Medical archive security optimization query system based on block chain
By using blockchain-based permission verification, data integrity verification, and path optimization modules, the system solves the problems of ambiguous permission identification and data traceability in existing medical record query systems, and realizes real-time permission matching, data integrity identification, and abnormal behavior auditing, thereby improving the system's security and reliability.
Patent Information
- Application Number
- CN202511438983.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-10-10
AI Technical Summary
Existing medical record security optimization query systems are prone to ambiguity in permission identification and lag in control rule response under conditions of concurrent requests from multiple roles or high-frequency access. This makes it difficult to effectively capture fine-grained abnormal operations, and data integrity is difficult to trace, leading to a break in the audit accountability chain and affecting the credibility and controllability of the information system.
The system employs a blockchain-based permission verification module, data integrity verification module, access path optimization module, and log auditing module. Through dynamic permission mapping, data credibility assessment, path priority scheduling, and abnormal behavior identification, it generates a dynamic permission mapping table, a data credibility assessment model, and an archive security audit data table, thereby achieving real-time permission matching, data integrity identification, and abnormal behavior auditing.
It effectively prevents unauthorized access, enhances the ability to identify data integrity during use, improves query efficiency and response accuracy, enables rapid comparison of abnormal behavior and generation of audit data, improves the auditability and accountability of file access, and enhances access security and trust levels throughout the data lifecycle.
Smart Images

Figure CN120910318A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security, and in particular to a medical record security optimization query system based on a block chain. BACKGROUND
[0002] The technical field of data security relates to the protection of the integrity, confidentiality and controllability of information during storage, transmission and access, and includes encryption mechanisms, access control, identity authentication, data tracing, information hiding and tamper resistance technology, etc. It is widely used in data-sensitive scenarios such as medical treatment and industrial control. In particular, in high-risk environments, technical means are used to ensure the trustworthiness and attack resistance of data during its life cycle, and building a trust mechanism and audit capability in data circulation has become an important research direction in this field. Among them, the traditional medical record security optimization query system refers to the basic query platform used for the secure storage and authorized access of personal medical records in the medical information management process. The system realizes the management and scheduling of user access to record content through centralized database cooperation, based on username and password identity recognition methods, permission level division mechanisms, log recording systems, and rule-based access control strategies. At the same time, it relies on the backup and mirroring mechanisms of the database itself to complete data fault tolerance and recovery operations. This approach has problems such as attack risk and lack of operational trustworthiness due to its centralized structure in actual application.
[0003] The existing technology is based on a centralized database combined with fixed permission division and rule control strategy operation mode, which is prone to permission recognition ambiguity and control rule response lag in the case of multiple role concurrent requests or high frequency access. When relying on static identity recognition and log recording methods for behavior auditing, it is difficult to effectively capture fine-grained abnormal operations, especially in cases where behavior patterns are similar but operation intentions are significantly different, which can easily cause the lack of abnormal identification or misjudgment. In addition, the data recovery and fault tolerance capability of the system itself relies on the database backup mechanism. Once unauthorized access or intermediate node attacks occur, data integrity is difficult to trace, resulting in a broken audit accountability chain. In the scenario of frequent interaction of medical records and high-frequency update of sensitive information, the trustworthiness and controllability of the information system are seriously affected. SUMMARY
[0004] The purpose of the present application is to solve the shortcomings in the prior art and to provide a medical record security optimization query system based on a block chain.
[0005] In order to achieve the above-mentioned purpose, the present application adopts the following technical scheme: a medical record security optimization query system based on a block chain comprises: The permission verification module obtains an access request and identity information of a user, analyzes a key association structure, extracts a user identity hash value and a key mapping label, identifies a corresponding permission level index and compares an access request instruction parameter, marks a permission label corresponding to the request and matches an authorization level, and generates a dynamic permission mapping table; The data integrity verification module extracts a storage node signature field and current data based on the dynamic permission mapping table, identifies a structure feature code, compares the label with the consistency of the corresponding node in the linked list, and generates a data credibility evaluation model; The access path optimization module identifies high-frequency access nodes and low-frequency archive nodes according to the data credibility evaluation model, counts access time periods and request source distribution frequencies, extracts node inter-hop distances, analyzes the change distribution of node connection directions and hop distances, and generates a path priority scheduling table of a query request; The log audit module calls the path priority scheduling table of the query request, collects time intervals and operation types of access behaviors, filters access abnormal frequencies and operation period overlap regions, compares original operation records with current behavior feature label offset degrees, and generates an archive security audit data table.
[0006] As a further scheme of the application, the dynamic permission mapping table includes permission level identification, key segment structure, and timestamp sequence distribution, the data credibility evaluation model includes signature consistency score, verification value deviation interval, and original signature distribution graph, the path priority scheduling table of the query request includes a high-frequency node list, an archive node distribution weight, and an access frequency difference matrix, and the archive security audit data table includes an abnormal behavior label, an operation type statistic, and an audit result classification.
[0007] As a further scheme of the application, the permission verification module includes: The identity analysis submodule obtains an access request and identity information of a user, extracts key segment identification values in a key segment structure, locates an identity field index position corresponding to the segments, filters key segment combination fields associated with the labels, compares identity parameters in the access request with key combination information in the mapping table, analyzes key association relationships, and generates a key level mapping amount; The timestamp correction submodule extracts a timestamp of an access request according to the key level mapping amount, extracts a timestamp corresponding field index in the key level, identifies an offset difference value between the access request timestamp and the key timestamp field, filters time period labels exceeding an error threshold and performs data replacement correction, corrects the time deviation, and generates a time synchronization factor; The authority mapping generation submodule reads an authority label index value corresponding to the time synchronization factor based on the time synchronization factor, combines a key level and a timestamp sequence, extracts an access control field content corresponding to the authority level, locates a key access behavior label item in the timestamp sequence, combines authority index results corresponding to the key level and the behavior label, assigns an authority level label, and generates a dynamic authority mapping table.
