A medical data secure transmission method and system

By converting the AES key into a key matrix and updating the key elements before each round of encryption, the problem of low security of medical data transmission is solved, improving the security and stability of data transmission.

CN119449311BActive Publication Date: 2025-05-16BEIJING WANLIANDA XINKE INSTR CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510031138.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-16
Estimated Expiration
2045-01-09

AI Technical Summary

Technical Problem

In the prior art, medical data is relatively safe during transmission, and there is a risk of medical data leakage, especially the keys of the AES algorithm are easily cracked in reverse derivation.

Method used

By converting the AES key into a key matrix, and randomly updates the key elements in the key matrix before each round of encryption, forming the key matrix after i updates, and then encrypting.

Benefits of technology

It improves the security of medical data during transmission and reduces the risk of patient medical data being leaked. Even if a certain round of keys is intercepted, it is difficult to crack the initial key through reverse derivation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449311B_ABST
    Figure CN119449311B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for secure transmission of medical data, and relates to the field of data security technology. The method for secure transmission of medical data includes: converting an AES key into a key matrix; using each key element in the key matrix as a random seed, updating each key element in the key matrix i times through a random function, and obtaining an i-updated key matrix, wherein the initial value of i is 1, and i≤N, N represents the number of encryption rounds corresponding to AES encryption; performing the i-th round of encryption on the medical data through the i-th updated key matrix, so as to obtain the encrypted medical data after completing N rounds of encryption; and sending the encrypted medical data to a medical data storage server. The method and system for secure transmission of medical data disclosed in the present invention can improve the security of medical data during transmission, reduce the risk of leakage of patient medical data, and ensure data transmission security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data security, and in particular relates to a method and system for securely transmitting medical data. Background Art

[0002] With the development of medical informatization, the transmission and sharing of medical data has become increasingly important. For example, the transmission of test data from the 13C-urea breath test used to detect Helicobacter pylori (Hp) has become crucial. However, because medical data contains sensitive information such as patient personal information, diagnostic results, and treatment plans, its leakage or improper use can have serious consequences. Therefore, ensuring the secure transmission of medical data has become a major challenge for medical institutions.

[0003] Currently, the most commonly used method for secure transmission of medical data is encryption through the Advanced Encryption Standard (AES) algorithm. The standard AES algorithm encryption generally uses 10, 12, or 16 rounds of cyclic operations. Once the key of one round is intercepted, the initial key is at risk of being cracked through reverse deduction. The security of medical data transmission is low, and there is a risk of medical data leakage.

[0004] Therefore, how to provide an effective solution to improve the security of medical data during transmission has become a difficult problem that needs to be solved urgently in the existing technology. Summary of the Invention

[0005] The purpose of the present invention is to provide a method and system for securely transmitting medical data to solve the above-mentioned problems existing in the prior art.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] In a first aspect, the present invention provides a method for securely transmitting medical data, comprising:

[0008] Convert the AES key to a key matrix;

[0009] Using each key element in the key matrix as a random seed, update each key element in the key matrix i times using a random function to obtain a key matrix after i updates, where the initial value of i is 1, and i≤N, where N represents the number of encryption rounds corresponding to AES encryption;

[0010] Performing the i-th round of encryption on the medical data using the key matrix updated for the i-th time, so as to obtain the encrypted medical data after completing N rounds of encryption;

[0011] sending the encrypted medical data to a medical data storage server;

[0012] Using each key element in the key matrix as a random seed, updating each key element in the key matrix i times by a random function, including:

[0013] Based on the current timestamp, using each key element in the key matrix as a random seed, update each key element in the key matrix i times through a random function;

[0014] The random function is Knew=PRNG(Kold, Ti, h, j), where Knew represents the updated key element, Kold represents the key element before the update, PRNG represents a pseudo-random number generator, Ti represents the current timestamp, h represents the row index of the key element in the key matrix, and j represents the column index of the key element in the key matrix.

