Medical data auditing method and device

By combining hash structures and overlay trees, the flexibility and security issues of data auditing in scenarios with multiple data holders are resolved, enabling accurate verification of data integrity and security and avoiding the risk of collusion and deception.

CN119862610BActive Publication Date: 2026-07-24MINZU UNIVERSITY OF CHINA +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MINZU UNIVERSITY OF CHINA
Filing Date
2024-12-02
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In scenarios with multiple data holders, data ownership certificates cannot be flexibly applied, posing a risk of collusion between third-party auditors and cloud service providers to deceive, resulting in unreliable data audit results. This is particularly problematic in medical disputes, where it severely damages the interests of data owners.

Method used

By employing a combination of hash structure and overlay tree, and through collaborative work between terminal devices, cloud servers, and auditing terminals, a pre-defined random number generation algorithm and public key decryption technology are used to generate and verify the overlay tree, ensuring data integrity and security.

Benefits of technology

It enables the accuracy verification of data in scenarios with multiple data holders, avoids collusion between the auditing end and the cloud service end, and ensures the accuracy and security of data verification results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119862610B_ABST
    Figure CN119862610B_ABST
Patent Text Reader

Abstract

The disclosure provides a medical data auditing method and device, the method comprises the following steps: acquiring an auditing instruction sent by a terminal device; acquiring a hash structure, attributes of to-be-audited medical data and a first overlay tree sent by a cloud server; using a preset random number generation algorithm, selecting at least one leaf node in the hash structure to form a second overlay tree based on a first random number; using a pre-acquired public key to decrypt the attributes of the to-be-audited medical data; verifying the attributes of each leaf node in the first overlay tree and the second overlay tree based on the decrypted attributes of the to-be-audited medical data; and if the attributes of the corresponding leaf nodes in the first overlay tree and the second overlay tree have a mapping relationship, the to-be-verified medical data is verified to be passed. When the data is not tampered with, there is a mapping relationship between the first overlay tree and the second overlay tree, and the first overlay tree and the second overlay tree are respectively generated by the cloud server and the auditing unit, thereby solving the problem of joint fraud between the auditing unit and the cloud server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data processing technology, specifically to a method and apparatus for auditing medical data. Background Technology

[0002] As a convergence of the internet, the medical internet enables the optimized allocation and efficient utilization of medical resources. Based on medical internet technology, a hospital stores its medical data on a cloud platform, which other hospitals or patients can then access, facilitating cross-hospital access for patients. However, the storage of data on cloud platforms carries the risk of unauthorized data tampering.

[0003] In related technologies, data ownership certificates are used to address the aforementioned issues. However, data ownership certificates are only applicable to scenarios where data is held by a single data holder. When multiple data holders exist, data ownership certificates are inflexible and cannot meet the needs of practical applications. Furthermore, there is a risk that third-party auditors may collude with other entities to deceive the data ownership certificate system. Summary of the Invention

[0004] This disclosure presents a method and apparatus for auditing medical data.

[0005] The first aspect of this disclosure provides a medical data auditing method, applied at the auditing end, the method comprising: Obtain an audit instruction sent by a terminal device, the audit instruction including a tag and a first random number for the medical data to be audited; The cloud server sends a hash structure corresponding to the tag of the medical data to be audited, the attributes of the medical data to be audited, and a first overlay tree. The first overlay tree is a cover tree containing the medical data to be audited, generated by the cloud server in response to the audit instruction based on the first random number and the hash structure. The attributes of the medical data to be audited are data encrypted by the terminal device based on a preset private key after the storage information of the medical data to be audited is encrypted. Using a preset random number generation algorithm, at least one leaf node is selected from the hash structure based on the first random number to form a second cover tree; The attributes of the medical data to be audited are decrypted using a pre-acquired public key. Based on the attributes of the medical data to be audited obtained after decryption, the attributes of each leaf node in the first overlay tree and the second overlay tree are verified. If there is a mapping relationship between the attributes of the corresponding leaf nodes in the first overlay tree and the second overlay tree, a verification pass message is sent to the terminal device.

[0006] An embodiment of the second aspect of this disclosure provides a medical data auditing method applied to a terminal device, the method comprising: After the medical data to be audited and its attributes are sent to the cloud server for storage, an audit instruction is sent to the cloud server and the auditing end. The audit instruction includes the tag of the medical data to be audited and a first random number, so that the cloud server generates a first overlay tree and a hash structure based on the tag of the medical data to be audited and the first random number, and feeds back the first overlay tree, the hash structure and the attributes of the medical data to be audited to the auditing end. Obtain the verification pass information fed back by the auditing end based on the audit instruction, the first overlay tree, the hash structure, and the attributes of the medical data to be audited.

[0007] An embodiment of the third aspect of this disclosure provides a medical data auditing method applied to a cloud server, the method comprising: The system obtains the medical data to be audited and its attributes sent by the terminal device, stores the medical data to be audited and its attributes, and then obtains the audit instruction sent by the terminal device. The audit instruction includes the tag of the medical data to be audited and a first random number. Based on the tags of the medical data to be audited, and the medical data to be audited, a hash structure is generated; Using a preset random number generation algorithm, based on the first random number, at least one leaf node is selected in the hash structure to generate a first covering tree; The first overlay tree, the hash structure, and the attributes of the medical data to be audited are sent to the auditing end.

