Smart city data sharing system based on block chain technology

By adopting blockchain technology and cryptography in the medical data sharing system, we design data sharing modules driven by layered data storage and smart contracts, and combining privacy protection technologies such as zero-knowledge proof and homomorphic encryption, we solve the problems of centralized storage, fragile security, and high privacy leakage risks in the medical data sharing system, and realize the secure storage, efficient sharing and privacy protection of data.

CN120086195AActive Publication Date: 2025-06-03ALMEIDE SMART MEDICAL (HUZHOU) CO LTD

Patent Information

Application Number
CN202510155082.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-06-03
Estimated Expiration
2045-02-12

AI Technical Summary

Technical Problem

The existing medical data sharing system has problems such as centralized data storage, fragile security, high risk of privacy leakage, cumbersome and complex data sharing processes and simple smart contract functions, which are difficult to meet the needs of efficient sharing of medical data and privacy protection.

Method used

Blockchain technology is used to combine cryptography to design data layered storage and blockchain mapping modules to realize distributed storage and efficient sharing of data; through smart contract-driven data sharing modules, multi-role and multi-level authorization management and automated execution are realized; and privacy protection technologies such as zero-knowledge proof and homomorphic encryption are integrated to ensure data privacy and security.

Benefits of technology

It has realized the secure storage, efficient sharing, privacy protection and full-process traceability of medical data, improved the quality of medical services, promoted the development of medical research, and protected the legitimate rights and interests of all parties.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120086195A_ABST
    Figure CN120086195A_ABST
Patent Text Reader

Abstract

The invention discloses a smart city data sharing system based on a block chain technology, and relates to the crossing field of medical data processing and information technologies. The system comprises the following modules: 1, a data storage and block chain mapping module, which generates an abstract by using a salting SHA-256 algorithm, stores the abstract in a block chain, stores original data in an IPFS distributed manner, sets redundancy and cache, and regulates abstract storage according to data popularity; 2, a data sharing module driven by the intelligent contract, which is used for subdividing authorization levels, setting pre-request verification, dynamically updating rules and automatically executing functions to guarantee compliance and controllability; the privacy protection technology fusion module expands zero-knowledge proof application and optimizes multi-party security calculation by adopting hybrid encryption; and 4, a data tracing and compliance auditing module which records logs to form a historical chain, traces and outputs an auditing report. According to the invention, the security, efficiency and compliance of medical data sharing can be comprehensively improved, and the application prospect is wide.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the cross - field of medical data processing and information technology, and particularly to a smart city data sharing system based on blockchain technology. Background Art

[0002] In recent years, the medical industry has been undergoing profound changes, and medical data sharing has become a key factor in promoting medical progress. With the exponential acceleration of the medical informatization process, the amount of medical data has been increasing exponentially, covering a vast and diverse range of information such as patient medical records, test reports, and imaging data. These data contain huge value. If effective sharing can be achieved, on the one hand, it can provide comprehensive reference for clinical diagnosis, helping doctors to integrate multi - source information across geographical and institutional limitations, giving accurate treatment plans, reducing the risks of misdiagnosis and missed diagnosis, and improving the quality of medical services; on the other hand, for medical research, rich data samples are the cornerstone of scientific research innovation, which can accelerate the processes of new drug research and development, disease mechanism exploration, etc., and open up new paths for overcoming difficult and complicated diseases.

[0003] In the traditional medical data sharing mode, the data storage and management architecture is the primary pain point. Most medical institutions adopt centralized storage, that is, gathering a vast amount of medical data in a single data center. This architecture has drawbacks. The integration and storage of data are highly centralized, lacking a risk - dispersing mechanism, with weak security and a high risk of privacy leakage. Internal illegal operations are impossible to guard against completely. Driven by interests, some individuals privately sell data, further exacerbating the privacy crisis. On the other hand, in the face of the explosive growth of data, centralized storage is overwhelmed. The storage cost soars like a runaway wild horse. The costs of purchasing, maintaining large - scale storage devices and continuous expansion are a heavy burden on medical institutions; at the same time, the retrieval and access efficiency is low. A large amount of data is piled up in one place, and the query response is slow, seriously delaying the normal operation of medical services.

