Patient data analysis and processing system and method

By adopting adaptive encryption mechanisms and multiple secure computing technologies in the patient data analysis system, the shortcomings of data privacy protection, multi-party collaborative computing and behavioral pattern analysis in the existing technology are solved, and efficient, real-time and secure patient data analysis and processing are achieved.

CN119720259BActive Publication Date: 2025-05-13MIANYANG THIRD PEOPLES HOSPITAL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510224642.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-13
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

The existing patient data analysis methods have significant shortcomings in data privacy protection, multi-party collaborative computing, behavioral pattern analysis, etc., especially in the problems of high algorithm complexity, poor real-time performance and limited data privacy protection capabilities.

Method used

Adaptive encryption mechanism is adopted to select an appropriate encryption algorithm (AES-128 or AES-256) for encryption by assigning sensitivity values ​​to each element in the patient information data set and dynamically compute the encryption strength in combination with the access frequency. At the same time, technical means such as security calculation based on data collaboration, zero-knowledge proof, differential privacy protection of intelligent noise injection, permission management, behavior analysis and abnormal detection under dynamic roles and time conditions are adopted.

Benefits of technology

It improves the accuracy and real-time nature of data processing, ensures comprehensive protection of patient privacy and system security, enhances the flexibility and privacy protection capabilities of encryption mechanisms, and improves the security, flexibility and operation efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119720259B_ABST
    Figure CN119720259B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of patient data analysis and processing, and discloses a patient data analysis and processing system and method. This method solves the problem that data sensitivity differences cannot be quantified by assigning sensitivity values ​​to patient information data, ensuring that sensitive data is protected with higher strength. By counting access frequencies and calculating encryption strength, the encryption requirements for frequently accessed data are optimized, over-encryption is avoided, and system performance is improved. The encryption strength is calculated by combining sensitivity with access frequency, and the encryption strategy is dynamically adjusted to ensure that highly sensitive data is protected. At the same time, the encryption strength of high-frequency data is moderate to ensure system availability. By setting an encryption strength threshold and introducing AES‑128 and AES‑256 algorithms, the problem that a single encryption algorithm cannot meet different data requirements is solved, and encryption performance and resource utilization are optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of patient data analysis and processing, and in particular to a patient data analysis and processing system and method. Background Art

[0002] With the development of medical technology, patient data analysis and processing play an increasingly important role in clinical management. By analyzing the patient's condition changes, care needs, and related medical data, the medical team can develop more accurate treatment and care plans. However, existing patient data analysis methods still face many challenges in practical applications, especially in terms of data privacy protection, collaborative computing, and behavior pattern analysis.

[0003] In medical data processing, statistical analysis and machine learning models are widely used in disease prediction, treatment effect evaluation, etc. However, these methods usually rely on large-scale labeled data sets and training samples, and when applied to multi-party collaborative computing and real-time data processing, there are problems such as high algorithm complexity and poor real-time performance. In addition, these technologies have limited ability to protect patient privacy and may cause hidden dangers of data leakage. In the daily management of patient data, the detection of abnormal behavior is crucial, such as unauthorized access and data tampering. Existing behavior detection methods are mostly based on traditional threshold judgments or static rules, which cannot fully cope with abnormal behaviors in complex dynamic environments. Once a security incident occurs, it is usually difficult for the system to detect it in time and take effective preventive measures.

[0004] In summary, patient data analysis and processing methods face severe challenges in terms of data privacy protection, multi-party collaborative computing, behavioral pattern analysis, etc. In order to address the above issues, this case proposes a more innovative and efficient patient data analysis and processing method to improve the accuracy and real-time performance of data processing while ensuring comprehensive protection of patient privacy and system security. Summary of the invention

[0005] The present invention provides a patient data analysis and processing system and method, which facilitates solving the problems mentioned in the above background technology.

[0006] The present invention provides the following technical solution: a patient data analysis and processing method, comprising:

[0007] S1. Build an adaptive encryption mechanism;

[0008] Obtain the patient's information data set after the patient agrees, denoted as W;

[0009] The patient information data set is specifically, W={patient personal information, medical record data, payment record};

[0010] Assign a sensitivity value to each element in the patient information dataset , the sensitivity value is between [0,10];

[0011] Count the access frequency of each element in the patient information dataset in the past month , the calculation formula is:

[0012] , is the access frequency of the i-th element in the patient information dataset;

[0013] Depending on the sensitivity of the data and access frequency , calculate encryption strength :

[0014] ,in is the encryption strength of the i-th element in the patient information dataset;

[0015] Set encryption strength threshold;

[0016] Set the encryption algorithm set, denoted as AES, where AES={AES-128, AES-256};

[0017] when When ≤ encryption strength threshold, the first element in the AES set is used to encrypt the i-th element in the patient information dataset;

[0018] when > encryption strength threshold, the second element in the AES set is used to encrypt the i-th element in the patient information dataset;

[0019] S2, secure computing based on data collaboration;

[0020] S3, zero-knowledge proof based on custom verification protocol;

[0021] S4, Differential privacy protection with smart noise injection;

[0022] S5. Permission management under dynamic roles and time conditions;

[0023] S6. Behavior analysis and anomaly detection.

