Permission matching method and system based on medical participants

Through the two-way authorization matching method, the problem of permission matching errors in the hospital permission management system is solved, accurate permission authorization for people with different identities is achieved, and the security of medical data and the real-time access control are improved.

CN120473103APending Publication Date: 2025-08-12WEST CHINA HOSPITAL SICHUAN UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510559793.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, the hospital permission management system cannot achieve fast and accurate permission matching, resulting in permission matching errors and security risks, and the permission change request processing time is too long.

Method used

Through the two-way authorization matching method, we can obtain the device type, identify the target role, connect to the interactive center to deploy permissions, identify the execution role and execute permission authorization, and use attribute access control and role access control to achieve dynamic matching.

Benefits of technology

It has achieved accurate authorization of personnel with different identities such as surgical doctors, anesthesiologists, nurses, etc., improving the security of medical data and real-time access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120473103A_ABST
    Figure CN120473103A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric digital data processing, in particular to a permission matching method and system based on medical participants, and the method comprises the steps: obtaining a use equipment type, and executing target role authorization based on the equipment use type; connecting an interaction center, deploying an authorization result, and obtaining authority; connecting an execution end and identifying an execution role; executing permission identification based on the identification execution role; authorization is performed on the identified permissions. According to the method provided by the invention, accurate authority authorization can be performed on medical participants with different identities, such as a surgeon, an anesthetist, a nurse, a technician, a repair doctor and the like; meanwhile, according to the method, identity verification can be performed on the user in front of the screen in real time, and access is denied once the user does not have the permission through identification, so that the security of the medical data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of electronic digital data processing, and in particular to a method for matching permissions based on medical participants, and also to a system. Background Art

[0002] With the development of modern medical technology, the initial permission allocation lacks a dynamic adjustment mechanism, making it impossible to track user permission usage and difficult to detect potential security issues in a timely manner. There is also a risk of medical information leakage. In addition, due to the unreasonable design of the permission matching process, the processing time of permission change requests is too long, affecting the normal work of users.

[0003] The existing Chinese invention patent application with publication number CN117540404A, entitled A Management Authority Matching Method, discloses determining the resources that need to be managed and the corresponding authorities, defining different user roles in the system; formulating authority standards, clarifying the responsibilities and authorities of each role in the system, designing the resources that need to be managed and the corresponding authorities, and defining the hierarchical structure of different user roles in the system; setting up an effective identity authentication mechanism; automatically assigning initial authorities according to the user's role and identity during the registration or initialization phase, considering dynamically adjusting authorities according to the user's behavior and needs; recording the authority usage of each user to promptly detect abnormal behavior; setting a strategy for regular authority review, establishing an effective communication mechanism, and responding in a timely manner, and implementing an authority revocation mechanism to revoke authorities in a timely manner.

[0004] The aforementioned technical solution can ensure that permissions remain consistent with changes in work tasks, but the overall processing process is redundant and cannot achieve reasonable matching of permissions. Summary of the Invention

[0005] Through research, the inventors discovered that the hospital's authority management system can authorize personnel with different identities, such as surgeons, anesthesiologists, nurses, technicians, and interns, and grant them the authority to browse the imaging data of various equipment in the operating room. However, due to the large number of people, there will be problems of identity duplication or authority matching errors.

[0006] The purpose of this application is to provide a method and system for authority matching based on medical participants, which solves the technical problem that the existing technology cannot provide fast and accurate authority matching for target roles through two-way authorization matching.

[0007] According to one aspect of the present application, a permission matching method based on medical participants is provided, which is executed by a processor to obtain the type of device used and perform target role authorization based on the device usage type; connect to the interaction center, deploy the authorization result, and obtain permission; connect to the execution end, identify the execution role; perform permission identification based on the identified execution role; and perform authorization for the identified permission.

[0008] In some embodiments, the process of obtaining the device type and performing target role authorization based on the device usage type is as follows: obtaining at least one device based on target event requirements; determining the target role based on the device, and performing target role matching authorization.

[0009] In some embodiments, the process of connecting to the interaction center, deploying the authorization result, and obtaining the permission is: connecting to the interaction center, performing writing on the target role that has matched the authorization; performing deployment on the written data, and determining the corresponding permission of the deployed data.

[0010] In some embodiments, the process of connecting to the execution end and identifying the execution role is as follows: the interaction center connects to the execution end and obtains information of the target role to be operated; and determines the execution role type based on the target role information.

[0011] In some embodiments, the process of identifying permissions based on identifying the execution role is as follows: matching the previous permission content of the same role type according to the determined role type; and identifying permissions based on the previous permission content.

