Psychiatric electronic medical record system and device based on national secret algorithm

The electronic medical record system for psychiatric specialties based on national cryptographic algorithms solves the problem that existing systems cannot meet the requirements for data security and privacy protection in psychiatric specialties, and achieves full-cycle encryption to ensure data security and reliability.

CN120853779APending Publication Date: 2025-10-28SHANGHAI CHANGNING DISTRICT MENTAL HEALTH CENT +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510923322.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Existing electronic medical record systems are not adapted to the characteristics of psychiatric medical record data, especially in terms of data security, privacy protection, and long-term storage, and cannot meet the special needs of psychiatric medical records.

Method used

The electronic medical record system for mental health specialties, which adopts national cryptographic algorithms, includes a user authentication module, a data classification and encryption module, an encrypted data storage module, and a communication module. It uses national cryptographic algorithms to perform user authentication, data classification encryption, and storage, achieving full-cycle encryption and ensuring data security and privacy.

Benefits of technology

It effectively protects electronic medical record data in psychiatric specialties in terms of privacy management, long-term tracking and storage, and prevention of leakage through sharing during medical visits, thereby improving the security and reliability of the data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120853779A_ABST
    Figure CN120853779A_ABST
Patent Text Reader

Abstract

The invention provides a special psychiatric electronic medical record system and a special psychiatric electronic medical record device based on a national cryptographic algorithm, aiming at a login registration request of an electronic medical record user side, the national cryptographic algorithm is used for carrying out user identity verification, and after the verification is passed, the national cryptographic algorithm is used for carrying out classified encryption processing on user side data to form national cryptographic encrypted data and storing the national cryptographic encrypted data. And data needing to be transmitted to other systems or received from other systems are adapted through the data adaptation intermediate layer, so that the national secret data and the international data are transmitted to corresponding systems, and the national secret data of other systems are stored. By means of full-period encryption based on the national secret algorithm, the protection requirements of the psychiatric electronic medical record data in the aspects of privacy management, long-term tracking storage, doctor-seeing sharing leakage prevention and the like are fully met, and a powerful guarantee is provided for the safety and reliability of the electronic medical record data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electronic medical records, and in particular to a psychiatric electronic medical record system and device based on national cryptographic algorithms. Background Technology

[0002] With the rapid development of medical informatization, electronic medical record (EMR) systems have been widely used in medical institutions at all levels, greatly improving the efficiency of medical data management and the collaboration in diagnosis and treatment. However, most EMR systems currently on the market are general designs and lack in-depth adaptation for psychiatric specialties. Psychiatric medical records have specific requirements.

[0003] First, psychiatric medical records often involve complex data types. These records need to encompass multidimensional data, including assessments of the patient's complex mental state, disease progression, psychological scale tests, electroencephalogram (EEG) data, and imaging data, as well as descriptive assessments of the condition. Different types of data have varying requirements for encryption and security processing. Second, this data often contains a large amount of personal privacy information, such as psychological state, family conflicts, and personal privacy incidents, making it highly sensitive in terms of privacy protection. Third, psychiatric medical records require long-term preservation: mental illnesses often have the characteristic of "one illness, lifelong treatment," and patient histories need to be preserved long-term to track treatment effects and changes in the condition. This not only requires responsible personnel to provide accountable observations of the condition at each stage of the record-keeping process but also places higher demands on the security and stability of data storage.

[0004] Although some electronic medical record (EMR) systems have adopted national cryptographic algorithms to enhance information encryption and protection, these applications have not been optimized to address the specific data characteristics and security requirements of psychiatric medical records. Psychiatric patient data involves personal privacy and sensitive psychological information; leakage would have serious consequences. Existing systems cannot adequately guarantee the confidentiality and integrity of psychiatric medical record data. Therefore, there is an urgent need to develop an EMR system that meets the requirements of psychiatric medical records and deeply integrates national cryptographic algorithms. Summary of the Invention

[0005] In view of the shortcomings of the prior art described above, the purpose of this invention is to provide a psychiatric electronic medical record system and device based on national cryptographic algorithms, in order to solve the problems that existing psychiatric electronic medical record systems cannot adapt to the characteristics of psychiatric electronic medical record data and cannot guarantee data security.

[0006] To achieve the above and other related objectives, a first aspect of the present invention provides a psychiatric electronic medical record system based on national cryptographic algorithms. The system includes: a user authentication module, a data classification and encryption module, an encrypted data storage module, and a communication module. The user authentication module is used to authenticate a user's identity using national cryptographic algorithms based on a user login / registration request sent by the electronic medical record user terminal. The data classification and encryption module, connected to the user authentication module, is used to classify and encrypt data from the electronic medical record user terminal using national cryptographic algorithms after successful user authentication, obtaining national cryptographically encrypted data. The encrypted data storage module, connected to the data classification and encryption module, is used to store the national cryptographically encrypted data. The communication module includes a data adaptation intermediate layer, connected to the encrypted data storage module, used to adapt national cryptographically encrypted data that needs to be transmitted to other systems or data from other systems through the data adaptation intermediate layer, so as to transmit national cryptographic or international data to the corresponding system, or to store national cryptographic data in the encrypted data storage module.

[0007] In some embodiments of the first aspect of the present invention, the user authentication module performs user authentication using a corresponding national cryptographic algorithm authentication method based on the type of the electronic medical record user terminal that sends the user login / registration request. Specifically, if the electronic medical record user terminal sending the user login / registration request is an electronic medical record healthcare terminal, a combination of digital certificate authentication based on the SM2 algorithm, dynamic password authentication, and biometric recognition is used for user authentication, and user access permissions are determined after successful authentication. If the electronic medical record user terminal sending the user login / registration request is an electronic medical record patient terminal, a combination of mobile phone number, SMS verification code, and biometric recognition is used for user authentication, and user access permissions are determined after successful authentication.

