Medical information security storage method and system based on block chain technology
By adopting blockchain technology, Merkel tree algorithm and elliptic curve encryption algorithm in the medical data storage system, the problems of low security and low data sharing efficiency of existing medical data storage systems are solved, and the effects of highly encrypted, immutable and efficient retrieval are achieved, and trust and collaboration among multiple institutions are promoted.
Patent Information
- Application Number
- CN202411987223.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-23
AI Technical Summary
Existing medical data storage systems are low in security, are vulnerable to the risk of hacker attacks and internal personnel abuse, and it is difficult to establish a mutual trust mechanism between multiple independently operated medical institutions, resulting in inefficient data sharing and lack of trust.
A multi-level distributed ledger network architecture based on blockchain technology is adopted, combining role-based access control model and zero-knowledge proof protocol to perform fine operation permission allocation, and the Merkel tree algorithm and Byzantine fault tolerance consensus technology are used to ensure data immutability and full traceability. At the same time, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient, and a content-based indexing technology and a Bloom filter are introduced to optimize the retrieval performance.
显著增强了系统的安全性和隐私保护,确保了医疗信息的高度加密和不可篡改性,提高了数据检索的效率和服务响应能力,促进了多机构间的信任和高效协作,构建了健康的数据共享生态系统。
Smart Images

Figure CN120030588A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of secure storage technology, and in particular, to a method and system for secure storage of medical information based on blockchain technology. Background Art
[0002] In the healthcare industry, medical institutions need to securely store and share a large amount of sensitive patient data. This data includes not only routine information such as medical records and diagnostic results, but may also involve complex data types such as genomics and imaging data. With the development of medical informatization, the demand for data exchange between medical institutions is increasing, requiring a technical solution that can ensure data privacy and achieve efficient collaboration. In addition, strict legal and regulatory requirements such as the Health Insurance Portability and Accountability Act or the General Data Protection Regulation need to be met to protect patients' privacy rights.
[0003] Currently, many medical institutions use traditional centralized databases to manage medical data. These systems usually rely on a single server or data center for data storage and access control. In order to achieve data sharing among multiple institutions, some institutions use encryption technology and access control lists to limit data access rights. However, this centralized architecture has the risk of single point failure and it is difficult to establish a mutual trust mechanism between multiple independently operated medical institutions.
[0004] The main problem with existing centralized solutions is that they are less secure and vulnerable to hacker attacks and insider abuse. In addition, due to the lack of a unified authentication and permission management system, data sharing between different institutions is often inefficient and error-prone. Especially when collaborating across institutions, the consistency and integrity of data cannot be effectively guaranteed, resulting in a lack of trust and affecting the quality and efficiency of medical services. Summary of the invention
[0005] The embodiments of the present application provide a method and system for secure storage of medical information based on blockchain technology, so as to solve the problem that the prior art is susceptible to the risk of hacker attacks and abuse by insiders.
[0006] In a first aspect, the present application embodiment provides a method for securely storing medical information based on blockchain technology, including:
[0007] Construct a multi-level distributed ledger network architecture, use the role-based access control model and the zero-knowledge proof protocol to perform fine-grained operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and combine the time lock mechanism to limit data access rights within a preset time period to obtain a data interaction environment;
[0008] According to the data interaction environment, the Merkle tree algorithm is used to integrate the operation details, timestamps and operator identities, and added to the blockchain after verification by the Byzantine fault-tolerant consensus technology to generate a log summary;
[0009] According to the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient, the patient's medical record is encrypted to obtain an encrypted medical data file, content-based indexing technology is introduced to create an inverted index and a Bloom filter, the encrypted medical data file is optimized for retrieval, and an encrypted medical data storage system is generated;
[0010] When the encrypted medical data storage system exchanges medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated to transfer medical data between different blockchains, and a credit scoring system is established through qualification certification and reputation assessment of cooperative medical institutions to generate a data sharing ecosystem.
[0011] Optionally, according to the data interaction environment, the Merkle tree algorithm is used to integrate the operation details, timestamps and operator identities, and added to the blockchain after verification by the Byzantine fault-tolerant consensus algorithm, to ensure that all medical information change histories cannot be tampered with and are fully traceable, and to generate a log summary, including:
[0012] Using the data interaction environment, the operation details, timestamp and operator identity of each medical information change event are collected and processed to obtain a change event record;
[0013] Based on the change event record, a Merkle tree algorithm is applied to construct a binary tree structure, and hash operations are performed on each change event record and summarized layer by layer to obtain a root hash value, wherein the unique root hash value is used as a log summary;
[0014] According to the log summary, verification processing is performed between multiple nodes in the distributed ledger network through Byzantine fault-tolerant consensus technology to generate a verified log summary.
[0015] Optionally, the data interaction environment is used to collect and process the operation details, timestamp and operator identity of each medical information change event to obtain a change event record, including:
[0016] Using the data interaction environment, a listener is started to monitor and process all operations involving changes in medical information in real time to obtain an operation trigger signal;
[0017] According to the operation trigger signal, the specific operation content of each change event is captured to obtain the operation details;
[0018] Based on the operation trigger signal, record the exact time point of each change event and generate a timestamp;
[0019] According to the operation trigger signal and the operation details, verify the identity of the operator who performs the change operation, and compare it with the pre-registered identity information database to confirm the legitimacy of the operator, and obtain the verified operator identity;
[0020] A change event record is constructed using the operation details, the timestamp and the verified operator identity.
[0021] Optionally, performing verification processing among multiple nodes in a distributed ledger network through Byzantine fault-tolerant consensus technology according to the log summary to generate a verified log summary includes:
[0022] Using the log summary, the proposing node initiates a proposal process for the medical information change event, generates and broadcasts a proposal message;
[0023] According to the proposal message, the receiving node checks the validity of the proposal, and generates a pre-prepared message and broadcasts it to other nodes if the proposal is valid;
[0024] When a node receives a preset number of valid pre-prepare messages, it confirms the proposal, generates a prepare message and broadcasts it to other nodes;
[0025] According to the prepare message, when a node receives prepare messages from more than a preset threshold number of nodes, it enters the commit state and submits the proposal, generates a commit message and broadcasts it to other nodes;
[0026] Based on the submission message, when a node receives submission messages from more than the preset threshold number of nodes, it confirms that the proposal has been finalized, updates the local copy and adds the log summary to the blockchain to obtain a verified log summary.
[0027] Optionally, according to the log summary, using an elliptic curve encryption algorithm to generate a unique public-private key pair for each patient, encrypting the patient's medical record to obtain an encrypted medical data file, introducing a content-based indexing technology to create an inverted index and a Bloom filter, optimizing the retrieval process on the encrypted medical data file, and generating an encrypted medical data storage system, including:
[0028] According to the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient to obtain a public-private key pair exclusive to the patient;
[0029] Using the patient's exclusive public-private key pair, the medical record is encrypted using the patient's public key to obtain an encrypted medical data file;
[0030] Based on the encrypted medical data file, a content-based indexing technology is introduced to create an inverted index, and the keyword or phrase position in the file is indexed to generate an inverted index structure;
[0031] According to the encrypted medical data file, a Bloom filter is applied to build a fast checking mechanism to reduce unnecessary disk read operations and generate a Bloom filter configuration;
[0032] The inverted index structure and the Bloom filter configuration are used to optimize the retrieval process of the encrypted medical data file to generate an encrypted medical data storage system.
[0033] Optionally, based on the encrypted medical data file, a content-based indexing technology is introduced to create an inverted index, index the keyword or phrase position in the file, and generate an inverted index structure, including:
[0034] Using the encrypted medical data file, and using the patient's public key to perform secure parsing processing on the text information contained in the encrypted medical data file to obtain parsed text information;
[0035] According to the parsed text information, natural language processing technology is applied to perform word segmentation, stop word removal and lemma restoration on the parsed text information to extract keywords and phrases to obtain a keyword phrase set;
[0036] Based on the keyword phrase set, locate the specific position of each keyword phrase in the file, record the position information of its occurrence, and generate a position information table;
[0037] Using the position information table, create an inverted index entry for each keyword phrase to generate a preliminary inverted index entry set, wherein each entry contains the keyword or phrase and the position information where it appears in the file;
[0038] According to the preliminary inverted index entry set, the index entries are optimized to generate an inverted index structure.
[0039] Optionally, when the encrypted medical data storage system exchanges medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated to transfer medical data between different blockchains, and a credit scoring system is established through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem, including:
[0040] When the encrypted medical data storage system needs to exchange medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated;
[0041] Using the cross-chain bridging mechanism, a unique hash value is created for the medical data to be transmitted at the sending end, and used as a hash locking condition to obtain a hash locking setting;
[0042] According to the hash lock setting, a valid time window is set as a time lock condition to ensure that the data is transmitted within the specified time and generate a time lock configuration;
[0043] Based on the hash lock setting and the time lock configuration, the data transfer process in the cross-chain bridging mechanism is started to transfer the encrypted medical data from the source blockchain system to the target blockchain system to obtain a successfully transferred data record;
[0044] Using the successfully transmitted data records, conduct qualification certification and credit assessment on the cooperative medical institutions participating in the data exchange, establish a credit scoring system, and obtain certification and assessment results;
[0045] Based on the certification and evaluation results, a data sharing ecosystem is generated.
