Medical information management system and management method
By adopting data partition isolation storage and encryption technology in the medical information management system and combining access rights control, the problem of insufficient confidentiality of users' medical information in the existing system is solved, and higher information security and confidentiality are achieved.
Patent Information
- Application Number
- CN202411853293.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-16
- Publication Date
- 2025-05-06
AI Technical Summary
The existing medical information management system has defects in the confidentiality of user medical information, which can easily lead to information leakage and cannot effectively protect user medical privacy.
A medical information management system is designed, using data partition isolation storage and encryption technology, restricting staff's viewing rights through access rights control, and using encryption to protect the privacy of users' medical information.
It improves the security and confidentiality of user medical information, prevents information leakage, and ensures comprehensive protection and leakage protection of user medical information.
Smart Images

Figure CN119939619A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of medical technology, and in particular to a medical information management system and a management method. Background Art
[0002] Medical information management system is a frontier science that integrates medicine, information, management, computer and other disciplines. It has been widely used in developed countries and has created good social and economic benefits. Medical information management system is the necessary technical support and infrastructure for modern hospital operations. The purpose of implementing medical information management system is to strengthen hospital management, improve hospital work efficiency, and improve medical quality with more modern, scientific and standardized means, thereby establishing a new image of modern hospitals. This is also the inevitable direction of future hospital development. User medical information needs to be managed through the management system;
[0003] At present, the confidentiality measures for users' medical information in the medical information management system are poor. It is easy for different staff to retrieve user information at will due to the simple opening method and unlimited opening permissions, resulting in the leakage of medical information and the failure to protect the privacy of users' medical care;
[0004] In view of the above technical defects, a solution is now proposed. Summary of the invention
[0005] The purpose of the present invention is to provide a medical information management system and management method, which has good confidentiality, can partition and isolate the medical information used for storage, and limit the viewing of staff according to the setting of access rights, while protecting the privacy of user medical information in an encrypted manner, so as to solve the problems raised in the above-mentioned background technology.
[0006] To achieve the above object, the present invention provides the following technical solution: a medical information management system, comprising:
[0007] Data collection module, which collects user information by inputting it through a computer terminal;
[0008] Data processing module, pre-processing the collected data information;
[0009] Data analysis module, which classifies and summarizes the processed data information;
[0010] Data isolation storage module, which partitions and isolates the classified data for storage;
[0011] Data access control module, which opens the data information stored in partition isolation by verifying the visitor information;
[0012] The data encryption module encrypts the user's medical data information and uses the secret key to open and query the user's detailed information.
[0013] Exemplarily, the data isolation storage module includes a data partition isolation module and a data storage module, which first partitions and isolates the collected different data information, and divides the data to be stored into several groups of data blocks according to predetermined rules for storage.
[0014] Exemplarily, the data storage module includes a physical backup unit and a cloud backup unit;
[0015] Includes data files and log files that need to be backed up in the database;
[0016] The physical backup unit directly copies the database files and logs to complete the backup;
[0017] Monitor Redo log changes: Before the backup starts, continuously monitor the changes in the Redo log and record the changes in the data;
[0018] Copy data files: Send data files to backup storage through data streams, monitor changes in Redo logs, and back up changed data to storage;
[0019] Back up Binlog log files: Back up Binlog log files to storage to ensure the integrity of the logs;
[0020] Write original data information: After the backup is completed, the backup metadata information is written to the backup storage to form a complete time point.
[0021] Exemplary, differential backup is also included:
[0022] Back up incremental data blocks based on the last successful full backup; when restoring to the differential backup time point, you only need to apply the differential backup data blocks to the full backup data, and finally restore the full backup data to the MySQL data directory and start the database service.
[0023] Exemplarily, the cloud backup unit includes:
[0024] The data information is transmitted via the network to a remote cloud server for storage, and the data information is encrypted and compressed during the storage process.
[0025] Exemplarily, in the data access control module, role-based access control (RBAC) and session management are used to limit user access rights, set and collect user names, passwords, IP address ranges, user roles, etc.
[0026] Exemplarily, when inputting information access rights, the user information includes the user identification, the group to which the user belongs, the user terminal type, and at least a medical information management system in the department to which the user belongs.
[0027] Exemplarily, when accessing information files, the files are opened by inputting a user name and password, a magnetic card, a fingerprint, or any combination of other medical information management systems.
[0028] Exemplarily, the data encryption module includes: generating a unique identifier and a timestamp for each piece of user data, including: data encryption and hash generation: encrypting each piece of identified and extracted user-related information.
