Hospital database data encryption storage method, device and system and storage medium

By applying a data encryption method based on hash encryption algorithm in hospital databases, the problem that traditional security measures cannot meet the needs of new network attacks is solved, and efficient security protection of hospital database information is achieved.

CN120030564APending Publication Date: 2025-05-23SHANGHAI CITY PUDONG NEW DISTRICT ZHOUPU HOSPITAL
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411948274.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing technology cannot effectively ensure the security of hospital database information, especially when facing diversified and frequent network attacks, traditional methods cannot meet the new information security management needs.

Method used

Using a hash encryption algorithm method, the medical raw data is logistically mapped, mapped to discrete multi-dimensional space in time, generated a mapping sequence, and encrypted through a hash encryption matrix to generate encrypted data, and finally stored the encrypted data in the database.

Benefits of technology

It effectively reduces the packet loss rate of hospital databases, improves the security of information, and ensures the security of information during storage and transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030564A_ABST
    Figure CN120030564A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a hospital database data encryption storage method, device and system and a storage medium, and the method comprises the steps: mapping medical original data into a multidimensional space which is discrete in time according to a preset strategy, and obtaining a mapping sequence; performing encryption processing on the mapping sequence based on a Hash encryption method to obtain encrypted data; and storing the encrypted data in a database. According to the method provided by the embodiment of the invention, the Hash encryption algorithm is applied to the information security management and storage of the hospital database aiming at the defects and defects of the traditional method, so that the packet loss rate of the hospital database is effectively reduced, and the information security is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer software technology, and in particular to a hospital database data encryption storage method, device, system and storage medium. Background Art

[0002] With the rapid development of digitalization and information technology, medical institutions have begun to build and apply information systems. Databases are the main tool for storing hospital data information and store a large amount of medical information. This information has important confidentiality value. Once lost or damaged, it will not only affect the normal operation of the hospital, but also reduce the hospital's medical service level. Therefore, hospitals attach great importance to database information security and need to take effective measures to safely manage and store database information.

[0003] Databases and other digital record storage can be protected by passwords, firewalls, and other security mechanisms. At present, hospitals have taken three main measures to address database information security issues: building a medical information system security firewall, applying anti-virus software, and applying a certificate authority (CA) authentication system.

[0004] These measures have ensured the security of database information to a certain extent. However, with the rapid development of information technology, network attacks have become more diverse and frequent, and traditional methods can no longer meet the new information security management needs. In actual applications, the correlation coefficient of adjacent data in encrypted information documents is high, and the database packet loss rate is high. Existing data security protection technology cannot effectively guarantee information security. Summary of the invention

[0005] In view of the technical defects in the prior art, the purpose of the embodiments of the present invention is to provide a hospital database data encryption storage method, device, system and storage medium to complete the safe storage of hospital database information based on the hash encryption algorithm.

[0006] To achieve the above objectives, in a first aspect, an embodiment of the present invention provides a method for encrypting and storing data in a hospital database, comprising:

[0007] Mapping the raw medical data in a time-discrete multidimensional space according to a preset strategy to obtain a mapping sequence;

[0008] Encrypt the mapping sequence based on the hash encryption method to obtain encrypted data;

[0009] Store encrypted data in the database.

[0010] Furthermore, the original medical data is mapped into a multi-dimensional space discrete in time according to a preset strategy, including:

[0011] Assuming that the original medical data is v, the original medical data is mapped into a multidimensional space that is discrete in time by discrete processing. The calculation formula is:

[0012] x n+1 =εx n (1-x n ) (1)

[0013] Where: x n+1 represents the original medical data v after Logistic mapping; ε represents a constant; x n Represents a mapping variable.

[0014] Furthermore, the value range of ε is [0,4].

