A medical data sharing method and system based on blockchain

Through blockchain technology and encryption algorithms, the problems of frequent authorization and low retrieval efficiency in medical data sharing are solved, and efficient, secure sharing of medical data and personalized diagnosis are achieved.

CN120412868BActive Publication Date: 2025-09-30HECHUANG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510491056.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-09-30
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

Existing technologies have problems with frequent authorization and low retrieval efficiency in medical data sharing, making it difficult to quickly and accurately obtain key medical information for multiple treatments, resulting in inefficient medical diagnosis.

Method used

A blockchain-based medical data sharing system is adopted. Through the sorting module, settlement module, self-check module and sharing module, hash value comparison, RSA combined with AES encryption mode and distributed storage system are used to realize data encryption processing and self-checking, extract key data to generate label values, and realize one-time authorization to obtain relevant information.

Benefits of technology

It improves the accuracy and security of medical data sharing, ensures patient privacy, improves medical diagnosis efficiency, and enables fast and accurate data acquisition and personalized treatment plans.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120412868B_ABST
    Figure CN120412868B_ABST
Patent Text Reader

Abstract

The present invention discloses a medical data sharing method and system based on blockchain, which relates to the field of data communication technology; it includes a sorting module, a settlement module, a self-checking module, an acquisition module and a sharing module: the sorting module collects patient diagnosis and treatment data from the hospital information system, obtains diagnosis and treatment records, calculates hash values ​​and uploads them to the blockchain; its technical points are: extracting key data in the diagnosis and treatment records and inputting them into an identification model to generate label values, using the label values ​​to show the importance of the diagnosis and treatment data, and being able to screen and judge the diagnosis and treatment data, thereby facilitating medical personnel to accurately grasp the patient's medical information, helping doctors to evaluate the patient's condition from multiple dimensions, and providing more personalized treatment plans; enabling doctors to make more accurate judgments on the condition in clinical practice, helping doctors to achieve earlier and more accurate diagnosis in clinical practice, and formulate treatment plans in a timely manner, and has good application prospects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data communication technology, and in particular to a blockchain-based medical data sharing method and system. Background Art

[0002] Electronic health records are an important part of building medical informatization. They contain personal sensitive data such as patients' basic information, medical records, and expense lists. By continuously increasing the utilization rate of EHR, the quality of medical services can be improved, doctors can be assisted in comprehensively judging the patient's condition, and the doctor-patient relationship can be effectively eased and medical costs can be reduced.

[0003] Sharing medical data is of great significance for the treatment and analysis of diseases. Currently, medical data is usually shared through internal hospital systems, various social software or shared documents. However, this method has great barriers, making it difficult to achieve true data sharing and solve data security issues.

[0004] At present, various medical institutions still use traditional database systems to store and maintain medical information, and the systems are independent of each other, which makes it impossible to effectively share data between hospitals and institutions. In addition, because patients' medical records are stored in hospitals and medical institutions and are kept and used by staff, as time goes by, patients can easily lose control of their medical records.

[0005] Currently, a Chinese patent with the existing patent document number "CN110797099B" discloses a blockchain-based medical data sharing method and system, which records the following: the first medical database uses a first private key to sign the number of the medical data to be shared and the identity of the target hospital and sends it to the on-chain smart contract. After a permission check, the target hospital identity is written into the corresponding sharing list; the second medical database uses a second private key to sign the number of the medical data to be shared and the identity of the target hospital and sends it to the on-chain smart contract. After a permission check, the hospital fingerprint and corresponding hash value of the second medical database are determined; the second medical database obtains the encrypted medical data object from the Interstellar File System cluster and sends a decryption key request; the first medical database determines the decryption key based on the sharing list; the second medical database decrypts the medical data object based on the second private key and the decryption key. The present invention improves the data security of medical data sharing and has good sharing performance.

[0006] However, during the implementation of the above technical solution, at least the following technical problems were found:

[0007] The above solutions all interact with medical data in a single, simple manner. However, in practice, a patient's single illness often involves multiple hospitals and treatments. This solution requires frequent authorization and retrieval, which is inefficient. Furthermore, in actual use, large amounts of data often need to be downloaded in batches, and then reviewed one by one, which is time-consuming and difficult to quickly and accurately grasp key medical information. This leads to inefficient medical diagnosis and fails to meet patient needs. Therefore, a blockchain-based medical data sharing method and system is provided. Summary of the Invention

[0008] (1) Technical problems solved

[0009] In response to the shortcomings of the existing technology, the present invention provides a blockchain-based medical data sharing method and system, which obtains the hash values ​​of the corresponding uploaded files of the hospital and the user, and performs comparison and self-inspection, which can determine whether the data has been changed, thereby effectively judging the accuracy of the uploaded data, laying a real foundation for subsequent review, has a high reference value, has good application prospects, and solves the problems raised in the background technology.

[0010] (2) Technical solution

[0011] To achieve the above objectives, the present invention is implemented through the following technical solutions:

[0012] A blockchain-based medical data sharing system includes a collation module, a settlement module, a self-check module, an acquisition module, and a sharing module:

[0013] Arrangement module: collects patient diagnosis and treatment data from the hospital information system, obtains diagnosis and treatment records, calculates the hash value hash1 and uploads it to the blockchain;

[0014] The settlement module obtains the secondary hash value hash2 of the patient's medical record, then encrypts it using RSA combined with AES encryption mode. The encrypted file is generated into a file identifier FileID using a distributed storage system. Key data in the medical record is extracted and input into the identification model to generate a tag value Tag. The tag value and the file identifier are integrated into a file identification value FileTag. All historical tag values ​​of the patient are summarized to form a tag table TagTable. The tag table, file identification value, hash2 and key ciphertext are submitted to the blockchain.

[0015] Self-check module: compares hash1 and hash2. If they are the same, the tag value, file identification value and encrypted file are submitted to the blockchain. If they are different, they are not uploaded and an alarm is issued that there is a data failure.

