Closed-loop automatic management method and system for outgoing examination of patients based on intelligent access control system

By deploying full-coverage card readers and RFID wristbands with built-in encrypted identity information at ward exits, combined with the hospital information system, automated management of patients' outpatient examinations is achieved. This solves the problems of manual record deviation and data inaccuracy in traditional management, meets the standardization requirements of electronic medical record review, and improves management efficiency and security.

CN121726005APending Publication Date: 2026-03-24ZHEJIANG PROVINCIAL PEOPLES HOSPITAL
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-20
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Traditional patient outpatient examination management relies on manual operation, which results in record omissions, time logic inconsistencies, and impaired data accuracy and logic. It cannot achieve dynamic monitoring of patients and synchronous determination of examination plan duration, and it is difficult to meet the standardization requirements of electronic medical record review.

Method used

By using RFID wristbands with built-in encrypted identity information and full-coverage card readers, the system enables automated identification and information verification of patients leaving and returning to their wards. By comparing the actual time spent outside with the planned examination time, it triggers tiered alarms and integrates deeply with the hospital information system to form a closed-loop management system.

Benefits of technology

It enables automated recording and identity verification of patients' ward entry and exit times, ensuring data accuracy and security, meeting the standardized requirements of electronic medical record review, improving management efficiency and security, and adapting to the multi-scenario needs of general hospitals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121726005A_ABST
    Figure CN121726005A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of RFID management, in particular to a closed-loop automatic management method and system for outgoing examination of patients based on an intelligent access control system. The method comprises the following steps: configuring an RFID wrist strap with built-in encrypted identity information for a patient, and deploying a card reader fully covered by a radio frequency identification range at an exit of a ward; when the patient approaches an exit, activating a chip corresponding to the RFID wrist strap, receiving the encrypted identity information, decrypting the encrypted identity information, and extracting core identity data to verify the outgoing authority; recording ward leaving time after the permission is passed, synchronizing to a hospital information system through an encryption interface, and driving a door lock to be opened by the access control system; when the patient returns, the card reader performs secondary identification, records the time of returning to the ward and synchronizes the data; the system compares the actual going-out duration with the inspection plan duration, judges abnormity in combination with a timeout condition, and triggers graded alarm; the medical staff receives the alarm information and then checks the alarm information, and the system updates the processing result to complete closed-loop management. The medical care management efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of RFID management, and in particular to a patient outbound examination closed-loop automatic management method and system based on an intelligent access control system. BACKGROUND

[0002] Under the background of deepening medical informatization construction, fine management of the whole process of patient diagnosis and treatment has become the core demand to improve the quality of medical services and ensure medical safety. Among them, patient outbound examination as an important part of diagnosis and treatment, the whole process tracking record of out of ward, examination, back to ward, not only is the clear requirement of 6-level electronic medical record evaluation standard, but also is the key to avoid patient missing, delay diagnosis and treatment, and ensure medical safety. However, the traditional patient outbound examination management mode highly depends on nurses to manually operate PDA to scan patient wristband and record the time of out and back to ward. This way has significant drawbacks: when nursing work is busy, it is easy to miss records, and it is impossible to realize dynamic monitoring of patients; after the fact, the time logic contradiction (such as the out of ward time is later than the examination time, and the back to ward time is earlier than the examination time) often appears in the supplementary record, resulting in damaged data accuracy and logic.

[0003] The patent document with publication number "CN113990505A" discloses a psychiatric hospital inpatient management system based on Internet of Things, which includes: information input module, entrance and exit management module, patient outbound range management module, patient risk assessment module, patient information feedback module, patient hospitalization management module, face recognition technology is used to store patient information when inpatient is admitted to hospital, face recognition devices are set at each entrance and exit of the hospital, when the patient needs to leave the ward to go to the outpatient department for examination or treatment area treatment, etc., the patient outbound range permission is set, the alarm is given according to the risk level of the patient, and the patient outbound information is fed back to the ward in real time, so as to facilitate the nursing staff to contact the patient in time. The present application improves the outbound control safety of special patients, but the scheme focuses on the outbound range restriction and risk interception of patients in psychiatric hospitals, and does not design for the closed-loop management needs of ordinary hospital patient outbound examination - lacks deep linkage with hospital information system, cannot synchronize the overtime determination of examination plan duration; does not realize the automatic and accurate record of out and back to ward time, still has data record deviation, and cannot meet the standardization requirements of electronic medical record evaluation on diagnosis and treatment process tracking record, and cannot adapt to the efficient management scene of patient outbound examination in general hospitals. SUMMARY

[0004] The present application provides a patient out-of-hospital examination closed-loop automatic management method based on an intelligent access control system, which can realize automatic identification and information verification of patients going out and returning to the ward through RFID wristbands with built-in encrypted identity information and full-coverage card readers at the ward exit, accurately record the time without manual intervention, avoid data recording deviation, meet the standardization requirements of electronic medical record evaluation on diagnosis and treatment process tracking, and fill the gap of patient out-of-hospital examination overtime control in ordinary hospitals. After receiving the alarm, the medical staff checks and processes it, and the system updates the processing result to form a complete closed loop, which not only guarantees the orderliness and safety of patient out-of-hospital examination, but also improves the efficiency of medical management. The patient out-of-hospital examination closed-loop automatic management method based on an intelligent access control system includes the following steps: configuring RFID wristbands with built-in encrypted identity information for patients, and deploying full-coverage card readers at the ward exit; when the patient approaches the exit, the card reader activates the RFID wristband chip and receives the encrypted identity information, decrypts it to extract the core identity data and verify the out-of-hospital permission; after the permission is verified, the out-of-hospital time is recorded and synchronized to the hospital information system through an encrypted interface; the door lock is opened by the access control system; the patient returns to the ward, and the card reader identifies again to record the return time and synchronize the data; the system compares the actual out-of-hospital time with the examination plan time, and determines the abnormality according to the overtime situation, and triggers a hierarchical alarm; after receiving the alarm information, the medical staff checks and processes it, and the system updates the processing result to complete the closed-loop management. In the present application, RFID wristbands with built-in encrypted identity information are configured for patients, and full-coverage card readers are deployed at the ward exit, which realizes automatic identification of patients going out and returning to the ward, completes identity verification and time recording without manual intervention, completely solves the deviation problem of traditional manual recording, and meets the standardization requirements of electronic medical record evaluation on diagnosis and treatment process tracking. When the patient goes out, the card reader activates the wristband chip, decrypts the identity information, and verifies the permission, and after passing the verification, the out-of-hospital time is automatically recorded and synchronized to the hospital information system through an encrypted interface, and the door is opened synchronously, which guarantees the efficiency and safety of the access; when the patient returns, the card reader identifies again to record the return time and form complete in-out trajectory data. The system deeply links with the hospital information system, synchronizes the patient examination plan time, accurately compares the actual out-of-hospital time with the plan time, triggers a hierarchical alarm according to the overtime situation, fills the gap of patient out-of-hospital examination overtime control in ordinary hospitals, and effectively prevents the risk of patient loss and delayed treatment. After receiving the alarm information, the medical staff checks and processes it quickly, and the system updates the processing result in real time to form a closed-loop management of "identification-recording-comparison-alarm-processing-feedback". The overall scheme not only guarantees the safety and orderliness of patient out-of-hospital examination, but also greatly improves the efficiency of medical management, reduces the cost of manual control, perfectly adapts to the patient management needs of comprehensive hospitals with multiple scenes and high efficiency, and balances the process standardization and convenience of use.

[0005] As preferred, the RFID wristband with built-in encrypted identity information is configured for the patient, and the read carder with full coverage of radio frequency identification range is deployed at the exit of the ward, comprising the following steps: calling the patient medical record identification, name, allergy history and sensitive information corresponding to the current diagnosis and treatment scheme from the hospital information system, processing the data by combining symmetric encryption and asymmetric encryption, encrypting the information body by AES algorithm, and protecting the symmetric key by RSA algorithm; writing the complete encrypted data into the passive RFID wristband chip, the chip packaging adopts medical-grade waterproof and anticorrosive material, and is integrally formed with the anti-tear wristband, the surface of the wristband is printed with desensitized identity identification and emergency contact information; installing the read carder on the central axis of the exit passage of the ward, adjusting the installation height and angle through multiple tests to ensure that the radio frequency signal covers the passage width and the identification distance is controlled within a reasonable range to avoid signal interference between adjacent passages; connecting the read carder with the ARM main controller of the access control system through the SPI bus, configuring the working frequency and data transmission baud rate of the read carder to match the communication parameters of the wristband chip, and enabling the built-in hash check function of the read carder to ensure data integrity; test the scene of patients of different sizes wearing wristbands passing at different speeds, record the identity recognition response time and accuracy, and adjust the antenna gain for identification delay exceeding threshold or misidentification. In the application, the problems of patient identity information leakage risk, incomplete identification range and signal interference are effectively solved through secure information encryption and precise equipment deployment. After calling the patient sensitive information from the hospital information system, the encryption method combining AES and RSA algorithms is adopted, which not only ensures the safety of the information body, but also protects the key through asymmetric encryption to prevent data leakage; the RFID wristband adopts medical-grade waterproof and anticorrosive material and anti-tear design, and the surface is printed with desensitized identification, which takes into account safety and practicality. Precisely deploy the read carder at the exit of the ward, adjust the installation parameters through multiple tests to ensure that the radio frequency signal fully covers the passage without adjacent interference, connect with the SPI bus and match the parameters, enable the hash check function to ensure stable data transmission. Optimize the antenna gain through multiple scene tests to improve the identification response speed and accuracy under different passing states, and realize the safe storage and reliable identification of identity information. This step breaks through the limitation that information security and identification efficiency cannot be considered in traditional management, lays a foundation for subsequent automatic permission verification and time recording, and meets the requirements of data security and process standardization for electronic medical record evaluation.

[0006] As preferred, when the patient approaches the exit, the card reader activates the RFID wristband corresponding chip and receives the encrypted identity information, and after decryption, the core identity data is extracted to check the exit permission, including the following steps: after the patient enters the card reader radio frequency coverage area, the passive RFID wristband chip in the wristband receives radio frequency energy to activate, and sends a response signal containing encrypted identity information and chip unique code to the card reader according to the preset protocol; after the card reader receives the response signal, the local stored decryption key is called to decrypt the encrypted information, and the data check value is calculated through the SHA-256 hash algorithm, and the integrity is verified by comparing the check field attached to the signal; after the check is passed, the patient medical record identification and wristband code are extracted, the data is packaged into a message format conforming to the HL7 protocol, and is transmitted to the access control main controller through an encrypted communication link; the main controller retrieves the current diagnosis and treatment plan of the patient from the hospital information system based on the medical record identification, extracts the exit examination item, planned departure time, expected return period and accompanying personnel information and other permission related data; combined with the current system time and diagnosis and treatment plan data, the permission is judged, if it is in the planned exit period and there is a valid examination appointment, it is marked as permission passed, otherwise the permission rejection reason is recorded and the early warning is triggered. In the application, through intelligent identity verification and diagnosis and treatment data linkage, the problems of inaccurate permission judgment and lack of deep linkage with the hospital information system are effectively solved. When the patient approaches the exit, the passive RFID wristband receives radio frequency energy to activate and sends encrypted information, the card reader decrypts and verifies the data integrity through the hash, packages the data according to the HL7 protocol and transmits it to the main controller, ensuring the standardization of information interaction. The main controller retrieves the diagnosis and treatment plan from the hospital information system based on the patient medical record identification, extracts the exit examination item, planned period and other data, and judges the permission combined with the current time, allowing only planned exit, avoiding random access by irrelevant personnel. This step realizes the deep binding of patient identity recognition, permission verification and diagnosis and treatment plan, breaks through the limitation of similar patents only limiting the exit range, accurately adapts to the management needs of ordinary hospital patient exit examination, not only guarantees the orderliness of patient exit, but also provides accurate plan data support for subsequent overtime judgment, meets the standardization requirements of electronic medical record evaluation on diagnosis and treatment process tracking.

[0007] As preferred, after the card reader receives the response signal, the decryption key stored locally is called to decrypt the encrypted information, and the data check value is calculated through the SHA-256 hash algorithm, and the integrity is verified by comparing the check field attached to the signal, including the following steps: after the built-in encryption processing module of the card reader receives the response signal, the unique code of the chip and the encrypted identity information are first separated, the legality of the wristband is confirmed through code matching; the RSA private key stored in the security chip is called to decrypt to obtain the AES symmetric key, and then the symmetric key is used to decrypt the identity information ciphertext to restore the original data plaintext; the decrypted plaintext data is calculated by using the SHA-256 hash algorithm to generate a fixed-length hash value, and the original hash check field attached in the response signal is extracted; the hash value calculated in real time is compared with the original check field bit by bit, and if they are completely consistent, it is determined that the data has not been tampered with, and the integrity check is passed; if they are inconsistent, the abnormal processing procedure is started, the error information and the current timestamp are recorded, and the data exception alarm is sent to the main controller, and the subsequent identity recognition process is refused. In the application, through the double decryption and hash check mechanism, the problem of tampering of data in the transmission process and unreliable identity information verification is effectively solved. After the card reader receives the signal, the chip code is separated to confirm the legality of the wristband, the RSA private key is decrypted to obtain the AES key, and then the identity information plaintext is restored, and the double encryption design greatly improves the information security. The SHA-256 hash algorithm is used to calculate the hash value of the plaintext, and the check field attached to the signal is compared bit by bit to ensure that the data has not been tampered with, and the integrity check is passed, and then the subsequent process can be entered; if they are inconsistent, the abnormal processing is started, the error information is recorded and an alarm is given, and the identity recognition is refused. This step builds a rigorous data security check system, breaks through the limitation of the traditional identification method lacking data integrity verification, guarantees the authenticity and reliability of the patient's identity information, provides a safe and reliable data basis for the subsequent processes such as permission determination and time recording, avoids management errors caused by data tampering, and further strengthens the standardization and safety of patient out-of-hospital management.

