Intelligent encryption method of medical information data based on digital signature

By adopting digital signature, support vector machine algorithm, data anonymization and desensitization technology, and blockchain technology in the processing of medical information data, the problem of insufficient security and privacy protection of medical information data in the existing technology is solved, and efficient, transparent and secure data processing and transmission is achieved.

CN119272349BActive Publication Date: 2025-05-23SHANXI ZHIJIE COMPUTER SOFTWARE ENG CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411312181.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-20
Publication Date
2025-05-23
Estimated Expiration
2044-09-20

AI Technical Summary

Technical Problem

When protecting the security, integrity and privacy of medical information data, the prior art has problems such as low encryption efficiency, insufficient privacy protection, lack of intelligent encryption strategies, insufficient audit and transparency, and lack of data transmission security.

Method used

The intelligent encryption method of medical information data based on digital signature is adopted, combining digital signature technology, symmetric encryption and asymmetric encryption technology, support vector machine algorithm, data anonymization and desensitization technology, and blockchain technology to achieve security protection and intelligent encryption of medical information data.

Benefits of technology

It improves the integrity, authenticity and confidentiality of medical information data in the transmission and storage process, realizes an intelligent encryption strategy, comprehensively protects patient privacy, enhances the transparency and credibility of data processing processes, and ensures the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119272349B_ABST
    Figure CN119272349B_ABST
Patent Text Reader

Abstract

The present invention discloses a medical information data intelligent encryption method based on digital signature, including S1, obtaining medical information data; S2, using public key infrastructure and hash function to generate digital signature of medical information data; S3, performing data anonymization and desensitization processing on medical information data, and removing sensitive information through privacy protection technology; S4, introducing machine learning algorithm and rule-based encryption strategy, dynamically analyzing the type, sensitivity and user behavior of medical information data, and intelligently selecting encryption algorithm; S5, using a method combining symmetric encryption and asymmetric encryption to quickly encrypt large amounts of medical information data; S6, securely storing and transmitting the encrypted medical information data and the encrypted symmetric key, and using blockchain technology to record the signature and encryption process of medical information data. The present invention has the advantages of high security, high intelligence, comprehensive privacy protection and transparent data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent encryption of medical information data, and in particular to an intelligent encryption method of medical information data based on digital signature. Background Art

[0002] With the rapid development of information technology, the amount and importance of medical information data are increasing, and the security, integrity and privacy protection of medical information have become the focus of global attention. Medical information data contains sensitive data such as patients' personal information, diagnosis information, treatment records, and drug usage. If this information is illegally accessed or tampered with, it will have a serious impact on patient privacy and the reputation of medical institutions. Therefore, how to improve encryption efficiency and ensure the transparency and credibility of the data processing process while protecting the security, integrity and privacy of medical information data has become an urgent problem to be solved.

[0003] In the existing technology, traditional medical information data protection methods mainly rely on static encryption technology and access control mechanisms. These methods have the following obvious defects in the face of increasingly complex medical data environments and evolving security threats:

[0004] 1. Single encryption technology: Traditional methods usually use a single encryption technology to uniformly process all medical information data. It is difficult to dynamically adjust the encryption strategy according to the sensitivity and type of the data, resulting in low encryption efficiency and inability to fully protect highly sensitive data.

[0005] 2. Insufficient privacy protection: In traditional methods, there is a lack of effective privacy protection measures before data encryption, such as data anonymization and desensitization. As a result, even after the data is encrypted, once the key is leaked, the patient's privacy information may still be directly obtained.

[0006] 3. Lack of intelligent encryption strategies: Traditional encryption methods rely on fixed rules and preset strategies. They are unable to perform intelligent encryption based on the actual situation of medical information data and are difficult to adapt to data requirements of different types and sensitivities, resulting in a lack of flexibility and efficiency in the encryption process.

[0007] 4. Insufficient auditing and transparency: The data processing process in existing technologies usually lacks transparency and traceability, and it is difficult to provide complete operation logs and tamper-proof audit records, resulting in insufficient credibility of the data processing process.

[0008] 5. Lack of data transmission security: During the data transmission process, traditional methods usually rely on basic transmission encryption technology, which is difficult to fully guarantee the confidentiality and integrity of data and is vulnerable to the threat of data theft and tampering.

[0009] Therefore, how to provide an intelligent encryption method for medical information data based on digital signatures is an urgent problem that technicians in this field need to solve. Summary of the invention

[0010] One purpose of the present invention is to propose a medical information data intelligent encryption method based on digital signature. The present invention combines digital signature technology, symmetric encryption and asymmetric encryption technology, support vector machine algorithm, data anonymization and desensitization technology and blockchain technology, and describes in detail the process of realizing medical information data security protection and intelligent encryption. It has the advantages of high security, high intelligence, comprehensive privacy protection and transparent data processing.

