Bank medical intelligent terminal data secure transmission and real-time management and control system and method
By placing sensitivity level annotation and dynamic blocking of medical business data, combined with blockchain hash identification and zero-knowledge proof of silver medical intelligent terminal data security transmission system, the problem of rigid data transmission strategy and audit in the existing technology is solved, and efficient data protection and real-time management and control are achieved.
Patent Information
- Application Number
- CN202510579253.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-07-08
AI Technical Summary
In the existing medical terminal data transmission solutions, the data classification standards are single, and it is difficult to adapt to multi-level sensitive scenarios, resulting in rigid encryption strategies, lack of coordination between dynamic shard cutting and transmission path security, and it is easy to intercept key data by malicious attackers using timing characteristics. Moreover, traditional methods do not integrate blockchain and zero-knowledge proof technology, and it is impossible to achieve decentralized auditing on the premise of ensuring privacy, making it difficult to meet the high compliance requirements of medical services.
The Yinyi intelligent terminal data security transmission and real-time management and control system are adopted, and the medical business data is marked with sensitivity level and dynamic blocking through the preprocessing module, and dynamic shard cutting and encryption are used to combine the multi-dimensional feature extraction of the behavior analysis module and real-time threat assessment of the strategy regulation module. Blockchain hash identification and zero-knowledge proof are used for audit traceability, so as to achieve coordination between dynamic encryption and shard cutting, block the timing attack path, and perform decentralized audit and tampering positioning.
It improves the accuracy of data protection, blocks the timing attack path, realizes the dual guarantees of decentralized audit and tampering positioning, and meets the needs of full-link secure transmission and real-time control of medical terminal data.
Smart Images

Figure CN120281558A_ABST
Abstract
Description
Background Art
[0002] In the existing medical terminal data transmission solutions, the data classification and grading criteria are single, making it difficult to adapt to multi-level sensitive scenarios, resulting in rigid encryption strategies. At the same time, there is a lack of coordination between dynamic fragmentation and transmission path security, making it easy for malicious attackers to intercept key data using timing characteristics. In the auditing link, relying on centralized institutions for verification poses a risk of hidden tampering. In addition, traditional methods do not integrate blockchain and zero-knowledge proof technologies, and cannot achieve decentralized auditing while ensuring privacy, making it difficult to meet the high compliance requirements of medical services.
[0003] Therefore, there is an urgent need to provide a technical solution to solve the above problems. Summary of the Invention
[0004] To solve the above technical problems, the present invention provides a data security transmission and real-time control system and method for silver-medical intelligent terminals.
[0005] In a first aspect, the present invention provides a data security transmission and real-time control system for silver-medical intelligent terminals, and the technical solution of the system is as follows:
[0006] The data security transmission and real-time control system for silver-medical intelligent terminals includes: a preprocessing module, an encrypted transmission module, a behavior analysis module, a policy regulation module, and an auditing and tracing module;
[0007] The preprocessing module is used to: obtain medical service data and device status data, label the sensitivity level tags for the medical service data based on a pre-constructed classification and grading model, divide the medical service data with the sensitivity level tags into multiple data blocks according to preset rules, and generate a hash identifier uniquely bound to each data block through a blockchain node;
[0008] The encrypted transmission module is used to: match a preset combination of encryption algorithms according to the sensitivity level tags, extract the timing pulse sequence in the device status data, determine the fragmentation timing reference, and based on the fragmentation timing reference, perform dynamic fragmentation on each data block to generate target medical service data with fragmentation serial numbers, recombine the target medical service data with the hash identifier to generate an encrypted data packet carrying the hash identifier and the fragmentation serial number, and transmit the encrypted data packet to a target node through an encrypted transmission protocol;
[0009] The behavior analysis module is used to: capture the traffic characteristics of the transmission path of the encrypted data packet, obtain the operation behavior log, input the traffic characteristics and the operation behavior log into a federated learning model, extract a multi-dimensional feature vector including data flow direction, terminal identity, and operation timing, and calculate a real-time threat index based on the multi-dimensional feature vector;
[0010] The said policy control module is used for: dynamically switching the encryption algorithm combination according to the real-time threat index to obtain a target encryption algorithm combination, generating a hash identifier verification rule based on the target encryption algorithm combination, sending a control instruction of the hash identifier verification rule to the target node, and isolating abnormal transmission paths based on software-defined network technology;
[0011] The said audit and traceability module is used for: performing reverse recombination verification on the data flow process according to the hash identifier and the shard sequence number stored in the blockchain, using a zero-knowledge proof algorithm to verify the integrity signature and operation compliance label of each shard of medical service data. If the verification fails, a data tampering warning is generated, a preset data backtracking mechanism is triggered, and an audit report is generated.
[0012] The beneficial effects of a silver-medical intelligent terminal data secure transmission and real-time control system of the present invention are as follows:
[0013] The system of the present invention drives dynamic encryption and shard cutting through sensitivity grading labels, improves the accuracy of data protection, blocks timing attack paths based on the coordination of shard timing benchmarks and encrypted transmission protocols, combines blockchain hash identifiers and zero-knowledge proof verification, realizes dual guarantees of decentralized audit and tampering positioning, and meets the requirements of full-link secure transmission and real-time control of medical terminal data.
[0014] Based on the above solution, a silver-medical intelligent terminal data secure transmission and real-time control system of the present invention can also be improved as follows.
[0015] In an optional manner, the preprocessing module is specifically used for:
[0016] Using the natural language processing model in the classification and grading model to perform semantic recognition on the key entity information in the medical service data, where the key entity information includes: patient identity information and diagnosis codes;
[0017] Inputting the key entity information into the classification and grading model, and labeling the sensitivity level label according to the preset sensitivity grading rule; among them, the data containing the patient identity information is labeled as first-sensitive-level data, the data containing the diagnosis code is labeled as second-sensitive-level data, and the remaining data is labeled as third-sensitive-level data;
[0018] Based on the sensitivity level label, using a dynamic window segmentation algorithm to block the medical service data; among them, the block length of the first-sensitive-level data is set to a fixed value, and the block lengths of the second-sensitive-level data and the third-sensitive-level data are dynamically adjusted according to the data entropy value;
[0019] Input the chunked data into the smart contract of the blockchain node, generate the hash identifier associated with the content and chunking order of each data chunk through the SHA-3 algorithm, and write the hash identifier into the Merkle tree structure of the blockchain.
[0020] In the above optional method, the patient identity information and diagnostic codes in the medical data are accurately identified through a natural language processing model, and the data sensitivity level is dynamically labeled in combination with the preset sensitivity grading rules, realizing the refined classification of key entity information. The dynamic window segmentation algorithm is used to differentially chunk data with different sensitivity levels, ensuring the anti-disclosure ability of highly sensitive data. The hash identifier bound to the data chunk content and order is generated through the SHA-3 algorithm and written into the blockchain Merkle tree, enhancing the immutability and traceability of data chunking and blockchain evidence storage, and solving the risk of sensitive information exposure caused by traditional static chunking.
[0021] In an optional way, the encryption transmission module is specifically used for:
[0022] Construct an encryption policy mapping table according to the sensitivity level label; among them, the first sensitive level data adopts the nested policy of asymmetric encryption algorithm and symmetric encryption algorithm, the second sensitive level data adopts the combination policy of short-key asymmetric encryption algorithm and stream encryption algorithm, and the third sensitive level data adopts the single-layer policy of standard symmetric encryption algorithm;
[0023] Based on the encryption policy mapping table, extract the initial timing pulse sequence from the device status data, perform Fourier transform on the initial timing pulse sequence to generate the initial shard timing reference;
[0024] Dynamically adjust the offset of the initial shard timing reference according to the shard threshold corresponding to the sensitivity level label to generate the shard timing reference.
[0025] In the above optional method, by constructing an encryption policy mapping table, nested encryption algorithms are matched for data with different sensitivity levels, realizing the dynamic adaptation of encryption intensity and data value. The frequency domain characteristics of the device timing pulse sequence are extracted through Fourier transform to generate an anti-interference shard timing reference, and the offset is dynamically adjusted in combination with the sensitivity label, which can effectively resist attacks and interceptions based on timing rules, thus solving the problems of traditional encryption policy rigidity and easy prediction of timing sharding, and improving the real-time security and algorithm flexibility of data transmission.
[0026] In an optional way, the encryption transmission module is also specifically used for:
[0027] Dynamically calculate the shard length threshold for each data block according to the pulse interval of the sharding timing reference, and based on the shard length threshold, use a streaming sharding algorithm to cut each data block to generate multiple shard units. Embed a shard sequence number at the head of each shard unit, calculate the hash digest of the content of the previous shard unit through the SHA-3 algorithm, and add the hash digest to the head of the current shard unit to form a shard hash chain;
[0028] Attach a unique incrementing sequence identifier to each shard unit based on the timestamp of the sharding timing reference, cross-reorganize each shard unit with the hash identifier according to the shard sequence number, generate a chained check code based on the hash digests of adjacent shard units in the shard hash chain, and bind the chained check code with the sequence identifier to construct an encrypted data packet containing hash chain verification logic;
[0029] Generate a dynamic session key based on the TLS / SSL protocol, perform application layer encryption on the encrypted data packet, and append the timestamp and device fingerprint information to form a complete verification chain, and transmit it to the target node.
