Medical information security encryption transmission and storage method, device, equipment and medium

By adopting classified encryption, distributed storage and backup strategies in the medical information system, the security risks in the transmission and storage process of medical information are solved, the high security of medical information and the reliability of the system are achieved, and the privacy and rights of patients are protected.

CN120030559APending Publication Date: 2025-05-23山东浪潮智慧医疗科技有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411863271.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art poses security risks in the transmission and storage of medical information, such as information leakage, data tampering and single point of failure, which leads to threatening patient privacy protection and medical security.

Method used

Through classified encryption, distributed storage, secure transmission channels and backup policies, storage requests for medical information are obtained and sliced ​​and sent to distributed storage nodes through secure channels for storage and backup, and indexes are set. When a failure occurs, the data is restored from the backup using a preset recovery strategy, and medical information is obtained through index query and decryption after user permission verification is passed.

Benefits of technology

It effectively reduces the risk of leakage and tampering of medical information during transmission and storage, improves the security of medical information and the reliability of the system, ensures that only authorized users can access and obtain medical information, and protects the privacy and rights of patients.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030559A_ABST
    Figure CN120030559A_ABST
Patent Text Reader

Abstract

The invention provides a medical information security encryption transmission and storage method, device, equipment and medium, and belongs to the technical field of medical information security, the method comprises the following steps: obtaining a storage request of medical information, and determining an encryption strategy according to a data type; slicing various types of data in the medical information, encrypting the data according to the determined encryption strategy, sending the encrypted data to a distributed storage node for storage and backup by using a secure transmission channel, and setting an index; when a certain distributed storage node has a fault, recovering from the backup according to a preset recovery strategy; and obtaining a reading request of the medical information, verifying the user permission, querying from the distributed storage node according to the index, and reading the medical information to the user terminal through the secure transmission channel for decryption and assembly to obtain the final medical information. According to the invention, the safety protection capability of medical information is improved, the risk of information leakage and tampering is reduced, and the continuity of data and the stable operation of the system are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of medical information security technology, and specifically relates to a method, device, equipment and medium for secure encryption transmission and storage of medical information. Background Art

[0002] With the rapid development of Internet medicine, the security of patients' medical information has become increasingly prominent. Medical information not only involves personal privacy, but also directly relates to the life safety of patients. However, in the existing technology, there are many security risks in the transmission and storage of medical information, such as information leakage, data tampering, etc., which pose a serious threat to patients' privacy protection and medical safety.

[0003] Specifically, on the one hand, although traditional encryption technology has been used to protect the transmission of medical information during data transmission, the single encryption method cannot completely resist new types of network attacks, making it easy for information to be stolen or tampered with during transmission, thus failing to effectively protect the confidentiality of medical information. On the other hand, medical information is usually stored on a single node, which not only poses a risk of data leakage, but also may lead to a single point of failure. Once the node fails or is destroyed, the entire medical information system may be paralyzed, seriously affecting the continuity and reliability of medical services. In addition, some medical systems lack a complete data backup strategy, or have technical difficulties in data recovery, resulting in the inability to restore data in a timely manner when it is lost or damaged, thus posing a serious threat to the security of patients' medical information.

[0004] In summary, traditional medical information storage and storage methods cannot ensure the security of medical information, posing a serious threat to patients' privacy protection and medical safety. Summary of the invention

[0005] In a first aspect, an embodiment of the present application provides a method for securely encrypting, transmitting and storing medical information, comprising the following steps: S1. Obtain a storage request for medical information, classify the data in the medical information, and determine an encryption strategy according to the data type; S2. Slice each type of data in the medical information according to the set segmentation strategy, encrypt each slice according to the determined encryption strategy, and send it to the distributed storage node for storage and backup using a secure transmission channel, and set an index; S3. When a distributed storage node fails, the lost medical information data is restored from the backup according to the preset recovery strategy; S4. Obtain a read request for medical information, verify user permissions, and query from distributed storage nodes based on the index after the user permissions are verified. Then, read the encrypted slices of the queried medical information through a secure transmission channel to the user terminal for decryption and assembly to obtain the final medical information.

[0006] Furthermore, the specific steps of step S1 are as follows: S11. The medical information system identifies the registration request of the patient user, generates a first secret key for symmetric encryption for the patient user, and sends the first secret key to the patient user through a secure transmission channel; S12. The medical information system requests the patient user terminal to generate a first key pair for asymmetric encryption, and obtains the public key in the first key pair through a secure transmission channel; S13. The medical information system generates a second key pair for each distributed storage node, and saves the private key of the second key pair to the corresponding distributed storage node, and saves the public key of each second key pair as a public key table according to the serial number of the distributed storage node; S14. Obtain a storage request for medical information in the medical information system, and identify the patient's basic information, medical records, diagnostic reports, and imaging data in the storage request; S15. Set the medical information data of the patient's basic information and medical record type to be encrypted using the AES encryption algorithm; S16. Set the medical information data of the diagnosis report and image data types to be encrypted using the RSA asymmetric encryption algorithm.