[0008] As a further scheme of the present application, the data integrity verification module comprises: The signature extraction submodule extracts an encrypted signature field of the archive storage node based on the dynamic authority mapping table, locates a signature identification segment in the storage node and extracts a corresponding value, reads a field position index in the signature structure and labels a field source, counts a signature field frequency and divides a signature structure level, identifies a signature distribution feature, and generates a signature sequence set. The consistency verification submodule calls the signature sequence set, verifies the consistency of the current archive data, extracts a signature field corresponding to a data segment to be verified, reads a comparison sequence between an original data block and a signature structure, calculates an offset fusion difference value, compares a signature sequence in an original record, and generates a verification value deviation amount. The credibility evaluation submodule analyzes a signature consistency score based on the verification value deviation amount, extracts an original signature node index table and extracts a corresponding score value interval, screens a key field position and a score mutation node, and generates a data credibility evaluation model through an original signature distribution.
[0009] As a further scheme of the present application, the access path optimization module comprises: The node distribution analysis submodule extracts a distribution feature of a high-frequency access node and a low-frequency archive node according to the data credibility evaluation model, labels an access label of the node and extracts a corresponding access count, extracts a node physical position information, identifies a storage density distribution and an access hotspot area between nodes, and generates a node distribution difference amount. The frequency difference calculation submodule calls the node distribution difference amount, analyzes an access frequency difference between the high-frequency node and the low-frequency node, extracts a node access frequency interval value and generates a frequency group mapping, labels a behavior trigger node, identifies a jump section and a continuous access sequence feature of the frequency interval, and generates a frequency distribution matrix. The path priority generation submodule extracts a node weight field and a frequency factor based on the frequency distribution matrix, combines a node weight and an access frequency difference, calculates an access intensity fluctuation fusion index, screens a node channel with an abnormal access intensity distribution and labels a path priority sequence, assigns a path priority label, and generates a path priority scheduling table of a query request.
[0010] As a further scheme of the present application, the log audit module comprises: The behavior mode extraction submodule calls a path priority scheduling table of the query request, collects a time interval and an operation type of the user access behavior, identifies a behavior mode feature, and generates a behavior mode distribution diagram; The abnormal behavior screening submodule screens a behavior mode exceeding a normal range based on the behavior mode distribution diagram, extracts an operation offset value in a behavior sequence and counts repeated hop numbers, labels an operation overload section and a path switching abnormal position, identifies a behavior sequence exceeding a threshold and matches an abnormal trigger node, marks an abnormal behavior node, and generates an abnormal behavior marking table; The audit data generation submodule counts an operation type distribution according to the abnormal behavior marking table, extracts a node behavior record and an operation code index value, constructs an operation frequency distribution diagram, analyzes a node operation type mapping relationship, analyzes an operation concentrated area in the behavior mode and a high-frequency abnormal node, combines the behavior mode feature, and generates an archive security audit data table.
[0011] As a further scheme of the application, the system further comprises a data trace tracking module: The data trace tracking module collects an operation track and a data flow path of the abnormal behavior node based on the archive security audit data table, extracts a data transfer time sequence and a forwarding node identification information, analyzes an intersection distribution of the track node and the data flow path in the node index table, and generates a data flow trace result; The data flow trace result comprises an operation track distribution diagram, a path consistency marking, and an archive query trace node list.
[0012] As a further scheme of the application, the data trace tracking module comprises: The track extraction submodule extracts an operation track of the abnormal behavior node based on the archive security audit data table, identifies a time sequence and an execution command number of each operation node, extracts an inter-node jump relationship and an operation trigger field, screens a continuous operation chain and generates a node association mapping, identifies a track continuity feature, and generates an operation track distribution diagram; The path consistency analysis submodule calls the operation track distribution diagram, analyzes consistency of the track and the data flow path, extracts a node index in the operation track and compares the data flow path, screens a path section with consistent fields and labels a hop number consistent node, marks a consistent path node, and generates a path consistency marking table; The trace node generation submodule traces a distribution feature of the consistent path node according to the path consistency marking table, extracts an access time sequence and a data transfer record of the marked node, identifies a transfer direction identifier, extracts a terminal trigger node and a first section execution node interval, and generates an archive query trace node list.
[0013] Compared with the prior art, the application has the advantages and positive effects that: In the application, through the dynamic permission mapping mechanism generated by associating the access request with the identity information with the key structure, the real-time matching of the permission and the instruction parameter is effectively realized, the over-authorization access problem caused by the static authorization is avoided, the credibility evaluation model generated based on the data structure characteristics enhances the integrity identification ability of the data in the use process, the path priority scheduling logic constructed in combination with the node access frequency, the hop distance and the time period information significantly improves the query efficiency and the response accuracy, through the operation behavior combination and the overlapping period identification, the rapid comparison and the audit data generation of the abnormal behavior are realized, the traceability characteristics are further extracted in the intersection distribution of the data flow path and the time sequence, the auditability and the accountability of the file access are improved, and the access security and the trust level in the data life cycle are overall enhanced. BRIEF DESCRIPTION OF DRAWINGS
[0014] Figure 1 is a system flowchart of the application; Figure 2 is a permission verification module flowchart in the application; Figure 3 is a data integrity verification module flowchart in the application; Figure 4 is an access path optimization module flowchart in the application; Figure 5 is a log audit module flowchart in the application; Figure 6 is a data traceability tracking module flowchart in the application. DETAILED DESCRIPTION
[0015] In order to make the purpose, technical scheme and advantages of the application more clear and understandable, the application will be further described in detail below in combination with the drawings and examples. It should be understood that the specific examples described herein are only used to explain the application and do not limit the application.