[0030] In the above optional manner, a shard hash chain is generated by using a streaming sharding algorithm in combination with a sharding timing reference. Through hash digest chained verification and a unique incrementing sequence identifier, the integrity of the shard units and the non-tampering of the transmission order are ensured. Through dynamic session key encryption and device fingerprint binding, an end-to-end verification chain is constructed, blocking the man-in-the-middle attack path, so as to be able to achieve triple verification of the content integrity, timing consistency, and transmission link credibility of sharded data, and solve the problems of traditional shard recombination attacks and single verification logic.
[0031] In an optional manner, the behavior analysis module is specifically used for:
[0032] Collect traffic characteristics of the transmission path based on the software-defined network controller, extract operation behavior characteristics from the device audit log, and synchronously associate the pulse interval in the traffic characteristics with the timestamp of the operation behavior characteristics through a timing alignment algorithm to obtain synchronous characteristics;
[0033] Input the synchronous characteristics into the graph convolutional network in the federated learning model to extract a multi-dimensional feature vector including data flow correlation degree, device identity fingerprint, and operation instruction sequence;
[0034] Based on the historical attack patterns and dynamic behavior baselines stored in the preset threat knowledge graph, a threat assessment matrix including weight assignment rules and feature deviation thresholds is constructed. According to the spatio-temporal correlation strength of each dimension in the multi-dimensional feature vector, the distribution difference probability between the current behavior pattern and the known attack patterns is calculated through the KL divergence algorithm, and the weight coefficient is dynamically adjusted in combination with the device type and network load status, and the real-time threat index is output.
[0035] In the above optional manner, the traffic features and operation behavior logs are fused through the federated learning model to extract the multi-dimensional spatio-temporal feature vectors of data flow direction, device identity, and operation time sequence, and the distribution difference probability of the behavior pattern is dynamically evaluated in combination with the threat knowledge graph and the KL divergence algorithm, and the weight coefficient is adjusted based on the device type and network load, realizing the accurate calculation of the threat index, breaking through the limitation of relying on the traditional rule base, and improving the real-time detection ability and complex scenario adaptability for new attacks.
[0036] In an optional manner, the policy regulation module is specifically used for:
[0037] When the real-time threat index exceeds the preset switching threshold, dynamically switch the encryption algorithm combination in the encryption policy mapping table to determine the target encryption algorithm combination, and determine the network layer identifier of the abnormal transmission path according to the real-time threat index and the abnormal data flow direction feature in the multi-dimensional feature vector;
[0038] Based on the public key attribute of the asymmetric encryption algorithm in the target encryption algorithm combination, generate an initial hash identifier verification rule including the recursive verification logic of the hash digest, and compile the initial hash identifier verification rule into the hash identifier verification rule that can be executed across nodes through the blockchain smart contract;
[0039] Add the redundant check shard unit to the shard hash chain, and activate the multi-path parallel transmission mechanism of the shard unit data based on the multi-path transmission load balancing algorithm of the shard unit data;
[0040] Send a verification control instruction including the hash identifier verification rule to the target node, and perform cross-node two-way verification on the distributed consistency of the hash identifier and the continuity of the shard sequence number through the blockchain smart contract;
[0041] Based on the flow table dynamic control protocol of the software-defined network controller, send an update instruction including the traffic blocking rule and the priority marking isolation policy to the target switch bound to the abnormal transmission path, add the network layer identifier and the terminal feature information to the isolation policy queue, synchronously update the flow table entries of the target switch according to the time stamp of the shard timing reference, block the data forwarding interface of the abnormal transmission path, and construct a virtual isolation channel.
[0042] In the above optional methods, the encryption algorithm combination is dynamically switched based on the real-time threat index, and the cross-node verification rules are compiled in combination with the blockchain smart contract to achieve the coordinated response of the encryption strategy and the abnormal path. The availability of data transmission is guaranteed through multi-path parallel transmission and redundant sharding load balancing mechanism. The flow table dynamic control protocol is used to block the abnormal path interface and build a virtual isolation channel, which solves the problem of passive response delay of traditional defense and forms a security protection system with active isolation, dynamic redundancy and cross-layer verification.
[0043] In an optional manner, the audit traceability module is specifically used to:
[0044] Extract the hash chain and shard number of the target data block from the blockchain, and reconstruct the original shard order through the reverse traversal algorithm;
[0045] Generate the integrity signature of each shard medical service data using the zero-knowledge proof algorithm, and verify the consistency between the hash summary of each shard unit and the blockchain record;
[0046] If the verification fails, the historical sharded medical business data in the blockchain backup node is extracted and the difference is compared to locate the tampering position, and the tampering position is bound to the abnormal event timestamp corresponding to the shard sequence number to generate the audit report containing the abnormal timing mark and the abnormal transmission path location record.
[0047] In the above optional methods, the integrity signature of the shard data is verified by the zero-knowledge proof algorithm, realizing compliance verification under privacy protection. The tampering location is located by comparing the differences in the historical data of the blockchain, and the tampering event is bound to the shard sequence number, timestamp and path information to generate an audit report, breaking through the trust bottleneck of centralized auditing, realizing a closed loop of tampering traceability, compliance verification and evidence chain solidification, and solving the problem of traditional auditing relying on manual verification and tampering concealment and difficulty in tracing.
[0048] In a second aspect, the present invention provides a method for secure transmission and real-time control of data of a bank-medical intelligent terminal, and the technical solution of the method is as follows:
[0049] Obtain medical service data and equipment status data, label the medical service data with sensitivity level labels based on a pre-built classification and grading model, divide the medical service data with the sensitivity level labels into multiple data blocks according to preset rules, and generate a hash identifier uniquely bound to each data block through a blockchain node;
[0050] Match a preset encryption algorithm combination according to the sensitivity level label, extract the timing pulse sequence in the device status data, determine the sharding timing reference, and based on the sharding timing reference, perform dynamic sharding cutting on each data block to generate target medical service data with sharding serial numbers. Recombine the target medical service data with the hash identifier to generate an encrypted data packet carrying the hash identifier and the sharding serial number, and transmit the encrypted data packet to the target node through an encrypted transmission protocol;
[0051] Capture the traffic characteristics of the transmission path of the encrypted data packet and obtain the operation behavior log. Input the traffic characteristics and the operation behavior log into the federated learning model to extract a multi-dimensional feature vector including data flow direction, terminal identity, and operation timing, and calculate the real-time threat index based on the multi-dimensional feature vector;
[0052] According to the real-time threat index, dynamically switch the encryption algorithm combination to obtain a target encryption algorithm combination. Based on the target encryption algorithm combination, generate a hash identifier verification rule, send a control instruction of the hash identifier verification rule to the target node, and isolate the abnormal transmission path based on software-defined network technology;
[0053] According to the hash identifier and the sharding serial number stored in the blockchain, perform reverse recombination verification on the data transfer process, and use the zero-knowledge proof algorithm to verify the integrity signature and operation compliance label of each sharded medical service data. If the verification fails, generate a data tampering warning, trigger a preset data backtracking mechanism, and generate an audit report.
[0054] The beneficial effects of a method for secure transmission and real-time control of data of a silver-medical intelligent terminal according to the present invention are as follows:
[0055] The method of the present invention drives dynamic encryption and sharding cutting through sensitivity grading labels, improves the accuracy of data protection, blocks the timing attack path based on the coordination of the sharding timing reference and the encrypted transmission protocol, combines blockchain hash identifier and zero-knowledge proof verification, realizes double guarantees of decentralized audit and tampering positioning, and meets the requirements of full-link secure transmission and real-time control of medical terminal data.
[0056] In a third aspect, the technical solution of an electronic device according to the present invention is as follows:
[0057] It includes a memory, a processor, and a program stored on the memory and running on the processor. When the processor executes the program, the steps of the method for secure transmission and real-time control of data of the silver-medical intelligent terminal according to the present invention are implemented.
[0058] In a fourth aspect, the technical solution of a computer-readable storage medium provided by the present invention is as follows:
[0059] Instructions are stored in a computer-readable storage medium. When the computer-readable storage medium reads the instructions, the computer-readable storage medium is caused to execute the steps of the method for secure data transmission and real-time control of a silver-medical intelligent terminal according to the present invention.
[0060] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the description. And in order to make the above and other objects, features and advantages of the present invention more obvious and understandable, the following specifically gives the specific embodiments of the present invention. Description of the Drawings
[0061] The drawings are only used to illustrate the embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to denote the same components. In the drawings:
[0062] Figure 1 is a schematic structural diagram of an embodiment of a system for secure data transmission and real-time control of a silver-medical intelligent terminal according to the present invention;
[0063] Figure 2 is a schematic flowchart of an embodiment of a method for secure data transmission and real-time control of a silver-medical intelligent terminal according to the present invention;
[0064] Figure 3 is a schematic structural diagram of an embodiment of an electronic device according to the present invention. Detailed Embodiments
[0065] The exemplary embodiments of the present invention will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein.
