A dynamic medical data anonymization processing system and method based on message monitoring

Through the dynamic medical data anonymization processing system based on message monitoring, the problem that traditional static anonymization technology cannot respond to data changes in a timely manner is solved, efficient and secure anonymization processing of medical data is achieved, and the flexibility and compliance of the system are improved.

CN119475438BActive Publication Date: 2025-05-06DIGITAL HEALTH CHINA TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510051014.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-06
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

Traditional static anonymization technology cannot respond to rapid changes in medical data in a timely manner, resulting in patient sensitive information that may be leaked during the use of data, affecting the patient's sense of trust and compliance of medical services.

Method used

The dynamic medical data anonymization processing system based on message monitoring is adopted, and the anonymization strategy is defined through the configuration management module, the message monitoring module monitors data change events, the cache management module stores and updates anonymization rules and medical data, the dynamic data calling module responds to user requests, the anonymization rule execution module performs multi-level anonymization processing, and the verification and audit module performs compliance verification.

Benefits of technology

It realizes instant response to data changes, quickly adjusts anonymization rules, reduces the risk of patient identity information leakage, improves the security and compliance of medical data use, and enhances the flexibility and adaptability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119475438B_ABST
    Figure CN119475438B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of medical data privacy protection and information security technology, and in particular to a dynamic medical data anonymization processing system and method based on message monitoring, the system comprising a configuration management module, a message monitoring module, a cache management module, a cache refresh module, a dynamic data call module, an anonymization rule execution module, and a verification and audit module. The present invention adopts a message monitoring mechanism to capture change events related to medical data in real time and adjust anonymization rules in a timely manner; by adopting anonymization strategies defined by multi-type annotations, it can meet the complexity of medical data and diverse privacy protection requirements; by combining delayed loading and functional programming modes, it optimizes the performance of anonymization processing and ensures the efficiency and compliance of data processing; by verifying the anonymized data, it ensures that the processed data can meet the requirements of laws and regulations, while protecting the privacy of patients, maintaining the integrity and analysis value of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of medical data privacy protection and information security technology, and in particular to a dynamic medical data anonymization processing system and method based on message monitoring. Background Art

[0002] In modern medical practice, with the widespread use of electronic health records (EHR), medical imaging and genomic data, protecting patient privacy has become a crucial issue. Sensitive information of patients is not only related to personal privacy, but also involves strict requirements of laws and regulations. Traditional static anonymization technology often cannot respond to rapid changes in data in a timely manner. The anonymization of patients' sensitive information needs to rely on software engineers to develop according to actual on-site conditions. Subsequent system updates will interrupt the normal operation of the system, which may cause patients' sensitive information to be leaked during data use, thereby affecting patients' trust and the compliance of medical services, as well as the stability and scalability of the medical system. In order to protect patients' sensitive information while ensuring the value of data analysis and improve the convenience and scalability of the system, there is an urgent need for an anonymization processing system and method that can dynamically respond to data changes.

[0003] Therefore, a dynamic medical data anonymization processing system and method based on message monitoring is proposed. Summary of the invention

[0004] Based on this, it is necessary to provide a dynamic medical data anonymization processing system and method based on message monitoring to address the above technical problems.

[0005] According to a first aspect of the present invention, a dynamic medical data anonymization processing system based on message monitoring is provided, comprising: a configuration management module, which is used to adopt anonymization strategies defined by multi-type annotations, construct configuration information of anonymization rules, and manage dynamic update information; a message monitoring module, which is used to adopt a message monitoring mechanism to monitor notification events related to anonymization rule updates in an external configuration center or a message queue, parse and process the notification events, obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the corresponding relationship between the anonymization rules and sensitive fields based on the obtained dynamic update information; and by subscribing to predefined topics, monitor and obtain change events related to medical data in a relational database; a cache management module, which is used to store, query, incrementally update, and manage anonymization rules and medical data, and adopt a concurrency control mechanism to manage the concurrent processing volume of anonymization rules or medical data by multiple threads to ensure the consistency of anonymization rules or medical data during concurrent operations; a cache refresh module, which is used to trigger a cache refresh mechanism after receiving a change event, and perform a cache refresh on the change event by matching the subject type of the change event according to the sensitive fields and enumerated data types in the configuration information of the anonymization rule. The module is used to perform row parsing processing, obtain content parsing information, and re-acquire the latest medical data from the relational database and store it in the cache, and there is a corresponding relationship between the latest medical data and the content parsing information; the dynamic data calling module is used to respond to the target medical data access request sent by the user end, and determine whether there is valid target medical data in the cache. If so, the valid target medical data is dynamically acquired and called from the cache. If not or the cache is invalid, the latest target medical data is re-acquired from the relational database and stored in the cache; the anonymization rule execution module is used to identify and process the target medical data using the annotation mechanism, obtain the sensitive fields to be processed, and through the reflection parsing annotation technology, in the context creation process of the serializer, according to the enumerated data type to which the sensitive fields to be processed belong, delay loading and binding the anonymization rules of the corresponding enumerated data type, and based on the anonymization rules of the enumerated data type, perform multi-level anonymization processing on the sensitive fields to be processed to obtain the processing results; the verification and audit module is used to verify the processing results according to the content information required by laws and regulations, and feedback the verified processing results to the user end, and audit log records the target medical data, target anonymization rules and processing results.

