A method for protecting privacy of patient information of a three-dimensional physical examination system sharing system
By classifying physical examination information into three categories and performing different levels of security processing and converting it into two-dimensional point cloud data storage, the problem of insufficient differentiation in privacy protection in existing technologies is solved, and the security and flexibility of the three-dimensional physical examination system sharing system are realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-19
- Publication Date
- 2026-04-07
AI Technical Summary
Existing 3D physical examination system sharing systems fail to differentiate privacy protection based on the sensitivity of information during the data sharing process. This results in either over-protection affecting the usability of the data or insufficient protection making sensitive information easily leaked.
Patient physical examination information is divided into three categories, and different levels of security processing are applied to each category: highly sensitive information is masked and encrypted, moderately sensitive information is desensitized and obfuscated, and low-sensitivity information is kept in its original state. The information is then converted into two-dimensional point cloud data for storage to ensure information relevance and security.
It achieves layered privacy protection, ensuring the security of highly sensitive information while maintaining the usability of moderately sensitive information and the availability of low-sensitivity information, thereby improving the security and flexibility of the data sharing system.
Smart Images

Figure CN121167787B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to a method for protecting patient information privacy in a three-dimensional physical examination system sharing system. Background Technology
[0002] With the rapid development of medical informatization, 3D physical examination system sharing systems have been widely used in medical institutions to store and share patients' physical examination information, promoting collaborative analysis and diagnosis of medical data. However, this data sharing also brings serious risks of patient privacy leaks. Existing privacy protection methods typically employ uniform encryption or desensitization technologies, failing to differentiate processing based on the sensitivity of the information. For example, highly sensitive information such as identity identifiers and medical history records have different privacy protection requirements than general physical examination indicators (such as height and weight), but existing methods often apply the same level of protection to all information, resulting in either over-protection affecting the usability and sharing efficiency of the data, or insufficient protection making sensitive information vulnerable to malicious access. Summary of the Invention
[0003] This application provides a method for protecting patient information privacy in a three-dimensional physical examination system sharing system, which improves the security and flexibility of the three-dimensional physical examination system sharing system and effectively balances the needs of privacy protection and data sharing.
[0004] To achieve the above objectives, this application adopts the following technical solution:
[0005] Firstly, a method for protecting patient information privacy in a three-dimensional physical examination system sharing system is provided, applied to an electronic device. The method includes: the electronic device acquiring a patient's physical examination information, which includes target physical examination information of the first, second, and third categories, wherein the privacy protection priority of the target physical examination information of the first category is higher than that of the target physical examination information of the second category, and the privacy protection priority of the target physical examination information of the second category is higher than that of the target physical examination information of the third category; the electronic device performing a first security processing on the target physical examination information of the first category to obtain target hidden information of the first category, and performing a second security processing on the target physical examination information of the second category to obtain target hidden information of the second category, wherein the information security of the first security processing is higher than that of the second security processing; and the electronic device storing the target hidden information of the first, second, and third categories in the three-dimensional physical examination system sharing system, wherein the target hidden information of the first category is associated with the target hidden information of the second category, and the target hidden information of the second category is associated with the target physical examination information of the third category.
[0006] Therefore, by categorizing physical examination information into three classes according to privacy protection priority and applying higher-level security processing to high-priority information, a hierarchical privacy protection system is achieved. This ensures that highly sensitive information (such as the first class) receives the strongest protection, moderately sensitive information (such as the second class) receives appropriate protection, and low-sensitivity information (such as the third class) remains in its original state, thereby optimizing data usability while protecting privacy. During storage, the hidden information in the first and second classes is associated with the information in the third class, allowing authorized users to trace data relationships for medical analysis, while unauthorized users cannot access the original sensitive content. This method improves the security and flexibility of the 3D physical examination system sharing system, effectively balancing the needs of privacy protection and data sharing.
[0007] Optionally, the first type of target medical examination information is information that is not shared by default. Electronic devices perform a first security process on this first type of target medical examination information to obtain the hidden information, which includes: the electronic device performs a masking process on the first type of target medical examination information to obtain the masked medical examination information; the masking process refers to filtering out the internal parameters of the information; and the electronic device performs an encryption process on the masked medical examination information to obtain the hidden information. It can be seen that by first performing a masking process (filtering out internal parameters) and then performing an encryption process on the first type of target medical examination information, dual security protection is achieved. The masking process eliminates the detailed parameters of the information, reducing the risk of direct leakage, while the encryption process ensures that even if the data is illegally accessed, the original content cannot be deciphered. This combined measure significantly enhances the security of highly sensitive information while maintaining the data's storage format in the shared system, allowing authorized users to only recover the information using a specific key, thereby preventing privacy leaks in extreme scenarios (such as system intrusion).
[0008] Optionally, the electronic device performs a second security processing on the second type of target physical examination information to obtain the second type of target hidden information, including: the electronic device performs desensitization and obfuscation processing on the second type of target physical examination information to obtain the second type of target hidden information, where obfuscation processing refers to blurring the scope of the information.
