Medical data trusted processing method and system based on smart contract

Medical data transactions are carried out through smart contracts and blockchain platforms, and the problem of high data privacy leakage and maintenance costs in medical data transactions in existing technology is solved, and data privacy protection and cost reduction are achieved.

CN119993359AInactive Publication Date: 2025-05-13CHONGQING UNIV

Patent Information

Application Number
CN202510063698.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing medical data transaction methods pose a risk of data privacy leakage, and the maintenance cost of medical data is high.

Method used

Using a trusted medical data processing method based on smart contracts, the system public parameters and system master key are generated through the key generation center, the entity generates entity key pairs, and medical data transactions are used to ensure data privacy and transparency.

Benefits of technology

It realizes data privacy protection, reduces the maintenance cost of medical data, and reduces the trust cost through automated transaction verification and execution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119993359A_ABST
    Figure CN119993359A_ABST
Patent Text Reader

Abstract

The invention relates to a data security technology, and discloses a medical data trusted processing method based on an intelligent contract, which comprises the following steps: a key generation center generates system public parameters and a system master key; the data purchaser initiates a medical data transaction application to the block chain platform according to the transaction number, the medical data processing keyword and the data purchaser IP address, and deploys an intelligent contract in the block chain platform; the data purchaser and the data manager serve as two transaction parties to generate data demand features according to the smart contract; the data manager encrypts the medical data according to the data demand features to obtain encrypted medical data; the data manager performs zero-knowledge verification, and the proxy re-encryption module converts the encrypted medical data into an intermediary ciphertext and sends the intermediary ciphertext to the data purchaser; and the data purchaser decrypts the medium ciphertext to obtain the medical data. The invention further provides a system of the medical data credible processing method based on the smart contract, data privacy can be protected, and the maintenance cost of the medical data can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a medical data trusted processing method and system based on smart contracts. Background Art

[0002] With the continuous advancement of technologies such as big data and artificial intelligence, the in-depth mining and analysis of medical data has become an important means to promote medical research and clinical decision-making. However, due to the existence of data silos and information barriers, a large amount of medical data is locked in independent data managers and data buyers and cannot be fully utilized. Therefore, it is particularly important to carry out medical data transactions.

[0003] Medical data trading refers to the process of sharing medical data resources between data managers (such as hospitals, disease rehabilitation centers, etc.) and data buyers (such as various medical and disease research institutions). As important participants in medical data trading, data owners and data buyers have important significance for promoting the advancement of medical technology and upgrading medical services. For example, as one of the main sources of medical data, data managers have rich clinical data and patient information, which are of great reference value for data buyers to conduct medical research. Data buyers have professional data analysis technology and research capabilities, which can deeply explore the potential value of medical data and provide scientific and effective diagnosis and treatment suggestions and technical support for data managers. Through medical data trading between data managers and data buyers, we can achieve complementary advantages and win-win sharing of data resources, promote the close integration of medical research and clinical practice, and promote the sustainable and healthy development of the medical industry.

[0004] Existing medical data transaction methods include the following: 1. Direct transaction method, 2. Lease and retrieval transaction method, 3. Short-term and long-term transaction method. The direct transaction method will make it difficult to ensure the security of medical data, there is a risk of data leakage and abuse, and it is difficult for both parties to accurately assess the value of the data, which may lead to unreasonable prices. In the lease and retrieval transaction method, the buyer can use the data flexibly according to actual needs, but the profit sharing mechanism is difficult to implement because it is impossible to accurately define the profit range obtained from the data, and the buyer may face additional costs for data updates and maintenance. In the short-term and long-term transaction method, short-term transactions may cause the buyer to need to purchase additional data updates in the future, while long-term transactions may increase the buyer's performance costs and risks. For example, changes in data type, accuracy, quantity and other requirements may lead to renegotiation or price reduction requirements. The above transaction methods have the risk of data privacy leakage, and the maintenance cost of medical data is high. Summary of the invention

[0005] The present invention provides a medical data trusted processing method and system based on smart contracts, which can protect data privacy and reduce the maintenance cost of medical data.

