Chronic disease data security collection and intelligent management method and system based on block chain
By using blockchain-based encrypted data collection and intelligent management methods, the security issues of chronic disease data during transmission and access are solved, achieving end-to-end data security management and trusted analysis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-04
- Publication Date
- 2026-03-27
- Estimated Expiration
- Not applicable · inactive patent
Smart Images

Figure CN121744376A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of medical information security technology, and in particular to a blockchain-based method and system for secure collection and intelligent management of chronic disease data. Background Technology
[0002] In the field of medical information security technology, there is a need to collect, analyze, and share data on chronic diseases in order to achieve intelligent management of the diagnosis and treatment process.
[0003] In related data management methods, data sharing and analysis are achieved through centralized server storage and access control. However, this method lacks end-to-end security control during data transmission and access, which can easily lead to the leakage of sensitive information, thus making it impossible to achieve encrypted protection and secure management of chronic disease data. Summary of the Invention
[0004] Therefore, it is necessary to provide a blockchain-based method, system, computer equipment, and computer-readable storage medium for secure collection and intelligent management of chronic disease data, addressing the aforementioned technical issues.
[0005] Firstly, this application provides a blockchain-based method for secure collection and intelligent management of chronic disease data, including: Chronic disease data of each target object is collected and encrypted to obtain encrypted data, and the encrypted data is uploaded to a preset blockchain network through a preset secure channel; Based on the indexing mechanism of the blockchain network, homomorphic encryption analysis is performed on the chronic disease indicator fields in the encrypted data to obtain ciphertext analysis results that reflect the disease trend in the ciphertext state. Upon receiving an access request, the system performs identity authentication on the medical staff access object corresponding to the access request based on the permission control mechanism of the blockchain network, and returns the data that matches the access request in the encrypted analysis results to the authenticated medical staff access object, so that the chronic disease data can complete the full-link security management process for diagnosis and treatment scenarios in encrypted state.
[0006] Secondly, this application also provides a blockchain-based system for secure collection and intelligent management of chronic disease data, including: The encrypted data acquisition module is used to collect chronic disease data of various target objects and encrypt them to obtain encrypted data, and then upload the encrypted data to a preset blockchain network through a preset secure channel. The ciphertext analysis module is used to perform homomorphic encryption analysis on the chronic disease indicator fields in the encrypted data according to the indexing mechanism based on the blockchain network, and obtain the ciphertext analysis results that reflect the disease trend in the ciphertext state. The authentication module is used to receive access requests, authenticate the identity of the medical staff access object corresponding to the access request according to the permission control mechanism based on the blockchain network, and return the data that matches the access request in the encrypted analysis results to the authenticated medical staff access object, so that the chronic disease data can complete the full-link security management process for diagnosis and treatment scenarios in encrypted state.
[0007] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the above steps.
[0008] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the above steps.
[0009] The aforementioned blockchain-based method, system, computer equipment, and computer-readable storage medium for secure collection and intelligent management of chronic disease data firstly encrypt the collected chronic disease data of each target object and upload it to the blockchain network through a secure channel, thereby ensuring the confidentiality and integrity of the data throughout the collection and transmission process and forming a traceable on-chain record. Secondly, based on the indexing mechanism of the blockchain network, homomorphic encryption analysis is performed on the chronic disease indicator fields in the encrypted data, thereby analyzing the characteristics of chronic disease data without decryption to obtain encrypted analysis results, achieving trusted analysis and processing in encrypted form. Thirdly, based on the access control mechanism of the blockchain network, identity authentication and data matching are performed on access requests, thereby ensuring that only authorized medical personnel can obtain encrypted chronic disease data that matches their access requests. Based on this, the entire technical solution realizes end-to-end encrypted management of chronic disease data from collection, transmission, storage, analysis to access for medical scenarios, making data processing both secure and controllable and analytically usable. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a flowchart illustrating a blockchain-based method for secure collection and intelligent management of chronic disease data in one embodiment. Figure 2 This is a block diagram of a blockchain-based chronic disease data security collection and intelligent management system in one embodiment. Detailed Implementation
[0012] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0013] In one embodiment, such as Figure 1 As shown, a blockchain-based method for secure collection and intelligent management of chronic disease data is provided. This embodiment illustrates the method by applying it to a server. It is understood that this method can also be applied to terminals, and further to systems including terminals and servers, and is implemented through interaction between the terminal and the server. In this embodiment, the method includes the following steps S101 to S103.
[0014] Step S101: Collect chronic disease data of each target object and encrypt it to obtain encrypted data. Upload the encrypted data to the preset blockchain network through the preset secure channel.
[0015] The target population refers to individuals who need chronic disease monitoring and management, such as patients with long-term hypertension, diabetes, or heart disease. Chronic disease data refers to multidimensional health information related to the chronic disease status of the target population, including basic information (identity number, age, gender, past medical history, etc.), medical records (prescriptions, treatment plans, follow-up records, etc.), and chronic disease monitoring indicators (periodic monitoring data such as blood glucose, blood pressure, heart rate, weight, and blood lipids).
[0016] For example, firstly, a corresponding chronic disease data collection process is established for multiple target objects, that is, the raw chronic disease data of each target object is collected through terminal devices or medical management interfaces. Secondly, to ensure the security of subsequent processing, an encryption stage is entered after the collection is completed. This is equivalent to encoding the chronic disease data of different target objects and different categories according to encryption rules such as AES-256 encryption algorithm, thereby transforming the basic information, medical records and chronic disease monitoring indicators of each target object into irreversible encrypted data.
[0017] Next, after encryption is completed, to prevent data leakage and tampering during transmission, the encrypted data is uploaded to the blockchain network through a pre-set secure channel. The secure channel refers to a pre-established encrypted communication path between different ends, used to ensure confidentiality and integrity during data transmission, such as a transmission link based on the TLS 1.3 protocol or an end-to-end encryption mechanism.
[0018] Furthermore, encrypted data is accompanied by target object identifiers and timestamps during the upload process. After receiving the data, the blockchain network automatically generates the corresponding block index and completes the data on-chain registration, thereby forming a traceable encrypted storage record. Based on this, the entire process from data collection, encryption, transmission to on-chain is completed, realizing the secure collection and on-chain recording of chronic disease data of multiple target objects.
[0019] Step S102: Based on the indexing mechanism of the blockchain network, homomorphic encryption analysis is performed on the chronic disease indicator fields in the encrypted data to obtain the ciphertext analysis results that reflect the disease trend in the ciphertext state.
