Medical image privacy protection auxiliary detection method and system based on secret sharing
By converting medical images into DCT coefficient matrix and storing them in the IPFS system, using blockchain technology and smart contracts to achieve data segmentation and reconstruction, the problem of balancing data privacy and availability of traditional encryption methods is solved, data security and availability are improved, and telemedicine data is promoted securely.
Patent Information
- Application Number
- CN202510468234.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-07-29
AI Technical Summary
The prior art is difficult to balance between ensuring the privacy and availability of medical image data. Traditional encryption methods are burdened with high computing during processing and have a risk of data leakage. Anonymization methods may lead to reduced data availability.
Using a method based on secret sharing, medical images are converted into DCT coefficient matrix and stored in IPFS system, blockchain technology is used to store index files, and data segmentation and reconstruction are realized through smart contracts to ensure data security and availability.
It enhances data security, ensures the balance between data privacy and availability, improves query efficiency and traceability, and promotes the secure sharing of telemedicine data.
Smart Images

Figure CN120387188A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and more particularly to a medical image privacy protection assisted detection method and system based on secret sharing. Background Art
[0002] With the rapid development of information technology and the progress of medical imaging technology, medical images (such as X-rays, CT scans, MRI, etc.) play an increasingly important role in clinical diagnosis, treatment planning, and disease monitoring. Especially for the diagnosis of complex diseases such as cancer, high-quality medical images are indispensable. However, these images usually contain sensitive information of patients, including personal identification information and health status data. With the development of telemedicine services, ensuring the security and privacy of these sensitive data has become particularly important.
[0003] Traditional medical image privacy protection methods mainly include: Encryption technology: Using symmetric or asymmetric encryption algorithms to protect statically stored data. However, when processing encrypted data, it usually has to be decrypted first, which not only increases the computational burden but also may expose the data during the decryption process. Anonymization / de-identification: Removing or changing information that can identify the patient's identity. Nevertheless, complete anonymization may reduce the usability of the data and there is a risk of re-identification. Therefore, how to ensure the usability of data while guaranteeing the privacy of the data is an urgent problem for those skilled in the art to solve. Summary of the Invention
[0004] In view of this, the present invention provides a medical image privacy protection assisted detection method and system based on secret sharing, which overcomes the above-mentioned defects.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] A medical image privacy protection assisted detection method based on secret sharing, comprising:
[0007] An IPFS system and a blockchain are configured on the main server side, wherein a smart contract is deployed on the blockchain, and the smart contract includes business logic and a secret sharing algorithm; a verification mechanism and the same secret sharing algorithm as that in the smart contract are configured on the sub-server side;
[0008] The main server side converts the encrypted medical image sent by the data side into a DCT coefficient matrix; packs and stores the DCT coefficient matrix and related metadata into the IPFS system, constructs an index file based on the returned IPFS address, and stores the index file in the blockchain;
[0009] After receiving the query requests sent by n request terminals, the main server terminal verifies the legality of the query requests. After passing the verification, it calls the corresponding DCT coefficient matrix and related metadata according to the index file in the preset security area, and divides the DCT coefficient matrix and related metadata into n secret shares according to the secret sharing algorithm in the smart contract, and sends the n secret shares to the n request terminals respectively;
[0010] The n request terminals send the received secret shares to the sub-server terminal, verify the legality of the secret shares according to the verification mechanism, and reconstruct the encrypted medical image using the secret sharing algorithm of the sub-server terminal according to the verification result and store it in the sub-server terminal. The n request terminals view the reconstructed encrypted medical image in a shared manner.
[0011] In one embodiment, the steps for obtaining the encrypted medical image are as follows:
[0012] Perform homomorphic encryption on the privacy data in the medical image to generate the encrypted medical image.
[0013] In one embodiment, preprocessing is further included, and the specific steps are as follows:
[0014] Perform standardization processing on the encrypted medical image to obtain a standard image;
[0015] Parse the standard image and extract various data in the standard image as the metadata;
[0016] Classify the standard image according to the metadata to generate a preprocessed image.
