Drug information encryption and tamper-proofing method based on blockchain and advanced encryption standard
By combining blockchain with AES encryption technology, hierarchical encryption and tamper-proofing of drug information are achieved, solving the problems of drug information security and tampering, providing transparent supervision and efficient access control, and meeting legal and regulatory requirements.
Patent Information
- Application Number
- CN202510076586.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-01-17
AI Technical Summary
In existing technologies, drug information encryption methods are not secure enough, centralized permissions lead to an insecure data framework, pose a risk of tampering, and fail to meet data security and legal requirements.
By combining blockchain with Advanced Encryption Standard (AES) and asymmetric encryption technology, the system uses smart contracts to achieve hierarchical encryption and tamper-proofing of drug information. It utilizes blockchain for decentralized storage and records operation logs, and combines hash algorithms to ensure data integrity.
It enables decentralized storage of drug information, improves data security and integrity, prevents tampering, provides a transparent regulatory mechanism and efficient access control, and meets legal and regulatory requirements.
Smart Images

Figure CN119995825B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application mainly relates to the technical field of medicine platform, and particularly discloses a medicine information encryption and tamper-proofing method based on a blockchain and an advanced encryption standard. BACKGROUND
[0002] Medicine information encryption is an important means for the pharmaceutical industry to protect its core data. Medicine research and development data is one of the most core intellectual property rights of an enterprise, including medicine confidential formula, research and development achievements, technical data, etc. A large amount of patient information is involved in the process of medicine research and development, and if these information is leaked, the privacy rights of patients will be seriously infringed, and the enterprise will suffer immeasurable negative impact. With the continuous improvement of data security laws and regulations, the pharmaceutical industry needs to strengthen the protection of internal confidential data to meet the requirements of relevant laws and regulations. By implementing permission control, document transparent encryption, outgoing file control, audit, and full life cycle management strategies, the security of medicine information can be effectively improved.
[0003] Blockchain is a distributed ledger technology that allows participants in a network to exchange data securely, traceably and tamper-proof without the need for a centralized trust authority. Blockchain combines data blocks in a chain-like manner according to time sequence through a specific data structure, and uses cryptography to ensure the security of data transmission and access.
[0004] AES is a symmetric encryption algorithm that uses complex key exchange technology to encrypt and decrypt information. AES encryption algorithm provides strong security protection, which can effectively prevent hacker attacks and protect data security. At the same time, AES encryption algorithm has very low processing delay, which can improve the efficiency performance of the blockchain network. In addition, AES encryption algorithm also has high flexibility and can be applied to various application scenarios.
[0005] According to the anti-tampering method for the first marketing electronic data of medicines based on sharing provided in application No. CN202311778334.7, the present application relates to the technical field of medicine platform, and comprises the following steps: constructing an electronic data sharing service platform to provide data traceability sharing space for production enterprises, intermediate wholesale enterprises and downstream enterprises; the production enterprises upload the first marketing electronic data of medicines to the platform, and the platform determines the accuracy of the data based on CA authentication and medicine management audit; in the process of transmission of the first marketing electronic data, the platform generates an encryption key and a decryption key, uses an abstract extraction algorithm to randomly extract abstract data of the first marketing electronic data, encrypts the abstract data and the random extraction rule by using the encryption key, generates an encrypted package and the first marketing electronic data, and transmits the combination; the receiving end decrypts the encrypted package by using the decryption key, obtains the random extraction rule to extract the abstract data of the received data again, compares the abstract data with the abstract data in the encrypted package, and determines the integrity of the data, which is beneficial to prevent tampering during transmission.
[0006] The encryption method of MD5 in the prior art is not secure enough, and the encryption method in the prior art is not transparent enough, which leads to the centralization of authority, and when the authorized person has a secret thought, the entire encryption framework will no longer be secure, which has a huge impact and loss on the medicine platform. SUMMARY
[0007] Therefore, the purpose of the present application is to provide a medicine information encryption and tamper-proofing method based on blockchain and advanced encryption standard to solve the technical problems proposed in the background art.
