Medical examination informatization integration operation and maintenance method and system based on information security
By introducing a hardware security authentication module and physical authentication process into the medical testing information system, combined with risk assessment and biometric authentication, the problem of lack of physical security authentication for user operation permission verification was solved, thereby improving the system's security and access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-13
- Publication Date
- 2026-03-10
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing medical testing information system lacks a physical security authentication mechanism for verifying user operation permissions, resulting in lax access control. This leads to high-risk operations being executed without sufficient verification, posing risks of information leakage and data tampering.
A hardware security authentication module and physical authentication process are introduced. Real-time risk assessment is performed through a scenario risk assessment engine. Combined with software permission verification, multi-factor authentication and biometric authentication, the MOSFET switching state of the hardware switch matrix is controlled to establish a physical signal path to execute operation requests.
It effectively prevents unauthorized operations and data leaks, ensures the security of medical testing information, and enhances the rigor of access control and system security.
Smart Images

Figure CN121637528A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data management, in particular to a medical examination informationization integrated operation and maintenance method and system based on information security. BACKGROUND
[0002] In a medical examination informationization system, user operation permission verification usually relies on software-level identity authentication and role authorization. However, this approach often lacks physical security authentication mechanisms for the operation process, and is vulnerable to network attacks, identity forgery, or permission abuse. In addition, the control of user permissions is often too simple and fails to distinguish different operation risks in detail, especially when sensitive data or critical operations are involved, there is a lack of effective multi-factor authentication means. This makes it possible for high-risk operations to be performed without sufficient verification, thereby bringing the risk of information leakage, data tampering, or illegal operations. SUMMARY
[0003] The present application provides a medical examination informationization integrated operation and maintenance method and system based on information security, which is used to solve the technical problems of lack of physical security authentication mechanism and loose permission control in the user operation permission verification process of the prior art.
[0004] In view of the above problems, the present application provides a medical examination informationization integrated operation and maintenance method and system based on information security.
[0005] In a first aspect of the present application, a medical examination informationization integrated operation and maintenance method based on information security is provided, which comprises: In a medical examination main system, receiving an operation instruction of a user for an operation request, verifying the software permission of the user; when the software permission verification is passed, sending a security channel opening request corresponding to the operation request to an independent hardware security authentication module, the hardware security authentication module receives the security channel opening request and starts a physical authentication process; after the physical authentication process is passed, the hardware security authentication module controls the target MOSFET switch corresponding to the operation request in the internal switch matrix to switch from the off state to the on state, establishing a physical signal path; the execution signal corresponding to the operation request issued by the medical examination main system is transmitted to the corresponding peripheral execution device via the physical signal path, thereby executing the operation request.
[0006] In a second aspect of the present application, a medical examination informationization integrated operation and maintenance system based on information security is provided, which comprises: The check module is used for checking software permission of a user in a medical examination main system after receiving an operation instruction of the user for an operation request; the authentication module is used for sending a security channel opening request corresponding to the operation request to an independent hardware security authentication module after the software permission check passes, and the hardware security authentication module receives the security channel opening request and starts a physical authentication process; the state switching module is used for switching a target MOSFET switch corresponding to the operation request in an internal switch matrix from an off state to an on state to establish a physical signal path after the physical authentication process passes; and the execution module is used for transmitting an execution signal corresponding to the operation request from the medical examination main system to a corresponding peripheral execution device via the physical signal path, so as to execute the operation request.
[0007] The one or more technical solutions provided in the application have at least the following technical effects or advantages: The application receives an operation instruction of a user for an operation request in a medical examination main system, checks software permission of the user, sends a security channel opening request corresponding to the operation request to an independent hardware security authentication module after the software permission check passes, and the hardware security authentication module receives the security channel opening request and starts a physical authentication process; the target MOSFET switch corresponding to the operation request in the internal switch matrix is switched from the off state to the on state by the hardware security authentication module after the physical authentication process passes, to establish a physical signal path; and the execution signal corresponding to the operation request from the medical examination main system is transmitted to the corresponding peripheral execution device via the physical signal path, so as to execute the operation request. The application solves the technical problems of lacking a physical security authentication mechanism and loose permission control in the user operation permission check process in the prior art, introduces the hardware security authentication module and the physical authentication process, prevents unauthorized operation and data leakage, and ensures the security of medical examination information. BRIEF DESCRIPTION OF DRAWINGS
[0008] In order to more clearly illustrate the technical solutions in the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments description. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without any creative effort based on these drawings.
[0009] Figure 1 The medical examination informationization integrated operation and maintenance method flowchart based on information security provided by the embodiments of the application is shown in the following figure. Figure 2A medical examination informationization integrated operation and maintenance system structure schematic diagram based on information security is provided in the embodiments of the present application.
