Homomorphic encryption cross-border compliance medical data sharing privacy protection system and method

By using a homomorphic encryption cross-border compliant medical data sharing system, dynamic trust assessment and data sensitivity classification of the sharing parties can be achieved, thus solving privacy and compliance risks in cross-border medical data sharing and ensuring data transmission security and compliance.

CN121644247APending Publication Date: 2026-03-10LINGSHU TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-05
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Cross-border medical data sharing faces issues such as data privacy leaks, high compliance risks, and a lack of trust. Existing systems struggle to accurately screen trusted sharing partners, implement differentiated encryption, and conduct end-to-end security monitoring.

Method used

By using a homomorphic encrypted cross-border compliant medical data sharing system, including qualification information acquisition, shared trust value calculation, data classification encryption, and security feature assessment, a dynamic trust assessment model is constructed to achieve accurate screening of sharing parties and classification of sensitive data categories, and secure transmission on the blockchain.

Benefits of technology

Accurately select trusted sharing partners to enhance the security of cross-border data sharing, protect privacy, balance data usage efficiency, ensure compliant and controllable data transmission, and reduce the risk of data loss, tampering, and leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644247A_ABST
    Figure CN121644247A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of medical data sharing privacy protection, in particular to a homomorphic encryption cross-border compliance medical data sharing privacy protection system and method. The method comprises the following steps: calculating a sharing credible value of a sharing party based on a historical global trust value and an updated global trust value; judging whether the sharing party meets the cross-border compliance medical data sharing requirement or not based on the sharing credible value of the sharing party, if yes, receiving the cross-border compliance medical data sharing request of the sharing party, configuring homomorphic encryption algorithm types for data of different sensitive categories, and completing data encryption; and performing sharing transmission on the cross-border compliance medical data after data encryption on a sharing platform. The problems of privacy disclosure, high compliance risk, trust missing and the like confronted by current cross-border medical data sharing can be solved, and safe, compliance and efficient circulation of cross-border medical data is promoted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of medical data sharing privacy protection technology, specifically to a homomorphic encrypted cross-border compliant medical data sharing privacy protection system and method. Background Technology

[0002] Cross-border medical data encompasses diverse information such as patient medical records, medical imaging data, and gene testing data. Its cross-regional circulation can promote the complementarity of high-quality medical resources, accelerate the process of new drug research and development, and realize joint diagnosis and treatment of difficult and complex diseases, which is of great significance to the development of global medical and health undertakings.

[0003] However, cross-border medical data sharing faces multiple severe challenges, seriously restricting its security, compliance, and efficiency. On the one hand, medical data contains a large amount of sensitive personal information, involving patient privacy. If leaked, tampered with, or misused during the sharing process, it will cause significant damage to patients' legitimate rights and interests. Existing cross-border compliant medical data sharing privacy protection systems suffer from low data protection security. On the other hand, existing cross-border medical data sharing mechanisms have significant shortcomings in trust assessment and security protection. Traditional trust assessments of sharing parties often rely on single-dimensional qualification verification or short-term interaction data, failing to comprehensively consider the sharing party's historical behavior and real-time dynamic changes. This results in biased and delayed trust assessments, making it difficult to accurately screen trustworthy sharing objects and posing data security risks due to malicious sharing party access. Furthermore, the lack of a comprehensive assessment mechanism for storage and transmission security during data transmission makes it difficult to monitor data transmission status in real time and effectively avoid security risks such as data loss and tampering during transmission.

[0004] Therefore, there is an urgent need for a homomorphic encrypted cross-border compliant medical data sharing privacy protection system and method to solve the above problems. Summary of the Invention

[0005] The purpose of this invention is to provide a homomorphic encrypted cross-border compliant medical data sharing privacy protection system and method: aiming to solve the problems of privacy leakage, high compliance risks and lack of trust currently faced in cross-border medical data sharing.

[0006] The objective of this invention can be achieved through the following technical solutions:

[0007] On the one hand, a homomorphic encrypted cross-border compliant medical data sharing privacy protection system, the system includes:

[0008] The qualification information acquisition unit is used to acquire the sharing qualification information of cross-border compliant medical data sharing parties. The sharing qualification information includes historical sharing qualification information and current sharing qualification information.

[0009] The shared trust value calculation unit is used to calculate the historical global trust value of the sharing party based on historical shared qualification information, calculate the updated global trust value of the sharing party based on the current shared qualification information, and calculate the shared trust value of the sharing party based on the historical global trust value and the updated global trust value.

[0010] The data sharing management unit is used to determine whether a sharing party meets the requirements for cross-border compliant medical data sharing based on the sharing trust value of the sharing party. If so, the sharing party's cross-border compliant medical data sharing request is accepted; otherwise, the sharing party's cross-border compliant medical data sharing request is not accepted.

[0011] The homomorphic encryption unit is used to respond to cross-border compliant medical data sharing requests and classify the cross-border compliant medical data of the sharing party to obtain the sensitive categories corresponding to the cross-border compliant medical data of the sharing party. The homomorphic encryption algorithm type is configured for different sensitive categories of data to complete data encryption.

[0012] The data sharing and transmission unit is used to share and transmit encrypted cross-border compliant medical data on the blockchain: it calculates the storage security feature value and transmission security feature value corresponding to the encrypted cross-border compliant medical data, determines whether the encrypted cross-border compliant medical data meets the sharing and transmission requirements based on the storage security feature value and transmission security feature value, and shares and transmits cross-border compliant medical data that meets the sharing and transmission requirements.

