Data security management device based on medical data operation mode

The data security management system for medical data addresses the lack of comprehensive protection by integrating identity verification, access control, encryption, and auditing, ensuring confidentiality and integrity throughout the data lifecycle.

CN120321027APending Publication Date: 2025-07-15TIANJIN UNIV

Patent Information

Application Number
CN202510730581.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

The existing data security systems lack effective security protection in medical data protection, especially in the big data era, the security protection needs for medical data have not been fully met.

Method used

It provides a data security management device based on the medical data operation model, including a management backend system, a data encryption module, a data desensitization module, a sensitive identification module, a data permission module and a data security audit module. Through technical means such as identity authentication, access control, data encryption, data desensitization and security audit, the full life cycle protection of medical data is achieved.

Benefits of technology

It realizes multi-level protection of medical data in the process of collection, transmission, storage, processing, retrieval, exchange and display, ensures the confidentiality, authenticity, integrity and undeniability of data, prevents illegal access and tampering, and meets the data security needs of different application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321027A_ABST
    Figure CN120321027A_ABST
Patent Text Reader

Abstract

The invention discloses a data security management device based on a medical data operation mode, and relates to the technical field of data security management, and the device comprises a management background system, a data encryption module, a data desensitization module, a sensitive identification module, a data authority module, a data security auditing module and a database. According to the application, the technical means of data desensitization, encryption and the like are adopted to enhance the protection of the data in the processes of acquisition, transmission, storage, processing, retrieval, exchange, display and propagation, so that the data are ensured to be used according to laws and regulations in each link and are not illegally pretended, stolen, tampered, deleted and denied, the confidentiality, authenticity, integrity and non-repudiation of data information are ensured, and the security and reliability of the data are improved. And a security solution integrating identity authentication, access control, data encryption, data desensitization, communication encryption, resource control and security audit is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data security management, and particularly to a data security management device based on a medical data operation mode. Background Art

[0002] With the rapid development of information technology innovation, the information wave characterized by digitization, networking, and intelligence is booming. More and more sensitive data is stored in data centers, and there is an urgent need for data privacy and data security technologies to protect sensitive information from being leaked. Among them, patients' medical data is highly sensitive.

[0003] Most of the current data security systems on the market are designed based on traditional data security architectures, and more focus on the security of infrastructure such as operating systems, network environments, database software, and security protection devices, and relatively lack the security protection of medical data itself. In the big data era, the security protection of medical data itself has become particularly important. Therefore, there is an urgent need for a data security management system that can strengthen the security protection of medical data itself. Summary of the Invention

[0004] The purpose of the present application is to provide a data security management device based on a medical data operation mode, which can provide an integrated security solution from identity authentication, access control (dual control of application permissions and data permissions), data encryption, data desensitization, communication encryption, resource control, and security auditing.

[0005] To achieve the above purpose, the present application provides the following solutions:

[0006] The present application provides a data security management device based on a medical data operation mode, including: a management background system, a data encryption module, a data desensitization module, a sensitive identification module, a data permission module, a data security auditing module, and a database;

[0007] Among them, the management background system includes a security configuration module; the security configuration module includes a standard management sub-module, a data classification sub-module, a sensitive level sub-module, an intelligent classification and grading sub-module, and an algorithm configuration sub-module;

[0008] The standard management sub-module is used to: define the standards for data classification and grading and the open form, and support the establishment of a data security knowledge base;

[0009] The data classification sub-module is used to: configure the data classification information through the system page and verify the classification results; the data classification information includes classification names, source standards, classification levels, and data security policies; the data security policies include desensitization methods and encryption algorithms;

[0010] The sensitive level sub-module is used to: configure sensitive level information through the system page; the sensitive level information includes sensitive name, level identifier, and source standard;

[0011] The intelligent classification and grading sub-module is used to: configure intelligent algorithm information for identifying sensitive fields in medical data through the system page; the intelligent algorithm information includes algorithm name, algorithm identifier, algorithm script, and algorithm parameters;

