Patient information query system based on cloud computing

By combining data preprocessing, feature mapping, trust assessment and authority review modules, the problems of multi-source heterogeneous data analysis bias and data leakage risk are solved, cross-institutional data consistency analysis and real-time security protection are achieved, and clinical diagnosis efficiency and model adaptability are improved.

CN120673952AInactive Publication Date: 2025-09-19SHANDONG YUANHUI INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510660622.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-09-19
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing cloud computing-based patient information query system has multi-source heterogeneous data redundancy and data format differences that lead to analysis bias. The traditional encryption mechanism lacks real-time dynamic trust assessment, and authority management is difficult to adapt to complex and changeable remote diagnosis and treatment scenarios. The case fitting analysis model is prone to degradation and the risk of data leakage is high.

Method used

The data preprocessing module is used to deduplicate and standardize multi-source data formats, the feature mapping module performs symptom fit analysis, the trust assessment module uses asymmetric encryption and dynamic trust scoring, the permission review module identifies abnormal requests and adjusts permissions in real time, and the feedback iteration module optimizes case association strength.

Benefits of technology

It achieves cross-institutional data consistency analysis, improves clinical diagnosis efficiency and accuracy, protects against data leakage risks in real time, automatically adjusts permissions, enhances model adaptability, and balances data sharing efficiency and security needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120673952A_ABST
    Figure CN120673952A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of patient information management, in particular to a patient information query system based on cloud computing, which comprises a data preprocessing module, a feature mapping module, a trust evaluation module, a permission auditing module and a feedback iteration module. According to the method, the consistency of basic data is improved by integrating multi-source data and de-duplication standardization based on a distributed architecture, accurate layered mapping of physiological indexes and disease types is realized in combination with a disease classification standard, a reliable analysis reference is provided for cross-mechanism cooperation, and symptom fitting degree analysis is accelerated by adopting a parallel computing architecture; high-correlation cases are screened to improve clinical diagnosis efficiency and precision, asymmetric encryption is combined with a dynamic trust scoring mechanism, the risk of abnormal data leakage is blocked, remote diagnosis and treatment scene abnormal requests are identified through streaming data processing, the problem of lagging of traditional manual auditing is solved, chronic disease management data are continuously collected through a standardized feedback interface, and the accuracy of remote diagnosis and treatment is improved. And the model adaptive capability is enhanced, and the data sharing efficiency and security requirements are balanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of patient information management, and in particular to a patient information query system based on cloud computing. Background Art

[0002] The field of patient information management technology encompasses the collection, storage, management, and analysis of medical information. This area primarily focuses on effectively processing patient medical data to improve the quality and efficiency of healthcare services. Core content encompasses the management of patient medical records, diagnosis and treatment information, medication usage, and test results. Through various information systems, medical institutions can access and update patient information in real time, thereby optimizing workflows and enhancing service capabilities. Furthermore, information security and data privacy protection play a crucial role in this area, ensuring the security and protection of sensitive patient information.

[0003] The cloud computing-based patient information query system utilizes cloud computing technology to build a centralized platform for efficient query and management of patient information. The system addresses technical aspects such as data storage and retrieval, information sharing and collaboration, access control, and permission management. Through a cloud computing architecture, data interoperability between different medical institutions is achieved, facilitating the sharing of patient information more conveniently. This system utilizes a user interface and cloud server connection, allowing medical personnel to access patients' electronic medical records and related health records at any time with authorization. Furthermore, the system implements automated data backup to ensure data integrity and durability.

[0004] Existing technologies rely on centralized cloud platforms to integrate medical data. Multi-source, heterogeneous data lacks deep cleansing and standardization, leading to redundant data that consumes storage resources. Differences in data formats between institutions can easily lead to analytical biases. For example, inconsistent test result units can lead to misjudgments. Traditional encryption mechanisms are designed only for static data and lack dynamic trust assessment of real-time access behavior. This makes it difficult to promptly identify potential threats when frequent, unconventional query requests occur, increasing the risk of data leakage. For example, malicious users exploiting legitimate permissions to download sensitive information in bulk. Permission management utilizes a fixed hierarchical strategy, making it difficult to adapt to the complex and changing access scenarios of remote diagnosis and treatment. Abnormal operations require manual intervention and response delays, making it difficult to promptly block high-risk operations. For example, unauthorized access during cross-regional consultations is difficult to trace. Case fit analysis relies on matching based on a fixed rule base, lacking a feedback-driven association strength adjustment mechanism. Data association accuracy relies on manual maintenance, and long-term model degradation is prone to occur. For example, emerging disease features are not promptly incorporated, leading to matching failures. Summary of the Invention

[0005] The purpose of the present invention is to solve the shortcomings of the prior art and propose a patient information query system based on cloud computing.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: a patient information query system based on cloud computing, the system comprising:

[0007] The data preprocessing module collects basic patient information from electronic health records, deduplicates and standardizes the format of multi-source data, extracts physiological indicators from clinical test data, classifies disease types according to disease classification standards, and generates a feature-standardized data set;

[0008] The feature mapping module analyzes the symptom fit based on the patient characteristics in the feature standardized data set, screens highly correlated cases in the clinical diagnosis scenario, and constructs a case fit association table;

[0009] The trust assessment module processes the patient identifier in the case fit association table using asymmetric encryption technology, sets the access request density, data integrity check value and compliance status parameters in the smart contract, and generates a dynamic trust score based on the parameter association relationship based on real-time access behavior analysis;

[0010] The permission review module performs threshold comparison based on the dynamic trust score and permission classification strategy, identifies abnormal requests in remote diagnosis and treatment scenarios through a streaming data processing mechanism, marks risky operations, and forms a permission change queue;

[0011] The feedback iteration module calls the operation records in the permission change queue, collects chronic disease management scenario feedback data, adjusts the case fit correlation strength, and generates parameter optimization indicators.

[0012] As a further solution of the present invention, the feature standardized data set includes physiological indicators and disease type classifications, the case fit association table includes symptom fit scores, high-correlation case identifiers, and feature mapping relationships, the dynamic trust score includes access request density, data integrity check value, and compliance status parameters, the permission change queue includes abnormal request marks and risk operation marks, and the parameter optimization indicators include feedback data and association strength adjustment results.

[0013] As a further solution of the present invention, the data preprocessing module includes:

[0014] The information collection submodule collects basic patient information from electronic health records, extracts the patient number, date of birth, gender, and initial diagnosis time fields, compares and removes duplicate records based on the patient number, and uses the data source identifier to identify records with the same field values ​​but different sources and removes duplicates, generating a unique patient identification value set.