[0008] An embodiment of the fourth aspect of this disclosure provides a medical data auditing device, applied at an auditing end, the device comprising: The first instruction acquisition module is used to acquire an audit instruction sent by the terminal device, wherein the audit instruction includes a tag of the medical data to be audited and a first random number; The module for obtaining data to be verified is used to obtain the hash structure corresponding to the tag of the medical data to be audited, the attributes of the medical data to be audited, and the first overlay tree sent by the cloud server. The first overlay tree is a cover tree containing the medical data to be audited generated by the cloud server in response to the audit instruction based on the first random number and the hash structure. The attributes of the medical data to be audited are data after the terminal device encrypts the storage information of the medical data to be audited based on a preset private key. A second cover tree generation module is used to select at least one leaf node from the hash structure based on the first random number using a preset random number generation algorithm to form a second cover tree. The verification module is used to decrypt the attributes of the medical data to be audited using a pre-acquired public key, and based on the attributes of the medical data to be audited obtained after decryption, to verify the attributes of each leaf node in the first coverage tree and the second coverage tree. If there is a mapping relationship between the attributes of the corresponding leaf nodes in the first coverage tree and the second coverage tree, the module sends verification pass information to the terminal device.

[0009] An embodiment of the fifth aspect of this disclosure provides a medical data auditing device, applied to a terminal device, the device comprising: The module for sending auditable data is used to send the medical data to be audited and its attributes to the cloud server for storage, and then send an audit instruction to the cloud server and the auditing end. The audit instruction includes the tag of the medical data to be audited and a first random number, so that the cloud server generates a first overlay tree and a hash structure based on the tag of the medical data to be audited and the first random number, and feeds back the first overlay tree, the hash structure and the attributes of the medical data to be audited to the auditing end. The verification information acquisition module is used to acquire the verification pass information fed back by the auditing end based on the auditing instruction, the first overlay tree, the hash structure, and the attributes of the medical data to be audited.

[0010] An embodiment of the sixth aspect of this disclosure provides a medical data auditing device applied to a cloud server, the device comprising: The second instruction acquisition module is used to acquire the medical data to be audited and the attributes of the medical data to be audited sent by the terminal device, store the medical data to be audited and the attributes of the medical data to be audited, and then acquire the audit instruction sent by the terminal device. The audit instruction includes the tag of the medical data to be audited and a first random number. A hash structure generation module is used to generate a hash structure based on the tags of the medical data to be audited and the medical data to be audited. A first cover tree generation module is used to generate a first cover tree by selecting at least one leaf node in the hash structure based on the first random number using a preset random number generation algorithm. The sending module is used to send the first overlay tree, the hash structure, and the attributes of the medical data to be audited to the auditing end.

[0011] An embodiment of the seventh aspect of this disclosure provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the computer program to implement the methods described in the first, second, and third aspects above.

[0012] An embodiment of the eighth aspect of this disclosure provides a computer-readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the methods described in the first, second, and third aspects above.

[0013] The technical solutions provided in this disclosure have at least the following technical effects or advantages: The system acquires an audit instruction sent by a terminal device, which includes a tag for the medical data to be audited and a first random number. It also acquires a hash structure corresponding to the tag of the medical data to be audited, the attributes of the medical data to be audited, and a first overlay tree sent by a cloud server. Using a preset random number generation algorithm, based on the first random number, at least one leaf node is selected from the hash structure to form a second overlay tree. The first overlay tree is generated by the cloud server based on the first random number. The system then decrypts the attributes of the medical data to be audited using a pre-acquired public key. Based on the decrypted attributes, the system verifies the attributes of each leaf node in both the first and second overlay trees. If a mapping relationship exists between the attributes of corresponding leaf nodes in the first and second overlay trees, the medical data to be verified passes verification, and a verification pass instruction is sent to the terminal device. If the data has not been tampered with, a mapping relationship exists between the first and second overlay trees. Furthermore, since the first and second overlay trees are generated separately by the cloud server and the audit server, there is no issue of collusion between the audit server and the cloud server, ensuring the accuracy of the verification results.

[0014] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description or may be learned by practice of this disclosure. Attached Figure Description

[0015] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this disclosure. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 This illustration shows an application scenario diagram of the medical data auditing method provided in an embodiment of the present disclosure; Figure 2 The diagram illustrates the execution flowchart of an auditing method for medical data auditing according to an embodiment of this disclosure. Figure 3 This diagram illustrates a terminal device execution flowchart of a medical data auditing method provided in an embodiment of the present disclosure; Figure 4 This illustration shows a cloud server execution flowchart of a medical data auditing method provided in an embodiment of this disclosure; Figure 5 A schematic diagram of the audit terminal of a medical data auditing device provided in one embodiment of this disclosure is shown; Figure 6 A schematic diagram of a terminal device of a medical data auditing apparatus provided in one embodiment of the present disclosure is shown; Figure 7 A schematic diagram of a cloud server for a medical data auditing device provided in one embodiment of this disclosure is shown; Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure is shown; Figure 9 A schematic diagram of a storage medium provided according to an embodiment of the present disclosure is shown. Detailed Implementation

[0016] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0017] It should be noted that, unless otherwise stated, the technical or scientific terms used in this disclosure shall have the ordinary meaning as understood by one of ordinary skill in the art to which this disclosure pertains.

[0018] The following describes the technical scenarios involved in the embodiments of this disclosure.

[0019] With the rapid development of information technology and the increasing demand for healthcare, the Internet of Things (IoT), a product of the integration of the internet and the healthcare field, has enabled the widespread adoption of applications such as telemedicine and intelligent diagnosis, promoting the optimal allocation and efficient utilization of medical resources. Cloud storage of medical data, a crucial component of the IoT, plays a key role in breaking down "hospital data silos," facilitating information sharing and collaboration, and preventing issues such as duplicate examinations and inconsistent treatment information during patient care. However, the data stored on cloud servers also presents challenges to the IoT. Data stored on cloud servers may be illegally altered, lost due to external hacker attacks, or even incomplete due to cloud service provider errors or storage system failures. The data owner cannot ascertain whether the data remains secure and intact. Related technologies primarily address this issue through Data Holding Certificates (DPB).