[0016] Acquisition module: obtains the verified medical institution's access permissions and access requirements, inputs the critical tag value generated in the identification model, compares the critical tag value with the tag value in the tag table in the blockchain, screens the tag value set that meets the requirements, and generates the corresponding file identification value set;

[0017] Sharing module: According to the file identifier in the file identification value recorded in the file identification value set, the corresponding encrypted file storage location is checked in the distributed storage system, the encrypted file is decrypted, and the data obtained is summarized to form a medical sharing set.

[0018] Furthermore, after collecting patient diagnosis and treatment data from the hospital information system, the collected data needs to be encrypted to obtain diagnosis and treatment records;

[0019] The encryption process steps are as follows:

[0020] Determine the category of sensitive privacy information, identify sensitive fields, and encrypt the sensitive fields using the Fernet encryption algorithm to obtain a first-level encrypted file;

[0021] Define the data access level of medical institutions, use the CP-ABE encryption algorithm to build a tree structure, and formulate the encryption strategy of the tree structure;

[0022] The primary encrypted file is encrypted twice using a tree-structured encryption strategy to obtain a secondary encrypted file, namely the medical record.

[0023] Furthermore, when calculating the hash value hash1 and the secondary hash value hash2, the SHA-256 algorithm is used to process the medical record data, and then the hexdigest method is used to obtain the hash value.

[0024] Furthermore, the steps for encrypting medical records using RSA combined with AES encryption mode are as follows:

[0025] Generate a pair of keys using the RSA algorithm, and encrypt the AES key using the RSA public key;

[0026] Use the AES algorithm to encrypt the secondary encrypted file using the encrypted AES key;

[0027] The encrypted secondary encrypted file is the encrypted file, and the key generated during encryption is the key ciphertext.

[0028] Furthermore, the steps for extracting key data from the medical records and inputting them into the identification model to generate tag values ​​are as follows:

[0029] Utilize data filtering algorithms to extract data from medical records and screen out key data, including patient sensitivity level, disease key data, and treatment key data. Disease key data includes, but is not limited to, disease type and disease level. Treatment key data includes, but is not limited to, the level of the treating hospital, treatment duration, treating physician level, and treatment price.

[0030] Weighted processing is performed on the patient's sensitivity level, key disease data, and key treatment data to obtain sensitivity assessment value, disease assessment value, and treatment assessment value;

[0031] The identification model uses a pre-trained convolutional neural network model, and the sensitivity assessment value, disease assessment value, and treatment assessment value are input into the identification model to obtain the label value.

[0032] Furthermore, the training method of the convolutional neural network model is as follows:

[0033] Collect shared medical records from a medical database after expert evaluation of label values, and use a stratified sampling method to divide the data into training, validation, and test sets.

[0034] Construct a convolutional neural network to perform regression tasks. Use the sensitivity assessment values, disease assessment values, and treatment assessment values ​​in the training set as the input of the convolutional neural network, use the expert assessment label values ​​as the output of the convolutional neural network, train the convolutional neural network, and obtain an initial convolutional neural network.

[0035] Use the validation set to validate the convolutional neural network and monitor changes in model performance;

[0036] The verified convolutional neural network is used to perform model testing, and the initial convolutional neural network with a preset test accuracy is output as the trained convolutional neural network model.

[0037] Furthermore, the steps to obtain the verified medical institution's access permissions and access requirements are as follows:

[0038] Obtain access requirements from medical institutions, including basic disease data and basic treatment data;

[0039] Obtain patient feedback reports and generate sensitive assessment values ​​based on the feedback;

[0040] The sensitive assessment value, disease basic data and treatment basic data are input into the pre-trained convolutional neural network model to obtain the critical label value.

[0041] Furthermore, the steps for generating a file identification value set are as follows:

[0042] Obtain the tag table stored on the blockchain and compare the critical tag value with the tag value on the tag table in the blockchain;

[0043] Use data filtering techniques to remove label values ​​belonging to other disease categories;

[0044] For the same disease, the conditional judgment algorithm is used to eliminate the label values ​​below the critical label value to obtain a label value set that meets the requirements;

[0045] Obtain the tag value in the tag value set, find the file identification value corresponding to the tag value, and summarize the file identification values ​​to form a file identification value set.

[0046] Furthermore, the corresponding encrypted file storage location is checked in the distributed storage system, and the steps to decrypt the encrypted file are as follows:

[0047] Convert the file identification value into a file identifier;

[0048] Query the encrypted file in the distributed storage system through the file identifier and transmit the encrypted file to the medical institution node;

[0049] Query the node identity of the medical institution and send the private key and the key of the corresponding encryption level;

[0050] Use the private key to decrypt the key ciphertext obtained on the blockchain to obtain the key, then use the key pair to decrypt the encrypted file to obtain the medical record data, and finally use the key corresponding to the encryption level to decrypt the medical record data to obtain the shared file;

[0051] The shared files obtained are arranged in descending order of label values ​​to form a medical sharing set.

[0052] Furthermore, a data processing method applied to a flow cytometer comprises the following steps:

[0053] Collect patient diagnosis and treatment data from the hospital information system, obtain diagnosis and treatment records, calculate the hash value hash1 and upload it to the blockchain;

[0054] Obtain the secondary hash value hash2 of the patient's medical record, then encrypt it using RSA combined with AES encryption mode. Use the distributed storage system to generate a file identifier FileID from the encrypted file. Extract key data from the medical record and input it into the identification model to generate a tag value Tag. Combine the tag value and the file identifier into a file identification value FileTag. Summarize all the patient's historical tag values ​​to form a tag table TagTable. Submit the tag table, file identification value, hash2, and key ciphertext to the blockchain.

[0055] Compare hash1 and hash2. If they are the same, the tag value, file identification value, and encrypted file are submitted to the blockchain. If they are different, they are not uploaded and an alarm is issued that there is a data failure.

