A Method for Dynamically Encrypting and Uploading Data on a Medical Information Cloud Platform
By monitoring and analyzing network information in real time, using machine models to generate transmission abnormality indexes, intelligently perceive and evaluate risks in the upload process of medical information, solving the problem of data loss or damage caused by abnormalities during medical information upload process, and achieving the integrity and accuracy of medical information.
Patent Information
- Application Number
- CN202411648466.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-19
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2044-11-19
AI Technical Summary
Medical information may have abnormalities during uploading to the cloud after local encryption, resulting in data loss or damage, affecting the integrity and accuracy of medical information, especially in emergencies.
By monitoring and analyzing network security information and network transmission quality information in real time, using pre-learned machine models to generate transmission abnormality indexes, intelligently perceive and evaluate the risk status during the upload of medical information, and take corresponding early warning measures.
It effectively reduces the risk of data loss or damage during the upload of medical information, ensures the integrity and accuracy of medical information, responds to emergencies in a timely manner, and reduces the incidence of misdiagnosis, treatment delays or medication errors.
Smart Images

Figure CN119520091B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of medical information cloud platform data, and particularly relates to a method for dynamically encrypting and uploading data of a medical information cloud platform. Background Art
[0002] The method for dynamically encrypting and uploading data of a medical information cloud platform is a technology to ensure the security of sensitive medical data during transmission. First, "dynamic encryption" means that during the process of data uploading from local devices (such as hospital computers or diagnostic devices) to the cloud platform, the system will generate and use different encryption keys in real time according to the specific situation of the transmission. This dynamic encryption method can effectively prevent large-scale data leakage after a single encryption key is cracked. Even if an encryption key is obtained by an attacker, they can only decrypt a very small part of the data, rather than all of it. Dynamic encryption usually combines modern encryption algorithms, such as AES or RSA, to ensure the confidentiality and integrity of the data.
[0003] Secondly, the uploading method usually refers to the encryption strategy and steps during the data transmission process. The medical information cloud platform will conduct identity verification before the start of data transmission to ensure the legitimacy of the identities of the sender and the receiver. The data is encrypted locally and uploaded to the cloud through a secure transmission protocol to prevent interception or tampering during the transmission process. In addition, dynamic encryption uploading usually involves segmented transmission. Combining with distributed storage technology, the data is split into multiple small pieces and encrypted and uploaded separately to further improve security. Such an uploading method can not only protect patient privacy but also ensure the compliance of medical data during transmission and storage, meeting the requirements of relevant laws and regulations on medical information protection.
[0004] The prior art has the following deficiencies:
[0005] If an abnormality occurs during the process of encrypting and uploading medical information to the cloud locally, a series of serious consequences may be caused, especially when it comes to sensitive personal information and patient privacy. If there are problems during the encrypted uploading process, some data may be lost or damaged, and the integrity and accuracy of medical information are crucial. Especially in emergency situations, any incorrect or incomplete data may directly affect the diagnosis and treatment plan and prognosis of patients. If doctors cannot obtain complete and accurate medical records, it may lead to misdiagnosis, treatment delay, or medication errors, thus causing irreversible damage to patients' health. In addition, many medical data are also closely related to health monitoring and public health management at the regional or national level. If the encrypted uploading fails, key public health data may be leaked or lost, hindering the monitoring and management of the epidemic situation and disease trends by the government or public health institutions, and further delaying the epidemic warning and control measures, threatening the health and safety of the entire society.
[0006] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure, and thus it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0007] The object of the present invention is to provide a method for dynamically encrypting and uploading medical information cloud platform data to solve the problems in the above background art.
[0008] To achieve the above object, the present invention provides the following technical solutions: including the following steps;
[0009] Obtain various parameter information generated during the process of encrypting medical information locally and uploading it to the cloud, including network security information and network transmission quality information;
[0010] Under the detection window, analyze the obtained network security information and network transmission quality information, input the analyzed network security information and network transmission quality information into a pre-trained machine model, generate a transmission anomaly index through the learning model, and perform intelligent perception on the process of encrypting medical information locally and uploading it to the cloud based on the transmission anomaly index;
[0011] Based on the result output by the machine learning model, divide the process of encrypting medical information locally and uploading it to the cloud into a high-risk transmission anomaly state or a low-risk transmission anomaly state, and perform intelligent evaluation on the process of encrypting medical information locally and uploading it to the cloud;
[0012] For the evaluated high-risk transmission anomaly state, continuously obtain the process information of encrypting medical information locally and uploading it to the cloud, and further divide the high-risk transmission anomaly state into a sudden state, an unstable state, and a continuous state;
[0013] For different types of high-risk transmission anomaly states, take different warning measures.