[0013] Furthermore, the calculation of the historical global trust value of the sharing party based on historical shared qualification information specifically includes the following process:

[0014] Set a historical sharing period, dividing the historical sharing period into G historical time periods, with each historical time period containing one historical sharing qualification information;

[0015] Historical sharing qualification information includes the sharing qualification information of the first historical period, the sharing qualification information of the second historical period, and so on up to the Gth historical period; among them, the sharing qualification information of the historical period includes the qualification compliance rate, the active sharing interaction rate, and the cross-border medical data sharing project approval success rate. The qualification compliance rate is the ratio between the number of valid qualification documents uploaded in the historical period and the minimum number of qualification documents required. The active sharing interaction rate is the ratio between the number of active sharing interactions and the number of negative sharing interactions. The cross-border medical data sharing project approval success rate is the proportion of cross-border medical data sharing projects that have been approved by regulatory agencies.

[0016] The local trust value for the first historical period is obtained by adding the qualification compliance rate, the active sharing and interaction rate, and the approval success rate of cross-border medical data sharing projects in the first historical period. The local trust value for the second historical period is obtained sequentially, until the local trust value for the Gth historical period is obtained.

[0017] Calculate the local trust value in the first historical period, the local trust value in the second historical period, and the average of the local trust values ​​up to the Gth historical period. Record the average value as the historical global trust value of the sharing party.

[0018] Furthermore, the process of calculating the updated global trust value of the sharing party based on the shared qualification information at the current moment specifically includes the following steps:

[0019] The time period between the current moment and the previous historical sharing cycle is recorded as the time threshold. The time threshold is divided into several sub-time periods, and the sharing qualification information of the sub-time periods is obtained. The sharing qualification information of the time period includes the number of positive sharing interactions and the number of negative sharing interactions.

[0020] Compare the number of positive sharing interactions in each sub-period with the preset threshold for the number of positive sharing interactions. Sub-periods with a number of positive sharing interactions greater than the preset threshold for the number of positive sharing interactions are recorded as multiplier sub-periods. Compare the number of negative sharing interactions with the preset threshold for the number of negative sharing interactions. Sub-periods with a number of negative sharing interactions greater than the preset threshold for the number of negative sharing interactions are recorded as abnormal sub-periods.

[0021] The number of sub-periods with multipliers within the statistical time threshold (BL) and the number of abnormal sub-periods (YX) are used to calculate the updated global trust value (XR) of the sharing party using a specific formula. ,in, , These are the multiplier sub-period coefficient and the abnormal sub-period coefficient, respectively.

[0022] Furthermore, the process of calculating the shared trust value of the sharing party based on the historical global trust value and the updated global trust value specifically includes the following steps:

[0023] Calculate the updated global trust value and historical global trust value The difference between ;

[0024] Based on difference Calculate the forgetting factor corresponding to the global trust value. :

[0025] ;

[0026] in, It is an adjustment coefficient used to adjust the rate of change of the forgetting factor, satisfying the condition ;

[0027] Based on forgetting factor Calculate the shared trust value KX of the sharing party:

[0028] .

[0029] Furthermore, determining whether a sharing party meets the requirements for cross-border compliant medical data sharing based on its sharing credibility value specifically includes the following processes:

[0030] Load the shared trust value threshold and determine whether the shared trust value of the sharing party exceeds the shared trust value threshold. If it does, the sharing party is deemed to meet the requirements for cross-border compliant medical data sharing; otherwise, the sharing party is deemed not to meet the requirements for cross-border compliant medical data sharing.

[0031] Furthermore, the cross-border compliant medical data of the sharing party is categorized to obtain the sensitive categories corresponding to the sharing party's cross-border compliant medical data. This process specifically includes the following steps:

[0032] Combining cross-border compliant medical data from the sharing parties into a dataset ,in For data packets, where, , Set the k value for the data packet size based on the size and shape of the dataset; randomly select the dataset. Let one data point be used as the initial centroid; when the number of initial centroids is less than k, let... Let be the initial centroid, where Based on the objective function Calculate the distance D(x) between the data packets in the dataset and the existing initial centroids; take the data packet corresponding to the maximum value in D(x) as the next initial centroid; obtain k initial centroids in sequence, and then analyze the dataset based on the k initial centroids. Clustering is performed to obtain k sensitive categories.

[0033] Furthermore, the calculation of the storage security feature value corresponding to the encrypted cross-border compliant medical data specifically includes the following process:

[0034] Obtain the public / private key pair of the encrypted cross-border compliant medical data. ,in, For public key, For private key, based on Generate a capacity file containing N data entries. and capacity file Stored on a node of the current shared platform;

[0035] The challenge is generated using a challenge generation algorithm and historical block parameters. ;

[0036] A node on the current sharing platform is based on the challenge and local storage capacity file Generate storage capacity value;

[0037] The storage security feature value of cross-border compliant medical data after encryption is calculated based on the storage capacity value.

[0038] Furthermore, the calculation of the transmission security feature value corresponding to the encrypted cross-border compliant medical data specifically includes the following process:

[0039] A data transmission management cycle is generated, which is the time taken for cross-border compliant medical data transmission after data encryption. The data transmission management cycle is divided into several sub-periods. Based on the transmission information of the file containing the encrypted cross-border compliant medical data in the blockchain, the data transmission frequency of the file in the blockchain within the sub-period is obtained. A rectangular coordinate system is established with the execution time of the sub-period as the X-axis and the data transmission frequency as the Y-axis. A data transmission security curve is plotted by plotting points. The number of all rising segments and falling segments of the curve are obtained from the data transmission security curve, and the ratio of the number of rising segments to the number of falling segments is recorded as the transmission excellence ratio. The data transmission security curve is obtained by normalizing the data between the lengths of the line segments above the preset data transmission security curve. The transmission excellence ratio is multiplied by the value to obtain the product value. A set of transmission performance values ​​is constructed using the product value, and then the maximum subset and minimum subset in the set are obtained. The difference between the maximum subset and the minimum subset in the set is marked as the transmission security feature index, where the maximum subset is the maximum value of the transmission performance value and the minimum subset is the minimum value of the transmission performance value.