[0020] Data ownership verification is a security protocol primarily used to verify the integrity and correctness of data stored on cloud servers. The verification process mainly involves the data owner, the cloud server, and a third-party auditing platform. If a third-party auditing platform colludes with the cloud server and data holders (such as doctors and patients) to deceive the system, the audit results may become unreliable, especially in medical disputes, severely damaging the interests of the data owner.

[0021] In view of this, this disclosure proposes a medical data auditing method. In this disclosure, the method can be applied to, for example... Figure 1 The medical data auditing system shown includes a terminal device 101, a cloud server 102, and an audit terminal 103. The terminal device is used by data holders to send data to be audited to the cloud server. Specifically, doctors or patients can send their data to the cloud server for storage by logging in. When a doctor or patient needs to audit the data stored on the cloud server, they send an audit command to both the cloud server and the audit terminal. After receiving the audit command, the cloud server sends the stored data to be audited to the audit terminal. The audit terminal then performs the audit based on the obtained data and finally sends the audit results back to the terminal device.

[0022] The following describes a medical data auditing method proposed according to embodiments of this disclosure, with examples.

[0023] Figure 2 This disclosure illustrates a medical data auditing method provided by an embodiment of the present disclosure. This medical data auditing method is applied at the auditing end and may include the following steps: In step S11, the audit instruction sent by the terminal device is obtained.

[0024] The audit instructions include the label and first random number of the medical data to be audited.

[0025] In step S12, the hash structure corresponding to the tag of the medical data to be audited, the attributes of the medical data to be audited, and the first overlay tree sent by the cloud server are obtained.

[0026] The first overlay tree is a cloud server responding to the audit instruction and generating an overlay tree containing the medical data to be audited based on the first random number and hash structure. The attributes of the medical data to be audited are the data encrypted by the terminal device based on a preset private key.

[0027] For example, after receiving the audit instruction sent by the terminal device, the audit data to be audited corresponding to the audit instruction sent by the cloud server is obtained. The audit data to be audited is represented in the form of a hash structure. In order to further verify the audit data to be audited, it is also necessary to obtain the attributes of the audit data sent by the cloud server and the first overlay tree generated by the cloud server based on the first random number. The first overlay tree is generated by the cloud server alone, which avoids the problem of collusion with the audit end to deceive.

[0028] In step S13, a preset random number generation algorithm is used to select at least one leaf node in the hash structure based on the first random number to form a second cover tree.

[0029] For example, the auditing end generates a second random number based on the first random number in the auditing instruction. Based on the second random number and a preset mapping relationship, it determines at least one leaf node corresponding to the second random number and uses this leaf node as a leaf node to construct the second coverage tree. Specifically, in some embodiments, step S13 can be implemented as follows: Iterating using a preset random number generation algorithm until the iteration count reaches the first random number, determining the second random number generated by the preset random number generation algorithm at the current iteration count; and selecting at least one leaf node from the hash structure based on the second random number to form the second coverage tree.

[0030] For example, the preset random number generation algorithm, in this embodiment of the disclosure, may utilize a singular attractor to generate a second random number. The first random number is used as the iteration number of the chaotic system with the singular attractor. When the iteration number of the chaotic system reaches the first random number, the corresponding second random number is output. Specifically, the following are the specific equations of the four-dimensional chaotic system:

[0031] in The four state variables of the chaotic system This refers to system parameters.

[0032] Because of its high sensitivity to the first random number and the unpredictability of the iterative results, chaos theory has become a powerful tool for generating high-quality random numbers and enhancing security. Even if the generation algorithm is known, due to the inherent complexity of the system and its extreme sensitivity to initial conditions, it is difficult to reverse-engineer the original information or predict the subsequent second random number, thus greatly improving the level of information security.

[0033] After generating the second random number, the leaf node corresponding to the second random number is determined according to a preset mapping relationship. This leaf node is the one in the hash structure sent by the cloud server. The position and number of leaf nodes determined by the second random number in the hash structure are related to the preset mapping relationship. Furthermore, since the second random number is difficult to predict, the subsequent determination of leaf nodes based on it is also difficult to predict. Auditing the leaf nodes determined by the second random number eliminates the need to audit all nodes in the hash structure, reducing the computational load and improving audit speed.

[0034] The specific process of generating the second cover tree can be as follows: based on the mapping relationship between the second random number and the audit block, determine at least one audit block corresponding to the second random number; determine the node corresponding to the at least one audit block in the hash structure; and take the node corresponding to the at least one audit block as the leaf node to generate the second cover tree.

[0035] For example, the leaf nodes in the hash structure are the data blocks corresponding to the medical files to be audited. That is, when stored on the cloud server, the hash structure is composed of the data blocks of the medical data to be audited. Auditing the medical data to be audited means auditing whether the corresponding data blocks have been tampered with. Therefore, based on the mapping relationship between the second random number and the audit blocks, at least one audit block corresponding to the second random number is determined, and each audit block serves as a leaf node to generate the second overlay tree.

[0036] In step S14, the attributes of the medical data to be audited are decrypted using the pre-acquired public key. Based on the attributes of the medical data to be audited obtained after decryption, the attributes of each leaf node in the first and second overlay trees are verified. If there is a mapping relationship between the attributes of the corresponding leaf nodes in the first and second overlay trees, verification information is sent to the terminal device.

[0037] Next, the leaf nodes determined by the second random number form a new hash structure, which is the second cover tree. The second cover tree is used to further verify the first cover tree. If the verification passes, it means that the medical data to be audited has not been tampered with.

[0038] For example, when using the second coverage tree to verify the first coverage tree, it is possible to verify whether the number of leaf nodes in the coverage tree and the attributes of the audit blocks constituting each leaf node are the same. If the attributes of the audit blocks constituting each leaf node are the same, it indicates that the verification of the medical data to be audited has passed.