[0006] To achieve the above purpose, the present invention provides a medical data trusted processing method based on smart contracts, comprising:

[0007] The key generation center generates system public parameters and system master keys, and distributes the system public parameters and system master keys to entities, and assists the entities in generating entity key pairs, wherein the entities include patient devices, data managers, and data buyers, and the entity key pairs include patient device key pairs, data manager key pairs, and data buyer key pairs;

[0008] The data buyer initiates a medical data transaction application to the blockchain platform based on the transaction number, medical data processing keywords, and the data buyer's IP address, and deploys a smart contract on the blockchain platform;

[0009] The data buyer and the data manager, as the two parties in the transaction, generate a zero-knowledge proof based on the smart contract to obtain the data demand characteristics;

[0010] The data manager encrypts the medical data according to the data demand characteristics to obtain encrypted medical data, and uploads the encrypted medical data to the information storage and recording module of zero-knowledge proof;

[0011] The data manager performs zero-knowledge verification. If the verification is successful, the patient device generates a conversion key using the public key in the data buyer's key pair and stores the conversion key in the proxy re-encryption module. The proxy re-encryption module converts the encrypted medical data into an intermediate ciphertext and sends it to the data buyer.

[0012] The data buyer obtains the intermediate ciphertext from the proxy re-encryption module, and uses the private key in the data buyer's key pair to decrypt the intermediate ciphertext to obtain the medical data.

[0013] Optionally, the key generation center generates system public parameters and a system master key, including:

[0014] The key generation center inputs the security parameter λ and selects two multiplication cyclic groups G1 and G2 generated by prime numbers p;

[0015] Use the multiplication cyclic group G1 and the multiplication cyclic group G2 to set up a cryptographic bilinear map, select a secure hash function to map the elements in the multiplication cyclic group G1 and the multiplication cyclic group G2, and generate an integer multiplication group

[0016] The key generation center randomly selects three integers from the integer multiplication group to generate the system master key, and selects generators from the multiplication cyclic group G1, and combines the prime number p, the multiplication cyclic group G1, the multiplication cyclic group G2 and the hash function to generate the system public parameters.

[0017] Optionally, distributing the system public parameters and the system master key to the entity to assist the entity in generating an entity key pair includes:

[0018] The key generation center randomly selects four integers from the integer multiplication group, generates patient device encryption parameters according to the patient identifier using a preset parameter generation method, and generates a patient device key pair according to the patient device encryption parameters.

[0019] Optionally, the data buyer and the data manager, as the transaction parties, generate a zero-knowledge proof according to the smart contract, including:

[0020] The data manager calls the smart contract to query the medical data processing keywords and extracts the keyword medical data based on the medical data processing keywords. After binding the keyword medical data to the personal digital signature, the first zero-knowledge proof is generated. The data buyer generates the second zero-knowledge proof based on the medical data he needs.

[0021] Optionally, the step of binding the keyword medical data to the personal digital signature and generating the first zero-knowledge proof includes:

[0022] The data manager generates extended information based on the patient device's identity, current local time, and private medical data of the patient device;

[0023] Select a random integer from the integer multiplication group, and perform hash calculation on it in conjunction with the extended information to obtain an extended hash operation value;

[0024] Generate a digital signature using a preset digital signature calculation formula according to the extended hash operation value and the patient device private key in the patient device key pair;

[0025] The data manager constructs a computing logic circuit based on the medical data computing keywords provided by the data buyer, generates a zero-knowledge key pair based on the security parameters and the computing logic circuit, and generates a trusted zero-knowledge proof based on the generated key, medical data, digital signature, computing logic circuit output result, and computing logic circuit hash value output result in the zero-knowledge key pair.

[0026] Optionally, the data manager performs zero-knowledge verification, including:

[0027] The first zero-knowledge proof and the second zero-knowledge proof are stored in a zero-knowledge proof verification module, and the digital signature of the patient device is verified using the patient device public key in the patient device key pair. After the verification is passed, the first zero-knowledge proof is checked using the verification key in the zero-knowledge key pair, and the zero-knowledge verification is completed after the check is completed.

[0028] Optionally, the patient device generates a conversion key using a public key in a data buyer key pair, including:

[0029] The conversion key RK is generated using the following formula: p→d :

[0030] ReKeyGen(PK,Sk p ,PK d )→RK p→d

[0031] Among them, PK is the system common parameter, SK p The patient device private key, PK d The public key of the data buyer in the data buyer key pair;

[0032] ReKete(PK,SK p ,PK d ) represents the conversion key generation function, and the processing process includes:

[0033] The key generation center randomly selects two integers Calculate the following parameter values ​​and generate the conversion key RK p→d ,in, is the multiplicative group of integers:

[0034] rk1=(k1B3+B1)+(k2B3+B2)*ID p

[0035]

[0036] R p→d =(rk1,rk2)

[0037] Among them, rk1 is the first part of the key, rk2 is the second part of the key, B1 is the first conversion parameter, B2 is the second conversion parameter, B3 is the third conversion parameter, ID p is the patient identifier, D1 is the fourth conversion parameter, D2 is the fifth conversion parameter, and D3 is the sixth conversion parameter.

