Internet-based Medical Data Security Monitoring Method and System

By slicing medical data in segments, prioritizing and dynamic migration, and performing data integrity verification, the problem of difficulty in monitoring illegal unification behavior in the existing technology is solved, and efficient safety monitoring and protection of medical data is achieved.

CN119783174BActive Publication Date: 2025-06-20CROSS STRAIT TSINGHUA RESEARCH INSTITUTE +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510284574.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-06-20
Estimated Expiration
2045-03-11

AI Technical Summary

Technical Problem

In medical data processing, it is difficult for the existing technology to effectively monitor and prevent illegal acts of the party, especially in the complex and changeable environment of statistical data, and it is difficult to distinguish the boundaries between operational analysis and suspicious data aggregation.

Method used

By storing medical data in segments according to the preset data size threshold, and giving different storage priorities and migration strategies to different storage areas, dynamically migrate data segments and perform data integrity verification on the migrated data to monitor and trace illegal unification behavior.

Benefits of technology

It has increased the difficulty of illegal unified behavior, enhanced the security and integrity of medical data, ensured that key information within the hospital is not abused, and effectively prevented the occurrence of illegal unified behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119783174B_ABST
    Figure CN119783174B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for monitoring the security of medical data based on the Internet. The method includes: segmenting and storing medical data according to a preset data volume size threshold T1; assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively; determining whether the storage duration t of the data segment is greater than a preset migration threshold T2. If so, migrating the data segment stored in the first storage area of the local server to the third storage area of the cloud server, or migrating from the second storage area of the cloud server to the fourth storage area of the local server; performing data integrity verification on the migrated data segment. Through the solution of the present invention, the difficulty of illegal prescription statistics behavior can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of medical data processing, and particularly relates to a method and system for monitoring the security of medical data based on the Internet. Background Art

[0002] The security monitoring of medical data based on the Internet aims to protect the data privacy and integrity in medical institutions. By constructing a multi-level security protection system, it realizes the effective identification and prevention of various risk factors during network transmission, storage, and access processes, ensuring that doctors' and patients' information is not leaked or tampered with. However, in practical applications, there are also some problems, such as how to monitor illegal behavior of statistical data access. Due to the complexity and variability of statistical data in the medical environment, there is no absolutely clear boundary between normal operation analysis and suspicious data aggregation; under the premise of not affecting the daily work efficiency of the hospital, accurately capturing abnormal activities requires more refined design and higher technical requirements. Summary of the Invention

[0003] In view of this, the present invention provides a method and system for monitoring the security of medical data based on the Internet, which at least partially solves the problems existing in the prior art.

[0004] A method for monitoring the security of medical data based on the Internet in this application includes:

[0005] Segment and store medical data according to a preset data volume size threshold T1, where data segments with a data volume size less than or equal to the threshold T1 are stored in the first storage area of the local server, and data segments with a data volume size greater than the threshold T1 are stored in the second storage area of the cloud server;

[0006] Assign different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively. The priority P1 of the data segments in the first storage area of the local server is higher than the priority P2 of the data segments in the second storage area of the cloud server, and when a data access request is detected, the data segments with a higher priority are preferentially accessed and verified;

[0007] Judge whether the storage duration t of the data segment is greater than a preset migration threshold T2. If so, migrate the data segment stored in the first storage area of the local server to the third storage area of the cloud server, or migrate it from the second storage area of the cloud server to the fourth storage area of the local server;

[0008] Perform data integrity verification on the migrated data segments to monitor and trace illegal behavior of statistical data access.

[0009] Furthermore, the migration threshold T2 is set according to the security level and update frequency of the data.

[0010] Furthermore, performing data integrity verification on the migrated data segment includes comparing whether the hash value H of the data segment is equal to the pre-stored standard hash value H0. If they are not equal, it is determined that there is a risk of data tampering, a security alarm is triggered, and relevant data information is recorded.

[0011] Furthermore, after the step of storing the medical data in segments according to a preset data volume size threshold T1, the following steps are also included:

[0012] Determine the storage density D of the data segment;

[0013] Classify the data segments according to the storage density D. The data segments with a storage density greater than the preset density threshold D0 are stored in the fifth storage area of the local server, and the data segments with a storage density less than or equal to the preset density threshold D0 are stored in the sixth storage area of the cloud server;

[0014] Assign different storage redundancies R to the data segments stored in the fifth storage area of the local server and the sixth storage area of the cloud server. The redundancy of the data segments in the fifth storage area of the local server is R1, and the redundancy of the data segments in the sixth storage area of the cloud server is R2, and R1 < R2. When a data loss risk is detected, data recovery is performed according to the redundancy;

[0015] Judge whether the storage frequency f of the data segment is greater than the preset frequency threshold F1. If so, migrate the data segment stored in the fifth storage area of the local server to the seventh storage area of the cloud server, or migrate it from the sixth storage area of the cloud server to the eighth storage area of the local server.

[0016] Furthermore, after the step of assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server, the following steps are also included:

[0017] Calculate the access popularity H of the data segment;

[0018] Sort the data segments according to the access popularity H, and the data segments with high access popularity are preferentially processed in the data access request queue;

[0019] Set the storage validity period E of the data segment. When the storage duration t is greater than the storage validity period E, upgrade the encryption strength of the data segment. The data segment with the upgraded encryption strength is stored in the ninth storage area of the local server or the tenth storage area of the cloud server;

[0020] Judge whether the access source O of the data segment belongs to the preset trusted source set Ω. If it belongs to the trusted source set, normal data access verification is performed. If it does not belong to the trusted source set, increase the difficulty coefficient K of the data access verification.