[0040] Furthermore, determining whether the encrypted cross-border compliant medical data meets the requirements for sharing and transmission based on storage security feature values ​​and transmission security feature values ​​specifically includes the following process:

[0041] The storage security feature value and the transmission security feature value are normalized and then added together to obtain the data sharing transmission security value corresponding to the encrypted cross-border compliant medical data. The data sharing transmission security value threshold is loaded, and it is determined whether the data sharing transmission security value exceeds the data sharing transmission security value threshold. If it does, it is determined that the encrypted cross-border compliant medical data meets the sharing transmission requirements; otherwise, it is determined that the encrypted cross-border compliant medical data does not meet the sharing transmission requirements.

[0042] On the other hand, a homomorphic encryption method for protecting privacy in cross-border compliant medical data sharing includes:

[0043] Obtain the sharing qualification information of cross-border compliant medical data sharing parties, including historical sharing qualification information and current sharing qualification information;

[0044] The historical global trust value of the sharing party is calculated based on the historical shared qualification information. The updated global trust value of the sharing party is calculated based on the current shared qualification information. The shared trust value of the sharing party is calculated based on the historical global trust value and the updated global trust value.

[0045] Based on the sharing trust value of the sharing party, determine whether the sharing party meets the requirements for cross-border compliant medical data sharing. If yes, accept the sharing party's cross-border compliant medical data sharing request; otherwise, do not accept the sharing party's cross-border compliant medical data sharing request.

[0046] Respond to cross-border compliant medical data sharing requests and classify the cross-border compliant medical data of the sharing party to obtain the sensitive categories corresponding to the cross-border compliant medical data of the sharing party. Configure homomorphic encryption algorithm types for data of different sensitive categories to complete data encryption.

[0047] For cross-border compliant medical data that has been encrypted, the following steps are taken to share and transmit it on the sharing platform: Calculate the storage security feature value and transmission security feature value corresponding to the encrypted cross-border compliant medical data; determine whether the encrypted cross-border compliant medical data meets the sharing and transmission requirements based on the storage security feature value and transmission security feature value; and share and transmit the cross-border compliant medical data that meets the sharing and transmission requirements.

[0048] Compared to existing solutions, the beneficial effects achieved by this invention are:

[0049] Accurately screening trusted sharing parties enhances the security of cross-border data sharing: By comprehensively collecting historical and current sharing qualification information of sharing parties through the qualification information acquisition unit, calculating historical and updated global trust values, and introducing a sharing trust value calculation model with a forgetting factor, dynamic and accurate assessment of the trust status of sharing parties is achieved. This effectively filters out trusted sharing parties, rejects access requests from untrusted entities, avoids data security risks caused by malicious sharing behavior from the source, and lays a solid foundation of trust for cross-border medical data sharing.

[0050] Differentiated encryption ensures privacy and security while balancing data usage efficiency: Addressing the differences in sensitive attributes of cross-border compliant medical data, clustering analysis is used to categorize the data into sensitive types. Adaptive homomorphic encryption algorithms are then configured for different sensitive categories, ensuring strong encryption of highly sensitive medical data and effectively preventing unauthorized theft or cracking during sharing, storage, and transmission, thus fully protecting patient privacy and data security. Simultaneously, it avoids over-encryption of less sensitive data, reducing the computational overhead of encryption and decryption, ensuring efficiency in data sharing and subsequent analysis, and achieving a balance between privacy protection and data usability.

[0051] End-to-end security monitoring ensures compliant and controllable data transmission: During the data transmission phase, by calculating the storage security feature value and the transmission security feature value, it is possible to accurately determine whether the encrypted data meets the requirements for shared transmission. Only data that meets the security standards is transmitted, effectively avoiding risks such as loss, tampering, and leakage during data transmission. Attached Figure Description

[0052] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0053] Figure 1 This is a system block diagram of a homomorphic encrypted cross-border compliant medical data sharing privacy protection system according to an embodiment of the present invention;

[0054] Figure 2 This is a flowchart illustrating the workflow of a homomorphic encrypted cross-border compliant medical data sharing privacy protection system according to an embodiment of the present invention.

[0055] Figure 3 This is a flowchart illustrating a method for protecting privacy in cross-border compliant medical data sharing using homomorphic encryption, according to an embodiment of the present invention. Detailed Implementation

[0056] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0057] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more exemplary embodiments. Numerous specific details are provided in the following description to give a full understanding of exemplary embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more of the specific details omitted, or other methods, components, steps, etc., can be employed. In other instances, well-known structures, methods, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this disclosure.

[0058] This embodiment provides a homomorphic encrypted cross-border compliant medical data sharing privacy protection system. Figure 1 This is a system block diagram of a homomorphic encrypted cross-border compliant medical data sharing privacy protection system according to an embodiment of the present invention, such as... Figure 1As shown, the system includes:

[0059] The qualification information acquisition unit is used to acquire the sharing qualification information of cross-border compliant medical data sharing parties. The sharing qualification information includes historical sharing qualification information and current sharing qualification information.

