An information management platform and method supporting multi-center data fusion

By constructing a cross-center user monitoring node network and a secure index hash table, combined with a hierarchical permission module and access control algorithm, the problems of scattered data storage and crude permission management in multi-center systems were solved, realizing secure integration and intelligent access of cross-center data, and improving data collaboration efficiency and patient experience.

CN120511076BActive Publication Date: 2025-10-28HANGZHOU ZHIXIANGHUIYI HEALTH MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510964907.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-10-28
Estimated Expiration
2045-07-14

AI Technical Summary

Technical Problem

In existing medical information systems, data storage is scattered across multiple centers and has heterogeneous formats, resulting in low efficiency of cross-center queries, difficulty in sharing patient historical data, and lax access control with risks of unauthorized access and privacy leaks. Business collaboration is difficult, and the lack of multi-center data support leads to repetitive operations and a fragmented patient experience.

Method used

A cross-center user monitoring node network is constructed through the profile index module, cross-center data aggregation is achieved using the secure index hash table of the global fusion module, a dynamic permission system is constructed through the hierarchical permission module, and a precise index list is generated through the cross-center access module. By combining hash algorithms, graph algorithms, and access control algorithms, secure fusion and collaborative access of multi-center data are realized.

Benefits of technology

It enables secure integration and intelligent access to cross-center data, ensuring data consistency and integrity. Fine-grained cross-domain permission layering improves the efficiency and security of multi-center data collaborative access, provides a unified self-service portal, and enhances the patient experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120511076B_ABST
    Figure CN120511076B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of data security technology, and particularly relates to an information management platform and method supporting multi-center data fusion. The platform utilizes a profile indexing module with hash and graph algorithms to construct a profile monitoring node network based on user monitoring information from different centers and a single-center hash index. A global fusion module uses a secure index hash table containing single and cross-center hash index mappings to generate a cross-center global profile node network through an association matching algorithm. The cross-center index mapping is constructed based on a dynamic feature anchoring algorithm and valid time. A hierarchical permission module combines hierarchical permission criteria and access control algorithms to generate a global permission hierarchical access node network. A cross-center access module obtains an index intent information list based on user access intent, permission level, and historical access frequency, combined with the global permission network. This platform achieves secure fusion and collaborative access of multi-center data, ensuring data isolation and cross-domain sharing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security technology, and in particular relates to an information management platform and method that supports multi-center data fusion. Background Technology

[0002] In existing medical information systems, centers for cancer prevention and chronic disease management, among others, employ independent information management systems, which suffer from numerous technical shortcomings. Regarding data, fragmented storage and heterogeneous formats create data silos, leading to low efficiency in cross-center queries and difficulty in sharing patient historical data. In terms of access control, traditional models are crude, posing risks of unauthorized access and privacy breaches. Business collaboration is difficult, with multidisciplinary consultations and referrals relying heavily on offline processes, resulting in low efficiency. Management decisions lack multi-center data support, and patients require repetitive operations, leading to a fragmented experience. Current data interface solutions only achieve limited interoperability, exhibiting shortcomings such as difficulty in balancing data sharing and business isolation, insufficient access control, and a lack of intelligent analysis capabilities, necessitating a more comprehensive technical solution. Summary of the Invention

[0003] To address the shortcomings of existing technologies, this invention proposes an information management platform and method supporting multi-center data fusion. The platform's profile indexing module constructs a profile monitoring node network based on user monitoring information from different centers and a single-center hash index. The global fusion module, utilizing a secure index hash table containing single and cross-center hash index mappings, generates a cross-center global profile node network through an association matching algorithm. The cross-center index mapping is constructed based on a dynamic feature anchoring algorithm and valid time. The hierarchical permission module combines hierarchical permission criteria and access control algorithms to generate a global permission hierarchical access node network. The cross-center access module obtains a list of index intent information based on user access intent, permission level, and historical access frequency, combined with the global permission network. This platform achieves secure fusion and collaborative access of multi-center data, ensuring data isolation and efficient cross-domain sharing.

[0004] To achieve the above objectives, the present invention provides the following technical solution:

[0005] An information management platform supporting multi-center data fusion includes:

[0006] The profile index module is used to obtain monitoring information of users in different centers, and based on the monitoring information of users in different centers and the preset single center user hash index, obtain the monitoring node network of profile information of different centers through graph algorithm;

[0007] The global fusion module, based on a secure index hash table constructed from the monitoring node network of profile information from different centers and the hash indexes of all users, obtains the cross-center global profile information monitoring node network through an association matching algorithm; the secure index hash table includes single-center user hash indexes and cross-center user hash index mappings;

[0008] The hierarchical permission module, based on the cross-center global profile information monitoring node network and the preset hierarchical permission criteria, obtains the cross-center global permission hierarchical access node network through access control algorithms; the hierarchical permission criteria are constructed based on the access object permissions, the information sensitivity level of the cross-center global profile information monitoring node network, and the cross-center information transmission security level.

[0009] The cross-center access module determines the user's access intent and permission level based on the access user information. Based on the user's access intent and permission level, access frequency of historical intent information, and cross-center global permission hierarchical access node network, it obtains a list of access user index intent information through a preset cross-center business isolation algorithm. The single-center user hash index is obtained by using a hash algorithm based on the user's basic information and the monitoring information of the user's corresponding center. The cross-center user hash index mapping is constructed by combining the user hash index of the same user in different centers with a dynamic feature anchoring algorithm and a preset effective time.

[0010] Specifically, the portrait indexing module includes portrait units, sensitivity assessment units, single index units, and node construction units;

[0011] The profiling unit obtains a single-center user profile and corresponding sensitive feature extraction space based on the basic information of a single user in different centers, multimodal monitoring information, and a preset multimodal profiling model.

[0012] The sensitivity assessment unit obtains the graded sensitivity information space corresponding to the single-center user information by combining the single-center user profile and the corresponding sensitive feature extraction space with the preset graded sensitivity assessment model.

[0013] A single index unit, based on the hierarchical sensitivity information space corresponding to the single central user information and combined with the preset permission level, obtains the hierarchical hash permission index corresponding to the single central user through a hash algorithm;

[0014] The node construction unit obtains the single-center profile information monitoring node network by constructing edge weights based on the similarity of monitoring information between single profile nodes and corresponding hierarchical hash permission indexes.

[0015] Specifically, the global fusion module includes a global mapping unit and a cross-center mapping unit;

[0016] The global mapping unit, based on the hierarchical hash permission index corresponding to the same user in different central profile information monitoring node networks, combined with the dynamic feature anchoring algorithm, obtains the cross-center mapping feature code of the corresponding user between different centers.

[0017] The cross-center mapping unit obtains the cross-center user hash index mapping by combining the cross-center mapping feature codes of all users in the monitoring node network of profile information in different centers with a feature splicing algorithm and a preset random valid time interval. Based on the cross-center user hash index mapping and the monitoring node network of profile information in different centers, it obtains the cross-center global profile information monitoring node network through a topology algorithm.

[0018] Specifically, the hierarchical permission module includes a hierarchical permission unit and a hierarchical permission mapping unit;

[0019] The hierarchical permission unit obtains the hierarchical access permission level corresponding to the user based on the user's basic information and the preset sensitivity level range of accessible information.