[0021] Further, after the step of determining whether the storage duration t of the data segment is greater than a preset migration threshold T2, the following steps are further included:

[0022] Calculate the storage cost C of the data segment;

[0023] Screen the data segments according to the storage cost C, and the data segments with a storage cost higher than the preset cost threshold C0 are preferentially migrated;

[0024] Perform data backup on the migrated data segment. The backup data is stored in the eleventh storage area of the local server and the twelfth storage area of the cloud server, and the synchronization update period of the backup data and the original data is T3;

[0025] Judge whether the access frequency change rate of the data segment is greater than a preset change rate threshold F2. If so, adjust the storage location and storage priority of the data segment.

[0026] Further, the method further includes:

[0027] When the storage density D is greater than or equal to a preset density threshold D0 and the storage time t is greater than a preset time threshold T4, store the data segment in the thirteenth storage area of the local server; otherwise, store it in the fourteenth storage area of the cloud server;

[0028] Assign different storage access restrictions L to the data segments stored in the thirteenth storage area of the local server and the fourteenth storage area of the cloud server. The access restriction of the data segment in the thirteenth storage area of the local server is L1, and the access restriction of the data segment in the fourteenth storage area of the cloud server is L2, and L1 > L2;

[0029] Judge whether the number of storage location change times M of the data segment is greater than a preset change number threshold M0. If so, upgrade the data encryption algorithm for the data segment.

[0030] Further, the method further includes:

[0031] Set different preset density thresholds De0 for the data segments of different departments. When the storage density D is greater than or equal to the corresponding preset density threshold De0, store the data segment in the fifteenth storage area of the local server; otherwise, store it in the sixteenth storage area of the cloud server;

[0032] Assign different storage audit levels A to the data segments stored in the fifteenth storage area of the local server and the sixteenth storage area of the cloud server. The audit level of the data segment in the fifteenth storage area of the local server is A1, and the audit level of the data segment in the sixteenth storage area of the cloud server is A2, and A1 > A2;

[0033] Determine whether the permission level Pd of the doctor to whom the data segment belongs is greater than or equal to the preset permission condition Pd0. If so, allow partial sensitive data operations on the data segment; otherwise, prohibit sensitive data operations.

[0034] A medical data security monitoring system based on the Internet according to the present application includes:

[0035] A segmentation module for segmenting and storing medical data according to a preset data volume size threshold T1, where data segments with a data volume size less than or equal to the threshold T1 are stored in the first storage area of the local server, and data segments with a data volume size greater than the threshold T1 are stored in the second storage area of the cloud server;

[0036] A priority determination module for respectively assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server, where the priority of the data segments in the first storage area of the local server, P1, is higher than the priority of the data segments in the second storage area of the cloud server, P2, and when a data access request is detected, access verification is preferentially performed on the data segments with a higher priority;

[0037] A judgment module for judging whether the storage duration t of the data segment is greater than a preset migration threshold T2. If so, migrate the data segment stored in the first storage area of the local server to the third storage area of the cloud server, or migrate from the second storage area of the cloud server to the fourth storage area of the local server;

[0038] An integrity verification module for performing data integrity verification on the migrated data segment to monitor and trace illegal statistical behavior.

[0039] The present invention provides a method and system for monitoring the security of medical data based on the Internet. The method includes: segmenting and storing medical data according to a preset data volume size threshold T1; respectively assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server; judging whether the storage duration t of the data segment is greater than a preset migration threshold T2. If so, migrate the data segment stored in the first storage area of the local server to the third storage area of the cloud server, or migrate from the second storage area of the cloud server to the fourth storage area of the local server; performing data integrity verification on the migrated data segment. Through the solution of the present invention, the difficulty of illegal statistical behavior can be increased. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] To more clearly illustrate the technical solutions of the exemplary embodiments of the present disclosure, the following will briefly introduce the accompanying drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present disclosure, and thus should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0041] Figure 1 is a flowchart of the method for monitoring the security of medical data based on the Internet in this application;

[0042] Figure 2 is a flowchart of the steps after segmenting and storing medical data according to a preset data volume threshold T1;

[0043] Figure 3 is a flowchart of the steps after assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively;

[0044] Figure 4 is a flowchart of the steps after determining whether the storage duration t of the data segment is greater than a preset migration threshold T2;

[0045] Figure 5 is a flowchart of the method for monitoring the security of medical data based on the Internet in another embodiment of this application;

[0046] Figure 6 is a flowchart of the method for monitoring the security of medical data based on the Internet in yet another embodiment of this application;

[0047] Figure 7 is a structural block diagram of the system for monitoring the security of medical data based on the Internet in this application. Detailed implementation manners

[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer and more understandable, the following will further elaborate on the embodiments of the present disclosure in combination with the embodiments and the accompanying drawings. The illustrative embodiments and their descriptions of the present disclosure are only used to explain the embodiments of the present disclosure and do not limit the embodiments of the present disclosure.

[0049] Next, referring to the accompanying drawings, the method for monitoring the security of medical data based on the Internet of the present invention will be described. This method realizes the effective monitoring of illegal prescription statistics behavior through multiple key steps such as segmenting and storing medical data, setting priorities, dynamic migration, and integrity verification. These measures can enhance the security and integrity of the data, ensure that the key information within a hospital or medical institution is not misused, and especially prevent the occurrence of illegal prescription statistics (i.e., using the statistics of doctor's prescription volumes for commercial promotion or other non-medical purposes) behavior.

[0050] In addition, it should be understood that in this application, storage areas belonging to the same local server, such as the first storage area, the fourth storage area, etc., can be different storage areas or in a subset relationship. For example, the fourth storage area can be a subset of the first storage area or an independent storage area. The same applies to the storage areas of cloud servers.