[0016] In the description of the application, it should be understood that the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the application and simplify the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the application. In addition, in the description of the application, the meaning of "a plurality of" is two or more, unless otherwise specifically limited.
[0017] Referring to Figure 1 A medical file security optimization query system based on a blockchain comprises: The permission verification module obtains an access request and identity information of a user, parses a key association structure, extracts a user identity hash value and a key mapping label, identifies a corresponding permission level index and compares an access request instruction parameter, extracts a timestamp mapping value, marks a request corresponding permission label and matches an authorization level, and generates a dynamic permission mapping table; The data integrity verification module extracts a storage node signature field and current data based on the dynamic permission mapping table, identifies a structure feature code and obtains a verification label, collects an original signature sequence to construct a signature linked list, compares the label with the consistency of the corresponding node in the linked list, and generates a data credibility evaluation model; The access path optimization module identifies high-frequency access nodes and low-frequency archive nodes according to the data credibility evaluation model, counts access time periods and request source distribution frequencies, extracts node inter-hop distances, analyzes the change distribution of node connection directions and hop intervals, and generates a path priority scheduling table of a query request; The log audit module calls the path priority scheduling table of the query request, collects the time interval and operation type of the access behavior, filters the access abnormal frequency and operation period overlap area, extracts the operation command combination and behavior repetition mode, compares the original operation record with the current behavior feature label offset degree, and generates an archive security audit data table; The data source tracking module collects the operation trajectory and data flow path of the abnormal behavior node based on the archive security audit data table, extracts the data transfer time sequence and forwarding node identification information, analyzes the intersection distribution of the trajectory node and the data flow path in the node index table, and generates a data flow traceability result.
[0018] The dynamic permission mapping table includes permission level identification, key segmentation structure, and timestamp sequence distribution. The data credibility evaluation model includes signature consistency score, verification value deviation interval, and original signature distribution graph. The path priority scheduling table of the query request includes a high-frequency node list, an archive node distribution weight, and an access frequency difference matrix. The archive security audit data table includes an abnormal behavior label, an operation type statistic, and an audit result classification. The data flow traceability result includes an operation trajectory distribution graph, a path consistency label, and an archive query traceability node list.
[0019] Please refer to Figure 2 The permission verification module includes: The identity analysis submodule obtains an access request and identity information of a user, extracts a key segment identification value in a key segmentation structure, locates the identity field index position corresponding to the segmentation, filters the key segment combination field of the associated label, compares the identity parameter in the access request with the key combination information in the mapping table, analyzes the key association relationship, and generates a key level mapping quantity; Access request and identity information of a user are acquired. In an electronic medical record system, a user attempts to access a medical record of a specific patient. First, the access request of the user is acquired, which contains the identity information of the user, such as a username, a role, and the like, and a medical record ID of the request access. A preset key segment structure is extracted, which contains a user role, an access time, and the like. Each key segment identifier value corresponds to the specific content of the key segment, for example, the role is “doctor” and the access time is “14:30”. The corresponding identity field index position of the segment is located. According to the key segment identifier value, the corresponding field index position in the identity information is found, for example, the “doctor” role corresponds to the “title” field in the user identity information, and the “14:30” corresponds to the “access time” field. The key segment combination field associated with the marker is screened, for example, the preset “doctor” role is associated with the “specific time period” access permission, and the combination field containing the two key segments is screened. The identity parameters in the access request are compared with the key combination information in the mapping table, for example, the “title = doctor” in the user identity information is compared with the entry of “doctor role allowing access to medical record” in the mapping table. The key association relationship is analyzed, the comparison result is analyzed, and it is determined whether the user has access permission. The key segment, the identity field index, the key combination information and the access permission association relationship are integrated into a key level mapping quantity, which can be represented as a multi-dimensional array or a tree structure, which is used for subsequent timestamp correction and permission mapping.
[0020] A timestamp correction submodule extracts the timestamp of the access request according to the key level mapping quantity, extracts the timestamp corresponding field index in the key level, identifies the offset difference value between the access request timestamp and the key time field, screens the time period tags exceeding the error threshold and performs data replacement correction, corrects the time deviation, and generates a time synchronization factor. The timestamp corresponding field index is found from the key level mapping quantity, for example, the “access time” field. The offset difference value between the access request timestamp and the key time field is identified. The access request timestamp is compared with the key time field, and the offset difference value is calculated. If the precision of the key time field is minute and the precision of the access request timestamp is second, conversion and comparison are needed. The time period tags exceeding the error threshold are screened and data replacement correction is performed. If the error threshold preset by the system is 5 seconds, the time period tags with an offset difference value exceeding 5 seconds are screened and data replacement correction is performed, for example, “15:00:10” is corrected to “15:00:00”. The timestamp precision is ensured to be consistent, the time deviation is corrected, all timestamps are corrected to be consistent with the precision of the key time field, and a time synchronization factor is generated, which is used for subsequent permission mapping. The factor can be represented as a time offset or a time correction function.
