Private library local area network medical knowledge security sharing system

By using a multimodal medical knowledge parsing and reconstruction engine and a controlled peer-to-peer private library network architecture, the problems of multi-source heterogeneous data parsing and standardized reconstruction, access control and privacy protection in the medical knowledge sharing process of existing technologies are solved, and the secure and efficient sharing and management of medical knowledge is realized.

CN121885248APending Publication Date: 2026-04-17THE FIRST AFFILIATED HOSPITAL OF FUJIAN MEDICAL UNIV +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
THE FIRST AFFILIATED HOSPITAL OF FUJIAN MEDICAL UNIV
Filing Date
2026-03-17
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies for sharing medical knowledge among medical institutions suffer from several problems, including poor semantic interoperability of multi-source heterogeneous medical data, inability to uniformly parse and standardize heterogeneous medical knowledge, difficulty in automatically extracting decision rules from clinical treatment guidelines, coarse granularity of clinical access control, lack of desensitization mechanisms for patient privacy information, and lack of traceability of medical knowledge assets.

Method used

A multimodal medical knowledge parsing and reconstruction engine is used for clinical semantic parsing, medical concept association extraction and standardized reconstruction. Combined with a controlled peer-to-peer private library network architecture, a fine-grained dynamic access control matrix, a content security gateway and an anonymization processing unit, it enables secure storage, authorized access and sharing of medical knowledge.

Benefits of technology

It enables unified analysis and standardized reconstruction of multi-source heterogeneous medical knowledge, ensuring the security, sharing flexibility and management depth of medical knowledge, meeting the comprehensive needs of clinical practice and medical research management, and ensuring the security of patient privacy information and the traceability of knowledge assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121885248A_ABST
    Figure CN121885248A_ABST
Patent Text Reader

Abstract

The invention discloses a private library local area network medical knowledge security sharing system, and belongs to the technical field of medical health information. The system takes a multi-modal medical knowledge analysis and reconstruction engine as a core, accesses multi-source heterogeneous medical data through interfaces such as DICOM and HL7, and performs semantic analysis and standardized packaging based on a medical ontology knowledge graph to generate a unified medical knowledge object. The system constructs a controlled peer-to-peer private library network, and realizes two-way encryption transmission and fine-grained dynamic access control between nodes based on a digital certificate; classification and desensitization are carried out on the recognizable information of the patient through the content security gateway, and invisible watermarks are embedded to realize knowledge circulation full-life-cycle traceability. Unified semantic analysis and clinical decision rule conversion of multi-source medical knowledge are realized, and the medical knowledge integration efficiency and sharing compliance in a local area network are remarkably improved on the premise of ensuring privacy security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of medical and health information technology, specifically relating to a private library local area network medical knowledge secure sharing system. Background Technology

[0002] With the continuous development of medical informatization, medical institutions have accumulated a vast amount of medical knowledge resources through long-term clinical diagnosis and treatment and medical research activities. These resources encompass core assets such as clinical treatment guidelines, standardized treatment pathways, case study reports, and cutting-edge medical research literature. As key elements for improving the quality of medical services and the efficiency of clinical research output, the orderly circulation and in-depth utilization of these resources within medical institutions and within specific authorized scopes is particularly important. By constructing an efficient medical knowledge-sharing mechanism, not only can the clinical decision support capabilities of medical staff be significantly enhanced, but it can also promote interdisciplinary and inter-clinical medical research collaboration and knowledge innovation.

[0003] Among these, the private database sharing model based on the local area network environment of medical institutions has become a key technological track to meet the high security requirements of medical data and patient privacy compliance guidelines due to its physical isolation characteristics. This technological direction aims to provide a platform for the secure storage, authorized access, and collaborative use of highly sensitive medical knowledge in a closed or controlled medical network environment. Its core objective is to maximize the release of the value of medical knowledge while ensuring the sovereignty and security boundaries of medical data.

[0004] Existing technologies still face multiple challenges in handling medical knowledge sharing. On the one hand, some solutions primarily focus on the aggregation and publication of single data types such as standardized medical terminology. While technologies like distributed ledgers can improve process traceability, they struggle to simultaneously accommodate complex, multi-source, heterogeneous medical knowledge units such as full-text medical literature, structured clinical guidelines, medical imaging reports, and clinical research experimental data. Furthermore, their sharing mechanisms are often unidirectional, lacking the ability for flexible, dynamic, and controlled bidirectional exchange between multiple medical institution private repositories. On the other hand, while existing medical resource retrieval and sharing platforms have achieved initial integration, their sharing models are generally quite rudimentary, relying mainly on pre-defined identity lists and lacking core security mechanisms such as fine-grained clinical access control tailored to the characteristics of medical knowledge, secure desensitization of patient privacy information, and prevention of secondary distribution of medical knowledge assets. Moreover, existing systems largely focus on application-level retrieval and discovery, while bottlenecks remain in building independent, controllable private repository infrastructure within closed medical LAN environments that supports secure management of complex medical knowledge objects and efficient clinical research collaboration. This makes it difficult to simultaneously meet the comprehensive needs of clinical practice and medical research management in terms of security, sharing flexibility, and management depth. Therefore, there is an urgent need for a secure sharing system for medical knowledge on a private local area network. Summary of the Invention

