Laboratory detection data access method
Through the database of improved abstract algorithm and hash index structure, the retrieval efficiency and data security of laboratory detection systems in high concurrency scenarios are solved, and the unique identification and full-link protection of the detection data are realized, meeting the requirements of GLP and ISO 17025 standards.
Patent Information
- Application Number
- CN202510414582.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-22
AI Technical Summary
The existing laboratory testing system is inefficient in retrieval when facing massive heterogeneous detection data, which is difficult to support high-concurrency scenarios, and data integrity and security are difficult to guarantee, which cannot meet the requirements of GLP and ISO 17025 standards.
A database using an improved digest algorithm and hash index structure is used to generate multi-layer hash values and QR code verification to realize unique identification and encrypted transmission of data blocks, and a full-link protection system is built.
While ensuring that the processing load does not increase, the uniqueness of the summary results and anti-malware access capabilities are strengthened, adapting to a high-concurrency environment, ensuring the non-deniability of data and the auditability of operational behaviors.
Smart Images

Figure CN120354427A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing and access, and particularly to a method for accessing laboratory test data. Background Art
[0002] In the field of laboratory testing, with the popularization of high-throughput testing equipment and the exponential growth of the scale of test data, how to achieve the secure storage, efficient retrieval, and auditable traceability of test data has become the core pain point of the industry. Traditional laboratory information management systems (LIMS) mostly adopt conventional database architectures. Their linear indexing methods based on timestamps or sample numbers have problems of a sharp drop in retrieval efficiency when facing massive heterogeneous test data (such as spectral data, chromatogram, multi-dimensional test results), and it is difficult to support high-concurrency scenarios where multiple laboratory technicians submit in parallel and access in real time.
[0003] In the prior art, there are significant defects in the integrity guarantee mechanism of test data: on the one hand, the storage of test results depends on basic hash verification, and it is easy to be unable to effectively identify data tampering behavior due to algorithm collisions. Especially in the scenario of generating multi-version test reports, version confusion may lead to serious quality control risks; on the other hand, during the process of test data interaction, plaintext transmission or static key encryption is often used between the client and the server, which is vulnerable to man-in-the-middle attacks or malicious tampering by internal personnel, and cannot meet the strict requirements of standards such as GLP (Good Laboratory Practice), ISO 17025, etc. for the security of the entire data life cycle.
[0004] In addition, laboratory test data needs to be retained for a long time and support judicial-level evidence chain traceability. However, traditional systems lack a cryptographic-based dynamic solidification mechanism, resulting in the risk of batch tampering of audit logs in the data creation, modification, and sharing links. In terms of preventing parameter injection attacks, existing solutions are difficult to distinguish normal test parameter adjustments from malicious instruction injections, which may lead to abnormal test logic or contamination of original data.
[0005] Therefore, there is an urgent need to construct a dedicated data processing architecture for laboratory testing scenarios. This architecture needs to achieve a strong unique identification of test data fingerprints, ensure millisecond-level response capabilities in a high-concurrency environment, and at the same time establish a full-link protection system covering data generation, transmission, storage, and access, ensuring the non-repudiation of test results, version traceability, and auditable operation behaviors, so as to meet the rigid requirements for the credibility and compliance of test data in fields such as pharmaceutical research and development and environmental monitoring. Summary of the Invention
[0006] The purpose of the present invention is to provide a method for accessing laboratory test data. This method combines an improved digest algorithm with a database having a hash index structure to strengthen the uniqueness of the digest result and the ability to prevent malicious access while ensuring that the processing load does not increase.