[0038] In order to solve the above problems, the present invention also provides a system of a medical data trusted processing method based on smart contracts, including a blockchain platform, a data buyer, a data manager, a key generation center and a patient device. The patient device communicates with the data manager in a two-way manner. The data manager and the patient device send medical data features to the blockchain platform, and the data buyer sends medical data requirements to the blockchain platform.

[0039] Optionally, the key generation center generates system public parameters and system master keys, and distributes the system public parameters and system master keys to entities to assist the entities in generating entity key pairs, wherein the entities include patient devices, data managers and data buyers, and the entity key pairs include patient device key pairs, data manager key pairs and data buyer key pairs.

[0040] Optionally, the blockchain platform includes a smart contract, in which data availability matching and proxy re-encryption are performed.

[0041] The key generation center of the present invention generates key pairs for patient devices, data managers and data buyers, which can ensure that each entity has an independent key to prevent data risks caused by key leakage. In addition, the data buyer and the data manager, as the two parties to the transaction, generate zero-knowledge proofs according to the smart contract to avoid directly sharing sensitive data and realize the privacy protection of the patient's device. In addition, the encrypted medical data is converted into an intermediate ciphertext through the proxy re-encryption module, so that the data buyer cannot directly access the original data and must decrypt it through the conversion key, further enhancing data privacy protection. In addition, all transaction applications and operation records are stored on the blockchain, which can ensure the transparency of data transactions. Through the blockchain and smart contracts, the data buyer and the data manager do not need to fully trust each other. The system automatically verifies and executes transactions, reduces the trust cost, and uses zero-knowledge proofs for verification, so that the verification process does not need to disclose sensitive information, reducing dependence on third-party verification agencies. The present invention can protect data privacy and reduce the maintenance cost of medical data. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 A flowchart of a medical data trusted processing method based on smart contracts provided by an embodiment of the present invention;

[0043] Figure 2 A system diagram of a medical data trusted processing method based on smart contracts provided by an embodiment of the present invention;

[0044] Figure 3 A smart contract function diagram of a medical data trusted processing method based on a smart contract provided by an embodiment of the present invention;

[0045] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0046] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0047] The embodiment of the present application provides a medical data trusted processing method based on smart contracts. The execution subject of the medical data trusted processing method based on smart contracts includes but is not limited to at least one of the electronic devices such as the server and the terminal that can be configured to execute the method provided by the embodiment of the present application. In other words, the medical data trusted processing method based on smart contracts can be executed by software or hardware installed on a terminal device or a server device, and the software can be a blockchain platform. The server includes but is not limited to: a single server, a server cluster, a cloud server or a cloud server cluster, etc. The server can be an independent server, or it can be a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (Content Delivery Network, CDN), and basic cloud computing services such as big data and artificial intelligence platforms.

[0048] Reference Figure 1 FIG. 1 is a flow chart of a medical data trust processing method based on smart contracts provided by an embodiment of the present invention. In this embodiment, the medical data trust processing method based on smart contracts includes:

[0049] S1. The key generation center generates system public parameters and system master keys, and distributes the system public parameters and system master keys to entities to assist the entities in generating entity key pairs, wherein the entities include patient devices, data managers and data buyers, and the entity key pairs include patient device key pairs, data manager key pairs and data buyer key pairs.

[0050] In the embodiment of the present invention, the key generation center refers to a fully trusted entity that is responsible for generating master keys, system parameters, and distributing public keys and secret keys to patient devices, data managers (when necessary), and data buyers.

[0051] In the embodiment of the present invention, the data manager is a data management organization. The patient will entrust and authorize the data manager to encrypt the medical data and conduct data transactions. As the actual owner of the medical data, the patient should safely own and control his or her private medical and health data and gain benefits in the process. The data manager includes but is not limited to hospitals and disease rehabilitation centers.

[0052] In the embodiment of the present invention, the data buyer refers to a typical data buyer who needs medical data for health science research. They usually entrust smart contracts to publish the attribute requirements of medical data. They do not believe that the medical data provided by the patient's device will meet their requirements, and they hope to use smart contracts to ensure the validity and availability of the data. In the embodiment of the present invention, the data buyer includes but is not limited to various medical and disease research institutions.