[0009] As can be seen, by performing anonymization and obfuscation on the second type of target medical examination information, privacy is protected while retaining some of the data's usability. Anonymization removes direct identifiers (such as names), while obfuscation converts specific values into ranges (such as age becoming age groups), making the information unlinkable to individuals but still usable for statistical analysis and macro-level research. This method reduces the risk of leakage of moderately sensitive information while ensuring the usability of the sharing system in medical research and avoiding data waste caused by over-protection.
[0010] In one possible design, the electronic device stores the first type of target hiding information, the second type of target hiding information, and the third type of target physical examination information in the 3D physical examination system sharing system. This includes: the electronic device converting the third type of target physical examination information into third-type point cloud data in a two-dimensional space corresponding to the xy coordinate system, according to a third rule; the third-type point cloud data is obtained by converting the third type of physical examination information; and the electronic device converting the second type of target hiding information into second-type point cloud data in a two-dimensional space, according to the third rule and the region where the third point cloud data is located in the two-dimensional space. The regions where the first and third point cloud data are located overlap in two-dimensional space. All point cloud data of the second type are obtained by converting the hidden information of the second type. According to the third rule and the region where the second point cloud data is located in two-dimensional space, the electronic device converts the target hidden information of the first type into the first point cloud data of the first type in two-dimensional space. The region where the first point cloud data is located overlaps with the region where the second point cloud data is located in two-dimensional space, and the region where the first point cloud data is located overlaps with the region where the third point cloud data is located in two-dimensional space. All point cloud data of the first type are obtained by converting the hidden information of the first type.
[0011] As can be seen, by converting various types of information into point cloud data in two-dimensional space and ensuring the overlap between point cloud regions, the visual storage of information correlation is achieved. The third type of information is directly converted into point cloud data; the second type of hidden information overlaps with the third type of point cloud region; the first type of hidden information overlaps with the second type of point cloud region but not with the third type. This hierarchical structure ensures that the data maintains its inherent correlation during storage, but unauthorized users cannot directly interpret the hidden content. Point cloud conversion improves the efficiency and security of data storage, while providing authorized users with a spatial relationship-based retrieval and reconstruction method, enhancing the overall reliability of the shared system.
[0012] Optionally, the electronic device converts the second type of target hiding information into second type of second point cloud data in two-dimensional space according to the third rule and the region where the third point cloud data is located in two-dimensional space. This includes: the electronic device converting the second type of target hiding information into initial point cloud data of the second type in two-dimensional space according to the third rule; the electronic device determining whether the initial point cloud data of the second type is the point cloud data with the largest overlap area with the region where the third point cloud data is located in two-dimensional space according to the region where the third point cloud data is located in two-dimensional space; if yes, the electronic device confirms the initial point cloud data of the second type as the second point cloud data and confirms the third rule as the second rule; if no, the electronic device translates the initial point cloud data of the second type by a second distance to obtain translated point cloud data of the second type, confirms the translated point cloud data of the second type as the second point cloud data, and updates the preset rule to include translating by a second distance to obtain the second rule, wherein the translated point cloud data of the second type is the point cloud data with the largest overlap area with the region where the third point cloud data is located in two-dimensional space.
[0013] It can be seen that by dynamically adjusting the position of the second type of point cloud data to ensure maximum overlap with the third type of point cloud data, the accuracy of information association is optimized. If the initial point cloud data does not meet the maximum overlap condition, it is adjusted by translation and the rules are updated, which improves the flexibility and accuracy of data storage. This method makes the association between the second type of hidden information and the third type of information in two-dimensional space closer, facilitating subsequent authorized users to quickly locate and restore the data, while reducing storage redundancy and improving the performance of the shared system.
[0014] Optionally, the electronic device converts the first type of target hiding information into first type of first point cloud data in two-dimensional space according to the third rule and the region where the second point cloud data is located in two-dimensional space. This includes: the electronic device converting the first type of target hiding information into initial point cloud data of the first type in two-dimensional space according to the third rule; the electronic device determining whether the initial point cloud data of the first type is the point cloud data with the largest overlap area with the region where the second point cloud data is located in two-dimensional space according to the region where the second point cloud data is located in two-dimensional space; if yes, the electronic device determining the initial point cloud data of the first type as the first point cloud data and determining the third rule as the first rule; if no, the electronic device shifting the initial point cloud data of the first type by a first distance to obtain shifted point cloud data of the first type, determining the shifted point cloud data of the first type as the first point cloud data, and updating the preset rule to include shifting by a first distance to obtain the first rule, wherein the shifted point cloud data of the first type is the point cloud data with the largest overlap area with the region where the second point cloud data is located in two-dimensional space.
[0015] As can be seen, by shifting and adjusting the first type of point cloud data in a manner similar to that described above, the maximum overlap area between it and the second type of point cloud data is ensured, thereby strengthening the correlation between highly sensitive and moderately sensitive information. The determination and updating of the first rule guarantees the consistency of the transformation process, enabling authorized users to accurately trace the data chain during restoration. This enhances the coherence and reliability of the overall privacy protection system, while avoiding data loss or erroneous access due to unclear associations.
