Sensitive data encryption access control method based on block chain smart contract

By using smart contracts and asymmetric encryption algorithms on the blockchain, encrypted storage and fine-grained access control of sensitive medical data are solved, and the problem of insufficient security of sensitive data storage and transmission in traditional technologies is achieved, and higher data security and privacy protection are achieved.

CN120030561AInactive Publication Date: 2025-05-23SHENZHEN ZHONGYUE YUNCHUANG TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411887706.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-20
Publication Date
2025-05-23
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art has the risk of single point of failure and data leakage when protecting sensitive data, especially in the storage and transmission of medical data, making it difficult to effectively ensure the security and privacy of the data.

Method used

The sensitive data encryption access control method based on blockchain smart contracts is adopted to encrypt medical record data through asymmetric encryption algorithms, and fine-grained access control is realized through smart contracts to ensure that only authorized personnel can access sensitive data.

Benefits of technology

Through encrypted storage and access control, ensuring that sensitive data will not be leaked or tampered with, reducing the risk of privacy leakage, improving data security and privacy protection, and enhancing the scalability and automation of data management systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030561A_ABST
    Figure CN120030561A_ABST
Patent Text Reader

Abstract

The invention discloses a sensitive data encryption access control method based on a block chain smart contract, and relates to the technical field of encryption access control, and the method comprises the following steps: carrying out the encryption processing of original medical record data of a patient based on an asymmetric encryption algorithm, and converting the original medical record data into a ciphertext; creating an intelligent contract which comprises access control logic, checking the identity and access conditions of the visitor according to the access control logic, and judging whether the visitor is allowed to obtain the access authority; obtaining access data information according to the access control logic, and testing the key by using a cryptographic analysis tool to obtain a cracking probability; and based on the access data information and the cracking probability, determining the encryption performance after prime number modification according to fuzzy reasoning. According to the invention, the problem of medical data leakage in the prior art is solved, the legality and compliance of data access are ensured, and the sensitive medical data of the patient is better protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted access control, and more specifically, to a sensitive data encrypted access control method based on blockchain smart contracts. Background Art

[0002] Blockchain is a decentralized distributed ledger technology that was first introduced by Bitcoin and has received widespread attention. It provides a secure and reliable way to store records by distributing data on multiple nodes and ensuring the immutability and transparency of data through encryption technology. With the development of technology, the application scope of blockchain is not limited to digital currency, but has also expanded to smart contracts, supply chain management, voting systems, medical data sharing and other fields. Smart contracts are programmable codes or protocols on the blockchain that can automatically execute contract terms when certain conditions are met. Smart contracts are usually used to define and execute transaction rules, asset transfers, etc. Sensitive data can be encrypted and stored on the blockchain network to ensure that only authorized users can access it. This means that even if the nodes of the blockchain network are attacked or leaked, the data itself remains encrypted and cannot be read directly. Blockchain can be used as a distributed identity authentication and permission management system. Through smart contracts, fine-grained access control policies can be created to ensure that only legitimate users can access sensitive data. The identity of users can be verified through encrypted signatures, and smart contracts will check the user's permissions according to predefined rules. All data access requests and behaviors will be recorded in the blockchain and cannot be tampered with, which provides transparency and audit capabilities to ensure the legality and compliance of data access.

[0003] Deficiencies of existing technologies:

[0004] With the development of information technology, the storage and transmission of sensitive data are facing increasingly severe security challenges. Traditional access control mechanisms usually rely on centralized authentication servers, which have the risk of single point failure and data leakage. It is crucial for medical institutions to protect patients' sensitive medical data, which is not only related to the patient's personal privacy, but also involves law, ethics, and the quality of medical services. Unauthorized disclosure or abuse of these data will not only infringe on the patient's privacy, but also may lead to psychological, social and professional adverse consequences. Therefore, the present invention proposes a sensitive data encryption access control method based on blockchain smart contracts to protect the access rights of sensitive data in a decentralized environment and better protect the patient's sensitive medical data. The selection and modification of prime numbers in the RSA algorithm involve many aspects, including the size of prime numbers, randomness, avoidance of special patterns, primality detection, etc. By adjusting and optimizing these factors, the security of the RSA algorithm can be improved, and the encryption process can be prevented from being easily cracked due to improper prime number selection.

