Medical data privacy protection and sharing system and method based on security data sandbox

By building a secure data sandbox environment, combined with dynamically configured security policies and efficient data processing capabilities, the dual needs of medical data privacy protection and sharing are addressed, the secure processing and flexible sharing of patient data are achieved, and the digital transformation of the medical industry is promoted.

CN120809038APending Publication Date: 2025-10-17SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510865999.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

The data sandbox in existing technologies has limited application in the medical field. It lacks targeted privacy protection mechanisms and efficient data sharing capabilities, and is difficult to meet the dual needs of privacy protection and data sharing of medical data.

Method used

Build a secure data sandbox environment, combining dynamically configured security policies and efficient data processing capabilities, including data collection, preprocessing, sandbox environment configuration, data analysis and processing, data sharing and collaboration, as well as log auditing and compliance checking modules to ensure privacy protection and secure sharing during data processing.

Benefits of technology

It enables secure processing of patient data in an isolated environment, supports flexible data sharing and collaboration, promotes the digital transformation of the medical industry, and complies with medical data privacy protection regulations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120809038A_ABST
    Figure CN120809038A_ABST
Patent Text Reader

Abstract

The invention discloses a medical data privacy protection and sharing system and method based on a security data sandbox, and relates to the technical field of data security and analysis, and the system comprises a data collection and import module which is responsible for collecting patient data from a medical institution and importing the patient data into the security data sandbox; the data preprocessing module is responsible for performing desensitization, encryption and standardization processing on the patient data of the security data sandbox; the sandbox environment configuration module is responsible for dynamically configuring a security policy of a sandbox environment according to data analysis or sharing requirements; the data analysis and processing module is responsible for operating a data analysis task in a sandbox environment; the data sharing and cooperation module is responsible for safely sharing the processing result to an authorized external mechanism or researcher according to a preset sharing rule and recording a sharing behavior; and the log auditing and compliance checking module is responsible for performing whole-course auditing on the data processing and sharing process. The privacy of the patient can be protected, and safe sharing of medical data can be promoted.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security and analysis, and in particular to a medical data privacy protection and sharing system and method based on a secure data sandbox. BACKGROUND

[0002] In the medical field, patient data privacy protection and security are of great importance. Medical data often contain sensitive information (such as medical records, diagnosis results, medication records, etc.), and traditional data processing methods cannot meet the dual needs of privacy protection and data sharing. In addition, medical institutions need to share data with external institutions in research and clinical collaboration scenarios, but there is a risk of leakage and misuse during data sharing.

[0003] The secure data sandbox technology, as an isolated environment, can process and share data while ensuring data security. However, the data sandbox in existing technology is limited in application in the medical field, lacking targeted privacy protection mechanisms and efficient data sharing capabilities. SUMMARY

[0004] The present application provides a medical data privacy protection and sharing system and method based on a secure data sandbox to address the needs and deficiencies of current technology development. By constructing a secure and isolated data sandbox environment, combining dynamic configuration of security policies and efficient data processing capabilities, the present application provides a secure, flexible, and efficient solution for medical institutions.

[0005] In a first aspect, the present application provides a medical data privacy protection and sharing system based on a secure data sandbox, which solves the above technical problems by adopting the following technical solutions:

[0006] A medical data privacy protection and sharing system based on a secure data sandbox includes the following steps:

[0007] A data collection and import module is responsible for collecting patient data from different data sources of a medical institution and importing the collected patient data into a secure data sandbox;

[0008] A data preprocessing module is responsible for desensitizing, encrypting, and standardizing the patient data imported into the secure data sandbox to ensure that the data meets privacy protection requirements;

[0009] A sandbox environment configuration module is responsible for dynamically configuring the security policies of the sandbox environment, including data isolation levels and access control rules, according to data analysis or sharing needs;

[0010] A data analysis and processing module is responsible for running data analysis tasks in the sandbox environment to ensure that patient privacy is not leaked during data processing;

[0011] a data sharing and collaboration module, configured to share the processing result with authorized external institutions or researchers in a secure manner according to preset sharing rules, and record the sharing behavior for auditing;

[0012] a log auditing and compliance checking module, configured to audit the data processing and sharing process to ensure compliance with medical data privacy protection regulations.

