Portable medical image full data storage and label system

By constructing a portable medical image data storage and labeling system, the problems of incomplete image data encapsulation, lack of labeling system and insufficient security in existing technologies have been solved. This system achieves high integrity, high portability and efficient interactivity of medical image data, thereby improving diagnostic and treatment efficiency and data security.

CN121565398APending Publication Date: 2026-02-24SHANGHAI YIMAN ELECTRONIC TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511742469.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-25
Publication Date
2026-02-24

AI Technical Summary

Technical Problem

Existing portable medical image storage solutions lack a systematic encapsulation and standardized tagging system for the full data structure of medical images, resulting in easy loss of metadata, format incompatibility, and insufficient security, failing to meet the requirements of high integrity, high portability, and efficient interactivity.

Method used

A portable medical image data storage and labeling system is constructed, including a medical image full data encapsulation module, a multi-dimensional label generation module, a local secure storage module, an intelligent reading and parsing module, and a cross-platform interactive interface module. It adopts lossless compression, digital watermarking, hardware-level encryption, biometric authentication, and protocol adaptive technology to achieve complete storage, secure management, and rapid retrieval of image data.

Benefits of technology

It achieves high integrity, high portability and efficient interactivity of medical imaging data, ensures the security and traceability of data outside the hospital network environment, improves the efficiency of doctors in consultation and remote diagnosis and treatment scenarios, avoids the phenomenon of data silos, and ensures the timeliness and legal validity of diagnostic opinions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121565398A_ABST
    Figure CN121565398A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of medical information, particularly relates to a portable medical image full-data storage and labeling system, and aims to solve the problems of insufficient integrity, portability and traceability of medical image data under a film-free background. The system comprises a full-amount data packaging module, a multi-dimensional label generation module, a localization safety storage module, an intelligent reading analysis module and a cross-platform interaction interface module, safety storage and second-level retrieval are achieved through hardware encryption, biometric authentication and structured labels, offline label updating and multi-protocol compatibility are supported, and diagnosis and treatment efficiency and data sovereignty guarantee are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of medical information technology, specifically relating to a portable medical image full data storage and tagging system. Background Technology

[0002] In the field of medical imaging technology, end-to-end digital storage and display has become a core direction for the development of modern medical systems. With the continuous advancement of diagnostic and treatment methods, medical imaging data exhibits characteristics such as high resolution, multimodality, and large capacity, placing higher demands on data integrity, traceability, and convenient access. Against this backdrop, traditional image output methods based on physical film, due to inherent defects such as large storage space requirements, susceptibility to damage, and difficulty in sharing, are gradually becoming unsuitable for the needs of digital diagnostic and treatment environments. Especially under the national policy guidance of vigorously promoting green healthcare and reducing medical waste, the phasing out of film has accelerated significantly.

[0003] Portable medical image data management has become a crucial aspect of clinical practice. Doctors and patients urgently need a portable medium that can completely preserve original image data and its associated information (such as examination parameters, diagnostic labels, timestamps, etc.) to support cross-institutional consultations, remote follow-up visits, and continuous management of personal health records. Although current storage chip technology has high-speed read / write and large-capacity characteristics, existing portable storage solutions mostly focus on data copying functions and lack a systematic encapsulation and standardized labeling system for the entire medical image data structure. This leads to the easy loss of metadata during image data migration or the inability to be recognized by professional systems due to format incompatibility.

[0004] Existing technologies still have significant shortcomings in achieving portable medical image data: First, the stored content is limited to image pixel data, ignoring the rich metadata defined by standards such as DICOM, resulting in information gaps; second, there is a lack of a unified and scalable tagging mechanism, making it impossible to effectively link clinical diagnostic opinions, patient identities, and examination contexts; third, the system lacks secure access and data integrity verification mechanisms designed for medical scenarios, posing risks of privacy leaks and data tampering during portable use. These problems severely restrict the efficient, secure, and reliable transfer of medical image data in out-of-hospital settings, urgently requiring a new medical image data management system that integrates full data storage, structured tagging, and portability. Summary of the Invention

[0005] The purpose of this invention is to provide a portable medical image data storage and tagging system to solve the technical problem that existing medical image output and display methods cannot meet the needs of patients and doctors for high integrity, high portability, high traceability and efficient interactive medical image data management in the context of the gradual elimination of film.

[0006] The technical solution of this invention is a portable medical image full data storage and tagging system, comprising a medical image full data encapsulation module, a multi-dimensional tag generation module, a localized secure storage module, an intelligent reading and parsing module, and a cross-platform interactive interface module. The medical image full data encapsulation module receives raw image data streams output from medical imaging equipment and simultaneously integrates metadata information associated with the image. This metadata information includes patient identification, examination timestamp, equipment model, scanning parameters, diagnostic physician identification, and clinical diagnostic conclusion. The multi-dimensional tag generation module automatically generates a structured tag set based on the metadata information and a preset clinical knowledge graph. This structured tag set includes anatomical location tags, pathological feature tags, image quality tags, and clinical use tags. The localized secure storage module stores the encapsulated full data package... The data is encrypted and bound to the corresponding structured tag set and written to a portable solid-state storage medium. The portable solid-state storage medium uses a hardware-level encryption chip that complies with medical data security standards and supports a dual access control mechanism of physical write protection switch and biometric authentication. The intelligent reading and parsing module is used to automatically parse the internal structure of the full data packet after authenticating the accessed portable solid-state storage medium on an authorized terminal device, restore the original image data and its associated metadata, and build a local index directory based on the structured tag set to achieve fast retrieval and visualization by tag dimension. The cross-platform interaction interface module is used to provide a standardized data exchange protocol, supporting seamless integration with hospital information systems, image archiving and communication systems, and mobile medical terminals, ensuring that the full content of medical image data can be completely read and rendered in different operating systems and hardware environments.

[0007] Furthermore, the medical image full data encapsulation module uses a lossless compression algorithm to encapsulate the original image data, with the compression ratio controlled within 1.5 times to ensure that no information is lost in the image details; at the same time, the module embeds a digital watermark during the encapsulation process. The digital watermark contains a unique identifier for the data packet and a timestamp hash value, which is used for subsequent data integrity verification.