[0020] The hierarchical permission mapping unit, based on the hierarchical access permission level corresponding to the accessing user and the hierarchical sensitivity information space and cross-center mapping feature code corresponding to each user in the cross-center global profile information monitoring node network, uses access control algorithms combined with simulation algorithms to simulate cross-center hierarchical access information indexing, thereby obtaining the cross-center global permission hierarchical access node network.

[0021] Specifically, the process of constructing a cross-center user hash index mapping includes:

[0022] The basic information and multimodal monitoring information of each user in a single center are input into the multimodal feature extraction layer of the multimodal profiling model to obtain the basic feature space of a single user and the feature space of a single monitoring status in the current center.

[0023] Set the basic characteristics of a single user to the highest sensitivity level, and input the feature space of a single monitoring state into a sensitive keyword feature extraction layer with a pre-set sensitive word level library to obtain the sensitive word sequence of a single user and the number of sensitive words of the corresponding level.

[0024] Based on the sequence of sensitive words for each user and the number of sensitive words at each level, the overall sensitivity level and individual sensitivity level of a single user are obtained through a sensitivity level assessment layer.

[0025] Specifically, the process of constructing the cross-center user hash index mapping also includes:

[0026] Based on the comprehensive sensitivity level and single-level sensitivity of a single user, using a decision tree architecture, the comprehensive sensitivity level is taken as the trunk, the basic characteristics of the single user are set as the root node, and based on the single-level sensitivity, the keyword information corresponding to each sensitivity level is stored in the corresponding branch node of the trunk in order of sensitivity from near to far, starting from the root node, thus obtaining a single user sensitivity information decision tree.

[0027] Based on the information stored in each node of the decision tree for sensitive information of a single user, the label and distinguishing identifier information corresponding to each node are obtained through a random truncation algorithm;

[0028] Based on the label and distinguishing information corresponding to each node, a hash algorithm is used to obtain the hierarchical hash index corresponding to each node of the single user sensitive information decision tree.

[0029] Specifically, the process of constructing the cross-center user hash index mapping also includes:

[0030] Based on the sensitivity level corresponding to the access permissions of historical users in a single center, a support vector machine is used to obtain the lower-level mapping function of access permissions-sensitivity within a single center.

[0031] The access permission-sensitivity sub-mapping function enables users to access the current user's sensitive information decision tree within a single center, and simultaneously access user information stored in nodes of the same or lower sensitivity levels within the sensitive information decision trees of related users.

[0032] Based on the access permission-sensitivity sub-mapping function within a single center, combined with the hierarchical hash index corresponding to each node, the hierarchical hash permission index corresponding to each node is obtained and embedded into the node corresponding to the single user sensitive information decision tree to obtain the single user hierarchical permission decision tree.

[0033] Based on the information stored in the nodes of all single-user hierarchical permission decision trees within a single center and the corresponding hierarchical hash permission index, the association similarity between each single-user hierarchical permission decision tree and the information of nodes with the same sensitivity level and the information of nodes with lower-level levels in the remaining single-user hierarchical permission decision trees is obtained through a lower-level association matching algorithm.

[0034] Specifically, the process of constructing the cross-center user hash index mapping also includes:

[0035] Based on the correlation similarity between the node information of the same sensitivity level and the lower level node information in each single user hierarchical permission decision tree and the remaining single user hierarchical permission decision trees, a correlation similar connection is constructed. The hierarchical hash permission index corresponding to the two connected nodes is combined with the public key obtained by the zero proof algorithm and embedded into the corresponding connection. At the same time, the generated private key is configured into the two connected nodes respectively to obtain a single central user hierarchical permission decision forest.

[0036] Based on the hierarchical hash permission index built into the nodes of different sensitivity levels in the single user hierarchical permission decision tree of the same user in different centers, the dynamic feature anchoring algorithm is used to randomly extract index subsequences of length N from the hierarchical hash permission indexes of different levels and concatenate all the extracted index subsequences to obtain the cross-center fused index sequence.

[0037] Simultaneously, feature index information of length M is extracted from each index subsequence corresponding to the center containing the same user information. Based on the two feature index information extracted from any two centers that simultaneously contain the same user, a verifiable segmentation algorithm is used to obtain the concatenated feature code between any two cross-center fusion index sequences, where N>M.

[0038] Specifically, the process of constructing the cross-center user hash index mapping also includes:

[0039] Based on the concatenated feature code corresponding to any two cross-center fusion index sequences, the cross-center fusion index sequences corresponding to any two single users in any two centers are concatenated, and the bidirectional mapping between the access level of any two centers and the sensitivity level of non-local centers and the cross-center security index factor constructed by the cross-center data security level are embedded into the concatenated feature code corresponding to any two centers, so as to obtain the single user cross-center user hash index mapping.

[0040] Based on the above construction process of single-user cross-center user hash index mapping, the single-user cross-center user hash index mapping corresponding to all users is obtained;

[0041] Based on a single-center user hierarchical permission decision forest combined with the single-user cross-center user hash index mapping corresponding to all users, the single-center hierarchical permission information index and the cross-center user hierarchical permission decision forest are trained by combining access control algorithm with simulation algorithm and index anomaly function corresponding to the single-center user hierarchical permission decision forest and global index anomaly function corresponding to the cross-center user hierarchical permission decision forest, and the trained cross-center global permission hierarchical access node network is obtained.

[0042] An information management method supporting multi-center data fusion includes:

[0043] Acquire user monitoring information from different centers, and based on the user monitoring information from different centers combined with a preset single user hash index, obtain a network of monitoring nodes for profile information from different centers through a graph algorithm;

[0044] A secure index hash table, constructed based on a network of monitoring nodes for profile information from different centers and combined with hash indexes of all users, is used to obtain a cross-center global profile information monitoring node network through an association matching algorithm. The secure index hash table includes a single-center user hash index and a cross-center user hash index mapping.

[0045] Based on the cross-center global profile information monitoring node network and the preset hierarchical permission criteria, the access control algorithm obtains the cross-center global permission hierarchical access node network; the hierarchical permission criteria are constructed based on the access object permissions, the information sensitivity level of the cross-center global profile information monitoring node network, and the cross-center information security level.

[0046] The single-center user hash index is obtained by combining the user's basic information with the monitoring information of the user's corresponding center through a hash algorithm; the cross-center user hash index mapping is constructed by combining the user hash index of the same user in different centers with a dynamic feature anchoring algorithm and a preset effective time.

[0047] Based on the access user information, determine the user's access intent and permission level, and combine the user's access intent and permission level with the access frequency of historical intent information with the cross-center global permission hierarchical access node network to obtain a list of access user index intent information.