[0004] There are also many problems in the implementation level of data sharing rules. Currently, it mainly relies on manual management processes. From the authorization of data owners to the acquisition of data by users, the links are cumbersome and complex. When medical institutions cooperate, they need to spend a lot of time and energy negotiating authorization details and signing agreements, and there is a lack of unified and transparent norms, which is extremely likely to breed irregular sharing chaos. The definition of data usage rights among different institutions is vague, resulting in chaotic authorization. Some data is used beyond the scope, while some legitimate needs are blocked due to the sluggish process and are difficult to meet the strict compliance requirements of medical data sharing, greatly hindering the in - depth exploration and full release of the value of medical data.

[0005] The blockchain technology emerged as the times require. With characteristics such as decentralization, immutability, and traceability, it has lit a ray of hope for breaking the deadlock of medical data sharing. It breaks the drawbacks of traditional centralized storage, distributes data storage among numerous nodes, reduces the risk of single-point failures, and strengthens privacy protection. The intelligent contract mechanism is expected to automate the execution of sharing rules, enhancing transparency and efficiency. However, most existing blockchain-based medical data sharing solutions remain at the theoretical concept or preliminary practice stage and have not yet fully and deeply integrated blockchain with the complex business requirements of medical data. Either the data storage optimization is insufficient, with redundant and inefficient blockchain storage; or the privacy protection means are single, making it difficult to cope with the high sensitivity challenges of medical data; or the intelligent contract functions are simple and crude, unable to adapt to diverse authorization scenarios and dynamic rule adjustments.

[0006] This invention precisely targets these pain points, conducts in-depth research, and is committed to creating an innovative and complete blockchain-based medical data sharing system to comprehensively overcome existing problems and open up a new path for medical data sharing. Summary of the Invention

[0007] The purpose of this invention is to overcome the defects of the prior art and provide an innovative blockchain-based medical data sharing system. By integrating cutting-edge technologies such as blockchain and cryptography, it realizes the "secure storage, efficient sharing, privacy protection, and full traceability" of medical data, improves the quality of medical services, promotes the development of medical research, and safeguards the legitimate rights and interests of all parties.

[0008] Data Storage and Blockchain Mapping Module: 1) Data Hierarchical Storage Structure: (1) It has a data digest generation and storage sub-module, which uses the salted SHA-256 hashing algorithm to generate data digests. The salt value is generated based on the exclusive identifier of the medical institution and the precise timestamp of data generation to ensure the uniqueness and stability of the digest, and it is stored on the blockchain in the form of a structure including the data hash value, data source, generation time, and original data index identifier; (2) It also includes an original data distributed storage sub-module, which relies on IPFS to store original medical data, uses content-based hashing as the data identifier to ensure retrieval efficiency, simultaneously builds a local cache index mechanism to improve retrieval speed, and implements a multi-copy redundancy storage strategy to back up data on multiple geographically dispersed IPFS nodes, and verifies the consistency of replicas through the verification function Verif ycopy (D original ,D copy ) to ensure data integrity. 2) Blockchain Storage Optimization Function: Introduce the data heat factor h, combine the newly added data volume n per unit time and the current available storage space s of the blockchain, and dynamically adjust the data digest storage strategy through the storage cost optimization function C store (n, s, h). When the data heat is high, give priority to immediately storing the digest. Conversely, calculate the delay duration T based on the remaining time and data growth delay=(s threshold - s) / n * k(s threshold is the storage threshold, and k is the adjustment coefficient) for delayed storage; also use the abstract storage priority scoring function Score priority (D)= w 1 * e + w 2 *(1 / t valid )+ w 3 * l privacy (e is the urgency level, t valid is the validity period, l privacy is the privacy level, and w 1 , w 2 , w 3 are weight coefficients) to score and sort according to data characteristics, and preferentially store the key data abstracts.