[0008] In some embodiments of the first aspect of the present invention, the data classification encryption module includes: a structured data encryption unit, used to encrypt structured data transmitted from the electronic medical record user terminal using field encryption; an unstructured data encryption unit, used to encrypt unstructured data transmitted from the electronic medical record user terminal using file encryption; and an encrypted data verification unit, connected to the structured data encryption unit and the unstructured data encryption unit, used to calculate the SM3 hash value of the encrypted data to generate an encrypted data digest, so as to verify whether the encrypted data has been tampered with.

[0009] In some embodiments of the first aspect of the present invention, the encryption using field encryption includes: encrypting structured data by field according to the cipher block chaining mode of the SM4 algorithm; the encryption using file encryption includes: generating an independent key using the CTR mode of the SM4 algorithm and encrypting the file based on the key.

[0010] In some embodiments of the first aspect of the present invention, the encrypted data storage module is used to uniformly store the encrypted data, the corresponding encrypted data digest, and the corresponding timestamp.

[0011] In some embodiments of the first aspect of the present invention, the communication module uses the SSL / TLS protocol based on the SM2, SM3, and SM4 algorithms to form an encrypted channel with other systems.

[0012] In some embodiments of the first aspect of the present invention, the data adaptation intermediate layer includes an environment parameter parsing submodule and an adaptation submodule; wherein, the environment parameter parsing submodule is used to identify the encryption environment of other systems; the adaptation submodule includes independently encapsulated Chinese cryptographic algorithms and international algorithms, used to call and convert encryption algorithms adapted to the corresponding environment according to the identified encryption environment information; when the environment parameter parsing submodule identifies that other systems are Chinese cryptographic encryption environments, the Chinese cryptographic encryption processing data is directly interacted in the encryption channel; when the environment parameter parsing submodule identifies that other systems are international encryption environments, the international encryption processing data is converted into Chinese cryptographic encryption processing data by the adaptation submodule and then enters the Chinese cryptographic encryption environment through the encryption channel; the Chinese cryptographic encryption processing data is converted into international encryption processing data by the adaptation submodule and then enters the international encryption environment through the encryption channel.

[0013] In some embodiments of the first aspect of the present invention, the international encryption environment identified by the environmental parameter parsing submodule can be an intranet system or an extranet system: when the international encryption environment is an intranet system, the international encryption processing data of the intranet system is converted into national cryptographic encryption processing data through the data adaptation intermediate layer and then enters the encrypted data storage module through the encryption channel; the national cryptographic encryption processing data retrieved from the encrypted data storage module is converted into international encryption processing data through the data adaptation intermediate layer and then enters the intranet system through the encryption channel; when the international encryption environment is an extranet system, the international encryption processing data of the extranet system is converted into national cryptographic encryption processing data through the data adaptation intermediate layer and then enters the encrypted data storage module through the encryption channel; the national cryptographic encryption processing data retrieved from the encrypted data storage module is converted into international encryption processing data through the data adaptation intermediate layer and then enters the extranet system through the encryption channel.

[0014] In some embodiments of the first aspect of the present invention, the electronic medical record system for mental health based on the national cryptographic algorithm further includes a key management module, which includes a key generation submodule, a key distribution submodule, and a key update and destruction submodule.

[0015] To achieve the above and other related objectives, a second aspect of the present invention provides a psychiatric electronic medical record device based on a national cryptographic algorithm. The device includes a memory, a processor, and a computer program stored in the memory.

[0016] As described above, the psychiatric electronic medical record system and device based on national cryptographic algorithms of the present invention has the following beneficial effects: The present invention uses national cryptographic algorithms to conduct user authentication for login and registration requests on the electronic medical record user terminal. After successful authentication, the user terminal data is classified and encrypted using national cryptographic algorithms to form national cryptographic encrypted data, which is then stored. For data that needs to be transmitted to or received from other systems, adaptation is performed through a data adaptation intermediate layer to realize the transmission of national cryptographic and international data between corresponding systems, as well as the storage of national cryptographic data from other systems. With its full-cycle encryption based on national cryptographic algorithms, the present invention fully meets the protection needs of psychiatric electronic medical record data in terms of privacy management, long-term tracking and storage, and prevention of leakage in shared medical records, providing strong protection for the security and reliability of electronic medical record data, and has significant practical value and inventiveness. Attached Figure Description

[0017] Figure 1 The diagram shown is a schematic of a module of a psychiatric electronic medical record system based on national cryptographic algorithms in one embodiment of the present invention.

[0018] Figure 2 The diagram shown is a structural schematic of a mental health electronic medical record management platform based on national cryptographic algorithms in one embodiment of the present invention.

[0019] Figure 3 The diagram shown is a schematic diagram of the process structure of the electronic medical record system for mental health based on the national cryptographic algorithm in an embodiment of the present invention.

[0020] Figure 4 The diagram shown is a schematic diagram of a mental health electronic medical record system based on national cryptographic algorithms in one embodiment of the present invention. Detailed Implementation

[0021] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, unless otherwise specified, the following embodiments and features described therein can be combined with each other.

