Medical data sharing method based on dynamic attribute-based encryption and medium

Through dynamic attribute-based encryption and geofencing technology, blockchain self-healing contracts generate differential key ΔKey, solving the problems of low emergency authorization efficiency and insufficient user privacy protection in blockchain medical systems, and achieving rapid response and efficient access to medical data.

CN120378086APending Publication Date: 2025-07-25RUIJIN HOSPITAL AFFILIATED TO SHANGHAI JIAO TONG UNIV SCHOOL OF MEDICINE

Patent Information

Application Number
CN202510578141.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing blockchain medical system has low authorization efficiency in emergency authorization scenarios, cannot adapt to dynamic scenarios, and insufficient user privacy protection.

Method used

The dynamic attribute-based encryption method is adopted to generate a differential key ΔKey through the blockchain self-healing contract, and combined with Merkle-Patricia Trie data index tree and geofencing technology, dynamically update access policies and enhance user privacy protection.

Benefits of technology

It improves the efficiency of emergency authorization, reduces storage overhead, enhances user privacy protection, and meets the medical data access needs in complex dynamic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378086A_ABST
    Figure CN120378086A_ABST
Patent Text Reader

Abstract

The invention relates to the field of medical data sharing, and provides a medical data sharing method based on dynamic attribute-based encryption and a medium, and the method comprises the steps: 1, constructing a medical data sharing platform through employing a block chain technology; 2, generating a data index tree; and step 3, when the user node queries the medical data, obtaining the access authority according to an access strategy: S3-1, the access strategy comprises a static attribute and a dynamic attribute, and a new access strategy is generated every time the dynamic attribute is changed; when a new access strategy is generated, automatically generating a corresponding differential key delta Key based on self-healing of the block chain; s3-2, the differential key delta Key is used for positioning a part associated with the dynamic attribute in the data index tree and updating index information of the part; and S3-3, the corresponding consensus node opens the corresponding medical data to the user node. The invention aims to solve the problems that the authorization efficiency is difficult to adapt to a dynamic scene and the user privacy protection is insufficient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of medical data sharing, and particularly to a medical data sharing method and medium based on dynamic attribute-based encryption. Background Art

[0002] Blockchain technology is an encrypted database technology jointly maintained by decentralized and distributed nodes. Applying it to medical data management has significant advantages. For example, based on the immutability of the blockchain, the integrity and traceability of medical data can be ensured. However, existing blockchain medical systems still have certain limitations:

[0003] On the one hand, existing encryption strategies that use static attributes such as doctor identity and department as encryption conditions have poor adaptability to dynamic scenarios. For example, the content disclosed in Chinese Patent CN113889208B adopts a fixed attribute encryption strategy. This encryption strategy results in a strong binding of permissions and data. In scenarios that require emergency authorization, such as first aid, it is necessary to re-encrypt and reconstruct the full-index, with insufficient timeliness and low permission update efficiency. The hospital scenario is different from other static organizational structures, and it is impossible to simply cover all situations with static attributes. Therefore, the current situation of being unable to support high-frequency temporary authorization restricts the development of blockchain medical systems.

[0004] On the other hand, although traditional zero-knowledge proofs can verify identities, they cannot prevent malicious nodes from inferring patients' sensitive information through multi-transaction correlation analysis. For example, inferring the disease type by drug purchase records, etc., lacking a fine-grained spatio-temporal attribute constraint mechanism, and still having deficiencies in protecting user information. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a medical data sharing method and medium based on dynamic attribute-based encryption in view of the above-mentioned defects of the prior art, aiming to solve the problems of difficult adaptation of authorization efficiency to dynamic scenarios and insufficient protection of user privacy in the prior art.

[0006] To solve the above technical problems,

[0007] In a first aspect, the present invention proposes a medical data sharing method based on dynamic attribute-based encryption, including the following steps:

[0008] Step 1: Use blockchain technology to build a medical data sharing platform. The platform includes a number of institutional nodes and consensus nodes connected through a P2P network. Each institutional node contains a number of user nodes; the consensus nodes serve as independent verification nodes and communicate bidirectionally with the institutional nodes. The institutional nodes at least include various medical institutions, and the user nodes at least include doctors in medical institutions;

[0009] Step 2: Each institutional node stores the encrypted medical data of this institution in the local server, and extracts features from the medical data to generate a corresponding data index tree.

[0010] Step 3: When the user node queries medical data, it needs to obtain the access permission according to the access policy and then access the medical data of the corresponding institutional node. The specific implementation steps are as follows:

[0011] S3-1: The access policy includes static attributes and dynamic attributes. The dynamic attributes include time constraints and space constraints. Each time the dynamic attributes change, a new access policy will be generated. When a new access policy is generated, based on the self-healing contract of the blockchain, the corresponding differential key ΔKey is automatically generated according to the following formula: [ΔKey = H(old policy ⊕ new policy ‖ timestamp)], where H is the hash coefficient; ⊕ is the exclusive OR operation.