[0011] A medical information data intelligent encryption method based on digital signature according to an embodiment of the present invention comprises the following steps:

[0012] S1. Obtain medical information data;

[0013] S2, using public key infrastructure and hash functions to generate digital signatures for medical information data;

[0014] S3. Anonymize and desensitize medical information data and remove sensitive information through privacy protection technology;

[0015] S4, introduce machine learning algorithms and rule-based encryption strategies, dynamically analyze the type, sensitivity and user behavior of medical information data, and intelligently select encryption algorithms;

[0016] S5. Use a combination of symmetric encryption and asymmetric encryption to quickly encrypt large amounts of medical information data, and use asymmetric encryption to encrypt symmetric keys;

[0017] S6. Securely store and transmit the encrypted medical information data and encrypted symmetric keys, and use blockchain technology to record the signature and encryption process of the medical information data, provide tamper-proof audit records, and improve the transparency and credibility of the data processing process through distributed ledger technology.

[0018] Optionally, the S1 specifically includes:

[0019] S11. Obtain the electronic medical record data of the patient from the database of the medical institution, pre-process the obtained electronic medical record data, remove redundant data and format the data, classify the pre-processed electronic medical record data according to data type and sensitivity, and extract feature information for each data category;

[0020] S12. Based on the extracted feature information, construct a data description matrix D:

[0021] D={d ij};

[0022] Among them, d ij Represents the j-th eigenvalue of the i-th category data;

[0023] S13. Analyze the data description matrix D to determine the sensitivity level S of each type of data i :

[0024]

[0025] Among them, w j is the weight of the jth feature, and n is the total number of features;

[0026] S14, according to the sensitivity level S i and the pre-set encryption strategy to generate a data encryption priority list P, where P = {p 1 ,p 2 ,…,p m}, p i is the encryption priority of the i-th category of data, and m is the total number of data categories;

[0027] S15. Pass the data encryption priority list P to the subsequent intelligent encryption module as a basis for encryption algorithm selection and execution.

[0028] Optionally, the S2 specifically includes:

[0029] S21. Use public key infrastructure to obtain the public key K of medical information data pub and private key K pri ;

[0030] S22, perform hash processing on the medical information data M to generate a hash value H(M):

[0031]

[0032] Among them, H(M) is the hash value, h i (m i ) represents the result of hash calculation on the i-th part of the medical information data. Represents a bitwise exclusive OR operation;

[0033] S23. Use private key K pri Digitally sign the hash value H(M) to generate a digital signature S:

[0034]

[0035] Where S is the digital signature and N is the modulus in the RSA algorithm;

[0036] S24, attaching the generated digital signature S to the medical information data M to form medical information data (M, S) with a digital signature;

[0037] S25. Before transmitting and storing medical information data with digital signatures, the recipient uses the public key K pub To verify the signature:

[0038]

[0039] Where H'(M) is the hash value recovered from the signature;

[0040] S26. Compare the verified hash value H'(M) with the hash value H(M) obtained by hashing the received medical information data M. If H'(M) = H(M), the signature verification is successful and the data has not been tampered with. If the signature verification is successful, the medical information data (M, S) with the digital signature will be securely stored or transmitted.

[0041] Optionally, the S3 specifically includes:

[0042] S31, pre-process the medical information data M, split the data by field, and obtain multiple data segments {m 1 ,m 2 ,…,m n}, where n is the number of data segments;

[0043] S32, for each data segment m i Perform data anonymization to remove and replace sensitive information that directly identifies the patient's identity, and obtain the anonymized data segment {m' 1 ,m' 2 ,…,m' n}:

[0044] m' i =m i -I i ;

[0045] Among them, I i Indicates data segment m i Directly identifiable information in

[0046] S33, anonymized data segment m' i Perform data desensitization to further hide sensitive information in the data by masking, transforming and randomizing, and obtain the desensitized data segment {m″ 1 ,m″ 2 ,…,m″ n}:

[0047] m″ i =(m′i +r i )modk;

[0048] Among them, r i is random noise, modk is modular operation, and k is a predetermined desensitization factor;

[0049] S34. Based on the sensitive information identification algorithm, calculate the sensitivity score s of each data segment i :

[0050] s i =α·I i +β·C i +γ·E i ;

[0051] Among them, I i For data segment m″ i The amount of directly identifying information contained in C i is the amount of indirect identification information contained in the data segment, E i is the amount of sensitive medical information contained in the data segment, α, β and γ are the corresponding weight coefficients;

[0052] S35. Combine the desensitized data segments and the sensitivity scores to form a desensitized data matrix D m And the sensitivity score matrix D s ,in:

[0053] D m ={m″ 1 ,m″ 2 ,…,m″ n};

[0054] D s ={s 1 ,s 2 ,…,s n};

[0055] S36. Desensitized data matrix D m Integrate and restore the desensitized data M″ in the original data structure, and convert the sensitivity score matrix D s Passed to the subsequent encryption module for encryption strategy formulation:

[0056]

[0057] S37. During the entire data anonymization and desensitization process, the log information of each operation step is recorded to form a complete operation record.