[0051] First, refer to Figure 1 to describe the Internet-based medical data security monitoring method of this application.

[0052] S101: Segment and store medical data according to a preset data volume size threshold T1. Among them, data segments with a data volume size less than or equal to the threshold T1 are stored in the first storage area of the local server, and data segments with a data volume size greater than the threshold T1 are stored in the second storage area of the cloud server.

[0053] Specifically, first, it is necessary to evaluate the data volume size of medical data, which can be carried out by means of data byte length or other appropriate data volume measurement methods. Then, data segments with a data volume size less than or equal to the threshold T1 are stored in the first storage area of the local server, while data segments with a data volume size greater than the threshold T1 are stored in the second storage area of the cloud server. The setting of the preset data volume size threshold T1 is crucial and is determined according to the type and importance of medical data. For example, for some routine patient basic information data, such as name, age, gender, etc., the data volume is relatively small and the importance is relatively low, and a relatively small T1 value can be set to store this part of the data in the first storage area of the local server. For some complex medical image data, gene detection data, etc., the data volume is huge and contains important diagnostic information, and a relatively large T1 value is set to store these data in the second storage area of the cloud server. Through such a differential storage method, the difficulty for illegal prescription trading behavior to obtain complete data is increased. Because it is difficult for illegal prescription trading actors to obtain a large amount of data from both the local and cloud sides at the same time, and the dispersed storage of data also reduces the risk of data leakage.

[0054] For example, in an embodiment, the electronic medical record system of a certain hospital adopts this segmented storage method. For the daily outpatient records of patients, the data volume is small and they are stored in the first storage area of the local server. For the surgical video records of patients, the data volume is huge and they are stored in the second storage area of the cloud server. In this way, even if illegal prescription trading actors obtain the data of the local server, they cannot obtain complete medical data, thus effectively protecting the privacy of patients and the security of medical data.

[0055] S102: Different storage priorities are assigned to the data segments stored in the first storage area of the local server and the second storage area of the cloud server. Among them, the priority of the data segment in the first storage area of the local server is P1, which is higher than the priority of the data segment in the second storage area of the cloud server, which is P2. And when a data access request is detected, the access verification is preferentially performed on the data segment with a higher priority.

[0056] After the data is segmented and stored, different storage priorities are assigned to the data segments stored in the first storage area of the local server and the second storage area of the cloud server. The priority of the data segment in the first storage area of the local server is P1, and the priority of the data segment in the second storage area of the cloud server is P2, and P1 is greater than P2. When a data access request is detected, the access verification is preferentially performed on the data segment with a higher priority. The purpose of this is to protect key data during the data access process by setting different storage priorities.

[0057] Specifically, the data segments stored in the local server are usually relatively important and frequently accessed data, so a higher priority P1 is assigned. When a data access request occurs, the system will preferentially perform access verification on these high-priority data segments to ensure that only legitimate access requests can obtain these key data. Although the data segments stored in the cloud server have a large amount of data, their importance and access frequency are relatively low, so a lower priority P2 is assigned. Through this setting of priorities, the security of key data can be more effectively protected under limited resource conditions. For example, in an embodiment, in the medical data storage system of a medical institution, the data segment of the patient's diagnosis report stored in the local server is assigned a higher priority P1. When a doctor needs to consult a patient's diagnosis report, the system will preferentially perform access verification on these data segments to ensure that the doctor can quickly obtain the required key data. And the data segment of the patient's historical imaging stored in the cloud server is assigned a lower priority P2, and access verification will only be performed when necessary, thus avoiding unnecessary resource waste.

[0058] S103: Determine whether the storage duration t of the data segment is greater than the preset migration threshold T2. If so, migrate the data segment stored in the first storage area of the local server to the third storage area of the cloud server, or migrate it from the second storage area of the cloud server to the fourth storage area of the local server.

[0059] Specifically, it is determined whether the storage duration t of the data segment is greater than a preset migration threshold T2. If the storage duration t of the data segment is greater than the preset migration threshold T2, the data segment stored in the first storage area of the local server is migrated to the third storage area of the cloud server, or migrated from the second storage area of the cloud server to the fourth storage area of the local server. The preset migration threshold T2 is set according to the security level and update frequency of the data. By dynamically migrating the data and changing the storage location of the data, it is difficult for illegal data integration behavior to predict the storage location of the data, thereby improving the accuracy of monitoring illegal data integration behavior.

[0060] Specifically, when the data segment is stored in the local server for too long, the risk of data leakage may increase. At this time, migrating the data segment to the third storage area of the cloud server can utilize the high security and large-scale storage advantages of the cloud server to further protect the security of the data. On the contrary, when the data segment is stored in the cloud server for too long, the access efficiency of the data may decrease. At this time, migrating the data segment to the fourth storage area of the local server can improve the access speed of the data and meet the needs of medical services. For example, in one embodiment, in the medical data storage system of a certain hospital, after the daily examination data of patients is stored in the local server for a period of time, if the storage duration exceeds the preset migration threshold T2, it will be migrated to the third storage area of the cloud server. In this way, even if an illegal data integration actor obtains the data of the local server, they cannot obtain complete medical data, thereby effectively improving the accuracy of monitoring illegal data integration behavior.

[0061] S104: Perform data integrity verification on the migrated data segment to monitor and trace illegal data integration behavior.