[0005] In view of the above problems, the present invention proposes a solution. Summary of the invention

[0006] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a sensitive data encryption access control method based on blockchain smart contracts, which solves the problems raised in the above-mentioned background technology by protecting the access rights of sensitive data.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] The sensitive data encryption access control method based on blockchain smart contract includes the following steps: encrypting the original medical record data of the patient based on an asymmetric encryption algorithm, and converting the original medical record data into ciphertext; creating a smart contract, wherein the smart contract includes access control logic, checking the visitor identity and access conditions according to the access control logic, and judging whether the visitor is allowed to obtain access rights; obtaining access data information according to the access control logic, and using a cryptanalysis tool to test the key to obtain the cracking probability; and determining the encryption performance after modifying the prime number according to fuzzy reasoning based on the access data information and the cracking probability.

[0009] In a preferred embodiment, the encryption process of the asymmetric encryption algorithm is as follows: in asymmetric encryption, a pair of public keys and a pair of private keys are generated; the public key is publicly distributed and anyone can use it to encrypt data; the private key is kept confidential and can only be held by the patient and the authorized doctor, and is used to decrypt data encrypted by the public key.

[0010] In a preferred embodiment, the specific steps of creating a smart contract are as follows: install a browser-based Solidity development environment to write and deploy smart contracts; import the OpenZeppelin library to provide a variety of permission management tools; use the Ownable contract to implement basic access control functions; after the contract is written, use the Remix IDE to compile, deploy and test, simulate accounts of different roles to execute methods in the contract, and verify whether the access control logic is correct.

[0011] In a preferred embodiment, the specific process of checking the visitor's identity and access conditions according to the access control logic and determining whether the visitor is allowed to obtain access rights is as follows: it is stipulated that only the patient himself and the authorized doctor can access the patient's medical records, and the authorized doctor must access within a specific time period; the visitor registers identity information, and the visitor's identity is determined by digital information; if the visitor is the patient himself, the visitor is allowed to obtain access rights and access the medical records; if the visitor is an authorized doctor and access is made within a specific time period, the visitor is allowed to obtain access rights and access the medical records, and if the visit is not made within the specific time period, the visitor is not allowed to obtain access rights; if the visitor is not the patient himself or an authorized doctor, the visitor is not allowed to obtain access rights.

[0012] In a preferred embodiment, the process of accessing medical records is as follows: when the visitor is allowed to obtain access rights, the smart contract unlocks the encrypted data stored on the blockchain and decrypts the data using a private key.

[0013] In a preferred embodiment, the access data information includes decomposition risk deviation data; the process of obtaining the cracking probability is as follows: obtain the number of key bits and the number of key cracking attempts per second by the attacker, and calculate the time it takes for the attacker to crack the key based on the number of key bits and the number of key cracking attempts; divide the preset time by the key cracking time to obtain the number of key cracking attempts that can be made within a preset period, and calculate the cracking probability based on the number of key cracking attempts and the number of key bits.

[0014] In a preferred embodiment, the specific steps of determining the encryption performance after modifying the prime number based on the access data information and the cracking probability according to fuzzy reasoning are as follows: defining the decomposed risk deviation data and the cracking probability as input variables, and dividing them into different fuzzy sets respectively; defining the encryption performance after modifying the prime number as an output variable, and dividing it into fuzzy sets;

[0015] Formulate fuzzy rules to describe the impact of decomposition risk deviation data and cracking probability on the encryption performance after the prime number is modified; perform fuzzy reasoning based on the fuzzy rules to determine the encryption performance after the prime number is modified.