[0006] Optionally, the configuration management module includes: a configuration construction submodule, which is used to classify sensitive fields according to predefined enumerated data types to obtain multiple sensitive field classification results under each enumerated data type, each sensitive field classification result under each enumerated data type corresponds to a policy category number, each policy category number corresponds to an anonymization rule, the configuration information of each anonymization rule is constructed based on a Lambda expression or a regular expression, and each anonymization rule has a corresponding relationship with the sensitive field classification result; a configuration management submodule, which is used to add, modify and delete anonymization rules.

[0007] Optionally, the message monitoring module includes: an anonymization rule monitoring submodule, which is used to set a message listener in an external configuration center or a message queue based on Redis Stream, monitor and obtain notification events related to anonymization rule updates in the external configuration center or the message queue, parse and process the notification events, obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the correspondence between the corresponding anonymization rules and sensitive fields based on the obtained dynamic update information; a medical data monitoring submodule, which is used to set a message listener in a relational database, monitor and obtain change events related to medical data in the relational database by subscribing to predefined topics, wherein the predefined topics include patient information change topics, medical record change topics, diagnosis information change topics, drug and treatment plan change topics, doctor operation record change topics, and hospitalization and discharge record change topics.

[0008] Optionally, the cache management module includes: an anonymization rule management submodule, which is used to store, query and incrementally update anonymization rules, and set a periodic check key for the anonymization rules in the cache, in which the inspection and maintenance time is set; a medical data management submodule, which is used to store, query and incrementally update medical data, and set an expiration key for the medical data in the cache, in which the expiration key is set with an expiration time; a concurrency control submodule, which adopts a concurrency control mechanism to manage the concurrency of multiple threads processing anonymization rules or medical data, wherein the concurrency control mechanism includes a lock mechanism, a timestamp control mechanism and a multi-version concurrency control mechanism to ensure that the consistency of the anonymization rules or medical data is maintained during concurrent operations.

[0009] Optionally, the dynamic data calling module includes: a response submodule, used to respond to a target medical data access request sent by a user terminal; a dynamic calling submodule, used to determine whether there is valid target medical data in the cache; if there is valid target medical data in the cache, dynamically obtain and call the valid target medical data from the cache; if there is no valid target medical data in the cache or the cache is expired, re-acquire the latest target medical data from the relational database and store the latest target medical data in the cache.

[0010] Optionally, the anonymization rule execution module includes: a serialization and deserialization sub-module, which is used to use the annotation mechanism to identify and process the target medical data, obtain the sensitive fields to be processed, and use reflection parsing annotation technology to, during the context creation process of the serializer, delay loading and bind the anonymization rules of the corresponding enumeration data type according to the enumeration data type to which the sensitive fields to be processed belong; an anonymization processing sub-module, which is used to perform multi-level anonymization processing on the sensitive fields to be processed based on the anonymization rules of the bound enumeration data type and the policy category number corresponding to the sensitive fields to be processed to obtain the processing results.

[0011] Optionally, the verification and audit module includes: a verification submodule, which is used to verify the processing results according to the content information required by laws and regulations, and feed back the verified processing results to the user end; an audit diary recording submodule, which is used to audit log the target medical data, target anonymization rules and processing results to obtain an audit diary.

[0012] According to a second aspect of the present invention, a method for anonymizing dynamic medical data based on message monitoring is provided, comprising: using an anonymization strategy defined by multi-type annotations through a configuration management module to construct configuration information of anonymization rules and manage dynamic update information; using a message monitoring mechanism through a message monitoring module to monitor notification events related to anonymization rule updates in an external configuration center or a message queue, parsing and processing the notification events to obtain corresponding dynamic update information, and dynamically refreshing the corresponding anonymization rules in the cache or the corresponding relationship between the anonymization rules and sensitive fields based on the obtained dynamic update information; and monitoring and obtaining change events related to medical data in a relational database by subscribing to predefined topics; storing, querying, incrementally updating, and managing anonymization rules and medical data through a cache management module, and using a concurrency control mechanism to manage the concurrent processing volume of anonymization rules or medical data by multiple threads to ensure the consistency of anonymization rules or medical data during concurrent operations; triggering a cache refresh mechanism after receiving a change event through a refresh cache module, and performing a check on the change event by matching the subject type of the change event according to the sensitive fields and enumerated data types in the configuration information of the anonymization rule. The system performs row parsing processing to obtain content parsing information, and re-acquires the latest medical data from the relational database and stores it in the cache, and there is a corresponding relationship between the latest medical data and the content parsing information; responds to the target medical data access request sent by the user end through the dynamic data call module, and determines whether there is valid target medical data in the cache. If so, the valid target medical data is dynamically acquired and called from the cache. If not or the cache is invalid, the latest target medical data is re-acquired from the relational database and stored in the cache; the anonymization rule execution module uses the annotation mechanism to identify and process the target medical data to obtain the sensitive fields to be processed, and uses the reflection parsing annotation technology to delay loading and bind the anonymization rules of the corresponding enumerated data types according to the enumerated data types to which the sensitive fields to be processed belong in the context creation process of the serializer. Based on the anonymization rules of the enumerated data types, the sensitive fields to be processed are anonymized at multiple levels to obtain the processing results; the verification and audit module verifies the processing results according to the content information required by laws and regulations, and feeds back the verified processing results to the user end, and performs audit log records on the target medical data, the target anonymization rules and the processing results.