[0029] The medical information management method comprises the following steps:
[0030] S1: User medical data collection, collecting user medical information data through data terminals;
[0031] S2: Data processing, pre-processing the collected user medical data;
[0032] S3: Data analysis, classifying and summarizing the pre-processed user medical data;
[0033] S4: Data isolation storage, partitioning and isolating the classified data;
[0034] S5: Data access control, opening the data information stored in partition isolation by verifying the visitor information;
[0035] S6: Data encryption: Encrypt user medical data information, and use the secret key to open and query user details.
[0036] Compared with the prior art, the present invention has the following beneficial effects:
[0037] The present invention improves the security and confidentiality of user medical information by controlling access rights and encrypting user medical data. It can not only prevent leakage, but also avoid data leakage when data is damaged, thereby comprehensively protecting and preventing leakage of medical data. Secondly, partition isolation is used to separate storage for different uses, so as to facilitate query and storage as well as prevent leakage. Different access rights can further protect the medical information of important users. The encryption method can be used to encrypt the medical information of each user, and medical personnel outside the department cannot open it with the corresponding secret key, thereby realizing the confidentiality and security protection of medical users' information in multiple directions.
[0038] Other features and advantages of the present invention will be described in the following description, and partly become obvious from the description, or be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is a system block diagram of the present invention;
[0040] Figure 2 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION
[0041] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0042] The present invention provides a medical information management system, comprising:
[0043] Data collection module, which collects user information by inputting it through a computer terminal;
[0044] Data processing module, pre-processing the collected data information;
[0045] Data analysis module, which classifies and summarizes the processed data information;
[0046] Data isolation storage module, which partitions and isolates the classified data for storage;
[0047] Data access control module, which opens the data information stored in partition isolation by verifying the visitor information;
[0048] The data encryption module encrypts the user's medical data information and uses the secret key to open and query the user's detailed information.
[0049]
[0050] Among them, x i represents the i-th archive data after normalization, X i represents the i-th original archive data, X max , X min Respectively represent the maximum and minimum values of the original archive data;
[0051] The data analysis module (300) extracts data features and analyzes abnormal data based on the normalized archive data;
[0052] The feature extraction is as follows:
[0053] After preprocessing, we obtain the archive data set x, which contains L characteristic attributes:
[0054] x=p(L)+r(L)
[0055] Among them, p(l) is the characteristic attribute parameter of the archive data, and r(l) is the discrete parameter;
[0056] Decompose the characteristic attribute parameter p(l) and extract the archive characteristic data p i :
[0057]
[0058] p i =p q +p l
[0059] Among them, A(w i ) is the set of rule vectors of discrete ranges, α is the number of discrete ranges, p q 、p l is the qth and lth characteristic attributes in the characteristic attribute parameters, r i is the eigenvalue vector of the i-th (i∈(1,M)) archive data, r is the centroid of the archive data, (r i -r) T Represents data r i - transpose of r, w i is the weight of the i-th archive data;
[0060] In the process of abnormal data analysis, the improved particle swarm algorithm is used to traverse the archive feature data points, and the cluster center point is selected with the minimum distance between the archive feature data point and the cluster center point as the fitness function; the particle population is initialized, and the particles are iteratively updated through the following algorithm to find the optimal solution:
[0061]
[0062] in, represents the speed of the nth particle at the t+1th iteration, represents the speed of the nth particle at the tth iteration, represents the position of the nth particle at the t+1th iteration, represents the position of the nth particle at the tth iteration, ω is the inertia weight of the particle, r1 and r2 are both random numbers between [0,1], represents the individual's best historical position; represents the optimal position of the group;
[0063] ω changes according to the number of iterations:
[0064]
[0065] Among them, ω max is the maximum weight, ω min is the minimum weight, is the chaotic variable, u is the number of chaotic iterations, v is the variable dimension, t max Indicates the maximum number of iterations.
[0066] The improved particle algorithm divides the input D-dimensional archival feature data into N categories. The number of archival data feature clustering centers after division is D×N. The archival data is clustered:
[0067]
[0068] Among them, p dj is the j-th category archive data feature of the d-th dimension (d∈[1,D]), n dj is the number of features of the j-th category archive data in the d-th dimension, c dj is the cluster center of the j-th data feature in the d-th dimension;
[0069] Based on the softmax classifier, the abnormal threshold is divided to identify the abnormality of the archival data based on the clustering results of the archival data;
[0070] Preferred:
[0071] The data isolation storage module includes a data partition isolation module and a data storage module. Different collected data information is first partitioned and isolated, and the data to be stored is divided into several groups of data blocks according to predetermined rules for storage.