[0048] Compared with the prior art, the beneficial effects of the present invention are:

[0049] This invention addresses the shortcomings of existing technologies by employing a multi-module collaborative approach to achieve secure fusion and intelligent access to multi-center data. Specifically, the profile index module utilizes hash and graph algorithms to construct a semantic node network from heterogeneous monitoring information, enabling structured association and integration of cross-center data. The global fusion module uses a secure index hash table with dynamic anchor mapping, based on an association matching algorithm, to accurately aggregate cross-center data and verify its uniqueness, ensuring consistency and integrity of multi-source data. The hierarchical permission module combines information sensitivity levels and cross-center security rules to construct a dynamic permission system, achieving fine-grained cross-domain permission layering through access control algorithms, ensuring data isolation while meeting compliant access requirements. The cross-center access module generates a precise index list based on user intent, permission level, and historical access characteristics, improving the efficiency and targeting of collaborative access to multi-center data, achieving an organic balance between data fusion depth and security protection strength. Attached Figure Description

[0050] Figure 1 This is a module structure diagram of an information management platform supporting multi-center data fusion according to Embodiment 1 of the present invention;

[0051] Figure 2 This is a simplified schematic diagram of a single-center user hierarchical permission decision forest according to Embodiment 1 of the present invention;

[0052] Figure 3 This is a flowchart of an information management method supporting multi-center data fusion according to Embodiment 2 of the present invention. Detailed Implementation

[0053] Example

[0054] Please see Figure 1One embodiment of this invention provides an information management platform that supports multi-center data fusion, applied to cross-center indexing security protection of patient data in various departments or clinical centers within a hospital, such as centers corresponding to tumor prevention and treatment, chronic disease management, minimally invasive intervention, and pain management, including:

[0055] The profile index module is used to obtain monitoring information of users in different centers, and based on the monitoring information of users in different centers and the preset single center user hash index, obtain the monitoring node network of profile information of different centers through graph algorithm;

[0056] The global fusion module, based on a secure index hash table constructed from the monitoring node network of profile information from different centers and the hash indexes of all users, obtains the cross-center global profile information monitoring node network through an association matching algorithm; the secure index hash table includes single-center user hash indexes and cross-center user hash index mappings;

[0057] The hierarchical permission module, based on the cross-center global profile information monitoring node network and the preset hierarchical permission criteria, obtains the cross-center global permission hierarchical access node network through access control algorithms; the hierarchical permission criteria are constructed based on the access object permissions, the information sensitivity level of the cross-center global profile information monitoring node network, and the cross-center information transmission security level.

[0058] The cross-center access module determines the user's access intent and permission level based on the access user information. Based on the user's access intent and permission level and the access frequency of historical intent information, combined with the cross-center global permission hierarchical access node network, it obtains a list of access user index intent information through a preset cross-center business isolation algorithm. In this embodiment, the cross-center business isolation algorithm is used to isolate the query process of each business scenario. For example, queries from the chronic disease center channel and queries from the pain center are isolated from each other to avoid business conflicts.

[0059] It should be further explained that if this embodiment is applied to a hospital, each department is treated as a separate center;

[0060] It should be further explained that, in this embodiment, the single-center user hash index is obtained by combining the user's basic information with the monitoring information of the user's corresponding center through a hash algorithm; the cross-center user hash index mapping is constructed by combining the user hash index of the same user in different centers with a dynamic feature anchoring algorithm and a preset effective time.

[0061] Furthermore, the portrait indexing module includes portrait units, sensitivity assessment units, single index units, and node construction units;

[0062] The profiling unit obtains a single-center user profile and corresponding sensitive feature extraction space based on the basic information of a single user in different centers, multimodal monitoring information, and a preset multimodal profiling model.

[0063] The sensitivity assessment unit obtains the graded sensitivity information space corresponding to the single-center user information by combining the single-center user profile and the corresponding sensitive feature extraction space with the preset graded sensitivity assessment model.

[0064] A single index unit, based on the hierarchical sensitivity information space corresponding to the single central user information and combined with the preset permission level, obtains the hierarchical hash permission index corresponding to the single central user through a hash algorithm;

[0065] The node construction unit obtains the single-center profile information monitoring node network by constructing edge weights based on the similarity of monitoring information between single profile nodes and corresponding hierarchical hash permission indexes.

[0066] Furthermore, the global fusion module includes a global mapping unit and a cross-center mapping unit;

[0067] The global mapping unit, based on the hierarchical hash permission index corresponding to the same user in different central profile information monitoring node networks, combined with the dynamic feature anchoring algorithm, obtains the cross-center mapping feature code of the corresponding user between different centers.

[0068] The cross-center mapping unit obtains the cross-center user hash index mapping by combining the cross-center mapping feature codes of all users in the monitoring node network of profile information in different centers with a feature splicing algorithm and a preset random valid time interval. Based on the cross-center user hash index mapping and the monitoring node network of profile information in different centers, it obtains the cross-center global profile information monitoring node network through a topology algorithm.

[0069] Furthermore, the hierarchical permission module includes a hierarchical permission unit and a hierarchical permission mapping unit;

[0070] The hierarchical permission unit obtains the hierarchical access permission level corresponding to the user based on the user's basic information and a preset range of accessible information sensitivity levels. It should be noted that the permission levels in this embodiment are defined by those skilled in the art based on the specific data security protection requirements.

[0071] The hierarchical access permission mapping unit, based on the hierarchical access permission level corresponding to the accessing user and the hierarchical sensitivity information space and cross-center mapping feature code corresponding to each user in the cross-center global profile information monitoring node network, simulates the cross-center hierarchical access permission information index through access control algorithms combined with simulation algorithms to obtain the cross-center global access permission hierarchical access node network. It should be further noted that the access control algorithms in this embodiment preferentially adopt attribute-based access control algorithms and role-based access control algorithms, specifically:

[0072] Based on the hierarchical access permission levels of users, the user-level sensitivity information space in the cross-center global profile information monitoring node network, the cross-center mapping feature code, and the information sensitivity level range, the system determines the basic role permissions of users through RBAC (Role-Based Access Control Algorithm), and then refines the role permissions using ABAC (Attribute-Based Access Control Algorithm). A multi-dimensional access strategy is constructed by combining user attributes (such as affiliated center and position), environmental attributes (such as access time and device IP), and data attributes (such as information sensitivity level and cross-center mapping feature code). The strategy engine parses the strategy rules to match and resolve access requests. For example, when a doctor in the oncology center accesses chronic disease data, the system dynamically adjusts the accessible fields (e.g., displaying only blood glucose trends instead of specific gene data) based on their role permissions and data sensitivity level using the ABAC strategy. The final output is a cross-center global hierarchical access permission node network. This network uses nodes to represent accessible data resources and edges to represent access paths based on permission levels, achieving fine-grained cross-center data access control and hierarchical protection of sensitive information. It should be further explained that the multi-dimensional access strategy in this embodiment takes user attributes (such as affiliated center, role identity, job level), environmental attributes (such as access time, device IP address, network location), data attributes (such as information sensitivity level, data type, cross-center mapping feature code), and operation attributes (such as read, modify, and delete operation types) as core dimensions. The strategy uses a predefined policy rule engine to logically combine and weight the attributes of each dimension. For example, the strategy can be defined as "when a user is an attending physician in the oncology center and accesses chronic disease data with a sensitivity level of 'medium' in the cross-center global profile through the hospital's intranet device during working hours, only blood glucose trend data that is not related to genes is allowed to be read". By matching and resolving conflicts of the attributes of each dimension, precise control of cross-center data access permissions based on scenario dynamic adjustment is achieved.