[0058] Optionally, the S4 specifically includes:

[0059] S41. Use the support vector machine algorithm to analyze the preprocessed medical information data and extract the data feature vector:

[0060] F={f 1 ,f 2 ,…,f m};

[0061] Among them, f i represents the i-th feature of the data, and m is the number of features;

[0062] S42, Rule-based encryption policy library Define encryption rules for data of different types and sensitivities

[0063] S43, input the extracted feature vector F into the support vector machine model, and calculate the encryption priority P of each data segment = {p 1 ,p 2 ,…,p n}, where p i is the encryption priority of the i-th data segment:

[0064]

[0065] Among them, w is the weight vector, f i is the feature vector of the ith data segment, b is the bias term, It is a logistic regression activation function that maps the score to (0,1);

[0066] S44, according to the calculated encryption priority P, from the rule base Select the appropriate encryption rule And assign corresponding encryption algorithms and parameters to each data segment;

[0067] S45. For each data segment m i Apply the selected encryption algorithm A i To encrypt:

[0068] c i =A i (m i ,k i );

[0069] Among them, c i is the encrypted data segment, A i is the selected encryption algorithm, k i is the corresponding encryption key;

[0070] S46, all the encrypted data segments {c 1 ,c 2 ,…,cn}Combined into encrypted medical information data C:

[0071] C={c 1 ,c 2 ,…,c n};

[0072] S47. During the encryption process, the encryption algorithm selection and encryption process of each data segment are recorded to form a complete operation log.

[0073] Optionally, the S5 specifically includes:

[0074] S51, symmetric encryption of medical information data M using symmetric encryption algorithm A s and the symmetric key K s To encrypt data:

[0075] C s =A s (M,K s );

[0076] Among them, C s is the symmetrically encrypted data, A s is a symmetric encryption algorithm, K s is a symmetric key;

[0077] S52, generate a symmetric key K for encryption s An asymmetric key pair, including the public key K pub and private key K pri ;

[0078] S53, using asymmetric encryption algorithm A a and the public key K pub For the symmetric key K s To encrypt:

[0079] C a =A a (K s ,K pub );

[0080] Among them, C a is the symmetric key after asymmetric encryption, A a It is an asymmetric encryption algorithm;

[0081] S54, the symmetrically encrypted data C s and the asymmetrically encrypted symmetric key C a Combined into the final encrypted data packet P:

[0082] P={C s ,C a};

[0083] S55, when storing or transmitting the final encrypted data packet P, record the operation log of each step;

[0084] S56. During the data decryption process, the receiver uses the private key K pri The encrypted symmetric key C a Decrypt and recover the symmetric key K s :

[0085]

[0086] in, It is an asymmetric decryption algorithm;

[0087] S57, use the recovered symmetric key K s and symmetric decryption algorithm For encrypted data C s Decrypt and restore the original medical information data M:

[0088]

[0089] in, It is a symmetric decryption algorithm.

[0090] Optionally, the S6 specifically includes:

[0091] S61, storing the encrypted medical information data P, using distributed database technology to store the data slices on multiple storage nodes, each data slice P i Includes encrypted data segment C s and encryption key segment C a :

[0092]

[0093] Among them, P i is the data shard of the i-th storage node, and are the encrypted data and encryption key of the i-th data segment respectively;

[0094] S62. Use blockchain technology to record the storage and access operations of each data shard, and record each operation as a block in the blockchain:

[0095] B k = {O k ,H(B k-1 ),T k};

[0096] Among them, B k is the kth block, O kTo store or access detailed information of the operation, H(B k-1 ) is the hash value of the previous block, T k The timestamp of the operation;

[0097] S63. During data storage and access, the data is encrypted using the transport layer security protocol;

[0098] S64. Fine-grained control of data access rights through access control lists and role-based access control mechanisms:

[0099]

[0100] Where A(u,r) is the access right of user u to role r, 1 means access is allowed, 0 means access is denied;

[0101] S65. During the data access and operation process, a detailed log of each access and operation is recorded. The log record format is as follows:

[0102] L i = {U i ,O i ,T i};

[0103] Among them, L i is the i-th log record, U i is the user ID, O i is the operation type, T i is the operation time;

[0104] S66. Audit and back up the stored data and operation logs regularly. The audit and backup process is as follows:

[0105]

[0106] Where A(t) is the audit record at time t, H(L i ) is the hash value of the i-th log record.

[0107] The beneficial effects of the present invention are:

[0108] (1) The present invention combines digital signature technology, symmetric encryption and asymmetric encryption technology to ensure the integrity, authenticity and confidentiality of medical information data during transmission and storage. Digital signature technology generates digital signatures of medical information data through public key infrastructure and hash functions, effectively preventing data tampering and forgery, and improving data security.

