Clinical test data safety operation system

By designing a clinical trial data security operating system, the shortcomings of the existing clinical trial systems in terms of data security, integrity and privacy are solved, and multi-level protection of clinical trial data is achieved, and the requirements of regulatory agencies and ethics committees are met.

CN120180488APending Publication Date: 2025-06-20安徽海汇临研科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510240209.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The existing clinical trial system has shortcomings in data security, integrity and privacy, making it difficult to effectively protect clinical trial data.

Method used

A clinical trial data security operating system was designed, including data encryption end, access control end, data backup and recovery end, audit log end, security audit and monitoring end, case tracking and privacy protection end, security training and awareness end, through data communication between these modules, multi-level protection of clinical trial data is achieved.

Benefits of technology

It effectively improves the safety and privacy of clinical trial data, ensures the integrity and reliability of data, and meets the requirements of regulatory agencies and ethics committees for clinical trial data protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180488A_ABST
    Figure CN120180488A_ABST
Patent Text Reader

Abstract

The invention discloses a clinical test data safety operation system which is communicated with a clinical test data system. The clinical test data safety operation system comprises a data encryption end, an access control end, a data backup and recovery end, an audit log end, a safety audit and monitoring end, a case tracking and privacy protection end and a safety training and consciousness end. The data encryption end, the access control end, the data backup and recovery end, the auditing log end, the security auditing and monitoring end, the case tracking and privacy protection end and the security training and consciousness end are in data communication. According to the invention, the security and privacy of the data in the clinical test system can be protected, and the integrity and reliability of the data can be ensured, so that the requirements of supervision institutions and ethical committee on clinical test data protection can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of clinical drug trials, and particularly to a clinical trial data security operation system. Background Art

[0002] Clinical trials refer to any systematic study of drugs in humans (patients or healthy volunteers) to confirm or reveal the effects of the test drugs, adverse reactions, and the absorption, distribution, metabolism, and excretion of the test drugs, with the aim of determining the efficacy and safety of the test drugs. Simply put, clinical trials investigate the impact of medical products and medical devices on the course of human diseases, but they are conducted in a controlled experimental environment. However, participating in a clinical trial is not something that can be done at will; it also depends on luck. First of all, the hospital where the patient seeks medical treatment must conduct projects that match the patient's indications. In addition, each clinical trial has different inclusion and exclusion criteria, and the patient's own situation also needs to meet a certain threshold before they can participate; it is not something that can be done casually.

[0003] In the prior art, a clinical trial system is generally used to manage all clinical trials, such as the identity information of trial patients, medical record data, trial data, etc. However, the security, integrity, and privacy of existing clinical trial systems are very low. Summary of the Invention

[0004] In order to solve the above problems, the present invention provides a clinical trial data security operation system.

[0005] To achieve the above object, the technical solution of the present invention is as follows:

[0006] A clinical trial data security operation system, the clinical trial data security operation system is connected to a clinical trial data system, and the clinical trial data security operation system includes a data encryption end, an access control end, a data backup and recovery end, an audit log end, a security audit and monitoring end, a case tracking and privacy protection end, and a security training and awareness end, and data communication occurs between the data encryption end, the access control end, the data backup and recovery end, the audit log end, the security audit and monitoring end, the case tracking and privacy protection end, and the security training and awareness end.

[0007] In a preferred embodiment of the present invention, the data encryption end includes a data transmission encryption module, a data storage encryption module, a data field-level encryption module, a data access control and key management module, and a strong password and password policy module. The data transmission encryption module includes a data transmission encryption unit, which is used to encrypt the data in the clinical trial system during the transmission process; the data storage encryption module includes a data storage encryption unit, which is used to encrypt and protect the data by using an encryption algorithm when the clinical trial system stores the data in a database or a file system; the data field-level encryption module includes a data field-level encryption unit, which is used to implement field-level encryption for sensitive personally identifiable information or other important data fields; the data access control and key management module includes a data access control and key management unit, which is used to restrict the clinical trial system so that only authorized users can access and decrypt the data through an access control mechanism; the strong password and password policy module includes a strong password and password policy unit, which is used to enhance the security of data encryption.

[0008] In a preferred embodiment of the present invention, the access control end includes a user authentication module, a user role and permission management module, a data field-level access control module, an audit log module, an IP address filtering and access control list module, and a two-factor authentication module. The user authentication module includes a user authentication unit, which is used to require the user to perform authentication; the user role and permission management module includes a user role and permission management unit, which is used to set different user roles, and each role has corresponding permissions and access levels; the data field-level access control module includes a data field-level access control unit, which is used to implement data field-level access control to restrict the user to only access the data fields for which they have permissions; the audit log module includes an audit log unit, which is used to record the operation and access logs of the user; the IP address filtering and access control list module includes an IP address filtering and access control list unit, which is used to restrict the access of specific IP addresses or networks based on the method of IP address filtering or access control list; the two-factor authentication module includes a two-factor authentication unit, which is used to enhance the access security.