[0016] The technical effects and advantages of the sensitive data encryption access control method based on blockchain smart contracts of the present invention are as follows:

[0017] 1. The present invention ensures that sensitive data will not be leaked or tampered with through encrypted storage and access control. With the decentralized nature of blockchain, data storage and access rights are not concentrated on a single centralized server, reducing the risk of privacy leakage. Smart contracts can define complex access control policies according to specific needs to ensure accurate management of access rights. Each data access and permission operation is recorded through blockchain, providing a transparent audit trail to ensure the legality and security of data operations.

[0018] 2. The present invention improves the scalability and automation of the patient medical record management system. With the continuous development of informatization in the medical industry, the patient medical record management system needs to have higher automation and scalability. Smart contracts automatically execute access policies and key management, which not only reduces manual intervention but also reduces the complexity of system operations. This automation makes the medical data management system more efficient, especially when processing large-scale data. Smart contracts can ensure that data exchange and sharing between different medical institutions always meet security and privacy requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 This is a structural diagram of the sensitive data encryption access control method based on blockchain smart contracts of the present invention. DETAILED DESCRIPTION

[0020] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0021] Embodiment 1, Figure 1 The present invention provides a sensitive data encryption access control method based on blockchain smart contracts.

[0022] S10, converting the original medical record data of the patient into ciphertext through encryption processing based on an asymmetric encryption algorithm, and obtaining public and private keys based on an RSA algorithm;

[0023] The asymmetric encryption algorithm uses a pair of public and private keys, wherein the public key is used to encrypt data and the private key is used to decrypt data;

[0024] The encryption process of the asymmetric encryption algorithm is as follows:

[0025] In asymmetric encryption, you first need to generate a pair of public keys and a pair of private keys;

[0026] The public key is publicly distributed and anyone can use it to encrypt data;

[0027] The private key is kept confidential and can only be held by the patient and the authorized doctor, and is used to decrypt data encrypted by the public key;

[0028] The specific process of obtaining public and private keys based on the RSA algorithm is as follows:

[0029] Randomly select two different large prime numbers p and q, multiply the two large prime numbers to get the modulus n, and calculate the Euler function based on the two large prime numbers. The formula is as follows:

[0030] The Euler function is used to select the public key exponent in the RSA algorithm. An integer e is selected as the public key exponent so that e and are mutually prime, and Calculate e pairs The modular inverse function of gets the private key prime number d, the public key is (n, e), and the private key is (n, d);

[0031] The specific calculation formula of the encryption process of the asymmetric encryption algorithm is as follows: C = M e *(mod n); where C is the ciphertext, M is the medical record data converted into digital form through ASCII code, and e and n are the generated public key pair;

[0032] The process of converting medical record data into ciphertext is as follows:

[0033] A public key is usually used to encrypt the patient's medical record data, which may be a file in text, digital or other forms;

[0034] The original medical record data is converted into ciphertext through encryption algorithms;

[0035] The encrypted ciphertext can be transmitted securely over the network. Even if it is intercepted in the middle, the third party cannot decrypt the data because they do not have the private key.

[0036] The main purpose of encrypting the patient's medical record data based on an asymmetric encryption algorithm is to protect the patient's privacy and ensure that only authorized personnel can decrypt and access these sensitive data. Asymmetric encryption algorithms use a pair of public and private keys, where the public key is used to encrypt data and the private key is used to decrypt data.

[0037] S20, creating a smart contract, wherein the smart contract includes access control logic, and checks the visitor's identity and access conditions according to the access control logic to determine whether the visitor is allowed to obtain access rights;

[0038] The specific steps for creating a smart contract are as follows:

[0039] First, install the development environment. You can use Remix IDE (a browser-based Solidity development environment to write and deploy smart contracts;

[0040] Import the OpenZeppelin library. For complex access control logic, OpenZeppelin is a widely used smart contract library that provides a variety of permission management tools. Using Ownable contracts can easily implement basic access control functions.