[0010] The reference signs are explained as follows: a check module 11, an authentication module 12, a state switching module 13, and an execution module 14. DETAILED DESCRIPTION
[0011] The present application provides a medical examination informationization integrated operation and maintenance method and system based on information security, aiming at solving the technical problems of lacking physical security authentication mechanism and loose permission control in the user operation permission check process of the prior art. By introducing a hardware security authentication module and a physical authentication process, unauthorized operation and data leakage are prevented, and the security of medical examination information is ensured.
[0012] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative labor fall within the protection scope of the present application.
[0013] It should be noted that any variation of the terms “comprise” and “have” is intended to cover non-exclusive inclusion, for example, a process, method, system, product or server comprising a series of steps or units does not have to be limited to those clearly listed steps or units, but can include other steps or modules that are not clearly listed or inherent to the process, method, product or device.
[0014] Embodiment one, as shown in the present application provides a medical examination informationization integrated operation and maintenance method based on information security, which comprises: Figure 1 Step S100: receiving an operation instruction of a user for an operation request in a medical examination main system, and checking the software permission of the user.
[0015] In the embodiments of the present application, after receiving the operation instruction of the user for the operation request in the medical examination main system, a scenario risk assessment engine is first called, a plurality of context factors are collected and analyzed in real time, including operation time, geographical location of user login, sample risk level of operation and historical operation behavior mode of the user. Then, the context factors are weighted calculated according to a preset risk assessment model, to generate a real-time risk score of each operation request. Finally, the real-time risk score is compared with a set risk threshold, to complete the check of the software permission of the user.
[0016] Further, the method provided by the application embodiment further comprises the following steps of: After the medical examination main system receives the operation instruction of the user, the scenario risk assessment engine is called to collect and analyze a plurality of context factors in real time, the plurality of context factors at least including operation time, user login geographic location, sample risk level operated, and user historical operation behavior mode; according to a preset risk assessment model, the plurality of context factors are weighted and calculated to generate a real-time risk score of the operation request; the real-time risk score is compared with a preset risk threshold to complete software permission verification.
[0017] In the application embodiment, when a user submits an operation request in the medical examination main system, the operation instruction of the user is first received and parsed. The operation instruction contains specific tasks that the user wants to perform, such as data query or medical examination operation. Then the scenario risk assessment engine is called to collect and analyze a plurality of context factors in real time. Among them, the scenario risk assessment engine obtains a plurality of context factors including operation time, user login geographic location, sample risk level operated, and user historical operation behavior mode by collecting data from system logs, user sessions, examination item databases and other data sources in real time.
[0018] Then, according to a preset risk assessment model, the plurality of context factors are weighted and calculated. Among them, the risk assessment model is an evaluation model obtained by training a large number of historical security events and normal operation data through a machine learning algorithm. By inputting the plurality of context factors into the risk assessment model for processing, a real-time risk score of the operation request is obtained.
[0019] Finally, the real-time risk score is compared with a preset risk threshold. If the real-time risk score is lower than a first threshold, it is determined as a low-risk scenario, and the software permission verification is directly passed. If the real-time risk score is between the first threshold and a second threshold, it is determined as a medium-risk scenario, and a strengthened authentication process is triggered to complete a multi-factor authentication of the user on the medical examination main system interface. If the real-time risk score is higher than the second threshold, it is determined as a high-risk scenario, and the operation request is rejected, and a security event log is generated and reported. Through the process, the software permission verification is completed.
[0020] Further, the method provided by the application embodiment further comprises the following steps of: If the real-time risk score is lower than a first threshold value, a low-risk scenario is determined, and a software permission check is directly passed; if the real-time risk score is between the first threshold value and a second threshold value, a medium-risk scenario is determined, and a strengthened authentication process is triggered, and the user completes a multi-factor authentication on a medical examination main system interface; if the real-time risk score is higher than the second threshold value, a high-risk scenario is determined, and the operation request is rejected, and a security event log is generated and reported.
[0021] In the embodiments of the present application, when the real-time risk score is lower than a first threshold value, a low-risk scenario is determined, and a software permission check is directly passed. The first threshold value is a preset score threshold value.