[0013] Optionally, the data preprocessing module specifically includes:

[0014] a sensitive data identification unit, configured to identify sensitive data in the accessed patient data based on preset sensitive data identification rules;

[0015] a desensitization execution unit, configured to match corresponding desensitization rules based on the identification result of the sensitive data identification unit, and execute the desensitization rules to realize desensitization of the sensitive data;

[0016] a data sampling unit, configured to sample the patient data that is not identified by the sensitive data identification unit and the sensitive data desensitized by the desensitization execution unit by at least one algorithm of fast sampling, random sampling and intelligent sampling, to obtain sample data;

[0017] a simulated sample generation unit, configured to simulate the sample data obtained by the data sampling unit by using an intelligent simulation technology based on a large model, to generate sample data without sensitive information;

[0018] a sample data uploading unit, configured to upload the sample data generated by the simulated sample generation unit to a sandbox environment, for subsequent data analysis and model training.

[0019] Further optionally, the sandbox environment configuration module dynamically configures the security policy of the sandbox environment according to the data analysis or sharing requirements, including three data isolation levels of process isolation, container isolation and physical isolation, and access control rules based on user roles and time context.

[0020] Further optionally, the sandbox environment includes a running environment and a debugging environment, wherein the running environment supports access to the patient data imported by the data collection and import module, and the debugging environment supports access to the sample data uploaded by the sample data uploading unit.

[0021] A user uses the sample data to perform modeling and training on the debugging environment, optimizes the model parameters through the visualization tool of the debugging environment, obtains a prediction model meeting the requirements, and then submits the prediction model to the running environment. The prediction model automatically accesses the patient data in the running environment, processes the data according to a preset logic, generates analysis results, and the running environment stores the analysis results in an encrypted manner, allowing only authorized users to access.

[0022] Optionally, the preset sharing rules include at least one of result watermarking, key encryption, and administrator review, where:

[0023] Result watermarking method: Add a watermark to the analysis results in the format and embedding method selected by the user. The user obtains the result file with the watermark. This method needs to be approved by the administrator.

[0024] Key encryption method: The user provides an encryption key, and the system uses it to encrypt the analysis results before returning them. The process requires administrator approval to ensure the confidentiality of data transmission and storage;

[0025] Administrator review method: After the user submits a download application, the system automatically identifies sensitive data. The administrator reviews the identification results together with the original data. Only after approval can the user download the actual analysis results.

[0026] In a second aspect, the present invention provides a method for protecting and sharing medical data privacy based on a secure data sandbox. The technical solutions adopted to solve the above technical problems are as follows:

[0027] A medical data privacy protection and sharing method based on a secure data sandbox comprises the following steps:

[0028] S1. Collect patient data from different data sources in medical institutions and import the collected patient data into a secure data sandbox;

[0029] S2. Desensitize, encrypt, and standardize patient data imported into the secure data sandbox to ensure that the data complies with privacy protection requirements;

[0030] S3. Dynamically configure the security policies of the sandbox environment, including data isolation levels and access control rules, based on data analysis or sharing requirements.

[0031] S4. Run data analysis tasks in a sandbox environment to ensure that patient privacy is not disclosed during data processing;

[0032] S5. Securely share the processing results with authorized external organizations or researchers according to pre-set sharing rules, and record the sharing behavior for auditing;

[0033] S6. Conduct a full audit of the data processing and sharing process from step S2 to step S5 to ensure compliance with medical data privacy protection regulations.

[0034] Optionally, step S2 specifically includes:

[0035] S2.1. Based on pre-set sensitive data identification rules, perform sensitive data identification on the received patient data;

[0036] S2.2, set different sensitive type desensitization rules, match the corresponding desensitization rules based on the identification result, and then execute the desensitization rules to realize the desensitization of sensitive data;

[0037] S2.3, at least one algorithm of rapid sampling, random sampling and intelligent sampling is used to sample the patient data which is not identified and the sensitive data after desensitization, and sample data is obtained;

[0038] S2.4, using intelligent simulation technology based on large model, simulating the obtained sample data to generate sample data without sensitive information;

[0039] S2.5, uploading the generated sample data to sandbox environment for subsequent data analysis and model training.