[0014] Preferably, the network security information includes the TLS handshake failure rate, which refers to the number or proportion of failures during the TLS handshake process when establishing a secure connection. The network transmission quality information includes the jitter variance, which refers to the degree of fluctuation of the arrival time during the data packet transmission process and reflects the stability of the network connection.
[0015] Preferably, under the detection window, after performing anomaly analysis on the TLS handshake failure rate and the jitter variance, generate a TLS handshake failure rate index and a jitter variance index respectively, input the TLS handshake failure rate index and the jitter variance index into a pre-trained machine model, generate a transmission anomaly index through the machine model, and perform intelligent perception on the process of encrypting medical information locally and uploading it to the cloud based on the transmission anomaly index.
[0016] Preferably, after performing anomaly analysis on the TLS handshake failure rate under the detection window, the specific steps for generating the TLS handshake failure rate index are as follows:
[0017] Under the detection window, collect TLS handshake-related data based on the network monitoring system. The specific data is the number of successful handshakes N success and the number of failed handshakes N failure , calculate the total number of TLS handshake requests through data. The calculation expression is as follows: N total =N success +N failure , where N total represents the total number of TLS handshake requests;
[0018] Based on a specific time period within the detection window range, designated as S, calculate the dynamic change of the TLS handshake failure rate. The calculation expression is as follows:
[0019] ,
[0020] where FR S represents the TLS handshake failure rate, N failure (S) represents the number of TLS failed handshakes within the time period S, and N total (S) represents the total number of TLS handshake requests within the time period S;
[0021] Considering the influence of different network conditions on the TLS handshake failure rate, introduce a weight factor to calculate the weighted failure rate. The calculation expression is as follows: WFR S =FR S ×W, where W represents the weight factor of the network condition, and WFR S represents the weighted failure rate. The calculation method of the weight factor W of the network condition is as follows:
[0022] ,
[0023] where L is the network latency and B is the bandwidth utilization rate;
[0024] Calculate the TLS handshake failure rate index. The calculation expression is as follows:
[0025] ,
[0026] where I TLS represents the TLS handshake failure rate index, C represents the number of potential threats, and D represents the system protection ability index.
[0027] Preferably, after performing anomaly analysis on the jitter variance under the detection window, the specific steps for generating the jitter variance index are as follows:
[0028] Within the detection window, record the arrival time of each data packet, and label the data packet arrival time as T i , then T i ={T1, T2, T3,..., T N}, where N represents the total number of data packets, and T i represents the arrival time of each data packet i;
[0029] Calculate the arrival time difference between two adjacent data packets. The calculation expression is as follows: ΔT i =|T i -T i-1 |. In the formula, ΔT i represents the arrival time difference between adjacent data packets, representing the delay jitter in network transmission, that is, the arrival time difference between the i-th and the i-1-th data packets;
[0030] Define a delay weight function, the purpose of which is to accurately capture jitter. The calculation expression is as follows:
[0031] ,
[0032] In the formula, W(T i ) represents the delay weight function, and α is an adjustment parameter used to control the sensitivity of jitter;
[0033] Substitute the delay weight function W(T i ) into the formula for the jitter variance index. The calculation expression is as follows:
[0034] ,
[0035] In the formula, Jvar represents the jitter variance index.
[0036] Preferably, input the TLS handshake failure rate index I TLS and the jitter variance index Jvar into a pre-learned machine model, and generate a transmission anomaly index TE through the machine model. The basis formula is as follows:
[0037] ,
[0038] In the formula, k1 and k2 are respectively the preset proportionality coefficients of the TLS handshake failure rate index I TLS and the jitter variance index Jvar, and both k1 and k2 are greater than 0.
[0039] Preferably, compare the generated transmission anomaly index with a preset transmission anomaly index reference threshold. The comparison result is as follows:
[0040] If the transmission anomaly index is greater than or equal to a pre-set reference threshold of the transmission anomaly index, the process of encrypting medical information locally and uploading it to the cloud is classified as a high-risk transmission anomaly state;
[0041] If the transmission anomaly index is less than the pre-set reference threshold of the transmission anomaly index, the process of encrypting medical information locally and uploading it to the cloud is classified as a low-risk transmission anomaly state.