[0008] Preferably, the step of using the SHA-256 hash algorithm to calculate the decrypted plaintext data, generating a fixed-length hash value, and simultaneously extracting the original hash verification field attached to the response signal includes the following steps: standardizing the format of the decrypted plaintext data, removing redundant spaces and control characters to ensure the data format remains consistent with that before encryption; initializing the SHA-256 algorithm calculation environment, inputting the standardized plaintext data in blocks according to algorithm requirements, and sequentially performing message padding, hash value initialization, and iterative compression operations; generating a 256-bit hash value after the operation, and converting it to a hexadecimal string format for storage; extracting the original hash verification field from the extended field of the response signal, which is synchronously generated and attached by the hospital information system when writing to the wristband; and verifying the format of the extracted original verification field to confirm that it conforms to the hexadecimal string specification and has a length of 64 characters. If it does not conform, the verification is directly judged as a failure. This invention effectively solves the problems of inconsistent data formats and lack of reliable integrity verification through standardization and strict hash verification. Standardizing the format of the decrypted plaintext data, removing redundant spaces and control characters, ensures that the data remains consistent with that before encryption, avoiding verification deviations due to format differences. The SHA-256 algorithm environment is initialized, and the operation is performed in blocks according to the specifications to generate a 256-bit hash value, which is then converted into a hexadecimal string. Simultaneously, the original verification field pre-attached by the hospital information system is extracted from the response signal, and its format is rigorously verified to ensure compliance with hexadecimal specifications and length requirements; otherwise, the verification fails. This step constructs a dual-protection integrity verification system, overcoming the limitations of traditional, simplistic verification methods. It ensures that patient identity information is not tampered with during transmission, providing a reliable data foundation for subsequent processes such as permission determination and time recording. This further meets the standardized requirements for data accuracy and security in electronic medical record review and strengthens the rigor of patient out-of-town management.

[0009] Preferably, after the permission is granted, the ward exit time is recorded and synchronized to the hospital information system via an encrypted interface. The access control system drives the door lock to open by including the following steps: After the permission is granted, the main controller calls the built-in real-time clock module to obtain the current time accurate to the second, and stores this time as the ward exit time, associated with the patient's medical record identifier and wristband code; a ward exit record is generated according to a preset data format, including a basic information segment, a permission information segment, and a time information segment, wherein the basic information segment uses desensitization processing to hide sensitive data; the ward exit record is transmitted to the patient flow management submodule of the hospital information system through an encrypted data synchronization interface based on the SSL / TLS protocol, and end-to-end encryption is enabled during the transmission process to ensure security; after receiving the record, the hospital information system writes it into the patient's electronic medical record database through the I2C bus, updates the patient status field, and triggers the synchronization of the diagnosis and treatment process nodes; the main controller sends a level trigger signal to the access control actuator to drive the electromagnetic lock to power off and unlock, and at the same time controls the exit indicator light to change from red to green through the GPIO pin, recording the access control opening timestamp. This invention effectively solves the problems of non-standard ward exit time recording, insecure data transmission, and lack of deep integration with the hospital information system by accurately recording time and synchronizing encrypted data. After authorization, the main controller calls the real-time clock module to obtain the ward exit time accurate to the second, associates it with the patient's identifier, and stores it to achieve automated and accurate time recording, avoiding errors from manual recording. The generated ward exit record undergoes sensitive data anonymization processing and is synchronized to the hospital information system via an SSL / TLS encrypted interface. End-to-end encryption ensures data transmission security. After receiving the record, the system writes it to the electronic medical record database and updates the patient's status, triggering synchronization of the treatment process nodes. Simultaneously, the main controller drives the access control to unlock and controls the indicator light switching, recording the opening timestamp, forming a complete closed loop for ward exit initiation. This step achieves automated and standardized management of the ward exit process, overcoming the limitations of similar patents that lack deep integration with the hospital information system. It provides accurate data for subsequent timeout judgment and process traceability, meets the requirements of electronic medical record review for treatment process tracking, and is suitable for efficient management scenarios in comprehensive hospitals.

[0010] Preferably, the secondary identification by the card reader upon patient return, recording the return time to the ward and synchronizing data includes the following steps: After the patient returns to the ward and enters the card reader's identification range, the card reader repeats the identity recognition and data decryption process, finding the corresponding ward exit record through wristband code matching; after the main controller confirms identity matching and the existence of an outgoing record without a closed loop, it calls the real-time clock module again to obtain the current time and records it as the return time to the ward; the difference between the return time and the ward exit time is calculated to obtain the actual outgoing duration, and this duration is integrated with the round-trip timestamp and ward number to form a complete outgoing time record; the complete record is pushed to the hospital information system through an encrypted synchronization interface, and the system automatically associates the corresponding examination item information and supplements it to the outgoing management section of the patient's medical record; the hospital information system updates the patient's status and simultaneously triggers the duration statistics engine to compare and analyze the current outgoing duration with the historical average duration of the examination item. This invention effectively solves the problems of missing patient return records, inaccurate outgoing duration statistics, and insufficient linkage of medical data through secondary identification and complete data closure. When a patient returns, the card reader repeats the identity verification process, matching the wristband code with the corresponding ward exit record. The main controller records the return time and calculates the actual outing duration, integrating these into a complete outing time record. This record is synchronized to the hospital information system via an encrypted interface. The system automatically associates examination information, supplementing the patient's medical record, updating the patient's status, and triggering a duration statistics engine for comparison and analysis with historical average durations. This step achieves end-to-end data recording and linkage for patients' outings, overcoming the limitations of missing return records and scattered data in traditional management. It ensures accurate outing duration statistics, providing a reliable basis for subsequent overtime determination. Simultaneously, the deep linkage of medical data meets the standardized requirements of electronic medical record review for process tracking, allowing medical staff to clearly grasp the complete trajectory of patients' outings for examinations, improving management efficiency, and perfectly adapting to the closed-loop management needs of general hospitals for patients' outings for examinations.

[0011] Preferably, the actual outing duration is obtained by calculating the difference between the return time and the departure time. Integrating this duration with the round-trip timestamps and ward number to form a complete outing time record includes the following steps: Using a timestamp difference calculation method, the return time and departure time are converted to Unix timestamps, and the time difference in seconds is obtained by subtracting the values; the second-level time difference is converted to the actual outing duration in hour-minute-second format, and the percentage deviation from the preset standard duration of the examination item is calculated; the current ward number and card reader device identifier are retrieved from the configuration information stored in the main controller and associated with the round-trip timestamps, actual outing duration, and percentage deviation; the associated data is standardized to ensure that the data type and length of each field meet the reception requirements of the hospital information system; the fields are combined in a preset order to generate a complete outing time record, a record type identifier and data version number are added, and a record check code is generated using the CRC32 algorithm and appended to the end. This invention effectively solves the problems of non-standardized actual outing duration statistics, inconsistent data formats, and difficulty in adapting to hospital information systems through standardized duration calculation and complete data integration. The Unix timestamp difference calculation method is used to convert the return-to-ward and departure times into second-level time differences, and then into hour-minute-second format. Simultaneously, the percentage deviation from the standard duration is calculated to ensure accurate and intuitive duration statistics. Ward number, equipment identifier, and other information are retrieved and associated with round-trip timestamps, actual duration, and percentage deviation. After field normalization, complete records are generated in a preset order, and type identifiers, version numbers, and CRC32 checksums are added to ensure data integrity and identifiability. This step overcomes the limitations of traditional duration statistics methods, which are often crude and fragmented. It achieves standardized and structured integration of out-of-ward time data, ensuring that the data format meets the hospital information system's reception requirements. This provides standardized data support for subsequent anomaly detection and data traceability, meets the standardized requirements of electronic medical record review for process records, and improves the data standardization and usability of patient out-of-ward management in general hospitals.

[0012] Preferably, the process of generating a complete record of the outing period by combining the fields in a preset order, adding a record type identifier and a data version number, and generating a record check code by using the CRC32 algorithm and appending it to the end includes the following steps: Arranging the fields in the order of record type identifier - data version number - ward number - equipment identifier - ward exit timestamp - ward return timestamp - actual duration - deviation percentage; setting the record type identifier as a fixed character field for rapid classification and identification by the hospital information system; using a two-digit code for the data version number to identify the current data format version; initializing the CRC32 check algorithm, using the arranged field combination as input data, and performing check calculations to generate a 32-bit check code; converting the check code into an eight-digit hexadecimal string, appending it to the end of the record to form a complete data frame, and adding frame header and frame tail identifiers for data frame boundary identification.

[0013] The length of a complete data frame is checked. If it exceeds a preset transmission threshold, it is fragmented, and the fragment number and total number of fragments are marked to ensure transmission integrity. This invention effectively solves the problems of chaotic data frame formats, error-prone transmission, and low system recognition efficiency by standardizing field sorting and using multiple data verifications. Fields are arranged in a fixed order, with clear record type identifiers and data version numbers, facilitating rapid classification and format adaptation by the hospital information system and reducing the difficulty of data parsing. A CRC32 algorithm is used to generate a checksum and append it to the end of the record. Combined with frame header and footer identifiers, the data frame boundaries are defined to ensure that the data is not tampered with or lost during transmission. Data frames exceeding the transmission threshold are fragmented, and the fragment number and total number of fragments are marked to ensure the complete transmission of large volumes of data. This step constructs a standardized and highly reliable data transmission format system, overcoming the limitations of traditional data transmission lacking unified standards. It significantly improves the parsing efficiency and accuracy of data in the hospital information system, avoids data loss or parsing failure due to inconsistent formats, provides stable data linkage for the entire process of patient outpatient management, and further strengthens the standardization level of medical process records.

[0014] Preferably, the system compares the actual outing time with the planned examination time, determines anomalies based on overtime, and triggers tiered alarms, including the following steps: The hospital information system retrieves the preset standard duration and allowable fluctuation threshold for the patient's current examination from the treatment plan database. The threshold is set according to clinical guidelines based on the examination type; the difference between the actual outing time and the standard duration is calculated. If the absolute value of the difference exceeds the allowable fluctuation threshold, it is marked as a time anomaly, and the specific deviation value is recorded; the expected return time period in the examination plan is retrieved. If the current time has exceeded this time period and no return to the ward record has been detected, it is marked as an overtime non-return anomaly; the two anomaly marking results are integrated. If there is an overtime non-return anomaly, it is judged as a level one anomaly; if there is only a time anomaly, it is judged as a level two anomaly; a corresponding alarm command is generated according to the anomaly level and transmitted to the access control system through an encrypted communication link to trigger the corresponding level of alarm response mechanism. This invention effectively solves the problems of lack of overtime control, non-targeted alarms, and difficulty in adapting to the outing examination scenarios of patients in general hospitals in traditional management through accurate anomaly determination and tiered alarms. The hospital information system retrieves the preset standard duration of examination items and the allowable fluctuation threshold set by clinical guidelines, calculates the difference between the actual outing time and the standard duration, and marks the duration as abnormal. Simultaneously, it checks whether the expected return time has been exceeded and whether the patient has not returned, marking this as an overdue return abnormality. Integrating these two abnormal results, it determines the level of abnormality as either Level 1 (overdue return) or Level 2 (duration abnormality only), generating corresponding alarm commands to trigger the response mechanism. This step achieves refined and differentiated management of abnormal situations, breaking through the limitations of similar patents that only restrict the scope of outings. Through deep integration with the hospital information system, it accurately synchronizes the planned examination duration for overdue judgment, filling the gap in the management of overdue examinations for patients in ordinary hospitals. Tiered alarms allow medical staff to prioritize high-level abnormalities based on urgency, improving risk management efficiency, effectively preventing risks such as patient abortion and delayed treatment, and perfectly adapting to the multi-scenario, high-efficiency closed-loop patient management needs of comprehensive hospitals.

[0015] Preferably, the integration of the two abnormality marking results, where an overdue return anomaly is classified as a Level 1 abnormality and only a duration anomaly is classified as a Level 2 abnormality, includes the following steps: Retrieving the abnormality classification standard from the system configuration module, clarifying that Level 1 abnormalities correspond to emergency situations requiring immediate action, and Level 2 abnormalities correspond to general situations requiring routine verification; prioritizing overdue return anomaly markers, regardless of the presence of a duration anomaly marker, the anomaly is prioritized as a Level 1 abnormality; if only a duration anomaly marker exists, further verifying the deviation percentage, upgrading to Level 1 abnormality if the deviation exceeds twice the threshold, otherwise maintaining the Level 2 abnormality classification; associating the final abnormality level with the corresponding judgment criteria to generate an abnormality data packet containing patient identity information, abnormality type, level, and judgment criteria; encrypting the abnormality data packet and storing it in a local database, simultaneously generating a timestamp to provide data support for subsequent traceability. This invention effectively solves the problems of ambiguous alarm classification, unclear judgment criteria, and lack of traceability support in traditional alarm systems through refined abnormality classification and complete data retention. The system retrieves preset anomaly grading standards to clearly define the boundary between Level 1 emergency response and Level 2 routine checks. Overdue returns are prioritized and categorized as Level 1 anomalies. The grade is dynamically adjusted based on the percentage deviation in time; if the deviation exceeds twice the threshold, it is upgraded to Level 1, achieving precise grading of anomalies. The final anomaly grade is linked to the judgment criteria to generate an encrypted data packet containing patient identity, anomaly type, grade, and supporting data. This packet is stored in a local database and timestamped, providing complete data support for subsequent traceability. This step overcomes the limitations of similar patents that only provide general alarms based on risk levels. It constructs a dynamic grading mechanism based on actual out-of-hospital situations, making anomaly judgment more aligned with the management needs of patients undergoing out-of-hospital examinations in general hospitals. This ensures that emergencies are prioritized while avoiding excessive consumption of medical resources by routine anomalies. Furthermore, data retention meets the standardized requirements of electronic medical record review for process traceability, improving the standardization and traceability of management.