[0073] The patient-side self-service module provides end users with access to cross-system data queries and business processing.

[0074] The patient-side self-service module includes a unified service portal unit, a personalized data dashboard unit, and an intelligent semantic search unit;

[0075] The unified service portal unit integrates service entry points from multiple systems, such as appointment, inquiry, and application, and supports single sign-on and service status tracking;

[0076] In this embodiment, the unified service portal unit implements SSO based on the OIDC protocol and routes requests through the microservice gateway.

[0077] The personalized data dashboard unit generates a customized list view of user access intent information based on user historical behavior, such as highlighting high-frequency access mechanisms. In this embodiment, the personalized data dashboard unit uses a collaborative filtering algorithm to analyze user behavior patterns and implements dynamic dashboard configuration based on D3.js.

[0078] The intelligent semantic search unit supports parsing the input query to obtain the query intent, combines it with an indexing algorithm, calls the built-in hash index of each node, and returns cross-system aggregated results, for example, "find records related to X in 2023". Furthermore, the indexing algorithm in this embodiment is preferably a tree index or a variant of a tree index algorithm;

[0079] In this embodiment, the intelligent semantic search unit builds a semantic understanding engine based on the BERT model and uses Elasticsearch to achieve distributed cross-center retrieval.

[0080] The process first achieves secure aggregation and efficient access to cross-center medical data through a multi-dimensional technical architecture. The profiling and indexing module, leveraging a multimodal profiling model and a hierarchical sensitivity assessment model, transforms patient basic information and multimodal data such as medical images and gene testing into a hierarchical sensitive feature space. Combined with a hash algorithm, it constructs index nodes with permission identifiers, enabling precise hierarchical and structured management of sensitive data, providing underlying support for subsequent cross-center access control. The global fusion module uses a dynamic feature anchoring algorithm to generate cross-center mapping feature codes and merges the index node networks from different centers into a global network through a topology algorithm. A secure index hash table, combined with zero-knowledge proofs and other mechanisms, ensures privacy protection during cross-center data association, achieving secure aggregation and global semantic mapping of multi-source medical data. The hierarchical permission module constructs hierarchical permission criteria based on access object permissions, data sensitivity levels, and transmission security requirements. It simulates cross-center permission indexing using access control algorithms and simulation algorithms. This architecture forms a fine-grained, hierarchical access node network, effectively preventing unauthorized access and data leakage risks. The cross-center access module uses a business isolation algorithm to isolate query channels from different centers, and optimizes access paths based on historical access frequency analysis to avoid query conflicts in different business scenarios such as tumor prevention and chronic disease management, thereby improving the efficiency of cross-center data access. The patient-side self-service module achieves single sign-on across multiple systems through the OIDC protocol, builds personalized data dashboards based on collaborative filtering algorithms and D3.js, and uses the BERT semantic understanding engine combined with Elasticsearch to achieve cross-center semantic retrieval, providing patients with a unified and intelligent self-service entry point. The overall technical architecture forms a closed-loop system of "data hierarchical, cross-center integration, hierarchical permission, business isolation, and intelligent services," ensuring the compliance and security of medical data while achieving efficient indexing of cross-center data and intelligent upgrades to patient self-service, thereby improving the efficiency of multi-center medical collaboration and patient experience.

[0081] Furthermore, the process of constructing the cross-center user hash index mapping includes:

[0082] The basic information and multimodal monitoring information of each user in a single center are input into the multimodal feature extraction layer of the multimodal profiling model to obtain the basic feature space of a single user and the feature space of a single monitoring status in the current center.

[0083] It should be noted that the specific steps for obtaining the basic feature space of a single user and the feature space of a single monitoring status in this embodiment include:

[0084] First, collect basic information and multimodal monitoring information of patients within a single center. It should be further noted that the basic information in this embodiment includes, but is not limited to, structured data such as patient name, ID number, medical record number, and attending department. The multimodal monitoring information in this embodiment includes, but is not limited to: PET-CT images, pathological slide images, and gene mutation detection reports for the cancer prevention and treatment center; dynamic monitoring curves of blood glucose and blood pressure, and medication orders for the chronic disease management center; surgical image sequences and intraoperative physiological index data for the minimally invasive intervention center; and pain score time-series records and neurophysiological detection reports for the pain treatment center.

[0085] Second, the collected data is input into the multimodal feature extraction layer of the multimodal profiling model, specifically as follows:

[0086] Step 1: Localize and extract features of lesion regions from medical images using a 3D convolutional neural network. It should be noted that lesion region localization and feature extraction include, but are not limited to, identifying the size, location, and metabolic activity of tumors.

[0087] Step 2: Analyze the fluctuation patterns and abnormal peaks of time-series data such as blood glucose and blood pressure using a bidirectional long short-term memory network, and use a pre-trained language model in the medical field to parse semantic information such as symptom descriptions, treatment plans, and allergy history in medical record texts; in this embodiment, the pre-trained language model in the medical field is preferably PubMedBERT.

[0088] Step 3: Use graph neural networks to construct a correlation map between gene mutation sites and disease phenotypes, and obtain the patient's basic feature space and single monitoring status feature space, including but not limited to image feature vectors, time-series trend vectors, text semantic vectors, etc.

[0089] Step 4: The patient's basic feature space and the single monitoring state feature space are mapped into a unified high-dimensional feature vector through the feature fusion algorithm. Combined with clinical diagnostic criteria, a patient profile is constructed that includes dimensions such as disease stage, treatment response, and risk of complications. At the same time, the sensitive feature recognition algorithm matches identification information such as ID card number and home address through regular expressions, uses a medical sensitive word library combined with semantic analysis to locate sensitive content such as hereditary tumor history and mental illness diagnosis, and marks the sensitivity level of pathogenic mutation sites based on gene privacy protection rules to form a set of sensitive features.

[0090] Step 5: Based on the guidelines for health and medical data security, sensitive features are mapped to a three-dimensional sensitive feature extraction space according to the risk of leakage: the X-axis represents the identifiability of the identity, such as the ID card number being high-risk; the Y-axis represents the sensitivity of the disease, such as the HIV diagnosis being highly sensitive; and the Z-axis represents the data update frequency, such as real-time physiological indicators being moderately sensitive. This quantifies the protection priority of each feature and provides underlying feature support for hierarchical desensitization and access control for cross-center access.

[0091] The basic characteristics of a single user are set to the highest sensitivity level. At the same time, the feature space of a single monitoring state is input into a sensitive keyword feature extraction layer with a pre-set sensitive word level library to obtain the sensitive word sequence of a single user and the number of sensitive words of the corresponding level. It should be noted that in this embodiment, the sensitive keyword feature extraction layer preferably uses a Chinese pre-trained BERT model and a comprehensive fuzzy evaluation algorithm.

[0092] Based on the sequence of sensitive words categorized by level for a single user and the number of sensitive words at each level, the overall sensitivity level and individual level sensitivity of the single user are obtained through a sensitivity level evaluation layer. It should be further noted that the sensitivity level evaluation layer in this embodiment incorporates a hierarchical sensitivity evaluation model. The steps for constructing and training the hierarchical sensitivity evaluation model include:

[0093] First, a sensitive word classification system is defined based on a medical knowledge graph, dividing sensitive words into 5 levels. For example, ID numbers are level 5 and disease names are level 3. The medical knowledge graph is preferably a health and medical data security guideline.