[0042] Preferably, for the evaluated high-risk transmission anomaly state, continuously obtain a data set of several transmission anomaly indices generated under several detection windows during the process of encrypting medical information locally and uploading it to the cloud, and conduct a comprehensive analysis;
[0043] Calculate the average value and standard deviation of several transmission anomaly indices in the data set, and compare the calculated average value of the transmission anomaly index and the standard deviation of the transmission anomaly index with the pre-set reference threshold of the average value of the transmission anomaly index and the pre-set reference threshold of the standard deviation of the transmission anomaly index respectively. The comparison results are as follows:
[0044] If the average value of the transmission anomaly index is greater than or equal to the pre-set reference threshold of the transmission anomaly index, the high-risk transmission anomaly state is further classified as a continuous state;
[0045] If the average value of the transmission anomaly index is less than the pre-set reference threshold of the transmission anomaly index and the standard deviation of the transmission anomaly index is greater than or equal to the pre-set reference threshold of the standard deviation of the transmission anomaly index, the high-risk transmission anomaly state is further classified as an unstable state;
[0046] If the average value of the transmission anomaly index is less than the pre-set reference threshold of the transmission anomaly index and the standard deviation of the transmission anomaly index is less than the pre-set reference threshold of the standard deviation of the transmission anomaly index, the high-risk transmission anomaly state is further classified as a sudden state.
[0047] In the above technical solution, the technical effects and advantages provided by the present invention:
[0048] By real-time monitoring and analyzing network security information and network transmission quality information, the present invention can timely identify potential abnormal hidden dangers during the transmission process. This intelligent perception mechanism effectively reduces the risk of data loss or damage during the upload process of medical information. By comparing the transmission anomaly index with the pre-set reference threshold, it can quickly determine whether the upload process is in a high-risk state, so as to take corresponding early warning measures. Such a real-time monitoring and feedback mechanism not only ensures the integrity and accuracy of medical information, but also can respond in a timely manner in case of emergencies, reducing the incidence of misdiagnosis, treatment delay or medication error, and ultimately protecting the health and safety of patients.
[0049] Through the intelligent evaluation of the abnormal state of high-risk transmission, the system can classify it into a continuous state, an unstable state, and a sudden state. This sub-division management enables the medical information cloud platform to take targeted countermeasures according to different abnormal states. For example, for the continuous state, in-depth network optimization and resource allocation can be carried out; for the unstable state, real-time monitoring and appropriate traffic management can be carried out; and for the sudden state, the system can quickly activate the emergency response mechanism to ensure the timeliness and reliability of data transmission. This flexible resource configuration and response mechanism not only improves the operation efficiency of the platform, but also enhances the defense ability against potential security threats, thus providing a more stable and efficient data transmission service for medical institutions. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.
[0051] Figure 1 It is a method flowchart of a method for dynamically encrypting and uploading data of a medical information cloud platform according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0052] Now, the exemplary embodiments will be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these exemplary embodiments are provided so that the present disclosure will be more complete and comprehensive, and will fully convey the concept of the exemplary embodiments to those skilled in the art.
[0053] The present invention provides a method for dynamically encrypting and uploading data of a medical information cloud platform as shown in Figure 1 and includes the following steps;
[0054] Obtain various parameter information generated during the process of locally encrypting medical information and uploading it to the cloud, including network security information and network transmission quality information;
[0055] The network security information includes the TLS handshake failure rate. The TLS handshake failure rate refers to the number or proportion of failures that occur during the TLS handshake process when establishing a secure connection. The network transmission quality information includes the jitter variance. The jitter variance refers to the degree of fluctuation in the arrival time during the data packet transmission process, reflecting the stability of the network connection;
[0056] Under the detection window, the obtained network security information and network transmission quality information are analyzed, and the analyzed network security information and network transmission quality information are input into a pre-trained machine model. Through the learning model, a transmission anomaly index is generated, and based on the transmission anomaly index, the process of locally encrypting medical information and uploading it to the cloud is intelligently perceived;
[0057] Under the detection window, after performing anomaly analysis on the TLS (Transport Layer Security Protocol) handshake failure rate and jitter variance, a TLS handshake failure rate index and a jitter variance index are respectively generated. The TLS handshake failure rate index and the jitter variance index are input into a pre-trained machine model, and through the machine model, a transmission anomaly index is generated. Based on the transmission anomaly index, the process of locally encrypting medical information and uploading it to the cloud is intelligently perceived;
[0058] During the process of locally encrypting medical information and uploading it to the cloud, if the TLS handshake failure rate is unstable, it may indeed lead to anomalies in encrypted upload; the TLS handshake is a key step to ensure the establishment of a secure encrypted channel, and the failure or instability of the handshake process will directly affect the establishment and maintenance of the encrypted connection; if the handshake is unsuccessful, data transmission cannot be carried out through the encrypted channel, which may cause the data to be exposed to an insecure network environment during transmission, increasing the risk of data being intercepted or tampered with;