[0007] Furthermore, the specific steps of step S2 are as follows: S21. Slice each type of medical information data to ensure that each slice does not contain sensitive information; S22. Encode each slice in the original order, determine the target storage node for each slice from the distributed storage nodes, and set the slices containing adjacent codes to be stored in different distributed storage nodes; S23. Query the public key of the target storage node from the public key table for each slice, encrypt each slice using the determined encryption strategy, then use the queried public key to sign and generate a slice data packet, and encode each slice data packet in the original order; S24. Send each slice data packet to the target storage node using a secure transmission channel; S25. Each distributed storage node verifies the signature of the received slice data packet, discards it if the verification fails, saves it after the verification passes, and creates a storage index; S26. Divide the distributed storage nodes into regions in advance; S27. Each distributed storage node determines a backup storage node for the slice data packet that has been saved, the area to which the backup storage node belongs is farthest from the area to which the current distributed storage node belongs, and establishes a backup index.

[0008] Furthermore, the specific steps of step S21 are as follows: S211. Determine the basic slice size for each type of medical information data in advance; S212. Slice each type of medical information data according to the basic slice size; S213. Analyze whether each slice contains sensitive information; If yes, go to step S214; If not, proceed to step S22; S214. Perform a second split on the slice containing sensitive information, and return to step S213; The specific steps of step S23 are as follows: S231. Obtain a public key table, query the public key table according to the target storage node determined by each slice, and obtain the public key in the second key pair corresponding to each target storage node; S232. Identify the data type to which the slice belongs; When it is the patient's basic information or medical records, go to step S233; When the data type is diagnosis report or image data, the process goes to step S234; S233. The slice is encrypted by AES using the first key and then the hash value is calculated, and the process proceeds to step S235; S234. Perform RSA asymmetric encryption on the slice using the public key in the user's first key pair and then calculate the hash value; S235. The encrypted slice and hash value are signed with the public key of the second key pair of the target storage node to obtain a slice data packet; S236. Add the encoding of each slice data packet to the end of the slice data packet; The specific steps of step S25 are as follows: S251. The distributed storage node verifies the signature of the received slice data packet using the private key in the second key pair, and encrypts the slice and hash value; S252. Recalculate the hash value of the encrypted slice and compare it with the hash value of the signature verification; If they are consistent, the signature verification is successful and the process goes to step S253; If they are inconsistent, the signature verification fails, the currently received slice data packet is discarded, and the data sender is notified, and the process ends; S253. Save the slice data packet and create a storage index to record the user and code of the slice data packet; The specific steps of step S27 are as follows: S271. Regularly query each distributed storage node for newly added slice data packets; S272. Locate a distributed storage node, identify the distance between each distributed storage node and the located distributed storage node, and generate a backup table according to the distance; S273. Identify the storage node that is farthest from the backup table and the located distributed storage node; S274. Determine whether the identified storage node meets the backup requirements; If yes, go to step S276; If not, proceed to step S275; S275. Delete the identified storage node from the backup table and return to step S273; S276. Use the identified storage node as the target backup node, send the newly added slice data packet to the target backup node using a secure transmission channel, and create a backup index at the located distributed storage node and the target backup node at the same time.

[0009] Furthermore, the specific steps of step S3 are as follows: S31. Regularly check the operating status of each distributed storage node; If the operation is normal, go to step S4; If a distributed storage node fails, proceed to step S32; S32. Determine the fault type of the faulty distributed storage node; If the faulty distributed storage node is down, proceed to step S34; If some data is lost in the failed distributed storage node, go to step S33; S33. Determine the lost slice data packet, query the backup index of the failed distributed storage node, determine the backup address of the lost slice data packet, request the lost slice data packet from each target backup node according to the backup address, complete data recovery, and enter step S4; S34. Use a new storage node to replace the original failed distributed storage node, and send a broadcast message to each distributed storage node to query the data slice data packet whose data source is the failed distributed storage node; S35. Each distributed storage node identifies the data source address from the broadcast message, compares it with its own backup index, and returns the consistent slice data packet to the replacement distributed storage node to complete data recovery.