[0062] Specifically, data integrity verification is performed on the migrated data segment. The specific method is to verify by comparing whether the hash value H of the data segment is equal to the pre-stored standard hash value H0. If the hash value H is not equal to the pre-stored standard hash value H0, it is determined that there is a risk of data tampering, a security alarm is triggered, and relevant data information is recorded for monitoring and tracing illegal data statistics behaviors. The hash value is a fixed-length string calculated from the data segment through a hash algorithm. When any tiny change occurs in the data segment, its hash value will change significantly. Therefore, by comparing the hash values, it is possible to effectively detect whether the data has been tampered with. For example, in an embodiment, in the medical data storage system of a medical institution, after the patient's data segment is migrated to the third storage area of the cloud server, the system automatically calculates its hash value H and compares it with the pre-stored standard hash value H0. If it is found that the hash value H is not equal to the pre-stored standard hash value H0, the system immediately triggers a security alarm and records relevant data information, such as the storage location and access records of the data segment. In this way, even if an illegal data statistics actor tampers with the data, it can be discovered and traced in time, thus effectively protecting the security of medical data.

[0063] As Figure 2 shown, in this application, after the step of storing medical data in segments according to a preset data volume size threshold T1, the following steps are further included.

[0064] S201: Determine the storage density D of the data segment. In a specific embodiment, the storage density D can be calculated according to the formula D = S / V, where S represents the data volume size of the data segment, usually in bytes (Byte), and the range can be from KB to TB, etc.; V represents the storage space volume of the data segment, usually measured by the number of storage units, etc. This formula is used to measure the tightness of the data in the storage space for more refined classification management of the data segment. For example, in an embodiment, the data volume size S of a certain data segment is 10MB, and the storage space volume V is 10,000 storage units, then its storage density D = 10MB / 10,000 = 0.001MB / storage unit.

[0065] S202: Classify the data segments according to the storage density D. The data segments with a storage density greater than the preset density threshold D0 are stored in the fifth storage area of the local server, and the data segments with a storage density less than or equal to the preset density threshold D0 are stored in the sixth storage area of the cloud server.

[0066] Specifically, the preset density threshold D0 can be set according to the historical data storage situation and the performance of the storage device. For example, historical data shows that for data segments with a storage density above 0.002 MB per storage unit, their storage efficiency and security need to be focused on. At the same time, considering factors such as the read / write speed and storage capacity of the storage device, D0 is determined comprehensively. Data segments with a storage density greater than D0 are stored in the fifth storage area of the local server, and those less than or equal to D0 are stored in the sixth storage area of the cloud server. For example, if D0 is set to 0.002 MB per storage unit, the data segment with the calculated storage density D of 0.001 MB per storage unit will be stored in the sixth storage area of the cloud server.

[0067] S203: Different storage redundancies R are assigned to the data segments stored in the fifth storage area of the local server and the sixth storage area of the cloud server respectively. The redundancy of the data segments in the fifth storage area of the local server is R1, and the redundancy of the data segments in the sixth storage area of the cloud server is R2, and R1 < R2. When the risk of data loss is detected, data recovery is performed according to the redundancy.

[0068] Specifically, different storage redundancies R are assigned to the data segments stored in the fifth storage area of the local server and the sixth storage area of the cloud server respectively. The redundancy of the data segments in the fifth storage area of the local server is R1, and the redundancy of the data segments in the sixth storage area of the cloud server is R2, and R1 < R2. When the risk of data loss is detected, data recovery is performed according to the redundancy. For example, the redundancy R1 of the data segments in the fifth storage area of the local server is set to 1, that is, only one data copy is retained; the redundancy R2 of the data segments in the sixth storage area of the cloud server is set to 3, that is, three data copies are retained. This setting is because the data segments stored in the local server usually have a relatively high access frequency and a relatively small data volume. To ensure access efficiency and storage cost, the redundancy is relatively low; the data segments stored in the cloud server have a large data volume and a relatively low access frequency. Through a higher redundancy, key data can be more effectively recovered in case of data loss, increasing the obstacle to illegal access to medical records.

[0069] S204: Determine whether the storage frequency f of the data segment is greater than the preset frequency threshold F1. If so, migrate the data segment stored in the fifth storage area of the local server to the seventh storage area of the cloud server, or migrate it from the sixth storage area of the cloud server to the eighth storage area of the local server.

[0070] Specifically, it is determined whether the storage frequency f of the data segment is greater than a preset frequency threshold F1. The frequency threshold F1 is set according to the usage frequency and importance of the data. For example, for some frequently accessed and important patient diagnosis data, with a high usage frequency and great importance, F1 is set to 10 times a day; for some infrequently accessed patient historical physical examination data, F1 is set to 1 time a week. If the storage frequency f is greater than F1, the data segment in the fifth storage area of the local server is migrated to the seventh storage area of the cloud server, or migrated from the sixth storage area of the cloud server to the eighth storage area of the local server. For example, if the storage frequency f of a certain data segment is 15 times a day, which is greater than the preset frequency threshold F1 of 10 times a day, a data migration operation will be triggered. By migrating the data based on the storage frequency, it is difficult for illegal prescription trading behavior to grasp the storage pattern of the data, thereby improving the accuracy of monitoring illegal prescription trading behavior.

[0071] In addition, as Figure 3 shown, in this application, after the step of assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively, the following steps are further included.

[0072] S301: Calculate the access popularity H of the data segment. After assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively, it is first necessary to calculate the access popularity H of the data segment. There are various calculation methods for the access popularity H. For example, it can be comprehensively calculated based on parameters such as the number of accesses, access frequency, and access time interval of the data segment within a certain period of time. Specifically, a time window can be set, and the number of times the data segment is accessed within this time window is counted. At the same time, considering the time interval between each access, the data segment with more access times and shorter time intervals has a higher access popularity H. For example, in an embodiment, for a certain medical data segment A, it is accessed 10 times within the past 1 hour, and the average time interval between each access is 5 minutes, then its access popularity H can be calculated as H = 10 / 5 = 2. By calculating the access popularity H, the popularity of the data segment can be quantitatively evaluated, providing a basis for subsequent sorting and access control.

