Data encryption method and system for hospital information system

By using asymmetric encryption algorithms in the hospital information system to generate public and private keys, the public key is shared within the encryption domain, and the private key is only held by the main user terminal, which solves the problems of data security and privacy protection and achieves data privacy and security.

CN120512318BActive Publication Date: 2025-09-12NANJING CHUANGHONGJING INTELLIGENT TECH RES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511006830.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-22
Publication Date
2025-09-12
Estimated Expiration
2045-07-22

AI Technical Summary

Technical Problem

There are problems with data security and data privacy protection in hospital information systems. Digital data may be leaked, threatening the privacy of medical information and patient privacy.

Method used

An asymmetric encryption algorithm is used to generate public and private keys. The public key is used for data encryption, and the private key is used for data decryption. The public key is shared within the encryption domain, and the private key is only held by the main user terminal. Users are isolated by the encryption domain to ensure the security of data encryption and decryption.

Benefits of technology

It ensures the privacy of medical information data, prevents the leakage of patient privacy data, eliminates the risk of leakage caused by key transfer, and realizes flexible and secure data encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120512318B_ABST
    Figure CN120512318B_ABST
Patent Text Reader

Abstract

The present invention discloses a data encryption method and system for a hospital information system, comprising: forming a set of all users involved in the current process, generating an encryption domain, and designating a main user among all users in the encryption domain; the main user's terminal generates a public key and a private key based on an asymmetric encryption algorithm; the public key is sent to all users in the encryption domain respectively, and the private key is stored in the main user's terminal without performing any sending operation; all users in the encryption domain encrypt the medical information data created by each of them using the public key, and send the encrypted medical information data to the main user's terminal; the main user's terminal decrypts the encrypted medical information data and views the medical information data. The present invention encrypts the medical information data through an asymmetric encryption algorithm, thereby ensuring the privacy of the medical information data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of hospital information systems, and in particular to a data encryption method and system for hospital information systems. Background Art

[0002] Information systems are now being applied across all industries, and hospitals are no exception. Currently, the vast majority of hospitals have already implemented information systems. As a crucial component of network infrastructure, these systems cover and manage the entire medical process, significantly improving not only the efficiency of medical processes but also their standardization, reliability, and traceability.

[0003] However, hospital information systems also raise data security and privacy concerns. Digital data can be leaked for a variety of reasons, directly threatening the privacy of medical information and, in turn, leaking patients' private data. Therefore, a flexible, secure, and suitable data encryption method for hospital information systems is urgently needed to protect data privacy in hospital information systems. Summary of the Invention

[0004] The purpose of the present invention is to provide a data encryption method and system for hospital information systems, aiming to solve the data security and data privacy protection problems brought about by the hospital information system, and to provide a flexible, secure and suitable data encryption method suitable for hospital information scenarios to ensure the data privacy of the hospital information system.

[0005] In view of the above problems, the present application provides a data encryption method and system for a hospital information system.

[0006] The first aspect disclosed in the present application provides a data encryption method for a hospital information system, the method comprising:

[0007] All users involved in the current process are grouped together to form an encryption domain, and a master user is designated among all users in the encryption domain. The encryption domain is used to isolate all users involved in the current process, forming an encryption space that is not open to users outside the domain.

[0008] The primary user's terminal generates a public key and a private key based on an asymmetric encryption algorithm. The public key is used for data encryption, and the private key is used for data decryption. The public key consists of a public key exponent and a modulus, while the private key consists of a private key exponent and a modulus.

[0009] The public key is sent to all users in the encryption domain, and the private key is stored in the terminal of the master user without any sending operation;

[0010] All users in the encryption domain encrypt their own medical information data using the public key and send the encrypted medical information data to the terminal of the main user;

[0011] The terminal of the primary user decrypts the encrypted medical information data and views the medical information data.

[0012] Preferably, generating a public key and a private key specifically includes:

[0013] Randomly generate two prime numbers with binary digits of 2048 as the first prime number and the second prime number;

[0014] Calculate the product of the first prime number and the second prime number as the modulus, and calculate the Euler function value of the modulus ;

[0015] Generate less than And with The public key exponent is a positive integer that is mutually prime. The public key exponent and the modulus together constitute the public key.