[0010] Furthermore, the specific steps of step S4 are as follows: S41. Obtain a request to read medical information and the type of medical information corresponding to the request; S42. Whether the user subject using the read request has the read permission for the corresponding type of medical information; If yes, go to step S43; If not, return permission error and end; S43. Query the distributed storage node for storing the required medical information according to the storage index and issue a data read request; S44. The distributed storage node that receives the data read request calculates the hash value of the corresponding slice data packet, signs the slice data packet and its hash value using the private key in the second key pair, and returns it to the user terminal; S45. The patient user terminal obtains the public key of the distributed storage node of the returned data from the public key table query, and uses the queried public key to verify the signature of the returned data to obtain the slice data packet and the transmitted hash value; S46. The patient user terminal calculates a hash value based on the slice data packet and compares the calculated hash value with the transmitted hash value; If the comparison is consistent, go to step S47; If the comparison is inconsistent, the corresponding slice data packet is discarded, and a data storage error is returned, and the process ends; S47. Decrypt each slice data packet according to the determined encryption strategy, and assemble the decrypted slices according to the encoding to obtain the required medical information data.

[0011] Furthermore, the specific steps of step S47 are as follows: S471. Determine the data type of the medical information corresponding to the returned slice data packet; When it is the patient's basic information or medical records, go to step S472; When the data type is diagnosis report or image data, the process goes to step S234; S472. The patient user terminal uses the saved first key to perform AES decryption on the encrypted slice in the slice data packet to obtain the slice, and proceeds to step S474; S473. The patient user terminal uses the private key in the stored first key pair to perform RSA asymmetric decryption to obtain a slice; S474. Assemble each slice in sequence according to the coding to obtain the final medical information data.

[0012] In a second aspect, the present application also provides a device for securely encrypting, transmitting and storing medical information, including: A medical information encryption strategy determination module is used to obtain a storage request for medical information, classify the data in the medical information, and determine an encryption strategy according to the data type; The medical information storage and backup module is used to slice various types of data in the medical information according to the set segmentation strategy, encrypt each slice according to the determined encryption strategy, and send it to the distributed storage node for storage and backup using a secure transmission channel, and set an index; The medical information recovery module is used to restore the lost medical information data from the backup according to the preset recovery strategy when a distributed storage node fails; The medical information reading module is used to obtain the reading request of medical information, verify the user's authority, and query from the distributed storage node according to the index after the user's authority verification is passed. The encrypted slices of the queried medical information are then read to the user terminal through a secure transmission channel for decryption and assembly to obtain the final medical information.

[0013] In a third aspect, an embodiment of the present application further provides an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the steps of the method for secure encrypted transmission and storage of medical information as described in the first aspect are implemented.

[0014] In a fourth aspect, an embodiment of the present application further provides a storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method for secure encrypted transmission and storage of medical information as described in the first aspect are implemented.

[0015] It can be seen from the above technical solutions that the present invention has the following advantages: In the method for secure encrypted transmission and storage of medical information provided in this application, the risks of leakage and tampering of medical information during transmission and storage are effectively reduced, thereby improving the security of medical information through means such as classified encryption, distributed storage, secure transmission channels and backup strategies; through fault detection and data recovery mechanisms, the rapid recovery of the medical information system after a fault occurs and the continuity of data are ensured, thereby improving the reliability and stability of the system; through strict permission verification and data reading processes, it is ensured that only authorized users can access and obtain medical information, thereby protecting the privacy and rights of patients. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solution of the present invention, the accompanying drawings required for use in the description will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0017] Figure 1 This is a flow chart of the method for securely encrypting, transmitting and storing medical information of the present invention.

[0018] Figure 2 This is a schematic diagram of the medical information secure encryption transmission and storage system of the present invention. DETAILED DESCRIPTION

[0019] In the specific steps of the method for secure encrypted transmission and storage of medical information described in detail below, various embodiments of the present disclosure will be described more comprehensively. The present disclosure may have various embodiments, and adjustments and changes may be made therein. However, it should be understood that there is no intention to limit the various embodiments of the present disclosure to the specific embodiments disclosed herein, but rather the present disclosure should be understood to cover all adjustments, equivalents and / or alternatives that fall within the spirit and scope of the various embodiments of the present disclosure.

[0020] For example, with the rapid expansion of the Internet medical field, the security challenges of patients' medical information are becoming more and more severe. This type of information not only touches on the sensitive areas of personal privacy, but is also a direct factor related to the safety of patients' lives. Unfortunately, the existing technology has exposed many security vulnerabilities in the transmission and storage of medical information, such as information leakage and data tampering, which pose a major threat to patients' privacy protection and medical safety.

[0021] At the data transmission level, although traditional encryption technology has been used to strengthen the security of information transmission, this single encryption method is powerless in the face of ever-changing network attacks. Information can be easily stolen or maliciously tampered with by criminals during the transmission path, so the confidentiality of medical information cannot be fully guaranteed.

[0022] The storage of medical information is also fraught with danger. Information is often concentrated on a single storage node, which not only doubles the risk of data leakage, but also hides the hidden danger of single point failure. Once the key node fails or is maliciously damaged, the entire medical information system may collapse instantly, and the continuity and reliability of medical services will suffer a severe blow. What's worse is that some medical systems have obvious shortcomings in data backup and recovery, or lack a complete data backup strategy, or are stretched in data recovery technology. Once the data is lost or damaged, it is often difficult to recover quickly, so the patient's medical information security is at great risk.