[0008] Furthermore, the clinical knowledge graph in the multidimensional label generation module is jointly constructed from authoritative medical guidelines, imaging diagnostic standards, and historical case databases, with its nodes covering no less than 5,000 anatomical structures and 3,000 pathological manifestations. The label generation process adopts a hybrid strategy driven by rule-based reasoning and deep learning. Rule-based reasoning is used to ensure that the labels conform to clinical standards, while the deep learning model is used to automatically identify potential pathological regions from image pixel features and generate candidate labels. The final label set is output after the system automatically scores the confidence level, with the confidence threshold set to 85%.

[0009] Furthermore, the portable solid-state storage medium used in the localized secure storage module has IP68 dust and water resistance and a 1.5-meter drop-resistant structure design, with a storage capacity of no less than 512GB and a read / write speed of no less than 500MB per second; its hardware-level encryption chip supports the national cryptographic SM4 algorithm, and the key is generated by the user's biometrics and the device's unique serial number, and the key is not stored on any external server.

[0010] Furthermore, when the intelligent reading and parsing module is running on the terminal device, it first verifies the physical write protection status of the portable solid-state storage medium. If it is in the write protection enabled state, only reading operations are allowed. Then, it obtains the user's fingerprint or iris information through the biometric authentication module and compares it with the authorization template pre-stored in the storage medium. Only after successful comparison can the data packet be decrypted. The decrypted data packet is parsed according to the DICOM PS3.10 standard and the temporal and spatial relationships of the image sequence are automatically reconstructed.

[0011] Furthermore, the cross-platform interactive interface module supports three mainstream medical data protocols: DICOM, HL7, and FHIR, and has a built-in protocol adaptive engine that can automatically select the optimal transmission mode based on the interface capabilities of the target system. In mobile terminal scenarios, the module achieves smooth scaling and window width / level adjustment of 4K resolution medical images through a lightweight rendering engine, with a rendering latency of no more than 200 milliseconds.

[0012] Furthermore, the system also includes an offline label update submodule, which allows authorized physicians to add diagnostic opinions or correct labels to stored image data in a network-free environment. The updated content is encrypted and written to a dedicated partition of the storage medium in the form of incremental packets, and a new timestamp and digital signature are generated to ensure that the data version is traceable.

[0013] Furthermore, the portable solid-state storage medium is equipped with a status indicator light to display the connection status, authentication status, and remaining storage space of the storage medium in real time; when the remaining space is less than 10%, the system automatically triggers an early warning prompt and suggests that the user archive the data or replace the medium.

[0014] Compared with the prior art, the advantages and positive effects of the present invention are as follows: This invention completely solves the problem that traditional films or single DICOM files cannot carry complete clinical context information by constructing an integrated encapsulation system for full-volume medical image data and multi-dimensional structured tags. This makes portable media not only store image pixels but also become a knowledge carrier containing diagnostic logic and clinical semantics. The localized secure storage module, combined with hardware-level encryption and biometric authentication, achieves end-to-end secure management of medical data after it leaves the hospital network environment, effectively avoiding the risks of data leakage and unauthorized tampering. The intelligent reading and parsing module, through automatic indexing and tag-driven retrieval mechanisms, significantly improves the efficiency of doctors in obtaining key image information in consultation, referral, or remote diagnosis scenarios. The traditional manual browsing process, which takes several minutes, is shortened to a second-level positioning; the protocol adaptability of the cross-platform interactive interface module ensures the system's broad compatibility in heterogeneous medical environments, avoiding data silos caused by system barriers; the offline label update mechanism empowers clinicians with the right to authoritatively annotate image data in any scenario, ensuring the timeliness and legal validity of diagnostic opinions; overall, this invention not only conforms to the development trend of filmless medicine, but also constructs a new paradigm for medical image data management that is safe, intelligent, portable, and continuously evolving through system-level innovation, providing solid technical support for improving diagnostic and treatment efficiency, protecting data sovereignty, and promoting the implementation of hierarchical medical treatment. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of the overall technical solution architecture of the present invention. Detailed Implementation

[0016] Please refer to Figure 1 This invention provides a portable medical image data storage and tagging system. This system aims to address the shortcomings of existing medical image management models in meeting the healthcare industry's demands for high integrity, portability, traceability, and efficient interactivity of medical image data in the context of the phasing out of film. In this embodiment, the system is conceived as a compact, autonomous entity whose core functions focus on the acquisition, in-depth processing, secure storage, and intelligent interaction of medical image data.

[0017] The overall technical solution of this system includes: a medical image full-data encapsulation module, a multi-dimensional tag generation module, a localized secure storage module, an intelligent reading and parsing module, and a cross-platform interaction interface module. The system's workflow is as follows: the medical image full-data encapsulation module first receives and encapsulates the raw image data stream and associated metadata; then, the multi-dimensional tag generation module generates a structured tag set based on the metadata; the localized secure storage module encrypts and binds the encapsulated full data package and tag set and writes it to a portable solid-state storage medium; the intelligent reading and parsing module verifies the medium and parses the data on authorized terminals, enabling rapid retrieval and visualization; finally, the cross-platform interaction interface module provides standardized protocols to ensure seamless data integration and complete rendering across different medical systems. In addition, the system is also equipped with an offline tag update submodule for data correction and version tracking in offline environments.

[0018] The core responsibility of the medical imaging full-data encapsulation module is to receive raw data from medical imaging equipment and deeply integrate it with all associated metadata to form a complete and self-consistent full-data package. This module establishes real-time data connections with various medical imaging devices, such as computed tomography (CT) scanners, magnetic resonance imaging (MRI) machines, ultrasound diagnostic equipment, and digital subtraction angiography (DSA) machines, directly through high-speed data interfaces, such as Universal Serial Bus 3.0 or Thunderbolt interfaces. When the equipment generates a raw image data stream, the module synchronously initiates the data receiving process. The raw image data stream typically contains pixel array data, which describes the spatial distribution and intensity information of the image. The module supports multiple raw image data formats, such as DICOM raw pixel streams, lossless JPEG 2000 encoded streams, and uncompressed bitmap format data, ensuring compatibility with a wide range of imaging equipment.