[0012] The algorithm configuration sub-module is used to: configure desensitization algorithm information and encryption algorithm information through the system page; the desensitization algorithm information includes algorithm name, algorithm identifier, and algorithm script; the encryption algorithm information includes algorithm name, algorithm identifier, algorithm type, and algorithm script;

[0013] The sensitive identification module is used to: review the identified content using intelligent identification or manual identification methods;

[0014] The data permission module is used to: implement permission management based on the security policies or rules of the system, where users can only access the resources they are authorized to;

[0015] The data encryption module is used to: encrypt the data and return different data according to different access users and permissions;

[0016] The data desensitization module is used to: desensitize the data and return different data according to different access users and permissions;

[0017] The data security audit module is used to: audit the usage behavior of users when using the data security management device based on the medical data operation mode;

[0018] The database is used to store configuration data, metadata, documents, and operation logs.

[0019] Optionally, the management background system further includes a security overview module; the security overview module includes a labeling overview sub-module, a classification result sub-module, a policy summary sub-module, a labeling dynamics sub-module, a grading result sub-module, and a security audit sub-module, and is used to display the data security overview.

[0020] Optionally, the management background system further includes a classification and grading module; the classification and grading module includes a manual labeling sub-module, a result viewing sub-module, a labeling log sub-module, an intelligent labeling sub-module, a manual verification sub-module, and a sample query sub-module.

[0021] Optionally, the data security management device under the medical data operation mode further includes a security service system; the security service system includes a standard management module, a function management module, a report statistics module, a classification and grading module, a result annotation module, an annotation log module, and an SQL Parser component.

[0022] Optionally, the sensitive level sub-module is further configured to: intelligently recommend data security policies according to the grading results.

[0023] Optionally, the standard management sub-module is further configured to: define the standards for data classification and grading and open forms through manual configuration, rule configuration, or intelligent recognition.

[0024] Optionally, the data security management device under the medical data operation mode further includes a data monitoring module; the data monitoring module is configured to: monitor medical data in real time during the processes of data collection, transmission, storage, processing, retrieval, exchange, display, and dissemination, and give an alarm or record problems when problems are found.

[0025] Optionally, the data security management device under the medical data operation mode further includes a data security physical examination module, and the data security physical examination module is configured to: scan data security requirement items based on metadata and output a scoring report.

[0026] According to the specific embodiments provided by the present application, the following technical effects are disclosed in the present application:

[0027] The present application provides a data security management device under the medical data operation mode. Since it is provided with a management background system, a data encryption module, a data masking module, a sensitive identification module, a data permission module, a data security audit module, and a database, the present application performs diverse data hierarchical storage designs and centralized governance, meets different application scenarios and different data service requirements, and realizes the maximization of the value of health care data. Technical means such as data masking and encryption are used to strengthen the protection of data during the processes of data collection, transmission, storage, processing, retrieval, exchange, display, and dissemination, ensure that data is used legally and compliantly in each link, is not illegally impersonated, stolen, tampered with, deleted, or denied, and ensure the confidentiality, authenticity, integrity, and non-repudiation of data information. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0029] Figure 1 Schematic structural diagram of a data security management device based on a medical data operation mode provided by an embodiment of the present application;

[0030] Figure 2 Schematic flowchart of data security management based on a medical data operation mode provided by an embodiment of the present application. Specific embodiments

[0031] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0032] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below in conjunction with the drawings and specific embodiments.

[0033] In an exemplary embodiment, as Figure 1 shown, a data security management device based on a medical data operation mode is provided, including a management background system, a data encryption module, a data desensitization module, a sensitive identification module, a data permission module, a data security audit module, and a database.

[0034] Among them, the management background system includes a security configuration module; the security configuration module includes a standard management sub-module, a data classification sub-module, a sensitive level sub-module, an intelligent classification and grading sub-module, and an algorithm configuration sub-module.

[0035] The standard management sub-module is used to: define standards such as data classification and grading and opening forms, and support the establishment of a data security knowledge base. The standard management sub-module is also used to: users define standards for data classification and grading and opening forms through manual configuration, rule configuration, or intelligent recognition methods.