[0059] Secondly, an unstable TLS handshake failure rate will cause transmission interruptions or retries, thereby affecting the order and integrity of data packets; during the process of transmission interruption or retry, some data packets may be lost, duplicated, or fail to be correctly delivered to the cloud; since medical information usually requires the transmission of high-precision and complete data (such as medical records, diagnosis results, etc.), any loss or damage of data packets may result in incomplete transmission content, thereby affecting the overall accuracy and reliability of medical information;
[0060] Finally, the integrity and accuracy of medical information are crucial for patient diagnosis and treatment, and any anomaly during transmission will directly affect medical decisions; incomplete or damaged medical information may cause doctors to obtain incorrect or incomplete data, thereby resulting in misdiagnosis, treatment delays, or medication errors, and in severe cases, even threatening the patient's life safety;
[0061] Under the detection window, the specific steps for generating the TLS handshake failure rate index after performing anomaly analysis on the TLS handshake failure rate are as follows:
[0062] Under the detection window, collect TLS handshake-related data based on the network monitoring system. The specific data is the number of successful handshakes N success and the number of failed handshakes N failure , and calculate the total number of TLS handshake requests through data. The calculation formula is as follows: N total=N success +N failure , where N total represents the total number of TLS handshake requests;
[0063] It should be noted that the number of successful TLS handshakes and the number of failed TLS handshakes can be obtained through the following methods:
[0064] 1. Network monitoring tools
[0065] Use network monitoring and analysis tools (such as Wireshark, tcpdump, etc.) to capture and analyze network traffic; these tools can identify the TLS handshake process and record the number of successful and failed handshakes respectively by monitoring the status of data packets;
[0066] Successful TLS handshake: Usually there are "ClientHello" and "ServerHello" messages, and the process of finally successfully establishing a secure connection;
[0067] Failed TLS handshake: The identified error messages (such as "HandshakeFailure", "Alert" messages) can be marked as failed handshakes;
[0068] 2. Server logs
[0069] Many application servers and web servers (such as Apache, Nginx, etc.) will record detailed logs of TLS handshakes; in these logs, status information about each connection can be found, including records of successful and failed handshakes;
[0070] Record of successful handshake: Usually there will be a log entry indicating that the connection was successfully established;
[0071] Record of failed handshake: Log entries indicating errors or exceptions, such as certificate verification failure, key mismatch, etc.;
[0072] 3. Application monitoring
[0073] At the application layer, by integrating monitoring tools (such as Prometheus, Grafana, etc.), performance and security metrics of the application can be collected; these tools can provide detailed information about TLS connections and allow developers to customize metric collection;
[0074] Successful handshake: A counter can be defined to increase the number of successful connections;
[0075] Failed handshake: By capturing exception handling or error events, record the number of failed handshakes;
[0076] 4. Network devices
[0077] Some network devices (such as firewalls, load balancers, and intrusion detection systems) can also monitor the TLS handshake process and record the number of successes and failures; these devices usually have deep packet inspection (DPI) capabilities and can identify handshake messages in TLS traffic;
[0078] In this way, the system can comprehensively capture and record the number of successful and failed TLS handshakes, providing a data basis for subsequent analysis and monitoring;
[0079] Based on a specific time period within the detection window, designated as S, calculate the dynamic change of the TLS handshake failure rate. The calculation formula is as follows:
[0080] ,
[0081] In the formula, FR S represents the TLS handshake failure rate, and N failure (S) represents the number of failed TLS handshakes within the time period S, and N total (S) represents the total number of TLS handshake requests within the time period S;
[0082] It should be noted that the time period S refers to a specific time period within the detection window, which is used to calculate the number of TLS handshake requests and failures within this time period;
[0083] Considering the influence of different network conditions on the TLS handshake failure rate, introduce a weight factor to calculate the weighted failure rate. The calculation formula is as follows: WFR S =FR S ×W. In the formula, W represents the weight factor of the network condition, and WFR S represents the weighted failure rate. The calculation method of the weight factor W of the network condition is as follows:
[0084] ,
[0085] In the formula, L is the network latency and B is the bandwidth utilization rate;
[0086] It should be noted that the weight factor can be determined through the following methods:
[0087] 1. Rule of thumb: Based on the actual performance and historical data of the network environment, experts or network administrators can determine the importance of each factor according to experience and assign weights; this method is applicable to situations familiar with a specific environment;
[0088] 2. Data analysis: By analyzing historical network performance data, statistical methods (such as regression analysis) are used to evaluate the specific impact of various network conditions (such as latency, bandwidth, packet loss rate, etc.) on the TLS handshake failure rate, so as to calculate the corresponding weights for each factor;
[0089] 3. Machine learning: Using machine learning algorithms, a training model is used to automatically identify and determine the degree of influence of different network conditions on the TLS handshake failure rate; this method can handle complex non-linear relationships and provide more accurate weight allocation;
[0090] 4. Standardized metrics: Industry standards or best practice weight settings can be referred to and standardized according to the importance of different network conditions to ensure consistency in calculations;
[0091] Through these methods, the weighting factors can be reasonably determined, so that the calculation results can better reflect the impact of actual network conditions on the TLS handshake failure rate;
[0092] Calculate the TLS handshake failure rate index, and the calculation expression is as follows:
[0093] ,