[0053] As an embodiment of the present invention, a key generation center generates system public parameters and a system master key, including:

[0054] The key generation center inputs the security parameter λ and selects two multiplication cyclic groups G1 and G2 generated by prime numbers p;

[0055] Use the multiplication cyclic group G1 and the multiplication cyclic group G2 to set up a cryptographic bilinear map, select a secure hash function to map the elements in the multiplication cyclic group G1 and the multiplication cyclic group G2, and generate an integer multiplication group

[0056] The key generation center randomly selects three integers from the integer multiplication group to generate the system master key, and selects generators from the multiplication cyclic group G1, and combines the prime number p, the multiplication cyclic group G1, the multiplication cyclic group G2 and the hash function to generate the system public parameters.

[0057] Exemplarily, the key generation center may generate system public parameters and system master keys by using the following implementation steps:

[0058] Step 1: PKG (key generation center) first inputs a security parameter λ, selects two multiplication cyclic groups G1 and G2 generated by prime number p, and sets e: G1×G1→G2 as an encryption bilinear map;

[0059] Step 2: PKG selects four secure hash functions H: {0,1}*→{0,1} k ,

[0060] Step 3: PKG random selection For different generators of G1, then use the following formula Setup(1 λ )→(PK, MSK) Generate public parameters and master key, where PK = (p, G1, G2, e, g, h, H, H1, H2, H3), MSK = (a, b, c);

[0061] The patient device pi provides its unique identifier IDp to PKG, which will generate a key pair (PK p , S.K. p ), where PKp The patient device public key, SK p Private key for the patient's device;

[0062] PKG random selection And calculate the following parameter values:

[0063]

[0064] D1=h x , D2=h y , D3=h z

[0065] Finally, the patient device private key SK p =(A1, A2, A3, B1, B2, B3, D1, D2, D3) will be generated, where (A1, A2, A3) is used to decrypt the ciphertext, and (B1, B2, B3, D1, D2, D3) is used to construct the transformation key RK p→d , where A1 is the first decryption parameter, A2 is the second decryption parameter, A3 is the third decryption parameter, B1 is the first conversion parameter, B2 is the second conversion parameter, B3 is the third conversion parameter, D1 is the fourth conversion parameter, D2 is the fifth conversion parameter, and D3 is the sixth conversion parameter.

[0066] In addition, the data manager and the data buyer can obtain the key pair respectively through the same procedure.

[0067] S2. The data buyer initiates a medical data transaction application to the blockchain platform based on the transaction number, medical data processing keywords and the data buyer's IP address, and deploys a smart contract in the blockchain platform.

[0068] In the embodiment of the present invention, the blockchain platform refers to a data storage platform, and the data stored in the blockchain will be retained as evidence. It is also responsible for executing the distributed consensus of the transaction. In addition, the smart contract on the blockchain is mainly responsible for matching the needs and characteristics of the two parties to the transaction, that is, automatically judging the validity of the zero-knowledge proof without the participation of a third party.

[0069] In the embodiment of the present invention, before the data purchaser initiates a medical data transaction application to the blockchain platform according to the transaction number, medical data processing keywords and the data purchaser's IP address, the blockchain platform also includes: the blockchain platform assigns a blockchain address to each entity, and assigns a blockchain function and a blockchain role to each entity, and assigns a blockchain certificate to each entity through the blockchain role, wherein the blockchain certificate includes a registration certificate and a transaction certificate. In the embodiment of the present invention, the blockchain platform can adopt the Fabric blockchain platform, which is a permissioned blockchain. Only authenticated members can join the network to ensure data privacy and security.

[0070] For example, deploying smart contracts in a blockchain platform can be achieved by the following implementation steps:

[0071] Data Buyer RI j Initiate a transaction on the Fabric blockchain platform to send the transaction number, medical data processing keywords, and data buyer's IP address RI The transaction number No is the unique identifier of this transaction. j Only sending task keywords without executing subsequent steps, RI j A certain fee needs to be paid to the pre-stored value module in the contract as a reward to the data seller.

[0072] S3. The data buyer and the data manager, as the two parties in the transaction, generate a zero-knowledge proof based on the smart contract to obtain the data demand characteristics.

[0073] As an embodiment of the present invention, the data buyer and the data manager, as the two parties of the transaction, generate a zero-knowledge proof according to the smart contract, including:

[0074] The data manager calls the smart contract to query the medical data processing keywords and extracts the keyword medical data based on the medical data processing keywords. After binding the keyword medical data to the personal digital signature, the first zero-knowledge proof is generated. The data buyer generates the second zero-knowledge proof based on the medical data he needs.