[0016] Preferably, the step of generating corresponding alarm commands based on the anomaly level and transmitting them to the access control system via an encrypted communication link to trigger the corresponding alarm response mechanism includes the following steps: The hospital information system generates alarm commands according to the anomaly level. Level 1 anomaly commands include an emergency handling procedure identifier, and Level 2 anomaly commands include routine verification prompts. The alarm commands are transmitted via a VPN-based encrypted tunnel, with end-to-end encryption technology ensuring that the commands are not stolen or tampered with during transmission. The access control main controller receives the alarm command, decrypts and verifies it, and extracts the anomaly level, patient information, and core handling prompts. The corresponding alarm configuration file is called according to the anomaly level; Level 1 anomalies are configured for audible and visual alarm linkage, and Level 2 anomalies are configured primarily for visual prompts. The main controller sends a trigger signal containing the anomaly level and patient information to the alarm module, initiating the corresponding alarm output process. This invention effectively solves the problems of insecure alarm command transmission and lack of differentiated response mechanisms through hierarchical command generation and secure transmission. The hospital information system generates dedicated alarm commands according to the anomaly level; Level 1 commands include an emergency handling procedure identifier, and Level 2 commands include routine verification prompts, achieving precise command adaptation. VPN encrypted tunnels and end-to-end encryption technology are used to transmit commands, eliminating the risk of theft or tampering during transmission and ensuring command security. Upon receiving the command, the access control main controller decrypts and verifies it, extracts the core content, and calls the corresponding alarm configuration file. Level 1 anomalies trigger audible and visual alerts, while level 2 anomalies primarily use visual prompts, forming a differentiated response mechanism. This process overcomes the limitations of traditional alarm commands being singular and lacking secure transmission, achieving hierarchical and secure transmission of alarm commands and differentiated responses. This allows medical staff to quickly identify the urgency of anomalies, improving handling efficiency, and adapts to the multi-scenario alarm management needs of general hospitals, enhancing the security and practicality of the entire control system.

[0017] Preferably, the main controller sends a trigger signal containing the abnormality level and patient information to the alarm module, and the corresponding alarm output process includes the following steps: After receiving the trigger signal, the alarm module analyzes the abnormality level. For a level one abnormality, a triple alarm is triggered: a full-screen warning on the nurse station display, a high-frequency buzzer, and a push notification from the mobile application. For a level two abnormality, only a pop-up window on the display and an application notification are triggered. The display output content is rendered: for level one abnormalities, patient information and abnormality type are highlighted on a red background; for level two abnormalities, a yellow background is used. The buzzer operating parameters are configured: for level one abnormalities, a three-short-one-long beeping pattern is played in a loop until a release command is received; for level two abnormalities, there is no sound alarm. The mobile application terminal identifiers of the patient's responsible nurse and attending physician are obtained through the hospital's internal communication server, and the alarm information is packaged according to a preset template. The alarm information is sent to the corresponding terminal using a push protocol to ensure real-time delivery of information, while recording the push time and terminal reception status. This invention effectively solves the problems of traditional alarm prompts being singular, information transmission being untimely, and medical staff response efficiency being low through multi-dimensional hierarchical alarm output. After the alarm module analyzes the anomaly level, a Level 1 anomaly triggers a triple alarm: a full-screen warning on the nurse station display, a high-frequency buzzer, and a push notification to the mobile app. A Level 2 anomaly only triggers a pop-up window and an app notification. This multi-channel approach, combining visual, auditory, and mobile terminal signals, ensures rapid response in emergencies. Level 1 anomalies are highlighted in red with the patient's information and accompanied by a looping buzzer with a specific beeping pattern. Level 2 anomalies are displayed against a yellow background, allowing medical staff to intuitively distinguish the level of urgency. Alarm information is accurately pushed to the mobile terminals of the patient's responsible nurse and attending physician, with push and reception status recorded to ensure no information is missed. This step overcomes the limitations of similar patented alarm methods, constructing a multi-layered, differentiated alarm output system. It ensures rapid response to emergencies while avoiding excessive interference from conventional alarms in the hospital environment, significantly improving the efficiency of medical staff and perfectly adapting to the closed-loop management needs of patients undergoing examinations outside the hospital in general hospitals.

[0018] Preferably, the process of receiving and processing alarm information by medical staff, followed by system updates of the processing results to complete closed-loop management, includes the following steps:

[0019] Medical staff receive alarm information via a mobile application. After confirming, the system records the reception time, and the application interface displays the patient's examination items, outing duration, and abnormality details. The responsible nurse goes to the scene or contacts the patient by phone to confirm the situation. If it is a misjudgment, an abnormality removal application is submitted in the application, specifying the reason. If an abnormality is confirmed, the handling procedure is initiated, contacting the examination department, security department, or family members as needed. After handling, the handling measures and results are recorded. Medical staff enter the handling results into the mobile application, and the system synchronizes them to the hospital information system and access control system via an encrypted interface. The hospital information system updates the closed-loop status of the patient's outing record, the access control system deactivates the alarm, and the handling results are archived along with the abnormal data, completing this closed-loop management. This invention effectively solves the problems of cumbersome abnormality handling procedures, lack of result traceability, and missing closed-loop management in traditional systems through convenient verification operations and full-process closed-loop management. Medical staff receive alarm information in real time via a mobile application. After confirmation, the system automatically records the reception time, and the interface intuitively displays the patient's examination items, outing duration, and abnormality details, allowing them to grasp core information without additional queries. The responsible nurse can confirm the patient's condition through on-site verification or telephone contact. In case of misjudgment, a termination application must be submitted with the reason noted. If an abnormality is confirmed, the handling procedure is initiated, coordinating with relevant departments, security departments, or family members. After the handling is completed, the measures and results are recorded in detail. The handling results are synchronized to the hospital information system and access control system via an encrypted interface. The system updates the closed-loop status, deactivates the alarm, and links the archives, forming a complete management closed loop. This step overcomes the limitations of similar patents that only focus on risk interception and lack subsequent closed-loop processing. It realizes fully automated management of the entire process of abnormality from discovery, verification, handling to archiving. This not only improves the handling efficiency of medical staff but also meets the standardized requirements of electronic medical record review for tracking the diagnosis and treatment process through complete recording. It is perfectly adapted to the closed-loop management needs of patients going out for examinations in general hospitals.

[0020] The second technical solution of the present invention: a closed-loop automated management system for patients leaving for examinations based on an intelligent access control system, used to execute the closed-loop automated management method for patients leaving for examinations based on an intelligent access control system as described above. This closed-loop automated management system for patients leaving for examinations based on an intelligent access control system includes an RFID identification module, an access control module, a data synchronization module, a tiered alarm module, and a hospital information interaction module.

[0021] The RFID identification module includes a medical tamper-proof RFID wristband and a high-sensitivity reader. The wristband has a built-in encrypted storage chip that uses AES and RSA encryption technology to store patient identification information. The reader is deployed at the ward exit and supports RFID activation, data decryption, and hash verification. It communicates with the access control module via an SPI bus. The access control module is based on an ARM processor and runs an embedded Linux system. It integrates a real-time clock module and an access control driver unit for identity information parsing, exit permission determination, access control, and entry / exit time recording. It has a built-in security chip to store the decryption key. The data synchronization module uses S... The SL / TLS encrypted transmission protocol, configured with an end-to-end encrypted interface, enables real-time synchronization of access control data with the hospital information system. It supports data fragmentation transmission and verification to ensure transmission security and integrity. The tiered alarm module includes a nurse station display screen, a buzzer, and a mobile terminal push component. It executes differentiated alarm responses based on the anomaly level, supports alarm confirmation, deactivation, and handling record functions, and links with the hospital communication server to achieve information push. The hospital information interaction module is a built-in submodule of the hospital information system, used for retrieving patient treatment plans, storing outpatient records, and archiving anomaly judgment and handling results. It provides data query, statistics, and traceability interfaces. This invention, through a modular collaborative architecture design, effectively solves the problems of poor adaptability, limited functionality, and insufficient data linkage in traditional management systems. The RFID tagging module uses a medical-grade tamper-proof wristband and a high-sensitivity card reader, employing combined encryption technology to ensure patient information security and achieve automatic identity recognition and data verification. The access control module, based on an ARM processor, integrates a multi-functional unit to complete permission determination, access control, and time recording, ensuring standardized entry and exit management. The data synchronization module uses SSL / TLS encryption protocols to achieve real-time secure synchronization of access control data with the hospital information system, supporting fragmented transmission and verification. The tiered alarm module ensures timely delivery of abnormal information through differentiated responses from multiple terminals. The hospital information interaction module enables retrieval of treatment plans, record storage, and traceability, constructing a complete data link. Each module performs its specific function while deeply interconnected, breaking through the limitations of similar patents that focus on specific hospital scenarios. Designed specifically for patients in general hospitals undergoing outpatient examinations, it achieves full-process automation of identity recognition, access control, time recording, abnormal alarms, and closed-loop handling. This not only meets the standardized requirements of electronic medical record review but also improves management efficiency and security, adapting to the multi-scenario, high-efficiency management needs of general hospitals.

[0022] The following benefits are achieved: (1) By configuring secure identification and deploying full-coverage equipment, the problems of insufficient security and incomplete identification range of traditional patient identification are effectively solved. Patients are equipped with RFID wristbands with built-in encrypted identity information. AES and RSA combined encryption technology is used to store sensitive information such as medical record identification and name. The wristbands are made of medical-grade waterproof, anti-corrosion and tear-resistant material, and the surface is printed with desensitized identification and emergency information, which not only ensures information security but also takes into account practicality. A card reader with full coverage of radio frequency identification is deployed at the ward exit. The installation height and angle are adjusted through multiple tests to avoid signal interference from adjacent channels. At the same time, the wristband communication parameters are matched and the hash verification function is enabled. The antenna gain is optimized through multi-scenario testing to ensure that patients of different body types can be quickly identified when passing through at different speeds. This step breaks through the limitations of traditional identification methods that are prone to information leakage and unstable identification. It builds a secure and reliable identity recognition foundation, provides hardware support for subsequent automated permission verification and time recording, meets the data security requirements of electronic medical record review, and is suitable for the management scenario of patients going out for examinations in general hospitals. (2) By intelligent identity decryption and linkage verification of diagnosis and treatment data, the problems of lack of basis for permission judgment and insufficient linkage with the hospital information system are effectively solved. When the patient approaches the exit, the passive RFID wristband receives the radio frequency energy of the card reader to activate and send encrypted information. The card reader restores the data through double decryption, and ensures the integrity of the data through SHA-256 hash verification. After being encapsulated according to the HL7 protocol, it is transmitted to the main controller. The main controller retrieves the diagnosis and treatment plan from the hospital information system based on the patient's medical record identifier, extracts data such as out-of-hospital examination items and planned time periods, and determines the permission based on the current time, allowing only reasonable outings within the plan. This step realizes the deep binding of patient identity recognition and diagnosis and treatment plan, breaks through the limitation of similar patents that only restrict the scope of outings, avoids unauthorized personnel from entering and leaving at will, ensures the standardization and rationality of permission judgment, provides accurate plan data for subsequent time recording and overtime judgment, meets the requirements of electronic medical record review for linkage of diagnosis and treatment process, and improves the accuracy of patient outing management in general hospitals. (3) By automating time recording and encrypting data synchronization, the problems of non-standard ward exit time recording, insecure data transmission, and lack of system linkage are effectively solved. After authorization, the main controller calls the real-time clock module to obtain the patient's departure time accurate to the second, associates it with the patient's identifier, and stores it to avoid errors from manual recording. The generated departure record undergoes sensitive data anonymization processing and is synchronized to the hospital information system via an SSL / TLS encrypted interface. End-to-end encryption ensures secure transmission. Upon receiving the record, the system writes it to the electronic medical record database and updates the patient's status, triggering synchronization of the treatment process nodes. Simultaneously, the main controller drives the access control to unlock and controls the indicator light switching, recording the opening timestamp, forming a complete closed loop for departure initiation.This step breaks through the limitations of fragmented data records and unreliable transmission in traditional management, realizes the automation and standardization of the ward exit process, allows the hospital information system to keep track of the patient's outing dynamics in real time, provides accurate data for subsequent overtime judgment and process traceability, and meets the standardization requirements of electronic medical record review for process records. (4) Through secondary identification and complete data integration, the problems of missing patient return records and non-standard statistics of outing time are effectively solved. When the patient returns, the card reader repeats the identity recognition and data decryption process, matches the corresponding ward exit record through the wristband code, and the main controller records the return time after confirming the identity, calculates the actual outing time, and integrates the round-trip timestamp, ward number and other information to generate a complete record. The record is synchronized to the hospital information system through the encrypted interface. The system automatically associates the examination item information, supplements the patient's diagnosis and treatment record, updates the patient status and triggers the time statistics engine, and compares and analyzes it with the historical average time. This step realizes the closed-loop data of the entire process of patients going out from "out" to "back", breaking through the limitation of missing return records in traditional management, ensuring accurate statistics of outing time, providing a reliable basis for subsequent abnormal judgment, and at the same time, through deep linkage with the hospital information system, it meets the requirements of electronic medical record review for full tracking of the diagnosis and treatment process, allowing medical staff to clearly grasp the complete trajectory of patients going out for examinations. (5) Through accurate abnormal judgment and graded alarm, the problems of lack of overtime control and non-targeted alarm in traditional management are effectively solved. The system retrieves the preset standard time of examination items and the allowable fluctuation threshold set by clinical norms from the hospital information system, calculates the difference between the actual outing time and the standard time, and marks the time abnormality; at the same time, it checks whether the expected return time is exceeded and has not returned, and marks the overtime non-return abnormality. The two abnormal results are integrated to determine the first level (overtime non-return) and the second level (only time abnormality) abnormality level, generate corresponding alarm instructions, and trigger differentiated alarm responses through multiple channels such as nurse station display screen, buzzer, and mobile application. This step breaks through the limitations of similar patents that only focus on risk interception. By deeply linking with the hospital information system, it accurately synchronizes the examination plan duration for overtime judgment, filling the gap in the management of patients' overtime examinations outside the hospital. The graded alarm allows medical staff to prioritize the handling of high-level abnormalities according to the urgency, improves the efficiency of risk handling, effectively prevents risks such as patients getting lost and delaying treatment, and adapts to the management needs of multiple scenarios in general hospitals. (6) Through convenient verification and closed-loop management, it effectively solves the problems of cumbersome traditional abnormal handling process, lack of traceability of results, and lack of closed loop. Medical staff receive alarm information in real time through mobile application. After confirmation, the system records the receiving time. The interface intuitively displays the patient's examination items, outing duration and abnormal details, making it easy to quickly grasp the core information. The responsible nurse can confirm the situation through on-site verification or telephone contact. If a misjudgment is made, a release application is submitted and the reason is noted. If there is an abnormality, the relevant departments, security departments or family members are linked to handle it. After completion, the measures and results are recorded.The processing results are synchronized to the hospital information system and access control system via an encrypted interface. The system updates the closed-loop status, deactivates the alarm, and archives the data, forming a complete management chain. This step overcomes the limitations of similar patents that only focus on risk interception and lack subsequent closed-loop processing. It realizes full-process management of anomalies from discovery, verification, handling to archiving, which not only improves the efficiency of medical and nursing care, but also meets the standardized requirements of electronic medical record review for process traceability through complete records. It is perfectly adapted to the closed-loop management needs of patients going out for examinations in general hospitals. Attached Figure Description

[0023] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 This is a flowchart illustrating the steps of the closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system, as described in this invention. Figure 2 This is a schematic diagram of the process framework of the closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to the present invention; Figure 3 This is a schematic diagram of the modules of the closed-loop automated management system for patients going out for examinations based on the intelligent access control system of the present invention. Detailed Implementation

[0024] The present invention will be further described below with reference to the accompanying drawings and embodiments, but this should not be construed as limiting the present invention.