[0020] Among them, the chronic disease index field represents the key parameter field used in the encrypted data to reflect changes in the state of chronic diseases. It is used as the calculation input for homomorphic encryption analysis, such as average blood glucose, blood pressure change rate, heart rate fluctuation amplitude, or medication adherence index, etc., which are encrypted data items.
[0021] The encrypted analysis result refers to the encrypted calculation output obtained after performing homomorphic operations on the chronic disease indicator fields without decryption. It is used to reflect the disease trend while maintaining the encrypted state of the data. For example, it is an encrypted result vector that represents the trend of blood sugar increase or the direction of blood pressure fluctuation.
[0022] For example, encrypted data that has been uploaded to the blockchain is analyzed and retrieved based on an internally built indexing mechanism in the blockchain network. The indexing mechanism based on the blockchain network refers to the multi-dimensional data retrieval method established by the blockchain network, which is used to quickly locate encrypted data and its corresponding chronic disease indicator fields on the chain. For example, a mapping table is built by hash value, timestamp and data identifier to achieve accurate indexing and tracing of encrypted data on the chain.
[0023] Next, homomorphic encryption analysis is performed on the identified chronic disease indicator fields. Basic arithmetic operations, including addition and multiplication, are executed to extract the correlations between data without decryption. This allows for the analysis and aggregation of various encrypted chronic disease indicator fields, yielding ciphertext analysis results that reflect disease progression trends. This ciphertext analysis result enables centralized analysis of chronic disease data characteristics from multiple targets in an encrypted state and is stored in a blockchain network as structured data, providing a retrieval basis for subsequent access stages.
[0024] Step S103: Receive access request, perform identity authentication on the medical staff access object corresponding to the access request according to the access control mechanism based on the blockchain network, and return the data that matches the access request in the encrypted analysis results to the medical staff access object that has passed the identity authentication, so that chronic disease data can complete the full-link security management process for diagnosis and treatment scenarios in encrypted state.
[0025] Among them, the medical staff access target refers to medical practitioners or authorized institutions with legal access rights, who can initiate access requests through external systems or user terminals to read, analyze or retrieve the chronic disease data of the target object in diagnosis or research scenarios.
[0026] For example, upon receiving an external access request in the blockchain network, a blockchain-based access control mechanism is first triggered to ensure that data access operations are performed in a controlled and traceable environment. Specifically, the access control mechanism extracts and analyzes information contained in the access request, such as the identity credentials of the healthcare access recipient, the scope of the requested data, and the purpose of access, thereby verifying the digital identity of the healthcare access recipient. The access control mechanism represents an access control system established based on the blockchain network, used to verify the visitor's identity, assign access levels, and record access behavior upon receiving an access request. For example, it verifies the healthcare access recipient's digital signature and authorization certificate through blockchain nodes to determine whether they possess the corresponding access permissions.
[0027] Next, if the healthcare worker's access is verified, the matching data item is located in the previously generated encrypted analysis results based on the range of requested data contained in the access request. This matching process can be implemented through a blockchain index table, ensuring that the retrieval is completed within the on-chain record without involving any plaintext data retrieval. Furthermore, the matched data item is encapsulated and appended with an access information digest and an encrypted information digest, and then returned to the verified healthcare worker via the blockchain network.
[0028] Based on this, the entire process ensures that the receipt of access requests, identity authentication, data matching, and result transmission are all completed within the blockchain permission framework. The result is encrypted chronic disease data corresponding to the access request, thus realizing a controlled, encrypted, and fully recorded secure access process in the blockchain network.
[0029] The aforementioned blockchain-based method for secure collection and intelligent management of chronic disease data firstly encrypts the collected chronic disease data of each target object and uploads it to the blockchain network through a secure channel, ensuring the confidentiality and integrity of the data throughout the collection and transmission process and forming a traceable on-chain record. Secondly, based on the indexing mechanism of the blockchain network, homomorphic encryption analysis is performed on the chronic disease indicator fields in the encrypted data, thereby analyzing the characteristics of the chronic disease data without decryption to obtain encrypted analysis results, achieving trusted analysis and processing in encrypted form. Thirdly, based on the access control mechanism of the blockchain network, identity authentication and data matching are performed on access requests, ensuring that only authorized medical personnel can obtain encrypted chronic disease data that matches their access requests. Based on this, the entire technical solution achieves end-to-end encrypted management of chronic disease data from collection, transmission, storage, analysis to access for medical scenarios, making data processing both secure and controllable, and analytically usable.
[0030] In an exemplary embodiment, chronic disease data of each target object is collected and encrypted to obtain encrypted data, and the encrypted data is uploaded to a preset blockchain network through a preset secure channel, including steps S201 to S203.
[0031] Step S201: Collect chronic disease data of each target object, and encrypt the chronic disease data in blocks according to the preset encryption rules and the preset privacy level based on the characteristics of the chronic disease data to obtain each encrypted data block.
[0032] Among them, the encrypted data block refers to the structured encrypted unit generated after encryption processing, which is used as the basic storage unit for blockchain uploading and verification. For example, it is an independent encrypted data fragment containing key depth, field index and hash identifier.
[0033] For example, after collecting chronic disease data from various target objects, the chronic disease data is encrypted according to a preset encryption rule. The encryption rule represents the algorithm logic and key generation method followed when encrypting the chronic disease data. It is used to specify a unified standard for data segmentation, encoding, and key depth, such as determining the encryption strength and encryption method corresponding to different types of data fields, so as to ensure the security and consistency of data during transmission and storage.
[0034] Furthermore, this encryption rule, combined with a privacy level preset based on the characteristics of chronic disease data, standardizes the encryption strength and encryption process layers for data with different levels of sensitivity, thereby performing differentiated encryption operations on different types of data. The privacy level preset based on the characteristics of chronic disease data represents a security level system established according to the sensitivity and privacy risks of different fields in the chronic disease data, used to distinguish the level of protection that should be adopted when encrypting data. Specifically, based on the privacy level preset based on the characteristics of chronic disease data, the data is divided into three security levels: high, medium, and low. High-level data includes highly sensitive information such as personal identification and medical records; medium-level data includes records of changes in physiological indicators; and low-level data includes statistical or auxiliary information, thus achieving tiered protection.
[0035] Based on this, the encryption rules determine the corresponding encryption strength according to the privacy level of the data. Higher-level data uses deeper key depths and multi-layered nested structures, while lower-level data uses standard keys to achieve a balance between security and computational efficiency. After encryption, each encrypted segment is encapsulated in blocks, ensuring that each encrypted data block exists independently and has traceable identification information, forming a basic storage unit that can be subsequently transmitted and registered on the blockchain.
