Block chain evidence storage method and device for medical data operation features

By monitoring user operation behavior in real time in the medical data sharing network, generating electronic fingerprints and using blockchain to store evidence, the problem of data tampering and insufficient backup is solved, and efficient data storage and reliability are achieved.

CN120342571AActive Publication Date: 2025-07-18GENERAL HOSPITAL OF PLA
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510537584.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-18
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

In the existing medical data sharing network, data tamper-proof and active backup capabilities are insufficient, making it difficult to ensure the integrity and reliability of data records.

Method used

By monitoring users' operating behaviors on the medical data sharing network in real time, extracting operational feature data and using zero-knowledge proof technology to generate electronic fingerprints, combining the evidence storage blockchain of distributed ledger business to store evidence, realizing data tamper-proof and active backup.

Benefits of technology

Improves the anti-tampering capability of data and proactive backup capabilities to ensure the integrity and reliability of data records.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342571A_ABST
    Figure CN120342571A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a block chain evidence storage method and device for medical data operation characteristics. The method comprises the following steps: monitoring a medical data operation action executed by a user on a portal webpage provided by a medical data sharing network in real time to obtain user monitoring data; performing operation feature extraction according to the private information of the current user and the user monitoring data to obtain operation feature data; a block chain timestamp is obtained from the evidence storage block chain to serve as operation time; the operation characteristic data and the operation time form private data; according to a zero-knowledge proof technology, generating a zero-knowledge proof pi according to the private data, and sending the zero-knowledge proof pi to an evidence storage block chain for verification to obtain a corresponding verification result; when the verification is passed, generating an electronic fingerprint according to the private data, and performing uplink evidence storage on the electronic fingerprint through an asynchronous processing mode of a cache queue; and performing medical data operation based on the user monitoring data after successful evidence storage. According to the invention, the tamper-proofing capability and the active backup capability of the data can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly to a blockchain-based evidence storage method and device for medical data operation characteristics. Background Art

[0002] In a conventional medical data sharing network, recording information about users' data access / operation behaviors mostly relies on a log / event service mechanism. However, general log / event services usually use traditional databases for data storage. According to practical experience, this traditional method performs poorly in terms of data anti-tampering and active backup capabilities, and there is a risk of data being tampered with or lost, making it difficult to ensure the integrity and reliability of data records. Summary of the Invention

[0003] The objective of the present invention is to provide a blockchain-based evidence storage method, device, electronic device, and computer-readable storage medium for medical data operation characteristics in view of the deficiencies of the prior art. The present invention performs real-time monitoring on the medical data operation actions performed by a user on a portal web page provided by a medical data sharing network to obtain corresponding user monitoring data; extracts operation characteristics based on the private information of the current user and the user monitoring data to obtain corresponding operation characteristic data; obtains a blockchain timestamp from the evidence storage blockchain as the corresponding operation time; forms corresponding private data from the operation characteristic data and the operation time; generates a zero-knowledge proof π according to the zero-knowledge proof technology based on the private data and sends it to the evidence storage blockchain for verification to obtain a corresponding verification result; when the verification result is verified to be passed, performs electronic fingerprint generation processing on the private data to obtain corresponding electronic fingerprint data; performs on-chain evidence storage processing on the electronic fingerprint data through an asynchronous processing method of a cache queue; and after successful evidence storage, performs medical data operations based on the user monitoring data and feeds back the operation result to the current user. The present invention uses an evidence storage blockchain deployed with a distributed ledger service to record the evidence of users' data access / operation behaviors, which can not only improve the data anti-tampering ability through blockchain technology but also enhance the data active backup ability through the characteristics of the distributed ledger network.

[0004] To achieve the above objective, a first aspect of an embodiment of the present invention provides a blockchain-based evidence storage method for medical data operation characteristics, the method comprising:

[0005] The client monitors in real time the medical data operation actions performed by the user on the portal web page provided by the medical data sharing network to obtain corresponding user monitoring data; the user monitoring data includes an object identifier, an operation type, and operation data; the object identifier is the routing identifier path of the medical data object currently operated by the user, and the routing identifier path is composed of a routing identifier prefix and an end routing identifier, and the routing identifier path corresponds to a specific data storage location on the medical data sharing network; the operation type at least includes addition, modification, deletion, and download; when the operation type is addition or modification, the operation data is a medical data object; when the operation type is deletion or download, the operation data is empty;

[0006] Extract operation features from the private information of the current user and the user monitoring data to obtain corresponding operation feature data; and obtain the blockchain timestamp from the evidence-preserving blockchain as the corresponding operation time; and form corresponding private data from the operation feature data and the operation time; the operation feature data includes the user's private key, the object identifier, and the operation type;

[0007] Generate a zero-knowledge proof π according to the zero-knowledge proof technology based on the private data and send it to the evidence-preserving blockchain for verification to obtain a corresponding verification result;

[0008] When the verification result is verification passed, generate electronic fingerprint data according to the private data; and perform blockchain evidence-preserving processing on the electronic fingerprint data through the asynchronous processing method of the cache queue; and perform medical data operations based on the user monitoring data after successful evidence-preserving and feedback the operation result to the current user.

[0009] Preferably, the method further includes:

[0010] The medical data sharing network is a distributed data sharing network composed of multiple first network nodes; each of the first network nodes corresponds to a node type, and the node type at least includes a portal website node, a data storage node, and a data calculation node; the first network node with the node type of portal website node is used to provide access services for the portal web page; the first network node with the node type of data storage node is used to store the medical data object; the first network node with the node type of data calculation node is used to provide data storage services, data encryption and decryption services, and algorithm / model inference services;

[0011] The node network of the evidence-preserving blockchain is a distributed node network composed of multiple first network nodes with the node type of data calculation nodes in the medical data sharing network. A distributed ledger service is deployed on this distributed node network based on blockchain technology; all the first network nodes of the blockchain network jointly maintain a feature evidence-preserving ledger based on blockchain technology, and a complete ledger copy is stored on all the first network nodes; all the first network nodes on the evidence-preserving blockchain keep the whole-chain time synchronization through an external time server.

