Medical information sharing system and method based on medical devices

By constructing a medical information sharing system based on medical devices and employing encryption technology and access control, the problems of low efficiency in information exchange and privacy leaks of medical devices have been solved. This has enabled real-time sharing and secure access to medical information, thereby improving treatment outcomes and patient satisfaction.

CN120748602BActive Publication Date: 2025-12-05KONUO INTERNET OF THINGS TECH (SHANDONG) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511262403.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2025-12-05
Estimated Expiration
2045-09-05

AI Technical Summary

Technical Problem

Inefficient information exchange between medical devices, serious compatibility issues, high risk of patient privacy leaks, and ineffective interconnection of medical resources all negatively impact treatment outcomes.

Method used

A medical information sharing system based on medical devices is constructed, and encryption technology is used to store and transmit medical data. Real-time information sharing and collaborative diagnosis and treatment are realized through a management center, device acquisition module, data processing module, information analysis module and intelligent sharing module. Asymmetric encryption and encoding are used for double encryption, and access control is constructed through permission channels.

Benefits of technology

It enables real-time sharing of medical information and collaborative diagnosis and treatment, protects patient privacy, prevents unauthorized access and leakage, improves access control flexibility, and promotes the progress of medical informatization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120748602B_ABST
    Figure CN120748602B_ABST
Patent Text Reader

Abstract

The application discloses a medical information sharing system and method based on medical equipment, relates to the technical field of medical information processing, and comprises a management center, wherein the management center is connected with an equipment acquisition module, a data processing module, an information analysis module and an intelligent sharing module; an original cloud platform is constructed to perform first-layer encryption on collected medical equipment data, and a key set is obtained; medical equipment information is double-encrypted and updated based on the key set, and a cloud exchange platform is obtained; a channel permission of the cloud exchange platform is constructed, and an information flow channel is obtained; access information of an exchange user end is assimilated through the information flow channel, access ciphertext coding is obtained, the access ciphertext coding is matched and decrypted through the cloud exchange platform, and target sharing information is obtained; the data security is enhanced, the quality and efficiency of medical services are improved, and the overall development of the medical industry is promoted.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of medical information processing, in particular to a medical information sharing system and method based on medical equipment. BACKGROUND

[0002] With the rapid development of medical technology, various medical equipment is increasingly widely used in medical institutions. In the past, the exchange of information between medical equipment mainly relied on manual operation, which was low in efficiency and prone to errors, and the existing medical information system had the following problems: compatibility problems between medical equipment; patient privacy information was easily leaked in the process of medical information sharing, which posed a safety hazard to patients; there was a lack of effective information interconnection and intercommunication mechanism between medical equipment, resulting in insufficient utilization of medical resources and affecting the diagnosis and treatment effect.

[0003] In view of the above problems, the present application provides a medical information sharing system and method based on medical equipment, which uses encryption technology to encrypt and store medical data, ensures the safety of patient privacy information, integrates various encrypted medical equipment on one platform, realizes real-time sharing and collaborative diagnosis and treatment of medical information, and helps to improve the diagnosis and treatment level of medical institutions, reduce medical costs, improve patient satisfaction, promote the construction of medical informatization in China, and lay a foundation for the development of future smart medical care. SUMMARY

[0004] The purpose of the present application is to provide a medical information sharing system and method based on medical equipment to solve the problems of data sharing security, patient medical information leakage and communication process disorder mentioned in the background.

[0005] The medical information sharing system based on medical equipment comprises a management center, wherein the management center is connected with a device acquisition module, a data processing module, an information analysis module and an intelligent sharing module;

[0006] The device acquisition module is used for acquiring medical equipment information and constructing an original cloud platform.

[0007] The data processing module is used for first-layer encryption of medical equipment data based on the original cloud platform, obtaining a key set, wherein the key set comprises a public key set and a private key set.

[0008] The medical equipment information is one-time encrypted based on the key set, obtaining device initial ciphertext, and the device initial ciphertext is double-updated through the original cloud platform, obtaining a cloud exchange platform.

[0009] The information analysis module is used for constructing a permission channel for the cloud exchange platform, obtaining a hidden flow channel, and performing permission identification based on the hidden flow channel, obtaining an information flow channel.

[0010] The intelligent sharing module is used for information assimilation of the access terminal through the information flow channel, obtaining access ciphertext coding, range matching of the access ciphertext coding of the access terminal through the cloud exchange platform, obtaining the paired device ciphertext, channel decryption of the paired device ciphertext based on the information flow channel, and obtaining the target shared information.