[0066] Figure 1 shows a schematic structural diagram of an embodiment of a system 200 for secure data transmission and real-time control of a silver-medical intelligent terminal provided by the present invention, as Figure 1 shown, the system 200 includes: a preprocessing module 210, an encrypted transmission module 220, a behavior analysis module 230, a policy regulation module 240, and an audit and traceability module 250;
[0067] The preprocessing module 210 is configured to: obtain medical service data and device status data, label a sensitivity level label for the medical service data based on a pre-constructed classification and grading model, divide the medical service data with the sensitivity level label into multiple data blocks according to a preset rule, and generate a hash identifier uniquely bound to each data block through a blockchain node;
[0068] The encryption transmission module 220 is used to: match a preset encryption algorithm combination according to the sensitivity level label, extract the timing pulse sequence in the device status data, determine the sharding timing reference, and based on the sharding timing reference, perform dynamic sharding and cutting on each data block to generate target medical service data with sharding serial numbers, recombine the target medical service data with the hash identifier to generate an encrypted data packet carrying the hash identifier and the sharding serial number, and transmit the encrypted data packet to the target node through the encryption transmission protocol;
[0069] The behavior analysis module 230 is used to: capture the traffic characteristics of the transmission path of the encrypted data packet and obtain the operation behavior log, input the traffic characteristics and the operation behavior log into the federated learning model, extract the multi-dimensional feature vector including the data flow direction, the terminal identity and the operation timing, and calculate the real-time threat index based on the multi-dimensional feature vector;
[0070] The policy regulation module 240 is used to: dynamically switch the encryption algorithm combination according to the real-time threat index to obtain the target encryption algorithm combination, generate a hash identifier verification rule based on the target encryption algorithm combination, send a control instruction of the hash identifier verification rule to the target node, and isolate the abnormal transmission path based on the software-defined network technology;
[0071] The audit and traceability module 250 is used to: perform reverse recombination verification on the data transfer process according to the hash identifier and the sharding serial number stored in the blockchain, use the zero-knowledge proof algorithm to verify the integrity signature and the operation compliance label of each sharded medical service data. If the verification fails, generate a data tampering warning and trigger a preset data backtracking mechanism, and generate an audit report.
[0072] Specifically, the system performs a sensitivity assessment on the medical service data through a pre-constructed classification and grading model, and labels three-level sensitive labels according to the data type and privacy regulation requirements. Subsequently, the data after labeling is divided into data blocks of a fixed size according to a preset rule by using the blockchain-based data block protocol, and a unique hash identifier is generated through the SHA-256 algorithm. The hash value is bound to the data block content, the timestamp and the node signature, and is written into the blockchain ledger in real time to achieve non-tamperable evidence storage. The device status data is collected through the time series database, and the device operation parameters and the network status are recorded as the reference basis for subsequent dynamic sharding.
[0073] Match the encryption policy according to the sensitivity label. For highly sensitive data, a combined algorithm of AES-256 and SM9 asymmetric encryption is used. For medium and low sensitive data, AES-128 or ChaCha20-Poly1305 is selected. At the same time, analyze the timing pulse characteristics in the device status data, construct a sharded timing reference model, and dynamically adjust the sharding cutting frequency and size. After sharding, the data is appended with shard numbers and blockchain hash identifiers, reorganized into encrypted data packets, and transmitted to the target node through the TLS1.3 protocol. During the process, the proxy re-encryption technology is combined to allow authorized nodes to decrypt the data through the key conversion mechanism to avoid the exposure of the original key.
[0074] During the data transmission process, the software-defined network controller (SDN controller) is used to capture the traffic characteristics of the transmission path in real time, and the user identity, access time, and operation type in the operation log are collected synchronously. A distributed anomaly detection model is constructed using the federated learning framework. Each node locally trains an LSTM-based traffic behavior baseline model, and the central server aggregates the model parameters to update the global detector. The model outputs a multi-dimensional feature vector, including the data flow entropy value, the terminal identity confidence level, and the operation timing deviation degree. The real-time threat index (RTI) is calculated through weighted fusion to quantitatively evaluate the potential risks of the current transmission link.
[0075] When the threat index exceeds the preset threshold, the dynamic defense mechanism is triggered. The encryption algorithm switching protocol is called through the smart contract to upgrade the current encryption combination to a quantum-resistant algorithm (such as NTRU or Lattice-based); generate a BGP-based hash identifier verification rule to force the target node to perform a blockchain hash value verification before decryption; combine the software-defined network (SDN) technology to isolate the abnormal transmission path and reroute it to the backup link. The policy change records are synchronized to the blockchain network through the PBFT consensus mechanism to ensure the consistency of the network-wide policy.
[0076] Based on the hash identifier and shard number stored in the blockchain, construct a data flow graph. During the audit, two-stage verification is achieved through zero-knowledge proof (ZKP). Verify the integrity of the hash chain of each shard of data to ensure that it has not been tampered with; verify the identity compliance label in the operation log through ring signature. If the verification fails, start the reverse recombination mechanism to locate the abnormal shard and trigger a data rollback. Finally, a standardized report containing the timestamp, the list of verification nodes, and the audit conclusion is generated, that is, the audit report.
[0077] The technical solution of this embodiment is driven by sensitivity classification labels for dynamic encryption and sharding cutting, which improves the accuracy of data protection. Based on the coordination of the sharded timing reference and the encrypted transmission protocol, the timing attack path is blocked. Combining the blockchain hash identifier and zero-knowledge proof verification, it realizes the dual guarantees of decentralized audit and tampering location, meeting the requirements of the whole-link secure transmission and real-time control of medical terminal data.
[0078] In an optional manner, the preprocessing module 210 is specifically used for:
[0079] The natural language processing model in the classification and grading model is used to perform semantic recognition of key entity information in medical business data, including patient identity information and diagnosis codes;
[0080] Input key entity information into the classification and grading model, and annotate the sensitivity level labels according to the preset sensitivity grading rules; wherein, the data containing patient identity information is annotated as the first sensitivity level data, the data containing diagnosis codes is annotated as the second sensitivity level data, and the remaining data is annotated as the third sensitivity level data;
[0081] Based on the sensitivity level labels, the medical business data is divided into blocks using a dynamic window segmentation algorithm; wherein the block length of the first sensitivity level data is set to a fixed value, and the block length of the second sensitivity level data and the third sensitivity level data is dynamically adjusted according to the data entropy value;
[0082] The blocked data is input into the smart contract of the blockchain node, and a hash identifier associated with the content of each data block and the block order is generated through the SHA-3 algorithm, and the hash identifier is written into the Merkle tree structure of the blockchain.
[0083] In this embodiment, the natural language processing model in the classification and grading model is defined as a deep learning model using a BERT or BiLSTM-CRF structure, which is used to perform entity recognition on unstructured text in medical business data (such as medical records, examination reports). Key entity information includes patient identity information (such as name, ID number) and diagnosis code (such as ICD-10 code), where the diagnosis code is limited to internationally used standardized disease classification identifiers and does not involve specific diagnostic methods or treatment plans. The model parses text semantics through a pre-trained word vector library and outputs medical data with entity tags.
[0084] The sensitivity grading rules adopt a three-level labeling system: the first sensitivity level data is defined as a complete field containing patient identity information or a reversible data fragment with a hash map (such as a ciphertext of an ID card number), the second sensitivity level data is defined as a data unit containing a diagnosis code and an associated timestamp (such as "J45.901|2023-08-20"), and the third sensitivity level data is ordinary medical records that do not contain the above two types of entities (such as equipment logs, drug inventory). The labeling process is implemented through regular expression matching and entity position weighted algorithms. For example, when identity information and diagnosis codes exist in a data block at the same time, it is preferentially labeled as the first sensitivity level.
[0085] The dynamic window segmentation algorithm is used to adjust the chunking strategy according to sensitivity labels: for data of the first sensitivity level, the fixed chunk length is 512 bytes to ensure the consistency of encryption strength; the chunk lengths of data of the second and third sensitivity levels are dynamically calculated based on the data entropy value. Specifically, the Shannon entropy formula is used to measure the randomness of the byte distribution within the data block. When the entropy value is higher than the threshold, 256-byte short chunks are used to improve the transmission efficiency, and when the entropy value is lower than the threshold, 1024-byte long chunks are used to reduce the number of shards. The chunk boundary detects the data entity distribution density through a sliding window to avoid storing a single entity across chunks.
[0086] The data entropy value is defined as a byte-level information uncertainty index calculated using the Shannon entropy formula. This index is used to quantify the randomness of data. High-entropy data corresponds to encrypted ciphertext or compressed data, while low-entropy data corresponds to unencrypted structured text.
[0087] The SHA-3 algorithm uses the Keccak-256 variant to generate a 256-bit hash value as the unique identifier for the data block. The hash value is bound to the data block content, the chunk sequence number, and the hash value of the previous block. For example, the hash value H_n of the nth block is H_n = Hash(H_{n - 1} || Content_n || n), where || represents the concatenation operation. This association relationship ensures that the chunk order cannot be tampered with.