[0022] If the real-time risk score is between the first threshold value and a second threshold value, a medium-risk scenario is determined, and a strengthened authentication process is triggered, and the user completes a multi-factor authentication on a medical examination main system interface. The second threshold value is also a preset score threshold value and is greater than the first threshold value. In the strengthened authentication process, the medical examination main system generates a time-sensitive current operation session ID and a random cryptographic challenge code, and sends them to the hardware security authentication module for temporary storage. Then, an encrypted two-dimensional code is displayed to the user, which includes the session ID, a specific URL, and an instruction to start the hardware security authentication module authentication process. The user scans and analyzes the two-dimensional code through the authentication APP in the pre-bound mobile intelligent device, establishes a secure connection with the medical examination main system through the obtained URL, and uploads the session ID to request the cryptographic challenge code. Then, the user is prompted to input a personal identification code on the physical interaction device of the hardware security authentication module, and after verification, the module transmits the cryptographic challenge code to the mobile device through near field communication. The authentication APP calls the security element in the device, uses the user's private key to digitally sign the cryptographic challenge code, and transmits it back to the medical examination main system through the secure connection. The medical examination main system verifies the digital signature using the corresponding user public key, and after verification, determines that the strengthened authentication is successful, completes the software permission check, and notifies the hardware security authentication module of the verification result and clears the temporarily stored session ID and cryptographic challenge code.
[0023] When the real-time risk score is higher than the second threshold value, it indicates that multiple context factors deviate seriously from the normal mode, and the potential security threat is extremely high, so a high-risk scenario is determined, the operation request is rejected, and a security event log is generated and reported. The security event log includes all context factors that lead to the high-risk determination, the specific value of the real-time risk score, and the detailed information of the operation request.
[0024] Further, in the method provided by the embodiments of the present application, triggering the strengthened authentication process and completing the multi-factor authentication of the user on the medical examination main system interface further includes: The medical examination main system generates a time-sensitive operation session ID, and sends it to the hardware security authentication module together with a randomly generated cryptographic challenge code for temporary storage; an encrypted two-dimensional code is displayed to the user, which contains the session ID, URL, and an instruction for starting the authentication process on the hardware security authentication module; the user uses the authentication APP in the pre-bound mobile smart device to scan and parse the two-dimensional code, establishes a secure connection with the medical examination main system through the URL, and uploads the session ID to obtain the cryptographic challenge code, instructing the user to input a personal identification code on the physical interaction device of the hardware security authentication module to authorize the hardware security authentication module to release the challenge code; after verifying the user's personal identification code, the hardware security authentication module transmits the temporarily stored cryptographic challenge code to the mobile smart device through near field communication; the authentication APP uses the secure element in the device to digitally sign the cryptographic challenge code using the user's private key and returns it to the medical examination main system through the secure connection; the medical examination main system verifies the digital signature using the corresponding user public key, and if the verification is successful, determines that the enhanced authentication is successful, the software permission verification is passed, and notifies the hardware security authentication module of the verification result, and clears the temporarily stored session ID and cryptographic challenge code.
[0025] In the embodiments of the present application, after triggering the enhanced authentication process, the medical examination main system first generates a strictly time-sensitive operation session ID, which serves as a unique logical identifier for this authentication process, ensuring the independence of the authentication process and the ability to prevent replay attacks. At the same time, a random cryptographic challenge code is generated, which is a one-time use cryptographic random number used to verify the authenticity and response ability of the user end during the authentication process. The medical examination main system sends this session ID and cryptographic challenge code to the hardware security authentication module for secure temporary storage.
[0026] The medical examination main system then displays an encrypted two-dimensional code to the user. The encrypted two-dimensional code encodes the generated session ID, a specific URL pointing to the medical examination main system authentication interface, and an instruction for triggering the hardware security authentication module to start its physical authentication process. The user needs to use the authentication APP installed in the mobile smart device that has completed the pre-binding operation to scan this two-dimensional code. The authentication APP parses the encrypted two-dimensional code, extracts the URL, and establishes an end-to-end encrypted secure connection with the medical examination main system through the URL. Then, the authentication APP uploads the parsed session ID to the medical examination main system to request the corresponding cryptographic challenge code temporarily stored in the hardware security authentication module.
[0027] At this time, the user is instructed to enter his personal identification code on the physical interaction device of the hardware security authentication module. The personal identification code is a second factor credential that the user has previously set for locally authorizing the operation of the hardware device. After the hardware security authentication module independently verifies that the user-entered personal identification code is correct, it performs a release operation to transmit the previously temporarily stored cryptographic challenge code to the user's mobile smart device through near field communication technology.
[0028] After the authentication APP on the mobile smart device receives the cryptographic challenge code, it calls the security element integrated in the device. The security element is a hardware-protected independent security area for performing sensitive cryptographic operations. The authentication APP instructs the security element to perform a digital signature operation on the cryptographic challenge code using the user private key stored therein to generate a unique digital signature. The digital signature is returned to the medical examination host system through the established secure connection.
[0029] After the medical examination host system receives the digital signature, it uses the user public key corresponding to the user private key to perform cryptographic verification on the digital signature. The verification process confirms that the signature is indeed generated by the private key of the legitimate user and is correct for the cryptographic challenge code of this session. After the verification is passed, the medical examination host system determines that the enhanced authentication of this time is successful, indicating that the software permission check of the user is finally passed. The verification result is then notified to the hardware security authentication module, and a cleaning operation is performed to clear the temporarily stored operation session ID and cryptographic challenge code in the hardware security authentication module, ensuring the one-time validity of the authentication information.