[0040] Further optional, execute step S3, according to the data analysis or sharing demand, dynamically configure the security policy of sandbox environment, including three data isolation levels of process isolation, container isolation and physical isolation, and also including access control rules based on user role and time context.

[0041] Further optional, the sandbox environment involved includes running environment and debugging environment, wherein the running environment supports accessing the patient data imported in step S1, and the debugging environment supports accessing the sample data uploaded in step S2.5;

[0042] The user uses sample data to model and train on the debugging environment, optimizes model parameters through the visualization tool of the debugging environment, obtains a prediction model meeting the demand, and then submits the prediction model to the running environment. The prediction model automatically accesses the patient data in the running environment, processes the data according to the preset logic, generates analysis results, and the running environment stores the analysis results in encrypted form, allowing only authorized users to access.

[0043] Optionally, the preset sharing rule includes at least one of result watermarking, secret key encryption and administrator review, wherein:

[0044] The result watermarking mode adds a watermark in the analysis result according to the format and embedding mode selected by the user, the user obtains the result file with the watermark, and this mode needs to be approved by the administrator;

[0045] The secret key encryption mode: the user provides an encryption secret key, and the system returns the encrypted analysis result, and the process needs to be approved by the administrator to ensure the confidentiality of data transmission and storage;

[0046] The administrator review mode: after the user submits a download application, the system automatically identifies sensitive data, the administrator reviews in combination with the identification result and the original data, and the user can download the real analysis result after passing.

[0047] The medical data privacy protection and sharing system and method based on a secure data sandbox of the present invention has the following beneficial effects compared with the prior art:

[0048] This invention combines dynamically configured security policies and efficient data processing capabilities to build a secure and isolated data sandbox environment for medical institution data, which can not only protect patient privacy, but also promote the legal sharing and collaboration of medical data, and promote the digital transformation and innovative development of the medical industry; it is suitable for scenarios where medical institutions need to securely process patient privacy data in data analysis and sharing scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Attachment Figure 1 This is a module connection block diagram of the first embodiment of the present invention;

[0050] Attachment Figure 2 This is a flow chart of the method of embodiment 2 of the present invention. DETAILED DESCRIPTION

[0051] In order to make the technical solution, the technical problems solved and the technical effects of the present invention more clear, the technical solution of the present invention is clearly and completely described below in conjunction with specific embodiments.

[0052] Example 1:

[0053] Reference Attachment Figure 1 This embodiment proposes a medical data privacy protection and sharing system based on a secure data sandbox, which includes the following steps:

[0054] The data collection and import module is responsible for collecting patient data from different data sources of medical institutions and importing the collected patient data into the secure data sandbox;

[0055] The data preprocessing module is responsible for desensitizing, encrypting, and standardizing patient data imported into the secure data sandbox to ensure that the data meets privacy protection requirements;

[0056] The sandbox environment configuration module is responsible for dynamically configuring the security policies of the sandbox environment, including data isolation levels and access control rules, based on data analysis or sharing requirements.

[0057] The data analysis and processing module is responsible for running data analysis tasks in a sandbox environment to ensure that patient privacy is not leaked during data processing;

[0058] The data sharing and collaboration module is responsible for securely sharing the processing results with authorized external institutions or researchers according to preset sharing rules, and recording the sharing behavior for auditing;

[0059] A log audit and compliance check module is responsible for auditing the entire data processing and sharing process to ensure compliance with medical data privacy protection regulations.

[0060] In this embodiment, the data preprocessing module specifically includes:

[0061] A sensitive data identification unit is responsible for identifying sensitive data in the accessed patient data based on pre-set sensitive data identification rules.

[0062] A desensitization execution unit is built-in with different types of desensitization rules, and is responsible for matching the corresponding desensitization rules based on the identification results of the sensitive data identification unit, and then executing the desensitization rules to achieve desensitization of sensitive data.

[0063] A data sampling unit is responsible for sampling the patient data that has not been identified by the sensitive data identification unit and the sensitive data desensitized by the desensitization execution unit using at least one of a fast sampling, a random sampling, and an intelligent sampling algorithm to obtain sample data.