[0011] Preferably, the process of collecting medical equipment information includes:

[0012] Collecting and setting the medical equipment to obtain an information collection terminal;

[0013] Collecting data of the medical equipment through the information collection terminal to obtain medical equipment information;

[0014] According to the obtained medical equipment information, an original cloud platform is constructed, and the obtained medical equipment information is uploaded to the original cloud platform.

[0015] Preferably, the process of first-layer encryption of the medical equipment data according to the original cloud platform includes:

[0016] Setting a base point prime number, performing modulus statistics on the base point prime number to obtain an original modulus;

[0017] According to the obtained original modulus, a function is calculated to obtain an Euler function;

[0018] According to the Euler function, a public key exponent is set, and a private key is calculated according to the public key exponent and the original modulus to obtain a private key exponent;

[0019] The obtained public key exponent, private key exponent, and original modulus are combined to obtain a key set, and the obtained key set is uploaded to a management center.

[0020] Preferably, the process of obtaining the cloud exchange platform includes:

[0021] The medical equipment information is standardized to obtain standardized equipment information;

[0022] A public key set is obtained, the standardized equipment information is encrypted according to the public key set to obtain equipment initial ciphertext, and the equipment initial ciphertext is double-encrypted to obtain equipment ciphertext coding;

[0023] Based on the original cloud platform, the medical equipment data is updated and replaced according to the obtained equipment ciphertext coding to obtain the cloud exchange platform.

[0024] Preferably, the process of constructing a permission channel for the cloud exchange platform includes:

[0025] A dynamic interface is set based on the cloud exchange platform;

[0026] An AC user terminal is set up, and a transmission channel between the AC user terminal and a dynamic interface is constructed, which is referred to as a preliminary flow channel;

[0027] The preliminary flow channel is hidden to obtain a hidden flow channel.

[0028] Preferably, the process of authority identification based on the hidden flow channel comprises:

[0029] An authority identification instruction is issued to the AC user terminal according to the hidden flow channel, the AC user terminal submits identity identification materials to the management center according to the received authority identification instruction, the management center comprehensively audits the obtained identity identification materials, and an authority identification result is obtained;

[0030] A channel construction instruction is issued to the AC user terminal according to the authority identification result, the hidden flow channel is reconstructed through the channel construction instruction, and an information flow channel is obtained.

[0031] Preferably, the process of access information assimilation of the AC user terminal through the information flow channel comprises:

[0032] Identity identification materials are obtained based on the AC user terminal, target screening is performed on the obtained identity identification materials, and access target information is obtained;

[0033] The access target information is uploaded to the information flow channel, a public key set of the management center is obtained through the information flow channel, the access target information is homomorphic encrypted according to the public key set, and access information ciphertext is obtained;

[0034] The access information ciphertext is double-encrypted to obtain access ciphertext encoding.

[0035] Preferably, the process of obtaining target shared information comprises:

[0036] The access ciphertext encoding is uploaded to the cloud exchange platform through the information flow channel, the access ciphertext encoding is encoded matched through the cloud exchange platform according to the device ciphertext encoding, and a paired device code is obtained;

[0037] The paired device code is encoded restored based on the device ciphertext encoding, and a paired device ciphertext is obtained.

[0038] The obtained paired device ciphertext is uploaded to the information flow channel, a private key authorization instruction is issued to the management center through the information flow channel, the management center performs secondary verification on the AC user terminal according to the received private key authorization instruction, and a private key set is sent to the information flow channel corresponding to the AC user terminal with a qualified verification result;

[0039] According to the received private key set, the pairing device ciphertext is terminal decrypted, target shared information is obtained, and the obtained target shared information is uploaded to the exchange user terminal through the information flow channel.

[0040] Based on the above medical device-based medical information sharing system, the application also provides a medical device-based medical information sharing method, comprising the following steps:

[0041] Step one: collect medical device information, and construct an original cloud platform;

[0042] Step two: first-layer encryption is performed on medical device data according to the original cloud platform, a key set is obtained, the key set includes a public key set and a private key set; one-time encryption is performed on the medical device information based on the key set, device initial ciphertext is obtained, double update is performed on the device initial ciphertext through the original cloud platform, and a cloud exchange platform is obtained;

[0043] Step three: a hidden flow channel is obtained by constructing a permission channel for the cloud exchange platform; information flow channels are obtained by performing permission identification based on the hidden flow channel;

[0044] Step four: access information is assimilated to the exchange user terminal through the information flow channel, access ciphertext coding is obtained, pairing device ciphertext is obtained by performing range matching on the access ciphertext coding of the exchange user terminal through the cloud exchange platform, and target shared information is obtained by performing channel decryption on the pairing device ciphertext based on the information flow channel.