[0005] The purpose of this invention is to provide a secure sharing system for medical knowledge on a private local area network, in order to solve the technical problems faced by existing technologies in the process of sharing medical knowledge among medical institutions, such as poor semantic interoperability of multi-source heterogeneous medical data, inability to uniformly parse and standardize the reconstruction of heterogeneous medical knowledge such as medical images, clinical diagnosis and treatment records and medical literature, difficulty in automatically extracting and reusing decision rules contained in clinical diagnosis and treatment guidelines, lack of quantitative evaluation mechanism for the quality of medical knowledge before it is entered into the database, as well as coarse granularity of clinical permission control, lack of desensitization mechanism for patient privacy information and lack of traceability of medical knowledge assets.

[0006] To achieve the above objectives, the technical solution proposed by this invention includes: The multimodal medical knowledge parsing and reconstruction engine, as the core processing unit of the system, is used to perform clinical semantic parsing, medical concept association extraction, clinical decision rule transformation, medical knowledge quality assessment and standardized reconstruction on the multi-source heterogeneous medical knowledge units accessed by the system, and generate medical knowledge objects in a unified format. Based on the multimodal medical knowledge parsing and reconstruction engine, the system also includes: a controlled peer-to-peer private library network architecture, used to construct multiple logically isolated private storage nodes within the medical institution's local area network and establish bidirectional controlled exchange links between nodes based on clinical subject association indexes; a fine-grained dynamic access control matrix, used to calculate access permission scores in real time based on medical role attributes, clinical environment context, and medical knowledge sensitivity levels, and to execute dynamic access control; a content security gateway and desensitization processing unit, used to identify patient identifiable information based on a medical privacy feature library during the flow of medical knowledge, and to perform dynamic desensitization and masking processing according to security policies; and a knowledge fingerprint and flow tracing component, used to embed invisible watermarks and behavioral fingerprints into each flowing medical knowledge object, realizing flow tracking and secondary distribution auditing of medical knowledge assets throughout their entire lifecycle.

[0007] In one embodiment of the present invention, the multimodal medical knowledge parsing and reconstruction engine includes: The heterogeneous medical data access module is used to access medical imaging data through medical digital imaging and communication protocol interfaces, access clinical diagnosis and treatment data through electronic health record standardized interfaces, and adapt to full-text medical literature and scientific research experimental data. The medical semantic feature extraction module is used to extract core medical concepts and logical relationships such as disease names, drug names, anatomical sites, surgical terms and physiological indicators from text-based medical knowledge by performing part-of-speech tagging, named entity recognition and semantic vectorization mapping based on a preset medical ontology knowledge graph and using natural language processing technology. The medical metadata standardization encapsulation module is used to encapsulate the extracted medical semantic features and original data units according to the preset medical knowledge object description specifications, and generate standardized medical knowledge objects containing unique global identifiers, medical knowledge type tags, version information and sensitivity and security metadata.

[0008] Preferably, the controlled peer-to-peer private library network architecture uses distributed hash table technology to discover and locate nodes. Each private storage node has an independent encrypted storage space for storing the medical knowledge assets of the medical institution to which the node belongs.

[0009] In another embodiment, the establishment process of the bidirectional controlled switching link includes: The sending medical institution node initiates a sharing request to the receiving medical institution node, and the request carries a metadata digest of the medical knowledge object to be shared and the digital signature of the sending end; The receiving medical institution node verifies the legitimacy of the request and, upon successful verification, returns a receipt confirmation signal and an asymmetric encrypted package containing the symmetric encryption key. The sending medical institution node uses a symmetric encryption key to fully encrypt the medical knowledge object and transmits it to the receiving medical institution node through an encrypted tunnel within the local area network. The transmission process is controlled by the traffic monitoring module. When the instantaneous traffic exceeds the preset traffic threshold, the system automatically executes the traffic limiting strategy to ensure the stability of the local area network bandwidth of the medical institution.

[0010] Furthermore, the fine-grained dynamic access control matrix enables precise determination of medical knowledge access requests by constructing an access control model based on medical attributes.

[0011] In an optional embodiment, the access permission score is calculated as follows: The system obtains the medical role attributes of the accessing entity, including the professional title of medical staff, their affiliated clinical department, and historical integrity score; it also obtains the clinical environment context, including the security level of the medical area where the accessing terminal is located, the access time period, and the security hardening status of the terminal device; and it obtains the sensitivity level of the target medical knowledge object, which is automatically assessed by the content security gateway based on the density of patient privacy features contained in the medical knowledge content.

[0012] Input the above attributes into the preset permission evaluation algorithm to calculate the real-time access permission score.