[0008] To achieve the above purpose, the present application provides the following technical solutions:
[0009] The medicine information encryption and tamper-proofing method based on blockchain and advanced encryption standard comprises the following steps:
[0010] System initialization and key generation: build a blockchain network, deploy a smart contract, and generate a unique asymmetric key pair for each participant; and manage it through a key management system, including the receiver and the production enterprise;
[0011] Medicine information grading and encryption: according to the sensitivity and importance of medicine information, it is divided into different levels, and different encryption methods and keys are used for encryption of medicine information of different levels;
[0012] Data upload and blockchain record: upload the encrypted medicine information to the blockchain network, and pack the medicine information and the corresponding metadata together by the smart contract and record them on the blockchain; the metadata includes timestamp, information level, and encryption method;
[0013] Access control and decryption: the receiver submits an access request through a client application, the smart contract verifies the authority according to the identity information of the receiver and the information level of the access request, generates an access token and sends it to the receiver after verification, and the receiver decrypts the data using its own private key or symmetric key; for confidential information, the receiver also needs to obtain the public key of the production enterprise through the smart contract for decryption;
[0014] Data modification and update: if the production enterprise needs to modify the medicine information, it needs to submit a modification request with a modification reason, the smart contract automatically audits the compliance of the modification request, and after the audit is passed, the production enterprise re-encrypts the modified data and uploads it to the blockchain network, and the smart contract updates the records on the blockchain;
[0015] Audit and exception handling: the smart contract records all operation logs and automatically performs audit tasks regularly, triggers the alarm mechanism when abnormal data is found, notifies the relevant parties and takes appropriate measures, and records the abnormal data in the abnormal log on the blockchain.
[0016] Preferably, in the drug information grading and encryption, the levels of the drug information include public level, internal level and confidential level, wherein the public level information is stored in symmetric encryption or plaintext, and the internal level information is encrypted by using a symmetric encryption algorithm.
[0017] The confidential level information is encrypted by using an asymmetric encryption algorithm in combination with the public key of the participant.
[0018] Preferably, in the data uploading and blockchain recording, the smart contract further records the hash value of the data to ensure the integrity and tamper resistance of the data.
[0019] Preferably, in the access control and decryption, the smart contract automatically executes the permission verification and access control logic through the smart contract code on the blockchain.
[0020] Preferably, in the data modification and update, the smart contract further considers the timestamp of the modification request, the modification reason and the historical operation log when auditing the modification request.
[0021] Preferably, in the audit and exception handling, the smart contract further performs a data analysis task to extract useful information from the operation log and the exception log, so as to optimize the performance and security of the system.
[0022] Preferably, the blockchain network is used to store the encrypted drug information and metadata.
[0023] The smart contract is deployed on the blockchain network and is used to execute permission verification, access control, data recording, audit and exception handling.
[0024] The client application is used for the participant to submit an access request, upload and download encrypted data, and view the operation log and the exception log.
[0025] The key management system is used to generate and manage the asymmetric key pair for each participant.
[0026] In summary, the present application mainly has the following beneficial effects:
[0027] In the method of the present application, the decentralization and the improvement of data security are achieved by constructing a consortium chain, realizing the decentralized storage of drug information, avoiding the risk of single point failure and internal data tampering. The drug information is encrypted by using the AES-256 advanced encryption standard, which significantly improves the security of the data and effectively resists security threats such as collision attacks.
[0028] Enhanced data integrity and tamper-proofing are achieved through the introduction of smart contracts, enabling automated review, timestamping, and access control of drug information, thus ensuring data integrity and immutability. The SHA-3 algorithm is used to calculate hash values before and after data transmission, and blockchain verification further ensures data integrity during transmission and storage.
[0029] Efficient data management and access control, the client application provides a user-friendly interface, supports uploading, querying, downloading and modifying drug information, improving the convenience and efficiency of data management.