[0012] When constructing the evidence-preserving blockchain, each first network node with the node type of data calculation node in the medical data sharing network is recorded as a corresponding first candidate node; and the importance parameter W of each first candidate node is initialized based on the security index A, reachability index B, throughput rate index C, and real-time index D; and the PageRank algorithm is used to iterate the importance parameter W multiple times until the absolute difference between the results of the last two iterations of all the importance parameters W does not exceed a preset first threshold; and the first candidate nodes are sorted in descending order of the importance parameter W to form a corresponding first node sequence; and the evidence-preserving blockchain is composed of the top K first candidate nodes in the first node sequence; the security index A, the reachability index B, the throughput rate index C, and the real-time index D are each a normalized numerical index; the initialized importance parameter W = w1A + w2B + w3C + w4D, where w1, w2, w3, and w4 are four preset weight parameters.

[0013] Preferably, the extraction of the operation feature according to the private information of the current user and the user monitoring data to obtain the corresponding operation feature data specifically includes:

[0014] The client forms the corresponding operation feature data from the user private key of the current user, the object identifier of the user monitoring data, and the operation type.

[0015] Preferably, the obtaining of the blockchain timestamp on the evidence-preserving blockchain as the corresponding operation time specifically includes:

[0016] The client takes the first network node closest to the current user on the evidence-preserving blockchain as the corresponding current time server node; and sends a first time server request to the current time server node; and takes the first timestamp sent back by the current time server node as the corresponding operation time.

[0017] Preferably, the generation of the zero-knowledge proof π according to the zero-knowledge proof technology based on the private data and sending it to the evidence-preserving blockchain for verification to obtain the corresponding verification result specifically includes:

[0018] Step 51: The client generates a shared first Common Reference String (CRS) for the current user and the evidence storage blockchain according to the generation method of the Common Reference String (CRS) of the zk-SNARKs zero-knowledge proof technology.

[0019] Step 52: According to the arithmetic circuit configuration method of the zk-SNARKs zero-knowledge proof technology, a shared first arithmetic circuit is generated for the current user and the evidence storage blockchain according to the preset permission verification rules.

[0020] Among them, the permission verification rules include an operation type verification rule and an operation time verification rule; the operation type verification rule consists of multiple object-permission correspondence relationships; the object-permission correspondence relationship consists of a routing identifier prefix and a type of operation permission; the types of the operation permissions include an addition permission, a modification permission, a deletion permission, and a download permission; the permission values of each type of operation permission include allowed and prohibited; the operation time verification rule is that the time interval between the current time and the operation time cannot exceed a preset time interval threshold.

[0021] The input of the first arithmetic circuit is the object identifier prefix d, the object operation type s, the object operation time t, and the current time t now , and the output is the verification result r; the verification result r is 0 or 1, where 0 indicates verification failure and 1 indicates verification success.

[0022] The processing logic of the first arithmetic circuit is: if the object identifier prefix d and the object operation type s satisfy one of the object-permission correspondence relationships in the operation type verification rule, the first result is set to 1; if the object identifier prefix d and the object operation type s do not satisfy any of the object-permission correspondence relationships in the operation type verification rule, the first result is set to 0; if the absolute time difference between the current time t now and the object operation time t does not exceed the time interval threshold, the second result is set to 1; if the absolute time difference between the current time t now and the object operation time t exceeds the time interval threshold, the second result is set to 0; and the product of the first and second results is used as the corresponding verification result r.

[0023] Step 53: Extract the corresponding user private key, object identifier, operation type, and operation time from the private data.

[0024] Step 54, use the routing identification prefix of the object identification as the corresponding object identification prefix d; use the operation type as the corresponding object operation type s; use the operation time as the corresponding object operation time t; use the current time information as the corresponding current time t now ; and use the obtained object identification prefix d, object operation type s, object operation time t, and current time t now input them into the first arithmetic circuit for processing to obtain the corresponding verification result r;

[0025] Step 55, if the obtained verification result r this time is 1, extract the process data in the current processing process of the first arithmetic circuit according to the zero-knowledge evidence acquisition method of the zk-SNARKs zero-knowledge proof technology to form the corresponding first evidence; perform a hash calculation on the first evidence according to the zero-knowledge commitment generation method of the zk-SNARKs zero-knowledge proof technology and use the calculation result as the corresponding first commitment; sign the first evidence based on the user's private key to obtain the corresponding first signature; use the user public key corresponding to the user's private key as the corresponding first public key; and send the corresponding zero-knowledge proof π composed of the first public key, the first commitment, the first evidence, and the first signature to the evidence storage blockchain; and use the zero-knowledge proof verification result sent back by the evidence storage blockchain as the corresponding verification result.

[0026] Preferably, the method further includes:

[0027] The evidence storage blockchain extracts the corresponding first public key, first commitment, first evidence, and first signature from the zero-knowledge proof π;

[0028] and perform signature verification on the first signature according to the first public key and the first evidence; set the first comparison result to match when the signature verification passes this time, and set the first comparison result to not match when the signature verification fails this time;

[0029] perform a hash calculation on the first evidence according to the zero-knowledge commitment generation method of the zk-SNARKs zero-knowledge proof technology and use the calculation result as the corresponding second commitment; identify whether the first and second commitments match, if they match, set the second comparison result to match, if they do not match, set the second comparison result to not match;

[0030] load the first evidence as process data onto the shared first arithmetic circuit for reprocessing to obtain a new verification result r; identify whether the obtained verification result r this time is 1, if it is, set the third comparison result to match, if not, set the third comparison result to not match;

[0031] Identify whether all of the obtained first, second, and third comparison results are matches; if so, set the corresponding zero-knowledge proof verification result to verification passed; if not, set the corresponding zero-knowledge proof verification result to verification failed; and send the obtained zero-knowledge proof verification result back to the client.

[0032] Preferably, the generating the corresponding electronic fingerprint data according to the private data specifically includes:

[0033] The client extracts the corresponding user private key and the object identifier from the private data; and respectively performs digest calculations on the user private key and the object identifier based on the national cryptography SM3 algorithm to obtain the corresponding private key digest and identifier digest; and sequentially splices the private key and the identifier digest to form the corresponding spliced digest; and performs two digest calculations on the spliced digest based on the national cryptography SM3 algorithm to obtain the corresponding first and second digests; and sequentially splices the first and second digests to form the corresponding electronic fingerprint data;

[0034] Wherein, the private key digest, the identifier digest, the first digest, and the second digest are all 128-bit digital digests; the spliced digest and the electronic fingerprint data are both 256-bit digital digests.