[0016] Optionally, the electronic device stores the first type of target hiding information, the second type of target hiding information, and the third type of target physical examination information into the three-dimensional physical examination system sharing system, including: the electronic device stores the coordinates of the first point cloud data in two-dimensional space, the coordinates of the second point cloud data in two-dimensional space, and the coordinates of the third point cloud data in two-dimensional space into the three-dimensional physical examination system sharing system.
[0017] As can be seen, storing the coordinates of point cloud data instead of the raw information further reduces the risk of privacy leaks. Coordinate data occupies little storage space in the 3D physical examination system's sharing system and cannot be directly read as sensitive content, but it can be reverse-converted into raw information through rules. This method improves the security and efficiency of data storage, while supporting coordinate-based spatial queries and correlation analysis, enabling the sharing system to maintain high-performance data processing capabilities while protecting privacy.
[0018] Optionally, the method further includes: the electronic device storing the first rule in a first secure storage area, and then configuring the read key of the first secure storage area as key information in the target physical examination information of the second type; and the electronic device also storing the second rule in a second secure storage area, and then configuring the read key of the second secure storage area as key information in the target physical examination information of the third type.
[0019] As can be seen, by storing the first and second rules in a secure storage area and using key information as the read key, authorization control for rule access is increased. Only users with the corresponding key information (such as specific data in the second or third type of hidden information) can open the secure area and obtain the rules, preventing unauthorized restoration of hidden information. This provides an additional layer of security, ensuring the integrity and confidentiality of the entire privacy protection system and reducing the risk of rules being maliciously exploited.
[0020] Optionally, the method further includes: the electronic device reading third point cloud data from the 3D physical examination system sharing system, and converting the third point cloud data into third-class target physical examination information according to a third rule; the electronic device obtaining a second rule based on key information in the third-class target physical examination information; the electronic device reading second-class point cloud data with the largest overlap area with the third point cloud data in two-dimensional space from the 3D physical examination system sharing system, determining the second-class point cloud data with the largest overlap area as the second point cloud data, and converting the second point cloud data into second-class target hidden information according to the second rule; the electronic device obtaining a third rule based on key information in the second-class target physical examination information; the electronic device reading first-class point cloud data with the largest overlap area with the second point cloud data in two-dimensional space from the 3D physical examination system sharing system, determining the first-class point cloud data with the largest overlap area as the first point cloud data, and converting the first point cloud data into first-class target hidden information according to the first rule.
[0021] As can be seen, the above scheme describes the process of gradually reconstructing information from a shared system. By inversely transforming point cloud data and utilizing key information retrieval rules, it ensures that only authorized users can access the complete information. Starting with the third type of information, the second and first types of hidden information are gradually reconstructed. This method maintains the hierarchical nature of data associations while strictly controlling access permissions. This improves the usability and security of the shared system in practical applications, enabling medical professionals to efficiently access data when needed without exposing sensitive information to unauthorized parties.
[0022] Optionally, the electronic device obtains a second rule based on key information in the third type of target medical examination information, including: the electronic device uses the key information in the third type of target medical examination information as a reading key to open a second secure storage area; and obtains the second rule from the second secure storage area while the second secure storage area is open. The electronic device also obtains a first rule based on key information in the second type of target medical examination information, including: the electronic device uses the key information in the second type of target medical examination information as a reading key to open a first secure storage area; and obtains the first rule from the first secure storage area while the first secure storage area is open.
[0023] As can be seen, opening the secure storage area with key information ensures strict authorization for rule access. Using key information from the third type of target health check information to open the second secure storage area, and using key information from the second type of target health check information to open the first secure storage area, forms a multi-layered access control system to prevent rule leakage. This design enhances the system's defense depth, making it difficult to recover highly sensitive content even if some information is accessed, thereby comprehensively improving the level of privacy protection.
[0024] In a second aspect, an electronic device is provided, which is configured to perform the method as described in the first aspect.
[0025] Thirdly, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are executed on a computer, the computer causes the computer to perform the method described in the first aspect. Attached Figure Description
[0026] Figure 1 A flowchart illustrating the method for protecting patient information privacy in a three-dimensional physical examination system sharing system provided in this application embodiment;
[0027] Figure 2 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0028] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0029] This application will present various aspects, embodiments, or features relating to systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that individual systems may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. Furthermore, combinations of these approaches are also possible.
[0030] Furthermore, in the embodiments of this application, the words "exemplary," "for example," etc., are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design scheme described as "exemplary" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the term "exemplary" is intended to present the concept in a concrete manner.
[0031] In the embodiments of this application, the terms "information," "signal," "message," "channel," and "singaling" may sometimes be used interchangeably. It should be noted that, without emphasizing their distinction, their intended meanings are consistent. Similarly, "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing their distinction, their intended meanings are consistent. Furthermore, the " / " mentioned in this application can be used to indicate an "or" relationship.
[0032] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0033] For example, Figure 1 This application provides a flowchart illustrating a method for protecting patient information privacy in a three-dimensional physical examination system sharing system. This method can be applied to electronic devices.