[0025] Please see Figures 1-2 A closed-loop automated management method for patient out-of-hospital examinations based on an intelligent access control system includes the following steps: S01: Configuring patients with RFID wristbands containing built-in encrypted identity information, and deploying card readers with full RFID coverage at the ward exit; In this embodiment of the invention, core information such as patient medical record identifiers, names, allergy history, and treatment plans are extracted from the hospital information system, the information body is encrypted using the AES-256 algorithm, and the AES key is encrypted using the RSA-2048 algorithm. The encrypted ciphertext and key are integrated and written into the built-in chip of the RFID wristband. The wristband is made of medical-grade tear-resistant silicone material with an IP68 waterproof rating. The surface is laser-engraved with desensitized markings and an emergency telephone number, and a unique channel number is set via a DIP switch. A card reader is deployed at a height of 1.2 meters along the central axis of the ward exit channel. The antenna angle is adjusted to ensure that the RFID coverage reaches the full width of the 1.5-meter channel, and the identification distance is controlled between 0.3 and 0.8 meters. It is connected to the access control module via an SPI bus, configured with a working frequency of 13.56MHz and a baud rate of 115200bps to ensure accurate and interference-free identity recognition.

[0026] S02: When the patient approaches the exit, the card reader activates the corresponding chip on the RFID wristband and receives encrypted identity information. After decryption, it extracts core identity data to verify exit permissions. In this embodiment of the invention, after the patient enters the reader's radio frequency range wearing the RFID wristband, the passive chip is activated by sensing radio frequency energy and sends encrypted identity information and the chip's unique code according to the ISO15693 protocol. After receiving the signal, the card reader calls the RSA private key in the built-in security chip to decrypt the AES key, and then restores the plaintext data using the AES key. The data integrity is confirmed by SHA-256 hash verification. The patient's medical record identifier is extracted and transmitted to the access control module through an encrypted link. The module retrieves the treatment plan from the hospital information system based on this identifier, compares the current time with the planned exit time and valid examination appointment records. If the current time is within the planned time and the appointment is valid, the exit permission is granted; otherwise, it is denied and the reason for denial is recorded.

[0027] S03: After authorization, the ward time is recorded and synchronized to the hospital information system via an encrypted interface, and the access control system drives the door lock to open.

[0028] In this embodiment of the invention, after authorization, the access control module calls the real-time clock module to record the ward time (accurate to the second), and stores it in association with the patient's identification and wristband code. Through an SSL / TLS 1.3 encrypted interface, the ward exit time, anonymized patient identity information, and examination item names are synchronized to the hospital information system. The system updates the patient's status to "out for examination" and triggers synchronization of the treatment process nodes. Simultaneously, the module sends a 3.3V high-level signal to the access control actuator, driving the electromagnetic lock to power off and unlock. The door lock opening delay does not exceed 100ms, the exit indicator light changes from red to green, and the module synchronously records the access control opening timestamp, forming a complete exit record.

[0029] S04: Upon patient return, the card reader performs secondary identification, records the return time to the ward, and synchronizes the data. In this embodiment of the invention, after the patient completes the examination and returns to the ward, upon entering the card reader's identification range, the card reader repeats the identity activation, data decryption, and verification process, matching the locally stored unclosed-loop ward exit record using the wristband's unique code. After confirming identity matching, the access control module calls the real-time clock module to record the return time to the ward and calculates the actual outing duration (the difference between the return time and the exit time), accurate to the minute. The return time, actual outing duration, and ward number are integrated into a complete return record, which is pushed to the hospital information system through an encrypted synchronization interface. The system associates the examination item information, adds it to the outing management section of the patient's medical record, and updates the patient's status to "in-hospital."

[0030] S05: The system compares the actual outing time with the planned examination time, determines an anomaly based on the timeout situation, and triggers a tiered alarm. In this embodiment of the invention, the hospital information system retrieves the preset standard duration (e.g., 40 minutes) and the 20% allowable fluctuation threshold (32-48 minutes) for the examination item from the treatment plan database, and compares the actual outing time with the standard duration. If the actual duration exceeds the threshold (e.g., 50 minutes), it is marked as a duration anomaly; if the current time exceeds the expected return period and there is no return record, it is marked as an overdue return anomaly. The anomaly level is determined by priority: if there is an overdue return anomaly, it is a level one anomaly; if there is only a duration anomaly, it is a level two anomaly. A corresponding alarm command is generated and transmitted to the access control system through a VPN encrypted tunnel. Level one anomalies trigger audible and visual alarms and multi-terminal push notifications, while level two anomalies only trigger visual prompts and nurse station notifications.

[0031] S06: After receiving the alarm information, medical staff verify and process it, and the system updates the processing results to complete closed-loop management. In this embodiment of the invention, medical staff receive alarm information through a mobile application. After clicking to confirm, the system records the receiving time, and the application interface displays the patient's examination items, duration of absence, and abnormal details. The responsible nurse verifies the situation: if a misjudgment is made, a cancellation application is submitted with the reason noted; if an abnormality is confirmed, the handling procedure is initiated (contacting the examination department, security, or family members). After the handling is completed, medical staff enter the processing results, and the system synchronizes them to the hospital information system and access control system through an encrypted interface. The hospital information system updates the closed-loop status record, the access control system deactivates the alarm, and the processing results are associated with the abnormal data and archived, generating a complete closed-loop record containing the handling personnel, time, and measures, supporting subsequent query and traceability, and completing this management process.

[0032] The process of equipping patients with RFID wristbands containing built-in encrypted identity information and deploying RFID readers with full coverage at ward exits involves the following steps: Retrieving patient medical record identifiers, names, allergy history, and sensitive information corresponding to the current treatment plan from the hospital information system; processing the data using a combination of symmetric and asymmetric encryption, encrypting the information itself using the AES algorithm, and protecting the symmetric key using the RSA algorithm; writing the encrypted complete data into a passive RFID wristband chip, the chip being packaged in a medical-grade waterproof and corrosion-resistant material and integrally molded with the tear-resistant wristband; printing desensitized identity information and emergency contact information on the wristband surface; and deploying RFID readers with full coverage at the ward exit. A card reader is installed at the central axis position. Through multiple tests, the installation height and angle are adjusted to ensure that the radio frequency signal covers the channel width and the identification distance is controlled within a reasonable range, avoiding signal interference from adjacent channels. The card reader is connected to the ARM main controller of the access control system via an SPI bus. The card reader's operating frequency and data transmission baud rate are configured to match the communication parameters of the wristband chip. Simultaneously, the card reader's built-in hash verification function is enabled to ensure data integrity. Simulations are conducted simulating scenarios where patients of different body types wear the wristband and pass through at different speeds. The identity recognition response time and accuracy are recorded, and the antenna gain is adjusted for recognition delays exceeding thresholds or false recognitions. In this embodiment of the invention, core sensitive patient information is extracted from the hospital information system, including an 18-digit medical record identifier, name (de-anonymized to surname + asterisk), three types of allergy history (drug, food, and contact allergies), and current treatment plan (including examination items, medication plan, and nursing level), ensuring that the information completely covers the needs of identity recognition and security management. A dual-layer encryption scheme combining symmetric and asymmetric encryption is employed: the information itself is encrypted using the AES algorithm (256-bit key length, CBC encryption mode) to generate fixed-length ciphertext data; simultaneously, a random AES symmetric key is generated and encrypted using the RSA algorithm (2048-bit key length) to prevent key leakage during transmission. The encrypted AES ciphertext, RSA encryption key, and data length identifier are integrated into a complete data packet and written to a passive RFID wristband chip using a dedicated card writing device. The chip has a storage capacity of at least 4KB and supports more than 100,000 read / write operations. The wristband chip is encapsulated in medical-grade silicone material with IP68 waterproof and corrosion-resistant properties, and is integrally injection molded with a tear-resistant nylon wristband. The wristband's tensile strength at break is no less than 50N to prevent accidental dislodgement or deliberate removal by the patient. The wristband surface is laser-engraved with a desensitized identification identifier (last 6 digits of the medical record identifier + the first character of the patient's name) and the hospital's emergency contact number to prevent the leakage of private information. A card reader is installed at the center axis of the ward exit corridor. The card reader is wall-mounted and the installation height is fixed at 1.2 meters. The vertical angle between the card reader and the corridor floor is 90 degrees. The antenna angle is adjusted through multiple signal tests to ensure that the radio frequency signal covers the entire width of the corridor (not less than 1.5 meters). The identification distance is strictly controlled within the range of 0.3-0.8 meters.The card reader's data pins are connected to the corresponding pins of the ARM main controller of the access control system via the SPI bus. The card reader's operating frequency is configured to 13.56MHz (compliant with ISO15693 standard), and the data transmission baud rate is set to 115200bps, perfectly matching the communication parameters of the RFID wristband chip. The card reader's built-in hash verification function is enabled to generate check codes for transmitted data in real time, ensuring data transmission integrity. Three different body types of patients (weighing 40kg, 70kg, and 100kg) wearing wristbands are simulated, passing through the exit channel at speeds of 0.3m / s, 0.5m / s, and 0.8m / s respectively. This is tested 100 times consecutively, recording the identification response time and accuracy. The response time threshold is set to 300ms, and the accuracy threshold to 99.5%. If the response time exceeds the threshold, the antenna gain is increased via the card reader configuration software (in 1dB increments). If false identification occurs (e.g., identifying another patient's wristband), the antenna gain is reduced and the signal shielding design is optimized until the test data meets the preset standards.

[0033] When a patient approaches the exit, the card reader activates the corresponding chip on the RFID wristband and receives encrypted identity information. After decryption, the core identity data is extracted to verify the patient's exit permission, which includes the following steps: After the patient enters the card reader's radio frequency coverage area, the passive RFID wristband chip inside the wristband is activated by receiving radio frequency energy and sends a response signal containing encrypted identity information and the chip's unique code to the card reader according to a preset protocol. After receiving the response signal, the card reader calls the locally stored decryption key to decrypt the encrypted information, calculates the data verification value using the SHA-256 hash algorithm, and compares it with the verification field attached to the signal to verify integrity. After successful verification, the patient's medical record identifier and wristband code are extracted, and the data is encapsulated into a message format conforming to the HL7 protocol and transmitted to the access control main controller through an encrypted communication link. The main controller retrieves the patient's current treatment plan from the hospital information system based on the medical record identifier, extracting permission-related data such as out-of-home examination items, planned departure time, expected return time, and accompanying personnel information. The main controller combines the current system time and treatment plan data to determine permission. If the patient is within the planned out-of-home time and has a valid examination appointment, the permission is marked as granted; otherwise, the reason for permission denial is recorded and an early warning is prepared. In this embodiment of the invention, after a patient enters the radio frequency coverage area of ​​the card reader at the ward exit by wearing an RFID wristband, the passive RFID chip inside the wristband senses the radio frequency energy emitted by the card reader through its antenna, instantly generating a working voltage (3.3V) and activating the chip's internal communication module. The chip sends a response signal to the card reader according to the ISO15693 communication protocol. The signal contains two core data parts: encrypted patient identity information (AES ciphertext + RSA encryption key) and a unique chip code (64-bit binary number, factory-fixed and unmodifiable). The signal transmission power is controlled within 10mW to avoid electromagnetic interference to surrounding medical equipment. After receiving the response signal, the card reader first uses its built-in encryption processing module to call the decryption key stored in its local security chip to decrypt the RSA-encrypted AES key, obtaining the original AES symmetric key; then, it uses this AES key to decrypt the ciphertext of the identity information, restoring the original data such as the patient's medical record identifier and allergy history. Simultaneously, the decrypted plaintext data is processed using the SHA-256 hash algorithm to generate a fixed-length 256-bit hash value. This value is then compared bit-by-bit with the original hash verification field attached to the response signal. If they match completely, the data is deemed untampered and the integrity verification passes. If they do not match, the process is immediately terminated, and a data anomaly alarm is sent to the main controller. After successful verification, the card reader extracts the patient's 18-digit medical record identifier and the chip's unique code, encapsulates the data according to the message format specified in the HL7 protocol, with the message header containing a data type identifier and a transmission timestamp, the message body containing structured identity data, and a checksum appended to the message tail. The encapsulated message is transmitted to the access control main controller via an SSL encrypted communication link (TLS 1.3 protocol), with a data transmission rate of no less than 1 Mbps to ensure real-time data transmission.After receiving the message, the main controller initiates a data query request through the hospital information system interface based on the patient's medical record identifier. It retrieves the patient's current treatment plan, focusing on extracting relevant data such as outpatient examination items (e.g., CT scan, blood routine test), planned departure time (accurate to the minute), estimated return time (error not exceeding 30 minutes), and information of accompanying persons (name, contact information, relationship to the patient). The main controller compares the current system time (synchronized with the hospital information system time, error not exceeding 10 seconds) with the planned departure time and estimated return time in the treatment plan. If the current time falls within the planned outpatient time and a valid examination appointment record for the patient exists in the hospital information system (not canceled, not expired), the access is granted, and an open signal is sent to the access control mechanism. Otherwise, the reason for access denial is recorded (e.g., "exceeded planned return time" or "no valid examination appointment"), and an audible and visual alarm and reminder to medical staff are prepared.