[0023] In summary, traditional medical information storage and transmission methods are no longer able to meet the current security challenges, and patient privacy protection and medical safety are facing unprecedented threats. In order to cope with this severe situation, we must actively explore more advanced and comprehensive medical information security strategies and technical means.

[0024] In response to the above problems, this embodiment provides a method for securely encrypting, transmitting and storing medical information, which can improve the security of medical information during transmission and storage, and reduce the risk of information leakage and data tampering.

[0025] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0026] See also Figure 1 The figure is a flowchart of a method for securely encrypting, transmitting and storing medical information in a specific embodiment, the method comprising the following steps: S1. Obtain a storage request for medical information, classify the data in the medical information, and determine an encryption strategy according to the data type; It should be noted that different encryption strategies are used for different data types of medical information, which can ensure data security and effectively preserve data transmission efficiency; S2. Slice each type of data in the medical information according to the set segmentation strategy, encrypt each slice according to the determined encryption strategy, and send it to the distributed storage node for storage and backup using a secure transmission channel, and set an index; It should be noted that slicing medical information can both ensure data transmission efficiency and prevent data from being stolen as a whole, while backing up stored data can prevent data loss caused by single point failures; S3. When a distributed storage node fails, the lost medical information data is restored from the backup according to the preset recovery strategy; It should be noted that the data of the failed distributed storage can be restored through backup to ensure the security of the stored data; S4. Obtain the read request of medical information, verify the user's authority, and after the user's authority is verified, query from the distributed storage node according to the index, and then read the encrypted slice of the queried medical information to the user terminal through a secure transmission channel for decryption and assembly to obtain the final medical information; It should be noted that user permission verification ensures that only authorized users can access medical information, and encryption and decryption ensure user security. Even if the medical information is stolen, accurate data cannot be obtained.

[0027] This embodiment effectively improves the security of medical information during transmission and storage, and reduces the risk of information leakage and data tampering through classified encryption, distributed storage and backup, and secure transmission channels.

[0028] Further, as a refinement and extension of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process in this embodiment, another method for secure encryption transmission and storage of medical information is provided, which includes: S1. Obtain a storage request for medical information, classify the data in the medical information, and determine the encryption strategy according to the data type; the specific steps of step S1 are as follows: S11. The medical information system identifies the registration request of the patient user, generates a first secret key for symmetric encryption for the patient user, and sends the first secret key to the patient user through a secure transmission channel; S12. The medical information system requests the patient user terminal to generate a first key pair for asymmetric encryption, and obtains the public key in the first key pair through a secure transmission channel; S13. The medical information system generates a second key pair for each distributed storage node, and saves the private key of the second key pair to the corresponding distributed storage node, and saves the public key of each second key pair as a public key table according to the serial number of the distributed storage node; S14. Obtain a storage request for medical information in the medical information system, and identify the patient's basic information, medical records, diagnostic reports, and imaging data in the storage request; S15. Set the medical information data of the patient's basic information and medical record type to be encrypted using the AES encryption algorithm; S16. Set the medical information data of the diagnosis report and image data types to be encrypted using the RSA asymmetric encryption algorithm; The flexibility and security of encryption are improved through the development of encryption strategies, including the combined use of symmetric and asymmetric encryption, and the selection of encryption methods for different types of medical information; S2. Slice each type of data in the medical information according to the set segmentation strategy, encrypt each slice according to the determined encryption strategy, and send it to the distributed storage node for storage and backup using a secure transmission channel, and set an index; the specific steps of step S2 are as follows: S21. Slice each type of medical information data to ensure that each slice does not contain sensitive information; S22. Encode each slice in the original order, determine the target storage node for each slice from the distributed storage nodes, and set the slices containing adjacent codes to be stored in different distributed storage nodes; S23. Query the public key of the target storage node from the public key table for each slice, encrypt each slice using the determined encryption strategy, then use the queried public key to sign and generate a slice data packet, and encode each slice data packet in the original order; S24. Send each slice data packet to the target storage node using a secure transmission channel; S25. Each distributed storage node verifies the signature of the received slice data packet, discards it if the verification fails, saves it after the verification passes, and creates a storage index; S26. Divide the distributed storage nodes into regions in advance; S27. Each distributed storage node determines a backup storage node for the slice data packet that has been saved, the region to which the backup storage node belongs is the farthest from the region to which the current distributed storage node belongs, and establishes a backup index; It should be noted that the integrity and security of medical information during storage are ensured through slicing, coding, distributed storage and signing, while the risk of single point failure is reduced through backup strategies; S3. When a distributed storage node fails, the lost medical information data is restored from the backup according to the preset recovery strategy; the specific steps of step S3 are as follows: S31. Regularly check the operating status of each distributed storage node; If the operation is normal, go to step S4; If a distributed storage node fails, proceed to step S32; S32. Determine the fault type of the faulty distributed storage node; If the faulty distributed storage node is down, proceed to step S34; If some data is lost in the failed distributed storage node, go to step S33; S33. Determine the lost slice data packet, query the backup index of the failed distributed storage node, determine the backup address of the lost slice data packet, request the lost slice data packet from each target backup node according to the backup address, complete data recovery, and enter step S4; S34. Use a new storage node to replace the original failed distributed storage node, and send a broadcast message to each distributed storage node to query the data slice data packet whose data source is the failed distributed storage node; S35. Each distributed storage node identifies the data source address from the broadcast message, compares it with its own backup index, and returns the slice data packet that matches the comparison to the replacement distributed storage node to complete data recovery; It should be noted that the fault detection and fault recovery steps of the package periodic detection, fault type determination, and data recovery ensure the rapid recovery of the medical information system and the continuity of data after a fault occurs; S4. Obtain a read request for medical information, verify user authority, and query from the distributed storage node according to the index after the user authority verification is passed, and then read the encrypted slice of the queried medical information to the user terminal through a secure transmission channel for decryption and assembly to obtain the final medical information; the specific steps of step S4 are as follows: S41. Obtain a request to read medical information and the type of medical information corresponding to the request; S42. Whether the user subject using the read request has the read permission for the corresponding type of medical information; If yes, go to step S43; If not, return permission error and end; S43. Query the distributed storage node for storing the required medical information according to the storage index and issue a data read request; S44. The distributed storage node that receives the data read request calculates the hash value of the corresponding slice data packet, signs the slice data packet and its hash value using the private key in the second key pair, and returns it to the user terminal; S45. The patient user terminal obtains the public key of the distributed storage node of the returned data from the public key table query, and uses the queried public key to verify the signature of the returned data to obtain the slice data packet and the transmitted hash value; S46. The patient user terminal calculates a hash value based on the slice data packet and compares the calculated hash value with the transmitted hash value; If the comparison is consistent, go to step S47; If the comparison is inconsistent, the corresponding slice data packet is discarded, and a data storage error is returned, and the process ends; S47. Decrypt each slice data packet according to the determined encryption strategy, and assemble the decrypted slices according to the code to obtain the required medical information data; It should be noted that through permission verification, data reading request, data signature verification and decryption of medical information reading process, it is ensured that only authorized users can access and obtain medical information.