[0013] According to a third aspect of the present invention, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method when executing the computer program.

[0014] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and the computer program implements the steps of the method when executed by a processor.

[0015] The present application provides a dynamic medical data anonymization processing system and method based on message monitoring, which have the following beneficial effects: 1. Real-time and high efficiency: the system can respond to data changes immediately and quickly adjust anonymization rules, thereby effectively reducing the risk of patient identity information leakage and improving the security of medical data use; 2. Flexibility and adaptability: multi-type annotation technology allows users to flexibly define anonymization rules according to specific business needs and legal requirements, enhancing the system's adaptability to complex medical data environments; 3. System performance: the combination of delayed loading and functional programming technology significantly improves the efficiency of data processing, reduces the consumption of system resources, and provides medical institutions with an efficient data access experience; 4. Compliance assurance: through strict verification and audit mechanisms, ensure that the anonymization processing results comply with relevant laws and regulations, provide strong support for the legal and safe use of medical data, and protect patients' privacy and information security; 5. Data protection: anonymized medical data not only protects patients' sensitive information and enhances the public's trust in the use of medical data, but also provides a solid foundation for the medical industry in data sharing and innovative applications, thereby promoting the development of the industry. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a system principle block diagram of the present invention.

[0017] Figure 2 This is a system principle block diagram of the configuration management module of the present invention.

[0018] Figure 3 This is a system principle block diagram of the message monitoring module of the present invention.

[0019] Figure 4 This is a system principle block diagram of the cache management module of the present invention.

[0020] Figure 5 This is a system principle block diagram of the dynamic data calling module of the present invention.

[0021] Figure 6 This is a system principle block diagram of the anonymization rule execution module of the present invention.

[0022] Figure 7 This is a system principle block diagram of the verification and audit module of the present invention.

[0023] Figure 8 It is the overall flow chart of the present invention.

[0024] Fig. 9Schematic diagram of an electronic device of the present invention. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below through specific implementation methods in conjunction with the accompanying drawings. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0026] Embodiment 1

[0027] Reference Figure 1-6 A dynamic medical data anonymization processing system 100 based on message monitoring is disclosed. The system includes a configuration management module 110, a message monitoring module 120, a cache management module 130, a cache refresh module 140, a dynamic data calling module 150, an anonymization rule execution module 160 and a verification and audit module 170.

[0028] In some embodiments, the configuration management module 110 is used to adopt anonymization strategies defined by multiple types of annotations, construct configuration information of anonymization rules, and manage dynamic update information.

[0029] Furthermore, by setting up the configuration management module 110, centralized management of anonymization rules and dynamic update information can be achieved, and a unified rule storage interface is provided to support multiple storage methods of anonymization rules and dynamic update information, such as: file system, database, distributed configuration center, etc., so as to ensure the maintainability and consistency of configuration information and facilitate system expansion.

[0030] For further information, see Attachment Figure 2 The configuration management module 110 includes: a configuration construction submodule 1110, which is used to classify sensitive fields according to predefined enumerated data types to obtain multiple sensitive field classification results under each enumerated data type, each sensitive field classification result under each enumerated data type corresponds to a policy category number, each policy category number corresponds to an anonymization rule, the configuration information of each anonymization rule is constructed based on a Lambda expression or a regular expression, and each anonymization rule has a corresponding relationship with the sensitive field classification result; a configuration management submodule 1120, which is used to add, modify and delete anonymization rules.

[0031] Furthermore, the use of multi-type annotations to define flexible anonymization strategies, combined with extensible enumeration data types, can achieve multi-dimensional anonymization rule management. For example, the defined and extended anonymization strategies include the following: enumeration data types (such as phone, email, etc.) are used to quickly classify different data domains; strategy category numbers (such as 1, 2, etc.) are used to distinguish different anonymization rules under the same enumeration data type; anonymization rules are constructed using functional programming models. Specifically, the functional programming model is Lambda expression or regular expression, which is used to accurately describe the anonymization logic, such as retaining only the first three or last four digits of a mobile phone number, retaining the first and last four digits of an ID number, retaining the province and city for address information or only displaying the province, displaying only the surname or its first letter for a name, retaining the year for a date or retaining both the year and month, or directly replacing all sensitive information with a unified identifier (such as "***") to achieve comprehensive anonymization. In addition, by defining enumerated data types, the anonymization strategy is not only easy to expand new types, but also able to reuse existing logic, combined with the annotation mechanism and reflection parsing annotation technology to dynamically load or update anonymization rules. This method enables the privacy protection of medical data to be flexibly applied according to different scenarios to meet the complex needs of the medical industry.

[0032] In some embodiments, the message monitoring module 120 is used to adopt a message monitoring mechanism to monitor notification events related to anonymization rule updates in an external configuration center or a message queue, parse and process the notification events, obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the corresponding relationship between the corresponding anonymization rules and sensitive fields based on the obtained dynamic update information; and monitor and obtain change events related to medical data in a relational database by subscribing to predefined topics.