[0064] A simulated sample generation unit is responsible for simulating the sample data obtained by the data sampling unit using an intelligent simulation technology based on a large model to generate sample data without sensitive information.

[0065] A sample data uploading unit is used to upload the sample data generated by the simulated sample generation unit to a sandbox environment for subsequent data analysis and model training.

[0066] In this embodiment, the sandbox environment configuration module dynamically configures the security policy of the sandbox environment according to the data analysis or sharing requirements, including three data isolation levels of process isolation, container isolation, and physical isolation, and also including access control rules based on user roles and time context settings.

[0067] In this embodiment, the sandbox environment includes a running environment and a debugging environment, wherein the running environment supports access to patient data imported by the data collection and import module, and the debugging environment supports access to sample data uploaded by the sample data uploading unit.

[0068] The user uses the sample data to perform modeling training on the debugging environment, optimizes the model parameters through the visualization tools of the debugging environment, obtains a prediction model that meets the requirements, and then submits the prediction model to the running environment. The prediction model automatically accesses the patient data in the running environment, processes the data according to the preset logic, generates analysis results, and the running environment stores the analysis results in an encrypted manner, allowing only authorized users to access.

[0069] In this embodiment, the preset sharing rules include at least one of result watermarking, secret key encryption, and administrator review, wherein:

[0070] Result watermarking mode: add watermark to the analysis result according to the format and embedding mode selected by the user, and the user obtains the result file with watermark, and this mode needs to be approved by the administrator;

[0071] Key encryption mode: the user provides an encryption key, and the system returns the encrypted analysis result, and the process needs to be approved by the administrator to ensure the confidentiality of data transmission and storage;

[0072] Administrator review mode: after the user submits a download application, the system automatically identifies sensitive data, the administrator reviews in combination with the identification result and the original data, and the user can download the real analysis result after passing the review.

[0073] Embodiment two:

[0074] Reference appendix Figure 2 The embodiment proposes a medical data privacy protection and sharing method based on a secure data sandbox, which includes the following steps:

[0075] S1, collect patient data from different data sources of medical institutions, and import the collected patient data into a secure data sandbox.

[0076] S2, desensitization, encryption and standardization processing are performed on the patient data imported into the secure data sandbox to ensure that the data meets the privacy protection requirements, specifically including:

[0077] S2.1, based on the pre-set sensitive data identification rules, sensitive data identification is performed on the accessed patient data;

[0078] S2.2, set different desensitization rules for different sensitive types, match the corresponding desensitization rules based on the identification results, and then execute the desensitization rules to realize the desensitization of sensitive data;

[0079] S2.3, at least one algorithm of rapid sampling, random sampling and intelligent sampling is used to sample the patient data that has not been identified and the sensitive data after desensitization to obtain sample data;

[0080] S2.4, use intelligent simulation technology based on large models to simulate the obtained sample data to generate sample data without sensitive information;

[0081] S2.5, upload the generated sample data to the sandbox environment for subsequent data analysis and model training.

[0082] S3, dynamically configure the security policy of the sandbox environment according to the data analysis or sharing requirements, including three data isolation levels of process isolation, container isolation and physical isolation, and also including access control rules based on user roles and time context settings.

[0083] The sandbox environment includes a running environment and a debugging environment, wherein the running environment supports access to the patient data imported in step S1, and the debugging environment supports access to the sample data uploaded in step S2.5.

[0084] S4. Running the data analysis task in the sandbox environment to ensure that patient privacy is not leaked during data processing. Specifically, the user uses sample data to perform modeling training on the debugging environment, optimizes the model parameters through the visualization tools of the debugging environment, obtains a prediction model that meets the requirements, and then submits the prediction model to the running environment. The prediction model automatically accesses the patient data in the running environment, processes the data according to a preset logic, generates an analysis result, and the running environment stores the analysis result in an encrypted manner, allowing only authorized users to access.

[0085] S5. According to a preset sharing rule, the processing result is safely shared with an authorized external institution or researcher, and the sharing behavior is recorded for auditing.