[0030] Smart contracts automate data uploading, review, and encryption processes according to preset rules, reducing manual intervention and improving processing speed.
[0031] A transparent regulatory and auditing mechanism ensures that all operations are logged immutably on the blockchain, providing drug regulatory agencies with a transparent regulatory approach. Smart contracts automatically execute audit tasks periodically to check the integrity and compliance of data, ensuring its continued reliability.
[0032] A flexible data sharing and decryption mechanism generates a unique AES key for each transaction and uses the recipient's public key for asymmetric encryption, ensuring data security during the sharing process. The recipient uses their private key to decrypt the key packet, thereby decrypting the data and achieving secure data sharing and access. Attached Figure Description
[0033] Figure 1 This is a flowchart illustrating the overall process framework of the present invention.
[0034] Figure 2 This is a flowchart illustrating the specific technical solution and method framework of the present invention. Detailed Implementation
[0035] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0036] Example
[0037] like Figure 1 As shown, the method for encrypting and preventing tampering of drug information based on blockchain and advanced encryption standards includes the following steps:
[0038] System initialization and key generation: Build a blockchain network, deploy smart contracts, and generate a unique asymmetric key pair for each participant; manage the key through a key management system, with participants including recipients and production enterprises;
[0039] Drug information classification and encryption: According to the sensitivity and importance of drug information, it is divided into different levels, and different encryption methods and keys are used for encryption of drug information of different levels;
[0040] Data upload and blockchain record: The encrypted drug information is uploaded to the blockchain network, and the smart contract packages the drug information and the corresponding metadata together and records them on the blockchain; Metadata includes timestamp, information level, encryption method;
[0041] Access control and decryption: The recipient submits an access request through the client application, and the smart contract verifies the recipient's identity information and the information level of the access request, generates an access token and sends it to the recipient after verification, and the recipient uses its own private key or symmetric key to decrypt the data. For confidential information, the recipient also needs to obtain the public key of the production enterprise through the smart contract for decryption;
[0042] Data modification and update: If the production enterprise needs to modify the drug information, it needs to submit a modification request and attach a modification reason, and the smart contract automatically audits the compliance of the modification request. After the audit is passed, the production enterprise re-encrypts the modified data and uploads it to the blockchain network, and the smart contract updates the records on the blockchain;
[0043] Audit and exception handling: The smart contract records all operation logs and automatically performs audit tasks regularly. When abnormal data is found, the alarm mechanism is triggered, and the relevant parties are notified and appropriate measures are taken. At the same time, the abnormal data is recorded in the exception log on the blockchain.
[0044] In drug information classification and encryption, the level of drug information includes public, internal and confidential, among which public information is stored in symmetric encryption or plaintext, and internal information is encrypted using symmetric encryption algorithm;
[0045] Among them, the confidential information is encrypted using asymmetric encryption algorithm combined with the public key of the participant.
[0046] In data upload and blockchain record, the smart contract also records the hash value of the data to ensure the integrity and tamper resistance of the data.
[0047] In access control and decryption, the smart contract automatically executes the permission verification and access control logic through the smart contract code on the blockchain.
[0048] In data modification and update, the smart contract also considers the timestamp of the modification request, the modification reason and the historical operation log when auditing the modification request.
[0049] In audit and exception handling, the smart contract also performs data analysis tasks to extract useful information from operation logs and exception logs to optimize the performance and security of the system.
[0050] It should be noted that, in this embodiment, the system framework includes a blockchain network for storing encrypted drug information and metadata;
[0051] Smart contracts are deployed on a blockchain network to perform functions such as permission verification, access control, data logging, auditing, and exception handling.
[0052] The client application is used by participants to submit access requests, upload and download encrypted data, and view operation logs and exception logs;
[0053] The key management system is used to generate and manage asymmetric key pairs for each participant;
[0054] The data analysis module is used to extract useful information from operation logs and exception logs to optimize system performance and security.