[0073] S302: Sort the data segments according to the access heat H, and the data segments with high access heat are processed preferentially in the data access request queue. After calculating the access heat H of the data segments, sort the data segments according to the access heat H. The specific operation is to arrange all the data segments in descending order of their access heat H to form a sorted list. The data segments with high access heat are ranked in the front of the sorted list, and the data segments with low access heat are ranked at the back. For example, in an embodiment, there are three data segments A, B, and C, and their access heats H are 2, 3, and 1 respectively, then the sorted order is B, A, C. By sorting the data segments, it can be determined which data segments are the most concerned currently, so as to process the data segments with high access heat preferentially in the data access request queue, improving the efficiency and response speed of data access.

[0074] S303: Set the storage validity period E of the data segment. When the storage duration t is greater than the storage validity period E, upgrade the encryption strength of the data segment, and the data segment with the upgraded encryption strength is stored in the ninth storage area of the local server or the tenth storage area of the cloud server. Next, set the storage validity period E of the data segment. The storage validity period E is a time value preset according to factors such as the type, importance, and business requirements of the data segment, indicating the time length during which the data segment is valid in the storage system. When the storage duration t of the data segment is greater than the storage validity period E, it is considered that the data segment has exceeded its valid period. For example, in an embodiment, for the basic information data segment of a certain type of patient, set its storage validity period E to 1 year. When the storage time of this data segment exceeds 1 year, it is necessary to upgrade its encryption strength. By setting the storage validity period E, the life cycle of the data segment can be managed, ensuring the security and reliability of the data within the valid period, and at the same time providing a trigger condition for the upgrade of the data encryption strength.

[0075] S304: Determine whether the access source O of the data segment belongs to the preset trusted source set Ω. If it belongs to the trusted source set, perform normal data access verification. If it does not belong to the trusted source set, increase the difficulty coefficient K of data access verification. Finally, determine whether the access source O of the data segment belongs to the preset trusted source set Ω. The preset trusted source set Ω is a set of sources that are predefined according to the security policies and business requirements of medical data and are allowed to access the data segment, such as certain specific departments within the hospital, the work terminals of doctors, etc. The specific operation is to compare the source of the access request with the trusted source set Ω. If the access source O belongs to the trusted source set Ω, perform normal data access verification and allow the access request to pass; if the access source O does not belong to the trusted source set Ω, increase the difficulty coefficient K of data access verification, such as adding additional verification steps, increasing the complexity of verification, etc., to prevent illegal access. For example, in one embodiment, the trusted source set Ω includes the work terminals of departments such as the internal medicine department, surgery department, and laboratory department of the hospital. When an access request from an external network attempts to access a certain data segment, since its access source O does not belong to the trusted source set Ω, the system will increase the difficulty coefficient K of data access verification and require the visitor to provide more identity verification information, thereby effectively preventing illegal behavior of collating medical data.

[0076] As Figure 4 shown, in this application, after the step of determining whether the storage duration t of the data segment is greater than the preset migration threshold T2, the following steps are further included.

[0077] S401: Calculate the storage cost C of the data segment. Specifically, after determining whether the storage duration t of the data segment is greater than the preset migration threshold T2, first calculate the storage cost C of the data segment. The specific operation is to calculate through the formula C = c×S / B, where c represents the storage cost coefficient per unit data volume, which is usually determined according to factors such as the hardware cost and maintenance cost of the storage device, and the range can be from a few yuan to dozens of yuan per GB. The optimal value needs to be combined with the market situation and the hospital budget; S is the data volume size of the data segment, in bytes (Byte), and the range is from KB to TB, etc.; B is the storage efficiency of the storage device, usually measured by the amount of data that can be read and written per second, and the range is from MB / s to GB / s, etc. For example, in one embodiment, the data volume size S of a certain data segment is 10GB, the storage efficiency B of the storage device is 100MB / s, and the storage cost coefficient c per unit data volume is 0.1 yuan / GB, then its storage cost C = 0.1×10 / 100 = 0.01 yuan. This formula is used to quantify the cost consumption of the data segment during storage, so as to perform more reasonable screening and management of the data segment.

[0078] S402: Screen the data segments according to the storage cost C, and give priority to migrating the data segments with a storage cost higher than the preset cost threshold C0. Screen the data segments according to the calculated storage cost C. The specific operation is to screen out the data segments with a storage cost higher than the preset cost threshold C0 and give priority to migrating them. The preset cost threshold C0 is set according to the hospital's storage budget and data management strategy. For example, if the hospital hopes to control the storage cost within 0.05 yuan per GB, then set C0 to 0.05 yuan. In this way, for the data segment with the calculated storage cost C of 0.01 yuan, since it is lower than the preset cost threshold C0, it will not be migrated temporarily; while for another data segment with a storage cost C of 0.06 yuan, which is higher than the preset cost threshold C0, it will be migrated first. By screening the data segments, the data segments with higher storage costs can be processed first, optimizing the utilization of storage resources and improving the storage management efficiency of the hospital.

[0079] S403: Perform data backup on the migrated data segments. The backup data is stored in the eleventh storage area of the local server and the twelfth storage area of the cloud server, and the synchronization update period between the backup data and the original data is T3. Specifically, make a copy of the migrated data segments and store them in the specified storage areas of the local and the cloud respectively. The synchronization update period between the backup data and the original data is T3. For example, set T3 to once a day. In this way, when the original data is updated, the backup data will be synchronously updated at a specified time every day to ensure the timeliness and accuracy of the backup data. Through data backup and synchronous update, it can be quickly restored when the data is damaged by illegal data access behavior, ensuring the integrity and availability of medical data. For example, in one embodiment, the medical data of a certain hospital was backed up after migration. When it was found that the data was damaged by illegal data access behavior, the original data was quickly restored through the backup data, ensuring the normal operation of the hospital.