[0094] In the formula, I TLS represents the TLS handshake failure rate index, C represents the number of potential threats, and D represents the system protection ability index;
[0095] It should be noted that the number of potential threats and the determination of the system protection ability index can be carried out through the following methods:
[0096] 1. Number of potential threats
[0097] Historical data analysis: By analyzing the records of historical security events (such as intrusion detection systems, log analysis, etc.), count the number of security threats discovered in the past period of time; this can help identify common attack types and frequencies;
[0098] Threat intelligence: Utilize external threat intelligence sources (such as security reports, industry announcements, vulnerability databases, etc.) to understand emerging threats and attack trends in the current network environment, so as to evaluate the number of potential threats;
[0099] Risk assessment: By regularly conducting network security risk assessments, identify vulnerabilities and possible attack paths in the system, so as to determine the number of potential threats;
[0100] 2. System protection ability index
[0101] Security Control Assessment: Evaluate the effectiveness of existing security control measures (such as firewalls, intrusion detection systems, encryption technologies, etc.), and determine the protection ability indicators based on their resistance to known threats;
[0102] Compliance Standards: Refer to industry standards and best practices (such as ISO27001, NIST framework, etc.) to assess whether the system complies with these standards, and use this to measure the protection ability;
[0103] Vulnerability Scanning and Penetration Testing: Regularly conduct vulnerability scanning and penetration testing of the system, identify security weaknesses in the system, and evaluate the protection ability of the system based on the number and type of vulnerabilities discovered;
[0104] Response Ability Assessment: Evaluate the response time and handling ability of the system during a security incident, and measure its effectiveness in dealing with potential threats;
[0105] Through these methods, the number of potential threats and the system protection ability indicators can be reasonably determined, providing a basis for network security assessment;
[0106] When medical information is encrypted locally and uploaded to the cloud, the jitter variance is unstable, which may indeed cause anomalies during the encrypted upload process, leading to partial data loss or corruption, affecting the integrity and accuracy of medical information; the jitter variance reflects the volatility of the packet arrival time, and a large fluctuation will cause packets to arrive out of order or even be lost; if these problems occur during the encrypted data transmission process, the packets may not be reorganized or processed in the expected order, resulting in interference with the complete data chain of the transmission;
[0107] When the packet arrival times are inconsistent, the data receiver may not be able to reorganize the data in a timely manner, especially when medical data goes through complex encryption algorithms, and the receiver needs complete and correct ciphertext packets for decryption; when the jitter variance is large, some packets may be delayed too long or even lost, which will cause the encrypted information to not be transmitted completely; any lost encrypted packets will affect the decryption process, possibly resulting in decryption failure or generating incorrect decrypted data; as a result, the data uploaded to the cloud may be incomplete or corrupted, affecting the accuracy of medical information;
[0108] The integrity and accuracy of medical information are crucial for diagnosis and treatment. Once the data is lost or damaged, doctors may not be able to obtain complete medical record information, resulting in deviations in the diagnosis and treatment plan or delays in treatment; this is especially serious for emergency situations or critical medical decisions, and data loss or damage may directly affect patient health, leading to medical accidents; therefore, the transmission anomalies caused by unstable jitter variance not only threaten the integrity of the data, but may also seriously affect the reliability and security of medical information;
[0109] After performing anomaly analysis on the jitter variance under the detection window, the specific steps to generate the jitter variance index are as follows:
[0110] Within the detection window, record the arrival time of each data packet, and label the data packet arrival time as T i , then T i ={T1, T2, T3, ……, T N} where N represents the total number of data packets, and T i represents the arrival time of each data packet i;
[0111] Calculate the arrival time difference between two adjacent data packets. The calculation expression is as follows: ΔT i =|T i -T i-1 |. In the formula, ΔT i represents the arrival time difference between adjacent data packets, representing the delay jitter in network transmission, that is, the arrival time difference between the i-th and the (i - 1)-th data packets;
[0112] Define a delay weight function, the purpose of which is to accurately capture jitter. The calculation expression is as follows:
[0113] ,
[0114] In the formula, W(T i ) represents the delay weight function, and α is an adjustment parameter used to control the sensitivity of jitter;
[0115] It should be noted that jitter refers to the fluctuation or inconsistency of the arrival time of data packets during network transmission; usually, in an ideal network transmission environment, data packets should arrive at the receiver at uniform time intervals, but due to network delays, congestion, routing changes, etc., in actual situations, the arrival time of data packets may deviate; this deviation or fluctuation is jitter;
[0116] Jitter mainly affects time-sensitive network applications such as video calls, online games, and real-time data transmission (such as medical monitoring data); in these scenarios, data needs to be transmitted in strict order and at time intervals to ensure smooth and reliable communication; when jitter is large, the arrival time of data packets will be uneven, which may cause video or audio stuttering, delay, or data loss, affecting the user experience or system functions;
[0117] Jitter can be understood from the following aspects:
[0118] 1. Cause
[0119] Jitter is mainly caused by network uncertainty; specific reasons include network congestion, router forwarding delay, interference from physical media, and differences in packet transmission times on different paths; as the network complexity increases, the impact of these factors becomes more significant, resulting in an increase in the jitter amplitude;
[0120] 2. Impact