[0094] Second, historical medical data was collected to build a training set, and features such as the frequency of sensitive words, word co-occurrence relationship, and semantic similarity were extracted. The XGBoost algorithm was used to train the classification model, the model parameters were optimized through the gradient boosting mechanism, and 5-fold cross-validation was used to ensure generalization ability.

[0095] Third, an attention mechanism is introduced to dynamically adjust the weights of each feature, giving higher weights to high-risk features. The model outputs a single-level sensitivity and a comprehensive sensitivity level, and maps the probability of each level to a continuous value in the 0-1 range through the softmax function. Finally, the model performance is evaluated through the ROC curve to ensure that the AUC value is greater than the preset AUC threshold. In this embodiment, AUC is the area under the curve, which usually specifically refers to the area under the receiver operating characteristic curve.

[0096] Based on the comprehensive sensitivity level and single-level sensitivity of a single user, using a decision tree architecture, the comprehensive sensitivity level is taken as the trunk, the basic characteristics of the single user are set as the root node, and based on the single-level sensitivity, the keyword information corresponding to each sensitivity level is stored in the corresponding branch node of the trunk in order of sensitivity from near to far, starting from the root node, thus obtaining a single user sensitivity information decision tree.

[0097] Based on the information stored in each node of the decision tree for sensitive information of a single user, the label and distinguishing identifier information corresponding to each node are obtained through a random truncation algorithm;

[0098] It should be further explained that the process of obtaining the label and distinguishing identifier information in this embodiment includes:

[0099] First, feature vectors of nodes are extracted using the BERT model to generate 768-dimensional semantic vectors. Second, a cryptographically secure pseudo-random number generator is used to dynamically generate truncation parameters based on the node's sensitivity level. For example, anchors with shorter intervals are generated for highly sensitive nodes, while the intervals for low-sensitive nodes are expanded to 15 dimensions. Third, a fixed-length subsequence is truncated from the 768-dimensional semantic vector based on the anchor position. For example, 32 dimensions are truncated for highly sensitive nodes. The truncated sequence is Base64 encoded to generate basic labels. Simultaneously, information such as node sensitivity level and keyword frequency is hashed using SHA-256 to generate a 128-bit digest. The first 8 bits are used as a distinguishing prefix, concatenated with the basic label, and a CRC-16 checksum is added. Finally, a unique identifier containing semantic features, sensitivity level, and checksum information is formed, ensuring that the labels of different nodes have semantic distinguishability and data integrity.

[0100] Based on the label and distinguishing information corresponding to each node, a hash algorithm is used to obtain the hierarchical hash index corresponding to each node of the single user sensitive information decision tree;

[0101] It should be further explained that in this embodiment, SHA-256 hash operation is performed on each node of the user sensitive information decision tree, and the first 16 bytes are truncated as the base hash value; a prefix identifier is added according to the node sensitivity level, for example, high sensitivity = 0x01, medium sensitivity = 0x02, low sensitivity = 0x03, such as the hash of a high sensitivity node is 0x01-5a3f2b...; Bloom Filter is used to deduplicate the hashes of nodes at the same level, generating an index table containing 128-bit fingerprints for fast retrieval of sensitive features at the same level.

[0102] Based on the sensitivity level corresponding to the access permissions of historical users in a single center, a support vector machine is used to obtain the lower-level mapping function of access permissions-sensitivity within a single center.

[0103] It should be further explained that this embodiment first collects access logs from multiple clinical centers over the past Q years, including but not limited to user roles, access data sensitivity levels, and operation times. Samples are extracted to construct a training set. Secondly, an SVM model with an RBF kernel is used to train the mapping function. The input is the user role, including but not limited to doctors, nurses, administrators, and patients. The access scenarios include but are not limited to diagnosis, research, and quality control. The output is the highest sensitivity level allowed for access. For example, chief physicians can access highly sensitive data, while interns are limited to low-sensitivity data. Finally, the hyperparameters are adjusted through 5-fold cross-validation to ensure that the model accuracy is greater than the preset accuracy threshold.

[0104] The access permission-sensitivity sub-mapping function enables users to access the current user's sensitive information decision tree within a single center, and simultaneously access user information stored in nodes of the same or lower sensitivity levels within the sensitive information decision trees of related users.

[0105] Based on the access permission-sensitivity sub-mapping function within a single center, combined with the hierarchical hash index corresponding to each node, the hierarchical hash permission index corresponding to each node is obtained and embedded into the node corresponding to the single user sensitive information decision tree to obtain the single user hierarchical permission decision tree.

[0106] It should be further explained that this embodiment first embeds the mapping function generated by SVM into the decision tree nodes, and sets an access permission threshold for each node. For example, a highly sensitive node requires the role of a chief physician. Secondly, the LSH (Local Sensitive Hash) algorithm is used to calculate the feature similarity between decision trees of different patients. When the cosine similarity of the node feature vectors is greater than a preset similarity threshold, a cross-tree connection is established. It should also be noted that the connection weights in this embodiment are calculated using a Bayesian probability model based on the feature co-occurrence frequency, forming a weighted association network. For example, the co-occurrence frequency is a% for "BRCA1 mutation" and "family history of breast cancer".

[0107] Based on the information stored in the nodes of all single-user hierarchical permission decision trees in a single center and the corresponding hierarchical hash permission index, the association similarity between each single-user hierarchical permission decision tree and the information of nodes with the same sensitivity level and the information of nodes with the same lower level in the remaining single-user hierarchical permission decision trees is obtained through the lower-level association matching algorithm.

[0108] Based on the correlation similarity between the node information of the same sensitivity level and the lower level node information in each single user hierarchical permission decision tree and the remaining single user hierarchical permission decision trees, a correlation similar connection is constructed. The hierarchical hash permission index corresponding to the two connected nodes is combined with the public key obtained by the zero proof algorithm and embedded into the corresponding connection. At the same time, the generated private key is configured into the two connected nodes respectively to obtain a single central user hierarchical permission decision forest.

[0109] Please see Figure 2 Assuming that A1 in the diagram corresponds to the root node of a single user in the tumor center, A11 to A14 indicate the branching nodes of different sensitivities corresponding to single user A1, A2 is the root node of the second user, and A21 to A25 are the branching nodes of different levels of sensitivity corresponding to the second user. A1 and A2 are both hierarchical permission decision trees for single users in the tumor center, and B11 to B14 corresponding to A1 are the hierarchical permission decision trees for single users corresponding to the detection information of user A1 in the pain center.

[0110] It should be further explained that this embodiment first uses the EC-Schnorr zero-knowledge proof algorithm for cross-tree connections to generate a 256-bit elliptic curve public key, which is stored in the connection edge and private key and assigned to the corresponding node. When it is necessary to verify the consistency of features between two nodes, the verification is completed through a non-interactive proof mechanism without revealing the original features, thereby reducing access latency while meeting the real-time access requirements.