[0019] While receiving the raw image data stream, the medical image full data encapsulation module integrates metadata information closely related to the image in parallel. This metadata information forms the context of the image and is indispensable for subsequent diagnosis, retrieval, and decision-making. Metadata information includes, but is not limited to: patient identification, which adopts a unique patient identification coding rule that conforms to international medical information standards, such as medical record number or globally unique identifier, to ensure the identifiability and privacy protection of patient information; examination timestamp, which accurately records the date and specific time of image acquisition, accurate to the millisecond level, providing a basis for the temporal analysis of image data; device model, which records in detail the manufacturer, specific model and serial number of the medical device that generated the image, helping to trace the source of the image and calibration parameters; scanning parameters, which cover various technical settings in the image acquisition process, such as radiation dose, scan slice thickness, acquisition sequence, matrix size, window width and window level preset values, etc., these parameters are crucial for image quality assessment and reproduction; diagnostic physician identification, which records the unique identification information of the physician responsible for the current image diagnosis, such as physician employee number or electronic signature certificate identifier, to ensure the traceability of diagnostic responsibility; and clinical diagnostic conclusion, which is the preliminary or final diagnostic opinion given by the diagnostic physician based on the image results, and its format is usually structured text or coded terminology, such as the International Classification of Diseases code. The module uses an internal data structure, such as JSON or XML, to organize all this metadata information in key-value pairs and establish a logical association with the original image data, ensuring consistency between the two during storage.

[0020] Furthermore, the medical image full-data encapsulation module employs a lossless compression algorithm to encapsulate the original image data. Choosing lossless compression aims to ensure that every detail of the image pixels is fully preserved, avoiding any information loss that could adversely affect subsequent diagnosis. In this embodiment, the module preferably uses lossless modes such as JPEG 2000 or lossless H.264 algorithms for data compression. During execution, the compression ratio is strictly controlled to within 1.5 times. This limitation is based on a comprehensive consideration of image data processing efficiency and storage space efficiency. While a higher compression ratio can save more storage space, it may increase encoding and decoding time overhead, while a compression ratio that is too low cannot effectively reduce data volume. A compression ratio of 1.5 times has been experimentally verified to achieve efficient data transmission and storage while maintaining excellent image quality.

[0021] Simultaneously, this module embeds a digital watermark during the encapsulation process. Digital watermarking is a covert technology designed to embed additional information into image data without affecting visual quality. In this embodiment, the digital watermark comprises two key components: a unique data packet identifier and a timestamp hash value. The unique data packet identifier is a globally unique string generated by the system to ensure that each encapsulated full data packet has a unique identity. The timestamp hash value is the result of encrypted hashing of the timestamp at the time the data packet was generated. The digital watermark embedding algorithm employs a robust discrete wavelet transform domain embedding method to ensure that the watermark information can still be effectively extracted after routine image processing operations. The main purpose of embedding the digital watermark is for subsequent data integrity verification. When data packets may be tampered with during transmission or storage, by extracting and verifying the digital watermark, the system can quickly detect unauthorized modifications or damage to the data, thereby ensuring the originality and credibility of medical image data. After completing data encapsulation, compression, and watermark embedding, the module outputs a full data packet in a unified format, ready for subsequent tag generation and secure storage.

[0022] The multidimensional tag generation module's core function is to automatically and intelligently generate a set of structured tags based on metadata information provided by the medical image full-data encapsulation module and combined with a deep clinical knowledge graph. The module receives input including patient identification, examination timestamps, equipment model, scanning parameters, diagnosing physician identification, and clinical diagnostic conclusions. This metadata information forms the basis for tag generation.

[0023] Furthermore, the clinical knowledge graph in the multidimensional label generation module is constructed from three main parts: authoritative medical guidelines, imaging diagnostic standards, and a historical case database. Authoritative medical guidelines include international and national disease diagnosis and treatment guidelines, such as the World Health Organization's International Classification of Diseases (ICD-1) and clinical practice guidelines published by various professional societies. Imaging diagnostic standards encompass common imaging report templates and diagnostic standards, such as the American College of Radiology's Radiological Reporting and Data System (ACRS). The historical case database is a large-scale, anonymized collection of medical imaging cases, containing a large amount of confirmed and labeled imaging data and clinical information. The clinical knowledge graph is stored and managed using graph database technology, with nodes covering no fewer than 5,000 anatomical structures and no fewer than 3,000 pathological manifestations. Anatomical structure nodes include all relevant terms and hierarchical relationships from macroscopic organ systems to microscopic tissue and cell levels, such as "heart," "left ventricle," and "myocardium." Pathological manifestation nodes describe various abnormal signs that may appear in imaging, such as "nodules," "calcification," "effusion," and "tumor necrosis." These nodes are connected by semantic relationships, such as "contains", "located in", "manifests as", and "diagnoses as", forming a large and rigorous medical semantic network.

[0024] The tag generation process employs a hybrid strategy driven by rule-based reasoning and deep learning. The rule-based reasoning engine ensures that the generated tags conform to strict clinical standards and logical consistency. This engine has a built-in set of rules defined by medical experts, such as "If an image shows a solid nodule larger than 1 cm in diameter with irregular boundaries in the lung, lung cancer should be considered, and the candidate tag 'malignant tumor' should be generated." Rule-based reasoning primarily processes structured information in metadata, such as keyword matching of clinical diagnostic conclusion text and comparison of equipment parameters with image quality standards.

[0025] Deep learning models are used to automatically identify potential pathological regions and generate candidate labels from image pixel features. In this embodiment, the deep learning model employs a convolutional neural network architecture pre-trained on a large-scale medical image dataset, such as U-Net or a variant of Mask R-CNN. The model can perform pixel-by-pixel analysis of the raw image data, automatically segment lesion regions, and predict corresponding pathological feature labels, such as "pulmonary nodules," "liver cysts," and "bone hyperplasia," based on their morphological features, texture features, and spatial distribution. The model is trained using a historical case database containing a large amount of labeled data, and supervised learning enables it to accurately extract visual features from images and map them to medical concepts.