[0121] Jitter has a greater impact on real-time data transmission, especially in applications that require real-time data processing, such as video conferencing, VoIP (Voice over Internet Protocol), and medical monitoring systems, etc.; excessive jitter can lead to disordered arrival order of packets, or even packet loss, which in turn causes a decline in audio or video quality, interruption of data streams, or errors in the processing of sensitive data;
[0122] 3. Measurement of Jitter
[0123] Jitter is usually measured by analyzing the arrival time differences of multiple packets; it does not depend on the delay of a single packet, but focuses on the delay fluctuations between adjacent packets; common jitter measurement methods include jitter variance, maximum jitter, etc.; the greater the jitter, the higher the instability of network transmission; lower jitter means that packets arrive at relatively uniform intervals and the network stability is better;
[0124] In summary, jitter reflects the instability in network transmission; time-sensitive network applications require effective control of jitter to ensure the order and timely transmission of packets, so as to maintain the quality and reliability of transmission;
[0125] Substitute the delay weight function W(T i ) into the formula for the jitter variance index, and the calculation expression is as follows:
[0126] ,
[0127] In the formula, Jvar represents the jitter variance index;
[0128] Under the detection window, from the calculation expression of the jitter variance index, the larger the value of the jitter variance index indicates that the time fluctuation of network transmission is greater, the arrival order and time of packets are more unstable, and thus the probability of abnormal hidden dangers occurring during the process of uploading locally encrypted medical information to the cloud is also greater. This instability increases the possibility of packet loss, damage or delay, affecting the integrity and decryption accuracy of encrypted data. On the contrary, if the value of the jitter variance index is smaller, it indicates that the network transmission is more stable, the probability of abnormal hidden dangers is relatively small, and the uploading process is more reliable.
[0129] Substitute the TLS handshake failure rate index I TLSThe jitter variance index Jvar and the TLS handshake failure rate index I are input into a pre-trained machine model, and the transmission anomaly index TE is generated by the machine model according to the following formula:
[0130] ,
[0131] In the formula, k1 and k2 are the proportionality coefficients preset for the TLS handshake failure rate index I TLS and the jitter variance index Jvar respectively, and both k1 and k2 are greater than 0.
[0132] Under the detection window, it can be seen from the calculation expression of the transmission anomaly index that the larger the value of the TLS handshake failure rate index generated during the process of uploading the medical information encrypted locally to the cloud, and the larger the value of the jitter variance index, the larger the value of the transmission anomaly index, indicating that the probability of an anomaly occurring during the process of uploading the medical information encrypted locally to the cloud is greater. Conversely, the smaller the value of the TLS handshake failure rate index generated during the process of uploading the medical information encrypted locally to the cloud, and the smaller the value of the jitter variance index, the smaller the value of the transmission anomaly index, indicating that the probability of an anomaly occurring during the process of uploading the medical information encrypted locally to the cloud is smaller;
[0133] Based on the results output by the machine learning model, the process of uploading the medical information encrypted locally to the cloud is divided into a high-risk transmission anomaly state or a low-risk transmission anomaly state, and an intelligent evaluation is carried out on the process of uploading the medical information encrypted locally to the cloud;
[0134] The generated transmission anomaly index is compared with a preset reference threshold of the transmission anomaly index, and the comparison results are as follows:
[0135] If the transmission anomaly index is greater than or equal to the preset reference threshold of the transmission anomaly index, the process of uploading the medical information encrypted locally to the cloud is divided into a high-risk transmission anomaly state;
[0136] If the transmission anomaly index is less than the preset reference threshold of the transmission anomaly index, the process of uploading the medical information encrypted locally to the cloud is divided into a low-risk transmission anomaly state;
[0137] For the evaluated high-risk transmission anomaly state, continuously obtain the process information of uploading the medical information encrypted locally to the cloud, and further divide the high-risk transmission anomaly state into a sudden state, an unstable state and a continuous state;
[0138] For the evaluated high-risk transmission anomaly state, continuously obtain a number of transmission anomaly indexes generated under a number of detection windows during the process of uploading the medical information encrypted locally to the cloud, and establish a data set for comprehensive analysis;
[0139] Calculate the average value and standard deviation of several transmission anomaly indices within the data set, and compare the calculated average value of the transmission anomaly index and the standard deviation of the transmission anomaly index with the pre-set reference threshold of the average value of the transmission anomaly index and the pre-set reference threshold of the standard deviation of the transmission anomaly index respectively. The comparison results are as follows:
[0140] If the average value of the transmission anomaly index is greater than or equal to the pre-set reference threshold of the transmission anomaly index, further classify the high-risk transmission anomaly status as a persistent state;
[0141] If the average value of the transmission anomaly index is less than the pre-set reference threshold of the transmission anomaly index and the standard deviation of the transmission anomaly index is greater than or equal to the pre-set reference threshold of the standard deviation of the transmission anomaly index, further classify the high-risk transmission anomaly status as an unstable state;
[0142] If the average value of the transmission anomaly index is less than the pre-set reference threshold of the transmission anomaly index and the standard deviation of the transmission anomaly index is less than the pre-set reference threshold of the standard deviation of the transmission anomaly index, further classify the high-risk transmission anomaly status as a sudden state;
[0143] For different types of high-risk transmission anomaly statuses, take different warning measures.