[0039] Specifically, in some embodiments, step S14 can be implemented in the following way: parsing each leaf node in the first coverage tree; if the number of each leaf node in the first coverage tree is the same as the number of each leaf node in the second coverage tree, then each leaf node in the second coverage tree is used as the leaf node of the first coverage data to generate a verification coverage tree; if the attributes of the leaves of the verification coverage tree have a mapping relationship with the attributes of the medical data to be audited obtained after decryption, then the medical data to be verified passes the verification.

[0040] For example, based on the fact that the first cover tree and the second cover tree have the same structure (the same number of leaf nodes), the leaf nodes in the second cover tree are used as the leaf nodes of the first cover tree to generate a verification cover tree. If the data has not been tampered with, the information contained in each node of the verification cover tree is the same as that in each node of the first cover tree or there is a mapping relationship.

[0041] Specifically, the auditing end determines the first coverage tree returned by the cloud service end. 'and the second cover tree calculated by itself If the tree structures are different, return FALSE and end the process.

[0042] From the first cover tree Extract After saving, calculate Replace the corresponding values; if all leaf nodes are complete, the root node can be calculated. Then, the root node is determined according to the following check formula. If the value is correct, the verification will fail, indicating that the returned value is incorrect. If the data is incorrect or there is an error in the data block information outside of the challenge verification, return FALSE directly.

[0043]

[0044] Continue to determine whether the following test formula is true, where As already obtained above. If this is also true, it means the medical data stored on the cloud server is correct, passes the integrity audit, and returns TRUE; otherwise, output FALSE.

[0045]

[0046] The attributes of the medical data to be audited are generated by encrypting various stored information using a preset private key. Furthermore, regardless of whether it's the hash structure sent by the cloud server, the first overlay tree, or the leaf nodes in the second overlay tree generated by the auditing end, they all contain various stored information after parsing. Comparing the stored information in the attributes with the parsed stored information from the leaf nodes, if a mapping relationship exists, it indicates that the data has not been tampered with.

[0047] In this embodiment, the attributes of the medical data to be audited obtained from the cloud server include various storage information of the medical data to be audited. This storage information includes information about the data blocks corresponding to each leaf node in the hash structure after the terminal device sends the medical data to be audited to the cloud server. Therefore, verification can be performed based on the attributes of the medical data to be audited.

[0048] Specifically, verifying the attributes of leaf nodes in the coverage tree includes at least one of the following: the attributes include the second preset element of the medical data to be audited to which the leaf node belongs, the label of the medical data to be audited, the number of leaf nodes of the medical data to be audited, and the timestamp; verifying that there is a mapping relationship between the attributes of the leaf nodes in the coverage tree and the attributes of the medical data to be audited, including at least one of the following: Verify whether the labels of the leaf nodes in the verification tree match the labels of the medical files to be audited. To verify whether the number of leaf nodes in the medical file to which the leaf nodes in the cover tree belong is the same as the number of leaf nodes in the medical data to be audited; If verifying whether the timestamps corresponding to the leaf nodes in the overlay tree are the same as the timestamps of the medical data to be audited; If we want to verify whether there is a bilinear mapping relationship between the second preset element corresponding to the leaf node in the cover tree and the first preset element in the medical data to be audited.

[0049] Specifically, the first preset element is the storage information added by the terminal device before sending the medical data to be audited to the cloud server. If there is a bilinear mapping relationship between the first preset element and the first preset element in the leaf node of the verification coverage tree, then the verification is successful.

[0050] It can also verify whether the number of leaf nodes (total number of data blocks), labels, and timestamps in the hash structure of the attributes corresponding to each leaf node in the overlay tree are consistent.

[0051] In the embodiments of this disclosure, the first and second preset elements have the property of bilinear mapping. Let... It is a large prime number. and Both are prime numbers of order 1. The group. Let's assume... Let be an additive group. It is a multiplicative group. Function This is called a bilinear mapping. Its favorable properties make cryptographic schemes simpler and more efficient; it possesses the following properties: Bilinear: for any and ,satisfy Or for any ,have and .

[0052] Non-degeneracy: if yes The generator, then yes The generator. That is to say, .

[0053] Computability: Given There exists an efficient algorithm to compute bilinear pairs. .

[0054] Corresponding to the aforementioned medical data auditing method applied to the auditing end, this application also discloses a medical auditing method applied to terminal devices, such as... Figure 3 As shown, the medical data auditing method of this disclosure embodiment may include the following steps: In step S21, after the medical data to be audited and its attributes are sent to the cloud server for storage, an audit instruction is sent to the cloud server and the auditing end. The audit instruction includes the tag and first random number of the medical data to be audited, so that the cloud server can generate a first overlay tree and hash structure based on the tag and first random number of the medical data to be audited, and feed back the first overlay tree, hash structure and the attributes of the medical data to be audited to the auditing end.

[0055] For example, the terminal device is used by relevant personnel to organize and send medical data to a cloud server for storage. These relevant personnel may include doctors, nurses, and patients. Before sending the medical data to the cloud server for storage, a key can be assigned to the relevant personnel to log in to the terminal device for authentication.

[0056] Specifically, the relevant keys can be generated by a dedicated key management center, for example, by setting security parameters. The key management center generates the relevant keys for medical personnel. The key management center can be a standalone server or an embedded terminal device.