[0045] Compared with the prior art, the application has the following beneficial effects:

[0046] 1. The original cloud platform is constructed, various types of medical device information collected are stored, real-time sharing and collaborative diagnosis and treatment of medical information are realized;

[0047] 2. The original data stored is updated to obtain the cloud exchange platform by using double encryption of asymmetric encryption and coding in the constructed original cloud platform, so that the patient privacy can be better protected, unauthorized access and leakage of sensitive medical information can be prevented;

[0048] 3. The transmission channel for information exchange with the user terminal is constructed in the cloud exchange platform, the transmission channel is identified by permission, multi-level access control strategy is facilitated, different access permissions are allocated to different users and devices, and the flexibility of access control is improved;

[0049] 4, identity verification is carried out on the access object, access permission is obtained, illegal personnel impersonating access personnel to steal medical information is prevented, the confidentiality and integrity of medical information can be effectively protected, unauthorized access and tampering are prevented, the access object uploads the access target to the cloud exchange platform according to the obtained access permission, ciphertext matching and decryption are carried out, and finally the required target shared information is obtained, which is helpful to promote the informatization process of the entire medical industry. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0051] Figure 1 The schematic diagram of the present application. DETAILED DESCRIPTION

[0052] The technical solutions of the present application will be described below in conjunction with the embodiments, obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0053] As shown in Figure 1 The medical information sharing system based on medical equipment includes a management center, the management center is connected with a device acquisition module, a data processing module, an information analysis module and an intelligent sharing module;

[0054] The device acquisition module is used for acquiring medical equipment information and constructing an original cloud platform.

[0055] The data processing module is used for first-layer encryption of medical equipment data according to the original cloud platform, obtaining a key set, the key set including a public key set and a private key set.

[0056] Based on the key set, the medical equipment information is one-time encrypted, the device initial ciphertext is obtained, the device initial ciphertext is double-updated through the original cloud platform, and the cloud exchange platform is obtained.

[0057] The information analysis module is used for constructing a permission channel for the cloud exchange platform, obtaining a hidden flow channel, and performing permission identification based on the hidden flow channel, obtaining an information flow channel.

[0058] The intelligent sharing module is used for information assimilation of the access user terminal through the information flow channel, obtaining access ciphertext coding, range matching of the access ciphertext coding of the access user terminal through the cloud exchange platform, obtaining a paired device ciphertext, channel decryption of the paired device ciphertext based on the information flow channel, and obtaining target shared information.

[0059] In actual application, each hospital or medical institution has a large number of medical devices for providing medical examination for patients. If repeated medical examinations are performed between different departments or different medical institutions, the cost is repeated, and the risk of increased radiation exposure is caused. At this time, the medical information of different medical devices needs to be shared, which can promote the cooperation of multidisciplinary teams, realize collaborative diagnosis and treatment, and improve the treatment effect. First, the medical device information is collected through the device collection module, and the specific process includes:

[0060] The medical device is collected and set to obtain an information collection end.

[0061] The collection setting indicates that a corresponding information collection end is set for each medical device to collect data information of the medical device. Each hospital or medical institution has a corresponding medical device for medical examination of patients. Therefore, a corresponding information collection end is set for each medical device.

[0062] The medical device information is collected through the information collection end to obtain medical device information. The medical device information includes patient basic information, clinical data, and treatment data. The patient basic information includes but is not limited to name, age, gender, medical record number, and contact information. The clinical data includes but is not limited to heart rate, blood pressure, body temperature, laboratory examination results, and imaging examination results. The treatment data includes but is not limited to drug prescription, operation record, and treatment plan. In particular, for each piece of medical device information, the medical examination and pathological report record of each patient can be matched through the patient basic information. For each examination report image, the corresponding test personnel, patient, examination time, and examination result can be obtained. That is, although the medical device information is in the form of image report, the patient information can still be obtained. At the same time, these data are examination results performed at different times, in different hospitals or departments. Therefore, to systematically analyze the treatment condition of the patient, it is necessary to collect all examination data of the medical device at all times. Therefore, the medical data needs to be shared to realize systematic analysis.