[0015] Further, the mapping sequence is encrypted based on the hash encryption method to obtain encrypted data, including:

[0016] Assuming that the plaintext information carried by the mapping sequence is z, an initial key is set, and the initial key is assigned to the control factor as an iteration initial value, and the plaintext information z sequence is converted into a positive number sequence F;

[0017] Performing a number of rounds of XOR calculations on the positive number sequence F to generate a hash key stream;

[0018] Splitting the key stream to generate a hash encryption matrix;

[0019] Normalize the positive number sequence F;

[0020] Using the hash encryption matrix to perform synchronous scrambling diffusion on the normalized plaintext information z sequence elements, mapping the data at random positions in the plaintext information z to sequential positions;

[0021] The sequence elements of the plaintext information z after synchronous scrambling diffusion are normalized, and then the plaintext information z is diffused in two rounds of blocks using the hash encryption matrix to generate ciphertext and obtain the encrypted data.

[0022] In a second aspect, an embodiment of the present invention further provides a hospital database data encryption storage device, comprising:

[0023] A discrete module, used for mapping the raw medical data into a multi-dimensional space that is discrete in time according to a preset strategy to obtain a mapping sequence;

[0024] An encryption module, used for encrypting the mapping sequence based on a hash encryption method to obtain encrypted data;

[0025] The storage module is used to store the encrypted data in the database.

[0026] Furthermore, the discrete module is specifically used for:

[0027] Assuming that the original medical data is v, the original medical data is mapped into a multidimensional space that is discrete in time by discrete processing. The calculation formula is:

[0028] x n+1 =εx n (1-x n ) (1)

[0029] Where: x n+1 represents the original medical data v after Logistic mapping; ε represents a constant; x n Represents a mapping variable.

[0030] Furthermore, the value range of ε is [0,4].

[0031] Furthermore, the encryption module is specifically used for:

[0032] Assuming that the plaintext information carried by the mapping sequence is z, an initial key is set, and the initial key is assigned to the control factor as an iteration initial value, and the plaintext information z sequence is converted into a positive number sequence F;

[0033] Performing a number of rounds of XOR calculations on the positive number sequence F to generate a hash key stream;

[0034] Splitting the key stream to generate a hash encryption matrix;

[0035] Normalize the positive number sequence F;

[0036] Using the hash encryption matrix to perform synchronous scrambling diffusion on the normalized plaintext information z sequence elements, mapping the data at random positions in the plaintext information z to sequential positions;

[0037] The sequence elements of the plaintext information z after synchronous scrambling diffusion are normalized, and then the plaintext information z is diffused in two rounds of blocks using the hash encryption matrix to generate ciphertext and obtain the encrypted data.

[0038] In the third aspect, an embodiment of the present invention also provides a hospital database data encryption storage system, characterized in that it includes a processor, an input device, an output device and a memory, and the processor, input device, output device and memory are interconnected, wherein the memory is used to store a computer program, and the computer program includes program instructions, and the processor is configured to call the program instructions to execute the method described in the first aspect.

[0039] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program, the computer program includes program instructions, and when the program instructions are executed by a processor, the processor executes the method described in the first aspect.

[0040] By implementing the method provided in the embodiment of the present invention, the shortcomings and defects of the traditional method are addressed, and the hash encryption algorithm is applied to the safe storage of hospital database information, which effectively reduces the packet loss rate of the hospital database and ensures information security. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the specific implementation of the present invention or the technical solution in the prior art, the drawings required for use in the specific implementation or the description of the prior art are briefly introduced below.

[0042] Figure 1 It is a schematic diagram of the process of the hospital database data encryption storage method provided by an embodiment of the present invention;

[0043] Figure 2 It is a structural diagram of a hospital database data encryption storage device provided by an embodiment of the present invention.

[0044] Figure 3 It is a structural diagram of a hospital database data encryption storage system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0045] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0046] It should be understood that when used in this specification and the appended claims, the terms "include" and "comprises" indicate the presence of described features, integers, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or combinations thereof.

[0047] It should also be understood that the terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include plural forms.

[0048] It should be further understood that the term "and / or" used in the present specification and the appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0049] As used in this specification and the appended claims, the term "if" may be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if [described condition or event] is detected" may be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.

[0050] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in this application should have the common meanings understood by those skilled in the art to which the invention belongs.

[0051] like Figure 1 As shown, an embodiment of the present invention provides a flowchart of a method for encrypting and storing data in a hospital database. Specifically, the method may include the following steps:

[0052] Step S110: Map the raw medical data into a multi-dimensional space that is discrete in time according to a preset strategy to obtain a mapping sequence.

