Safety medical data sharing method with timeliness based on block chain and ring signature

By adopting blockchain and ring signature technology in medical data sharing, fragmented storage, trust issues and privacy leakage risks in medical data sharing are solved, and safe and efficient medical data sharing is achieved.

CN120199393APending Publication Date: 2025-06-24SECOND AFFILIATED HOSPITAL OF COLLEGE OF MEDICINEOF XIAN JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510108900.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The sharing of medical data between different hospitals involves fragmented storage, trust issues, data tampering risks and privacy leakage risks, making it difficult to achieve secure and efficient data sharing.

Method used

Using a blockchain and ring signature method, we use a method to generate user private keys and public keys, sign electronic health files, and use distributed file sharing systems and smart contracts to achieve secure sharing and access control of data.

Benefits of technology

It realizes the secure, reliable and efficient sharing of medical data, ensures the privacy and integrity of data, and reduces the risk of data tampering and leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120199393A_ABST
    Figure CN120199393A_ABST
Patent Text Reader

Abstract

The invention provides a safety medical data sharing method with timeliness based on a block chain and a ring signature. The method comprises the following steps: selecting system safety parameters and determining a used hash function; respectively generating private keys and public keys corresponding to different user attributes based on the system security parameters; generating an electronic health record based on the diagnosis and treatment data of the patient, and signing the electronic health record by a doctor; the patient encrypts the electronic health archive signed by the doctor by using the symmetric key to generate an encrypted electronic health archive, and the encrypted electronic health archive is uploaded to a distributed file sharing system; the patient encapsulates the hash index returned by the distributed file sharing system, the smart contract with access control, the private key of the patient and a decryption algorithm in a data packet, and uploads the data packet to the block chain node; and the sharing user obtains the electronic health file from the distributed file sharing system based on the intelligent contract with access control and the Hash index. According to the method, the data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data sharing, and in particular to a secure medical data sharing method with timeliness based on blockchain and ring signature. Background Art

[0002] With the rapid development of blockchain-based healthcare, the privacy issue of medical data has become a major challenge in the healthcare industry. Electronic Health Records (EHRs) contain patients' consultation information, treatment results, medical histories, and examination data, which help to provide convenient health record storage services. In recent years, EHRs have gradually replaced paper medical records, avoiding the problem of losing electronic medical records when patients transfer to other hospitals for treatment. EHR sharing can help doctors obtain previous medical histories and examination data, greatly reducing the waste of medical information caused by repeated examinations. At the same time, when a serious infectious disease occurs, the secure sharing of EHRs can also enable professional medical teams from different regions to make comprehensive, accurate, and efficient diagnoses, providing universal healthcare. However, in the medical field, there are many problems with the secure sharing of EHRs. First, medical data from different hospitals are stored in a fragmented state, so it is difficult to access records from different institutions or at different times. Second, there is a trust problem with medical data between different medical institutions. Different medical institutions cannot guarantee that the verified data and medical records will not be tampered with, so it is difficult to gain the trust of other medical institutions. Finally, medical data sharing is uncontrolled, posing a risk of privacy leakage. If a patient's private data is leaked, it may lead to various problems, such as doctor-patient disputes. Therefore, when sharing EHRs in the healthcare field, it is crucial to protect the privacy of the data. Summary of the Invention

[0003] In view of this, the present invention provides a secure medical data sharing method with timeliness based on blockchain and ring signature to solve the above problems.

[0004] The present invention provides a secure medical data sharing method with timeliness based on blockchain and ring signature, including: selecting system security parameters and determining the hash function to be used; generating private keys and public keys corresponding to different user attributes based on the system security parameters, where the user attributes include hospital administrators, doctors, and patients; generating an electronic health record based on the patient's diagnosis and treatment data, and the doctor signs the electronic health record; the patient encrypts the doctor-signed electronic health record using a symmetric key to generate an encrypted electronic health record, and uploads the encrypted electronic health record to a distributed file sharing system; the patient encapsulates the hash index returned by the distributed file sharing system, the smart contract with access control, the patient's private key, and the decryption algorithm in a data packet, and uploads the data packet to a blockchain node; the sharing user obtains the data packet from the blockchain node based on the smart contract with access control, and obtains the electronic health record from the distributed file sharing system based on the hash index in the data packet.