[0035] Preferably, the processing of storing the electronic fingerprint data on the chain through the asynchronous processing method of the cache queue specifically includes:

[0036] Step 81, the client sets the storage status corresponding to the current electronic fingerprint data to not yet stored; and forms a corresponding first cache data from the current electronic fingerprint data and the corresponding operation type and adds it to a preset first cache queue; and uses the first network node on the storage blockchain that is closest to the current user as the corresponding current storage node;

[0037] Wherein, when the first cache queue is not empty, it is composed of one or more of the first cache data;

[0038] Step 82, when the first cache queue is not empty, use the first cache data with the earliest time in the queue as the corresponding current cache data; and perform block encapsulation processing on the current cache data according to the ledger block data encapsulation rule of the feature storage ledger to obtain the corresponding current newly added block; and perform full-chain ledger update processing on the current newly added block through the current storage node; and after the full-chain ledger update processing is successful, delete the current cache data from the first cache queue, and set the storage status of the electronic fingerprint data corresponding to the current cache data to stored successfully.

[0039] Preferably, after successful evidence preservation, medical data operations are performed based on the user monitoring data and the operation results are fed back to the current user, specifically including:

[0040] Step 91, when the evidence preservation status corresponding to the electronic fingerprint data is set to successful evidence preservation, the client uses the user monitoring data corresponding to the current electronic fingerprint data as the corresponding current monitoring data; and extracts the corresponding object identifier, operation type, and operation data from the current monitoring data;

[0041] Step 92, and identify the operation type;

[0042] Step 93, if the operation type is addition or modification, use the operation data as a corresponding current medical data object, and upload the current medical data object to the storage location corresponding to the object identifier in the medical data sharing network, and feed back to the current user that the operation is completed when the upload ends;

[0043] Step 94, if the operation type is deletion, delete the medical data object stored at the storage location corresponding to the object identifier in the medical data sharing network, and feed back to the current user that the operation is completed when the deletion ends;

[0044] Step 95, if the operation type is download, download the medical data object stored at the storage location corresponding to the object identifier in the medical data sharing network to the storage location specified by the current user, and feed back to the current user that the operation is completed when the download ends.

[0045] A second aspect of the embodiments of the present invention provides a device for implementing the blockchain evidence preservation method for the medical data operation features described in the first aspect above. The device includes: a behavior monitoring module, an operation feature extraction module, a zero-knowledge proof verification module, and a blockchain evidence preservation module;

[0046] The behavior monitoring module is used to monitor in real time the medical data operation actions performed by the user on the portal web page provided by the medical data sharing network to obtain the corresponding user monitoring data; the user monitoring data includes an object identifier, an operation type, and operation data; the object identifier is the routing identifier path of the medical data object currently operated by the user, and the routing identifier path is composed of a routing identifier prefix and an end routing identifier, and the routing identifier path corresponds to a specific data storage location on the medical data sharing network; the operation type at least includes addition, modification, deletion, and download; when the operation type is addition or modification, the operation data is a medical data object; when the operation type is deletion or download, the operation data is empty;

[0047] The operation feature extraction module is used to extract operation features according to the private information of the current user and the user monitoring data to obtain corresponding operation feature data; obtain the blockchain timestamp from the evidence-preserving blockchain as the corresponding operation time; and form corresponding private data from the operation feature data and the operation time; the operation feature data includes the user private key, the object identifier, and the operation type.

[0048] The zero-knowledge proof verification module is used to generate a zero-knowledge proof π according to the zero-knowledge proof technology based on the private data and send it to the evidence-preserving blockchain for verification to obtain a corresponding verification result.

[0049] The blockchain evidence-preserving module is used to, when the verification result is verification passed, perform electronic fingerprint generation processing according to the private data to obtain corresponding electronic fingerprint data; perform on-chain evidence-preserving processing on the electronic fingerprint data through the asynchronous processing mode of the cache queue; and perform medical data operation based on the user monitoring data after successful evidence-preserving and feedback the operation result to the current user.

[0050] A third aspect of an embodiment of the present invention provides an electronic device, including: a memory, a processor, and a transceiver.

[0051] The processor is used to be coupled with the memory, read and execute the instructions in the memory to implement the method steps described in the first aspect above.

[0052] The transceiver is coupled with the processor, and the processor controls the transceiver to perform message sending and receiving.

[0053] A fourth aspect of an embodiment of the present invention provides a computer-readable storage medium, and the computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a computer, the computer is caused to execute the instructions of the method described in the first aspect above.

[0054] An embodiment of the present invention provides a blockchain evidence storage method, device, electronic device and computer-readable storage medium for medical data operation characteristics. As can be seen from the above content, the embodiment of the present invention monitors in real time the medical data operation actions performed by a user on a portal web page provided by a medical data sharing network to obtain corresponding user monitoring data; extracts operation characteristics based on the private information of the current user and the user monitoring data to obtain corresponding operation characteristic data; obtains a blockchain timestamp from the evidence storage blockchain as the corresponding operation time; forms corresponding private data from the operation characteristic data and the operation time; generates a zero-knowledge proof π according to the private data by the zero-knowledge proof technology and sends it to the evidence storage blockchain for verification to obtain a corresponding verification result; when the verification result is verified to pass, performs electronic fingerprint generation processing on the private data to obtain corresponding electronic fingerprint data; performs on-chain evidence storage processing on the electronic fingerprint data through an asynchronous processing method of a cache queue; and after the evidence storage is successful, performs medical data operation based on the user monitoring data and feeds back the operation result to the current user. The embodiment of the present invention uses an evidence storage blockchain deployed with a distributed ledger service to record the data access / operation behaviors of users, which not only improves the anti-tampering ability of data but also enhances the active backup ability of data. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 FIG. is a schematic diagram of a blockchain evidence storage method for medical data operation characteristics provided by Embodiment 1 of the present invention;

[0056] Figure 2 FIG. is a module structure diagram of a blockchain evidence storage device for medical data operation characteristics provided by Embodiment 2 of the present invention;

[0057] Figure 3 FIG. is a schematic structural diagram of an electronic device provided by Embodiment 3 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0058] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0059] Embodiment 1 of the present invention provides a blockchain evidence storage method for medical data operation characteristics, as Figure 1 shown in the schematic diagram of a blockchain evidence storage method for medical data operation characteristics provided by Embodiment 1 of the present invention. The method mainly includes the following steps:

[0060] Step 1, the client monitors in real time the medical data operation actions performed by the user on the portal web page provided by the medical data sharing network to obtain corresponding user monitoring data.