[0021] The permission mapping generation submodule reads the permission label index value corresponding to the synchronization factor based on the time synchronization factor, combines the key level and the timestamp sequence, extracts the access control field content corresponding to the permission level, locates the key access behavior identification item in the timestamp sequence, merges the permission index results corresponding to the key level and the behavior label, assigns the permission level label, and generates a dynamic permission mapping table; Based on the time synchronization factor, the key level and the timestamp sequence are combined to read the permission label index value corresponding to the synchronization factor, and the access control field content corresponding to the permission level is extracted. For example, according to the time synchronization factor, the corresponding permission label index value in the key level is searched, the index value corresponds to a permission level or an access control list, the key access behavior identification item in the timestamp sequence is located, for example, for an electronic medical record system, the key access behavior is "viewing medical records", "modifying medical records", etc., the identification item related to the behavior in the timestamp sequence is located, for example, a user viewed the medical record at "15:00:00", the behavior is recorded, the permission index results corresponding to the key level and the behavior label are merged, a comprehensive permission index result is generated, a permission level label is assigned, a permission level label is assigned to the access request according to the comprehensive permission index result, for example, the permission level is "read only", a dynamic permission mapping table is generated, and user identity information, access time, access behavior and permission level label and other information are integrated into a dynamic permission mapping table. The table can be used for subsequent access control and auditing.
[0022] Please refer to Figure 3 The data integrity verification module includes: The signature extraction submodule extracts the encrypted signature field of the archive storage node based on the dynamic permission mapping table, locates the signature identification segment in the storage node and extracts the corresponding value, reads the field position index in the signature structure and marks the field source, counts the frequency of the signature field and divides the signature structure level, identifies the signature distribution characteristics, and generates a signature sequence set. Based on the dynamic permission mapping table, the signature field extracted to a certain medical record is "SHA256 (medical record content + timestamp + permission tag)", the signature identifier segment in the storage node is located and the corresponding value is extracted, the field position index in the signature structure is read and the field source is marked, the position index of each field in the signature structure is read, for example, the medical record content is located at 1-100 bytes, the timestamp is located at 101-110 bytes, and the permission tag is located at 111-120 bytes. The frequency of the signature field is counted and the signature structure hierarchy is divided, the frequency of each signature field is counted, and the signature structure is divided into different levels according to the frequency, for example, the frequency of the medical record content and the timestamp is higher, and the frequency of the permission tag is lower. The distribution characteristics of the signature are identified, the distribution characteristics of the signature are identified, for example, the signature length, the signature algorithm, etc., and a signature sequence set is generated for subsequent consistency verification, for example, the signature length is 256 bits, the signature algorithm is SHA256, and all signature fields contain medical record content, timestamp and permission tag.
[0023] The consistency verification submodule calls the signature sequence set to verify the consistency of the current archive data, extracts the signature field corresponding to the data segment to be verified, reads the comparison sequence between the original data block and the signature structure, and uses the formula: ; The offset fusion difference value is calculated, the signature sequence in the original record is compared, and the verification value deviation is generated; wherein, represents the offset fusion difference value, represents the offset difference value extracted between the i-th original data block and the signature structure, represents the comparison deviation between the i-th signature sequence and the reference signature structure, represents the length of the i-th original data block, represents the total number of offset sequences, represents the average value of the offset estimate after fusion of all segment differences; The signature sequence set is called to verify the consistency of a certain medical record, the signature field corresponding to the data segment to be verified is extracted, for example, the signature field of the current medical record content is "SHA256 (medical record content + timestamp + permission tag)", the comparison sequence between the original data block and the signature structure is read, the comparison sequence between the original data block and the signature structure is read, which defines how to compare the original data block and the signature structure, for example, the comparison sequence is "first compare the medical record content, then compare the timestamp, and finally compare the permission tag", the formula is called to calculate the offset fusion difference value, and the calculated offset fusion difference value is compared with the signature sequence in the original record; The formula has the advantage of more comprehensively evaluating the consistency of data by combining the offset difference between the original data block and the signature structure, the deviation between the signature sequence and the reference signature structure, and the length of the original data block, represents the offset fusion difference value, with the unit of bytes, represents the offset difference value extracted between the i-th original data block and the signature structure, with the unit of bytes, reflecting the positional deviation between the original data and the signature structure, for example, the distance between the position of a field in the data block and the expected position of the field in the signature structure, represents the comparison deviation between the i-th signature sequence and the reference signature structure, with the unit of bits, reflecting the difference between the signature sequence and the expected reference signature structure, for example, the deviation in signature algorithm, key, etc., represents the length of the i-th original data block, with the unit of bytes, used to weight the offset difference, because a longer data block indicates a more serious problem if the same offset occurs, represents the total number of segments of the offset sequence, represents the mean value of the offset estimate after fusion of all segment differences, with the unit of bytes, providing an overall offset reference, through summation, square root operation, etc., finally obtaining a comprehensive offset fusion difference value D, the smaller the value, the higher the consistency of the data, the larger the value, the lower the consistency of the data, assuming the following data: n=3, =2 bytes, =1 bit, =100 bytes, =3 bytes, =0 bits, =150 bytes, =1 byte, =1 bit, =200 bytes, first calculate for subsequent calculation of D value, The calculation of is slightly complex because it involves unit conversion (bits to bytes, assuming 1 byte=8 bits), to simplify the calculation, ignore the unit conversion, and directly use the given bit value as an approximate byte value: ; Then, calculate : ; The result shows that the offset fusion difference value is about 0.66 bytes, assuming that the preset difference threshold is 1 byte, the value is lower than the threshold, it is considered that the consistency of the data is higher, which means that the offset and deviation between the signature sequence in the data block and the original data block are relatively small. The consistency check result of the data is compared with the preset threshold to obtain the conclusion whether the data is consistent, and the check value deviation amount is generated.