[0046] In a second aspect, the embodiment of the present application provides a medical information security storage system based on blockchain technology, including:
[0047] A construction module is used to construct a multi-level distributed ledger network architecture, and use a role-based access control model and a zero-knowledge proof protocol to perform fine-grained operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and combine a time lock mechanism to limit data access rights within a preset time period to obtain a data interaction environment;
[0048] Add a module for integrating operation details, timestamps and operator identities using a Merkle tree algorithm according to the secure and compliant data interaction environment, and adding them to the blockchain after verification by the Byzantine Fault Tolerant consensus technology, to ensure that all medical information change histories cannot be tampered with and are fully traceable, and to generate a log summary;
[0049] A retrieval module is used to generate a unique public-private key pair for each patient using an elliptic curve encryption algorithm according to the log summary, encrypt the patient's medical record to obtain an encrypted medical data file, introduce content-based indexing technology to create an inverted index and a Bloom filter, optimize the retrieval process of the encrypted medical data file, and generate an encrypted medical data storage system;
[0050] The activation module is used to activate the cross-chain bridging mechanism based on hash locking and time locking when the encrypted medical data storage system exchanges medical information with other blockchain systems, accurately transmit and process medical data between different blockchains, and establish a credit scoring system through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem.
[0051] In a third aspect, an embodiment of the present application provides a computing device, comprising a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a method for secure storage of medical information based on blockchain technology as described in the first aspect.
[0052] In a fourth aspect, an embodiment of the present application provides a computer storage medium storing a computer program. When the computer program is executed by a computer, it implements a method for secure storage of medical information based on blockchain technology as described in the first aspect.
[0053] In the embodiment of the present application, a multi-level distributed ledger network architecture is constructed, and a role-based access control model and a zero-knowledge proof protocol are used to perform fine operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and a time lock mechanism is combined to limit data access rights within a preset time period to obtain a data interaction environment; according to the data interaction environment, a Merkle tree algorithm is used to integrate operation details, timestamps, and operator identities, and after verification by the Byzantine fault-tolerant consensus technology, they are added to the blockchain to generate a log summary; according to the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient, and the patient's medical records are encrypted to obtain an encrypted medical data file, and a content-based indexing technology is introduced to create an inverted index and a Bloom filter, and the encrypted medical data file is optimized for retrieval processing to generate an encrypted medical data storage system; when the encrypted medical data storage system exchanges medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated to transfer medical data between different blockchains, and a credit scoring system is established through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem.
[0054] The technical solution of this application has the following beneficial effects:
[0055] By building a multi-level distributed ledger network architecture and combining the role-based access control model (RBAC) and zero-knowledge proof protocol, it ensures that different types of nodes have fine-grained operation permission allocation to prevent unauthorized access. At the same time, the time lock mechanism further limits the data access rights within the preset time period, greatly enhancing the security and privacy protection of the system; the Merkle tree algorithm is used to integrate operation details, timestamps and operator identities, and is added to the blockchain after verification through the Byzantine fault-tolerant consensus technology to generate an unalterable log summary. This not only ensures the security and full traceability of all medical information change histories, but also provides a solid foundation for subsequent data audits; the elliptic curve cryptography algorithm (ECC) is used to generate a unique public-private key pair for each patient to ensure high encryption of medical records and protect personal privacy. The introduction of content-based indexing technology and the creation of inverted indexes and Bloom filters optimizes the retrieval efficiency of encrypted medical data files, making it possible to quickly locate and access required information even in large-scale data sets, improving the system's response speed and service quality; the cross-chain bridging mechanism based on hash locking and time locking is activated to achieve the secure transmission of medical data between different blockchain systems and maintain data consistency and integrity. By establishing a credit scoring system through qualification certification and credibility assessment of cooperative medical institutions, we have promoted trust and efficient collaboration among multiple institutions, built a healthy data sharing ecosystem, and facilitated the effective use of medical resources and the improvement of patient service experience.
[0056] Furthermore, by using the Merkle tree algorithm to integrate operation details, timestamps, and operator identities, and adding them to the blockchain after verification with the Byzantine fault-tolerant consensus technology, this method ensures that all medical information change histories are immutable and traceable throughout the process. Specifically, a secure and compliant data interaction environment is used to collect relevant data for each medical information change event, generating a detailed record of change events; based on these records, a Merkle tree structure is constructed and a unique root hash value is calculated as a log summary, which enhances the integrity and consistency of the data; finally, the Byzantine fault-tolerant consensus technology is used to perform verification processing between multiple nodes, generating a verified log summary, and effectively preventing data tampering and inconsistency. This series of measures not only improves the transparency and credibility of the system, but also significantly improves the security and management efficiency of medical data, solving the defects of data being easily tampered with and difficult to track in existing solutions.
[0057] Furthermore, by using the elliptic curve encryption algorithm to generate a unique public-private key pair for each patient, and combining content-based indexing technology and Bloom filters, this method not only achieves high encryption protection of medical records, but also significantly improves the retrieval efficiency of encrypted medical data files. Specifically, a unique public-private key pair is generated for each patient based on the log summary to ensure the security and privacy of medical records; the medical records are encrypted using the patient's public key to generate encrypted medical data files to prevent unauthorized access and leakage. In addition, the introduction of content-based indexing technology to create an inverted index structure can quickly locate the location of keywords or phrases in the file, and the Bloom filter is used to build a fast check mechanism to reduce unnecessary disk read operations and further optimize the retrieval performance. The encrypted medical data storage system finally formed greatly improves the query speed and service response capabilities while ensuring data security, effectively solving the problems of low efficiency and insufficient security of encrypted data retrieval in existing solutions.
[0058] These and other aspects of the present application will become more clearly understood in the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0060] Figure 1 A flowchart of a method for secure storage of medical information based on blockchain technology provided in an embodiment of the present application;
[0061] Figure 2 A schematic diagram of the structure of a medical information security storage system based on blockchain technology provided in an embodiment of the present application;
[0062] Figure 3 A schematic diagram of the structure of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0063] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0064] In some of the processes described in the specification and claims of this application and the above-mentioned figures, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., do not represent the order of precedence, and do not limit the "first" and "second" to be different types.
[0065] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.
[0066] Figure 1 A flowchart of a method for securely storing medical information based on blockchain technology is provided for an embodiment of the present application. Figure 1 As shown, the method includes:
[0067] 101. Construct a multi-level distributed ledger network architecture, use a role-based access control model and a zero-knowledge proof protocol to perform fine-grained operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and combine a time lock mechanism to limit data access rights within a preset time period to obtain a data interaction environment;
[0068] In this step, building a multi-level distributed ledger network architecture involves designing and implementing a blockchain network with multiple levels, each of which is responsible for different functions. Using the role-based access control model (RBAC) and the zero-knowledge proof protocol (ZKP), different types of nodes are finely assigned operation permissions to ensure that only authorized users can access the preset data resources within a specific time. Combined with the time lock mechanism to further restrict data access rights, the system can effectively manage data access within a specified time period, thereby creating a safe and reliable data interaction environment.
[0069] In the embodiment of this application, a multi-level distributed ledger network architecture is first built, the roles of each node and their corresponding operation permissions are defined through the RBAC model, and ZKP is used to ensure that sensitive information is not leaked. Then, a time lock mechanism is introduced to set an effective period for each type of data access to prevent the security risks caused by long-term pending status. Finally, a clear structure, clear permissions and
[0070] Suppose a large medical institution wants to establish an efficient and secure data sharing platform within its internal and external partners. The institution first deploys a multi-layer distributed ledger network, including the core layer, business layer, and service layer. The core layer is responsible for maintaining the stable operation of the entire system; the business layer is divided into multiple subnets according to the functions of each department, such as diagnosis and treatment, pharmacy, etc.; the service layer is used to support specific medical service applications. The role permissions of employees in different departments are set through the RBAC model, and ZKP technology is used to protect patient privacy. At the same time, time locks are embedded in all data access requests to ensure that relevant data can only be accessed within the specified time range, thus building an open and controlled data interaction environment.
[0071] 102. According to the data interaction environment, the Merkle tree algorithm is used to integrate the operation details, timestamps and operator identities, and after verification by the Byzantine fault-tolerant consensus technology, they are added to the blockchain to generate a log summary;
[0072] In this step, the Merkle tree algorithm is used to integrate the operation details, timestamps, and operator identities of each medical information change event, which are used to generate an unalterable log summary. The Merkle tree is a binary tree structure whose leaf nodes store the hash values of the actual data, while non-leaf nodes store the combination of the hash values of their child nodes. In this way, the authenticity of any single record can be efficiently verified while ensuring the consistency and integrity of the entire batch of records.