[0022] It should be noted that in the following description, reference is made to the accompanying drawings, which illustrate several embodiments of the invention. It should be understood that other embodiments may also be used, and changes in mechanical composition, structure, electrical system, and operation may be made without departing from the spirit and scope of the invention. The following detailed description should not be considered limiting, and the scope of the embodiments of the invention is defined only by the claims of the published patents. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. Spatially related terms, such as “upper,” “lower,” “left,” “right,” “below,” “below,” “lower part,” “above,” “upper part,” etc., may be used herein to illustrate the relationship between one element or feature shown in the figures and another element or feature.

[0023] Throughout this specification, when it is said that a part is "connected" to another part, this includes not only "direct connection" but also "indirect connection" by placing other elements in between. Furthermore, when it is said that a part "includes" a certain constituent element, unless otherwise stated otherwise, this does not exclude other constituent elements, but rather means that other constituent elements may also be included.

[0024] The terms "first," "second," and "third," etc., used herein are for the purpose of describing various parts, components, regions, layers, and / or segments, but are not limiting. These terms are used only to distinguish one part, component, region, layer, or segment from others. Therefore, the "first part," "component," "region," "layer," or "segment" described below may refer to a "second part," "component," "region," "layer," or "segment" without departing from the scope of this invention.

[0025] Furthermore, as used herein, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It should be further understood that the terms “comprising,” “including,” indicate the presence of the stated feature, operation, element, component, item, kind, and / or group, but do not preclude the presence, occurrence, or addition of one or more other features, operations, elements, components, items, kinds, and / or groups. The terms “or” and “and / or” as used herein are interpreted as inclusive, or mean any one or any combination thereof. Thus, “A, B, or C” or “A, B, and / or C” means “any one of: A; B; C; A and B; A and C; B and C; A, B, and C.” Exceptions to this definition arise only when combinations of elements, functions, or operations are inherently mutually exclusive in some manner.

[0026] This invention provides a psychiatric electronic medical record system based on national cryptographic algorithms. For login and registration requests from electronic medical record users, national cryptographic algorithms are used for user authentication. After successful authentication, user-end data is categorized and encrypted using national cryptographic algorithms to form nationally encrypted data, which is then stored. For data that needs to be transmitted to or received from other systems, an adaptation middleware layer is used to enable the transmission of national and international cryptographic data between corresponding systems, as well as the storage of national cryptographic data from other systems. This invention, with its full-lifecycle encryption based on national cryptographic algorithms, fully meets the protection needs of psychiatric electronic medical record data in terms of privacy management, long-term tracking and storage, and prevention of leakage during patient sharing, providing strong protection for the security and reliability of electronic medical record data.

[0027] The present invention will now be described in detail with reference to the accompanying drawings, so that those skilled in the art can readily implement it. The present invention can be embodied in many different forms and is not limited to the embodiments described herein.

[0028] like Figure 1 The illustration shows a schematic diagram of a psychiatric electronic medical record system based on national cryptographic algorithms in an embodiment of the present invention.

[0029] The system includes: a user authentication module 101, a data classification and encryption module 102, an encrypted data storage module 103, and a communication module 104. The user authentication module 101 is used to authenticate users using a national cryptographic algorithm based on user login / registration requests sent by the electronic medical record user terminal. The data classification and encryption module 102, connected to the user authentication module 101, is used to classify and encrypt data from the electronic medical record user terminal using a national cryptographic algorithm after successful user authentication, obtaining national cryptographic encrypted data. The encrypted data storage module 103, connected to the data classification and encryption module 102, is used to store the national cryptographic encrypted data. The communication module 104, connected to the encrypted data storage module 103, includes a data adaptation middleware layer connected to the encrypted data storage module 103, used to adapt national cryptographic encrypted data that needs to be transmitted to other systems or received data from other systems through the data adaptation middleware layer, so as to transmit national cryptographic or international data to the corresponding system, or store national cryptographic data in the encrypted data storage module 103.

[0030] In one embodiment, the user authentication module 101 performs user authentication using a corresponding national cryptographic algorithm based on the type of the electronic medical record user terminal that sent the user login / registration request; wherein,

[0031] If the electronic medical record user terminal sending the user login / registration request is the electronic medical record healthcare terminal, user authentication is performed using a combination of digital certificate authentication based on the SM2 algorithm, dynamic password authentication such as dynamic passwords generated by hardware tokens, and biometric recognition such as fingerprints or facial recognition. If the electronic medical record user terminal sending the user login / registration request is the electronic medical record patient terminal, user authentication is performed using a combination of mobile phone number, SMS verification code, and biometric recognition such as fingerprints or facial recognition.

[0032] After identity authentication, user access permissions are determined for both the medical staff and patient ends of the electronic medical record system. These permissions are set based on the user's identity and responsibilities. Specifically, psychiatrists have the authority to view, create, and modify the medical history of patients in their department; psychotherapists can only view and update the medical history related to psychotherapy; hospital administrators can view the management and statistical information of all patient medical history in the hospital, but cannot directly access the detailed medical history of specific patients; nurses have the authority to execute and record nursing orders issued by doctors, enter patient nursing observation records, and record patient daily behavior scales, but do not have the authority to modify diagnosis and treatment plans or view patients' historical medical records; patients can view the non-sensitive parts of their own medical records and examination and test reports, and can submit self-assessment records and apply for follow-up consultations. Considering the mental state of patients with mental illness, access to complete diagnostic evidence that may affect the patient's condition is generally restricted, and access to other patients' medical records is prohibited. Taking doctor access as an example, the SM9 algorithm generates a different key encryption key (KEK) for each doctor in each department. When a doctor accesses data, they need to use the department-specific KEK to decrypt the field encryption key (DEK), and then use the DEK to decrypt the data, thus achieving categorized access control. In addition, during the access control process, the SM2 algorithm encrypts, stores, and verifies user permission information to ensure the security of permission information.