[0111] Based on the hierarchical hash permission index built into the nodes of different sensitivity levels in the single user hierarchical permission decision tree of the same user in different centers, the dynamic feature anchoring algorithm is used to randomly extract index subsequences of length N from the hierarchical hash permission indexes of different levels and concatenate all the extracted index subsequences to obtain the cross-center fused index sequence.

[0112] It should be further explained that this embodiment uses a dynamic feature anchoring algorithm to extract a subsequence of length N=32 from the hash index of each center for the same patient in different centers with a hierarchical permission decision tree. It should be noted that the anchoring interval in this embodiment is dynamically adjusted according to the sensitivity level, with a 5-byte interval for high-sensitivity layers and a 15-byte interval for low-sensitivity layers. For example, the first 32 bits of the high-sensitivity index 0x01-abc...... in the cancer prevention and treatment center are extracted, and the middle 32 bits of the sensitive index 0x02-def...... in the chronic disease management center are extracted.

[0113] Simultaneously, feature index information of length M is extracted from each index subsequence corresponding to the center containing the same user information. Based on the two feature index information extracted from any two centers that simultaneously contain the same user, the concatenated feature code between any two cross-center fusion index sequences is obtained through a verifiable segmentation algorithm.

[0114] It should be further explained that in this embodiment, feature segments are first extracted from the index subsequences corresponding to any two centers according to a preset offset, and the Paillier homomorphic encryption algorithm is used to encrypt the feature segments. The Groth16 zero-knowledge proof protocol is used to verify that the hash values ​​of the two encrypted feature segments are equal, ensuring that the verification process does not reveal the original feature content.

[0115] Secondly, the verified feature segment hash value is concatenated with the cross-center security index factor. The security index factor is embedded in a specified position using ASN.1 encoding format. Then, the concatenated data is processed using the SHA-512 hash algorithm to generate a 64-byte concatenated feature code. It should be noted that the cross-center security index factor in this embodiment includes, but is not limited to, security attributes such as data transmission encryption level and access control policy. Furthermore, the feature code in this embodiment ensures the uniqueness, immutability, and secure traceability of the cross-center index concatenation by integrating encryption verification, security factor embedding, and hash operation, thereby realizing the secure association and verification of sensitive data indexes in different centers.

[0116] Based on the concatenation feature code corresponding to any two cross-center fusion index sequences, the cross-center fusion index sequences corresponding to any two centers for a single user are concatenated, and the bidirectional mapping between the access level of any two centers and the sensitivity level of non-centers and the cross-center security index factor constructed by the cross-center data security level are built into the concatenation feature code corresponding to any two centers, so as to obtain the cross-center user hash index mapping for a single user.

[0117] Based on the above construction process of single-user cross-center user hash index mapping, the single-user cross-center user hash index mapping corresponding to all users is obtained;

[0118] Based on a single-center user hierarchical permission decision forest combined with the single-user cross-center user hash index mapping corresponding to all users, the single-center hierarchical permission information index and the cross-center user hierarchical permission decision forest are trained by combining access control algorithm with simulation algorithm and index anomaly function corresponding to the single-center user hierarchical permission decision forest and global index anomaly function corresponding to the cross-center user hierarchical permission decision forest, and the trained cross-center global permission hierarchical access node network is obtained.

[0119] It should be further explained that the training process of the access control algorithm combined with the simulation algorithm in this embodiment includes:

[0120] First, the fusion features of the hierarchical hash permission index and cross-center hash index mapping of the single-center hierarchical permission decision forest are extracted and used as training input;

[0121] Secondly, an initial permission model is constructed using the SVM permission mapping function in the access control algorithm. Combined with the simulation algorithm, access samples containing multi-center scenarios such as tumor prevention and control and chronic disease management are generated, covering business scenarios such as normal access, unauthorized access, and cross-center business conflicts.

[0122] Third, during training, the model's ability to identify abnormal access is detected by using a single-center index anomaly function and a cross-center global index anomaly function. The accuracy of permission hierarchical verification is performed for normal access. For abnormal access, the permission threshold of decision tree nodes and the security factor weight of cross-center mapping feature codes are optimized in reverse through loss functions (including but not limited to the fusion of conflict probability and access delay).

[0123] Fourth, Monte Carlo simulation is introduced to dynamically adjust the cross-center security index factor, and a gradient descent algorithm is used to iteratively optimize the access control strategy. This allows the model to gradually optimize the permission control logic as it simulates the access behavior of users with different roles. Finally, adaptive training generates a cross-center global hierarchical access node network, achieving accurate permission interception and path optimization for real access requests. It should be further noted that in this embodiment, different user roles include doctors, nurses, administrators, and patients.

[0124] This process deeply integrates access control algorithms and simulation algorithms to construct an adaptive cross-center access control system. Specifically, firstly, by extracting the fusion features of a single-center hierarchical access decision forest and a cross-center hash index mapping, it ensures that the training input covers the access control logic of the hierarchical hash access index and the security association features of the cross-center fusion index. This provides comprehensive semantic and security dimension feature support for the subsequent access control model, enabling the model to understand the sensitivity levels and access mapping relationships of data from different centers. Secondly, an initial model is constructed using an SVM access mapping function, combined with simulation algorithms to generate access samples covering multi-center scenarios such as tumor prevention and chronic disease management. By simulating the normal and abnormal access behaviors of different roles such as doctors, nurses, administrators, and patients in diagnostic and research scenarios, the model can learn the access boundaries of various business scenarios during the training phase. This multi-scenario simulation training mechanism ensures that the model can accurately identify cross-center business conflicts in practical applications, such as query isolation between chronic disease centers and pain centers, avoiding unauthorized data access caused by ambiguous access rules.

[0125] Fifth, through a dual-index anomaly detection mechanism involving both single-center and cross-center indexing, combined with a loss function to inversely optimize the decision tree node permission threshold and cross-center security factor weights, a "detection and optimization" closed loop is formed. This mechanism enables the system to dynamically adjust the access threshold of highly sensitive nodes (such as the access control of chief physicians) and optimize the cross-tree connection weights based on feature co-occurrence frequency (such as the association between BRCA1 mutation and family history of breast cancer), thereby improving the access efficiency of moderately sensitive data such as "disease names" while ensuring the security of the most sensitive data such as "ID numbers". Fourth, Monte Carlo simulation is introduced to dynamically adjust the cross-center security indexing factor, combined with the gradient descent algorithm to iteratively optimize the access strategy, making the model... This system can adapt to differences in data security levels across different centers. For example, it incorporates a bidirectional mapping between access levels and sensitivity levels within the cross-center concatenated feature codes. This allows for real-time responses to compliance requirements of health and medical data security guidelines, dynamically adjusting data transmission encryption levels and access control policies to ensure privacy protection during cross-center data association. For instance, it uses Paillier encryption and Groth16 proofs to achieve secure verification of the feature codes. Finally, the adaptively trained cross-center global hierarchical access node network integrates security mechanisms such as Bloom Filter deduplication and EC-Schnorr zero-knowledge proofs to achieve precise permission interception and path optimization for genuine access requests. While ensuring the confidentiality of highly sensitive data such as gene testing reports, this system, through the synergy of hierarchical hash indexes and permission mapping, enables authorized users such as doctors to efficiently obtain complete patient profiles across centers, improving the efficiency of multi-center medical collaboration. Simultaneously, through dynamic feature anchoring algorithms and uniqueness verification of concatenated feature codes, it ensures the immutability and secure traceability of cross-center data indexes, forming a technical closed loop of security protection, efficient access, and compliance management.