[0009] Smart contract-driven data sharing module: 1) Smart contract architecture: (1) Include the data owner contract, breaking through the limitations of traditional authorization, which can subdivide the authorization levels, such as setting the "can comment but not modify" permission, and authorizing through the function Grant multi (ID user , D, l auth ) and record the authorization information (ID user , D, l auth , T auth , T expire ) in the contract list, and at the same time equipped with an authorization revocation mechanism, the function Revoke auth (ID user , D) can delete the authorization according to the owner's instruction and notify the user; (2) Also include the data user contract, with a pre-request verification link in the front, and the function PreVerif yuser (ID user , ID data ) screens the user's preliminary authorization qualifications according to the whitelist, cooperation agreement, etc., and only after passing can a formal request be initiated. And every time the user completes a key operation, the details are fed back to the contract independent log area through the function Feedback use (O type , D, T op ); (3) And the sharing rule contract, building a dynamic rule adjustment mechanism, the function Update rule (newRuleSet, T eff ) updates the rule set newRuleSet in a timely manner according to laws and regulations, and feedback from recent events, and pushes notifications to all parties before taking effect. At the same time, it supports cross-institutional customization of rules, and the function Adapt inst (ID inst , rule inst ) embeds the institution-specific rule rule inst (IDinst (for institutional identification). 2) Automatic execution functions: (1) It has a function E for optimizing the request verification process share (req, rule), which verifies the user access request in multiple dimensions. In addition to the conventional identity and data identification verification, for scenarios such as scientific research, it links to an external scientific research management system to verify information such as project filing and ethical compliance. When risks such as abnormal cross-regional requests and massive downloads in a short period are found during the verification, it warns the owner and administrator through the function Warn risk (req, riskType); (2) It also includes an access control execution function, which adopts a progressive authorization strategy for complex data interaction requirements. The function Progressive grant (reqStage, ID user , D) assigns appropriate permissions according to the project stage, and at the same time sets a timeout control mechanism. When the function opens the access channel, it starts a timer. If the operation is not completed within the specified time T timeout , the channel is automatically closed, and the function Ttimeout control (ID user , D) records the timeout event for investigation and notification.

[0010] Privacy protection technology integration module: 1) Zero-knowledge proof application model: (1) It includes a function for supporting complex assertion proofs. For a complex assertion P such as "the patient is 30 - 50 years old, has a specific chronic disease, and has no major surgery in the past year" complex , the extended proof generation function G zkp (P complex , D) disassembles the assertion into sub-assertions and generates corresponding zero-knowledge proof components π 1 , π 2 , …, π n , and the data user verifies the sub-proofs according to the assertion logic through the verification function V zkp ((π 1 , π 2 , …, π n ), P comple x); (2) It also has a function for extending and reusing the proof validity. It constructs a proof reuse mechanism. After the data owner generates the zero-knowledge proof π of the assertion P, it stores it in a specific area of the blockchain, stores the associated validity period and the scenario label T agscene , and other users can quickly reuse and confirm through the reuse verification function R zkp (π, P, Tag scene ) in the same scenario and within the validity period. And in long-term tracking scenarios such as chronic disease management, the link function Link zkp (π prev , π next)The concatenation of each stage proves that users can trace back the data verification trajectory along the chain. 2) The collaborative model of homomorphic encryption and multi-party secure computation: (1) It has the function of optimizing the adaptability of encryption algorithms. In view of the differences in medical data types, a hybrid encryption algorithm is adopted. Text data is encrypted by the BFV algorithm to ensure basic security and frequent operation requirements, and image data is encrypted by the FHEW algorithm to strengthen privacy protection. Through the dynamic encryption selection function Select enic (D type )Automatically switches according to the data type, and according to the number of participating institutions n share 、and the real-time security threat level threatLevel (evaluated by the security monitoring system), the encryption parameters are optimized in real time through the parameter adjustment function Adjust param (n share ,threatLevel); (2) It also includes the function of refining the multi-party secure computation process. Before starting the multi-party secure computation protocol, the authentication of participating parties is strengthened. The multi-factor authentication function Auth mpc (ID inst ,Key pub ,Bio feat )Comprehensively verifies the institutional identity identifier ID inst 、the public key Key pub and the biometric characteristics (pre-stored in the blockchain). After jointly calculating to obtain the encrypted statistical result E(S), the result verification function Verify mpc (E(S), rule comp )Verifies according to the preset rules and the expected result range. If it is abnormal, the audit function Vudit mpc (E(S), Log comp )Traces back the calculation log Log comp to troubleshoot problems.