[0033] In one embodiment, the data classification encryption module 102 includes: a structured data encryption unit, used to encrypt the structured data transmitted from the electronic medical record user terminal using field encryption; the structured data includes the patient's medical record text, psychological assessment results, etc., and is encrypted using field encryption.

[0034] The unstructured data encryption unit is used to encrypt unstructured data transmitted from the electronic medical record user terminal using file encryption methods; the unstructured data includes electroencephalographic data, imaging data, etc., and is encrypted using file encryption methods.

[0035] The encrypted data verification unit connects the structured data encryption unit and the unstructured data encryption unit. It is used to calculate the SM3 hash value of the encrypted data to generate an encrypted data digest. The SM3 digital digest generates a unique 256-bit fixed-length digest for any data and uses collision resistance and one-wayness to realize data integrity verification, thereby verifying whether the encrypted data generated by the above units has been tampered with.

[0036] In one embodiment, the encryption using field encryption includes: encrypting structured data by field using a CBC mode based on the SM4 algorithm. Taking a MySQL database as an example, a custom stored procedure is developed to call the SM4 encryption function during data insertion to encrypt sensitive fields such as diagnostic conclusions and treatment plans. For example, for the `diagnosis_result` field, before executing the INSERT INTO medical_history(patient_id,diagnosis_result,...) statement, the value of `diagnosis_result` is first encrypted using the SM4 encryption function SM4_encrypt('diagnosis content', master key), and then the ciphertext is inserted into the database.

[0037] In one embodiment, the file encryption method includes: generating an independent key using the CTR mode of the SM4 algorithm and encrypting the file based on that key. Taking a DICOM format MRI image file as an example, an encryption tool is developed to read the file header information and pixel data. After dividing the pixel data into fixed block sizes, it is encrypted using the SM4-CTR mode, and the DICOM file is regenerated after encryption. A 128-bit random key is generated for each file, and the key is bound to identifiers such as patient ID and file type using the SM9 algorithm. The key is stored in an independent key management table, and access requires verification of user permissions and identifier information to obtain the key.

[0038] In one embodiment, the encrypted data storage module 103 is used to uniformly store the national cryptographic encryption data, the corresponding encrypted data digest, and the corresponding timestamp. The encrypted data storage module 103 associates and stores the SM4-encrypted national cryptographic encryption data, the ciphertext data digest generated by the SM3 algorithm, and the timestamp containing the SM3 hash, thereby achieving end-to-end secure management and control of data storage in terms of encrypted storage, integrity verification, and time traceability. This ensures the confidentiality, integrity, and operational auditability of psychiatric electronic medical record data during the storage process.

[0039] In one embodiment, the communication module uses the SSL / TLS protocol based on SM2, SM3, and SM4 algorithms to form an encrypted channel with other systems. During data transmission using national cryptographic encryption, a secure communication channel is constructed using the national cryptographic SSL / TLS protocol based on SM2, SM3, and SM4 algorithms, providing a secure encrypted channel for data interaction between different systems within the hospital and with external institutions. This protocol uses the SM2 algorithm to achieve two-way authentication and key negotiation between the server and client, utilizes the SM3 algorithm to perform hash operations on the transmitted data to generate a unique digest for integrity verification, and employs the SM4 algorithm for symmetric encryption of the transmitted data to ensure confidentiality. Within the hospital, data interaction between the HIS / LIS system and the electronic medical record system, as well as information transmission between the nurse station terminal and the server, are all conducted through this encrypted channel, preventing internal personnel from intercepting and stealing data or tampering with the transmitted content. In external data sharing scenarios, such as data transmission between the hospital and research institutions, regional medical platforms, or overseas institutions, both parties complete authentication and establish a secure connection through the national cryptographic SSL / TLS handshake protocol.

[0040] In one embodiment, the data adaptation intermediate layer includes an environment parameter parsing submodule and an adaptation submodule; wherein,

[0041] The environment parameter parsing submodule is used to identify the encryption environment of other systems that transmit data with the system. This submodule acquires key parameters supporting the adaptation algorithm through multiple data acquisition methods: on the one hand, it reads static configuration information such as network environment identifiers and security policy levels from the system configuration file to clarify the basic security framework of the current operating environment; on the other hand, it parses network protocol header information in real time, such as encryption protocol fields in HTTP request headers, algorithm negotiation data during the TLS handshake phase, and dynamic parameters transmitted by the application, such as target system type and data sensitivity level markers, to obtain a list of algorithms supported by the target system, such as the Chinese national cryptographic algorithms SM2 / SM3 / SM4 or international algorithms RSA / AES / SHA-256, and encryption protocol versions such as the Chinese national cryptographic SSL protocol GMT 0024 or the international protocol TLS 1.3, etc. For example, when the environment parameter parsing submodule reads intranet parameters from the system configuration file, it can determine that it is an intranet environment; if a Chinese national cryptographic identifier is detected in the fields of the network request header, it confirms that the target system supports Chinese national cryptographic encryption; conversely, if an international algorithm identifier is identified, it switches to international algorithm adaptation logic. This multi-dimensional environmental parameter analysis provides accurate decision-making basis for the adaptation submodule, enabling it to dynamically select and call the corresponding encryption algorithm interface based on the acquired environmental identifiers and algorithm support information. This achieves automatic conversion and seamless integration of encryption algorithms when exchanging data between different systems, thereby ensuring the security of data transmission in complex network environments.