[0033] For further information, see Attachment Figure 3 The message monitoring module 120 includes: an anonymization rule monitoring submodule 1210, which is used to set a message listener in an external configuration center or a message queue based on Redis Stream, monitor and obtain notification events related to anonymization rule updates in the external configuration center or the message queue, parse and process the notification events, obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the corresponding relationship between the anonymization rules and sensitive fields based on the obtained dynamic update information; a medical data monitoring submodule 1220, which is used to set a message listener in a relational database, monitor and obtain change events related to medical data in the relational database by subscribing to predefined topics, wherein the predefined topics include patient information change topics, medical record change topics, diagnosis information change topics, drug and treatment plan change topics, doctor operation record change topics, and hospitalization and discharge record change topics.

[0034] Furthermore, a message listener is set in an external configuration center or message queue through Redis Stream to listen to notification events related to anonymization rule updates in the external configuration center or message queue, parse notification events related to anonymization rule updates (such as adding, modifying or deleting anonymization rules), obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the correspondence between the corresponding anonymization rules and sensitive fields based on the parsed dynamic update information. By adopting a message listening mechanism, it can ensure that the anonymization strategies defined by multi-type annotations can be dynamically updated without restarting the service, supporting flexible adjustments during system runtime to adapt to changes in medical data protection policies or business needs.

[0035] Furthermore, a message listener is set in the relational database Mysql through Redis Stream, and by subscribing to predefined topics, change events related to medical data in the relational database are monitored and obtained, where the predefined topics include patient information change topics, medical record change topics, diagnosis information change topics, drug and treatment plan change topics, doctor operation record change topics, and hospitalization and discharge record change topics.

[0036] Furthermore, with respect to the topic of patient information changes, the types of change events mainly include the patient's personal information, such as name, ID number, date of birth, gender, contact information, etc. When the patient's personal information changes, the system can obtain these change data in real time and anonymize the change data involving sensitive information in order to protect the patient's privacy.

[0037] Furthermore, with respect to the topic of medical record changes, the types of change events mainly include patients' medical record data, such as medical history, medical records, diagnosis, treatment process, etc., which are used to monitor changes in patients' medical record data in real time and anonymize changes in medical record data involving sensitive information to ensure that medical record data meets privacy protection requirements during storage and processing.

[0038] Furthermore, for the diagnosis information change topic, the types of change events mainly include the patient's diagnosis information, such as disease name, diagnosis time, diagnosis result, etc., which is used to monitor the patient's updated diagnosis information in real time to ensure that the diagnosis information does not leak sensitive data.

[0039] Furthermore, with respect to the topic of changes in medications and treatment plans, the types of change events mainly include medication prescriptions and treatment plans, such as drug name, dosage, and method of use, which are used to monitor changes in medications and treatment plans in real time to avoid leaking patients’ medical treatment details.

[0040] Furthermore, with respect to the topic of changes in doctors’ operation records, the types of change events mainly include doctors’ operation logs, such as prescriptions, operation records, etc., which are used to monitor changes in doctors’ operation logs in real time to ensure that sensitive information during the operation process is properly anonymized.

[0041] Furthermore, with respect to the topic of hospitalization and discharge record changes, the types of change events mainly include the patient's hospitalization records, discharge records, ward arrangements and other hospitalization and discharge record data, which are used to monitor changes in hospitalization and discharge record data in real time, and ensure anonymization when processing sensitive information during the patient's hospitalization process.

[0042] In some embodiments, the cache management module 130 is used to store, query, incrementally update, and manage anonymization rules and medical data, and adopt a concurrency control mechanism to manage the concurrency of multiple threads processing anonymization rules or medical data to ensure that the consistency of anonymization rules or medical data is maintained during concurrent operations.

[0043] For further information, see Attachment Figure 4 The cache management module 130 includes: an anonymization rule management submodule 1310, which is used to store, query and incrementally update anonymization rules, and set a periodic check key for the anonymization rules in the cache, and the periodic check key is set with an inspection and maintenance time; a medical data management submodule 1320, which is used to store, query and incrementally update medical data, and set an expiration key for the medical data in the cache, and the expiration key is set with an expiration time; a concurrency control submodule 1330, which is used to adopt a concurrency control mechanism to manage the concurrency of multiple threads processing anonymization rules or medical data, wherein the concurrency control mechanism includes a lock mechanism, a timestamp control mechanism and a multi-version concurrency control mechanism to ensure that the consistency of anonymization rules or medical data is maintained during concurrent operations.

[0044] Furthermore, by setting up a cache management module 130, efficient storage and fast query capabilities for anonymization rules and medical data can be provided, and incremental updates and automatic expiration management of cached data can be supported. A periodic check key is set for the anonymization rule in the cache, and an inspection and maintenance time is set in the periodic check key to periodically check the integrity and validity of the anonymization rule, so as to automate the maintenance capabilities of the anonymization rule, reduce the cost of manual intervention, ensure the reliability of the long-term operation of the system, and support delayed task loading and timed refresh of the cache of anonymization rules.

