A data protection and analysis system for telemedicine

Through the data protection and analysis system, customized desensitization and sandbox technology are used to achieve local storage and remote analysis of remote diagnosis and treatment data, solve the problems of data security and privacy protection, and improve the efficiency of medical resource allocation.

CN119150337BActive Publication Date: 2025-10-10FUDAN UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310718895.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-16
Publication Date
2025-10-10
Estimated Expiration
2043-06-16

AI Technical Summary

Technical Problem

In remote diagnosis and treatment, how to break down information silos and achieve remote online analysis of data while ensuring data security, while avoiding data and privacy leaks.

Method used

A data protection and analysis system is provided, including data collection, storage, weak privacy data preparation, analysis authorization and feedback modules. It adopts customized desensitization methods and sandbox technology to ensure that data is stored locally and analyzed remotely, accesses the intranet through VPN, and uses a hard password dongle for authorization analysis.

Benefits of technology

It realizes local storage and remote analysis of data, reduces network load and data leakage risk, ensures data security and privacy protection, solves the problem of users being unable to use hard password dongle software remotely, and improves the efficiency of medical resource allocation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119150337B_ABST
    Figure CN119150337B_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of remote diagnosis and treatment, and specifically relates to a data protection and analysis system for remote diagnosis and treatment. The system comprises a data acquisition module and a data storage module arranged in an intranet, a weak privacy data preparation module, a data analysis authorization module and an analysis data return module arranged on a local transfer platform in the intranet, and a remote login and data analysis module arranged in an extranet. The data collected by different devices are uploaded and stored in the local, and the data to be analyzed are privacy desensitized. After identity verification and authority authorization of an analyst, the local software on the local transfer platform is opened to read the desensitized files through remote login of the local transfer platform in the extranet, and real-time data labeling and interpretation are performed. The whole data access and analysis process is completed in the local, thereby reducing the network load and the risk of data leakage. The sandbox technology is used to realize whole-process monitoring of the user, thereby avoiding data leakage caused by copying and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of remote diagnosis and treatment, and in particular relates to a data protection and analysis system for remote diagnosis and treatment. Background Art

[0002] With the continuous development of the healthcare industry in recent years, healthcare-related data has also been accumulating. Healthcare data is characterized by large volume, diverse structure, rapid growth, and high application value. However, because it involves private information such as personal attributes and health status, inadequate protection measures can lead to data loss, patient privacy breaches, and data tampering. To prevent the potential for healthcare data leaks, most hospitals and research institutions restrict external access by setting data access permissions. This results in a lack of information flow between hospitals and creates "information silos" between hospitals. Breaking down traditional data silos and hastily transitioning to sharing and open access inevitably presents numerous risks: 1. Data privacy breaches; 2. Data security issues: ensuring data authenticity, integrity, and trustworthiness; and 3. The distribution of rights and interests between data owners and users. Breaking down information silos and promoting the development of telemedicine without data sharing across systems remains a challenge. Summary of the Invention

[0003] The purpose of the present invention is to provide a data protection and data analysis system for remote diagnosis and treatment, which can realize remote online analysis of data without leaving the local area while ensuring data security and avoiding the problem of information islands.

[0004] The data protection and analysis system for remote diagnosis and treatment provided by the present invention includes: a data acquisition module, a data storage module, a weak privacy data preparation module, a data analysis authorization module, a parsed data return module, and a remote login and data analysis module, wherein:

[0005] The data acquisition module is used to collect various information data required for remote diagnosis and analysis, such as electrophysiological signals (e.g., electroencephalogram, electrooculogram, electromyography, electrocardiogram, etc.), voice signals, images, body composition, motion signals, 3D human body / head and face scans, etc.

[0006] The data storage module is used to store various types of information data collected by the data collection module;

[0007] The weak privacy data preparation module is mainly used to screen the data to be analyzed and perform privacy desensitization on the filtered data to facilitate the next step of data analysis. It specifically includes: performing data screening and data de-privacy operations; screening different data categories according to different data analysis requirements; using a customized desensitization method that combines different desensitization methods to desensitize personal identity information or sensitive information such as name, ID number, address, phone number, email address, image, voice, etc.

[0008] The data analysis authorization module is first used to establish access rights, time limits, number of accesses, data destruction policies, etc., and uses a sandbox to record the entire process of user operations during the data analysis process, prohibiting users from copying data or rewriting original data during use. Secondly, data analysis software is installed on the transfer platform and connected to a password dongle to ensure that users can open the analysis software for data analysis after being authorized for data analysis.