[0024] Optionally, the secure computing based on data collaboration specifically includes:

[0025] Dynamically generate encryption keys based on the sensitivity of the data :

[0026] ;

[0027] in, is the key of the i-th element in the patient information dataset; is a modular operation;

[0028] XOR encrypt each element in the patient information dataset:

[0029] ;

[0030] in, is the i-th element in the patient information dataset; is the key of the i-th element in the patient information dataset; The encrypted data of the i-th element in the patient information data set;

[0031] Design a collaborative calculation function based on the cumulative sum calculation of encrypted data, and then perform encrypted data calculations on the two departments to obtain the encrypted results:

[0032] ;

[0033] Given multiple encrypted data items E(X1), E(X2), ..., E(X n ), and perform data accumulation calculation through collaborative computing:

[0034] ;

[0035] in, Represents the exclusive OR operation; is the original value of the i-th data; E(X i ) is the encrypted value of the i-th data; n is the total number of data items;

[0036] If the collaborative computing involves two-dimensional data, the data encryption calculation is performed through the two-dimensional collaborative computing function:

[0037] ;

[0038] in, is the element in the two-dimensional data, m and n are the number of rows and columns of the two-dimensional data;

[0039] Key-based , use the dynamic XOR decryption algorithm to decrypt data:

[0040] .

[0041] Optionally, the zero-knowledge proof based on the custom verification protocol specifically includes:

[0042] S31, data encryption;

[0043] For each data item Encryption is performed using a The XOR encryption algorithm is as follows:

[0044] ;

[0045] in, is the key of the i-th data item; is an XOR operation; is the i-th data item; is the encrypted data;

[0046] S32. Define a zero-knowledge proof protocol;

[0047] Set up a custom zero-knowledge proof protocol ZKP (X i ,[a,b]):

[0048] Enter the encrypted data and validation interval [a,b];

[0049] The output prover submits a zero-knowledge proof to the verifier without leaking it The specific value of

[0050] The certifier is specifically a party that proves that the data meets the conditions;

[0051] The verifier is specifically a party that verifies whether the condition is satisfied;

[0052] S33, Challenge-Response Mechanism;

[0053] Challenge phase: The verifier randomly selects a challenge C, C {0, 1};

[0054] Response phase:

[0055] If C=0, the prover needs to prove belongs to the interval [a,b];

[0056] If C=1, the prover needs to generate encrypted data and provide it to the verifier;

[0057] The prover chooses a random number r, r {0, 1}, then perform encryption:

[0058] ;

[0059] Encrypt the random number r and send it to the verifier, and decide the content of the response based on the verifier's challenge C;

[0060] S34, verification stage;

[0061] If C=0, the verifier determines whether the zero-knowledge proof provided by the prover satisfies [a,b], specifically:

[0062] ;

[0063] If the calculation result matches the verification value, the data is successfully verified. satisfy [a,b];

[0064] If C=1, the verifier checks Whether it meets expectations.

[0065] Optionally, the differential privacy protection of the intelligent noise injection specifically includes:

[0066] Data Perform statistical analysis and calculate data The mean and standard deviation of :

[0067] ;

[0068] ;

[0069] According to the mean and standard deviation , generating noise :

[0070] ;in, For the The noise of the data; For noise The mean is With variance Normal distribution of

[0071] The noise Inject data and update the statistical results as follows:

[0072] ;in, is the statistical result of the data after injecting noise; For data Sum and calculate the statistical results; For each data item The sum of the added noise.

[0073] Optionally, the permission management under the dynamic role and time conditions specifically includes:

[0074] S51, Role and authority definition;

[0075] For each user Ui Set a role R i and a set of permissions P i , where P i is a dataset containing all allowed operations;

[0076] Permission Set P i ={p1, p2, ..., p k}, where p k Indicates the operation permissions of the feature;

[0077] The specific correspondence between roles and permissions is as follows:

[0078] ;

[0079] S52, definition of time conditions and environmental conditions;

[0080] For each role Set a valid access time window and effective environmental conditions ;

[0081] The effective access time window Specifically, ,in, The earliest time to allow access, The latest time that access is allowed;

[0082] The effective environmental conditions are specifically: ,in For geographical location, is the device type;

[0083] S53, authority adjustment function;

[0084] Based on the user's current role, time window, and environmental conditions, the final permission set is calculated through the permission adjustment function:

[0085] ;

[0086] Permission adjustment function The specific form is:

[0087] ;

[0088] in, The current time requested by the user. The current environment conditions of the user. is a restricted set of permissions;

[0089] S54, authority verification and dynamic modification;

[0090] Each time a user requests access, the system calculates the , verify the user's access rights;

[0091] If the verification is successful, the user can continue to access the data, otherwise the access will be denied;

[0092] The verification formula is:

[0093] ;

[0094] If it returns , then the access permission is allowed;

[0095] If it returns , access is denied.

[0096] Optionally, the behavior analysis and anomaly detection specifically include:

[0097] S61, behavioral feature extraction;

[0098] Extract user behavior data B from system logs;

[0099] The behavior data includes the access data type R, access frequency F, time distribution T of data operation and operation mode M;

[0100] Define the behavior feature vector B as: B=(R, F, T, M);

[0101] S62, historical behavior model construction;

[0102] Constructing a useless historical behavior model is:

[0103] ;

[0104] in, , , , They are the data type, access frequency, data operation time and operation method corresponding to the i-th access;

[0105] S63, calculation of the difference between current behavior and historical behavior;

[0106] Compare current behavior Historical Behavior Model , calculate the deviation between current behavior and historical behavior :

[0107] ;

[0108] in, and are the data values ​​of the current behavior and the historical behavior in the i-th dimension, and m is the dimension of the feature vector;

[0109] Setting the deviation threshold ;

[0110] like , an abnormal alarm is triggered.

[0111] A system for implementing the patient data analysis and processing method, comprising:

[0112] Computing module: used for data calculation;

[0113] Information collection module: collects patient information, including personal information, medical records, and payment records; collects behavioral data of data visitors, including the type of data accessed, access frequency, time of data operations, and operation methods.