[0036] Therefore, this encryption process, which pre-defines privacy levels based on the characteristics of chronic disease data, has specific applicability and practicality in clinical scenarios. Because chronic disease data is characterized by its long-term, continuous, and multi-source heterogeneous nature, the differences in sensitivity between different fields directly affect the balance between clinical analysis and privacy protection. This encryption process classifies chronic disease data into different levels based on its medical attributes and clinical usage scenarios. This ensures that core data is protected while maintaining computability, while general statistical data is transmitted and computed efficiently with lower key depths. This approach ensures security while preserving the continuity and usability of medical analysis. Therefore, this method cannot be achieved simply by dividing privacy levels in any data scenario; rather, it is a hierarchical encryption mechanism specifically designed for the multidimensional characteristics of chronic disease data.
[0037] Step S202: Generate authentication information based on each encrypted data block, and establish a secure transmission session with dynamic negotiation characteristics within the secure channel based on the authentication information.
[0038] Step S203: Based on the secure transmission session, each encrypted data block is encrypted and transmitted within the secure channel to upload the encrypted data block to the blockchain network.
[0039] For example, after the generation of each encrypted data block is completed, in order to ensure the authenticity and reliability of the data source during the transmission process, it is necessary to establish authentication information to identify the legality and integrity of the data during the transmission process. The authentication information refers to the verification data created after the encrypted data block is generated based on its source, content and encryption characteristics. For example, it includes the identifier of the encrypted data block, encrypted digest information and time tag, so as to ensure that the data identity can be verified in subsequent communications and to prevent forgery or tampering.
[0040] After generating authentication information for each encrypted data block, a dynamic negotiation mechanism is initiated in the secure channel based on this authentication information to construct a secure transmission session with dynamic negotiation characteristics. This enables the encrypted transmission of each encrypted data block within the secure channel and its uploading to the blockchain network. The secure transmission session refers to a dynamic communication connection established within the secure channel based on authentication information. It is used to execute controlled transmission of encrypted data blocks during the data upload phase. For example, a session identifier is established by using authentication parameters and a session key generated through one-time negotiation. This limits the timeliness and uniqueness of data interaction throughout the entire transmission cycle, ensuring the security and traceability of the transmission process.
[0041] Specifically, encrypted data blocks, secure transmission sessions, and secure channels constitute a continuous hierarchical relationship in the secure transmission of chronic disease data. Encrypted data blocks are basic data units processed with privacy grading and encryption rules, carrying specific chronic disease data. Secure transmission sessions are communication sessions dynamically established based on authentication information before transmission, used to limit the timeliness and legitimacy of encrypted data block transmission. Secure channels are the underlying encrypted communication paths that carry the session, providing a physically and logically isolated protective environment for the transmission of encrypted data blocks. These three are sequentially linked: encrypted data blocks are encapsulated and identified through secure transmission sessions and are completely transmitted within secure channels, thus forming a three-layered security structure of mutually constraining data content, transmission control, and transmission medium, ensuring the trustworthiness of chronic disease data throughout the entire process from the source to the blockchain network.
[0042] Furthermore, each secure transmission session is dynamically negotiated and generated by a pre-defined system, used to transmit a set of encrypted data blocks within a specific time period or task scope. Multiple encrypted data blocks are uploaded sequentially within the same session to ensure that batch data has unified authentication and encryption control, thereby improving transmission efficiency and management consistency while ensuring security.
[0043] Furthermore, the uploading process of chronic disease data typically involves multi-terminal collaboration, cross-time-period batch synchronization, and continuous updates. If fixed-key transmission is used for an extended period, security risks can easily accumulate over multiple rounds of communication. The aforementioned dynamic negotiation mechanism, by regenerating authentication parameters and session keys in each session, enables multiple encrypted data blocks to be transmitted in a controlled sequence within a unified session format, thus avoiding the leakage risks associated with long-term key reuse. Based on this, this session construction method can accurately match the dynamic collection and blockchain uploading process of chronic disease data, possessing structured applicability and security management value for clinical scenarios.
[0044] In this embodiment, firstly, chronic disease data is divided into blocks for encryption based on encryption rules and privacy levels, thereby enabling fine-grained control over the encryption strength and structural independence of data at different sensitivity levels. Secondly, authentication information is generated based on the encrypted data blocks, and a secure transmission session with dynamic negotiation characteristics is established to ensure security control in terms of timeliness and reliability during transmission. Thirdly, the encrypted data blocks are uploaded within a secure channel based on the secure transmission session, thereby achieving encryption consistency and traceability throughout the entire process of data transmission and on-chain registration. Based on this, the entire technical solution achieves hierarchical encryption and secure on-chain management of dynamic session transmission for chronic disease data.
[0045] In an exemplary embodiment, after uploading each encrypted data block to the blockchain network, the method further includes steps S301 to S303.
[0046] Step S301: Calculate the hash digest for each encrypted data block to obtain the hash identifier corresponding to each encrypted data block.
[0047] For example, after an encrypted data block is uploaded to the blockchain network, a hash digest calculation is performed on each encrypted data block to achieve data integrity verification and subsequent retrieval management. Specifically, this process takes the ciphertext content, generation time, and encryption parameters of the encrypted data block as input, and generates a fixed-length hash value through a one-way hash operation, thus obtaining the hash identifier corresponding to each encrypted data block. Furthermore, the ciphertext content is not decrypted during the calculation process; instead, a digest is directly generated based on its binary characteristics to maintain the data's verifiability in its ciphertext state.
[0048] After the calculation is completed, a mapping relationship is established between the hash identifier and the corresponding encrypted data block, and the hash index table is recorded. This hash index table becomes the core retrieval basis after the encrypted data block is put on the chain, and can be used to locate, compare and verify the integrity of the data.
[0049] Step S302: Based on the multi-source distribution characteristics in the chronic disease monitoring process in the diagnosis and treatment scenario, determine the consortium blockchain corresponding to the blockchain network, match each hash identifier with each node address of the consortium blockchain, and obtain the address matching record.
[0050] For example, after obtaining the hash identifiers of each encrypted data block, in order to ensure the logical consistency and controllable access of data registration in the blockchain network, the structure of the blockchain network needs to be adapted and configured based on the multi-source distribution characteristics formed during the chronic disease monitoring process. The multi-source distribution characteristics indicate that chronic disease data exhibits multi-point distribution across institutions, terminals, and time dimensions during the generation and collection process, reflecting the diversity and geographical dispersion of data sources. For instance, the blood pressure data of the same patient may come from different collection sources such as home monitoring devices, hospital terminals, and community health centers.