[0011] Data traceability and compliance audit module: 1) Operation log recording model: In the blockchain, a log record containing the operation time T op 、、the identity ID of the operation subject op (owner, user, etc.), the identifier ID of the operation object obj (data digest or original data identifier) and the operation details description Desc op is generated for each data operation. With the help of the log storage function S log (L), it is stored in chronological order to form an immutable operation history chain. 2) Traceability and audit functions: It has a traceability function T race (ID obj ,T start ,T end ), according to the given data object identifier and time interval, accurately retrieves the operation history from the blockchain log and restores the data flow path; it also includes a compliance audit function A udit (rule, Lset ), based on the compliance rule set rule and the operation log set L set Review the logs and output an audit report covering the number and type of illegal operations and the entities involved.

[0012] The advantages of the present invention are:

[0013] 1. Innovative data hierarchical storage combined with blockchain optimization strategy effectively balances data integrity verification and storage resource limitations, greatly improves system scalability, reduces storage costs, and adapts to the rapid growth of medical data.

[0014] 2. The sophisticated smart contract system covers multi-role and multi-level authorization management, and cooperates with automatic execution functions to realize the automation and transparency of data sharing processes, significantly improve sharing efficiency, reduce human errors and illegal operations, and protect the rights and interests of data owners.

[0015] 3. The integration of cutting-edge multiple privacy protection technologies provides precise protection for each link of data sharing. Whether it is complex assertion verification, real-time consultation interaction, or long-term data tracking and analysis, it can ensure the privacy security of sensitive medical data and overcome the industry's privacy problems.

[0016] 4. The powerful logging, tracing and auditing functions based on blockchain give the system the ability to supervise data throughout the process. The data flow path is clear and traceable, and illegal operations are nowhere to hide, which greatly enhances the credibility of the system and meets the strict compliance requirements of the medical industry. BRIEF DESCRIPTION OF THE DRAWINGS The drawings described herein are used to provide a further understanding of the embodiments of the present invention, constitute a part of the present invention, and do not constitute a limitation of the embodiments of the present invention.

[0018] Figure 1 :The overall architecture diagram of the medical data sharing system based on blockchain.

[0019] Figure 2 : Functional diagram of data storage module.

[0020] Figure 3 : Functional diagram of the privacy protection module.

[0021] Figure 4 :Smart contract module functional diagram.

[0022] Figure 5 : Functional diagram of data traceability and audit module.

[0023] Figure 6 :Detailed step diagram of system data sharing process.

[0024] Figure 7 :Schematic diagram of zero-knowledge proof application model.

[0025] Figure 8 : Schematic diagram of the collaborative model of homomorphic encryption and multi-party secure computation.

[0026] Figure 9 : Interaction diagram of key links for privacy protection.

[0027] Figure 10 : Schematic diagram of dynamic adjustment of data storage.

[0028] Figure 11 : Trigger diagram for rule update of smart contract. Specific implementation manners

[0030] Implementation example 1

[0031] Appendix Figures 1-5 shows the overall architecture diagram of the medical data sharing system based on blockchain and the function diagrams of each functional module. Data producers such as medical institutions need to ensure stable and reliable network connection when accessing the system, and the connection status can be detected by regularly sending heartbeat packets. If the network is interrupted, the system automatically starts the reconnection mechanism and attempts to re-establish the connection. The number of reconnection attempts can be set to three, and the interval time between each attempt gradually increases, such as 10 seconds for the first time, 20 seconds for the second time, and 30 seconds for the third time.

[0032] Configure the data digest generation tool locally and strictly generate the data digest according to the salted SHA-256 algorithm. The generation of the salt value should combine the unique identifier of the medical institution and the timestamp accurate to milliseconds to ensure the uniqueness and stability of the digest. For example, the unique identifier of the medical institution can be the code uniformly assigned by the health department, and the timestamp accurate to milliseconds can effectively prevent the repeated generation of the digest.