[0029] In an embodiment of the present invention, based on step S21, step S23, step S25 and step S27, a possible embodiment is given below to illustrate its specific implementation scheme in a non-limiting manner.

[0030] The specific steps of step S21 are as follows: S211. Determine the basic slice size for each type of medical information data in advance; S212. Slice each type of medical information data according to the basic slice size; S213. Analyze whether each slice contains sensitive information; If yes, go to step S214; If not, proceed to step S22; S214. Perform a second split on the slice containing sensitive information, and return to step S213; The specific steps of step S23 are as follows: S231. Obtain a public key table, query the public key table according to the target storage node determined by each slice, and obtain the public key in the second key pair corresponding to each target storage node; S232. Identify the data type to which the slice belongs; When it is the patient's basic information or medical records, go to step S233; When the data type is diagnosis report or image data, the process goes to step S234; S233. The slice is encrypted by AES using the first key and then the hash value is calculated, and the process proceeds to step S235; S234. Perform RSA asymmetric encryption on the slice using the public key in the user's first key pair and then calculate the hash value; S235. The encrypted slice and hash value are signed with the public key of the second key pair of the target storage node to obtain a slice data packet; S236. Add the encoding of each slice data packet to the end of the slice data packet; The specific steps of step S25 are as follows: S251. The distributed storage node verifies the signature of the received slice data packet using the private key in the second key pair, and encrypts the slice and hash value; S252. Recalculate the hash value of the encrypted slice and compare it with the hash value of the signature verification; If they are consistent, the signature verification is successful and the process goes to step S253; If they are inconsistent, the signature verification fails, the currently received slice data packet is discarded, and the data sender is notified, and the process ends; S253. Save the slice data packet and create a storage index to record the user and code of the slice data packet; The specific steps of step S27 are as follows: S271. Regularly query each distributed storage node for newly added slice data packets; S272. Locate a distributed storage node, identify the distance between each distributed storage node and the located distributed storage node, and generate a backup table according to the distance; S273. Identify the storage node that is farthest from the backup table and the located distributed storage node; S274. Determine whether the identified storage node meets the backup requirements; If yes, go to step S276; If not, proceed to step S275; S275. Delete the identified storage node from the backup table and return to step S273; S276. Use the identified storage node as the target backup node, send the newly added slice data packet to the target backup node using a secure transmission channel, and create a backup index at the same time on the located distributed storage node and the target backup node; It should be noted that the reliability and efficiency of encrypted transmission and storage are improved through the processing of sensitive information, the generation and signature verification of sliced ​​data packets.