[0088] The Merkle tree structure is a binary tree that stores hash identifiers in the blockchain. The leaf nodes are the hash values of each data block, and the non-leaf nodes are the concatenated hashes of their child nodes. For example, the process of constructing the Merkle tree for data blocks B1 - B4 is as follows: Hash(B1) and Hash(B2) generate the parent node Hash12, Hash(B3) and Hash(B4) generate the parent node Hash34, and finally the root node is Hash(Hash12 || Hash34). This structure is used to quickly verify the integrity of data blocks. Any single block tampering will cause the hash value of the root node to change.
[0089] Specifically, medical business data is input into the natural language processing model, and the model outputs JSON-structured data with entity tags. According to the entity tagging results, the data is labeled as the first sensitivity level, the second sensitivity level, or the third sensitivity level.
[0090] For data of the first sensitivity level, a fixed 512-byte chunk is used. If the original data is less than 512 bytes, random numbers are filled to form a complete block. For data of the second sensitivity level, the entropy value is calculated: if the entropy value ≥ 7.5 (such as encrypted diagnostic codes), 256-byte chunks are used; if the entropy value < 7.5 (such as plaintext diagnostic codes), 1024-byte chunks are used. When chunking, the entity boundary is detected through a sliding window to ensure that a single entity is not stored across chunks.
[0091] Input the chunked data into the smart contract in sequence and call the SHA-3 algorithm to generate a chained hash.
[0092] For example, the hash chain of the chunk sequence B1→B2→B3 is as follows:
[0093] H1 = Hash(B1||0x00);
[0094] H2 = Hash(H1||B2||0x01);
[0095] H3 = Hash(H2||B3||0x02);
[0096] Among them, 0x00 and 0x01 are chunk sequence identifiers. All hash values are written into the Merkle tree, the leaf nodes are arranged in the chunk sequence, and the root hash value is stored on the chain.
[0097] In an optional manner, the encryption transmission module 220 is specifically used for:
[0098] Construct an encryption policy mapping table according to the sensitivity level label; among them, the data of the first sensitivity level adopts a nested policy of asymmetric encryption algorithm and symmetric encryption algorithm, the data of the second sensitivity level adopts a combined policy of short-key asymmetric encryption algorithm and stream encryption algorithm, and the data of the third sensitivity level adopts a single-layer policy of standard symmetric encryption algorithm;
[0099] Based on the encryption policy mapping table, extract the initial timing pulse sequence from the device status data, perform Fourier transform on the initial timing pulse sequence, and generate the initial shard timing reference;
[0100] Dynamically adjust the offset of the initial shard timing reference according to the shard threshold corresponding to the sensitivity level label to generate the shard timing reference.
[0101] In this embodiment, the encryption policy mapping table is defined as a mapping table based on the sensitivity level label and the encryption algorithm. The data of the first sensitivity level adopts a nested policy of asymmetric encryption algorithm and symmetric encryption algorithm, that is, first use the RSA or ECC algorithm to perform asymmetric encryption on the data, and then use AES-256 for symmetric encryption to form a double protection layer. The data of the second sensitivity level adopts a combined policy of short-key asymmetric encryption algorithm and stream encryption algorithm. Among them, short-key asymmetric encryption refers to selecting elliptic curve encryption (ECC-224) to reduce the key length, and stream encryption uses the ChaCha20-Poly1305 algorithm to achieve byte-by-byte encryption, which is suitable for dynamic data streams. The data of the third sensitivity level adopts a single-layer policy of standard symmetric encryption algorithm, that is, only use the AES-128 algorithm for encryption to reduce the calculation overhead.
[0102] The timing pulse sequence refers to the periodic network bandwidth fluctuation signal extracted from the device status data, which is manifested as a continuous pulse waveform on the time axis. The extraction process includes:
[0103] 1) Obtain timing parameters such as network transmission delay and packet loss rate through the device status acquisition interface;
[0104] 2) Use the sliding window algorithm to detect the peak and valley points of the pulse and generate the original pulse sequence.
[0105] The Fourier transform is used to convert the time-domain pulse sequence into frequency-domain characteristics, identify the main frequency component (such as a periodic pulse of the order of 10 ms), and generate the initial sliced timing reference accordingly. For example, if the main pulse frequency is 100 Hz, the initial sliced timing reference interval is 10 ms.
[0106] The slicing threshold is dynamically set according to the sensitivity level. Further, the first sensitivity level corresponds to a strict threshold (such as the pulse interval offset ≤ 1 ms), which forces the sliced timing reference to remain stable; the second and third levels use elastic thresholds (such as an offset allowance of ±5 ms), allowing the slicing frequency to be adjusted according to the network state. The dynamic adjustment process is as follows:
[0107] 1) Calculate the difference Δ between the current pulse interval and the initial reference;
[0108] 2) If Δ exceeds the threshold, correct the sliced reference offset according to the sensitivity level weight coefficient (the weight of the first level is 0.8, the second level is 0.5, and the third level is 0.3) to ensure that the fluctuation of the high-sensitive data slicing interval is minimized.
[0109] The final generation rule of the sliced timing reference is: by superimposing the dynamically adjusted offset on the initial reference interval, a sliced time window adapted to the network state is formed. For example, if the initial reference is 10 ms, and for the second sensitivity level data, Δ = +3 ms is detected and the threshold is ±5 ms, then the actual slicing interval is adjusted to 10 ms + (3 ms × 0.5) = 11.5 ms.
[0110] Specifically, for encryption policy matching, the data of the first sensitivity level (such as the ciphertext of the patient's ID number) is encrypted by RSA-2048 and then encrypted by AES-256 to form nested ciphertext. The data of the second sensitivity level (such as the ICD-10 diagnosis code) uses the ECC-224 encryption public key and combines with the ChaCha20 stream encryption to generate hybrid ciphertext. The data of the third sensitivity level (such as device logs) is directly encrypted by AES-128.
[0111] For timing reference generation, collect the network status data of the acquisition device and extract the bandwidth pulse sequence. Apply the Fast Fourier Transform (FFT) to the pulse sequence to identify the main frequency component (for example, the detected main frequency is 50 Hz, corresponding to a period of 20 ms). Set the sharding threshold according to the sensitivity label: the first level allows a deviation of ±1 ms, the second level ±3 ms, and the third level ±5 ms.
[0112] For dynamic sharding execution, when the network bandwidth drops and the pulse interval extends to 22 ms (initial reference 20 ms), the data offset Δ of the first sensitivity level is +2 ms, exceeding the threshold by 1 ms, triggering reference correction, that is, the new sharding interval = 20 ms - (2 ms × 0.8) = 18.4 ms. For the data of the second sensitivity level in the same scenario, Δ = +2 ms does not exceed the threshold of 3 ms, and the original sharding interval of 20 ms is maintained.
[0113] In an alternative approach, the encryption transmission module 220 is further specifically configured to:
[0114] Dynamically calculate the sharding length threshold for each data block according to the pulse interval of the sharding timing reference, and based on the sharding length threshold, use a streaming sharding algorithm to cut each data block to generate multiple sharding units. Embed the sharding sequence number at the head of each sharding unit, calculate the hash digest of the content of the previous sharding unit through the SHA-3 algorithm, and add the hash digest to the head of the current sharding unit to form a sharding hash chain;
[0115] Attach a unique increasing sequence identifier to each sharding unit based on the timestamp of the sharding timing reference, cross-reorganize each sharding unit and the hash identifier according to the sharding sequence number, generate a chained check code according to the hash digest of adjacent sharding units in the sharding hash chain, and bind the chained check code with the sequence identifier to construct an encrypted data packet containing hash chain verification logic;
[0116] Generate a dynamic session key based on the TLS / SSL protocol, perform application layer encryption on the encrypted data packet, and attach the timestamp and device fingerprint information to form a complete verification chain, and transmit it to the target node.
[0117] In this embodiment, the pulse interval of the sharding timing reference refers to the time difference between adjacent wave peaks / valleys of the timing signal formed by the network bandwidth fluctuation extracted from the device status data. Its function is to dynamically reflect the network transmission stability. For example, when the pulse interval shortens, it indicates a decrease in network bandwidth, and the sharding length needs to be reduced to avoid transmission delay. The sharding length threshold is dynamically calculated according to the ratio of the pulse interval to the preset upper limit of transmission delay. For example, when the pulse interval is 50 ms, the sharding length threshold = reference bandwidth × 50 ms × (1 - packet loss rate).
[0118] The streaming sharding algorithm uses a sliding window mechanism to perform real-time cutting on data blocks. When a data block enters the transmission buffer, the algorithm dynamically adjusts the window step size according to the current shard length threshold. For example, if the threshold decreases from 1MB to 512KB, the window step size is synchronously reduced by 50%, ensuring that the shard size adapts to the network state. The shard sequence number is embedded in the header of each shard unit and encoded using Gray code to avoid recombination errors caused by sequence jumps.
[0119] The SHA-3 algorithm is used here to generate the hash digest of the shard unit, and its features include:
[0120] 1) It achieves collision resistance based on the sponge structure, ensuring that any tampering with the content of the previous shard will cause changes in the hash values of all subsequent shards;
[0121] 2) The length of the hash digest is fixed at 512 bits, which is compatible with the Merkle tree node structure of the blockchain.