[0061] Here, the client in the embodiment of the present invention is a module, application software, device, equipment, server or system that accesses the medical data sharing network.

[0062] The medical data sharing network in the embodiment of the present invention is a distributed data sharing network composed of multiple first network nodes. Each first network node in the network corresponds to a node type, and the node type at least includes a portal website node, a data storage node, and a data calculation node. Among them: 1) The first network node with the node type of the portal website node is used to provide access services to the portal web page; 2) The first network node with the node type of the data storage node is used to store medical data objects; 3) The first network node with the node type of the data calculation node is used to provide data storage services, data encryption / decryption services, and algorithm / model inference services.

[0063] The evidence-preserving blockchain mentioned below is constructed based on the data calculation nodes in the medical data sharing network. The specific construction method is as follows: When constructing the evidence-preserving blockchain, the first network nodes with the node type of data calculation nodes in the medical data sharing network are recorded as corresponding first candidate nodes; and the importance parameter W of each first candidate node is initialized based on the security index A, reachability index B, throughput index C, and real-time index D; and the PageRank algorithm is used to iterate the importance parameter W multiple times until the absolute difference between the results of the last two iterations of all importance parameters W does not exceed a preset first threshold; and the first candidate nodes are sorted in descending order of the importance parameter W to form a corresponding first node sequence; and the evidence-preserving blockchain is composed of the first K first candidate nodes ranked at the top in the first node sequence; and distributed ledger services are deployed on the evidence-preserving blockchain based on blockchain technology; where the security index A, reachability index B, throughput index C, and real-time index D are each a normalized numerical index; the initialized importance parameter W = w1A + w2B + w3C + w4D, and w1, w2, w3, and w4 are four preset weight parameters; the first threshold is a preset threshold parameter.

[0064] That is to say, the node network of the evidence-preserving blockchain in the embodiments of the present invention is a distributed node network composed of multiple first network nodes of data computing nodes in the medical data sharing network; a distributed ledger service is deployed on this distributed node network based on blockchain technology. Based on the characteristics of the distributed ledger service, we know that all the first network nodes of the blockchain network in the embodiments of the present invention jointly maintain a feature evidence-preserving ledger based on blockchain technology and there are complete ledger copies stored on all the first network nodes; all the first network nodes on the evidence-preserving blockchain maintain full-chain time synchronization through an external time server.

[0065] The user monitoring data in the embodiments of the present invention includes an object identifier, an operation type, and operation data. Among them, the object identifier is the routing identifier path of the medical data object currently operated by the user, and the routing identifier path is composed of a routing identifier prefix and an end routing identifier, and the routing identifier path corresponds to a specific data storage location on the medical data sharing network. The operation type includes at least add, modify, delete, and download. When the operation type is add or modify, the operation data is a medical data object; when the operation type is delete or download, the operation data is empty.

[0066] Step 2, the client extracts operation features according to the private information of the current user and the user monitoring data to obtain corresponding operation feature data; and obtains the blockchain timestamp from the evidence-preserving blockchain as the corresponding operation time; and forms corresponding private data from the operation feature data and the operation time.

[0067] Specifically, it includes: Step 21, extracting operation features according to the private information of the current user and the user monitoring data to obtain corresponding operation feature data.

[0068] Among them, the operation feature data includes the user private key, the object identifier, and the operation type.

[0069] Specifically, it includes: forming corresponding operation feature data from the user private key of the current user, the object identifier, and the operation type of the user monitoring data.

[0070] Step 22, and obtaining the blockchain timestamp from the evidence-preserving blockchain as the corresponding operation time.

[0071] Specifically, it includes: taking the first network node closest to the current user on the evidence-preserving blockchain as the corresponding current time server node; and sending a first time request to the current time server node; and taking the first timestamp sent back by the current time server node as the corresponding operation time.

[0072] Step 23, and forming corresponding private data from the operation feature data and the operation time.

[0073] Here, the private data of the embodiments of the present invention includes user private keys, object identifiers, operation types, and operation times.

[0074] Step 3: The client generates a zero-knowledge proof π according to the zero-knowledge proof technology based on the private data and sends it to the deposit blockchain for verification to obtain the corresponding verification result.

[0075] Specifically, it includes: Step 31: The client generates a shared first Common Reference String (CRS) for the current user and the deposit blockchain according to the generation method of the common reference string of the zk-SNARKs zero-knowledge proof technology.

[0076] Step 32: According to the arithmetic circuit configuration method of the zk-SNARKs zero-knowledge proof technology, a shared first arithmetic circuit is generated for the current user and the deposit blockchain according to the preset permission verification rules.

[0077] Here, the permission verification rules of the embodiments of the present invention include operation type verification rules and operation time verification rules; among them, the operation type verification rules are composed of multiple object-permission correspondence relationships; each object-permission correspondence relationship is composed of a routing identifier prefix and a type of operation permission; the types of operation permissions include addition permission, modification permission, deletion permission, and download permission; the permission values of various operation permissions include allowed and prohibited; the operation time verification rule is that the time interval between the current time and the operation time cannot exceed the preset time interval threshold.

[0078] The input of the first arithmetic circuit of the embodiments of the present invention is the object identifier prefix d, the object operation type s, the object operation time t, and the current time t now , and the output is the verification result r; the verification result r is 0 or 1, 0 indicates verification failure, and 1 indicates verification success.

[0079] The processing logic of the first arithmetic circuit of the embodiments of the present invention is: if the object identifier prefix d and the object operation type s satisfy a type of object-permission correspondence relationship in the operation type verification rules, the first result is set to 1; if the object identifier prefix d and the object operation type s do not satisfy any type of object-permission correspondence relationship in the operation type verification rules, the first result is set to 0; if the absolute time difference between the current time t now and the object operation time t does not exceed the time interval threshold, the second result is set to 1; if the absolute time difference between the current time t now and the object operation time t exceeds the time interval threshold, the second result is set to 0; and the product of the first and second results is used as the corresponding verification result r.

[0080] Step 33: Extract the corresponding user private key, object identifier, operation type, and operation time from the private data.