[0026] The final label set is output by the system after automatic confidence scoring. Each generated candidate label is assigned a confidence score between 0 and 1, representing the system's assessment of the label's accuracy. The confidence score is calculated by weighted fusion of the matching strength of rule-based reasoning and the prediction probability of the deep learning model. For example, if the deep learning model predicts a region as a "nodule" with a probability of 0.9, and rule-based reasoning also confirms the mention of "nodule" in the diagnosis through keyword matching, then the label's confidence will be very high. The system sets a confidence threshold of no less than 85%. Only when a label's confidence score exceeds this threshold will it be included in the final structured label set. The structured label set includes anatomical location labels, pathological feature labels, image quality labels, and clinical use labels. Anatomical location labels precisely identify the body parts involved in the image, such as "right upper lobe of the lung." Pathological feature labels describe detected abnormalities, such as "ground-glass opacity." Image quality labels assess image sharpness and noise levels, such as "high quality" and "motion artifacts present." Clinical use tags indicate the clinical application scenario of the image, such as "diagnostic assessment", "preoperative planning", and "follow-up observation". These tags are output in a structured format, such as a tag tree consisting of hierarchical relationships or a semantic vector, and are bound to the full data packet.

[0027] The core function of the localized secure storage module is to securely bind and encrypt the encapsulated and tagged full data package of medical images with the corresponding structured tag set, and finally write it to a portable solid-state storage medium. This module first receives the full data package output by the full medical image data encapsulation module and the structured tag set output by the multi-dimensional tag generation module. Before writing to the solid-state storage medium, the module encrypts and binds these two parts of data. Encryption binding refers to integrating the full data package and the structured tag set into a single logical unit and encrypting this logical unit as a whole, ensuring the consistency of their physical storage correlation and encryption strength.

[0028] Furthermore, the portable solid-state storage media used in the localized secure storage module features IP68 dust and water resistance and a 1.5-meter drop-resistant design. The IP68 protection rating means the storage media is completely dustproof and can withstand prolonged immersion in water deeper than 1 meter without damage, ensuring reliability in various harsh medical environments. The 1.5-meter drop-resistant design ensures the media can withstand impacts from accidental drops, effectively protecting internal data. The media has a storage capacity of at least 512GB, providing ample space to store large amounts of high-resolution medical image data. Its read / write speed is at least 500MB per second, ensuring efficient data transfer and meeting the demands of rapid access.

[0029] The portable solid-state storage medium integrates a hardware-level encryption chip that meets medical data security standards. This chip supports the SM4 algorithm, a block cipher algorithm released by the State Cryptography Administration of China, characterized by high security and high efficiency, effectively resisting various known attacks. The key generation mechanism is crucial to the security of this module: the key is generated jointly by the user's biometrics and the device's unique serial number. The user's biometrics can be fingerprints or iris information, which is recorded by a secure acquisition device upon initial use and stored in an isolated secure area within the medium after encryption. The device's unique serial number is a globally unique identifier embedded in the hardware at the time of manufacture. These two elements are fused using a preset secure hash function and a key derivation function to generate the final encryption key. Crucially, this key is not stored on any external server. This means that even if an external system is attacked, it cannot obtain the decryption key, thus achieving physical isolation protection of the data key and greatly improving data security.

[0030] Portable solid-state storage media also supports a dual access control mechanism: a physical write-protection switch and biometric authentication. The physical write-protection switch is a mechanical toggle switch on the outside of the media. When in the "write-protection enabled" state, the storage area of ​​the media becomes read-only, and all write operations are rejected at the hardware level, effectively preventing virus infection or malicious tampering. The biometric authentication mechanism is an access control mechanism implemented at the software level. It verifies whether the user has permission to access the media by comparing their fingerprint or iris information. Subsequent data read and write operations are only allowed after successful biometric authentication.

[0031] Before writing data, the module first generates a session key through an internal key management subsystem, which is encrypted and protected by the master key. Then, the full data packet and structured tag set are encapsulated into an encrypted data block and encrypted using the SM4 algorithm with the session key. After encryption, the encrypted data block is written to the portable solid-state storage medium. During the writing process, the module also performs write integrity checks, such as cyclic redundancy checks, to ensure that the data is not corrupted during transmission to the medium.

[0032] Portable solid-state storage media are equipped with status indicator lights to display the connection status, authentication status, and remaining storage space in real time. The connection status indicator, for example, a solid green light, indicates that the media has successfully connected to the terminal device and is communicating normally. The authentication status indicator, for example, a flashing blue light, indicates that the media is undergoing biometric authentication; after successful authentication, the indicator may turn solid blue. The remaining storage space indicator uses color or flashing frequency changes—green for sufficient space, yellow for warning, and red for critically low space—to visually display the current storage capacity usage to the user. When the remaining space falls below 10%, the system automatically triggers a warning. The warning is presented on the connected terminal device as an audio signal or a pop-up window, suggesting that the user archive data or replace the media. This mechanism aims to prevent data loss or inability to write new data due to running out of storage space, thereby ensuring the continuous availability and data integrity of the system.

[0033] The intelligent reading and parsing module's core function is to intelligently parse the full data packets within the portable solid-state storage medium after authenticating the connection on an authorized terminal device. This allows for the reconstruction of the original image data and its associated metadata, and the construction of a local index directory based on a structured tag set. Ultimately, this enables rapid retrieval and visualization by tag dimension. This module is designed as an application embedded in a medical workstation or mobile diagnostic terminal.

[0034] Furthermore, when the intelligent read and parsing module runs on the terminal device, it first executes a multi-layered security verification process. The first step is to verify the physical write-protection status of the portable solid-state storage medium. The module detects the current position of the physical write-protection switch by reading specific registers or signals of the medium's hardware interface. If the medium is detected to be in a write-protection enabled state, the system will strictly restrict all write operations, allowing only read operations. This is intended to prevent unauthorized modification or deletion of the original data due to misoperation or other reasons during diagnosis or consultation, thereby maintaining the integrity and legal validity of the data source.