[0109] (2) The present invention introduces support vector machine algorithm and rule-based encryption strategy, dynamically analyzes the type, sensitivity and user behavior of medical information data, intelligently selects the most suitable encryption algorithm, and improves encryption efficiency and security. The application of intelligent encryption strategy enables the system to flexibly adjust the encryption scheme according to the actual needs of different data, thereby achieving efficient encryption processing.

[0110] (3) The present invention uses data anonymization and desensitization technology to process medical information data before encryption, and further protects patient privacy by removing or hiding sensitive information, reducing the risk of data leakage. Data anonymization and desensitization technology ensures that even if the data is illegally obtained, sensitive information will not be directly identified, effectively protecting data privacy.

[0111] (4) The present invention uses blockchain technology to record the storage and access operations of medical information data, and records each operation as a block in the blockchain, providing an audit record that cannot be tampered with. The application of blockchain technology improves the transparency and credibility of the data processing process and ensures the security and traceability of data storage and access.

[0112] (5) The present invention uses the transport layer security protocol to encrypt data during data storage and transmission, ensuring the confidentiality and integrity of the data during transmission and preventing the data from being stolen or tampered with during transmission. The application of the transport layer security protocol provides a secure transmission environment and ensures the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0113] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0114] Figure 1 A flowchart of a medical information data intelligent encryption method based on digital signature proposed by the present invention;

[0115] Figure 2 A flowchart of intelligent encryption strategy selection for an intelligent encryption method for medical information data based on digital signature proposed by the present invention;

[0116] Figure 3 A schematic diagram of the encrypted data packet generation process of a medical information data intelligent encryption method based on digital signature proposed by the present invention;

[0117] Figure 4 The schematic diagram of data storage and access control proposed for the present invention shows how to record operations using distributed database and blockchain technology. DETAILED DESCRIPTION

[0118] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.

[0119] refer to Figure 1-Figure 4 , a medical information data intelligent encryption method based on digital signature, comprising the following steps:

[0120] S1. Obtain medical information data;

[0121] In this implementation, S1 specifically includes:

[0122] S11. Obtain the electronic medical record data of the patient from the database of the medical institution, pre-process the obtained electronic medical record data, remove redundant data and format the data, classify the pre-processed electronic medical record data according to data type and sensitivity, and extract feature information for each data category;

[0123] S12. Based on the extracted feature information, construct a data description matrix D:

[0124] D={d ij};

[0125] Among them, d ij Represents the jth eigenvalue of the i-th category data;

[0126] S13. Analyze the data description matrix D to determine the sensitivity level S of each type of data i :

[0127]

[0128] Among them, w j is the weight of the jth feature, and n is the total number of features;

[0129] S14, according to the sensitivity level S i and the pre-set encryption strategy to generate a data encryption priority list P, where P = {p 1 ,p 2 ,…,p m}, p i is the encryption priority of the i-th category of data, and m is the total number of data categories;

[0130] S15. Pass the data encryption priority list P to the subsequent intelligent encryption module as a basis for encryption algorithm selection and execution.

[0131] S2, using public key infrastructure and hash functions to generate digital signatures for medical information data;

[0132] In this implementation, S2 specifically includes:

[0133] S21. Use public key infrastructure to obtain the public key K of medical information data pub and private key K pri ;

[0134] S22, perform hash processing on the medical information data M to generate a hash value H(M):

[0135]

[0136] Among them, H(M) is the hash value, h i (m i ) represents the result of hash calculation on the i-th part of the medical information data. Represents a bitwise exclusive OR operation;

[0137] S23. Use private key K pri Digitally sign the hash value H(M) to generate a digital signature S:

[0138]

[0139] Where S is the digital signature and N is the modulus in the RSA algorithm;

[0140] S24, attaching the generated digital signature S to the medical information data M to form medical information data (M, S) with a digital signature;

[0141] S25. Before transmitting and storing medical information data with digital signatures, the recipient uses the public key K pub To verify the signature:

[0142]

[0143] Where H'(M) is the hash value recovered from the signature;

[0144] S26. Compare the verified hash value H'(M) with the hash value H(M) obtained by hashing the received medical information data M. If H'(M) = H(M), the signature verification is successful and the data has not been tampered with. If the signature verification is successful, the medical information data (M, S) with the digital signature will be securely stored or transmitted.