[0012] S3-2: The differential key ΔKey is used to locate the part associated with the dynamic attributes in the data index tree and update the index information of this part.

[0013] S3-3: Based on the updated data index tree, the consensus node opens the corresponding medical data to the user node.

[0014] Further, the expression of the access policy is:

[0015] <Access policy> ::= <Static attribute> "AND" <Dynamic attribute>

[0016] <Dynamic attribute> ::= "(" <Time constraint> ")" | "(" <Space constraint> ")".

[0017] <Time constraint> ::= "Time" "∈" "[" <Start time> "," <End time> "]".

[0018] <Space constraint> ::= "GPS" "∈" "[" <Longitude> "," <Latitude> "," "Radius" <Distance> "m]".

[0019] Further, the data index tree is designed based on Merkle-Patricia Trie. The data index tree includes at least a root node, a parent node, and a leaf node. The index information of each node is expressed by a hash value.

[0020] Further, the specific steps for the differential key ΔKey to locate the part associated with the dynamic attributes in the data index tree and update the index information of this part include:

[0021] Hash-encode the dynamic attributes using the differential key ΔKey to generate a path prefix; starting from the root node, traverse the Merkle-Patricia Trie data index tree according to the path prefix to find the leaf node associated with the dynamic attributes;

[0022] Modify the index information of the leaf node and recalculate its hash value;

[0023] Recursively update the hash values of the parent nodes along the path until the root node.

[0024] Furthermore, after generating the differential key ΔKey in step S3-1, the self-healing contract sends the differential key ΔKey to the side chain, and the side chain broadcasts the differential key ΔKey to all user nodes; the side chain is specifically used to process access policy change transactions.

[0025] Furthermore, in the first-aid scenario, a geofence is automatically generated based on the spatial constraint conditions in the dynamic attributes. When the GPS coordinates of the user node fall within the geofence, the self-healing contract triggers the issuance of immediate access permissions.

[0026] Furthermore, the zk-STARKs algorithm is integrated into the self-healing contract to verify whether the user node meets all the dynamic attributes in the new access policy. The specific expression is:

[0027] [Proof π = zkSTARK.Prove(ΔKey, policy change record)]

[0028] In the formula, zkSTARK.Prove is a proof generation algorithm based on zero-knowledge succinct transparent arguments, which supports the joint proof of the legality of ΔKey and the authenticity of the access policy change; DeltaKey is the differential key ΔKey; the policy change record includes the old access policy, the new access policy, and the timestamp.

[0029] Furthermore, in step S3-2, it also includes adding a dynamic obfuscation mechanism based on the differential key ΔKey:

[0030] Extract the real-time spatio-temporal tags of the user node, including the timestamp and GPS coordinates;

[0031] Process the extracted spatio-temporal tags through the hash function H to generate an obfuscation factor MixTag = H(T||G), where H is the hash function, T is the timestamp, G is the GPS coordinate, and || represents the string concatenation operation;

[0032] Combine the differential key ΔKey with the obfuscation factor MixTag to generate a dynamic obfuscation key ObfuscationKey =

[0033] H(ΔKey ⊕ MixTag), where H is a hash function, ΔKey is the differential key ΔKey, MixTag is the confusion factor, and ⊕ represents the exclusive-or operation;

[0034] Based on ObfuscationKey, perform dynamic perturbation on the part of the data index tree associated with dynamic attributes, including node order adjustment, node hash perturbation, and redundant false node insertion;

[0035] On the premise of ensuring data integrity, through dynamic obfuscation processing, reduce the anti-identification rate of user nodes when accessing the data index tree to within the anti-identification threshold range.

[0036] Furthermore, the consensus node periodically verifies the anti-identification rate. When the anti-identification rate exceeds the anti-identification threshold, automatically adjust the obfuscation parameters to reduce the anti-identification rate to within the anti-identification threshold range.

[0037] In a second aspect, a computer-readable storage medium is provided, on which multiple instructions are stored, characterized in that the instructions are adapted to be loaded and executed by a processor to implement the steps of the medical data sharing method based on dynamic attribute-based encryption as described in any one of the above.

[0038] The beneficial effects brought by the present invention are:

[0039] 1. Traditional encryption strategies mostly use static attributes such as doctor identity and department as encryption conditions, and have poor adaptability to dynamic scenarios. By dividing the access policy into static attributes and dynamic attributes, the present invention only needs to update the differential key ΔKey when the dynamic attributes change, without regenerating the full amount of keys, realizing the refinement of policy management granularity, greatly improving the adaptability to dynamic scenarios, being able to quickly respond to temporary authorization requirements, and meeting the medical data access requirements in complex dynamic environments such as hospitals.