[0144] For different types of high-risk transmission anomaly statuses, take different warning measures. For the high-risk transmission anomaly statuses of the persistent state and the unstable state, issue a red warning prompt (high-level warning) and a yellow warning prompt (medium-level warning), and notify the relevant personnel to conduct a detailed inspection and maintenance. For the high-risk transmission anomaly status of the sudden state, since it may recover by itself in a short time, no warning prompt is issued, but the relevant information is recorded for subsequent analysis.
[0145] By real-time monitoring and analyzing network security information and network transmission quality information, the present invention can timely identify potential abnormal hidden dangers during the transmission process. This intelligent perception mechanism effectively reduces the risk of data loss or damage during the upload of medical information. By comparing the transmission anomaly index with the pre-set reference threshold, it can quickly determine whether the upload process is in a high-risk state, so as to take corresponding warning measures. Such a real-time monitoring and feedback mechanism not only ensures the integrity and accuracy of medical information, but also can respond in a timely manner in case of emergencies, reducing the incidence of misdiagnosis, treatment delay or medication error, and ultimately protecting the health and safety of patients.
[0146] Through the intelligent evaluation of the abnormal state of high-risk transmission, the system of the present invention can classify it into a persistent state, an unstable state, and a sudden state. This refined management enables the medical information cloud platform to take targeted countermeasures according to different abnormal states. For example, for the persistent state, in-depth network optimization and resource allocation can be carried out; for the unstable state, real-time monitoring and appropriate traffic management can be carried out; and for the sudden state, the system can quickly activate the emergency response mechanism to ensure the timeliness and reliability of data transmission. This flexible resource configuration and response mechanism not only improves the operating efficiency of the platform but also enhances the defense ability against potential security threats, thus providing a more stable and efficient data transmission service for medical institutions.
[0147] Only some exemplary embodiments of the present invention have been described above by way of illustration. Without doubt, for those of ordinary skill in the art, the described embodiments can be modified in various different ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.
Claims
1. A method for dynamically encrypting and uploading data on a medical information cloud platform, comprising the following steps; Obtain various parameter information generated during the process of uploading medical information to the cloud after being encrypted locally, including network security information and network transmission quality information; In the detection window, the obtained network security information and network transmission quality information are analyzed, and the analyzed network security information and network transmission quality information are input into the pre-learned machine model. The transmission anomaly index is generated through the learning model, and the process of uploading medical information to the cloud after local encryption is intelligently perceived based on the transmission anomaly index; Based on the results output by the machine learning model, the process of uploading medical information from local encryption to the cloud is divided into high-risk transmission abnormality state or low-risk transmission abnormality state, and the process of uploading medical information from local encryption to the cloud is intelligently evaluated; For the assessed high-risk transmission abnormality status, several transmission abnormality indexes generated under several detection windows in the process of continuously obtaining medical information when it is locally encrypted and uploaded to the cloud are used to establish a data set for comprehensive analysis; The average value and standard deviation of several transmission anomaly indexes in the data set are calculated, and the calculated average value and standard deviation of the transmission anomaly index are compared with the preset transmission anomaly index average value reference threshold and the preset transmission anomaly index standard deviation reference threshold, respectively. The comparison results are as follows: If the average value of the transmission anomaly index is greater than or equal to the preset transmission anomaly index reference threshold, the high-risk transmission anomaly state is further divided into a continuous state; If the average value of the transmission anomaly index is less than the preset transmission anomaly index reference threshold and the standard deviation of the transmission anomaly index is greater than or equal to the preset transmission anomaly index standard deviation reference threshold, the high-risk transmission anomaly state is further classified as an unstable state; If the average value of the transmission anomaly index is less than the preset transmission anomaly index reference threshold and the standard deviation of the transmission anomaly index is less than the preset transmission anomaly index standard deviation reference threshold, the high-risk transmission anomaly state is further classified as a burst state; Take different early warning measures for different types of high-risk transmission abnormal conditions; Network security information includes TLS handshake failure rate. TLS handshake failure rate refers to the number or proportion of failures that occur during the TLS handshake process when establishing a secure connection. Network transmission quality information includes jitter variance. Jitter variance refers to the degree of fluctuation in the arrival time during data packet transmission, which reflects the stability of the network connection.