[0035] Subsequently, the module obtains the user's fingerprint or iris information through the biometric authentication module. This requires the terminal device to integrate a high-precision biometric sensor, such as an optical fingerprint reader or an infrared iris scanner. The acquired user biometric data is preprocessed locally, including feature point extraction and cryptographic hashing. The processed user biometric data is then securely compared with a pre-stored authorization template within the storage medium. The pre-stored authorization template is entered securely by the authorized user during the initial configuration of the medium and encrypted and stored in a secure area within the medium. The comparison process employs secure multi-party computation or homomorphic encryption technology to ensure that the user's biometric data does not leak its original information during the comparison process. The data packet can only be decrypted after a successful comparison. If the comparison fails or the user is not authenticated, the module will refuse access to the data packet and log a security message to prevent unauthorized access.

[0036] The decrypted data packets are parsed according to the DICOM PS3.10 standard. The DICOM PS3.10 standard is a medical standard for digital imaging and communication, defining the structure and encoding rules for storing medical image information. The parser can identify the DICOM header, information object definitions, and transmission syntax in the data packets, thereby accurately separating the raw pixel data from the embedded metadata. During parsing, the module also automatically reconstructs the temporal and spatial relationships of the image sequence. This is crucial for multi-frame dynamic images (e.g., echocardiography) or multi-sequence scans (e.g., contrast-enhanced MRI). By parsing the frame number, scan position, and time information contained in the DICOM tags, the module reorganizes scattered image frames or sequences into three-dimensional or four-dimensional image data with the correct spatiotemporal context, ensuring that doctors can view and understand the images in the most intuitive way.

[0037] After parsing, the module constructs a local index directory based on the structured tag set. This index directory is an optimized database structure, such as a relational database or document database, which stores the reference path, metadata summary, and all associated structured tags for each image data package, with tags as the core dimension. Through this local index directory, users can perform rapid searches by tag. For example, doctors can quickly filter out matching image cases by entering tag combinations such as "right upper lobe nodule," "preoperative assessment," and "high resolution," reducing the traditional manual browsing process that takes minutes or even hours to mere seconds.

[0038] The system also supports visualization. The module incorporates a high-performance rendering engine capable of real-time rendering of the restored original image data. The rendering engine supports multiple image display modes, such as grayscale, pseudo-color, multi-planar reconstruction, and 3D volumetric reconstruction. Users can perform smooth zooming, panning, and window width / level adjustments on their terminal devices to observe image details from the best perspective. Furthermore, the rendering engine supports the visual overlay of structured labels, such as highlighting pathological areas on the image and annotating them with corresponding pathological feature labels, thereby enhancing diagnostic intuitiveness.

[0039] The cross-platform interaction interface module's core function is to provide standardized and flexible data exchange protocols, ensuring seamless integration between this portable medical image data storage and labeling system and heterogeneous medical information systems. This enables complete reading and high-quality rendering of medical image data across different operating systems and hardware environments. This module serves as the system's external gateway.

[0040] Furthermore, the cross-platform interaction interface module supports three mainstream medical data protocols: DICOM, HL7, and FHIR. The DICOM protocol is the de facto standard in the field of medical imaging, and the module supports multiple service classes such as image storage, query / retrieval, and worklists, enabling direct interaction with hospital image archiving and communication systems. The HL7 protocol is a widely used messaging standard in healthcare, and the module supports HL7 V2 and V3 versions, enabling the exchange of text data such as patient information and medical orders with hospital information systems. The FHIR protocol is a new generation of medical interoperability standard based on modern network technology. The module supports the FHIR resource model and RESTful application programming interface, enabling data exchange with emerging mobile diagnostic terminals or cloud-based medical applications in a lighter and more flexible manner.

[0041] The module incorporates a built-in protocol adaptive engine. This engine is an intelligent decision-making system that dynamically detects the target system's interface capabilities and preferences during connection establishment and automatically selects the optimal transmission mode and protocol version. For example, when connecting to a modern PACS system that supports DICOM web, the engine will prioritize the DICOM web interface for HTTP-based image transmission; while when connecting to a traditional PACS system, the engine will fall back to the standard DICOM C-STORE service. If the target system supports multiple protocols, the engine will weigh factors such as data type, transmission efficiency, and security requirements using an internal decision algorithm. For instance, for large-scale image data, it may prioritize the more efficient DICOM; for patient metadata, it may choose HL7 or FHIR.

[0042] In mobile scenarios, this module utilizes a lightweight rendering engine to achieve smooth scaling and window width / level adjustment of 4K resolution medical images. Traditional full-resolution medical images involve massive amounts of data, and direct rendering on resource-constrained mobile devices faces performance bottlenecks. The lightweight rendering engine employs multi-resolution pyramid storage, tile loading technology, and GPU-accelerated rendering technology. When a user zooms on a mobile device, the engine intelligently loads image tiles corresponding to the zoom level, rather than loading the entire high-resolution image, significantly reducing memory usage and computational load. Window width / level adjustment is a display parameter unique to medical images, used to adjust the brightness and contrast of the image to highlight different tissue structures. The lightweight rendering engine achieves millisecond-level real-time window width / level adjustment by directly manipulating the GPU's lookup table or shaders, ensuring users on mobile devices can enjoy an interactive experience comparable to that of a professional workstation. Rendering latency is strictly controlled within 200 milliseconds, meaning that any user interaction receives almost instant visual feedback, guaranteeing the real-time nature and efficiency of mobile diagnosis and treatment.

[0043] The offline label update submodule addresses the practical need for authorized physicians to add diagnostic comments or correct labels on stored medical image data in offline environments without network connectivity. This module is a standalone software component, typically deployed on authorized terminal devices used with portable solid-state storage media. The offline label update submodule is activated when the portable solid-state storage media is connected to the terminal device.

[0044] This submodule first verifies the identity and authorization level of the currently operating physician through the authentication mechanism of the intelligent reading and parsing module. Only authorized physicians can update the data, ensuring the authority and legality of data modifications. In offline environments, physicians can retrieve and review image data stored on the media. Physicians can add new diagnostic annotations to the image data, such as adding detailed descriptions of a pathological area or correcting inaccurate labels automatically generated by the system. For example, a physician can change "suspected inflammation" to "confirmed bacterial pneumonia" and add a new clinical recommendation label.