[0051] Therefore, based on the multi-source distribution characteristics formed during chronic disease monitoring, the node structure of the blockchain network is screened and configured to determine a consortium blockchain network suitable for chronic disease data collaboration. Here, a consortium blockchain network refers to a blockchain network jointly maintained by multiple nodes with independent data management permissions but needing to collaborate under the same trust framework. Each node represents a different data management entity, used to achieve secure data sharing and consistent verification among medical, research, or public health institutions.
[0052] Subsequently, using the hash identifier corresponding to each encrypted data block as an index, the nodes in the consortium blockchain network are compared and mapped sequentially. In this process, the node's identity, affiliated organization, and on-chain role permissions are matched to determine the node address to which each encrypted data block belongs.
[0053] After the matching is completed, a corresponding address matching record is generated. The address matching record represents the matching result formed according to the correspondence between hash identifier and node address when mapping encrypted data blocks to the consortium blockchain network. It is used to indicate the target node address to which each encrypted data block should be registered. For example, it records the association information between the hash identifier of an encrypted data block and the node address corresponding to the hospital to which it belongs.
[0054] Therefore, it is evident that selecting and configuring the node structure of a blockchain network based on the multi-source distribution characteristics formed during chronic disease monitoring to determine a suitable consortium blockchain network for chronic disease data collaboration represents a scenario-applicable network construction process. This process does not simply set a fixed consortium blockchain network, but rather dynamically determines the node composition with medical collaboration attributes based on the characteristics of chronic disease data distribution across institutions, terminals, and time periods. Each node functionally corresponds to a different data management entity, and the network structure is configured to match data flow paths and security requirements, thus enabling the consortium blockchain network to be targeted and practical for chronic disease data collaboration and verification.
[0055] Step S303: Write each encrypted data block to the blockchain network according to the address matching record.
[0056] For example, during the process of writing each encrypted data block to the blockchain network, address matching records are used as indexes to verify the correspondence between the hash identifier of the encrypted data block and the node address, ensuring that the data is accurately transmitted to the designated node. Subsequently, each node performs consistency verification on the received encrypted data block and completes block generation and on-chain data updates, making each encrypted data block a stable on-chain entry in the blockchain network. Based on this, targeted data registration and multi-node synchronization are achieved, ensuring that the uploaded data has traceable, verifiable, and tamper-proof characteristics, thereby obtaining a complete and reliable on-chain data structure.
[0057] In this embodiment, firstly, a hash digest calculation is performed on each encrypted data block to generate a corresponding hash identifier, thereby verifying the integrity and uniqueness of the encrypted data content. Secondly, based on the multi-source distribution characteristics of the chronic disease monitoring process, a corresponding consortium blockchain is determined, and an address matching record is established, thereby realizing the logical correspondence and distributed allocation between data and consortium blockchain nodes. Thirdly, based on the address matching record, each encrypted data block is written into the blockchain network, thereby realizing the targeted registration and traceable storage of encrypted data. Based on this, the entire technical solution realizes a full-process verification system from encrypted data identification and node mapping to on-chain registration, ensuring the security, consistency, and traceability of chronic disease data stored on the blockchain.
[0058] In an exemplary embodiment, based on the indexing mechanism of the blockchain network, homomorphic encryption analysis is performed on the chronic disease indicator field in the encrypted data to obtain the ciphertext analysis result reflecting the disease trend in the ciphertext state, including steps S401 to S402.
[0059] Step S401: Based on the indexing mechanism of the blockchain network, the on-chain positional relationship of the chronic disease indicator fields in the encrypted data is parsed to obtain the ciphertext space used to support homomorphic operations.
[0060] Among them, the on-chain position relationship of chronic disease indicator fields represents the storage order, distribution nodes and index mapping relationship of each chronic disease indicator field in the blockchain network. It is used to determine the corresponding on-chain position of the same target object at different times or from different sources. For example, the storage path and time index sequence of fields such as blood sugar and blood pressure in different blocks.
[0061] The ciphertext space used to support homomorphic operations represents a computable data domain built on the on-chain positional relationship of encrypted data. It enables homomorphic operations to be performed without exposing the original data, thereby achieving a secure computing environment for disease trend analysis. For example, it allows for weighted, comparative, or aggregated calculations of the encrypted values of multiple chronic disease indicator fields in the ciphertext state.
[0062] For example, firstly, based on the indexing mechanism of the blockchain network, the storage location, associated block number, and node identification information of each chronic disease indicator field are read; then, through this information, the on-chain positional relationship of each chronic disease indicator field is structured and analyzed, thereby identifying the field correspondence between the same target object at different time periods or different nodes, so that the originally dispersed encrypted data forms a traceable structural chain at the logical level.
[0063] Next, based on the field correspondence obtained from the parsing, each chronic disease indicator field is reorganized into the corresponding computable data domain in order to construct a ciphertext space to support homomorphic operations. This ciphertext space defines the index position, access path, and operation boundary of each chronic disease indicator field in the ciphertext state, so that the encrypted data has overall computational capabilities while maintaining independence.
[0064] Therefore, homomorphic operations require data to possess addressability and structural consistency in mathematical space. Chronic disease data is complexly distributed on the blockchain; without parsing the on-chain positional relationships, the executability and consistency of subsequent encryption operations cannot be guaranteed. Through the above processing, multiple ciphertext spaces are ultimately obtained after index reconstruction. Essentially, each ciphertext space is a computational domain constructed based on the same target object, and the chronic disease indicator fields it contains all originate from encrypted data uploaded by this target object at different times or from different collection sources. Thus, by aggregating these scattered fields into the same ciphertext space, it maintains logical continuity and computability in the ciphertext state, thereby ensuring that the homomorphic operation results accurately reflect the disease progression trend of the target object.
[0065] Step S402: In the encrypted space, based on the periodic correlation between fields, perform homomorphic operations on the covered chronic disease indicator fields according to algorithm logic to obtain encrypted analysis results that reflect the disease trend in the encrypted state.
[0066] Among them, the periodic correlation between fields represents the dynamic relationship between the same or multiple chronic disease indicator fields within different time periods. It is used to describe the regular structure of indicator values as they evolve over time, such as the corresponding trend relationship between blood glucose levels and blood pressure changes within a continuous monitoring period.