[0024] The credibility evaluation submodule analyzes the signature consistency score based on the check value deviation amount, extracts the original signature node index table and extracts the corresponding score value interval, filters the key field position and the score mutation node, and generates a data credibility evaluation model through the original signature distribution. Based on the check value deviation amount, analyze the signature consistency score, extract the original signature node index table and extract the corresponding score value interval, extract the original signature node index table, and extract the corresponding score value interval, for example, the score value interval is [0, 100], filter the key field position and the score mutation node, filter the key field position and the score mutation node, for example, the medical record content field and the timestamp field are key fields, and the score mutation node refers to the node where the score value changes significantly. Through the original signature distribution, for example, by analyzing historical signature data, it is found that factors such as signature length, signature algorithm and key have an impact on data credibility. The higher the signature consistency score, the higher the data credibility; otherwise, the data credibility is lower, for example, the check value deviation amount of a certain medical record file is 0.66 bytes, then the credibility score of the file can be obtained as 85 points. According to the score, the data credibility is evaluated based on the check value deviation amount, which reflects the difference between the signature sequence and the reference signature structure. For example, the check value deviation amount is 0.66, analyze the signature consistency score, for example, assuming that there is a linear relationship between the deviation amount and the score, the smaller the deviation amount, the higher the score, extract the original signature node index table and extract the corresponding score value interval, for example, extract the historical score value interval [70, 100], filter the key field position and the score mutation node, the key fields include medical record content, timestamp, etc. The score mutation node refers to the node where the score value changes significantly. Through the original signature distribution, for example, the distribution range, mean, variance, etc. of the signature value are counted. Assuming that the average value of the historical score is 80 and the variance is 5, a data credibility evaluation model is generated, which considers factors such as check value deviation amount, historical score and signature distribution to evaluate the credibility of the data. The data credibility evaluation model can more accurately evaluate the credibility of the data by comprehensively considering multiple factors.
[0025] Please refer to Figure 4 , the access path optimization module includes: The node distribution analysis submodule extracts the distribution characteristics of high-frequency access nodes and low-frequency archive nodes according to the data credibility evaluation model, marks the access labels of the nodes and extracts the corresponding access counts, extracts the physical location information of the nodes, identifies the storage density distribution and access hotspot areas between the nodes, and generates a node distribution difference quantity; According to the data credibility evaluation model, for example, the medical record reading node is a high-frequency access node, and the backup storage node is a low-frequency archive node. The access labels of the nodes are marked and the corresponding access counts are extracted. The access labels of the nodes are marked, and the corresponding access counts are extracted, for example, the reading node is marked as "read" and the access count is 1000 times. The physical location information of the nodes is extracted, for example, the IP address, geographic location, etc. of the server. The storage density distribution and access hotspot areas between the nodes are identified, for example, the storage density of some areas is higher, and the access frequency of some areas is higher. A node distribution difference quantity is generated for subsequent access path optimization, for example, which can be represented as the distance between high-frequency access nodes and low-frequency archive nodes. The distribution characteristics of high-frequency access nodes and low-frequency archive nodes will be extracted.
[0026] The frequency difference calculation submodule calls the node distribution difference quantity, analyzes the access frequency difference between high-frequency nodes and low-frequency nodes, extracts the node access frequency interval value and generates a frequency group mapping, marks the behavior trigger nodes, identifies the jump section and continuous access sequence characteristics of the frequency interval, and generates a frequency distribution matrix. The node distribution difference quantity is called, for example, nodes with access frequency in [0, 100] are mapped to "low-frequency nodes", nodes with access frequency in [101, 1000] are mapped to "medium-frequency nodes", and nodes with access frequency in [1001, 10000] are mapped to "high-frequency nodes". The behavior trigger nodes are marked, for example, medical record reading nodes, medical record modification nodes, etc. The jump section and continuous access sequence characteristics between the frequency intervals are identified, for example, some nodes change from low-frequency nodes to high-frequency nodes, or some nodes are continuously accessed multiple times. The node distribution difference quantity reflects the difference between high-frequency nodes and low-frequency nodes in physical location and access frequency, for example, the difference quantity is (high-frequency node access frequency - low-frequency node access frequency) / distance. The access frequency difference between high-frequency nodes and low-frequency nodes is analyzed, the node access frequency interval value is extracted, and a frequency group mapping is generated, for example, the access frequency is divided into three intervals: low (0-100 times / day), medium (101-1000 times / day), and high (1001 times / day or more). The behavior trigger nodes are marked, for example, user login, data query, etc. The jump section and continuous access sequence characteristics between the frequency intervals are identified, for example, a node suddenly jumps from low-frequency to high-frequency, or a node is continuously accessed frequently. A frequency distribution matrix is generated, which records the access frequency relationship between nodes.