[0015] Based on the above-disclosed content, the present invention converts an AES key into a key matrix; using each key element in the key matrix as a random seed, updates each key element in the key matrix i times using a random function to obtain an updated key matrix i times, where the initial value of i is 1, and i≤N, where N represents the number of encryption rounds corresponding to AES encryption. Thus, before each round of encryption, each key element in the key matrix is ​​updated once, and then the medical data is encrypted for the i-th round using the i-th updated key matrix, so that after completing N rounds of encryption, encrypted medical data is obtained, and the encrypted medical data is sent to a medical data storage server. In this way, by improving the AES algorithm, each key element in the key matrix is ​​updated once before each round of encryption. Even if the key of one round is intercepted, it is difficult to decrypt it through reverse deduction to obtain the initial key, thereby improving the security of medical data during transmission, reducing the risk of patient medical data being leaked, and ensuring data transmission security.

[0016] In one possible design, sending the encrypted medical data to the medical data storage server includes:

[0017] Performing secondary encryption on the encrypted medical data using an asymmetric encryption algorithm to obtain secondary encrypted medical data;

[0018] The secondary encrypted medical data is sent to the medical data storage server.

[0019] In one possible design, before converting the AES key into a key matrix, the method further includes:

[0020] Encrypting the AES key using an asymmetric encryption algorithm to obtain an encrypted AES key;

[0021] The encrypted AES key is sent to the medical data storage server.

[0022] In one possible design, the asymmetric encryption algorithm is an elliptic curve algorithm.

[0023] In one possible design, the medical data is detection data from an isotope 13C urea breath test.

[0024] In a second aspect, the present invention provides a medical data secure transmission system, comprising:

[0025] A key conversion unit, used for converting an AES key into a key matrix;

[0026] an updating unit, configured to update each key element in the key matrix i times using a random function using each key element in the key matrix as a random seed, to obtain a key matrix updated i times, where an initial value of i is 1, and i≤N, where N represents the number of encryption rounds corresponding to AES encryption;

[0027] a round encryption unit, configured to perform an i-th round of encryption on the medical data using the key matrix updated for the i-th time, so as to obtain encrypted medical data after completing N rounds of encryption;

[0028] A sending unit, configured to send the encrypted medical data to a medical data storage server;

[0029] When the updating unit is used to update each key element in the key matrix i times by using a random function using each key element in the key matrix as a random seed, the updating unit is specifically used to:

[0030] Based on the current timestamp, using each key element in the key matrix as a random seed, update each key element in the key matrix i times through a random function;

[0031] The random function is Knew=PRNG(Kold, Ti, h, j), where Knew represents the updated key element, Kold represents the key element before the update, PRNG represents a pseudo-random number generator, Ti represents the current timestamp, h represents the row index of the key element in the key matrix, and j represents the column index of the key element in the key matrix.

[0032] In a third aspect, the present invention provides an electronic device comprising a memory, a processor and a transceiver that are communicatively connected in sequence, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the method for securely transmitting medical data as described in the first aspect or any possible design of the first aspect.

[0033] In a fourth aspect, the present invention provides a computer-readable storage medium having instructions stored thereon. When the instructions are run on a computer, the method for securely transmitting medical data according to the first aspect or any possible design of the first aspect is executed.

[0034] In a fifth aspect, the present invention provides a computer program product comprising instructions, which, when executed on a computer, causes the computer to execute the method for securely transmitting medical data as described in the first aspect or any possible design of the first aspect.

[0035] Beneficial effects:

[0036] The medical data security transmission method and system provided by the present invention can, by improving the AES algorithm, update each key element in the key matrix before each round of encryption. Even if the key of one round is intercepted, it is difficult to crack it through reverse deduction to obtain the initial key, thereby improving the security of medical data during transmission, reducing the risk of patient medical data being leaked, ensuring data transmission security, and facilitating practical application and promotion. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 A flowchart of a method for securely transmitting medical data provided in an embodiment of the present application;

[0038] Figure 2 A schematic block diagram of a medical data security transmission system provided in an embodiment of the present application;

[0039] Figure 3 A schematic block diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0040] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the present invention will be briefly introduced below in conjunction with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the structure of the drawings is only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention.

[0041] It should be understood that although the terms "first," "second," etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element can be referred to as a second element, and similarly, a second element can be referred to as a first element without departing from the scope of the exemplary embodiments of the present invention.

[0042] It should be understood that the term "and / or" that may appear in this document is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B may indicate three situations: A exists alone, B exists alone, and A and B exist at the same time. The term " / and" that may appear in this document describes another type of association object relationship, indicating that two relationships may exist. For example, A / and B may indicate two situations: A exists alone, and A and B exist alone. In addition, the character " / " that may appear in this document generally indicates that the previous and subsequent associated objects are in an "or" relationship.