[0040] 2. The present invention uses the differential key ΔKey to locally update the data index tree. Because this method only needs to update the index information of the part associated with dynamic attributes each time, rather than the entire index tree, compared with traditional full-scale updates, it greatly reduces the storage overhead. At the same time, the consensus node only needs to compare the new and old root hashes to know whether the index tree is correctly updated, without having to repeatedly verify a large amount of data, improving the timeliness and accuracy of data processing.

[0041] 3. The dynamic obfuscation based on spatio-temporal tags of the present invention, that is, extracting the real-time spatio-temporal tags of user nodes to generate the confusion factor MixTag, combining with the differential key ΔKey to generate the dynamic obfuscation key ObfuscationKey, and performing dynamic perturbation on the part of the data index tree associated with dynamic attributes, significantly improves the anti-correlation ability, prevents malicious nodes from inferring patients' sensitive information through multi-transaction correlation analysis, and enhances user privacy protection.

[0042] 4. In the traditional mode, the emergency authorization process during first aid is complex and inefficient, making it difficult to meet time-sensitive medical needs. In the present invention, attribute-based encryption (CP-ABE) and geofencing technology are combined and applied to the first aid scenario. When the GPS coordinates of the user node carried by the first aid personnel fall within the geofence, that is, the spatial dynamic attribute change is satisfied. At this time, the self-healing contract, based on the CP-ABE mechanism, quickly and automatically generates a differential key ΔKey, enabling the first aid personnel to immediately obtain access rights and acquire critical medical data, significantly improving the authorization efficiency and providing strong support for the efficient development of first aid work. Brief Description of the Drawings

[0043] The present invention will be further described below in conjunction with the drawings.

[0044] Figure 1 It is a schematic flowchart of the medical data sharing method based on dynamic attribute-based encryption according to an embodiment of the present invention. Detailed Embodiment

[0045] The present invention involves the following technical terms and constraints:

[0046] Blockchain technology: A distributed ledger technology based on the consortium chain architecture, constructed using the Hyperledger Fabric 2.2 framework, supporting the PBFT consensus algorithm, and realizing the decentralized storage, immutable recording, and cross-institutional consensus verification of medical data.

[0047] P2P network: A peer-to-peer communication network based on the gRPC protocol, connecting institutional nodes, consensus nodes, and user nodes to achieve distributed data transmission without a central server.

[0048] Node: An independent physical or logical entity that constitutes the blockchain network. Institutional nodes include the local servers of medical institutions, which are responsible for storing encrypted medical data and maintaining the data index tree; consensus nodes are used to verify the validity of transactions; user nodes include doctor terminal devices, which initiate data access requests after digital certificate authentication.

[0049] Access policy: Used to control the access rights of users to medical data.

[0050] Self-healing contract PAC (Policy Auto-healing Contract): An automated protocol based on blockchain technology, which pre-defines rules and logic in the form of code and automatically executes operations when the trigger conditions are met without manual intervention. It is the core component for realizing dynamic attribute-based encryption.

[0051] Merkle - Patricia Trie: A hierarchical hash tree structure used to store medical data indexes.

[0052] Hash Encoding: Use the SHA - 256 algorithm to perform a one - way hash operation on the data to generate a 256 - bit fixed - length hash value.

[0053] An embodiment of the present invention provides a medical data sharing method based on dynamic attribute - based encryption, including:

[0054] Step 1: Use blockchain technology to build a medical data sharing platform. The platform includes a number of institutional nodes and consensus nodes connected through a P2P network. Each institutional node contains a number of user nodes; the consensus nodes act as independent verification nodes and communicate bidirectionally with the institutional nodes. The institutional nodes at least include various medical institutions, and the user nodes at least include doctors in medical institutions.

[0055] Step 2: Each institutional node stores the encrypted medical data of its own institution in the local server and extracts features from the medical data to generate a corresponding data index tree.

[0056] When a user node queries medical data, it needs to obtain access permission according to the access policy and then access the medical data of the corresponding institutional node. The specific implementation steps are as follows:

[0057] S3 - 1: The access policy includes static attributes and dynamic attributes. The dynamic attributes include time constraints and space constraints. Each time the dynamic attributes change, a new access policy is generated. When a new access policy is generated, based on the self - healing contract of the blockchain, the corresponding differential key ΔKey is automatically generated according to the following formula: [ΔKey = H(old policy ⊕ new policy ‖ timestamp)], where H is the hash coefficient; ⊕ is the exclusive - or operation.

[0058] S3 - 2: The differential key ΔKey is used to locate the part associated with the dynamic attributes in the data index tree and update the index information of this part.

[0059] S3 - 3: Based on the updated data index tree, the consensus node opens the corresponding medical data to the user node.