[0055] Technical solution:
[0056] 1. System Architecture:
[0057] Blockchain network: A consortium blockchain consisting of manufacturers, intermediate wholesalers, downstream companies, and drug regulatory agencies, used to store and verify drug information.
[0058] Smart contracts: Deployed on the blockchain for automated auditing, timestamp recording, data encryption, and access control.
[0059] Client application: Provides a user interface for all participants, supporting information uploading, querying, downloading, and modification functions.
[0060] 2. Method and steps: as follows Figure 2 As shown,
[0061] S1: System Initialization
[0062] S11: Blockchain Network Setup: Use blockchain frameworks such as Hyperledger Fabric or Ethereum, configure consensus mechanisms (such as Raft or PoA), and ensure data consistency and immutability.
[0063] S12: Smart Contract Deployment: Write and deploy smart contracts, defining the logic for data uploading, auditing, encryption, storage, and access control.
[0064] S13: Client Application Development: We use React Native to develop cross-platform client applications, ensuring a good user experience and compatibility.
[0065] S2: Drug Information Upload and Review
[0066] S21: Information Upload: The production enterprise uploads drug information through the client application, including drug name, specification, production date, expiration date, etc.
[0067] S22: Smart Contract Audit: The smart contract automatically checks the completeness of the drug information and calls external APIs (such as drug regulatory databases) to verify the accuracy of the information.
[0068] S3: Data Encryption and Timestamp Recording
[0069] S31: AES Encryption: After the audit passes, the drug information is encrypted using the AES-256 algorithm to generate encrypted data.
[0070] S32: Timestamp Recording: The smart contract records the current timestamp and packages it together with the encrypted data, uploading it to the blockchain.
[0071] S4: Data Modification and Verification
[0072] S41: Modification Request: If the production enterprise needs to modify the drug information, it needs to submit a modification request through the client application and attach the modification reason.
[0073] S42: Multi-factor Authentication: Two-factor authentication (such as SMS verification code + biometric identification) is used to verify the identity of the production enterprise.
[0074] S43: Smart Contract Verification: The smart contract verifies the reasonableness and compliance of the modification request, and after passing, re-encrypts and updates the data on the blockchain.
[0075] S5: Data Sharing and Decryption
[0076] S51: Encryption Key Generation: A unique symmetric key (AES key) is generated for each transaction, and the recipient's public key is used for asymmetric encryption to generate a key package.
[0077] S52: Data Transmission: The encrypted data, key package, and timestamp information are sent to the recipient together.
[0078] S53: Decryption and Verification: The recipient uses their own private key to decrypt the key package, obtains the AES key, and then decrypts the data. At the same time, the timestamp information is queried through the smart contract to verify the integrity and timeliness of the data.
[0079] S6: Data Integrity Check
[0080] S61: Hash Check: Before and after data transmission, the SHA-3 algorithm is used to calculate the hash value of the data to ensure that the data has not been tampered with during transmission.
[0081] S62: Blockchain verification: The recipient queries the data hash value on the blockchain through the smart contract, compares it with the locally calculated hash value, and further confirms the integrity of the data.
[0082] S7: Audit and exception handling
[0083] S71: Logging: All operations leave unalterable log records on the blockchain, including uploading, auditing, modifying, accessing, etc.
[0084] S72: Regular audit: The smart contract automatically performs audit tasks regularly to check the integrity and compliance of the data.
[0085] S73: Exception handling: When abnormal data is found, the smart contract immediately triggers the alarm mechanism, notifies the relevant parties and takes appropriate measures.
[0086] The working principle of the present application is:
[0087] Asymmetric encryption and hierarchical protection: The present application uses asymmetric encryption technology to realize hierarchical protection of data, ensuring the security of information of different levels. At the same time, through the smart contract, automatic access control and permission verification are realized, improving the efficiency and transparency of the system.
[0088] Blockchain technology ensures data tamper-proof: All operation records and data are stored on the blockchain, ensuring data tamper-proof and transparency. This helps to enhance the trust and cooperation between the participants.