[0016] Generate public key exponent modulo The modulus inverse element is used as the private key exponent, and the private key exponent and modulus together constitute the private key.

[0017] Preferably, all users in the encryption domain encrypt their own created medical information data using a public key and send the encrypted medical information data to the terminal of the primary user, specifically including:

[0018] All users in the encryption domain convert their created medical information data into a string format to generate a string to be encrypted;

[0019] Convert the character string to be encrypted into a character encoding sequence using a preset character encoding format;

[0020] The character encoding sequence is divided into blocks of equal length, each block includes bytes, where n is the modulus. If the number of bytes in the last block is less than , the last block is padded with zero characters until the number of bytes is If the total number of bytes in the character encoding sequence is less than , zero characters are used to fill the number of bytes , and as a unique block;

[0021] For each block, it is encoded into a plaintext block integer using big-endian encoding, and encrypted based on the public key using formula (1) to generate a ciphertext block integer as the encryption result, where M is the plaintext block integer, e is the public key exponent, mod is the modulo operation, and C is the ciphertext block integer:

[0022] Formula (1);

[0023] All ciphertext block integers are concatenated to generate encrypted medical information data, and the encrypted medical information data is sent to the terminal of the main user.

[0024] Preferably, the primary user's terminal decrypts the encrypted medical information data, specifically including:

[0025] The primary user's terminal splits all ciphertext blocks in the encrypted medical information data into integers;

[0026] For each ciphertext block integer, based on the private key, the plaintext block integer is decrypted using formula (2), where C is the ciphertext block integer, d is the private key exponent, and mod is the modulo operation. is the decrypted plaintext block integer:

[0027] Formula (2);

[0028] All decrypted plaintext block integers are decoded into original blocks through big-endian decoding, and after removing the padded zero bytes, they are merged into the original character encoding sequence, and further converted into the original string through the same character encoding form as the encryption process to generate decrypted medical information data.

[0029] A second aspect disclosed in the present application provides a data encryption system for a hospital information system, the system being used in the above-mentioned data encryption method for a hospital information system, the system comprising:

[0030] An initialization module, which is used to group all users involved in the current process, generate an encryption domain, and designate a master user among all users in the encryption domain. The encryption domain is used to isolate all users involved in the current process, forming an encryption space that is not open to users outside the domain.

[0031] A key generation module, which is used by the primary user's terminal to generate a public key and a private key based on an asymmetric encryption algorithm. The public key is used for data encryption, and the private key is used for data decryption. The public key consists of a public key exponent and a modulus, and the private key consists of a private key exponent and a modulus.

[0032] A key distribution module, which sends the public key to all users in the encryption domain and stores the private key in the terminal of the master user without performing any sending operation;

[0033] An encryption module, which is used to encrypt the medical information data created by all users in the encryption domain using a public key and send the encrypted medical information data to the terminal of the primary user;

[0034] A decryption module is used by the terminal of the main user to decrypt the encrypted medical information data and view the medical information data.

[0035] The third aspect disclosed in the present application provides a computer device including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above-mentioned data encryption method for a hospital information system when executing the computer program.

[0036] The fourth aspect disclosed in the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-mentioned data encryption method for a hospital information system.

[0037] The fifth aspect disclosed in the present application provides a computer program product, including a computer program or instructions, which, when executed by a processor, implement the steps of the above-mentioned data encryption method for a hospital information system.

[0038] The beneficial effects of the present invention are:

[0039] (1) Encrypt medical information data through asymmetric encryption algorithm to ensure the privacy of medical information data and prevent the leakage of patients' private data;

[0040] (2) The concept of encryption domain is proposed. All users in the encryption domain encrypt medical information data through a shared public key, and decryption is completed only by the private key. The private key is only held by the terminal of the main user, eliminating the risk of key leakage caused by key transfer. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0042] Figure 1 The figure is an overall flow chart of a data encryption method for hospital information systems.

