography), to encrypt the physiological and biochemical health data and the behavioral and lifestyle data. According to the data sensitivity, an encryption algorithm is selected. For example, AES-256 is used for highly sensitive data. The script automatically traverses the data set to implement the corresponding encryption, and at the same time determines the data storage location according to the shunting rules. After the local data is encrypted, it is stored in a secure area, such as the Android Keystore or the iOS Keychain. After the cloud data is encrypted, it is uploaded through the APIs of services such as Amazon S3, Google Cloud Storage, or Microsoft Azure Storage, and SSL and server-side encryption are used to ensure the security of the transmission. At the same time, an encryption management service is integrated to handle the full life cycle management of the keys, ensure the key strength and rotate them regularly. All encryption operations are accompanied by detailed log records, recording the details of the encrypted data, the algorithm, the key, and the storage location, to achieve the comprehensive and secure storage of personal health data, and finally obtain locally encrypted health data and cloud-encrypted health data.

[0101] Through the in-depth understanding of data access, the present invention realizes an in-depth insight into the user's access preferences and data usage patterns. Through efficient data access frequency analysis and optimized storage resource management, the present invention can monitor the storage capacity in real time and identify the most frequently accessed data categories, providing an intelligent decision-making basis for resource allocation and data storage. Through the data shunting decision, it further ensures that the data is reasonably allocated between the local and the cloud according to its access frequency and storage requirements, improving the efficiency and rationality of data storage. Through hybrid storage and encryption measures, the confidentiality and security of health data are improved. The flexible data storage scheme allows the selection of the most suitable storage location according to the data characteristics, and the improved data retrieval efficiency ensures a quick response to the user's query requests. In addition, the encryption and shunting strategies of the present invention strengthen the compliance of data protection, reduce compliance risks, and enhance the user's trust and satisfaction with the system.

[0102] Preferably, step S35 includes the following steps:

[0103] Step S351: Divide the top three categories in the sorted list of category health data access frequencies into local terminal storage categories, and divide the categories after the third into cloud storage categories, to obtain local storage category data and cloud storage category data;

[0104] Specifically, a data analysis tool, such as the Pandas library in Python, can be used to read and process the sorted list of category health data access frequencies. The script automatically retrieves the first three categories in the list and marks them as local storage categories. The remaining categories are automatically classified as cloud storage categories. This process involves list slicing and conditional filtering operations, and finally generates two sets of data: local storage category data and cloud storage category data, corresponding to the data categories to be stored on the local terminal and in the cloud respectively.

[0105] Step S352: Perform category mapping and diversion on the physiological and biochemical health data and behavioral and lifestyle pattern data according to the local storage category data and cloud storage category data, to obtain a local pre-screened health data set and a cloud pre-screened health data set;

[0106] Specifically, a Python script, combined with the Pandas library, can be used to classify and process personal health data according to the local storage category data and cloud storage category data. The script traverses the personal health data set and performs category mapping and diversion by matching the category labels of the data with the local storage category data. The qualified data is assigned to the local pre-screened health data set, and the unqualified data is assigned to the cloud pre-screened health data set. This process involves data filtering and set operations, and finally forms two independent data subsets, corresponding to the storage requirements of the local and cloud respectively.

[0107] Step S353: Quantify the storage space requirements of the local pre-screened health data set to obtain local storage requirement data;

[0108] Specifically, a script can be used to quantify the storage space requirements of the local pre-screened health data set. The specific operations include calculating the size of each file in the data set and summing these sizes to obtain the total storage requirement. In Python, the os.path.getsize() function can be used to obtain the size of a single file and then apply it to all files in the data set. Summing these values gives the local storage requirement data.

[0109] Step S354: Calculate the storage occupancy ratio of the local storage requirement data and the terminal available storage capacity data to obtain local storage occupancy rate data;

[0110] Specifically, a simple mathematical calculation can be used to compare the local storage requirement data with the available storage capacity data of the terminal, and the storage occupancy ratio can be calculated. This ratio is obtained by dividing the storage requirement by the available capacity and converted into a percentage form, so as to obtain the local storage occupancy rate data.