[0036] The data classification sub-module is used to: configure data classification information through the system page and verify the classification results; the data classification information includes classification names, source standards, classification levels, and data security policies; the data security policies include desensitization methods and encryption algorithms. Specifically, the data classification sub-module supports multi-level classification, supports setting classification names and source standards, supports intelligent recommendation of classification results, supports manual annotation / verification of classification results, etc.

[0037] The sensitive level sub-module is used to: configure sensitive level information through the system page; the sensitive level information includes sensitive name, level identifier, and source standard. The sensitive level sub-module supports intelligent recommendation of classification results, supports manual annotation / verification of classification results, and supports setting default policies (desensitization method / encryption method), default opening form, etc.

[0038] The sensitive level sub-module is also used to: intelligently recommend data security policies based on classification results. It supports users to define data classification and grading through manual configuration / rule configuration / intelligent recognition, and recommends default data security policies (desensitization methods, encryption algorithms, etc.) according to the data classification and grading results. It can also automatically upgrade or downgrade data according to the implementation of data security policies. For example, downgrade the data that has been encrypted at the bottom layer.

[0039] The intelligent classification and grading sub-module is used to: configure intelligent algorithm information for identifying sensitive fields in medical data through the system page; the intelligent algorithm information includes algorithm name, algorithm identifier, algorithm script (regular expression / code), and algorithm parameters.

[0040] The algorithm configuration sub-module is used to: configure desensitization algorithm information and encryption algorithm information through the system page to define sensitive data characteristics and desensitization rules; the desensitization algorithm information includes algorithm name, algorithm identifier, and algorithm script (regular expression / code); the encryption algorithm information includes algorithm name, algorithm identifier, algorithm type, and algorithm script (regular expression / code).

[0041] The management background system also includes a security overview module; the security overview module includes an annotation overview sub-module, a classification result sub-module, a policy summary sub-module, an annotation dynamics sub-module, a grading result sub-module, and a security audit sub-module, which are used to display the data security overview, including data source statistics, data classification statistics, data grading statistics, data desensitization statistics, data encryption statistics, and data access statistics overview.

[0042] The management background system also includes a classification and grading module; the classification and grading module includes a manual annotation sub-module, a result viewing sub-module, an annotation log sub-module, an intelligent annotation sub-module, a manual verification sub-module, and an example query sub-module.

[0043] The sensitive identification module is used to: review the identified content using intelligent identification or manual identification methods. The sensitive identification module is divided into an intelligent identification sub-module and a manual identification sub-module. Among them, the intelligent identification sub-module is used to: view intelligent identification tasks and review the identified content; the manual identification sub-module is used to: identify sensitive information and processing methods through manual identification, as well as identify and review, import offline identification, and whether to enable the source layer identification switch.

[0044] The data permission module is used to implement permission management according to the system's security policies or rules, so that users can only access the resources they are authorized to access. In order to configure the platform's privacy level policy and level name, the data permission module includes a data authorization submodule and a permission acceptance submodule; wherein, the data authorization submodule is used for: the platform to authorize data for ecological enterprises, support row and column control, support data desensitization and data encryption, and implement data permission management; the permission acceptance submodule is used to approve / revoke permission applications from other companies to implement application permission management. The data permission module sets data permissions for users, supports user behavior analysis and violation alerts for accessing users, and supports partner management.

[0045] The data encryption module is used to encrypt data and return different data according to different access users and permissions.

[0046] The data desensitization module is used to desensitize the data and return different data according to different access users and permissions.

[0047] For the raw data collection and aggregation layer, the algorithm configuration submodule, data encryption module and data desensitization module support intelligent identification of sensitive data and automatic matching of desensitization rules or setting of encryption algorithms. You can also manually set sensitive data types and desensitization rules for specific metadata dictionaries.