[0009] The parsed data return module is used to return the parsed data to the data storage module;

[0010] The remote login and data analysis module includes: after the user authenticates his identity, he uses VPN to access the intranet, and then accesses the local transit platform through the bastion host; after accessing the local bastion host, he opens the connection password dog and uses authorized professional analysis software to parse the data that needs to be analyzed.

[0011] In the present invention, the data acquisition module can collect multimodal data, including but not limited to the following data collection, such as: using a polysomnography device to collect physiological data related to the subject's sleep throughout the night; using electroencephalography and near-infrared equipment to collect brain function-related data of the subject; using an electronic glottis device to collect voice data of the subject; using inbody to collect body composition data of the subject; using dual-energy X-ray (DXA) to measure bone density data, etc.

[0012] In the present invention, when storing collected data, the data storage module generates an index tag with time and device information based on the data collection device and collection time. The index tag facilitates rapid query and reading of the data at a later time; based on the index tag, the target storage address of the data is determined to improve the data storage efficiency of the data.

[0013] In the present invention, a customized desensitization method is adopted in the weak privacy data preparation module, including: selecting different desensitization methods for different data types. For example, for structured data, k-anonymity, l-diversity, differential privacy, symmetric encryption, asymmetric encryption, conformal encryption and other methods can be used for irreversible / recoverable desensitization; for image data, Gaussian blur and other methods are used for desensitization; for audio data, sensitive audio is replaced with blank audio and other methods for desensitization, etc., so as to protect data involving personal identity information or sensitive information.

[0014] In the present invention, the data analysis authorization module adopts the security sandbox technology, which can record the entire process of user operation, prohibit users from copying data and rewriting original data during the operation, and further improve the data security during use.

[0015] In the present invention, in the parsed data return module, the parsed data is returned as a single file or in batches.

[0016] In the present invention, the remote login and data analysis module allows users to remotely access the intranet through the external network, read the data that needs to be analyzed, and analyze the data; for example, the collected nighttime electrophysiological signals are interpreted to identify sleep micro-events, sleep rhythms, sleep diseases, etc.; the collected brain function (EEG, near-infrared, brain imaging, etc.) signals are interpreted to identify brain function status, etc.; the collected voice signals are interpreted to identify voice-related diseases, such as pathological voice, etc.; the analysis results can be pushed to users as part of the health report, and can also be pushed to later data analysts as a gold standard to facilitate later data analysts to conduct in-depth data mining.

[0017] The data protection and analysis system of the present invention is used for remote diagnosis and treatment, and its operation or workflow is as follows:

[0018] (1) Upload and store data collected by different devices locally, such as: using polysomnography to collect physiological data related to the subject's sleep throughout the night; using electroencephalography and near-infrared devices to collect brain function data related to the subject; using electronic glottis to collect voice data of the subject; using inbody to collect body composition data of the subject; using dual-energy X-ray (DXA) to measure bone density data, etc.

[0019] (2) When it is necessary to parse a certain type or types of data, the data to be parsed is first privacy-masked, and the privacy-masked data is pushed to the data parsing authorization module on the local transfer platform;

[0020] (3) Doctors / data analysts log in remotely to the local transfer platform, verify their identity and authorize permissions, then open the local software on the local transfer platform to read the desensitized files and perform real-time data annotation and interpretation;

[0021] (4) Afterwards, the analysis results are pushed and stored locally through the parsing data return module;

[0022] During the entire process, data storage, backup, analysis, and management are all completed locally, ensuring that the data does not leave the local area, reducing network load and the risk of data leakage; at the same time, each operation of doctors / data analysts will be performed in a sandbox, which can realize full-process monitoring and avoid data leakage caused by duplication.

[0023] In the present invention, a weak privacy data preparation module, a data parsing authorization module and a parsed data return module are deployed on a local transit platform; the transit platform first provides a customized desensitization method based on the characteristics of different data types, and can select a desensitization solution according to different data types, effectively reducing the leakage of sensitive information and improving data security; for analysis software that requires a hard password dongle to use, by accessing the local transit platform data parsing authorization module, after local authorization, the user can remotely access the transit platform and use the analysis software to perform data parsing, solving the problem that when users use existing cloud storage technology, they cannot use professional software that requires a hard password dongle for analysis; at the same time, sandbox technology is used to monitor the user throughout the entire process to avoid data leakage caused by copying, etc.

[0024] The present invention provides a specific solution for local data storage and remote analysis, which enjoys absolute data control over the data and does not rely on a third party. At the same time, for analysis software that requires a hard password dongle to access during the data analysis process, a solution for remote use of the software is provided.

[0025] The present invention can effectively improve the rational allocation of medical resources and facilitate remote consultation, teaching research, telemedicine, etc.