[0081] Step 34: Use the routing identification prefix of the object identification as the corresponding object identification prefix d; use the operation type as the corresponding object operation type s; use the operation time as the corresponding object operation time t; and use the current time information as the corresponding current time t now ; and use the obtained object identification prefix d, object operation type s, object operation time t, and current time t now Input them into the first arithmetic circuit for processing to obtain the corresponding verification result r;

[0082] Step 35: If the verification result r obtained this time is 1, extract the process data in the current processing process of the first arithmetic circuit according to the zero-knowledge evidence acquisition method of the zk-SNARKs zero-knowledge proof technology to form the corresponding first evidence; perform a hash calculation on the first evidence according to the zero-knowledge commitment generation method of the zk-SNARKs zero-knowledge proof technology and use the calculation result as the corresponding first commitment; sign the first evidence based on the user's private key to obtain the corresponding first signature; use the user public key corresponding to the user's private key as the corresponding first public key; and form the corresponding zero-knowledge proof π by the first public key, first commitment, first evidence, and first signature and send it to the evidence storage blockchain; and use the zero-knowledge proof verification result sent back by the evidence storage blockchain as the corresponding verification result.

[0083] Here, the verification process of the evidence storage blockchain in the embodiment of the present invention after receiving the zero-knowledge proof π is as follows:

[0084] Step A1: Extract the corresponding first public key, first commitment, first evidence, and first signature from the zero-knowledge proof π;

[0085] Step A2: Verify the first signature according to the first public key and first evidence; set the first comparison result to match when the signature verification passes this time, and set the first comparison result to not match when the signature verification fails this time;

[0086] Step A3: Perform a hash calculation on the first evidence according to the zero-knowledge commitment generation method of the zk-SNARKs zero-knowledge proof technology and use the calculation result as the corresponding second commitment; identify whether the first and second commitments match. If they match, set the second comparison result to match; if they do not match, set the second comparison result to not match;

[0087] Step A4: Load the first evidence as process data onto the shared first arithmetic circuit for reprocessing to obtain a new verification result r; identify whether the verification result r obtained this time is 1. If it is, set the third comparison result to match; if not, set the third comparison result to not match;

[0088] Step A5, and identify whether all of the obtained first, second, and third comparison results are matches; if so, set the corresponding zero-knowledge proof verification result to verification passed; if not, set the corresponding zero-knowledge proof verification result to verification failed; and send the obtained zero-knowledge proof verification result back to the client.

[0089] Step 4, when the verification result is verification passed, the client generates an electronic fingerprint based on the private data to obtain the corresponding electronic fingerprint data; and performs an on-chain storage process on the electronic fingerprint data through the asynchronous processing method of the cache queue; and based on the user monitoring data, performs a medical data operation after the storage is successful and feeds back the operation result to the current user;

[0090] Specifically including: Step 41, when the verification result is verification passed, generate an electronic fingerprint based on the private data to obtain the corresponding electronic fingerprint data;

[0091] Specifically including: extracting the corresponding user private key and object identifier from the private data; and respectively performing a digest calculation on the user private key and object identifier based on the national cryptography SM3 algorithm to obtain the corresponding private key digest and identifier digest; and sequentially concatenating the private key and identifier digest to form the corresponding concatenated digest; and performing a two-time digest calculation on the concatenated digest based on the national cryptography SM3 algorithm to obtain the corresponding first and second digests; and sequentially concatenating the first and second digests to form the corresponding electronic fingerprint data;

[0092] Among them, the private key digest, identifier digest, first digest, and second digest are all 128-bit digital digests; the concatenated digest and electronic fingerprint data are both 256-bit digital digests;

[0093] Step 42, and perform an on-chain storage process on the electronic fingerprint data through the asynchronous processing method of the cache queue;

[0094] Specifically including: Step 421, set the storage status corresponding to the current electronic fingerprint data to not yet stored; and form a corresponding first cache data from the current electronic fingerprint data and the corresponding operation type and add it to the preset first cache queue; and use the first network node on the storage blockchain that is closest to the current user as the corresponding current storage node;

[0095] Among them, when the first cache queue is not empty, it is composed of one or more first cache data;

[0096] Step 422, when the first cache queue is not empty, use the first cache data with the earliest time in the queue as the corresponding current cache data; and based on the ledger block data encapsulation rule of the feature evidence ledger, perform block encapsulation processing on the current cache data to obtain the corresponding current newly added block; and perform full-chain ledger update processing on the current newly added block through the current evidence storage node; and after the full-chain ledger update processing is successful, delete the current cache data from the first cache queue, and set the evidence storage status of the electronic fingerprint data corresponding to the current cache data to successfully stored.

[0097] Step 43, and perform medical data operations based on the user monitoring data after successful evidence storage and feedback the operation result to the current user.

[0098] Specifically, it includes: Step 431, when the evidence storage status corresponding to the electronic fingerprint data is set to successfully stored, use the user monitoring data corresponding to the current electronic fingerprint data as the corresponding current monitoring data; and extract the corresponding object identifier, operation type, and operation data from the current monitoring data.

[0099] Step 432, and identify the operation type.

[0100] Step 433, if the operation type is add or modify, use the operation data as a corresponding current medical data object, and upload the current medical data object to the storage location corresponding to the object identifier in the medical data sharing network, and feedback to the current user that the operation is completed when the upload ends.

[0101] Step 434, if the operation type is delete, delete the medical data object stored at the storage location corresponding to the object identifier in the medical data sharing network, and feedback to the current user that the operation is completed when the deletion ends.

[0102] Step 435, if the operation type is download, download the medical data object stored at the storage location corresponding to the object identifier in the medical data sharing network to the storage location specified by the current user, and feedback to the current user that the operation is completed when the download ends.

[0103] Figure 2 This is the module structure diagram of a blockchain evidence storage device for medical data operation features provided in the second embodiment of the present invention. The device is a terminal device or a server for implementing the foregoing method embodiment, or can be a device that enables the foregoing terminal device or server to implement the foregoing method embodiment. For example, the device can be a device or a chip system of the foregoing terminal device or server. As Figure 2 shown, the device includes: a behavior monitoring module 201, an operation feature extraction module 202, a zero-knowledge proof verification module 203, and a blockchain evidence storage module 204.

[0104] The behavior monitoring module 201 is used to perform real-time monitoring on the medical data operation actions executed by the user on the portal web page provided by the medical data sharing network to obtain corresponding user monitoring data; the user monitoring data includes an object identifier, an operation type, and operation data; the object identifier is the routing identifier path of the medical data object currently operated by the user, and the routing identifier path consists of a routing identifier prefix and an end routing identifier, and the routing identifier path corresponds to a specific data storage location on the medical data sharing network; the operation type includes at least addition, modification, deletion, and download; when the operation type is addition or modification, the operation data is a medical data object; when the operation type is deletion or download, the operation data is empty.