[0043] Figure 2 This is an overall structural diagram of a data encryption system used in hospital information systems. DETAILED DESCRIPTION

[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0045] Example 1:

[0046] like Figure 1 As shown, an embodiment of the present application provides a data encryption method for a hospital information system, the method comprising:

[0047] All users involved in the current process are formed into a set, an encryption domain is generated, and a master user is designated among all users in the encryption domain. The encryption domain is used to isolate all users involved in the current process and form an encryption space that is not open to users outside the domain.

[0048] The primary user's terminal generates a public key and a private key based on an asymmetric encryption algorithm. The public key is used for data encryption and the private key is used for data decryption. The public key consists of a public key exponent and a modulus, and the private key consists of a private key exponent and a modulus.

[0049] The specific steps for generating public and private keys are as follows:

[0050] Randomly generate a 2048-bit odd number and force the highest bit and the lowest bit of the number to be 1, convert the binary number to a decimal integer, and use the pre-screening method to check whether the number can be divided by prime numbers less than 1000. If it can, then randomly generate a 2048-bit odd number again according to the above method and use the pre-screening method to check. If not, use the Miller-Rabin algorithm to test the primality of the number to verify whether it is a prime number. If it is, then use the number as the first prime number. If not, then randomly generate a 2048-bit odd number again according to the above method and execute the above process. Theoretically, the probability of failing to generate a prime number using the above process is , which is almost impossible, and using the above process to generate a 2048-bit prime number only takes 0.1-1 seconds on a high-performance CPU, which has a relatively fast generation speed;

[0051] Generate a 2048-bit prime number again according to the above method as the second prime number;

[0052] Calculate the product of the first prime number and the second prime number as the modulus, and calculate the Euler function value of the modulus , according to the properties of Euler function, ;

[0053] Generate less than And with The public key exponent is a positive integer that is mutually prime. The public key exponent and the modulus together constitute the public key.

[0054] Generate public key exponent modulo The modular inverse element is used as the private key exponent, that is, the private key exponent × public key exponent 1mod , the private key exponent and modulus together constitute the private key.

[0055] The public key is sent to all users in the encryption domain, and the private key is stored in the terminal of the main user without any sending operation. Specifically, the decryption and viewing of medical information data can only be performed on the terminal of the main user. The private key is not shared with any other user, nor is it sent or transferred in any form. This ensures that only the main user has the authority to decrypt and view medical information data, and also ensures that the private key will not be leaked during the sending or transfer process. At the same time, all users in the encryption domain use the shared public key to encrypt medical information data, which also has the effect of a digital signature, because the public key is only shared within the encryption domain, ensuring that the current encryption domain isolates all users involved in the current process.

[0056] All users in the encryption domain encrypt the medical information data they create using the public key and send the encrypted medical information data to the terminal of the main user.

[0057] The above operation specifically includes the following steps:

[0058] All users in the encryption domain convert their created medical information data into a string format to generate a string to be encrypted;

[0059] Convert the character string to be encrypted into a character encoding sequence using a preset character encoding format;

[0060] The character encoding sequence is divided into blocks of equal length, each block includes bytes, where n is the modulus. If the number of bytes in the last block is less than , the last block is padded with zero characters until the number of bytes is If the total number of bytes in the character encoding sequence is less than , zero characters are used to fill the number of bytes , and as a unique block;

[0061] For each block, it is encoded into a plaintext block integer using big-endian encoding, and encrypted based on the public key using formula (1) to generate a ciphertext block integer as the encryption result, where M is the plaintext block integer, e is the public key exponent, mod is the modulo operation, and C is the ciphertext block integer:

[0062] Formula (1);

[0063] All ciphertext block integers are concatenated to generate encrypted medical information data, and the encrypted medical information data is sent to the terminal of the main user.

[0064] The terminal of the primary user decrypts the encrypted medical information data and views the medical information data.

[0065] The specific steps of the above decryption include:

[0066] The primary user's terminal splits all ciphertext blocks in the encrypted medical information data into integers;

[0067] For each ciphertext block integer, based on the private key, the plaintext block integer is decrypted using formula (2), where C is the ciphertext block integer, d is the private key exponent, and mod is the modulo operation. is the decrypted plaintext block integer:

[0068] Formula (2);

[0069] All decrypted plaintext block integers are decoded into original blocks through big-endian decoding, and after removing the padded zero bytes, they are merged into the original character encoding sequence, and further converted into the original string through the same character encoding form as the encryption process to generate decrypted medical information data.