[0030] Step S200: After the software permission check is passed, a security channel opening request corresponding to the operation request is sent to the independent hardware security authentication module, and the hardware security authentication module receives the security channel opening request and starts a physical authentication process.
[0031] In the embodiments of the present application, after the software permission check is passed, the medical examination host system sends a security channel opening request corresponding to the operation request to the independent hardware security authentication module. After the hardware security authentication module receives the security channel opening request, it extracts the operation type code by analyzing the request, queries the built-in permission mapping table to determine the allowed physical authentication method, and then only enables the corresponding sensor to collect user biometric information, and compares the collected information with the pre-stored security certificate, generates an authentication pass signal or returns authentication failure information according to the comparison result and records a log.
[0032] Further, in the method provided by the embodiments of the present application, the hardware security authentication module receives the security channel opening request and starts a physical authentication process, and further includes: The hardware security authentication module receives and parses the security channel opening request, extracts the operation type code; queries the built-in permission mapping table to determine one or more physical authentication modes allowed by the operation type code, only enables the sensors corresponding to the determined physical authentication modes, waits for user input, and collects user biometric information; compares the user biometric information with the pre-stored security certificate, if the comparison is successful, an authentication pass signal is generated; if the comparison fails, an authentication failure information is returned to the medical examination main system, and a failure log is recorded.
[0033] In the embodiment of the application, after receiving the security channel opening request sent by the medical examination main system, the hardware security authentication module first parses the security channel opening request and extracts the operation type code contained therein. The operation type code is a digital code uniquely identifying a specific operation category. Subsequently, the hardware security authentication module queries the permission mapping table stored in it, which is a security policy database defining the correspondence between different operation type codes and allowed physical authentication modes. According to the query result, one or more physical authentication modes allowed by the current operation type code are determined.
[0034] Next, based on the determined physical authentication mode, the hardware security authentication module starts the corresponding biometric feature collection process. In this process, only the specific sensors corresponding to the selected authentication mode are enabled, such as fingerprint identification module, iris scanner or voiceprint collector, etc., while other sensors are kept in the off state to implement the principle of least privilege. Then it enters a waiting state, ready to collect the user's biometric information.
[0035] When the user provides the required biometric information, the hardware security authentication module compares the real-time collected user biometric information with the security certificate pre-stored in the security storage area. The security certificate is a legal user biometric template stored by encryption. If the collected biometric information matches the template stored in the security certificate successfully, the hardware security authentication module generates an authentication pass signal, indicating that the user's identity has passed the physical layer verification. If the comparison fails, the hardware security authentication module returns an authentication failure information to the medical examination main system, and records a failure log in the local security log, including time stamp and failure reason and other key information.
[0036] Step S300: After the physical authentication process is passed, the hardware security authentication module controls the target MOSFET switch corresponding to the operation request in the internal switch matrix to switch from the off state to the on state, establishing a physical signal path.
[0037] Further, the method provided by the application embodiment further comprises: The switch matrix includes a plurality of independent safety channels composed of a plurality of MOSFET switches, and each safety channel is connected in series to an enable signal line of a peripheral execution device.
[0038] In the embodiment of the present application, after the physical authentication process is passed, the hardware security authentication module starts the process of establishing the physical signal path. In this process, the microcontroller of the hardware security authentication module first generates a corresponding digital control signal according to the safety channel opening request, which contains the identification information of the target channel. Then, the digital-to-analog converter converts this digital control signal into an analog control voltage with a preset voltage value. Then the analog control voltage is applied to the gate pin of the target MOSFET switch in the switch matrix. The MOSFET switch, as a voltage-controlled semiconductor device, forms a conductive channel between its source and drain after obtaining sufficient voltage at the gate, realizing the switching from the off state to the on state, and establishing the physical signal path connecting the medical test main system and the peripheral execution device through this process.
[0039] Among them, the switch matrix as a key hardware component is composed of a plurality of metal oxide semiconductor field effect transistors to form a plurality of independent safety channels. Each safety channel corresponds to an independent MOSFET switch and is connected in a physical series manner to the enable signal line of a specific peripheral execution device. The enable signal line is a key control line that controls the start or stop of the peripheral execution device. In the default safety state, all MOSFET switches remain in the off state, and the enable signal line is in an electrically isolated state; when the target MOSFET switch is turned on, the corresponding safety channel establishes a complete electrical connection, and the enable signal is transmitted to the target peripheral execution device, thereby realizing the final execution of the operation.