[0126] Sixth, this embodiment also achieves precise positioning of sensitive features in medical data from structured to semantic through the technical coupling of multimodal feature fusion and hierarchical sensitivity assessment, providing fine-grained semantic support for cross-center access control; the synergy of decision tree architecture and hierarchical hash index organizes sensitive features according to risk level and assigns permission identifiers, forming an integrated semantic and permission index structure, which not only ensures the isolated storage of highly sensitive data, but also improves the retrieval efficiency of features of the same level through Bloom filter deduplication; the combination of dynamic feature anchoring algorithm and Paillier homomorphic encryption dynamically adjusts the anchoring interval to balance security and efficiency when splicing cross-center indexes, and achieves secure association of data that is usable but not visible by combining Groth16 proof; the integration of access control algorithm and Monte Carlo simulation enables the system to dynamically optimize permission thresholds based on historical access patterns and real-time load, and form a flexible permission strategy that adapts to the needs of multiple roles such as doctors, nurses and patients through gradient descent iteration, ultimately realizing the implicit technical effect of "hierarchical sensitive features, dynamic access control and traceable security verification" for cross-center medical data. Example

[0127] Please see Figure 3 Another embodiment of the present invention provides: an information management method supporting multi-center data fusion, comprising:

[0128] S1, obtain monitoring information of users in different centers, and obtain the monitoring node network of profile information of different centers by combining the monitoring information of users in different centers with the preset single user hash index through graph algorithm; the graph algorithm in this embodiment is preferably an adjacency index, path index or subgraph index algorithm, etc.

[0129] S2, a secure index hash table is constructed based on the monitoring node network of different center profile information combined with the hash index of all users. Through the association matching algorithm, a cross-center global profile information monitoring node network is obtained. The secure index hash table includes a single center user hash index and a cross-center user hash index mapping.

[0130] S3, based on the cross-center global profile information monitoring node network and the preset hierarchical permission criteria, the cross-center global permission hierarchical access node network is obtained through the access control algorithm; the hierarchical permission criteria are constructed according to the access object permissions combined with the information sensitivity level of the cross-center global profile information monitoring node network and the cross-center information security level.

[0131] The single-center user hash index is obtained by combining user basic information with monitoring information of the user's corresponding center through a hash algorithm; the cross-center user hash index mapping is constructed by combining the user hash index of the same user in different centers with a dynamic feature anchoring algorithm and a preset effective time.

[0132] S4. Determine the user's access intent and permission level based on the access user information, and obtain a list of access user index intent information by combining the user's access intent and permission level with the access frequency of historical intent information and the cross-center global permission hierarchical access node network. Example

[0133] An electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement an information management method that supports multi-center data fusion.

[0134] A computer-readable storage medium having computer instructions stored thereon, which, when executed, perform an information management method supporting multi-center data fusion.

[0135] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments under the guidance of the present invention without departing from the spirit and scope of the claims. All of these variations are within the protection scope of the present invention.

[0136] If the technical solution disclosed herein involves personal information, the product using this technical solution has clearly informed the user of the personal information processing rules and obtained the user's voluntary consent before processing the personal information. If the technical solution disclosed herein involves sensitive personal information, the product using this technical solution has obtained the user's separate consent before processing the sensitive personal information, and also meets the requirement of "express consent". For example, at personal information collection devices such as cameras, clear and prominent signs are set up to inform users that they have entered the scope of personal information collection and that personal information will be collected. If an individual voluntarily enters the collection scope, it is deemed that they have agreed to the collection of their personal information; or on the personal information processing device, with clear signs / information informing users of the personal information processing rules, authorization is obtained from the individual through pop-up information or by asking the individual to upload their personal information; wherein, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.

Claims

1. An information management platform supporting multi-center data fusion, characterized in that, include: The profile index module is used to obtain monitoring information of users in different centers, and based on the monitoring information of users in different centers and the preset single center user hash index, obtain the monitoring node network of profile information of different centers through graph algorithm; The global fusion module, based on a secure index hash table constructed from the monitoring node network of different center profile information combined with the hash index of all users, obtains the cross-center global profile information monitoring node network through an association matching algorithm; the secure index hash table includes a single-center user hash index and a cross-center user hash index mapping; The hierarchical permission module, based on the cross-center global profile information monitoring node network and the preset hierarchical permission criteria, obtains the cross-center global permission hierarchical access node network through access control algorithms; The hierarchical permission criteria are constructed based on the access object permissions combined with the sensitivity level of cross-center global profile information monitoring node network information and the security level of cross-center information transmission. The cross-center access module determines the user's access intent and permission level based on the access user information. It then combines the user's access intent and permission level with historical intent information and access frequency, along with a cross-center global permission hierarchical access node network, to obtain a list of access user index intent information through a preset cross-center business isolation algorithm. The single-center user hash index is obtained by combining the user's basic information with the monitoring information of the user's corresponding center using a hash algorithm. The cross-center user hash index mapping is constructed based on the same user's hash indexes in different centers, combined with a dynamic feature anchoring algorithm and a preset effective time.

2. The information management platform supporting multi-center data fusion as described in claim 1, characterized in that, The portrait indexing module includes a portrait unit, a sensitivity evaluation unit, a single index unit, and a node construction unit; The profiling unit obtains a single-center user profile and corresponding sensitive feature extraction space based on the basic information of a single user in different centers, multimodal monitoring information, and a preset multimodal profiling model. The sensitivity assessment unit obtains the graded sensitivity information space corresponding to the single-center user information by combining the single-center user profile and the corresponding sensitive feature extraction space with a preset graded sensitivity assessment model. The single index unit obtains the hierarchical hash permission index corresponding to the single central user by combining the hierarchical sensitivity information space corresponding to the single central user information with the preset permission level and through a hash algorithm. The node construction unit constructs edge weights based on the similarity of monitoring information between single-profile nodes and nodes constructed according to the single-center user profile and the corresponding hierarchical hash permission index, thereby obtaining a single-center profile information monitoring node network.

3. The information management platform supporting multi-center data fusion as described in claim 2, characterized in that, The global fusion module includes a global mapping unit and a cross-center mapping unit; The global mapping unit obtains the cross-center mapping feature code of the corresponding user between different centers based on the hierarchical hash permission index corresponding to the same user in different center profile information monitoring node networks and the dynamic feature anchor algorithm. The cross-center mapping unit obtains the cross-center user hash index mapping by combining the cross-center mapping feature codes of all users in the different center profile information monitoring node network with a preset random valid time interval through a feature splicing algorithm. Based on the cross-center user hash index mapping and the center profile information monitoring node network, it obtains the cross-center global profile information monitoring node network through a topology algorithm.