[0033] Upload the original data to the IPFS distributed storage network. During the upload process, the upload progress is monitored in real time, and the user can understand the upload status through the progress bar or percentage display. If the upload is interrupted during the process, the system automatically retries the upload, and the number of retries can be set according to the actual situation, for example, up to five times. At the same time, in order to improve the upload efficiency, the large file can be split into small pieces for upload, and each small piece is marked after successful upload, so that only the unsuccessfully uploaded small pieces need to be re-uploaded in case of interruption.

[0034] Register the institution information on the blockchain. The registration information should include detailed information such as the institution name, address, contact information, and qualification certificate. During the registration process, the information is encrypted to ensure the security and integrity of the information. Advanced encryption algorithms, such as the national cryptographic SM2 algorithm, can be used to encrypt the registration information to prevent the information from being tampered with or stolen.

[0035] Establish an index link PreVerify with the data digest user(ID user , ID data ), the link establishment process should adopt a secure and reliable method to ensure the accuracy and stability of the link. The hash algorithm can be used to process the data digest to generate a unique index identifier, and then this identifier is associated with the institutional information to establish an index link.

[0036] Implementation Example 2

[0037] Appendix Figure 6 shows the detailed steps diagram of the system data sharing process. When the data user has a data access requirement, first, under the data user contract framework, through the pre-request verification function PreVerify user (ID user , ID data ) to verify its own qualifications. The verification process should include the verification of the user's identity, the rationality review of the data usage purpose, etc. For example, the user's identity information can be verified by comparing it with the user database to ensure its authenticity and validity; at the same time, the description of the usage purpose submitted by the user is reviewed to ensure that the usage purpose complies with the requirements of laws, regulations and the medical industry norms.

[0038] If the verification passes, a formal request is sent to the data owner. The request should include information such as a detailed description of the usage purpose and the required data identifiers. The description of the usage purpose should be specific and clear. For example, it is used for the research of a certain specific disease, clinical diagnosis, etc.; the required data identifiers should be accurate to specific data fields or data sets so that the data owner can accurately judge whether to authorize the access.

[0039] After receiving the request, the data owner makes an authorization decision through the authorization function Grant multi (ID user , D, l auth ) in the data owner contract. The authorization decision-making process should consider multiple factors, such as the sensitivity of the data, the user's credibility, the urgency of the usage purpose, etc. For example, if the data involves sensitive information of patients, such as ID numbers, medical records, etc., the authorization decision should be more cautious; if the user has a high credibility or the usage purpose is very urgent, such as for saving a patient's life, the authorization conditions can be appropriately relaxed.

[0040] If the authorization is approved, the authorization information is recorded on the blockchain. The recording process should ensure the accuracy and immutability of the information. The distributed ledger technology of the blockchain can be used to store the authorization information on multiple nodes, and the consensus mechanism is used to ensure the consistency of the information. At the same time, the authorization information is encrypted to prevent the information from being stolen or tampered with.

[0041] Notify the user of the authorization result. The notification can be done in a variety of ways, such as internal mail, email, SMS, etc., to ensure that the user can receive the authorization result in a timely manner. The notification content should include key information such as authorization details and validity period, so that the user can reasonably arrange the data usage plan.

[0042] The user automatically executes function E based on the authorization share (req, rule) access data. During the access process, the authorization scope and usage rules should be strictly followed, and data should not be used beyond the authorization scope. At the same time, the system should monitor data access in real time, such as access time, access times, access locations, etc., to ensure the safe use of data.

[0043] Each time a key operation is completed, such as 50% of data download is completed, a stage of data analysis is completed, etc., the Feedback function is used to generate a feedback message. use (O type , D, T op ) Real-time feedback of operation details to the independent contract log area. The feedback information should include detailed information such as operation type, operation object, operation time, etc., so that the data owner can understand the use of the data in a timely manner.

[0044] Implementation Example 3

[0045] Attached Figures 7-11 The implementation details of privacy protection in the data sharing process are shown. In data verification scenarios, such as when a telemedicine consultation needs to verify some of the patient's data features, if it is a complex assertion verification, after the doctor initiates the request, the system background generates a function G through proof zkp (P complex ,D) Quickly generate sub-assertion proof components. The generation process should use efficient algorithms and parallel computing technologies to ensure the speed and accuracy of proof generation. For example, a distributed computing framework can be used to split complex assertions into multiple sub-assertions, distribute them to multiple computing nodes for simultaneous proof generation, and then merge and verify the generated sub-proof components.