[0056] Obtain the verified medical institution's access permissions and access requirements, input the critical tag value generated in the identification model, compare the critical tag value with the tag value in the tag table in the blockchain, screen the tag value set that meets the requirements, and generate the corresponding file identification value set;

[0057] According to the file identifier in the file identification value recorded in the file identification value set, the corresponding encrypted file storage location is checked in the distributed storage system, the encrypted file is decrypted, and the data obtained are summarized to form a medical sharing set.

[0058] (3) Beneficial effects

[0059] The present invention provides a blockchain-based medical data sharing method and system, which has the following beneficial effects:

[0060] The present invention provides a blockchain-based medical data sharing method and system, which obtains the hash values ​​of the corresponding uploaded files of the hospital and the user, and compares and performs self-inspection, which can determine whether the data has been changed, thereby effectively judging the accuracy of the uploaded data, laying a real foundation for subsequent review, has high reference value, and has good application prospects.

[0061] The present invention provides a blockchain-based medical data sharing method and system, which adopts RSA combined with AES encryption mode encryption, and combines with the characteristics of blockchain's tamper-proof, secure and reliable decentralized distributed storage, can effectively ensure the security of data, has good use effect, and has good application prospects.

[0062] The present invention provides a blockchain-based medical data sharing method and system, which fully considers the privacy of patients, collects the patient's medical data from the hospital information system and encrypts it using an encryption algorithm, and adopts a tree-structured encryption strategy, which can meet the needs of different medical institutions and can fully ensure that the patient's privacy data is not leaked. It has higher security, good use effect, and good application prospects.

[0063] The present invention provides a blockchain-based medical data sharing method and system, which extracts key data from medical records and inputs them into an identification model to generate label values. The label values ​​are used to show the importance of the medical data, and can realize the screening and judgment of the medical data, thereby facilitating medical personnel to accurately grasp the patient's medical information, helping doctors to evaluate the patient's condition from multiple dimensions, and provide more personalized treatment plans; enabling doctors to make more accurate condition judgments in clinical practice, helping doctors to achieve earlier and more accurate diagnosis in clinical practice, and formulate treatment plans in a timely manner.

[0064] The present invention provides a blockchain-based medical data sharing method and system, which introduces the user's patient sensitivity level data into the identification model, which can facilitate understanding of the patient's attitude towards sharing medical information. It also adopts the method of synchronously retrieving all diagnosis and treatment data by tag value, which can achieve one-time authorization and comprehensive acquisition of relevant information, thereby greatly improving efficiency and helping doctors to achieve earlier and more accurate diagnosis in clinical practice and formulate treatment plans in a timely manner.

[0065] The present invention provides a blockchain-based medical data sharing method and system, which integrates the tag value and the file identifier into a file identification value. This method can use a specific algorithm to reversely deduce the tag value and the file identifier from the file identification value, making it easy to find the file when it is lost. In addition, the file identifier cannot be directly deduced using a single file identification value. The method can include the patient's data on the blockchain, increase the number of blockchain interactions, have high overall security, good use effect, and have good application prospects. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 This is a flowchart of the overall process of a blockchain-based medical data sharing system of the present invention;

[0067] Figure 2 This is a flowchart of a blockchain-based medical data sharing method of the present invention. DETAILED DESCRIPTION

[0068] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0069] Market research:

[0070] Medical information refers to all data and knowledge related to medical activities, including patients' health status, diagnosis results, treatment plans, medication usage, and medical device information. This information plays a vital role in medical decision-making, patient management, and medical services. However, medical institutions still use traditional database systems to store and maintain medical information, which has the following shortcomings:

[0071] Information security cannot be guaranteed: Traditional database systems are stored, kept, and used by staff. As time goes by, patients can easily lose control of their medical records.

[0072] Information is difficult to protect: Traditional database systems import data directly from medical databases and then use a retrieval mechanism to directly retrieve data. During the retrieval, the entire medical data is fully displayed, making it difficult to hide irrelevant personal information and other disease data.

[0073] To improve the above shortcomings, existing technologies use blockchain to store medical data. When used, hospitals obtain corresponding information from the blockchain after user authorization. However, the existing solutions are only basic applications of blockchain and have the following defects:

[0074] Frequent authorizations: A single patient's illness often involves multiple hospitals and multiple treatments. This solution requires frequent authorizations and searches, which is inefficient.

[0075] Incomplete data acquisition: In actual use, it is often necessary to download large amounts of data in batches, and then check the data one by one. This takes a long time and makes it difficult to quickly and accurately grasp key medical information, resulting in low efficiency in medical diagnosis.

[0076] In response to the above problems, this application proposes a medical data sharing system based on blockchain, data hierarchical encryption, and label importance evaluation, which fully considers the privacy of patients, collects patient medical data from the hospital information system, and encrypts it using an encryption algorithm. It also adopts a tree-structured encryption strategy, which can meet the needs of different medical institutions and fully ensure that the patient's high-privacy data is not leaked. It extracts key data from the medical records and inputs them into the identification model to generate label values. The label values ​​are used to show the importance of the medical data, which can realize the screening and judgment of the medical data, making it convenient for medical personnel to accurately grasp the patient's medical information. By comparing the hash value for self-checking, it can determine whether the data has been changed, thereby effectively judging the accuracy of the uploaded data. It adopts RSA combined with AES encryption mode for encryption, and cooperates with The blockchain's tamper-proof, secure and reliable decentralized distributed storage characteristics can effectively ensure data security. Introducing users' patient sensitivity level data into the identification model can facilitate understanding of patients' attitudes towards sharing medical information. In addition, the use of label values ​​to synchronously retrieve all medical data can achieve one-time authorization. The label value and file identifier are integrated into a file identification value. This method can use a specific algorithm to reverse the file identification value to deduce the label value and file identifier, making it easy to find the file when it is lost. In addition, the file identifier cannot be directly calculated using a single file identification value. It can include the patient's data on the blockchain, increase the number of blockchain interactions, have high overall security, good use effect, and have good application prospects, providing an effective solution for medical data sharing.