[0043] In order to improve the security of medical data during transmission, the embodiments of the present application provide a method and system for secure transmission of medical data, which can improve the security of medical data during transmission and reduce the risk of leakage of patients' medical data.

[0044] The medical data security transmission method provided in the embodiment of the present application can be applied to a medical data collection terminal or a local terminal device of a hospital. It is understood that the execution subject does not constitute a limitation on the embodiment of the present application.

[0045] The following is a detailed description of the method for securely transmitting medical data provided in the embodiments of the present application.

[0046] like Figure 1 As shown, it is a flowchart of the medical data security transmission method provided in the first aspect of the embodiment of the present application, which is used for the secure transmission of medical data, such as the transmission of detection data in the isotope 13C urea breath test for Helicobacter pylori detection. The medical data security transmission method may include but is not limited to the following steps S101-S104.

[0047] Step S101: Convert the AES key into a key matrix.

[0048] The length of an AES key can be 128 bits, 192 bits, or 256 bits. After the AES key is converted into a key matrix, the key matrix can be a 4×4, 4×6, or 4×8 key matrix, and the length of each key element in the key matrix is ​​8 bits.

[0049] Step S102: Using each key element in the key matrix as a random seed, update each key element in the key matrix i times through a random function to obtain a key matrix updated i times.

[0050] Wherein, i is a positive integer, the initial value of i is 1, and i≤N, where N represents the number of encryption rounds corresponding to AES encryption.

[0051] In the general AES algorithm, encryption with a 128-bit AES key requires 10 rounds of calculations, i.e., the number of rounds is 10. Encryption with a 192-bit AES key requires 12 rounds of calculations, i.e., the number of rounds is 12. Encryption with a 256-bit AES key requires 16 rounds of calculations, i.e., the number of rounds is 16. Therefore, when the AES key length is 128 bits, the value of N can be 10, when the AES key length is 192 bits, the value of N can be 12, and when the AES key length is 256 bits, the value of N can be 16.

[0052] Specifically, when updating each key element in the key matrix, each key element in the initial key matrix can be used as a random seed, and each key element in the key matrix can be updated once using a random function to obtain a key matrix after the first update. Then, each key element in the key matrix after the first update can be used as a random seed, and each key element in the key matrix can be updated twice using a random function. Then, each key element in the key matrix after the second update can be used as a random seed, and each key element in the key matrix can be updated three times using a random function. This process can be deduced by analogy until each key element in the key matrix is ​​updated N times.

[0053] In one or more embodiments, when updating each key element in the key matrix through a random function, each key element in the key matrix can be updated i times through the random function based on the current timestamp and using each key element in the key matrix as a random seed.

[0054] In one or more embodiments, each key element in the key matrix may be updated i times using a random function in a pseudo-random number generator (PRNG). The random function can be expressed as Knew = PRNG(Kold, Ti, h, j), where Knew represents the updated key element, Kold represents the key element before the update, PRNG represents the pseudo-random number generator, Ti represents the current timestamp, h represents the row index of the key element in the key matrix, and j represents the column index of the key element in the key matrix. Updating elements using a random function of a pseudo-random number generator is a conventional technique and is not further described here.

[0055] It can be understood that when the key elements in the key matrix are updated through a random function, if it is based on the current timestamp, with the key elements in the key matrix as random seeds, and the key elements in the key matrix are updated i times through a random function, then when the medical data is subsequently sent to the medical data storage server, the timestamp when the key element is updated needs to be sent to the medical data storage server so that the medical data storage server can restore the data according to the timestamp when the key element is updated.

[0056] Step S103: Perform the i-th round of encryption on the medical data using the key matrix updated for the i-th time, so as to obtain the encrypted medical data after completing N rounds of encryption.

[0057] Among them, the process of each round of encryption is consistent with the cyclic operation process of the AES algorithm, and includes four processes: byte replacement (SubBytes), row shift (ShiftRows), column confusion (MixColumns) and round key addition (AddRoundKey). They will not be repeated in the embodiments of this application.

[0058] Step S104: Send the encrypted medical data to the medical data storage server.