[0034] like Figure 1 As shown, the process of the patient information privacy protection method in this 3D physical examination system is as follows:
[0035] S101, The electronic device acquires the patient's physical examination information, which includes the first type of target physical examination information, the second type of target physical examination information, and the third type of target physical examination information.
[0036] The privacy protection priority of the first category of target physical examination information is higher than that of the second category, and the privacy protection priority of the second category of target physical examination information is higher than that of the third category.
[0037] The target medical examination information in Category 1 (i.e., core privacy) is information that is not shared by default. For example, Category 1 target medical examination information may include at least one of the following: the patient's ID number, mobile phone number, 3D facial model, or medical history (such as infectious diseases or genetic diseases). Category 2 target medical examination information is sensitive privacy. For example, Category 2 target medical examination information may include at least one of the following: the patient's name, age, 3D organ model (such as liver or heart), or key medical examination indicators (such as blood glucose or tumor markers), and requires conditional sharing. Category 3 target medical examination information is general privacy. For example, Category 3 target medical examination information may include at least one of the following: the date of the medical examination, the name of the institution, or routine indicators (such as height, weight, and non-biometric related items), and may be shared publicly to a limited extent.
[0038] Electronic devices can automatically scan the patient's three-dimensional physical examination data and label the information level according to classification rules, thus obtaining the target physical examination information of the first category, the target physical examination information of the second category, and the target physical examination information of the third category.
[0039] S102, the electronic device performs a first security process on the target physical examination information of the first type to obtain the target hiding information of the first type, and the electronic device performs a second security process on the target physical examination information of the second type to obtain the target hiding information of the second type.
[0040] The information security of the first security process is higher than that of the second security process.
[0041] For the first category of target medical examination information:
[0042] Electronic devices can perform masking processing on the first type of target physical examination information to obtain masked physical examination information. Masking processing refers to filtering out the internal parameters of the information, such as directly replacing the 3D facial model with a 2D facial contour. Electronic devices can then perform encryption processing on the masked physical examination information to obtain the first type of target hidden information. For example, if the SM4 national cryptographic algorithm is used for encryption, only authorized administrators can decrypt it.
[0043] As can be seen, by first performing masking (filtering out internal parameters) and then encryption on the first type of target physical examination information, dual security protection is achieved. Masking eliminates detailed parameters of the information, reducing the risk of direct leakage, while encryption ensures that even if the data is illegally accessed, the original content cannot be deciphered. This combined approach significantly enhances the security of highly sensitive information while maintaining the data's storage format within the shared system, allowing authorized users to only recover the information using a specific key, thereby preventing privacy leaks in extreme scenarios (such as system intrusion).
[0044] For the second category of target medical examination information:
[0045] Electronic devices can perform desensitization and blurring processing on the second type of target physical examination information to obtain the second type of target hidden information. Among them, blurring processing refers to blurring the range of information, such as removing personalized features from three-dimensional organ models (e.g., only labeling the tumor location as "abnormal in the liver region" without displaying the specific coordinates), and retaining the range value of key indicators (e.g., blood glucose "6.1-7.0 mmol / L", without displaying the precise value of 6.5 mmol / L).
[0046] It can be seen that by performing anonymization and obfuscation on the second type of target medical examination information, privacy is protected while retaining some of the data's usability. Anonymization removes direct identifiers (such as names), e.g., a name anonymized to "Zhang*San," while obfuscation converts specific values into ranges (such as age becoming an age group), making the information unlinkable to individuals but still usable for statistical analysis and macro-level research. This method reduces the risk of leakage of moderately sensitive information while ensuring the usability of the sharing system in medical research and avoiding data waste caused by over-protection.
[0047] The desensitization and blurring process is reversible in real time (only authorized users can restore some information according to their permissions), and the restoration operation requires secondary authentication (such as face recognition + dynamic password).
[0048] S103, the electronic device stores the target hiding information of the first type, the target hiding information of the second type, and the target physical examination information of the third type into the three-dimensional physical examination system sharing system.
[0049] In the three-dimensional physical examination system sharing system, the first type of target hidden information is related to the second type of target hidden information, and the second type of target hidden information is related to the third type of target physical examination information.
[0050] For example, an electronic device can convert third-type target physical examination information into third-type point cloud data in a two-dimensional space corresponding to the xy coordinate system according to the third rule. The third-type point cloud data includes multiple point cloud points in the two-dimensional space. All third-type point cloud data are obtained by converting third-type physical examination information. The third rule can be a conversion algorithm, such as linear transformation (using an invertible matrix for transformation) or hash-based reversible encoding (such as using a reversible hash function, such as a hash based on the Feistel structure), etc. The same applies below and will not be elaborated further.
[0051] Then, the electronic device can convert the second type of target hiding information into second type of second point cloud data in two-dimensional space according to the third rule and the region where the third point cloud data is located in two-dimensional space. The second type of second point cloud data includes multiple point cloud points in two-dimensional space. The region where the second point cloud data is located in two-dimensional space overlaps with the region where the third point cloud data is located in two-dimensional space, and all the second type of point cloud data is obtained by converting the second type of hiding information.