[0122] The construction logic of the shard hash chain is to use the SHA-3 hash value of the content of the previous shard as the verification field in the header of the current shard, forming a one-way irreversible chain structure. For example, the header of shard N contains the hash value of shard N-1, enabling cross-shard integrity verification.
[0123] The sequence identifier is generated by hashing the concatenation of the timestamp (accurate to the microsecond level) of the shard timing reference and the device ID, ensuring global uniqueness. For example, the concatenation of the timestamp "20250429123045123456" and the device ID "DEV_001" is hashed using SHA-3 to generate the identifier "a3f8b...", which is used to resist replay attacks. The chained checksum is iteratively calculated by performing an exclusive OR operation on the hash digests of adjacent shards, and finally an aggregated checksum is generated for quick verification at the receiving end.
[0124] The dynamic session key of the TLS / SSL protocol is generated using the ECDHE ephemeral key exchange mechanism, and an independent key pair is generated for each transmission session. The client generates ephemeral elliptic curve parameters and negotiates a 256-bit symmetric key with the target node through the SSL protocol. The key lifecycle is synchronized with the shard timing reference and is automatically discarded after timeout. The device fingerprint information includes the hash value of the MAC address and the firmware version encoding, which is Base64-encoded and appended to the tail of the encrypted data packet for two-way authentication of the identity of the target node.
[0125] Specifically, for shard cutting and hash chain generation, the initial data block (2MB) calculates the shard length threshold as 512KB according to the current pulse interval of 20ms and is divided into 4 shard units through a sliding window. The sequence number "0x0001" is written in the header of shard 1, and the content is hashed using SHA-3 to generate H1; the hash H1 is embedded in the header of shard 2 and the content hash H2 is calculated, and so on to form a hash chain.
[0126] For packet recombination and verification, the fragmentation units and blockchain hash identifiers are arranged in an odd-even cross pattern (e.g., fragmentation unit 1 is bound to hash identifier A, and fragmentation unit 2 is bound to identifier B) to generate a cross-recombination matrix. Calculate the exclusive OR value of adjacent fragment hashes to generate a chained verification code "0x9A7F", which is bound to the sequence identifier and stored in the packet verification area.
[0127] For application layer encrypted transmission, a temporary session key "0x2E5C..." is negotiated through the TLS1.3 protocol, and the packet is encrypted using the AES-GCM mode. Append the device fingerprint "DEV001_V2.3|MAC:9A:CD..." and the UTC timestamp "20250429T123045Z" to form a complete verification chain, and transmit it to the target node through multi-path TCP concurrency.
[0128] In an optional manner, the behavior analysis module 230 is specifically used for:
[0129] Collect traffic characteristics of the transmission path based on the software-defined network controller, and extract operation behavior characteristics from the device audit log. Synchronize and correlate the pulse intervals in the traffic characteristics with the timestamps of the operation behavior characteristics through the time series alignment algorithm to obtain synchronized characteristics;
[0130] Input the synchronized characteristics into the graph convolutional network in the federated learning model to extract a multi-dimensional feature vector containing data flow correlation degree, device identity fingerprint, and operation instruction sequence;
[0131] Based on the historical attack patterns and dynamic behavior baselines stored in the preset threat knowledge graph, construct a threat assessment matrix containing weight assignment rules and feature deviation thresholds. According to the spatio-temporal correlation strength of each dimension in the multi-dimensional feature vector, calculate the distribution difference probability between the current behavior pattern and the known attack patterns through the KL divergence algorithm, and dynamically adjust the weight coefficients in combination with the device type and network load status to output a real-time threat index.
[0132] In this embodiment, the software-defined network controller refers to a network management and control component deployed on the central node, which can obtain the traffic statistics information of the switch port in real time through the OpenFlow protocol. Its function is to collect traffic characteristics of the transmission path with millisecond-level accuracy, including: packet size distribution, transmission rate fluctuation, TCP retransmission rate. For example, when it is detected that the burst traffic on a certain path exceeds 3 times the baseline value, trigger the feature collection mechanism and record the pulse interval sequence within the time window.
[0133] The device audit log is stored in the encrypted storage area of the terminal device, and records operation behavior characteristics including device operation types (such as data read and write, port start and stop), operation timestamps, and the signatures of the initiating processes.
[0134] The log entry format is:
[0135] "20250429_123045|DEV001|WRITE|PID:0x3A2B|SIG:9C8D...", integrity signature is performed through the SM3 algorithm to prevent tampering.
[0136] The timing alignment algorithm uses dynamic time warping technology to non-linearly match the pulse interval sequence in the traffic characteristics (such as [20ms, 35ms, 15ms]) with the timestamps of the operation behavior characteristics (such as [12:30:45.100, 12:30:45.135, 12:30:45.150]). By constructing a cost matrix to calculate the minimum path offset, for example, aligning the second pulse interval of 35ms to the time period of 12:30:45.135 - 12:30:45.170, a synchronous feature with completely synchronized time axes is generated.
[0137] The federated learning model is formed by aggregating local models of multiple terminal devices. Among them, the nodes of the graph convolutional network represent device and server entities, and the edge weights represent the data transmission frequency. For example, the edge weight between the device node DEV001 and the server node SRV_003 = the number of transmissions in the past 5 minutes / the total number of transmissions. After the model inputs the synchronous feature, the data flow correlation degree (such as the path contribution value of DEV001 → SRV_003), the device identity fingerprint (such as the combined feature of MAC address hash and SSL certificate fingerprint), and the operation instruction sequence (such as the time interval pattern of consecutive write instructions) are calculated in the hidden layer.
[0138] The threat knowledge graph is stored in the form of a graph database, containing the relationship topology of historical attack events, such as the triple link of "port scan → vulnerability exploitation → data exfiltration". The dynamic behavior baseline statistically calculates the mean and variance of the normal operation mode through a sliding time window. For example, the average data transmission volume from 9:00 to 10:00 every day is taken as the reference value ± 15%.
[0139] The threat assessment matrix is a two-dimensional weight table. The rows represent the feature dimensions (such as data flow anomaly degree, device fingerprint credibility), and the columns represent the attack types (such as DDoS, man-in-the-middle attack). The matrix element values are dynamically calculated according to the indication strength of the feature for the attack. For example, the initial weight of the data flow anomaly degree for the man-in-the-middle attack is 0.7, and it is adjusted up to 0.9 when the network load exceeds 70%.
[0140] The KL divergence algorithm is used to quantify the difference in probability distributions between the current behavior pattern and the attack patterns in the knowledge graph. The multi-dimensional feature vector is normalized to a probability distribution P, and the known attack pattern distribution is Q. Calculate KL(P||Q) = ΣP(i)log(P(i) / Q(i)). When the calculation result exceeds a threshold (such as 1.2), a threat is determined. The weight coefficient is dynamically adjusted by multiplication according to the device type (such as the weight of the terminal device = 0.8, the weight of the server = 1.2) and the network load (such as the coefficient = 1.0 when the load is 50%, and the coefficient = 1.5 when the load is 80%), and finally a real-time threat index normalized to 0-1 is output.
[0141] Specifically, for feature synchronization and input, collect the traffic pulse sequence [15ms, 22ms, 18ms] of the acquisition transmission path, and extract the operation timestamp sequence [12:30:45.100, 12:30:45.122, 12:30:45.140] from the device audit log. Generate the synchronized feature pairs through the time series alignment algorithm: pulse 15ms → 12:30:45.100 - 12:30:45.115, and the operation "WRITE" occurs at 12:30:45.112, which is determined to be a valid association within the time window.
[0142] For the federated learning model processing, input the synchronized features into the graph convolutional network. Calculate that the data flow correlation degree between the DEV001 device node and the SRV_003 server node is 0.85 (threshold 0.6), the device fingerprint matching degree is 0.92 (threshold 0.9), and it is detected that the interval between three consecutive write operations is 12ms (the baseline mean is 25ms ± 5ms). Output the multi-dimensional feature vector [0.85, 0.92, 0.65, 0.78], which respectively correspond to the flow anomaly degree, fingerprint credibility, operation frequency deviation value, and time series compactness index.
[0143] For the generation of the threat index, retrieve the feature distribution Q = [0.8, 0.3, 0.7, 0.6] of the man-in-the-middle attack from the threat knowledge graph, and the current feature distribution P = [0.85, 0.92, 0.65, 0.78]. Calculate the KL divergence value = 0.85ln(0.85 / 0.8) + 0.92ln(0.92 / 0.3) +... ≈ 1.35. Combine the device type coefficient (terminal device 0.8) and the network load coefficient (70% → 1.2), and the final threat index = 1.35 × 0.8 × 1.2 = 1.296, which exceeds the preset threshold of 1.0 and triggers an alarm.