[0114] The present invention has the following beneficial effects:

[0115] 1. The problem of data sensitivity differences being unable to be quantified is solved by assigning a sensitivity value to each element in the patient information dataset. The sensitivity value is in the range of [0,10], which can accurately reflect the importance and sensitivity of the data. This design enables the system to identify the security requirements of different data elements, provides a basis for subsequent encryption strategies, and ensures that sensitive data is protected with higher strength. The problem of the inability to consider the impact of data access frequency on encryption requirements is solved by counting the access frequency of each element in the patient information dataset and introducing the calculation formula. The calculation formula clarifies the access frequency of each data element, so that frequently accessed data can adopt appropriate encryption strength, thereby balancing encryption security and access efficiency. This mechanism avoids over-encryption of frequently accessed data and improves system performance. The problem of encryption strategies being unable to dynamically adapt to data characteristics is solved by combining data sensitivity and access frequency to calculate encryption strength. The sensitivity and access frequency of the data are comprehensively considered, so that the encryption strength can protect highly sensitive data and optimize frequently accessed data. By performing a logarithmic transformation on the frequency, the unlimited increase in encryption strength caused by high-frequency data is avoided, ensuring the availability of the system. By setting the encryption strength threshold and introducing the steps of encryption algorithm set, the problem that a single encryption algorithm cannot meet different data security requirements is solved. When the encryption strength is less than or equal to the threshold, the system selects the lightweight AES-128 algorithm for encryption to meet the security requirements of ordinary data; when the encryption strength is greater than the threshold, the system selects the stronger AES-256 algorithm for encryption to ensure that highly sensitive data is more protected. This hierarchical encryption strategy improves the utilization efficiency of encryption resources while ensuring data security. By dynamically selecting the encryption algorithm according to the encryption strength, the problem that the traditional encryption mechanism cannot adjust the strategy according to the data characteristics is solved. The design of hierarchical selection of AES-128 or AES-256 algorithms optimizes encryption performance, reduces unnecessary computing overhead, and ensures high-intensity encryption of sensitive data. This adaptive encryption mechanism improves the security, flexibility and operation efficiency of the system.

[0116] 2. By using the adaptive XOR encryption algorithm to dynamically generate encryption keys, the problem that the traditional fixed key encryption method cannot adapt to the data sensitivity is solved. The key is dynamically generated by combining data sensitivity and random factors to provide differentiated encryption strength for data of different sensitivities. This design enhances the flexibility of the encryption mechanism and ensures the matching of data security and sensitivity. By performing XOR encryption on each element in the patient information data set, the problem of high complexity of the traditional encryption algorithm is solved. The encryption is completed using a simple XOR operation, which significantly reduces the computational complexity of the encryption process while maintaining data security. This method is suitable for efficient encryption of large-scale data sets. By designing the steps of collaborative computing functions based on the accumulation and calculation of encrypted data, the risk of privacy leakage in cross-departmental data collaborative computing is solved. Under the premise of ensuring the encryption state of the data, data collaborative computing between departments is realized to avoid the leakage of original data. This improves the privacy protection capability of collaborative computing and meets the needs of departmental collaboration. By introducing the steps of collaborative computing functions for two-dimensional data, the problem of incompatibility of two-dimensional data such as tables and images is solved. The step of decrypting data through a key-based dynamic XOR decryption algorithm solves the problems of decryption complexity and insufficient consistency in the process of restoring encrypted data. Decryption is completed using a key consistent with the encryption process, ensuring the accuracy and efficiency of decryption. At the same time, it supports dynamically changing key strategies, improving the security and reliability of data processing.

[0117] 3. Through data encryption, the problem of data being stolen during transmission and storage is solved, and the initial protection of data is achieved. Each data item is encrypted based on the key, which effectively protects the privacy and security of the data. At the same time, due to the dynamic characteristics of the key, the encryption process is more adaptable and can effectively resist attacks against fixed keys. The zero-knowledge proof protocol defined in step S32 solves the problem of the original data being leaked during the data verification process, and achieves a balance between security and verification functions. The defined protocol ZKP (X i ,[a,b]) allows the prover to i Under the specific value of , it proves to the verifier that the data belongs to the interval [a,b]. This ensures the validity of the verification while protecting data privacy, which is especially suitable for sensitive data verification scenarios. Through the challenge-response mechanism, the problems of fraud and forgery in the verification process are solved, and the dynamic and security of the verification are enhanced. Through the verification stage, the problems of unquantifiable and unreliable verification results are solved, ensuring the credibility of the verification results. The verifier confirms whether the data is in the expected interval according to the formula. This verification method is directly based on the relationship between encrypted data and keys, without exposing the original data, thereby achieving high efficiency and reliability of the verification process.

[0118] 4. By performing statistical analysis on the data and calculating the mean and standard deviation, the problem of insufficient privacy protection of the original data is solved, ensuring that data analysis can be performed without leaking sensitive information. Calculating the mean and standard deviation is a basic statistical analysis of data distribution. This operation does not rely on the sensitive information of a single data point, but focuses on the characteristics of the overall data set. Through this process, the data can be moderately statistically modeled, providing a suitable basis for subsequent noise injection to ensure that sensitive information is not exposed. By generating noise based on the mean and standard deviation, the problem of how to generate sufficiently random noise without losing effectiveness in data privacy protection is solved. The standard deviation-based noise is generated through a formula to ensure the consistency of the noise with the original data distribution, so that individual data can be effectively hidden without destroying the global statistical characteristics. The generated noise has a certain degree of randomness, which can interfere with the attacker's opportunity to obtain the original data, while ensuring the availability of the statistical analysis results and enhancing the effect of privacy protection. By injecting noise into the data and updating the statistical results, the problem of how to balance data privacy and data availability in practical applications is solved. After injecting noise into the data set, the statistical results are updated. In this way, even if the data is disturbed by noise, the calculated statistics still reflect the overall characteristics of the data set, thereby ensuring data privacy while avoiding affecting subsequent analysis and decision-making processes. This method effectively avoids statistical bias caused by excessive disturbance and ensures the practical application value of the data.