[0075] Furthermore, the keyword medical data is bound to the personal digital signature to generate the first zero-knowledge proof, including:

[0076] The data manager generates extended information based on the patient device's identity, current local time, and private medical data of the patient device;

[0077] Select a random integer from the integer multiplication group, and perform hash calculation on it in conjunction with the extended information to obtain an extended hash operation value;

[0078] Generate a digital signature using a preset digital signature calculation formula according to the extended hash operation value and the patient device private key in the patient device key pair;

[0079] The data manager constructs a computing logic circuit based on the medical data computing keywords provided by the data buyer, generates a zero-knowledge key pair based on the security parameters and the computing logic circuit, and generates a trusted zero-knowledge proof based on the generated key, medical data, digital signature, computing logic circuit output result, and computing logic circuit hash value output result in the zero-knowledge key pair.

[0080] Exemplarily, the first zero-knowledge proof is generated after binding the keyword medical data to the personal digital signature, which can be implemented by the following steps:

[0081] 1. According to the patient's device identity p i , the current local time T, and the private medical data D of the patient's device, the data manager can generate extended information δ, that is, δ = (D, T, IDp).

[0082] 2. Take the extended information δ = (D, T, IDp) as input, and fill in a random integer r selected from the integer multiplication group for hash operation, and H(δ, r) can be calculated.

[0083] 3. Generate digital signature σ a =AuthSign(SK p , H(δ, r)), where Sk P Patient device p i The private key of the password is , and H(δ, r) is the hash value calculated previously.

[0084] 4. The data manager constructs a computational logic circuit C based on the medical data processing keywords provided by the data buyer: The calculation logic circuit C converts the common parameter vector <PK1, PK2...PK n >, medical data set <d1, d2, ..., d n , r> and auxiliary data <ID p′ T≥ as input. Among them, ID p is the patient identifier, T is the timestamp, and r is a random number. Circuit C will output a result R and a hash value h, namely: C( <d1,d2,...,d n >)→(R, h) These two values ​​are used to verify the authenticity and availability of the data.

[0085] 5. In order to output a zero-knowledge key pair, the data manager takes the security parameter λ and the computational logic circuit C as input parameters, namely ZKPKeyGen(1 λ, C)→(EKc, VKc), where EKc is used to generate zero-knowledge proof and VKc is used to verify zero-knowledge proof.

[0086] 6. Next, use zero-knowledge proof to generate the key EKc, the medical data D of the patient’s device, and the signature σ a , the result R generated in step 4 and a hash value Then output a credible zero-knowledge proof π, namely:

[0087] Exemplarily, after the data manager generates the zero-knowledge proof π, the data buyer uses the same steps as above to output a credible zero-knowledge proof π′. The difference is that the medical data in step 1 comes from the simulated data D′ provided by the data buyer according to its own needs. Secondly, in step 4, the data buyer constructs a computational logic circuit C′ according to its specific needs for medical data.

[0088] S4. The data manager encrypts the medical data according to the data demand characteristics to obtain encrypted medical data, and uploads the encrypted medical data to the zero-knowledge proof information storage and recording module.

[0089] In the embodiment of the present invention, the data manager encrypts the medical data according to the data demand characteristics to obtain the encrypted medical data, which can be implemented by the following implementation steps:

[0090] After the data requirements of both parties are generated, the data manager will encrypt the medical data. The data manager uses the encryption function For its medical data D <d1,d2,...,d n >Encryption is performed, and the encrypted data is Right now For a single encrypted element Composed of a collection.

[0091] PKG random selection And calculate:

[0092]

[0093] in, is the first encryption element, is the second encryption element, is the third encryption element, It is the fourth encryption element.

[0094] Subsequently, the data manager initiates a transaction with the transaction number No as input and calls the information storage and reward contract to store the encrypted data of this transaction. Upload to the information storage record module for storage.

[0095] S5. The data manager performs zero-knowledge verification. If the verification is successful, the patient device uses the public key in the data buyer's key pair to generate a conversion key and stores the conversion key in the proxy re-encryption module. The proxy re-encryption module converts the encrypted medical data into an intermediate ciphertext and sends it to the data buyer.