[0060] The shared trust value calculation unit is used to calculate the historical global trust value of the sharing party based on historical shared qualification information, calculate the updated global trust value of the sharing party based on the current shared qualification information, and calculate the shared trust value of the sharing party based on the historical global trust value and the updated global trust value.

[0061] The data sharing management unit is used to determine whether a sharing party meets the requirements for cross-border compliant medical data sharing based on the sharing trust value of the sharing party. If so, the sharing party's cross-border compliant medical data sharing request is accepted; otherwise, the sharing party's cross-border compliant medical data sharing request is not accepted.

[0062] The homomorphic encryption unit is used to respond to cross-border compliant medical data sharing requests and classify the cross-border compliant medical data of the sharing party to obtain the sensitive categories corresponding to the cross-border compliant medical data of the sharing party. The homomorphic encryption algorithm type is configured for different sensitive categories of data to complete data encryption.

[0063] The data sharing and transmission unit is used to share and transmit encrypted cross-border compliant medical data on the sharing platform: it calculates the storage security feature value and transmission security feature value corresponding to the encrypted cross-border compliant medical data, determines whether the encrypted cross-border compliant medical data meets the sharing and transmission requirements based on the storage security feature value and transmission security feature value, and shares and transmits cross-border compliant medical data that meets the sharing and transmission requirements.

[0064] In summary, this invention obtains the sharing qualification information of cross-border compliant medical data sharing parties; calculates the historical global trust value of the sharing party based on historical sharing qualification information, calculates the updated global trust value of the sharing party based on the current sharing qualification information, and calculates the sharing trust value of the sharing party based on the historical global trust value and the updated global trust value; determines whether the sharing party meets the requirements for cross-border compliant medical data sharing based on the sharing trust value; if yes, accepts the cross-border compliant medical data sharing request from the sharing party; if no, does not accept the cross-border compliant medical data sharing request from the sharing party; responds to the cross-border compliant medical data sharing request and classifies the cross-border compliant medical data of the sharing party to obtain the sensitive categories corresponding to the cross-border compliant medical data of the sharing party; configures homomorphic encryption algorithm types for data of different sensitive categories to complete data encryption; and shares and transmits the encrypted cross-border compliant medical data on the blockchain. This invention can construct a privacy protection solution for medical data sharing that takes into account the accuracy of trust assessment, the specificity of data encryption, the controllability of transmission security, and cross-border compliance, in order to solve the current problems of privacy leakage, high compliance risks, and lack of trust in cross-border medical data sharing, and promote the safe, compliant and efficient circulation of cross-border medical data.

[0065] In some embodiments, Figure 2 This is a flowchart illustrating the workflow of a homomorphic encrypted cross-border compliant medical data sharing privacy protection system according to an embodiment of the present invention. Figure 2 As shown, the process of calculating the historical global trust value of a sharing party based on historical shared qualification information includes the following steps:

[0066] Step 1: Set the historical sharing period, dividing the historical sharing period into G historical time periods, each historical time period containing one historical sharing qualification information;

[0067] It is worth noting that the duration of the historical sharing period is set by the system. For example, the system's runtime over the past 30 days can be used as a historical sharing period, with each day being a historical time period.

[0068] Historical sharing qualification information includes the sharing qualification information of the first historical period, the sharing qualification information of the second historical period, and so on up to the Gth historical period; among them, the sharing qualification information of the historical period includes the qualification compliance rate, the active sharing interaction rate, and the cross-border medical data sharing project approval success rate. The qualification compliance rate is the ratio between the number of valid qualification documents uploaded in the historical period and the minimum number of qualification documents required. The active sharing interaction rate is the ratio between the number of active sharing interactions and the number of negative sharing interactions. The cross-border medical data sharing project approval success rate is the proportion of cross-border medical data sharing projects that have been approved by regulatory agencies.

[0069] It is worth noting that the determination of the number of active sharing interactions is as follows:

[0070] Only when all four of the following prerequisites are met can the sharing interactions of the sharing party be counted in the "Number of Active Sharing Interactions," ensuring that the statistical results truly reflect compliant and valuable sharing behaviors:

[0071] Compliance prerequisites: The sharing behavior has passed the cross-border data compliance review (such as completing the data export security assessment, obtaining patient authorization, and having complete filing documents), and complies with the regulations of the target country or region (such as GDPR, HIPAA, and the "Data Export Security Assessment Measures").

[0072] Value premise: Shared data is used for clear and legitimate business purposes (such as clinical diagnosis and treatment collaboration, medical research, and public health emergency response), rather than for aimless transmission, testing, or redundant backup;

[0073] Security prerequisites: The sharing process is completed through a compliant transmission channel (such as an encrypted VPN or TLS 1.3 protocol), with no security incidents such as data leakage, tampering, or unauthorized access.

[0074] Authenticity premise: The sharing behavior is a genuine business need of both parties, excluding invalid behaviors such as test interactions, misoperations, and duplicate transmissions.

[0075] The number of negative sharing interactions is determined as follows: if any one of the above four prerequisites is not met, it is considered a negative sharing interaction.

[0076] Step 2: Add the qualification compliance rate, active sharing and interaction rate and cross-border medical data sharing project approval success rate in the first historical period to obtain the local trust value in the first historical period, and then obtain the local trust value in the second historical period, until the local trust value in the Gth historical period is obtained.

[0077] Step 3: Calculate the local trust value in the first historical period, the local trust value in the second historical period, and the average of the local trust values ​​up to the Gth historical period. Record the average value as the historical global trust value of the sharing party.