[0060] Specifically, Step 1 involves preliminary preparation, node creation and configuration, and network connection and communication:

[0061] In terms of preliminary preparations, it includes hardware facility preparations: Prepare appropriate server hardware for each node. For institutional nodes (such as various medical institutions), servers with higher configurations can be selected. For example, servers with Intel Xeon processors, 32GB or more of memory, and 1TB or more of hard disk capacity can be used to ensure the ability to store a large amount of medical data. The consensus nodes also need to have servers with certain performance to ensure the efficient progress of verification work. User nodes (such as the devices used by doctors in medical institutions) can be ordinary office computers or mobile devices, but it is necessary to ensure stable network connections. Software environment setup: Install blockchain-related software and tools. Hyperledger Fabric can be selected as the blockchain framework. It is an open-source enterprise-level distributed ledger platform with good scalability and security. Install the corresponding Hyperledger Fabric components on each node, including Peer nodes (used to process transactions and maintain the ledger), Orderer nodes (used to sort transactions), etc. At the same time, install the software required for P2P network communication, such as the communication library supporting the gRPC protocol, to achieve efficient communication between nodes.

[0062] Regarding node creation and configuration, institutional node creation: Each medical institution, as an institutional node, needs to be registered in the blockchain network. First, generate the key pair of the institutional node, including the public key and the private key, for identity authentication and data encryption. Then, submit the information of the institutional node (such as institutional name, public key, etc.) to the consensus node for review and registration. After successful registration, the institutional node will be assigned a unique identifier for identification in the blockchain network. Institutional nodes are not limited to medical institutions and can also include pharmaceutical companies, government departments, etc. Consensus node creation: Similarly, the consensus node also needs to generate its own key pair and be registered in the blockchain network. The consensus nodes need to be configured with each other to establish a P2P network connection and determine the relevant parameters of the consensus algorithm (such as the PBFT algorithm). User node creation: Doctors in medical institutions, as user nodes, need to be registered under the affiliated institutional node. Doctors use their personal information (such as name, staff number, etc.) and the generated key pair for registration. The institutional node reviews the doctor's information. After passing the review, a unique user identifier is assigned to the doctor, and their information is synchronized to the blockchain network. Similarly, user nodes are not limited to doctors and can also include administrative staff in hospitals, etc.

[0063] In terms of network connection and communication, the P2P network is set up as follows: All nodes are connected using P2P network technology. Each node can act as both a client and a server, and data transmission and communication are carried out through the gRPC protocol. When a node starts up, it will automatically discover and connect to other nodes, forming a distributed network topology. Two-way communication mechanism: A two-way communication mechanism is established between the consensus nodes and the institutional nodes. The institutional nodes can send transaction requests (such as data upload, data query, etc.) to the consensus nodes. The consensus nodes verify and process the transaction requests and feedback the processing results to the institutional nodes. At the same time, the consensus nodes can also synchronize the latest status and information of the blockchain to the institutional nodes to ensure data consistency among all nodes.

[0064] Specifically, step two involves data storage and encryption. To ensure the security of medical data, a suitable encryption algorithm is selected to encrypt the data. The symmetric encryption algorithm (such as the AES algorithm) can be used to encrypt medical data because the symmetric encryption algorithm has high encryption efficiency. The asymmetric encryption algorithm (such as the RSA algorithm) can be used to encrypt the symmetric encryption key to ensure the security of the key. At the same time, the local servers of the institutional nodes need to be reasonably configured to ensure efficient storage and management of medical data. The distributed file system (such as the Ceph distributed file system) can be used to store data to improve data reliability and scalability. At the same time, a data backup and recovery mechanism is configured for the server to prevent data loss.

[0065] Specifically, the static attributes in step S3-1 mainly refer to fixed identity tags, such as: affiliated hospital = Hospital A, professional title = chief physician, department = endocrinology department, etc.; the dynamic attributes mainly refer to environmental conditions that change in real time, including time constraints and space constraints.

[0066] Specifically, when the dynamic attributes in step S3-2 change, for example, due to an emergency, a doctor transfers from a specialized ward to a rescue room. At this time, a new access policy will be generated, and the self-healing contract on the blockchain will automatically perform the following calculations:

[0067] Exclusive OR operation: Compare the binary values of the old policy and the new policy bit by bit. The same bits become 0, and different bits become 1. For example: old policy binary string ⊕ new policy binary string = difference bit string;

[0068] Add a timestamp: Concatenate the above difference bit string with the current time;

[0069] Hash calculation: Generate a 32-byte differential key ΔKey through the SHA-256 hash function. The formula is: ΔKey = H(old policy ⊕ new policy ‖ timestamp).