[0007] The technical solution for achieving the object of the present invention is as follows: The present invention includes the following steps: S1. Format the original records of the detection data and the detection report into a fixed-length data block G1 and a variable-length data block G2 respectively. Calculate the digest of both the fixed-length data block G1 and the variable-length data block G2, and generate corresponding 32-bit hexadecimal hash values A1 and A2 respectively; S2. Construct a resource archive database; the resource archive database contains resource archive database entries jointly composed of the hash value A1 and the data block G1, and also contains resource archive database entries jointly constructed by the hash value A2, the data block G2 and the physical address; the resource archive database is stored and accessed in a hash index structure; S3. After verifying the operator's identity, the service interface P0 formats the operator UID, the report approval process data and the external access authorization parameters into a fixed-length data block G3, and calculates the digest of the fixed-length data block G3 to obtain a 32-bit hexadecimal hash value A3; the hash value A3 and the data block G3 jointly constitute a resource archive database entry; S4. The service interface P0 assembles the URL address of the external access interface P1 with the hash values A1, A2, and A3 to generate a formal secure access link, and presents it in the form of a two-dimensional code; S5. The client triggers an identity recognition operation by scanning the two-dimensional code, automatically binds the unique identifier UID of the client and initiates a detection data access request to the external access interface P1. After receiving the access request, the external access interface P1 parses the hash value and the visitor UID, performs a reversible scrambling operation on the returned data after passing the triple hash legality verification, and the client uses the hash value A3 to decode and present it.
[0008] Further, after receiving the access request in step S5 above, the external access interface P1 performs parameter parsing and processing, decomposes and obtains the hash values A1, A2, A3 and the visitor identity identifier UID from the parameter string submitted in the network request; synchronously generates an access log record containing the complete information of the parameter string; then checks the access legality and record legality respectively with the hash values A1, A2, A3; if all pass, perform a reversible scrambling operation on the corresponding returned data block with the hash value A3 to form a ciphertext, and then return the access result; after receiving the ciphertext, the client uses the hash value A3 obtained by scanning the code to decode the ciphertext and present it for the user to read.
[0009] Further, the above digest calculation is carried out according to the following steps: (1) Perform tail padding on the input data so that the remainder of the length of the padded data divided by 512 is 448; (2) Add a 64-bit original data length value to the tail of the padded data; (3) Divide the processed data into N frames with a length of 512 bits; (4) Divide each frame into 16 32-bit data groups M0 - M15; (5) Initialize four 32-bit parameters A, B, C, and D; (6) Perform four arithmetic operations on each data group, and the processing functions are FF, GG, HH, and II; (7) Accumulate the operation results of each processed frame with the initial parameters; (8) Combine the accumulated parameters to generate a 128-bit digest string.
[0010] Further, the padding in step (1) starts with binary "1000..."; The 64-bit length value added in step (2) is the binary bit length of the original input data; The generation of the initialization parameters in step (5) includes: in the prime number sequence (2, 3, 5, 7, 11, 13......), take the first four prime numbers 2, 3, 5, 7; find the algebraic approximation of the first 20 digits before the square root of each prime number; obtain: √2 ≈ 1.41421356237309504880; √3 ≈ 1.73205080756887729353; √5 ≈ 2.23606797749979000081; √7 ≈ 2.64575131106459062904; Starting from the 2nd, 3rd, 5th, and 7th digits after the decimal point of the above approximate values respectively, take eight natural numbers to form the following arrays: (1, 4, 2, 1, 3, 5, 6, 2); (2, 0, 5, 0, 8, 0, 7, 5); (6, 7, 9, 7, 7, 4, 9, 9); (3, 1, 1, 0, 6, 4, 5, 9); Combine each array pairwise from left to right and perform hexadecimal conversion to get: (0e 15 23 3e); (14 32 50 4b); (43 61 4a 63); (1f 0a 40 3b); Then the initial values of the variables referenced in the subsequent grouped calculations are respectively: A = 0x0e15233e; B = 0x1432504b; C = 0x43614a63; D = 0x1f0a403b; In step (6), four rounds of non - linear transformation operations are performed on each 32 - bit data group M0 - M15 obtained in step (4); the specific implementation methods of each processing function are as follows: The operation of FF(a, b, c, d, Mj, s, ti) is a = b + ((a + F(b, c, d)+Mj + ti) <<< s); The operation of GG(a, b, c, d, Mj, s, ti) is a = b + ((a + G(b, c, d)+Mj + ti) <<< s); The operation of HH(a, b, c, d, Mj, s, ti) is a = b + ((a + H(b, c, d)+Mj + ti) <<< s); The operation of II(a, b, c, d, Mj, s, ti) is a = b + ((a + I(b, c, d)+Mj + ti) <<< s); The Boolean operations of logical functions F, G, H, and I are defined as follows: F(X, Y, Z)=(X & Y)|((~X)&Z); G(X, Y, Z)=(X & Z)|(Y & (~Z)); H(X, Y, Z)=X ^ Y ^ Z; I(X, Y, Z)=Y ^ (X | (~Z)); Where: a, b, c, d are the initial input data, that is, A, B, C, D generated by the initialization parameters in