[0040] Further, in the method provided by the application embodiment, the hardware security authentication module controls the target MOSFET switch corresponding to the operation request in the internal switch matrix to switch from the off state to the on state to establish the physical signal path, and further comprises: The microcontroller of the hardware security authentication module generates a corresponding digital control signal according to the safety channel opening request; converts the digital control signal into an analog control voltage with a preset voltage value through a digital-to-analog converter; applies the analog control voltage to the gate of the target MOSFET in the switch matrix, so that a conductive channel is formed between the source and drain of the target MOSFET, and the physical signal path is established.
[0041] In the embodiment of the present application, after the physical authentication process is passed, the microcontroller of the hardware security authentication module starts to perform the physical signal path establishment. First, the microcontroller parses the received security channel opening request to extract the operation parameters and device identification information therein. According to the parsing result, the microcontroller generates a corresponding digital control signal, which is in the form of binary coding and contains a target channel address and specific control instructions.
[0042] Subsequently, the digital control signal is transmitted to the digital-to-analog converter through the data bus. The digital-to-analog converter converts the received digital control signal into an analog control voltage with a precise voltage value. During the conversion process, the digital-to-analog converter outputs a corresponding voltage value according to the numerical value of the digital signal through an internal precision resistance network, ensuring that the generated analog control voltage meets the driving requirements of the MOSFET.
[0043] Then, the analog control voltage is transmitted to the gate of the target MOSFET in the switch matrix through the wire. MOSFET is a voltage-controlled semiconductor device, and when the gate receives sufficient analog control voltage, a conductive channel connecting the source and drain will be formed inside. The formation of the conductive channel causes the MOSFET to switch from the off state to the on state, establishing a low-impedance electrical path between the source and drain. This on state establishes a complete physical signal path at the physical layer, allowing the control signal to be transmitted to the corresponding peripheral execution device through this path.
[0044] Further, the method provided by the embodiment of the application further comprises: According to the operation request, the target logical device identifier of the target peripheral execution device required for operation execution is obtained; the hardware security authentication module pre-stores a device-channel mapping table, and the device-channel mapping table stores each logical device identifier and a corresponding unique MOSFET switch channel ID; by querying the device-channel mapping table, the target channel ID corresponding to the target logical device identifier is matched to determine the target MOSFET.
[0045] In the embodiment of the present application, the hardware security authentication module first obtains the target logical device identifier of the target peripheral execution device required for operation according to the operation request. The target logical device identifier is a digital code uniquely identifying a specific peripheral execution device, which is obtained by parsing the data packet content in the operation request.
[0046] The hardware security authentication module internally pre-stores a device-channel mapping table, which is a database storing the association relationship between each logical device identifier and the corresponding MOSFET switch channel ID. Each logical device identifier corresponds to a unique MOSFET switch channel ID in the device-channel mapping table, and the one-to-one correspondence relationship ensures that each peripheral execution device has an independent control channel.
[0047] The target logical device identifier is matched with the record in the mapping table by querying the device-channel mapping table. The query process adopts a sequential search or hash search algorithm to quickly locate the record item containing the target logical device identifier in the device-channel mapping table. The corresponding MOSFET switch channel ID is extracted from the matched record, and the channel ID is the target channel ID.
[0048] Finally, according to the obtained target channel ID, the target MOSFET to be controlled is determined. The target MOSFET is a specific metal oxide semiconductor field effect transistor device in the switch matrix corresponding to the target channel ID, and its physical position is uniquely determined by the arrangement rule of the channel ID in the switch matrix.
[0049] Further, in the method provided by the application embodiment, after determining the target MOSFET, the method further includes: According to the target channel ID, it is checked whether the corresponding channel is currently occupied by other operations. If it is not occupied, an instruction is sent to the switch matrix through the hardware security authentication module to physically disconnect all redundant MOSFET switches connected to the target peripheral execution device, and then turn on the target MOSFET switch and turn it off after the operation request is executed. If it is occupied, a channel occupation state signal is returned to the medical examination main system, the operation instruction flow of the user is suspended, and an occupation prompt information is popped up on the user interface.
[0050] In the application embodiment, the hardware security authentication module first checks whether the corresponding channel is currently occupied by other operations according to the obtained target channel ID. The checking process is completed by querying the channel state record table in the module. The table records the occupation status of each MOSFET switch channel in real time. By reading the state information corresponding to the target channel ID, if the state shows that it is not occupied, the channel activation process is entered.
[0051] If the channel is unoccupied, the hardware security authentication module immediately sends a control command to the switch matrix. This control command first performs a physical disconnection operation by disconnecting all redundant MOSFET switches connected to the target peripheral execution device, ensuring that at any given time, only one controlled physical path is active for that device. This step is achieved by applying a turn-off voltage to the gate of the redundant MOSFET switches, putting them in the off state. Subsequently, a turn-on command is sent to the target MOSFET switch, outputting a preset analog control voltage to the gate of the target MOSFET switch via a digital-to-analog converter, establishing a dedicated physical signal path. During the operation request execution, the hardware security authentication module continuously monitors the channel status. Once the operation request is completed, the target MOSFET switch is automatically disconnected, its gate voltage is adjusted to the turn-off value, the conductive channel disappears, the channel is restored to its unoccupied state, and the corresponding status information in the channel status log is updated.