[0017] In one embodiment, the steps for obtaining the DCT coefficient matrix are as follows:
[0018] Convert the encrypted medical image based on the discrete cosine transform algorithm to generate one or more initial DCT coefficient matrices;
[0019] Perform dynamic quantization on the initial DCT coefficient matrix to obtain the quantized initial DCT coefficient matrix;
[0020] Divide the quantized initial DCT coefficient matrix into multiple sub-matrices and mark the status of each sub-matrix;
[0021] Based on the recursive segmentation method, divide each sub-matrix to the single-pixel level;
[0022] Encode the non-zero elements and continuous zero values respectively, and construct a DCT coefficient matrix based on the encoded data and the corresponding position information.
[0023] In one embodiment, the matrix quantization step is as follows:
[0024] Divide the encrypted medical image into multiple regions, and dynamically select quantization parameters according to the characteristics of each region;
[0025] Quantize the initial DCT coefficient matrix based on the quantization parameters to obtain the quantized initial DCT coefficient matrix.
[0026] In one embodiment, the step of obtaining the index file is as follows:
[0027] Package and store the DCT coefficient matrix and related metadata in the IPFS system to obtain a unique IPFS hash address; the related metadata includes encrypted privacy data, image type, and timestamp;
[0028] Construct the index file according to the IPFS hash address and the related metadata.
[0029] In one embodiment, the verification step of the query request includes:
[0030] The requesting end homomorphically encrypts the privacy data to generate encrypted data, an encrypted timestamp, and a zero-knowledge proof, and sends them to the main server end;
[0031] After receiving the encrypted data, the encrypted timestamp, and the zero-knowledge proof, the main server end queries the index file stored in the blockchain based on the smart contract to verify the legality of the query request;
[0032] According to the verification result, determine whether to call the DCT coefficient matrix and related metadata.
[0033] In one embodiment, the step of sending the secret shares includes:
[0034] Take the DCT coefficient matrix and related metadata as inputs, use the secret sharing algorithm in the smart contract to generate n secret shares according to the number of requesting ends, and dynamically calculate and set the minimum number of reconstruction shares k according to the sensitivity level of the encrypted medical image, the number of requesting ends, and the level of the requesting ends, where k is less than or equal to n;
[0035] Send the n secret shares to the n requesting ends respectively.
[0036] In one embodiment, the step of reconstructing the encrypted medical image includes:
[0037] The sub-server end verifies the validity of the requesting end that receives the secret shares through a verification mechanism;
[0038] When the number of the verified requestors satisfies the minimum reconstruction share number k, select any k secret shares submitted by the requestors among the verified requestors, and output the restored DCT coefficient matrix and metadata based on the secret sharing algorithm of the sub-server;
[0039] Based on the restored DCT coefficient matrix and metadata, perform inverse quantization and inverse DCT transformation to obtain the reconstructed encrypted medical image, and n requestors view the reconstructed encrypted medical image in a shared manner.
[0040] A medical image privacy protection-assisted detection system based on secret sharing, the specific steps are as follows:
[0041] A data terminal, configured to perform homomorphic encryption on privacy data in a medical image to generate the encrypted medical image;
[0042] A main server, configured with an IPFS system and a blockchain, wherein a smart contract is deployed on the blockchain, and the smart contract includes business logic and a secret sharing algorithm; it is configured to convert the encrypted medical image sent by the data terminal into a DCT coefficient matrix; pack and store the DCT coefficient matrix and related metadata into the IPFS system, construct an index file based on the returned IPFS address, and store the index file in the blockchain; verify the legality of the query request sent by the requestor, and after the verification passes, call the corresponding DCT coefficient matrix and related metadata according to the index file in a preset security area, and according to the secret sharing algorithm in the smart contract, divide the DCT coefficient matrix and related metadata into n secret shares according to the number of data terminals, and send the n secret shares to n requestors respectively;
[0043] A requestor, configured to send the query request to the main server, receive the secret share returned by the main server, and send the secret share to the sub-server;
[0044] A sub-server, configured with a verification mechanism and the same secret sharing algorithm as that in the smart contract; it is configured to receive the secret shares sent by n requestors, verify the legality of the secret shares according to the verification mechanism, and reconstruct the encrypted medical image according to the verification result using the secret sharing algorithm of the sub-server and store it in the sub-server, and n requestors view the reconstructed encrypted medical image in a shared manner.