[0096] As an embodiment of the present invention, the data manager performs zero-knowledge verification, including:

[0097] The first zero-knowledge proof and the second zero-knowledge proof are stored in a zero-knowledge proof verification module, and the digital signature of the patient device is verified using the patient device public key in the patient device key pair. After the verification is passed, the first zero-knowledge proof is checked using the verification key in the zero-knowledge key pair, and the zero-knowledge verification is completed after the check is completed.

[0098] For example, the data manager can perform zero-knowledge proof by using the following implementation steps:

[0099] The data manager initiates a transaction with the transaction number No as input and calls the unique query module in the information storage and reward contract to query the remuneration given by the data buyer. If accepted, further verification of the data demand characteristics is performed. The verification process is: store π and π′ in the zero-knowledge proof record module in the zero-knowledge proof management contract in the zero-knowledge proof verification module. Secondly, the module will automatically verify whether the zero-knowledge proof meets the requirements of the data buyer without the participation of a third party. That is, the following verification formula is used for verification: Verify(VKc, PKp, p, R, h, s a )→(True or false). (PK p , S.K. p ). First use the public key PK of the patient's device p Verify the digital signature of the patient deviceσ a , and then check the zero-knowledge proof π through the verification key VKc. If both verifications are completed, the smart contract will compare the zero-knowledge proof π, the calculation result R, and the hash value h calculated based on the medical data of the patient's device with the zero-knowledge proof π′, the calculation result R′, and the hash value h′ calculated based on the data buyer's requirements. If all verifications pass, the result of rejection (False) or acceptance (True) will be output in the proof result comparison module.

[0100] As an embodiment of the present invention, the patient device generates a conversion key using the public key in the data buyer's key pair, including:

[0101] The conversion key RK is generated using the following formula: p→d :

[0102] ReKeyGen(PK, SKp , PK d )→RK p→d

[0103] Among them, PK is the system common parameter, SK p The patient device private key, PK d The public key of the data buyer in the data buyer key pair;

[0104] ReKeyGen(PK, SK p , PK d ) represents the conversion key generation function, and the processing process includes:

[0105] The key generation center randomly selects two integers Calculate the following parameter values ​​and generate the conversion key RK p→d ,in, is the multiplicative group of integers:

[0106] rk1=(k1B3+B1)+(k2B3+B2)*ID p

[0107]

[0108] R p→d =(rk1,rk2)

[0109] Among them, rk1 is the first part of the key, rk2 is the second part of the key, B1 is the first conversion parameter, B2 is the second conversion parameter, B3 is the third conversion parameter, ID p is the patient identifier, D1 is the fourth conversion parameter, D2 is the fifth conversion parameter, and D3 is the sixth conversion parameter.

[0110] As an embodiment of the present invention, the proxy re-encryption module converts the encrypted medical data into an intermediate ciphertext, including:

[0111] The proxy re-encryption module will convert the intermediate ciphertext CRK p→d Sent to the data buyer. The specific process is as follows:

[0112]

[0113] in, is the first encryption conversion element, is the second encryption conversion element, is the third encryption conversion element, It is an intermediate ciphertext.

[0114] The embodiment of the present invention converts the encrypted patient device data ciphertext Convert to intermediate ciphertext CRK p→d, where the intermediate ciphertext can be obtained by the private key SK of the data buyer d Decryption.

[0115] S6. The data buyer obtains the intermediate ciphertext from the proxy re-encryption module, and uses the private key in the data buyer's key pair to decrypt the intermediate ciphertext to obtain the medical data.

[0116] In the embodiment of the present invention, the private key in the key pair of the data buyer is used to decrypt the intermediate ciphertext to obtain the medical data, which can be implemented by the following steps:

[0117] Data Buyer RI j Obtain the intermediate ciphertext CRK from the proxy re-encryption module p→d , and then use the data buyer's private key SK d Decrypt the intermediate ciphertext, that is:

[0118] Data Buyer RI j Intermediate ciphertext CRK p→d Decrypt and obtain medical data D.

[0119]

[0120] At this point, the data buyer obtains the medical data through the transaction. In addition, the public keys and identity information of both parties in the entire transaction process are recorded in the information storage and recording module for query. At this point, the entire transaction method ends.

[0121] In the embodiment of the present invention, when using the data buyer's private key SK d During the decryption process of the intermediate ciphertext, the blockchain platform cannot obtain any information related to the plaintext.