[0052] Specifically, the electronic device can convert the second type of target hiding information into second type of initial point cloud data in two-dimensional space according to the third rule. The electronic device can determine whether the second type of initial point cloud data is the point cloud data with the largest overlap area with the area of the third point cloud data in two-dimensional space, based on the region where the third point cloud data is located in two-dimensional space. The overlap area can be the area of the overlapping region between the outer circle of the third point cloud data in two-dimensional space and the outer circle of the second type of initial point cloud data in two-dimensional space. If yes, the electronic device identifies the initial point cloud data of the second type as the second point cloud data and identifies the third rule as the second rule; if no, the electronic device translates the initial point cloud data of the second type by a second distance to obtain translated point cloud data of the second type, identifies the translated point cloud data of the second type as the second point cloud data, and updates the preset rule to include translating by a second distance to obtain the second rule. The translated point cloud data of the second type is the point cloud data with the largest overlap area with the third point cloud data in two-dimensional space in the second type of point cloud data, so as to ensure that the second point cloud data can be uniquely indexed by the overlap area when reading data later.
[0053] It can be seen that by dynamically adjusting the position of the second type of point cloud data to ensure maximum overlap with the third type of point cloud data, the accuracy of information association is optimized. If the initial point cloud data does not meet the maximum overlap condition, it is adjusted by translation and the rules are updated, which improves the flexibility and accuracy of data storage. This method makes the association between the second type of hidden information and the third type of information in two-dimensional space closer, facilitating subsequent authorized users to quickly locate and restore the data, while reducing storage redundancy and improving the performance of the shared system.
[0054] Finally, the electronic device can convert the first type of target hiding information into first type of first point cloud data in two-dimensional space based on the third rule and the region where the second point cloud data is located in two-dimensional space. The first type of first point cloud data includes multiple point cloud points in two-dimensional space. The region where the first point cloud data is located in two-dimensional space overlaps with the region where the second point cloud data is located in two-dimensional space, but the region where the first point cloud data is located in two-dimensional space does not overlap with the region where the third point cloud data is located in two-dimensional space. All first type of point cloud data is obtained by converting the first type of hiding information.
[0055] Specifically, the electronic device can convert the target hiding information of the first type into initial point cloud data of the first type in two-dimensional space according to the third rule. The electronic device can determine whether the initial point cloud data of the first type is the point cloud data with the largest overlap area with the area where the second point cloud data is located in two-dimensional space, based on the region where the second point cloud data is located in two-dimensional space. The overlap area can be the area of the overlapping region between the outer circle of the second point cloud data in two-dimensional space and the outer circle of the initial point cloud data of the first type in two-dimensional space. If yes, the electronic device identifies the initial point cloud data of the first type as the first point cloud data and identifies the third rule as the first rule; if no, the electronic device translates the initial point cloud data of the first type by a first distance to obtain translated point cloud data of the first type, identifies the translated point cloud data of the first type as the first point cloud data, and updates the preset rule to include translating by a first distance to obtain the first rule. The translated point cloud data of the first type is the point cloud data with the largest overlap area with the second point cloud data in two-dimensional space in the first type of point cloud data, so as to ensure that the first point cloud data can be uniquely indexed by the overlap area when reading data later.
[0056] As can be seen, by shifting and adjusting the first type of point cloud data in a manner similar to that described above, the maximum overlap area between it and the second type of point cloud data is ensured, thereby strengthening the correlation between highly sensitive and moderately sensitive information. The determination and updating of the first rule guarantees the consistency of the transformation process, enabling authorized users to accurately trace the data chain during restoration. This enhances the coherence and reliability of the overall privacy protection system, while avoiding data loss or erroneous access due to unclear associations.
[0057] It can also be seen that by converting various types of information into point cloud data in two-dimensional space and ensuring the overlap between point cloud regions, the visual storage of information correlation is achieved. The third type of information is directly converted into point cloud data; the second type of hidden information overlaps with the third type of point cloud region; the first type of hidden information overlaps with the second type of point cloud region but not with the third type. This hierarchical structure ensures that the data maintains its inherent correlation during storage, but unauthorized users cannot directly interpret the hidden content. Point cloud conversion improves the efficiency and security of data storage, while providing authorized users with a spatial relationship-based retrieval and reconstruction approach, enhancing the overall reliability of the shared system.
[0058] Therefore, electronic devices can store the coordinates of the first point cloud data in two-dimensional space (i.e., the coordinates of each point cloud point in the first point cloud data in two-dimensional space), the coordinates of the second point cloud data in two-dimensional space (i.e., the coordinates of each point cloud point in the second point cloud data in two-dimensional space), and the coordinates of the third point cloud data in two-dimensional space (i.e., the coordinates of each point cloud point in the third point cloud data in two-dimensional space) into the three-dimensional physical examination system sharing system.