[0145] S3. Anonymize and desensitize medical information data and remove sensitive information through privacy protection technology;

[0146] In this implementation, S3 specifically includes:

[0147] S31, pre-process the medical information data M, split the data by field, and obtain multiple data segments {m1 ,m 2 ,…,m n}, where n is the number of data segments;

[0148] S32, for each data segment m i Perform data anonymization to remove and replace sensitive information that directly identifies the patient's identity, and obtain the anonymized data segment {m' 1 ,m' 2 ,…,m' n}:

[0149] m' i =m i -I i ;

[0150] Among them, I i Indicates data segment m i Directly identifiable information in

[0151] S33, anonymized data segment m' i Perform data desensitization to further hide sensitive information in the data by masking, transforming and randomizing, and obtain the desensitized data segment {m″ 1 ,m″ 2 ,…,m″ n}:

[0152] m″ i =(m′ i +r i )modk;

[0153] Among them, ri 为 Random noise, modk is the modular operation, k is the predetermined desensitization factor;

[0154] S34. Based on the sensitive information identification algorithm, calculate the sensitivity score s of each data segment i :

[0155] s i =α·I i +β·C i +γ·E i ;

[0156] Among them, I i For data segment m″ i The amount of directly identifying information contained in C i is the amount of indirect identification information contained in the data segment, E i is the amount of sensitive medical information contained in the data segment, α, β and γ are the corresponding weight coefficients;

[0157] S35. Combine the desensitized data segments and the sensitivity scores to form a desensitized data matrix D m And the sensitivity score matrix D s ,in:

[0158] D m ={m″ 1 ,m″ 2 ,…,m″ n};

[0159] D s ={s 1 ,s 2 ,…,s n};

[0160] S36. Desensitized data matrix D m Integrate and restore the desensitized data M″ in the original data structure, and convert the sensitivity score matrix D s Passed to the subsequent encryption module for encryption strategy formulation:

[0161]

[0162] S37. During the entire data anonymization and desensitization process, the log information of each operation step is recorded to form a complete operation record.

[0163] S4, introduce machine learning algorithms and rule-based encryption strategies, dynamically analyze the type, sensitivity and user behavior of medical information data, and intelligently select encryption algorithms;

[0164] In this implementation, S4 specifically includes:

[0165] S41. Use the support vector machine algorithm to analyze the preprocessed medical information data and extract the data feature vector:

[0166] F={f 1 ,f 2 ,…,f m};

[0167] Among them, f i Represents the i-th feature of the data, and m is the number of features;

[0168] S42, Rule-based encryption policy library Define encryption rules for data of different types and sensitivities

[0169] S43, input the extracted feature vector F into the support vector machine model, and calculate the encryption priority P of each data segment = {p 1 ,p 2 ,…,p n}, where p i is the encryption priority of the i-th data segment:

[0170]

[0171] Among them, w is the weight vector, f i is the feature vector of the ith data segment, b is the bias term, It is a logistic regression activation function that maps the score to (0,1);

[0172] S44, according to the calculated encryption priority P, from the rule base Select the appropriate encryption rule And assign corresponding encryption algorithms and parameters to each data segment;

[0173] S45. For each data segment m i Apply the selected encryption algorithm A i To encrypt:

[0174] c i =A i (m i ,k i );

[0175] Among them, c i is the encrypted data segment, A i is the selected encryption algorithm, k i is the corresponding encryption key;

[0176] S46, all the encrypted data segments {c 1 ,c 2 ,…,c n}Combined into encrypted medical information data C:

[0177] C={c 1 ,c 2 ,…,c n};

[0178] S47. During the encryption process, the encryption algorithm selection and encryption process of each data segment are recorded to form a complete operation log.

[0179] S5. Use a combination of symmetric encryption and asymmetric encryption to quickly encrypt large amounts of medical information data, and use asymmetric encryption to encrypt symmetric keys;

[0180] In this implementation, S5 specifically includes:

[0181] S51, symmetric encryption of medical information data M using symmetric encryption algorithm A s and the symmetric key K sTo encrypt data:

[0182] C s =A s (M,K s );

[0183] Among them, C s is the symmetrically encrypted data, A s is a symmetric encryption algorithm, K s is a symmetric key;

[0184] S52, generate a symmetric key K for encryption s An asymmetric key pair, including the public key K pub and private key K pri ;

[0185] S53, using asymmetric encryption algorithm A a and the public key K pub For the symmetric key K s To encrypt:

[0186] C a =A a (K s ,K pub );

[0187] Among them, C a is the symmetric key after asymmetric encryption, A a It is an asymmetric encryption algorithm;

[0188] S54, the symmetrically encrypted data C s and the asymmetrically encrypted symmetric key C a Combined into the final encrypted data packet P:

[0189] P={C s ,C a};

[0190] S55, when storing or transmitting the final encrypted data packet P, record the operation log of each step;

[0191] S56. During the data decryption process, the receiver uses the private key K pri The encrypted symmetric key C a Decrypt and recover the symmetric key K s :

[0192]

[0193] in, It is an asymmetric decryption algorithm;

[0194] S57, use the recovered symmetric key K sand symmetric decryption algorithm For encrypted data C s Decrypt and restore the original medical information data M:

[0195]

[0196] in, It is a symmetric decryption algorithm.