[0026] Compared with existing data protection and data analysis platforms for remote diagnosis and treatment, the present invention has the following substantial advantages:

[0027] (1) Existing cloud storage technology or hosted storage technology requires data to be stored on a virtual server hosted by a third party. Therefore, it is usually necessary to consider not only the reliability of the service provider / supplier, but also potential hosting interruption events, data security risks, etc. The present invention not only provides a specific solution for local data storage and remote analysis, but also enjoys absolute data control over the data without relying on a third party. For data analysis, data can be analyzed online without leaving the local server.

[0028] (2) The customized desensitization method provided by the present invention adopts different desensitization schemes for different data types, which can effectively reduce the leakage of sensitive information and improve data security;

[0029] (3) For professional analysis software that needs to be connected to a hard dongle such as a USB / serial port / parallel port, the present invention provides a solution for a local transfer platform. The hard dongle can be directly connected to the local transfer platform. After local authorization, the user can remotely access the transfer platform and use the analysis software to perform data analysis, which solves the problem that users cannot use professional software that requires a hard dongle for analysis when using existing cloud storage technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 It is a diagram of the data protection and analysis system for remote diagnosis and treatment according to the present invention.

[0031] Figure 2 It is the data protection and analysis system process framework for remote diagnosis and treatment of the present invention.

[0032] Figure 3 It is a sleep monitoring system-annotated list.

[0033] Figure 4 is an example of sleep data.

[0034] Figure 5 This is an example of sleep annotation data results.

[0035] Figure 6 This is an example of sleep data labeling completion and result verification. Implementation Method

[0036] Taking remote sleep data analysis and annotation as an example, the present invention is further introduced:

[0037] 1. Open the data protection and analysis system for remote diagnosis and treatment, including the sleep monitoring system - see the marked list Figure 3 shown.

[0038] Doctors / data analysts access the local transfer platform through remote login (local transfer platform system interface, such as Figure 3 shown), Figure 3The annotation list includes "To be Annotated", "All Annotations", "My Annotations", as well as a verification list and a report list. Click "To be Annotated" in the annotation list to display the sleep data that has been pushed from the local server to the platform and is waiting to be parsed. Click "All Annotations" to display the parsing / annotation status of all sleep data that has been pushed from the local server to the platform. Click "My Annotations" to display the history of the annotated data related to me. The verification list mainly shows which data has completed secondary verification and which data is waiting for secondary verification. The report list is mainly used to display the specific details of the annotation-based situation, which reports have been generated, and whether the reports have been pushed back to the local area.

[0039] 2. Read the sleep data to be parsed that has been pushed to the platform from the local server and start data parsing. Figure 4 shown.

[0040] from Figure 3 Click on the interface to start labeling, and then enter the data analysis process. Data analysis is mainly done by opening the authorized data analysis software, such as Figure 4 As shown, doctors / data analysts then begin to manually interpret the data.

[0041] 3. Complete the sleep data analysis and save the data analysis results. Figure 5 shown.

[0042] After completing the data analysis, the sleep data annotation results are generated, such as Figure 5 The results mainly include an objective quantitative evaluation of the entire sleep data, including the duration of falling asleep, the latency of falling asleep, the proportion of time in each sleep stage, etc. After saving the sleep data annotation results, you can Figure 3 You can query the generated reports in the report list.

[0043] 4. Verify the sleep data analysis results and send them back to the local server. Figure 6 shown.

[0044] If you need to verify the sleep data analysis results generated in step 2-3, you can open Figure 3 The verification list is checked for a second time. After passing the second verification, you can Figure 3 Check the verification status in all the tags. After the verification is completed, the remote analysis of a data set is completed.

Claims

1. A data protection and analysis system for remote diagnosis and treatment, characterized in that: include: Data collection module, data storage module, weak privacy data preparation module, data analysis and authorization module, analysis data return module, remote login and data analysis module; The system is divided into two parts: the intranet and the extranet. The data acquisition module and data storage module are deployed in the intranet, the weak privacy data preparation module, data analysis and authorization module, and analysis data return module are deployed on the local transfer platform of the intranet; the remote login and data analysis module is deployed in the extranet. The data acquisition module is used to collect various types of information data required for remote diagnosis and analysis, including electrophysiological signals, voice signals, image data, and body composition information; The data storage module is used to store various types of information data collected by the data collection module; The weak privacy data preparation module is mainly used to screen the data to be parsed and perform privacy desensitization on the screened data to facilitate the next step of data parsing. Specifically, it includes: performing data screening and data de-privacy operations; screening different data categories according to different data parsing requirements; using a customized desensitization method that combines different desensitization methods to desensitize personal identity information or sensitive information, including name, ID number, address, phone number, email address, image, and voice; The data analysis authorization module is used to first establish access rights, time limits, number of accesses, and data destruction policies. It also uses a sandbox to record the entire process of user operations during the data analysis process, prohibiting users from copying data or rewriting original data during use. Secondly, data analysis software is installed on the transfer platform and connected to a password dongle to ensure that users can open the analysis software for data analysis after being authorized to perform data analysis. The parsed data return module returns the parsed data to the data storage module after authorization by the parsing personnel; The remote login and data analysis module includes: after the user authenticates his identity, he uses VPN to access the intranet, and then accesses the local transit platform through the bastion host; after accessing the local bastion host, he opens the connection password dog and uses authorized professional analysis software to parse the data that needs to be analyzed.