[0111] Step S355: If the local storage occupancy rate data is greater than the preset storage threshold, calculate the excess storage amount for the local storage occupancy rate data and the preset storage threshold to obtain the storage space excess data;

[0112] Specifically, if the local storage occupancy rate data is greater than the preset storage threshold, a simple conditional statement can be used to determine whether subsequent calculations need to be performed. Once the condition is met, the script will use a mathematical formula to calculate the excess storage amount, that is, the difference between the current occupancy rate and the threshold. This calculation can be achieved through a subtraction operation, and the result will be stored in a variable, representing the storage space excess data.

[0113] Step S356: Quantify the time-series storage requirements for each category of health data based on the local pre-screened healthy data set to obtain the time-series storage requirement data for the first category of health data, the time-series storage requirement data for the second category of health data, and the time-series storage requirement data for the third category of health data, and align the time-series storage requirement data for the first category of health data, the time-series storage requirement data for the second category of health data, and the time-series storage requirement data for the third category of health data on the time axis to obtain a multi-category health data time-series storage matrix;

[0114] Specifically, a Python script can be used, combined with the Pandas library, to group the health data of each category in chronological order and calculate the storage requirements for each day. This can be achieved through the groupby() function, grouping the data by date and using the sum() function to accumulate the data volume for each day. The same operation is performed for the health data of each category, and the results are stored in different variables respectively, such as first_category_daily_storage, second_category_daily_storage, and third_category_daily_storage. Then, use the merge() function or concat() function of Pandas to align these time-series data on a unified time axis to form a multi-category health data time-series storage matrix. This matrix will show the storage requirements of different categories of data over time.

[0115] Step S357: Calculate the critical date for the multi-category health data time-series storage matrix based on the storage space excess data to obtain the cloud migration date data;

[0116] Specifically, multiple types of time-series storage matrices of health data can be analyzed to identify the storage requirements for each day. For example, assume that the time-series storage matrices of multiple types of health data are the storage requirement data for 7 consecutive days, and these data are 0.5G on the first day, 0.3G on the second day, 0.6G on the third day, 0.4G on the fourth day, 0.6G on the fifth day, 0.5G on the sixth day, and 0.7G on the seventh day. Starting from 0.5G on the first day, accumulate the storage requirements day by day, including 0.3G on the second day and 0.6G on the third day, until the accumulated value reaches 1.4G, exceeding the 1G storage space excess threshold. Once the threshold is exceeded, stop accumulating and record this day as the last day for data migration. Next, list all categories of health data from the first day to this day as candidates for migrated data. Create a list or table to detail these dates and the corresponding storage requirement data, forming part of the data migration plan. This plan will clearly indicate which data needs to be migrated to the cloud at what time to effectively release local storage space. Finally, obtain a migration date data containing dates and storage requirements.

[0117] Step S358: Extract and eliminate time-threshold data from the local pre-screened health data set according to the cloud migration date data to obtain a cloud migration health data set and a final local storage health data set, and add the cloud migration health data set to the cloud pre-screened health data set to obtain a final cloud storage health data set.

[0118] Specifically, the cloud migration date data can be used to identify the local pre-screened health data set that needs to be migrated. Through time-threshold data extraction, data records within a specific date range are screened out. This involves sorting and filtering operations on the data set, which can be implemented using database queries or data processing software such as Excel and the Pandas library in Python. For example, in Pandas, the query() method or boolean indexing of the DataFrame object can be used to select records in a specific date column. Once these records are selected, they will be eliminated from the local pre-screened health data set and form the cloud migration health data set. Subsequently, the cloud migration health data set is merged with the cloud pre-screened health data set to form the final cloud storage health data set. This process requires data synchronization tools or scripts to automate data movement and updates.

[0119] Step S359: Based on the physiological and biochemical health data and the behavioral and lifestyle pattern data, make a summary of the data diversion decision according to the final local storage health data set and the final cloud storage health data set to obtain a data diversion strategy.

[0120] Specifically, the final local stored health data set and the final cloud stored health data set can be reviewed. Using data visualization tools such as Tableau or Power BI can help understand the distribution and characteristics of the data. The data can be examined in terms of categories, access frequencies, privacy sensitivity levels, and storage locations to determine whether the data has been correctly diverted. Additionally, machine learning models such as decision trees or logistic regression can be used to predict the optimal storage location for the data. Based on these analysis results, a set of data diversion rules can be formulated to clarify which types of data should be stored locally and which should be stored in the cloud. These rules will be compiled into a data diversion strategy document, and ultimately a data diversion strategy will be obtained.