[0041] In Solidity, Ownable can be used to implement simple access control. The Ownable contract sets the deployer as the owner of the contract by default. The contract owner can perform specific operations, and other users do not have permission to perform these operations unless authorized;

[0042] After writing the contract, you can use Remix IDE to compile, deploy and test it. You can simulate accounts of different roles in Remix to execute the methods in the contract to verify whether the access control logic is correct.

[0043] The specific process of checking the visitor's identity and access conditions according to the access control logic and determining whether to allow the visitor to obtain access rights is as follows:

[0044] It stipulates that only the patient and the authorized physician can access the patient's medical records, and the authorized physician must have access within a specific time period;

[0045] The visitor registers his or her identity information on the blockchain, and the visitor's identity is determined by digital information. If the visitor is the patient himself or herself, the visitor is allowed to obtain access rights;

[0046] If the visitor is an authorized doctor and the visit is made within a specific time period, the visitor is allowed to obtain access rights. If the visit is not made within the specific time period, the visitor is not allowed to obtain access rights.

[0047] If the visitor is not the patient himself and the authorized doctor, the visitor will not be allowed to obtain access rights.

[0048] When the visitor is allowed to obtain access rights, the smart contract unlocks the encrypted data stored on the blockchain and decrypts the data using the private key; the calculation formula for decrypting the data using the private key is as follows: M = C d *(mod n); where C is the ciphertext, M is the medical record data, and d and n are the generated public key pairs.

[0049] Access control logic plays a vital role in protecting patient medical records. By checking the accessor identity and access conditions, access control can ensure that only authorized personnel can access sensitive patient information. The following are its specific benefits in protecting medical records:

[0050] Ensure data privacy and confidentiality: Access control verifies the identity of visitors and ensures that only authenticated personnel can access patients' medical records. This prevents unauthorized personnel from obtaining sensitive information and protects patients' privacy. By limiting visitors to only view patient information related to their work, it avoids excessive sharing of information and reduces the risk of leakage of patients' personal data.

[0051] Enhanced data security: Access control can introduce multiple authentication mechanisms to further improve security. Even if an attacker can obtain the credentials of a visitor, a second layer of verification is still required to access sensitive data. Access control usually includes monitoring and logging of data access, recording who accessed what information, when, and what actions were taken. In this way, system administrators can detect abnormal behavior in a timely manner and prevent data leakage or tampering.

[0052] Ensure the right access rights: Through the allocation of roles and responsibilities, medical institutions can precisely define which staff members have access to which types of patient information. This precise control ensures that each role only obtains necessary data, and access rights can be dynamically adjusted based on changes in the patient's status, the department the patient is in, or the medical team. This means that in different clinical scenarios, medical staff can flexibly access relevant information, but always maintain appropriate control;

[0053] Reduce internal risks: Without strict access control, medical staff may abuse their authority and access patient information that is not related to their work. Access control prevents this kind of behavior by setting permission restrictions. When an employee leaves or changes roles, timely updating their access rights can prevent old employees from still being able to access sensitive patient data and avoid internal information leakage;

[0054] Improve patient trust: Patients will have greater trust in medical institutions and staff when they know their medical records are strictly protected. Trust is a very important factor in medical services, especially when it comes to personal health information;

[0055] Improve medical quality: Appropriate access control ensures that medical staff can obtain accurate patient information when needed, helping them make more informed medical decisions. This is crucial to improving the quality of diagnosis and treatment. Since each role can only access relevant information, information overload and misunderstanding are avoided, reducing the risk of misdiagnosis or missed diagnosis.