[0067] For example, within the encrypted space constructed in the aforementioned steps, homomorphic operations are performed on the corresponding chronic disease indicator fields to achieve quantitative analysis of disease progression trends while maintaining the encrypted state of the data. Specifically, firstly, based on the field index structure established in the encrypted space, the numerical relationships of the corresponding chronic disease indicator fields are read and mapped, logically recombining the originally scattered data into a computable dataset. Subsequently, homomorphic operations are performed according to the preset algorithm logic, performing basic mathematical operations such as addition, multiplication, and proportion on the values of each chronic disease indicator field in the encrypted state to simulate indicator calculations in a plaintext environment, while the calculation results remain encrypted, ensuring that the entire calculation process does not touch the original data content.
[0068] Furthermore, by combining the periodic correlation between chronic disease indicator fields, homomorphic operations are performed on the values of the corresponding chronic disease indicator fields, so that the operation results reflect the dynamic changes between different collection periods in the time dimension, so as to obtain the encrypted analysis results that reflect the disease trend in encrypted state; that is, the establishment of periodic correlation depends on the statistical mapping between data of the same target object in different time periods, so as to capture the long-term change trend in encrypted state.
[0069] Therefore, it is evident that, within the encrypted space, by combining the periodic correlations between fields and performing homomorphic operations on the corresponding chronic disease indicator fields based on algorithmic logic, the resulting encrypted analysis results have specific application scenarios. Specifically, this process is not a simple repetitive calculation of encrypted data, but rather a calculation based on the dynamic coupling between the time-series characteristics of chronic disease data and physiological indicators. Through algorithmic logic, encrypted weighting and difference calculations are performed between indicators, and then combined with periodic correlations to extract long-term trends, enabling the calculation results to reflect the directionality and rhythm of disease progression in the encrypted state. Thus, this homomorphic operation method is designed for the periodic and cumulative characteristics of chronic disease monitoring, reflecting actual disease progression patterns without decrypting the data, and possesses practical applicability for diagnostic and treatment analysis.
[0070] In this embodiment, firstly, a ciphertext space is constructed to support homomorphic operations by parsing the on-chain positional relationships of chronic disease indicator fields. This achieves unified positioning and logical mapping of distributed data in the ciphertext state, ensuring structural consistency and addressing feasibility in subsequent operations. Secondly, in the ciphertext space, homomorphic operations based on algorithmic logic are performed on the chronic disease indicator fields, combined with the periodic correlation relationships between fields. This extracts ciphertext analysis results reflecting disease trends while maintaining the ciphertext state of the data. Based on this, the entire technical solution achieves the collaborative processing of encrypted data structure reconstruction and trend analysis, enabling chronic disease data to complete calculations and correlation analysis under fully encrypted conditions, ensuring the unity of security and clinical analysis value.
[0071] In an exemplary embodiment, the method further includes steps S501 to S502.
[0072] Step S501: Obtain a training set based on the pre-defined features of chronic disease data, and desensitize sensitive information in the training set to obtain the target training set.
[0073] Among them, the training set based on the pre-defined characteristics of chronic disease data refers to a data set that is structured according to the characteristics of chronic disease data such as temporal continuity, multidimensionality of indicators and individual differences. It is used to provide a sample basis that reflects the trend of disease course during the algorithm learning stage. For example, it includes a sample set containing multi-period monitoring data such as blood glucose, blood pressure, heart rate, and weight and their time series labels.
[0074] For example, before performing homomorphic operations on the corresponding chronic disease indicator fields based on algorithmic logic within the encrypted space, a training set is obtained for the algorithm's logic learning computation. This training set typically contains a large amount of sensitive information involving personal privacy; therefore, the data content must be strictly anonymized before training. Specifically, firstly, the fields in the training set are filtered according to preset data classification rules to identify sensitive parts containing identity identifiers, geographical locations, or medical records. These are then de-identified through methods such as replacement, masking, or perturbation, thereby achieving privacy protection without affecting the statistical distribution characteristics of the data. Next, the anonymized data undergoes feature normalization and structuring processing to ensure that data from different sources and in different formats have consistent field dimensions and numerical scales during training.
[0075] Therefore, the learning of the algorithmic logic used for homomorphic operations depends on the integrity and security of data features. If the original data is used directly for training, there is a risk of privacy leakage; while excessive anonymization will destroy the correlation between data. Thus, by using a reasonable anonymization process, a target training set can be obtained that preserves the characteristics of chronic disease data without leaking privacy.
[0076] Step S502: Based on the target training set, learn and calculate the homomorphic operation parameters under different candidate ciphertext spaces to obtain the algorithm logic that supports calling under any candidate ciphertext space, so as to perform homomorphic operations on the chronic disease indicator fields under any candidate ciphertext space.
[0077] The candidate ciphertext space represents multiple computable data fields generated through encryption methods and possessing independent structural features under different encryption environments. These fields are used to learn and verify the adaptability of homomorphic operation logic during the algorithm training phase.
[0078] For example, based on the target training set obtained in the preceding steps, homomorphic operation parameters under different candidate ciphertext spaces are learned and calculated to construct algorithm logic that can be universally applied in any encryption environment. Specifically, firstly, the structural features of the candidate ciphertext spaces are analyzed to identify the differences in field indexing methods, ciphertext mapping structures, and encryption depths among the candidate ciphertext spaces, and these differences are used as input conditions for parameter learning. Subsequently, the homomorphic operation parameters under different candidate ciphertext spaces are trained using the target training set, enabling the operation logic to perform weighted analysis and difference calculation between indicators in the ciphertext state. Furthermore, during the training process, based on the time series characteristics and periodic correlation of the indicators, multiple rounds of iterative learning are performed on data within different collection periods to extract the encryption calculation patterns corresponding to long-term trends. Thus, through this training method, the algorithm logic can accurately express the directionality and rhythm of the disease progression trend in the ciphertext state.
[0079] Next, the adaptation performance of the trained homomorphic operation parameters is verified in multiple candidate ciphertext spaces, and the computational convergence and stability indices under different candidate ciphertext spaces are recorded. The differences between the candidate ciphertext spaces are then uniformly mapped to form an algorithm logic that can be called across ciphertext spaces.
[0080] Therefore, chronic disease data comes from diverse sources and has inconsistent encryption structures. If the computational logic does not have the ability to operate across ciphertext spaces, the comparability and trend consistency of homomorphic operation results cannot be guaranteed. Thus, through the above process, an algorithm logic that supports execution in any candidate ciphertext space is finally obtained, enabling it to stably complete the weighting, comparison, and trend extraction of indicators in different ciphertext spaces, providing a unified and transferable computational foundation for the ciphertext analysis stage.