[0121] Through priority storage allocation, the present invention ensures that health data categories with high access frequencies can be retrieved quickly, greatly improving the data retrieval efficiency. By intelligently allocating data to local or cloud according to access frequencies and storage requirements, the use of storage resources is optimized. Through accurate storage requirement assessment and dynamic storage management, combined with real-time monitoring of quantitative calculations and storage occupancy ratios, the storage strategy can be flexibly adjusted, effectively avoiding waste or exhaustion of storage space. In addition, the analysis of temporal storage requirements further optimizes the data storage time, ensuring the timeliness and availability of the data. The intelligent data migration decision balances the storage loads between local and cloud through the calculation of critical dates, while the optimized data storage structure ensures that the local storage concentrates the currently and recently most needed data through the extraction and elimination of time threshold data. The adaptability of the present invention to the data storage strategy, while enhancing data security, reduces the risks of data loss and leakage.

[0122] Preferably, step S4 includes the following steps:

[0123] Step S41: Obtain user query request data;

[0124] Specifically, the user query request data can be captured through integrated user interface components, thereby obtaining the user query request data.

[0125] Step S42: Perform authentication parsing on the user query request data to obtain user identity characteristic data;

[0126] Specifically, it can be achieved by integrating OAuth or OpenID Connect authentication protocols. The user logs in to the application, and the backend service verifies their credentials and returns an authentication token (such as a JWT) to the application. This token is then sent along with each query request, and the server extracts the user's identity characteristic data by parsing the token.

[0127] Step S43: Obtain an authorized user identity characteristic library;

[0128] Specifically, the authorized user identity feature library is stored in the server's database. This library contains the user's biometric data, such as fingerprint or facial recognition information. When an application needs to verify the user's identity, it requests a copy of this library or relevant data from the server for local matching. This can be achieved through secure API calls.

[0129] Step S44: Perform multimodal biometric matching on the authorized user identity feature library and the user identity feature data to obtain authentication similarity data;

[0130] Specifically, through secure API calls, using the HTTPS security protocol, retrieve the stored authorized user identity feature library from the server database, including but not limited to the user's fingerprint or facial recognition biometric data. After receiving the data, the application activates the biometric sensor on the device to capture the user's current biometric features and calls the biometric service of the corresponding operating system, such as Android's BiometricPrompt or iOS's LocalAuthentication framework, for multimodal biometric matching. The service on the device executes the matching algorithm, compares the user identity feature data with the data in the database, generates a similarity score to reflect the confidence of the match, and finally obtains the authentication similarity data.

[0131] Step S45: If the authentication similarity data is greater than the preset similarity threshold, then use the full access permission as the data access permission result; otherwise, use the denied access permission as the data access permission result.

[0132] Specifically, if the similarity score is higher than the preset threshold, the server will generate an access permission token or update the user status in the database to reflect the user's access permission. If the similarity score is lower than the threshold, the server will record this failed verification attempt and trigger additional security measures, such as account locking or notifying the user. This decision-making process can be implemented through the backend logic on the server, which checks the similarity score and updates the user permissions accordingly.

[0133] By adopting multimodal biometric matching technology, the present invention greatly enhances the accuracy of authentication, effectively prevents unauthorized access and data leakage, thereby significantly improving the security of the system. Accurate authentication parsing not only provides personalized services for users with specific identity characteristics, but also lays the foundation for efficient access control, ensuring fast response based on similarity thresholds and timely granting or denying of access permissions. This process enhances users' trust in the system security, safeguards the confidentiality and integrity of user data, optimizes the user experience, and reduces time delays caused by waiting for authentication. In addition, the flexible permission management mechanism of the present invention allows organizations to adjust the access control level according to different security policies and business requirements. For users with authentication similarity higher than the threshold in emergency situations, the present invention can quickly grant full access permissions to meet emergency access needs. In addition, precise identity feature matching reduces the risk of misoperation, improves the accuracy and reliability of data processing, promotes the reasonable sharing of data and cooperation between different institutions or teams, and enhances the utilization efficiency and value of data.