step (5); Mj represents the 32 - bit message block being processed currently; s is the preset number of bits for circular left - shift; ti is a 32 - bit constant determined according to the current round; the constant value of ti is calculated using the absolute value of the sine function, specifically: ti = floor(2³² × |sin(i)|), where i represents the serial number of the current operation step, and i ∈ [1, 64]; <<< means: circularly shift the binary bit sequence of the 32 - bit operand s bits to the left, and the high - order bits shifted out from the left end are filled into the low - order bits at the right end in turn; The initial parameters A, B, C, and D are respectively used as the inputs of a, b, c, and d for the first-round operation. Sixteen 32-bit data groups M0 - M15 divided from each 512-bit data block are subjected to four rounds of iterative processing; each round contains 16 basic operations, and a total of 16×4 = 64 transformation operations are performed in four rounds; each operation uses the preset s shift parameter and the ti constant table value. Step (7) cyclically operates on the current 512-bit data block in step (6) to obtain intermediate results a, b, c, and d; then the intermediate results a, b, c, and d are respectively accumulated with the initial values or the results of the previous block operation A, B, C, and D, and the operation method is as follows: A = a + A; B = b + B; C = c + C; D = d + D; If there is a next 512-bit data block, the updated A, B, C, and D are used as the input parameters for the next block to continue the operation; otherwise, the final A, B, C, and D are output as the calculation results of the message digest.
[0011] The present invention has positive effects: (1) Through the improved digest algorithm and combined with the database of the hash index structure, the present invention strengthens the uniqueness of the digest result and the anti-malicious access ability while ensuring that the processing load does not increase.
[0012] (2) The database of the hash index structure of the present invention is more suitable for ensuring the access speed in high-concurrency application scenarios; at the same time, it adapts to scenarios with strict requirements for the evidence chain of data creation and sharing.
[0013] (3) The present invention prevents parameter injection-style network attacks from succeeding; avoids accessing inconsistent data versions; (4) All data interactions between the client and the platform in the present invention are scrambled ciphertexts or irreversible private keys, which improves the information security of both parties to the access, and in this process, all access requests and return results cannot be partially tampered with. Brief Description of the Drawings
[0014] In order to make the content of the present invention easier to be clearly understood, the following further elaborates on the present invention according to specific embodiments in conjunction with the drawings, where Figure 1 is a schematic diagram of the implementation steps of the present invention. Detailed Embodiments
[0015] See Figure 1 , the present invention includes the following steps: S1. Format the original records of the detection data and the detection report into a fixed-length data block G1 and a variable-length data block G2 respectively. Calculate the digest for both the fixed-length data block G1 and the variable-length data block G2, and generate the corresponding 32-bit hexadecimal hash values A1 and A2 respectively. S2. Construct a resource archive database; the resource archive database contains resource archive database entries jointly composed of the hash value A1 and the data block G1, and also contains resource archive database entries jointly constructed by the hash value A2, the data block G2, and the physical address; the resource archive database is stored and accessed in a hash index structure. S3. After verifying the operator's identity, the service interface P0 formats the operator UID, the report approval process data, and the external access authorization parameters into a fixed-length data block G3, and calculates the digest for the fixed-length data block G3 to obtain a 32-bit hexadecimal hash value A3; the hash value A3 and the data block G3 jointly form a resource archive database entry. S4. The service interface P0 assembles the URL address of the external access interface P1 with the hash value A1, the hash value A2, and the hash value A3 to generate a formal secure access link, and presents it in the form of a QR code. S5. The client triggers an identity recognition operation by scanning the QR code, automatically binds the unique identifier UID of the client, and initiates a detection data access request to the external access interface P1. After receiving the access request, the external access interface P1 performs parameter parsing and processing, and decomposes and obtains the hash value A1, the hash value A2, the hash value A3, and the visitor identity identifier UID from the parameter string submitted in the network request; synchronously generates an access log record containing the complete information of the parameter string; then checks the access legality and record legality respectively with the hash value A1, the hash value A2, and the hash value A3; if all pass, perform a reversible scrambling operation on the corresponding returned data block with the hash value A3 to form a ciphertext, and then return the access result; after receiving the ciphertext, the client decodes the ciphertext with the hash value A3 obtained by scanning the code and presents it for the user to read.