[0073] In the embodiment of the present application, whenever a medical information change occurs, the system will collect the operation details, timestamp and operator identity of the change to form a change event record. Then, the Merkle tree algorithm is used to organize multiple change event records into a binary tree, and the hash value is calculated layer by layer until the root node, and a unique root hash value is obtained as a log summary. Finally, the validity of all change events in the batch is verified through the Byzantine Fault Tolerant Consensus Technology (PBFT), and it is added to the blockchain to ensure that all change histories cannot be tampered with and are traceable throughout the process.
[0074] Suppose a hospital generates a large number of medical information change events every day, such as medical record updates or diagnosis result entries. In order to ensure the security and traceability of these change records, the hospital uses the Merkle tree algorithm to integrate all daily change events. Specifically, whenever a new change event occurs, the system automatically records the detailed operation content, occurrence time, and operator identity information. Subsequently, this information is constructed into a Merkle tree, in which each leaf node represents a change event record, and the root node summarizes the hash values of all change events of the day, forming a unique and tamper-proof log summary. Through the PBFT consensus algorithm, the hospital can jointly verify the authenticity and consistency of these change events with other participating nodes and securely add them to the blockchain.
[0075] 103. Based on the log summary, use the elliptic curve encryption algorithm to generate a unique public-private key pair for each patient, encrypt the patient's medical record to obtain an encrypted medical data file, introduce content-based indexing technology to create an inverted index and a Bloom filter, optimize the retrieval process of the encrypted medical data file, and generate an encrypted medical data storage system;
[0076] In this step, based on the previously generated log summary, the elliptic curve cryptography (ECC) algorithm is used to generate a unique public-private key pair for each patient to ensure that the patient's medical records are highly encrypted and protected. The public-private key pair is used to encrypt and decrypt the patient's medical data files, so that only those who hold the corresponding private key can access the decrypted original data. In addition, content-based indexing technology and Bloom filters are introduced to create inverted indexes and fast check mechanisms, respectively, to optimize retrieval performance and improve query efficiency.
[0077] In an embodiment of the present application, the system generates an exclusive public-private key pair for each patient based on the log summary to ensure the security and privacy of medical records. All medical data files of the patient are encrypted using their public key to generate encrypted medical data files. In order to facilitate subsequent retrieval operations, the system introduces content-based indexing technology and creates an inverted index structure, so that specific keywords or phrases can be quickly located even in large amounts of data. At the same time, Bloom filters are applied to reduce unnecessary disk read operations, further improving retrieval efficiency. Ultimately, these measures work together to generate a secure and efficient encrypted medical data storage system.
[0078] Suppose a patient named Zhang San received multiple diagnosis and treatment services in a hospital, generating a wealth of medical records. In order to protect Zhang San's privacy, the hospital used the ECC algorithm to generate a unique pair of public and private keys for him. Whenever Zhang San's medical data needs to be updated or queried, the hospital will use his public key to encrypt the newly generated data to ensure that only Zhang San himself or an authorized doctor can decrypt and view the specific content through the private key. At the same time, the hospital also used inverted index technology to establish a detailed keyword index to facilitate quick search of Zhang San's medical records. In addition, through the application of Bloom filters, the hospital reduced redundant data reading operations and improved the overall retrieval speed. In summary, this solution not only ensures the security of Zhang San's medical data, but also greatly facilitates the workflow of medical staff.
[0079] 104. When the encrypted medical data storage system exchanges medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated to transfer medical data between different blockchains, and a credit scoring system is established through qualification certification and reputation assessment of cooperative medical institutions to generate a data sharing ecosystem.
[0080] In this step, when the encrypted medical data storage system needs to exchange medical information with other blockchain systems, the cross-chain bridging mechanism based on hash lock and time lock is activated to ensure that medical data between different blockchains can be accurately transmitted. The qualification certification and reputation evaluation of cooperative medical institutions establish a credit scoring system, which promotes efficient collaboration among multiple institutions and builds a healthy data sharing ecosystem. Hash lock ensures the security of data transmission, while time lock limits the validity period of transmission to prevent long-term pending status.
[0081] In the embodiment of the present application, when it is necessary to exchange medical information between different blockchain systems, the system will activate the cross-chain bridging mechanism, which ensures the security and timeliness of data transmission through hash locking and time locking. First, the sender creates a unique hash value for the data to be transmitted and uses it as a hash locking condition; the receiver can unlock and accept the data only after verifying the same hash value. Secondly, a valid time window is set as a time locking condition to ensure that the data is transmitted within the specified time. In addition, through strict qualification certification and reputation assessment of cooperative medical institutions, the system has established a credit scoring system, which promotes trust and efficient collaboration among multiple parties, and ultimately forms a safe and reliable data sharing ecosystem.
[0082] Suppose two hospitals, A and B, want to achieve secure sharing of patient medical information through blockchain technology. When hospital A needs to send the latest diagnosis and treatment report of a patient to hospital B, both parties activate the cross-chain bridging mechanism based on hash locking and time locking. Hospital A generates a unique hash value for the report and sets a 72-hour time window as the validity period for delivery. During this period, after receiving the report, hospital B confirms the integrity and authenticity of the data by verifying the same hash value. In order to ensure the reliability of the cooperation, the two hospitals also conducted qualification certification and reputation assessment and established a credit scoring system. This series of measures not only ensures the security and timeliness of data transmission, but also enhances the trust between the two parties and promotes wider cooperation and resource sharing.
[0083] In summary, steps 101 to 104 cover the entire process from building a secure data interaction environment, ensuring that change history cannot be tampered with, protecting patient privacy to promoting efficient collaboration among multiple institutions. The aim is to provide a comprehensive and secure medical information security storage solution to meet the medical industry's needs for data security, privacy protection and efficient collaboration.
[0084] In order to solve the problem of integrity and traceability of the medical information change history, in some embodiments, the Merkle tree algorithm is used to integrate the operation details, timestamps and operator identities according to the data interaction environment in step 102, and added to the blockchain after verification by the Byzantine fault-tolerant consensus algorithm, to ensure that all medical information change histories cannot be tampered with and are fully traceable, and generate a log summary, including:
[0085] Utilizing the data interaction environment, the operation details, timestamp and operator identity of each medical information change event are collected and processed to obtain a change event record; based on the change event record, a Merkle tree algorithm is applied to construct a binary tree structure, and hash operations are performed on each change event record and summarized layer by layer to obtain a root hash value, wherein the unique root hash value is used as a log summary; based on the log summary, verification processing is performed between multiple nodes in a distributed ledger network through Byzantine fault-tolerant consensus technology to generate a verified log summary.
[0086] In this embodiment, the data interaction environment is used to collect and process the operation details of each medical information change event (such as which fields are modified), timestamp (recording the exact time when the change occurred) and operator identity (confirming the person who performed the change) to obtain a change event record; based on the change event record, a Merkle tree algorithm is applied to construct a binary tree structure, and hash operations are performed on each change event record and summarized upward layer by layer to ultimately obtain a root hash value, that is, a unique root hash value as a log summary; based on the log summary, verification processing is performed between multiple nodes in the distributed ledger network through Byzantine fault-tolerant consensus technology to generate a verified log summary.
[0087] In an embodiment of the present application, first, the system captures the relevant data of each medical information change event from a secure data interaction environment to form a detailed change event record; secondly, these records are used to construct a Merkle tree structure, in which each change event record is converted into a hash value, and aggregated upward layer by layer until a unique root hash value is generated; thirdly, this root hash value serves as a log summary, representing the comprehensive hash result of all change events; finally, through the Byzantine fault-tolerant consensus technology, the validity of the log summary is verified between multiple nodes to ensure its authenticity and consistency, thereby generating a verified log summary.
[0088] Here is a specific example:
[0089] Suppose a hospital records a large number of patient treatment activities every day, including medical record updates, diagnosis result entry, etc. In order to ensure the security and traceability of these change records, the hospital adopts the improved Merkle tree algorithm and Byzantine fault-tolerant consensus technology. Whenever a new change event occurs, the system automatically records the detailed operation content, occurrence time, and operator identity information; then, this information is constructed into a Merkle tree, in which each leaf node represents a change event record, and the root node summarizes the hash value of all change events on that day, forming a unique and tamper-proof log summary; through the Byzantine fault-tolerant consensus algorithm, the hospital and other participating nodes jointly verify the authenticity and consistency of these change events and securely add them to the blockchain. Through the above steps, the hospital not only ensures that all medical information change histories are tamper-proof and traceable throughout the process, but also improves the transparency and credibility of the system.