[0005] In another implementation of the present invention, private keys and public keys corresponding to different user attributes are generated based on system security parameters, including: generating a master key S for the hospital director based on the system security parameters, and a master public key P0 = S·P, where P is a generator; the doctor selects a random number According to the doctor's identity ID i Perform calculations to obtain the doctor's private key S i = x i ·S·H1(ID i ) and public key Y i = x i ·(P + H1(ID i )) Each doctor generates a key pair (Y i , S i ); for each patient P i seen by doctor D ij The identity is ID ij , the patient selects any one And randomly select a symmetric S ij = x ij ·S i ·H1(ID ij ), the patient generates a key pair (Y ij , S ij ) and a symmetric key K ij .

[0006] In another implementation of the present invention, an electronic health record is generated based on the patient's diagnosis and treatment data, and the doctor signs the electronic health record, including: generating an electronic health record based on the patient's diagnosis and treatment data; setting the serial number of the signing doctor as i, and the key pair as (Y i , S i ), and randomly selecting N doctor identities in the hospital to form a set L = {ID1, ID2,..., ID V ,..., ID n}, which includes the signing doctor; denoting the electronic health record as M, and randomly selecting Use it to generate a ring signature δ.

[0007] In another implementation of the present invention, the time-limited secure medical data sharing method based on blockchain and ring signature further includes: the doctor combines the electronic health record and the ring signature into a message (M ij , δ) encrypted with the public key Y ij of patient P i , and sends it to patient P ij ,

[0008] In another implementation of the present invention, the patient encrypts the doctor-signed electronic health record using a symmetric key to generate an encrypted electronic health record, and uploads the encrypted electronic health record to the distributed file sharing system, including: Patient P ij uses his own symmetric key K ij to encrypt the electronic health record M to generate a ciphertext The ciphertext is uploaded to the distributed file sharing system.

[0009] In another implementation of the present invention, the patient encapsulates the hash index returned by the distributed file sharing system, the smart contract with access control, the patient's private key, and the decryption algorithm in a data packet, and uploads the data packet to the blockchain node, including: The distributed file sharing system returns a hash index; the patient encrypts the hash index and the symmetric key using the patient's public key Y ij to generate The smart contract with access control private key S ij and the decryption algorithm are encapsulated in the data packet; the data packet is uploaded to the blockchain node.

[0010] In another implementation of the present invention, the sharing user obtains the data packet from the blockchain node, and based on the smart contract with access control, obtains the electronic health record from the distributed file sharing system, including: The sharing user obtains the data packet from the blockchain node; verifies the data packet based on the smart contract with access control; if the verification is successful, the data packet executes the decryption algorithm to obtain the hash index and the symmetric key; the sharing user downloads the file in the distributed file sharing system according to the hash index to obtain the electronic health record.

[0011] In the time-limited secure medical data sharing method based on blockchain and ring signature of the present invention, a data packet is constructed, which includes a smart contract with access control and a decryption algorithm. Therefore, this solution can realize outsourced decryption of data and improve the efficiency of data sharing; in addition, it is particularly worth noting that the effective time of data is crucial for life cycle management and even calculating economic value. This solution intends to adopt a time-limited sharing scheme; the research content of this study can realize outsourced decryption of data, improve the efficiency of data sharing, and at the same time avoid the improper use of data, devices or services, thereby damaging the interests of stakeholders. Description of the Drawings

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. By reading the detailed description of the following embodiments, the advantages and benefits in the solutions become clear to those skilled in the art. The accompanying drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. In the accompanying drawings:

[0013] Figure 1 It is a step flowchart of a time-limited secure medical data sharing method based on blockchain and ring signature according to an embodiment of the present invention.

[0014] Figure 2 It is a flowchart of medical data sharing according to an embodiment of the present invention. Detailed implementation manners

[0015] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the following will clearly and detailedly describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art shall fall within the scope protected by the embodiments of the present invention.

[0016] Figure 1 It is a step flowchart of a time-limited secure medical data sharing method based on blockchain and ring signature provided by an embodiment of the present invention. As Figure 1 shown, this embodiment mainly includes the following steps:

[0017] S101. Select system security parameters and determine the hash function to be used.