[0197] S6. Securely store and transmit the encrypted medical information data and encrypted symmetric keys, and use blockchain technology to record the signature and encryption process of the medical information data, provide tamper-proof audit records, and improve the transparency and credibility of the data processing process through distributed ledger technology.

[0198] In this implementation, S6 specifically includes:

[0199] S61, the encrypted medical information data p is stored, and the data is fragmented and stored on multiple storage nodes using distributed database technology, and each data fragment P i Includes encrypted data segment C s and encryption key segment C a :

[0200]

[0201] Among them, P i is the data shard of the i-th storage node, and are the encrypted data and encryption key of the i-th data segment respectively;

[0202] S62. Use blockchain technology to record the storage and access operations of each data shard, and record each operation as a block in the blockchain:

[0203] B k = {O k ,H(B k-1 ),T k};

[0204] Among them, B k is the kth block, O k To store or access detailed information of the operation, H(B k-1 ) is the hash value of the previous block, T k The timestamp of the operation;

[0205] S63. During data storage and access, the data is encrypted using the transport layer security protocol;

[0206] S64. Fine-grained control of data access rights through access control lists and role-based access control mechanisms:

[0207]

[0208] Where A(u,r) is the access right of user u to role r, 1 means access is allowed, 0 means access is denied;

[0209] S65. During the data access and operation process, a detailed log of each access and operation is recorded. The log record format is as follows:

[0210] L i = {U i ,O i ,T i};

[0211] Among them, L i is the i-th log record, U i is the user ID, O i is the operation type, T i is the operation time;

[0212] S66. Audit and back up the stored data and operation logs regularly. The audit and backup process is as follows:

[0213]

[0214] Where A(t) is the audit record at time t, H(L i ) is the hash value of the i-th log record.

[0215] Embodiment 1:

[0216] In order to verify the feasibility and superiority of the present invention, we applied the present invention to the data management system of a large medical institution. The medical institution processes a large amount of medical information of patients every day, including medical records, diagnoses, treatment records, and drug usage. Due to the high sensitivity and privacy of these data, ensuring the security, integrity, and privacy protection of the data has become the top priority of the medical institution. The existing traditional encryption and access control methods are incapable of coping with complex security threats, and the risks of data leakage and illegal access still exist.

[0217] In this scenario, we applied the medical information data intelligent encryption method based on digital signature proposed in this invention, aiming to improve the security, intelligence level and processing efficiency of data protection. The specific implementation steps are as follows:

[0218] First, the electronic medical record data of medical institutions is obtained and preprocessed, including cleaning redundant data and formatting data. Then, a digital signature of the medical information data is generated using public key infrastructure and hash functions to ensure the integrity and authenticity of the data. Next, the data is anonymized and desensitized to protect patient privacy by removing or hiding directly identifying information.

[0219] After data preprocessing is completed, the support vector machine algorithm is used to analyze the data, extract data feature vectors, and intelligently select the appropriate encryption algorithm based on the rule-based encryption strategy library. The combined use of symmetric encryption and asymmetric encryption ensures the confidentiality of data transmission and storage. The encrypted data and keys are sharded and stored on multiple distributed database nodes. Blockchain technology is used to record the storage and access operations of each data shard, provide tamper-proof audit records, and ensure the transparency and credibility of data processing.

[0220] During data transmission, the transport layer security protocol is used for transmission encryption, and a fine-grained access control mechanism is used to ensure that only authorized users can access and operate encrypted data. All data access and operations are recorded in detail, including user identification, operation type and operation time, forming a complete operation log. The stored data and operation logs are audited and backed up regularly to ensure data security and traceability.

[0221] In order to verify the effect of the present invention, we conducted a six-month pilot operation in the medical institution and recorded various data. The specific results are as follows:

[0222] Table 1: Comparison of step count before and after

[0223] Data Category Before deploying the system After deploying the system Number of security incidents per month 12 times 1 time Real-time monitoring effect - 7 times Support vector machine algorithm effect - 15 times Accuracy 83.5% 97.8% False Positive Rate 4.5% 1.2% Response time 22 minutes 5 minutes Data Breach Prevention - Significantly reduced

[0224] It can be seen from the above data that the present invention significantly improves the security, privacy protection and processing efficiency of medical information data in practical applications. In particular, in terms of preventing data leakage and illegal access, the present invention demonstrates its excellent performance and effectively protects the privacy of patients and the confidentiality of data. The multiple innovative technical means of the present invention provide a comprehensive and efficient solution for the intelligent encryption and protection of medical data.

[0225] In practical application, the process of the present invention includes:

[0226] The electronic medical record data is obtained and pre-processed, such as removing redundancy and formatting data. Then, a public key infrastructure and hash function are used to generate a digital signature of the data to ensure the integrity and authenticity of the data. Next, the data is anonymized and desensitized to remove direct identifying information to protect patient privacy.