[0042] The adaptation submodule includes independently encapsulated Chinese cryptographic algorithms and international algorithms, used to call and adapt encryption algorithms to the corresponding environment based on the identified encryption environment information. The adaptation submodule integrates Chinese cryptographic algorithms (such as SM2, SM3, SM4, SM9, etc.) and mainstream international algorithms (such as RSA, SHA-256, AES, etc.), constructing a flexible algorithm calling system through modular design. This module encapsulates the core functions of each algorithm into independent function modules. For example, the encryption and decryption operations of the SM4 algorithm are encapsulated into the SM4_encrypt() and SM4_decrypt() functions respectively, and the AES algorithm is also encapsulated into corresponding functions, thus achieving standardized encapsulation of encryption and decryption logic for different algorithms. Each function module follows a unified interface specification, with consistent input parameters such as the data to be processed, the key, and the output format. Upper-layer applications do not need to concern themselves with the specific algorithm implementation details; they only need to call the standard interface to complete the encryption or decryption operation. For example, when the system detects that the target environment supports the SM9 identifier cryptography algorithm, the adaptation submodule can directly call the SM9_encrypt() function to encrypt the data. If the system detects that the international environment requires the AES algorithm, it automatically switches to the AES_encrypt() function. The entire process is seamlessly integrated through a unified interface. This design, which abstracts algorithm functions into independent modules and provides standard calling interfaces, not only ensures the coexistence and flexible switching of national and international cryptographic algorithms within the same system, but also improves the maintainability and scalability of the system through standardized encapsulation. This provides efficient technical support for the secure interaction of electronic medical record data in psychiatric hospitals under different encryption environments.

[0043] Specifically, when the environment parameter parsing submodule identifies the target system as a national cryptographic encryption environment through system configuration files, network protocol headers, or application parameters, the data is directly encrypted using national cryptographic algorithms such as SM2 and SM4, and interacted in an encrypted channel built on the national cryptographic SSL / TLS protocol to ensure compliance with domestic cryptographic application standards.

[0044] When the environment parameter parsing submodule identifies the target system as an international encryption environment through system configuration, network protocol headers, or application parameters, the data adaptation middleware layer will perform bidirectional algorithm conversion and secure transmission according to the data flow: If it is necessary to transmit national cryptographically encrypted data, such as SM2 signatures or SM4 encrypted diagnostic records, to an international encryption environment, the adaptation submodule will call international algorithms to convert SM2 encrypted data into RSA encrypted data, SM4 encrypted data into AES encrypted data, and SM3 encrypted data into SHA-256 encrypted data. After conversion, it will be sent to the target system through an SSL / TLS encrypted channel. For example, when a hospital shares de-identified data with a multinational pharmaceutical company that uses international encryption standards, it needs to convert the SM4 encrypted medication record data into AES format before transmission. If encrypted data is received from an international encryption environment, the adaptation submodule will call national cryptographic algorithms to convert RSA encrypted data into SM2 encrypted data, AES encrypted data into SM4 encrypted data, and SHA-256 encrypted data into SM3 encrypted data. The converted national cryptographically encrypted data will be stored in the encrypted data storage module 103 after its integrity is verified through the SSL / TLS channel. Throughout the process, the environmental parameter parsing submodule monitors the target system's algorithm support list and security level requirements in real time, dynamically adjusts the conversion strategy, and achieves secure data exchange and storage under different encryption systems.

[0045] In one embodiment, the communication module 104 can interact with other systems via an intranet or an extranet: when the data adaptation intermediate layer under the communication module identifies the target system as an international encrypted environment, regardless of whether the system is an intranet system or an extranet system, the data adaptation intermediate layer will perform bidirectional algorithm conversion based on the identification result.

[0046] If the international encryption environment is an intranet system, the internationally encrypted data it generates (such as RSA / AES / SHA-256 encryption) will first be converted into national cryptographic encryption data (corresponding to SM2 / SM4 / SM3 format) through a data adaptation intermediate layer, and then enter the encrypted data storage module 103 via a national cryptographic SSL / TLS encrypted channel. Conversely, national cryptographic encryption data retrieved from the encrypted data storage module 103 will be converted back to the international encryption format to adapt to the target system when returned to the intranet system. For example, when an internationally encrypted LIS system interacts with a nationally encrypted electronic medical record system within a hospital, the image data of the LIS system will undergo format conversion before transmission.

[0047] If the international encryption environment is an external network system, such as an overseas research institution or a cross-regional medical platform, the internationally encrypted data of the external network system will also be converted to the national cryptographic format through the data adaptation intermediate layer before storage. Data retrieved from the encrypted data storage module 103, however, needs to be converted to an international format before being transmitted to the external network system through the encrypted channel. For example, when a hospital shares de-identified data with a WHO database using international encryption standards, the data will first be converted from SM4 / SM3 format to AES / SHA-256 format before transmission. This bidirectional conversion mechanism, through the dynamic scheduling of the data adaptation intermediate layer, ensures that regardless of whether the target system is located on an internal or external network, or uses national or international cryptographic algorithms, data can flow securely through the encrypted channel, while simultaneously meeting the national cryptographic encryption requirements of the storage stage, thus achieving data interoperability and secure storage between different encryption environments.

[0048] In one embodiment, the electronic medical record system for psychiatric specialties based on national cryptographic algorithms further includes a key management module, which is used for key generation, key distribution, and key updating and destruction.

[0049] Key generation involves using a national cryptographic random number generator to generate encryption keys, ensuring their randomness and unpredictability. Specific keys are generated for different data types and encryption scenarios, such as data storage keys, data transmission keys, and authentication keys. Key distribution utilizes a key distribution protocol based on the SM2 algorithm to distribute keys to authorized users and system components. For example, when medical staff join the workforce, their digital certificates and related keys are distributed to their work terminals through the hospital's internal security network, with strict access verification. Key updates and destruction require regular key updates. A reasonable update cycle is set based on key usage frequency and security requirements. When a key is no longer in use or reaches its expiration date, it is securely destroyed according to a prescribed procedure to prevent security risks from key leakage.