[0063] In particular, when data collection is performed on medical devices, a uniform format and standard are followed, that is, the format and standard of medical device information are uniform, that is, medical device information from any medical device or information system can be understood and processed in other systems, so that the collected medical device information can be normally circulated in all systems, and medical personnel can easily obtain the required medical device information; in the field of medical informatization, multiple standards and formats are widely used, such as HL7, DICOM, FHIR;

[0064] According to the obtained medical device information, an original cloud platform is constructed, the original cloud platform is a blank cloud platform without storing any data, and the obtained medical device information is uploaded to the original cloud platform.

[0065] The first layer encryption is performed on the obtained medical device data based on the original cloud platform, and a key set is obtained.

[0066] It should be further explained that in the specific implementation process, the first layer encryption means that the medical device data is first encrypted in the original cloud platform to obtain the key required for encryption; in this embodiment, RSA asymmetric encryption algorithm is used for encryption; so that the specific medical device data displayed in the original cloud platform is in the form of encrypted ciphertext, and the specific process includes:

[0067] A base point prime number is set, the base point prime number includes a first base point and a second base point, and the base point prime number is a larger prime number, in this embodiment, the larger the selected base point prime number is, the better, which can increase the key length and improve the security of encryption;

[0068] The obtained first base point is marked as T1, and the obtained second base point is marked as T2.

[0069] The obtained base point prime number is subjected to modulus statistics to obtain an original modulus, and the obtained original modulus is marked as n, wherein n=T1*T2.

[0070] According to the obtained original modulus, a function is calculated to obtain an Euler function, and the obtained Euler function is marked as φ(n)=(T1-1)*(T2-1).

[0071] According to the obtained Euler function, a public key index is set, and the obtained public key index is marked as e, wherein e satisfies 1

[0072] According to the obtained public key index and original modulus, a private key is calculated to obtain a private key index, and the obtained private key index is marked as d, wherein d is the multiplicative inverse of e modulo φ(n).

[0073] The obtained public key exponent, private key exponent, and original modulus are cryptographically combined to obtain a key set, which includes a public key set and a private key set, wherein the public key set = (n, e) and the private key set = (n, d).

[0074] Upload the obtained key set to the management center;

[0075] Specifically, the obtained public key set is used to encrypt the data, and the private key set is used to decrypt the encrypted ciphertext. The public key set is public and can be obtained directly through the original cloud platform, while the private key set is confidential and is only granted to authorized users. Here, "authorized" refers to the permission to obtain this part of the ciphertext. With this permission, the private key set can be sent to the user for decryption.

[0076] The obtained medical equipment information is formatted and standardized to obtain standardized equipment information, which is then marked as m;

[0077] The standardization of the format means that, based on the data format corresponding to asymmetric encryption, medical device information is also converted into a data format suitable for encryption, which is called standardized device information. For example, image data such as X-rays, CT scans, and MRIs can be encrypted by converting them into standardized device information in DICOM format. For another example, if a medical device collects a patient's ECG data, then to encrypt the ECG data, the patient's ECG data needs to be converted into a digital format, such as the standard ECG data format, which is standardized device information and facilitates encryption.

[0078] Obtain the public key set, encrypt the standard device information using the obtained public key set to obtain the initial ciphertext of the device, and mark the obtained initial ciphertext as W, where, And satisfy m < n. If a long standard device information is given, it is first divided into segments, then each segment is encrypted separately, and finally all segments are concatenated to obtain the corresponding initial device ciphertext, ensuring that each segment is less than the original modulus.

[0079] The initial ciphertext of the device is double-encrypted to obtain the device ciphertext code;

[0080] It should be further explained that, in the specific implementation process, the double encryption means that, based on the initial ciphertext obtained from the first layer of encryption, the initial ciphertext is encrypted again. The final ciphertext code obtained is the ciphertext form after two encryptions, which greatly improves the level of security and effectively prevents the leakage of medical device information. The specific process includes:

[0081] The obtained initial device ciphertext is encoded to obtain the device ciphertext encoding. Encoding conversion means using an encoding algorithm to convert the initial device ciphertext into encoded data, which is the device ciphertext encoding. For example, if the encoding algorithm is Base64, the initial device ciphertext is encoded to generate a Base64 encoded string, which is the device ciphertext encoding. Similarly, if you want to restore the encoded device ciphertext, you also use the Base64 encoding algorithm to restore it. In particular, for the initial device ciphertext within the same original cloud platform, only one encoding algorithm can be selected, that is, the encoding rules followed are the same.