[0080] S404: Determine whether the change rate of the access frequency of the data segment is greater than a preset change rate threshold F2. If so, adjust the storage location and storage priority of the data segment. Specifically, calculate the change rate of the access frequency of the data segment within a certain period of time. For example, by comparing the current access frequency with the average access frequency over a past period of time, the change rate is calculated. The preset change rate threshold F2 is set according to the business requirements and data security policies of the hospital. For example, F2 is set to 50%. When the change rate of the access frequency of the data segment is greater than F2, it is considered that there may be potential illegal statistical party behavior. For example, the average access frequency of a certain data segment was 10 times per day in the past week, and the current access frequency is 15 times per day. The change rate is (15 - 10) / 10 = 50%, which is equal to the preset change rate threshold F2, then the adjustment mechanism is triggered. By monitoring the change rate of the access frequency, potential illegal statistical party behavior can be detected in a timely manner and measures can be taken to improve the data security protection ability of the hospital.

[0081] In addition, when it is determined that the change rate of the access frequency of the data segment is greater than the preset change rate threshold F2, adjust the storage location and storage priority of the data segment. The specific operation is to migrate the data segment from the current storage location to other storage locations, such as from a local server to a cloud server, or from a cloud server to a local server. At the same time, adjust the storage priority of the data segment. For example, adjust the storage priority from P1 to P2, or from P2 to P1. By adjusting the storage location and storage priority, the access path and access difficulty of the data segment can be changed, further increasing the difficulty of illegal statistical party behavior. For example, in one embodiment, a data segment of a certain hospital was migrated from a local server to a cloud server and the storage priority was adjusted due to the change rate of the access frequency being greater than the preset threshold, effectively preventing the occurrence of illegal statistical party behavior.

[0082] Next, refer to Figure 5 , and describe another embodiment of the present application.

[0083] S501: When the storage density D is greater than or equal to the preset density threshold D0 and the storage time t is greater than the preset time threshold T4, store the data segment in the thirteenth storage area of the local server; otherwise, store it in the fourteenth storage area of the cloud server. Specifically, first obtain the storage density D and storage time t of the data segment, and then compare them with the preset density threshold D0 and time threshold T4. For example, in one embodiment, the storage density D of a certain data segment is 0.002 MB / storage unit, and the preset density threshold D0 is 0.001 MB / storage unit; the storage time t is 30 days, and the preset time threshold T4 is 15 days. Since D > D0 and t > T4, this data segment is stored in the thirteenth storage area of the local server. By introducing the storage time factor, the data storage can be arranged more reasonably, and the difficulty for illegal data access behavior to obtain long-term stored data can be increased.

[0084] S502: Assign different storage access restrictions L to the data segments stored in the thirteenth storage area of the local server and the fourteenth storage area of the cloud server. The access restriction for the data segment in the thirteenth storage area of the local server is L1, and the access restriction for the data segment in the fourteenth storage area of the cloud server is L2, and L1 > L2. Specifically, set the corresponding access restriction parameters according to the storage location of the data segment. For example, in one embodiment, the access restriction L1 for the data segment in the thirteenth storage area of the local server is that double-factor authentication is required for each access, including entering the username and password, and receiving a mobile phone SMS verification code; the access restriction L2 for the data segment in the fourteenth storage area of the cloud server is that only the username and password need to be entered for each access. When a data access request is detected, perform corresponding access control according to the access restriction. By setting different storage access restrictions, key data can be protected more effectively.

[0085] S503: Determine whether the number of storage location changes M of the data segment is greater than a preset change number threshold M0. If so, upgrade the data encryption algorithm for the data segment. Specifically, record the number of location changes of the data segment during storage and then compare it with the preset change number threshold M0. For example, in one embodiment, a certain data segment is migrated from the thirteenth storage area of the local server to the fourteenth storage area of the cloud server during storage, and then migrated from the fourteenth storage area of the cloud server back to the thirteenth storage area of the local server. The number of storage location changes M is 2, and the preset change number threshold M0 is 1. Since M > M0, the data encryption algorithm for the data segment is upgraded. Triggering the encryption algorithm upgrade by frequently changing the storage location can enhance the security of the data and make it more difficult for illegal data access behavior to obtain valid data. For example, in one embodiment, the AES-128 encryption algorithm is originally used to encrypt the data segment. Since the number of storage location changes M is greater than the preset threshold M0, it is upgraded to the AES-256 encryption algorithm. This can further improve the security of the data and prevent illegal data access behavior from obtaining valid data.

[0086] Next, refer to Figure 6 to describe another embodiment of the present application.

[0087] S601: Set different preset density thresholds De0 for the data segments of different departments. When the storage density D is greater than or equal to the corresponding preset density threshold De0, the data segment is stored in the fifteenth storage area of the local server; otherwise, it is stored in the sixteenth storage area of the cloud server. Specifically, determine the corresponding density threshold according to the data characteristics and business requirements of each department. For example, for the data segments of the radiology department, since its data volume is usually large and the storage density requirement is high, a relatively high preset density threshold De0 can be set; while for the data segments of the general internal medicine department, the data volume is relatively small and the storage density requirement is low, a relatively low preset density threshold De0 can be set. When the storage density D is greater than or equal to the corresponding preset density threshold De0, the data segment is stored in the fifteenth storage area of the local server; otherwise, it is stored in the sixteenth storage area of the cloud server. For example, in one embodiment, the preset density threshold De0 for the radiology department is 0.002 MB / storage unit, and the preset density threshold De0 for the general internal medicine department is 0.001 MB / storage unit. By considering department factors, storage optimization can be carried out according to the data characteristics of different departments, and the difficulty for illegal data access behavior to obtain data of specific departments can be increased.