[0134] Preferably, step S5 includes the following steps:

[0135] Step S51: If the data access permission result is full access permission, perform semantic parsing and intention recognition on the user query request data to obtain query intention data;

[0136] Specifically, when the user is granted full access permission, the user's query request data is deeply processed. Using natural language processing (NLP) technology, for example, by invoking a pre-trained language model, such as BERT or its variants, semantic parsing of the query request is performed. These models can identify and understand the keywords and phrases in the user query, and then identify the user's query intention. Intention recognition can be achieved by training a classifier that maps the query text to predefined intention categories. Once the query intention is determined, query intention data is generated.

[0137] Step S52: Perform intelligent data retrieval and selective decryption on the local encrypted health data and the cloud encrypted health data according to the query intention data to obtain authorized health data, and feedback the authorized health data to the query user;

[0138] Specifically, intelligent data retrieval can be performed based on query intent data. This involves searching for health data that matches the query intent in the local database and cloud storage services. Search engine technologies, such as Elasticsearch, are used to index and query the stored data. For encrypted data, selective decryption is performed using the same encryption algorithm and key as when the data was encrypted. For example, if the data was encrypted using the AES algorithm, the corresponding decryption algorithm is applied to restore the original form of the data. The decryption process needs to ensure that only data visible to authorized users is decrypted. After retrieval and decryption, the data is processed and formatted, and then fed back to the user as authorized health data.

[0139] Step S53: If the data access permission result is a denied access permission, a preset zero-trust security policy is triggered to immediately terminate the user session and record the abnormal behavior.

[0140] Specifically, if the user's data access permission result is a denied access, a preset zero-trust security policy will be immediately triggered. This involves using a Security Information and Event Management (SIEM) system to monitor and respond to security events. When an unauthorized access attempt is detected, the SIEM system will automatically terminate the relevant user session and record the abnormal behavior in the security log. In addition, the system will update the Access Control List (ACL) or Identity and Access Management (IAM) policy to prevent unauthorized users from attempting to access again.

[0141] Through intelligent query response, the present invention achieves precise understanding and processing of user query requests, significantly improving the intelligent level of data processing. The efficient data retrieval ability ensures quick and accurate access to encrypted health data in the local and cloud based on the user's query intent. Secure selective decryption guarantees that only legally authorized users can obtain the decrypted data, strengthening data security and privacy protection. For unauthorized access, the triggering of the zero-trust security policy effectively prevents data leakage and privacy infringement, enhancing the risk control ability. In addition, while quickly responding to the query needs of authorized users, user satisfaction is improved. The present invention also promotes the reasonable utilization of data, prevents data abuse, and supports continuous security monitoring. By recording abnormal behaviors, it strengthens the monitoring and analysis of security threats, thereby enhancing the overall security and reliability of the system.

[0142] Preferably, the present invention also provides a computer-readable storage medium storing a storage and reading method for a health data that can be loaded and executed by a processor as described above.

[0143] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-exclusive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the application documents are intended to be encompassed within the present invention.

[0144] The above description is only a specific implementation manner of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather conform to the broadest scope consistent with the principles and novel features invented herein.