[0082] Based on the original cloud platform, the medical device data is updated and replaced according to the obtained device encrypted code to obtain the cloud exchange platform;

[0083] The update and replacement refers to replacing the original medical device data with the device ciphertext code until all medical device data in the original cloud platform has been replaced with the corresponding device ciphertext code, thus completing the encrypted storage of medical device information. The updated original cloud platform is designated as the cloud exchange platform, where all medical device information can be accessed for exchange and learning among different medical personnel, achieving medical data sharing. Specifically, the medical device data first undergoes a first layer of encryption to obtain the initial ciphertext, and then the initial ciphertext is encrypted a second time to obtain the device ciphertext code. This double encryption provides an additional layer of security. Even if one layer of encryption is cracked, the other layer protects the data, which greatly increases the difficulty for attackers to crack the data.

[0084] The process involves constructing a permission channel on the cloud exchange platform to obtain a hidden flow channel, performing permission verification based on this hidden flow channel, and obtaining an information flow channel. The specific steps include:

[0085] A dynamic interface is set up for the obtained cloud exchange platform. The dynamic interface is used to provide an access point for communication users to obtain information within the cloud exchange platform. That is, a connection with the cloud exchange platform is established through the dynamic interface in order to obtain the required medical equipment information. Here, the communication users refer to the personnel who need to obtain information from the cloud exchange platform, including but not limited to medical staff, researchers, and medical administrators.

[0086] Set up the communication user terminal, which is the access port held by the communication user. On the communication user's side, it is the port used for identity entry and permission recognition.

[0087] Based on the communication user terminal, a transmission channel is constructed between the communication user terminal and the dynamic interface, which is denoted as the pre-flow channel.

[0088] Furthermore, the transmission channel starts from the user terminal and extends to any dynamic interface of the cloud exchange platform to construct a channel for transmitting information. That is, the dynamic interface corresponding to the cloud exchange platform is different at different times, so it is impossible to predict from which end the user terminal accesses the cloud exchange platform. This helps to protect the privacy of the cloud exchange platform and prevents information from being lost due to the destruction of the fixed transmission channel.

[0089] The permissions of the obtained pre-existing flow channel are hidden to obtain a hidden flow channel. That is, before the communication user terminal obtains the permission to obtain medical device information from the cloud exchange platform, the pre-existing flow channel is hidden. In other words, the pre-existing flow channel is not displayed and it is impossible to obtain data information from the cloud exchange platform through the pre-existing flow channel. At this time, there is no pre-existing flow channel, but the channel position is reserved, that is, a channel that is not displayed, which is called a hidden flow channel.

[0090] Based on the obtained hidden flow channel, the communication user terminal sends an authorization instruction. The communication user terminal submits identity verification materials to the management center according to the received authorization instruction. The management center conducts a comprehensive review of the obtained identity verification materials and obtains the authorization result, which includes qualified authorized users and non-authorized users.

[0091] Based on the obtained permission assessment results, a channel construction command is issued to the communication user terminal. The hidden flow channel is reconstructed through the channel construction command to obtain the information flow channel.

[0092] It should be further explained that, in the specific implementation process, the permission determination instruction indicates that, based on the hidden flow channel, since the communication user terminal does not have the permission to access the cloud exchange platform to obtain medical device data, the preliminary flow channel is hidden, that is, there is no channel actually used for transmitting information. Therefore, it is necessary to first determine the permission of the communication user terminal. The identity determination materials include the identity information and access target of the communication user terminal. The identity information refers to the identity feature information of the communication user terminal, which is used to verify the identity of the communication user terminal through the management center to the work address or work background, confirm the authenticity of the identity, and prevent the acquisition of information by forging the identity. The access target indicates which medical device information in the cloud exchange platform to obtain, such as obtaining the examination reports of department b, project c, performed by patients a1, a3, a5, and a6 within the past three years.