[0070] In summary, the data encryption method for a hospital information system provided by the embodiment of the present application has the following technical effects:

[0071] (1) Encrypt medical information data through asymmetric encryption algorithm to ensure the privacy of medical information data and prevent the leakage of patients' private data;

[0072] (2) The concept of encryption domain is proposed. All users in the encryption domain encrypt medical information data through a shared public key, and decryption is completed only by the private key. The private key is only held by the terminal of the main user, eliminating the risk of key leakage caused by key transfer.

[0073] Example 2:

[0074] Based on the same inventive concept as the data encryption method for hospital information system in embodiment 1, Figure 2 As shown, the present application provides a data encryption system for a hospital information system, the system comprising:

[0075] An initialization module, which is used to group all users involved in the current process, generate an encryption domain, and designate a master user among all users in the encryption domain. The encryption domain is used to isolate all users involved in the current process, forming an encryption space that is not open to users outside the domain.

[0076] A key generation module, which is used by the primary user's terminal to generate a public key and a private key based on an asymmetric encryption algorithm. The public key is used for data encryption, and the private key is used for data decryption. The public key consists of a public key exponent and a modulus, and the private key consists of a private key exponent and a modulus.

[0077] A key distribution module, which sends the public key to all users in the encryption domain and stores the private key in the terminal of the master user without performing any sending operation;

[0078] An encryption module, which is used to encrypt the medical information data created by all users in the encryption domain using a public key and send the encrypted medical information data to the terminal of the primary user;

[0079] A decryption module is used by the terminal of the main user to decrypt the encrypted medical information data and view the medical information data.

[0080] Through the above detailed description of a data encryption method for a hospital information system in this specification, those skilled in the art can clearly understand a data encryption system for a hospital information system in this embodiment. Since it corresponds to the method disclosed in the embodiment, the description is relatively simple. For relevant matters, please refer to the method part.

[0081] Example 3:

[0082] In the third embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps of the above-mentioned data encryption method for a hospital information system when executing the computer program.

[0083] Example 4:

[0084] In the fourth embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned data encryption method for a hospital information system are implemented.

[0085] Embodiment 5:

[0086] In the fifth embodiment, a computer program product is provided, including a computer program or instructions, which implement the steps of the above-mentioned data encryption method for a hospital information system when executed by a processor.

[0087] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0088] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data encryption method for a hospital information system, characterized in that: The method comprises: All users involved in the current process are grouped together to form an encryption domain, and a master user is designated among all users in the encryption domain. The encryption domain is used to isolate all users involved in the current process, forming an encryption space that is not open to users outside the domain. The primary user's terminal generates a public key and a private key based on an asymmetric encryption algorithm. The public key is used for data encryption, and the private key is used for data decryption. The public key consists of a public key exponent and a modulus, and the private key consists of a private key exponent and a modulus. Generating the public key and the private key specifically includes the following steps: Randomly generate two prime numbers with binary digits of 2048 as the first prime number and the second prime number; calculate the product of the first prime number and the second prime number as the modulus, and calculate the Euler function value of the modulus ; Generate less than And with A mutually prime positive integer is used as the public key exponent. The public key exponent and modulus together constitute the public key. Generate the public key exponent modulus The inverse element of the module is used as the private key exponent, and the private key exponent and the modulus together constitute the private key; The public key is sent to all users in the encryption domain, and the private key is stored in the terminal of the master user without any sending operation; All users in the encryption domain encrypt their own medical information data using the public key and send the encrypted medical information data to the terminal of the main user. The specific steps include: All users in the encryption domain convert their own medical information data into a string to generate a string to be encrypted; convert the string to be encrypted into a character code sequence using a preset character encoding format; divide the character code sequence into blocks of equal length, each block including bytes, where n is the modulus. If the number of bytes in the last block is less than , the last block is padded with zero characters until the number of bytes is If the total number of bytes in the character encoding sequence is less than , zero characters are used to fill the number of bytes , and as a unique block; for each block, encode it into a plaintext block integer through big-endian encoding, and encrypt it based on the public key using formula (1) to generate a ciphertext block integer as the encryption result, where M is the plaintext block integer, e is the public key exponent, mod is the modulus operation, and C is the ciphertext block integer: Formula (1) concatenate all ciphertext blocks integers to generate encrypted medical information data, and send the encrypted medical information data to the primary user's terminal; The primary user's terminal decrypts the encrypted medical information data and checks the medical information data, specifically including the following steps: The primary user's terminal splits all the ciphertext block integers in the encrypted medical information data; for each ciphertext block integer, based on the private key, the plaintext block integer is decrypted using formula (2), where C is the ciphertext block integer, d is the private key exponent, and mod is the modulo operation. is the decrypted plaintext block integer: Formula (2) All decrypted plaintext block integers are decoded into original blocks through big-endian decoding, and after removing the padded zero bytes, they are merged into the original character encoding sequence, and further converted into the original string through the same character encoding form as the encryption process to generate decrypted medical information data.