[0090] In order to solve the problem of real-time monitoring and accurate recording of medical information change events, in some embodiments, the data interaction environment is used to collect and process the operation details, timestamp and operator identity of each medical information change event to obtain a change event record, including:
[0091] Utilizing the data interaction environment, a listener is started to monitor and process all operations involving changes in medical information in real time, and an operation trigger signal is obtained. Based on the operation trigger signal, the specific operation content of each change event is captured to obtain operation details; based on the operation trigger signal, the exact time point of each change event is recorded and a timestamp is generated; based on the operation trigger signal and the operation details, the identity identifier of the person performing the change operation is verified, and compared with a pre-registered identity information database to confirm the legitimacy of the operator and obtain a verified operator identity identifier; using the operation details, the timestamp and the verified operator identity identifier, a change event record is constructed.
[0092] In this embodiment, the data interaction environment is utilized to start a listener to perform real-time monitoring and processing of all operations involving changes in medical information to obtain an operation trigger signal; based on the operation trigger signal, the specific operation content of each change event is captured to obtain operation details; based on the operation trigger signal, the exact time point of each change event is recorded to generate a timestamp; based on the operation trigger signal and the operation details, the identity identifier of the person performing the change operation is verified, and compared with a pre-registered identity information database to confirm the legitimacy of the operator and obtain a verified operator identity identifier; using the operation details, the timestamp and the verified operator identity identifier, a change event record is constructed.
[0093] In the embodiment of the present application, first, the system monitors all operations involving changes in medical information in real time by starting a listener, and generates an operation trigger signal once a change behavior is detected; secondly, based on the operation trigger signal, the system automatically captures the specific operation content of each change event to form detailed operation details; thirdly, the system accurately records the occurrence time of each change event according to the same trigger signal and generates an accurate timestamp; finally, based on the operation trigger signal and operation details, the system verifies the identity of the person performing the change operation to ensure that it matches the information in the pre-registered identity information database, thereby confirming the legitimacy of the operator, and integrating the operation details, timestamp and verified operator identity into a complete change event record.
[0094] Here is a specific example:
[0095] Suppose a medical institution deploys an advanced medical information system to ensure that every change in medical information can be accurately recorded and cannot be tampered with. To achieve this goal, the institution first starts a special listener in its data interaction environment to monitor any operation involving medical information changes in real time; whenever a new change event occurs, the listener immediately sends an operation trigger signal; after receiving the signal, the system quickly captures the specific operation content of the change, such as which medical record fields are modified or what diagnostic results are added; at the same time, the system records the exact time of the change event to ensure that each operation has a unique timestamp; next, the system checks whether the identity of the person performing the change operation is legal based on the operation trigger signal and the captured operation details. This step involves comparing with the pre-registered identity information database to confirm the legitimacy of the operator; finally, the system combines the operation details, timestamp and verified operator identity to construct a detailed change event record. Through the above steps, the medical institution not only achieves comprehensive monitoring and accurate recording of medical information changes, but also greatly improves the security and traceability of data.
[0096] In order to solve the verification and consistency problems of medical information change events, in some embodiments, the log summary is verified between multiple nodes in the distributed ledger network through the Byzantine fault-tolerant consensus technology to generate a verified log summary, including:
[0097] Using the log summary, the proposing node initiates proposal processing for the medical information change event, generates and broadcasts a proposal message; based on the proposal message, the receiving node checks the validity of the proposal, and generates a pre-preparation message and broadcasts it to other nodes if the proposal is valid; when the node receives a preset number of valid pre-preparation messages, it confirms the proposal, generates a preparation message and broadcasts it to other nodes; based on the preparation message, when the node receives preparation messages from more than a preset threshold number of nodes, it enters the submission state and submits the proposal, generates a submission message and broadcasts it to other nodes; based on the submission message, when the node receives submission messages from more than the preset threshold number of nodes, it confirms that the proposal has been finalized, updates the local copy and adds the log summary to the blockchain to obtain a verified log summary.
[0098] In this embodiment, by using the log digest, the proposing node initiates the proposal processing for the medical information change event, generates and broadcasts a proposal message; according to the proposal message, the receiving node checks the validity of the proposal, and generates a pre-prepared message and broadcasts it to other nodes when the proposal is valid; when a node receives a preset number of valid pre-prepared messages, it performs confirmation processing on the proposal, generates a prepared message and broadcasts it to other nodes; according to the prepared message, when a node receives the prepared messages from more than a preset threshold number of nodes, it enters the commit state and performs commit processing on the proposal, generates a commit message and broadcasts it to other nodes; based on the commit message, when a node receives the commit messages from more than the preset threshold number of nodes, it confirms that the proposal has been finally determined, updates the local copy and adds the log digest to the blockchain to obtain a verified log digest.
[0099] In the embodiment of the present application, first, the system uses the log digest as a basis, and one or more proposing nodes initiate a proposal for a new medical information change event, generate a proposal message and broadcast it in the network; second, after each receiving node receives the proposal message, it checks its validity. If the proposal is valid, it generates a pre-prepared message and broadcasts it to other nodes; third, when a certain node receives a sufficient number of valid pre-prepared messages, it confirms the proposal and generates a prepared message to continue broadcasting; finally, once a certain node receives the prepared messages from more than a preset threshold number of nodes, it will enter the commit state, complete the commit processing of the proposal, and generate a commit message to broadcast to other nodes. Finally, when more than a preset threshold number of nodes confirm the commit message, all nodes will update the local copy and officially add the log digest to the blockchain to ensure that the proposal is finally determined.
[0100] The following is a specific example:
[0101] Suppose a medical institution uses a distributed ledger network based on Byzantine fault-tolerant consensus technology to manage medical information changes. In order to ensure that each change can be accurately recorded and cannot be tampered with, the system first initiates a proposal for a new medical information change event based on the latest log summary, generates a proposal message and broadcasts it to all participating nodes through the network; after receiving the proposal message, each receiving node immediately checks its validity. If the proposal is valid, it generates a pre-prepare message and broadcasts it; when a node receives a sufficient number of valid pre-prepare messages, it will confirm the proposal and generate a prepare message to continue broadcasting to other nodes; next, once a node receives more than the preset threshold of prepare messages from nodes, it will enter the submission state, complete the submission process of the proposal, and generate a submission message to broadcast to other nodes; finally, when more than the preset threshold of nodes confirm the submission message, all nodes synchronously update the local copy and formally add the log summary to the blockchain to ensure that the proposal is finalized. Through the above steps, the medical institution not only achieves efficient verification of medical information changes, but also ensures the consistency and immutability of data, greatly improving the credibility and security of the system.
[0102] This application takes into account that in the prior art, the security and traceability of medical information change records face many challenges. Traditional methods often rely on centralized database systems, which are not only susceptible to single point failures, but also difficult to ensure the integrity and non-tamperability of the data. In addition, due to the lack of an effective verification mechanism, the authenticity and source reliability of the data are also difficult to be fully guaranteed. Therefore, an embodiment of the present invention proposes an optional solution based on a Merkle tree algorithm and hash operations, which aims to solve the above problems and provide a safe, reliable and efficient medical information change record management mechanism.
[0103] Optionally, based on the change event record, a Merkle tree algorithm is applied to construct a binary tree structure, hash operations are performed on each change event record and summarized layer by layer to obtain a unique root hash value, the unique root hash value is the log summary, including:
[0104] When calculating the hash value H of each change event record i Previously, the system standardized and formatted information such as operation details, timestamps, and identity identification, and generated random salt values and permission level verification signatures to ensure data consistency and security; the authenticity of each change record was confirmed through digital signature technology to provide high-quality basic data for subsequent hash operations;
[0105] H i =SHA 256(E(O i )||E(T i )||E(I i )||Si ||P i ||V i )
[0106] Among them, H i is the hash value of the i-th change event record; SHA256 means using the SHA-256 algorithm for hashing; E(x) means encrypting x to enhance security; O i Represents the operation details of the i-th change event; T i is the timestamp of the i-th change event; I i is the operator identity of the i-th change event; S i is the random salt value for the ith change event, used to increase the randomness and uniqueness of the hash result and prevent rainbow table attacks; P i is the permission level of the operator. By incorporating it into the hash calculation, operations at different permission levels can be further distinguished. i It is the verification signature, i.e. the operator’s digital signature, which is used to verify the authenticity of the operation and ensure the reliability of the data source;
[0107] After calculating H i Finally, the system organizes all hash values into a binary tree structure. Two adjacent hash values are combined and hashed again using the SHA256 algorithm, and are summarized layer by layer until a unique root node is obtained. For an odd number of hash values, the last one is used as a separate layer for calculation to ensure that all change event records are efficiently integrated into a compact log summary, in preparation for calculating the root hash value R.