[0059] As can be seen, storing the coordinates of point cloud data instead of the raw information further reduces the risk of privacy leaks. Coordinate data occupies little storage space in the 3D physical examination system's sharing system and cannot be directly read as sensitive content, but it can be reverse-converted into raw information through rules. This method improves the security and efficiency of data storage, while supporting coordinate-based spatial queries and correlation analysis, enabling the sharing system to maintain high-performance data processing capabilities while protecting privacy.
[0060] Furthermore, the electronic device can store the first rule in a first secure storage area, and then configure the read key of the first secure storage area as key information in the second type of target medical examination information (specifically, a field at a specified location in the second type of target medical examination information, which can be preset by the administrator); and the electronic device can also store the second rule in a second secure storage area, and then configure the read key of the second secure storage area as key information in the third type of target medical examination information (specifically, a field at a specified location in the third type of target medical examination information, which can be preset by the administrator). The first and second secure storage areas are independent privacy storage areas, meaning their storage addresses are not contiguous. Additionally, the third rule can be stored in a public storage area.
[0061] As can be seen, by storing the first and second rules in a secure storage area and using key information as the read key, authorization control for rule access is increased. Only users with the corresponding key information (such as specific data in the second or third type of hidden information) can open the secure area and obtain the rules, preventing unauthorized restoration of hidden information. This provides an additional layer of security, ensuring the integrity and confidentiality of the entire privacy protection system and reducing the risk of rules being maliciously exploited.
[0062] In conjunction with S101-S103 above, after S103, the method further includes the following steps:
[0063] Step S1: The electronic device reads the third point cloud data from the three-dimensional physical examination system sharing system, and converts the third point cloud data into the third type of target physical examination information according to the third rule.
[0064] Step S2: The electronic device obtains the second rule based on the key information in the target physical examination information of the third category.
[0065] Specifically, the electronic device uses key information from the third type of target physical examination information (i.e., the third type of target physical examination information has already been obtained through reverse conversion) as a reading key to open the second secure storage area; and obtains the second rule from the second secure storage area when the second secure storage area is opened.
[0066] Step S3: The electronic device reads the second type of point cloud data with the largest overlapping area with the third point cloud data in two-dimensional space from the three-dimensional physical examination system sharing system, and determines the second type of point cloud data with the largest overlapping area as the second point cloud data, and converts the second point cloud data into the second type of target hidden information according to the second rule;
[0067] Step S4: The electronic device obtains the third rule based on the key information in the target physical examination information of the second category.
[0068] Specifically, the electronic device uses key information from the second type of target physical examination information (i.e., the second type of target physical examination information has already been obtained through reverse conversion) as a reading key to open the first secure storage area; and obtains the first rule from the first secure storage area when the first secure storage area is opened.
[0069] Step S4: The electronic device reads the first type of point cloud data with the largest overlapping area with the second point cloud data in two-dimensional space from the three-dimensional physical examination system sharing system, and determines the first type of point cloud data with the largest overlapping area as the first point cloud data, and converts the first point cloud data into target hiding information of the first type according to the first rule.
[0070] As can be seen, the above scheme describes the process of gradually restoring information from a shared system. By inversely transforming point cloud data and utilizing key information to obtain rules, it ensures that only authorized users can access complete information. Starting with the third type of information, the second and first types of hidden information are gradually restored. This method maintains the hierarchical nature of data associations while strictly controlling access permissions. This improves the usability and security of the shared system in practical applications, enabling medical professionals to efficiently obtain data when needed without exposing sensitive information to unauthorized parties. Furthermore, opening secure storage areas with key information ensures strict authorization for rule-based access. Using key information from the third type of target physical examination information to open the second secure storage area, and using key information from the second type of target physical examination information to open the first secure storage area, forms a multi-layered access control system to prevent rule leakage. This design enhances the system's defense depth, making it difficult to easily restore highly sensitive content even if some information is accessed, thereby comprehensively improving the level of privacy protection.
[0071] In summary, by categorizing physical examination information into three classes based on privacy protection priorities and applying higher-level security processing to high-priority information, a hierarchical privacy protection system is achieved. This ensures that highly sensitive information (such as the first class) receives the strongest protection, moderately sensitive information (such as the second class) receives appropriate protection, and low-sensitivity information (such as the third class) remains in its original state, thereby optimizing data usability while protecting privacy. During storage, the hidden information in the first and second classes is associated with the information in the third class, allowing authorized users to trace data relationships for medical analysis, while unauthorized users cannot access the original sensitive content. This method improves the security and flexibility of the 3D physical examination system sharing system, effectively balancing the needs of privacy protection and data sharing.
[0072] Figure 2 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Exemplarily, the electronic device may be a terminal device, or a chip (system) or other component or assembly that can be disposed in the terminal device. Figure 2As shown, the electronic device 400 may include a processor 401. Optionally, the electronic device 400 may also include a memory 402 and / or a transceiver 403. The processor 401 is coupled to the memory 402 and the transceiver 403, for example, they can be connected via a communication bus. Alternatively, the electronic device 400 may also be a chip, such as including the processor 401; in this case, the transceiver may be the chip's input / output interface.