[0012] In some embodiments, the process of performing authorization on the identified permission is: performing time sequence matching according to the identified permission; and performing role authorization on the identified permission based on the time sequence matching.

[0013] According to another aspect of the present application, a method and system for matching permissions based on medical participants are provided, the system including a processor and at least comprising:

[0014] A front-end acquisition module, configured to acquire a device usage type and perform target role authorization based on the device usage type;

[0015] An authority determination module, which is used to connect to the interaction center, deploy authorization results, and obtain permissions;

[0016] a first identification module, configured to connect to an execution end and identify an execution role;

[0017] a second identification module, the second identification module being configured to perform permission identification based on the identification of the execution role;

[0018] An execution module is used to execute authorization for the identified permission.

[0019] In some embodiments, the processor is data-connected to the front-end acquisition module, the authority determination module, the first identification module, the second identification module, and the execution module.

[0020] Compared with the existing technology, the present application has the following beneficial effects: the method of the present application can accurately authorize permissions for medical participants with different identities such as surgeons, anesthesiologists, nurses, technicians, and interns; at the same time, the method of the present application can authenticate the user in front of the screen in real time. Once it is determined that the user does not have the permission, access will be denied, thereby improving the security of medical data. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0022] Figure 1 This is a flowchart of the permission matching method of this application;

[0023] Figure 2 This is the structural diagram of the permission matching system of this application;

[0024] Figure 3 This is a schematic diagram of the permission matching method of this application. DETAILED DESCRIPTION

[0025] The following is a combination of the appended examples of the present application Figure 1-3 The technical solutions in the embodiments of the present application are described clearly and completely. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments.

[0026] Example 1

[0027] Figure 1 The flowchart of the method for matching medical personnel's rights based on this embodiment is provided. The method is executed by a processor. The processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0028] The methods specifically include:

[0029] The device type used is obtained, and target role authorization is performed based on the device usage type. In this embodiment, the devices used include at least surgical equipment such as ultrasound equipment, monitoring equipment, ventilators, imaging equipment, anesthesia equipment, and external computer devices such as DSA, nurse terminals, doctor terminals, interventional imaging signals, personal computer signals, external network computer signals, and PACS systems. In some possible implementations, based on the target event requirements, at least one device is obtained; based on the device used, the target role is determined, and authorization is performed to match the target role.

[0030] Connect to the interaction center, deploy the authorization results, and obtain permissions. The interaction center is equipped with a core cabinet, and the core cabinet is equipped with an interaction unit, which performs information interaction operations. In some possible implementations, connect to the interaction center, execute a write operation on the target role that has matched the authorization; execute the deployment on the written data, and determine the corresponding permissions for the deployed data. It is understandable that medical participants with different identities generally have different operational requirements. If these medical participants are given the same permissions, the security of medical data will not be properly guaranteed. In addition, if medical participants with the same identity are given the same permissions, accurate permission matching will also not be achieved. Based on this, matching target roles with permission execution can effectively solve the aforementioned problems. Specifically: This embodiment uses attribute-based access control (ABAC) to dynamically match permissions based on user attributes (such as department and position), resource attributes (such as file classification level), and environmental conditions (such as access time and IP address), achieving one-to-one permission matching.

[0031] Connect to the execution end and identify the execution role. In this embodiment, the execution end includes at least the following medical participants: technicians, doctors, nurses, anesthesiologists, trainees, etc. In other possible scenarios, the execution end can also be the personnel of the corresponding scenario. In some possible implementations, the interaction center connects to the execution end and obtains the target role information to be operated; based on the target role information, the execution role type is determined. It can be understood that the interaction center uses a distributed interaction method to determine the personnel decision of the execution end, and according to the determined role information, the role type is determined based on the role-based access control (RBAC), that is, by defining the role, granting the role the authority, and then associating the user with the role.

[0032] Based on the identification of the execution role, the execution authority identification is performed. According to the role information, the authority inheritance and dependency analysis method is used to identify the authority. Through the information such as the field or department to which the role belongs, the inherited authority is deduced, and matching is performed based on this authority to complete the identification. In some possible implementation methods, according to the determination of the role type, the authority content of the same role type in the past is matched; based on the previous authority content, the authority is identified. It can be understood that the previous authority content of the same role type is the information such as the field or department to which the role belongs.

[0033] Authorization is performed on the identified permissions. In some possible implementations, timing matching is performed based on the identified permissions; based on the timing matching, role authorization is performed on the identified permissions. It should be noted that the timing matching in this implementation is based on matching at different time points. For example, when scientific research is limited to 21:00 to 23:00 in the evening, researchers will only be able to perform permission matching and identification within this time period. For other time periods, permissions cannot be matched. When the match is successful, the corresponding permissions are granted. It should be noted that timing matching can be performed based on time periods or time points.