[0016] The digest calculation is carried out according to the following steps: (1) Perform tail padding on the input data so that the remainder of the length of the padded data divided by 512 is 448. (2) Add a 64-bit original data length value to the tail of the padded data. (3) Divide the processed data into N frames according to a length of 512 bits. (4) Divide each frame into 16 32-bit data groups M0 - M15. (5) Initialize four 32-bit parameters A, B, C, D. (6) Perform four arithmetic operations on each data group, and the processing functions are FF, GG, HH, II. (7) Accumulate the operation result of each processed frame with the initial parameters; (8) Combine the accumulated parameters to generate a 128-bit digest string.
[0017] The padding in step (1) starts with binary "1000..."; The 64-bit length value added in step (2) is the binary bit length of the original input data; The generation of the initial parameters in step (5) includes: among the prime number sequence (2, 3, 5, 7, 11, 13......), take the first four prime numbers 2, 3, 5, 7; find the algebraic approximation of the first 20 digits before the square root of each prime number; obtain: √2 ≈ 1.41421356237309504880; √3 ≈ 1.73205080756887729353; √5 ≈ 2.23606797749979000081; √7 ≈ 2.64575131106459062904; Take eight natural numbers starting from the 2nd, 3rd, 5th, and 7th digits after the decimal point of the above approximate values respectively to form the following arrays: (1, 4, 2, 1, 3, 5, 6, 2); (2, 0, 5, 0, 8, 0, 7, 5); (6, 7, 9, 7, 7, 4, 9, 9); (3, 1, 1, 0, 6, 4, 5, 9); Combine each array pairwise from left to right and perform hexadecimal conversion to obtain: (0e 15 23 3e); (14 32 50 4b); (43 61 4a 63); (1f 0a 40 3b); Then the initial values of the variables referenced in the subsequent block calculations are respectively: A = 0x0e15233e; B = 0x1432504b; C = 0x43614a63; D = 0x1f0a403b; In step (6), four rounds of non-linear transformation operations are performed on each 32-bit data group M0 - M15 obtained in step (4); the specific implementation methods of each processing function are: The operation of FF(a, b, c, d, Mj, s, ti) is a = b + ((a + F(b, c, d) + Mj + ti) <<< s); The operation of GG(a, b, c, d, Mj, s, ti) is a = b + ((a + G(b, c, d) + Mj + ti) <<< s); The operation of HH(a, b, c, d, Mj, s, ti) is a = b + ((a + H(b, c, d) + Mj + ti) <<< s); The operation of II(a, b, c, d, Mj, s, ti) is a = b + ((a + I(b, c, d) + Mj + ti) <<< s); The Boolean operations of the logical functions F, G, H, and I are defined as: F(X, Y, Z) = (X & Y) | ((~X) & Z); G(X, Y, Z) = (X & Z) | (Y & (~Z)); H(X, Y, Z) = X ^ Y ^ Z; I(X, Y, Z) = Y ^ (X | (~Z)); Where: a, b, c, d are the initial input data, which are A, B, C, D generated by the initialization parameters in step (5); Mj represents the 32-bit message block being currently processed; s is the preset number of circular left shift bits; ti is a 32-bit constant determined according to the current round; the value of the ti constant is generated by calculating the absolute value of the sine function, specifically: ti = floor(2³² × |sin(i)|), where i represents the sequence number of the current operation step, and i ∈ [1, 64]; <<< means: circularly shift the binary bit sequence of the 32-bit operand to the left by s bits, and the high bits shifted out from the left end are filled into the low bits at the right end in turn; The initial parameters A, B, C, D are respectively input as a, b, c, d for the first-round operation, and 16 32-bit data groups M0 - M15 divided from each 512-bit data block are processed through four rounds of iteration; each round contains 16 basic operations, and a total of 16 × 4 = 64 transformation operations are performed in four rounds; each operation uses the preset s shift parameter and the ti constant table value; Step (7) performs a cyclic operation on the current 512-bit data block in step (6) to obtain intermediate results a, b, c, and d; then the intermediate results a, b, c, and d are respectively accumulated with the initial values or the results of the previous block operation A, B, C, and D, and the operation method is as follows: A = a + A; B = b + B; C = c + C; D = d + D; If there is a next 512-bit data block, the updated A, B, C, and D are used as the input parameters for the next block to continue the operation; otherwise, the final A, B, C, and D are output as the calculation results of the message digest.