[0045] Furthermore, an expiration key is set for the medical data in the cache, and an expiration time is set in the expiration key, so that automatic expiration management of the medical data can be achieved, so as to effectively manage memory resources, avoid memory leaks and overflows, and ensure that the medical data in the cache is kept up to date.

[0046] Furthermore, by setting up a concurrency control submodule 1330 and adopting a concurrency control mechanism, cache pollution in multi-threaded scenarios can be avoided, and the loading speed of anonymization rules or medical data can be accelerated, significantly improving the processing performance in high-concurrency scenarios.

[0047] In some embodiments, the cache refresh module 140 is used to trigger the cache refresh mechanism after receiving a change event, and parse the change event according to the sensitive fields and enumerated data types in the configuration information of the anonymization rule, by matching the subject type of the change event, to obtain content resolution information, and re-acquire the latest medical data from the relational database and store it in the cache. There is a corresponding relationship between the latest medical data and the content resolution information.

[0048] Furthermore, by setting a cache refresh module 140, after receiving a change event, the system will immediately trigger a cache refresh mechanism, and parse the content of the change event by matching the subject type of the change event according to the sensitive fields in the configuration information and the enumerated data types used in the sensitive fields. Then, the system will retrieve the latest medical data from the relational database Mysql, such as patient information, medical record data, examination results, surgical records, and other medical data that need to be anonymized, and update the corresponding content in the cache. By using the cache refresh operation, it can be ensured that the medical data in the cache is always consistent with the medical data status in the relational database Mysql, so as to reduce the risk of using outdated data.

[0049] In some embodiments, the dynamic data calling module 150 is used to respond to a target medical data access request sent by a user terminal, and determine whether there is valid target medical data in the cache. If so, the valid target medical data is dynamically obtained and called from the cache. If not or the cache is invalid, the latest target medical data is re-obtained from the relational database and stored in the cache.

[0050] For further information, see Attachment Figure 5 The dynamic data calling module 150 includes: a response submodule 1510, which is used to respond to a target medical data access request sent by a user terminal; a dynamic calling submodule 1520, which is used to determine whether there is valid target medical data in the cache. If there is valid target medical data in the cache, the valid target medical data is dynamically obtained and called from the cache. If there is no valid target medical data in the cache or the cache is expired, the latest target medical data is re-acquired from the relational database and the latest target medical data is stored in the cache.

[0051] Furthermore, when the user requests access to the target medical data through the user-side visualization page, the system first checks whether there is valid target medical data in the cache. If so, the target medical data in the cache is automatically obtained and called. If not or the cache is invalid, the latest target medical data is obtained from the relational database again and stored in the cache to achieve synchronous update of the cache.

[0052] In some embodiments, the anonymization rule execution module 160 is used to use the annotation mechanism to identify and process the target medical data, obtain the sensitive fields to be processed, and through reflection parsing annotation technology, during the context creation process of the serializer, according to the enumeration data type to which the sensitive fields to be processed belong, delay loading and bind the anonymization rules of the corresponding enumeration data type, and perform multi-level anonymization processing on the sensitive fields to be processed based on the anonymization rules of the enumeration data type to obtain the processing results.

[0053] For further information, see Attachment Figure 6 The anonymization rule execution module 160 includes: a serialization and deserialization submodule 1610, which is used to identify and process the target medical data using the annotation mechanism to obtain the sensitive fields to be processed, and through the reflection parsing annotation technology, in the context creation process of the serializer, according to the enumeration data type to which the sensitive fields to be processed belong, delay loading and binding the anonymization rules of the corresponding enumeration data type; an anonymization processing submodule 1620, which is used to perform multi-level anonymization processing on the sensitive fields to be processed based on the anonymization rules of the bound enumeration data type, according to the policy category number corresponding to the sensitive fields to be processed, to obtain the processing results.

[0054] Furthermore, after calling the target medical data, the target medical data is anonymized according to the predefined anonymization rules. The anonymization rules are stored in the cache, allowing flexible application according to different sensitive fields. Different anonymization rules (such as fuzzification, randomization, etc.) are defined for different sensitive fields through multi-type annotations, and these anonymization rules are executed and applied to protect the privacy of medical data.

[0055] Furthermore, by setting up a serialization and deserialization submodule 1610, serialization support for JSON or other data formats is provided. By dynamically parsing annotation information, the corresponding anonymization rules can be bound according to the enumerated data type to which the sensitive field belongs, so as to ensure seamless integration of anonymization processing and serialization process, and directly output the processed desensitized medical data to avoid exposure of medical data.

[0056] Furthermore, by setting up an anonymization processing submodule 1620, the matching and replacement capabilities of Lambda expressions or regular expressions are provided to support complex string data desensitization logic, such as segmented processing of medical data such as mobile phone numbers, ID numbers, addresses, etc., which is used to match medical data with specific patterns and efficiently replace sensitive field parts, thereby ensuring the flexibility and accuracy of the anonymization rules.