[0144] In an alternative approach, the policy regulation module 240 is specifically used for:
[0145] When the real-time threat index exceeds the preset switching threshold, dynamically switch the encryption algorithm combination in the encryption policy mapping table to determine the target encryption algorithm combination, and determine the network layer identifier of the abnormal transmission path according to the real-time threat index and the abnormal data flow characteristics in the multi-dimensional feature vector;
[0146] Based on the public key attribute of the asymmetric encryption algorithm in the target encryption algorithm combination, generate an initial hash identifier verification rule containing the hash digest recursive verification logic, and compile the initial hash identifier verification rule into a hash identifier verification rule that can be executed across nodes through the blockchain smart contract;
[0147] Add the redundant check shard unit to the shard hash chain, and activate the multi-path parallel transmission mechanism of the shard unit data based on the multi-path transmission load balancing algorithm of the shard unit data;
[0148] Send a verification control instruction containing the hash identifier verification rule to the target node, and perform cross-node two-way verification on the distributed consistency of the hash identifier and the continuity of the shard sequence number through the blockchain smart contract;
[0149] Based on the flow table dynamic control protocol of the software-defined network controller, send an update instruction containing the traffic blocking rule and the priority marking isolation strategy to the target switch bound to the abnormal transmission path, add the network layer identifier and the terminal feature information to the isolation policy queue, synchronously update the flow table entries of the target switch according to the timestamp of the shard timing reference, block the data forwarding interface of the abnormal transmission path, and construct a virtual isolation channel.
[0150] In this embodiment, the real-time threat index refers to the quantified security risk value output by the behavior analysis module, with a range of 0-1. The higher the value, the higher the threat level of the current transmission environment. The preset switching threshold is set to 0.8 according to the historical attack data statistics. When the index exceeds this value, the encryption algorithm dynamic switching mechanism is triggered. For example, when the index reaches 0.85, it is determined that the encryption strength needs to be improved.
[0151] The encryption policy mapping table is a corresponding relationship table that stores the corresponding relationships between data of different sensitivity levels and encryption algorithm combinations. Specifically, in the implementation, the encryption policy for the first sensitive level data is RSA-4096 nested AES-256, the second sensitive level data uses ECC-256 combined with ChaCha20, and the third sensitive level data adopts AES-128. Dynamic switching means adjusting the mapping relationship according to the threat index. For example, when the threat index > 0.8, the nested policy for the first sensitive level data is upgraded to RSA-8192 nested AES-512.
[0152] An abnormal data flow characteristic refers to a parameter in a multi-dimensional feature vector that identifies a deviation of the data path from the normal mode. For example, when device A sends data to server B, an abnormal routing record is detected where the actual flow of the data packet is to an unknown IP address. The network layer identifier includes combined information of the source / destination IP address, VLAN tag, and MAC address, which is used to uniquely mark the transmission path. For example, the abnormal path identifier is "192.168.1.10 → 10.2.3.45|VLAN:100|MAC:00:1A:2B...".
[0153] The public key property of an asymmetric encryption algorithm refers to the public nature of the public key in the public key infrastructure (PKI). When generating the recursive verification logic for the hash digest, the public key is used to verify the signature of each shard digest in the hash chain layer by layer. For example, the hash value H1 of shard 1 needs to be verified with the public key, and the hash value H2 of shard 2 needs to verify the correlation between H1 and H2 simultaneously, forming a recursive verification chain.
[0154] A blockchain smart contract is deployed in blockchain nodes and is used to compile the initial hash identifier verification rules into code logic that can be executed across nodes. For example, when a target node receives an encrypted data packet, the smart contract automatically triggers a check on the continuity of the shard sequence number. If it detects that shard 3 is missing, it rejects the subsequent shards.
[0155] The redundant verification shard unit is a newly added backup data shard, and its content contains the aggregated result of the hash values of the previous N shards. For example, a redundant shard is inserted after every 10 shards, storing the exclusive OR operation result of the hash values of the previous 10 shards, which is used for quick verification of data integrity during transmission interruption.
[0156] The multi-path transmission load balancing algorithm adopts a weighted round-robin mechanism to allocate the transmission tasks of shard units in real-time according to the path bandwidth. For example, if the bandwidth occupancy rate of path A is 60% and that of path B is 30%, then the new shard unit is allocated to path B at a ratio of 2:1 to ensure transmission efficiency and fault tolerance.
[0157] Cross-node two-way verification refers to the synchronization and verification of the consistency of hash identifiers between a target node and at least two other blockchain nodes. For example, when the target node receives a shard, it sends verification requests to node X and node Y, and only confirms the validity of the shard after reaching a consensus on the hash value of shard 5 among the three.
[0158] The flow table dynamic control protocol is implemented based on the OpenFlow protocol and is used to issue traffic control rules to switches. The priority marking isolation strategy sets a priority field (such as 0 - 65535) in the flow table entry. When the network layer identifier of an abnormal path is detected, its traffic is marked as the lowest priority and the forwarding rate is limited to 1 Kbps to achieve soft isolation.
[0159] The virtual isolation channel is constructed through the VXLAN tunneling technology, encapsulating the traffic of the abnormal path into an independent virtual network. For example, a tunnel with VXLAN ID 5001 is created for the abnormal IP address 10.2.3.45, physically isolating its data packets from the normal traffic.
[0160] Specifically, for threat detection and algorithm switching, when the real-time threat index reaches 0.85 (switching threshold 0.8), the policy regulation module queries the encryption policy mapping table and switches the encryption algorithm for the first sensitive level data to RSA-8192 nested AES-512. Extract the abnormal data flow characteristics from the multi-dimensional feature vector, and find that the data packets originally destined for the server SRV_003 are actually sent to the unknown IP address 10.2.3.45, generating the network layer identifier "192.168.1.10 → 10.2.3.45|VLAN:100|MAC:00:1A:2B...".
[0161] For hash verification rule generation and execution, a recursive verification rule is generated based on the RSA public key. Further, each shard header contains the RSA signature of the previous shard hash value, and the target node needs to verify the validity of the signature with the public key. The blockchain smart contract compiles this rule into executable code, stipulating that the shard sequence numbers must be continuous and the adjacent shard hash values must match. For example, the header of shard 5 needs to contain the signature of the hash value of shard 4, otherwise a consistency warning is triggered.
[0162] For redundant shards and multi-path transmission, one redundant shard is inserted every 5 shards in the shard hash chain, storing the SHA-3 aggregation result of the first 5 shard hash values. For example, the redundant shard R1 = H1 ⊕ H2 ⊕ H3 ⊕ H4 ⊕ H5. According to the path load status (path A load 70%, path B load 30%), shards 6 - 10 are allocated to path A and path B in a 7:3 ratio, and the redundant shard R1 is transmitted through both paths at the same time.
[0163] For cross-node verification and flow table update, when the target node receives shard 6, it sends verification requests to blockchain nodes X and Y, and the three compare whether the hash values of shard 6 are the same. If node X returns an inconsistent result, then discard shard 6 and request retransmission. The software-defined network controller issues a flow table update instruction to the target switch, marking the traffic priority of the network layer identifier "10.2.3.45" as 100, restricting its forwarding interface rate to 1Kbps, and creating a virtual channel with VXLAN ID = 5001 to isolate this traffic.
[0164] The subsequent shard transmission of the abnormal path is restricted within the virtual channel, and the normal traffic is transmitted through the main path. The policy regulation module records the timestamp of this encryption algorithm switch, the position of redundant shard insertion, and the flow table change entries, writing them into the audit log for traceability use.
[0165] In an alternative approach, the audit traceability module 250 is specifically configured to:
[0166] Extract the hash chain and shard sequence number of the target data block from the blockchain, and reconstruct the original shard order through a reverse traversal algorithm;
[0167] Use the zero-knowledge proof algorithm to generate an integrity signature for each shard of medical business data, and verify the consistency between the hash digest of each shard unit and the blockchain record;
[0168] If the verification fails, extract the historical shard medical business data from the blockchain standby node, perform a difference comparison to locate the tampering position, and bind the tampering position to the abnormal event timestamp corresponding to the shard sequence number to generate an audit report containing abnormal timing marks and abnormal transmission path location records.
[0169] In this embodiment, the hash chain refers to a chain structure stored in the blockchain formed by the hash digest of the shard unit header. The hash value of each shard unit is generated based on the content of the previous shard, forming an irreversible association. For example, the hash value H5 of shard 5 is calculated from the content of shard 4, and any tampering of shard content will cause all subsequent hash values to mismatch.
[0170] The reverse traversal algorithm is used to start from the latest block of the blockchain and trace back the original shard order in reverse order according to the shard sequence number. The algorithm gradually traces back to the initial shard based on the predecessor hash pointer in the shard hash chain to reconstruct the complete shard sequence. For example, starting from shard 100, through the "predecessor hash" field of each shard header, traverse to shard 1 to verify the continuity of the sequence number and the integrity of the hash chain.
[0171] The zero-knowledge proof algorithm refers to zk-SNARK (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge), which is used to generate an integrity signature for shard data. This signature can prove that the shard content has not been tampered with without disclosing the original data. For example, use the Groth16 protocol to generate a proof π, and the verifier verifies the validity of π through public parameters to ensure that the shard hash is consistent with the blockchain record.