[0081] In this embodiment, firstly, the training set is anonymized to generate a target training set, thereby eliminating privacy risks while preserving the characteristics of chronic disease data and providing a secure and authentic data foundation for subsequent algorithm logic training. Secondly, the algorithm logic is trained by learning and calculating homomorphic operation parameters under different candidate ciphertext spaces, enabling it to perform indicator weighting, difference calculation, and periodic trend extraction in ciphertext. Based on this, the entire technical solution realizes algorithm learning for chronic disease data, enabling the operation logic to have multi-space adaptability and disease course trend expression capabilities while ensuring privacy.
[0082] In an exemplary embodiment, the identity of the medical access object corresponding to the access request is authenticated according to the access control mechanism based on the blockchain network, including steps S601 to S603.
[0083] Step S601: Determine the target data corresponding to the access request. In the access control mechanism of the blockchain network, generate the access request and the corresponding blockchain node authentication credentials based on the on-chain location information of the target data in the blockchain network.
[0084] For example, after determining the target data corresponding to the access request, the on-chain location information of the target data in the blockchain network is extracted, including the block number, hash identifier, record time, and associated node identifier. This information enables the determination of the uniqueness and verifiability of the target data in the on-chain distribution structure. Subsequently, based on the blockchain network's access control mechanism, the access request is matched with the on-chain data information of the target data to identify the blockchain node responsible for storing and verifying the target data. Furthermore, based on the obtained matching results, authentication credentials for the access request and the corresponding blockchain node are generated. These credentials are jointly generated using the access request identifier, the hash identifier of the target data, and the node key parameters, and are used to establish a trusted authentication chain between the accessing party and the node in subsequent interactions.
[0085] Therefore, data access in this blockchain network requires authorization and verification based on on-chain data information. Traditional identity-based authorization cannot reflect the true binding relationship of data on the chain. Therefore, it is necessary to generate authentication credentials based on the on-chain location characteristics of the data so that each access operation has a unique verification basis.
[0086] Step S602: Based on the authentication credentials, perform zero-knowledge proof interaction processing between the medical staff access object corresponding to the access request and the blockchain node to generate proof data without presenting identity information.
[0087] Step S603: Authenticate the identity of the medical staff accessing the device based on the proof data, and obtain the identity authentication result corresponding to the medical staff accessing the device.
[0088] For example, after obtaining the authentication credentials between the access request and the blockchain node, an encrypted interaction channel is established between the medical staff accessing the device and the designated blockchain node based on the authentication credentials. A zero-knowledge proof process is then performed within this encrypted interaction channel to complete the authorization verification without revealing the accessor's true identity information. Specifically, first, a random verification sequence is generated based on the content of the authentication credentials to distinguish different verification rounds during the interaction. Then, in each verification round, the blockchain node initiates a verification challenge to the medical staff accessing device based on the random verification sequence, requiring the medical staff accessing device to calculate the verification response based on the authentication credentials. Next, the medical staff accessing device generates response data using its own authorization key and the authentication credentials content and returns it to the blockchain node for verification. The blockchain node compares and analyzes the received response data with the expected result to confirm the consistency between the medical staff accessing device's calculation process and the authentication credentials.
[0089] Based on this, through this verification mechanism based on mathematical relationships, neither party needs to transmit or disclose any plaintext identity information throughout the entire process, achieving a balance between privacy protection and access control. After verification, the key content of the authentication credentials generated during the verification process, the random verification sequence, response data, and node verification results are organized into structured proof data.
[0090] Furthermore, based on this proof data, the final identity authentication of the medical staff accessing the device is performed. This involves comparing the completeness of the random verification sequence, the consistency of the response, and the node verification results to determine whether the medical staff accessing the device has legitimate access rights. If the medical staff accessing the device passes the identity authentication, the identity authentication result is generated and recorded in the access control module of the blockchain network to form a traceable authorization record.
[0091] Therefore, in the context of medical treatment, on the one hand, the generation process of authentication credentials centers on the on-chain location of specified chronic disease data, associating access requests with specific blockchain nodes. This ensures that the authentication process directly corresponds to the blockchain's storage structure, thereby achieving accuracy and traceability of access authorization. On the other hand, the zero-knowledge proof interaction process is designed to address the high sensitivity of chronic disease data and the multi-institutional collaboration characteristics of medical treatment scenarios. Specifically, by proving the validity of authorization without exposing identity information during the verification phase, it ensures that healthcare users can complete cross-node access verification within the distributed network. Based on this, the corresponding access control methods in the authentication credential generation and zero-knowledge proof interaction processes can both guarantee the compliant use of chronic disease data and prevent identity leakage and on-chain privacy exposure, demonstrating strong scenario-specific relevance and practical value for medical data security management.
[0092] In this embodiment, firstly, based on the on-chain location information of the target data, an authentication credential is generated between the access request and the blockchain node, thereby achieving precise binding between access authorization and data storage structure, ensuring that access control is verifiable and unique. Secondly, zero-knowledge proof interaction is performed based on the authentication credential, thereby generating proof data without exposing the access party's identity information, to perform identity authentication and generate identity authentication results, ensuring that access control is secure and private. Based on this, the entire technical solution implements an on-chain access control mechanism for chronic disease data, enabling the access verification process to simultaneously possess privacy protection, trusted verification, and blockchain traceability characteristics.
[0093] In an exemplary embodiment, the identity of the medical staff access object is authenticated based on the proof data to obtain the identity authentication result corresponding to the medical staff access object, including steps S701 to S702.
[0094] Step S701: Trigger the smart contract logic configured by the blockchain network based on the proof data. The authorization conditions in the smart contract logic correspond to different fine-grained permission level information in the diagnosis and treatment scenario.
[0095] Step S702: Based on the authorization conditions, the proof data is parsed to obtain the dynamic permission level. The preset permission level of the medical staff access object is matched with the dynamic permission level to obtain the identity authentication result corresponding to the medical staff access object.
[0096] Among them, smart contract logic refers to the set of automatically executed rules deployed in the blockchain network, which is used to automatically trigger judgment and processing operations based on preset authorization conditions during the identity authentication process; authorization conditions refer to the criteria used in the smart contract logic to determine the legality of access requests, so as to limit the access permissions of the access party in different data types or operation ranges.