[0057] Furthermore, this application uses a combination of delayed loading and functional programming mode technology to dynamically anonymize medical data, which not only achieves performance optimization and dynamic management of anonymization strategies, but also significantly improves the efficiency and compliance of medical data processing. The specific implementation method includes: first, using the annotation mechanism (such as: @Desensitization) to dynamically mark sensitive fields that need to be anonymized. During the context creation process of the serializer, through reflection parsing annotation technology, according to the enumeration data type to which the sensitive field belongs, delay loading and bind the corresponding anonymization strategy enumeration (DesensitizationStrategy) to avoid loading unnecessary anonymization rules in advance, so as to reduce system overhead; secondly, the anonymization rules adopt the functional programming mode, and each anonymization rule references the precisely defined anonymization logic through Lambda expressions or regular expressions, such as mobile phone numbers, ID numbers, addresses, dates, etc. Hierarchical protection of data of this type (retaining some information or completely masking it); secondly, it supports dynamic expansion and reuse of anonymization strategies, and allows multiple anonymization rules to act on the same field in sequence through the policy chain mode, meeting the multi-level privacy protection needs in complex scenarios; in addition, through the introduction of dynamic rule management mechanism through message monitoring or configuration center, anonymization rules can be loaded or updated in real time when the system is running to avoid service interruption, and support differentiated processing of multiple types of sensitive fields (such as dedicated serializers for date and numeric enumeration data types); finally, through delayed execution, cache mechanism optimization and rule execution log function, not only the performance of anonymization processing is improved, but also the security and traceability of medical data protection are ensured. The combination of delayed loading and functional programming mode provides flexibility and efficiency for the privacy protection of medical data, while meeting the diverse and complex compliance needs in the medical industry.

[0058] In some embodiments, the verification and audit module 170 is used to verify the processing results according to the content information required by laws and regulations, and to feed back the verified processing results to the user end, as well as to perform audit log records on the target medical data, target anonymization rules and processing results.

[0059] For further information, see Attachment Figure 7The verification and audit module 170 includes: a verification submodule 1710, which is used to verify the processing results according to the content information required by laws and regulations, and feed back the verified processing results to the user end; an audit diary recording submodule 1720, which is used to audit log the target medical data, target anonymization rules and processing results to obtain an audit diary.

[0060] Furthermore, by setting up the verification submodule 1710, the processing result can be verified after the anonymization processing is completed to ensure that it complies with the requirements of relevant laws and regulations (such as HIPAA, GDPR).

[0061] Furthermore, by setting up an audit diary recording submodule 1720, a detailed audit log is recorded, covering each step of the medical data processing, which may include responses to access requests for target medical data, conditions for triggering a cache refresh mechanism, executed anonymization rules and processing results, so as to provide a basis for subsequent compliance checks.

[0062] Embodiment 2

[0063] This embodiment provides a method for anonymizing dynamic medical data based on message monitoring on the basis of the above embodiment 1. Figure 8 , a dynamic medical data anonymization processing system based on message monitoring applied to embodiment 1, the method includes the following steps.

[0064] S1. Use the anonymization strategy defined by multi-type annotations through the configuration management module to build the configuration information of the anonymization rules and manage the dynamic update information.

[0065] S2. Using a message monitoring mechanism through a message monitoring module, monitor notification events related to anonymization rule updates in an external configuration center or a message queue, parse and process the notification events, obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the corresponding relationship between the anonymization rules and sensitive fields based on the obtained dynamic update information; and monitor and obtain change events related to medical data in a relational database by subscribing to predefined topics.

[0066] S3, store, query, incrementally update, and manage anonymization rules and medical data through the cache management module, and adopt a concurrency control mechanism to manage the concurrent processing of anonymization rules or medical data by multiple threads to ensure the consistency of anonymization rules or medical data during concurrent operations.

[0067] S4. After receiving the change event, the cache refresh mechanism is triggered by refreshing the cache module. According to the sensitive fields and enumerated data types in the configuration information of the anonymization rule, the change event is parsed by matching the subject type of the change event to obtain content parsing information, and the latest medical data is re-acquired from the relational database and stored in the cache. There is a corresponding relationship between the latest medical data and the content parsing information.

[0068] S5. Respond to the target medical data access request sent by the user terminal through the dynamic data calling module, and determine whether there is valid target medical data in the cache. If so, dynamically obtain and call the valid target medical data from the cache. If not or the cache is invalid, re-acquire the latest target medical data from the relational database and store it in the cache.

[0069] S6. The anonymization rule execution module uses the annotation mechanism to identify and process the target medical data to obtain the sensitive fields to be processed. The reflection parsing annotation technology is used to delay the loading and binding of the anonymization rules of the corresponding enumeration data type according to the enumeration data type to which the sensitive fields to be processed belong during the context creation of the serializer. Based on the anonymization rules of the enumeration data type, the sensitive fields to be processed are anonymized at multiple levels to obtain the processing results.

[0070] S7. The verification and audit module verifies the processing results according to the content information required by laws and regulations, and feeds back the verified processing results to the user end, and records the audit logs of the target medical data, target anonymization rules and processing results.

[0071] Embodiment 3

[0072] This embodiment further provides an electronic device based on the above embodiment 1. Fig. 9 , Fig. 9 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0073] like Fig. 9 As shown, the electronic device may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 to a random access memory (RAM) 303. Various programs and data required for the operation of the electronic device are also stored in the RAM 303. The processing device 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0074] Typically, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, etc., an output device 307 including, for example, a liquid crystal display (LCD), a speaker, etc., a storage device 308 including, for example, a magnetic tape, a hard disk, etc., and a communication device 309. The communication device 309 may allow the electronic device to communicate with other devices wirelessly or by wire to exchange data. Fig. 9 An electronic device having various devices is shown, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead. Fig. 9 Each block shown in the figure may represent one device, or may represent multiple devices as required.