4. An information management platform supporting multi-center data fusion as described in claim 3, characterized in that, The hierarchical permission module includes a hierarchical permission unit and a hierarchical permission mapping unit; The hierarchical permission unit obtains the hierarchical access permission level corresponding to the user based on the user's basic information and a preset range of accessible information sensitivity levels. The hierarchical permission mapping unit, based on the hierarchical access permission level corresponding to the accessing user and the hierarchical sensitivity information space and cross-center mapping feature code corresponding to each user in the cross-center global profile information monitoring node network, performs cross-center hierarchical access node network by combining access control algorithm and simulation algorithm to simulate cross-center hierarchical permission information index.

5. An information management platform supporting multi-center data fusion as described in claim 4, characterized in that, The process of constructing the cross-center user hash index mapping includes: The basic information and multimodal monitoring information of each user in a single center are input into the multimodal feature extraction layer of the multimodal profiling model to obtain the basic feature space of a single user and the feature space of a single monitoring status in the current center. Set the basic characteristics of a single user to the highest sensitivity level, and input the feature space of a single monitoring state into a sensitive keyword feature extraction layer with a pre-set sensitive word level library to obtain the sensitive word sequence of a single user and the number of sensitive words of the corresponding level. Based on the sequence of sensitive words for each user and the number of sensitive words at each level, the overall sensitivity level and individual sensitivity level of a single user are obtained through a sensitivity level assessment layer.

6. An information management platform supporting multi-center data fusion as described in claim 5, characterized in that, The process of constructing the cross-center user hash index mapping also includes: Based on the comprehensive sensitivity level and single-level sensitivity of a single user, using a decision tree architecture, the comprehensive sensitivity level is taken as the trunk, the basic characteristics of the single user are set as the root node, and based on the single-level sensitivity, the keyword information corresponding to each sensitivity level is stored in the corresponding branch node of the trunk in order of sensitivity from near to far, starting from the root node, thus obtaining a single user sensitivity information decision tree. Based on the information stored in each node of the decision tree for sensitive information of a single user, the label and distinguishing identifier information corresponding to each node are obtained through a random truncation algorithm; Based on the label and distinguishing information corresponding to each node, a hash algorithm is used to obtain the hierarchical hash index corresponding to each node of the single user sensitive information decision tree.

7. An information management platform supporting multi-center data fusion as described in claim 6, characterized in that, The process of constructing the cross-center user hash index mapping also includes: Based on the sensitivity level corresponding to the access permissions of historical users in a single center, a support vector machine is used to obtain the lower-level mapping function of access permissions-sensitivity within a single center. The access permission-sensitivity sub-mapping function enables users to access the current user's sensitive information decision tree within a single center, and simultaneously access user information stored in nodes of the same or lower sensitivity levels within the associated user's sensitive information decision tree. Based on the access permission-sensitivity sub-mapping function within a single center, combined with the hierarchical hash index corresponding to each node, the hierarchical hash permission index corresponding to each node is obtained and embedded into the node corresponding to the single user sensitive information decision tree to obtain the single user hierarchical permission decision tree. Based on the information stored in the nodes of all single-user hierarchical permission decision trees within a single center and the corresponding hierarchical hash permission index, the association similarity between each single-user hierarchical permission decision tree and the information of nodes with the same sensitivity level and the information of nodes with lower-level levels in the remaining single-user hierarchical permission decision trees is obtained through a lower-level association matching algorithm.

8. An information management platform supporting multi-center data fusion as described in claim 7, characterized in that, The process of constructing the cross-center user hash index mapping also includes: Based on the correlation similarity between the node information of the same sensitivity level and the lower level node information in each single user hierarchical permission decision tree and the remaining single user hierarchical permission decision trees, a correlation similar connection is constructed. The hierarchical hash permission index corresponding to the two connected nodes is combined with the public key obtained by the zero proof algorithm and embedded into the corresponding connection. At the same time, the generated private key is configured into the two connected nodes respectively to obtain a single central user hierarchical permission decision forest. Based on the hierarchical hash permission index built into the nodes of different sensitivity levels in the single user hierarchical permission decision tree of the same user in different centers, the dynamic feature anchoring algorithm is used to randomly extract index subsequences of length N from the hierarchical hash permission indexes of different levels and concatenate all the extracted index subsequences to obtain the cross-center fused index sequence. Simultaneously, feature index information of length M is extracted from each index subsequence corresponding to the center containing the same user information. Based on the two feature index information extracted from any two centers that simultaneously contain the same user, a verifiable segmentation algorithm is used to obtain the concatenated feature code between any two cross-center fusion index sequences, where N>M.

9. An information management platform supporting multi-center data fusion as described in claim 8, characterized in that, The process of constructing the cross-center user hash index mapping also includes: Based on the concatenation feature code corresponding to any two cross-center fusion index sequences, the cross-center fusion index sequences corresponding to any two centers for a single user are concatenated, and the bidirectional mapping between the access level of any two centers and the sensitivity level of non-centers and the cross-center security index factor constructed by the cross-center data security level are built into the concatenation feature code corresponding to any two centers, so as to obtain the cross-center user hash index mapping for a single user. Based on the above construction process of single-user cross-center user hash index mapping, the single-user cross-center user hash index mapping corresponding to all users is obtained; Based on a single-center user hierarchical permission decision forest combined with the single-user cross-center user hash index mapping corresponding to all users, the single-center hierarchical permission information index and the cross-center user hierarchical permission decision forest are trained by combining access control algorithm with simulation algorithm and index anomaly function corresponding to the single-center user hierarchical permission decision forest and global index anomaly function corresponding to the cross-center user hierarchical permission decision forest, and the trained cross-center global permission hierarchical access node network is obtained.

10. An information management method supporting multi-center data fusion, implemented based on an information management platform supporting multi-center data fusion as described in any one of claims 1-9, characterized in that, include: Acquire user monitoring information from different centers, and based on the user monitoring information from different centers combined with a preset single-center user hash index, obtain a network of monitoring nodes for user profile information from different centers through a graph algorithm; A secure index hash table, constructed based on a network of monitoring nodes for profile information from different centers and combined with hash indexes of all users, is used to obtain a cross-center global profile information monitoring node network through an association matching algorithm; the secure index hash table includes a single-center user hash index and a cross-center user hash index mapping. Based on the cross-center global profile information monitoring node network and the preset hierarchical permission criteria, the cross-center global permission hierarchical access node network is obtained through access control algorithms. The hierarchical permission criteria are constructed based on the access object permissions combined with the sensitivity level of cross-center global profile information monitoring node network information and the security level of cross-center information transmission. The single-center user hash index is obtained by combining user basic information with monitoring information of the user's corresponding center through a hash algorithm; the cross-center user hash index mapping is constructed by combining the user hash index of the same user in different centers with a dynamic feature anchoring algorithm and a preset effective time. Based on the access user information, the user's access intent and permission level are determined. Then, based on the user's access intent and permission level and the access frequency of historical intent information, combined with the cross-center global permission hierarchical access node network, a list of access user index intent information is obtained through a preset cross-center business isolation algorithm.

Citation Information

Patent Citations

  • Attribute-based access-controlled data-storage system

    US20140201520A1

  • Systems, methods, and apparatuses for implementing a multi tenant blockchain platform for managing einstein platform decisions using distributed ledger technology (DLT)

    US20200252205A1