[0027] The path priority generation submodule extracts the node weight field and the frequency factor based on the frequency distribution matrix, in combination with the node weight and the access frequency difference, and adopts the formula: calculates the access intensity fluctuation fusion index, screens the node channel with abnormal access intensity distribution, marks the path priority sequence, assigns the path priority label, and generates the path priority scheduling table of the query request; wherein, represents the access intensity fluctuation fusion index, represents the access frequency variation amplitude of the jth node in the adjacent scheduling period, represents the access frequency of the jth node on the path, represents the order index of the jth node in the path, represents the number of nodes in the current path; Based on the frequency distribution matrix, in combination with the node weight and the access frequency difference, the formula is called to calculate the access intensity fluctuation fusion index. In the electronic medical record system, the medical records of some patients need to be urgently reviewed, at which time the access path needs to be optimized. represents the access intensity fluctuation fusion index, which is unitless and is used to quantify the access intensity fluctuation degree of the path. The higher the index, the greater the access intensity fluctuation of the path, represents the access frequency variation amplitude of the jth node in the adjacent scheduling period, which is in units of times / minute and reflects the change of the node access frequency. For example, the node is accessed 10 times in the last minute and 20 times in the current minute, then = 10 times / minute, represents the access frequency of the jth node on the path, which is in units of times / minute and is used to normalize the frequency variation amplitude to avoid the slight change of the high-frequency node being excessively magnified, represents the order index of the jth node in the path, which is unitless and is used to sort the nodes on the path. The node closer to the starting point has a greater impact, represents the number of nodes in the current path. For example, a path contains 3 nodes, then m = 3; The advantage of the formula is that by comprehensively considering the access frequency variation amplitude, the node access frequency, and the order index of the node in the path, the access intensity fluctuation of the path can be comprehensively evaluated, thereby providing a more reasonable basis for path priority scheduling. Assuming that a path contains 3 nodes, the parameter values are as follows: = 5, = 10, = 1, = 10, = 20, = 2, = 2, = 5, = 3, substituting the parameters into the formula: ; The results show that the access intensity fluctuation fusion index is about 11.45, assuming that the preset fluctuation threshold is 10, the value is higher than the threshold, it is considered that the access intensity fluctuation of the path is larger, the numerical result of the access intensity fluctuation fusion index is higher, indicating that the access intensity fluctuation of the path is larger, there is a burst access or abnormal access behavior, therefore, the path needs to be prioritized and higher priority needs to be allocated to process potential risks in time, and a path priority scheduling table of query request is generated.
[0028] Please refer to Figure 5 , the log audit module includes: The behavior pattern extraction submodule calls the path priority scheduling table of query request, collects the time interval and operation type of user access behavior, identifies the behavior pattern characteristics, and generates a behavior pattern distribution map; The path priority scheduling table of query request is called, for example, the user views the medical record at 10:00 and modifies the medical record at 10:05, the time interval is 5 minutes, and the operation type is "view" and "modify", the behavior pattern characteristics are identified, for example, the user frequently views the medical record and occasionally modifies the medical record, the system analyzes the time interval and operation type of user access behavior, identifies the behavior pattern characteristics, for example, the behavior pattern of a normal doctor is to view the medical record first, then diagnose, and then issue a prescription, analyzes the mapping relationship between the node operation type, the user's access behavior on the path includes login, query, modification, upload and other operations, each operation corresponds to an operation type, for example, the login operation corresponds to "login", the query operation corresponds to "query", the node behavior record includes access time, user identity, operation type, operation result and other information, and the behavior pattern distribution map is generated.
[0029] The abnormal behavior screening submodule screens the behavior pattern that exceeds the normal range based on the behavior pattern distribution map, extracts the operation offset value in the behavior sequence and counts the repeated jump number, marks the operation overload segment and path switching abnormal position, identifies the behavior sequence that exceeds the threshold and matches the abnormal trigger node, marks the abnormal behavior node, and generates an abnormal behavior marking table; Based on the behavior pattern distribution map, for example, frequent modification of medical records, unauthorized access, etc., the operation offset value in the behavior sequence is extracted and the repeated jump count is counted, the operation offset value in the behavior sequence is extracted, and the repeated jump count is counted, for example, the user continuously skips multiple nodes, or repeatedly operates multiple times on the same node, the operation overload segment and path switching abnormal position are marked, for example, the operation frequency of some nodes is too high, or the user frequently switches the access path, the behavior sequence that exceeds the threshold is identified and the abnormal trigger node is matched, the behavior sequence that exceeds the threshold is identified and the abnormal trigger node is matched, for example, the user accesses a large number of medical records in a short time, it is considered that the behavior sequence exceeds the threshold, and the abnormal trigger node is the medical record review node, the abnormal behavior node is marked, the abnormal behavior marking table is generated, the behavior sequence that exceeds the threshold will be identified, and the sequence table indicates the abnormal behavior of the user, for example, the user frequently accesses multiple medical records in a short time, the operation overload segment and path switching abnormal position are marked, the operation overload segment is marked, for example, the access frequency of a certain node is much higher than the average level, the abnormal behavior node is marked, for example, the user who frequently accesses medical records is marked as "suspicious user".
[0030] The audit data generation submodule counts the operation type distribution according to the abnormal behavior marking table, extracts the node behavior record and operation code index value, constructs the operation frequency distribution map, analyzes the mapping relationship between the node and the operation type, analyzes the operation concentrated area and high-frequency abnormal node in the behavior pattern, and generates the archive security audit data table combined with the behavior pattern characteristics; According to the abnormal behavior marking table, for example, the number of times of operations such as viewing medical records, modifying medical records, and uploading reports, the node behavior record and operation code index value are extracted, for example, the operation code index value can represent the operation type, for example, "01" represents viewing medical records, and "02" represents modifying medical records, an operation frequency distribution map is constructed to show the frequency distribution of different operation types, the mapping relationship between the node and the operation type is analyzed, the operation concentrated area and high-frequency abnormal node in the behavior pattern are identified, for example, the operation type in some areas is relatively concentrated, or some nodes frequently exhibit abnormal behavior, combined with the behavior pattern characteristics, for example, the behavior pattern of a normal doctor is to first view the medical record, then diagnose, and then issue a prescription, based on the behavior pattern characteristics, the abnormal behavior is analyzed, the operation behavior in the system is counted, and the archive security audit data table is generated. The data table is used to record the detailed information of all operation behaviors.