[0108]
[0109] Where R represents the final log summary, that is, the root hash value of the Merkle tree; MerkleRoot is a recursive function that is used to summarize the hash values of two child nodes layer by layer until the root hash value is calculated; C(x, y) represents the combination of two hash values x and y, specifically, first concatenating and then hashing through SHA256, that is, C(x, y) = SHA 256(x||y); H i is the hash value of the i-th change event record; n is the total number of change event records; represents the rounding down operation, ensuring that when the number of change event records is an odd number, the last node participates in the calculation as a single layer; k is an index variable used to traverse all pairs of hash values;
[0110] After calculating the root hash value R, the system performs an integrity check on it and may introduce a time-weighted factor to adjust its importance and improve its ability to resist attacks. Ultimately, the root hash value is added to the blockchain and becomes an unchangeable part, ensuring the security and traceability of the change history and providing a trust basis for the secure storage system of medical information.
[0111] The formula is designed to ensure the consistency, security and immutability of all change event records. The system creates high-quality basic data for each change record through standardized processing, random salt value generation, and permission level verification signatures. Then, the SHA-256 algorithm is used to calculate the hash value of each change event record, and the Merkle tree structure is used to summarize these hash values layer by layer, and finally a unique root hash value is obtained as the log summary. This solution not only enhances the system's anti-attack capabilities, but also provides full traceability of the change history, thus laying a solid trust foundation for the medical information security storage system.
[0112] The following is a brief introduction to the design reasons of each sub-item of the formula:
[0113] H i =SHA 256(E(O i )||E(T i )||E(I i )||S i ||P i ||V i )
[0114] Operation details encryption E(O i ): Ensure the confidentiality of operation details; timestamp encryption E(T i ): Ensure the authenticity of the time; identity encryption E(I i ): protect the operator's identity privacy; random salt value S i : Increase the randomness and uniqueness of the hash result; permission level P i :Distinguish operations with different permission levels; verify signature V i : Confirm the authenticity of the operation;
[0115] The following is a brief introduction to how to obtain the parameters of the formula:
[0116] O i Extract operation details from the change event record; i Get the current timestamp from the system clock; I i Obtain the operator's identity from the user authentication system; S i Randomly generated by the system; P i Obtained from the authority management system according to the operator's role; V iGenerated by the operator using digital signature technology.
[0117] The following is a brief introduction to the design reasons of each sub-item of the formula:
[0118]
[0119] Combined hash function C(x, y): ensures efficient merging of two hash values; index variable k: used to traverse all pairs of hash values; round down operation Handling odd number of hash values; Total number of change event records n: Determine the total number of hash values involved in the calculation; Final root hash value R: Provides a compact log summary;
[0120] The following is a brief introduction to how to obtain the parameters of the formula:
[0121] H 2k and H 2k+1 Calculated in the previous step; k is an index variable that increases from 0; n is the number of all change event records; Calculate the number of hash value logarithms that need to be merged; H n When n is an odd number, it is calculated as a separate layer.
[0122] Assume that a medical institution generates a large number of medical information change events every day, such as medical record updates or diagnosis result input. In order to ensure the security and traceability of these change records, the system first records the operation details of each change record. i , timestamp T i , Operator Identification I i Perform standardization and formatting, and generate a random salt value S i And permission level verification signature P i Subsequently, digital signature technology is used to confirm the authenticity of each change record and generate a verification signature V i Specifically, for the first change event record, we have:
[0123] H 1 =SHA 256(E(O 1 )||E(T 1 )||E(I 1 )||S 1 ||P 1 ||V 1 )
[0124] Assume that E(O 1 )、E(T 1 )、E(I 1 ) are respectively “medical record update”, “2024-12-22 10:00:00”, “doctor A”, S1 is a randomly generated string, P 1 As the "attending physician", V 1 This is the digital signature of Doctor A. After SHA-256 operation, we get H 1 The specific value of .
[0125] Next, the system organizes all hash values into a binary tree structure, combines two adjacent hash values and hashes them again using the SHA256 algorithm, and aggregates them layer by layer until a unique root node is obtained. For example, if there are three change event records, their hash values are H 1 , H 2 and H 3 ,but:
[0126] R = MerkleRoot({C(H 1 , H 2 ), H 3})
[0127] Among them, C(H 1 , H 2 )=SHA 256(H 1 ||H 2 ), and finally the root hash value R is calculated.
[0128] Through the above steps, medical institutions not only achieve high encryption and immutability of all medical information change records, but also greatly improve the transparency and credibility of the system. In particular, the introduction of the time weighting factor to adjust the importance of the root hash value further enhances the system's anti-attack ability. This shows that even in the face of complex and changing environments, the solution can effectively protect the security and privacy of medical information and solve many problems existing in existing technologies.
[0129] In order to solve the problem of secure storage and efficient retrieval of medical data, in some embodiments, in step 103, according to the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient, the patient's medical record is encrypted to obtain an encrypted medical data file, content-based indexing technology is introduced to create an inverted index and a Bloom filter, the encrypted medical data file is optimized for retrieval, and an encrypted medical data storage system is generated, including:
[0130] According to the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient to obtain a patient-specific public-private key pair; using the patient-specific public-private key pair, the medical record is encrypted using the patient's public key to obtain an encrypted medical data file; based on the encrypted medical data file, a content-based indexing technology is introduced to create an inverted index, and the keyword or phrase position in the file is indexed to generate an inverted index structure; according to the encrypted medical data file, a Bloom filter is applied to build a fast checking mechanism to reduce unnecessary disk read operations and generate a Bloom filter configuration; using the inverted index structure and the Bloom filter configuration, the encrypted medical data file is optimized for retrieval processing to generate an encrypted medical data storage system.
[0131] In this embodiment, based on the log summary, an elliptic curve cryptography (ECC) algorithm is used to generate a unique public-private key pair for each patient to ensure that each patient has an exclusive key pair for protecting their medical data; using the patient-exclusive public-private key pair, the medical record is encrypted using the patient's public key to generate an encrypted medical data file to prevent unauthorized access; based on the encrypted medical data file, a content-based indexing technology is introduced to create an inverted index, and the keyword or phrase position in the file is indexed to generate an inverted index structure to quickly locate the required information; based on the encrypted medical data file, a Bloom filter is applied to build a fast check mechanism to reduce unnecessary disk read operations, generate a Bloom filter configuration, and improve retrieval efficiency; using the inverted index structure and the Bloom filter configuration, the encrypted medical data file is optimized for retrieval processing, and finally an encrypted medical data storage system is generated.
[0132] In the embodiment of the present application, firstly, the system generates a unique public-private key pair for each patient based on the log summary to ensure that the medical data of each patient can be highly encrypted and protected; secondly, the medical record is encrypted using the patient's public key to generate an encrypted medical data file to ensure that only the person holding the corresponding private key can decrypt and view the original data; thirdly, the system introduces content-based indexing technology, creates an inverted index structure, and indexes the positions of keywords or phrases in the file, so that specific information can be quickly located even in a large amount of data; finally, a Bloom filter is applied to build a fast check mechanism to reduce unnecessary disk read operations and further improve retrieval efficiency. Through these measures, the system generates a safe and efficient encrypted medical data storage system.
[0133] Here is a specific example:
[0134] Suppose a medical institution needs to store and manage its huge patient database securely and efficiently. To achieve this goal, the institution first generates a unique public-private key pair for each patient based on the log summary to ensure that each patient's medical data can be highly encrypted and protected; then, all medical records are encrypted using the patient's public key to generate encrypted medical data files, ensuring that only authorized personnel holding the corresponding private key can decrypt and view the original data; next, the system introduces content-based indexing technology to create a detailed inverted index structure to index the location of keywords or phrases in the file, so that medical staff can quickly locate the required medical records; finally, a Bloom filter is used to build a fast check mechanism to reduce unnecessary disk read operations and significantly improve retrieval efficiency. Through the above steps, the medical institution not only achieves high encryption protection of patient medical data, but also greatly improves the speed of data retrieval and service response capabilities, meeting the needs of daily medical services.
[0135] In order to solve the problem of efficient retrieval of encrypted medical data files, in some embodiments, based on the encrypted medical data files, a content-based indexing technology is introduced to create an inverted index, index the positions of keywords or phrases in the files, and generate an inverted index structure, including:
[0136] The encrypted medical data file is used to perform secure parsing processing on the text information contained in the encrypted medical data file using the patient's public key to obtain the parsed text information; based on the parsed text information, natural language processing technology is applied to perform word segmentation, stop word removal and word form restoration processing on the parsed text information to extract keywords and phrases to obtain a keyword phrase set; based on the keyword phrase set, the specific position of each keyword phrase in the file is located, the position information of its occurrence is recorded, and a position information table is generated; using the position information table, an inverted index entry is created for each keyword phrase to generate a preliminary inverted index entry set, wherein each entry contains the keyword or phrase and the position information of its occurrence in the file; based on the preliminary inverted index entry set, the index entries are optimized to generate an inverted index structure.