[0045] It can be seen from the above technical solutions that the present invention provides a medical image privacy protection-assisted detection method and system based on secret sharing. Compared with the prior art, it has the following beneficial effects:
[0046] Enhanced data security: By converting medical images into DCT coefficient matrices and storing them in IPFS, and using blockchain technology to store index files, effective encryption and distributed storage of the original images and their metadata are achieved; not only does it increase the difficulty for attackers to obtain complete information, but it also ensures that even if some nodes are compromised, sensitive information will not be leaked.
[0047] Guarantee the balance between data privacy and availability: Use the method of homomorphic encryption to encrypt factor data and use the secret sharing algorithm to split data. On the premise of ensuring data security, it allows legitimate users to process or analyze data without decrypting, thus maintaining the availability and functionality of the data, and at the same time avoiding the problem of data utility loss caused by complete anonymization.
[0048] Improve query efficiency and traceability: Use smart contracts to implement an automated verification process, which can quickly respond to and process query requests from different requesters, and at the same time ensure that all operations are executed according to preset rules, improving the system's response speed and service quality. In addition, since all transaction records are stored on the blockchain, any access behavior can be traced, enhancing the transparency of the system.
[0049] Promote the development of telemedicine: This method provides a reliable data sharing solution for telemedicine services, enabling doctors in different regions and institutions to safely exchange patient information and jointly participate in the diagnostic decision-making process, which helps to improve the level of medical services, especially for the early detection and precise treatment of complex diseases such as cancer. Description of the Drawings
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0051] Figure 1 It is a schematic flowchart of the method provided by the present invention;
[0052] Figure 2 It is a schematic structural diagram of the system provided by the present invention. Detailed Embodiments
[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0054] On the one hand, an embodiment of the present invention discloses a medical image privacy protection-assisted detection method based on secret sharing, as Figure 1 shown, and the specific steps are as follows:
[0055] An IPFS system and a blockchain are configured on the main server side. Among them, a smart contract is deployed on the blockchain, and the smart contract includes business logic and a secret sharing algorithm; a verification mechanism and the same secret sharing algorithm as in the smart contract are configured on the sub-server side;
[0056] The main server side converts the encrypted medical image sent by the data end into a DCT coefficient matrix; packs and stores the DCT coefficient matrix and related metadata in the IPFS system, constructs an index file based on the returned IPFS address, and stores the index file in the blockchain;
[0057] After the main server side receives the query requests sent by n request sides, it verifies the legality of the query requests. After passing the verification, it calls the corresponding DCT coefficient matrix and related metadata according to the index file in a preset safe area, and divides the DCT coefficient matrix and related metadata into n secret shares according to the secret sharing algorithm in the smart contract, and sends the n secret shares to the n request sides respectively;
[0058] The n request sides send the received secret shares to the sub-server side, verify the legality of the secret shares according to the verification mechanism, and reconstruct the encrypted medical image using the secret sharing algorithm of the sub-server side according to the verification result and store it on the sub-server side, and the n request sides view the reconstructed encrypted medical image in a shared manner.
[0059] In one embodiment, the step of obtaining the encrypted medical image is: performing homomorphic encryption on the privacy data in the medical image to generate an encrypted medical image.
[0060] Further, the personal identity information of the patient is encrypted using a homomorphic encryption algorithm. In this embodiment, elliptic curve homomorphic encryption is adopted. For the privacy data in the medical image (such as the patient's personal identity information (ID number, name, etc.), disease type (lung cancer, liver cancer, etc.), etc.), first convert it into plaintext represented in integer form, and then obtain the ciphertext using the elliptic curve homomorphic encryption method.
[0061] In one embodiment, it further includes preprocessing, and the specific steps are as follows:
[0062] Perform standardization processing on the encrypted medical image to obtain a standard image;
[0063] Parse the standard image and extract various data in the standard image as metadata;
[0064] Classify the standard image according to the metadata to generate a preprocessed image.
[0065] Furthermore, the standardization processing includes identifying and removing noise and artifacts in the image to improve the image quality; performing geometric transformations on the image, such as scaling, rotation, etc., to unify the size and format of the image; performing grayscale processing on the image, etc.
[0066] Furthermore, a neural network model suitable for image parsing, such as a convolutional neural network (CNN) or a recurrent neural network (RNN), can be used to parse the encrypted data.
[0067] Furthermore, an algorithm suitable for classification tasks, such as a support vector machine (SVM), a decision tree, or a random forest, can be used to classify the encrypted medical image.