[0088] S602: Different storage audit levels A are assigned to the data segments stored in the fifteenth storage area of the local server and the sixteenth storage area of the cloud server. The audit level of the data segment in the fifteenth storage area of the local server is A1, and the audit level of the data segment in the sixteenth storage area of the cloud server is A2, and A1 > A2. Specifically, according to the storage location of the data segment, the corresponding audit level is set. For example, in one embodiment, the audit level A1 of the data segment in the fifteenth storage area of the local server is a high-level audit, the audit period is once a day, and the audit content includes data access records, data modification records, etc.; the audit level A2 of the data segment in the sixteenth storage area of the cloud server is a medium-level audit, the audit period is once a week, and the audit content includes data access records, etc. When performing data auditing, audit operations of corresponding intensity are carried out according to the audit level. By setting different storage audit levels, data can be supervised more effectively, and illegal statistics collection behavior can be prevented.

[0089] S603: Determine whether the permission level Pd of the doctor to whom the data segment belongs is greater than or equal to the preset permission condition Pd0. If so, allow the data segment to perform partial sensitive data operations; otherwise, prohibit sensitive data operations. Specifically, determine whether the permission level Pd of the doctor to whom the data segment belongs is greater than or equal to the preset permission condition Pd0. The specific operation is to obtain the doctor's permission level information and compare it with the preset permission condition. For example, in one embodiment, the preset permission condition Pd0 is a high-level permission, and only doctors with high-level permissions can perform partial sensitive data operations. If the doctor's permission level Pd is greater than or equal to the preset permission condition Pd0, allow the data segment to perform partial sensitive data operations; otherwise, prohibit sensitive data operations. For example, a certain doctor's permission level Pd is a high-level permission, which is greater than or equal to the preset permission condition Pd0. Therefore, this doctor can perform sensitive data operations on the data segment, such as data modification, data deletion, etc. Through permission level control, it can be ensured that only authorized personnel can perform specific data operations, reducing the risk of illegal statistics collection behavior.

[0090] In addition, as Figure 7 shown, the present application also provides an Internet-based medical data security monitoring system 700, including:

[0091] A segmentation module 701, configured to segment and store medical data according to a preset data volume size threshold T1, where the data segment with a data volume size less than or equal to the threshold T1 is stored in the first storage area of the local server, and the data segment with a data volume size greater than the threshold T1 is stored in the second storage area of the cloud server;

[0092] A priority determination module 702 is configured to assign different storage priorities to data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively. The priority of the data segment in the first storage area of the local server is P1, which is higher than the priority of the data segment in the second storage area of the cloud server, which is P2. When a data access request is detected, access verification is preferentially performed on the data segment with a higher priority.

[0093] A judgment module 703 is configured to judge whether the storage duration t of the data segment is greater than a preset migration threshold T2. If so, the data segment stored in the first storage area of the local server is migrated to the third storage area of the cloud server, or migrated from the second storage area of the cloud server to the fourth storage area of the local server.

[0094] An integrity verification module 704 is configured to perform data integrity verification on the migrated data segment to monitor and trace illegal data integration behaviors.

[0095] The functions and implementation manners of the various modules of the Internet-based medical data security monitoring system 700 have been described above with reference to the accompanying drawings and will not be elaborated herein.

[0096] The specific embodiments described above have further elaborated the objectives, technical solutions, and beneficial effects of the embodiments of the present disclosure. It should be understood that the above description is only the specific embodiments of the embodiments of the present disclosure and is not used to limit the protection scope of the embodiments of the present disclosure. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the embodiments of the present disclosure shall be included in the protection scope of the embodiments of the present disclosure.

Claims

1. A medical data security monitoring method based on the Internet, characterized in that: Including: Segment and store medical data according to a preset data volume size threshold T1, where data segments with a data volume size less than or equal to the threshold T1 are stored in the first storage area of the local server, and data segments with a data volume size greater than the threshold T1 are stored in the second storage area of the cloud server; Assign different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively. Among them, the priority P1 of the data segments in the first storage area of the local server is higher than the priority P2 of the data segments in the second storage area of the cloud server. And when a data access request is detected, access verification is preferentially performed on the data segments with higher priority; Judge whether the storage duration t of the data segment is greater than a preset migration threshold T2. If so, migrate the data segment stored in the first storage area of the local server to the third storage area of the cloud server, or migrate it from the second storage area of the cloud server to the fourth storage area of the local server; Perform data integrity verification on the migrated data segment to monitor and trace illegal statistical behavior; After the step of segmenting and storing medical data according to a preset data volume size threshold T1, it further includes: Determine the storage density D of the data segment; Classify the data segments according to the storage density D. Data segments with a storage density greater than the preset density threshold D0 are stored in the fifth storage area of the local server, and data segments with a storage density less than or equal to the preset density threshold D0 are stored in the sixth storage area of the cloud server; Assign different storage redundancies R to the data segments stored in the fifth storage area of the local server and the sixth storage area of the cloud server respectively. The redundancy of the data segments in the fifth storage area of the local server is R1, and the redundancy of the data segments in the sixth storage area of the cloud server is R2, and R1 < R2. When a data loss risk is detected, data recovery is performed according to the redundancy; Judge whether the storage frequency f of the data segment is greater than a preset frequency threshold F1. If so, migrate the data segment stored in the fifth storage area of the local server to the seventh storage area of the cloud server, or migrate it from the sixth storage area of the cloud server to the eighth storage area of the local server.