[0050] In one embodiment, the electronic medical record system for psychiatric specialties based on national cryptographic algorithms uses national cryptographic algorithms for protection in both log recording and audit security.

[0051] A sophisticated security audit log mechanism is established within the medical history system. This includes creating comprehensive security audit logs to record key user actions such as login, data access, and key management. Log content includes information such as operation time, user, operation type, target, and result. To prevent malicious tampering, the system uses the national cryptographic SM3 hash algorithm to generate a unique 256-bit digest for each log entry. This digest is stored synchronously with the log content, ensuring the content remains tamper-proof and unforgeable during transmission.

[0052] In the audit and analysis phase, security audit logs are analyzed regularly to promptly identify abnormal operations and security vulnerabilities. For example, analyzing user login failure records identifies brute-force attacks; monitoring data access frequency and scope reveals unauthorized access. Simultaneously, big data analytics is used to deeply mine audit logs, providing a basis for optimizing system security strategies. The entire log and audit system is based on national cryptographic algorithms, forming a closed-loop national cryptographic encryption security system from integrity protection during log generation and confidentiality assurance during transmission to behavioral modeling during analysis.

[0053] It should be noted that the division of modules in the embodiment of the psychiatric electronic medical record system based on national cryptographic algorithms is merely a logical functional division. In actual implementation, all or part of these modules can be integrated into a single physical entity, or they can be physically separated. Furthermore, these units can be implemented entirely in software through processing element calls; they can be implemented entirely in hardware; or some units can be implemented by processing element calls to software, while others are implemented in hardware. Since the implementation principle of the multi-camera target counting system based on dynamic warning lines has been described in the preceding embodiments, it will not be repeated here.

[0054] To better illustrate the above-mentioned electronic medical record system for psychiatry based on national cryptographic algorithms, the present invention provides the following specific embodiments.

[0055] Example 1: Figure 2 This is a schematic diagram of the structure of the electronic medical record management platform for psychiatry described in this embodiment.

[0056] The user authentication module can cover the architecture layers, including the access layer, interface layer, and service layer.

[0057] At the access layer, IoT devices, mobile apps, and PCs at the access layer initiate connections through SSL / TLS channels. The terminals have built-in SM2 digital certificates and use SM2 private keys to sign and prove their identity during the handshake phase. The API gateway at the interface layer verifies the legitimacy through SM2 public keys.

[0058] At the interface layer, in addition to verifying the terminal identity, the API gateway also verifies the SM2 signature token in the request (such as user login status, device authorization code) to block unauthorized access; and verifies the integrity of the request through SM3 hash to prevent tampering.

[0059] For the service layer, when a request enters the business service, the permission system calls the SM2-signed RPC interface to verify the service identity, such as whether the HIS system has permission to read and write medical records, and determines the user's operation permissions according to the SM4-encrypted permission rules.

[0060] The data classification and encryption module covers an architecture layer including an interface layer and a service layer.

[0061] Data classification at the interface layer: After the API gateway decrypts the terminal request via the SM4 algorithm, it automatically classifies and marks the data according to the URL path and data type, such as text medical records or test images, and forwards it to the corresponding business service.

[0062] At the service layer, national cryptographic algorithms are used for encryption: text-based medical records, such as diagnostic descriptions, are encrypted using SM4 CBC mode fields; image files, such as DICOM format files, are encrypted using SM4 CTR mode files; and basic service components, such as Redis cache, RocketMQ messages, and log components, are encrypted using their respective national cryptographic algorithms.

[0063] The encrypted data storage module primarily covers the storage layer of the architecture:

[0064] Files, including medical images and PDF medical records, are encrypted using the SM4 algorithm before storage. Decryption keys must be obtained from the key management module. Redis caches and audit logs are encrypted using their respective national cryptographic algorithms.

[0065] The communication module mainly covers the architecture layer, including the interface layer and the service layer:

[0066] At the interface layer, protocol encryption is used. HTTP / HTTPS uses the Chinese national cryptographic standard SSL. The terminal and API gateway negotiate the session key through SM2, encrypt the request or response content with SM4, and verify the integrity with SM3. If connecting to a HIS system that has not been upgraded to Chinese cryptographic standard, the API gateway has a built-in data adaptation middleware layer to realize the conversion between SM4 and AES algorithms, and the conversion between Chinese national cryptographic standard SSL and international TLS protocols.

[0067] Within the service layer, inter-service calls (REST / RPC) are transmitted via a national cryptographic SSL channel, with the request body encrypted using SM4 to ensure secure intranet communication; message queues (RocketMQ) not only encrypt the message body but also support national cryptographic message filtering.

[0068] It is worth noting that the data adaptation middleware layer covers the service layer. When interacting with intranet systems such as HIS and LIS, the middleware layer automatically handles: Algorithm adaptation: If the intranet uses AES encryption, it converts SM4 encrypted data into AES encrypted data (or vice versa), so that the data of the intranet system that has not been modified with national cryptographic data can interact with the national cryptographic data of the electronic medical record system, reducing the cost of hospital system modification.

[0069] Taking the application of electronic medical record management platforms in psychiatric specialties by doctors as an example:

[0070] Identity authentication module: Doctors initiate requests through the mobile APP (access layer). The APP signs the identity information with the SM2 private key. The API gateway (interface layer) verifies the identity information with the SM2 public key. The permission system (service layer) verifies whether the doctor has permission to query the medical record based on the permission rules encrypted with SM4.