[0077] R&D concept:

[0078] Example 1, please refer to Figure 1 This embodiment provides a blockchain-based medical data sharing system. The system is mainly for the comprehensive management of patient medical data. It mainly focuses on the five processes of data encryption, chain self-checking, data label importance classification, sharing screening and data aggregation. It mainly integrates database, blockchain, encryption technology, convolutional neural network and other technologies to build a data collection-data analysis-sharing integrated system. The specific structure of the system is as follows:

[0079] 1. Hospital data collation and processing

[0080] 1.1 Data Collection

[0081] This system is mainly composed of the following six entities: hospital (patient's historical treatment hospital), patient, trusted authorization center, distributed storage system, blockchain and medical institution (third party, used for the latest treatment of patient's disease or research institution).

[0082] The most basic thing when using this system is to collect accurate patient diagnosis and treatment data, that is, to obtain accurate data from the hospital and obtain diagnosis and treatment records.

[0083] After collecting patient diagnosis and treatment data from the hospital information system, the collected data needs to be encrypted to obtain diagnosis and treatment records;

[0084] The encryption process steps are as follows:

[0085] Determine the category of sensitive privacy information, identify sensitive fields, and encrypt the sensitive fields using the Fernet encryption algorithm to obtain a first-level encrypted file;

[0086] Sensitive fields are private data that have been verified by the user, mainly including information that can identify an individual or have a significant impact on the patient, such as name, age, height and weight.

[0087] The Fernet encryption algorithm uses AES-CBC (Advanced Encryption Standard - Cipher Block Chaining Mode) with a 256-bit key. During the encryption process, a random initialization vector (IV) is generated and used together with the key to encrypt the plaintext. The encrypted ciphertext consists of three parts: the Base64URL-encoded IV, the encrypted message, and a message authentication code (MAC). The MAC is based on the HMAC (Hash Message Authentication Code) algorithm and is calculated using the same key as the encrypted message. It is used to verify that the message has not been tampered with during transmission or storage.

[0088] The specific plan is as follows:

[0089] Generate and store keys;

[0090] The key uses the Fernet.generate_key() method provided by the cryptography library to generate a 256-bit encryption key.

[0091] Keys are protected with strict access permissions so that only authorized processes can read them, such as in a hardware security module (HSM) or a key management system (KMS) with strict access controls.

[0092] encryption;

[0093] Use the Fernet class to instantiate an object, pass in the encryption key, and then call the encrypt() method to encrypt sensitive fields.

[0094] In subsequent use, use the obtained key to instantiate the Fernet object and call the decrypt() method to decrypt the ciphertext.

[0095] Define the data access level of medical institutions, use the CP-ABE encryption algorithm to build a tree structure, and formulate the encryption strategy of the tree structure;

[0096] The primary encrypted file is encrypted twice using a tree-structured encryption strategy to obtain a secondary encrypted file, namely the medical record.

[0097] For example, hospitals within medical institutions are categorized into primary, secondary, and tertiary levels. This scale classification system reflects the size and strength of a hospital. Primary hospitals are typically community health service centers or township health centers, secondary hospitals are regional hospitals or municipal (county) level people's hospitals, and tertiary hospitals are large general hospitals or provincial hospitals. Different hospital levels represent different technical levels and overall strengths, with Class A hospitals being the highest and Class B hospitals being the next. Hospitals also have departmental levels, and there are specific levels of doctor (expert, chief physician, deputy chief physician, general physician) and nurse (head nurse, head nurse, and general nurse) grades within hospitals. To prevent patient information from being arbitrarily viewed, a hierarchical encryption approach is required.

[0098] For example, after obtaining the data, it is decrypted and first undergoes hospital level authentication (access policy 1), followed by department authentication (access policy 2), and then identity authentication (access policy 3). Different hospitals, different departments, and different doctors see different hidden contents of the decrypted data, thereby achieving effective protection of information.

[0099] 1.2 Hash Calculation

[0100] The medical records are encrypted. In order to verify whether the data has been tampered with later, corresponding editing processing is required at this time, that is, the hash value hash1 is calculated and uploaded to the blockchain. At this time, the hospital deletes the medical records to ensure data security.

[0101] When the hash value hash1 is uploaded to the blockchain, the trusted authorization center authorizes the hospital and reviews the hospital to ensure its identity is authentic and valid.

[0102] 2. Data on-chain

[0103] 2.1 Data Processing

[0104] This step is mainly based on the process of patients processing data, uploading it to the chain and storing encrypted files in a distributed storage system, and mainly relies on the settlement module.

[0105] Obtain the secondary hash value hash2 of the patient's medical record, and then encrypt it using RSA combined with AES encryption mode to generate an encrypted file and key-type ciphertext.

[0106] When calculating the hash value hash1 and the secondary hash value hash2, the SHA-256 algorithm is used to process the medical record data, and then the hexdigest method is used to obtain the hash value.

[0107] Calculating hash values ​​is an existing technical solution, and this patent does not improve it. Therefore, no further description will be given on this.

[0108] Obtain the secondary hash value hash2 of the patient's medical record, and then encrypt it using RSA combined with AES encryption mode;

[0109] The steps to encrypt medical records using RSA combined with AES encryption mode are as follows:

[0110] Generate a pair of keys using the RSA algorithm, and encrypt the AES key using the RSA public key;

[0111] The steps for RSA key generation are as follows: A pair of keys, namely a public key and a private key, are generated using the RSA algorithm, which is completed by the key management module of the encryption system;

[0112] First, the generation process is based on large prime number operations in number theory. Two large prime numbers p and q are selected and n = p × q is calculated.