[0031] In an embodiment of the present invention, based on step S47, a possible embodiment is given below to illustrate its specific implementation scheme in a non-limiting manner.

[0032] The specific steps of step S47 are as follows: S471. Determine the data type of the medical information corresponding to the returned slice data packet; When it is the patient's basic information or medical records, go to step S472; When the data type is diagnosis report or image data, the process goes to step S234; S472. The patient user terminal uses the saved first key to perform AES decryption on the encrypted slice in the slice data packet to obtain the slice, and proceeds to step S474; S473. The patient user terminal uses the private key in the stored first key pair to perform RSA asymmetric decryption to obtain a slice; S474. Assemble the slices in order according to the coding to obtain the final medical information data to be understood; It should be noted that the accuracy and efficiency of reading medical information are improved through the decryption method and assembly process of slices of different types of medical information.

[0033] The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present invention.

[0034] like Figure 2 As shown, the following is an embodiment of the medical information secure encryption transmission and storage device provided by the embodiment of the present disclosure. The device and the medical information secure encryption transmission and storage method of the above-mentioned embodiments belong to the same inventive concept. For details not described in detail in the embodiment of the medical information secure encryption transmission and storage device, please refer to the embodiment of the medical information secure encryption transmission and storage method above.

[0035] The device includes: A medical information encryption strategy determination module is used to obtain a storage request for medical information, classify the data in the medical information, and determine an encryption strategy according to the data type; The medical information storage and backup module is used to slice various types of data in the medical information according to the set segmentation strategy, encrypt each slice according to the determined encryption strategy, and send it to the distributed storage node for storage and backup using a secure transmission channel, and set an index; The medical information recovery module is used to restore the lost medical information data from the backup according to the preset recovery strategy when a distributed storage node fails; The medical information reading module is used to obtain the reading request of medical information, verify the user's authority, and query from the distributed storage node according to the index after the user's authority verification is passed. The encrypted slices of the queried medical information are then read to the user terminal through a secure transmission channel for decryption and assembly to obtain the final medical information.

[0036] The medical information secure encryption transmission and storage device provided in this embodiment realizes the encryption, storage, backup, recovery and reading functions of medical information through modular design, thereby improving the overall security and reliability of the system.

[0037] The medical information security encryption transmission and storage method provided in the embodiment of the present application can be applied to electronic devices. It can be understood by those skilled in the art that the electronic device structure involved in the embodiment of the present invention does not constitute a limitation on the electronic device, and the electronic device may include more or less components than shown, or combine certain components, or arrange different components. In an embodiment of the present invention, the electronic device includes but is not limited to a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples, and are not intended to limit the implementation of the embodiments of the present application described and / or required herein.

[0038] The electronic device may include a processor, an external memory interface, an internal memory, a universal serial bus (USB) interface, a charging management module, a power management module, a battery, a wireless communication module, an audio module, a speaker, a microphone, a sensor module, buttons, a camera, a display, and a SIM card interface, etc.

[0039] It is to be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device. In other embodiments of the present application, the electronic device may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0040] The processor may include one or more processing units, for example, the processor may include a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated into one or more processors.

[0041] The processor can be the nerve center and command center of the electronic device. The controller can generate an operation control signal according to the instruction operation code and timing signal to complete the control of fetching and executing instructions.

[0042] A memory may also be provided in the processor for storing instructions and data. In some embodiments, the memory in the processor is a cache memory. The memory may store instructions or data that the processor has just used or is cyclically used. If the processor needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor, and thus improves system efficiency.

[0043] The above-mentioned electronic device implements the method for secure encrypted transmission and storage of medical information of the present application, which receives medical information storage requests, classifies data and determines encryption strategies; slices and encrypts each type of data, distributes it to distributed storage nodes through a secure channel and sets indexes; if a node fails, restores data from a backup; when receiving a read request, after verifying user permissions, queries and reads encrypted slices through indexes, transmits them to the user terminal through a secure channel for decryption and assembly, and finally obtains the medical information solution, thereby improving the security of medical information, ensuring the rapid recovery of the medical information system after a failure and the continuity of data, improving the reliability and stability of the system, ensuring that only authorized users can access and obtain medical information, and protecting the privacy and rights of patients.

[0044] The storage medium provided in this application stores a program product that can implement a method for secure encrypted transmission and storage of medical information.