[0119] 5. Through the definition of roles and permissions, the problem of unclear or overly complex permission allocation in permission management is solved, and the flexibility and controllability of the system are improved. i Set a role R i and a set of permissions P i , which simplifies permission management. By clearly defining the permission set corresponding to each role, it ensures that the operation scope and operation permissions of each user are clearly defined. This method avoids the complexity of assigning permissions to each user individually, improves the efficiency of permission management, reduces the difficulty of management, and enhances the scalability of the system. By defining time conditions and environmental conditions, it solves the problem that traditional permission management cannot adapt to complex access control requirements. Set effective access time windows and environmental conditions for each role. i , introduced dynamic permission control based on time and environment. This method can adjust permissions according to actual conditions, for example, restricting a role from accessing certain data during non-working hours or in a specific location. By setting a specific time window and environmental conditions, such as geographic location and device type, ensure that permission access is more accurate and secure, and avoid abuse or misuse of permissions. The permission adjustment function solves the problem of dynamic changes in user permissions in complex scenarios, and improves the flexibility and real-time performance of access control. Based on the user's current role, time window and environmental conditions, the permission adjustment function dynamically calculates the final permission set. This function ensures that under certain conditions, the user's permissions will be adjusted according to actual needs, thereby preventing access to sensitive information under inappropriate conditions. For example, if a user originally has higher permissions, the permissions will be automatically restricted when the specific time or environmental conditions are not met, ensuring the security and flexibility of the system. Through permission verification and dynamic modification, the problem that static permissions in traditional permission management cannot cope with actual environmental changes is solved, and the security of the system is enhanced. Each time a user requests access, the system will re-verify the user's access rights based on the current time and environmental conditions to ensure that the user accesses the data under the specified time and environmental conditions. If the verification fails, access is denied to prevent illegal access. Through this mechanism, the system can perform dynamic permission control in real time according to the timeliness and environmental conditions of the user's request, effectively preventing abuse of permissions or unauthorized access.

[0120] 6. Through behavioral feature extraction, the problem of incomplete or difficult to quantify user behavior analysis in system logs is solved, and the accuracy of behavioral analysis is improved. User behavior data is extracted from system logs, including the type of data accessed, access frequency, time distribution of data operations and operation methods, and user behavior is converted into a structured feature vector. Through this operation, every interactive behavior of users in the system can be fully captured, including the data they accessed, frequency, operation period and method, etc., thus laying the foundation for subsequent behavioral analysis and anomaly detection. This method solves the problem of unstructured information processing in traditional log data and improves the efficiency and accuracy of data analysis. Through the construction of historical behavior models, the problem of lack of historical data comparison and dynamic monitoring is solved, ensuring that behavioral analysis is based on real historical data. The historical behavior model is constructed to record the behavioral characteristics of each user in different time periods in history. The model provides a standardized reference for each user's behavior, ensuring that anomaly detection is based on the user's normal historical behavior trajectory, and avoiding misjudging accidental behavior as abnormal. This process makes behavioral analysis not only rely on current data, but also provides a more accurate judgment basis in combination with historical data. By calculating the difference between current behavior and historical behavior, the problem of how to monitor user behavior deviations and anomalies in real time is solved, and the system's anomaly detection capability is improved. Compare the current behavior with the historical behavior model, calculate the deviation between the current behavior and the historical behavior, and quantify the degree of abnormality of the user behavior. By setting the deviation threshold, when the deviation exceeds the set threshold, the system will trigger an abnormal alarm. This method can promptly discover abnormal patterns of user behavior and avoid potential security risks, such as abnormal frequent access, operations during non-working hours, abnormal data access, etc. Real-time deviation calculation and alarm mechanism can effectively improve the security of the system and prevent problems such as data leakage and account abuse. BRIEF DESCRIPTION OF THE DRAWINGS

[0121] Figure 1 It is a schematic diagram of the process of the present invention. DETAILED DESCRIPTION

[0122] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0123] Example, see Figure 1 , a patient data analysis and processing method, comprising:

[0124] S1. Build an adaptive encryption mechanism;

[0125] Obtain the patient's information data set after the patient agrees, denoted as W;

[0126] The patient information data set is specifically, W={patient personal information, medical record data, payment record};

[0127] Assign a sensitivity value to each element in the patient information dataset , the sensitivity value is between [0,10]; the higher the sensitivity, the more sensitive the data;

[0128] Count the access frequency of each element in the patient information dataset in the past month , the calculation formula is:

[0129] , is the access frequency of the i-th element in the patient information dataset;

[0130] Depending on the sensitivity of the data and access frequency , calculate encryption strength :

[0131] ,in is the encryption strength of the i-th element in the patient information dataset, This is the result of logarithmic transformation of the frequency, ensuring that the encryption strength of frequently accessed data is moderate;

[0132] Set encryption strength threshold;

[0133] Set the encryption algorithm set, denoted as AES, where AES={AES-128, AES-256};

[0134] when When ≤ encryption strength threshold, the first element in the AES set is used to encrypt the i-th element in the patient information dataset;

[0135] when > encryption strength threshold, the second element in the AES set is used to encrypt the i-th element in the patient information dataset;

[0136] S2, secure computing based on data collaboration;

[0137] S3, zero-knowledge proof based on custom verification protocol;

[0138] S4, Differential privacy protection with smart noise injection;

[0139] S5. Permission management under dynamic roles and time conditions;

[0140] S6. Behavior analysis and anomaly detection.