[0070] In one implementation, the expression of the access policy is:

[0071] <Access Policy> ::= <Static Attribute> "AND" <Dynamic Attribute>

[0072] <Dynamic Attribute> ::= "(" <Time Constraint> ")" | "(" <Spatial Constraint> ")"

[0073] <Time Constraint> ::= "time" "∈" "[" <Start Time> "," <End Time> "]"

[0074] <Spatial Constraint> ::= "GPS" "∈" "[" <Longitude> "," <Latitude> "," "radius" <Distance> "m]"。

[0075] For example: policy = "(Doctor AND Class III Grade A Hospital) AND (GPS ∈ [116.3°E, 39.9°N, radius 500m]) AND (time ∈ [2023-01-01T08:00, 2023-01-01T20:00])", and the constraint end time can avoid the overlong opening time of special permissions.

[0076] In one implementation, the data index tree is designed based on Merkle-Patricia Trie. The data index tree includes at least a root node, a parent node, and a leaf node, and the index information of each node is expressed by a hash value.

[0077] In one implementation, the differential key ΔKey is used to locate the part associated with the dynamic attribute in the data index tree and update the index information of this part. The specific steps include:

[0078] Perform hash encoding on the dynamic attribute using the differential key ΔKey to generate a path prefix; starting from the root node, traverse the Merkle-Patricia Trie data index tree according to the path prefix to find the leaf node associated with the dynamic attribute;

[0079] Modify the index information of the leaf node and recalculate its hash value;

[0080] Recursively update the hash values of the parent nodes along the path until the root node.

[0081] Specifically, features are extracted from medical data, and each feature value is hashed using SHA-256. The static_hash + dynamic_hash is used as the path from the root to the leaf. The parent node stores the intermediate hash in the path, and the leaf node stores the data hash + path, and recursively calculates the hashes of the parent node and the root node upward. Any change in the node content will cause the upper-layer hash value to change. The index tree locates data through hierarchical hashing. When the dynamic attributes change, only the node hashes on the path need to be modified, and they are updated layer by layer from bottom to top. Finally, the root hash is chained to ensure consistency, which can prevent tampering. The consensus node only needs to compare the new and old root hashes to know whether the index tree is correctly updated.

[0082] In one implementation, after generating the differential key ΔKey in step S3-1, the self-healing contract sends the differential key ΔKey to the side chain, and the side chain broadcasts the differential key ΔKey to all user nodes; the side chain is specifically used to process access policy change transactions.

[0083] In one implementation, in an emergency scenario, a geographical fence is automatically generated based on the spatial constraint conditions in the dynamic attributes. When the GPS coordinates of the user node fall within the geographical fence, the self-healing contract triggers the issuance of instant access permissions.

[0084] Specifically, the main blockchain (main chain) is responsible for storing the core transactions of medical data (such as data upload, consensus records), and the side chain is a dedicated high-speed channel specifically for processing high-frequency, low-complexity transactions such as access policy changes. When the dynamic attributes of a doctor change, the self-healing contract on the main chain calculates ΔKey, "packages" ΔKey into a side chain transaction, and quickly sends it to the side chain through a cross-chain communication protocol. After receiving ΔKey, the side chain broadcasts a notice to all user nodes (such as doctor terminals) through the P2P network. The broadcast method can be based on the gossip protocol, and each node forwards it to its neighbor nodes after receiving it.

[0085] Specifically, the geographical fence refers to a preset set of polygon coordinates or circular radius range in the self-healing contract based on the spatial constraint conditions in the dynamic attributes. In an emergency scenario, the user node carried by the emergency doctor reports the GPS coordinates in real time. If the coordinates meet the fence conditions, the self-healing contract automatically executes: find the latest ΔKey of the doctor; the corresponding institutional node sends a temporary access instruction; after receiving the instruction, the institutional node opens the medical data of the specified patient.

[0086] For example:

[0087] 1. Initial encryption: Patient A encrypts the medical record data and sets the basic policy: "Cardiologist AND Peking Union Medical College Hospital".

[0088] 2. Emergency Authorization: When a sudden myocardial infarction occurs, append the dynamic attribute "GPS location within a 500m radius of the emergency room of 301 Hospital" through the PAC contract, and set the time window to 1 hour.

[0089] 3. Differential Update: The contract automatically generates ΔKey and broadcasts it through the side chain. Doctor B can obtain access rights immediately after entering the geofence without re-encrypting all the data.

[0090] In one implementation, the self-healing contract integrates the zk-STARKs algorithm to verify whether the user node meets all the dynamic attributes in the new access policy. The specific expression is:

[0091] [Proof π = zkSTARK.Prove(ΔKey, Policy Change Record)]

[0092] In the formula, zkSTARK.Prove is a proof generation algorithm based on zero-knowledge succinct transparent arguments, which supports the joint proof of the legitimacy of ΔKey and the authenticity of the access policy change; DeltaKey is the differential key ΔKey; the policy change record includes the old access policy, the new access policy, and the timestamp.