[0172] The integrity signature verification process includes two steps: 1) Verify the validity of the zero-knowledge proof π to confirm the correctness of the shard hash calculation; 2) Compare the current shard hash value with the historical hash stored in the blockchain. If any link fails, a tampering alarm is triggered. For example, if the hash calculation proof of shard 20 is invalid or does not match the hash value recorded in blockchain node X, it is determined that the shard has been tampered with.
[0173] An abnormal timing mark is structured data containing a shard sequence number, a tampered timestamp, and a path location code. When the verification fails, the system extracts the historical data of the standby node and locates the specific tampered shard through differential comparison. For example, if the hash of shard 35 in node A is H35, and it becomes H35' in node B, then the abnormal time is marked as the generation timestamp of shard 35, and the transmission path ID is recorded as "PATH_192.168.1.10→10.2.3.45".
[0174] The data traceback mechanism is automatically triggered by the blockchain smart contract, and it pulls the untampered shard copies from the standby node to replace the abnormal shards. For example, when shard 50 is marked as abnormal, the smart contract calls the copies of shard 50 in nodes X, Y, and Z, selects the correct version for recovery using the majority consensus principle, and updates the audit report.
[0175] Specifically, for shard order reconstruction, the audit traceability module extracts the hash chain of shard sequence numbers 200 - 250 from the latest blockchain block (block height 1000), and verifies the previous hash pointers of each shard in reverse order (250→249→…→200) through a reverse traversal algorithm. If the previous hash of shard 230 points to shard 229, but the calculated hash value of shard 229 does not match the pointer, then it is determined that shard 230 has a risk of being tampered with.
[0176] For zero-knowledge proof verification, a zk-SNARK integrity signature is generated for shard 230. Using the Groth16 protocol, with the shard content as the private input, the hash value H230 is calculated and the proof π is generated. The verification node verifies the validity of π through elliptic curve bilinear pairing. If the verification fails, it is confirmed that the shard content has been tampered with.
[0177] For differential comparison and location, the historical versions of shard 230 stored in the blockchain standby nodes (nodes X, Y, and Z) are extracted. By comparing the hash values, it is found that H230' of node X is inconsistent with H230 of Y and Z. Further comparing the content differences, the tampered location is located in the "diagnostic code" field (offset 120 - 128 bytes) of shard 230.
[0178] For audit report generation, the abnormal timestamp is recorded as the generation time of shard 230, "2025-04-29 14:23:05", and the abnormal path identifier is the transmission path from the source IP "192.168.1.10" to the destination IP "10.2.3.45". The report includes a hexadecimal differential comparison diagram of the tampered field and a hash value comparison table before and after recovery.
[0179] For automatic recovery, the data backtracking mechanism calls the smart contract to obtain valid copies of shard 230 from nodes Y and Z, overwrite the abnormal data of node A, add a recovery transaction record to the blockchain, and update the Merkle root hash. The audit report is synchronously uploaded to the regulatory node for filing.
[0180] Figure 2 The flowchart of an embodiment of a method for secure data transmission and real-time control of a silver-medical intelligent terminal provided by the present invention is shown. As Figure 2 shown, the method includes the following steps:
[0181] Obtain medical service data and device status data, label the sensitivity level tags for the medical service data based on a pre-constructed classification and grading model, divide the medical service data with sensitivity level tags into multiple data blocks according to preset rules, and generate a hash identifier uniquely bound to each data block through a blockchain node;
[0182] According to the sensitivity level tags, match a preset encryption algorithm combination, extract the timing pulse sequence in the device status data, determine the shard timing reference, and based on the shard timing reference, perform dynamic shard cutting on each data block to generate target medical service data with shard numbers, recombine the target medical service data with the hash identifier to generate an encrypted data packet carrying the hash identifier and shard number, and transmit the encrypted data packet to the target node through an encrypted transmission protocol;
[0183] Capture the traffic characteristics of the transmission path of the encrypted data packet, obtain the operation behavior log, input the traffic characteristics and the operation behavior log into the federated learning model, extract a multi-dimensional feature vector including data flow direction, terminal identity and operation timing, and calculate the real-time threat index based on the multi-dimensional feature vector;
[0184] According to the real-time threat index, dynamically switch the encryption algorithm combination to obtain a target encryption algorithm combination, generate a hash identifier verification rule based on the target encryption algorithm combination, send a control instruction of the hash identifier verification rule to the target node, and isolate the abnormal transmission path based on software-defined network technology;
[0185] According to the hash identifier and shard number stored in the blockchain, perform reverse recombination verification on the data transfer process, use the zero-knowledge proof algorithm to verify the integrity signature and operation compliance label of each shard of medical service data. If the verification fails, generate a data tampering warning, trigger a preset data backtracking mechanism, and generate an audit report.
[0186] The technical solution of this embodiment drives dynamic encryption and sharding cutting through sensitivity grading tags, improving the accuracy of data protection. Based on the coordination of sharding timing benchmarks and encryption transmission protocols, it blocks the timing attack path. Combining blockchain hash identification and zero-knowledge proof verification, it realizes dual guarantees of decentralized auditing and tampering positioning, meeting the requirements of full-link secure transmission and real-time control of medical terminal data.
[0187] For the steps of each parameter and step in the above-mentioned method for secure transmission and real-time control of data of the silver-medical intelligent terminal in this embodiment to achieve the corresponding functions, reference can be made to the parameters and each module in the embodiment of the silver-medical intelligent terminal data secure transmission and real-time control system 200 in the above text, which will not be elaborated here.
[0188] As Figure 3 shown, an electronic device 300 according to an embodiment of the present invention, the electronic device 300 includes a processor 320, the processor 320 is coupled to a memory 310, and at least one computer program 330 is stored in the memory 310. The at least one computer program 330 is loaded and executed by the processor 320 so that the electronic device 300 implements any one of the above silver-medical intelligent terminal data secure transmission and real-time control systems. Specifically:
[0189] The electronic device 300 may vary greatly due to configuration or performance differences, and may include one or more processors 320 (Central Processing Units, CPUs) and one or more memories 310. Among them, at least one computer program 330 is stored in the one or more memories 310, and the at least one computer program 330 is loaded and executed by the one or more processors 320 so that the electronic device 300 implements any one of the silver-medical intelligent terminal data secure transmission and real-time control methods provided in the above embodiments. Of course, the electronic device 300 may also have components such as wired or wireless network interfaces, keyboards, and input / output interfaces for input / output. The electronic device 300 may also include other components for implementing the functions of the device, which will not be elaborated here.
[0190] A computer-readable storage medium according to an embodiment of the present invention stores at least one computer program, and the at least one computer program is loaded and executed by a processor so that the computer implements any one of the above silver-medical intelligent terminal data secure transmission and real-time control methods.
[0191] Optionally, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.
[0192] In an exemplary embodiment, a computer program product or a computer program is further provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes any one of the above-mentioned data security transmission and real-time control methods for the bank-medical intelligent terminal.
[0193] Those skilled in the art know that the present invention can be implemented as a system, a method, or a computer program product. Therefore, the present disclosure can be specifically implemented in the following forms: it can be completely hardware, can be completely software (including firmware, resident software, microcode, etc.), or can be a combination of hardware and software. Generally, it is referred to as "circuit", "module" or "system" in this article. In addition, in some embodiments, the present invention can also be implemented in the form of a computer program product in one or more computer-readable media, and the computer-readable media contain computer-readable program codes.
[0194] Any combination of one or more computer-readable media can be adopted. The computer-readable media can be computer-readable signal media or computer-readable storage media. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device.
[0195] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limitations on the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A silver-medical intelligent terminal data security transmission and real-time control system, characterized in that, Including: A preprocessing module, an encrypted transmission module, a behavior analysis module, a policy regulation module, and an audit and traceability module; The preprocessing module is used to: obtain medical service data and device status data, label the sensitivity level tags for the medical service data based on a pre-constructed classification and grading model, divide the medical service data with the sensitivity level tags into multiple data blocks according to preset rules, and generate a hash identifier uniquely bound to each data block through a blockchain node; The encrypted transmission module is used to: match a preset encryption algorithm combination according to the sensitivity level tag, extract the timing pulse sequence in the device status data, determine the sharding timing benchmark, and based on the sharding timing benchmark, perform dynamic sharding and cutting on each data block to generate target medical service data with shard numbers, recombine the target medical service data with the hash identifier to generate an encrypted data packet carrying the hash identifier and the shard number, and transmit the encrypted data packet to the target node through an encrypted transmission protocol; The behavior analysis module is used to: capture the traffic characteristics of the transmission path of the encrypted data packet, obtain the operation behavior log, input the traffic characteristics and the operation behavior log into a federated learning model, extract a multi-dimensional feature vector including data flow direction, terminal identity, and operation timing, and calculate the real-time threat index based on the multi-dimensional feature vector; The policy regulation module is used to: dynamically switch the encryption algorithm combination according to the real-time threat index to obtain a target encryption algorithm combination, generate a hash identifier verification rule based on the target encryption algorithm combination, send a control instruction of the hash identifier verification rule to the target node, and isolate the abnormal transmission path based on software-defined network technology; The audit and traceability module is used to: perform reverse recombination verification on the data transfer process according to the hash identifier and the shard number stored in the blockchain, use the zero-knowledge proof algorithm to verify the integrity signature and operation compliance label of each shard of medical service data, if the verification fails, generate a data tampering warning and trigger a preset data backtracking mechanism, and generate an audit report.