[0071] Data classification and encryption module: After the permission verification is passed, the electronic medical record service (service layer) encrypts the text content with SM4 CBC and the image file with SM4 CTR according to the medical record type, and generates an SM3 hash value.

[0072] Communication module: The encrypted data is returned to the APP through the national cryptographic SSL channel (interface layer). The APP decrypts the data using the session key and displays the plaintext. If it needs to be synchronized to the HIS system, the data adaptation intermediate layer converts the SM4 ciphertext into a format supported by HIS for encrypted transmission.

[0073] Encrypted data storage module: If a doctor modifies a medical record, the new data is encrypted with SM4, and the key obtained through the key management module is written to the encrypted database and Redis cache. At the same time, the operation log of SM3 hash + SM2 signature is recorded in the log component.

[0074] Similar to the principles of the above embodiments, the present invention provides a method for electronic medical records in psychiatry based on national cryptographic algorithms.

[0075] like Figure 3 The method includes:

[0076] Step S31: The electronic medical record user terminal sends a user login / registration request, uses the national cryptographic algorithm to authenticate the user and confirm user permissions;

[0077] Step S32: Use the national cryptographic algorithm to classify and encrypt the data from the electronic medical record user terminal to obtain the national cryptographic encrypted data and generate the corresponding encrypted data digest;

[0078] Step S33: Store the data encrypted with national cryptographic standards, the corresponding encrypted data digest, and the timestamp in a unified manner;

[0079] Step S34: Transmit the national cryptographic encryption data that needs to be transmitted to other systems or the data received from other systems to the corresponding system after adaptation, and store the received national cryptographic data in the encrypted data storage module.

[0080] Similar to the principles of the above embodiments, the present invention provides a psychiatric electronic medical record device based on national cryptographic algorithms.

[0081] The psychiatric electronic medical record system based on national cryptographic algorithms provided in this invention can be implemented on the terminal side or the server side. For the hardware structure of the application terminal of the psychiatric electronic medical record system based on national cryptographic algorithms, please refer to [link to relevant documentation]. Figure 4 This is a schematic diagram of an optional hardware structure of an application terminal 4000 for a psychiatric electronic medical record system based on national cryptographic algorithms, provided in an embodiment of the present invention. Figure 4 As shown, the computer device includes at least one processor 401, a memory 402, at least one network interface 403, and a user interface 405. The various components in the device are coupled together via a bus system 404. It is understood that the bus system 404 is used to implement communication between these components. In addition to a data bus, the bus system 404 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in… Figure 4 The general will label all buses as bus systems.

[0082] The user interface 405 may include a monitor, keyboard, mouse, trackball, clicker, button, touchpad, or touch screen.

[0083] It is understood that memory 402 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM) or programmable read-only memory (PROM), used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM) and synchronous static random access memory (SSRAM). The memories described in the embodiments of this invention are intended to include, but are not limited to, these and any other suitable categories of memory.

[0084] In this embodiment of the invention, the memory 402 is used to store various types of data to support the operation of the electronic terminal 400. Examples of this data include: any executable program for operation on the electronic terminal 400, such as the operating system 4021 and application program 4022; the operating system 4021 contains various system programs, such as the framework layer, core library layer, driver layer, etc., for implementing various basic services and handling hardware-based tasks. The application program 4022 may contain various applications, such as a media player, browser, etc., for implementing various application services. The implementation of the multi-camera target counting method based on dynamic warning lines provided in this embodiment of the invention can be included in the application program 4022.

[0085] The methods disclosed in the above embodiments of the present invention can be applied to processor 401, or implemented by processor 401. Processor 401 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in processor 401 or by instructions in the form of software. The processor 401 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 401 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. General-purpose processor 401 may be a microprocessor or any conventional processor, etc. The steps of the accessory optimization method provided in the embodiments of the present invention can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, which is located in a memory. The processor reads the information in the memory and combines it with its hardware to complete the steps of the aforementioned method.

[0086] In an exemplary embodiment, the electronic terminal 400 may be used by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), or complex programmable logic devices (CPLDs) to execute the aforementioned method.

[0087] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented using computer program-related hardware. The aforementioned computer program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0088] In the embodiments provided in this application, the computer-readable and writable storage medium may include read-only memory, random access memory, EEPROM, CD-ROM or other optical disc storage devices, disk storage devices or other magnetic storage devices, flash memory, USB flash drive, portable hard drive, or any other medium capable of storing desired program code in the form of instructions or data structures and accessible by a computer. Additionally, any connection may be appropriately referred to as a computer-readable medium. For example, if instructions are transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of the medium. However, it should be understood that computer-readable and writable storage media and data storage media do not include connections, carrier waves, signals, or other transient media, but are intended for non-transient, tangible storage media. The disks and optical discs used in the application include compact discs (CDs), laser discs, optical discs, digital multifunction discs (DVDs), floppy disks, and Blu-ray discs, where disks typically copy data magnetically, while optical discs use lasers to copy data optically.

[0089] In summary, this invention provides a psychiatric electronic medical record system and device based on national cryptographic algorithms. This invention utilizes national cryptographic algorithms for user authentication during login and registration requests on the electronic medical record client. Upon successful authentication, the user-end data is categorized and encrypted using national cryptographic algorithms, forming nationally encrypted data which is then stored. For data that needs to be transmitted to or received from other systems, an adaptation layer is used to facilitate the transmission of national and international cryptographic data between corresponding systems, as well as the storage of national cryptographic data from other systems. This invention, with its full-cycle encryption based on national cryptographic algorithms, fully meets the protection needs of psychiatric electronic medical record data in terms of privacy management, long-term tracking and storage, and prevention of leakage during shared medical visits. It provides strong protection for the security and reliability of electronic medical record data, demonstrating significant practical value and inventiveness.