[0141] The problem of data sensitivity differences being unable to be quantified is solved by assigning a sensitivity value to each element in the patient information dataset. The sensitivity value is in the range of [0,10], which can accurately reflect the importance and sensitivity of the data. This design enables the system to identify the security requirements of different data elements, provides a basis for subsequent encryption strategies, and ensures that sensitive data is protected with higher strength. The problem of the inability to consider the impact of data access frequency on encryption requirements is solved by counting the access frequency of each element in the patient information dataset and introducing a calculation formula. The calculation formula clarifies the access frequency of each data element, so that frequently accessed data can adopt appropriate encryption strength, thereby balancing encryption security and access efficiency. This mechanism avoids over-encryption of frequently accessed data and improves system performance. The problem of encryption strategies being unable to dynamically adapt to data characteristics is solved by combining data sensitivity and access frequency to calculate encryption strength. The sensitivity and access frequency of the data are comprehensively considered, so that the encryption strength can protect highly sensitive data and optimize frequently accessed data. By performing a logarithmic transformation on the frequency, the unlimited increase in encryption strength caused by high-frequency data is avoided, ensuring the availability of the system. By setting the encryption strength threshold and introducing the steps of encryption algorithm set, the problem that a single encryption algorithm cannot meet different data security requirements is solved. When the encryption strength is less than or equal to the threshold, the system selects the lightweight AES-128 algorithm for encryption to meet the security requirements of ordinary data; when the encryption strength is greater than the threshold, the system selects the stronger AES-256 algorithm for encryption to ensure that highly sensitive data is more protected. This hierarchical encryption strategy improves the utilization efficiency of encryption resources while ensuring data security. By dynamically selecting the encryption algorithm according to the encryption strength, the problem that the traditional encryption mechanism cannot adjust the strategy according to the data characteristics is solved. The design of hierarchical selection of AES-128 or AES-256 algorithms optimizes encryption performance, reduces unnecessary computing overhead, and ensures high-intensity encryption of sensitive data. This adaptive encryption mechanism improves the security, flexibility and operation efficiency of the system.

[0142] The secure computing based on data collaboration specifically includes:

[0143] Dynamically generate encryption keys based on the sensitivity of the data :

[0144] ;

[0145] in, is the key of the i-th element in the patient information dataset; is a modular operation;

[0146] XOR encrypt each element in the patient information dataset:

[0147] ;

[0148] in, is the i-th element in the patient information dataset; is the key of the i-th element in the patient information dataset; The encrypted data of the i-th element in the patient information data set;

[0149] Design a collaborative calculation function based on the cumulative sum calculation of encrypted data, and then perform encrypted data calculations on the two departments to obtain the encrypted results:

[0150] ;

[0151] Given multiple encrypted data items E(X1), E(X2), ..., E(X n ), and perform data accumulation calculation through collaborative computing:

[0152] ;

[0153] in, Represents the exclusive OR operation; is the original value of the i-th data; E(X i ) is the encrypted value of the i-th data; n is the total number of data items;

[0154] If the collaborative computing involves two-dimensional data, such as tables or images, the two-dimensional collaborative computing function is used to encrypt the data:

[0155] ;

[0156] in, is the element in the two-dimensional data, m and n are the number of rows and columns of the two-dimensional data;

[0157] Key-based , use the dynamic XOR decryption algorithm to decrypt data:

[0158] .

[0159] By using the adaptive XOR encryption algorithm to dynamically generate encryption keys, the problem that the traditional fixed key encryption method cannot adapt to the data sensitivity is solved. The key is dynamically generated by combining data sensitivity and random factors to provide differentiated encryption strength for data of different sensitivities. This design enhances the flexibility of the encryption mechanism and ensures the matching of data security and sensitivity. By performing XOR encryption on each element in the patient information data set, the problem of high complexity of the traditional encryption algorithm is solved. The encryption is completed using a simple XOR operation, which significantly reduces the computational complexity of the encryption process while maintaining data security. This method is suitable for efficient encryption of large-scale data sets. By designing the collaborative calculation function based on the accumulation and calculation of encrypted data, the risk of privacy leakage in cross-departmental data collaborative calculation is solved. Under the premise of ensuring the data encryption state, data collaborative calculation between departments is realized to avoid the leakage of original data. This improves the privacy protection capability of collaborative calculation and meets the needs of departmental collaboration. By introducing the collaborative calculation function for two-dimensional data, the problem of incompatibility of two-dimensional data such as tables and images is solved. The step of decrypting data through a key-based dynamic XOR decryption algorithm solves the problems of decryption complexity and insufficient consistency in the process of restoring encrypted data. Decryption is completed using a key consistent with the encryption process, ensuring the accuracy and efficiency of decryption. At the same time, it supports dynamically changing key strategies, improving the security and reliability of data processing.

[0160] The zero-knowledge proof based on the custom verification protocol specifically includes:

[0161] S31, data encryption;

[0162] For each data item Encryption is performed using a The XOR encryption algorithm is as follows:

[0163] ;

[0164] in, is the key of the i-th data item; is an XOR operation; is the i-th data item; is the encrypted data;

[0165] S32. Define a zero-knowledge proof protocol;

[0166] Set up a custom zero-knowledge proof protocol ZKP (X i ,[a,b]):

[0167] Enter the encrypted data and validation interval [a,b];

[0168] The output prover submits a zero-knowledge proof to the verifier without leaking it The specific value of

[0169] The certifier is specifically a party that proves that the data meets the conditions;

[0170] The verifier is specifically a party that verifies whether the condition is satisfied;

[0171] S33, Challenge-Response Mechanism;

[0172] Challenge phase: The verifier randomly selects a challenge C, C {0, 1};

[0173] Response phase:

[0174] If C=0, the prover needs to prove belongs to the interval [a,b];

[0175] If C=1, the prover needs to generate encrypted data and provide it to the verifier;

[0176] The prover chooses a random number r, r {0, 1}, then perform encryption:

[0177] ;

[0178] Encrypt the random number r and send it to the verifier, and decide the content of the response based on the verifier's challenge C;

[0179] S34, verification stage;

[0180] If C=0, the verifier determines whether the zero-knowledge proof provided by the prover satisfies [a,b], specifically:

[0181] ;

[0182] If the calculation result matches the verification value, the data is successfully verified. satisfy [a,b];

[0183] If C=1, the verifier checks Whether it meets expectations.