[0068] In one embodiment, the steps for obtaining the DCT coefficient matrix are as follows:
[0069] Convert the encrypted medical image based on the discrete cosine transform algorithm to generate one or more initial DCT coefficient matrices;
[0070] Perform dynamic quantization on the initial DCT coefficient matrix to obtain the quantized initial DCT coefficient matrix;
[0071] Divide the quantized initial DCT coefficient matrix into multiple sub-matrices and mark the status of each sub-matrix;
[0072] Based on the recursive segmentation method, divide each sub-matrix to the single-pixel level;
[0073] Encode the non-zero elements and continuous zero values respectively, and construct the DCT coefficient matrix based on the encoded data and the corresponding position information.
[0074] Furthermore, perform block processing on the encrypted medical image, convert each image block into an 8x8 or 16x16 pixel matrix, and then apply the discrete cosine transform algorithm to each image block to perform the conversion, generating one or more DCT coefficient matrices corresponding to each image block; for example, for each 8x8 pixel image block, calculate its DCT coefficients to form a DCT coefficient matrix of the same size.
[0075] In one embodiment, the matrix quantization steps are as follows:
[0076] Divide the encrypted medical image into multiple regions, and dynamically select quantization parameters according to the characteristics of each region;
[0077] Quantize the initial DCT coefficient matrix based on the quantization parameters to obtain the quantized initial DCT coefficient matrix.
[0078] Furthermore, use a pre-trained deep learning model (such as a convolutional neural network CNN) to automatically identify different types of tissue structures or abnormal regions (such as lesion areas) in the image; and divide the image into multiple regions according to the recognition results. For regions marked as important (such as lesion areas); dynamically adjust the quantization parameters according to the region characteristics (such as frequency distribution, texture complexity) and the preset quality requirements (such as PSNR, SSIM values) to ensure the optimal overall compression ratio without affecting the diagnostic accuracy; Quantize the initial DCT coefficient matrix based on the dynamically adjusted quantization parameters.
[0079] Furthermore, the flag of the state of each sub-matrix is divided into two states: 0 or 1; the flag of the zero sub-matrix is set to 0, and the flag of the non-zero sub-matrix is set to 1.
[0080] The recursive segmentation method includes: determining whether the sub-matrix with a flag of 1 is composed of a single pixel; if not, cut it again, cut the sub-matrix with a flag of 1 into several sub-matrices at the next level, and continue to set the flag until reaching the single pixel level; sequentially store the values of the single pixels and the corresponding flags.
[0081] For non-zero sub-matrices, use entropy coding techniques (such as arithmetic coding or Huffman coding) to encode the non-zero elements and their position information; for multiple consecutive zero values, use run-length encoding (RLE) to simplify the representation and reduce redundancy; use the compressed data as the final DCT coefficient matrix.
[0082] In one embodiment, the steps for generating the index file are:
[0083] Pack and store the DCT coefficient matrix and related metadata in the IPFS system to obtain a unique IPFS hash address; the related metadata includes encrypted privacy data, image type, and timestamp;
[0084] Construct an index file based on the IPFS hash address and related metadata.
[0085] Furthermore, the DCT coefficient matrix and related metadata (including but not limited to privacy encrypted data, image type, image generation time, etc.) are packed and stored in the IPFS system to obtain a unique IPFS hash address;
[0086] Construct an index file that contains the homomorphically encrypted patient identity data, cancer types (such as lung cancer, breast cancer, etc.), timestamps (image generation time), image types (e.g., X-ray films, CT scans, etc.), and the IPFS addresses of the corresponding DCT coefficient matrices; and store the key information (at least including patient identity data, timestamp, and cancer type) in the index file into the blockchain; the index file format is designed as JSON or CSV format for easy parsing and querying.
[0087] In another embodiment, before packing and storing the DCT coefficient matrix and related metadata into the IPFS system, data identification generation is also required. The method for generating the identification is: use two different strong hash functions to generate a file identification, and its expression is:
[0088] H' = H1 ⊕ H2;
[0089] where, H1 uses the SHA-256 function; H2 uses the BLAKE2 function.
[0090] In one embodiment, the verification steps of the query request include:
[0091] The requesting end homomorphically encrypts the privacy data to generate encrypted data, encrypted timestamp, and zero-knowledge proof, and sends them to the main server end;
[0092] After receiving the encrypted data, encrypted timestamp, and zero-knowledge proof, the main server end queries the index file stored in the blockchain based on the smart contract to verify the legality of the query request;
[0093] According to the verification result, determine whether to call the DCT coefficient matrix and related metadata.