[0046] Data users pass the verification function V in a short time zkp ((π 1 , π 2 , …, π n ), P complex ) receives and verifies the results. The verification process should be carried out strictly in accordance with the algorithm and protocol of zero-knowledge proof to ensure the accuracy and privacy of the verification. For example, the interactive verification method of zero-knowledge proof can be used to verify the validity of the sub-proof components through multiple interactions, while ensuring that no sensitive information is leaked during the verification process.

[0047] If it is a simple real-time indicator verification, such as confirming the patient's temperature range, through the interactive function Izkp (P, D, rounds) completes the verification efficiently within the specified number of interaction rounds. The setting of the interaction rounds should be adjusted according to the importance and urgency of the data. For example, for urgent medical situations such as saving a patient's life, fewer interaction rounds can be set to complete the verification as soon as possible; for general medical situations, more interaction rounds can be set to ensure the accuracy of the verification.

[0048] When multiple institutions jointly conduct medical data statistical analysis, each institution first passes through the multi-factor authentication function Auth mpc (ID inst , Key pub , Bio feat ) to complete the identity authentication. The authentication process should adopt a strict identity authentication mechanism to ensure the legality and security of the participating institutions. For example, an identity authentication method based on the public key infrastructure (PKI) can be adopted, combining multiple factors such as the institution's digital certificate, public key, and biometric characteristics for authentication to ensure the accuracy and reliability of the authentication.

[0049] After successful authentication, according to the data type, text data is encrypted by the BFV algorithm and image data is encrypted by the FHEW algorithm to participate in the joint calculation. The encryption process should adopt advanced encryption algorithms and technologies to ensure the security and privacy of the data. For example, homomorphic encryption technology can be adopted to encrypt the data and then perform joint calculations. During the calculation process, there is no need to decrypt the data, ensuring the privacy of the data.

[0050] After the calculation is completed, the result verification function Verify mpc (E(S), rule comp ) verifies the result. The verification process should be carried out strictly according to the preset rules and algorithms to ensure the accuracy and reliability of the calculation result. For example, digital signature technology can be adopted to verify the signature of the calculation result to ensure the integrity and authenticity of the result.

[0051] In case of anomalies, the audit function Audit mpc (E(S), Log comp ) conducts a retrospective investigation. The investigation process should adopt detailed audit logs and data analysis technologies to ensure that problems can be quickly located and repaired. For example, a distributed audit log system can be adopted to record and audit each step in the calculation process so that problems can be quickly traced and investigated in case of anomalies.

[0052] Implementation Example Four If the regulatory department or data owner has doubts about the usage of a certain data, through the traceability function T race (ID obj , T start , T end) Given the input data identifier and the suspicious time period, the system quickly retrieves all the operation records of this data during this period from the vast amount of log records stored in the blockchain. The retrieval process should adopt efficient indexing techniques and query algorithms to ensure that relevant records can be retrieved quickly and accurately. For example, the inverted index technique can be used to index the log records so that relevant records can be quickly located after the input data identifier and time period are provided.

[0053] Completely restore the data flow path to provide strong support for the investigation. The restoration process should adopt visualization techniques and data analysis techniques to sort out and analyze the retrieved operation records and display the data flow path in a graphical way. For example, a flowchart or a sequence diagram can be used to show the entire process of data from generation to use, so that the regulatory authorities or data owners can clearly understand the data flow situation.

[0054] Regularly (such as monthly) or when a specific event is triggered (such as a data leakage risk warning), the system relies on the compliance audit function A udit (rule, L set ) and combines the preset compliance rules with the operation log set within a period of time to automatically generate an audit report. The report generation process should adopt automation techniques and data visualization techniques to ensure the accuracy and readability of the report. For example, machine learning algorithms can be used to analyze the operation logs, automatically identify illegal operations and risk behaviors, and display them in the form of charts in the audit report, so that the regulatory authorities or data owners can quickly understand the compliance situation of the system.