[0015] The format conversion submodule extracts the numerical fields associated with clinical tests based on the patient's unique identification value set, performs name conversion, unit conversion, and format adjustment according to the field mapping rules, identifies numerical anomalies and marks missing values ​​with reference to the field preset interval, and obtains a unified indicator field set;

[0016] The feature generation submodule completes disease type matching based on the unified indicator field set, combined with disease diagnosis codes and classification standards, divides the indicators into corresponding categories based on the matching results, calls the distribution characteristics of the numerical features in each group to perform parameter conversion processing, and generates a feature standardized data set.

[0017] As a further solution of the present invention, the feature mapping module includes:

[0018] The feature extraction submodule calls symptom parameters, physical sign parameters and diagnosis and treatment records based on the patient features in the feature standardized data set, integrates the parameter data, and obtains a patient feature value set;

[0019] The fitness calculation submodule calls the feature combination between patients based on the patient feature value set, compares the values ​​of similar parameters, generates corresponding scores based on the symptom fitness interval, and obtains a fitness score data set;

[0020] The case screening submodule sets a screening threshold based on the fitness score data set, extracts patient number combinations whose scores meet the conditions, completes combination classification and number mapping, establishes a corresponding structure between numbers and scores, and obtains a case fitness association table.

[0021] As a further solution of the present invention, the trust assessment module includes:

[0022] The identification encryption submodule calls the identification information field in the current access request based on the patient identifier in the case fit association table, performs an asymmetric encryption operation, calculates the encryption strength characteristic value, extracts the encrypted ciphertext, combines the access session identifier and the parameter information to determine the identity mapping association degree, and generates an identity matching value;

[0023] The density detection submodule calls the access record parameters in the smart contract based on the identity matching value, extracts the access density field and behavior interval data, compares and analyzes the access density per unit time with the ciphertext-associated behavior interval status, and generates an access frequency difference value;

[0024] The dynamic scoring submodule extracts the data integrity check value and compliance status parameters based on the access frequency difference value, calls the behavior continuity indicator and session sequence status, determines whether the offset relationship between the behavior stability and the compliance status exceeds the verification threshold range, and obtains a dynamic trust score.

[0025] As a further solution of the present invention, the specific calculation formula for calculating the encryption strength characteristic value is:

[0026]

[0027] Among them, λ represents the dynamic adjustment factor, v represents the square root of the public key modulus, d represents the absolute value of the private key exponent, s represents the reciprocal of the product of the prime factors in the access session identifier, g represents the number of ciphertext blocks, and c represents the absolute value of the private key exponent. w Represents the encrypted value corresponding to the w-th block of ciphertext, Se represents the square root of the public key prime number Se, q represents the cube root of the public key prime number q, and ‖Se·q‖ represents the absolute value of the product of the public key prime number Se and q.

[0028] As a further solution of the present invention, the authority review module includes:

[0029] Based on the dynamic trust score value, the behavioral trust assessment submodule extracts trust parameter features from the source address, access time period, and identity credential information in the remote diagnosis and treatment request. It combines the time difference, frequency change, and identity matching status in similar parameter groups to calculate a comprehensive evaluation index, determine the change range and fluctuation trend of the trust score, and generate a dynamic trust deviation value.

[0030] The threshold comparison submodule determines the degree of deviation based on the dynamic trust deviation value and the control interval set in the permission classification strategy, extracts the permission deviation characteristics based on the permission level and operation limit of the current request, completes the intervention trigger signal identification, and generates the permission deviation intervention coefficient;

[0031] The operation marking submodule makes status judgment based on the permission offset intervention coefficient and the risk identification benchmark of the corresponding permission level, identifies the instruction type, target module and parameter characteristics in the operation content, screens the operation combination that triggers the risk judgment conditions, uniformly records them as risk operation information, and generates the permission change queuing rate.

[0032] As a further solution of the present invention, the specific calculation formula for calculating the comprehensive evaluation index is:

[0033]

[0034] Among them, H represents the comprehensive evaluation index, α represents the adjustment coefficient of the time difference in the similar parameter group, β represents the weight factor of the frequency change, Δt avg Represents the average absolute value of the time difference between adjacent accesses to the same source address, Δt k Represents the absolute value of the time difference between the kth adjacent accesses, Δf std represents the absolute value of the standard deviation of the number of requests within the same access time period, γ represents the denominator smoothing factor, δ represents the correction coefficient of identity matching, and s matchIndicates the matching percentage between the identity credential and the preset template.

[0035] As a further solution of the present invention, the feedback iteration module includes:

[0036] The permission record submodule extracts the operation time, interface number and user identity based on the permission change queue rate, identifies the call frequency and execution status of the same module in different time periods, and filters the frequent calls and abnormal operations in the operation behavior based on the identity, and generates a call abnormality ratio value;

[0037] The feedback aggregation submodule extracts the chronic disease label and management process identifier in the standardized feedback interface based on the call abnormality ratio value, calculates the discrete trend value of the process feedback, classifies the feedback frequency and feedback intensity under the same process, establishes the correlation distribution between the feedback item and the label, and generates the feedback intensity density coefficient;

[0038] The fitting adjustment submodule calls the sample information and parameter records of the feedback intensity density coefficient, compares the characteristic parameters in the sample with the changes in feedback intensity, adjusts the original correlation settings according to the parameter range between similar features, and generates parameter optimization indicators.

[0039] As a further solution of the present invention, the specific calculation formula for the discrete trend value fed back by the calculation process is:

[0040]

[0041] Among them, Z represents the feedback frequency normalization factor corresponding to the chronic disease label, B represents the feedback intensity adjustment coefficient of the management process identification, γ represents the cross-interference compensation amount between processes, and f i Represents the feedback frequency value recorded in the i-th standardized feedback interface, μ f Represents the arithmetic mean of the p-time feedback frequency in the current process, s j represents the quantified feedback strength value in the jth standardized feedback interface, p represents the total number of feedback interface calls in the current process, and m represents the number of valid strength records in the current process.