[0089] Flexible access control and decryption mechanism: The present application provides a flexible access control and decryption mechanism, allowing the recipient to decrypt data according to their own permissions and needs. This helps to meet the information security needs of different participants.
[0090] The present application combines asymmetric encryption, blockchain technology and smart contract technology to build a secure, efficient and transparent drug information hierarchical encryption and access control system. The system not only ensures the integrity and tamper-proof of data, but also realizes flexible access control and permission verification function, with significant creativity and practicality.
[0091] The above examples are only to illustrate the technical idea of the present application, and cannot limit the protection scope of the present application. Any modification made according to the technical idea of the present application on the basis of the technical solution falls within the protection scope of the present application.
Claims
1.A method for encrypting and tamper-proofing drug information based on blockchain and advanced encryption standard, characterized in that, The method comprises the following steps: System initialization and key generation: setting up a blockchain network, deploying a smart contract, and generating a unique asymmetric key pair for each participant; And managed through the key management system, participants include recipients and production enterprises; Drug information classification and encryption: according to the sensitivity and importance of drug information, it is divided into different levels, and different encryption methods and keys are used to encrypt drug information of different levels; Data upload and blockchain record: upload the encrypted drug information to the blockchain network, and pack the drug information and the corresponding metadata together by the smart contract and record them on the blockchain; The metadata includes timestamp, information level, and encryption method; Access control and decryption: the recipient submits an access request through the client application, the smart contract verifies the access request according to the identity information of the recipient and the information level, generates an access token and sends it to the recipient after verification, and the recipient uses its own private key or symmetric key to decrypt the data. For confidential information, the recipient also needs to obtain the sender's public key through the smart contract for decryption; Specifically, a unique symmetric key is generated for each transaction, and the public key of the recipient is used for asymmetric encryption to generate a key package, and the symmetric key is specifically an AES key; The recipient uses its own private key to decrypt the key package and obtains the AES key to decrypt the data; at the same time, the timestamp information is queried through the smart contract to verify the integrity and timeliness of the data; Data modification and update: if the production enterprise needs to modify the drug information, it needs to submit a modification request and attach a modification reason, the smart contract automatically audits the compliance of the modification request, and after the audit is passed, the production enterprise re-encrypts the modified data and uploads it to the blockchain network, and the smart contract updates the record on the blockchain; The smart contract also considers the timestamp of the modification request, the modification reason and the historical operation log when auditing the modification request; Audit and exception handling: the smart contract records all operation logs and automatically performs audit tasks regularly, triggers the alarm mechanism when abnormal data is found, notifies the relevant parties and takes corresponding measures, and records the abnormal data in the exception log on the blockchain. 2.The method of claim 1, wherein, In the drug information classification and encryption, the level of drug information includes public, internal and confidential, and the public information is stored in symmetric encryption or plaintext; Among them, the confidential information is encrypted by using the asymmetric encryption algorithm combined with the public key of the participant. 3.The method of claim 1, wherein, In the data upload and blockchain record, the smart contract also records the hash value of the data to ensure the integrity and tamper resistance of the data. 4.The method of claim 1, wherein, In the access control and decryption, the smart contract automatically executes the permission verification and access control logic through the smart contract code on the blockchain. 5.The method of claim 1, wherein, In the audit and exception handling, the smart contract also performs data analysis tasks to extract useful information from the operation log and exception log to optimize the performance and security of the system. 6.The method of claim 1, wherein, The blockchain network is used to store encrypted drug information and metadata; The smart contract is deployed on the blockchain network to perform permission verification, access control, data recording, audit and exception handling; The client application is used by participants to submit access requests, upload and download encrypted data, and view operation logs and exception logs. The key management system is used to generate and manage asymmetric key pairs for each participant.
Citation Information
Patent Citations
Anti-tampering method based on shared electronic data of first-time drug sales
CN117857151B
Distributed password management system and method based on block chain
CN119210688A
Systems and methods for secure key management using distributed ledger technology
US20220311597A1