[0227] After preprocessing, the support vector machine algorithm is used to extract features from the data, and the appropriate encryption algorithm is intelligently selected based on the encryption policy library of the rules. The data is encrypted using a combination of symmetric and asymmetric encryption, and the encrypted data and key shards are stored on multiple distributed database nodes. Blockchain technology is used to record the storage and access operations of each data shard, providing an unalterable audit record to ensure the transparency and credibility of data processing.

[0228] During data transmission, the transport layer security protocol is used for encryption to ensure the security of data transmission. Through a fine-grained access control mechanism, it is ensured that only authorized users can access and operate encrypted data. All data access and operations will be recorded in detail, including user identification, operation type and operation time, forming a complete operation log. The stored data and operation logs are audited and backed up regularly to ensure data security and traceability.

[0229] The above embodiments show that the present invention significantly improves the security, privacy protection and processing efficiency of medical information data in practical applications, especially in preventing data leakage and illegal access. The multiple innovative technical means of the present invention provide a comprehensive and efficient solution for the intelligent encryption and protection of medical data.

[0230] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.

Claims

1. A medical information data intelligent encryption method based on digital signature, comprising the following steps: S1. Obtain medical information data; S2, using public key infrastructure and hash functions to generate digital signatures for medical information data; S3. Anonymize and desensitize medical information data and remove sensitive information through privacy protection technology; S4, introduce machine learning algorithms and rule-based encryption strategies, dynamically analyze the type, sensitivity and user behavior of medical information data, and intelligently select encryption algorithms; S5. Use a combination of symmetric encryption and asymmetric encryption to quickly encrypt large amounts of medical information data, and use asymmetric encryption to encrypt symmetric keys; S6. Securely store and transmit the encrypted medical information data and the encrypted symmetric key, and use blockchain technology to record the signature and encryption process of the medical information data, provide tamper-proof audit records, and improve the transparency and credibility of the data processing process through distributed ledger technology; The S4 specifically includes: S41. Use the support vector machine algorithm to analyze the preprocessed medical information data and extract the data feature vector: F={f1,f2,…,f m }; Among them, f i represents the i-th feature of the data, and m is the number of features; S42, Rule-based encryption policy library Define encryption rules for data of different types and sensitivities S43, input the extracted feature vector F into the support vector machine model, and calculate the encryption priority P of each data segment = {p1, p2, ..., p n }, where p i is the encryption priority of the i-th data segment: Among them, w is the weight vector, f i is the feature vector of the ith data segment, b is the bias term, It is a logistic regression activation function that maps the score to between (0,1); S44, according to the calculated encryption priority P, from the rule base Select the appropriate encryption rule And assign corresponding encryption algorithms and parameters to each data segment; S45. For each data segment m i Apply the selected encryption algorithm A i To encrypt: c i =A i (m i ,k i ); Among them, c i is the encrypted data segment, A i is the selected encryption algorithm, k i is the corresponding encryption key; S46, all the encrypted data segments {c1, c2, ..., c n }Combined into encrypted medical information data C: C={c1,c2,…,c n }; S47. During the encryption process, the encryption algorithm selection and encryption process of each data segment are recorded to form a complete operation log.

2. According to claim 1, a medical information data intelligent encryption method based on digital signature is characterized in that: The S1 specifically includes: S11. Obtain the electronic medical record data of the patient from the database of the medical institution, pre-process the obtained electronic medical record data, remove redundant data and format the data, classify the pre-processed electronic medical record data according to data type and sensitivity, and extract feature information for each data category; S12. Based on the extracted feature information, construct a data description matrix D: D={d ij }; Among them, d ij Represents the jth eigenvalue of the i-th category data; S13. Analyze the data description matrix D to determine the sensitivity level S of each type of data i : Among them, w j is the weight of the jth feature, and n is the total number of features; S14, according to the sensitivity level S i and the pre-set encryption strategy to generate a data encryption priority list P, where P = {p1, p2, ..., p m }, p i is the encryption priority of the i-th category of data, and m is the total number of data categories; S15. Pass the data encryption priority list P to the subsequent intelligent encryption module as a basis for encryption algorithm selection and execution.

3. According to claim 2, a medical information data intelligent encryption method based on digital signature is characterized in that: The S2 specifically includes: S21. Use public key infrastructure to obtain the public key K of medical information data pub and private key K pri ; S22, perform hash processing on the medical information data M to generate a hash value H(M): Among them, H(M) is the hash value, h i (m i ) represents the result of hash calculation on the i-th part of the medical information data. Represents a bitwise exclusive OR operation; S23. Use private key K pri Digitally sign the hash value H(M) to generate a digital signature S: Where S is the digital signature and N is the modulus in the RSA algorithm; S24, attaching the generated digital signature S to the medical information data M to form medical information data (M, S) with a digital signature; S25. Before transmitting and storing medical information data with digital signatures, the recipient uses the public key K pub To verify the signature: Where H'(M) is the hash value recovered from the signature; S26. Compare the verified hash value H'(M) with the hash value H(M) obtained by hashing the received medical information data M. If H'(M) = H(M), the signature verification is successful and the data has not been tampered with. If the signature verification is successful, the medical information data (M, S) with the digital signature will be securely stored or transmitted.