[0009] In a preferred embodiment of the present invention, the data backup and recovery end includes a regular data backup module, a data backup storage module, a data recovery module, a data consistency check module, and a disaster recovery backup module. The regular data backup module includes a regular data backup unit, and the regular data backup unit is used to automatically back up clinical trial data regularly; the data backup storage module includes a data backup storage unit, and the data backup storage unit is used to back up data; the data recovery module includes a data recovery unit, and the data recovery unit is used to restore the backup data to the clinical trial system and recover the integrity of the clinical trial data when the clinical trial system fails or data is lost; the data consistency check module includes a data consistency check unit, and the data consistency check unit is used to perform a data consistency check during the data recovery process to ensure that the backup data is consistent with the data in the last normal state of the system; the disaster recovery backup module includes a disaster recovery backup unit, and the disaster recovery backup unit is used to perform disaster recovery backup in addition to regular backup.

[0010] In a preferred embodiment of the present invention, the audit log end includes an operation log recording module, an abnormal event recording module, a data change recording module, an audit log retention module, and an audit log reporting module. The operation log recording module includes an operation log recording unit, and the operation log recording unit is used to record the operations performed by users in the clinical trial system; the abnormal event recording module includes an abnormal event recording unit, and the abnormal event recording unit is used to record the abnormal events occurring in the clinical trial system; the data change recording module includes a data change recording unit, and the data change recording unit is used to record any modification, deletion, or addition operations performed on the data in the clinical trial system; the audit log retention module includes an audit log retention unit, and the audit log retention unit is used to reasonably retain the audit log and make it non-tamperable; the audit log reporting module includes an audit log reporting unit, and the audit log reporting unit is used to provide the function of generating an audit log report for regular auditing and risk assessment.

[0011] In a preferred embodiment of the present invention, the security audit and monitoring terminal includes a security event logging module, a security policy and rule audit module, a user behavior monitoring module, a security vulnerability scanning and vulnerability management module, a data access monitoring module, and a real-time alarm and response module. The security event logging module includes a security event logging unit for recording security events occurring in the clinical trial system; the security policy and rule audit module includes a security policy and rule audit unit for auditing the security policies and rules in the clinical trial system to ensure compliance with relevant security standards and regulatory requirements; the user behavior monitoring module includes a user behavior monitoring unit for monitoring the behavior of users in the clinical trial system; the security vulnerability scanning and vulnerability management module includes a security vulnerability scanning and vulnerability management unit for regularly scanning the clinical trial system for security vulnerabilities; the data access monitoring module includes a data access monitoring unit for monitoring access to sensitive data; the real-time alarm and response module includes a real-time alarm and response unit that provides a real-time alarm function for the clinical trial system, capable of issuing an alarm in a timely manner when abnormal activities or security events are detected and taking corresponding response measures.

[0012] In a preferred embodiment of the present invention, the case tracking and privacy protection terminal includes an anonymization and desensitization module, a data access permission control module, a case tracking and audit module, a data encryption and transmission security module, a case data backup and recovery module, and a privacy protection policy and compliance module.

[0013] In a preferred embodiment of the present invention, the anonymization and de - sensitization module includes an anonymization and de - sensitization unit, which is used to anonymize and de - sensitize sensitive personal identity information to protect the privacy of case data; the data access permission control module includes a data access permission control unit, which is used to enable the clinical trial data system to have a strict data access permission control mechanism to ensure that only authorized personnel can access specific case data; the case tracking and auditing module includes a case tracking and auditing unit, which is used to record the access history and operation logs of case data; the data encryption and transmission security module includes a data encryption and transmission security unit, which is used to perform an encryption mechanism for the transmission and storage of case data to ensure the security of data during transmission; the case data backup and recovery module includes a case data backup and recovery unit, which is used to regularly back up case data to prevent data loss or damage; the privacy protection policy and compliance module includes a privacy protection policy and compliance unit, which is used to establish and comply with relevant privacy protection policies and comply with applicable privacy protection regulations and standards.

[0014] In a preferred embodiment of the present invention, the security training and awareness terminal includes a security training materials and courses module, a user security awareness reminder module, a password management requirement module, a multi - factor authentication module, a security prompt and alert module, and a security awareness activity and reward mechanism module.

[0015] In a preferred embodiment of the present invention, the security training materials and courses module includes a security training materials and courses unit, which is used to provide security training materials and courses; the user security awareness reminder module includes a user security awareness reminder unit, which is used to regularly send security awareness reminders to enhance users' attention and concern for data security; the password management requirement module includes a password management requirement unit, which is used to require users to use strong passwords and regularly prompt users to modify their passwords; the multi - factor authentication module includes a multi - factor authentication unit, which is used to support multi - factor authentication; the security prompt and alert module includes a security prompt and alert unit, which is used to monitor users' operation behaviors and issue alerts when anomalies or potential security risks are found; the security awareness activity and reward mechanism module includes a security awareness activity and reward mechanism unit, which is used to organize security awareness activities to increase users' attention and participation in data security.