[0057] The following is the specific process for generating the user key: Let the bilinear mapping function... ,in and It is a multiplicative cyclic group, and its generator is Large prime numbers of order are make It is mapped to Hash function of a domain It is mapped to One-way hash function for a domain: It is a hash function based on a hash algorithm. Select a random number. The public key is calculated using the master private key. , Used as the master key, and generate corresponding keys based on the unique identification number (UIN) of the relevant personnel. After receiving the key, the relevant personnel will perform the following verification:

[0058] If the equation is true, it means the key was successfully received, and True is returned to the key management center; otherwise, False is returned to the key management center, and the other party is asked to resend the key.

[0059] Before the medical data to be audited is sent to the cloud server for storage, it needs to be processed. Specifically, based on the medical data to be audited and the preset classification criteria, the medical data to be audited is divided into at least one medical sub-data; each medical sub-data is divided into at least one data block; at least one data block corresponding to any medical sub-data is used as the leaf node of the corresponding medical sub-data hash tree to generate the corresponding medical sub-data hash tree; the hash tree corresponding to at least one medical sub-data and the attributes of the medical data to be audited are sent to the cloud server for storage.

[0060] For example, the raw medical data is first categorized into medical sub-data based on the sensitivity of the data fields. This includes, for example, personal attribute data, health status data, medical application data, medical payment data, health resource data, and public health data. Afterward, a random number is generated. (Used to generate a data block for every few fields), and for medical sub-data Divide into blocks:

[0061] in This represents a certain medical sub-data. The number of fields, Represents a symbolic function. Indicates the first The first medical sub-data There are several data blocks, therefore the total number of blocks can be calculated. and .

[0062] It should be noted that when the user is a doctor or related medical personnel, after generating the data blocks for each medical sub-data, it is also possible to... Randomly select an element Combined with document identifier Total number of file data blocks and current timestamp Then use the additional private key Signing these triples yields the file tags. Using a pre-generated private key and elements For each data block Obtain by signing , forming a homomorphic signature set .

[0063] According to multiple Construct multiple trees based on data block hash values For an MHT forest with leaf nodes, the set of root nodes of the tree is obtained. And calculate the total root node RT= Signing the root node Finally, put the first tuple Sending the data to the cloud server can be used to identify the status of the data stored on the cloud server, preventing data tampering, and will include the second tuple. The data is sent to the patient, who can then obtain the corresponding medical data to be audited based on the second tuple. This eliminates the need for further data segmentation and reduces unnecessary calculations.

[0064] In addition, the attributes of the medical data need to be sent to the cloud server. After receiving the audit instruction, the cloud server sends the attributes of the medical data to be audited to the auditing end. The auditing end then uses the attributes of the medical data to be audited to further verify whether the data has been tampered with.

[0065] Specifically, to ensure the security of the attributes of the medical data to be audited, the storage information of the medical data to be audited that constitutes the attributes is generated by encrypting the attributes with a preset private key. The preset private key is generated using a bilinear mapping rule, and the public key that matches the preset private key conforms to the bilinear mapping between the public and private keys, thereby improving the security of the attributes.

[0066] In step S22, the verification pass information fed back by the auditing end based on the audit instruction, the first overlay tree, the hash structure, and the attributes of the medical data to be audited is obtained. After the auditing end performs the audit based on the first overlay tree, the hash structure, and the medical data to be audited, the terminal device receives the verification information sent by the auditing end.

[0067] Corresponding to the aforementioned medical data auditing methods applied to auditing terminals and equipment, this application also discloses a medical auditing method applied to cloud servers, such as... Figure 4 As shown, the medical data auditing method of this disclosure embodiment may include the following steps: In step S31, the medical data to be audited and its attributes sent by the terminal device are obtained. After storing the medical data to be audited and its attributes, the audit instruction sent by the terminal device is obtained.

[0068] The audit instructions include the label and first random number of the medical data to be audited.

[0069] For example, the medical data to be audited and its attributes sent by the terminal device are stored on a cloud server. Upon receiving an audit instruction, where the tags in the audit instruction correspond to the medical data to be audited, the cloud server is then searched for the medical data to be audited corresponding to the tags.

[0070] In step S32, a hash structure is generated based on the tags of the medical data to be audited and the medical data to be audited.

[0071] For example, after the medical data to be audited is determined, the medical data to be audited is stored in the form of a hash tree on the cloud server. Therefore, the corresponding hash structure can be generated based on the hash tree of the medical data to be audited.

[0072] In step S33, a first covering tree is generated by using a preset random number generation algorithm and selecting at least one leaf node in the hash structure based on the first random number.

[0073] For example, similar to the auditing end, a second random number is generated using a random number generation algorithm, and at least one leaf node is selected from the hash structure based on the second random number to generate a first covering tree.

[0074] Specifically, the algorithm iterates using a preset random number generation algorithm until the number of iterations reaches the first random number, and then determines the second random number generated by the preset random number generation algorithm at the current iteration number. Based on the mapping relationship between the second random number and the data blocks corresponding to the leaf nodes in the hash tree, at least one audit block corresponding to the second random number is determined. The at least one audit block is used as a leaf node to generate the first cover tree.

[0075] For example, the preset random number generation algorithm can also use a chaotic system with a singular attractor to generate the second random number. It's important to note that this algorithm must be consistent with both the server-side and audit-side preset random number generation algorithms to ensure that the second random number generated by the cloud server and the audit-side is identical. Therefore, the leaf nodes determined by the second random number will correspond between the audit-side and the cloud server.

[0076] In step S34, the first overlay tree, hash structure, and attributes of the medical data to be audited are sent to the auditing end.