4. According to claim 3, a medical information data intelligent encryption method based on digital signature is characterized in that: The S3 specifically includes: S31, pre-process the medical information data M, split the data by field, and obtain multiple data segments {m1, m2, ..., m n }, where n is the number of data segments; S32, for each data segment m i Perform data anonymization, remove and replace sensitive information that directly identifies the patient, and obtain the anonymized data segment {m'1,m'2,…,m' n }: m' i =m i -I i ; Among them, I i Indicates data segment m i Directly identifiable information in S33, anonymized data segment m' i Perform data desensitization to further hide sensitive information in the data by masking, transforming and randomizing, and obtain the desensitized data segment {m″1,m″2,…,m″ n }: m″ i =(m′ i +r i )modk; Among them, r i is random noise, mod is modular operation, and k is a predetermined desensitization factor; S34. Based on the sensitive information identification algorithm, calculate the sensitivity score s of each data segment i : s i =α·I i +β·C i +γ·E i ; Among them, I i For data segment m″ i The amount of directly identifying information contained in C i is the amount of indirect identification information contained in the data segment, E i is the amount of sensitive medical information contained in the data segment, α, β and γ are the corresponding weight coefficients; S35. Combine the desensitized data segments and the sensitivity scores to form a desensitized data matrix D m And the sensitivity score matrix D s ,in: D m ={m″1,m″2,…,m″ n }; D s ={s1,s2,…,s n }; S36. Desensitized data matrix D m Integrate and restore the desensitized data M″ in the original data structure, and convert the sensitivity score matrix D s Passed to the subsequent encryption module for encryption strategy formulation: S37. During the entire data anonymization and desensitization process, the log information of each operation step is recorded to form a complete operation record.

5. According to claim 4, a medical information data intelligent encryption method based on digital signature is characterized in that: The S5 specifically includes: S51, symmetric encryption of medical information data M using symmetric encryption algorithm A s and the symmetric key K s To encrypt data: C s =A s (M,K s ); Among them, C s is the symmetrically encrypted data, A s is a symmetric encryption algorithm, K s is a symmetric key; S52, generate a symmetric key K for encryption s An asymmetric key pair, including the public key K pub and private key K pri ; S53, using asymmetric encryption algorithm A a and the public key K pub For the symmetric key K s To encrypt: C a =A a (K s ,K pub ); Among them, C a is the symmetric key after asymmetric encryption, A a It is an asymmetric encryption algorithm; S54, the symmetrically encrypted data C s and the asymmetrically encrypted symmetric key C a Combined into the final encrypted data packet P: P={C s ,C a }; S55, when storing or transmitting the final encrypted data packet P, record the operation log of each step; S56. During the data decryption process, the receiver uses the private key K pri The encrypted symmetric key C a Decrypt and recover the symmetric key K s : in, It is an asymmetric decryption algorithm; S57, use the recovered symmetric key K s and symmetric decryption algorithm For encrypted data C s Decrypt and restore the original medical information data M: in, It is a symmetric decryption algorithm.

6. According to claim 5, a medical information data intelligent encryption method based on digital signature is characterized in that: The S6 specifically includes: S61, storing the encrypted medical information data P, using distributed database technology to store the data slices on multiple storage nodes, each data slice P i Includes encrypted data segment C s and encryption key segment C a : Among them, P i is the data shard of the i-th storage node, and are the encrypted data and encryption key of the i-th data segment respectively; S62. Use blockchain technology to record the storage and access operations of each data shard, and record each operation as a block in the blockchain: B k ={O k ,H(B k-1 ),T k }; Among them, B k is the kth block, O k To store or access detailed information of the operation, H(B k-1 ) is the hash value of the previous block, T k The timestamp of the operation; S63. During data storage and access, the data is encrypted using the transport layer security protocol; S64. Fine-grained control of data access rights through access control lists and role-based access control mechanisms: Where A(u,r) is the access right of user u to role r, 1 means access is allowed, 0 means access is denied; S65. During the data access and operation process, a detailed log of each access and operation is recorded. The log record format is as follows: L i ={U i ,O i ,T i }; Among them, L i is the i-th log record, U i is the user ID, O i is the operation type, T i is the operation time; S66. Audit and back up the stored data and operation logs regularly. The audit and backup process is as follows: Where A(t) is the audit record at time t, H(L i ) is the hash value of the i-th log record.

Citation Information

Patent Citations

  • Medical data sharing method based on block chain

    CN114979210A

  • File processing method and system based on digital information security

    CN118114301A