[0137] In this embodiment, the encrypted medical data file is used to perform secure parsing processing on the text information contained in the encrypted medical data file using the patient's public key to obtain the parsed text information; based on the parsed text information, natural language processing technology is applied to perform word segmentation, stop word removal and word form restoration processing on the parsed text information to extract keywords and phrases to obtain a keyword phrase set; based on the keyword phrase set, the specific position of each keyword phrase in the file is located, the position information of its occurrence is recorded, and a position information table is generated; using the position information table, an inverted index entry is created for each keyword phrase to generate a preliminary inverted index entry set, wherein each entry contains the keyword or phrase and the position information of its occurrence in the file; based on the preliminary inverted index entry set, the index entries are optimized to generate an inverted index structure.
[0138] In the embodiment of the present application, firstly, the system uses the patient's public key to perform secure parsing of the text information in the encrypted medical data file to ensure that the text content is extracted without leaking sensitive information; secondly, by applying natural language processing (NLP) technology, the parsed text information is subjected to pre-processing steps such as word segmentation, stop word removal, and word form restoration, and representative keywords and phrases are extracted from it to form a keyword phrase set; thirdly, the system locates the specific position of each keyword phrase in the file, and records the location information of its occurrence, and generates a detailed location information table; finally, using the location information table, an inverted index entry is created for each keyword phrase, a preliminary inverted index entry set is generated, and it is optimized, and finally an efficient inverted index structure is constructed. This not only improves the retrieval efficiency of encrypted medical data files, but also ensures the security and privacy of the data.
[0139] Here is a specific example:
[0140] Suppose a medical institution needs to efficiently manage its encrypted patient medical records. To achieve this goal, the institution first uses the patient's public key to securely parse the text information in the encrypted medical data file to ensure that all available text content is extracted without leaking sensitive information; then, the system uses natural language processing technology to segment these text information, remove stop words and restore word forms, and extract representative keywords and phrases, such as "hypertension" and "diabetes treatment", to form a keyword phrase set; next, the system locates the specific position of each keyword phrase in the file, records its location information, and generates a detailed location information table; finally, using the location information table, an inverted index entry is created for each keyword phrase, a preliminary inverted index entry set is generated, and it is optimized, and finally an efficient inverted index structure is constructed. Through the above steps, medical staff can quickly locate the required medical records, significantly improve the query speed and service response capabilities, while ensuring the security and privacy of patient data.
[0141] This application takes into account that, in the prior art, the secure storage and full traceability of medical information face many challenges. Traditional encryption methods often cannot fully protect the privacy and integrity of data, especially in the case of multi-institutional collaboration, it is difficult to ensure that the operations of each participant are legal and transparent. In addition, due to the lack of effective authority management and identity authentication mechanisms, the risk of data leakage and tampering increases. Therefore, an embodiment of the present invention proposes an optional solution for generating patient-specific public and private key pairs based on an elliptic curve encryption algorithm, aiming to solve the above problems and provide a safe, reliable and efficient medical information encryption mechanism.
[0142] Optionally, after ensuring the security and full traceability of all medical information change histories based on the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient to obtain a patient-specific public-private key pair, including:
[0143] When generating the public key P i Previously, the system verified and standardized the patient’s identity information, combined the log summary and timestamp, and randomly generated the initial offset, geographic factor, and initial seed point for each patient to ensure the consistency and security of the input data;
[0144]
[0145] Among them, P i is the point on the elliptic curve corresponding to the public key of the i-th patient; g is the generator of the elliptic curve, which is used to generate points on the elliptic curve; H(x) represents the hash operation of x using the SHA-256 algorithm; D iis the unique identifier of the ith patient, used to distinguish different patients; L is the log summary, which is the log summary calculated previously, used to ensure security and full traceability; T i It is a timestamp, which records the time when the public and private keys were generated to increase the influence of the time factor; R i,0 is the initial offset randomly generated for each patient, used to enhance the randomness and uniqueness of the public key; S i,init is the initial seed point generated for each patient, used to further increase the randomness of the public key; F i is a geographic factor generated based on the patient's geographic location, used to enhance security in combination with physical location information; p is a large prime modulus defined by the elliptic curve, used to ensure that the calculation result is within a finite field;
[0146] After calculating the public key P i After that, the system randomly generates secret factors and introduces fixed points, generates additional items through time feathers and verification signatures, and introduces a confusion layer in combination with bitwise XOR operations to construct a private key S associated with the public key. i , ensuring its uniqueness and security;
[0147]
[0148] Among them, S i is the private key of the i-th patient; P i is the point on the elliptic curve corresponding to the public key of the i-th patient; K i It is a secret factor randomly generated for each patient, used to increase the randomness and uniqueness of the private key; Q is a fixed point preset by the system, used to enhance the association between the private key and the public key; represents a bitwise XOR operation, which is used to introduce an additional layer of obfuscation; H(x) represents the hash operation of x using the SHA-256 algorithm; T i Is the timestamp, recording the time when the public and private keys were generated; V i is the verification signature, i.e. the operator’s digital signature, used to verify the authenticity of the operation; E(x) represents the encryption of x, which is used to further protect the security of the private key; C i is the patient's health status code, which reflects the patient's current health status and is used as part of the private key generation; q is the order of the elliptic curve, which is used to ensure the validity of the private key within a finite field;
[0149] Complete private key S i After the calculation, the system performs integrity check on the private key and includes the patient's health status code in the encryption process, and finally converts the public key P i and private key S i Bind to form a unique and secure patient-specific public and private key pair.
[0150] The formula is designed to ensure the security and full traceability of all medical information change history. The system first verifies and standardizes the patient's identity information, and combines the log summary and timestamp to randomly generate an initial offset, geographic factor, and initial seed point for each patient to ensure the consistency and security of the input data. Then, the patient's public key P is generated through complex mathematical operations. i and private key S i The two are bound to form a unique and secure patient-specific public and private key pair. This solution not only enhances the system's anti-attack capability, but also provides full traceability of change history, thus laying a solid trust foundation for the medical information security storage system.
[0151] The following is a brief introduction to the design reasons of each sub-item of the formula:
[0152]
[0153] Generator g: used to generate points on the elliptic curve; hash operation H(x): ensure the uniqueness and consistency of input data; unique identity D i : Distinguish different patients; Log summary L: Ensure safety and full traceability; Timestamp T i : Add the influence of time factor; initial offset R i,0 : Enhance the randomness and uniqueness of the public key; initial seed point S i,init : Further increase the randomness of the public key; geographic factor F i : Combined with physical location information to enhance security; Large prime modulus p: Ensure that the calculation result is within a finite field;
[0154] The following is a brief introduction to how to obtain the parameters of the formula:
[0155] g is the preset elliptic curve generator; D i Extracted from patient registry information; L is obtained from the previously calculated log summary; T i Get the current timestamp from the system clock; R i,0 Randomly generated by the system; S i,init Randomly generated by the system; F i Generated according to the patient's geographic location; p is the large prime modulus defined by the preset elliptic curve.
[0156] The following is a brief introduction to the design reasons of each sub-item of the formula:
[0157]
[0158] Public Key P i : Ensure the association between the private key and the public key; secret factor K i: Increase the randomness and uniqueness of the private key; Fixed point Q: Enhance the correlation between the private key and the public key; Bitwise XOR operation Introducing an additional layer of obfuscation; Hash operation H(x): ensures the uniqueness and consistency of input data; Timestamp T i : Record the time when the public and private keys are generated; verify the signature V i :Verify the authenticity of the operation; Encryption processing E(x): Protect the security of the private key; Health status code C i : reflects the patient's current health status; the order q of the elliptic curve: ensures the validity of the private key within a finite field;
[0159] The following is a brief introduction to how to obtain the parameters of the formula:
[0160] P i Calculated from the previous step; K i Randomly generated by the system; Q is a preset fixed point; f i Get the current timestamp from the system clock; V i Generated by the operator using digital signature technology; E(C i ) uses a symmetric encryption algorithm to encrypt the health status code; q is the order of the preset elliptic curve.
[0161] Suppose a medical institution needs to generate a unique and secure public-private key pair for each of its patients. To achieve this goal, the system first verifies and standardizes the patient's identity information, combines the log summary and timestamp, and randomly generates an initial offset, geographic factor, and initial seed point for each patient. Specifically, for the first patient, we have:
[0162]
[0163] Assume g is a known circular curve generator, D 1 is the unique identifier of “patient A”, L is the log digest calculated previously, T 1 is ″2024-12-2210:00:00″, R 1,0 is a randomly generated string, S 1,init is a randomly generated initial seed point, F 1 is the geographic factor generated based on the geographic location of patient A, and p is the large prime modulus defined by the elliptic curve. After calculation, we get P 1 The specific value of .