[0045] Updates are encrypted and written to a dedicated partition of the storage medium in incremental packets. An incremental packet is a single data structure containing only the modified content, rather than rewriting the entire data packet, significantly reducing write operations, improving efficiency, and minimizing media wear. This incremental packet is encrypted using the same SM4 algorithm as the full data packet, ensuring the confidentiality of the updated content. The dedicated partition is a reserved, independently managed storage area on the portable solid-state storage medium specifically for storing these offline update incremental data. Simultaneously with writing the incremental packet, the system generates a new timestamp and digital signature. The new timestamp precisely records the time of the update operation. The digital signature is generated by signing the incremental packet content with the operator's digital certificate private key, used to verify the authenticity and integrity of the updated content and the operator's identity. This metadata is stored along with the incremental packet in the dedicated partition. Ensuring data version traceability is a key objective of this module. Through the timestamp and digital signature attached to each incremental packet, the system can construct a complete chain of modification history. When the media is reconnected to a hospital information system or PACS system with a network environment, the offline label update submodule automatically detects the incremental packets in the dedicated partition and initiates a data synchronization mechanism. The synchronization process verifies the digital signature of the incremental packets, parses the updated content, and then securely merges it into the main database, updating the latest version of the image data record. In this way, even modifications made offline can be seamlessly integrated into the overall medical information system after reconnection, maintaining data consistency and reliability.

[0046] This embodiment constructs a closed-loop, secure, intelligent, and highly portable medical image data management system through the collaborative work of all the aforementioned units. It integrates raw image pixel data, comprehensive metadata, and intelligently generated structured tag sets into a single package, solving the problem that traditional films or single DICOM files cannot carry complete clinical context information. The localized secure storage module, combined with hardware-level encryption, biometric authentication, and physical write protection, achieves end-to-end secure management of medical data after it leaves the hospital network environment, effectively mitigating the risks of data leakage and unauthorized tampering. The intelligent reading and parsing module, through automatic indexing and tag-driven retrieval mechanisms, significantly improves the efficiency of doctors in obtaining key image information during consultations, referrals, or remote diagnosis scenarios, reducing the traditional manual browsing process of several minutes to seconds. The cross-platform interactive interface module's protocol adaptability ensures the system's broad compatibility in heterogeneous medical environments, avoiding data silos caused by system barriers. The offline tag update submodule empowers clinicians with the right to authoritatively annotate image data in any scenario, ensuring the timeliness and legal validity of diagnostic opinions. Overall, this invention not only conforms to the development trend of filmless medicine, but also constructs a new paradigm for medical image data management that is safe, intelligent, portable and continuously evolving through system-level innovation, providing solid technical support for improving diagnostic and treatment efficiency, protecting data sovereignty and promoting the implementation of hierarchical medical treatment.

[0047] This system design overcomes many challenges in existing medical image management. For example, in a tiered healthcare system, patients may carry image data between different levels of medical institutions. Traditionally, image data is often presented in the form of physical films, which are not only bulky and fragile but also unable to carry all metadata and diagnostic information. While a single DICOM file is a digital format, it lacks structured tags, requiring doctors to spend a significant amount of time manually searching for key information, and its security is difficult to guarantee when disconnected from the hospital's intranet. This invention, through portable solid-state storage media, combined with comprehensive data encapsulation and robust security mechanisms, enables patients to safely and conveniently carry complete medical image data, effectively solving these problems.

[0048] In telemedicine and consultation scenarios, doctors often face problems such as low image data transmission efficiency, poor cross-platform compatibility, and a lack of unified semantic annotation. This invention's cross-platform interaction interface module, by supporting multiple mainstream protocols and a built-in protocol adaptive engine, ensures smooth flow of image data between different medical systems and remote terminals. The multi-dimensional tag generation module provides unified, structured semantic annotation, enabling different experts to understand the same image based on the same knowledge context, greatly improving consultation efficiency and diagnostic accuracy. Simultaneously, the intelligent reading and parsing module's rapid retrieval capability allows remote experts to quickly locate key areas and pathological features in images, avoiding lengthy manual screening processes.

[0049] In the fields of medical teaching and research, high-quality, well-annotated medical image datasets are indispensable resources. This invention's system can automatically generate refined multidimensional labels, providing a powerful tool for constructing large-scale, high-value teaching and research image databases. The offline label update submodule allows researchers or teaching physicians to professionally annotate and comment on images in offline environments, further enriching the semantic information of the dataset. Simultaneously, embedded digital watermarks and strict access control mechanisms within the data packets ensure the originality and security of research data, preventing unauthorized use and tampering, thereby promoting the effective dissemination of medical knowledge and innovative research.

[0050] The medical imaging full-data encapsulation module employs a multi-threaded parallel processing architecture when processing raw image data streams. The data receiving subsystem directly writes raw image data to a memory buffer via a high-speed direct memory access channel, avoiding CPU interrupt overhead and achieving extremely high data throughput. The metadata integration subsystem uses an asynchronous task queue to retrieve relevant metadata from device information interfaces and the hospital information system in real time, performing preliminary data cleaning and standardization. For example, it unifies the timestamp formats output from different devices, standardizes patient identification, and removes redundant or inconsistent information. To ensure data real-time performance and consistency, the module maintains an internal time synchronization service, synchronizing with an external high-precision time server via a network time protocol to ensure accurate alignment of timestamps for all images and metadata, preventing data corruption caused by time drift. For lossless compression, the module uses block-based parallel compression technology, dividing large-size image data into multiple smaller blocks, which are then executed in parallel by multiple processor cores, significantly reducing compression time. The digital watermark is embedded in the compressed data block. The embedding strength is optimized to ensure the robustness of the watermark without affecting the entropy value of the image data, thus ensuring the effectiveness of lossless compression. After encapsulation, the module sends key information such as the metadata digest of the data packet, watermark information, and storage location to an internal logging subsystem for auditing and troubleshooting.