[0105] The operation feature extraction module 202 is used to extract operation features according to the private information of the current user and the user monitoring data to obtain corresponding operation feature data; and obtain the blockchain timestamp from the evidence-preserving blockchain as the corresponding operation time; and form corresponding private data from the operation feature data and the operation time; the operation feature data includes the user private key, the object identifier, and the operation type.

[0106] The zero-knowledge proof verification module 203 is used to generate a zero-knowledge proof π according to the zero-knowledge proof technology based on the private data and send it to the evidence-preserving blockchain for verification to obtain the corresponding verification result.

[0107] The blockchain evidence-preserving module 204 is used to, when the verification result is verification passed, perform electronic fingerprint generation processing according to the private data to obtain corresponding electronic fingerprint data; and perform on-chain evidence-preserving processing on the electronic fingerprint data through the asynchronous processing method of the cache queue; and perform medical data operations based on the user monitoring data after successful evidence-preserving and feedback the operation result to the current user.

[0108] A blockchain evidence-preserving device for medical data operation features provided by an embodiment of the present invention can execute the method steps in the above method embodiment, and its implementation principle and technical effect are similar, which will not be elaborated here.

[0109] It should be noted that the division of each module of the above device is only a division of logical functions. In actual implementation, it can be fully or partially integrated into a physical entity, or physically separated. And these modules can all be implemented in the form of software called by processing elements; they can also all be implemented in hardware form; it is also possible that some modules are implemented in the form of software called by processing elements, and some modules are implemented in hardware form. For example, the behavior monitoring module can be a separately established processing element, or can be integrated in a certain chip of the above device. In addition, it can also be stored in the memory of the above device in the form of program code, and the function of the above determined module is called and executed by a certain processing element of the above device. The implementation of other modules is similar. In addition, all or part of these modules can be integrated together or can be independently implemented. The processing element described here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed by the integrated logic circuit in the processor element or the instruction in software form.

[0110] For example, the above modules can be one or more integrated circuits configured to implement the above method, such as: one or more application specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), etc. Again, when a certain module above is implemented in the form of a processing element scheduling program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call program code. Again, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0111] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the foregoing method embodiments are generated in whole or in part. The above computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the above computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wireless (such as infrared, wireless, Bluetooth, microwave, etc.). The above computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The above available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0112] Figure 3 FIG. 4 is a schematic structural diagram of an electronic device provided in Embodiment 3 of the present invention. The electronic device may be a terminal device or a server for implementing the method of the foregoing embodiments, or may be a terminal device or a server for implementing the method of the foregoing embodiments connected to the foregoing terminal device or server. As Figure 3 shown, the electronic device may include: a processor 301 (such as a CPU), a memory 302, and a transceiver 303; the transceiver 303 is coupled to the processor 301, and the processor 301 controls the transceiver operations of the transceiver 303. Various instructions may be stored in the memory 302 for completing various processing functions and implementing the processing steps described in the foregoing method embodiments. Preferably, the electronic device according to the embodiments of the present invention further includes: a power supply 304, a system bus 305, and a communication port 306. The system bus 305 is used to implement communication connections between components. The above communication port 306 is used for the electronic device to connect and communicate with other peripherals.

[0113] In Figure 3The system bus 305 mentioned above can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The system bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface is used to implement communication between the database access device and other devices (such as clients, read-write libraries, and read-only libraries). The memory may include Random Access Memory (RAM), and may also include non-volatile memory, such as at least one disk memory.

[0114] The above-mentioned processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), a Graphics Processing Unit (GPU), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0115] It should be noted that the embodiments of the present invention also provide a computer-readable storage medium, in which instructions are stored. When it runs on a computer, it causes the computer to execute the methods and processing procedures provided in the above embodiments.

[0116] An embodiment of the present invention provides a blockchain evidence storage method, device, electronic device, and computer-readable storage medium for medical data operation characteristics. As can be seen from the above content, the embodiment of the present invention monitors the medical data operation actions performed by a user on the portal web page provided by the medical data sharing network in real time to obtain corresponding user monitoring data; extracts operation characteristics based on the private information of the current user and the user monitoring data to obtain corresponding operation characteristic data; obtains a blockchain timestamp from the evidence storage blockchain as the corresponding operation time; forms corresponding private data from the operation characteristic data and the operation time; generates a zero-knowledge proof π according to the private data by the zero-knowledge proof technology and sends it to the evidence storage blockchain for verification to obtain a corresponding verification result; when the verification result is verified to pass, performs electronic fingerprint generation processing according to the private data to obtain corresponding electronic fingerprint data; performs blockchain evidence storage processing on the electronic fingerprint data through the asynchronous processing method of the cache queue; and performs medical data operation based on the user monitoring data after successful evidence storage and feeds back the operation result to the current user. The embodiment of the present invention uses an evidence storage blockchain deployed with a distributed ledger service to record the data access / operation behavior of users, which not only improves the anti-tampering ability of data but also enhances the active backup ability of data.

[0117] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented in hardware, software modules executed by a processor, or a combination of both. The software modules may be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0118] The above-described specific embodiments further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above is only the specific embodiment of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A blockchain deposit and evidence method for medical data operation characteristics, characterized in that, The method includes: The client monitors in real time the medical data operation actions performed by the user on the portal web page provided by the medical data sharing network to obtain corresponding user monitoring data; the user monitoring data includes an object identifier, an operation type, and operation data; the object identifier is the routing identifier path of the medical data object currently operated by the user, and the routing identifier path is composed of a routing identifier prefix and an end routing identifier, and the routing identifier path corresponds to a specific data storage location on the medical data sharing network; the operation type at least includes addition, modification, deletion, and download; when the operation type is addition or modification, the operation data is a medical data object; when the operation type is deletion or download, the operation data is empty; Extract operation features according to the private information of the current user and the user monitoring data to obtain corresponding operation feature data; obtain the blockchain timestamp from the proof-of-existence blockchain as the corresponding operation time; and form corresponding private data from the operation feature data and the operation time; the operation feature data includes the user's private key, the object identifier, and the operation type; Generate a zero-knowledge proof π according to the private data by the zero-knowledge proof technology and send it to the proof-of-existence blockchain for verification to obtain a corresponding verification result; When the verification result is verification passed, perform electronic fingerprint generation processing according to the private data to obtain corresponding electronic fingerprint data; perform on-chain proof-of-existence processing on the electronic fingerprint data through the asynchronous processing method of the cache queue; and perform medical data operations based on the user monitoring data after successful proof-of-existence and feedback the operation result to the current user.