[0164] Next, the system randomly generates secret factors and introduces fixed points, generates additional items through time feathers and verification signatures, and introduces a confusion layer combined with bitwise XOR operations to construct a private key S associated with the public key. 1 :
[0165]
[0166] Assume K 1 is a randomly generated secret factor, Q is a preset fixed point, and V 1 is the doctor's digital signature, E(C 1 ) is the encrypted result of the health status code of patient A, and q is the order of the elliptic curve. After calculation, we get S 1 The specific value of .
[0167] Complete private key S 1 After the calculation, the system performs integrity check on the private key and includes the patient's health status code in the encryption process, and finally converts the public key P 1 and private key S 1 Bind to form a unique and secure patient-specific public and private key pair.
[0168] Through the above steps, medical institutions not only achieve high encryption and tamper-proof of all medical information change records, but also greatly improve the transparency and credibility of the system. In particular, the introduction of the health status code as part of the private key further enhances the personalization and security of the system. This shows that even in the face of complex and changing environments, the solution can effectively protect the security and privacy of medical information and solve many problems existing in the existing technology. For example, the threshold is set to a certain security level. Since the result is greater than the set threshold, it shows that the system can effectively prevent unauthorized access and data modification, ensuring the safe storage and transmission of medical data.
[0169] In order to solve the problem of secure transmission of medical data and trust establishment between different blockchain systems, in some embodiments, when the encrypted medical data storage system in step 104 exchanges medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated to transfer medical data between different blockchains, and a credit scoring system is established through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem, including:
[0170] When the need to exchange medical information between the encrypted medical data storage system and other blockchain systems is detected, a cross-chain bridging mechanism based on hash locking and time locking is activated; using the cross-chain bridging mechanism, a unique hash value is created for the medical data to be transmitted at the sending end, and it is used as a hash locking condition to obtain a hash locking setting; according to the hash locking setting, a valid time window is set as a time locking condition to ensure that the data is transmitted within the specified time, and a time locking configuration is generated; based on the hash locking setting and the time locking configuration, the data transmission process in the cross-chain bridging mechanism is started, and the encrypted medical data is transferred from the source blockchain system to the target blockchain system to obtain a successfully transmitted data record; using the successfully transmitted data record, the cooperative medical institutions participating in the data exchange are authenticated for qualifications and reputation, a credit scoring system is established, and authentication and evaluation results are obtained; according to the authentication and evaluation results, a data sharing ecosystem is generated.
[0171] In this embodiment, when the need to exchange medical information between the encrypted medical data storage system and other blockchain systems is detected, a cross-chain bridging mechanism based on hash locking and time locking is activated; using the cross-chain bridging mechanism, a unique hash value is created for the medical data to be transmitted at the sending end, and it is used as a hash locking condition to obtain a hash locking setting; according to the hash locking setting, a valid time window is set as a time locking condition to ensure that the data is transmitted within the specified time, and a time locking configuration is generated; based on the hash locking setting and the time locking configuration, the data transmission process in the cross-chain bridging mechanism is started, and the encrypted medical data is transferred from the source blockchain system to the target blockchain system to obtain a successfully transmitted data record; using the successfully transmitted data record, the cooperative medical institutions participating in the data exchange are authenticated for qualifications and reputation, a credit scoring system is established, and authentication and evaluation results are obtained; according to the authentication and evaluation results, a data sharing ecosystem is generated.
[0172] In the embodiment of the present application, first, when it is detected that medical information needs to be exchanged between the encrypted medical data storage system and other blockchain systems, the system activates the cross-chain bridging mechanism based on hash locking and time locking; secondly, the sender creates a unique hash value for the medical data to be transmitted and uses it as a hash locking condition to ensure the security of data transmission; thirdly, a valid time window is set as a time locking condition to ensure that the data is transmitted within the specified time to prevent long-term pending status; finally, based on the hash locking setting and time locking configuration, the data transmission process in the cross-chain bridging mechanism is started to transfer the encrypted medical data from the source blockchain system to the target blockchain system securely. After completion, the system uses the successfully transmitted data records to conduct qualification certification and reputation assessment of the cooperative medical institutions participating in the data exchange, establish a credit scoring system, thereby promoting trust and efficient collaboration among multiple parties, and ultimately generating a healthy data sharing ecosystem.
[0173] Here is a specific example:
[0174] Suppose that a medical institution A wants to achieve secure sharing of patient medical information with another medical institution B through blockchain technology. In order to ensure the security and timeliness of data transmission, the system first activates the cross-chain bridging mechanism based on hash lock and time lock when detecting the need for medical information exchange between medical institutions A and B; then, medical institution A creates a unique hash value for the medical data to be transmitted and uses it as a hash lock condition to ensure that the data can only be unlocked and accepted after the receiver verifies the same hash value; next, the system sets a 72-hour effective time window as a time lock condition to ensure that the data is transmitted within this period; then, based on the hash lock setting and time lock configuration, the cross-chain bridging mechanism starts the data transmission process, and securely transfers the encrypted medical data from the blockchain system of medical institution A to the blockchain system of medical institution B; after completion, the system uses the successfully transmitted data records to conduct qualification authentication and reputation assessment of medical institutions A and B, establish a credit scoring system, and confirm the cooperation qualifications and reputation of both parties; through the above steps, the two medical institutions not only achieve the secure sharing of patient medical information, but also promote trust and efficient collaboration between each other, and finally form a healthy data sharing ecosystem.
[0175] Figure 2 A schematic diagram of a medical information security storage system based on blockchain technology is provided for the present application embodiment. Figure 2 As shown, the device comprises:
[0176] A construction module 21 is used to construct a multi-level distributed ledger network architecture, use a role-based access control model and a zero-knowledge proof protocol to perform fine-grained operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and combine a time lock mechanism to limit data access rights within a preset time period to obtain a data interaction environment;
[0177] An adding module 22 is used to integrate the operation details, timestamps and operator identities using a Merkle tree algorithm according to the secure and compliant data interaction environment, and add them to the blockchain after verification by the Byzantine fault-tolerant consensus technology, to ensure that all medical information change histories cannot be tampered with and are fully traceable, and to generate a log summary;
[0178] A retrieval module 23 is used to generate a unique public-private key pair for each patient using an elliptic curve encryption algorithm according to the log summary, encrypt the patient's medical record to obtain an encrypted medical data file, introduce a content-based indexing technology to create an inverted index and a Bloom filter, perform optimized retrieval processing on the encrypted medical data file, and generate an encrypted medical data storage system;
[0179] The activation module 24 is used to activate the cross-chain bridging mechanism based on hash locking and time locking when the encrypted medical data storage system exchanges medical information with other blockchain systems, accurately transmit and process medical data between different blockchains, and establish a credit scoring system through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem.
[0180] Figure 2 The medical information security storage system based on blockchain technology can be executed Figure 1 The implementation principle and technical effect of the medical information security storage method based on blockchain technology described in the embodiment shown are not repeated here. The specific way in which each module and unit performs operations in the medical information security storage system based on blockchain technology in the above embodiment has been described in detail in the embodiment of the method, and will not be elaborated here.
[0181] In one possible design, Figure 2 A medical information security storage system based on blockchain technology in the illustrated embodiment can be implemented as a computing device, such as Figure 3 As shown, the computing device may include a storage component 31 and a processing component 32;
[0182] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32 .
[0183] The processing component 32 is used to: construct a multi-level distributed ledger network architecture, use the role-based access control model and the zero-knowledge proof protocol to perform fine-grained operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and combine the time lock mechanism to limit the data access rights within a preset time period to obtain a data interaction environment; according to the data interaction environment, use the Merkle tree algorithm to integrate the operation details, timestamps and operator identities, and add them to the blockchain after verification by the Byzantine fault-tolerant consensus technology to generate a log summary; according to the log summary, use the elliptic curve encryption algorithm to generate a unique public-private key pair for each patient, encrypt the patient's medical records to obtain an encrypted medical data file, introduce content-based indexing technology to create an inverted index and a Bloom filter, optimize the retrieval processing of the encrypted medical data file, and generate an encrypted medical data storage system; when the encrypted medical data storage system exchanges medical information with other blockchain systems, activate the cross-chain bridging mechanism based on hash locking and time locking, transfer medical data between different blockchains, and establish a credit scoring system through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem.
[0184] The processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components to perform the above method.
[0185] The storage component 31 is configured to store various types of data to support operations at the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0186] Of course, the computing device may also include other components, such as input / output interfaces, display components, communication components, etc.
[0187] The input / output interface provides an interface between the processing component and the peripheral interface module, which may be an output device, an input device, etc.
[0188] The communication component is configured to facilitate, among other things, wired or wireless communications between the computing device and other devices.
[0189] Among them, the computing device can be a physical device or an elastic computing host provided by a cloud computing platform, etc. In this case, the computing device can refer to a cloud server, and the above-mentioned processing components, storage components, etc. can be basic server resources rented or purchased from the cloud computing platform.