[0113] Then calculate the Euler function φ(n) = (p-1) × (q-1), and then select an integer e from 1 to φ(n) that is coprime with φ(n) as the exponent part of the public key. Then use the extended Euclidean algorithm to calculate the modular inverse d of e with respect to φ(n). d is used as the exponent part of the private key, and finally the public key (e, n) and private key (d, n) are obtained.

[0114] The AES key generation process is as follows: The AES key is generated by the cryptographic system using a secure random number generator. The AES algorithm supports key lengths of 128, 192, and 256 bits. The appropriate key length is typically selected based on security requirements. For example, when a 128-bit key is selected, the random number generator generates 16 bytes (128 bits) of random data as the AES key.

[0115] Use the AES algorithm to encrypt the secondary encrypted file using the encrypted AES key;

[0116] The process of using the AES algorithm to encrypt the AES key is as follows: encrypt the generated AES key with the previously generated RSA public key. When encrypting, the AES key is regarded as a large integer m, and the RSA encryption formula c = m is used. e (modn), where c is the encrypted ciphertext, and e and n are the parameters of the RSA public key. This calculation yields the encrypted AES key ciphertext, which can only be decrypted with the corresponding RSA private key to restore the original AES key.

[0117] When encrypting the secondary encrypted file using the encrypted AES key, select CBC mode. The secondary encrypted file is divided into blocks according to the AES block size (e.g., 128 bits). An XOR operation is performed on each block, and the XOR result is encrypted using the AES key. Subsequent data blocks are XORed with the encrypted result of the previous block and then encrypted again using the AES key. This block-by-block encryption process results in the final secondary encrypted file.

[0118] The encrypted secondary encrypted file is the encrypted file, and the key generated during encryption is the key ciphertext.

[0119] When the encrypted file is generated by the distributed storage system, the encrypted file is uploaded to the distributed storage system. The distributed storage system generates the file identifier FileID according to the content of the encrypted file and sends the file identifier FileID to the patient.

[0120] 2.2 Label judgment

[0121] Label judgment is mainly to judge the disease and its corresponding importance.

[0122] Extract key data from medical records and input them into the identification model to generate tag values;

[0123] The steps to extract key data from medical records and input it into the identification model to generate tag values ​​are as follows:

[0124] Utilize data filtering algorithms to extract data from medical records and screen out key data, including patient sensitivity level, disease key data, and treatment key data. Disease key data includes, but is not limited to, disease type and disease level. Treatment key data includes, but is not limited to, the level of the treating hospital, treatment duration, treating physician level, and treatment price.

[0125] The patient's sensitivity level, disease key data and treatment key data are weighted to obtain the sensitivity assessment value MGpg, disease assessment value JBpg and treatment assessment value ZLpg;

[0126] The formula for calculating the sensitivity assessment value is as follows:

[0127]

[0128] Where Lx is the number of sensitive words selected by the patient, Lz is the total number of sensitive words provided during the test, djx is the number of levels set by the patient in the tree structure, for example, (hospital level, department level, doctor level), and djz is the maximum number of levels set in the preset tree structure. The average number of levels set for patients in the tree structure. For example, the hospital level is divided into 4 levels: A, B, C, and no level. For example, if the hospital level is set to 4 levels, the department level is set to 3 levels, and the doctor level is set to 2 levels, then is 3, if If there is a decimal, it will be rounded up. Sz is the number of the highest level in the preset tree structure. This method can reflect the user's sensitivity. The larger the MGpg, the less sensitive the patient is, and the smaller the MGpg, the more sensitive the patient is.

[0129] The formula for calculating the disease assessment value is as follows:

[0130] JBpg=jbxs×jbdj

[0131] Where jbxs is the preset basic coefficient of the patient's disease type, and jbdj is the disease level assessed by the hospital, such as asymptomatic, mild, moderate, and severe, corresponding to levels 1-4.

[0132] The formula for calculating the treatment assessment value is as follows:

[0133]

[0134] Wherein, yydj is the grade of the treating hospital, such as Grade A, Grade B, Grade C, no grade, etc. mentioned above; ysdj is the grade of the treating doctor, such as the expert, chief physician, etc. mentioned above; Sy is the treatment duration; Sp is the preset standard treatment duration based on the disease assessment value and the grade of the treating hospital; Gy is the treatment price; Gy is the preset standard treatment price based on the disease assessment value and the grade of the treating hospital.

[0135] Because medical data mainly provides research value for subsequent treatment or other medical institutions, under normal circumstances, plans with too low or too high treatment duration, too low or too high prices all need to be treated separately. In addition, there are certain differences in plans formulated by hospitals and doctors of different levels. Under normal circumstances, the higher the level, the more it needs to be processed further to lay the foundation for the subsequent calculation of label values.

[0136] The identification model uses a pre-trained convolutional neural network model, and the sensitivity assessment value, disease assessment value, and treatment assessment value are input into the identification model to obtain the label value.

[0137] The training method of the convolutional neural network model is as follows:

[0138] Collect shared medical records from a medical database after expert evaluation of label values, and use a stratified sampling method to divide the data into training, validation, and test sets.

[0139] Construct a convolutional neural network to perform regression tasks. Use the sensitivity assessment values, disease assessment values, and treatment assessment values ​​in the training set as the input of the convolutional neural network, use the expert assessment label values ​​as the output of the convolutional neural network, train the convolutional neural network, and obtain an initial convolutional neural network.

[0140] Use the validation set to validate the convolutional neural network and monitor changes in model performance;

[0141] During validation, the mean absolute error or root mean square error indicator is used to evaluate the model.

[0142] The verified convolutional neural network is used to perform model testing, and the initial convolutional neural network with a preset test accuracy is output as the trained convolutional neural network model.

[0143] The model structure of the convolutional neural network model is as follows:

[0144] Input layer: The input is sensitivity evaluation value, disease evaluation value and treatment evaluation value.