2. The blockchain deposit and certification method for medical data operation characteristics according to claim 1, characterized in that The method further includes: The medical data sharing network is a distributed data sharing network composed of multiple first network nodes; each of the first network nodes corresponds to a node type, and the node type at least includes a portal website node, a data storage node, and a data calculation node; the first network node of which the node type is a portal website node is used to provide access services for the portal web page; the first network node of which the node type is a data storage node is used to store the medical data object; the first network node of which the node type is a data calculation node is used to provide data storage services, data encryption and decryption services, and algorithm / model inference services; The node network of the proof-of-existence blockchain is a distributed node network composed of multiple first network nodes of which the node type is a data calculation node in the medical data sharing network, and a distributed ledger service is deployed on this distributed node network based on blockchain technology; all the first network nodes of the blockchain network jointly maintain a feature proof-of-existence ledger based on blockchain technology and all the first network nodes have complete ledger copies; all the first network nodes on the proof-of-existence blockchain maintain full-chain time synchronization through an external time server; When constructing the evidence-preserving blockchain, the first network nodes of each node type as data calculation nodes in the medical data sharing network are denoted as corresponding first candidate nodes; and the importance parameter W of each first candidate node is initialized based on the security index A, reachability index B, throughput rate index C, and real-time index D; and the PageRank algorithm is used to iterate the importance parameter W multiple times until the absolute difference between the results of the last two iterations of all the importance parameter W does not exceed a preset first threshold; and the first candidate nodes are sorted in descending order of the importance parameter W to form a corresponding first node sequence; and the K first candidate nodes with higher rankings in the first node sequence form the evidence-preserving blockchain; the security index A, the reachability index B, the throughput rate index C, and the real-time index D are each a normalized numerical index; the initialized importance parameter W = w1A + w2B + w3C + w4D, where w1, w2, w3, and w4 are four preset weight parameters.

3. The blockchain deposit and certification method for medical data operation characteristics according to claim 1, characterized in that The extraction of the operation characteristics according to the private information of the current user and the user monitoring data to obtain the corresponding operation characteristic data specifically includes: The client forms the corresponding operation characteristic data from the user private key of the current user, the object identifier of the user monitoring data, and the operation type.

4. The blockchain deposit and certification method for medical data operation characteristics according to claim 1, characterized in that, The obtaining of the blockchain timestamp from the evidence-preserving blockchain as the corresponding operation time specifically includes: The client takes the first network node closest to the current user on the evidence-preserving blockchain as the corresponding current time synchronization node; and sends a first time synchronization request to the current time synchronization node; and takes the first timestamp sent back by the current time synchronization node as the corresponding operation time.

5. The blockchain evidence storage method for medical data operation characteristics according to claim 1, characterized in that The generation of the zero-knowledge proof π according to the zero-knowledge proof technology for the private data and sending it to the evidence-preserving blockchain for verification to obtain the corresponding verification result specifically includes: Step 51, the client generates a shared first CRS for the current user and the evidence-preserving blockchain according to the public reference string CRS generation method of the zk-SNARKs zero-knowledge proof technology. Step 52, according to the arithmetic circuit configuration method of the zk-SNARKs zero-knowledge proof technology, a shared first arithmetic circuit is generated for the current user and the evidence-preserving blockchain according to the preset permission verification rules. Among them, the permission verification rules include an operation type verification rule and an operation time verification rule; the operation type verification rule consists of multiple object-permission correspondence relationships; the object-permission correspondence relationship consists of a routing identifier prefix and a type of operation permission; the types of operation permissions include addition permission, modification permission, deletion permission, and download permission; the permission values of each type of operation permission include allowed and prohibited; the operation time verification rule is that the time interval between the current time and the operation time cannot exceed a preset time interval threshold. The inputs of the first arithmetic circuit are the object identification prefix d, the object operation type s, the object operation time t, and the current time t now , and the output is the verification result r; the verification result r is 0 or 1, where 0 indicates verification failure and 1 indicates verification success; The processing logic of the first arithmetic circuit is as follows: if the object identifier prefix d and the object operation type s satisfy one of the object-permission correspondence relationships in the operation type verification rule, set the first result to 1; if the object identifier prefix d and the object operation type s do not satisfy any of the object-permission correspondence relationships in the operation type verification rule, set the first result to 0; if the current time t now and the absolute time difference from the object operation time t does not exceed the time interval threshold, set the second result to 1; if the current time t now and the absolute time difference from the object operation time t exceeds the time interval threshold, set the second result to 0; and use the product of the first and second results as the corresponding verification result r; Step 53: Extract the corresponding user private key, object identifier, operation type, and operation time from the private data; Step 54, use the routing identifier prefix of the object identifier as the corresponding object identifier prefix d; use the operation type as the corresponding object operation type s; use the operation time as the corresponding object operation time t; and use the current time information as the corresponding current time t now ; and input the obtained object identifier prefix d, object operation type s, object operation time t, and current time t now into the first arithmetic circuit for processing to obtain the corresponding verification result r; Step 55: If the obtained verification result r is 1, extract the process data during the current processing of the first arithmetic circuit according to the zero-knowledge proof acquisition method of the zk-SNARKs zero-knowledge proof technology to form the corresponding first proof; perform a hash calculation on the first proof according to the zero-knowledge commitment generation method of the zk-SNARKs zero-knowledge proof technology and use the calculation result as the corresponding first commitment; sign the first proof based on the user private key to obtain the corresponding first signature; use the user public key corresponding to the user private key as the corresponding first public key; and send the corresponding zero-knowledge proof π composed of the first public key, the first commitment, the first proof, and the first signature to the evidence storage blockchain; and use the zero-knowledge proof verification result sent back by the evidence storage blockchain as the corresponding verification result.