[0056] S30, obtaining a prime number in the RSA algorithm based on the Miller-Rabin primality test, modifying another prime number according to the secure prime number algorithm, and using a cryptanalysis tool to test the private key generated by the RSA algorithm after the prime number is modified to obtain a cracking probability;

[0057] The specific process of obtaining a prime number in the RSA algorithm based on the Miller-Rabin primality test is as follows:

[0058] Randomly select an odd number m that is larger than the original prime number, and divide m-1 by 2 until an odd number d is obtained, where the number of divisions by 2 is s, and m-1 is expressed as 2 s *d;

[0059] Choose an integer a in the range [2, m-2] as the base and calculate a d mod m, if the result is 1 or m-1, then m may be a prime number, if the result is not 1 or m-1, continue the iterative operation If the result is 1 or m-1, then m may be a prime number;

[0060] Repeatedly test multiple random bases a until the preset maximum number of repeated tests is reached. If the results in all tests are 1 or m-1, then m is a prime number, otherwise m is not a prime number;

[0061] When m is not a prime number, test whether m+2 is a prime number. If m+2 is not a prime number, continue to iterate in this way until a prime number p is found. b ;

[0062] According to the secure prime number algorithm, the prime number p b Modify another prime number, another prime number p b The calculation formula is as follows: b =2p b +1;

[0063] Based on the modified prime number, the public and private keys are obtained according to the RSA algorithm, and the private key is tested using a cryptanalysis tool to obtain the probability of successful cracking within a preset time. The process of obtaining the cracking probability is as follows:

[0064] The number of bits of the private key and the number of attempts to crack the key per second by the attacker are obtained, and the time it takes for the attacker to crack the private key is calculated by dividing the number of bits of the private key by the number of attempts to crack the key per second. The preset time is divided by the time to crack the private key to obtain the number of attempts to crack the private key within the preset period, and the probability of cracking the private key is calculated based on the number of attempts to crack the private key and the number of bits of the private key.

[0065] The specific calculation formula of the cracking probability is as follows: In the formula, P is the probability of cracking, N is the number of digits of the private key, T is the preset time, and t is the time to crack the private key. is the number of attempts to crack the key;

[0066] The probability of cracking is of great significance in the field of information security, especially when protecting patient medical records. It not only involves the technical aspects of cryptography and data encryption, but also directly relates to the confidentiality of medical data and the privacy protection of patients. The following are some key benefits of the probability of cracking for protecting patient medical records:

[0067] Improve data security: The cracking probability reflects the possibility of an attacker successfully cracking the encryption or accessing the protected data. If the cracking probability of the encryption algorithm is extremely low, it means that it is very difficult for an attacker to obtain the patient's medical records through brute force, exhaustive search or other means. By using a strong encryption algorithm to reduce the cracking probability, data leakage or malicious tampering can be effectively prevented, and data confidentiality can be enhanced;

[0068] Enhanced patient privacy protection: Patients’ medical records contain sensitive personal health information. Leakage of this information may lead to identity theft, financial loss, and even social stigmatization. By reducing the probability of cracking, patients’ privacy can be ensured not to be easily violated. For example, the use of high-strength encryption in medical institutions, hospitals, and clinics can effectively prevent medical records from being illegally accessed, thereby protecting patients’ privacy and information security.

[0069] Improve trust: Medical institutions need to ensure the reliability of their data protection measures. Patients and the public's trust in medical institutions depends largely on their ability to protect patients' medical records. If the probability of cracking is low, patients are more likely to believe that the institution will protect their personal information and are more willing to share important medical data. This trust helps improve the quality and efficiency of medical services;

[0070] Improve emergency response capabilities:

[0071] If the probability of encryption being cracked is low, institutions may need more time to discover and respond to potential security vulnerabilities and attacks. In this case, medical institutions can more effectively monitor and respond to abnormal activities in the system. The strength of encryption algorithms and protection measures can provide security teams with more time to discover and respond to attacks, reducing potential losses.

[0072] Strengthen remote access security: With the popularity of telemedicine and electronic health record (EHR) systems, protecting the security of medical records has become more complicated. Remote access usually means that data is transmitted over the network, increasing the risk of attack. By reducing the probability of cracking, it can ensure that no matter where the patient or doctor accesses it, the data can be reliably protected, reducing the possibility of being attacked by a man-in-the-middle when transmitted over an insecure network.