[0122] The key generation center of the present invention generates key pairs for patient devices, data managers and data buyers, which can ensure that each entity has an independent key to prevent data risks caused by key leakage. In addition, the data buyer and the data manager, as the two parties to the transaction, generate zero-knowledge proofs according to the smart contract to avoid directly sharing sensitive data and realize the privacy protection of the patient's device. In addition, the encrypted medical data is converted into an intermediate ciphertext through the proxy re-encryption module, so that the data buyer cannot directly access the original data and must decrypt it through the conversion key, further enhancing data privacy protection. In addition, all transaction applications and operation records are stored on the blockchain, which can ensure the transparency of data transactions. Through the blockchain and smart contracts, the data buyer and the data manager do not need to fully trust each other. The system automatically verifies and executes transactions, reducing the trust cost, and uses zero-knowledge proofs for verification, so that the verification process does not need to disclose sensitive information, reducing dependence on third-party verification agencies. The present invention can protect data privacy and reduce the maintenance cost of medical data.

[0123] like Figure 2 , which is a system diagram of a medical data trusted processing method based on smart contracts provided in one embodiment of the present invention.

[0124] As an embodiment of the present invention, a system of a medical data trusted processing method based on smart contracts includes a blockchain platform, a data buyer, a data manager, a key generation center and a patient device. The patient device communicates with the data manager in a two-way manner. The data manager and the patient device send medical data features of the medical data to the blockchain platform, and the data buyer sends medical data requirements to the blockchain platform.

[0125] Furthermore, the key generation center generates system public parameters and system master keys, and distributes the system public parameters and system master keys to entities to assist the entities in generating entity key pairs, wherein the entities include patient devices, data managers and data buyers, and the entity key pairs include patient device key pairs, data manager key pairs and data buyer key pairs.

[0126] Furthermore, the blockchain platform includes a smart contract, in which data availability matching and proxy re-encryption are performed.

[0127] like Figure 3 As shown, it is a smart contract functional diagram of a medical data trusted processing method based on a smart contract provided by one embodiment of the present invention.

[0128] It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0129] Therefore, no matter from which point of view, the embodiments should be regarded as illustrative and non-restrictive, and the scope of the present invention is limited by the appended claims rather than the above description, so it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present invention. Any attached figure mark in the claims should not be regarded as limiting the claims involved.

[0130] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, artificial intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.

[0131] In addition, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in the system claim can also be implemented by one unit or device through software or hardware. The words first, second, etc. are used to indicate names, and do not indicate any particular order.

[0132] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention.

Claims

1. A medical data trusted processing method based on smart contracts, characterized in that: The method comprises: The key generation center generates system public parameters and system master keys, and distributes the system public parameters and system master keys to entities, and assists the entities in generating entity key pairs, wherein the entities include patient devices, data managers, and data buyers, and the entity key pairs include patient device key pairs, data manager key pairs, and data buyer key pairs; The data buyer initiates a medical data transaction application to the blockchain platform based on the transaction number, medical data processing keywords, and the data buyer's IP address, and deploys a smart contract on the blockchain platform; The data buyer and the data manager, as the two parties in the transaction, generate a zero-knowledge proof based on the smart contract to obtain the data demand characteristics; The data manager encrypts the medical data according to the data demand characteristics to obtain encrypted medical data, and uploads the encrypted medical data to the information storage and recording module of zero-knowledge proof; The data manager performs zero-knowledge verification. If the verification is successful, the patient device generates a conversion key using the public key in the data buyer's key pair and stores the conversion key in the proxy re-encryption module. The proxy re-encryption module converts the encrypted medical data into an intermediate ciphertext and sends it to the data buyer. The data buyer obtains the intermediate ciphertext from the proxy re-encryption module, and uses the data buyer's private key in the data buyer's key pair to decrypt the intermediate ciphertext to obtain the medical data.

2. The medical data trusted processing method based on smart contracts as claimed in claim 1, characterized in that: The key generation center generates system public parameters and system master keys, including: The key generation center inputs the security parameter λ and selects two multiplication cyclic groups G1 and G2 generated by prime numbers p; Use the multiplication cyclic group G1 and the multiplication cyclic group G2 to set up a cryptographic bilinear map, select a secure hash function to map the elements in the multiplication cyclic group G1 and the multiplication cyclic group G2, and generate an integer multiplication group The key generation center randomly selects three integers from the integer multiplication group to generate the system master key, and selects generators from the multiplication cyclic group G1, and combines the prime number p, the multiplication cyclic group G1, the multiplication cyclic group G2 and the hash function to generate the system public parameters.