[0073] The following is combined Figure 2 The various components of electronic device 400 are described in detail below:
[0074] The processor 401 is the control center of the electronic device 400. It can be a single processor or a collective term for multiple processing elements. For example, the processor 401 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).
[0075] Optionally, the processor 401 can perform various functions of the electronic device 400, such as the aforementioned functions, by running or executing software programs stored in the memory 402 and calling scientific data stored in the memory 402. Figure 1 The method for protecting patient information privacy in the shared system of the three-dimensional physical examination system is shown.
[0076] In a specific implementation, as one example, processor 401 may include one or more CPUs, for example... Figure 2 CPU0 and CPU1 are shown in the diagram.
[0077] In a specific implementation, as one example, the electronic device 400 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, a processor may refer to one or more devices, circuits, and / or processing cores used to process scientific data (such as computer programs or instructions).
[0078] The memory 402 is used to store the software program that executes the solution of this application, and is controlled by the processor 401 to execute it. The specific implementation method can be referred to the above method embodiment, and will not be repeated here.
[0079] Optionally, the memory 402 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or scientific data structures and accessible by a computer, but not limited thereto. The memory 402 may be integrated with the processor 401 or may exist independently and be accessible through the interface circuit of the electronic device 400. Figure 2 (Not shown in the image) is coupled to processor 401, but this embodiment does not specifically limit this.
[0080] Transceiver 403 is used for communication with other electronic devices. For example, if electronic device 400 is a terminal device, transceiver 403 can be used to communicate with a network device or with another terminal device. As another example, if electronic device 400 is a network device, transceiver 403 can be used to communicate with a terminal device or with another network device.
[0081] Alternatively, transceiver 403 may include a receiver and a transmitter. Figure 2 (Not shown separately). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.
[0082] Alternatively, the transceiver 403 can be integrated with the processor 401, or it can exist independently and be connected via the interface circuit of the electronic device 400. Figure 2 (Not shown in the image) is coupled to processor 401, but this embodiment does not specifically limit this.
[0083] Understandable Figure 2 The structure of the electronic device 400 shown does not constitute a limitation on the electronic device. Actual electronic devices may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0084] Furthermore, the technical effects of the electronic device 400 can be referred to the technical effects of the methods described in the above method embodiments, and will not be repeated here.
[0085] It should be understood that the processor in the embodiments of this application can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0086] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0087] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or scientific data center to another website, computer, server, or scientific data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a scientific data storage device such as a server or scientific data center that contains one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.
[0088] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.
[0089] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.
[0090] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0091] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0092] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0093] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0094] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0095] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0096] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0097] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for protecting patient information privacy in a three-dimensional physical examination system sharing system, characterized in that, Applied to electronic devices, the method includes: The electronic device acquires the patient's physical examination information, which includes a first type of target physical examination information, a second type of target physical examination information, and a third type of target physical examination information. The privacy protection priority of the first type of target physical examination information is higher than that of the second type of target physical examination information, and the privacy protection priority of the second type of target physical examination information is higher than that of the third type of target physical examination information. The electronic device performs a first security processing on the target physical examination information of the first type to obtain target hiding information of the first type, and the electronic device performs a second security processing on the target physical examination information of the second type to obtain target hiding information of the second type. The information security of the first security processing is higher than that of the second security processing. The electronic device stores the first type of target hiding information, the second type of target hiding information, and the third type of target physical examination information in the three-dimensional physical examination system sharing system. In the three-dimensional physical examination system sharing system, the first type of target hiding information is associated with the second type of target hiding information, and the second type of target hiding information is associated with the third type of target physical examination information. The electronic device stores the target hiding information of the first type, the target hiding information of the second type, and the target physical examination information of the third type into the three-dimensional physical examination system sharing system, including: According to the third rule, the electronic device converts the third type of target physical examination information into third type of third point cloud data in the two-dimensional space corresponding to the xy coordinate system. All third type of point cloud data are obtained by converting the third type of physical examination information. The electronic device converts the second type of target hiding information into second type of second point cloud data in the two-dimensional space according to the third rule and the region where the third point cloud data is located in the two-dimensional space. The region where the second point cloud data is located in the two-dimensional space overlaps with the region where the third point cloud data is located in the two-dimensional space. All second type point cloud data are obtained by converting the second type of hiding information. The electronic device converts the first type of target hiding information into first type of first point cloud data in the two-dimensional space according to the third rule and the region where the second point cloud data is located in the two-dimensional space. The region where the first point cloud data is located in the two-dimensional space overlaps with the region where the second point cloud data is located in the two-dimensional space, and the region where the first point cloud data is located in the two-dimensional space does not overlap with the region where the third point cloud data is located in the two-dimensional space. All point cloud data of the first type are obtained by converting the first type of hiding information.
2. The method according to claim 1, characterized in that, The first type of target physical examination information is information that is not shared by default. The electronic device performs a first security process on the first type of target physical examination information to obtain the first type of target hidden information, including: The electronic device performs a masking process on the target physical examination information of the first type to obtain the masked physical examination information. The masking process refers to filtering out the internal parameters of the information. The electronic device performs encryption processing on the shielded physical examination information to obtain the target hidden information of the first type.