[0097] The different levels of permission information represent a hierarchical permission system based on the role, responsibilities, and authorized scope of the access party. This system is used to precisely control the scope of data that different roles can access and the depth of their operations. For example, doctors have the permission to view and analyze data, while data administrators only have the permission to review and register data.
[0098] For example, after obtaining the proof data generated in the preliminary verification stage, the smart contract logic configured in the blockchain network is triggered based on the key content of the authentication credentials, the random verification sequence, the response data, and the node verification results contained therein, to initiate the identity authentication and permission determination process corresponding to the medical scenario. The authorization conditions in the smart contract logic are preset and integrated during the deployment phase according to the types and characteristics of various proof data, so that these authorization conditions correspond to different fine-grained permission levels.
[0099] Therefore, when parsing the proof data, instead of comparing each type of proof data independently before performing authorization matching, the authentication credentials, random verification sequences, response data, and node verification results are used as input parameters to compare against multiple authorization conditions corresponding to different fine-grained permission levels. This allows for the dynamic determination of the fine-grained level of access permissions based on the content of the proof data.
[0100] When the preset permission level of the healthcare worker accessing the device matches the dynamic permission level parsed from the proof data, an authentication result is generated and recorded in the blockchain network; otherwise, an unauthorized authentication result is returned. Thus, through the above authentication and permission determination process, the authorization determination process closely aligns with the security level classification of chronic disease data access, thereby improving the accuracy and applicability of authentication results.
[0101] For example, during a visit, an access request is received from an attending physician. The system extracts authentication credentials, a random verification sequence, response data, and node verification results from the proof data generated during the pre-verification phase. The smart contract logic embeds this data as input parameters into the authorization condition judgment process. The authentication credentials reflect the identity level of the medical staff accessing the device, the random verification sequence and response data reflect the security and integrity of the interaction, and the node verification result reflects the on-chain trustworthiness of the access request. Therefore, based on the aforementioned proof data, the smart contract logic compares multiple authorization conditions corresponding to different fine-grained permission levels, thereby automatically parsing the corresponding dynamic permission level. If the parsed dynamic permission level matches the attending physician's preset permission level, an authentication result is generated and recorded on the blockchain network.
[0102] Furthermore, the permission level obtained from the data parsing demonstrates that it reflects the dynamic trust level of the healthcare access recipient during the current access process. This level is calculated by comprehensively considering authentication credentials, random verification sequences, response data, and node verification results, representing the immediate access trust level. In contrast, the permission level of the healthcare access recipient is a statically defined authorization range pre-set by the system, based on job duties and roles. These two levels correspond to access security and responsibility authorization, respectively, and there is no data duplication. By comparing these two, it can be determined whether the access request is within the authorized scope, thereby preventing unauthorized access and ensuring the security and accuracy of access control.
[0103] In this embodiment, firstly, the smart contract logic configured by the blockchain network is triggered based on the proof data to parse the proof data. Then, the preset permission level of the medical staff access object is matched and compared with the dynamic permission level obtained based on the proof data parsing, thereby ensuring that the approval of access permissions is subject to both static authorization and dynamic credibility constraints. Based on this, the entire technical solution realizes the integrated determination of identity authentication and access authorization, making the access control process both scenario adaptable, security-constrained, and blockchain traceable.
[0104] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0105] Based on the same inventive concept, this application also provides a blockchain-based chronic disease data security collection and intelligent management system for implementing the aforementioned blockchain-based chronic disease data security collection and intelligent management method. The solution provided by this system is similar to the implementation scheme described in the above method. Therefore, the specific limitations of one or more embodiments of the blockchain-based chronic disease data security collection and intelligent management system provided below can be found in the limitations of the blockchain-based chronic disease data security collection and intelligent management method described above, and will not be repeated here.
[0106] In one exemplary embodiment, such as Figure 2 As shown, a blockchain-based secure collection and intelligent management system for chronic disease data is provided, including: an encrypted collection module 101, a ciphertext analysis module 102, and an authentication module 103, wherein: The encrypted data acquisition module 101 is used to collect chronic disease data of various target objects and encrypt them to obtain encrypted data, and then upload the encrypted data to the preset blockchain network through a preset secure channel. The ciphertext analysis module 102 is used to perform homomorphic encryption analysis on the chronic disease indicator fields in the encrypted data based on the indexing mechanism of the blockchain network, and obtain the ciphertext analysis results that reflect the disease trend in the ciphertext state. The authentication module 103 is used to receive access requests, perform identity authentication on the medical and healthcare access objects corresponding to the access requests according to the access control mechanism based on the blockchain network, and return the data that matches the access request in the encrypted analysis results to the medical and healthcare access objects that have passed the identity authentication, so that chronic disease data can complete the full-link security management process for diagnosis and treatment scenarios in encrypted state.
[0107] In an exemplary embodiment, the encrypted acquisition module 101 is further configured to: acquire chronic disease data of each target object; encrypt the chronic disease data in blocks according to preset encryption rules and a preset privacy level based on the characteristics of the chronic disease data to obtain each encrypted data block; generate authentication information based on each encrypted data block; establish a secure transmission session with dynamic negotiation characteristics in a secure channel based on the authentication information; and encrypt and transmit each encrypted data block in a secure channel according to the secure transmission session to upload each encrypted data block to the blockchain network.
[0108] In an exemplary embodiment, the system further includes a writing module, which is used to: perform hash digest calculation on each encrypted data block to obtain a hash identifier corresponding to each encrypted data block; determine the consortium blockchain corresponding to the blockchain network based on the multi-source distribution characteristics in the chronic disease monitoring process in the diagnosis and treatment scenario; match each hash identifier with the address of each node in the consortium blockchain to obtain an address matching record; and write each encrypted data block to the blockchain network according to the address matching record.
[0109] In an exemplary embodiment, the ciphertext analysis module 102 is further configured to: parse the on-chain positional relationship of chronic disease indicator fields in the encrypted data according to the indexing mechanism of the blockchain network to obtain a ciphertext space for supporting homomorphic operations; and, in the ciphertext space, perform homomorphic operations based on algorithmic logic on the covered chronic disease indicator fields in combination with the periodic correlation between fields to obtain a ciphertext analysis result reflecting the disease trend in the ciphertext state.
[0110] In an exemplary embodiment, the system further includes a training module, which is used to: acquire a training set based on the features of chronic disease data, desensitize sensitive information in the training set to obtain a target training set; and learn and calculate homomorphic operation parameters under different candidate ciphertext spaces according to the target training set to obtain algorithm logic that supports calls under any candidate ciphertext space, so as to perform homomorphic operations on chronic disease indicator fields under any candidate ciphertext space.