[0075] In particular, according to some embodiments of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, some embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from the network through the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the above-mentioned functions defined in the method of some embodiments of the present disclosure are executed.

[0076] Embodiment 4

[0077] Based on the above-mentioned embodiment 1, this embodiment further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the above-mentioned method are implemented.

[0078] It should be noted that the computer-readable medium mentioned above in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, device or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer readable signal media may also be any computer readable medium other than computer readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0079] In this embodiment, the client and the server may communicate using any currently known or future developed network protocol such as HTTP (HyperTextTransferProtocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an adhoc peer-to-peer network), as well as any currently known or future developed network.

[0080] The computer-readable medium may be included in the device, or may exist independently without being installed in the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: obtains training data, converts the training data into initial data; determines an initial rule base based on the initial data, and optimizes the parameters of the initial rule base to obtain a target rule base; calculates the rules in the target rule base according to a preset activation weight calculation formula to obtain activation weights; determines abnormal information according to the test data and the activation weights.

[0081] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0082] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0083] The units described in some embodiments of the present disclosure may be implemented by software or hardware. The units described may also be provided in a processor, for example, may be described as: a processor including a data acquisition unit, a rule determination unit, a weight calculation unit, and an anomaly determination unit. The names of these units do not, in some cases, constitute limitations on the units themselves, for example, the data acquisition unit may also be described as a "unit for acquiring training data".

[0084] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that may be used include, without limitation, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), etc.

[0085] Obviously, it should be understood by those skilled in the art that the above-mentioned various steps of the present invention can be performed in a manner different from the present invention, and the simulation method and experimental equipment include but are not limited to the above description. The above-mentioned various steps of the present invention can be performed in an order different from that here in some cases, and the steps shown or described above can be performed separately. Therefore, the present invention is not limited to any specific combination of hardware and software.

[0086] The above contents are further detailed descriptions of the present invention in combination with specific implementation methods, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the scope of protection of the present invention.

Claims

1. A dynamic medical data anonymization processing system based on message monitoring, characterized in that: include: Configuration management module, which is used to adopt anonymization strategies defined by multi-type annotations, build configuration information of anonymization rules, and manage dynamic update information; A message monitoring module is used to adopt a message monitoring mechanism to monitor notification events related to anonymization rule updates in an external configuration center or a message queue, parse and process the notification events, obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the corresponding relationship between the anonymization rules and sensitive fields based on the obtained dynamic update information; and monitor and obtain change events related to medical data in a relational database by subscribing to predefined topics; A cache management module is used to store, query, incrementally update, and manage anonymization rules and medical data, and adopt a concurrency control mechanism to manage the concurrent processing of anonymization rules or medical data by multiple threads to ensure the consistency of anonymization rules or medical data during concurrent operations; A cache refresh module is used to trigger a cache refresh mechanism after receiving a change event, parse the change event according to the sensitive fields and enumerated data types in the configuration information of the anonymization rule, match the subject type of the change event, obtain content parsing information, and re-acquire the latest medical data from the relational database and store it in the cache. There is a corresponding relationship between the latest medical data and the content parsing information, and the latest medical data is the medical data that needs to be anonymized; The dynamic data calling module is used to respond to the target medical data access request sent by the user end, determine whether there is valid target medical data in the cache, and if so, dynamically obtain and call the valid target medical data from the cache; if not or the cache is invalid, re-acquire the latest target medical data from the relational database and store it in the cache; The anonymization rule execution module is used to identify and process the target medical data using the annotation mechanism to obtain the sensitive fields to be processed, and through the reflection parsing annotation technology, in the context creation process of the serializer, according to the enumeration data type to which the sensitive fields to be processed belong, delay loading and binding the anonymization rules of the corresponding enumeration data type, and based on the anonymization rules of the enumeration data type, perform multi-level anonymization processing on the sensitive fields to be processed to obtain the processing results; The verification and audit module is used to verify the processing results according to the content information required by laws and regulations, and to feed back the verified processing results to the user end, as well as to record the audit log of the target medical data, target anonymization rules and processing results.

2. According to the message monitoring-based dynamic medical data anonymization processing system of claim 1, it is characterized in that: The configuration management module includes: A configuration construction submodule is used to classify the data according to predefined enumeration data types to obtain multiple sensitive field classification results under each enumeration data type, each sensitive field classification result under each enumeration sensitive field data type corresponds to a policy category number, each of the policy category numbers corresponds to an anonymization rule, the configuration information of each of the anonymization rules is constructed based on Lambda expressions or regular expressions, and each of the anonymization rules has a corresponding relationship with the sensitive field classification result; Configuration management submodule, used to add, modify and delete anonymization rules.