[0018] S102. Generate private keys and public keys corresponding to different user attributes respectively based on the system security parameters, where the user attributes include hospital directors, doctors, and patients.

[0019] S103. Generate an electronic health record based on the patient's diagnosis and treatment data, and the doctor signs the electronic health record.

[0020] S104. The patient encrypts the doctor-signed electronic health record using a symmetric key to generate an encrypted electronic health record, and uploads the encrypted electronic health record to the distributed file sharing system.

[0021] S105. The patient encapsulates the hash index, smart contract with access control, the patient's private key, and the decryption algorithm returned by the distributed file sharing system in a data packet, and uploads the data packet to the blockchain node.

[0022] S106. The shared user obtains a data packet from a blockchain node based on a smart contract with access control, and obtains an electronic health record from a distributed file sharing system based on the hash index in the data packet.

[0023] In the time-limited secure medical data sharing method based on blockchain and ring signature of the present invention, a data packet is constructed, which includes a smart contract with access control and a decryption algorithm. Therefore, this solution can achieve outsourced decryption of data and improve the efficiency of data sharing. In addition, it is particularly worth noting that the effective time of data is crucial for life cycle management and even calculating economic value. This solution intends to adopt a time-limited sharing scheme. The research content of this study can achieve outsourced decryption of data, improve the efficiency of data sharing, and avoid improper use of data, devices or services, thereby damaging the interests of stakeholders.

[0024] In another implementation manner of the present invention, private keys and public keys corresponding to different user attributes are generated based on system security parameters, including: generating a master key S of the hospital director based on system security parameters, and a master public key P0 = S·P, where P is a generator; the doctor selects a random number According to the doctor's identity ID i Perform calculations to obtain the doctor's private key S i = x i ·S·H1(ID i ) and public key Y i = x i ·(P + H1(ID i )) Each doctor generates a key pair (Y i , S i ); for each patient P i seen by doctor D ij The identity is ID ij , the patient selects any one And randomly select a symmetric S ij = x ij ·S i ·H1(ID ij ), the patient generates a key pair (Y ij , S ij ) and a symmetric key K ij .

[0025] Exemplarily, the security parameter is used to determine the security level of the encryption system. G1 is a cyclic additive group, P is a generator (where G1 is generated by the generator P), G T Is a cyclic multiplicative group, q is a large prime number, which is the order of group G1 and G T ; e is a mapping relationship e: G1×G1→G T ; Define two different hash functions After the system parameters are generated, they will be released for use by other domains.

[0026] It should be understood that the master key S in the hospital system is generated and owned by the hospital's leader or person in charge. The public key is the public key P0 = S·P. The doctor randomly selects a random number and then calculates the doctor's private key S i based on his identity ID i = x i ·S·H1(ID i ) and the public key Y i = x i ·(P + H1(ID i )); D i The identity of each patient P ij seen by the doctor is ID ij , and the patient randomly selects any one and then the patient randomly selects a symmetric S ij = x ij ·S i ·H1(ID ij ). Thus, each doctor in the hospital system generates a key pair (Y i , S i ), and the patient generates a key pair (Y ij , S ij ) and a symmetric key K ij .

[0027] In another implementation of the present invention, based on the patient's diagnosis and treatment data, an electronic health record is generated, and the doctor signs the electronic health record, including: generating an electronic health record based on the patient's diagnosis and treatment data; setting the serial number of the signing doctor to i, the key pair to (Y i , S i ), and selecting any N doctor identities in the hospital to form a set L = {ID1, ID2,..., ID V ,..., ID n}, which includes the signing doctor; denoting the electronic health record as M, and randomly selecting and using it to generate a ring signature δ.

[0028] Exemplarily, for the patient P ij who has seen a doctor, the doctor D i generates an electronic medical record, and the doctor signs the generated EHR. First, set the serial number of the signing doctor to i, the key pair to (Y i , S i ), and select any N doctor identities in the hospital to form a set L = {ID1, ID2,..., ID V ,..., IDn}, which includes the signer, and then the EHR is denoted as M, and a random selection is made to generate the ring signature δ using it.