[0078] In some embodiments, calculating the updated global trust value of the sharing party based on the shared qualification information at the current moment specifically includes the following process:

[0079] The time period between the current moment and the previous historical sharing cycle is recorded as the time threshold. The time threshold is divided into several sub-time periods, and the sharing qualification information of the sub-time periods is obtained. The sharing qualification information of the time period includes the number of positive sharing interactions and the number of negative sharing interactions.

[0080] Compare the number of positive sharing interactions in each sub-period with the preset threshold for the number of positive sharing interactions. Sub-periods with a number of positive sharing interactions greater than the preset threshold for the number of positive sharing interactions are recorded as multiplier sub-periods. Compare the number of negative sharing interactions with the preset threshold for the number of negative sharing interactions. Sub-periods with a number of negative sharing interactions greater than the preset threshold for the number of negative sharing interactions are recorded as abnormal sub-periods.

[0081] The preset threshold for the number of positive sharing interactions is set at 8 times. This is based on the actual operational data of domestic and international cross-border medical collaboration platforms (such as the EU Medical Data Space EDS and the China Cross-border Medical Data Circulation Pilot Platform). The monthly number of positive interactions of compliant sharing parties is generally concentrated between 5 and 12 times, and 8 times is the median of this range. This ensures that the threshold is not too low, which may lead to the misjudgment of "pseudo-positive sharing parties", nor too high, which may exclude sharing parties with normal collaboration.

[0082] The preset threshold for the number of positive sharing interactions can be set to 3 times. A single serious negative interaction can trigger a compliance risk warning. Three or more monthly negative interactions indicate that the sharing party has a clear lack of compliance awareness or operational loopholes. Setting this threshold can help screen high-risk entities in a timely manner.

[0083] The number of sub-periods with multipliers within the statistical time threshold (BL) and the number of abnormal sub-periods (YX) are used to calculate the updated global trust value (XR) of the sharing party using a specific formula. ,in, , These are the multiplier sub-period coefficient and the abnormal sub-period coefficient, respectively.

[0084] It is worth noting that, , All coefficients are dimensionless, with values ​​limited to the range of [1.0, 2.0]. This ensures that the coefficients have a significant moderating effect on the trust value calculation while avoiding extreme deviations in the updated global trust value (XR) due to excessively large coefficients (such as being too high or too low), thus ensuring the rationality and stability of the trust assessment results. For example, , They are 1.2 and 1.8 respectively.

[0085] In some embodiments, calculating the shared trust value of the sharing party based on the historical global trust value and the updated global trust value specifically includes the following process:

[0086] Calculate the updated global trust value and historical global trust value The difference between ;

[0087] Based on difference Calculate the forgetting factor corresponding to the global trust value. :

[0088] ;

[0089] in, It is an adjustment coefficient used to adjust the rate of change of the forgetting factor, satisfying the condition The value indicates that, The coefficient is dimensionless and its value is limited to the interval (0, 0.5). This interval ensures the sensitivity of the forgetting factor to the adjustment of the confidence value difference while avoiding the influence of other factors. An excessively large value can lead to an imbalance in the weight of historical or updated global trust values ​​within the shared trust value. Therefore, it's crucial to ensure a balance between the dynamism and stability of trust assessment. For example, 0.3 is acceptable.

[0090] Based on forgetting factor Calculate the shared trust value KX of the sharing party:

[0091] .

[0092] In some embodiments, determining whether a sharing party meets the requirements for cross-border compliant medical data sharing based on the sharing trust value of the sharing party specifically includes the following process:

[0093] Load the shared trust value threshold and determine whether the shared trust value of the sharing party exceeds the shared trust value threshold. If it does, the sharing party is deemed to meet the requirements for cross-border compliant medical data sharing; otherwise, the sharing party is deemed not to meet the requirements for cross-border compliant medical data sharing.

[0094] It is worth noting that, in conjunction with the coefficients set above... , They are 1.2 and 1.8 respectively. The threshold values ​​can be 0.3 and 1.7 (≥8 positive interactions, ≥3 negative interactions). The range of KX is [0, 1]. 0.7 is in the "high confidence interval" of this range, which not only meets the "strict security" requirements for cross-border medical data sharing, but also avoids the possibility of compliant sharing parties being mistakenly rejected due to excessively high threshold values.

[0095] In some embodiments, classifying the cross-border compliant medical data of the sharing party to obtain the sensitive categories corresponding to the cross-border compliant medical data of the sharing party specifically includes the following process:

[0096] Combining cross-border compliant medical data from the sharing parties into a dataset ,in For data packets, where, , Set the k value for the data packet size based on the size and shape of the dataset; randomly select the dataset. Let one data point be used as the initial centroid; when the number of initial centroids is less than k, let... Let be the initial centroid, where Based on the objective function Calculate the distance D(x) between the data packets in the dataset and the existing initial centroids; take the data packet corresponding to the maximum value in D(x) as the next initial centroid; obtain k initial centroids in sequence, and then analyze the dataset based on the k initial centroids. Clustering is performed to obtain k sensitive categories.

[0097] For example, k can be set to 3, which defines three categories: high sensitivity, medium sensitivity, and low sensitivity. Homomorphic encryption algorithm types are configured for different sensitivity levels of data: Fully Homomorphic Encryption (FHE) is used for high sensitivity data, Partially Homomorphic Encryption (PHE) is used for medium sensitivity data, and Lightweight Homomorphic Encryption (LHE) is used for low sensitivity data.