[0055] The report details information such as the number, type, and involved institutions or personnel of the illegal operations, providing a basis for subsequent rectification and accountability to ensure that the system always operates in compliance. The report content should be specific and clear, including detailed descriptions of illegal operations, analysis of the reasons for violations, and rectification suggestions, so that the regulatory authorities or data owners can take effective measures for rectification and accountability to ensure the compliance operation of the system.

Claims

1. A smart city data sharing system based on blockchain technology, which realizes the safe storage, efficient sharing, privacy protection and full traceability of medical data, improves the quality of medical services, promotes the development of medical research and protects the legitimate rights and interests of all parties, characterized by: Contains: data storage and blockchain mapping module, smart contract-driven data sharing module, privacy protection technology integration module and data traceability and compliance audit module: The data storage and blockchain mapping module can realize hierarchical storage and blockchain mapping management of medical data, including: data hierarchical storage structure and blockchain storage optimization function components; the data hierarchical storage structure has a data summary generation and storage submodule, which uses a salted SHA-256 hash algorithm to generate a data summary. The salt value is generated based on the exclusive identification of the medical institution and the precise timestamp of data generation to ensure the uniqueness and stability of the summary, and is stored on the blockchain in the form of a structure containing a data hash value, a data source, a generation time and an original data index identifier; the data hierarchical storage structure includes a raw data distributed storage submodule, which relies on IPFS to store raw medical data, uses content-based hashes as data identifiers to ensure retrieval efficiency, and at the same time builds a local cache index mechanism to improve retrieval speed, and implements a multi-copy redundant storage strategy to back up data at multiple geographically dispersed IPFS nodes, and through the verification function Verify copy (D original , D copy ) Verify the consistency of the replicas to ensure data integrity; The blockchain storage optimization function is expressed as follows: introducing the data heat factor h, combining the amount of new data per unit time n, and the current available storage space s of the blockchain, through the storage cost optimization function C store (n, s, h) dynamically adjusts the data summary storage strategy. When the data is hot, the summary is stored immediately first. Otherwise, the delay time T is calculated according to the remaining time and data growth. delay =(s threshold -s) / n*k delayed storage, where s threshold is the storage threshold, k is the adjustment coefficient; The blockchain storage optimization function uses the summary storage priority scoring function Score priority (D) = w1*e+w2*(1 / t valid )+w3*l privacy Sorting by data characteristics, giving priority to storing key data summaries; Among them, e is the urgency, t valid For validity period, privacy is the privacy level, w1, w2, w3 are weight coefficients; The smart contract-driven data sharing module can realize the sharing process under the control of medical data smart contracts, including: smart contract architecture and automatic execution function components; the smart contract architecture includes a data owner contract, breaking through the limitations of traditional authorization, and can subdivide the authorization level through the function Grant multi (ID user ,D,l auth Authorize and record authorization information (ID user ,D,l auth , T auth , T expire ) in the contract list, and is equipped with an authorization revocation mechanism, function Revoke auth (ID user , D) can delete authorization and notify users according to the owner's instructions; the smart contract architecture includes a data user contract, a pre-request verification link, and a function PreVerify user (ID user , ID data ) Screen the user's preliminary authorization qualifications according to the whitelist, cooperation agreement, etc., and only after passing can a formal request be initiated. And every time the user completes a key operation, the user will receive a feedback function. use (O type , D, T op ) Feedback details to the independent log area of ​​the contract; the smart contract architecture can build a dynamic rule adjustment mechanism, function Update rule (nweRuleSet, T eff ) Update the rule set newRuleSet in a timely manner based on laws, policies, and recent event feedback, and push notifications to all parties before it takes effect. It also supports cross-institutional custom rules, and the function Adapt inst (ID inst , rule inst ) Embedded institution-specific rules inst ; The automatic execution function has a request verification process optimization function E share (req, rule), multi-dimensional verification of user access requests. When abnormal cross-region requests, massive downloads in a short period of time, and other risks are found during the verification, the function Warn is used risk (req, riskType) to warn the owner and administrator; the automatic execution function includes the access control execution function, which adopts