[0042] Compared with the prior art, the advantages and positive effects of the present invention are:

[0043] In the present invention, by integrating multi-source data and deduplicating and standardizing based on a distributed architecture, redundant interference and format differences are eliminated, the consistency of basic data is improved, and the disease classification standards are combined to achieve accurate hierarchical mapping of physiological indicators and disease types, providing a reliable analysis benchmark for cross-institutional collaboration. A parallel computing architecture is used to accelerate symptom fit analysis, screen highly correlated cases to improve clinical diagnosis efficiency and accuracy, and shorten the decision-making cycle for complex cases. Through asymmetric encryption combined with a dynamic trust scoring mechanism, access density, data integrity and compliance status are monitored in real time, and static security rules are upgraded to a real-time behavior-driven dynamic protection system to block the risk of abnormal data leakage. Streaming data processing identifies abnormal requests in remote diagnosis and treatment scenarios, and automatically triggers threshold comparisons in combination with permission grading strategies, marking high-risk operations in real time and adjusting access rights to solve the lag problem of traditional manual review. The standardized feedback interface continuously collects chronic disease management data, and the closed-loop iteration optimizes the case correlation strength, enhances the model's adaptability, and balances data sharing efficiency and security requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0045] Figure 1 is a system flow chart of the present invention;

[0046] Figure 2 Schematic diagram of the system framework of the present invention;

[0047] Figure 3 This is a flow chart of the data preprocessing module of the present invention;

[0048] Figure 4 This is a flow chart of the feature mapping module of the present invention;

[0049] Figure 5 is a flow chart of the trust assessment module of the present invention;

[0050] Figure 6 This is a flow chart of the authority review module of the present invention;

[0051] Figure 7 This is a flowchart of the feedback iteration module of the present invention. DETAILED DESCRIPTION

[0052] The technical solution of the present invention is described below in conjunction with the accompanying drawings.

[0053] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.

[0054] In the embodiments of the present invention, the terms "image" and "picture" may be used interchangeably. It should be noted that, when the distinction between them is not emphasized, their intended meanings are the same. The terms "of," "corresponding," and "corresponding" may be used interchangeably. It should be noted that, when the distinction between them is not emphasized, their intended meanings are the same.

[0055] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.

[0056] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0057] See also Figure 1 ,Patient information query system based on cloud computing, the system includes:

[0058] The data preprocessing module collects basic patient information from electronic health records, performs multi-source data deduplication and format standardization through a distributed storage architecture, extracts physiological indicators from clinical test data, classifies disease types according to disease classification standards, and generates feature-standardized data sets;

[0059] The feature mapping module uses a parallel computing architecture to perform symptom fit analysis based on patient features in the feature-normalized dataset, screens highly correlated cases in clinical diagnosis scenarios, and constructs a case fit correlation table.

[0060] The trust assessment module uses asymmetric encryption technology to process patient identifiers in the case fit association table, sets access request density, data integrity check value, and compliance status parameters in the smart contract, and generates a dynamic trust score based on the parameter association relationship based on real-time access behavior analysis;

[0061] The permission review module performs threshold comparison based on dynamic trust scores and permission classification policies. It uses a streaming data processing mechanism to identify abnormal requests in remote diagnosis and treatment scenarios, mark risky operations, and form a permission change queue.

[0062] The feedback iteration module calls the operation records in the permission change queue, collects feedback data of chronic disease management scenarios through the standardized feedback interface, adjusts the correlation strength of case fit, and generates parameter optimization indicators.

[0063] The feature standardization data set includes physiological indicators and disease type classification. The case fit association table includes symptom fit score, high-correlation case identification, and feature mapping relationship. The dynamic trust score includes access request density, data integrity check value, and compliance status parameters. The permission change queue includes abnormal request tags and risk operation tags. The parameter optimization indicators include feedback data and association strength adjustment results.

[0064] See also Figure 2 and Figure 3 ,The data preprocessing module includes information acquisition submodule, format conversion submodule, and feature generation submodule;

[0065] The information collection submodule collects basic patient information from electronic health records, extracts the patient number, date of birth, gender, and initial diagnosis time fields, compares and removes duplicate records based on the patient number, and uses the data source identifier to identify records with the same field values ​​but different sources and removes duplicates, generating a unique patient identification value set.

[0066] First, extract the patient number, date of birth, gender and time of first visit from the structured or semi-structured archival files. The data format includes XML, JSON or HL7 types. When extracting, locate the corresponding fields through keyword recognition and field mapping rules. For example, the identification tag contains "Patient_ID" as the number, "DOB" for date of birth, etc. After obtaining the field, construct it into a preliminary patient information table. If a number corresponds to multiple records, check whether there are redundant records by comparing field by field. The standard for judging duplication is that the number is the same and the date of birth, gender and time of first visit are consistent. If there is inconsistency in the field, it is necessary to further introduce "data source identification" for judgment, and cross-check the records with different source identifications but the same field values. For example, when one source is a regional hospital and the other is a provincial platform, it is preferred. Keep the latter records first. If the sources are the same but there are differences in the fields, such as a difference of only 1 day in birth date and a difference of 2 days in initial diagnosis time, it can be considered as information floating and merged. Records with completely different sources but exactly the same fields are considered duplicate information. Select one of them and keep it. After removing redundant records, build a patient unique identification set. Each identification value is bound to a set of basic attributes to ensure that subsequent processes are processed consistently based on this. In actual applications, if a system receives three records numbered A123456, if the birth dates are all August 15, 1975, the genders are all male, and the initial diagnosis times are all March 1, 2022, but the sources include "outpatient HIS system", "inpatient system", and "physical examination platform", then the platform records with high information integrity and authoritative sources are retained, and a unique identification is generated for subsequent clinical data analysis and processing.

[0067] The format conversion submodule extracts the numerical fields associated with clinical tests based on the patient's unique identification value set, performs name conversion, unit conversion, and format adjustment according to the field mapping rules, identifies numerical anomalies and marks missing values ​​with reference to the field's preset interval, and obtains a unified indicator field set;

[0068] Based on the aforementioned unique identification value set, the format conversion submodule extracts the clinical test result information associated with the patient one by one, including field name, unit and test value. The original field may be expressed in different naming forms, such as "GLU", "GLUCOSE" and "blood sugar", which all point to the same test item. They are converted into standard names through the field mapping table, and the unit conversion is completed according to the preset rules, such as converting "mmol / L" to "mg / dL". After conversion, the result is uniformly retained to two decimal places, and the decimal place processing is completed by rounding. If the test result is an abnormal symbol or missing data, it is directly marked as empty or missing, and uniformly filled with "NA" to indicate missing values. Then the field reference interval is introduced to complete the numerical judgment processing, such as the standard interval of the blood sugar field is 7 0 to 110 mg / dL. If the result after conversion exceeds this range, it is marked as abnormal. The judgment standard is: a value lower than the lower limit or higher than the upper limit is abnormal. Fields such as hemoglobin, alanine aminotransferase, and urea nitrogen are processed in this way. For example, the blood glucose value in the original record is 5.6 mmol / L, which corresponds to approximately 101 mg / dL after conversion and is judged to be normal within the standard range. For example, the original record of ALT is 130 U / L, and the reference upper limit is 56 U / L, which is much higher than the upper limit and is directly marked as an abnormal value. After all fields are converted, converted, missing, and identified as abnormal, a standard field set in a unified format is generated. Each data item contains the field's Chinese standard name, unified unit, adjusted value, and abnormal status mark, which will be used as the basis for feature generation later.