[0059] In one or more embodiments, when encrypted medical data is sent to a medical data storage server, it can be re-encrypted using an asymmetric encryption algorithm to obtain the re-encrypted medical data, which is then sent to the medical data storage server. This allows for re-encryption of the medical data, further enhancing data security.

[0060] To ensure that the medical data storage server can decrypt the encrypted medical data it receives, in one or more embodiments, before converting the AES key into a key matrix, the AES key can be encrypted using an asymmetric encryption algorithm to obtain an encrypted AES key, which is then sent to the medical data storage server. In this way, the medical data storage server can decrypt the encrypted AES key using the asymmetric encryption algorithm to obtain the AES key, and then synchronize the AES key with the medical data storage server so that the medical data storage server can decrypt the encrypted medical data using the AES key upon receiving it.

[0061] The asymmetric encryption algorithm may be, but is not limited to, an elliptic curve algorithm (ECC), a RAS algorithm, etc., and is not specifically limited in the embodiments of the present application.

[0062] In summary, the present invention provides a method for securely transmitting medical data. This method converts an AES key into a key matrix; using each key element in the key matrix as a random seed, updates each key element in the key matrix i times using a random function to obtain an updated key matrix, where the initial value of i is 1, and i≤N, where N represents the number of encryption rounds corresponding to AES encryption. Thus, before each round of encryption, each key element in the key matrix is ​​updated. The medical data is then encrypted for the i-th round using the i-th updated key matrix, resulting in encrypted medical data after completing N rounds of encryption. The encrypted medical data is then sent to a medical data storage server. In this manner, by improving the AES algorithm, each key element in the key matrix is ​​updated before each round of encryption. Even if the key for a particular round is intercepted, it is difficult to decipher the initial key through reverse deduction. This improves the security of medical data during transmission, reduces the risk of patient medical data being leaked, ensures data transmission security, and facilitates practical application and promotion.

[0063] See also Figure 2 The present invention provides a medical data security transmission system for securely transmitting medical data, such as the transmission of detection data in an isotope 13C urea breath test for Helicobacter pylori detection. The medical data security transmission system includes:

[0064] A key conversion unit, used for converting an AES key into a key matrix;

[0065] an updating unit, configured to update each key element in the key matrix i times using a random function using each key element in the key matrix as a random seed, to obtain a key matrix updated i times, where an initial value of i is 1, and i≤N, where N represents the number of encryption rounds corresponding to AES encryption;

[0066] a round encryption unit, configured to perform an i-th round of encryption on the medical data using the key matrix updated for the i-th time, so as to obtain encrypted medical data after completing N rounds of encryption;

[0067] The sending unit is used to send the encrypted medical data to the medical data storage server.

[0068] The medical data security transmission system provided in the second aspect of this embodiment can improve the AES algorithm and update each key element in the key matrix before each round of encryption. Even if the key of one round is intercepted, it is difficult to crack it through reverse deduction to obtain the initial key, thereby improving the security of medical data during transmission, reducing the risk of leakage of patients' medical data, ensuring data transmission security, and facilitating practical application and promotion.

[0069] like Figure 3 As shown, the third aspect of an embodiment of the present application provides an electronic device, comprising a memory, a processor and a transceiver that are communicatively connected in sequence, wherein the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the medical data security transmission method as described in the first aspect of the embodiment.

[0070] For example, the memory may include, but is not limited to, random access memory (RAM), read-only memory (ROM), flash memory, first-in-first-out memory (FIFO) and / or first-in-last-out memory (FILO), etc.; the processor may include, but is not limited to, a microprocessor of the STM32F105 series, an ARM (Advanced RISC Machines), an X86 or other architecture processor, or a processor with an integrated NPU (neural-network processing units); the transceiver may include, but is not limited to, a WiFi (Wireless Fidelity) wireless transceiver, a Bluetooth wireless transceiver, a General Packet Radio Service (GPRS) wireless transceiver, a ZigBee protocol (a low-power local area network protocol based on the IEEE802.15.4 standard, ZigBee) wireless transceiver, a 3G transceiver, a 4G transceiver and / or a 5G transceiver, etc.

[0071] A fourth aspect of this embodiment provides a computer-readable storage medium storing instructions containing the method for securely transmitting medical data described in the first aspect of this embodiment. Specifically, the computer-readable storage medium stores instructions that, when executed on a computer, execute the method for securely transmitting medical data described in the first aspect. The computer-readable storage medium refers to a data storage medium, which may include, but is not limited to, a floppy disk, an optical disk, a hard disk, a flash memory, a USB flash drive, and / or a memory stick. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable device.