[0048] The data security audit module is used to: audit the user's use of the data security management device based on the medical data operation mode and record the user's use behavior. Display indicators of possible violations or major security risks in data access, data change, and user operations. The audit content of the data security audit module includes important data, core data access statistics, high-frequency data change statistics, etc. Data can be traced through data security audits and reports, and it has security situation awareness and data watermarking functions.

[0049] The database is used to store configuration data, metadata, documents and operation logs. The metadata database system can define metadata, provide metadata and sample data, and define data element mapping. Data standard system: define privacy levels, define classifications (including classification and security policies); configure metadata classification and grading information (including security policies) through defined data element mapping relationships; perform metadata classification and grading audits, establish a security policy knowledge base, and control data permissions.

[0050] The data security management device based on the medical data operation mode also includes a security service system; the security service system includes a standard management module, a function management module, a report statistics module, a classification and grading module, a result marking module, a marking log module and a SQLParser component.

[0051] In the security service system, the specific functions of each module are as follows:

[0052] Standard management module: Maintains standard normative documents related to the country and the industry, facilitating access for data security management personnel and serving as a reference guide for data security management.

[0053] Classification and grading module: Based on relevant national and industry standards, formulates a classification and grading framework for data according to the business areas to which the data belongs, that is, which classifications are included, what sensitive types are under each classification, and what sensitive levels correspond to each type.

[0054] Function management module: Manages the function of the feature model recognition function for automatic classification and grading. The platform classifies and grades the metadata of sensitive data in a "smart-based, manual-assisted" manner. In terms of intelligence, randomly extracts data from the table as samples, applies the feature model recognition function to perform intelligent analysis on the data content, and then supplements it with manual sampling inspection to finally achieve the classification and grading of the data.

[0055] Result annotation module: Manages the function of the classification and grading annotation results. Facilitates users to conduct sampling inspections, audits, and revisions on the classification and grading results.

[0056] Report statistics module: Classifies and grades the result statistics function. According to the sensitive data types of the classification and grading, view which sensitive data are involved in the enterprise data assets, which data have been desensitized, and what desensitization methods are used, etc., and can deeply understand which databases, which tables, and which fields these data are distributed in.

[0057] Annotation log module: Records the annotation information of each sensitive metadata, including the annotator (system or a certain user), annotation time, operation type (including annotation, audit, revision, etc.), facilitating the audit of data security annotation.

[0058] It should be noted that the management background system sets, modifies, and displays various configuration rules. The security service system analyzes and processes data based on the configuration rules of the management background, that is, generates relevant execution tasks based on the rules and manages these tasks, uses standard formulation as a reference, and generates relevant data annotation information through classification and grading rules, sensitive level rules, and manual annotation + intelligent annotation rules. For example, when classifying and grading a data table, control the access data permissions and scope through the classification and grading module in the security service system in combination with SQL Parser (SQL parsing) according to the classification and grading rules; guide the SQL engine to encrypt and desensitize the data.

[0059] In another exemplary embodiment of the present application, data security runs through the entire data life cycle, and the functions of the data security system can be divided into security management functions and security control functions. The security management function is a function visible in the background of the security system, and its responsibility is to manage security policy configuration, security audit, and security monitoring visualization; the security control function is the security control ability embedded in the data processing process, such as data desensitization, encryption, permission control, etc. As Figure 2 shown, the data security management device provided by the present application based on the medical data operation mode can solve the following health care data operation scenarios:

[0060] (1) Business scenarios

[0061] 1. Data query scenario: When a user queries data using an instant query tool, data permission verification and data desensitization are performed according to the user's permissions; it mainly solves the data security requirements of the data resource layer and the data mart layer.

[0062] 2. Interface call scenario: When a user calls a platform-related data interface, data permission verification and data desensitization are performed according to the permissions of the tenant where the user is located; data encryption is performed on the fields (human identifiers) that need to be encrypted. For the interfaces provided by ecological enterprises (provided by the interface system), except for business needs, data is physically processed in principle. It mainly solves the data security requirements of the data mart layer.