[0077] Corresponding to the above implementation methods for medical data auditing, this disclosure also provides a medical data auditing device, which is applied at the auditing end to perform the above-mentioned tasks. Figure 2 A medical data auditing method illustrated in any embodiment. Figure 5 As shown, the medical data auditing device includes: The first instruction acquisition module 501 is used to acquire an audit instruction sent by the terminal device, wherein the audit instruction includes a tag of the medical data to be audited and a first random number; The module 502 for obtaining data to be verified is used to obtain the hash structure corresponding to the tag of the medical data to be audited, the attributes of the medical data to be audited, and the first overlay tree sent by the cloud server. The first overlay tree is a cover tree containing the medical data to be audited generated by the cloud server in response to the audit instruction based on the first random number and the hash structure. The attributes of the medical data to be audited are data after the terminal device encrypts the storage information of the medical data to be audited based on a preset private key. The second cover tree generation module 503 is used to select at least one leaf node in the hash structure based on the first random number using a preset random number generation algorithm to form a second cover tree. The verification module 504 is used to decrypt the attributes of the medical data to be audited using a pre-acquired public key, and verify the attributes of each leaf node in the first overlay tree and the second overlay tree based on the attributes of the medical data to be audited after decryption. If there is a mapping relationship between the attributes of the corresponding leaf nodes in the first overlay tree and the second overlay tree, the verification pass information is sent to the terminal device.

[0078] Optionally, the second cover tree module 503 is generated, specifically for: The algorithm is iterated using a preset random number generation algorithm until the number of iterations reaches the first random number, and then the second random number generated by the preset random number generation algorithm at the current iteration number is determined. Based on the second random number, at least one leaf node is selected from the hash structure to form a second cover tree.

[0079] Optionally, the second cover tree generation module 503 is further used for: Based on the mapping relationship between the second random number and the audit block, at least one audit block corresponding to the second random number is determined; Determine the node corresponding to the at least one audit block in the hash structure; The node corresponding to the at least one audit block is used as a leaf node to generate a second cover tree.

[0080] Optionally, the verification module 504 is specifically used for: parse each leaf node in the first cover tree; If the number of leaf nodes in the first coverage tree is the same as the number of leaf nodes in the second coverage tree, then each leaf node in the second coverage tree is used as a leaf node of the first coverage data to generate a verification coverage tree. If the attributes of the leaves of the verification cover tree have a mapping relationship with the attributes of the medical data to be audited after decryption, then the medical data to be verified passes the verification.

[0081] Optionally, the attributes of the leaf nodes in the verification coverage tree include at least one of the following: the attributes include a second preset element of the medical data to be audited to which the leaf node belongs, the tag of the medical data to be audited, the number of leaf nodes of the medical data to be audited, and a timestamp; the verification module 504 includes components for implementing at least one of the following: Verify whether the medical document tag corresponding to the leaf node in the verification coverage tree matches the tag of the medical data to be audited; If the number of leaf nodes in the verification coverage tree corresponding to the medical file to which the leaf node belongs is the same as the number of leaf nodes in the medical data to be audited; If the timestamp corresponding to the leaf node in the verification coverage tree is the same as the timestamp of the medical data to be audited; If there exists a bilinear mapping relationship between the second preset element corresponding to the leaf node in the verification coverage tree and the first preset element in the medical data to be audited.

[0082] Corresponding to the above implementation methods for medical data auditing, this disclosure also provides a medical data auditing device, which is applied to a terminal device and used to perform the above-described... Figure 3 A medical data auditing method illustrated in any embodiment. Figure 6 As shown, the medical data auditing device includes: The module 601 for sending auditable data is used to send the medical data to be audited and its attributes to the cloud server for storage, and then send an audit instruction to the cloud server and the auditing end. The audit instruction includes a tag and a first random number of the medical data to be audited, so that the cloud server generates a first overlay tree and a hash structure based on the tag and the first random number of the medical data to be audited, and feeds back the first overlay tree, the hash structure, and the attributes of the medical data to the auditing end. The verification information acquisition module 602 is used to acquire the verification pass information fed back by the auditing end based on the auditing instruction, the first overlay tree, the hash structure, and the attributes of the medical data to be audited.

[0083] Optionally, the module 601 for sending data to be audited is specifically used for: Based on the medical data to be audited and the preset classification criteria, the medical data to be audited is divided into at least one medical sub-data. Each medical sub-data is divided into at least one data block; Use at least one data block corresponding to any medical sub-data as the leaf node of the corresponding medical sub-data hash tree to generate the corresponding medical sub-data hash tree; The hash tree corresponding to the at least one medical sub-data and the attributes of the medical data to be audited are sent to the cloud server for storage.

[0084] Optionally, the attributes of the medical data to be audited are obtained by encrypting at least one of the following stored information using a preset private key. The stored information includes at least one of the following: a first preset element, a tag of the medical data to be audited, the number of leaf nodes in the hash tree corresponding to the at least one medical sub-data, and a timestamp.

[0085] Corresponding to the above implementation methods for medical data auditing, this disclosure also provides a medical data auditing device, which is applied to a cloud server and used to perform the above-mentioned... Figure 4 A medical data auditing method illustrated in any embodiment. Figure 7 As shown, the medical data auditing device includes: The second instruction acquisition module 701 is used to acquire the medical data to be audited and the attributes of the medical data to be audited sent by the terminal device, store the medical data to be audited and the attributes of the medical data to be audited, and then acquire the audit instruction sent by the terminal device. The audit instruction includes the tag of the medical data to be audited and a first random number. A hash structure generation module 702 is used to generate a hash structure based on the tags of the medical data to be audited and the medical data to be audited. The first cover tree generation module 703 is used to generate a first cover tree by selecting at least one leaf node in the hash structure based on the first random number using a preset random number generation algorithm. The sending module 704 is used to send the first overlay tree, the hash structure, and the attributes of the medical data to be audited to the auditing end.