[0190] The present application also provides a computer storage medium storing a computer program, wherein the computer program can achieve the above-mentioned Figure 1 A method for securely storing medical information based on blockchain technology in the illustrated embodiment.
[0191] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0192] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0193] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0194] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for secure storage of medical information based on blockchain technology, characterized in that: include: Construct a multi-level distributed ledger network architecture, use the role-based access control model and the zero-knowledge proof protocol to perform fine-grained operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and combine the time lock mechanism to limit data access rights within a preset time period to obtain a data interaction environment; According to the data interaction environment, the Merkle tree algorithm is used to integrate the operation details, timestamps and operator identities, and added to the blockchain after verification by the Byzantine fault-tolerant consensus technology to generate a log summary; According to the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient, the patient's medical record is encrypted to obtain an encrypted medical data file, content-based indexing technology is introduced to create an inverted index and a Bloom filter, the encrypted medical data file is optimized for retrieval, and an encrypted medical data storage system is generated; When the encrypted medical data storage system exchanges medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated to transfer medical data between different blockchains, and a credit scoring system is established through qualification certification and reputation assessment of cooperative medical institutions to generate a data sharing ecosystem.
2. The method according to claim 1, characterized in that According to the data interaction environment, the Merkle tree algorithm is used to integrate the operation details, timestamps and operator identification, and added to the blockchain after verification by the Byzantine fault-tolerant consensus algorithm, to ensure that all medical information change histories cannot be tampered with and are fully traceable, and to generate a log summary, including: Using the data interaction environment, the operation details, timestamp and operator identity of each medical information change event are collected and processed to obtain a change event record; Based on the change event record, a Merkle tree algorithm is applied to construct a binary tree structure, and hash operations are performed on each change event record and summarized layer by layer to obtain a root hash value, wherein the unique root hash value is used as a log summary; According to the log summary, verification processing is performed between multiple nodes in the distributed ledger network through Byzantine fault-tolerant consensus technology to generate a verified log summary.
3. The method according to claim 2, characterized in that The data interaction environment is used to collect and process the operation details, timestamp and operator identity of each medical information change event to obtain a change event record, including: Using the data interaction environment, a listener is started to monitor and process all operations involving changes in medical information in real time to obtain an operation trigger signal; According to the operation trigger signal, the specific operation content of each change event is captured to obtain the operation details; Based on the operation trigger signal, record the exact time point of each change event and generate a timestamp; According to the operation trigger signal and the operation details, verify the identity of the operator who performs the change operation, and compare it with the pre-registered identity information database to confirm the legitimacy of the operator, and obtain the verified operator identity; A change event record is constructed using the operation details, the timestamp and the verified operator identity.
4. The method according to claim 2, characterized in that: According to the log summary, verification processing is performed between multiple nodes in the distributed ledger network through the Byzantine fault-tolerant consensus technology to generate a verified log summary, including: Using the log summary, the proposing node initiates a proposal process for the medical information change event, generates and broadcasts a proposal message; According to the proposal message, the receiving node checks the validity of the proposal, and generates a pre-prepared message and broadcasts it to other nodes if the proposal is valid; When a node receives a preset number of valid pre-prepare messages, it confirms the proposal, generates a prepare message and broadcasts it to other nodes; According to the prepare message, when a node receives prepare messages from more than a preset threshold number of nodes, it enters the commit state and submits the proposal, generates a commit message and broadcasts it to other nodes; Based on the submission message, when a node receives submission messages from more than the preset threshold number of nodes, it confirms that the proposal has been finalized, updates the local copy and adds the log summary to the blockchain to obtain a verified log summary.
5. The method according to claim 1, characterized in that The method generates a unique public-private key pair for each patient using an elliptic curve encryption algorithm according to the log summary, encrypts the patient's medical record to obtain an encrypted medical data file, introduces content-based indexing technology to create an inverted index and a Bloom filter, optimizes the retrieval process for the encrypted medical data file, and generates an encrypted medical data storage system, including: According to the log summary, an elliptic curve encryption algorithm is used to generate a unique public-private key pair for each patient to obtain a public-private key pair exclusive to the patient; Using the patient's exclusive public-private key pair, the medical record is encrypted using the patient's public key to obtain an encrypted medical data file; Based on the encrypted medical data file, a content-based indexing technology is introduced to create an inverted index, and the keyword or phrase position in the file is indexed to generate an inverted index structure; According to the encrypted medical data file, a Bloom filter is applied to build a fast checking mechanism to reduce unnecessary disk read operations and generate a Bloom filter configuration; The inverted index structure and the Bloom filter configuration are used to optimize the retrieval process of the encrypted medical data file to generate an encrypted medical data storage system.
6. The method according to claim 5, characterized in that Based on the encrypted medical data file, the content-based indexing technology is introduced to create an inverted index, index the keyword or phrase position in the file, and generate an inverted index structure, including: Using the encrypted medical data file, and using the patient's public key to perform secure parsing processing on the text information contained in the encrypted medical data file to obtain parsed text information; According to the parsed text information, natural language processing technology is applied to perform word segmentation, stop word removal and lemma restoration on the parsed text information to extract keywords and phrases to obtain a keyword phrase set; Based on the keyword phrase set, locate the specific position of each keyword phrase in the file, record the position information of its occurrence, and generate a position information table; Using the position information table, create an inverted index entry for each keyword phrase to generate a preliminary inverted index entry set, wherein each entry contains the keyword or phrase and the position information where it appears in the file; According to the preliminary inverted index entry set, the index entries are optimized to generate an inverted index structure.
7. The method according to claim 1, characterized in that When the encrypted medical data storage system exchanges medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated to transfer medical data between different blockchains, and a credit scoring system is established through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem, including: When the encrypted medical data storage system needs to exchange medical information with other blockchain systems, a cross-chain bridging mechanism based on hash locking and time locking is activated; Using the cross-chain bridging mechanism, a unique hash value is created for the medical data to be transmitted at the sending end, and used as a hash locking condition to obtain a hash locking setting; According to the hash lock setting, a valid time window is set as a time lock condition to ensure that the data is transmitted within the specified time and generate a time lock configuration; Based on the hash lock setting and the time lock configuration, the data transfer process in the cross-chain bridging mechanism is started to transfer the encrypted medical data from the source blockchain system to the target blockchain system to obtain a successfully transferred data record; Using the successfully transmitted data records, conduct qualification certification and credit assessment on the cooperative medical institutions participating in the data exchange, establish a credit scoring system, and obtain certification and assessment results; Based on the certification and evaluation results, a data sharing ecosystem is generated.
8. A medical information security storage system based on blockchain technology, characterized in that: include: A construction module is used to construct a multi-level distributed ledger network architecture, and use a role-based access control model and a zero-knowledge proof protocol to perform fine-grained operation authority allocation processing on different types of nodes in the multi-level distributed ledger network architecture, and combine a time lock mechanism to limit data access rights within a preset time period to obtain a data interaction environment; Add a module for integrating operation details, timestamps and operator identities using a Merkle tree algorithm according to the secure and compliant data interaction environment, and adding them to the blockchain after verification by the Byzantine Fault Tolerant consensus technology, to ensure that all medical information change histories cannot be tampered with and are fully traceable, and to generate a log summary; A retrieval module is used to generate a unique public-private key pair for each patient using an elliptic curve encryption algorithm according to the log summary, encrypt the patient's medical record to obtain an encrypted medical data file, introduce content-based indexing technology to create an inverted index and a Bloom filter, optimize the retrieval process of the encrypted medical data file, and generate an encrypted medical data storage system; The activation module is used to activate the cross-chain bridging mechanism based on hash locking and time locking when the encrypted medical data storage system exchanges medical information with other blockchain systems, accurately transmit and process medical data between different blockchains, and establish a credit scoring system through qualification certification and reputation evaluation of cooperative medical institutions to generate a data sharing ecosystem.
9. A computing device, characterized in that It comprises a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a medical information security storage method based on blockchain technology as described in any one of claims 1 to 7.
10. A computer storage medium, characterized in that: A computer program is stored, and when the computer program is executed by a computer, a method for secure storage of medical information based on blockchain technology as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Method and device for medical information sharing privacy protection based on blockchain technology
CN106682530A
Cross-chain reward and punishment method based on anonymous service and hash locking
CN112053146A
Medical private data protection method based on block chain technology
CN112398920A
Smart community system based on block chain
CN113052744A
Novel electronic medical record sharing method fusing block chain and real behavior characteristics
CN113793665A
Cited By
Intelligent medical equipment management system and method
CN120236733A
Intelligent medical equipment management system and method
CN120236733B
Cross-region and cross-mechanism health medical data security sharing method based on block chain
CN120342788A
Block chain-based electronic evidence full-life-cycle evidence storage and tracing method and system
CN121009587A
A blockchain-based electronic evidence full-life-cycle storage and traceability method and system
CN121009587B