[0045] The method for secure encrypted transmission and storage of medical information includes: obtaining a storage request for medical information, classifying the data in the medical information, and determining an encryption strategy according to the data type; slicing each type of data in the medical information according to a set segmentation strategy, encrypting each slice according to the determined encryption strategy, and sending the slice to a distributed storage node for storage and backup using a secure transmission channel, and setting an index; when a distributed storage node fails, restoring the lost medical information data from the backup according to a preset recovery strategy; obtaining a read request for medical information, verifying user authority, and querying from the distributed storage node according to the index after the user authority verification is passed, and then reading the encrypted slices of the queried medical information to the user terminal through a secure transmission channel for decryption and assembly to obtain the final medical information.

[0046] In some possible embodiments, the method for secure encrypted transmission and storage of medical information disclosed herein can be implemented in the form of a program product, which includes a program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps described in the above "Exemplary Method" section of this specification according to various exemplary embodiments of the present disclosure.

[0047] The storage medium of the present disclosure can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, a system, device or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0048] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for securely encrypting, transmitting and storing medical information, characterized in that: The steps include: S1. Obtain a storage request for medical information, classify the data in the medical information, and determine an encryption strategy according to the data type; S2. Slice each type of data in the medical information according to the set segmentation strategy, encrypt each slice according to the determined encryption strategy, and send it to the distributed storage node for storage and backup using a secure transmission channel, and set an index; S3. When a distributed storage node fails, the lost medical information data is restored from the backup according to the preset recovery strategy; S4. Obtain a read request for medical information, verify user permissions, and query from distributed storage nodes based on the index after the user permissions are verified. Then, read the encrypted slices of the queried medical information through a secure transmission channel to the user terminal for decryption and assembly to obtain the final medical information.

2. The method for securely encrypting, transmitting and storing medical information as claimed in claim 1, characterized in that: The specific steps of step S1 are as follows: S11. The medical information system identifies the registration request of the patient user, generates a first secret key for symmetric encryption for the patient user, and sends the first secret key to the patient user through a secure transmission channel; S12. The medical information system requests the patient user terminal to generate a first key pair for asymmetric encryption, and obtains the public key in the first key pair through a secure transmission channel; S13. The medical information system generates a second key pair for each distributed storage node, and saves the private key of the second key pair to the corresponding distributed storage node, and saves the public key of each second key pair as a public key table according to the serial number of the distributed storage node; S14. Obtain a storage request for medical information in the medical information system, and identify the patient's basic information, medical records, diagnostic reports, and imaging data in the storage request; S15. Set the medical information data of the patient's basic information and medical record type to be encrypted using the AES encryption algorithm; S16. Set the medical information data of the diagnosis report and image data types to be encrypted using the RSA asymmetric encryption algorithm.

3. The method for secure encrypted transmission and storage of medical information as claimed in claim 2, characterized in that: The specific steps of step S2 are as follows: S21. Slice each type of medical information data to ensure that each slice does not contain sensitive information; S22. Encode each slice in the original order, determine the target storage node for each slice from the distributed storage nodes, and set the slices containing adjacent codes to be stored in different distributed storage nodes; S23. Query the public key of the target storage node from the public key table for each slice, encrypt each slice using the determined encryption strategy, then use the queried public key to sign and generate a slice data packet, and encode each slice data packet in the original order; S24. Send each slice data packet to the target storage node using a secure transmission channel; S25. Each distributed storage node verifies the signature of the received slice data packet, discards it if the verification fails, saves it after the verification passes, and creates a storage index; S26. Divide the distributed storage nodes into regions in advance; S27. Each distributed storage node determines a backup storage node for the slice data packet that has been saved, the area to which the backup storage node belongs is farthest from the area to which the current distributed storage node belongs, and establishes a backup index.

4. The method for secure encrypted transmission and storage of medical information as claimed in claim 3, characterized in that: The specific steps of step S21 are as follows: S211. Determine the basic slice size for each type of medical information data in advance; S212. Slice each type of medical information data according to the basic slice size; S213. Analyze whether each slice contains sensitive information; If yes, go to step S214; If not, proceed to step S22; S214. Perform a second split on the slice containing sensitive information, and return to step S213; The specific steps of step S23 are as follows: S231. Obtain a public key table, query the public key table according to the target storage node determined by each slice, and obtain the public key in the second key pair corresponding to each target storage node; S232. Identify the data type to which the slice belongs; When it is the patient's basic information or medical records, go to step S233; When the data type is diagnosis report or image data, the process goes to step S234; S233. The slice is encrypted by AES using the first key and then the hash value is calculated, and the process proceeds to step S235; S234. Perform RSA asymmetric encryption on the slice using the public key in the user's first key pair and then calculate the hash value; S235. The encrypted slice and hash value are signed with the public key of the second key pair of the target storage node to obtain a slice data packet; S236. Add the encoding of each slice data packet to the end of the slice data packet; The specific steps of step S25 are as follows: S251. The distributed storage node verifies the signature of the received slice data packet using the private key in the second key pair, and encrypts the slice and hash value; S252. Recalculate the hash value of the encrypted slice and compare it with the hash value of the signature verification; If they are consistent, the signature verification is successful and the process goes to step S253; If they are inconsistent, the signature verification fails, the currently received slice data packet is discarded, and the data sender is notified, and the process ends; S253. Save the slice data packet and create a storage index to record the user and code of the slice data packet; The specific steps of step S27 are as follows: S271. Regularly query each distributed storage node for newly added slice data packets; S272. Locate a distributed storage node, identify the distance between each distributed storage node and the located distributed storage node, and generate a backup table according to the distance; S273. Identify the storage node that is farthest from the backup table and the located distributed storage node; S274. Determine whether the identified storage node meets the backup requirements; If yes, go to step S276; If not, proceed to step S275; S275. Delete the identified storage node from the backup table and return to step S273; S276. Use the identified storage node as the target backup node, send the newly added slice data packet to the target backup node using a secure transmission channel, and create a backup index at the located distributed storage node and the target backup node at the same time.