[0034] After receiving the response signal, the card reader calls the locally stored decryption key to decrypt the encrypted information. It then calculates a data checksum using the SHA-256 hash algorithm and compares it with the checksum field attached to the signal to verify integrity. The steps include: The card reader's built-in encryption module, upon receiving the response signal, first separates the chip's unique code from the encrypted identity information, confirming the wristband's legitimacy through code matching; it then calls the RSA private key stored in the security chip to decrypt and obtain the AES symmetric key, which is used to decrypt the encrypted identity information, restoring the original plaintext data; the SHA-256 hash algorithm is used to calculate a fixed-length hash value on the decrypted plaintext data, while simultaneously extracting the original hash checksum field attached to the response signal; the real-time calculated hash value is compared bit-by-bit with the original checksum field. If they match completely, the data is determined not to have been tampered with, and the integrity verification passes; if they do not match, an exception handling process is initiated, recording the error information and the current timestamp, and simultaneously sending a data anomaly alarm to the main controller, rejecting subsequent identity verification processes. In this embodiment of the invention, after receiving the response signal sent by the RFID wristband through the encryption processing module built into the card reader, the signal is first demodulated and decoded to separate the two parts of data: the unique chip code and the encrypted identity information. The unique chip code is queried through the local database to verify whether the code has been bound to the patient information in the hospital information system and whether the wristband status is "in use" (not reported lost, not cancelled). If the code is not bound or the status is abnormal, the wristband is directly determined to be invalid, the subsequent decryption process is rejected, and the illegal chip code and the current timestamp are recorded. If the wristband code is valid, the encryption processing module calls the RSA private key stored in the dedicated security chip (hardware encryption, anti-cracking) to decrypt the RSA encryption key in the encrypted identity information. The decryption process is completed in the hardware encryption engine to avoid exposing the key at the software level. After obtaining the original AES symmetric key, the key is used in AES-256-CBC decryption mode to decrypt the encrypted identity information, restoring the complete plaintext data such as the patient's medical record identifier, name, allergy history, and treatment plan. The decryption process takes less than 50ms to ensure a rapid response. After decryption, the encryption module initiates the SHA-256 hash algorithm to perform hash calculations on the decrypted plaintext data. It iterates through each byte of data, generating a 256-bit hash value using the fixed hash function of the SHA-256 algorithm, strictly adhering to the FIPS 180-4 standard. Simultaneously, the original hash check field (the SHA-256 hash value calculated on the plaintext data before encryption, transmitted along with the ciphertext) is extracted from the response signal. The real-time calculated hash value is then compared bit-by-bit with the original check field, from the most significant bit to the least significant bit, verifying each binary digit individually.If all bits are completely identical, it is determined that the data has not been tampered with during transmission, the integrity verification passes, and the encryption processing module sends a verification pass signal to the card reader's main control unit, allowing the subsequent permission determination process to continue. If any bit is inconsistent, the exception handling process is immediately initiated, and error information (details of hash value mismatch, chip code, transmission timestamp) is recorded in the local log. At the same time, a data exception alarm is sent to the access control main controller via the SPI bus. The alarm signal includes an error code and relevant context data. The card reader refuses to perform subsequent identity recognition and access control operations and keeps the access control in the closed state.

[0035] The SHA-256 hash algorithm is used to calculate the hash value of the decrypted plaintext data, generating a fixed-length hash value. Simultaneously, the original hash verification field attached to the response signal is extracted. The process includes the following steps: Standardizing the format of the decrypted plaintext data, removing redundant spaces and control characters to ensure the data format remains consistent with that before encryption; initializing the SHA-256 algorithm calculation environment, inputting the standardized plaintext data in blocks according to the algorithm requirements, and sequentially performing message padding, hash value initialization, and iterative compression operations; generating a 256-bit hash value after the operation, and converting it to a hexadecimal string format for storage; extracting the original hash verification field from the extended field of the response signal, which is generated and attached synchronously by the hospital information system when writing to the wristband; and verifying the format of the extracted original verification field to confirm that it conforms to the hexadecimal string specification and is 64 characters long. If it does not conform, the verification is directly deemed a failure. In this embodiment of the invention, the decrypted plaintext data undergoes format standardization processing. A character filtering algorithm removes redundant spaces (including leading and trailing spaces and invalid spaces in the middle), tabs, newlines, and other control characters. Simultaneously, the data is rearranged according to a preset field order (medical record identifier → name → allergy history → treatment plan) to ensure the data format is completely consistent with the original format written to the wristband by the hospital information system, avoiding hash calculation deviations due to format differences. The SHA-256 algorithm calculation environment is initialized, the algorithm's working mode is configured to standard hash mode, and additional extension functions are disabled. The standardized plaintext data is split into 512-bit blocks. For blocks shorter than 512 bits, bits are padded according to the SHA-256 algorithm padding rules (first padding with one 1-bit, then several 0-bits, and finally adding the original data length identifier). Iterative compression operations are performed on each data block sequentially: first, a Boolean operation is performed between the data block and the current hash value; then, the hash value is updated through 64 rounds of cyclic shifting, XOR, and other operations. Each round of operation strictly follows the fixed function formula and constant parameters of the SHA-256 algorithm to ensure compliance during the calculation process. After all data block operations are completed, a 256-bit binary hash value is generated. This hash value is then converted into a 64-character hexadecimal string (each 4 binary bits correspond to one hexadecimal character) using an encoding conversion algorithm and stored in the reader's temporary buffer. The original hash verification field is extracted from the extended field of the response signal (bytes 3-66 of the signal frame). This field is generated and appended by the hospital information system when writing to the wristband chip, using the same SHA-256 algorithm for the same plaintext data, and is stored synchronously with the encrypted identity information. The extracted original verification field undergoes format verification: first, it checks if the character length is 64 characters; then, it verifies each character to ensure it belongs to the 0-9, AF hexadecimal character set. If the length is incorrect or contains illegal characters, the data integrity verification fails, triggering the exception handling process.

[0036] After authorization, the time of leaving the ward is recorded and synchronized to the hospital information system via an encrypted interface. The access control system drives the door lock to open through the following steps: After authorization is granted, the main controller calls the built-in real-time clock module to obtain the current time accurate to the second, and stores this time as the ward exit time, associated with the patient's medical record identifier and wristband code; a ward exit record is generated according to a preset data format, including basic information, authorization information, and time information, with the basic information section using desensitization to hide sensitive data; the ward exit record is transmitted to the patient flow management submodule of the hospital information system through an encrypted data synchronization interface based on the SSL / TLS protocol, with end-to-end encryption enabled during transmission to ensure security; after receiving the record, the hospital information system writes it to the patient's electronic medical record database via the I2C bus, updates the patient status field, and triggers the synchronization of the diagnosis and treatment process nodes; the main controller sends a level trigger signal to the access control actuator to drive the electromagnetic lock to power off and unlock, and simultaneously controls the exit indicator light to change from red to green via GPIO pins, recording the access control opening timestamp. In this embodiment of the invention, the main controller calls the built-in real-time clock module to obtain the current time the moment the permission is approved. The time format is accurate to the second (year-month-day hour:minute:second). This time is used as the patient's ward departure time and is bound to the 18-digit medical record identifier and the 64-digit wristband chip unique code through an association algorithm to form core record data. The ward record is generated according to the preset structured data format: the basic information segment includes the anonymized medical record identifier (last 6 digits), the first character of the name + asterisk, and the ward number, hiding sensitive data such as the full name and detailed allergy history; the permission information segment includes the name of the outpatient examination, the planned departure time, and the permission judgment result (approved / rejected); the time information segment includes the ward departure timestamp and the record generation timestamp. The three data segments are concatenated with a separator, and the total length is fixed at 256 bytes. The ward exit record is transmitted to the patient flow management submodule of the hospital information system via an encrypted data synchronization interface based on the TLS 1.3 protocol. The interface adopts a two-way authentication mechanism, with the main controller and the hospital information system verifying the legitimacy of each other's digital certificates. The transmitted data is encrypted with AES-256 before being sent, and the receiving end decrypts it before processing to ensure end-to-end data security. After receiving the record, the hospital information system writes the data to a designated data table in the patient's electronic medical record database via the I2C bus (the table structure includes fields such as medical record identifier, wristband code, ward exit time, examination items, and permission status). At the same time, the patient status field is updated to "out for examination", triggering the diagnosis and treatment process node synchronization mechanism, and pushing the ward exit record to the corresponding nurse station workstation, attending physician terminal, and examination department system.The main controller sends a high-level trigger signal (3.3V, lasting 500ms) to the access control actuator, driving the internal coil of the electromagnetic lock to de-energize and the latch to open, thus unlocking the door. At the same time, the controller outputs a control signal through the GPIO pin to switch the red prohibition indicator light at the exit to a green passage indicator light. The indicator light switching delay is no more than 100ms. The main controller synchronously records the access control opening timestamp and stores it in association with the ward exit timestamp to form a complete access control operation record.

[0037] The process of a card reader performing secondary identification upon a patient's return, recording the return time to the ward, and synchronizing data includes the following steps: After the patient returns to the ward and enters the card reader's recognition range, the card reader repeats the identity recognition and data decryption process, matching the wristband code to find the corresponding ward exit record; after the main controller confirms the identity match and the existence of an outgoing record that is not closed-loop, it calls the real-time clock module again to obtain the current time and records it as the return time to the ward; the difference between the return time and the outgoing time is calculated to obtain the actual outgoing duration, and this duration is integrated with the round-trip timestamp and ward number to form a complete record of the outgoing time period; the complete record is pushed to the hospital information system through an encrypted synchronization interface, and the system automatically associates the corresponding examination item information and supplements it to the outgoing management section of the patient's medical record; the hospital information system updates the patient's status and simultaneously triggers the duration statistics engine to compare and analyze the current outgoing duration with the historical average duration of the examination item. In this embodiment of the invention, after a patient completes an examination and returns to the ward, upon entering the radio frequency coverage area of ​​the exit card reader, the card reader repeats the identity recognition process: activating the wristband chip, receiving the response signal, decrypting the identity information, and performing SHA-256 hash verification. All steps are completely consistent with the exit process, ensuring accurate identity recognition. The card reader queries the local cache using the unique code of the wristband chip. If a previously stored unclosed-loop exit record is found (i.e., a record that records the exit time but not the return time), the identity matching result is transmitted to the main controller along with the exit record. If no corresponding record is found or the record is already closed-loop, the access denial process is applied. After confirming identity matching and the existence of an unclosed-loop exit record, the main controller again calls the real-time clock module to obtain the current time (accurate to the second), records it as the patient's return time, and calculates the interval between the return time and the exit time using a time difference algorithm to obtain the actual exit duration (unit: minutes). The duration calculation is accurate to the integer part, with any fraction of a minute counted as a full minute. The actual duration of absence, ward exit timestamp, ward return timestamp, ward number, and examination item name are integrated into a complete record of the absence period, which is then added to the original ward exit record to form closed-loop management data. New fields added to the record include return status (normal return / timeout return) and actual absence duration. The data format remains structured for easy system parsing. The complete closed-loop record is pushed to the hospital information system via the same encrypted synchronization interface (TLS 1.3 protocol) used for absences. Upon receiving the record, the system automatically associates it with the corresponding examination item information (examination result status, examination department feedback) through the medical record identifier, adding the complete record to the absence management section of the patient's electronic medical record and linking it to the treatment record.The hospital information system updates the patient's status from "out for examination" to "in hospital" and triggers the duration statistics engine to extract the historical average out-of-hospital time for the examination item over the past 3 months (calculated from the out-of-hospital time of similar patients with the same examination item in the statistical database). The system compares and analyzes the patient's actual out-of-hospital time with the historical average time. If it exceeds the average time by more than 30%, it is marked as an abnormal time and a reminder notification is sent to the nurse station.

[0038] The actual outing duration is calculated by determining the difference between the return time and the departure time. This duration, along with the round-trip timestamps and ward number, is then integrated into a complete record of the outing period. The steps include: using a timestamp difference calculation method, converting the return and departure times to Unix timestamps, and subtracting the values ​​to obtain the time difference in seconds; converting the second-level time difference to the actual outing duration in hour-minute-second format, and calculating the percentage deviation from the preset standard duration of the examination item; retrieving the current ward number and card reader device identifier from the configuration information stored in the main controller, and associating them with the round-trip timestamps, actual outing duration, and percentage deviation; performing field normalization on the associated data to ensure that the data type and length of each field meet the reception requirements of the hospital information system; combining the fields in a preset order to generate a complete record of the outing period, adding a record type identifier and data version number, and generating a record checksum using the CRC32 algorithm and appending it to the end. In this embodiment of the invention, the timestamp difference calculation method is used. First, the time of leaving the ward (e.g., 2024-12-07 09:30:15) and the time of returning to the ward (e.g., 2024-12-07 10:15:30) are converted into Unix timestamps, that is, the number of seconds from 00:00:00 UTC on January 1, 1970 to the corresponding time. The timestamps of leaving the ward are calculated as 1754587815 and returning to the ward as 1754590530. By subtracting the values ​​(1754590530-1754587815), the time difference in seconds is obtained as 2715 seconds. The second-level time difference is converted into hour-minute-second format: 2715 seconds divided by 3600 equals 0 hours, the remainder 2715 seconds divided by 60 equals 45 minutes, and the remaining 15 seconds, the final actual time of leaving the ward is 00:45:15. Simultaneously, the preset standard duration of the examination item (such as a chest CT scan) is retrieved as 40 minutes (2400 seconds). The deviation percentage is calculated using the formula "(actual duration - standard duration) / standard duration × 100%", i.e., (2715-2400) / 2400×100%=13.125%, resulting in a deviation percentage of 13.125%. The current ward number (e.g., ward 302) and card reader device identifier (e.g., RD-302-01) are retrieved from the configuration information stored in the main controller. The ward number, device identifier, and the timestamps of leaving and returning to the ward, the actual time spent outside (00:45:15), and the deviation percentage (13.125%) are then bound to the data through the associated field (medical record identifier). The associated data is standardized by field processing: ward numbers are uniformly formatted as 3 digits + 1 letter, equipment identifiers are formatted as prefix + ward number + serial number, timestamps are retained as 10 integers, actual durations are in HH:MM:SS format, and deviation percentages are retained as three decimal places, ensuring that the data type and length of each field fully comply with the hospital information system's acceptance requirements.The fields are combined in a preset order: "ward number - equipment identifier - ward exit timestamp - ward return timestamp - actual outing duration - deviation percentage". A record type identifier "OUT_IN_RECORD" (fixed 12 characters) and a data version number "01" (two-digit code) are added. The combined complete data is verified using the CRC32 algorithm to generate a 32-bit binary check code, which is then appended to the end of the record to form a complete and verifiable record of the outing period.