[0029] In another implementation of the present invention, the time-limited secure medical data sharing method based on blockchain and ring signature further includes: the doctor combines the electronic health record and the ring signature into a message encrypted with the public key Y ij of patient P ij (M i , δ), and sends it to patient P ij ,

[0030] In another implementation of the present invention, the patient encrypts the doctor-signed electronic health record using a symmetric key to generate an encrypted electronic health record, and uploads the encrypted electronic health record to the distributed file sharing system, including: patient P ij encrypts the electronic health record M using his own symmetric key K ij to generate a ciphertext and uploads the ciphertext to the distributed file sharing system.

[0031] Exemplarily, the patient has control over the storage and sharing of data, and realizes the storage and sharing of data through signature verification. After patient P ij receives the message, uses the private key S ij to decrypt it, obtains (M, δ), calculates h1, and verifies whether it holds. If so, the signature is correct, and other operations can continue; otherwise, the signature is invalid.

[0032] Preferably, patient P ij encrypts the plaintext M using his own symmetric key K ij to generate a ciphertext and uploads it to the distributed file sharing (IPFS) system.

[0033] In another implementation of the present invention, the patient encapsulates the hash index returned by the distributed file sharing system, the smart contract with access control, the patient's private key, and the decryption algorithm in a data packet, and uploads the data packet to the blockchain node, including: the distributed file sharing system returns the hash index; the patient encrypts the hash index and the symmetric key, and uses the patient's public key Y ij to generate encapsulates the smart contract with access control, the private key S ij and the decryption algorithm in the data packet; uploads the data packet to the node of the blockchain.

[0034] Exemplarily, the IPFS system returns a unique hash value for indexing subsequent data. After the data is stored, the patient encrypts the generated hash index and symmetric key after splicing with their own public key Y ij Generate

[0035] Furthermore, encapsulate the SCO package, patient P ij The smart contract with access control, Private key S ij and the decryption algorithm are encapsulated in an SCO package, and then the SCO package is uploaded to the blockchain. The SCO package can be stored in the nodes after reaching a consensus among the blockchain nodes.

[0036] In another implementation of the present invention, the sharing user obtains a data packet from a blockchain node, and based on the smart contract with access control, obtains an electronic health record from a distributed file sharing system, including: the sharing user obtains a data packet from a blockchain node; verifies the data packet based on the smart contract with access control; if the verification is successful, the data packet executes the decryption algorithm to obtain a hash index and a symmetric key; the sharing user downloads a file in the distributed file sharing system according to the hash index to obtain the electronic health record.

[0037] Exemplarily, the sharing user uses the time-limited key generated by the CS-TBK algorithm obtained from the data owner to send an SCO message request to the SCO processing node. The SCO processing node returns the specified SCO message to the sharing user. After receiving the SCO package, the sharing user first performs verification of the smart contract with access control. If it fails, no operation is performed and the process exits; if the verification passes, the SCO package automatically executes the decryption algorithm to decrypt SK and presents the Hash index and K for decryption to obtain the Hash index and K ij presented to the sharing user.

[0038] Furthermore, the sharing user downloads a file in the IPFS system according to the Hash index to obtain First, verify δ through If δ passes the verification, then use K ij to decrypt to obtain M, thus realizing message sharing; if the signature δ verification fails, send a tracking request to the audit node.

[0039] It should be understood that the audit node collects the T i values of each ring member according to the SK i in δ and the ring member list L, and its T i = TK i ·x -1, the node interacts with each member of the ring once to collect the required values. The blockchain node collects all T i After that, through the formula e(TK i , P + Q i ) = e(T i , Y i ) to verify the validity of T i . If all T i are valid, then calculate Then, through the formula e(T, P + Q i ) = e(E, Y i ) to emit Y i Find the signing doctor to achieve recovery.

[0040] So far, specific embodiments of the present invention have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing can be advantageous.

[0041] It should be noted that all directional indications (such as up, down, left, right, back...) in the embodiments of the present invention are only used to explain the relative positional relationship, movement conditions, etc. between components in a specific posture (as shown in the drawings). If the specific posture changes, the directional indications will change accordingly.

[0042] In the description of the present invention, the terms "first" and "second" are only used for the convenience of describing different components or names, and cannot be understood as indicating or implying an order relationship, relative importance, or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features.