[0018] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for accessing laboratory test data; characterized in that It includes the following steps: S1. Format the original record of detection data and the detection report into a fixed-length data block G1 and a variable-length data block G2 respectively, calculate the digest for both the fixed-length data block G1 and the variable-length data block G2, and generate corresponding 32-bit hexadecimal hash values A1 and A2 respectively; S2. Construct a resource archive database; the resource archive database contains resource archive database entries jointly composed of the hash value A1 and the data block G1, and also contains resource archive database entries jointly constructed by the hash value A2, the data block G2, and the physical address; the resource archive database is stored and accessed in a hash index structure; S3. After verifying the operator's identity, the service interface P0 formats the operator UID, report approval flow data, and external access authorization parameters into a fixed-length data block G3, and calculates the digest for the fixed-length data block G3 to obtain a 32-bit hexadecimal hash value A3; the hash value A3 and the data block G3 jointly form a resource archive database entry; S4. The service interface P0 assembles the URL address of the external access interface P1 with the hash values A1, A2, and A3 to generate a formal secure access link, and presents it in the form of a QR code; S5. The client triggers an identity recognition operation by scanning the QR code, automatically binds the unique identifier UID of the client, and initiates a detection data access request to the external access interface P1. After receiving the access request, the external access interface P1 parses the hash value and the visitor UID, performs a reversible scrambling operation on the returned data after passing the triple hash legality verification, and the client decodes and presents it using the hash value A3.
2. The laboratory test data access method according to claim 1, wherein: In step S5, after the external access interface P1 receives the access request, it performs parameter parsing processing, decomposes and obtains the hash values A1, A2, A3, and the visitor identity identifier UID from the parameter string submitted in the network request; synchronously generates an access log record containing the complete information of the parameter string; then checks the access legality and record legality with the hash values A1, A2, and A3 respectively; if all pass, it performs a reversible scrambling operation on the corresponding returned data block with the hash value A3 to form a ciphertext, and then returns the access result; after receiving the ciphertext, the client decodes the ciphertext using the hash value A3 obtained by scanning the code and presents it for the user to read.
3. The laboratory test data access method according to claim 1 or 2, characterized in that: The digest calculation is carried out according to the following steps: (1) Perform tail padding on the input data so that the remainder of the length of the padded data divided by 512 is 448; (2) Add a 64-bit original data length value to the tail of the padded data; (3) Divide the processed data into N frames according to a length of 512 bit; (4) Divide each frame into 16 32-bit data groups M0 - M15; (5) Initialize four 32-bit parameters A, B, C, D; (6) Perform four arithmetic operations on each data group, and the processing functions are FF, GG, HH, II; (7) Accumulate the operation results after processing each frame with the initial parameters; (8) Combine the accumulated parameters to generate a 128-bit digest string.