Claims

1. A method for storing and reading health data, characterized in that: The following steps are involved: Step S1: Collect personal health data of the target object to obtain physiological and biochemical health data and behavioral life pattern data; Step S2: Performing privacy preference analysis on the target object based on the physiological and biochemical health data and behavioral life pattern data to obtain a privacy sensitivity data set; Formulate hierarchical encryption strategies for physiological and biochemical health data and behavioral life pattern data according to the privacy sensitivity data set, and obtain a hierarchical encryption strategy set; Step S3: making data diversion decisions on physiological and biochemical health data and behavioral life pattern data to obtain a data diversion strategy; According to the hierarchical encryption strategy set and the data diversion strategy, the physiological and biochemical health data and the behavioral life pattern data are mixed and stored and encrypted to obtain local encrypted health data and cloud encrypted health data; wherein step S3 includes the following steps: Step S31: Collect health data history access logs of the target object to obtain history access log data; Step S32: performing statistics on the access frequency of each category of health data on the historical access log data to obtain a category health data access frequency data set, wherein the category health data access frequency data set includes a plurality of category health data access frequency data, and each category health data access frequency data corresponds to a category of health data; Step S33: sorting the category health data access frequency data set in descending order to obtain a category health data access frequency sorting list; Step S34: Dynamically monitor the storage resources of the local terminal to obtain the available storage capacity data of the terminal; Step S35: Based on the historical access log data and the terminal available storage capacity data, a data diversion decision is made on the physiological and biochemical health data and the behavioral life pattern data according to the category health data access frequency sorting list to obtain a data diversion strategy; wherein step S35 includes the following steps: Step S351: classify the first three categories in the health data access frequency sorting list as local terminal storage categories, and classify the categories after the third as cloud storage categories, to obtain local storage category data and cloud storage category data; Step S352: Classify and map the physiological and biochemical health data and the behavioral life pattern data according to the local storage category data and the cloud storage category data to obtain a local initial screening health data set and a cloud initial screening health data set; Step S353: quantifying the storage space requirement of the local initial screening health data set to obtain local storage requirement data; Step S354: Calculate the storage occupancy ratio of the local storage demand data and the terminal available storage capacity data to obtain local storage occupancy rate data; Step S355: if the local storage occupancy rate data is greater than the preset storage threshold, excess storage amount calculation is performed on the local storage occupancy rate data and the preset storage threshold to obtain storage space excess data; Step S356: quantifying the time series storage requirements of each category of health data based on the local initial screening health data set, obtaining time series storage requirement data of the first category of health data, time series storage requirement data of the second category of health data, and time series storage requirement data of the third category of health data, and aligning the time axis of the time series storage requirement data of the first category of health data, the time series storage requirement data of the second category of health data, and the time series storage requirement data of the third category of health data, to obtain a time series storage matrix of multiple categories of health data; Step S357: Calculate the critical date of the time series storage matrix of multiple types of health data according to the excess storage space data to obtain cloud migration date data; Step S358: extract and remove the time threshold data of the local initial screening health data set according to the cloud migration date data, obtain the cloud migration health data set and the final local storage health data set, and add the cloud migration health data set to the cloud initial screening health data set to obtain the final cloud storage health data set; Step S359: Based on the physiological and biochemical health data and the behavioral life pattern data, a data diversion decision summary is performed according to the final local storage health data set and the final cloud storage health data set to obtain a data diversion strategy; Step S36: Mix and store and encrypt the physiological and biochemical health data and the behavioral life pattern data according to the hierarchical encryption strategy set and the data diversion strategy to obtain local encrypted health data and cloud encrypted health data; Step S4: obtaining user query request data; performing identity authentication analysis on the user query request data to obtain user identity feature data; determining access rights for the querying user based on the user identity feature data to obtain a data access rights result; Step S5: Based on the local encrypted health data and the cloud encrypted health data, intelligent data retrieval and selective decryption are performed according to the data access permission results to obtain authorized health data, and the authorized health data is fed back to the querying user.

2. The method for storing and reading health data according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: collecting eye micro-electrophysiological signals of the target object to obtain enhanced eye movement data of the object; Step S12: performing neuromorphic computation processing on the enhanced eye movement data of the object to obtain neural coded eye movement feature data of the object; Step S13: performing a multi-spectral dynamic skin resistance scan on the target object to obtain enhanced skin physiological data of the object, and performing terahertz spectrum analysis on the enhanced skin physiological data of the object to obtain deep skin metabolism characteristic data of the object; Step S14: non-invasively collecting physiological parameters of the target object to obtain comprehensive physiological data of the object; Step S15: Performing physiological rhythm dynamic modeling analysis on the comprehensive physiological data of the subject to obtain physiological rhythm prediction data of the subject; Step S16: Performing micro-sampling of the target object with a nano-biosensor to obtain the nano-level biochemical index data of the target object, and performing integrated monitoring of the target object with a smart wearable device to obtain the all-weather activity trajectory data of the target object; Step S17: Conduct non-contact sleep monitoring on the target subject to obtain the subject's full-cycle sleep quality data; Step S18: classify and integrate the subject's neural coding eye movement feature data, the subject's deep skin metabolism feature data, the subject's physiological rhythm prediction data, and the subject's nanoscale biochemical indicator data to obtain physiological and biochemical health data, and classify and integrate the subject's all-day activity trajectory data and the subject's full-cycle sleep quality data to obtain behavioral life pattern data.