[0086] The preset sharing rule includes at least one of a result watermark, a secret key encryption, and an administrator review, wherein:

[0087] The result watermark mode: a watermark is added to the analysis result in a format and embedding mode selected by the user, the user obtains a result file with the watermark, and this mode needs to be approved by the administrator;

[0088] The secret key encryption mode: the user provides an encryption secret key, the system encrypts the analysis result with the secret key and returns it, and the process needs to be approved by the administrator to ensure the confidentiality of data transmission and storage;

[0089] The administrator review mode: after the user submits a download application, the system automatically identifies sensitive data, the administrator reviews in combination with the identification result and the original data, and the user can download the real analysis result after passing;

[0090] S6. The data processing and sharing process of steps S2-S5 are audited throughout the process to ensure compliance with medical data privacy protection regulations.

[0091] As can be seen from the above, the medical data privacy protection and sharing system and method based on a secure data sandbox according to the present application ensure the privacy protection and security of patient data in an isolated environment through secure data sandbox technology; support dynamic sandbox configuration, which can flexibly adjust security policies according to data analysis or sharing needs; provide efficient data analysis capabilities, support various medical scenarios such as disease prediction and drug research and development; support secure data sharing functions to facilitate collaboration with external institutions or researchers while preventing data leakage; and provide complete log auditing functions to ensure that data processing and sharing processes comply with medical data privacy protection regulations.

[0092] The principles and implementation manners of the present application are described in detail by using the above specific examples, and these examples are only used to help understand the core technical content of the present application. Based on the above specific examples of the present application, any improvement and modification of the present application made by the person skilled in the art without departing from the principles of the present application shall fall within the patent protection scope of the present application.

Claims

1. A medical data privacy protection and sharing system based on a secure data sandbox, characterized by: The steps include: The data collection and import module is responsible for collecting patient data from different data sources of medical institutions and importing the collected patient data into the secure data sandbox; The data preprocessing module is responsible for desensitizing, encrypting, and standardizing patient data imported into the secure data sandbox to ensure that the data meets privacy protection requirements; The sandbox environment configuration module is responsible for dynamically configuring the security policies of the sandbox environment, including data isolation levels and access control rules, based on data analysis or sharing requirements. The data analysis and processing module is responsible for running data analysis tasks in a sandbox environment to ensure that patient privacy is not leaked during data processing; The data sharing and collaboration module is responsible for securely sharing the processing results with authorized external institutions or researchers according to preset sharing rules, and recording the sharing behavior for auditing; The log audit and compliance check module is responsible for auditing the entire data processing and sharing process to ensure compliance with medical data privacy protection regulations.

2. The medical data privacy protection and sharing system based on secure data sandbox according to claim 1 is characterized in that: The data preprocessing module specifically includes: The sensitive data identification unit is responsible for identifying sensitive data of the received patient data based on pre-set sensitive data identification rules; The desensitization execution unit has built-in desensitization rules for different sensitive types. It is responsible for matching the corresponding desensitization rules based on the recognition results of the sensitive data recognition unit, and then executing the desensitization rules to desensitize sensitive data. The data sampling unit is responsible for sampling the patient data that has not been identified by the sensitive data identification unit and the sensitive data that has been desensitized by the desensitization execution unit through at least one algorithm of rapid sampling, random sampling, and intelligent sampling to obtain sample data; The simulation sample generation unit is responsible for using intelligent simulation technology based on large models to simulate the sample data obtained by the data sampling unit and generate sample data without sensitive information; The sample data uploading unit is used to upload the sample data generated by the simulation sample generation unit to the sandbox environment for subsequent data analysis and model training.

3. The medical data privacy protection and sharing system based on secure data sandbox according to claim 2 is characterized in that: The sandbox environment configuration module dynamically configures the security policy of the sandbox environment according to data analysis or sharing requirements, including three data isolation levels: process isolation, container isolation, and physical isolation, as well as access control rules based on user roles and time context settings.