[0094] In one embodiment, the secret share sending steps include:
[0095] Take the DCT coefficient matrix and related metadata as inputs, use the secret sharing algorithm in the smart contract to generate n secret shares according to the number of requesting ends, and dynamically calculate and set the minimum reconstruction share number k according to the sensitivity level of the encrypted medical image, the number of requesting ends, and the level of the requesting ends, where k is less than or equal to n;
[0096] Send the n secret shares to the n requesting ends respectively.
[0097] In one embodiment, the encrypted medical image reconstruction steps include:
[0098] The sub-server end verifies the validity of the requesting end that receives the secret share through the verification mechanism;
[0099] When the number of verified requesters meets the minimum reconstruction share number k, select the secret shares submitted by any k requesters among the verified requesters, and output the DCT coefficient matrix and metadata based on the secret sharing algorithm of the sub-server;
[0100] Based on the DCT coefficient matrix and metadata, perform inverse quantization and inverse DCT transformation to obtain the reconstructed encrypted medical image, and n requesters view the reconstructed encrypted medical image in a shared manner.
[0101] Furthermore, the requester uses the homomorphic encryption algorithm to encrypt the patient's name and send the encrypted patient's name and request timestamp to the main server;
[0102] The main server receives the encrypted patient's name and request timestamp, and compares them with the hash value of the patient identity data stored in the blockchain. If the match is successful, obtain the cancer image data corresponding to the timestamp from the IPFS system;
[0103] The main server uses the smart contract to implement the secret sharing algorithm, divides the cancer image data into n shares, and distributes them to n requesters;
[0104] The n requesters use the verification mechanism provided by the sub-server to confirm the validity of the requesters and use the reconstruction step of the secret sharing algorithm to restore the complete cancer image data.
[0105] Even further, assume that n medical institutions or medical staff (i.e., requesters) need to access the cancer image data of a certain patient at a specific time. To protect the patient's privacy and ensure the secure sharing of data, use the elliptic curve homomorphic encryption (ECC) algorithm to encrypt the patient's name m, obtain the encrypted ciphertext C and the zero-knowledge proof π, send the encrypted ciphertext C and the zero-knowledge proof π to the main server side, verify the integrity of the encrypted ciphertext C and the zero-knowledge proof π at the main server side, verify the timeliness of the request according to the timestamp, after verification passes, obtain the public parameters for generating and verifying the zero-knowledge proof from the smart contract, parse and verify the zero-knowledge proof π, after verification passes, then construct a corresponding hash value based on the public key part in the encrypted ciphertext C, use this hash value to search for matching data on the blockchain, if there is matching data, return the query result, if not, return a failure message.
[0106] If the verification is passed, the master server calls the API of the IPFS system in a preset secure area according to the query result to retrieve the corresponding DCT matrix and its metadata. Specifically: First, create an isolated environment, for example, through containerized deployment and network isolation technologies, to ensure that all operations are carried out in a controlled environment; use the access policy in the smart contract to verify the access rights of the requesting party, and retrieve the required DCT matrix and its metadata from the IPFS API interface according to the query result in the established isolated environment.
[0107] The master server constructs a system of hyperplane equations according to the Blakley secret sharing algorithm, splits the DCT matrix and its metadata into n secret shares, and the initial minimum reconstruction share number k, and distributes these shares to n requesting parties through the smart contract, and dynamically adjusts the threshold value k of the secret sharing. Its adjustment rule is:
[0108] Dynamically calculate and set the minimum reconstruction share number k according to the sensitivity level of the encrypted medical image, the number of requesting parties, and the level of the requesting parties. That is, if the image is very sensitive, more shares are required to reconstruct the secret; if the security level of the requesting party is high, a lower k value may be allowed. Its expression is:
[0109]
[0110] In the formula, L is the sensitivity level of the encrypted medical image; n is the number of requesting parties; G is the average level of the requesting parties.
[0111] In another embodiment, if a requesting party joins or exits midway, the minimum reconstruction share number k is dynamically adjusted.