[0093] Specifically, the zk-STARKs algorithm is integrated into the self-healing contract. The main function of this algorithm is to verify whether the user node meets all the dynamic attributes in the new access policy. When the dynamic attributes of the user node change, such as the time changes from one period to another, or the spatial location transfers from one area to another, a new access policy will be generated. At this time, the self-healing contract will generate the differential key ΔKey according to the previous rules and record the detailed information of the policy change. These information constitute the policy change record, which includes the old access policy, the new access policy, and the timestamp. Specifically, the zkSTARK.Prove proof generation algorithm based on zero-knowledge succinct transparent arguments will be used. This algorithm takes the differential key ΔKey and the policy change record as inputs and outputs a proof π. This proof π is a joint proof of the legitimacy of ΔKey and the authenticity of the access policy change. During the verification process, there is no need to disclose the specific policy content and data details to the consensus nodes. Just provide this proof π, and the consensus nodes can confirm whether the ΔKey is generated according to the correct rules and whether the change of the access policy is real and effective through the verification mechanism of the zk-STARKs algorithm.

[0094] In actual operation, when a user node makes a data access request, a proof π is first generated, and then the proof π is sent to the consensus node. The verifier uses the verification function of the zk-STARKs algorithm to verify the proof π. If the verification passes, it means that the user node satisfies all the dynamic attributes in the new access policy, and thus the corresponding access permission can be granted to allow the user node to access the corresponding medical data. In this way, the effective verification and management of user access permissions are achieved under the premise of protecting privacy.

[0095] In one implementation, step S3-2 further includes adding a dynamic obfuscation mechanism based on the differential key ΔKey:

[0096] Extract the real-time spatio-temporal tags of the user node, including the timestamp and GPS coordinates;

[0097] Process the extracted spatio-temporal tags through the hash function H to generate the obfuscation factor MixTag = H(T||G), where H is the hash function, T is the timestamp, G is the GPS coordinate, and || represents the string concatenation operation;

[0098] Specifically, MixTag = H(T||G)\text{MixTag} = H(T\|G)MixTag = H(T||G)

[0099] Combine the differential key ΔKey with the obfuscation factor MixTag to generate the dynamic obfuscation key ObfuscationKey =

[0100] H(ΔKey⊕MixTag), where H is the hash function, DeltaKey is the differential key ΔKey, MixTag is the obfuscation factor, and ⊕ represents the exclusive OR operation;

[0101] Specifically, ObfuscationKey = H(ΔKey⊕MixTag)\text{ObfuscationKey} = H(ΔKey

[0102] \oplus\text{MixTag})ObfuscationKey = H(ΔKey⊕MixTag)

[0103] Based on ObfuscationKey, perform dynamic perturbation on the part of the data index tree associated with the dynamic attributes, including node order adjustment, node hash perturbation, and redundant false node insertion; these perturbation methods are only examples, and other perturbation methods can also be used;

[0104] In this embodiment, the ObfuscationKey is used as the input of the hash function H', generating a 256-bit binary sequence K. K is evenly divided into three parts, corresponding to the control parameters of node order adjustment, node hash perturbation, and redundant false node insertion respectively. The first 80 bits are used to determine the permutation rule for node order adjustment, the middle 80 bits are used as the offset for node hash perturbation, and the last 96 bits determine the insertion position and quantity of redundant false nodes.

[0105] Node order adjustment: For the N nodes associated with dynamic attributes in the data index tree (assuming the node set is V = {v1, v2,..., vN}), an N-order permutation matrix P is constructed according to the first 80 bits of K. The node set V is rearranged according to the row-column mapping relationship of P. For example, if P(3,1) = 1, then the original third node v3 is exchanged with the first node v1, thus changing the logical order of the nodes in the index tree.

[0106] Node hash perturbation: For each node v to be perturbed, its original hash value H(v) is extracted. The middle 80 bits of K are converted into a decimal number M, and each byte of H(v) is subjected to an exclusive OR operation, that is, H'(v) = H(v) ⊕ M. For example, if the original hash value H(v) is [0x12, 0x34, 0x56] and M = 10, then the new hash value H'(v) = [0x12^10, 0x34^10, 0x56^10] = [0x1a, 0x3e, 0x50].

[0107] Redundant false node insertion: The last 96 bits of K are converted into two 48-bit integers X and Y. X is used to determine the quantity of false nodes to be inserted. For example, X mod 10 + 5 means inserting 5 to 14 false nodes; Y is used to generate a random offset for the insertion position. In the dynamic attribute branch of the index tree, starting from the root node, false nodes are inserted according to the path offset determined by Y. The structure of each false node is the same as that of a real node, but the stored attribute value is a preset invalid identifier.