[0016] The beneficial effects of the present invention are:

[0017] The present invention can protect the security and privacy of data in a clinical trial system, ensure the integrity and reliability of the data, so as to meet the requirements of regulatory agencies and ethics committees for the protection of clinical trial data. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0019] Figure 1 It is a schematic structural diagram of the data encryption end;

[0020] Figure 2 It is a schematic structural diagram of the access control end;

[0021] Figure 3 It is a schematic structural diagram of the data backup and recovery end;

[0022] Figure 4 It is a schematic structural diagram of the audit log end;

[0023] Figure 5 It is a schematic structural diagram of the security audit and monitoring end;

[0024] Figure 6 It is a schematic structural diagram of the case tracking and privacy protection end;

[0025] Figure 7 It is a schematic structural diagram of the security training and awareness end. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] In order to make the technical means, creative features, achieved purposes and functions of the present invention easy to understand, the present invention will be further described below.

[0027] See Figures 1-7 , the clinical trial data security operation system provided by the present invention is connected to the existing clinical trial system for data communication, so as to protect the data in the clinical trial system.

[0028] The clinical trial data security operation system provided by the present invention can also be directly set in the clinical trial system, so as to protect the data in the clinical trial system.

[0029] The clinical trial data security operation system includes a data encryption end 1, an access control end 2, a data backup and recovery end 3, an audit log end 4, a security audit and monitoring end 5, a case tracking and privacy protection end 6, and a security training and awareness end 7. The data encryption end 1, the access control end 2, the data backup and recovery end 3, the audit log end 4, the security audit and monitoring end 5, the case tracking and privacy protection end 6, and the security training and awareness end 7 communicate with each other, and can process the data in the clinical trial system through mutual cooperation.

[0030] The data encryption end 1, the access control end 2, the data backup and recovery end 3, the audit log end 4, the security audit and monitoring end 5, the case tracking and privacy protection end 6, and the security training and awareness end 7 can directly conduct data communication through a dedicated network and dedicated line network, which can improve the security and efficiency of data transmission.

[0031] See Figure 1 , the data encryption end 1 is used to protect the security and confidentiality of the data in the clinical trial system. Through these data encryption functions, the data in the clinical trial system is protected during the transmission and storage processes, ensuring that only authorized users can access and use the data. Encryption technology is one of the important means to ensure the security of clinical trial data, which can reduce the risks of data leakage and unauthorized access, and ensure the confidentiality and integrity of clinical trial data.

[0032] The data encryption end 1 includes a data transmission encryption module 101, a data storage encryption module 102, a data field-level encryption module 103, a data access control and key management module 104, and a strong password and password policy module 105.

[0033] The data transmission encryption module includes a data transmission encryption unit 101a and a data transmission encryption database unit 101b.

[0034] The data transmission encryption unit 101a is used to provide a secure communication protocol (such as SSL / TLS) for the clinical trial system to encrypt the data during the transmission process. This can ensure that the data is encrypted during the transmission from the user device to the system server, preventing third-party eavesdropping and data tampering.

[0035] The data transmission encryption database unit 101b is used to store data transmission encryption information.

[0036] The data storage encryption module 102 includes a data storage encryption unit 102a and a data storage encryption database unit 102b.

[0037] The data storage encryption unit 102a is used to encrypt and protect clinical trial data using an encryption algorithm when the clinical trial system stores the data in a database or a file system. This ensures that even if the data storage medium is accessed or leaked, unauthorized personnel cannot interpret or use the encrypted data.

[0038] The data storage encryption database unit 102b is used to store data storage encryption information.

[0039] The data field-level encryption module 103 includes a data field-level encryption unit 103a and a data field-level encryption database unit 103b.

[0040] The data field-level encryption unit 103a is used to perform field-level encryption on sensitive personally identifiable information or other important data fields in the clinical trial system. This means that the encrypted data is stored in the database, and only authorized users can decrypt and access the original data.

[0041] The data field-level encryption database unit 103b is used to store data field-level encryption information.

[0042] The data access control and key management module 104 includes a data access control and key management unit 104a and a data access control and key management database unit 104b.

[0043] The data access control and key management unit 104a is used to restrict access to decrypted data to authorized users only through an access control mechanism. The access control can be based on user roles, permissions, and authentication. At the same time, an effective key management mechanism is required to manage and protect the keys used by the encryption algorithm.

[0044] The data access control and key management database unit 104b is used to store data access control and key management information.

[0045] The strong password and passphrase policy module 105 includes a strong password and passphrase policy unit 105a and a strong password and passphrase policy database unit 105b.

[0046] The strong password and passphrase policy unit 105a is used to implement a strong password and passphrase policy to increase the security of data encryption, requiring users to set complex passwords and change them regularly to prevent unauthorized access.

[0047] The strong password and passphrase policy database unit 105b is used to store strong password and passphrase policy information.

[0048] See Figure 2, the access control terminal 2 ensures that only authorized users can access the clinical trial system and related clinical trial data. Through these access control functions, it can be ensured that only authorized users can access the system and related data. The access control functions help prevent unauthorized access, data leakage, and abuse, and improve the security and confidentiality of clinical trial data.

[0049] The access control terminal 2 includes a user authentication module 201, a user role and permission management module 202, a user role and permission management module 203, an audit log module 204, an IP address filtering and access control list module 205, and a two-factor authentication module 206.