2. The silver-medical intelligent terminal data security transmission and real-time control system according to claim 1, characterized in that Specifically, the preprocessing module is used to: Use the natural language processing model in the classification and grading model to perform semantic recognition on the key entity information in the medical service data, and the key entity information includes: patient identity information and diagnosis codes; Input the key entity information into the classification and grading model, and label the sensitivity level tags according to the preset sensitivity grading rules; among them, the data containing the patient identity information is labeled as first-level sensitive data, the data containing the diagnosis code is labeled as second-level sensitive data, and the remaining data is labeled as third-level sensitive data; Based on the sensitivity level tags, use the dynamic window segmentation algorithm to divide the medical service data into blocks; among them, the block length of the first-level sensitive data is set to a fixed value, and the block lengths of the second-level sensitive data and the third-level sensitive data are dynamically adjusted according to the data entropy value; Input the chunked data into the smart contract of the blockchain node, generate the hash identifier associated with the content and chunking order of each data block through the SHA-3 algorithm, and write the hash identifier into the Merkle tree structure of the blockchain.
3. The silver-medical intelligent terminal data security transmission and real-time control system according to claim 2, wherein The encryption transmission module is specifically used for: Construct an encryption policy mapping table according to the sensitivity level label; wherein, the first sensitive level data adopts a nested policy of asymmetric encryption algorithm and symmetric encryption algorithm, the second sensitive level data adopts a combined policy of short-key asymmetric encryption algorithm and stream encryption algorithm, and the third sensitive level data adopts a single-layer policy of standard symmetric encryption algorithm; Based on the encryption policy mapping table, extract the initial timing pulse sequence from the device status data, perform Fourier transform on the initial timing pulse sequence, and generate the initial sharding timing reference; Dynamically adjust the offset of the initial sharding timing reference according to the sharding threshold corresponding to the sensitivity level label to generate the sharding timing reference.
4. The silver-medical intelligent terminal data security transmission and real-time control system according to claim 3, characterized in that, The encryption transmission module is also specifically used for: Dynamically calculate the sharding length threshold of each data block according to the pulse interval of the sharding timing reference, and based on the sharding length threshold, use the stream sharding algorithm to cut each data block to generate multiple sharding units, embed the sharding serial number at the head of each sharding unit, and calculate the hash digest of the content of the previous sharding unit through the SHA-3 algorithm, and add the hash digest to the head of the current sharding unit to form a sharding hash chain; Attach a unique increasing sequence identifier to each sharding unit based on the timestamp of the sharding timing reference, cross-recombine each sharding unit with the hash identifier according to the sharding serial number, generate a chain check code according to the hash digest of adjacent sharding units in the sharding hash chain, and bind the chain check code with the sequence identifier to construct an encrypted data packet containing hash chain check logic; Generate a dynamic session key based on the TLS / SSL protocol, perform application layer encryption on the encrypted data packet, and attach the timestamp and device fingerprint information to form a complete verification chain, and transmit it to the target node.
5. The silver-medical intelligent terminal data security transmission and real-time control system according to claim 4, characterized in that, The behavior analysis module is specifically used for: Collect the traffic characteristics of the transmission path based on the software-defined network controller, extract the operation behavior characteristics from the device audit log, and synchronously associate the pulse interval in the traffic characteristics with the timestamp of the operation behavior characteristics through the timing alignment algorithm to obtain the synchronous characteristics; Input the synchronous characteristics into the graph convolutional network in the federated learning model to extract a multi-dimensional feature vector including data flow correlation degree, device identity fingerprint and operation instruction sequence; Based on the historical attack patterns and dynamic behavior baselines stored in the preset threat knowledge graph, construct a threat assessment matrix including weight assignment rules and feature deviation thresholds, calculate the distribution difference probability between the current behavior pattern and the known attack pattern through the KL divergence algorithm according to the spatio-temporal correlation strength of each dimension in the multi-dimensional feature vector, and dynamically adjust the weight coefficient in combination with the device type and network load status, and output the real-time threat index.
6. The silver-medical intelligent terminal data security transmission and real-time control system according to claim 5, characterized in that, The policy regulation module is specifically used for: When the real-time threat index exceeds a preset switching threshold, dynamically switch the encryption algorithm combination in the encryption policy mapping table to determine the target encryption algorithm combination, and determine the network layer identifier of the abnormal transmission path according to the real-time threat index and the abnormal data flow characteristics in the multi-dimensional feature vector; Based on the public key attribute of the asymmetric encryption algorithm in the target encryption algorithm combination, generate an initial hash identifier verification rule containing the hash digest recursive verification logic, and compile the initial hash identifier verification rule into the hash identifier verification rule that can be executed across nodes through a blockchain smart contract; Add a redundant check sharding unit to the sharded hash chain, and activate the multi-path parallel transmission mechanism of the sharding unit data based on the multi-path transmission load balancing algorithm of the sharding unit data; Send a verification control instruction containing the hash identifier verification rule to the target node, and perform cross-node two-way verification on the distributed consistency of the hash identifier and the continuity of the shard sequence number through a blockchain smart contract; Based on the flow table dynamic control protocol of the software-defined network controller, send an update instruction containing a traffic blocking rule and a priority marking isolation policy to the target switch bound to the abnormal transmission path, add the network layer identifier and terminal feature information to the isolation policy queue, and synchronously update the flow table entries of the target switch according to the time stamp of the sharding time sequence reference, block the data forwarding interface of the abnormal transmission path, and construct a virtual isolation channel.
7. The silver-medical intelligent terminal data security transmission and real-time control system according to claim 6, characterized in that, The audit traceability module is specifically used for: Extract the hash chain and shard sequence number of the target data block from the blockchain, and reconstruct the original shard order through a reverse traversal algorithm; Use the zero-knowledge proof algorithm to generate an integrity signature for each shard of medical service data, and verify the consistency between the hash digest of each shard unit and the blockchain record; If the verification fails, extract the historical shard medical service data in the blockchain backup node, perform a difference comparison to locate the tampering position, and bind the tampering position to the abnormal event time stamp corresponding to the shard sequence number to generate the audit report containing the abnormal time sequence mark and the abnormal transmission path location record.
8. A method for secure transmission and real-time control of data in a silver-medical intelligent terminal, characterized in that, Including: Obtain medical service data and device status data, label the sensitivity level label for the medical service data based on a pre-constructed classification and grading model, divide the medical service data with the sensitivity level label into multiple data blocks according to a preset rule, and generate a hash identifier uniquely bound to each data block through a blockchain node; According to the sensitivity level label, match a preset encryption algorithm combination, extract the time sequence pulse sequence in the device status data, determine the sharding time sequence reference, and perform dynamic sharding and cutting on each data block based on the sharding time sequence reference to generate target medical service data with a shard sequence number, recombine the target medical service data with the hash identifier to generate an encrypted data packet carrying the hash identifier and the shard sequence number, and transmit the encrypted data packet to the target node through an encrypted transmission protocol; Capture traffic characteristics of the transmission path of the encrypted data packet, and obtain operation behavior logs. Input the traffic characteristics and the operation behavior logs into a federated learning model, extract a multi-dimensional feature vector including data flow direction, terminal identity, and operation timing sequence, and calculate a real-time threat index based on the multi-dimensional feature vector; According to the real-time threat index, dynamically switch the encryption algorithm combination to obtain a target encryption algorithm combination. Based on the target encryption algorithm combination, generate a hash identifier verification rule, send a control instruction of the hash identifier verification rule to the target node, and isolate the abnormal transmission path based on software-defined network technology; According to the hash identifier and the shard sequence number stored in the blockchain, perform reverse recombination verification on the data transfer process, use the zero-knowledge proof algorithm to verify the integrity signature and operation compliance label of each shard of medical service data. If the verification fails, generate a data tampering warning, trigger a preset data backtracking mechanism, and generate an audit report.
9. An electronic device, characterized in that, The electronic device includes a processor, the processor is coupled with a memory, and at least one computer program is stored in the memory. The at least one computer program is loaded and executed by the processor so that the electronic device implements the method for secure transmission and real-time control of data of the smart terminal for medical and banking services as claimed in claim 8.
10. A computer-readable storage medium, characterized in that, At least one computer program is stored in the computer-readable storage medium. The at least one computer program is loaded and executed by a processor so that the computer-readable storage medium implements the method for secure transmission and real-time control of data of the smart terminal for medical and banking services as claimed in claim 8.
Citation Information
Patent Citations
DE123045A
Cited By
Business data synchronization method, system and terminal based on distributed heterogeneous data source
CN120448461A
Business data synchronization method, system and terminal based on distributed heterogeneous data sources
CN120448461B
SAP mobile auditing system and method
CN120567569A
A sap mobile auditing system and method
CN120567569B
Intelligent private data fragmentation and recombination method and system based on AI
CN120632943A