[0108] On the premise of ensuring data integrity, through dynamic obfuscation processing, the anti-identification rate of user nodes when accessing the data index tree is reduced to within the anti-identification threshold range.

[0109] Specifically, the anti-identification rate is a quantitative index to measure the dynamic obfuscation effect of the data index tree, defined as the probability that an attacker can correctly identify the association relationship of dynamic attributes in the data index tree by observing information such as the data index tree structure and node access sequences. In this embodiment, the anti-identification threshold is set to 3%, that is, the anti-identification rate should be ≤ 3%.

[0110] In one implementation, the consensus node periodically verifies the anti-identification rate. When the anti-identification rate exceeds the anti-identification threshold, it automatically adjusts the obfuscation parameters to reduce the anti-identification rate within the anti-identification threshold range.

[0111] Specifically, the obfuscation parameters include perturbation frequency, false node ratio, and so on.

[0112] The embodiment of the present invention also provides a computer-readable storage medium, on which multiple instructions are stored, characterized in that the instructions are adapted to be loaded and executed by a processor to implement the steps of the medical data sharing method based on dynamic attribute-based encryption as described in any one of the above.

[0113] The advantages of the present invention are as follows:

[0114] 1. Most traditional encryption strategies use static attributes such as doctor identity and department as encryption conditions, and have poor adaptability to dynamic scenarios. By dividing the access policy into static attributes and dynamic attributes, the present invention only needs to update the differential key ΔKey when the dynamic attributes change, without regenerating the full amount of keys, realizing the refinement of the policy management granularity, greatly improving the adaptability to dynamic scenarios, being able to quickly respond to temporary authorization requirements, and meeting the medical data access requirements in complex dynamic environments such as hospitals.

[0115] 2. The present invention uses the differential key ΔKey to locally update the data index tree. Because this method only needs to update the index information associated with the dynamic attributes each time, rather than the entire index tree, compared with the traditional full amount update, it greatly reduces the storage overhead. At the same time, the consensus node only needs to compare the new and old root hashes to know whether the index tree is correctly updated, without having to repeatedly verify a large amount of data, improving the timeliness and accuracy of data processing.

[0116] 3. The dynamic obfuscation based on spatio-temporal tags of the present invention, that is, extracting the real-time spatio-temporal tags of user nodes to generate the obfuscation factor MixTag, combining with the differential key ΔKey to generate the dynamic obfuscation key ObfuscationKey, and dynamically perturbing the part associated with the dynamic attributes in the data index tree, significantly improves the anti-correlation ability, prevents malicious nodes from inferring patients' sensitive information through multi-transaction correlation analysis, and enhances user privacy protection.

[0117] 4. In the traditional mode, the emergency authorization process during first aid is complex and inefficient, making it difficult to meet time-sensitive medical needs. In the present invention, attribute-based encryption (CP-ABE) and geofencing technology are combined and applied to the first aid scenario. When the GPS coordinates of the user node carried by the first aid personnel fall within the geofence, that is, the spatial dynamic attribute change is satisfied. At this time, the self-healing contract, based on the CP-ABE mechanism, quickly and automatically generates the differential key ΔKey, enabling the first aid personnel to immediately obtain access rights and acquire critical medical data, significantly improving the authorization efficiency and providing strong support for the efficient development of first aid work.

[0118] It should be understood that the application of the present invention is not limited to the above examples. For those of ordinary skill in the art, improvements or transformations can be made according to the above description, and all such improvements and transformations should fall within the protection scope of the appended claims of the present invention.

Claims

1. A medical data sharing method based on dynamic attribute-based encryption, comprising the following steps: Step 1: Use blockchain technology to build a medical data sharing platform, which includes several institutional nodes and consensus nodes connected through a P2P network. Each institutional node contains several user nodes; the consensus nodes serve as independent verification nodes and communicate bidirectionally with the institutional nodes. The institutional nodes at least include various medical institutions, and the user nodes at least include doctors in medical institutions; Step 2: Each institutional node stores the encrypted medical data of its own institution in the local server and extracts features from the medical data to generate a corresponding data index tree; Step 3: When a user node queries medical data, it needs to obtain access permission according to the access policy and then access the medical data of the corresponding institutional node. The specific implementation steps are as follows: S3-1: The access policy includes static attributes and dynamic attributes. The dynamic attributes include time constraints and space constraints. Each time the dynamic attributes change, a new access policy will be generated; when a new access policy is generated, based on the self-healing contract of the blockchain, the corresponding differential key ΔKey is automatically generated according to the following formula: [ΔKey = H(old policy ⊕ new policy ‖ timestamp)], where H is the hash coefficient; ⊕ is the exclusive OR operation; S3-2: The differential key ΔKey is used to locate the part associated with the dynamic attributes in the data index tree and update the index information of this part; S3-3: Based on the updated data index tree, the consensus node opens the corresponding medical data to the user node.