[0050] The user authentication module 201 includes a user authentication unit 201a and a user authentication database unit 201b.

[0051] The user authentication unit 201a is used to authenticate the users logging in to the clinical trial system, usually by means of a username and password. Users need to provide valid credentials to log in to the system to ensure that only authorized users can access the system.

[0052] The user authentication database unit 201b is used to store user authentication information.

[0053] The user role and permission management module 202 includes a user role and permission management unit 202a and a user role and permission management database unit 202b.

[0054] The user role and permission management unit 202a is used to set different user roles for the clinical trial system, and each role has specific permissions and access levels. For example, different roles such as research doctors, research nurses, and research coordinators may have different permissions and can only access the data and functions they need.

[0055] The user role and permission management database unit 202b is used to store user role and permission management information.

[0056] The access control module 203 at the data field level includes an access control unit 203a at the data field level and an access control database unit 203b at the data field level.

[0057] The access control unit 203a at the data field level is used for the clinical trial system to implement access control at the data field level, restricting users to only access the data fields they have permissions to. This can ensure that sensitive data can only be accessed by authorized users and improve the confidentiality and privacy of the data.

[0058] The access control database unit 203b at the data field level is used for access control information at the data field level.

[0059] The audit log module 204 includes an audit log unit 204a and an audit log database unit 204b.

[0060] The audit log unit 204a is used to record the operation and access logs of users, which may specifically include login information, access time, access content, etc. The audit log can help track and monitor user behavior and provide an audit trail function to facilitate the discovery of abnormal behavior and security incidents.

[0061] The audit log database unit 204b is used to store audit log information.

[0062] The IP address filtering and access control list module 205 includes an IP address filtering and access control list unit 205a and an IP address filtering and access control list database unit 205b.

[0063] The IP address filtering and access control list unit 205a is used to provide a way based on IP address filtering or access control list for the clinical trial system to restrict access to specific IP addresses or networks. This helps prevent unauthorized external access and intrusion.

[0064] The IP address filtering and access control list database unit 205b is used to store IP address filtering and access control list information.

[0065] The two-factor authentication module 206 includes a two-factor authentication unit 206a and a two-factor authentication database unit 206b.

[0066] The two-factor authentication unit 206a is used to provide support for two-factor authentication for the clinical trial system to increase access security, requiring users to provide additional authentication methods when logging in, such as mobile phone verification codes, fingerprint recognition, or hardware tokens, etc.

[0067] The two-factor authentication database unit 206b is used to store two-factor authentication information.

[0068] See Figure 3 , the data backup and recovery end 3 is used to ensure the integrity and reliability of the data of the clinical trial system to cope with data loss, clinical trial system failures, or other unexpected situations. Through these data backup and recovery functions, the reliability and persistence of the data can be ensured. The data backup and recovery function helps protect clinical trial data from data loss, system failures, or other potential risks and ensures that the data can be restored and accessed when needed.

[0069] The data backup and recovery end 3 includes a regular data backup module 301, a data backup storage module 302, a data recovery module 303, a data consistency check module 304, and a disaster recovery backup module 305.

[0070] The regular data backup module 301 includes a regular data backup unit 301a and a regular data backup database unit 301b.

[0071] The regular data backup unit 301a is used to automatically backup clinical trial data regularly, including medical records, test results, drug information, etc. The backup frequency can be set according to requirements and risk assessment to ensure timely data backup.

[0072] The regular data backup database unit 301b is used to store regular data backup information.

[0073] The data backup storage module 302 includes a data backup storage unit 302a and a data backup storage database unit 302b.

[0074] The data backup storage unit 302a is used to backup data, specifically by storing it in an independent server, cloud storage, or other offline media to prevent the loss of data synchronized with the main system. Appropriate security measures should be taken for the backup data, such as data encryption and access control, to protect the security of the backup data.

[0075] The data backup storage database unit 302b is used to store data backup storage information.

[0076] The data recovery module 303 includes a data recovery unit 303a and a data recovery database unit 303b.

[0077] The data recovery unit 303a is used to provide a data recovery function when the clinical trial system fails or data is lost. It can restore the backup data to the system to restore the integrity of the clinical trial data. The recovery process should be reliable and traceable to ensure the accuracy and consistency of the data.

[0078] The data recovery database unit 303b is used to store data recovery information.

[0079] The data consistency check module 304 includes a data consistency check unit 304a and a data consistency check database unit 304b.

[0080] The data consistency check unit 304a is used to perform data consistency checks during the data recovery process to ensure that the backup data is consistent with the data in the last normal state of the system. This can prevent data inconsistency problems caused by damaged or incomplete backup data.

[0081] The data consistency check database unit 304b is used to store data consistency check information.

[0082] The disaster recovery backup module 305 includes a disaster recovery backup unit 305a and a disaster recovery backup database unit 305b.

[0083] The disaster recovery and backup unit 305a is used for disaster recovery and backup in addition to regular backups, that is, backing up data and storing it in distributed servers, different geographical locations, or other disaster recovery mechanisms to cope with natural disasters, fires, or other emergencies.