[0093] Furthermore, the comprehensive review means that if the management center's review of the identity verification materials of the communication user terminal is qualified, it means that the information provided by the communication user terminal is true and the access target obtained is consistent with the cloud exchange platform. In this case, the communication user terminal can obtain the permission to access the cloud exchange platform and is granted the permission to obtain medical device information. That is, the permission identification result is qualified user. If the review result is unqualified, it means that the information provided by the communication user terminal is untrue or the access target exceeds the scope of the cloud exchange platform. In this case, the communication user terminal is not granted the permission to obtain medical device information. That is, the permission identification result is unauthorized user.

[0094] The channel construction instruction indicates that if the user terminal's permission assessment result is a qualified user, the hidden flow channel will be reconstructed into a preparatory flow channel and recorded as an information flow channel. Conversely, if the user terminal's permission assessment result is an unauthorized user, no channel construction instruction will be issued. That is, the user terminal of an unauthorized user does not have a preparatory flow channel to build with the dynamic interface, and therefore cannot transmit information. In particular, the information flow channel represents an information transmission channel with access to the cloud exchange platform. Preparatory flow channels generated before the access rights are determined are all hidden flow channels, that is, they do not have a substantial channel, but are only a connection direction, indicating that a transmission channel can be built. This can protect the data security of the cloud exchange platform to the greatest extent and prevent unauthorized personnel from obtaining medical device information by forging identities, directly blocking the route of obtaining medical information from the acquisition channel.

[0095] The access information of the communicating user terminal is assimilated through the information flow channel to obtain the access ciphertext encoding. The specific process includes:

[0096] Based on the identity verification materials obtained from the communication user terminal, the obtained identity verification materials are used to filter the target and obtain access target information;

[0097] The target filtering refers to the access target of the communication user terminal within the identity verification material, that is, which medical device information of the cloud exchange platform is desired to be obtained, denoted as the access target information. For example, if all medical reports of patient a8 within three years are available, then the access target information here includes patient a8's name, age, gender, medical record number, etc. Through patient a8's access target information, all medical device information of him / her within three years in the cloud exchange platform can be obtained. This is based on the fact that each piece of medical device information is generated by the patient, so obtaining the patient's detailed information can obtain all the corresponding medical treatment information of the patient. If it is desired to study the pathological report characteristics of a certain disease, then the corresponding access target information is the patient report and medical treatment report corresponding to the examination equipment involved in the disease.

[0098] The obtained access target information is uploaded to the information flow channel. The public key set of the management center is obtained through the information flow channel. The access target information is homomorphically encrypted according to the obtained public key set to obtain the ciphertext of the access information.

[0099] The homomorphic encryption means that the same encryption process is performed on the standard device information, and the obtained ciphertext of the access information is denoted as F, where, z represents the target information to be accessed. The target information to be accessed here is the same as the standard device information and is converted into a unified format, which is suitable for RSA asymmetric encryption.

[0100] The obtained access information ciphertext is double-encrypted to obtain the access ciphertext encoding. The encoding algorithm of the obtained access ciphertext encoding is the same as the device ciphertext encoding algorithm.

[0101] The cloud exchange platform performs range matching on the encrypted access data of the user terminals to obtain the encrypted data of the paired devices. Based on the information flow channel, the encrypted data of the paired devices is decrypted to obtain the target shared information. The specific process includes:

[0102] The obtained encrypted access data is uploaded to the cloud exchange platform through the information flow channel;

[0103] The cloud exchange platform performs encoding matching on the access ciphertext based on the obtained device ciphertext encoding to obtain the paired device encoding;

[0104] It needs further explanation that, in the specific implementation process, the encoding matching refers to comparing the access ciphertext encoding one by one with the device ciphertext encoding in the cloud exchange platform. That is, each access ciphertext encoding is compared with all device ciphertext encodings within the cloud exchange platform. The comparison involves first matching the first character of the access ciphertext encoding with the first character of the device ciphertext encoding. If every character of the corresponding part of the access ciphertext encoding and the device ciphertext encoding is the same, then the device ciphertext encoding is recorded as the paired device encoding. This indicates that the access ciphertext encodings generated based on the access target of the exchange user terminal have the same part of the encoding segment, that is, the ciphertext corresponding to this part of the encoding segment is the same, which can determine the device encoding. If the decrypted data matches the access target, and one character in the corresponding part of the access ciphertext code and the device ciphertext code is different, then move the access ciphertext code to the next character of the device ciphertext code for comparison. If all characters are the same, a matching device code is obtained. If at least one character is different, continue moving the access ciphertext code to the next character of the device ciphertext code for comparison until no character in the device ciphertext code matches the access ciphertext code. Then, change to a different device ciphertext code and repeat the above process until all device ciphertext codes in the cloud exchange platform match the access ciphertext code. Statistically analyze the obtained matching device codes to obtain all matching device ciphertext codes.