[0072] The fifth aspect of this embodiment provides a computer program product containing instructions, which, when executed on a computer, enables the computer to execute the medical data secure transmission method as described in the first aspect of the embodiment, wherein the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0073] It should be understood that certain details are provided in the following description to facilitate a thorough understanding of the example embodiments. However, one of ordinary skill in the art will appreciate that the example embodiments can be practiced without these specific details. For example, a system may be shown in block diagrams to avoid obscuring the example with unnecessary detail. In other instances, well-known processes, structures, and techniques may be shown without unnecessary detail to avoid obscuring the example embodiments.

[0074] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention shall be included in the scope of protection of the present invention.

Claims

1. A method for secure transmission of medical data, characterized in that: include: Convert AES key to key matrix; Using each key element in the key matrix as a random seed, updating each key element in the key matrix i times through a random function to obtain a key matrix after i updates, where the initial value of i is 1, and i≤N, N represents the number of encryption rounds corresponding to AES encryption; Performing an i-th round of encryption on the medical data using the key matrix updated for the i-th time, so as to obtain the encrypted medical data after completing N rounds of encryption; sending the encrypted medical data to a medical data storage server; Using each key element in the key matrix as a random seed, updating each key element in the key matrix i times by a random function, including: Based on the current timestamp, each key element in the key matrix is ​​used as a random seed, and each key element in the key matrix is ​​updated i times by a random function; The random function is Knew=PRNG(Kold, Ti, h, j), where Knew represents the updated key element, Kold represents the key element before updating, PRNG represents a pseudo-random number generator, Ti represents the current timestamp, h represents the row index of the key element in the key matrix, and j represents the column index of the key element in the key matrix.

2. The method for secure transmission of medical data according to claim 1, characterized in that: The step of sending the encrypted medical data to the medical data storage server comprises: The encrypted medical data is re-encrypted by using an asymmetric encryption algorithm to obtain the re-encrypted medical data; The twice-encrypted medical data is sent to the medical data storage server.

3. The method for secure transmission of medical data according to claim 1, characterized in that: Before converting the AES key into a key matrix, the method further comprises: Encrypting the AES key using an asymmetric encryption algorithm to obtain an encrypted AES key; The encrypted AES key is sent to the medical data storage server.

4. The method for securely transmitting medical data according to claim 2 or 3, characterized in that: The asymmetric encryption algorithm is an elliptic curve algorithm.

5. The method for secure transmission of medical data according to claim 1, characterized in that: The medical data is the detection data of the isotope 13C urea breath test.

6. A medical data security transmission system, characterized in that: include: A key conversion unit, used for converting an AES key into a key matrix; An updating unit, configured to use each key element in the key matrix as a random seed, and update each key element in the key matrix i times through a random function to obtain a key matrix updated i times, wherein an initial value of i is 1, and i≤N, where N represents the number of encryption rounds corresponding to AES encryption; A round encryption unit, used for performing an i-th round of encryption on the medical data using the key matrix updated for the i-th time, so as to obtain the encrypted medical data after completing N rounds of encryption; A sending unit, used to send the encrypted medical data to a medical data storage server; When the updating unit is used to update each key element in the key matrix i times by using a random function using each key element in the key matrix as a random seed, it is specifically used to: Based on the current timestamp, each key element in the key matrix is ​​used as a random seed, and each key element in the key matrix is ​​updated i times by a random function; The random function is Knew=PRNG(Kold, Ti, h, j), where Knew represents the updated key element, Kold represents the key element before updating, PRNG represents a pseudo-random number generator, Ti represents the current timestamp, h represents the row index of the key element in the key matrix, and j represents the column index of the key element in the key matrix.

7. An electronic device, characterized in that: It comprises a memory, a processor and a transceiver which are communicatively connected in sequence, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the medical data security transmission method as described in any one of claims 1 to 5.

8. A computer program product comprising a computer program or instructions, characterized in that The computer program or the instruction, when executed by a computer, implements the method for securely transmitting medical data as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • POS machine data encryption method and device

    CN114513297A

  • Encryption method and device

    CN116015611A