[0053] In this embodiment, the original medical data includes image information, text information, video information, etc., and the hospital database information is digitized using Logistic mapping technology.

[0054] Specifically, assuming that the original medical data is v, the original medical data is mapped into a multidimensional space that is discrete in time by discrete processing. The calculation formula is:

[0055] x n+1 =εx n (1-x n ) (1)

[0056] Where: x n+1 represents the original medical data v after Logistic mapping; ε represents a constant, and the value range of ε is [0,4]; x n Represents the mapping variable. Formula (1) is used to repeatedly fold and stretch the original medical data in multidimensional space, making the data information in a chaotic state.

[0057] Step S120: Encrypt the mapping sequence based on the hash encryption method to obtain encrypted data.

[0058] In order to improve the security of information, the mapping sequence is encrypted using a hash encryption algorithm based on the mapping process, including:

[0059] Step S121: Assume that the plaintext information carried by the mapping sequence is z, and the information size is n×m, set an initial key, the initial key consists of two bits, and assume that the key is G(h0,k0), set the initial key, assign the initial key to the control factor as the iteration initial value, and convert the plaintext information z sequence into a positive number sequence F,

[0060] F = floor[mod(z)] (2)

[0061] Where: F represents the converted plaintext information sequence; floor represents the rounded down plaintext sequence pair.

[0062] Step S122: performing a number of rounds of XOR calculations on the positive number sequence F to generate a hash key stream.

[0063] The XOR calculation formula is:

[0064]

[0065] Where: e represents the plaintext information after XOR; ⊕ represents the bitwise XOR operation; sum(F) represents the sum of the sequence elements of the plaintext information z. After 20 to 100 rounds of XOR, a hash key stream is generated.

[0066] Step S123: split the key stream to generate a hash encryption matrix.

[0067] In this embodiment, the hash key stream is divided into groups of 16 bits to construct a 4×4 initial hash encryption matrix.

[0068] Step S124: normalize the positive number sequence F.

[0069] The calculation formula is:

[0070] g=mean(F) / 256 (4)

[0071] Where: g represents the normalized plaintext information sequence element; mean(F) represents the mean of the sequence elements of the positive sequence F.

[0072] Step S125: Use the hash encryption matrix to perform synchronous scrambling and diffusion on the normalized sequence elements of the plaintext information z, and map the data at random positions in the plaintext information z to sequential positions.

[0073] The hash encryption matrix is ​​used to synchronously scramble and diffuse the plaintext information z sequence, mapping the data at random positions in the plaintext information z to sequential positions. The calculation formula is:

[0074]

[0075] Where: R(x,y) represents the plaintext information after synchronous scrambling and diffusion; FDD represents the hash encryption matrix; x* and y* represent the horizontal and vertical coordinates of the plaintext information data in the spatial sequence respectively; g* represents the integer generated by the sequence conversion.

[0076] Step S126: normalize the sequence elements of the plaintext information z after synchronous scrambling and diffusion, and then use the hash encryption matrix to diffuse the plaintext information z in two rounds of blocks to generate ciphertext and obtain the encrypted data.

[0077] Then use formula (4) to normalize the plaintext information z sequence elements, and then use the hash encryption matrix to diffuse the plaintext information in two rounds. The calculation formula is:

[0078] D(x,y)=FDDR(x,y)P (6)

[0079] Where: D(x,y) represents the ciphertext information after block diffusion; P represents the ciphertext matrix. Through two rounds of block diffusion, the length of the information sequence is diffused to twice the original length, completing the information encryption based on the hash encryption algorithm and obtaining the encrypted data.

[0080] Step S130: Storing the encrypted data in a database.

[0081] When users download or forward database information, they need to decrypt it to obtain the plaintext information. Decryption is the inverse operation of encryption, and the decryption process is as follows;

[0082] First, the initial hash matrix is ​​generated using the initial key and the sum of the ciphertext sequence elements. The ciphertext information sequence elements are substituted into equations (5) and (6), and the encrypted information is reversed to convert the information sequence into its original state.

[0083] Second, the information elements are restored to their original positions and the diffusion operation is removed.