[0063] 3. Data storage scenario: When using functions such as data collection, ETL (Extract-Transform-Load, which is used to describe the process of extracting data from the source end, transforming it, and loading it to the destination end) to store data, the fields that need to be encrypted (manually identified / automatically identified sensitive data) are encrypted and stored; it mainly solves the data security requirements of the raw data collection and aggregation layer, the data resource layer, and the data mart layer.

[0064] Data query and data storage are performed through the SQLParser component in the security service system.

[0065] Among them, the specific process of the data query engine is as follows: When a user queries data, the SQL statement is parsed to determine whether there is permission. If so, it is determined whether to return desensitized data or encrypted data. If desensitized data is returned, the desensitization algorithm is called to desensitize the original medical data, and the desensitized medical data is returned; if encrypted data is returned, the encryption algorithm is called to encrypt the original medical data, and the encrypted medical data is returned. If neither desensitized data nor encrypted data is returned, the original medical data is returned, indicating that the user has the permission to view the original medical data; if not, that is, the user does not have permission, this access is rejected.

[0066] The specific processing process of the data storage engine is as follows: When the user stores data, the device writes medical data, parses it by analyzing the SQL statement, and determines whether there is permission. If so, that is, if there is permission, it further determines whether to store it encrypted. If encrypted storage is performed, the encryption function is called to encrypt the medical data, and the encrypted medical data is stored, and the processing result is returned; if encrypted storage is not performed, the medical data written by the user device is directly stored, and the processing result is returned; if there is no permission, access is denied, that is, storing medical data is refused, and the data storage process ends.

[0067] 4. Data export scenario: When exporting data, data desensitization and encryption need to be performed according to the data permissions of the account. If privilege elevation is required, users are supported to submit applications: After being reviewed by the administrator of the tenant where the user is located, the permissions of the weighted tenant can be exported. It mainly addresses the data security requirements at the data mart layer.

[0068] (2) Security supervision

[0069] 5. Data monitoring scenario:

[0070] The data security management device based on the medical data operation mode further includes a data monitoring module; the data monitoring module is used for: during the processes of data collection, transmission, storage, processing, retrieval, exchange, display, and dissemination, real-time monitoring of medical data is carried out, and problems are alerted or recorded when problems are found. Through the home page monitoring, data security indicator data is provided, such as: data asset distribution, classification and grading results, data risk warnings, etc.

[0071] 6. Data security physical examination scenario:

[0072] The data security management device based on the medical data operation mode further includes a data security physical examination module. The data security physical examination module is used for: scanning the data security requirement items based on the metadata, and outputting a score report to display the data security monitoring results. - For the original data collection and aggregation layer, data resource layer, and data mart layer.

[0073] 7. Data security audit scenario: Configure inspection items according to audit requirements and output an audit report.

[0074] This application has the following beneficial effects:

[0075] (1) Focus on risk assessment and risk-based protection strategies for pre-event prevention, and implement control strategies through access control and authorization control. It includes: risk identification, data protection, authorization control, etc. This part has a higher priority.

[0076] (2) Prevent data leakage through functions such as traffic monitoring and behavior analysis during the process, and give early warnings for abnormal behaviors. The priority of this part is secondary.

[0077] (3) There are certain requirements for the retrospective ability, data security reports, and continuous improvement of data security policies after the event.

[0078] This application deeply integrates the security system with the big data platform, designs the security architecture from the facility layer, data layer, application layer, and business layer. Especially in the application layer, security measures are integrated into the application system to form a security solution integrating identity authentication, access control (dual control of application permissions and data permissions), data encryption, data desensitization, communication encryption, resource control, and security audit. According to the data hierarchical governance design method in the medical data operation mode, it is very necessary to design a data security management system that meets the characteristics requirements of the original data collection and aggregation layer, data resource layer, and data mart layer and covers the entire life cycle of data.