[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs. The terms used in the description of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention.

[0044] It should be noted that although the specific embodiments of the present invention have been described in detail in conjunction with the drawings, it should not be construed as a limitation on the protection scope of the present invention. Various modifications and variations that can be made by those skilled in the art without creative efforts within the scope described in the claims still belong to the protection scope of the present invention.

[0045] The examples of the embodiments of the present invention are intended to concisely illustrate the technical features of the embodiments of the present invention, so that those skilled in the art can intuitively understand the technical features of the embodiments of the present invention, and shall not be used as an improper limitation of the embodiments of the present invention.

[0046] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A time-sensitive secure medical data sharing method based on blockchain and ring signature, characterized in that: include: Select system security parameters and determine the hash function to be used; Based on the system security parameters, private keys and public keys corresponding to different user attributes are generated respectively, wherein the user attributes include hospital director, doctor and patient; Based on the patient's diagnosis and treatment data, an electronic health record is generated, and the doctor signs the electronic health record; The patient uses a symmetric key to encrypt the electronic health record signed by the doctor to generate an encrypted electronic health record, and uploads the encrypted electronic health record to a distributed file sharing system; The patient encapsulates the hash index returned by the distributed file sharing system, the smart contract with access control, the patient's private key, and the decryption algorithm in a data packet, and uploads the data packet to the blockchain node; The shared user obtains the data packet from the blockchain node based on a smart contract with access control, and obtains the electronic health record from the distributed file sharing system based on a hash index in the data packet.

2. The method according to claim 1, characterized in that The generating of private keys and public keys corresponding to different user attributes based on the system security parameters includes: Generate a master key S of the person in charge of the hospital based on the system security parameters, the master public key P0=S·P, where P is a generator; Doctor chooses random number Based on the doctor's ID i Calculate and get the doctor's private key S i =x i ·S·H1(ID i ) and public key Y i =x i ·(P+H1(ID i )), each doctor generates a key pair (Y i ,S i ); Doctor D i Every patient P ij The identity is ID ij , the patient chooses any And randomly select a symmetric S ij =x ij ·S i H1(ID ij ), the patient generates a key pair (Y ij ,S ij ) and the symmetric key K ij .

3. The method according to claim 2, characterized in that The electronic health record is generated based on the patient's diagnosis and treatment data, and the doctor signs the electronic health record, including: Generate electronic health records based on patients’ diagnosis and treatment data; Set the signing doctor's serial number to i and the key pair to (Y i ,S i ), and select any N doctor identities in the hospital to form a set L = {ID1, ID2, ..., ID V ,...,ID n }, which contains said signature doctor; The electronic health record is denoted as M, and a random Use it to generate a ring signature δ.

4. The method according to claim 3, characterized in that Also includes: The doctor combines the electronic health record and the ring signature into a single signature using the patient's P ij The public key Y ij Encrypted message (M i ,δ), and sent to patient P ij , 5. The method according to claim 3, characterized in that: The patient encrypts the electronic health record signed by the doctor using a symmetric key to generate an encrypted electronic health record, and uploads the encrypted electronic health record to a distributed file sharing system, including: Patient P ij Use your own symmetric key K ij Encrypt the electronic health record M to generate a ciphertext The ciphertext Upload to a distributed file sharing system.

6. The method according to claim 2, characterized in that The patient encapsulates the hash index returned by the distributed file sharing system, the smart contract with access control, the patient's private key, and the decryption algorithm in a data packet, and uploads the data packet to the blockchain node, including: The distributed file sharing system returns a hash index; The patient encrypts the hash index and the symmetric key using the patient's public key Y ij generate Smart contracts with access control, Private Key S ij and decryption algorithm encapsulated in the data packet; The data packet is uploaded to the node of the blockchain.

7. The method according to claim 1, characterized in that The shared user obtains the data packet from the blockchain node, and based on the smart contract with access control, obtains the electronic health record from the distributed file sharing system, including: The shared user obtains the data packet from the blockchain node; Verifying the data packet based on the smart contract with access control; If the verification is successful, the data packet executes the decryption algorithm to obtain the hash index and the symmetric key; The sharing user downloads the file in the distributed file sharing system according to the hash index to obtain the electronic health record.