[0184] Through data encryption, the problem of data being stolen during transmission and storage is solved, and the initial protection of data is achieved. Each data item is encrypted based on the key, which effectively protects the privacy of the data. At the same time, due to the dynamic characteristics of the key, the encryption process is more adaptable and can effectively resist attacks on fixed keys. The zero-knowledge proof protocol defined in step S32 solves the problem of the original data being leaked during the data verification process, and achieves a balance between security and verification functions. The defined protocol ZKP (X i ,[a,b]) allows the prover to i Under the specific value of , it proves to the verifier that the data belongs to the interval [a,b]. This ensures the validity of the verification while protecting data privacy, which is especially suitable for sensitive data verification scenarios. Through the challenge-response mechanism, the problems of fraud and forgery in the verification process are solved, and the dynamic and security of the verification are enhanced. Through the verification stage, the problems of unquantifiable and unreliable verification results are solved, ensuring the credibility of the verification results. The verifier confirms whether the data is in the expected interval according to the formula. This verification method is directly based on the relationship between encrypted data and keys, without exposing the original data, thereby achieving high efficiency and reliability of the verification process.

[0185] The differential privacy protection of the intelligent noise injection specifically includes:

[0186] Data Perform statistical analysis and calculate data The mean and standard deviation of :

[0187] ;

[0188] ;

[0189] According to the mean and standard deviation , generating noise :

[0190] ;in, For the The noise of the data; For noise The mean is With variance Normal distribution of

[0191] The noise Inject data and update the statistical results as follows:

[0192] ;in, is the statistical result of the data after injecting noise; For data Sum and calculate the statistical results; For each data item The sum of the added noise.

[0193] By performing statistical analysis on the data and calculating the mean and standard deviation, the problem of insufficient privacy protection of the original data is solved, ensuring that data analysis can be performed without leaking sensitive information. Calculating the mean and standard deviation is a basic statistical analysis of the data distribution. This operation does not rely on the sensitive information of a single data point, but focuses on the characteristics of the overall data set. Through this process, the data can be moderately statistically modeled, providing a suitable basis for subsequent noise injection to ensure that sensitive information is not exposed. By generating noise based on the mean and standard deviation, the problem of how to generate sufficiently random noise without losing effectiveness in data privacy protection is solved. The standard deviation-based noise is generated through a formula to ensure the consistency of the noise with the original data distribution, so that individual data can be effectively hidden without destroying the global statistical characteristics. The generated noise has a certain degree of randomness, which can interfere with the attacker's opportunity to obtain the original data, while ensuring the availability of the statistical analysis results and enhancing the effect of privacy protection. By injecting noise into the data and updating the statistical results, the problem of how to balance data privacy and data availability in practical applications is solved. After injecting noise into the data set, the statistical results are updated. In this way, even if the data is disturbed by noise, the calculated statistics still reflect the overall characteristics of the data set, thereby ensuring data privacy while avoiding affecting subsequent analysis and decision-making processes. This method effectively avoids statistical bias caused by excessive disturbance and ensures the practical application value of the data.

[0194] The permission management under the dynamic role and time conditions specifically includes:

[0195] S51, Role and authority definition;

[0196] For each user U i Set a role R i and a set of permissions P i , where P i It is a data set that contains all allowed operations, such as read, write, modify, delete, etc.

[0197] Permission Set P i ={p1, p2, ..., p k}, where p k Indicates the operation permissions of the feature, such as accessing data A, modifying data B, etc.;

[0198] The specific correspondence between roles and permissions is as follows:

[0199] ;

[0200] For example, the permission set P1 corresponding to role R1 may be P1={read(A), write(B)};

[0201] S52, definition of time conditions and environmental conditions;

[0202] For each role Set a valid access time window and effective environmental conditions ;

[0203] The effective access time window Specifically, ,in, The earliest time to allow access, The latest time allowed for access, such as ;

[0204] The effective environmental conditions are specifically: ,in For geographical location, is the device type;

[0205] S53, authority adjustment function;

[0206] Based on the user's current role, time window, and environmental conditions, the final permission set is calculated through the permission adjustment function:

[0207] ;

[0208] Permission adjustment function The specific form is:

[0209] ;

[0210] in, The current time requested by the user. The current environment conditions of the user. It is a restricted permission set, which is used to indicate the permissions granted to the user when the user's access request does not meet the specified time conditions or environmental conditions. For example, role R1 originally has P1={read(A), write(B)}. If the conditions are not met, the restricted permissions May become ={read(A)};

[0211] S54, authority verification and dynamic modification;

[0212] Each time a user requests access, the system calculates the , verify the user's access rights;

[0213] If the verification is successful, the user can continue to access the data, otherwise the access will be denied;

[0214] The verification formula is:

[0215] ;

[0216] If it returns , then the access permission is allowed;

[0217] If it returns , access is denied.