5. The method for securely encrypting, transmitting and storing medical information as claimed in claim 3, characterized in that: The specific steps of step S3 are as follows: S31. Regularly check the operating status of each distributed storage node; If the operation is normal, go to step S4; If a distributed storage node fails, proceed to step S32; S32. Determine the fault type of the faulty distributed storage node; If the faulty distributed storage node is down, proceed to step S34; If some data is lost in the failed distributed storage node, go to step S33; S33. Determine the lost slice data packet, query the backup index of the failed distributed storage node, determine the backup address of the lost slice data packet, request the lost slice data packet from each target backup node according to the backup address, complete data recovery, and enter step S4; S34. Use a new storage node to replace the original failed distributed storage node, and send a broadcast message to each distributed storage node to query the data slice data packet whose data source is the failed distributed storage node; S35. Each distributed storage node identifies the data source address from the broadcast message, compares it with its own backup index, and returns the consistent slice data packet to the replacement distributed storage node to complete data recovery.

6. The method for securely encrypting, transmitting and storing medical information as claimed in claim 4, characterized in that: The specific steps of step S4 are as follows: S41. Obtain a request to read medical information and the type of medical information corresponding to the request; S42. Whether the user subject using the read request has the read permission for the corresponding type of medical information; If yes, go to step S43; If not, return permission error and end; S43. Query the distributed storage node for storing the required medical information according to the storage index and issue a data read request; S44. The distributed storage node that receives the data read request calculates the hash value of the corresponding slice data packet, signs the slice data packet and its hash value using the private key in the second key pair, and returns it to the user terminal; S45. The patient user terminal obtains the public key of the distributed storage node of the returned data from the public key table query, and uses the queried public key to verify the signature of the returned data to obtain the slice data packet and the transmitted hash value; S46. The patient user terminal calculates a hash value according to the slice data packet and compares the calculated hash value with the transmitted hash value; If the comparison is consistent, go to step S47; If the comparison is inconsistent, the corresponding slice data packet is discarded, and a data storage error is returned, and the process ends; S47. Decrypt each slice data packet according to the determined encryption strategy, and assemble the decrypted slices according to the encoding to obtain the required medical information data.

7. The method for securely encrypting, transmitting and storing medical information as claimed in claim 6, characterized in that: The specific steps of step S47 are as follows: S471. Determine the data type of the medical information corresponding to the returned slice data packet; When it is the patient's basic information or medical records, go to step S472; When the data type is diagnosis report or image data, the process goes to step S234; S472. The patient user terminal uses the saved first key to perform AES decryption on the encrypted slice in the slice data packet to obtain the slice, and proceeds to step S474; S473. The patient user terminal uses the private key in the stored first key pair to perform RSA asymmetric decryption to obtain a slice; S474. Assemble each slice in sequence according to the coding to obtain the final medical information data.

8. A medical information secure encryption transmission and storage device, characterized in that: include: A medical information encryption strategy determination module is used to obtain a storage request for medical information, classify the data in the medical information, and determine an encryption strategy according to the data type; The medical information storage and backup module is used to slice various types of data in the medical information according to the set segmentation strategy, encrypt each slice according to the determined encryption strategy, and send it to the distributed storage node for storage and backup using a secure transmission channel, and set an index; The medical information recovery module is used to restore the lost medical information data from the backup according to the preset recovery strategy when a distributed storage node fails; The medical information reading module is used to obtain the reading request of medical information, verify the user's authority, and query from the distributed storage node according to the index after the user's authority verification is passed. The encrypted slices of the queried medical information are then read to the user terminal through a secure transmission channel for decryption and assembly to obtain the final medical information.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the method for secure encryption, transmission and storage of medical information as described in any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for secure encrypted transmission and storage of medical information as described in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Authority verification method, electronic equipment, storage medium and program product

    CN120354435A