[0034] It should be understood that various forms of processes shown above can be used to reorder, add or delete steps, as long as the expected results of the technical solutions disclosed in this application can be achieved, and this document does not limit them here.

[0035] Example 2

[0036] Based on the same inventive concept as the method for matching the rights of medical participants in the first embodiment, Figure 2 As shown, this embodiment also provides a permission matching system based on medical participants. The system includes a processor. Exemplarily, the permission matching method based on medical participants can be divided into one or more modules, one or more modules are stored in a memory, and executed by a processor to complete this application. One or more modules can be a series of computer program instruction segments that can complete specific functions, and the instruction segments are used to describe the execution process of the computer program. For example, the computer program can be divided into a front-end acquisition module, a permission determination module, a first identification module, a second identification module and an execution module. The specific functions of each module are as follows: the front-end acquisition module is used to obtain the type of device used and execute target role authorization based on the device usage type; the permission determination module is used to connect to the interaction center, deploy authorization results, and obtain permissions; the first identification module is used to connect to the execution end and identify the execution role; the second identification module is used to perform permission identification based on the identification of the execution role; the execution module is used to execute authorization for the identified permissions.

[0037] In some embodiments, the processor data is connected to the front-end acquisition module, the authority determination module, the first identification module, the second identification module, and the execution module.

[0038] The specific example of the permission matching method based on medical participants in the aforementioned embodiment 1 is also applicable to the permission matching system based on medical participants in this embodiment. Through the aforementioned detailed description of the permission matching method based on medical participants, those skilled in the art can clearly understand the permission matching system based on medical participants in this embodiment, so for the sake of brevity of the specification, it will not be described in detail here.

[0039] The above shows and describes the basic principles and main features of the present application and the advantages of the present application. It is obvious to those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and that the present application can be implemented in other specific forms without departing from the spirit or basic features of the present application. Therefore, no matter from which point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present application is defined by the appended claims rather than the above description, and it is intended that all changes that fall within the meaning and range of equivalents of the claims are included in the present application. Any figure mark in the claims should not be construed as limiting the claim to which it relates.

[0040] In addition, it should be understood that although this specification is described in terms of implementation methods, not every implementation method contains only one independent technical solution. This narrative method of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other implementation methods that can be understood by those skilled in the art.

Claims

1. A method for matching permissions based on medical personnel, the method being executed by a processor, characterized in that: Obtain the device type used and perform target role authorization based on the device usage type; Connect to the interaction center, deploy authorization results, and obtain permissions; Connect to the execution end and identify the execution role; Based on the identification of execution roles, execution permissions are identified; Perform authorization for the identified permissions.

2. The method according to claim 1, characterized in that The process of obtaining the device usage type and performing target role authorization based on the device usage type is as follows: Based on the target event requirements, obtaining at least one device to be used; Based on the device used, the target role is determined and authorization is performed matching the target role.

3. The method according to claim 2, characterized in that The process of connecting to the interaction center, deploying the authorization results, and obtaining permissions is as follows: Connect to the interaction center and write to the target role that has matched the authorization; Perform deployment on written data and determine the corresponding permissions for the deployed data.

4. The method according to claim 3, characterized in that The process of connecting to the execution end and identifying the execution role is as follows: The interaction center connects to the execution end to obtain the target role information to be operated; Based on the target role information, role type determination is performed.

5. The method according to claim 4, characterized in that The process of identifying execution permissions based on identifying execution roles is as follows: According to the determined role type, match the previous permissions of the same role type; Identify permissions based on previous permissions content.

6. The method according to claim 5, characterized in that The process of authorizing the identified permissions is as follows: Perform timing matching based on identified permissions; Based on time series matching, role authorization is performed on identification permissions.

7. A system for matching medical personnel based on their authority, the system comprising a processor, characterized in that: Also include at least: A front-end acquisition module, configured to acquire a device usage type and perform target role authorization based on the device usage type; An authority determination module, which is used to connect to the interaction center, deploy authorization results, and obtain permissions; a first identification module, configured to connect to an execution end and identify an execution role; a second identification module, the second identification module being configured to perform permission identification based on the identification of the execution role; An execution module is used to execute authorization for the identified permission.

8. The system according to claim 7, characterized in that The processor is data-connected to the front-end acquisition module, the authority determination module, the first identification module, the second identification module, and the execution module.

Citation Information

Patent Citations

  • Management authority matching method, device and system

    CN117540404A