[0031] Please refer to Figure 6 , the data trace tracking module comprises: The trajectory extraction submodule extracts the operation trajectory of the abnormal behavior node based on the archive security audit data table, identifies the time sequence and execution command number of each operation node, extracts the inter-node jump relationship and operation trigger field, filters the continuous operation chain and generates the node association mapping, identifies the trajectory continuity feature, and generates the operation trajectory distribution map; Based on the archive security audit data table, for example, the user views the medical record at 10:00 (node number 1), modifies the medical record at 10:05 (node number 2), and uploads the report at 10:10 (node number 3), the inter-node jump relationship and operation trigger field are extracted, for example, from the medical record viewing node to the medical record modifying node, the user clicks the "modify" button to trigger the modification operation, the continuous operation chain is filtered, and the node association mapping is generated, for example, view medical record → modify medical record → upload report, the trajectory continuity feature is also identified, the operation trajectory distribution diagram is generated, for example, the user continuously accesses multiple medical record nodes in a short period of time, the operation nodes are numbered in chronological order, for example, 1, 2, 3, …, the inter-node jump relationship and operation trigger field are extracted, for example, from node 1 to node 2, the operation triggered is "view medical record". This module analyzes a series of operations of the user in the archive system.
[0032] The path consistency analysis submodule calls the operation trajectory distribution diagram to analyze the consistency of the trajectory and the data flow path, extracts the node index in the operation trajectory and compares the data flow channel, filters the path sections with consistent fields and marks the jump number consistent nodes, marks the consistent path nodes, and generates the path consistency marking table; The path consistency analysis submodule calls the operation trajectory distribution diagram to analyze the consistency of the trajectory and the data flow path, extracts the node index in the operation trajectory and compares the data flow channel, extracts the node index in the operation trajectory and compares the data flow channel, for example, the operation trajectory is node 1→node 2→node 3, and the data flow channel is node A→node B→node C, filters the path sections with consistent fields and marks the jump number consistent nodes, for example, node 1 in the operation trajectory corresponds to node A in the data flow channel, then the path section is considered consistent, the jump number of node 1 and node A is consistent, the consistent path nodes are marked, the consistent path nodes are marked, and the path consistency marking table is generated, which analyzes the consistency of the trajectory and the data flow path, if the user accesses the data according to the predefined process, it is considered that the trajectory and the data flow path are consistent, the path sections with consistent fields are filtered and the jump number consistent nodes are marked, for example, the nodes that meet the predefined process are marked as "normal nodes".
[0033] The traceability node generation submodule traces the distribution characteristics of the consistent path nodes according to the path consistency marking table, extracts the access time sequence of the marked nodes and the data transfer record, identifies the transfer direction identifier, extracts the terminal trigger node and the first section execution node interval, and generates the archive query traceability node list; According to the path consistency marking table, for example, the access path of a normal user conforms to a predefined process, the access time sequence of the marking node is extracted, the data transfer record is extracted, the access time sequence of the marking node is extracted, and the data transfer record is extracted, for example, the user accesses node A at 10:00, data is transferred from node A to node B at 10:05, the transfer direction identifier is identified, the transfer direction identifier is identified, for example, data is transferred from node A to node B, indicating that the transfer direction is A->B, the terminal trigger node and the first execution node interval are extracted, the terminal trigger node and the first execution node interval are extracted, for example, the user triggers an abnormal behavior at node C, then node C is the terminal trigger node, the first execution node is node A, the access relationship and the data transfer relationship among nodes A, B, C and nodes are contained, the nodes conforming to the predefined process are tracked, the access time sequence of the marking node is extracted, the data transfer record is extracted, the transfer direction identifier is identified, the direction of data flow is determined, the terminal trigger node and the first execution node interval are extracted, and the file query traceability node list is generated.
[0034] The above is only a preferred embodiment of the present application, and does not limit the present application in other forms. Any skilled person in the art can modify or change the above disclosed technical content to equivalent embodiments applied to other fields, but any simple modification, equivalent change and modification made according to the technical essence of the present application to the above embodiments without departing from the technical solution content of the present application still belongs to the protection scope of the present application.
Claims
1. A blockchain-based medical record security optimization query system, characterized in that, The system comprises: The permission verification module obtains the access request and identity information of the user, analyzes the key association structure, extracts the user identity hash value and key mapping label, identifies the corresponding permission level index and compares the access request instruction parameters, marks the request corresponding permission label and matches the authorization level, and generates a dynamic permission mapping table; The data integrity verification module extracts the storage node signature field and current data based on the dynamic permission mapping table, identifies the structure feature code, compares the label and the consistency of the corresponding node in the linked list, and generates a data credibility evaluation model; The access path optimization module identifies high-frequency access nodes and low-frequency archive nodes according to the data credibility evaluation model, counts the access time period and request source distribution frequency, extracts the node-to-node hop distance, analyzes the change distribution of node connection direction and hop distance interval, and generates a path priority scheduling table for query requests; The log audit module calls the path priority scheduling table for query requests, collects the time interval and operation type of access behavior, filters the access abnormal frequency and operation period overlap area, compares the original operation record and the current behavior feature label offset degree, and generates an archive security audit data table.
2. The blockchain-based medical record security optimized query system of claim 1, wherein, The dynamic permission mapping table includes permission level identification, key segmentation structure, and timestamp sequence distribution, the data credibility evaluation model includes signature consistency score, verification value deviation interval, and original signature distribution graph, the path priority scheduling table for query requests includes a high-frequency node list, an archive node distribution weight, and an access frequency difference matrix, and the archive security audit data table includes abnormal behavior markers, operation type statistics, and audit result classification.