[0069] The feature generation submodule matches disease types based on a unified indicator field set, combined with disease diagnosis codes and classification standards. Based on the matching results, the indicators are divided into corresponding categories, and the distribution characteristics of the numerical features in each group are used to perform parameter conversion processing to generate a feature standardized data set.

[0070] The feature generation submodule matches patients' disease classification based on clinical indicator data in a unified format and disease diagnosis codes in electronic medical records. The diagnosis codes are extracted according to the ICD-10 standard classification system. For example, E11.9 represents type 2 diabetes. After identifying the diagnosis code, the corresponding patient is classified into the corresponding disease category. Correspondingly, the fields associated with the disease are extracted from the standardized indicator set for classification. For example, the fields corresponding to diabetes include fasting blood glucose, glycosylated hemoglobin, insulin, etc. These fields are used as a group of classification indicators, and then feature conversion processing is performed on each field. The standard deviation method is used to adjust the data distribution so that each field has a unified dimension. For example, fasting blood glucose is 180 mg / dL, The average value in the corresponding diabetes sample is 100, the fluctuation range is 30, and the current value is 2.67 times higher than the average value, which can be considered a significant deviation. For some fields with large discrete fluctuations, the minimum-maximum normalization method is selected for processing, and the values ​​are classified into the interval between 0 and 1, so that the fields have a uniform distribution benchmark. The upper and lower limits are set according to the fields. For example, the ALT value range is 5 to 150, and the ALT value of a patient is 130, which is approximately equal to 0.86 after normalization. All standardized or normalized results are uniformly constructed into a feature matrix. Each row in the matrix represents a single patient, and each column represents a clinical test indicator, forming a complete standardized data structure for subsequent modeling and evaluation processes.

[0071] See also Figure 2 and Figure 4 ,The feature mapping module includes a feature extraction submodule, a ,fitting calculation submodule, and a case screening submodule;

[0072] The feature extraction submodule calls symptom parameters, physical sign parameters and diagnosis and treatment records based on the patient features in the feature standardization dataset, integrates the parameter data, and obtains the patient feature value set;

[0073] First, symptom parameters, physical sign parameters and medical records need to be extracted from the data set. Symptom parameters include cough frequency, fever degree, shortness of breath and other contents. The fever degree can be divided into mild (below 37.5℃), moderate (between 37.5℃ and 38.5℃), and severe (above 38.5℃). Physical sign parameters such as heart rate, blood pressure, and blood oxygen saturation, if there are multiple measurements in one day, can be processed by taking the median to ensure stability. For example, if a person's heart rate is recorded as 78 beats per minute, 82 beats per minute and 85 beats per minute on the same day, the median of 82 beats per minute can be used as the representative value. The medical records include Medication history, test items, hospitalization or outpatient treatment pathways, etc. are converted using a unified structured standard. For example, information on antibiotic use is uniformly marked as 1, and non-use is marked as 0. The text information is encoded and represented in combination with the ICD standard or universal drug coding to form a unified data structure. Finally, through aggregation, various parameters are integrated into a fixed-format feature set. For example, if a patient presents with moderate fever, a heart rate of 82 beats per minute, and uses antibiotics, then their feature combination can be represented as a set of standardized data, further forming a parameter value set containing all patient information, providing an input source for subsequent calculations and comparisons.

[0074] The fitness calculation submodule calls the feature combination between patients based on the patient feature value set, compares the values ​​of similar parameters, generates corresponding scores based on the symptom fitness interval, and obtains the fitness score data set;

[0075] After obtaining the feature value set of each patient, the fitting calculation submodule compares it with the similar patient group item by item. The range of similar patients can be screened according to age group, diagnostic label, and disease stage. For example, people aged 30 to 40 with the same respiratory disease are selected as the comparison objects, and each feature is compared with the samples in the control group. For fever level, if they are the same, they are scored as full marks. If there is a difference of one level, the score is halved. If the difference is too large, it is considered as mismatch and scored as 0 points. For heart rate parameters, if the difference is within 5 beats per minute, it is scored as full marks. If the difference widens to 6 to 10 beats per minute, it is only scored as full marks. Get half the score, and no points will be given if it exceeds this range; for consistent use of antibiotics, a full score can be assigned, and inconsistent scores can be assigned 0 points. All scores for each patient are accumulated and divided by the total number of features to get the patient's final fit score. For example, if a person's parameter comparison is fever level matching, heart rate deviation 5 beats per minute, and consistent antibiotic use, the corresponding scores are 1 point, 0.5 point, and 1 point, respectively, with a total score of 2.5. Divided by 3 features, the total score is 0.83. The fit of all people is calculated in this way, and a data set containing the scores of all patients is formed for subsequent screening and structure construction.

[0076] The case screening submodule sets the screening threshold based on the fit score data set, extracts the patient number combinations that meet the score conditions, completes the combination classification and number mapping, establishes the corresponding structure between the number and the score, and obtains the case fit association table;

[0077] The case screening submodule performs screening operations based on the fit score data set. First, the score screening threshold is set. The threshold can be flexibly set according to the specific goal. For example, if highly similar cases need to be screened, it can be set to 0.85. If large differences are allowed, it can be set to 0.65. After setting, the score of each patient is traversed and judged. Those who meet the threshold conditions will have their numbers included in the result combination. For example, a patient with ID_001 has a fit of 0.89 and exceeds the set threshold, then the number is retained; if another patient with ID_002 has a score of 0.61, it does not meet the conditions and needs to be excluded. In this way, all eligible numbers are screened out in turn, and a corresponding relationship is established between them and the score values, such as ID_001 corresponding to a score of 0.89, ID_005 corresponding to a score of 0.91, etc., and finally a mapping structure table is formed. This structure table presents the corresponding relationship between case numbers and their scores, which can be used for subsequent classification management, feature label grouping and other processing processes.

[0078] See also Figure 2 and Figure 5 ,The trust assessment module includes the identity encryption submodule, the density detection submodule, and the dynamic scoring submodule;

[0079] The identification encryption submodule uses the patient identifier in the case fit association table, calls the identification information field in the current access request, performs asymmetric encryption operations, calculates the encryption strength characteristic value, extracts the encrypted ciphertext, combines the access session identifier and parameter information to determine the degree of identity mapping association, and generates an identity matching value;

[0080] The specific calculation formula for calculating the encryption strength characteristic value is:

[0081]

[0082] Among them, λ represents the dynamic adjustment factor, v represents the square root of the public key modulus, d represents the absolute value of the private key exponent, s represents the reciprocal of the product of the prime factors in the access session identifier, g represents the number of ciphertext blocks, and c represents the absolute value of the private key exponent. w represents the encrypted value corresponding to the w-th block of ciphertext, Se represents the square root of the public key prime number Se, q represents the cube root of the public key prime number q, and ‖Se·q‖ represents the absolute value of the product of the public key prime number Se and q;

[0083] The dynamic adjustment factor λ is obtained by summing the prime factors of the access session identifier s. The access session identifier s monitored in this session is s=1 / (2×3×5)=0.0333, and its prime factors are 2, 3, and 5. The sum is λ=2+3+5=10.