2. A method for dynamically encrypting and uploading data on a medical information cloud platform according to claim 1, characterized in that: In the detection window, after performing anomaly analysis on the TLS handshake failure rate and jitter variance, the TLS handshake failure rate index and jitter variance index are generated respectively. The TLS handshake failure rate index and jitter variance index are input into the pre-learned machine model, and the transmission anomaly index is generated through the machine model. Based on the transmission anomaly index, the process of uploading medical information to the cloud after local encryption is intelligently perceived.
3. A method for dynamically encrypting and uploading data on a medical information cloud platform according to claim 2, characterized in that: In the detection window, after anomaly analysis of the TLS handshake failure rate, the specific steps to generate the TLS handshake failure rate index are as follows: In the detection window, based on the network monitoring system, collect TLS handshake related data, the specific data is the number of successful handshakes N success and the number of failed handshakes N failure , calculate the total number of TLS handshake requests through data, the calculation expression is as follows: N total =N success +N failure , where N total Indicates the total number of TLS handshake requests; Based on a specific time period within the detection window, denoted as S, the dynamic change of the TLS handshake failure rate is calculated. The calculation expression is as follows: , In the formula, FR S Indicates the TLS handshake failure rate, N failure (S) represents the number of TLS handshake failures in time period S, N total (S) represents the total number of TLS handshake requests in time period S; Considering the impact of different network conditions on the TLS handshake failure rate, a weight factor is introduced to calculate the weighted failure rate. The calculation expression is as follows: WFR S =FR S ×W, where W represents the weight factor of network conditions, WFR S represents the weighted failure rate, where the weight factor W of the network condition is calculated as follows: , In the formula, L is the network delay and B is the bandwidth utilization; Calculate the TLS handshake failure rate index. The calculation expression is as follows: , Where I TLS represents the TLS handshake failure rate index, C represents the number of potential threats, and D represents the system protection capability index.
4. A method for dynamically encrypting and uploading data on a medical information cloud platform according to claim 2, characterized in that: After performing anomaly analysis on the jitter variance in the detection window, the specific steps to generate the jitter variance index are as follows: In the detection window, the arrival time of each data packet is recorded and marked as T i , then T i ={T1, T2, T3, ..., T N }, N represents the total number of packets, T i represents the arrival time of each data packet i; Calculate the arrival time difference between two adjacent data packets. The calculation expression is as follows: ΔT i =|T i -T i-1 |, where ΔT i It represents the arrival time difference between adjacent data packets, representing the delay jitter in network transmission, that is, the arrival time difference between the i-th and i-1-th data packets; A delay weight function is defined to accurately capture jitter. The calculation expression is as follows: , In the formula, W(T i ) represents the delay weight function, α is the adjustment parameter used to control the sensitivity of jitter; The delay weight function W(T i ) is substituted into the formula of jitter variance index, and the calculation expression is as follows: , Where Jvar is the jitter variance index.
5. A method for dynamically encrypting and uploading data on a medical information cloud platform according to claim 2, characterized in that: The TLS handshake failure rate index I TLS The jitter variance index Jvar is input into the pre-learned machine model, and the transmission anomaly index TE is generated through the machine model according to the following formula: , Where k1 and k2 are the TLS handshake failure rate index I TLS The proportional coefficient of the jitter variance index Jvar is preset, and k1 and k2 are both greater than 0.
6. A method for dynamically encrypting and uploading data to a medical information cloud platform according to claim 5, characterized in that: The generated transmission anomaly index is compared with the preset transmission anomaly index reference threshold, and the comparison results are as follows: If the transmission anomaly index is greater than or equal to a preset transmission anomaly index reference threshold, the process of uploading the medical information to the cloud after local encryption is classified as a high-risk transmission anomaly state; If the transmission anomaly index is less than a preset transmission anomaly index reference threshold, the process of uploading the medical information to the cloud after local encryption is classified as a low-risk transmission anomaly state.
Citation Information
Patent Citations
School network security dynamic early warning method and system based on knowledge graph
CN118174949A
5G-based smart city intelligent security system and method
CN118283548A