[0098] In some embodiments, calculating the storage security feature value corresponding to the encrypted cross-border compliant medical data specifically includes the following process:

[0099] Obtain the public / private key pair of the encrypted cross-border compliant medical data. ,in, For public key, For private key, based on Generate a capacity file containing N data entries. and capacity file A node is stored in the current sharing platform; where the sharing platform is a platform for data sharing parties to share data, and the blockchain can also be regarded as a sharing platform. Accordingly, each data sharing party is recorded as a node.

[0100] Specifically, , , It is a set of collision-resistant hash functions, where, , It is a hash table data structure consisting of N data items; where the hash function can be SHA-256.

[0101] Based on public-private key pairs Calculate capacity file Unique identifier ,in, Indicates the public key Perform a hash operation;

[0102] For data x: calculate the corresponding key y from 1 to N: Create a hash table A with y as the key and x as the value;

[0103] Data Calculate the corresponding keys from 1 to N. : ; Look up the key in hash table A The corresponding value of x;

[0104] Calculate key z: With z as the key, Capacity file for values .

[0105] The challenge is generated using a challenge generation algorithm and historical block parameters. ;

[0106] Get the current block height h and historical block parameters. ;

[0107] If the current block height h is If the integer multiple of , then for the ... The capacity proof of each block is hashed once to obtain the challenge. If the current block height h is not If the integer multiple of , then for the ... The capacity proof of each block is hashed K times consecutively to obtain the challenge. .

[0108] A node on the current sharing platform is based on the challenge and local storage capacity file Generate storage capacity value;

[0109] According to the challenge and local storage capacity file Generating storage capacity values ​​specifically includes the following processes:

[0110] Capacity file from local storage Query for values ​​that meet the equality condition. :

[0111] ;

[0112] in, express and The last n digits are equal;

[0113] For those that meet the equality condition Calculate its mass Q:

[0114] ;

[0115] in, For the signature of the file containing the data, Parameters for initializing the capacity space;

[0116] Obtain the block difficulty parameter corresponding to the file, and record the difference between the quality Q and the difficulty parameter as the storage capacity value.

[0117] Based on the storage capacity value, calculate the storage security characteristics of the encrypted cross-border compliant medical data:

[0118] Generate a management cycle, divide the management cycle into several sub-periods, obtain the storage capacity value of all sub-periods, establish a rectangular coordinate system with the execution time of the sub-period as the X-axis and the storage capacity value as the Y-axis, and draw the data storage security characteristic curve by plotting points;

[0119] The number of line segments whose storage capacity exceeds the preset storage capacity threshold is obtained from the storage security characteristic curve. This storage capacity threshold is set by the system based on the historical transmission data of the sharing party. For example, the core of the storage capacity value calculation is a "quantitative indicator of storage integrity and security" generated based on the blockchain public-private key mechanism and challenge response mechanism. Combining the above discussion, the storage capacity value range is [0, 1] (after normalization). Setting the preset storage capacity threshold to 0.6, which falls within the "security compliance range," ensures both the effective retention and integrity of encrypted medical data by storage nodes and avoids the misjudgment of normal storage nodes as insecure due to an excessively high threshold, or the condoning of storage vulnerabilities due to an excessively low threshold.

[0120] Draw perpendicular lines from the two endpoints of the data storage security feature curve to the X-axis to obtain two perpendicular line segments. The data storage security feature curve, the two perpendicular line segments, and the X-axis form a graph. Calculate the area of ​​the graph, and then normalize the area of ​​the graph and the number of line segments before taking the ratio. The resulting ratio is recorded as the storage security feature value of the cross-border compliant medical data after data encryption.

[0121] In some embodiments, calculating the transmission security feature value corresponding to the encrypted cross-border compliant medical data specifically includes the following process:

[0122] A data transmission management cycle is generated, which is the time taken for cross-border compliant medical data transmission after data encryption. The data transmission management cycle is divided into several sub-periods. Based on the transmission information of the file containing the encrypted cross-border compliant medical data in the blockchain, the data transmission frequency of the file in the blockchain within the sub-period is obtained. A rectangular coordinate system is established with the execution time of the sub-period as the X-axis and the data transmission frequency as the Y-axis. A data transmission security curve is plotted by plotting points. The number of all rising segments and falling segments of the curve are obtained from the data transmission security curve, and the ratio of the number of rising segments to the number of falling segments is recorded as the transmission excellence ratio. The data transmission security curve is obtained by normalizing the data between the lengths of the line segments above the preset data transmission security curve. The transmission excellence ratio is multiplied by the value to obtain the product value. A set of transmission performance values ​​is constructed using the product value, and then the maximum subset and minimum subset in the set are obtained. The difference between the maximum subset and the minimum subset in the set is marked as the transmission security feature index, where the maximum subset is the maximum value of the transmission performance value and the minimum subset is the minimum value of the transmission performance value.

[0123] In some embodiments, determining whether the encrypted cross-border compliant medical data meets the requirements for shared transmission based on storage security feature values ​​and transmission security feature values ​​specifically includes the following process:

[0124] The storage security feature value and the transmission security feature value are normalized and then added together to obtain the data sharing transmission security value corresponding to the encrypted cross-border compliant medical data. A data sharing transmission security value threshold is then applied, and it is determined whether the data sharing transmission security value exceeds the threshold. If it does, the encrypted cross-border compliant medical data is deemed to meet the sharing transmission requirements; otherwise, it is deemed not to meet the sharing transmission requirements. It is worth noting that setting the sharing transmission security value threshold to 0.8 corresponds to "both storage security and transmission security meet basic security standards, and the combined value meets high security requirements." This aligns with the core requirement of "zero risk during the transmission process" for cross-border medical data while avoiding obstruction of compliant data transmission due to an excessively high threshold.