[0052] If the check reveals that the target channel is already occupied, the hardware security authentication module immediately returns a channel occupancy status signal to the main medical testing system. This signal includes the ID information of the occupied channel and the estimated release time. Upon receiving this signal, the main medical testing system pauses the current user's operation command flow and displays an occupancy notification on the user interface. The notification includes the name of the occupied device, the estimated waiting time, and suggested operating procedures, guiding the user to select another available device or wait for the current operation to complete.
[0053] Step S400: The execution signal corresponding to the operation request issued by the main medical testing system is transmitted to the corresponding peripheral execution device via the physical signal path, thereby executing the operation request.
[0054] In this embodiment, the medical testing main system generates an execution signal corresponding to the operation request. This execution signal is transmitted through an established physical signal path. This physical signal path consists of a conductive channel formed by a target MOSFET switch in a conducting state. The execution signal enters from the source of the MOSFET, exits from the drain through the conductive channel, and is finally transmitted to the corresponding peripheral execution device to drive the device to complete the requested specific operation.
[0055] In summary, the embodiments of this application have at least the following technical effects: This application receives user operation commands for operation requests in a medical testing main system and verifies the user's software permissions. Once the software permission verification is successful, a security channel opening request corresponding to the operation request is sent to an independent hardware security authentication module. The hardware security authentication module receives the security channel opening request and initiates a physical authentication process. After the physical authentication process is successful, the hardware security authentication module controls the target MOSFET switch corresponding to the operation request in the internal switch matrix to switch from an off state to an on state, establishing a physical signal path. The execution signal issued by the medical testing main system corresponding to the operation request is transmitted to the corresponding peripheral execution device via the physical signal path, thereby executing the operation request. This invention solves the technical problems of the lack of a physical security authentication mechanism and lax permission control in the user operation permission verification process of existing technologies. By introducing a hardware security authentication module and a physical authentication process, it achieves the technical effect of preventing unauthorized operations and data leakage, ensuring the security of medical testing information.
[0056] Example 2, based on the same inventive concept as the information security-based integrated operation and maintenance method for medical testing, as described in the previous examples, such as... Figure 2 As shown, this application provides an integrated operation and maintenance system for medical testing information systems based on information security. The system and method embodiments in this application are based on the same inventive concept. The system includes: Verification module 11 is used to receive operation instructions from users regarding operation requests in the main medical testing system and verify the user's software permissions; authentication module 12 is used to send a security channel opening request corresponding to the operation request to an independent hardware security authentication module after the software permission verification is passed. The hardware security authentication module receives the security channel opening request and initiates a physical authentication process; state switching module 13 is used to control the target MOSFET switch corresponding to the operation request in the internal switch matrix to switch from the off state to the on state after the physical authentication process is passed, thereby establishing a physical signal path; execution module 14 is used to transmit the execution signal corresponding to the operation request issued by the main medical testing system to the corresponding peripheral execution device via the physical signal path, thereby executing the operation request.
[0057] Furthermore, the system is also used to implement the following functions: The switch matrix includes multiple independent safety channels composed of multiple MOSFET switches, each safety channel being connected in series with the enable signal line of a peripheral actuator.
[0058] Furthermore, the system is also used to implement the following functions: The medical examination main system receives the operation instruction of the user, calls a scene risk assessment engine, collects and analyzes a plurality of context factors in real time, the plurality of context factors at least including operation time, user login geographic location, sample risk level operated and user historical operation behavior mode; according to a preset risk assessment model, the plurality of context factors are weighted and calculated to generate a real-time risk score of the operation request; the real-time risk score is compared with a preset risk threshold to complete software permission verification.
[0059] Further, the system is also used to realize the following functions: If the real-time risk score is lower than a first threshold, it is determined as a low-risk scene, and the software permission verification is directly passed; if the real-time risk score is between the first threshold and a second threshold, it is determined as a medium-risk scene, and a strengthened authentication process is triggered to complete a multi-factor authentication of the user on the medical examination main system interface; if the real-time risk score is higher than the second threshold, it is determined as a high-risk scene, the operation request is rejected, and a security event log is generated and reported.