[0084] The disaster recovery and backup database unit 305b is used to store disaster recovery and backup information.

[0085] See Figure 4 , the audit log terminal 4 is used to record and track key activities and events in the clinical trial system to monitor and audit the security and compliance of the clinical trial system. Through the audit log function, monitoring and auditing of the operations and data access of the clinical trial system can be achieved. The audit log records key operations and events, which helps to discover potential security threats, track data changes, and ensure system compliance. In addition, the audit log can also provide traceability and evidence to support investigations and dispute resolutions.

[0086] The audit log terminal 4 includes an operation log recording module 401, an abnormal event recording module 402, a data change recording module 403, an audit log retention module 404, and an audit log reporting module 405.

[0087] The operation log recording module 401 includes an operation log recording unit 401a and an operation log recording database unit 401b.

[0088] The operation log recording unit 401a is used to record the operations performed by users in the system, including logins, data access, data modification, permission changes, etc. Each operation should contain key information such as the operation time, executor, operation type, and specific operation content.

[0089] The operation log recording database unit 401b is used to store operation log recording information.

[0090] The abnormal event recording module 402 includes an abnormal event recording unit 402a and an abnormal event recording database unit 402b.

[0091] The abnormal event recording unit 402a is used to record abnormal events that occur in the system, such as login failures, access denials, illegal access attempts, etc. The recording of abnormal events can help identify potential security threats and risks.

[0092] The abnormal event recording database unit 402b is used to store abnormal event recording information.

[0093] The data change recording module 403 includes a data change recording unit 403a and a data change recording database unit 403b.

[0094] The data change record unit 403a is used to record any modifications, deletions, additions, etc. made to the clinical trial data in the clinical trial system. Specifically, it can include recording the data content before and after modification, the modification time, and the executor.

[0095] The data change record database unit 403b is used to store data change record information.

[0096] The audit log retention module 404 includes an audit log retention unit 404a and an audit log retention database unit 404b.

[0097] The audit log retention unit 404a is used to reasonably retain the audit log and ensure it cannot be tampered with. Ensure the integrity and traceability of the audit log for future auditing and investigation.

[0098] The audit log retention database unit 404b is used to store audit log retention information.

[0099] The audit log reporting module 405 includes an audit log reporting unit 405a and an audit log reporting database unit 405b.

[0100] The audit log reporting unit 405a can provide the function of generating an audit log report for regular auditing and risk assessment. The report should include key audit events and operations to help identify potential security issues and compliance violations.

[0101] The audit log reporting database unit 405b is used to store audit log report information.

[0102] See Figure 5 The security audit and monitoring terminal 5 is used to ensure the security and compliance of the clinical trial system. Through the security audit and monitoring function, security events and potential security risks can be detected and addressed in a timely manner to ensure the security and compliance of the system. Monitoring user behavior and data access helps prevent and guard against data leakage and abuse, improving the security and credibility of the system. At the same time, the real-time alarm and response function can strengthen the monitoring and response capabilities for security events, improving the security protection level of the system.

[0103] The security audit and monitoring terminal 5 includes a security event log recording module 501, a security policy and rule audit module 502, a user behavior monitoring module 503, a security vulnerability scanning and vulnerability management module 504, a data access monitoring module 505, and a real-time alarm and response module 506.

[0104] The security event log recording module 501 includes a security event log recording unit 501a and a security event log recording database unit 501b.

[0105] The security event logging unit 501a is used to record security events that occur in the system, such as login failures, abnormal access, data leaks, etc. The security event log should contain key information, such as event time, event type, executor, etc., for tracking and analyzing security events.

[0106] The security event logging database unit 501b is used to store security event logging information.

[0107] The security policy and rule auditing module 502 includes the security policy and rule auditing unit 502a and the security policy and rule auditing database unit 502b.

[0108] The security policy and rule auditing unit 502a is used to audit the security policies and rules in the system to ensure compliance with relevant security standards and regulatory requirements. It includes auditing and monitoring aspects such as access control, password policies, data encryption, etc.

[0109] The security policy and rule auditing database unit 502b is used to store security policy and rule auditing information.

[0110] The user behavior monitoring module 503 includes the user behavior monitoring unit 503a and the user behavior monitoring database unit 503b.

[0111] The user behavior monitoring unit 503a is used to monitor the behavior of users in the system, including login activities, access permission changes, data operations, etc. By analyzing user behavior, abnormal activities and potential security risks can be detected in a timely manner.

[0112] The user behavior monitoring database unit 503b is used to store user behavior monitoring information.

[0113] The security vulnerability scanning and vulnerability management module 504 includes the security vulnerability scanning and vulnerability management unit 504a and the security vulnerability scanning and vulnerability management database unit 504b.

[0114] The security vulnerability scanning and vulnerability management unit 504a is used to regularly scan the system for security vulnerabilities, discover potential vulnerabilities and weaknesses, and perform timely repairs and vulnerability management.

[0115] The security vulnerability scanning and vulnerability management database unit 504b is used to store security vulnerability scanning and vulnerability management information.