3. The medical data trusted processing method based on smart contracts as claimed in claim 1 or 2, characterized in that: The method of distributing the system public parameters and the system master key to the entity and assisting the entity in generating an entity key pair includes: The key generation center randomly selects four integers from the integer multiplication group, generates patient device encryption parameters according to the patient identifier using a preset parameter generation method, and generates a patient device key pair according to the patient device encryption parameters.

4. The medical data trusted processing method based on smart contracts as claimed in claim 1, characterized in that: The data buyer and the data manager, as the transaction parties, generate a zero-knowledge proof based on the smart contract, including: The data manager calls the smart contract to query the medical data processing keywords and extracts the keyword medical data based on the medical data processing keywords. After binding the keyword medical data to the personal digital signature, the first zero-knowledge proof is generated. The data buyer generates the second zero-knowledge proof based on the medical data he needs.

5. The medical data trusted processing method based on smart contracts as claimed in claim 4, characterized in that: The step of binding the keyword medical data to the personal digital signature and generating the first zero-knowledge proof includes: The data manager generates extended information based on the patient device's identity, current local time, and private medical data of the patient device; Select a random integer from the integer multiplication group, and perform hash calculation on it in conjunction with the extended information to obtain an extended hash operation value; Generate a digital signature using a preset digital signature calculation formula according to the extended hash operation value and the patient device private key in the patient device key pair; The data manager constructs a computing logic circuit based on the medical data computing keywords provided by the data buyer, generates a zero-knowledge key pair based on the security parameters and the computing logic circuit, and generates a trusted zero-knowledge proof based on the generated key, medical data, digital signature, output result of the computing logic circuit, and hash value output result of the computing logic circuit in the zero-knowledge key pair.

6. The medical data trusted processing method based on smart contracts according to claim 1 or 4, characterized in that: The data manager performs zero-knowledge verification, including: The first zero-knowledge proof and the second zero-knowledge proof are stored in a zero-knowledge proof verification module, and the digital signature of the patient device is verified using the patient device public key in the patient device key pair. After the verification is passed, the first zero-knowledge proof is checked using the verification key in the zero-knowledge key pair, and the zero-knowledge verification is completed after the check is completed.

7. The medical data trusted processing method based on smart contracts as claimed in claim 1, characterized in that: The patient device generates a conversion key using a data buyer's public key in a data buyer's key pair, including: The conversion key RK is generated using the following formula: p→d : ReKeyGen(PK,SK p ,PK d )→RK p→d Among them, PK is the system common parameter, SK p The patient device private key, PK d The data buyer's public key in the data buyer's key pair; ReKeyGen(PK, SK p , PK d ) represents the conversion key generation function, and the processing process includes: The key generation center randomly selects two integers Calculate the following parameter values ​​and generate the conversion key RK p→d ,in, is the multiplicative group of integers: <h2 style=";text-align:left;direction:ltr">rk1 = (k1B3+B1)+(k2B3+B2)*ID<h2 style=";text-align:left;direction:ltr"> p RC p→d =(rk1,rk2) Among them, rk1 is the first part of the key, rk2 is the second part of the key, B1 is the first conversion parameter, B2 is the second conversion parameter, B3 is the third conversion parameter, ID p is the patient identifier, D1 is the fourth conversion parameter, D2 is the fifth conversion parameter, and D3 is the sixth conversion parameter.

8. A system based on the medical data trusted processing method based on smart contracts according to any one of claims 1 to 7, characterized in that: The invention comprises a blockchain platform, a data buyer, a data manager, a key generation center and a patient device. The patient device communicates with the data manager in a two-way manner. The data manager and the patient device send the medical data to the blockchain platform. The data buyer sends the medical data demand to the blockchain platform. The key generation center communicates with the data manager, the patient device and the data buyer respectively.

9. The system of the medical data trusted processing method based on smart contract as claimed in claim 8, characterized in that: The key generation center generates system public parameters and system master keys, and distributes the system public parameters and system master keys to entities to assist the entities in generating entity key pairs, wherein the entities include patient devices, data managers and data buyers, and the entity key pairs include patient device key pairs, data manager key pairs and data buyer key pairs.

10. The system of the medical data trusted processing method based on smart contract as claimed in claim 8, characterized in that: The blockchain platform includes a smart contract, in which data availability matching and proxy re-encryption are performed.

Citation Information

Patent Citations

  • Electronic medical data privacy protection and security sharing system based on block chain

    CN112380543A

Cited By

  • Personalized transaction data processing method and system based on privacy preference and credibility

    CN121723509A

  • Transaction data personalization processing method and system based on privacy preference and trust degree

    CN121723509B