[0084] The square root v of the public key modulus is calculated from the public key modulus N = 15, N = Se·q = 3 × 5 = 15,

[0085] The private key exponent d is monitored as d=7 through the key generation protocol, and its absolute value |d|=7.

[0086] The inverse of the prime factor product of the access session identifier s has been monitored to be s=1 / (2×3×5)=0.0333, the number of ciphertext blocks g is calculated as g=3 according to the ciphertext block rule, and the ciphertext block value c w After encryption, the data monitoring is c1=256, c2=128, and c3=512.

[0087] Square root of the public key prime number Se The cube root of the public key prime q Se·q=3×5=15, and its absolute value ‖Se·q‖=15.

[0088] Substitute the parameters to calculate the numerator

[0089]

[0090] Calculate the denominator

[0091]

[0092] Calculate the first part

[0093] Calculate the second part

[0094]

[0095] Final H σ =0.0938+3=3.0938.

[0096] The result indicates that the encryption strength characteristic value is 3.0938, which is directly related to the absolute value of the product of the public key modulus, private key exponent, ciphertext block mean, and public key prime number. The encryption strength characteristic value is used as an intermediate result to subsequently combine the access session identifier and parameter information to determine the degree of identity mapping association and generate an identity matching value.

[0097] The "encryption strength characteristic value" isn't a standard measure of encryption security in traditional cryptography; rather, it's a structural characteristic metric provided by this system for dynamic trust scoring. This value, incorporating parameters such as the public key modulus, private key exponent, ciphertext block, and session identifier, reflects the complexity and uniqueness of the encryption behavior of each access request, thereby supporting the quantitative calculation of identity matching. A higher value indicates a more trustworthy and tamper-resistant encryption behavior.

[0098] The density detection submodule calls the access record parameters in the smart contract based on the identity matching value, extracts the access density field and behavior interval data, compares and analyzes the access density per unit time and the ciphertext-associated behavior interval status, and generates an access frequency difference value;

[0099] After receiving the identity matching value, the density detection submodule calls the access record parameter information stored in the smart contract, selects the timestamp, operation event, and device information recorded in the access behavior, and calculates the access frequency within a unit time window. For example, if there are 18 access behaviors in an hour, the access density is 0.005 times per second. It also extracts the operation time difference recorded in the encrypted log. For example, if the time interval between three consecutive behaviors is 18 seconds and 31 seconds, the average behavior interval is 24.5 seconds. The difference between access density and behavior interval is further compared with the average access density of similar identities in historical access data, for example, 0.003 times per second. By calculating the deviation ratio, it is concluded that the deviation between the current access behavior and the average density is 66.67%. Furthermore, the volatility of the behavior interval series is evaluated, the variance of the behavior interval is calculated, and the volatility level in the historical sample is compared. Finally, corresponding weights are set according to the degree of deviation in access frequency and the level of fluctuation in behavior intervals. For example, access frequency accounts for 70% and behavior intervals account for 30%. The two are weighted and combined to generate an access frequency difference value, which is used to measure the regularity and consistency of access behavior. If the value reaches 13 or above, it means that the access behavior is significantly deviated from expectations.

[0100] The dynamic scoring submodule extracts the data integrity check value and compliance status parameters based on the access frequency difference value, calls the behavior continuity indicator and session sequence status, and determines whether the offset relationship between behavior stability and compliance status exceeds the verification threshold range to obtain a dynamic trust score;

[0101] The dynamic scoring submodule receives the access frequency difference value and combines it with data integrity verification information, such as hash code comparison results and compliance status parameters, such as whether unauthorized field operations exist. It then extracts behavioral continuity indicators, including jumps in the behavioral sequence and the integrity of the operation process. It then analyzes the degree of difference between the access session's behavioral sequence and the reference sequence. For example, if the reference sequence contains four steps, while the current session only performs three steps, missing an edit step, the operation deviation rate is calculated as 25%. If the deviation rate exceeds the set threshold of 20%, the behavior is considered discontinuous. The access frequency difference is also normalized. For example, if the standard range is 0 to 20 and the current value is 13, the normalized value is 85%. The dynamic scoring is based on multiple dimensions, including behavioral stability, access frequency rationality, and data integrity compliance. These are weighted and added together in a 40%, 40%, and 20% ratio to form the final dynamic trust score. For example, if the behavioral sequence continuity is 75%, the frequency rationality is 15%, and the data integrity is acceptable, the final score is 56, which reflects the overall trustworthiness of the current access behavior based on these multiple factors.

[0102] See also Figure 2 and Figure 6 ,The permission audit module includes a trust assessment submodule, a threshold comparison submodule, and an ,operation marking submodule;

[0103] The behavioral trust assessment submodule extracts trust parameter features from the source address, access time period, and identity credential information in remote diagnosis and treatment requests based on dynamic trust scores. It then combines the time differences, frequency changes, and identity matching status of similar parameter groups to calculate comprehensive evaluation indicators, determine the magnitude of changes and fluctuation trends in the trust scores, and generate a dynamic trust offset value.

[0104] The specific calculation formula for the comprehensive evaluation index is:

[0105]

[0106] Among them, H represents the comprehensive evaluation index, α represents the adjustment coefficient of the time difference in the similar parameter group, β represents the weight factor of the frequency change, Δt avg Represents the average absolute value of the time difference between adjacent accesses to the same source address, Δt k Represents the absolute value of the time difference between the kth adjacent accesses, Δf std represents the absolute value of the standard deviation of the number of requests within the same access time period, γ represents the denominator smoothing factor, δ represents the correction coefficient of identity matching, and s match Represents the matching percentage between the identity credential and the preset template;

[0107] Parameter setting and data acquisition:

[0108] When calculating comprehensive evaluation indicators, the "Source Address", "Access Time Period", and "Identity Credential Information" fields are used in modeling in the following ways:

[0109] The access behavior differences of source addresses are indirectly reflected by the “time difference (Ti)” and its mean (ΔT);

[0110] The access time period affects the request frequency fluctuation, which is reflected in the "Standard Deviation of Request Count (σ)";