[0116] The data access monitoring module 505 includes the data access monitoring unit 505a and the data access monitoring database unit 505b.

[0117] The data access monitoring unit 505a is used to monitor the access to sensitive data, including who, when, and how the sensitive data is accessed. It ensures that only authorized personnel can access sensitive data and prevents data leakage and abuse.

[0118] The data access monitoring database unit 505b is used to store data access monitoring information.

[0119] The real-time alarm and response module 506 includes the real-time alarm and response unit 506a and the real-time alarm and response database unit 506b.

[0120] The real-time alarm and response unit 506a is used to provide a real-time alarm function for the clinical trial system. It can issue an alarm in a timely manner when abnormal activities or security incidents are detected and take corresponding response measures, such as blocking access, notifying the security administrator, etc.

[0121] The real-time alarm and response database unit 506b is used to store real-time alarm and response information.

[0122] See Figure 6 , the case tracking and privacy protection terminal 6 is used to ensure the privacy and security of case data and track and control the access to the data. Through the case tracking and privacy protection function, the privacy and security of case data can be ensured, and the access to the data can be effectively tracked and controlled. At the same time, it complies with privacy protection policies and regulatory requirements, protects the privacy rights and interests of case data, and enhances data security and credibility.

[0123] The case tracking and privacy protection terminal 6 includes the anonymization and desensitization module 601, the data access permission control module 602, the case tracking and audit module 603, the data encryption and transmission security module 604, the case data backup and recovery module 605, and the privacy protection policy and compliance module 606.

[0124] The anonymization and desensitization module 601 includes the anonymization and desensitization unit 601a and the anonymization and desensitization database unit 601b.

[0125] The anonymization and desensitization unit 601a is used to anonymize and desensitize sensitive personal identity information for the system to protect the privacy of case data. This can be achieved by removing or replacing sensitive information, encrypting sensitive fields, etc.

[0126] The anonymization and desensitization database unit 601b is used to store anonymization and desensitization information.

[0127] The data access permission control module 602 includes the data access permission control unit 602a and the data access permission control database unit 602b.

[0128] The data access permission control unit 602a is used for the system to have a strict data access permission control mechanism to ensure that only authorized personnel can access specific case data. The access permissions can be hierarchically managed according to roles, responsibilities, research stages, etc. to restrict unauthorized data access.

[0129] The data access permission control database unit 602b is used to store data access permission control information.

[0130] The case tracking and auditing module 603 includes a case tracking and auditing unit 603a and a case tracking and auditing database unit 603b.

[0131] The case tracking and auditing unit 603a is used for the system to record the access history and operation logs of case data, including who, when, and how the case data was accessed or modified. This allows for the tracking and auditing of data access to promptly detect abnormal access behaviors or potential data leaks.

[0132] The case tracking and auditing database unit 603b is used to store case tracking and auditing information.

[0133] The data encryption and transmission security module 604 includes a data encryption and transmission security unit 604a and a data encryption and transmission security database unit 604b.

[0134] The data encryption and transmission security unit 604a is used to provide an encryption mechanism for the transmission and storage of case data to ensure the security of data during transmission. Encryption technology can prevent data from being intercepted or tampered with by unauthorized personnel during transmission.

[0135] The data encryption and transmission security database unit 604b is used to store data encryption and transmission security information.

[0136] The case data backup and recovery module 605 includes a case data backup and recovery unit 605a and a case data backup and recovery database unit 605b.

[0137] The case data backup and recovery unit 605a is used for the system to regularly back up case data to prevent data loss or damage. At the same time, the storage and management of backup data also need to comply with relevant privacy protection requirements to ensure the security and integrity of backup data.

[0138] The case data backup and recovery database unit 605b is used to store case data backup and recovery information.

[0139] The privacy protection policy and compliance module 606 includes a privacy protection policy and compliance unit 606a and a privacy protection policy and compliance database unit 606b.

[0140] The Privacy Protection Policy and Compliance Unit 606a is used for the system to establish and comply with relevant privacy protection policies and meet applicable privacy protection regulations and standards. This includes compliance requirements in aspects such as the legality of obtaining case data, the clarity of data usage purposes, and the security of data storage and transmission.

[0141] The Privacy Protection Policy and Compliance Database Unit 606b is used to store privacy protection policies and compliance information.

[0142] See Figure 7 , the Security Training and Awareness Terminal 7 is used to enhance users' awareness and understanding of data security and strengthen their security awareness and behaviors when using the system. Through the security training and awareness functions, it can help users understand and master data security knowledge, enhance their emphasis on and protection awareness of data security, thereby reducing security risks and the possibility of data leakage.

[0143] The Security Training and Awareness Terminal 7 includes Security Training Materials and Course Modules 701, User Security Awareness Reminder Module 702, Password Management Requirement Module 703, Multi-Factor Authentication Module 704, Security Tips and Alerts Module 705, and Security Awareness Activities and Reward Mechanism Module 706.

[0144] The Security Training Materials and Course Modules 701 include Security Training Materials and Course Units 701a and Security Training Materials and Course Database Units 701b.