2. The medical data sharing method based on dynamic attribute-based encryption according to claim 1, wherein: The expression of the access policy is: <Access Policy> ::= <Static Attribute> "AND" <Dynamic Attribute> <Dynamic Attribute> ::= "(" <Time Constraint> ")" | "(" <Space Constraint> ") " <Time Constraint> ::= "time" "∈" "[" <Start Time> "," <End Time> "]" <Space Constraint> ::= "GPS" "∈" "[" <Longitude> "," <Latitude> "," "radius" <Distance> "m]" 3. The medical data sharing method based on dynamic attribute-based encryption according to claim 1, wherein: The data index tree is designed based on Merkle-Patricia Trie. The data index tree at least includes a root node, a parent node, and a leaf node. The index information of each node is expressed by a hash value.

4. The medical data sharing method based on dynamic attribute-based encryption according to claim 3, wherein: The specific steps for the differential key ΔKey to locate the part associated with the dynamic attributes in the data index tree and update the index information of this part include: Use the differential key ΔKey to perform hash encoding on the dynamic attributes to generate a path prefix; starting from the root node, traverse the Merkle-Patricia Trie data index tree according to the path prefix to find the leaf node associated with the dynamic attributes; Modify the index information of the leaf node and recalculate its hash value; Recursively update the hash values of the parent nodes along the path until the root node.

5. The medical data sharing method based on dynamic attribute-based encryption according to claim 1, wherein: In step S3-1, after generating the differential key ΔKey, the self-healing contract sends the differential key ΔKey to the side chain, and the side chain broadcasts the differential key ΔKey to all user nodes; the side chain is specifically used to process access policy change transactions.

6. The medical data sharing method based on dynamic attribute-based encryption according to claim 5, characterized in that: In the first aid scenario, a geographical fence is automatically generated based on the spatial constraint conditions in the dynamic attributes. When the GPS coordinates of the user node fall within the geographical fence, the immediate access permission is issued by triggering the self-healing contract.

7. The medical data sharing method based on dynamic attribute-based encryption according to claim 1, characterized in that: The zk-STARKs algorithm is integrated into the self-healing contract to verify whether the user node meets all the dynamic attributes in the new access policy. The specific expression is: [Proof \(\pi = \text{zkSTARK.Prove}(\DeltaKey, \text{policy change record})\)] In the formula, zkSTARK.Prove is a proof generation algorithm based on zero-knowledge succinct transparent arguments, which supports the joint proof of the legality of \(\DeltaKey\) and the authenticity of the access policy change; DeltaKey is the differential key \(\DeltaKey\); the policy change record includes the old access policy, the new access policy, and the timestamp.

8. The medical data sharing method based on dynamic attribute-based encryption according to claim 1, characterized in that: Step S3-2 also includes adding a dynamic obfuscation mechanism based on the differential key \(\DeltaKey\): Extract the real-time spatio-temporal tags of the user node, including the timestamp and GPS coordinates; Process the extracted spatio-temporal tags through the hash function H to generate the obfuscation factor MixTag = H(T||G). In the formula, H is the hash function, T is the timestamp, G is the GPS coordinate, and || represents the string concatenation operation; Combine the differential key \(\DeltaKey\) with the obfuscation factor MixTag to generate the dynamic obfuscation key ObfuscationKey = H(\(\DeltaKey \oplus\) MixTag). In the formula, H is the hash function, \(\DeltaKey\) is the differential key \(\DeltaKey\), MixTag is the obfuscation factor, and \(\oplus\) represents the exclusive OR operation; Perform dynamic perturbation on the part of the data index tree associated with the dynamic attributes based on ObfuscationKey, including node order adjustment, node hash perturbation, and redundant false node insertion; On the premise of ensuring data integrity, through dynamic obfuscation processing, reduce the anti-identification rate of the user node when accessing the data index tree to within the anti-identification threshold range.

9. The medical data sharing method based on dynamic attribute-based encryption according to claim 8, characterized in that: The consensus node periodically verifies the anti-identification rate. When the anti-identification rate exceeds the anti-identification threshold, automatically adjust the obfuscation parameters to reduce the anti-identification rate to within the anti-identification threshold range.

10. A computer-readable storage medium storing multiple instructions thereon, characterized in that, The instruction is suitable for being loaded and executed by a processor to implement the steps of the medical data sharing method based on dynamic attribute-based encryption as described in any one of the above claims 1-9.

Citation Information

Patent Citations

  • Blockchain-based on-chain and off-chain medical data sharing methods, devices, and equipment

    CN113889208B

Cited By

  • Data security protection method, device and system based on anti-quantum cryptography algorithm

    CN121396456A

  • Medical data privacy protection and authorization sharing method based on block chain

    CN122133184A