[0072] Store the above data in the preset database and divide it reasonably, such as partitioning or establishing an independent database, to achieve data isolation between different modules;
[0073] At the same time, container technologies, such as Docker, will be used to encapsulate each module into an independent container to improve system availability;
[0074] in:
[0075] The data storage module includes a physical backup unit and a cloud backup unit;
[0076] Includes data files and log files that need to be backed up in the database;
[0077] The physical backup unit directly copies the database files and logs to complete the backup;
[0078] Monitor Redo log changes: Before the backup starts, continuously monitor the changes in the Redo log and record the changes in the data;
[0079] Copy data files: Send data files to backup storage through data streams, monitor changes in Redo logs, and back up changed data to storage;
[0080] Back up Binlog log files: Back up Binlog log files to storage to ensure the integrity of the logs;
[0081] Write original data information: After the backup is completed, the backup metadata information is written to the backup storage to form a complete time point.
[0082] Data recovery: In the event of data loss or damage, data can be quickly restored through physical backup to ensure continuous operation of the system
[0083] Disaster recovery: Physical backup is one of the prerequisites for system disaster recovery, which can provide protection in the event of hardware failure or human error.
[0084] Efficiency and real-time performance: Physical backup is located below the file system and above the hardware disk drive, ignoring files and structures. The processing process is simple, the backup performance is high, and efficient real-time backup can be achieved.
[0085] Support various file systems: Physical backup is not limited by the file system and can support various file systems, including RAW partitions;
[0086] Additionally, differential backups are included:
[0087] Back up incremental data blocks based on the last successful full backup; when restoring to the differential backup time point, you only need to apply the differential backup data blocks to the full backup data, and finally restore the full backup data to the MySQL data directory and start the database service.
[0088] Save storage space: Differential backup only records the changed data since the last full backup, so the backup file is usually much smaller than the full backup, which effectively saves storage space, especially when the data does not change much;
[0089] Improve backup speed: Since differential backup only records changed data, the backup process is much faster than full backup, reducing the impact of backup operations on system performance;
[0090] Speed up recovery: When restoring a database, you only need to restore the last full backup first, and then apply the latest differential backup, which greatly simplifies the recovery process and improves the recovery speed;
[0091] Reduce the possibility of errors: By restoring the full backup first and then applying the differential backup, the possibility of errors during the recovery process is reduced.
[0092] Further, the cloud backup unit includes:
[0093] The data information is transmitted via the network to a remote cloud server for storage, and the data information is encrypted and compressed during the storage process.
[0094] Data protection: The primary purpose of cloud backup is to protect data from various potential threats, including hardware failure, human error, malicious attacks, etc. By backing up data to the cloud, even if local data is damaged or lost, it can be quickly restored from the cloud to ensure data integrity and availability;
[0095] Disaster recovery: In unforeseen events such as natural disasters, fires, and floods, local data backups are often unavoidable. Cloud backups, however, can effectively resist these catastrophic events because data is stored on remote servers, ensuring that enterprises can quickly resume business operations after a disaster.
[0096] Business continuity guarantee: For critical businesses, any data loss or interruption may lead to serious economic losses and customer trust crisis. Cloud backup ensures business continuity and stability by providing instant data recovery capabilities, reducing the risk of business interruption caused by data problems;
[0097] Cost optimization: Compared with traditional local backup solutions, cloud backup has significant advantages in hardware investment, maintenance costs, personnel training, etc. You can flexibly select backup capacity and service level according to actual needs to achieve cost optimization.
[0098] Furthermore, in the data access control module, role-based access control (RBAC) and session management are used to limit user access rights, set and collect user names, passwords, IP address ranges, and user roles.
[0099] Authentication: Before users access data, they need to authenticate their identities and permissions. Authentication can be performed using usernames, passwords, certificates, etc., and sensitive information such as passwords is encrypted to ensure the security of user information.
[0100] Permission control: Control the user's access to data based on the user's identity and permissions. You can use roles or access control lists to implement permission control to ensure that only authorized users or applications can access data;
[0101] Audit log: records information about user access to data in order to monitor and audit user access behavior. Audit logs can record user identity, access time, access content and other information, while protecting audit logs to prevent them from being tampered with or deleted;
[0102] Prevent data leakage and illegal operations: Through strict permission control, users' data operation permissions can be limited to prevent sensitive data from being illegally obtained or tampered with, thus ensuring data availability;
[0103] Improve system security: Through mechanisms such as identity authentication, permission control and audit logs, the security of the system can be effectively improved to prevent unauthorized access and operation;
[0104] Among them, when inputting information access rights, the user information includes the user identification, the user group, the user terminal type, and at least the medical information management system in the user's department. Each department cannot access each other, and its permissions are blocked, so as to better realize the protection of medical use in each department.