[0051] The clinical knowledge graph of the multi-dimensional tag generation module is constructed through a continuously iterative lifecycle. Initially, the knowledge graph extracts concepts and relationships from massive amounts of medical literature, authoritative textbooks, and online medical databases using automated text mining tools, followed by manual review and correction by medical experts. The node and edge structure of the graph follows Semantic Web standards, such as Web Ontology Language or Resource Description Framework, to facilitate machine understanding and reasoning. The graph also includes a confidence weighting system to evaluate the authority and reliability of each knowledge point. When new medical discoveries or clinical guidelines are published, the system automatically triggers the knowledge graph update mechanism, integrating new knowledge through a semi-automated process, followed by final confirmation by experts. During tag generation, the rule-based reasoning engine is used not only to verify the compliance of tags but also to handle ambiguities in metadata. For example, if multiple disease names appear in a clinical diagnosis, the rule-based reasoning engine combines image type, patient history, and other metadata to disambiguate using preset priority rules. Deep learning models, such as visual language models based on the Transformer architecture, enable the joint encoding of image visual features and textual diagnostic reports. This model, trained through multi-task learning, can not only identify lesions from pixels but also understand medical terminology in diagnostic reports, thus achieving more accurate label generation. For the confidence score of candidate labels, the module employs a weighted fusion model. This model comprehensively considers the prediction probability of the deep learning model, the matching degree of rule reasoning, and the authority weight of the corresponding knowledge points in the knowledge graph, ultimately outputting a comprehensive confidence score. This score not only determines whether a label is adopted but also provides doctors with a reference for the reliability of the labels.

[0052] When performing encrypted binding, the localized secure storage module first generates an encrypted hash value for the entire data packet and the structured tag set, using these two hash values ​​as fingerprints for data integrity. Then, the module uses a session key to symmetrically encrypt the data packet and tag set. The session key itself is asymmetrically encrypted using an encryption key generated from the user's biometrics and the device's unique serial number, forming an encrypted envelope. This layered encryption mechanism ensures the security of the master key; even if the session key is briefly leaked, the master key remains secure. A hardware-level encryption chip contains a true random number generator to generate highly random encryption keys, further enhancing security. The storage medium's file system employs a secure file system specifically designed for medical data, such as a HIPAA-compliant encrypted file system. This file system supports fine-grained access control and records all data access and modification operations, forming an immutable audit log. The physical write protection switch is implemented by a microcontroller monitoring the switch state and directly controlling the write enable pin of the solid-state storage medium. When write protection is enabled, the hardware will reject any write attempts made by the software. The biometric authentication module is tightly integrated with the encryption chip. After acquiring the user's biometric data, it converts it into an encrypted feature vector and compares it internally within the encryption chip, preventing the raw biometric data from being exposed in the processor or memory, thus maximizing user privacy. The status indicator system is managed by an embedded controller within the medium. By controlling the on / off state or flashing frequency of different colored LEDs, it provides intuitive operational status feedback to external users. The remaining storage space warning mechanism is based on real-time monitoring of available space using the file system. When the available space falls below a set threshold, such as 50GB, the system triggers a warning message through the terminal device's general application programming interface.

[0053] When the intelligent reading and parsing module runs on the terminal device, its biometric authentication module employs multimodal biometric fusion technology, such as comparing fingerprint and iris information. This fusion technology significantly improves the accuracy and robustness of authentication, reducing false acceptance and false rejection rates. During authentication, the user's biometric information does not leave the terminal device, and the comparison template is securely stored in an encrypted area within the medium to prevent interception. The data packet decryption process involves first using the master key generated from the user's biometrics and the device's unique serial number to decrypt the session key envelope, obtaining the session key, and then using the session key to decrypt the entire data packet. The decryption process is performed within a trusted execution environment or hardware security module of the terminal device to prevent man-in-the-middle attacks or malware from stealing the decrypted data. The DICOM PS3.10 standard parser is a highly optimized software library capable of parsing DICOM data streams in parallel and quickly building an in-memory information object model. This parser also includes an error recovery mechanism, attempting to extract as much valid information as possible even when encountering incomplete DICOM files. Reconstructing the temporal and spatial relationships of image sequences involves the precise reading and calculation of attributes such as Image Position Patient, Image Orientation Patient, Slice Thickness, and Pixel Spacing from DICOM tags to restore the accurate position and orientation of the images in three-dimensional space. The construction of the local index directory employs a strategy combining memory caching and disk persistence. Frequently used or recently accessed tag indexes reside in memory to accelerate retrieval, while the complete index directory is persistently stored in the encrypted file system of the terminal device. Visualization is achieved through graphics processing unit (GPU) acceleration technology. The rendering engine supports programmable shaders, allowing users to customize rendering parameters such as window width and window level curves, pseudo-color mapping, etc., to adapt to different diagnostic needs. Rendering results are directly output to a high-resolution medical monitor via the terminal device's display adapter, ensuring image quality.

[0054] The cross-platform interactive interface module's protocol adaptive engine is implemented based on machine learning algorithms. Upon initial system deployment, this engine scans the target hospital's network environment, collecting interface metadata, supported protocol versions, application programming interface specifications, and performance metrics from various medical information systems. This data is used to train a classification model that predicts the most suitable transmission protocol and mode for a given target system. During actual operation, when the system needs to interact with external systems, the engine performs real-time target system interface probing, such as sending protocol handshake messages, and dynamically adjusts the transmission strategy based on the response. This dynamic adaptability ensures high compatibility and interoperability in the face of diverse and evolving medical information environments. The lightweight rendering engine's implementation on mobile terminals not only utilizes tile loading and graphics processor acceleration but also integrates an intelligent prefetching algorithm. When a user pans or zooms an image, the engine predicts the area the user might view next and preloads data from portable solid-state storage media, further reducing rendering latency and providing a seamless user experience. For 4K resolution medical images, the engine employs specialized image sampling and interpolation algorithms, optimizing mobile device rendering performance while ensuring image visual quality. The stringent requirement of rendering latency not exceeding 200 milliseconds is achieved by optimizing the rendering pipeline at the software architecture level, reducing the number of data copies, and adopting efficient memory management strategies, ensuring that doctors can interact with images efficiently in mobile medical scenarios.