6. The blockchain evidence storage method for medical data operation features according to claim 5, characterized in that, The method further includes: The evidence storage blockchain extracts the corresponding first public key, first commitment, first proof, and first signature from the zero-knowledge proof π; perform signature verification on the first signature according to the first public key and the first proof; set the first comparison result to match when the current signature verification passes, and set the first comparison result to not match when the current signature verification fails; perform a hash calculation on the first proof according to the zero-knowledge commitment generation method of the zk-SNARKs zero-knowledge proof technology and use the calculation result as the corresponding second commitment; identify whether the first and second commitments match, set the second comparison result to match if they match, and set the second comparison result to not match if they do not match; load the first proof as process data onto the shared first arithmetic circuit for reprocessing to obtain a new verification result r; identify whether the obtained verification result r is 1, set the third comparison result to match if it is, and set the third comparison result to not match if it is not; identify whether the obtained first, second, and third comparison results are all matches; if so, set the corresponding zero-knowledge proof verification result to verification passed; if not, set the corresponding zero-knowledge proof verification result to verification failed; and send the obtained zero-knowledge proof verification result back to the client.

7. The blockchain deposit and certification method for medical data operation characteristics according to claim 1, characterized in that, The generation of the electronic fingerprint data according to the private data specifically includes: The client extracts the corresponding user private key and object identifier from the private data; performs a digest calculation on the user private key and the object identifier respectively based on the national cryptography SM3 algorithm to obtain the corresponding private key digest and identifier digest; sequentially splices the private key and the identifier digest to form the corresponding spliced digest; performs two digest calculations on the spliced digest based on the national cryptography SM3 algorithm to obtain the corresponding first and second digests; and sequentially splices the first and second digests to form the corresponding electronic fingerprint data; Among them, the private key digest, the identity digest, the first digest, and the second digest are all 128-bit digital digests; the spliced digest and the electronic fingerprint data are both 256-bit digital digests.

8. The blockchain evidence depositing method for medical data operation features according to claim 1, characterized in that, The asynchronous processing method through the cache queue is used to perform blockchain-based evidence storage processing on the electronic fingerprint data, which specifically includes: Step 81, the client sets the evidence storage status corresponding to the current electronic fingerprint data as not yet stored; and forms a corresponding first cache data from the current electronic fingerprint data and the corresponding operation type and adds it to a preset first cache queue; and uses the first network node closest to the current user on the evidence storage blockchain as the corresponding current evidence storage node; Among them, when the first cache queue is not empty, it is composed of one or more of the first cache data; Step 82, when the first cache queue is not empty, the first cache data with the earliest time in the queue is used as the corresponding current cache data; and based on the ledger block data encapsulation rule of the feature evidence storage ledger, block encapsulation processing is performed according to the current cache data to obtain the corresponding current new block; and the current evidence storage node is used to perform full-chain ledger update processing on the current new block; and after the full-chain ledger update processing is successful, the current cache data is deleted from the first cache queue, and the evidence storage status of the electronic fingerprint data corresponding to the current cache data is set as successfully stored.

9. The blockchain evidence storage method for the medical data operation characteristics according to claim 1, characterized in that After successful evidence storage, medical data operations are performed based on the user monitoring data and the operation results are fed back to the current user, which specifically includes: Step 91, when the evidence storage status corresponding to the electronic fingerprint data is set as successfully stored by the client, the user monitoring data corresponding to the current electronic fingerprint data is used as the corresponding current monitoring data; and the corresponding object identifier, operation type, and operation data are extracted from the current monitoring data; Step 92, and identify the operation type; Step 93, if the operation type is add or modify, the operation data is used as a corresponding current medical data object, and the current medical data object is uploaded to the storage location corresponding to the object identifier in the medical data sharing network, and when the upload is completed, the operation is fed back to the current user as completed; Step 94, if the operation type is delete, the medical data object stored at the storage location corresponding to the object identifier in the medical data sharing network is deleted, and when the deletion is completed, the operation is fed back to the current user as completed; Step 95, if the operation type is download, the medical data object stored at the storage location corresponding to the object identifier in the medical data sharing network is downloaded to the storage location specified by the current user, and when the download is completed, the operation is fed back to the current user as completed.

10. An apparatus for implementing the blockchain evidence storage method of the medical data operation feature described in any one of claims 1-9, characterized in that, The device includes: a behavior monitoring module, an operation feature extraction module, a zero-knowledge proof verification module, and a blockchain evidence storage module; The behavior monitoring module is used to monitor in real time the medical data operation actions performed by the user on the portal web page provided by the medical data sharing network to obtain corresponding user monitoring data; the user monitoring data includes an object identifier, an operation type, and operation data; the object identifier is the routing identifier path of the medical data object currently operated by the user, and the routing identifier path is composed of a routing identifier prefix and an end routing identifier, and the routing identifier path corresponds to a specific data storage location on the medical data sharing network; the operation type at least includes addition, modification, deletion, and download; when the operation type is addition or modification, the operation data is a medical data object; when the operation type is deletion or download, the operation data is empty. The operation feature extraction module is used to extract operation features according to the private information of the current user and the user monitoring data to obtain corresponding operation feature data; and obtain the blockchain timestamp from the proof-of-storage blockchain as the corresponding operation time; and form corresponding private data from the operation feature data and the operation time; the operation feature data includes the user private key, the object identifier, and the operation type. The zero-knowledge proof verification module is used to generate a zero-knowledge proof π according to the zero-knowledge proof technology based on the private data and send it to the proof-of-storage blockchain for verification to obtain a corresponding verification result. The blockchain proof-of-storage module is used to, when the verification result is verification passed, perform electronic fingerprint generation processing according to the private data to obtain corresponding electronic fingerprint data; and perform on-chain proof-of-storage processing on the electronic fingerprint data through the asynchronous processing method of the cache queue; and perform medical data operations based on the user monitoring data after successful proof-of-storage and feedback the operation result to the current user.

11. An electronic device, characterized in that, Including: A memory, a processor, and a transceiver; The processor is used to be coupled with the memory, read and execute the instructions in the memory to implement the method according to any one of claims 1-9. The transceiver is coupled with the processor, and the processor controls the transceiver to perform message sending and receiving.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a computer, the computer is caused to execute the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Electronic medical record system based on block chain and biological characteristics

    CN111274592A

  • Multi-person participation BIM drawing copyright protection system and method based on block chain

    CN111581605A

  • Big data supervision method based on block chain technology

    CN114900534A

  • System and method for information protection

    IN201947014599A

  • Patient-empowered data management: a secure blockchain architecture with decentralized ownership

    US12235984B1