[0145] The Security Training Materials and Course Units 701a are used to provide security training materials and courses covering basic concepts of data security, best practices, compliance requirements, etc. These materials and courses can include forms such as online training, video tutorials, and security guides to help users understand the importance of data security and related knowledge.

[0146] The Security Training Materials and Course Database Units 701b are used to store security training materials and course information.

[0147] The User Security Awareness Reminder Module 702 includes User Security Awareness Reminder Units 702a and User Security Awareness Reminder Database Units 702b.

[0148] The User Security Awareness Reminder Units 702a are used for the system to regularly send security awareness reminders to enhance users' emphasis on and attention to data security. This can be achieved through internal system notifications, pop-ups, or emails to remind users to pay attention to security matters, protect privacy, etc.

[0149] The User Security Awareness Reminder Database Units 702b are used to store user security awareness reminder information.

[0150] The password management requirement module 703 includes a password management requirement unit 703a and a password management requirement database unit 703b.

[0151] The password management requirement unit 703a is used for the system to require users to adopt strong passwords and regularly prompt users to modify their passwords. In addition, the system can provide password policy guidance, such as password length requirements, password complexity requirements, etc., to increase the security of passwords.

[0152] The password management requirement database unit 703b is used to store password management requirement information.

[0153] The multi-factor authentication module 704 includes a multi-factor authentication unit 704a and a multi-factor authentication database unit 704b.

[0154] The multi-factor authentication unit 704a is used for the system to support multi-factor authentication, such as using passwords and SMS verification codes, fingerprint recognition, etc., to improve the security of user logins to the system.

[0155] The multi-factor authentication database unit 704b is used to store multi-factor authentication information.

[0156] The security prompt and alert module 705 includes a security prompt and alert unit 705a and a security prompt and alert database unit 705b.

[0157] The security prompt and alert unit 705a is used for the system to monitor the operation behaviors of users and issue alerts when abnormalities or potential security risks are detected. This can help users identify and respond to potential security threats in a timely manner.

[0158] The security prompt and alert database unit 705b is used to store security prompt and alert information.

[0159] The security awareness activity and reward mechanism module 706 includes a security awareness activity and reward mechanism unit 706a and a security awareness activity and reward mechanism database unit 706b.

[0160] The security awareness activity and reward mechanism unit 706a is used for the system to organize security awareness activities, such as security knowledge competitions, security training lectures, etc., to increase users' attention and participation in data security. In addition, the system can also set up a security behavior reward mechanism to encourage users to actively take security measures and develop good security habits.

[0161] The security awareness activity and reward mechanism database unit 706b is used to store security awareness activity and reward mechanism information.

[0162] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only to illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.

Claims

1. A clinical trial data security operation system, characterized in that: The clinical trial data security operation system is connected to the clinical trial data system, and the clinical trial data security operation system includes a data encryption end, an access control end, a data backup and recovery end, an audit log end, a security audit and monitoring end, a case tracking and privacy protection end, and a security training and awareness end. Data communication is carried out between the data encryption end, the access control end, the data backup and recovery end, the audit log end, the security audit and monitoring end, the case tracking and privacy protection end, and the security training and awareness end.

2. A clinical trial data security operation system according to claim 1, characterized in that: The data encryption end includes a data transmission encryption module, a data storage encryption module, a data field-level encryption module, a data access control and key management module, and a strong password and password policy module. The data transmission encryption module includes a data transmission encryption unit, which is used to encrypt data in the clinical trial system during transmission; the data storage encryption module includes a data storage encryption unit, which is used to encrypt and protect data using an encryption algorithm when the clinical trial system stores data in a database or file system; the data field-level encryption module includes a data field-level encryption unit, which is used to implement field-level encryption for sensitive personal identity information or other important data fields; the data access control and key management module includes a data access control and key management unit, which is used to limit the clinical trial system to only authorized users who can access decrypted data through an access control mechanism; the strong password and password policy module includes a strong password and password policy unit, which is used to increase the security of data encryption.

3. A clinical trial data security operation system according to claim 1, characterized in that: The access control terminal includes a user identity authentication module, a user role and permission management module, a user role and permission management module, an audit log module, an IP address filtering and access control list module, and a two-factor identity authentication module. The user identity authentication module includes a user identity authentication unit, and the user identity authentication unit is used to require the user to authenticate the user; the user role and permission management module includes a user role and permission management unit, and the user role and permission management unit is used to set different user roles, each role has corresponding permissions and access levels; the data field level access control module includes a data field level access control unit, and the data field level access control unit is used to implement data field level access control, limiting users to access only data fields to which they have permissions; the audit log module includes an audit log unit, and the audit log unit is used to record user operations and access logs; the IP address filtering and access control list module includes an IP address filtering and access control list unit, and the IP address filtering and access control list unit is used to limit access to specific IP addresses or networks based on IP address filtering or access control lists; the two-factor identity authentication module includes a two-factor identity authentication unit, and the two-factor identity authentication unit is used to increase access security.