[0111] The matching degree and credibility of the identity certificate are expressed by "matching percentage (M)" and "correction coefficient (ε)";

[0112] α is the time difference adjustment coefficient, which is set to 0.8 based on the average contribution of time difference to trust score in historical data analysis;

[0113] β is the weight factor for frequency change, which is calibrated to 0.5 based on the sensitivity experiment of request frequency change;

[0114] Δt avg The average of the absolute values ​​of the time differences between adjacent accesses to the same source address is calculated by monitoring three consecutive access timestamps (e.g., 09:00, 09:05, 09:12) with adjacent intervals of |5| minutes and |7| minutes. minute; is the sum of the absolute values ​​of adjacent time differences, i.e. 5+7=12 minutes;

[0115] Δf std is the absolute value of the standard deviation of the number of requests in the same access time period. For example, if the number of requests in a certain time period is 20, 25, and 18, the mean μ is calculated to be 21, and the variance Standard deviation

[0116] γ is the denominator smoothing factor, which is set to 1.2 to avoid the denominator being zero and to balance the numerical range;

[0117] δ is the correction coefficient of identity matching, which is set to 0.4 based on the nonlinear effect of matching on trust score;

[0118] s match The percentage of matching between the identity credential and the preset template is calculated based on the character similarity between the preset template fields (such as name, ID number) and the actual input content, for example, a matching degree of 85%.

[0119] Formula calculation derivation process:

[0120] Time difference calculation:

[0121]

[0122] Frequency and identity match calculations:

[0123]

[0124] Comprehensive evaluation index H:

[0125] H=0.632+0.0506≈0.6826;

[0126] Result description:

[0127] The results indicate that the comprehensive evaluation index H is 0.6826, reflecting the combined impact of time differences and frequency changes. Identity matching corrects for the impact of frequency changes through the denominator. The numerical result H serves as an intermediate parameter, correlated with the magnitude and fluctuation trend of the trust score in the original paragraph. A dynamic trust offset value is generated through threshold determination or weighted fusion.

[0128] The threshold comparison submodule determines the degree of deviation based on the dynamic trust deviation value and the control interval set in the permission classification strategy. It extracts the permission deviation characteristics based on the permission level and operation limit of the current request, completes the intervention trigger signal identification, and generates the permission deviation intervention coefficient.

[0129] The threshold comparison submodule evaluates whether there is a permission deviation problem in the current request based on the received trust deviation value and the interval setting in the permission classification strategy. First, the permission level corresponding to the current access user is clarified. For example, if a permission level is medium, the upper limit of the corresponding operation behavior is 5 times per hour, and the trust deviation control interval allowed by this level is set to between 0 and 0.25. When the received trust deviation value is higher than the upper limit of this range, for example, 0.495, it can be confirmed that the request has exceeded the control tolerance. Then, the specific operation content of this request is analyzed, such as accessing medical records, modifying records, accessing For operations such as external platforms, each operation is assigned a different weight value based on its sensitivity. For example, the weight of medical record retrieval is 0.2, the weight of record modification is 0.3, and the weight of external platform access is 0.4. These operation weights are summarized and compared with the set operation upper limit to calculate the proportion of the current request within the operation capability range. This proportion is then multiplied by the degree of deviation to obtain a numerical value for quantifying the intervention level. When this value exceeds the authority intervention judgment benchmark, it indicates that the request not only has a trust deviation, but also triggers the authority intervention condition. Therefore, the system marks it with the authority deviation status and further uses it to identify risky operations.

[0130] The operation marking submodule makes status judgments based on the permission deviation intervention coefficient and the risk identification benchmark of the corresponding permission level, identifies the instruction type, target module and parameter characteristics in the operation content, selects the operation combination that triggers the risk judgment conditions, uniformly records them as risk operation information, and generates the permission change queue rate;

[0131] First, based on the permission level of the requesting user, find the risk identification benchmark value set at that level and make a preliminary judgment. For example, if the current permission level benchmark is 0.04 and the estimated coefficient is 0.0441, which is higher than the benchmark value, the operation content identification process is started, and the operation instructions contained in the request are analyzed item by item to identify whether they contain highly sensitive behavior types, such as deletion, batch export, remote writing, etc. Operation instructions will be marked separately; then analyze the system modules corresponding to these operations, such as whether they involve core systems such as image data management, inspection data system or third-party interface platform, and then set a risk score for each operation, such as exporting medical records is 0 .1, writing medical records is 0.05, and accessing third-party data is 0.12. These score values ​​are summarized. If the total value is higher than the pre-set risk judgment threshold, for example, higher than 0.2, then this request is considered a risk operation combination. Subsequently, the relevant information such as operation time, request identity, target module code, etc. are organized into standardized record entries and written into the risk operation log. At the same time, the number of requests with permission intervention records in the current operation queue is counted. For example, there are 8 requests in the current queue, 3 of which have been marked as intervention status, and the current permission change queue rate is 37.5%, which is used to further schedule resources or trigger blocking strategies.

[0132] See also Figure 2 and Figure 7 ,The feedback iteration module includes the authority recording submodule, the feedback collection submodule, and the ,fitness adjustment submodule;

[0133] The permission record submodule extracts the operation time, interface number, and user identity based on the permission change queue rate, identifies the call frequency and execution status of the same module in different time periods, and uses the identity to filter frequent calls and abnormal operations in the operation behavior to generate a call abnormality ratio value;

[0134] First, it is necessary to extract information including time, interface number and user identity from the operation log. The operation time is recorded in a unified format, the interface number is uniquely numbered according to the function, and the user identity is matched to the individual operation source through coding. Then, a time series based on the operation time is constructed, and the interface records under the same module are grouped into ten-minute intervals. The total number of interface calls and the corresponding execution status in each time period are counted separately. The execution status is distinguished by the return code. The return code of 200 represents success, and 400 and above represent abnormality. By calculating the changes in the number of calls and the proportion of abnormal status in adjacent time periods, the time when fluctuations in call frequency or execution status occur can be identified. For each segment, the identification threshold is set to a change in call frequency of more than 5 times, or a fluctuation in the abnormal proportion of more than 10%. In the identified fluctuation period, high-frequency call subjects are screened out based on user identity identification. The calculation standard is that the number of calls in this segment exceeds 1.5 times the average value of the past seven days. The number of calls and abnormal calls of all interfaces of such subjects in this segment are summarized, and the total number of calls and the number of abnormal calls are counted respectively. The abnormal ratio is obtained by dividing the number of abnormal calls by the total number of calls. For example, within ten minutes, a user calls an interface 20 times, of which 4 are abnormal, then the abnormal ratio is 20%. Finally, this abnormal ratio is summarized by interface, module and time dimensions, and a multi-dimensional record list is established for subsequent processing.