a progressive authorization strategy in the face of complex data interaction requirements. The function Progressive grant (reqStage, ID user ,D) Grant adaptation permissions according to the project stage, and set up a timeout control mechanism. When the function opens the access channel, the timer is started. If the specified time T is exceeded, timeout The operation is not completed, the channel is automatically closed, and the function Timeout control (ID user ,D) record timeout event notification and troubleshooting; The privacy protection technology fusion module is used to ensure the privacy security of medical data during the sharing process, including: zero-knowledge proof application model and homomorphic encryption and multi-party secure computing collaborative model components; the zero-knowledge proof application model includes complex assertion proof support functions, for complex assertion P complex , extended proof generation function G zkp (P complex , D) Disassemble the assertion into sub-assertions and generate the corresponding zero-knowledge proof components π1, π2, ..., π n , data users pass the verification function V zkp ((π1, π2, ..., π n ), P complex ) Verify the sub-proof according to the assertion logic; the zero-knowledge proof application model has the function of proof validity extension and reuse, and constructs a proof reuse mechanism. After the data owner generates the zero-knowledge proof π of the assertion P, it is stored in a specific area of ​​the blockchain and associated with the validity period With scene tag scene , other users in the same scenario and within the validity period can reuse the verification function R zkp (π,P,Tag scene ) Rapid reuse confirmation, and in long-term tracking scenarios such as chronic disease management, the link function Link zkp (π prev , π next ) The proofs of each stage are connected in series, and the user can trace back the data verification trajectory; the homomorphic encryption and multi-party secure computing collaborative model has the function of adaptive optimization of encryption algorithms. In view of the differences in medical data types, a hybrid encryption algorithm is adopted. Text data is encrypted with the BFV algorithm to ensure basic security and frequent computing requirements, and image data is encrypted with the FHEW algorithm to enhance privacy protection. Through the dynamic encryption selection function Select enic (D type ) automatically switches according to the data type and the number of participating institutions n share , real-time security threat level threatLevel, through parameter adjustment function Adjust param (n share , threatLevel) to optimize encryption parameters in real time; the homomorphic encryption and multi-party secure computing collaborative model includes a multi-party secure computing process refinement function, before starting the multi-party secure computing protocol, strengthening the identity authentication of the participants, and a multi-factor authentication function Auth mpc (ID inst ,Key pub , Bio feat ) Comprehensive verification agency identity ID inst 、Public Key pub and biometrics (pre-stored in blockchain), after joint calculation to obtain encrypted statistical results E(S), the result verification function Verify mpc (E(S), rule comp ) Verify according to preset rules and expected result range, and audit function if abnormal mpc (E(S), Log comp ) Backtracking calculation log Log comp Troubleshooting; The data traceability and compliance audit module is used to realize the traceability and compliance audit of the entire life cycle of medical data, including: an operation log recording model and a traceability and audit function component; The data traceability and compliance audit module includes an operation log recording model: a data log containing the operation time T is generated for each data operation on the blockchain. op , Operation subject identity ID op , operation object identifier and operation details description Desc op Log records, with the help of log storage function S log (L) Store in chronological order to form an unalterable operation history chain; the traceability and audit function: has a traceability function T race (ID obj , T start , T end ), based on the given data object identifier and time interval, accurately retrieve the operation history from the blockchain log and restore the data flow path; also includes compliance audit function A udit (rule,L set ), based on the compliance rule set rule and the operation log set L set Review the logs and output an audit report covering the number and type of illegal operations and the entities involved.

Citation Information

Patent Citations

  • Medical data sharing system and method based on block chain

    CN117912621A

  • Secure data sharing method and system based on block chain in smart power grid

    CN118585582A

  • Method for executing smart contract and blockchain node

    US20220066803A1

Cited By

  • Government affair block chain credible ecological architecture fused with smart contract and operation and maintenance management system

    CN120281478A

  • Private data storage sharing method and system based on block chain

    CN120528578A

  • A blockchain-based method and system for private data storage and sharing

    CN120528578B

  • Privacy data sharing method based on block chain and privacy security calculation

    CN120631855A

  • Block chain-based blood safety whole-course tracing system and method

    CN120895187A