[0039] The process involves combining fields in a preset order to generate a complete record of the outing period, adding a record type identifier and a data version number, and then generating a record checksum using the CRC32 algorithm and appending it to the end. This includes the following steps: Arranging fields in the order of record type identifier - data version number - ward number - equipment identifier - out-of-ward timestamp - back-to-ward timestamp - actual duration - deviation percentage; setting the record type identifier to a fixed character field for rapid classification and identification by the hospital information system; using a two-digit code for the data version number to identify the current data format version; initializing the CRC32 checksum algorithm by using the arranged field combination as input data and performing checksum calculations to generate a 32-bit checksum; converting the checksum into an eight-digit hexadecimal string and appending it to the end of the record to form a complete data frame, while adding frame header and frame tail identifiers for data frame boundary identification.

[0040] The length of a complete data frame is checked. If it exceeds a preset transmission threshold, it is fragmented, and the fragment number and total number of fragments are marked to ensure transmission integrity. In this embodiment of the invention, the fields are arranged in a preset order of "Record Type Identifier - Data Version Number - Ward Number - Device Identifier - Ward Exit Timestamp - Ward Return Timestamp - Actual Duration - Deviation Percentage" to ensure that the field order is consistent with the data parsing rules of the hospital information system. The record type identifier is set to a fixed character field "OUT_IN_RECORD". This identifier is used by the hospital information system to quickly identify the record category after receiving data, distinguishing between outbound records, return records, and other types of data. The data version number uses a two-digit code "01" to identify the current data format version, which facilitates data compatibility processing during subsequent system upgrades. Initialize the CRC32 checksum algorithm, configuring the algorithm polynomial to 0xEDB88320. Use the permuted field combination (e.g., "OUT_IN_RECORD01302RD-302-011754587815175459053000:45:1513.125%) as input data, passing it byte-by-byte into the CRC32 calculation engine. Perform checksum operations such as cyclic shifting and XOR operations to generate a 32-bit binary checksum (e.g., 10110010110100110001010011101101). Convert the 32-bit binary checksum into an eight-bit hexadecimal string (each four binary bits corresponding to one hexadecimal bit), obtaining the hexadecimal checksum "B2D314ED", which is then appended to the end of the record to form a complete data frame. Simultaneously, a frame header identifier "[START]" (a fixed 6-character identifier) ​​is added to the header of the data frame, and a frame tail identifier " " (a fixed 4-character identifier) ​​is added to the tail of the data frame for frame boundary identification during data transmission, avoiding confusion between multiple frames. The length of the complete data frame is checked. The preset transmission threshold is 1024 bytes. A byte counting tool indicates that the current data frame length is 128 bytes, which does not exceed the transmission threshold, so no fragmentation is required. If the data frame length exceeds 1024 bytes, it is fragmented into segments of 1024 bytes each. A fragment sequence number (starting from 01) and a total fragment count identifier are added to each fragment to ensure that the hospital information system can reassemble the complete data according to the sequence number after receiving it, guaranteeing transmission integrity.

[0041] The system compares the actual outing time with the planned examination time, and determines anomalies based on timeout conditions, triggering tiered alarms through the following steps: The hospital information system retrieves the preset standard duration and allowable fluctuation threshold for the patient's current examination from the treatment plan database. The threshold is set according to clinical guidelines based on the examination type; the difference between the actual outing time and the standard duration is calculated. If the absolute value of the difference exceeds the allowable fluctuation threshold, it is marked as a timeout anomaly, and the specific deviation value is recorded; the expected return time period in the examination plan is retrieved. If the current time has exceeded this time period and no return to the ward record has been detected, it is marked as an overdue return anomaly; the two anomaly marking results are integrated. If there is an overdue return anomaly, it is judged as a Level 1 anomaly; if only the duration anomaly exists, it is judged as a Level 2 anomaly; a corresponding alarm command is generated according to the anomaly level and transmitted to the access control system through an encrypted communication link, triggering the corresponding level of alarm response mechanism. In this embodiment of the invention, the hospital information system retrieves the preset standard duration of the patient's current examination (chest CT scan) from the treatment plan database through medical record identification. The standard duration is 40 minutes. Simultaneously, according to clinical guidelines, an allowable fluctuation threshold of 20% is set. That is, if the actual outing time exceeds 40 minutes ± 20% (32 to 48 minutes), it is considered an abnormal duration. The difference between the actual outing time (45 minutes) and the standard duration (40 minutes) is calculated to be 5 minutes. Since the absolute value of the difference (5 minutes) does not exceed the allowable fluctuation threshold (8 minutes), it is not marked as an abnormal duration. If the actual outing time is 50 minutes, and the difference of 10 minutes exceeds 8 minutes, it is marked as an abnormal duration, and the specific deviation value of 10 minutes is recorded. The estimated return time in the examination plan is before 10:10:00 on December 7, 2024. If the current system time is 10:20:00 on December 7, 2024, and no patient return record is detected, the patient is considered to have exceeded the estimated return time and is marked as an abnormality of not returning within the estimated time. If a return record is detected within the estimated return time, this abnormality is not marked. The marking results of duration abnormalities and time-out abnormalities are integrated: if a time-out abnormality exists, regardless of whether a duration abnormality exists, it is judged as a Level 1 abnormality; if only a duration abnormality exists but the expected return time is not exceeded, it is judged as a Level 2 abnormality; if neither exists, it is judged as normal. Corresponding alarm commands are generated according to the abnormality level: the alarm command for Level 1 abnormality is "ALARM_LEVEL_1", with information such as patient medical record identifier, ward number, and estimated return time; the alarm command for Level 2 abnormality is "ALARM_LEVEL_2", with information such as actual duration, standard duration, and deviation value.Alarm commands are transmitted to the access control system via an encrypted communication link based on the TLS 1.3 protocol. Level 1 anomalies trigger an audible and visual alarm (the red alarm light at the access control point flashes and the buzzer emits a continuous 1kHz alarm sound), and simultaneously push emergency notifications to the nurse station display screen and the attending physician's mobile APP; Level 2 anomalies only send a text reminder to the nurse station and do not trigger on-site audible and visual alarms, ensuring that the alarm response matches the severity of the anomaly.

[0042] The process of integrating the two types of anomaly marker results, classifying anomalies as Level 1 if there is a timeout anomaly and Level 2 anomalies if only duration anomalies are present, involves the following steps: Retrieving the anomaly classification criteria from the system configuration module, identifying Level 1 anomalies as emergency situations requiring immediate action and Level 2 anomalies as general situations requiring routine verification; prioritizing timeout anomaly markers, regardless of the presence of duration anomaly markers, always classifying them as Level 1 anomalies; further verifying the deviation percentage if only duration anomaly markers are present, upgrading to Level 1 anomalies if the deviation exceeds twice the threshold, otherwise maintaining the Level 2 anomaly classification; associating the final anomaly level with the corresponding judgment criteria to generate an anomaly data packet containing patient identity information, anomaly type, level, and judgment criteria; encrypting the anomaly data packet and storing it in the local database, simultaneously generating a timestamp to provide data support for subsequent traceability. In this embodiment of the invention, by retrieving preset abnormality grading standards from the abnormality management subunit of the system configuration module, it is clarified that Level 1 abnormalities correspond to "emergency situations requiring immediate intervention by medical staff" (such as patients not returning on time, or high-risk patients significantly exceeding the permitted time outside the ward), and Level 2 abnormalities correspond to "general situations requiring routine verification by nurses" (such as ordinary patients slightly exceeding the permitted time outside the ward). The grading standards are directly linked to the clinical treatment process. Priority is determined for the abnormality markers indicating not returning on time: if the system detects the presence of this marker (e.g., a patient is expected to return at 10:10, but has not yet been recorded as returning to the ward at 10:30), regardless of whether a time-related abnormality marker also exists, it is classified as a Level 1 abnormality with the highest priority, ensuring priority handling of emergency situations. If only a time-related abnormality marker exists (no not returning on time), the deviation percentage is further checked: the allowable fluctuation threshold for this examination item is retrieved as 20%. If the deviation percentage is 45% (more than twice the threshold, i.e., 40%), the original Level 2 abnormality is upgraded to a Level 1 abnormality; if the deviation percentage is 25% (not exceeding twice the threshold), the Level 2 abnormality is maintained. The final anomaly level is associated with the judgment criteria to generate an anomaly data packet. This packet includes anonymized patient identity information (last 6 digits of the medical record identifier, first character of name + asterisk), anomaly type (overdue return / abnormal duration), anomaly level (Level 1 / Level 2), and judgment criteria (e.g., "Overdue by 20 minutes, meets Level 1 anomaly criteria," "Deviation 25%, not exceeding twice the threshold, judged as Level 2 anomaly"). The data packet is stored in a structured JSON format, with fixed and unmodifiable field definitions. The anomaly data packet is encrypted using the AES-256 algorithm, with the encryption key automatically rotated periodically. The encrypted data packet is stored in a local encrypted database, marked with a generation timestamp accurate to milliseconds. The database employs hierarchical access control, allowing only authorized medical personnel to query it, providing complete data support for subsequent event tracing.

[0043] Based on the anomaly level, a corresponding alarm command is generated and transmitted to the access control system via an encrypted communication link. Triggering the corresponding alarm response mechanism involves the following steps: The hospital information system generates alarm commands according to the anomaly level. Level 1 anomaly commands include an emergency handling procedure identifier, while Level 2 anomaly commands include routine verification prompts. Alarm commands are transmitted via a VPN-based encrypted tunnel, with end-to-end encryption technology ensuring the commands are not stolen or tampered with during transmission. The access control main controller receives the alarm command, decrypts and verifies it, and extracts the anomaly level, patient information, and core handling prompts. The corresponding alarm configuration file is called based on the anomaly level; Level 1 anomalies are configured for audible and visual alarm linkage, while Level 2 anomalies are configured primarily for visual prompts. The main controller sends a trigger signal containing the anomaly level and patient information to the alarm module, initiating the corresponding alarm output process. In this embodiment of the invention, the hospital information system generates corresponding alarm commands based on the final anomaly level: Level 1 anomaly commands include the emergency response process identifier "EMERGENCY_HANDLING_001", along with the patient's medical record identifier, ward number, time of anomaly occurrence, estimated return time, and a prompt to "immediately contact the patient / examination department to confirm patient safety"; Level 2 anomaly commands include the routine verification prompt "ROUTINE_CHECK_002", along with the patient's absence duration, standard duration, deviation value, and a verification requirement to "verify the reason for the timeout and record it in the nursing documentation." An encrypted VPN tunnel is used to transmit alarm commands. The tunnel is constructed using the IPsec protocol, and the transmitted data is encapsulated and encrypted. End-to-end encryption technology is also enabled. The alarm command is encrypted using the RSA algorithm at the sending end and decrypted using a dedicated private key at the receiving end, ensuring that the command is not stolen, tampered with, or forged during transmission within the hospital's internal network. After receiving the alarm command via the network interface, the access control main controller first extracts the checksum from the command header and performs integrity verification on the command data. If the verification passes, it calls the built-in decryption module, uses a pre-stored decryption key to decrypt the command, and extracts the anomaly level, core patient information, and core treatment prompts, discarding redundant fields and retaining key data. Based on the anomaly level, it calls the corresponding alarm configuration file: Level 1 anomaly configuration files are defined as "audio-visual alarm linkage + multi-terminal push" mode, including parameters such as alarm light flashing frequency, buzzer beeping mode, and display screen format; Level 2 anomaly configuration files are defined as "visual prompts as the main mode + single-terminal notification" mode, enabling only display screen pop-ups and nurse station application notifications, without triggering an audio alarm. The main controller sends a trigger signal to the alarm module via GPIO pins. The signal contains an 8-bit anomaly level code (0x01 for Level 1, 0x02 for Level 2) and the last 6 bits of the patient's medical record identifier. The trigger signal is continuously output for 100ms to ensure stable reception by the alarm module and initiate the corresponding alarm output process.