[0084] Finally, the plaintext information after removing the diffusion operation is substituted into formula (2), and the filled elements in the information are removed and reshaped according to the inverse operation of the preprocessing method to obtain the original plaintext information z.

[0085] In summary, the method provided in the embodiment of the present invention is implemented to address the shortcomings and defects of traditional methods, apply the hash encryption algorithm to the safe storage of hospital database information, effectively reduce the packet loss rate of the hospital database, and ensure information security.

[0086] The correlation coefficient of adjacent data in the information document encrypted and managed by this method is low, the information scrambling effect is good, the packet loss rate of the hospital database is relatively low, and the security is high.

[0087] Based on the same inventive concept, the embodiment of the present invention also provides a hospital database data encryption storage device. Figure 2 As shown, the device may include:

[0088] The discrete module 201 is used to map the raw medical data into a multi-dimensional space that is discrete in time according to a preset strategy to obtain a mapping sequence;

[0089] The encryption module 202 is used to encrypt the mapping sequence based on the hash encryption method to obtain encrypted data;

[0090] The storage module 203 is used to store the encrypted data in a database.

[0091] Furthermore, the discrete module 201 is specifically used for:

[0092] Assuming that the original medical data is v, the original medical data is mapped into a multidimensional space that is discrete in time by discrete processing. The calculation formula is:

[0093] x n+1 =εx n (1-x n ) (1)

[0094] Where: x n+1 represents the original medical data v after Logistic mapping; ε represents a constant; x n Represents a mapping variable.

[0095] Furthermore, the value range of ε is [0,4].

[0096] Furthermore, the encryption module 202 is specifically used for:

[0097] Assuming that the plaintext information carried by the mapping sequence is z, an initial key is set, and the initial key is assigned to the control factor as an iteration initial value, and the plaintext information z sequence is converted into a positive number sequence F;

[0098] Performing a number of rounds of XOR calculations on the positive number sequence F to generate a hash key stream;

[0099] Splitting the key stream to generate a hash encryption matrix;

[0100] Normalize the positive number sequence F;

[0101] Using the hash encryption matrix to perform synchronous scrambling diffusion on the normalized plaintext information z sequence elements, mapping the data at random positions in the plaintext information z to sequential positions;

[0102] The sequence elements of the plaintext information z after synchronous scrambling diffusion are normalized, and then the plaintext information z is diffused in two rounds of blocks using the hash encryption matrix to generate ciphertext and obtain the encrypted data.

[0103] Based on the same inventive concept, an embodiment of the present invention provides a hospital database data encryption storage system. Figure 3 As shown, the system may include: one or more processors 101, one or more input devices 102, one or more output devices 103 and a memory 104, wherein the processors 101, input devices 102, output devices 103 and memory 104 are interconnected via a bus 105. The memory 104 is used to store a computer program, wherein the computer program includes program instructions, and the processor 101 is configured to call the program instructions to execute the method of the embodiment of the hospital database data encryption storage method.

[0104] It should be understood that in the embodiment of the present invention, the processor 101 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0105] The input device 102 may include a keyboard, etc., and the output device 103 may include a display (LCD, etc.), a speaker, etc.

[0106] The memory 104 may include a read-only memory and a random access memory, and provides instructions and data to the processor 101. A portion of the memory 104 may also include a non-volatile random access memory. For example, the memory 104 may also store information on the device type.

[0107] In a specific implementation, the processor 101, input device 102, and output device 103 described in the embodiment of the present invention can execute the implementation method described in the embodiment of the hospital database data encryption storage method provided in the embodiment of the present invention, which will not be repeated here.

[0108] It should be noted that, regarding the specific workflow of the hospital database data encryption storage system, please refer to the aforementioned method implementation example part, which will not be repeated here.

[0109] Furthermore, an embodiment of the present invention also provides a readable storage medium storing a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the above-mentioned hospital database data encryption storage method is implemented.

[0110] The computer-readable storage medium may be an internal storage unit of the background server described in the aforementioned embodiment, such as a hard disk or memory of the system. The computer-readable storage medium may also be an external storage device of the system, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (SecureDigital, SD) card, a flash card (Flash Card), etc. equipped on the system. Furthermore, the computer-readable storage medium may also include both an internal storage unit of the system and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the system. The computer-readable storage medium may also be used to temporarily store data that has been output or is to be output.