[0105] The paired device's ciphertext is obtained by restoring the ciphertext of the paired device based on the device's ciphertext encoding.

[0106] The encoding restoration refers to restoring the device's initial ciphertext before it is converted into an encoded form by using the corresponding encoding algorithm based on the device's ciphertext encoding. This initial ciphertext is denoted as the paired device ciphertext.

[0107] The obtained paired device ciphertext is uploaded to the information flow channel, and a private key authorization instruction is sent to the management center through the information flow channel. The management center performs a second verification on the communication user terminal based on the received private key authorization instruction, and sends a private key set to the information flow channel corresponding to the communication user terminal whose verification result is qualified.

[0108] Furthermore, the private key authorization instruction indicates that the encrypted data of the paired device can only be decrypted by obtaining the private key set. Since the private key set is stored in the management center, authorization must be obtained through the management center to obtain the private key set.

[0109] The secondary verification means that the management center verifies the identity verification materials of the communication user terminal again, and at the same time verifies the encrypted information of the paired device in the information flow channel to determine that it is medical information within the scope of the access target required by the communication user terminal, and that there is no medical information beyond the scope of the access target, so as to prevent the communication user terminal from obtaining unauthorized medical device information. If all these verification information are in compliance, then the verification result of the communication user terminal is qualified, and a private key set can be issued for decryption.

[0110] The terminal decrypts the encrypted data from the paired device using the received private key set to obtain the target shared information.

[0111] The terminal decryption refers to decrypting the paired device's ciphertext within the information flow channel based on the obtained private key set, thereby obtaining the target shared information. This obtained target shared information is denoted as G, where... ;

[0112] The obtained target shared information is uploaded to the communication user terminal through the information flow channel. That is, the communication user obtains the target medical information he / she needs. The medical equipment information in the cloud exchange platform is all medical information used for sharing. Different users can obtain the target shared information they need under the premise of security through dynamic interface.

[0113] Based on the aforementioned medical device-based medical information sharing system, the present invention also provides a medical device-based medical information sharing method, comprising the following steps:

[0114] Step 1: Collect medical device information and build the initial cloud platform;

[0115] Step 2: Perform first-level encryption on the medical device data based on the original cloud platform to obtain a key set, which includes a public key set and a private key set; perform a second-level encryption on the medical device information based on the key set to obtain the initial ciphertext of the device; and perform a double update on the initial ciphertext of the device through the original cloud platform to obtain the cloud exchange platform.

[0116] Step 3: Construct permission channels for the cloud exchange platform to obtain hidden flow channels, perform permission verification based on hidden flow channels, and obtain information flow channels;

[0117] Step 4: Assimilate the access information of the communication user terminal through the information flow channel to obtain the access ciphertext encoding. Perform range matching on the access ciphertext encoding of the communication user terminal through the cloud exchange platform to obtain the paired device ciphertext. Decrypt the paired device ciphertext based on the information flow channel to obtain the target shared information.

[0118] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A medical information sharing system based on medical devices, including a management center, characterized in that, The management center is connected to a device acquisition module, a data processing module, an information analysis module, and an intelligent sharing module; The device acquisition module is used to collect medical device information and build the original cloud platform; The data processing module is used to perform first-level encryption on medical device data based on the original cloud platform to obtain a key set, which includes a public key set and a private key set. The medical device information is encrypted once based on the key set to obtain the initial ciphertext of the device. The initial ciphertext of the device is then updated twice through the original cloud platform to obtain the cloud exchange platform. The information analysis module is used to construct permission channels for the cloud exchange platform and obtain hidden flow channels; The process of building access control channels for a cloud exchange platform includes: Dynamically configure interfaces based on the cloud exchange platform; Set up the communication client and construct the transmission channel between the communication client and the dynamic interface, which is denoted as the pre-flow channel. Hide permissions on the prepared flow channel to obtain the hidden flow channel; Access control is performed based on hidden information flow channels, and the process of obtaining information flow channels includes: The communication user terminal is issued an authorization instruction through the hidden flow channel. The communication user terminal submits identity verification materials to the management center according to the received authorization instruction. The management center conducts a comprehensive review of the obtained identity verification materials and obtains the authorization result. Based on the authorization results, a channel construction command is issued to the communication user terminal. The hidden flow channel is reconstructed through the channel construction command to obtain the information flow channel. The intelligent sharing module is used to assimilate access information from the communication user terminal through the information flow channel to obtain access ciphertext encoding, perform range matching on the access ciphertext encoding of the communication user terminal through the cloud exchange platform to obtain the paired device ciphertext, and perform channel decryption on the paired device ciphertext based on the information flow channel to obtain the target shared information.