2. A data encryption system for a hospital information system, characterized in that: The system comprises: An initialization module, which is used to group all users involved in the current process, generate an encryption domain, and designate a master user among all users in the encryption domain. The encryption domain is used to isolate all users involved in the current process, forming an encryption space that is not open to users outside the domain. A key generation module is used for the primary user's terminal to generate a public key and a private key based on an asymmetric encryption algorithm. The public key is used for data encryption and the private key is used for data decryption. The public key consists of a public key exponent and a modulus, and the private key consists of a private key exponent and a modulus. The generation of the public key and the private key specifically includes the following steps: Randomly generate two prime numbers with binary digits of 2048 as the first prime number and the second prime number; calculate the product of the first prime number and the second prime number as the modulus, and calculate the Euler function value of the modulus ; Generate less than And with A mutually prime positive integer is used as the public key exponent. The public key exponent and modulus together constitute the public key. Generate the public key exponent modulus The inverse element of the module is used as the private key exponent, and the private key exponent and the modulus together constitute the private key; A key distribution module, which sends the public key to all users in the encryption domain and stores the private key in the terminal of the master user without performing any sending operation; The encryption module is used to encrypt the medical information data created by all users in the encryption domain using the public key and send the encrypted medical information data to the terminal of the main user, specifically including the following steps: All users in the encryption domain convert their own medical information data into a string to generate a string to be encrypted; convert the string to be encrypted into a character code sequence using a preset character encoding format; divide the character code sequence into blocks of equal length, each block including bytes, where n is the modulus. If the number of bytes in the last block is less than , the last block is padded with zero characters until the number of bytes is If the total number of bytes in the character encoding sequence is less than , zero characters are used to fill the number of bytes , and as a unique block; for each block, encode it into a plaintext block integer through big-endian encoding, and encrypt it based on the public key using formula (1) to generate a ciphertext block integer as the encryption result, where M is the plaintext block integer, e is the public key exponent, mod is the modulus operation, and C is the ciphertext block integer: Formula (1) concatenate all ciphertext blocks integers to generate encrypted medical information data, and send the encrypted medical information data to the primary user's terminal; The decryption module is used for the primary user's terminal to decrypt the encrypted medical information data and view the medical information data, specifically including the following steps: The primary user's terminal splits all the ciphertext block integers in the encrypted medical information data; for each ciphertext block integer, based on the private key, the plaintext block integer is decrypted using formula (2), where C is the ciphertext block integer, d is the private key exponent, and mod is the modulo operation. is the decrypted plaintext block integer: Formula (2) All decrypted plaintext block integers are decoded into original blocks through big-endian decoding, and after removing the padded zero bytes, they are merged into the original character encoding sequence, and further converted into the original string through the same character encoding form as the encryption process to generate decrypted medical information data.

3. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the data encryption method for a hospital information system described in claim 1 are implemented.

4. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of a data encryption method for a hospital information system described in claim 1 are implemented.

5. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of a data encryption method for a hospital information system described in claim 1 are implemented.

Citation Information

Patent Citations

  • Encryption sharing system for medical data

    CN116527355A

  • Electronic medical data privacy protection method and system based on key encapsulation mechanism

    CN118101241A