3. According to the message monitoring-based dynamic medical data anonymization processing system of claim 1, it is characterized in that: The message monitoring module includes: The anonymization rule monitoring submodule is used to set a message listener in the external configuration center or message queue based on Redis Stream, monitor and obtain notification events related to anonymization rule updates in the external configuration center or message queue, parse and process the notification events, obtain corresponding dynamic update information, and dynamically refresh the corresponding anonymization rules in the cache or the corresponding relationship between the corresponding anonymization rules and sensitive fields based on the obtained dynamic update information; The medical data monitoring submodule is used to set a message listener in the relational database, and monitor and obtain change events related to medical data in the relational database by subscribing to predefined topics, wherein the predefined topics include patient information change topics, medical record change topics, diagnosis information change topics, drug and treatment plan change topics, doctor operation record change topics, and hospitalization and discharge record change topics.

4. A dynamic medical data anonymization processing system based on message monitoring according to claim 1, characterized in that: The cache management module includes: Anonymization rule management submodule is used to store, query and incrementally update anonymization rules, and set a periodic check key for the anonymization rules in the cache, in which the check and maintenance time is set; The medical data management submodule is used to store, query and incrementally update medical data, and set an expiration key for the medical data in the cache, in which an expiration time is set; The concurrency control submodule is used to manage the concurrent processing of anonymization rules or medical data by multiple threads using a concurrency control mechanism. The concurrency control mechanism includes a lock mechanism, a timestamp control mechanism, and a multi-version concurrency control mechanism to ensure that the consistency of anonymization rules or medical data is maintained during concurrent operations.

5. A dynamic medical data anonymization processing system based on message monitoring according to claim 4, characterized in that: The dynamic data calling module comprises: A response submodule, used to respond to a target medical data access request sent by a user terminal; The dynamic call submodule is used to determine whether there is valid target medical data in the cache. If there is valid target medical data in the cache, the valid target medical data is dynamically obtained and called from the cache. If there is no valid target medical data in the cache or the cache is expired, the latest target medical data is re-obtained from the relational database and stored in the cache.

6. A dynamic medical data anonymization processing system based on message monitoring according to claim 2, characterized in that: The anonymization rule execution module includes: The serialization and deserialization submodule is used to identify and process the target medical data using the annotation mechanism to obtain the sensitive fields to be processed, and through the reflection parsing annotation technology, during the context creation process of the serializer, according to the enumerated data type to which the sensitive fields to be processed belong, delay loading and bind the anonymization rules of the corresponding enumerated data type; The anonymization processing submodule is used to perform multi-level anonymization processing on the sensitive fields to be processed based on the anonymization rules of the bound enumeration data type and the policy category number corresponding to the sensitive fields to be processed to obtain the processing results.

7. A dynamic medical data anonymization processing system based on message monitoring according to claim 1, characterized in that: The verification and audit module includes: The verification submodule is used to verify the processing results according to the content information required by laws and regulations, and feed back the verified processing results to the user end; The audit log recording submodule is used to perform audit log recording on the target medical data, target anonymization rules and processing results to obtain an audit log.

8. A method for anonymizing dynamic medical data based on message monitoring, characterized in that: include: The configuration management module uses anonymization strategies defined by multiple types of annotations to build configuration information for anonymization rules and manage dynamic update information. The message monitoring module adopts a message monitoring mechanism to monitor notification events related to anonymization rule updates in an external configuration center or a message queue, parses and processes the notification events, obtains corresponding dynamic update information, and dynamically refreshes the corresponding anonymization rules in the cache or the corresponding relationship between the anonymization rules and sensitive fields based on the obtained dynamic update information; and monitors and obtains change events related to medical data in a relational database by subscribing to predefined topics; The cache management module is used to store, query, incrementally update, and manage anonymization rules and medical data. The concurrent control mechanism is used to manage the concurrent processing of anonymization rules or medical data by multiple threads to ensure the consistency of anonymization rules or medical data during concurrent operations. After receiving the change event, the cache refresh mechanism is triggered by refreshing the cache module. According to the sensitive fields and enumerated data types in the configuration information of the anonymization rule, the change event is parsed by matching the subject type of the change event to obtain content parsing information, and the latest medical data is re-acquired from the relational database and stored in the cache. There is a corresponding relationship between the latest medical data and the content parsing information, and the latest medical data is the medical data that needs to be anonymized; Respond to the target medical data access request sent by the user end through the dynamic data calling module, and determine whether there is valid target medical data in the cache. If so, dynamically obtain and call the valid target medical data from the cache. If not or the cache is invalid, re-acquire the latest target medical data from the relational database and store it in the cache; The target medical data is identified and processed by the anonymization rule execution module using the annotation mechanism to obtain the sensitive fields to be processed. The reflection parsing annotation technology is used to delay the loading and binding of the anonymization rules of the corresponding enumeration data type according to the enumeration data type to which the sensitive fields to be processed belong during the context creation process of the serializer. Based on the anonymization rules of the enumeration data type, the sensitive fields to be processed are anonymized at multiple levels to obtain the processing results. The verification and audit module verifies the processing results according to the content information required by laws and regulations, and feeds back the verified processing results to the user end, and records the audit logs of the target medical data, target anonymization rules and processing results.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to claim 8 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to claim 8 are implemented.

Citation Information

Patent Citations

  • Real-time data caching method and system for real-time database

    CN118964414A

  • Methods and systems for runtime data anonymization

    US20120259877A1