3. The method for storing and reading health data according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: extracting semantic labels from physiological and biochemical health data and behavioral life pattern data to obtain a health data semantic label set; Step S22: presenting the health data semantic tag set and the preset privacy sensitivity options to the target object, and recording the privacy sensitivity options checked by the target object to obtain a privacy sensitivity data set; Step S23: labeling the physiological and biochemical health data and the behavioral life pattern data with corresponding sensitivity according to the privacy sensitivity data set to obtain sensitivity-labeled health data; Step S24: performing same-level clustering on the sensitivity-labeled health data to obtain several groups of hierarchical health data; Step S25: Formulate hierarchical encryption strategies for several groups of hierarchical health data to obtain a hierarchical encryption strategy set.

4. The method for storing and reading health data according to claim 3, characterized in that: Step S25 includes the following steps: Step S251: Collect network security event logs from the local terminal to obtain local historical security event data; Step S252: Collect network security event logs from a preset health data cloud storage platform to obtain cloud historical security event data; Step S253: Perform frequency distribution statistics of various health data attacks on local historical security event data to obtain the frequency distribution data of local health data attacks; Step S254: Perform frequency distribution statistics of various health data attacks on the cloud historical security event data to obtain the frequency distribution data of health data attacks on the cloud; Step S255: Formulate hierarchical encryption strategies for several groups of hierarchical health data according to the attack frequency distribution data of local health data and the attack frequency distribution data of cloud health data to obtain a hierarchical encryption strategy set.

5. The method for storing and reading health data according to claim 4, characterized in that: Step S255 includes the following steps: Step S2551: Perform data category statistics on a group of hierarchical health data to obtain the number of health data categories and health data category name data for a single group; Step S2552: Perform comprehensive attack frequency calculation based on the attack frequency distribution data of local health data and the attack frequency distribution data of cloud health data to obtain attack frequency data of various types of data; Step S2553: if the number of categories of a single group of health data indicates that there is only one category of health data in the corresponding group of hierarchical health data, then a single category attack frequency is extracted from the attack frequency data of each category of data according to the health data category name data to obtain a single group of attack frequency data; Step S2554: If the number of categories of a single group of health data indicates that there are at least two or more categories of health data in the corresponding group of hierarchical health data, then the attack frequency data of each type of data is cumulatively calculated based on the health data category name data to obtain a single group of attack frequency data; Step S2555: extracting the privacy sensitivity level of a set of graded health data to obtain privacy sensitivity level data; Step S2556: If the single group of attack frequency data is greater than or equal to the preset attack frequency threshold data, and the privacy sensitivity level data is the highest privacy sensitivity or the intermediate privacy sensitivity, the corresponding group of hierarchical health data is securely homomorphically encrypted to obtain a secure encryption strategy; otherwise, the corresponding group of hierarchical health data is encrypted with a lightweight lattice cipher to obtain a lightweight encryption strategy; Step S2557: Execute steps S2551 to S2556 on each group of hierarchical health data to obtain a hierarchical encryption strategy set, wherein the hierarchical encryption strategy set includes several hierarchical encryption strategies, and each hierarchical encryption strategy corresponds to a group of hierarchical health data.

6. The method for storing and reading health data according to claim 1, characterized in that: Step S4 includes the following steps: Step S41: Obtain user query request data; Step S42: Perform identity authentication analysis on the user query request data to obtain user identity feature data; Step S43: Obtaining the authorized user identity feature database; Step S44: performing multimodal biometric matching on the authorized user identity feature database and the user identity feature data to obtain identity authentication similarity data; Step S45: If the identity authentication similarity data is greater than a preset similarity threshold, full access permission is used as the data access permission result; otherwise, denied access permission is used as the data access permission result.

7. The method for storing and reading health data according to claim 1, characterized in that: Step S5 includes the following steps: Step S51: If the result of the data access permission is full access permission, semantic analysis and intent recognition are performed on the user query request data to obtain query intent data; Step S52: intelligently retrieve and selectively decrypt the local encrypted health data and the cloud encrypted health data according to the query intention data to obtain the authorized health data, and feed back the authorized health data to the querying user; Step S53: If the result of the data access permission is to deny access permission, the preset zero-trust security policy is triggered, the user session is terminated immediately and the abnormal behavior is recorded.

8. A computer-readable storage medium storing a method for storing and reading health data as described in any one of claims 1 to 7 that can be loaded and executed by a processor.

Citation Information

Patent Citations

  • Classified and graded fitness health big data sharing system and method

    CN114513533A