[0111] In an exemplary embodiment, the authentication module 103 is further configured to: determine the target data corresponding to the access request; in the access control mechanism of the blockchain network, generate authentication credentials for the access request and the corresponding blockchain node based on the on-chain location information of the target data in the blockchain network; perform zero-knowledge proof interaction processing between the medical staff access object corresponding to the access request and the blockchain node based on the authentication credentials, so as to generate proof data without presenting identity information; and perform identity authentication on the medical staff access object based on the proof data to obtain the identity authentication result corresponding to the medical staff access object.
[0112] In an exemplary embodiment, the authentication module 103 is further configured to: trigger the smart contract logic configured by the blockchain network based on the proof data, wherein the authorization conditions in the smart contract logic correspond to different fine-grained permission level information in the diagnosis and treatment scenario; parse the proof data based on the authorization conditions to obtain the dynamic permission level; match the preset permission level of the medical staff access object with the dynamic permission level to obtain the identity authentication result corresponding to the medical staff access object.
[0113] The modules in the aforementioned blockchain-based chronic disease data security collection and intelligent management system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the computer device's memory as software, so that the processor can call and execute the corresponding operations of each module.
[0114] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of any of the above embodiments.
[0115] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the above embodiments.
[0116] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0117] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0118] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A blockchain-based method for secure collection and intelligent management of chronic disease data, characterized in that, The method includes: Chronic disease data of each target object is collected and encrypted to obtain encrypted data, and the encrypted data is uploaded to a preset blockchain network through a preset secure channel; Based on the indexing mechanism of the blockchain network, homomorphic encryption analysis is performed on the chronic disease indicator fields in the encrypted data to obtain ciphertext analysis results that reflect the disease trend in the ciphertext state. Upon receiving an access request, the system performs identity authentication on the medical staff access object corresponding to the access request based on the permission control mechanism of the blockchain network, and returns the data that matches the access request in the encrypted analysis results to the authenticated medical staff access object, so that the chronic disease data can complete the full-link security management process for diagnosis and treatment scenarios in encrypted state.
2. The method according to claim 1, characterized in that, The process of collecting chronic disease data from various target individuals, encrypting the data to obtain encrypted data, and uploading the encrypted data to a pre-defined blockchain network through a pre-defined secure channel includes: Chronic disease data of each target object is collected, and the chronic disease data is divided into blocks and encrypted according to preset encryption rules and privacy levels based on the characteristics of chronic disease data to obtain each encrypted data block. Authentication information is generated based on each encrypted data block, and a secure transmission session with dynamic negotiation characteristics is established in the secure channel based on the authentication information. According to the secure transmission session, each encrypted data block is encrypted and transmitted within the secure channel to upload the encrypted data block to the blockchain network.
3. The method according to claim 2, characterized in that, After uploading each encrypted data block to the blockchain network, the method further includes: Calculate the hash digest for each encrypted data block to obtain the hash identifier corresponding to each encrypted data block; Based on the multi-source distribution characteristics in the chronic disease monitoring process in the diagnosis and treatment scenario, the consortium blockchain corresponding to the blockchain network is determined, and each hash identifier is matched with each node address of the consortium blockchain to obtain address matching records. Each encrypted data block is written to the blockchain network according to the address matching record.
4. The method according to claim 1, characterized in that, The step of performing homomorphic encryption analysis on the chronic disease indicator fields in the encrypted data based on the indexing mechanism of the blockchain network to obtain ciphertext analysis results reflecting the disease progression trend in ciphertext state includes: Based on the indexing mechanism of the blockchain network, the on-chain positional relationship of the chronic disease indicator fields in the encrypted data is parsed to obtain a ciphertext space for supporting homomorphic operations. In the encrypted space, based on the periodic correlation between fields, homomorphic operations based on algorithmic logic are performed on the covered chronic disease indicator fields to obtain encrypted analysis results that reflect the disease course trend in the encrypted state.
5. The method according to claim 4, characterized in that, The method further includes: A training set based on the pre-defined features of chronic disease data is obtained, and sensitive information in the training set is desensitized to obtain the target training set. Based on the target training set, homomorphic operation parameters under different candidate ciphertext spaces are learned and calculated to obtain algorithm logic that supports invocation under any candidate ciphertext space, so as to perform homomorphic operations on chronic disease indicator fields under any candidate ciphertext space.
6. The method according to claim 1, characterized in that, The step of authenticating the identity of the medical access object corresponding to the access request based on the access control mechanism of the blockchain network includes: The target data corresponding to the access request is determined. In the access control mechanism of the blockchain network, the access request and the corresponding blockchain node authentication credentials are generated based on the on-chain location information of the target data in the blockchain network. Based on the authentication credentials, zero-knowledge proof interaction processing is performed between the medical access object corresponding to the access request and the blockchain node to generate proof data without presenting identity information. The identity of the medical staff access object is verified based on the proof data, and the identity verification result corresponding to the medical staff access object is obtained.
7. The method according to claim 6, characterized in that, The step of authenticating the identity of the medical staff accessing the device based on the proof data to obtain the identity authentication result corresponding to the medical staff accessing the device includes: The smart contract logic configured by the blockchain network is triggered based on the proof data, and the authorization conditions in the smart contract logic correspond to different fine-grained permission level information in the diagnosis and treatment scenario; Based on the authorization conditions, the proof data is parsed to obtain a dynamic permission level. The preset permission level of the medical staff access object is matched with the dynamic permission level to obtain the identity authentication result corresponding to the medical staff access object.
8. A blockchain-based system for secure collection and intelligent management of chronic disease data, characterized in that: The system includes: The encrypted data acquisition module is used to collect chronic disease data of various target objects and encrypt them to obtain encrypted data, and then upload the encrypted data to a preset blockchain network through a preset secure channel. The ciphertext analysis module is used to perform homomorphic encryption analysis on the chronic disease indicator fields in the encrypted data according to the indexing mechanism based on the blockchain network, and obtain the ciphertext analysis results that reflect the disease trend in the ciphertext state. The authentication module is used to receive access requests, authenticate the identity of the medical staff access object corresponding to the access request according to the permission control mechanism based on the blockchain network, and return the data that matches the access request in the encrypted analysis results to the authenticated medical staff access object, so that the chronic disease data can complete the full-link security management process for diagnosis and treatment scenarios in encrypted state.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.