[0145] Convolutional layers: Multiple convolutional layers with different kernel sizes are combined. For example, 3x3 and 5x5 kernels can be used. The 3x3 kernel can capture local, detailed features, while the 5x5 kernel can capture broader contextual information. By stacking multiple convolutional layers, such as using two 3x3 convolutional layers followed by a 5x5 convolutional layer, deeper features in the data can be gradually extracted.

[0146] A batch normalization layer is added after each convolutional layer to accelerate model convergence and, to a certain extent, prevent overfitting. Furthermore, the batch normalization layer normalizes the output data of the convolutional layer, making the data distribution more stable and facilitating subsequent activation function processing. The activation function chosen is the ReLU function, expressed as f(x) = max(0, x). The ReLU function effectively addresses the vanishing gradient problem and is computationally simple, accelerating model training.

[0147] Pooling layers: Pooling layers are inserted intermittently after convolutional layers. For example, a maximum pooling operation is used after every two convolutional layers, with the pooling kernel size set to 2x2. Maximum pooling can reduce the dimensionality of the data while retaining the main features, reducing the amount of computation, and compressing and abstracting the features to a certain extent, thereby enhancing the robustness of the model.

[0148] Fully connected layer: After a series of convolution and pooling operations, the data is flattened and then connected to the fully connected layer. The fully connected layer can comprehensively process and integrate the extracted features and ultimately output the prediction results.

[0149] The Adam optimizer is selected for the model, and the mean square error loss function is selected for error calculation during verification.

[0150] The formula of the mean square error loss function is as follows:

[0151]

[0152] Where MSE is mean square error, N is the number of samples, and yb i The i-th true label value, yi is the i-th model predicted label value.

[0153] You can also calculate the mean absolute error. The specific calculation formula is as follows:

[0154]

[0155] Where MAE is the mean absolute error, N is the number of samples, and yb i The i-th true label value, yi is the i-th model predicted label value.

[0156] You can also calculate the root mean square error. The specific calculation formula is as follows:

[0157]

[0158] Where RMSE is the root mean square error, N is the number of samples, and yb i The i-th true label value, yi is the i-th model predicted label value.

[0159] The mean absolute percentage error is used in the test, and the specific formula is as follows:

[0160]

[0161] Where MAPE is the mean absolute percentage error, N is the number of samples, and yb i The i-th true label value, yi is the i-th model predicted label value.

[0162] When in use, when the data is more complex and there is a lot of data, the model integration method is used to train multiple convolutional neural network models with different initialization parameters or to fuse the convolutional neural network model with the recurrent neural network (RNN) or support vector machine (SVM).

[0163] The label value consists of 8 digits, of which the first 3 digits are the disease number, the 4th digit is the disease level, and the following 4 digits are the display value based on the weighted evaluation of the sensitivity assessment value, disease assessment value, and treatment assessment value. For example, the label value is 12345678, where 123 is the disease number, 4 is the disease level, and 5678 is the weighted evaluation display value.

[0164] The tag value and the file identifier are combined into a file identification value FileTag.

[0165] The tag value and file identifier are directly concatenated in a certain order to form the file identification value. For example, the file identifier is placed first and the tag value is placed last, i.e. FID-00112345678.

[0166] To clearly distinguish between the file identifier and the tag value, a specific delimiter, such as -, can be used when concatenating them. The format of the combined file identifier value is file identifier-tag value, for example, FID-001-12345678. When parsing the file identifier value, the delimiter can be used to quickly and accurately separate the file identifier and tag value.

[0167] This method is relatively simple, but the security of the identifier is not high.

[0168] Alternatively, a regular algorithm may be used to mix the tag value and the file identifier, such as an evenly spaced distribution.

[0169] 2.3 Data on-chain

[0170] Aggregating all the patient's historical tag values ​​to form a tag table TagTable can facilitate subsequent query of all the patient's diagnosis and treatment data, facilitate sorting and query, and submit the tag table, file identification value, hash2 and key ciphertext to the blockchain.

[0171] 3. Data self-check

[0172] In order to ensure the accuracy of the data, it is necessary to compare the uploaded data. The most direct way is to directly compare the hash value. This step is based on the self-check module.

[0173] Self-check module: compares hash1 and hash2. If they are the same, the tag value, file identification value and encrypted file are submitted to the blockchain. If they are different, they are not uploaded and an alarm is issued that there is a data failure.

[0174] For example, if a patient tampers with medical records, the generated hash2 will be different from hash1, and an alarm will be issued. The patient will not be able to submit the label value, file identification value, and encrypted file to the blockchain, proving that the data is unreliable and untrue.

[0175] 4. Shared access

[0176] 4.1、Authorization;

[0177] The medical institution sends an access request to the patient node, which includes access requirements;

[0178] The patient agrees to the hospital node's access request and sets relevant review permissions, that is, modifies the access requirements.

[0179] The steps to obtain verified medical institution access permissions and access requirements are as follows:

[0180] Obtain access requirements from medical institutions, including basic disease data and basic treatment data;

[0181] generating a sensitive evaluation value based on the feedback;

[0182] Obtain patient feedback reports and modify the degree of access requirements. The greater the degree of modification, the more sensitive it is. The higher the sensitivity assessment value in this step, the higher the critical label value calculated by the convolutional neural network model.

[0183] The sensitive assessment value, disease basic data and treatment basic data are input into the pre-trained convolutional neural network model to obtain the critical label value.

[0184] The higher the critical tag value, the fewer medical records can be displayed.

[0185] 4.2. Initial data screening;

[0186] Compare the critical tag value with the tag value on the tag table in the blockchain. During the comparison, the user's permissions are used. For example, hospitals will only open medical records with higher than the critical tag value for the same disease, and will not disclose other disease data. For some medical institutions, all medical records with higher than the critical tag value will be open. The tag value set that meets the requirements will be screened and the corresponding file identification value set will be generated.