[0073] S40, substitute the modified prime number into the historical encryption algorithm to evaluate the decomposition risk of the historical algorithm, and calculate the difference with the original historical algorithm decomposition risk to obtain decomposition risk deviation data, and evaluate the encryption performance after the modified prime number based on the risk deviation data and the cracking probability according to fuzzy reasoning.

[0074] Bring the modified prime number into the historical RSA algorithm, and multiply the modified prime number to get the modulus of the RSA algorithm. Calculate the decomposition time of the historical classic algorithm based on the modulus. The specific calculation formula for the decomposition time of the historical classic algorithm is as follows: Where T x is the decomposition time of the historical classic algorithm, and n is the modulus of the RSA algorithm;

[0075] Calculate the difference between the decomposition time of the modified prime number using the historical classical algorithm and the decomposition time of the original historical classical algorithm as the decomposition risk deviation data;

[0076] The longer the decomposition time of the historical classic algorithm is, the better the encryption effect is. Therefore, the larger the decomposition risk deviation data is, the better the prime number modification effect is.

[0077] The specific process of evaluating the encryption performance after modifying the prime number based on risk deviation data and cracking probability according to fuzzy reasoning is as follows:

[0078] In step C1, the decomposed risk deviation data and cracking probability are defined as input variables, and they are divided into different fuzzy sets.

[0079] For example, "Low", "Medium", "High" for decomposing risk bias data, and "Low", "Medium", "High" for cracking probability.

[0080] Step C2, defining the encryption performance after the prime number is modified as an output variable, and dividing it into fuzzy sets, for example, "Yes", "No", for the encryption performance after the prime number is modified.

[0081] Step C3, formulate a set of fuzzy rules to describe the impact of different input variables on output variables. The definition of rules can be based on professional knowledge or obtained through data analysis and experiments. For example:

[0082] Mark the decomposed risk deviation data as B, the cracking probability as P, and the encryption performance after modifying the prime number as D, then we can define

[0083] Rule 1:IF(B is Low)AND(P is High)THEN(D is Low)

[0084] Rule 2:IF(B is High)AND(P is Low)THEN(D is High) ...

[0086] Step C4, performing fuzzy reasoning according to fuzzy rules to determine the encryption performance after the prime number is modified.

[0087] It should be noted that the division of fuzzy sets can be adjusted according to actual conditions. For example, although this embodiment takes three fuzzy sets as examples, the decomposition risk deviation data and cracking probability and the encryption performance after modifying the prime number can actually be divided into more than three sets to facilitate better precise adjustment.

[0088] Furthermore, for the judgment of the encryption performance after modifying the prime number, a threshold can be set according to the actual situation. For example, when the decomposition risk deviation data exceeds 15s, it is marked as "High", and when the cracking probability is higher than 0.6, it is marked as "High", etc., which will not be elaborated here.

[0089] In the medical industry, smart contracts, as an automated, self-executing contractual agreement, are gradually being used to manage and protect patients' medical records. Smart contracts provide transparent, decentralized and tamper-proof features through blockchain technology, which helps to improve data security and privacy protection. For patients' medical records, the access policy and key update mechanism of smart contracts can provide benefits at multiple levels:

[0090] Protect patient privacy and security: Smart contracts can set strict access control policies based on real-time needs. By defining different roles’ access rights to patient medical records, smart contracts can ensure that only authorized personnel can view, modify or process data. Smart contracts can flexibly update access policies based on actual conditions (for example, when patients need to adjust who can access their records) without the need for centralized institutions to intervene. Smart contracts can use public and private key encryption technology to protect the access of medical data. When patients or medical providers need to access medical records, the system will authenticate through encryption keys to avoid unauthorized access or data leakage. If the key is lost or leaked, it can be quickly updated or revoked to ensure that the data remains secure.

[0091] Enhanced data immutability: Once data is recorded on the blockchain, smart contracts ensure that any changes cannot be tampered with or deleted. This immutability is particularly important for medical data because it ensures that the patient's medical records can maintain integrity under any circumstances and prevent data from being maliciously tampered with or forged. When access policies and keys are updated, smart contracts ensure that these operations are recorded on the blockchain, and any attempt to change access rights will be transparently displayed and cannot be withdrawn.