[0060] Further, the system is also used to realize the following functions: A time-sensitive current operation session ID is generated by the medical examination main system, and a randomly generated cryptographic challenge code is sent to the hardware security authentication module for temporary storage; an encrypted two-dimensional code is displayed to the user, the two-dimensional code including the session ID, a URL and an instruction for starting the authentication process on the hardware security authentication module; the user uses the authentication APP in the pre-bound mobile smart device to scan and parse the two-dimensional code, establishes a secure connection with the medical examination main system through the URL, uploads the session ID to obtain the cryptographic challenge code, and instructs the user to input a personal identification code on the physical interaction device of the hardware security authentication module to authorize the hardware security authentication module to release the challenge code; the hardware security authentication module verifies the user's personal identification code, and then transmits the temporarily stored cryptographic challenge code to the mobile smart device through near field communication; the authentication APP uses the security element in the device to digitally sign the cryptographic challenge code using the user's private key and returns it to the medical examination main system through the secure connection; the medical examination main system verifies the digital signature using the corresponding user public key, and after verification, determines that the strengthened authentication is successful, the software permission verification is passed, and the verification result is notified to the hardware security authentication module to clear the temporarily stored session ID and cryptographic challenge code.
[0061] Further, the system is also used to realize the following functions: The hardware security authentication module receives and parses the secure channel opening request, extracts the operation type code, queries the built-in permission mapping table to determine one or more physical authentication methods allowed by the operation type code, activates only the sensors corresponding to the determined physical authentication methods, waits for user input, and collects user biometric information; compares the user biometric information with the pre-stored security certificate, and if the comparison is successful, generates an authentication pass signal; if the comparison fails, returns authentication failure information to the medical testing main system and records the failure log.
[0062] Furthermore, the system is also used to implement the following functions: The microcontroller of the hardware security authentication module generates a corresponding digital control signal according to the security channel opening request; converts the digital control signal into an analog control voltage with a preset voltage value through a digital-to-analog converter; and applies the analog control voltage to the gate of the target MOSFET in the switching matrix, so that a conductive channel is formed between the source and drain of the target MOSFET, thus establishing the physical signal path.
[0063] Furthermore, the system is also used to implement the following functions: The target logic device identifier of the target peripheral execution device required for operation execution is obtained according to the operation request; the hardware security authentication module has a pre-stored device-channel mapping table, which stores each logic device identifier and its corresponding unique MOSFET switch channel ID; by querying the device-channel mapping table, the target channel ID corresponding to the target logic device identifier is matched to determine the target MOSFET.
[0064] Furthermore, the system is also used to implement the following functions: Based on the target channel ID, check whether the corresponding channel is currently occupied by other operations; if it is not occupied, send an instruction to the switch matrix through the hardware security authentication module to physically disconnect all redundant MOSFET switches connected to the target peripheral execution device, and then turn on the target MOSFET switch. Disconnect after the operation request is completed; if it is occupied, return a channel occupancy status signal to the medical testing main system, suspend the user's operation instruction flow, and display an occupancy prompt message on the user interface.
[0065] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.
[0066] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A medical examination information integration operation and maintenance method based on information security, characterized in that, The method comprises the following steps: In a medical examination main system, an operation instruction of a user for an operation request is received, and software permission of the user is checked; When the software permission check is passed, a security channel opening request corresponding to the operation request is sent to an independent hardware security authentication module, the hardware security authentication module receives the security channel opening request, and starts a physical authentication process; After the physical authentication process is passed, the hardware security authentication module controls a target MOSFET switch corresponding to the operation request in an internal switch matrix to switch from an off state to an on state, and establishes a physical signal path; An execution signal corresponding to the operation request sent by the medical examination main system is transmitted to a corresponding peripheral execution device via the physical signal path, so that the operation request is executed.
2. The information security-based medical examination informationization integrated operation and maintenance method according to claim 1, wherein the switch matrix comprises a plurality of independent security channels composed of a plurality of MOSFET switches, and each security channel is connected in series on an enable signal line of a peripheral execution device. 3.The information security based medical examination informationization integrated operation and maintenance method according to claim 1, characterized in that, In a medical examination main system, an operation instruction of a user for an operation request is received, and software permission of the user is checked, comprising: After the medical examination main system receives the operation instruction of the user, a scene risk assessment engine is called, a plurality of context factors are collected and analyzed in real time, and the plurality of context factors at least include operation time, user login geographic location, sample risk level operated, and user historical operation behavior mode; According to a preset risk assessment model, the plurality of context factors are weighted and calculated to generate a real-time risk score of the operation request; The real-time risk score is compared with a preset risk threshold to complete software permission check.
4. The information security-based medical examination information integration operation and maintenance method of claim 3, wherein, The real-time risk score is compared with a preset risk threshold to complete software permission check, comprising: If the real-time risk score is lower than a first threshold, it is determined as a low-risk scene, and the software permission check is directly passed; If the real-time risk score is between the first threshold and a second threshold, it is determined as a medium-risk scene, and a strengthened authentication process is triggered, and a multi-factor authentication of the user on a medical examination main system interface is completed once; If the real-time risk score is higher than the second threshold, it is determined as a high-risk scene, the operation request is rejected, and a security event log is generated and reported.