[0055] The offline tag update submodule employs a version control system for its dedicated partition management. Each time a physician updates image data offline, the system creates a new version record in this dedicated partition. Each version record contains not only the incremental package, timestamp, and digital signature, but also a reference to the previous version. This allows the system to build a complete version history tree, tracing back to the details of every modification even after multiple offline updates. When the media is connected to the network, the synchronization mechanism utilizes this version history tree to merge offline modifications with the main database in a conflict-minimizing manner. If a version conflict occurs, such as different modifications to the same tag during offline and online periods, the system employs an intelligent conflict resolution strategy, such as prompting the physician for manual review or automatically selecting the latest version or expert version based on preset priority rules. Digital signature generation is based on a PKI (Public Key Infrastructure) system. Each authorized physician possesses a unique digital certificate, and their private key is securely stored in the hardware security module of the terminal device. During updates, the private key is used to sign the incremental package content, ensuring the non-repudiation and security of the signing process. The incremental packet data structure is designed as a scalable binary format, capable of accommodating various types of updates, such as text annotations, structured tag modifications, and even annotations for specific pixel regions. This refined offline update mechanism greatly enhances the system's flexibility and usability, freeing medical work from network constraints and improving overall diagnostic and treatment efficiency.

Claims

1. A portable medical image full data storage and tagging system, characterized in that, include: The medical image full data encapsulation module is used to receive the raw image data stream output from the medical imaging equipment and synchronously integrate the metadata information associated with the image. The metadata information includes patient identification, examination timestamp, equipment model, scanning parameters, diagnostic physician identification and clinical diagnosis conclusion. The multidimensional tag generation module is used to automatically generate a structured tag set based on the metadata information and the preset clinical knowledge graph. The structured tag set includes anatomical location tags, pathological feature tags, image quality tags, and clinical use tags. The localized secure storage module is used to encrypt and bind the encapsulated full data packet with the corresponding structured tag set and write it to the portable solid-state storage medium. The portable solid-state storage medium adopts a hardware-level encryption chip that complies with medical data security standards and supports a dual access control mechanism of physical write protection switch and biometric authentication. The intelligent reading and parsing module is used to automatically parse the internal structure of the full data packet after authenticating the access portable solid-state storage medium on the authorized terminal device, restore the original image data and its associated metadata, and build a local index directory based on the structured tag set to achieve fast retrieval and visualization by tag dimension. The cross-platform interaction interface module provides a standardized data exchange protocol, supporting seamless integration with hospital information systems, image archiving and communication systems, and mobile diagnostic terminals, ensuring complete reading and rendering of medical image data content across different operating systems and hardware environments.

2. The portable medical image full data storage and tagging system according to claim 1, characterized in that, The medical image full data encapsulation module uses a lossless compression algorithm to encapsulate the original image data, with a compression ratio controlled within 1.5 times. At the same time, the module embeds a digital watermark during the encapsulation process. The digital watermark contains a unique identifier for the data packet and a timestamp hash value, which is used for subsequent data integrity verification.

3. The portable medical image full data storage and tagging system according to claim 1, characterized in that, The clinical knowledge graph in the multidimensional label generation module is jointly constructed from authoritative medical guidelines, imaging diagnostic standards, and historical case databases. Its nodes cover no less than 5,000 anatomical structures and 3,000 pathological manifestations. The label generation process adopts a hybrid strategy driven by rule-based reasoning and deep learning. The final label set is output after the system automatically scores the confidence level, and the confidence threshold is set to 85%.

4. The portable medical image full data storage and tagging system according to claim 1, characterized in that, The portable solid-state storage medium used in the localized secure storage module has IP68 dust and water resistance and a 1.5-meter drop-resistant structure design, with a storage capacity of no less than 512GB and a read / write speed of no less than 500MB per second. Its hardware-level encryption chip supports the national standard SM4 algorithm. The key is generated by the user's biometrics and the device's unique serial number, and the key is not stored on any external server.

5. A portable medical image full data storage and tagging system according to claim 1, characterized in that, When the intelligent reading and parsing module is running on the terminal device, it first verifies the physical write protection status of the portable solid-state storage medium. If the write protection is enabled, only reading operations are allowed. Then, it obtains the user's fingerprint or iris information through the biometric authentication module and compares it with the authorization template pre-stored in the storage medium. Only after successful comparison can the data packet be decrypted. The decrypted data packet is parsed according to the DICOM PS3.10 standard and the temporal and spatial relationships of the image sequence are automatically reconstructed.

6. A portable medical image full data storage and tagging system according to claim 1, characterized in that, The cross-platform interactive interface module supports three mainstream medical data protocols: DICOM, HL7, and FHIR. It also has a built-in protocol adaptive engine that can automatically select the optimal transmission mode based on the interface capabilities of the target system. In mobile terminal scenarios, the module uses a lightweight rendering engine to achieve smooth scaling and window width and window level adjustment of 4K resolution medical images, with a rendering latency of no more than 200 milliseconds.

7. A portable medical image full data storage and tagging system according to claim 1, characterized in that, It also includes an offline label update submodule, which allows authorized physicians to add diagnostic opinions or correct labels to stored image data in the absence of a network environment. The updated content is encrypted and written to a dedicated partition of the storage medium in the form of incremental packets, and a new timestamp and digital signature are generated to ensure that the data version is traceable.

8. A portable medical image full data storage and tagging system according to claim 4, characterized in that, The portable solid-state storage medium is equipped with a status indicator light to display the connection status, authentication status and remaining storage space of the storage medium in real time. When the remaining space is less than 10%, the system will automatically trigger an early warning and suggest that the user archive the data or replace the medium.

9. A portable medical image full data storage and tagging system according to claim 3, characterized in that, The deep learning model employs a convolutional neural network architecture to automatically identify potential pathological regions from image pixel features and generate candidate labels; the rule inference engine incorporates a set of rules defined by medical experts to ensure that the labels conform to clinical standards.

10. A portable medical image full data storage and tagging system according to claim 7, characterized in that, The incremental packets are encrypted using the SM4 algorithm, and a dedicated partition is used to independently manage offline update data. The digital signature is generated by signing the incremental packet content with the operator's digital certificate private key, which is used to verify the authenticity and integrity of the updated content and the operator's identity.