2. The Internet-based medical data security monitoring method according to claim 1, characterized in that: The migration threshold T2 is set according to the security level and update frequency of the data.

3. The Internet-based medical data security monitoring method according to claim 1, characterized in that: Performing data integrity verification on the migrated data segment includes comparing whether the hash value H of the data segment is equal to the pre-stored standard hash value H0. If not, it is determined that there is a risk of data tampering, triggering a security alarm and recording relevant data information.

4. The Internet-based medical data security monitoring method according to claim 1, characterized in that: The step of respectively assigning different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server, further includes: Calculate the access popularity H of the data segment; Sort the data segments according to the access popularity H, and the data segments with higher access popularity are preferentially processed in the data access request queue; Setting a storage validity period E of the data segment, when the storage duration t is greater than the storage validity period E, performing an encryption strength upgrade on the data segment, and storing the data segment after the encryption strength upgrade in the ninth storage area of ​​the local server or the tenth storage area of ​​the cloud server; It is determined whether the access source O of the data segment belongs to the preset trusted source set Ω. If it does, the data access verification is performed normally. If it does not, the difficulty coefficient K of the data access verification is increased.

5. The Internet-based medical data security monitoring method according to claim 1, characterized in that: The judgment After the step of determining whether the storage time t of the data segment is greater than a preset migration threshold T2, the method further includes: Calculate the storage cost C of the data segment; Data segments are screened based on the storage cost C, and data segments with storage costs higher than the preset cost threshold C0 are migrated first; Back up the migrated data segment, and store the backup data in the eleventh storage area of ​​the local server and the twelfth storage area of ​​the cloud server. The synchronization update cycle of the backup data and the original data is T3; It is determined whether the access frequency change rate of the data segment is greater than a preset change rate threshold F2. If so, the storage location and storage priority of the data segment are adjusted.

6. The Internet-based medical data security monitoring method according to claim 1, characterized in that: The method further comprises: When the storage density D is greater than or equal to the preset density threshold D0 and the storage time t is greater than the preset time threshold T4, the data segment is stored in the thirteenth storage area of ​​the local server, otherwise it is stored in the fourteenth storage area of ​​the cloud server; Different storage access restrictions L are respectively assigned to the data segments stored in the thirteenth storage area of ​​the local server and the fourteenth storage area of ​​the cloud server, where the data segment access restriction of the thirteenth storage area of ​​the local server is L1, and the data segment access restriction of the fourteenth storage area of ​​the cloud server is L2, and L1>L2; It is determined whether the number of storage location changes M of the data segment is greater than a preset change number threshold M0. If so, the data encryption algorithm of the data segment is upgraded.

7. The Internet-based medical data security monitoring method according to claim 1, characterized in that: The method further comprises: Different preset density thresholds De0 are set for data segments of different departments. When the storage density D is greater than or equal to the corresponding preset density threshold De0, the data segment is stored in the fifteenth storage area of ​​the local server, otherwise it is stored in the sixteenth storage area of ​​the cloud server; Assign different storage audit levels A to the data segments stored in the fifteenth storage area of ​​the local server and the sixteenth storage area of ​​the cloud server, respectively. The audit level of the data segments in the fifteenth storage area of ​​the local server is A1, and the audit level of the data segments in the sixteenth storage area of ​​the cloud server is A2, and A1>A2; It is determined whether the authority level Pd of the doctor to which the data segment belongs is greater than or equal to the preset authority condition Pd0. If so, the data segment is allowed to perform some sensitive data operations, otherwise, sensitive data operations are prohibited.

8. A medical data security monitoring system based on the Internet, characterized in that: include: A segmentation module, used to segment and store the medical data according to a preset data volume threshold value T1, wherein data segments with a data volume less than or equal to the threshold value T1 are stored in a first storage area of ​​the local server, and data segments with a data volume greater than the threshold value T1 are stored in a second storage area of ​​the cloud server; A priority determination module, which is used to assign different storage priorities to the data segments stored in the first storage area of the local server and the second storage area of the cloud server respectively. Among them, the priority of the data segment in the first storage area of the local server is P1, which is higher than the priority of the data segment in the second storage area of the cloud server, which is P2. And when a data access request is detected, the data segment with a higher priority is preferentially accessed and verified; A judgment module, which is used to judge whether the storage duration t of the data segment is greater than the preset migration threshold T2. If so, the data segment stored in the first storage area of the local server is migrated to the third storage area of the cloud server, or migrated from the second storage area of the cloud server to the fourth storage area of the local server; An integrity verification module, which is used to perform data integrity verification on the migrated data segment, so as to monitor and trace illegal data statistics behavior; After the medical data is segmented and stored according to the preset data volume size threshold T1, it further includes: Determine the storage density D of the data segment; Classify the data segments according to the storage density D. The data segments with a storage density greater than the preset density threshold D0 are stored in the fifth storage area of the local server, and the data segments with a storage density less than or equal to the preset density threshold D0 are stored in the sixth storage area of the cloud server; Assign different storage redundancies R to the data segments stored in the fifth storage area of the local server and the sixth storage area of the cloud server respectively. The redundancy of the data segment in the fifth storage area of the local server is R1, and the redundancy of the data segment in the sixth storage area of the cloud server is R2, and R1 < R2. When a data loss risk is detected, data recovery is performed according to the redundancy; Judge whether the storage frequency f of the data segment is greater than the preset frequency threshold F1. If so, the data segment stored in the fifth storage area of the local server is migrated to the seventh storage area of the cloud server, or migrated from the sixth storage area of the cloud server to the eighth storage area of the local server.

Citation Information

Patent Citations

  • Data processing method and device, equipment and medium

    CN113918098A