3. The blockchain-based medical record security optimized query system of claim 1, wherein, The permission verification module comprises: The identity analysis submodule obtains the access request and identity information of the user, extracts the key segment identification value in the key segmentation structure, locates the identity field index position corresponding to the segmentation, filters the key segment combination field of the associated label, compares the identity parameters in the access request with the key combination information in the mapping table, analyzes the key association relationship, and generates a key level mapping amount; The timestamp correction submodule extracts the timestamp of the access request according to the key level mapping amount, extracts the timestamp corresponding field index in the key level, identifies the offset difference value between the access request timestamp and the key timestamp field, filters the time period label exceeding the error threshold and performs data replacement correction, corrects the time deviation, and generates a time synchronization factor; The permission mapping generation submodule generates a dynamic permission mapping table based on the time synchronization factor, combines the key level and timestamp sequence, reads the permission label index value corresponding to the synchronization factor, extracts the access control field content corresponding to the permission level, locates the key access behavior identification item in the timestamp sequence, combines the permission index results corresponding to the key level and behavior label, assigns the permission level label, and generates a dynamic permission mapping table.
4. The blockchain-based medical record security optimized query system of claim 3, wherein, The data integrity verification module comprises: The signature extraction submodule extracts the encrypted signature field of the archive storage node based on the dynamic permission mapping table, locates the signature identification segment in the storage node and extracts the corresponding value, reads the field position index in the signature structure and labels the field source, counts the frequency of the signature field and divides the signature structure hierarchy, identifies the signature distribution characteristics, and generates a signature sequence set; The consistency verification submodule calls the signature sequence set to verify the consistency of the current archive data, extracts the signature field corresponding to the data segment to be verified, reads the comparison sequence between the original data block and the signature structure, calculates the offset fusion difference value, compares the signature sequence in the original record, and generates a verification value deviation; The credibility evaluation submodule analyzes the signature consistency score based on the verification value deviation, extracts the original signature node index table and extracts the corresponding score value interval, filters the key field position and score mutation node, and generates a data credibility evaluation model through the original signature distribution.
5. The blockchain-based medical record security optimized query system of claim 4, wherein, The access path optimization module includes: The node distribution analysis submodule extracts the distribution characteristics of high-frequency access nodes and low-frequency archive nodes based on the data credibility evaluation model, labels the access tags of the nodes and extracts the corresponding access count, extracts the node physical location information, identifies the storage density distribution and access hotspot area between nodes, and generates a node distribution difference; The frequency difference calculation submodule calls the node distribution difference to analyze the access frequency difference between high-frequency nodes and low-frequency nodes, extracts the node access frequency interval value and generates a frequency group mapping, labels the behavior trigger node, identifies the jump section and continuous access sequence characteristics of the frequency interval, and generates a frequency distribution matrix; The path priority generation submodule extracts the node weight field and frequency factor based on the frequency distribution matrix, combines the node weight and access frequency difference, calculates the access intensity fluctuation fusion index, filters the node channels with abnormal access intensity distribution and labels the path priority sequence, assigns the path priority label, and generates a path priority scheduling table for the query request.
6. The blockchain-based medical record security optimized query system of claim 5, wherein, The log audit module includes: The behavior pattern extraction submodule calls the path priority scheduling table of the query request, collects the time interval and operation type of user access behavior, identifies the behavior pattern characteristics, and generates a behavior pattern distribution map; The abnormal behavior filtering submodule filters behavior patterns that exceed the normal range based on the behavior pattern distribution map, extracts the operation offset value in the behavior sequence and counts the repeated jump number, labels the operation overload section and path switching abnormal position, identifies the behavior sequence that exceeds the threshold and matches the abnormal trigger node, labels the abnormal behavior node, and generates an abnormal behavior label table; The audit data generation submodule counts the operation type distribution according to the abnormal behavior label table, extracts the node behavior record and operation code index value, constructs an operation frequency distribution map, analyzes the mapping relationship with the node operation type, analyzes the operation concentration area and high-frequency abnormal node in the behavior pattern, combines the behavior pattern characteristics, and generates an archive security audit data table.
7. The blockchain-based medical record security optimized query system of claim 1, wherein, The system also includes a data trace tracking module: The data trace tracking module collects operation track and data flow path of the abnormal behavior node based on the archive security audit data table, extracts data transfer time sequence and forwarding node identification information, analyzes intersection distribution of the track node and the data flow path in the node index table, and generates a data flow trace result; The data flow trace result includes an operation track distribution diagram, a path consistency mark, and an archive query trace node list.
8. The blockchain-based medical record security optimized query system of claim 7, wherein, The data trace tracking module includes: An operation track extraction submodule extracts operation track of the abnormal behavior node based on the archive security audit data table, identifies time sequence and execution command number of each operation node, extracts inter-node jump relationship and operation trigger field, filters continuous operation chain and generates node association mapping, identifies track continuity feature, and generates an operation track distribution diagram; A path consistency analysis submodule calls the operation track distribution diagram, analyzes consistency of the track and the data flow path, extracts node index in the operation track and compares data flow channels, filters path sections with consistent fields and marks nodes with consistent number of jumps, marks consistent path nodes, and generates a path consistency mark table; A trace node generation submodule traces distribution feature of the consistent path nodes according to the path consistency mark table, extracts access time sequence and data transfer record of the marked nodes, identifies transfer direction identification, extracts terminal trigger node and first segment execution node interval, and generates an archive query trace node list.
Citation Information
Patent Citations
Block chain-based provenance data dynamic permission access control system and method
CN120074872A
Enterprise management process optimization method and system
CN120106536A
Medical image encryption and secure storage method and system based on block chain
CN120110790A
Smart campus data management method and system
CN120219124A
Financial data processing system based on block chain
CN120563244A
Cited By
Digital sharing management method and security authority control system for hospital archives
CN121542492A