4. A clinical trial data security operation system according to claim 1, characterized in that: The data backup and recovery end includes a regular data backup module, a data backup storage module, a data recovery module, a data consistency check module, and a disaster recovery backup module. The regular data backup module includes a regular data backup unit, and the regular data backup unit is used to automatically back up clinical trial data regularly. The data backup storage module includes a data backup storage unit, which is used to back up data; the data recovery module includes a data recovery unit, which is used to restore the backup data to the clinical trial system when a failure occurs in the clinical trial system or data is lost, so as to restore the integrity of the clinical trial data; the data consistency check module includes a data consistency check unit, which is used to perform a data consistency check on the clinical trial system during the data recovery process to ensure that the backup data is consistent with the data of the last normal state of the system; the disaster recovery module includes a disaster recovery unit, which is used to perform disaster recovery backup in addition to regular backup.

5. A clinical trial data security operation system according to claim 1, characterized in that: The audit log terminal includes an operation log recording module, an abnormal event recording module, a data change recording module, an audit log retention module, and an audit log reporting module. The operation log recording module includes an operation log recording unit, and the operation log recording unit is used to record the operations performed by the user in the clinical trial system; the abnormal event recording module includes an abnormal event recording unit, and the abnormal event recording unit is used to record abnormal events occurring in the clinical trial system; The data change recording module includes a data change recording unit, which is used to record any modification, deletion or addition operations on the data in the clinical trial system; the audit log retention module includes an audit log retention unit, which is used to reasonably retain the audit log and cannot be tampered with; the audit log reporting module includes an audit log reporting unit, which is used to provide the function of generating an audit log report to facilitate regular audits and risk assessments.

6. A clinical trial data security operation system according to claim 1, characterized in that: The security audit and monitoring terminal includes a security event log recording module, a security policy and rule audit module, a user behavior monitoring module, a security vulnerability scanning and vulnerability management module, a data access monitoring module, and a real-time alarm and response module. The security event log recording module includes a security event log recording unit, and the security event log recording unit is used to record security events occurring in the clinical trial system; the security policy and rule audit module includes a security policy and rule audit unit, and the security policy and rule audit unit is used to audit the security policies and rules in the clinical trial system to ensure that they comply with relevant security standards and regulatory requirements; the user behavior monitoring module includes a user behavior monitoring unit, and the user behavior monitoring unit is used to monitor the behavior of users in the clinical trial system; the security vulnerability scanning and vulnerability management module includes a security vulnerability scanning and vulnerability management unit, and the security vulnerability scanning and vulnerability management unit is used to regularly scan the clinical trial system for security vulnerabilities; the data access monitoring module includes a data access monitoring unit, and the data access monitoring unit is used to monitor access to sensitive data; the real-time alarm and response module includes a real-time alarm and response unit, and the real-time alarm and response unit provides a real-time alarm function for the clinical trial system, and can promptly issue an alarm when abnormal activities or security events are found, and take corresponding response measures.

7. A clinical trial data security operation system according to claim 1, characterized in that: The case tracking and privacy protection end includes an anonymization and desensitization module, a data access permission control module, a case tracking and auditing module, a data encryption and transmission security module, a case data backup and recovery module, and a privacy protection policy and compliance module.

8. A clinical trial data security operation system according to claim 8, characterized in that: The anonymization and desensitization module includes an anonymization and desensitization unit, which is used to anonymize and desensitize sensitive personal identity information to protect the privacy of case data; the data access permission control module includes a data access permission control unit, which is used to ensure that the clinical trial system has a strict data access permission control mechanism to ensure that only authorized personnel can access specific case data; the case tracking and auditing module includes a case tracking and auditing unit, which is used to record the access history and operation log of case data; the data encryption and transmission security module includes a data encryption and transmission security unit, which is used to perform an encryption mechanism for the transmission and storage of case data to ensure the security of data during transmission; the case data backup and recovery module includes a case data backup and recovery unit, which is used to regularly back up case data to prevent data loss or damage; The privacy protection policy and compliance module includes a privacy protection policy and compliance unit, which is used to establish and comply with relevant privacy protection policies and comply with applicable privacy protection regulations and standards.

9. A clinical trial data security operation system according to claim 1, characterized in that: The security training and awareness end includes security training materials and course modules, user security awareness reminder modules, password management requirements modules, multi-factor authentication modules, security tips and alert modules, security awareness activities and reward mechanism modules.

10. A clinical trial data security operation system according to claim 9, characterized in that: The security training materials and course module includes security training materials and course units, and the security training materials and course units are used to provide security training materials and courses; the user security awareness reminder module includes a user security awareness reminder unit, and the user security awareness reminder unit is used to regularly send security awareness reminders to enhance the user's attention and concern for data security; The password management requirement module includes a password management requirement unit, which is used to require users to use strong passwords and regularly remind users to change their passwords; the multi-factor authentication module includes a multi-factor authentication unit, which is used to support multi-factor authentication; the security prompt and alarm module includes a security prompt and alarm unit, which is used to monitor the user's operating behavior and issue an alarm when an abnormality or potential security risk is found; the security awareness activity and reward mechanism module includes a security awareness activity and reward mechanism unit, which is used to organize security awareness activities to increase users' attention and participation in data security.