[0218] Through the definition of roles and permissions, the problem of unclear or overly complex permission allocation in permission management is solved, and the flexibility and controllability of the system are improved. i Set a role R i and a set of permissions P i , which simplifies permission management. By clearly defining the permission set corresponding to each role, it ensures that the operation scope and operation permissions of each user are clearly defined. This method avoids the complexity of assigning permissions to each user individually, improves the efficiency of permission management, reduces the difficulty of management, and enhances the scalability of the system. By defining time conditions and environmental conditions, it solves the problem that traditional permission management cannot adapt to complex access control requirements. Set effective access time windows and environmental conditions for each role. i , introduced dynamic permission control based on time and environment. This method can adjust permissions according to actual conditions, for example, restricting a role from accessing certain data during non-working hours or in a specific location. By setting a specific time window and environmental conditions, such as geographic location and device type, ensure that permission access is more accurate and secure, and avoid abuse or misuse of permissions. The permission adjustment function solves the problem of dynamic changes in user permissions in complex scenarios, and improves the flexibility and real-time performance of access control. Based on the user's current role, time window and environmental conditions, the permission adjustment function dynamically calculates the final permission set. This function ensures that under certain conditions, the user's permissions will be adjusted according to actual needs, thereby preventing access to sensitive information under inappropriate conditions. For example, if a user originally has higher permissions, the permissions will be automatically restricted when the specific time or environmental conditions are not met, ensuring the security and flexibility of the system. Through permission verification and dynamic modification, the problem that static permissions in traditional permission management cannot cope with actual environmental changes is solved, and the security of the system is enhanced. Each time a user requests access, the system will re-verify the user's access rights based on the current time and environmental conditions to ensure that the user accesses the data under the specified time and environmental conditions. If the verification fails, access is denied to prevent illegal access. Through this mechanism, the system can perform dynamic permission control in real time according to the timeliness and environmental conditions of the user's request, effectively preventing abuse of permissions or unauthorized access.

[0219] The behavior analysis and anomaly detection specifically include:

[0220] S61, behavioral feature extraction;

[0221] Extract user behavior data B from system logs;

[0222] The behavior data includes the access data type R, access frequency F, time distribution T of data operation and operation mode M;

[0223] Define the behavior feature vector B as: B=(R, F, T, M);

[0224] S62, historical behavior model construction;

[0225] Constructing a useless historical behavior model is:

[0226] ;

[0227] in, , , , They are the data type, access frequency, data operation time and operation method corresponding to the i-th access;

[0228] S63, calculation of the difference between current behavior and historical behavior;

[0229] Compare current behavior Historical Behavior Model , calculate the deviation between current behavior and historical behavior :

[0230] ;

[0231] in, and are the data values ​​of the current behavior and the historical behavior in the i-th dimension, and m is the dimension of the feature vector;

[0232] Setting the deviation threshold ;

[0233] like , an abnormal alarm is triggered.

[0234] Through behavioral feature extraction, the problem of incomplete or difficult to quantify user behavior analysis in system logs is solved, and the accuracy of behavioral analysis is improved. User behavior data is extracted from system logs, including the type of data accessed, access frequency, time distribution of data operations, and operation methods, and user behavior is converted into a structured feature vector. Through this operation, every interactive behavior of users in the system can be fully captured, including the data they accessed, frequency, operation period and method, etc., thus laying the foundation for subsequent behavioral analysis and anomaly detection. This method solves the problem of unstructured information processing in traditional log data and improves the efficiency and accuracy of data analysis. Through the construction of historical behavior models, the problem of lack of historical data comparison and dynamic monitoring is solved, ensuring that behavioral analysis is based on real historical data. The historical behavior model is constructed to record the behavioral characteristics of each user in different time periods in history. The model provides a standardized reference for each user's behavior, ensuring that anomaly detection is based on the user's normal historical behavior trajectory, and avoiding misjudging accidental behavior as abnormal. This process makes behavioral analysis not only rely on current data, but also provides a more accurate judgment basis in combination with historical data. By calculating the difference between current behavior and historical behavior, the problem of how to monitor user behavior deviations and anomalies in real time is solved, and the system's anomaly detection capability is improved. Compare the current behavior with the historical behavior model, calculate the deviation between the current behavior and the historical behavior, and quantify the degree of abnormality of the user behavior. By setting the deviation threshold, when the deviation exceeds the set threshold, the system will trigger an abnormal alarm. This method can promptly discover abnormal patterns of user behavior and avoid potential security risks, such as abnormal frequent access, operations during non-working hours, abnormal data access, etc. Real-time deviation calculation and alarm mechanism can effectively improve the security of the system and prevent problems such as data leakage and account abuse.

[0235] This embodiment also provides a system for a patient data analysis and processing method, including:

[0236] Computing module: used for data calculation;

[0237] Information collection module: collects patient information, including personal information, medical records, and payment records; collects behavioral data of data visitors, including the type of data accessed, access frequency, time of data operations, and operation methods.

[0238] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.