[0125] This invention also provides a homomorphic encryption method for protecting the privacy of cross-border compliant medical data sharing. Figure 3 This is a flowchart illustrating a method for protecting privacy in cross-border compliant medical data sharing using homomorphic encryption, as described in this invention. Figure 3 As shown, the method includes:

[0126] Step 1: Obtain the sharing qualification information of cross-border compliant medical data sharing parties. The sharing qualification information includes historical sharing qualification information and current sharing qualification information.

[0127] Step 2: Calculate the historical global trust value of the sharing party based on the historical shared qualification information, calculate the updated global trust value of the sharing party based on the current shared qualification information, and calculate the shared trust value of the sharing party based on the historical global trust value and the updated global trust value.

[0128] Step 3: Based on the sharing trust value of the sharing party, determine whether the sharing party meets the requirements for cross-border compliant medical data sharing. If yes, accept the sharing party's cross-border compliant medical data sharing request; otherwise, do not accept the sharing party's cross-border compliant medical data sharing request.

[0129] Step 4: Respond to the cross-border compliant medical data sharing request and classify the cross-border compliant medical data of the sharing party to obtain the sensitive categories corresponding to the cross-border compliant medical data of the sharing party. Configure the homomorphic encryption algorithm type for the data of different sensitive categories to complete the data encryption.

[0130] Step 5: Share and transmit the encrypted cross-border compliant medical data on the sharing platform.

[0131] Calculate the storage security feature value and transmission security feature value corresponding to the encrypted cross-border compliant medical data. Based on the storage security feature value and transmission security feature value, determine whether the encrypted cross-border compliant medical data meets the sharing and transmission requirements. Share and transmit the cross-border compliant medical data that meets the sharing and transmission requirements.

[0132] The above formulas are all dimensionless calculations, and the preset parameters in the formulas should be set by those skilled in the art according to the actual situation.

Claims

1. A homomorphic encryption cross-border compliance medical data sharing privacy protection system, characterized in that, The system comprises: a qualification information acquisition unit configured to acquire sharing qualification information of a cross-border compliance medical data sharing party, wherein the sharing qualification information comprises historical sharing qualification information and sharing qualification information at a current time; a sharing trust value calculation unit configured to calculate a historical global trust value of the sharing party based on the historical sharing qualification information, calculate an updated global trust value of the sharing party based on the sharing qualification information at the current time, and calculate a sharing trust value of the sharing party based on the historical global trust value and the updated global trust value; a data sharing management unit configured to determine whether the sharing party meets cross-border compliance medical data sharing requirements based on the sharing trust value of the sharing party, receive a cross-border compliance medical data sharing request of the sharing party if the sharing party meets the requirements, and not accept the cross-border compliance medical data sharing request of the sharing party if the sharing party does not meet the requirements; a homomorphic encryption unit configured to respond to the cross-border compliance medical data sharing request, classify cross-border compliance medical data of the sharing party, obtain sensitive categories corresponding to the cross-border compliance medical data of the sharing party, configure homomorphic encryption algorithm types for data of different sensitive categories, and complete data encryption; a data sharing transmission unit configured to share and transmit the cross-border compliance medical data after completing data encryption on a sharing platform, calculate storage security feature values and transmission security feature values corresponding to the cross-border compliance medical data after completing data encryption, determine whether the cross-border compliance medical data after completing data encryption meets sharing transmission requirements based on the storage security feature values and the transmission security feature values, and share and transmit the cross-border compliance medical data meeting the sharing transmission requirements.

2. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 1, characterized in that, The calculation of the historical global trust value of the sharing party based on the historical sharing qualification information comprises the following processes: a historical sharing period is set, the historical sharing period is divided into G historical time periods, and each historical time period contains a historical sharing qualification information; the historical sharing qualification information comprises sharing qualification information of a first historical time period, sharing qualification information of a second historical time period, and sharing qualification information of a Gth historical time period; a local trust value in the first historical time period is obtained by adding a qualification compliance rate, an active sharing interaction rate, and a cross-border medical data sharing project audit success rate in the first historical time period, a local trust value in the second historical time period is obtained in turn, and a local trust value in the Gth historical time period is obtained in turn; an average value of the local trust value in the first historical time period, the local trust value in the second historical time period, and the local trust value in the Gth historical time period is calculated, and the average value is recorded as the historical global trust value of the sharing party.

3. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 2, characterized in that, The calculation of the updated global trust value of the sharing party based on the sharing qualification information at the current time comprises the following processes: a time threshold between the current time and a previous historical sharing period is recorded, the time threshold is divided into a plurality of sub-time periods, and sharing qualification information of the sub-time periods is acquired, wherein the sharing qualification information of the time period comprises an active sharing interaction frequency and a negative sharing interaction frequency; a ratio sub-time period and an abnormal sub-time period are obtained through comparison and analysis; The calculation of the sharing trust value of the sharing party based on the historical global trust value and the updated global trust value comprises the following processes: The number BL of the sub-periods within the statistical time threshold and the number YX of the abnormal sub-periods are counted, and the updated global trust value XR of the sharing party is calculated by the following formula: wherein, , are the sub-period coefficient of the multiplier and the sub-period coefficient of the abnormality, respectively.

4. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 1, characterized in that, ​ ​ calculating a difference between the updated global trust value and the historical global trust value ;​ Based on the difference value Computing the forgetting factor corresponding to the global trust value : Based on a forgetting factor A sharing trusted value KX of the sharing party is calculated.

5. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 1, characterized in that, The judgment of whether the sharing party meets the cross-border compliance medical data sharing requirement based on the sharing trust value of the sharing party specifically includes the following processes: Loading the sharing trust value threshold, judging whether the sharing trust value of the sharing party exceeds the sharing trust value threshold, if yes, judging that the sharing party meets the cross-border compliance medical data sharing requirement, if not, judging that the sharing party does not meet the cross-border compliance medical data sharing requirement.

6. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 1, characterized in that, Classifying the cross-border compliance medical data of the sharing party to obtain the sensitive categories corresponding to the cross-border compliance medical data of the sharing party specifically includes the following processes: Combining cross-border compliant medical data from the sharing parties into a dataset ,in For data packets, where, , Set the k value for the data packet size based on the size and shape of the dataset; randomly select the dataset. Let one data point be used as the initial centroid; when the number of initial centroids is less than k, let... Let be the initial centroid, where Based on the objective function Calculate the distance D(x) between the data packets in the dataset and the existing initial centroids; take the data packet corresponding to the maximum value in D(x) as the next initial centroid; obtain k initial centroids in sequence, and then analyze the dataset based on the k initial centroids. Clustering is performed to obtain k sensitive categories.

7. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 1, characterized in that, Calculating the storage security feature value corresponding to the cross-border compliance medical data after data encryption specifically includes the following processes: Based on the storage capacity value, calculating the storage security feature value of the cross-border compliance medical data after data encryption. Obtaining cross-border compliance medical data after data encryption wherein, is the public key, is the private key, based on Generating a capacity file of N pieces of data and storing the capacity file in a node of the current sharing platform; generating a corresponding challenge by a challenge generation algorithm and historical block parameters ; A node of a current sharing platform according to a challenge and a locally stored capacity file generates a storage capacity value; Calculating the transmission security feature value corresponding to the cross-border compliance medical data after data encryption specifically includes the following processes:

8. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 1, characterized in that, Generating a data transmission management period, dividing the data transmission management period into a plurality of sub-periods, obtaining the data transmission frequency of the file in the blockchain within the sub-period based on the transmission information of the file in the blockchain of the cross-border compliance medical data after data encryption; Establishing a rectangular coordinate system with the execution time of the sub-period as the X-axis and the data transmission frequency as the Y-axis, drawing a data transmission security curve by dotting, constructing a set of transmission performance values based on the data transmission security curve, and then obtaining the maximum subset and the minimum subset in the set, and marking the difference between the maximum subset and the minimum subset in the set as the transmission security feature index, wherein the maximum subset is the maximum value of the transmission performance value, and the minimum subset is the minimum value of the transmission performance value. Based on the storage security feature value and the transmission security feature value, judging whether the cross-border compliance medical data after data encryption meets the sharing transmission requirement specifically includes the following processes: After the storage security feature value and the transmission security feature value are normalized, they are added to obtain the data sharing transmission security value corresponding to the cross-border compliance medical data after data encryption, load the data sharing transmission security value threshold, judge whether the data sharing transmission security value exceeds the data sharing transmission security value threshold, if yes, judge that the cross-border compliance medical data after data encryption meets the sharing transmission requirement, if not, judge that the cross-border compliance medical data after data encryption does not meet the sharing transmission requirement.

9. The homomorphic encryption cross-border compliance medical data sharing privacy protection system according to claim 1, characterized in that, The method is suitable for the homomorphic encryption cross-border compliance medical data sharing privacy protection system described in any one of claims 1 to 9, and the method comprises: Obtaining the sharing qualification information of the cross-border compliance medical data sharing party, wherein the sharing qualification information includes historical sharing qualification information and sharing qualification information at the current time; 10. A homomorphic encryption cross-border compliance medical data sharing privacy protection method, characterized in that, Based on the historical sharing qualification information, the historical global trust value of the sharing party is calculated, based on the sharing qualification information at the current time, the updated global trust value of the sharing party is calculated, and based on the historical global trust value and the updated global trust value, the sharing trust value of the sharing party is calculated; ​ ​ The shared trusted value based on the sharing party is used to determine whether the sharing party meets the cross-border compliance medical data sharing requirements. If yes, the cross-border compliance medical data sharing request of the sharing party is received. If no, the cross-border compliance medical data sharing request of the sharing party is not accepted. In response to the cross-border compliance medical data sharing request, the cross-border compliance medical data of the sharing party is classified to obtain the sensitive categories corresponding to the cross-border compliance medical data of the sharing party. Homomorphic encryption algorithm types are configured for data of different sensitive categories, and data encryption is completed. The cross-border compliance medical data after completing data encryption is shared and transmitted on the sharing platform. The storage security feature value and the transmission security feature value corresponding to the cross-border compliance medical data after completing data encryption are calculated. Whether the cross-border compliance medical data after completing data encryption meets the sharing transmission requirements is determined based on the storage security feature value and the transmission security feature value. The cross-border compliance medical data meeting the sharing transmission requirements is shared and transmitted.

Citation Information

Patent Citations

  • Data security transmission method and system based on terminal trust management

    CN113329204A

  • Medical big data sharing method based on federal learning and block chain

    CN114048515A

  • Medical data sharing privacy protection method based on fully homomorphic encryption

    CN114978467A

  • Medical data trusted sharing method based on block chain and federal learning

    CN116776373A

  • Biomedical data sharing system based on 5G Internet of Things

    CN117177243A