[0105] In addition, when information is accessed, the file can be opened by entering a user name and password, magnetic card, fingerprint, or any other medical information management system or a combination thereof. It can be opened according to the user name and password, magnetic card, fingerprint, or any other medical information management system or a combination thereof that is specially equipped for different medical personnel in each department. And because partitioned and isolated storage is performed during the storage process, each area is equipped with corresponding medical personnel for information, and only the corresponding responsible medical staff can open it. It can be opened by a single method or by a combination of the above methods.
[0106] Finally, the data encryption module includes: generating a unique identifier and timestamp for each piece of user data, including: data encryption and hash generation: encrypting each piece of identified and extracted user-related information.
[0107] Use a pair of keys: a public key and a private key. The public key is used to encrypt data, while the private key is used to decrypt data. The characteristic of this encryption method is that different keys are used for encryption and decryption, thus ensuring the security of data;
[0108] Key generation: Asymmetric encryption algorithms generate a pair of keys: a public key and a private key. The public key can be made public, while the private key must be kept secret.
[0109] Encryption process: The sender uses the receiver's public key to encrypt the data. Since only the receiver has the corresponding private key, only the receiver can decrypt the data.
[0110] Decryption process: The receiver uses his own private key to decrypt the encrypted data and restore the original data.
[0111] The medical information management method comprises the following steps:
[0112] S1: User medical data collection, collecting user medical information data through data terminals;
[0113] S2: Data processing, pre-processing the collected user medical data;
[0114] S3: Data analysis, classifying and summarizing the pre-processed user medical data;
[0115] S4: Data isolation storage, partitioning and isolating the classified data;
[0116] S5: Data access control, opening the data information stored in partition isolation by verifying the visitor information;
[0117] S6: Data encryption: Encrypt user medical data information, and use the secret key to open and query user details.
[0118] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A medical information management system, characterized in that: include: Data collection module, which collects user information by inputting it through a computer terminal; Data processing module, pre-processing the collected data information; Data analysis module, which classifies and summarizes the processed data information; Data isolation storage module, which partitions and isolates the classified data for storage; Data access control module, which opens the data information stored in partition isolation by verifying the visitor information; The data encryption module encrypts the user's medical data information and uses the secret key to open and query the user's detailed information.
2. The medical information management system according to claim 1, characterized in that: The data isolation storage module includes a data partition isolation module and a data storage module. Different collected data information is first partitioned and isolated, and the data to be stored is divided into several groups of data blocks according to predetermined rules for storage.
3. The medical information management system according to claim 2, characterized in that: The data storage module includes a physical backup unit and a cloud backup unit; Includes data files and log files that need to be backed up in the database; The physical backup unit directly copies the database files and logs to complete the backup; Monitor Redo log changes: Before the backup starts, continuously monitor the changes in the Redo log and record the changes in the data; Copy data files: Send data files to backup storage through data streams, monitor changes in Redo logs, and back up changed data to storage; Back up Binlog log files: Back up Binlog log files to storage to ensure the integrity of the logs; Write original data information: After the backup is completed, the backup metadata information is written to the backup storage to form a complete time point.
4. The medical information management system according to claim 3, characterized in that: Differential backups are also included: Back up incremental data blocks based on the last successful full backup; When restoring to the differential backup time point, you only need to apply the differential backup data blocks to the full backup data, and finally restore the full backup data to the MySQL data directory and start the database service.
5. The medical information management system according to claim 3, characterized in that: The cloud backup unit comprises: The data information is transmitted via the network to a remote cloud server for storage, and the data information is encrypted and compressed during the storage process.
6. The medical information management system according to claim 1, characterized in that: In the data access control module, role-based access control (RBAC) and session management are used to limit user access rights, set and collect user names, passwords, IP address ranges, user roles, etc.
7. The medical information management system according to claim 6, characterized in that: When inputting information access rights, the user information includes the user identification, the group to which the user belongs, the user terminal type, and at least the medical information management system in the department to which the user belongs.
8. The medical information management system according to claim 7, characterized in that: When accessing information files, the files can be opened by entering username and password, magnetic card and fingerprint, etc., in any medical information management system or a combination thereof.
9. The medical information management system according to claim 1, characterized in that: The data encryption module includes: generating a unique identifier and a timestamp for each piece of user data, including: data encryption and hash generation: encrypting each piece of identified and extracted user-related information.
10. A medical information management method, comprising the medical information management system according to any one of claims 1 to 9, characterized in that: The steps include: S1: User medical data collection, collecting user medical information data through data terminals; S2: Data processing, pre-processing the collected user medical data; S3: Data analysis, classifying and summarizing the pre-processed user medical data; S4: Data isolation storage, partitioning and isolating the classified data; S5: Data access control, opening the data information stored in partition isolation by verifying the visitor information; S6: Data encryption: Encrypt user medical data information, and use the secret key to open and query user details.