2. The medical information sharing system based on medical devices according to claim 1, characterized in that, The process of collecting medical device information includes: Configure medical equipment to collect data and obtain information from the data collection terminal; Data is collected from medical devices through an information collection terminal to obtain information about the medical devices; The original cloud platform is constructed based on the obtained medical equipment information, and the obtained medical equipment information is uploaded to the original cloud platform.

3. The medical information sharing system based on medical devices according to claim 1, characterized in that, The process of performing first-level encryption on medical device data based on the original cloud platform includes: Set a base prime number, perform modulus statistics on the base prime number, and obtain the original modulus; The Euler totient function is obtained by calculating the original modulus. The public key exponent is set according to the Euler totient function. The private key exponent is obtained by calculating the private key exponent and the original modulus. The obtained public key index, private key index, and original modulus are cryptographically combined to obtain a key set, which is then uploaded to the management center.

4. The medical information sharing system based on medical devices according to claim 1, characterized in that, The process of obtaining a cloud exchange platform includes: Standardize the format of medical equipment information to obtain standardized equipment information; Obtain the public key set, encrypt the standard device information according to the public key set to obtain the initial ciphertext of the device, and perform double encryption on the initial ciphertext of the device to obtain the device ciphertext code; Based on the original cloud platform, the medical device data is updated and replaced according to the obtained device encrypted code to obtain the cloud exchange platform.

5. The medical information sharing system based on medical devices according to claim 1, characterized in that, The process of assimilating access information to communication users through information flow channels includes: Based on the identity verification materials obtained from the communication user terminal, the obtained identity verification materials are used to filter the target and obtain access target information; The access target information is uploaded to the information flow channel, and the public key set of the management center is obtained through the information flow channel. The access target information is then homomorphically encrypted based on the public key set to obtain the ciphertext of the access information. The access information is double-encrypted to obtain the access ciphertext encoding.

6. The medical information sharing system based on medical devices according to claim 4, characterized in that, The process of obtaining target shared information includes: The access encrypted code is uploaded to the cloud exchange platform through the information flow channel. The cloud exchange platform performs encoding matching on the access encrypted code according to the device encrypted code to obtain the paired device code. The paired device's ciphertext is obtained by restoring the ciphertext of the paired device based on the device's ciphertext encoding. The obtained paired device ciphertext is uploaded to the information flow channel, and a private key authorization instruction is sent to the management center through the information flow channel. The management center performs a second verification on the communication user terminal based on the received private key authorization instruction, and sends a private key set to the information flow channel corresponding to the communication user terminal whose verification result is qualified. The terminal decrypts the encrypted data of the paired device based on the received private key set, obtains the target shared information, and uploads the obtained target shared information to the communicating user terminal through the information flow channel.

7. The medical information sharing method of the medical information sharing system based on medical devices according to any one of claims 1 to 6, characterized in that, Includes the following steps: Step 1: Collect medical device information and build the initial cloud platform; Step 2: Perform first-level encryption on the medical device data based on the original cloud platform to obtain a key set, which includes a public key set and a private key set; perform a second-level encryption on the medical device information based on the key set to obtain the initial ciphertext of the device; and perform a double update on the initial ciphertext of the device through the original cloud platform to obtain the cloud exchange platform. Step 3: Construct permission channels for the cloud exchange platform to obtain hidden flow channels, perform permission verification based on hidden flow channels, and obtain information flow channels; Step 4: Assimilate the access information of the communication user terminal through the information flow channel to obtain the access ciphertext encoding. Perform range matching on the access ciphertext encoding of the communication user terminal through the cloud exchange platform to obtain the paired device ciphertext. Decrypt the paired device ciphertext based on the information flow channel to obtain the target shared information.

Citation Information

Patent Citations

  • Blockchain data encryption method and system

    CN110826095A

  • Health medical big data sharing system and method

    CN117095799A