[0135] The feedback aggregation submodule extracts chronic disease labels and management process identifiers from the standardized feedback interface based on the call anomaly ratio value, calculates the discrete trend value of process feedback, categorizes the feedback frequency and feedback intensity under the same process, establishes the correlation distribution between feedback items and labels, and generates the feedback intensity density coefficient;

[0136] The specific calculation formula for the discrete trend value of the calculation process feedback is:

[0137]

[0138] Among them, Z represents the feedback frequency normalization factor corresponding to the chronic disease label, B represents the feedback intensity adjustment coefficient of the management process identification, γ represents the cross-interference compensation amount between processes, and f i Represents the feedback frequency value recorded in the i-th standardized feedback interface, μ f Represents the arithmetic mean of the p-time feedback frequency in the current process, s j represents the quantified feedback strength value in the jth standardized feedback interface, p represents the total number of feedback interface calls in the current process, and m represents the number of valid strength records in the current process;

[0139] The parameter values ​​in the formula are obtained in the following ways:

[0140] The Z value is 0.8, which is calculated based on the proportion of chronic disease label feedback frequency in historical data. E = total chronic disease label feedback frequency / total all label feedback frequency. The historical data statistical period is 30 days, the total feedback frequency is 120 times, and the total all label feedback frequency is 150 times. Therefore, E = 120 / 150 = 0.8;

[0141] The value of B is 0.3, which is determined by the weight coefficient of the management process identification. The management process identification is divided into three levels: high, medium, and low. The current process has a medium priority and a weight coefficient of 0.3;

[0142] The value of γ is 0.5. It is calculated based on the monitoring data of the interaction frequency between processes. The interaction frequency is 10 times / day. γ = interaction frequency × 0.05;

[0143] The value of p is 5. The total number of calls to the standardized feedback interface in the current process is 5 according to the system log statistics.

[0144] The value of m is 4, and the number of valid intensity records in the current process is 4 according to the system log statistics;

[0145] f i The values ​​are obtained through standardized feedback interface recording, and the five feedback frequency values ​​are 3, 5, 4, 6, and 2 respectively;

[0146] s j The values ​​are converted using the interface quantization rules, and the four feedback strength values ​​are 1.2, 1.5, 0.8, and 1.0 respectively.

[0147] The calculation steps are as follows:

[0148] μ f =(3+5+4+6+2) / 5=4;

[0149]

[0150] Z=4.8 / 1.449≈3.31.

[0151] The results show that the process feedback discrete trend value is 3.31, which is positively correlated with the distribution dispersion of feedback frequency and intensity. A larger H value indicates a more dispersed feedback distribution and a lower density. The calculated H value is used as an intermediate parameter to subsequently generate the feedback intensity density coefficient. The density status is determined by comparing the H value with a preset threshold (e.g., 2.5).

[0152] The "Feedback Frequency Normalization Factor (Z)" is a standardized metric used to measure the proportion of all feedback items for a specific chronic disease tag. This factor allows for a uniform comparison of feedback frequencies across different tags. It serves as an important reference for measuring feedback density. A higher Z value indicates a more frequent occurrence of the tag in feedback data, and thus a higher level of credibility and attention.

[0153] The fitness adjustment submodule calls the sample information and parameter records under the label associated with the feedback intensity density coefficient, compares the changes in the characteristic parameters and feedback intensity in the sample, adjusts the original association settings according to the parameter range between similar features, and generates parameter optimization indicators;

[0154] The fit adjustment submodule extracts sample records under the chronic disease tags associated with the feedback intensity and density coefficients, including various characteristic parameters such as systolic blood pressure, diastolic blood pressure, compliance rate, and frequency of follow-up visits. The mean and variation of the characteristic parameters of each sample are summarized for each tag, and the variation level is determined by the ratio of the standard deviation to the mean. For example, if the mean systolic blood pressure is 135 mmHg and the standard deviation is 12, the coefficient of variation for this item is 0.089. Samples under the high-intensity feedback process are compared with the standard sample, and anomalies are determined based on the mean difference and the significance of the difference. If a characteristic value deviates significantly or the result is statistically significant, the characteristic is marked as a candidate for adjustment. Weights are then assigned based on the stability of the characteristic parameters, with those with smaller variation receiving higher weights. The original parameter range is then adjusted, and the adjustment range is controlled by the feedback intensity. For example, if the feedback intensity and density coefficient is 6.4 and the original range is 70% to 100%, the upper limit is reduced to 92% based on the set ratio, forming a new range of 70% to 92%. Finally, a list of adjusted parameter settings is generated based on the chronic disease tag for subsequent matching.

[0155] Analysis of the encryption strength characteristic value, feedback frequency normalization factor (Z), and comprehensive evaluation index mentioned in the specification:

[0156] Encryption strength characteristic value: represents the complexity and structural characteristics of asymmetric encryption behavior in access requests, and is used for identity matching calculation in dynamic trust models;

[0157] Feedback frequency normalization factor (Z): represents the frequency ratio of a specific tag in all feedback items, used to evaluate feedback representativeness;

[0158] Comprehensive evaluation index: A comprehensive credibility index calculated by integrating factors such as time difference, access frequency, and identity matching, which is used for subsequent permission review.

[0159] It should be understood that the term "and / or" as used herein simply describes the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0160] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0161] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0162] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0163] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0164] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of the device or unit, which can be electrical, mechanical or other forms.

[0165] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0166] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0167] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0168] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. The patient information query system based on cloud computing is characterized by: The system comprises: The data preprocessing module collects basic patient information from electronic health records, deduplicates and standardizes the format of multi-source data, extracts physiological indicators from clinical test data, classifies disease types according to disease classification standards, and generates a feature-standardized data set; The feature mapping module analyzes the symptom fit based on the patient characteristics in the feature standardized data set, screens highly correlated cases in the clinical diagnosis scenario, and constructs a case fit association table; The trust assessment module processes the patient identifier in the case fit association table using asymmetric encryption technology, sets the access request density, data integrity check value and compliance status parameters in the smart contract, and generates a dynamic trust score based on the parameter association relationship based on real-time access behavior analysis; The permission review module performs threshold comparison based on the dynamic trust score and permission classification strategy, identifies abnormal requests in remote diagnosis and treatment scenarios through a streaming data processing mechanism, marks risky operations, and forms a permission change queue; The feedback iteration module calls the operation records in the permission change queue, collects chronic disease management scenario feedback data, adjusts the case fit correlation strength, and generates parameter optimization indicators.