2. The data protection and analysis system for remote diagnosis and treatment according to claim 1, characterized in that: The data acquisition module collects multimodal data, specifically including: using a polysomnography device to collect physiological data related to the subject's sleep throughout the night; using electroencephalography and near-infrared equipment to collect brain function-related data of the subject; using an electronic glottis device to collect voice data of the subject; using inbody to collect body composition data of the subject; and using dual-energy X-ray (DXA) to measure bone density data.

3. The data protection and analysis system for remote diagnosis and treatment according to claim 1, characterized in that: When storing collected data, the data storage module generates an index tag with time and device information based on the data collection device and collection time. The index tag facilitates rapid query and reading of the data at a later time; based on the index tag, the target storage address of the data is determined to improve the data storage efficiency of the data.

4. The data protection and analysis system for remote diagnosis and treatment according to claim 1, characterized in that: In the weak privacy data preparation module, a customized desensitization method is adopted, that is, different desensitization methods are selected according to different data types, including: for structured data, k-anonymity, l-diversity, differential privacy, symmetric encryption, asymmetric encryption or conformal encryption methods are used for irreversible / recoverable desensitization; for image data, Gaussian blur method is used for desensitization; for audio data, sensitive audio is replaced with blank audio for desensitization.

5. The data protection and analysis system for remote diagnosis and treatment according to claim 1, characterized in that: In the data analysis authorization module, the security sandbox technology is used to record the entire process of user operation, prohibiting users from copying data and rewriting original data during the operation process, further improving data security during use.

6. The data protection and analysis system for remote diagnosis and treatment according to claim 1, characterized in that: In the parsed data return module, the parsed data is returned as a single file or in batches.

7. The data protection and analysis system for remote diagnosis and treatment according to claim 1, characterized in that: The remote login and data analysis module allows users to remotely access the intranet through the external network, read the data that needs to be analyzed, and analyze the data, including: interpreting the collected nocturnal electrophysiological signals to determine sleep micro-events, sleep rhythms, and sleep diseases; interpreting the collected brain function signals to determine the brain function state, and the brain function signals include electroencephalogram, near-infrared, and brain imaging signals; interpreting the collected voice signals to identify voice-related diseases; the analysis results are pushed to the user as part of the health report, or pushed to the later data analysts as the gold standard to facilitate the later data analysts to conduct in-depth data mining.

8. The data protection and analysis system for remote diagnosis and treatment according to any one of claims 1 to 7, characterized in that: The workflow is: (1) Upload and store data collected by different devices locally, including: polysomnography to collect the subject's sleep-related physiological data throughout the night; electroencephalography and near-infrared devices to collect the subject's brain function-related data; electronic glottis to collect the subject's voice data; inbody to collect the subject's body composition data; and dual-energy X-ray (DXA) to measure bone density data. (2) When it is necessary to parse a certain type or types of data, the data to be parsed is first privacy-masked, and the privacy-masked data is pushed to the data parsing authorization module on the local transfer platform; (3) Doctors / data analysts log in remotely to the local transfer platform, verify their identity and authorize permissions, then open the local software on the local transfer platform to read the desensitized files and perform real-time data annotation and interpretation; (4) Afterwards, the analysis results are pushed and stored locally through the parsing data return module; the analysis results are pushed to the user as part of the health report, or pushed to the later data analysts as the gold standard to facilitate the later data analysts to conduct in-depth data mining; Throughout the entire process, data storage, backup, analysis, and management are all completed locally, ensuring that the data does not leave the local area, reducing network load and the risk of data leakage; at the same time, each operation of doctors / data analysts will be performed in a sandbox to achieve full-process monitoring and avoid data leakage caused by duplication.

Citation Information

Patent Citations

  • Novel medical information storage system

    CN110838349A

  • Systems and methods for converting and delivering medical images to mobile devices and remote communications systems

    US20110087651A1