[0112] After each requesting party receives its own secret share, it submits the share to the sub-server side. The sub-server side will verify whether the submitted secret share comes from a legitimate requesting party and has not been tampered with; after successful verification, when the minimum reconstruction share number k is satisfied, the sub-server side selects any k secret shares submitted by the requesting parties among the verified requesting parties, uses the secret sharing algorithm to output the DCT coefficient matrix and metadata, and performs inverse quantization and inverse DCT based on them to obtain the reconstructed encrypted medical image. When the sub-server side receives a request from the requesting party to view the reconstructed encrypted medical image, it realizes the viewing of the reconstructed encrypted medical image in a shared manner.
[0113] In one embodiment, a query table is constructed in the blockchain based on the patient identity information in the privacy data for quick search.
[0114] On the other hand, this embodiment also discloses a medical image privacy protection assisted detection system based on secret sharing, as Figure 2 shown. The specific steps are as follows:
[0115] A data terminal, which is used to perform homomorphic encryption on private data in a medical image to generate an encrypted medical image;
[0116] A main server terminal, configured with an IPFS system and a blockchain. Among them, a smart contract is deployed on the blockchain, and the smart contract includes business logic and a secret sharing algorithm; it is used to convert the encrypted medical image sent by the received data terminal into a DCT coefficient matrix; pack and store the DCT coefficient matrix and related metadata into the IPFS system, construct an index file based on the returned IPFS address, and store the index file in the blockchain; verify the legality of the query request sent by the request terminal, and after passing the verification, call the corresponding DCT coefficient matrix and related metadata according to the index file in a preset security area, and according to the secret sharing algorithm in the smart contract, divide the DCT coefficient matrix and related metadata into n secret shares according to the number of data terminals, and send the n secret shares to n request terminals respectively;
[0117] A request terminal, which is used to send a query request to the main server terminal, receive the secret shares returned by the main server terminal, and send the secret shares to the sub-server terminal;
[0118] A sub-server terminal, configured with a verification mechanism and the same secret sharing algorithm as in the smart contract; it is used to receive the secret shares sent by n request terminals, verify the legality of the secret shares according to the verification mechanism, and reconstruct the encrypted medical image according to the verification result using the secret sharing algorithm of the sub-server terminal and store it in the sub-server terminal, and the n request terminals view the reconstructed encrypted medical image in a shared manner.
[0119] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0120] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A medical image privacy protection assisted detection method based on secret sharing, characterized in that, The specific steps are as follows: An IPFS system and a blockchain are configured on the main server side. Among them, a smart contract is deployed on the blockchain, and the smart contract includes business logic and a secret sharing algorithm; a verification mechanism and the same secret sharing algorithm as in the smart contract are configured on the sub-server side; The main server side converts the encrypted medical image sent by the data terminal into a DCT coefficient matrix; packs and stores the DCT coefficient matrix and related metadata into the IPFS system, constructs an index file based on the returned IPFS address, and stores the index file in the blockchain; After the main server side receives query requests sent by n request terminals, it verifies the legality of the query requests. After passing the verification, it calls the corresponding DCT coefficient matrix and related metadata according to the index file in a preset safe area, and divides the DCT coefficient matrix and related metadata into n secret shares according to the secret sharing algorithm in the smart contract, and sends the n secret shares to the n request terminals respectively; The n request terminals send the received secret shares to the sub-server side, verify the legality of the secret shares according to the verification mechanism, and reconstruct the encrypted medical image using the secret sharing algorithm of the sub-server side according to the verification result and store it on the sub-server side. The n request terminals view the reconstructed encrypted medical image in a shared manner.
2. The auxiliary detection method for medical image privacy protection based on secret sharing according to claim 1, wherein, The steps for obtaining the encrypted medical image are as follows: Perform homomorphic encryption on the privacy data in the medical image to generate the encrypted medical image.
3. A medical image privacy protection assisted detection method based on secret sharing according to claim 1, characterized in that, It also includes preprocessing, and the specific steps are as follows: Perform standardization processing on the encrypted medical image to obtain a standard image; Parse the standard image and extract various data in the standard image as the metadata; Classify the standard image according to the metadata to generate a preprocessed image.