4. The laboratory test data access method according to claim 3, wherein: The padding in step (1) starts with binary "1000...". The 64-bit length value added in step (2) is the binary bit length of the original input data; The initialization parameter generation in step (5) includes: in the prime number sequence (2, 3, 5, 7, 11, 13......), take the first four prime numbers 2, 3, 5, 7; find the algebraic approximation of the first 20 digits of the square root of each prime number; obtain: √2≈1.41421356237309504880; √3≈1.73205080756887729353; √5≈2.23606797749979000081; √7≈2.64575131106459062904; Take eight natural numbers starting from the 2nd, 3rd, 5th, and 7th digits after the decimal point of the above approximate values respectively to form the following arrays: (1,4,2,1,3,5,6,2); (2,0,5,0,8,0,7,5); (6,7,9,7,7,4,9,9); (3,1,1,0,6,4,5,9); Combine each array in pairs from left to right and perform hexadecimal conversion to obtain: (0e 15 23 3e); (14 32 50 4b); (43 61 4a 63); (1f 0a 40 3b); Then the initial values of the variables referenced in the subsequent block calculations are respectively: A = 0x0e15233e; B = 0x1432504b; C = 0x43614a63; D = 0x1f0a403b; In step (6), four rounds of non-linear transformation operations are performed on each 32-bit data group M0 - M15 obtained in step (4); the specific implementation methods of each processing function are: The operation of FF(a, b, c, d, Mj, s, ti) is a = b + ((a + F(b, c, d) + Mj + ti) <<< s); The operation of GG(a, b, c, d, Mj, s, ti) is a = b + ((a + G(b, c, d) + Mj + ti) <<< s); The operation of HH(a, b, c, d, Mj, s, ti) is a = b + ((a + H(b, c, d) + Mj + ti) <<< s); The operation of II(a, b, c, d, Mj, s, ti) is a = b + ((a + I(b, c, d) + Mj + ti) <<< s); The Boolean operations of the logic functions F, G, H, and I are defined as: F(X, Y, Z) = (X & Y) | ((~X) & Z); G(X, Y, Z) = (X & Z) | (Y & (~Z)); H(X, Y, Z) = X ^ Y ^ Z; I(X, Y, Z) = Y ^ (X | (~Z)); Where: a, b, c, d are the initial input data, that is, A, B, C, D generated by the initialization parameters in step (5); Mj represents the 32-bit message block currently being processed; s is the preset circular left shift number of bits; ti is a 32-bit constant determined according to the current round; the constant value of ti is generated by calculating the absolute value of the sine function, specifically: ti = floor(2³² × |sin(i)|), where i represents the serial number of the current operation step, i ∈ [1, 64]; <<< means: circularly shift the binary bit sequence of the 32-bit operand to the left by s bits, and the high bits shifted out from the left end are filled into the low bits at the right end in turn; The initial parameters A, B, C, and D are respectively used as the inputs of a, b, c, and d in the first-round operation, and 16 32-bit data groups M0 - M15 divided from each 512-bit data block are subjected to four rounds of iterative processing; each round contains 16 basic operations, and a total of 16×4 = 64 transformation operations are performed in four rounds; each operation uses a preset s shift parameter and the ti constant table value. Step (7) circularly operates on the current 512-bit data block in step (6) to obtain intermediate results a, b, c, and d; then the intermediate results a, b, c, and d are respectively accumulated with the initial values or the results of the previous block operation A, B, C, and D, and the operation method is as follows: A = a + A; B = b + B; C = c + C; D = d + D; If there is a next 512-bit data block, the updated A, B, C, and D are used as the input parameters for the next block to continue the operation; otherwise, the final A, B, C, and D are output as the calculation results of the message digest.