[0092] Real-time and flexible key update mechanism: In traditional systems, key updates often require complex manual intervention and centralized management. Smart contracts can automatically update keys through pre-set rules without manual intervention. Patients can change their access keys or permissions at any time as needed to control who can access their medical records. This flexibility enables patients to better control the privacy of their medical data and avoid exposing medical data to unnecessary third parties.

[0093] Prevent unauthorized access and data leakage: Medical records usually contain sensitive information. Any unauthorized access may lead to data leakage or privacy violation. Smart contracts can ensure that data is only authorized to access when the predetermined conditions are met. Smart contracts can also automatically detect and prevent non-compliant access requests, reducing the possibility of human error and malicious attacks. Dynamic management of key updates and access rights enables the system to make timely adjustments and repairs when potential security threats occur (such as key theft or user identity tampering).

[0094] Improve transparency and trust in data sharing: Smart contracts allow efficient and secure data sharing between patients and healthcare providers. For example, with the patient's consent, doctors can temporarily access the patient's medical records, and when the patient withdraws permission, the system will immediately prohibit access. This transparent access control can enhance patients' trust in the medical system and prevent data from being abused during sharing; all key updates and access control changes will leave a permanent record on the blockchain to ensure auditing and tracking. Even if a data leak or security incident occurs, system administrators can identify responsibilities and take appropriate measures to repair them;

[0095] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.

[0096] The above embodiments may be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented by software, the above embodiments may be implemented in whole or in part in the form of a computer program product.

[0097] Those of ordinary skill in the art will appreciate that the modules and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0098] In addition, each functional module in each embodiment of the present application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.

[0099] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0100] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A sensitive data encryption access control method based on blockchain smart contracts, characterized in that: The following steps are involved: The original medical record data of the patient is converted into ciphertext through encryption based on the asymmetric encryption algorithm, and the public and private keys are obtained based on the RSA algorithm; Creating a smart contract, wherein the smart contract includes access control logic, and checks the visitor's identity and access conditions according to the access control logic to determine whether the visitor is allowed to obtain access rights; The prime numbers in the RSA algorithm are modified based on the Miller-Rabin primality test and the secure prime number algorithm, and the private key generated by the RSA algorithm after the prime numbers are modified is tested using a cryptanalysis tool to obtain the cracking probability; Substitute the modified prime number into the historical encryption algorithm to evaluate the decomposition risk of the historical algorithm, and calculate the difference with the original historical algorithm decomposition risk to obtain the decomposition risk deviation data. Based on the risk deviation data and the cracking probability, the encryption performance after the modified prime number is evaluated according to fuzzy reasoning.

2. According to claim 1, the method for sensitive data encryption access control based on blockchain smart contract is characterized in that: The encryption process of the asymmetric encryption algorithm is as follows: In asymmetric encryption, a pair of public keys and a pair of private keys are generated; The public key is publicly distributed and anyone can use it to encrypt data; The private key is kept confidential and can only be held by the patient and the authorized doctor, and is used to decrypt data encrypted by the public key.

3. The sensitive data encryption access control method based on blockchain smart contract according to claim 2 is characterized in that: The specific process of obtaining the public and private keys based on the RSA algorithm is as follows: Randomly select two different large prime numbers p and q, multiply the two large prime numbers to get the modulus n, and calculate the Euler function based on the two large prime numbers The formula is as follows: Select e as the public key exponent in the RSA algorithm through the Euler function, so that e and are mutually prime, and Calculate e pairs The modular inverse function obtains the private key prime number d, the public key is (n,e), and the private key is (n,d).