4. A medical image privacy protection assisted detection method based on secret sharing according to claim 1, characterized in that, The steps for obtaining the DCT coefficient matrix are as follows: Convert the encrypted medical image based on the discrete cosine transform algorithm to generate one or more initial DCT coefficient matrices; Perform dynamic quantization on the initial DCT coefficient matrix to obtain the quantized initial DCT coefficient matrix; Divide the quantized initial DCT coefficient matrix into multiple sub-matrices and mark the status of each sub-matrix; Divide each sub-matrix to the single-pixel level based on a recursive partitioning method; Encode non-zero elements and continuous zero values respectively, and construct a DCT coefficient matrix based on the encoded data and the corresponding position information.
5. A medical image privacy protection assisted detection method based on secret sharing according to claim 4, characterized in that, The matrix quantization steps are as follows: Divide the encrypted medical image into multiple regions, and dynamically select quantization parameters according to the characteristics of each region; Quantize the initial DCT coefficient matrix based on the quantization parameters to obtain the quantized initial DCT coefficient matrix.
6. The auxiliary detection method for medical image privacy protection based on secret sharing according to claim 1, wherein, The steps for obtaining the index file are as follows: Pack and store the DCT coefficient matrix and related metadata into the IPFS system to obtain a unique IPFS hash address; the related metadata includes encrypted privacy data, image type, and timestamp; Construct the index file according to the IPFS hash address and the relevant metadata.
7. A medical image privacy protection assisted detection method based on secret sharing according to claim 1, characterized in that, The verification steps of the query request include: The requesting end homomorphically encrypts the private data to generate encrypted data, an encrypted timestamp, and a zero-knowledge proof, and sends them to the main server end; After receiving the encrypted data, the encrypted timestamp, and the zero-knowledge proof, the main server end queries the index file stored in the blockchain based on the smart contract to verify the legality of the query request; According to the verification result, determine whether to call the DCT coefficient matrix and the relevant metadata.
8. A medical image privacy protection assisted detection method based on secret sharing according to claim 1, characterized in that, The secret share sending step includes: Taking the DCT coefficient matrix and the relevant metadata as inputs, using the secret sharing algorithm in the smart contract to generate n secret shares according to the number of requesting ends, and dynamically calculating and setting the minimum reconstruction share number k according to the sensitivity level of the encrypted medical image, the number of requesting ends, and the level of the requesting ends, where k is less than or equal to n; Send the n secret shares to the n requesting ends respectively.
9. The auxiliary detection method for medical image privacy protection based on secret sharing according to claim 8, characterized in that The encrypted medical image reconstruction step includes: The sub-server end verifies the validity of the requesting end that receives the secret share through a verification mechanism; When the number of requesting ends that pass the verification meets the minimum reconstruction share number k, select any k secret shares submitted by the requesting ends that pass the verification, and output the restored DCT coefficient matrix and metadata based on the secret sharing algorithm of the sub-server end; Based on the restored DCT coefficient matrix and metadata, perform inverse quantization and inverse DCT transformation to obtain the reconstructed encrypted medical image, and the n requesting ends view the reconstructed encrypted medical image in a shared manner.
10. A medical image privacy protection assisted detection system based on secret sharing, characterized in that, The specific steps are as follows: The data end is used to homomorphically encrypt the private data in the medical image to generate the encrypted medical image; The main server end is configured with an IPFS system and a blockchain. Among them, a smart contract is deployed on the blockchain, and the smart contract includes business logic and a secret sharing algorithm; it is used to convert the encrypted medical image sent by the data end into a DCT coefficient matrix; pack and store the DCT coefficient matrix and the relevant metadata into the IPFS system, construct an index file according to the returned IPFS address, and store the index file in the blockchain; verify the legality of the query request sent by the requesting end, and after passing the verification, call the corresponding DCT coefficient matrix and the relevant metadata according to the index file in a preset security area, and divide the DCT coefficient matrix and the relevant metadata into n secret shares according to the number of data ends according to the secret sharing algorithm in the smart contract, and send the n secret shares to the n requesting ends respectively; The requesting end is used to send the query request to the main server end, receive the secret share returned by the main server end, and send the secret share to the sub-server end; The sub-server side is configured with an authentication mechanism and the same secret sharing algorithm as in the smart contract; it is used to receive the secret shares sent by n request sides, verify the legality of the secret shares according to the authentication mechanism, and reconstruct the encrypted medical image using the secret sharing algorithm of the sub-server side according to the verification result and store it on the sub-server side. The n request sides view the reconstructed encrypted medical image in a shared manner.