[0086] Optionally, the first cover tree module 703 is used to generate: The algorithm is iterated using a preset random number generation algorithm until the number of iterations reaches the first random number, and then the second random number generated by the preset random number generation algorithm at the current iteration number is determined. Based on the mapping relationship between the second random number and the data blocks corresponding to the leaf nodes in the hash tree, at least one audit block corresponding to the second random number is determined; The first cover tree is generated by using the at least one audit block as a leaf node.

[0087] The medical data auditing device and the medical data auditing method provided in the above embodiments of this disclosure are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0088] This disclosure also provides an electronic device for performing the above-described medical data auditing method. Please refer to... Figure 8 This illustrates a schematic diagram of an electronic device provided by some embodiments of the present disclosure. For example... Figure 8 As shown, the electronic device includes: a processor 800, a memory 801, a bus 802, and a communication interface 803. The processor 800, the communication interface 803, and the memory 801 are connected via the bus 802. The memory 801 stores a computer program that can run on the processor 800. When the processor 800 runs the computer program, it executes the aforementioned provisions of this disclosure. Figures 2-4 The illustrated implementation provides a medical data auditing method.

[0089] The memory 801 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 803 (which can be wired or wireless), such as the Internet, wide area network, local area network, or metropolitan area network.

[0090] Bus 802 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Memory 801 is used to store programs, and the processor 800 executes the programs after receiving execution instructions. Figures 2-4 The illustrated embodiments reveal that the medical data auditing method can be applied to, or implemented by, the processor 800.

[0091] The processor 800 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 800 or by instructions in software form. The processor 800 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 801. Processor 800 reads the information in memory 801 and, in conjunction with its hardware, completes the steps of the above method.

[0092] The electronic device provided in this disclosure and the medical data auditing method provided in this disclosure are based on the same inventive concept and have the same beneficial effects as the methods they employ, operate, or implement.

[0093] This disclosure also provides a computer-readable storage medium corresponding to the medical data auditing method provided in the foregoing embodiments. Please refer to... Figure 9 The computer-readable storage medium shown is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it executes the medical data auditing method provided in any of the foregoing embodiments.

[0094] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.

[0095] The computer-readable storage medium provided in the above embodiments of this disclosure and the medical data auditing method provided in the embodiments of this disclosure are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0096] It should be noted that: Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of this disclosure may be practiced without these specific details. In some instances, well-known structures and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0097] Similarly, it should be understood that, in order to simplify this disclosure and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of this disclosure, various features of this disclosure are sometimes grouped together in a single embodiment, figure, or description thereof. However, this approach to disclosure should not be construed as reflecting a schematic diagram in which the claimed disclosure requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of this disclosure.

[0098] Furthermore, those skilled in the art will understand that although some embodiments described herein include certain features included in other embodiments but not others, combinations of features from different embodiments are intended to be within the scope of this disclosure and form different embodiments. For example, in the following claims, any of the claimed embodiments can be used in any combination.

[0099] The above description is merely a preferred embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.

Claims

1. A method for auditing medical data, characterized in that, When applied to the auditing end, the method includes: Obtain an audit instruction sent by a terminal device, the audit instruction including a tag and a first random number for the medical data to be audited; The cloud server sends a hash structure corresponding to the tag of the medical data to be audited, the attributes of the medical data to be audited, and a first overlay tree. The first overlay tree is a cover tree containing the medical data to be audited, generated by the cloud server in response to the audit instruction based on the first random number and the hash structure. The attributes of the medical data to be audited are data encrypted by the terminal device based on a preset private key after the storage information of the medical data to be audited is encrypted. Using a preset random number generation algorithm, at least one leaf node is selected from the hash structure based on the first random number to form a second cover tree; The attributes of the medical data to be audited are decrypted using a pre-acquired public key. Based on the attributes of the medical data to be audited obtained after decryption, the attributes of each leaf node in the first overlay tree and the second overlay tree are verified. If there is a mapping relationship between the attributes of the corresponding leaf nodes in the first overlay tree and the second overlay tree, a verification pass message is sent to the terminal device.

2. The method according to claim 1, characterized in that, The step of using a preset random number generation algorithm to select at least one leaf node from the hash structure based on the first random number to form a second cover tree includes: The algorithm is iterated using a preset random number generation algorithm until the number of iterations reaches the first random number, and then the second random number generated by the preset random number generation algorithm at the current iteration number is determined. Based on the second random number, at least one leaf node is selected from the hash structure to form a second cover tree.

3. The method according to claim 2, characterized in that, The step of selecting at least one leaf node from the hash structure based on the second random number to form a second cover tree includes: Based on the mapping relationship between the second random number and the audit block, at least one audit block corresponding to the second random number is determined; Determine the node corresponding to the at least one audit block in the hash structure; The node corresponding to the at least one audit block is used as a leaf node to generate a second cover tree.

4. The method according to claim 3, characterized in that, Based on the attributes of the decrypted medical data to be audited, the attributes of each leaf node in the first and second overlay trees are verified. If a mapping relationship exists between the attributes of the corresponding leaf nodes in the first and second overlay trees, verification pass information is sent to the terminal device, including: parse each leaf node in the first cover tree; If the number of leaf nodes in the first cover tree is the same as the number of leaf nodes in the second cover tree, then each leaf node in the second cover tree is used as a leaf node in the first cover tree to generate a verification cover tree. If the attributes of the leaves of the verification cover tree are mapped to the attributes of the medical data to be audited after decryption, then the medical data to be audited is verified.