[0044] The main controller sends a trigger signal containing the abnormality level and patient information to the alarm module, initiating the corresponding alarm output process, which includes the following steps: After receiving the trigger signal, the alarm module analyzes the abnormality level. For Level 1 abnormalities, a triple alarm is triggered: a full-screen warning on the nurse station display, a high-frequency buzzer, and a push notification from the mobile application. For Level 2 abnormalities, only a pop-up window on the display and an application notification are triggered. The display output content is rendered: for Level 1 abnormalities, patient information and abnormality type are highlighted on a red background; for Level 2 abnormalities, a yellow background is used. The buzzer operating parameters are configured: for Level 1 abnormalities, a three-short-one-long beeping pattern is played in a loop until a release command is received; for Level 2 abnormalities, there is no sound alarm. The mobile application terminal identifiers of the patient's responsible nurse and attending physician are obtained through the hospital's internal communication server, and the alarm information is packaged according to a preset template. The alarm information is sent to the corresponding terminal using a push protocol to ensure real-time delivery, while recording the push time and terminal reception status. In this embodiment of the invention, after receiving the trigger signal sent by the main controller, the alarm module analyzes the abnormality level code and patient information through the signal decoding circuit: if the code is 0x01 (Level 1 abnormality), a triple alarm mechanism is immediately activated—a full-screen warning on the nurse station display screen, a high-frequency buzzer, and a push notification on the responsible medical staff's mobile application; if the code is 0x02 (Level 2 abnormality), only the display screen pop-up prompt and the nurse station application notification are activated, without triggering an audio alarm to avoid interfering with normal medical treatment. The display screen output content is rendered: Level 1 abnormalities use a solid red background, with the patient's desensitized information (such as "Medical Record No.: XXXXXX Name: Zhang*"), abnormality type ("Overdue Return"), abnormal duration ("Overdue 20 minutes"), and handling prompts highlighted in the center, with the font enlarged to 1.5 times the normal size, and continuously displayed until a manual cancellation command is received; Level 2 abnormalities use a yellow gradient background, with a pop-up window in the upper right corner displaying patient information and abnormal details (such as "Medical Record No.: XXXXXX Outing Duration Deviation 25%), the pop-up window remains open for 5 minutes and then automatically collapses, which can be viewed by clicking to review. Configure buzzer operating parameters: For Level 1 anomalies, the buzzer uses a "three short, one long" beeping pattern (short beep 0.2 seconds, interval 0.1 seconds, long beep 1 second, cycle 1.6 seconds), with a fixed beeping frequency of 2kHz, continuously looping until medical staff enter the deactivation password in the system. For Level 2 anomalies, the buzzer remains silent. Through the terminal management submodule of the hospital's internal communication server, the system retrieves the mobile application terminal identifiers (such as device ID and mobile phone number binding information) of the responsible nurse and attending physician based on the patient's medical record identifier. The alarm information is then packaged according to preset templates: Level 1 anomaly templates include "[Emergency Alarm] Patient Zhang* (medical record number XXXXXX) has not returned within the specified time, exceeding the time limit by 20 minutes. Please check immediately!"; Level 2 anomaly templates include "[Routine Reminder] Patient Li* (medical record number YYYYYY)'s out-of-home examination time deviated by 25%. Please check the cause and record it."The alarm information is sent to the corresponding terminal using a hospital-specific push protocol. The push timeout is set to 30 seconds. If no confirmation of receipt is received from the terminal within 30 seconds, the alarm will be automatically resent twice. At the same time, the push time, terminal identifier and reception status (success / failure) are recorded locally in the alarm module. In case of failure, a backup notification mechanism (such as SMS reminder) is triggered to ensure that the alarm information is delivered to the relevant medical staff in real time.

[0045] After receiving alarm information, medical staff verify and process it, and the system updates the processing results to complete closed-loop management, including the following steps:

[0046] Medical staff receive alarm information via a mobile application. After clicking to confirm, the system records the reception time. The application interface displays the patient's examination items, outing duration, and abnormal details. The responsible nurse goes to the site or contacts the patient by phone to confirm the situation. If it is a misjudgment, an abnormality cancellation application is submitted in the application, specifying the reason. If an abnormality is confirmed, the handling procedure is initiated, contacting the examination department, security department, or family members as needed. After handling, the handling measures and results are recorded. Medical staff enter the handling results into the mobile application, and the system synchronizes them to the hospital information system and access control system via an encrypted interface. The hospital information system updates the closed-loop status of the patient's outing record, the access control system cancels the alarm status, and the handling results are archived along with the abnormal data, completing this closed-loop management. In this embodiment of the invention, after the medical staff's mobile application receives the alarm information, a prompt window automatically pops up on the application interface, displaying the alarm information content. The medical staff clicks the "Confirm Receipt" button in the window, and the mobile application immediately sends a receipt confirmation signal to the hospital information system. After receiving the signal, the system obtains the current time (accurate to the second) from the built-in real-time clock module, associates the time with the patient's medical record identifier and the medical staff's identifier, and stores it in the patient outing management database. Simultaneously, the application interface automatically switches to the patient details page. The top of the page displays the patient's examination name (e.g., chest CT scan), planned outing time (40 minutes), and actual outing time (55 minutes). The middle section displays the abnormality type (duration abnormality) and abnormal deviation (37.5%). The bottom displays the patient's ward number, bed number, and contact number of the examination department. All information is presented in a structured list format using the application's built-in rendering engine, facilitating quick viewing by medical staff. The responsible nurse takes corresponding actions based on the alarm information type: If it is a Level 1 abnormality (failure to return within the allotted time), immediately go to the card reader at the ward exit to check if there is a patient return record. If no return record is found, use the department contact function in the mobile application to call the examination department to confirm whether the patient is still in the examination department; if it is a misjudgment (e.g., the patient has returned but the card reader has not recognized the patient), in the abnormality handling interface of the mobile application, click the "Abnormality Removal Application" button, select the reason for the misjudgment (e.g., temporary card reader malfunction), enter the 6-digit personal employee ID verification code, and submit the removal application. If a genuine abnormality is confirmed (e.g., the patient left the examination area without authorization), the responsible nurse initiates the emergency response procedure: First, contact the hospital security department, providing the patient's physical characteristics and the time they left, requesting assistance in locating them; simultaneously, call the patient's family to inquire if they know the patient's whereabouts; during the process, record the operation content and time in the mobile application's operation record interface after each step is completed (e.g., contacting security, contacting family); after the operation is completed (e.g., finding the patient and bringing them back to the ward), fill in the operation result in the interface (e.g., "Patient found at 15:30, safely brought back to the ward, patient shows no abnormalities"), and submit the operation record.After medical staff enter the processing results in the mobile application, the application packages the processing results (including the personnel handling the case, the time of handling, the measures taken, and the outcome of handling) and the patient's medical record identifier into a data frame (the frame length is fixed at 1024 bytes) through an SSL encrypted communication link (based on the TLS 1.3 protocol) and sends it to the hospital information system. After receiving the data frame, the hospital information system decrypts the data through its built-in decryption module, extracts the processing results, updates the closed-loop status field in the patient's outing record, and changes the status from "abnormal pending processing" to "abnormal processed". At the same time, the hospital information system sends a status synchronization signal to the access control system. After receiving the signal, the access control system sends an alarm cancellation command to the alarm module, and the alarm module immediately stops the display screen warning and the buzzer sounding, and resumes normal operation. The hospital information system binds the processing results with the patient's abnormal data (abnormality level, abnormality occurrence time, alarm records) using a data association algorithm to generate a complete closed-loop management record. The record contains 12 fields (patient identifier, examination item, abnormality type, abnormality time, alarm time, receipt time, handling personnel, handling time, handling measures, handling result, closed-loop time, and data check code). A data check code is generated using the CRC32 algorithm and appended to the end of the record to ensure data integrity. The record is then stored in the hospital's data archive (1TB capacity). The archive adopts a hierarchical storage strategy, with records from the past 3 months stored on high-speed solid-state drives and records older than 3 months transferred to hard disk drives. This facilitates subsequent access to historical records by medical staff through the hospital's intranet, enabling closed-loop management of the patient's outpatient examinations.

[0047] A closed-loop automated management system for patients leaving for examinations based on intelligent access control systems, such as... Figure 3 As shown, the method for implementing the above-mentioned closed-loop automated management of patient out-of-home examinations based on an intelligent access control system includes an RFID identification module, an access control module, a data synchronization module, a tiered alarm module, and a hospital information interaction module.

[0048] The RFID identification module includes a medical tear-resistant RFID wristband and a high-sensitivity reader. The wristband has a built-in encrypted storage chip that uses a combination of AES and RSA encryption technology to store patient identification information. The reader is deployed at the ward exit and supports RF activation, data decryption, and hash verification functions. It communicates with the access control module via an SPI bus. In this embodiment of the invention, the RFID identification module comprises two core devices: a medical tear-resistant RFID wristband and a high-sensitivity reader. The wristband is made of medical-grade silicone and tear-resistant nylon tape, integrally injection molded with a breaking tensile strength of no less than 50N, an IP68 waterproof rating, and can withstand alcohol wiping disinfection. The wristband has a built-in 4KB encrypted storage chip that supports the ISO15693 communication protocol. When storing patient identification information, it uses a combination of AES and RSA encryption technology: first, plaintext information such as medical record identifiers, names, and allergy history is encrypted using a 256-bit AES algorithm to generate AES ciphertext; then, the AES symmetric key is encrypted using a 2048-bit RSA algorithm. The encrypted key and AES ciphertext are written together into the chip's storage area. The chip also stores a 64-bit factory-installed unique code to ensure the information cannot be tampered with. The card reader is wall-mounted and installed 1.2 meters above the centerline of the ward exit corridor. The RFID distance is controlled between 0.3 and 0.8 meters, the operating frequency is fixed at 13.56MHz, and the antenna gain can be adjusted within the range of 1-10dB via configuration software. The card reader features radio frequency activation, activating the passive chip within the wristband by emitting 10mW of radio frequency energy. It has a built-in encryption module that stores an RSA private key for decrypting encrypted information sent by the chip. An integrated SHA-256 hash verification unit calculates the hash value of the decrypted plaintext data and compares it with the verification field attached to the chip to verify integrity. The card reader connects to the access control module via an SPI bus. The SPI communication baud rate is set to 115200bps, with 8 data bits and 1 stop bit. Chip select control is implemented via the CS pin. After each identification process, the patient code, identification result, and timestamp are transmitted to the access control module via the SPI bus, ensuring real-time data exchange.

[0049] The access control module is based on an ARM processor and runs an embedded Linux system. It integrates a real-time clock module and an access control driver unit for identity information parsing, access permission determination, access control switch control, and entry / exit time recording. A built-in security chip stores decryption keys. In this embodiment, the access control module uses a 32-bit ARM processor with an 800MHz clock speed and runs an embedded Linux system with a fixed kernel version 4.19, supporting multi-task scheduling and hardware driver management. The module integrates a real-time clock module with a clock accuracy error of no more than ±2 seconds / day. It connects to the processor via an I2C bus, providing a precise time reference for access control switches and time recording. The integrated access control driver unit includes an electromagnetic lock control circuit and a status detection circuit. The driver unit connects to the processor via GPIO pins. When the processor outputs a 3.3V high-level signal, it drives the electromagnetic lock to power off and unlock; when it outputs a low-level signal, it controls the electromagnetic lock to lock. Simultaneously, the detection circuit feeds back the lock status (locked / unlocked) to the processor. The module features identity information parsing capabilities. After receiving encrypted data from the card reader, it uses a built-in decryption algorithm to parse the patient's identity information. Based on the parsed medical record identifier, it retrieves the treatment plan from the hospital information system and performs an exit permission check: if the current time falls within the planned exit period and a valid examination appointment exists, permission is granted; otherwise, it is denied. Once permission is granted, the processor records a ward timestamp and controls the access control unit to unlock. When the patient returns, the identity verification process is repeated, recording the ward timestamp again. All timestamps are accurate to the second and are associated with the patient's code, stored in the module's built-in 4GB flash memory. The module incorporates a dedicated security chip that uses hardware encryption to store the RSA private key and AES key. The security chip supports protection against physical and side-channel attacks. The key can only be accessed through authorized processor access and cannot be directly read, ensuring key storage security.

[0050] The data synchronization module employs the SSL / TLS encrypted transmission protocol and is configured with an end-to-end encrypted interface to achieve real-time synchronization of access control data with the hospital information system. It supports data fragmentation transmission and verification to ensure transmission security and integrity. In this embodiment, the data synchronization module uses the SSL / TLS 1.3 encrypted transmission protocol to construct an end-to-end encrypted communication link. The link supports bidirectional certificate authentication: the module incorporates the root certificate of the hospital information system and the device certificate of the hospital information system storage module. Before communication, both parties verify the validity of the certificates to prevent unauthorized device access. The module is configured with a standard RJ45 Ethernet interface, supporting a network transmission rate of 100Mbps full-duplex. A TCP connection is established with the hospital information system through this interface to achieve real-time synchronization of access control data. Synchronized data includes patient entry / exit timestamps, identity information, permission judgment results, and abnormal records. The data is encapsulated in a preset structured format, with each data frame containing a frame header (6-byte identifier), data length (2 bytes), data body (variable length), and a checksum (4-byte CRC32). When a single data entry exceeds 1024 bytes, the module automatically initiates fragmented transmission, splitting the data into 1024-byte segments. Each segment is marked with a 2-byte sequence number and a 2-byte total number of segments. The hospital information system then reassembles the data according to the sequence number. Before data transmission, the module calculates a CRC32 checksum and appends it to the end of the data frame. Upon receiving the data, the hospital information system recalculates the checksum and compares it with the end-of-frame checksum. If they do not match, the system sends a retransmission request to the module. Upon receiving the request, the module retransmits the corresponding data within 100ms, ensuring data integrity. The module has a built-in 16MB data cache. When the network is interrupted, synchronous data is temporarily stored in the cache. Once the network is restored, the cached data is automatically retransmitted to prevent data loss.