[0239] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A patient data analysis and processing method, characterized in that: include: S1. Build an adaptive encryption mechanism; Obtain the patient's information data set after the patient agrees, denoted as W; The patient information data set is specifically, W = {patient personal information, medical record data, payment record}; Assign a sensitivity value S to each element in the patient information dataset i , the sensitivity value is between [0,10]; Count the access frequency F of each element in the patient information dataset in the past month i , the calculation formula is: F i is the access frequency of the i-th element in the patient information dataset; According to the sensitivity of the data S i and access frequency F i , calculate the encryption strength C i : Among them C i is the encryption strength of the i-th element in the patient information dataset; Set encryption strength threshold; Set the encryption algorithm set, denoted as AES, where AES = {AES-128, AES-256}; When C i When ≤ encryption strength threshold, the first element in the AES set is used to encrypt the i-th element in the patient information dataset; When C i > encryption strength threshold, the second element in the AES set is used to encrypt the i-th element in the patient information dataset; S2, secure computing based on data collaboration; The secure computing based on data collaboration specifically includes: Dynamically generate encryption key K based on the sensitivity of the data i : Among them, K i is the key of the i-th element in the patient information data set; mod is the modular operation; XOR encrypt each element in the patient information dataset: Among them, X i is the i-th element in the patient information dataset; K i is the key of the ith element in the patient information dataset; E(X i ) is the encrypted data of the i-th element in the patient information data set; Design a collaborative calculation function based on the cumulative sum calculation of encrypted data, and then perform encrypted data calculations on the two departments to obtain the encrypted results: Given multiple encrypted data items E(X1), E(X2), ..., E(X n ), and perform data accumulation calculation through collaborative computing: in, Indicates XOR operation; X i is the original value of the i-th data; E(X i ) is the encrypted value of the i-th data; n is the total number of data items; If the collaborative computing involves two-dimensional data, the data encryption calculation is performed through the two-dimensional collaborative computing function: Among them, X i,j is the element in the two-dimensional data, m and n are the number of rows and columns of the two-dimensional data; Based on the key K i , use the dynamic XOR decryption algorithm to decrypt data: S3, zero-knowledge proof based on custom verification protocol; The zero-knowledge proof based on the custom verification protocol specifically includes: S31, data encryption; For each data item X i Encryption is performed using encryption strength C i The XOR encryption algorithm is as follows: Among them, K i is the key of the i-th data item; X is the XOR operation; i is the i-th data item; E'(X i ) is the encrypted data; S32. Define zero-knowledge proof protocol; Set up a custom zero-knowledge proof protocol ZKP (X i ,[a,b]): Enter the encrypted data E'(X i ) and verification interval [a,b]; The output prover submits a zero-knowledge proof to the verifier without revealing X i The specific value of The certifier is specifically a party that proves that the data meets the conditions; The verifier is specifically a party that verifies whether the condition is satisfied; S33, Challenge-Response Mechanism; Challenge phase: The verifier randomly selects a challenge C, C∈{0,1}; Response phase: If C = 0, the prover needs to prove X i belongs to the interval [a,b]; If C = 1, the prover needs to generate encrypted data E'(X i ) and provide it to the verifier; The prover chooses a random number r, r∈{0,1}, and then performs encryption: Encrypt the random number r and send it to the verifier, and decide the content of the response based on the verifier's challenge C; S34, verification stage; If C = 0, the verifier determines whether the zero-knowledge proof provided by the prover satisfies E'(X i )∈[a,b], specifically: If the calculation result matches the verification value, the data X is successfully verified. i Satisfy X i ∈[a,b]; If C = 1, the verifier checks whether E(r) meets expectations; S4, Differential privacy protection with smart noise injection; The differential privacy protection of the intelligent noise injection specifically includes: For data X={X1,X2,...,X n } Perform statistical analysis and calculate the mean and standard deviation of data X: Generate noise N based on mean μx and standard deviation σx i : N i =N(μx,σ 2 x); Among them, N i is the noise of the ith data; N(μx,σ 2 x) is the noise N i Subject to mean μx and variance σ 2 Normal distribution of x; The noise N i Inject data and update the statistical results as follows: in, is the statistical result of the data after the noise is injected; f(X) is the statistical result of summing the data X; For each data item X i The sum of the added noise; S5. Permission management under dynamic roles and time conditions; The permission management under the dynamic role and time conditions specifically includes: S51, Role and authority definition; For each user U i Set a role R i and a set of permissions P i , where P i is a dataset containing all allowed operations; Permission Set P i ={p1, p2, ..., p k }, where p k Indicates the operation permissions of the feature; The specific correspondence between roles and permissions is as follows: R i →P i ; S52, definition of time conditions and environmental conditions; For each character R i Set a valid access time window T i and effective environmental conditions Q i ; The effective access time window T i Specifically, T i ∈[t start ,t end ], where t start is the earliest time to allow access, t end The latest time that access is allowed; The effective environmental conditions are specifically: i ={location i ,device i }, where location i is the geographic location, device i is the device type; S53, authority adjustment function; Based on the user's current role, time window, and environmental conditions, the final permission set is calculated through the permission adjustment function: Permission adjustment function G(R i ,T i ,Q i ) is in the form of: Among them, t current The current time requested by the user, Q current is the user's current environmental condition, P restricted is a restricted set of permissions; S54, authority verification and dynamic modification; Each time a user requests access, the system calculates G(R i ,T i ,Q i ), verify the user's access rights; If the verification is successful, the user can continue to access the data, otherwise the access will be denied; The verification formula is: If it returns True, the access permission is allowed; If it returns False, access is denied; S6, behavior analysis and anomaly detection; The behavior analysis and anomaly detection specifically include: S61, behavioral feature extraction; Extract user behavior data B from system logs; The behavior data includes the access data type R, access frequency F, time distribution T of data operation and operation mode M; Define the behavior feature vector B as: B = (R, F, T, M); S62, historical behavior model construction; Constructing a useless historical behavior model is: Among them, R i , F i , T i , M i They are the data type, access frequency, data operation time and operation method corresponding to the i-th access; S63, calculation of the difference between current behavior and historical behavior; Compare current behavior B current With historical behavior model B history , calculate the deviation ΔB between current behavior and historical behavior: in, and are the data values ​​of the current behavior and the historical behavior in the i-th dimension, and m is the dimension of the feature vector; Set the deviation threshold ∈; If ΔB>∈, an abnormal alarm is triggered.

2. A system using the patient data analysis and processing method according to claim 1, characterized in that: include: Computing module: used for data calculation; Information collection module: collects patient information, including personal information, medical records, and payment records; Collect behavioral data of data visitors, including the type of data accessed, access frequency, time of data operations, and operation methods.

Citation Information

Patent Citations

  • File encryption method and device, computer equipment and storage medium

    CN118013557A

  • Private data protection method and system based on homomorphic encryption and federated learning

    CN119513919A