2. The patient information query system based on cloud computing according to claim 1, characterized in that: The feature standardized data set includes physiological indicators and disease type classifications; the case fit association table includes symptom fit scores, highly correlated case identifiers, and feature mapping relationships; the dynamic trust score includes access request density, data integrity check value, and compliance status parameters; the permission change queue includes abnormal request marks and risk operation marks; and the parameter optimization indicators include feedback data and association strength adjustment results.

3. The patient information query system based on cloud computing according to claim 1, characterized in that: The data preprocessing module includes: The information collection submodule collects basic patient information from electronic health records, extracts the patient number, date of birth, gender, and initial diagnosis time fields, compares and removes duplicate records based on the patient number, and uses the data source identifier to identify records with the same field values ​​but different sources and removes duplicates, generating a unique patient identification value set. The format conversion submodule extracts the numerical fields associated with clinical tests based on the patient's unique identification value set, performs name conversion, unit conversion, and format adjustment according to the field mapping rules, identifies numerical anomalies and marks missing values ​​with reference to the field preset interval, and obtains a unified indicator field set; The feature generation submodule completes disease type matching based on the unified indicator field set, combined with disease diagnosis codes and classification standards, divides the indicators into corresponding categories based on the matching results, calls the distribution characteristics of the numerical features in each group to perform parameter conversion processing, and generates a feature standardized data set.

4. The patient information query system based on cloud computing according to claim 3, characterized in that: The feature mapping module includes: The feature extraction submodule calls symptom parameters, physical sign parameters and diagnosis and treatment records based on the patient features in the feature standardized data set, integrates the parameter data, and obtains a patient feature value set; The fitness calculation submodule calls the feature combination between patients based on the patient feature value set, compares the values ​​of similar parameters, generates corresponding scores based on the symptom fitness interval, and obtains a fitness score data set; The case screening submodule sets a screening threshold based on the fitness score data set, extracts patient number combinations whose scores meet the conditions, completes combination classification and number mapping, establishes a corresponding structure between numbers and scores, and obtains a case fitness association table.

5. The cloud computing-based patient information query system according to claim 4, characterized in that: The trust evaluation module includes: The identification encryption submodule calls the identification information field in the current access request based on the patient identifier in the case fit association table, performs an asymmetric encryption operation, calculates the encryption strength characteristic value, extracts the encrypted ciphertext, combines the access session identifier and the parameter information to determine the identity mapping association degree, and generates an identity matching value; The density detection submodule calls the access record parameters in the smart contract based on the identity matching value, extracts the access density field and behavior interval data, compares and analyzes the access density per unit time with the ciphertext-associated behavior interval status, and generates an access frequency difference value; The dynamic scoring submodule extracts the data integrity check value and compliance status parameters based on the access frequency difference value, calls the behavior continuity indicator and session sequence status, determines whether the offset relationship between the behavior stability and the compliance status exceeds the verification threshold range, and obtains a dynamic trust score.

6. The cloud computing-based patient information query system according to claim 5, characterized in that: The specific calculation formula for calculating the encryption strength characteristic value is: Among them, λ represents the dynamic adjustment factor, v represents the square root of the public key modulus, d represents the absolute value of the private key exponent, s represents the reciprocal of the product of the prime factors in the access session identifier, g represents the number of ciphertext blocks, and c represents the absolute value of the private key exponent. w Represents the encrypted value corresponding to the w-th block of ciphertext, Se represents the square root of the public key prime number Se, q represents the cube root of the public key prime number q, and ||Se·q|| represents the absolute value of the product of the public key prime number Se and q.

7. The patient information query system based on cloud computing according to claim 5, characterized in that: The authority review module includes: Based on the dynamic trust score value, the behavioral trust assessment submodule extracts trust parameter features from the source address, access time period, and identity credential information in the remote diagnosis and treatment request. It combines the time difference, frequency change, and identity matching status in similar parameter groups to calculate a comprehensive evaluation index, determine the change range and fluctuation trend of the trust score, and generate a dynamic trust deviation value. The threshold comparison submodule determines the degree of deviation based on the dynamic trust deviation value and the control interval set in the permission classification strategy, extracts the permission deviation characteristics based on the permission level and operation limit of the current request, completes the intervention trigger signal identification, and generates the permission deviation intervention coefficient; The operation marking submodule makes status judgment based on the permission offset intervention coefficient and the risk identification benchmark of the corresponding permission level, identifies the instruction type, target module and parameter characteristics in the operation content, screens the operation combination that triggers the risk judgment conditions, uniformly records them as risk operation information, and generates the permission change queuing rate.

8. The patient information query system based on cloud computing according to claim 7, characterized in that: The specific calculation formula for calculating the comprehensive evaluation index is: Among them, H represents the comprehensive evaluation index, α represents the adjustment coefficient of the time difference in the similar parameter group, β represents the weight factor of the frequency change, Δt avg Represents the average absolute value of the time difference between adjacent accesses to the same source address, Δt k Represents the absolute value of the time difference between the kth adjacent accesses, Δf std represents the absolute value of the standard deviation of the number of requests within the same access time period, γ represents the denominator smoothing factor, δ represents the correction coefficient of identity matching, and s match Indicates the matching percentage between the identity credential and the preset template.

9. The patient information query system based on cloud computing according to claim 7, characterized in that: The feedback iteration module includes: The permission record submodule extracts the operation time, interface number and user identity based on the permission change queue rate, identifies the call frequency and execution status of the same module in different time periods, and filters the frequent calls and abnormal operations in the operation behavior based on the identity, and generates a call abnormality ratio value; The feedback aggregation submodule extracts the chronic disease label and management process identifier in the standardized feedback interface based on the call abnormality ratio value, calculates the discrete trend value of the process feedback, classifies the feedback frequency and feedback intensity under the same process, establishes the correlation distribution between the feedback item and the label, and generates the feedback intensity density coefficient; The fitting adjustment submodule calls the sample information and parameter records of the feedback intensity density coefficient, compares the characteristic parameters in the sample with the changes in feedback intensity, adjusts the original correlation settings according to the parameter range between similar features, and generates parameter optimization indicators.

10. The patient information query system based on cloud computing according to claim 9, characterized in that: The specific calculation formula for the discrete trend value fed back by the calculation process is: Among them, Z represents the feedback frequency normalization factor corresponding to the chronic disease label, B represents the feedback intensity adjustment coefficient of the management process identification, γ represents the cross-interference compensation amount between processes, and f i Represents the feedback frequency value recorded in the i-th standardized feedback interface, μ f Represents the arithmetic mean of the p-time feedback frequency in the current process, s j represents the quantified feedback strength value in the jth standardized feedback interface, p represents the total number of feedback interface calls in the current process, and m represents the number of valid strength records in the current process.