[0079] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0080] Specific examples are used in this article to elaborate on the principles and implementation methods of this application. The descriptions of the above embodiments are only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, there will be changes in the specific implementation methods and application scopes according to the idea of this application. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A data security management device under a medical data operation mode, characterized in that The data security management device under the medical data operation mode includes a management background system, a data encryption module, a data desensitization module, a sensitive identification module, a data permission module, a data security audit module, and a database; Among them, the management background system includes a security configuration module; the security configuration module includes a standard management sub-module, a data classification sub-module, a sensitive level sub-module, an intelligent classification and grading sub-module, and an algorithm configuration sub-module; The standard management sub-module is used to: define the standards for data classification and grading and the opening form, and support the establishment of a data security knowledge base; The data classification sub-module is used to: configure the data classification information through the system page and verify the classification results; the data classification information includes classification name, source standard, classification level, and data security policy; the data security policy includes desensitization method and encryption algorithm; The sensitive level sub-module is used to: configure the sensitive level information through the system page; the sensitive level information includes sensitive name, level identifier, and source standard; The intelligent classification and grading sub-module is used to: configure the intelligent algorithm information for identifying sensitive fields in medical data through the system page; the intelligent algorithm information includes algorithm name, algorithm identifier, algorithm script, and algorithm parameters; The algorithm configuration sub-module is used to: configure the desensitization algorithm information and encryption algorithm information through the system page; the desensitization algorithm information includes algorithm name, algorithm identifier, and algorithm script; the encryption algorithm information includes algorithm name, algorithm identifier, algorithm type, and algorithm script; The sensitive identification module is used to: use the intelligent identification method or the manual identification method to review the identified content; The data permission module is used to: implement permission management according to the security policy or rules of the system, where users can only access the resources they are authorized to; The data encryption module is used to: encrypt the data and return different data according to different access users and permissions; The data desensitization module is used to: desensitize the data and return different data according to different access users and permissions; The data security audit module is used to: audit the user's usage behavior when using the data security management device under the medical data operation mode; The database is used to store configuration data, metadata, documents, and operation logs.

2. The data security management device according to claim 1 under the medical data operation mode, characterized in that, The management background system further includes a security overview module; the security overview module includes a marking overview sub-module, a classification result sub-module, a policy summary sub-module, a marking dynamics sub-module, a grading result sub-module, and a security audit sub-module, which are used to display the data security overview.

3. The data security management device based on the medical data operation mode according to claim 1, characterized in that, The management background system further includes a classification and grading module; the classification and grading module includes a manual marking sub-module, a result viewing sub-module, a marking log sub-module, an intelligent marking sub-module, a manual verification sub-module, and an example query sub-module.

4. The data security management device based on the medical data operation mode according to claim 1, characterized in that The data security management device based on the medical data operation mode further includes a security service system; the security service system includes a standard management module, a function management module, a report statistics module, a classification and grading module, a result annotation module, an annotation log module, and an SQLParser component.

5. The data security management device based on the medical data operation mode according to claim 1, characterized in that, The sensitive level sub-module is further configured to: intelligently recommend data security policies according to the grading results.

6. The data security management device based on the medical data operation mode according to claim 1, characterized in that, The standard management sub-module is further configured to: define the standards for data classification, grading, and opening forms through manual configuration, rule configuration, or intelligent recognition.

7. The data security management device based on the medical data operation mode according to claim 1, characterized in that, The data security management device based on the medical data operation mode further includes a data monitoring module; the data monitoring module is configured to: perform real-time monitoring on medical data during the processes of data collection, transmission, storage, processing, retrieval, exchange, display, and dissemination, and give an alarm or record the problems when problems are found.

8. The data security management device according to claim 1 based on the medical data operation mode, characterized in that, The data security management device based on the medical data operation mode further includes a data security physical examination module, and the data security physical examination module is configured to: scan data security requirement items based on metadata and output a scoring report.

Citation Information

Patent Citations

  • Data management method and system based on data resource security identification level

    CN119442320A

  • E-commerce platform information security desensitization scheme analysis system based on artificial intelligence

    CN119538316A

  • Medical data supervision method, platform and medical server

    CN119864116A

  • Data personalized desensitization method and system and storage medium

    CN120030590A

Cited By

  • Medical data security management method

    CN121479827A