[0051] The graded alarm module includes a nurse station display screen, a buzzer, and a mobile terminal push component. It executes differentiated alarm responses based on the level of abnormality, supports alarm confirmation, deactivation, and treatment recording functions, and links with the hospital communication server to push information. In this embodiment, the graded alarm module consists of a nurse station display screen, a buzzer, and a mobile terminal push component. Each component connects to the access control module through different interfaces to achieve differentiated alarm responses. The nurse station display screen is a 19-inch touchscreen with a resolution of 1920×1080. It connects to the access control module via an HDMI interface. For a Level 1 abnormality, the display switches to a full-screen red warning mode, centrally displaying the patient's desensitized information, abnormality type, abnormality duration, and treatment prompts, with the font enlarged to 1.5 times the normal size. For a Level 2 abnormality, a yellow pop-up window appears in the upper right corner of the display screen, with a size of 1 / 4 of the screen area, displaying the patient's basic information and abnormality details. The pop-up window automatically closes after 5 minutes. The buzzer is an active piezoelectric type, operating at 3.3V. It connects to the access control module via GPIO pins. In case of a Level 1 anomaly, the module outputs a "three short, one long" pulse signal (short beep for 0.2 seconds, interval for 0.1 seconds, long beep for 1 second, cycle period 1.6 seconds), driving the buzzer to sound in this pattern. In case of a Level 2 anomaly, the module outputs a low level, and the buzzer remains silent. The mobile terminal push component connects to the hospital communication server via an Ethernet interface. The component has a built-in push protocol stack and supports the hospital's proprietary push protocol. When an alarm is triggered, the component obtains patient information and anomaly level from the access control module, calls a preset template to generate alarm information, and queries the mobile application terminal identifier (16-bit device ID) of the patient's responsible nurse and attending physician through the communication server. The alarm information is then pushed to the corresponding mobile terminal according to the terminal identifier. The module supports alarm confirmation and deactivation functions: After medical staff click "Confirm Receipt" on the mobile terminal, the terminal sends a confirmation signal to the module, and the module records the reception time; after the medical staff completes the treatment, they submit a deactivation request through the terminal. After receiving the request, the module sends a stop command to the display screen and buzzer, and records the treatment result, forming a complete alarm closed loop.

[0052] The hospital information interaction module is a built-in submodule of the hospital information system, used for retrieving patient treatment plans, storing outing records, and archiving anomaly judgment and processing results. It provides data query, statistics, and traceability interfaces. In this embodiment of the invention, the hospital information interaction module is a built-in submodule of the hospital information system, which links with the treatment plan database, electronic medical record database, and patient management database through internal system interfaces to achieve multi-dimensional data interaction. The module has a patient treatment plan retrieval function: when the access control module sends a patient's medical record identifier, the module queries the treatment plan database based on the identifier, extracts the patient's current examination items, planned outing time, estimated return time, examination department, and other permission-related data, and feeds it back to the access control module within 100ms. After receiving the patient's entry / exit timestamp and permission judgment result synchronized by the access control module, the module stores them in the patient outing management database according to the field format. The database table structure includes fields such as medical record identifier, entry / exit type (out / in), timestamp, ward number, equipment identifier, and permission status. Data storage adopts a partitioned table strategy, managed by date partitions to improve query efficiency. The module has a built-in anomaly detection engine that reads patient outing records from the database and compares them with the standard duration and expected return time in the treatment plan. If the actual outing duration exceeds the standard duration by 20% or the current time exceeds the expected return time and there is no return record, the corresponding anomaly level is marked, and the anomaly record is pushed to the access control module. After medical staff submit the processing results, the module receives and stores the processing results, updates the closed-loop status of the patient's outing record (from "Anomaly Pending Processing" to "Anomaly Processed"), and archives the processing results to the "Patient Outing Management" section of the electronic medical record database. The module provides data query, statistics, and traceability interfaces: authorized medical staff can access the query interface through the hospital intranet, input the medical record identifier or time range, and obtain the patient's historical outing records; the statistics interface supports statistics on anomaly incidence rate, average outing duration, etc., by department and time period; the traceability interface provides a complete data link query, which can view the generation time, transmission nodes, and processing process of each record, meeting data traceability requirements.

Claims

1. A closed-loop automated management method for patients leaving for examinations based on an intelligent access control system, characterized by: Includes the following steps: Patients are equipped with RFID wristbands containing built-in encrypted identity information, and radio frequency identification readers with full coverage are deployed at the ward exits; When a patient approaches the exit, the card reader activates the corresponding chip on the RFID wristband and receives the encrypted identity information. After decryption, it extracts the core identity data to verify the patient's exit permission. Once the permissions are granted, the ward time is recorded and synchronized to the hospital information system via an encrypted interface, which then drives the door lock to open. When the patient returns, the card reader performs a second identification, records the time of return to the ward, and synchronizes the data. The system compares the actual time spent away from home with the planned inspection time, and determines anomalies based on timeout conditions, triggering tiered alarms. After receiving the alarm information, medical staff verify and process it, and the system updates the processing results to complete closed-loop management.

2. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 1, characterized in that, The process of equipping patients with RFID wristbands containing built-in encrypted identity information and deploying radio frequency identification readers with full coverage at the ward exit includes the following steps: The system retrieves sensitive information such as patient medical record identifiers, names, allergy history, and current treatment plans from the hospital information system. It processes the data using a combination of symmetric and asymmetric encryption, encrypts the information body using the AES algorithm, and protects the symmetric key using the RSA algorithm. The encrypted complete data is written into the passive RFID wristband chip. The chip is packaged with medical-grade waterproof and corrosion-resistant material and integrated with the tear-resistant wristband. The wristband surface is printed with desensitized identification and emergency contact information. A card reader was installed at the central axis of the ward exit corridor. The installation height and angle were adjusted through multiple tests to ensure that the radio frequency signal covered the width of the corridor and that the identification distance was controlled within a reasonable range to avoid signal interference from adjacent corridors. The card reader is connected to the ARM main controller of the access control system via the SPI bus. The card reader's operating frequency and data transmission baud rate are configured to match the communication parameters of the wristband chip. At the same time, the built-in hash verification function of the card reader is enabled to ensure data integrity. The test simulated scenarios where patients of different body types wore wristbands and traveled at different speeds. The response time and accuracy of identity recognition were recorded, and the antenna gain was adjusted for recognition delays exceeding the threshold or false recognition.

3. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 1, characterized in that, When the patient approaches the exit, the card reader activates the corresponding chip on the RFID wristband and receives encrypted identity information. After decryption, the core identity data is extracted to verify exit permissions, including the following steps: When a patient enters the radio frequency coverage area of ​​the card reader, the passive RFID wristband chip inside the wristband receives radio frequency energy and is activated, sending a response signal containing encrypted identity information and the chip's unique code to the card reader according to a preset protocol; After receiving the response signal, the card reader calls the locally stored decryption key to decrypt the encrypted information, calculates the data check value using the SHA-256 hash algorithm, and compares it with the check field attached to the signal to verify the integrity. After successful verification, the patient's medical record identifier and wristband code are extracted, the data is encapsulated into a message format conforming to the HL7 protocol, and transmitted to the access control main controller via an encrypted communication link; The main controller retrieves the patient's current treatment plan from the hospital information system based on the medical record identifier, and extracts permission-related data such as outpatient examination items, planned departure time, expected return time, and information on accompanying persons; The system combines the current system time with the treatment plan data to determine permissions. If the patient is in the planned outing period and has a valid examination appointment, the permission is granted; otherwise, the reason for permission denial is recorded and an alert is prepared to be triggered.

4. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 3, characterized in that, After receiving the response signal, the card reader calls the locally stored decryption key to decrypt the encrypted information, calculates the data checksum using the SHA-256 hash algorithm, and compares it with the checksum field attached to the signal to verify integrity, including the following steps: After receiving the response signal, the encryption processing module built into the card reader first separates the chip's unique code from the encrypted identity information, and then verifies the wristband's legitimacy by matching the codes. The RSA private key stored in the security chip is used to decrypt and obtain the AES symmetric key. Then, the symmetric key is used to decrypt the ciphertext of the identity information and restore the original plaintext data. The SHA-256 hash algorithm is used to calculate the hash value of the decrypted plaintext data, and a fixed-length hash value is generated. At the same time, the original hash verification field attached to the response signal is extracted. The hash value calculated in real time is compared bit by bit with the original verification field. If they are completely consistent, it is determined that the data has not been tampered with and the integrity verification is passed. If the comparison is inconsistent, an exception handling process is initiated, the error information and the current timestamp are recorded, and a data anomaly alarm is sent to the main controller, rejecting the subsequent identity verification process.

5. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 4, characterized in that, The process of using the SHA-256 hash algorithm to calculate a fixed-length hash value from the decrypted plaintext data, and simultaneously extracting the original hash verification field attached to the response signal, includes the following steps: The decrypted plaintext data is standardized by removing redundant spaces and control characters to ensure that the data format is consistent with that before encryption. Initialize the SHA-256 algorithm computing environment, input the standardized plaintext data in blocks according to the algorithm requirements, and execute message padding, hash value initialization and iterative compression operations in sequence; After the calculation is completed, a 256-bit hash value is generated, which is then converted into a hexadecimal string format for storage. Extract the original hash check field from the extended fields of the response signal. This field is generated and appended synchronously by the hospital information system when writing to the wristband. The extracted original validation fields are format-validated to ensure they conform to the hexadecimal string specification and have a length of 64 characters. If they do not conform, the validation is deemed to have failed.

6. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 1, characterized in that, After the permissions are granted, the ward time is recorded and synchronized to the hospital information system via an encrypted interface. The access control system then drives the door lock to open, including the following steps: After the main controller passes the permission check, it calls the built-in real-time clock module to obtain the current time accurate to the second, and stores this time as the time of leaving the ward, along with the patient's medical record identifier and wristband code. The ward record is generated according to the preset data format, which includes a basic information section, an access information section and a time information section. The basic information section uses desensitization processing to hide sensitive data. The patient flow management submodule of the hospital information system transmits ward exit records to the encrypted data synchronization interface based on the SSL / TLS protocol, and end-to-end encryption is enabled to ensure security during the transmission process. After receiving the record, the hospital information system writes it into the patient's electronic medical record database via the I2C bus, updates the patient status field, and triggers the synchronization of the diagnosis and treatment process nodes. The main controller sends a level trigger signal to the access control actuator to drive the electromagnetic lock to power off and unlock. At the same time, it controls the exit indicator light to change from red to green through the GPIO pin and records the access control opening timestamp.

7. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 1, characterized in that, The process of the card reader performing secondary identification upon the patient's return, recording the time of return to the ward, and synchronizing the data includes the following steps: Once the patient returns to the ward and enters the card reader's recognition range, the card reader repeats the identity recognition and data decryption process, and finds the corresponding ward exit record by matching the wristband code. After the main controller confirms that the identity matches and there is an out-of-loop record, it calls the real-time clock module again to get the current time and records it as the time of returning to the ward. The difference between the time of returning to the ward and the time of leaving the ward is calculated to obtain the actual time spent outside. This time is then combined with the round-trip timestamps and the ward number to form a complete record of the time spent outside. The complete record is pushed to the hospital information system through an encrypted synchronization interface. The system automatically associates the corresponding examination item information and adds it to the outpatient management section of the patient's medical record. The hospital information system updates the patient's status and triggers the duration statistics engine to compare and analyze the duration of this outing with the historical average duration of the examination.

8. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 1, characterized in that, The system compares the actual time spent away from home with the planned inspection time, and determines abnormalities based on timeout conditions, triggering a tiered alarm through the following steps: The hospital information system retrieves the preset standard duration and allowable fluctuation threshold for the patient's current examination items from the treatment plan database. The threshold is set according to clinical guidelines based on the type of examination. Calculate the difference between the actual time spent outside and the standard time. If the absolute value of the difference exceeds the allowable fluctuation threshold, it is marked as an abnormal time. At the same time, the specific value of the deviation is recorded. Retrieve the expected return time from the inspection plan. If the current time has exceeded that time and no return to the ward record has been detected, mark it as an abnormal overdue return. The two types of anomaly marking results are integrated. If there is an outage failure to return, it is judged as a level 1 anomaly. If there is only a duration anomaly, it is judged as a level 2 anomaly. Based on the anomaly level, a corresponding alarm command is generated and transmitted to the access control system via an encrypted communication link, triggering the corresponding alarm response mechanism.

9. The closed-loop automated management method for patient out-of-home examinations based on an intelligent access control system according to claim 1, characterized in that, After receiving and processing the alarm information, the medical staff will verify and handle it, and the system will update the processing results to complete closed-loop management. This includes the following steps: Medical staff receive alarm information via a mobile application. After clicking to confirm, the system records the time of receipt. The application interface displays the patient's examination items, duration of absence, and abnormal details. The responsible nurse goes to the scene or contacts the patient by phone to confirm the patient's condition. If it is a misjudgment, an application to remove the abnormality is submitted in the application, and the reason is noted. If any abnormality is found, the handling procedure will be initiated, and the inspection department, security department or family members will be contacted as appropriate. After the handling is completed, the handling measures and results will be recorded. Medical staff enter the processing results into a mobile application, and the system synchronizes them to the hospital information system and access control system through an encrypted interface; The hospital information system updates the closed-loop status of patient exit records, the access control system deactivates the alarm, and the processing results are archived along with the abnormal data, thus completing this closed-loop management.

10. A closed-loop automated management system for patients leaving for examinations based on an intelligent access control system, characterized in that: The method for implementing the closed-loop automated management of patient outpatient examinations based on an intelligent access control system as described in any one of claims 1-9, wherein the closed-loop automated management system for patient outpatient examinations based on an intelligent access control system includes an RFID identification module, an access control module, a data synchronization module, a hierarchical alarm module, and a hospital information interaction module: The RFID identification module includes a medical tamper-proof RFID wristband and a high-sensitivity card reader. The wristband has a built-in encrypted storage chip that uses AES and RSA encryption technology to store patient identification information. The card reader is deployed at the ward exit and supports radio frequency activation, data decryption and hash verification functions. It communicates with the access control module via the SPI bus. The access control module is based on an ARM processor and runs an embedded Linux system. It integrates a real-time clock module and an access control driver unit for identity information parsing, exit permission determination, access control switch control and entry / exit time recording. It also has a built-in security chip to store decryption keys. The data synchronization module adopts the SSL / TLS encrypted transmission protocol and is configured with an end-to-end encrypted interface to achieve real-time synchronization of access control data and hospital information system. It supports data fragmentation transmission and verification to ensure transmission security and integrity. The graded alarm module includes a nurse station display screen, a buzzer, and a mobile terminal push component. It performs differentiated alarm responses according to the level of abnormality, supports alarm confirmation, cancellation, and handling recording functions, and links with the hospital communication server to realize information push. The hospital information interaction module is a built-in sub-module of the hospital information system. It is used for retrieving patient treatment plans, storing outpatient records, and archiving abnormal judgment and processing results. It also provides data query, statistics and traceability interfaces.

Citation Information

Patent Citations

  • Inpatient management system for psychiatric specialized hospital based on Internet of Things

    CN113990505A