5. The method according to claim 4, characterized in that, The attributes of the leaf nodes in the verification coverage tree include at least one of the following: the attributes include the second preset element of the medical data to be audited to which the leaf node belongs, the tag of the medical data to be audited, the number of leaf nodes of the medical data to be audited, and the timestamp; the attributes of the leaf nodes in the verification coverage tree and the attributes of the medical data to be audited have a mapping relationship, including at least one of the following: Verify whether the medical document tag corresponding to the leaf node in the verification coverage tree matches the tag of the medical data to be audited; If the number of leaf nodes in the verification coverage tree corresponding to the medical file to which the leaf node belongs is the same as the number of leaf nodes in the medical data to be audited; If the timestamp corresponding to the leaf node in the verification coverage tree is the same as the timestamp of the medical data to be audited; If there exists a bilinear mapping relationship between the second preset element corresponding to the leaf node in the verification coverage tree and the first preset element in the medical data to be audited.

6. A method for auditing medical data, characterized in that, Applied to a terminal device, the method includes: After the medical data to be audited and its attributes are sent to the cloud server for storage, an audit instruction is sent to the cloud server and the auditing end. The audit instruction includes the tag of the medical data to be audited and a first random number, so that the cloud server generates a first overlay tree and a hash structure based on the tag of the medical data to be audited and the first random number, and feeds back the first overlay tree, the hash structure and the attributes of the medical data to be audited to the auditing end. Obtain the verification pass information fed back by the auditing end based on the audit instruction, the first overlay tree, the hash structure, and the attributes of the medical data to be audited.

7. The method according to claim 6, characterized in that, The step of sending the medical data to be audited and its attributes to the cloud server for storage includes: Based on the medical data to be audited and the preset classification criteria, the medical data to be audited is divided into at least one medical sub-data. Each medical sub-data is divided into at least one data block; Use at least one data block corresponding to any medical sub-data as the leaf node of the corresponding medical sub-data hash tree to generate the corresponding medical sub-data hash tree; The hash tree corresponding to the at least one medical sub-data and the attributes of the medical data to be audited are sent to the cloud server for storage.

8. The method according to claim 6, characterized in that, The attributes of the medical data to be audited are obtained by encrypting at least one of the following stored information using a preset private key. The stored information includes at least one of the following: a first preset element, a tag of the medical data to be audited, the number of leaf nodes in the hash tree corresponding to the at least one medical sub-data, and a timestamp.

9. A method for auditing medical data, characterized in that, Applied to cloud servers, the method includes: The system obtains the medical data to be audited and its attributes sent by the terminal device, stores the medical data to be audited and its attributes, and then obtains the audit instruction sent by the terminal device. The audit instruction includes the tag of the medical data to be audited and a first random number. Based on the tags of the medical data to be audited, and the medical data to be audited, a hash structure is generated; Using a preset random number generation algorithm, based on the first random number, at least one leaf node is selected in the hash structure to generate a first covering tree; The first overlay tree, the hash structure, and the attributes of the medical data to be audited are sent to the auditing end.

10. The method according to claim 9, characterized in that, The step of using a preset random number generation algorithm to select at least one leaf node from the hash structure corresponding to the label of the medical data to be audited, based on the first random number, to generate a first covering tree includes: The algorithm is iterated using a preset random number generation algorithm until the number of iterations reaches the first random number, and then the second random number generated by the preset random number generation algorithm at the current iteration number is determined. Based on the mapping relationship between the second random number and the data blocks corresponding to the leaf nodes in the hash tree, at least one audit block corresponding to the second random number is determined; The first cover tree is generated by using the at least one audit block as a leaf node.

11. A medical data auditing device, characterized in that, The device, used in the auditing process, includes: The first instruction acquisition module is used to acquire an audit instruction sent by the terminal device, wherein the audit instruction includes a tag of the medical data to be audited and a first random number; The module for obtaining data to be verified is used to obtain the hash structure corresponding to the tag of the medical data to be audited, the attributes of the medical data to be audited, and the first overlay tree sent by the cloud server. The first overlay tree is a cover tree containing the medical data to be audited generated by the cloud server in response to the audit instruction based on the first random number and the hash structure. The attributes of the medical data to be audited are data after the terminal device encrypts the storage information of the medical data to be audited based on a preset private key. A second cover tree generation module is used to select at least one leaf node from the hash structure based on the first random number using a preset random number generation algorithm to form a second cover tree. The verification module is used to decrypt the attributes of the medical data to be audited using a pre-acquired public key, and based on the attributes of the medical data to be audited obtained after decryption, to verify the attributes of each leaf node in the first coverage tree and the second coverage tree. If there is a mapping relationship between the attributes of the corresponding leaf nodes in the first coverage tree and the second coverage tree, the module sends verification pass information to the terminal device.

12. A medical data auditing device, characterized in that, Applied to a terminal device, the device includes: The module for sending auditable data is used to send the medical data to be audited and its attributes to the cloud server for storage, and then send an audit instruction to the cloud server and the auditing end. The audit instruction includes the tag of the medical data to be audited and a first random number, so that the cloud server generates a first overlay tree and a hash structure based on the tag of the medical data to be audited and the first random number, and feeds back the first overlay tree, the hash structure and the attributes of the medical data to be audited to the auditing end. The verification information acquisition module is used to acquire the verification pass information fed back by the auditing end based on the auditing instruction, the first overlay tree, the hash structure, and the attributes of the medical data to be audited.

13. A medical data auditing device, characterized in that, The device, applied to cloud servers, includes: The second instruction acquisition module is used to acquire the medical data to be audited and the attributes of the medical data to be audited sent by the terminal device, store the medical data to be audited and the attributes of the medical data to be audited, and then acquire the audit instruction sent by the terminal device. The audit instruction includes the tag of the medical data to be audited and a first random number. A hash structure generation module is used to generate a hash structure based on the tags of the medical data to be audited and the medical data to be audited. A first cover tree generation module is used to generate a first cover tree by selecting at least one leaf node in the hash structure based on the first random number using a preset random number generation algorithm. The sending module is used to send the first overlay tree, the hash structure, and the attributes of the medical data to be audited to the auditing end.