[0187] The steps to generate a file identification value set are as follows:

[0188] Obtain the tag table stored on the blockchain and compare the critical tag value with the tag value on the tag table in the blockchain;

[0189] Use data filtering technology to remove label values ​​belonging to other disease categories (depending on the permission setting, this step can be removed if the permission is high);

[0190] For the same disease, the conditional judgment algorithm is used to eliminate the label values ​​below the critical label value to obtain a label value set that meets the requirements;

[0191] Obtain the tag value in the tag value set, find the file identification value corresponding to the tag value, and summarize the file identification values ​​to form a file identification value set.

[0192] The tag value corresponds to the file identification value one by one. After filtering out the tag value set, the file identification value is found on the blockchain through the tag value, and then the file identification values ​​are aggregated to construct a file identification value set.

[0193] 5. Shared access

[0194] 5.1 Data Retrieval

[0195] According to the file identifier in the file identification value centrally recorded in the file identification value, the corresponding encrypted file storage location is checked in the distributed storage system. This step is mainly based on the shared module.

[0196] The steps to check the storage location of the corresponding encrypted file in the distributed storage system are as follows:

[0197] Convert the file identification value into a file identifier;

[0198] Query the encrypted file in the distributed storage system through the file identifier and transmit the encrypted file to the medical institution node;

[0199] The file identification value is composed of the tag value and the file identifier, so a fixed algorithm can be used to parse and obtain the file identifier, and then the file identifier can be used to access the distributed storage system to retrieve the encrypted file.

[0200] 5.2 Decrypting Files

[0201] Decrypt the encrypted files and aggregate the obtained data to form a medical sharing set.

[0202] The steps to decrypt an encrypted file are as follows:

[0203] Query the node identity of the medical institution and send the private key and the key of the corresponding encryption level;

[0204] Use the private key to decrypt the key ciphertext obtained on the blockchain to obtain the key, then use the key pair to decrypt the encrypted file to obtain the medical record data, and finally use the key corresponding to the encryption level to decrypt the medical record data to obtain the shared file;

[0205] The shared files obtained are arranged in descending order of label values ​​to form a medical sharing set.

[0206] The weight coefficient is determined using the coefficient of variation method, which is a method of assigning weights to each indicator based on the degree of variation between the current value of each evaluation indicator and the target value. If the numerical difference of an indicator is large, it can clearly distinguish the evaluated objects, indicating that the indicator has rich discrimination information, and thus the indicator should be given a larger weight. On the contrary, if the numerical difference of each evaluated object on a certain indicator is small, then the ability of this indicator to distinguish the evaluation objects is weak, and thus the indicator should be given a smaller weight. This method directly uses the information contained in each indicator to obtain the weight of the indicator through calculation, and therefore is objective.

[0207] Example 2

[0208] A blockchain-based medical data sharing method, such as Figure 2 As shown, the following steps are included:

[0209] Collect patient diagnosis and treatment data from the hospital information system, obtain diagnosis and treatment records, calculate the hash value hash1 and upload it to the blockchain;

[0210] Obtain the secondary hash value hash2 of the patient's medical record, then encrypt it using RSA combined with AES encryption mode. Use the distributed storage system to generate a file identifier FileID from the encrypted file. Extract key data from the medical record and input it into the identification model to generate a tag value Tag. Combine the tag value and the file identifier into a file identification value FileTag. Summarize all the patient's historical tag values ​​to form a tag table TagTable. Submit the tag table, file identification value, hash2, and key ciphertext to the blockchain.

[0211] Compare hash1 and hash2. If they are the same, the tag value, file identification value, and encrypted file are submitted to the blockchain. If they are different, they are not uploaded and an alarm is issued that there is a data failure.

[0212] Obtain the verified medical institution's access permissions and access requirements, input the critical tag value generated in the identification model, compare the critical tag value with the tag value in the tag table in the blockchain, screen the tag value set that meets the requirements, and generate the corresponding file identification value set;

[0213] According to the file identifier in the file identification value recorded in the file identification value set, the corresponding encrypted file storage location is checked in the distributed storage system, the encrypted file is decrypted, and the data obtained by aggregation constitutes a medical sharing set.

[0214] In the application, the several formulas involved are all calculated by taking their numerical values ​​after removing the dimensions, and the formulas are established by collecting a large amount of data and performing software simulation to obtain a formula for the most recent real situation. Some coefficients or weights in the formulas are set by technical personnel in this field according to actual conditions, so they will not be elaborated here.

[0215] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. Those skilled in the art will appreciate that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution.

[0216] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, and may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment as needed.

[0217] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.

Claims

1. A blockchain-based medical data sharing system, characterized by: include: Arrangement module: collects patient diagnosis and treatment data from the hospital information system, obtains diagnosis and treatment records, calculates the hash value hash1 and uploads it to the blockchain; The settlement module obtains the secondary hash value hash2 of the patient's medical record, then encrypts it using RSA combined with AES encryption mode. A distributed storage system is used to generate a file identifier from the encrypted file. Key data in the medical record is extracted and input into the identification model to generate a label value. The label value and the file identifier are integrated into a file identification value. All historical label values ​​of the patient are summarized to form a label table. The label table, file identification value, hash2, and key ciphertext are submitted to the blockchain. Self-check module: compares hash1 and hash2. If they are the same, the tag value, file identification value and encrypted file are submitted to the blockchain. If they are different, they are not uploaded and an alarm is issued that there is a data failure. Acquisition module: obtains the verified medical institution's access permissions and access requirements, inputs the critical tag value generated in the identification model, compares the critical tag value with the tag value in the tag table in the blockchain, screens the tag value set that meets the requirements, and generates the corresponding file identification value set; Sharing module: According to the file identifier in the file identification value recorded in the file identification value set, the corresponding encrypted file storage location is checked in the distributed storage system, the encrypted file is decrypted, and the data obtained is summarized to form a medical sharing set.