[0111] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0112] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0113] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0114] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present invention, and these modifications or replacements should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.

Claims

1. A method for encrypting and storing data in a hospital database, characterized in that: include: Mapping the raw medical data in a time-discrete multidimensional space according to a preset strategy to obtain a mapping sequence; Encrypt the mapping sequence based on the hash encryption method to obtain encrypted data; Store encrypted data in the database.

2. A hospital database data encryption storage method as claimed in claim 1, characterized in that: The raw medical data is mapped into a multidimensional space that is discrete in time according to a preset strategy, including: Assuming that the original medical data is v, the original medical data is mapped into a multidimensional space that is discrete in time by discrete processing. The calculation formula is: x n+1 =εx n (1-x n ) (1) Where: x n+1 represents the original medical data v after Logistic mapping; ε represents a constant; x n Represents a mapping variable.

3. A hospital database data encryption storage method as claimed in claim 2, characterized in that: The value range of ε is [0,4].

4. A hospital database data encryption storage method as claimed in claim 1, characterized in that: The method of encrypting the mapping sequence based on the hash encryption method to obtain encrypted data includes: Assuming that the plaintext information carried by the mapping sequence is z, an initial key is set, and the initial key is assigned to the control factor as an iteration initial value, and the plaintext information z sequence is converted into a positive number sequence F; Performing a number of rounds of XOR calculations on the positive number sequence F to generate a hash key stream; Splitting the key stream to generate a hash encryption matrix; Normalize the positive number sequence F; Using the hash encryption matrix to perform synchronous scrambling diffusion on the normalized plaintext information z sequence elements, mapping the data at random positions in the plaintext information z to sequential positions; The sequence elements of the plaintext information z after synchronous scrambling diffusion are normalized, and then the plaintext information z is diffused in two rounds of blocks using the hash encryption matrix to generate ciphertext and obtain the encrypted data.

5. A hospital database data encryption storage device, characterized in that: include: A discrete module, used for mapping the raw medical data into a multi-dimensional space that is discrete in time according to a preset strategy to obtain a mapping sequence; An encryption module, used for encrypting the mapping sequence based on a hash encryption method to obtain encrypted data; The storage module is used to store the encrypted data in the database.

6. A hospital database data encryption storage device as claimed in claim 5, characterized in that: The discrete modules are specifically used for: Assuming that the original medical data is v, the original medical data is mapped into a multidimensional space that is discrete in time by discrete processing. The calculation formula is: x n+1 =εx n (1-x n ) (1) Where: x n+1 represents the original medical data v after Logistic mapping; ε represents a constant; x n Represents a mapping variable.

7. A hospital database data encryption storage device as claimed in claim 6, characterized in that: The value range of ε is [0,4].

8. A hospital database data encryption storage device as claimed in claim 5, characterized in that: The encryption module is specifically used for: Assuming that the plaintext information carried by the mapping sequence is z, an initial key is set, and the initial key is assigned to the control factor as an iteration initial value, and the plaintext information z sequence is converted into a positive number sequence F; Performing a number of rounds of XOR calculations on the positive number sequence F to generate a hash key stream; Splitting the key stream to generate a hash encryption matrix; Normalize the positive number sequence F; Using the hash encryption matrix to perform synchronous scrambling diffusion on the normalized plaintext information z sequence elements, mapping the data at random positions in the plaintext information z to sequential positions; The sequence elements of the plaintext information z after synchronous scrambling diffusion are normalized, and then the plaintext information z is diffused in two rounds of blocks using the hash encryption matrix to generate ciphertext and obtain the encrypted data.

9. A hospital database data encryption storage system, characterized in that: The method comprises a processor, an input device, an output device and a memory, wherein the processor, the input device, the output device and the memory are interconnected, wherein the memory is used to store a computer program, the computer program comprises program instructions, and the processor is configured to call the program instructions to execute the method according to any one of claims 1 to 4.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor is caused to perform the method according to any one of claims 1 to 4.

Citation Information

Cited By

  • Data security storage system based on network security

    CN122137626A