4. The sensitive data encryption access control method based on blockchain smart contract according to claim 3 is characterized in that: The access condition refers to a specific time period. The specific process of checking the visitor's identity and access condition according to the access control logic and determining whether to allow the visitor to obtain access rights is as follows: It stipulates that only the patient and the authorized physician can access the patient's medical records, and the authorized physician must have access within a specific time period; Visitors register their identity information and use digital information to determine the visitor's identity; If the visitor is the patient himself, the visitor is allowed to obtain access rights and access the medical records; If the visitor is an authorized doctor and the visit is made within a specific time period, the visitor is allowed to obtain access rights and access the medical records. If the visit is not made within the specific time period, the visitor is not allowed to obtain access rights; If the visitor is not the patient himself and the authorized doctor, the visitor will not be allowed to obtain access rights.

5. The sensitive data encryption access control method based on blockchain smart contract according to claim 4 is characterized in that: The specific process of modifying the prime numbers in the RSA algorithm based on the Miller-Rabin primality test and the secure prime number algorithm is as follows: Randomly select an odd number m that is greater than the original prime number, divide m-1 by 2 repeatedly until an odd number d is obtained, and record the number of times s is divided by 2, that is, m-1 = 2 s *d; Choose a random base a and calculate a d mod m, if the result is 1 or m-1, then m may be a prime number, otherwise continue iterating Until you get 1 or m-1; Repeat the test multiple times. If all the results are 1 or m-1, then m is a prime number. If m is not a prime number, test whether m+2 is a prime number. If not, continue testing m+4 until a prime number is found. A prime number is used to modify another prime number according to a secure prime number algorithm to obtain two modified prime numbers.

6. The sensitive data encryption access control method based on blockchain smart contract according to claim 5 is characterized in that: The process of obtaining the cracking probability is as follows: Get the number of bits of the private key and the number of attempts to crack the key per second by the attacker, and calculate the time it takes for the attacker to crack the private key by dividing the number of bits of the private key by the number of attempts to crack the key per second. The preset time is divided by the time to crack the private key to obtain the number of attempts to crack the private key within the preset period, and the probability of cracking is calculated based on the number of attempts to crack the private key and the number of bits of the private key.

7. The sensitive data encryption access control method based on blockchain smart contract according to claim 6 is characterized in that: The process of obtaining the decomposed risk deviation data is as follows: Bring the modified prime number into the historical RSA algorithm, multiply the modified prime number to get the modulus of the RSA algorithm, and calculate the decomposition time of the historical classic algorithm based on the modulus; The specific calculation formula for the decomposition time of the historical classic algorithm is as follows: Where T x is the decomposition time of the historical classic algorithm, and n is the modulus of the RSA algorithm; The difference between the decomposition time of the modified prime number using the historical classical algorithm and the decomposition time of the original historical classical algorithm is calculated as the decomposition risk deviation data.

8. The sensitive data encryption access control method based on blockchain smart contract according to claim 7 is characterized in that: The specific steps for evaluating the encryption performance after modifying the prime number based on risk bias data and cracking probability according to fuzzy reasoning are as follows: Decomposition risk deviation data and cracking probability are defined as input variables, and they are divided into different fuzzy sets respectively; The encryption performance after modifying the prime number is defined as the output variable, which is divided into fuzzy sets; Formulate fuzzy rules to describe the impact of decomposition risk bias data and cracking probability on encryption performance after modifying prime numbers; Fuzzy reasoning is performed based on fuzzy rules to determine the encryption performance after modifying the prime number.

9. The sensitive data encryption access control method based on blockchain smart contract according to claim 8 is characterized in that: The specific calculation formula of the encryption process of the asymmetric encryption algorithm is as follows: C = M e *(mod n); where C is the ciphertext, M is the medical record data converted into digital form through ASCII code, and e and n are the generated public key pair; the calculation formula for decrypting the data using the private key is as follows: M = C d *(mod n); where C is the ciphertext, M is the medical record data, and d and n are the generated public key pairs.

10. The sensitive data encryption access control method based on blockchain smart contract according to claim 9 is characterized in that: The specific calculation formula of the cracking probability is as follows: Where P is the probability of cracking, N is the number of key bits, T is the preset time, and t is the time to crack the key. Indicates the number of attempts to crack the key within the preset period.