2. The blockchain-based medical data sharing system according to claim 1, characterized in that: After collecting patient diagnosis and treatment data from the hospital information system, the collected data needs to be encrypted to obtain diagnosis and treatment records; The encryption process steps are as follows: Determine the category of sensitive privacy information, identify sensitive fields, and encrypt the sensitive fields using the Fernet encryption algorithm to obtain a first-level encrypted file; Define the data access level of medical institutions, use the CP-ABE encryption algorithm to build a tree structure, and formulate the encryption strategy of the tree structure; The primary encrypted file is encrypted twice using a tree-structured encryption strategy to obtain a secondary encrypted file, namely the medical record.

3. The blockchain-based medical data sharing system according to claim 2, characterized in that: When calculating the hash value hash1 and the secondary hash value hash2, the SHA-256 algorithm is used to process the medical record data, and then the hexdigest method is used to obtain the hash value.

4. The blockchain-based medical data sharing system according to claim 3, characterized in that: The steps to encrypt medical records using RSA combined with AES encryption mode are as follows: Generate a pair of keys using the RSA algorithm, and encrypt the AES key using the RSA public key; Use the AES algorithm to encrypt the secondary encrypted file using the encrypted AES key; The encrypted secondary encrypted file is the encrypted file, and the key generated during encryption is the key ciphertext.

5. The blockchain-based medical data sharing system according to claim 4, characterized in that: The steps to extract key data from medical records and input it into the identification model to generate label values ​​are as follows: Utilize data filtering algorithms to extract data from medical records and screen out key data, including patient sensitivity level, disease key data, and treatment key data. Disease key data includes, but is not limited to, disease type and disease level. Treatment key data includes, but is not limited to, the level of the treating hospital, treatment duration, treating physician level, and treatment price. Weighted processing is performed on the patient's sensitivity level, key disease data, and key treatment data to obtain sensitivity assessment value, disease assessment value, and treatment assessment value; The identification model uses a pre-trained convolutional neural network model, and the sensitivity assessment value, disease assessment value, and treatment assessment value are input into the identification model to obtain the label value.

6. The blockchain-based medical data sharing system according to claim 5, characterized in that: The training method of the convolutional neural network model is as follows: Collect shared medical records from a medical database after expert evaluation of label values, and use a stratified sampling method to divide the data into training, validation, and test sets. Construct a convolutional neural network to perform regression tasks. Use the sensitivity assessment values, disease assessment values, and treatment assessment values ​​in the training set as the input of the convolutional neural network, use the expert assessment label values ​​as the output of the convolutional neural network, train the convolutional neural network, and obtain an initial convolutional neural network. Use the validation set to validate the convolutional neural network and monitor changes in model performance; The verified convolutional neural network is used to perform model testing, and the initial convolutional neural network with a preset test accuracy is output as the trained convolutional neural network model.

7. The blockchain-based medical data sharing system according to claim 6, characterized in that: The steps to obtain verified medical institution access permissions and access requirements are as follows: Obtain access requirements from medical institutions, including basic disease data and basic treatment data; Obtain patient feedback reports and generate sensitive assessment values ​​based on the feedback; The sensitive assessment value, disease basic data and treatment basic data are input into the pre-trained convolutional neural network model to obtain the critical label value.

8. The blockchain-based medical data sharing system according to claim 7, characterized in that: The steps to generate a file identification value set are as follows: Obtain the tag table stored on the blockchain and compare the critical tag value with the tag value on the tag table in the blockchain; Use data filtering techniques to remove label values ​​belonging to other disease categories; For the same disease, the conditional judgment algorithm is used to eliminate the label values ​​below the critical label value to obtain a label value set that meets the requirements; Obtain the tag value in the tag value set, find the file identification value corresponding to the tag value, and summarize the file identification values ​​to form a file identification value set.

9. The blockchain-based medical data sharing system according to claim 8, characterized in that: Check the corresponding encrypted file storage location in the distributed storage system and decrypt the encrypted file as follows: Convert the file identification value into a file identifier; Query the encrypted file in the distributed storage system through the file identifier and transmit the encrypted file to the medical institution node; Query the node identity of the medical institution and send the private key and the key of the corresponding encryption level; Use the private key to decrypt the key ciphertext obtained on the blockchain to obtain the key, then use the key pair to decrypt the encrypted file to obtain the medical record data, and finally use the key corresponding to the encryption level to decrypt the medical record data to obtain the shared file; The shared files obtained are arranged in descending order of label values ​​to form a medical sharing set.

10. A data processing method for flow cytometer, using the system according to any one of claims 1 to 9, characterized in that: The steps include: Collect patient diagnosis and treatment data from the hospital information system, obtain diagnosis and treatment records, calculate the hash value hash1 and upload it to the blockchain; Obtain the secondary hash value hash2 of the patient's medical record, then encrypt it using RSA combined with AES encryption mode. Use the distributed storage system to generate a file identifier from the encrypted file. Extract key data from the medical record and input it into the identification model to generate a label value. Combine the label value and the file identifier into a file identification value. Summarize all the patient's historical label values ​​to form a label table. Submit the label table, file identification value, hash2, and key ciphertext to the blockchain. Compare hash1 and hash2. If they are the same, the tag value, file identification value, and encrypted file are submitted to the blockchain. If they are different, they are not uploaded and an alarm is issued that there is a data failure. Obtain the verified medical institution's access permissions and access requirements, input the critical tag value generated in the identification model, compare the critical tag value with the tag value in the tag table in the blockchain, screen the tag value set that meets the requirements, and generate the corresponding file identification value set; According to the file identifier in the file identification value recorded in the file identification value set, the corresponding encrypted file storage location is checked in the distributed storage system, the encrypted file is decrypted, and the data obtained by aggregation constitutes a medical sharing set.