[0090] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.

Claims

1. A psychiatric electronic medical record system based on national cryptographic algorithms, characterized in that, include: The system includes a user authentication module, a data classification and encryption module, an encrypted data storage module, and a communication module; among which... The user authentication module is used to verify user identity using a national cryptographic algorithm based on the user login / registration request sent by the electronic medical record user terminal. The data classification and encryption module is connected to the user identity authentication module. After the user identity is verified, the module uses the national cryptographic algorithm to classify and encrypt the data from the electronic medical record user terminal to obtain national cryptographic encrypted data. The encrypted data storage module is connected to the data classification encryption module and is used to store the national cryptographic encryption processed data; The communication module, connected to the encrypted data storage module, includes a data adaptation intermediate layer connected to the encrypted data storage module. It is used to adapt national cryptographic data that needs to be transmitted to other systems or data received from other systems through the data adaptation intermediate layer, so as to transmit national cryptographic or international data to the corresponding system, or to store national cryptographic data in the encrypted data storage module.

2. The electronic medical record system for psychiatric specialties based on national cryptographic algorithms according to claim 1, characterized in that, The user authentication module performs user authentication using the corresponding national cryptographic algorithm based on the type of electronic medical record user terminal that sent the user login / registration request; wherein... If the electronic medical record user terminal that sends the user login / registration request is the electronic medical record medical care terminal, the user identity is verified by a combination of digital certificate authentication, dynamic password authentication and biometric recognition based on the SM2 algorithm, and the user access permissions are determined after the identity is verified. If the electronic medical record user terminal sending the user login / registration request is the electronic medical record patient terminal, a combination of mobile phone number, SMS verification code and biometric identification is used for user identity authentication, and user access permissions are determined after the identity authentication is passed.

3. A psychiatric electronic medical record system based on national cryptographic algorithms according to claim 1, characterized in that, The data classification and encryption module includes: The structured data encryption unit is used to encrypt the structured data transmitted from the electronic medical record user terminal using field encryption methods; The unstructured data encryption unit is used to encrypt unstructured data transmitted from the electronic medical record user terminal using file encryption methods; The encrypted data verification unit connects the structured data encryption unit and the unstructured data encryption unit. It is used to calculate the SM3 hash value of the encrypted data to generate an encrypted data digest, so as to verify whether the encrypted data has been tampered with.

4. A psychiatric electronic medical record system based on national cryptographic algorithms according to claim 3, characterized in that, The encryption method using field encryption includes: using the CBC mode based on the SM4 algorithm to encrypt the structured data by field; the encryption method using file encryption includes: using the CTR mode based on the SM4 algorithm to generate an independent key and encrypting the file based on the key.

5. A psychiatric electronic medical record system based on national cryptographic algorithms according to claim 1, characterized in that, The encrypted data storage module is used to uniformly store the data processed by national cryptographic encryption, the corresponding encrypted data digest, and the corresponding timestamp.

6. A psychiatric electronic medical record system based on national cryptographic algorithms according to claim 1, characterized in that, The communication module uses the SM2, SM3 and SM4 algorithms and the SSL / TLS protocol to form an encrypted channel with other systems.

7. A psychiatric electronic medical record system based on national cryptographic algorithms according to claim 1, characterized in that, The data adaptation intermediate layer includes an environment parameter parsing submodule and an adaptation submodule; wherein... The environment parameter parsing submodule is used to identify the encryption environment of other systems that transmit data with the system. The adaptation submodule includes independently encapsulated national cryptographic algorithms and international algorithms, used to call and convert encryption algorithms adapted to the corresponding environment based on the identified encryption environment information; wherein, When the environment parameter parsing submodule identifies that other systems are in a national cryptographic encryption environment, it directly interacts with the corresponding system through the encryption channel. When the environment parameter parsing submodule identifies that other systems are in an international encryption environment, it calls the international algorithm to convert the national cryptographic encryption data that needs to be transmitted to other systems into international cryptographic data, and sends the international cryptographic data to the corresponding other systems through the encryption channel; or it calls the national cryptographic algorithm to convert the international cryptographic data received from other systems into national cryptographic data, and stores the national cryptographic data in the encryption data storage module.

8. A psychiatric electronic medical record system based on national cryptographic algorithms according to claim 7, characterized in that, The communication module can interact with other systems via intranet or extranet.

9. A psychiatric electronic medical record system based on national cryptographic algorithms according to claim 1, characterized in that, The electronic medical record system for mental health based on national cryptographic algorithms also includes a key management module, which is used for key generation, key distribution, and key updating and destruction.

10. A psychiatric electronic medical record device based on a national cryptographic algorithm, applied to a psychiatric electronic medical record system based on a national cryptographic algorithm as described in any one of claims 1 to 9, the device comprising: Memory, processor, and computer programs stored in memory.

Citation Information

Patent Citations

  • Medical and health information security management system

    CN110957025A

  • Searchable ciphertext medical record system based on national cryptographic algorithm traceability and forward security

    CN111625856A

  • Medical electronic medical record storage system with high confidentiality

    CN112382357A

  • Electronic medical record sharing method based on national cryptographic algorithm and IPFS

    CN114553582A

  • Security dynamic authority management method for alliance chain unstructured data storage

    CN115600237A