4. The medical data privacy protection and sharing system based on secure data sandbox according to claim 3 is characterized in that: The sandbox environment includes an operating environment and a debugging environment, wherein the operating environment supports access to patient data imported by the data acquisition and import module, and the debugging environment supports access to sample data uploaded by the sample data upload unit; Users use sample data to conduct modeling training in the debugging environment, optimize model parameters through the debugging environment's visualization tools, obtain a prediction model that meets the requirements, and then submit the prediction model to the operating environment. The prediction model automatically accesses the patient data in the operating environment, processes the data according to preset logic, and generates analysis results. The operating environment encrypts and stores the analysis results, allowing only authorized users to access them.

5. The medical data privacy protection and sharing system based on secure data sandbox according to claim 1 is characterized in that: The preset sharing rules include at least one of result watermarking, key encryption, and administrator review, where: Result watermarking method: Add a watermark to the analysis results in the format and embedding method selected by the user. The user obtains the result file with the watermark. This method needs to be approved by the administrator. Key encryption method: The user provides an encryption key, and the system uses it to encrypt the analysis results before returning them. The process requires administrator approval to ensure the confidentiality of data transmission and storage; Administrator review method: After the user submits a download application, the system automatically identifies sensitive data. The administrator reviews the identification results together with the original data. Only after approval can the user download the actual analysis results.

6. A medical data privacy protection and sharing method based on a secure data sandbox, characterized in that: The steps include: S1. Collect patient data from different data sources in medical institutions and import the collected patient data into a secure data sandbox; S2. Desensitize, encrypt, and standardize patient data imported into the secure data sandbox to ensure that the data complies with privacy protection requirements; S3. Dynamically configure the security policies of the sandbox environment, including data isolation levels and access control rules, based on data analysis or sharing requirements. S4. Run data analysis tasks in a sandbox environment to ensure that patient privacy is not disclosed during data processing; S5. Securely share the processing results with authorized external organizations or researchers according to pre-set sharing rules, and record the sharing behavior for auditing; S6. Conduct a full audit of the data processing and sharing process from step S2 to step S5 to ensure compliance with medical data privacy protection regulations.

7. The medical data privacy protection and sharing method based on secure data sandbox according to claim 6 is characterized in that: The step S2 specifically includes: S2.

1. Based on pre-set sensitive data identification rules, perform sensitive data identification on the received patient data; S2.

2. Set desensitization rules for different sensitive types, match the corresponding desensitization rules based on the identification results, and then execute the desensitization rules to desensitize sensitive data; S2.

3. Sample unidentified patient data and desensitized sensitive data using at least one of the following algorithms: rapid sampling, random sampling, and intelligent sampling to obtain sample data; S2.

4. Use intelligent simulation technology based on large models to simulate the acquired sample data and generate sample data without sensitive information; S2.

5. Upload the generated sample data to the sandbox environment for subsequent data analysis and model training.

8. The medical data privacy protection and sharing method based on secure data sandbox according to claim 7 is characterized in that: Execute step S3 to dynamically configure the security policy of the sandbox environment based on data analysis or sharing requirements, including three data isolation levels: process isolation, container isolation, and physical isolation, as well as access control rules based on user roles and time context.

9. The medical data privacy protection and sharing method based on secure data sandbox according to claim 8 is characterized in that: The sandbox environment includes a running environment and a debugging environment. The running environment supports access to the patient data imported in step S1, and the debugging environment supports access to the sample data uploaded in step S2.

5. Users use sample data to conduct modeling training in the debugging environment, optimize model parameters through the debugging environment's visualization tools, obtain a prediction model that meets the requirements, and then submit the prediction model to the operating environment. The prediction model automatically accesses the patient data in the operating environment, processes the data according to preset logic, and generates analysis results. The operating environment encrypts and stores the analysis results, allowing only authorized users to access them.

10. The medical data privacy protection and sharing method based on secure data sandbox according to claim 6, characterized in that: The preset sharing rules include at least one of result watermarking, key encryption, and administrator review, where: Result watermarking method: Add a watermark to the analysis results in the format and embedding method selected by the user. The user obtains the result file with the watermark. This method needs to be approved by the administrator. Key encryption method: The user provides an encryption key, and the system uses it to encrypt the analysis results before returning them. The process requires administrator approval to ensure the confidentiality of data transmission and storage; Administrator review method: After the user submits a download application, the system automatically identifies sensitive data. The administrator reviews the identification results together with the original data. Only after approval can the user download the actual analysis results.