3. The method according to claim 1, characterized in that, The electronic device performs a second security process on the target physical examination information of the second type to obtain target hiding information of the second type, including: The electronic device performs desensitization and blurring processing on the target physical examination information of the second type to obtain the target hidden information of the second type. The blurring processing refers to blurring the scope of the information.
4. The method according to claim 1, characterized in that, The electronic device, based on the third rule and the region where the third point cloud data is located in the two-dimensional space, converts the second type of target hiding information into second type of second point cloud data in the two-dimensional space, including: The electronic device converts the second type of target hiding information into the second type of initial point cloud data in the two-dimensional space according to the third rule; The electronic device determines, based on the region where the third point cloud data is located in the two-dimensional space, whether the initial point cloud data of the second type is the point cloud data with the largest overlap area with the region where the third point cloud data is located in the two-dimensional space among the point cloud data of the second type. If so, the electronic device determines the second type of initial point cloud data as the second point cloud data and the third rule as the second rule; If not, the electronic device translates the initial point cloud data of the second type by a second distance to obtain translated point cloud data of the second type, and determines the translated point cloud data of the second type as the second point cloud data, and updates the preset rules to include translating the second distance to obtain the second rule, wherein the translated point cloud data of the second type is the point cloud data with the largest overlap area with the region where the third point cloud data is located in the two-dimensional space in the second type of point cloud data.
5. The method according to claim 4, characterized in that, The electronic device, based on the third rule and the region where the second point cloud data is located in the two-dimensional space, converts the target hiding information of the first type into first point cloud data of the first type in the two-dimensional space, including: The electronic device converts the target hiding information of the first type into initial point cloud data of the first type in the two-dimensional space according to the third rule; The electronic device determines, based on the region where the second point cloud data is located in the two-dimensional space, whether the initial point cloud data of the first type is the point cloud data with the largest overlap area with the region where the second point cloud data is located in the two-dimensional space among the point cloud data of the first type. If so, the electronic device determines the initial point cloud data of the first type as the first point cloud data and determines the third rule as the first rule; If not, the electronic device translates the initial point cloud data of the first type by a first distance to obtain translated point cloud data of the first type, and determines the translated point cloud data of the first type as the first point cloud data, and updates the preset rule to include translating the first distance to obtain a first rule, wherein the translated point cloud data of the first type is the point cloud data with the largest overlap area with the area where the second point cloud data is located in the two-dimensional space in the first type of point cloud data.
6. The method according to claim 5, characterized in that, The electronic device stores the target hiding information of the first type, the target hiding information of the second type, and the target physical examination information of the third type into the three-dimensional physical examination system sharing system, including: The electronic device stores the coordinates of the first point cloud data in the two-dimensional space, the coordinates of the second point cloud data in the two-dimensional space, and the coordinates of the third point cloud data in the two-dimensional space into the three-dimensional physical examination system sharing system.
7. The method according to claim 6, characterized in that, The method further includes: The electronic device stores the first rule in a first secure storage area, and then configures the read key of the first secure storage area as key information in the target physical examination information of the second type; and the electronic device also stores the second rule in a second secure storage area, and then configures the read key of the second secure storage area as key information in the target physical examination information of the third type.
8. The method according to claim 6, characterized in that, The method further includes: The electronic device reads the third point cloud data from the three-dimensional physical examination system sharing system, and converts the third point cloud data into the target physical examination information of the third category according to the third rule; The electronic device obtains the second rule based on the key information in the target physical examination information of the third category; The electronic device reads the second type of point cloud data with the largest overlap area with the third point cloud data in the two-dimensional space from the three-dimensional physical examination system sharing system, determines the second type of point cloud data with the largest overlap area as the second point cloud data, and converts the second point cloud data into target hiding information of the second type according to the second rule. The electronic device obtains the third rule based on the key information in the target physical examination information of the second type; The electronic device reads the first type of point cloud data with the largest overlap area with the second point cloud data in the two-dimensional space from the three-dimensional physical examination system sharing system, determines the first type of point cloud data with the largest overlap area as the first point cloud data, and converts the first point cloud data into target hiding information of the first type according to the first rule.
9. The method according to claim 8, characterized in that, The electronic device obtains the second rule based on key information in the target physical examination information of the third category, including: The electronic device uses key information from the third type of target physical examination information as a reading key to unlock the second secure storage area; With the second secure storage area enabled, the second rule is retrieved from the second secure storage area; The electronic device obtains the first rule based on key information in the target physical examination information of the second type, including: The electronic device uses key information from the second type of target physical examination information as a reading key to unlock the first secure storage area; With the first secure storage area enabled, the first rule is retrieved from the first secure storage area.
Citation Information
Patent Citations
Fine-grained security data sharing method for patient health record privacy protection
CN116663047A
Artificial intelligence-based teenager mental health development track prediction system
CN120340858A