5. The information security-based medical examination information integration operation and maintenance method of claim 4, wherein, The strengthened authentication process is triggered, and the multi-factor authentication of the user on the medical examination main system interface is completed once, comprising: A time-limited operation session ID is generated by the medical examination main system, and a randomly generated cryptographic challenge code is sent to the hardware security authentication module for temporary storage; An encrypted two-dimensional code is displayed to the user, the two-dimensional code includes the session ID, a URL, and an instruction for starting an authentication process on the hardware security authentication module; An encrypted two-dimensional code is displayed to the user, the two-dimensional code includes the session ID, a URL, and an instruction for starting an authentication process on the hardware security authentication module; The user scans and parses the two-dimensional code using an authentication APP in a pre-bound mobile smart device, establishes a secure connection with the medical test main system through the URL, and uploads the session ID to obtain the cryptographic challenge code, instructs the user to input a personal identification code on a physical interaction device of the hardware security authentication module to authorize the hardware security authentication module to release the challenge code; The hardware security authentication module transmits the temporarily stored cryptographic challenge code to the mobile smart device through near field communication after verifying the user's personal identification code; The authentication APP uses the security element in the device to digitally sign the cryptographic challenge code using the user's private key and returns it to the medical test main system through the secure connection; The medical test main system verifies the digital signature using the corresponding user public key, and if the verification is successful, determines that the enhanced authentication is successful, the software permission verification is passed, and notifies the hardware security authentication module of the verification result, and clears the temporarily stored session ID and cryptographic challenge code.
6. The information security-based medical examination information integration operation and maintenance method of claim 1, wherein, The hardware security authentication module receives the secure channel opening request and starts the physical authentication process, including: The hardware security authentication module receives and parses the secure channel opening request and extracts the operation type code; Query the built-in permission mapping table to determine one or more physical authentication methods allowed by the operation type code, only enable the sensors corresponding to the determined physical authentication methods, wait for user input, and collect user biometric information; Compare the user biometric information with the pre-stored security certificate. If the comparison is successful, an authentication success signal is generated. If the comparison fails, an authentication failure information is returned to the medical test main system, and a failure log is recorded.
7. The information security-based medical examination information integration operation and maintenance method of claim 1, wherein, The hardware security authentication module controls the target MOSFET switch corresponding to the operation request in the internal switch matrix to switch from the off state to the on state to establish a physical signal path, including: The microcontroller of the hardware security authentication module generates a corresponding digital control signal according to the secure channel opening request; Convert the digital control signal to an analog control voltage of a preset voltage value through a digital-to-analog converter; Apply the analog control voltage to the gate of the target MOSFET in the switch matrix to form a conductive channel between the source and drain of the target MOSFET, and establish the physical signal path.
8. The information security-based medical examination information integration operation and maintenance method of claim 7, wherein, The determination step of the target MOSFET includes: Obtain the target logical device identifier of the target peripheral execution device required for operation execution according to the operation request; The device-channel mapping table is pre-stored in the hardware security authentication module, and the device-channel mapping table stores each logical device identifier and the corresponding unique MOSFET switch channel ID; Determine the target MOSFET by querying the device-channel mapping table and matching the target channel ID corresponding to the target logical device identifier.
9. The information security-based medical examination information integration operation and maintenance method of claim 8, wherein, After determining the target MOSFET, it further includes: According to the target channel ID, check whether the corresponding channel is currently occupied by other operations; If not occupied, send instruction to switch matrix through the hardware security authentication module, physically disconnect all redundant MOSFET switches connected with the target peripheral execution device, and turn on the target MOSFET switch again, and turn off the target MOSFET switch after the operation request is executed; If occupied, return a channel occupation state signal to the medical examination main system, suspend the operation instruction flow of the user, and pop up an occupation prompt information on the user interface.
10. The medical examination information integration operation and maintenance system based on information security, characterized in that, The system is used for executing the information security-based medical examination informationization integrated operation and maintenance method as claimed in any one of claims 1-9, and the system comprises: A verification module, configured to receive an operation instruction of an operation request of a user in a medical examination main system, and verify a software permission of the user; An authentication module, configured to send a security channel opening request corresponding to the operation request to an independent hardware security authentication module after the software permission verification passes; A state switching module, configured to switch a target MOSFET switch corresponding to the operation request in an internal switch matrix from an off state to an on state by the hardware security authentication module after the physical authentication process passes, and establish a physical signal path; An execution module, configured to transmit an execution signal corresponding to the operation request issued by the medical examination main system to a corresponding peripheral execution device through the physical signal path, so as to execute the operation request.