[0013] When the access permission score is higher than the preset admission threshold, the system grants full access permission; when the access permission score is in the preset downgrade range, the system grants only desensitized restricted access permission; when the access permission score is lower than the preset blocking threshold, the system rejects the access request and records the clinical safety event.

[0014] In addition, the content security gateway and the desensitization processing unit are executed before medical knowledge objects are output from the private library to the display terminal or shared with other medical institution nodes.

[0015] In a specific embodiment, the dynamic desensitization process is as follows: The content security gateway uses a pre-set medical privacy feature database to perform a full scan of medical knowledge objects, identifying first-class direct identifiers, including patient names, ID numbers, detailed addresses, and contact numbers, as well as second-class quasi-identifiers, including dates of birth, consultation times, and descriptions of specific rare diseases.

[0016] For the first type of direct identifiers, irreversible masking techniques are used for overlay processing; for the second type of quasi-identifiers, generalization techniques or differential privacy algorithms are used for perturbation processing, thereby reducing the risk of re-identification of specific patients through link attacks while meeting the clinical research reference value.

[0017] The intensity of desensitization is controlled by the access permission score; the higher the score, the lower the intensity of desensitization and the more medical information details are retained.

[0018] In one optional implementation, the knowledge fingerprint and flow tracing component embeds specific information into the binary stream or pixel layer of medical knowledge objects to achieve medical knowledge copyright protection and leakage tracing.

[0019] In another embodiment, the embedding process of the invisible watermark is as follows: The system generates a watermark sequence with strong anti-attack capabilities based on the unique hardware identifier of the receiving medical institution node, the access timestamp, and the medical operator's number.

[0020] By using spread spectrum hiding technology or transform domain coefficient fine-tuning technology, watermark sequences can be embedded into non-critical diagnostic areas of medical images or specific layout spacing of full-text medical documents.

[0021] The embedding process makes the watermark invisible to the naked eye; and within the preset robustness parameters, it maintains extractability for common secondary processing operations such as screenshots, photos, format conversions, or partial cropping, thereby providing a basis for tracing the source of medical knowledge leaks.

[0022] In addition, the system also includes a full lifecycle security audit module, which is used to record every step of the operation of medical knowledge objects from entry into the database, retrieval, preview, download to sharing and exchange between medical institutions in real time.

[0023] The audit log includes the operation time, the medical operation subject, the operation behavior, the identification of the medical knowledge objects involved, and the operation result. Blockchain technology is used to hash the audit log to improve the tamper-proof nature of the audit data and facilitate the preservation of medical audit evidence.

[0024] In a preferred embodiment, the system operates in an independent medical institution local area network physical environment or virtual private network environment. Through physical isolation or logical isolation, unauthorized connections with the external Internet are cut off, keeping medical knowledge assets within a controlled medical security boundary.

[0025] In addition, the multimodal medical knowledge parsing and reconstruction engine also has the function of tracking the evolution of medical knowledge.

[0026] When a clinical practice guideline or medical research report is updated, the system automatically identifies the differences between the old and new versions and sends update reminders to medical staff who have downloaded or referenced the old version. At the same time, it establishes a medical knowledge version evolution chain in a private repository to improve the timeliness and clinical accuracy of medical knowledge.

[0027] Meanwhile, the controlled peer-to-peer private library network architecture supports multi-level medical management models.

[0028] Within a large medical group, each member hospital manages its own private database as a secondary node, while the group headquarters acts as a primary node. Through a pre-defined global retrieval strategy, it achieves indexing and controlled scheduling of the entire group's medical knowledge assets without acquiring the original data from the secondary medical institution nodes.

[0029] Furthermore, the fine-grained dynamic access control matrix also includes behavior deviation monitoring logic.

[0030] The system continuously analyzes the operation sequences of medical users on the medical knowledge sharing platform and uses a hidden Markov model to construct a benchmark for normal operation behavior of medical users. When a user deviates from the benchmark by downloading more than a preset number of items within a predetermined time period, making abnormal searches across clinical disciplines, or intensively accessing highly sensitive patient-related medical knowledge objects during non-clinical on-call hours, the system will increase the risk weight coefficient in the user's access permission score and automatically trigger two-factor authentication or temporary blocking measures.

[0031] In another embodiment, the multimodal medical knowledge parsing and reconstruction engine also integrates a medical knowledge quality assessment module.

[0032] During the medical knowledge entry phase, the system quantitatively scores the professionalism, completeness, and logical consistency of medical knowledge units by comparing them with authoritative medical ontology databases and standardized medical terminology sets. Only medical knowledge units with scores higher than the preset quality score threshold are allowed to enter the sharing sequence, thereby ensuring the quality of shared medical knowledge from the source.

[0033] Optionally, the knowledge fingerprint and flow tracing component also has proactive defense capabilities.

[0034] When unauthorized screen recording software or illegal packet capture tools are detected in the terminal environment, the system automatically overlays a dynamic visible watermark of preset density on the display interface and triggers an alert in the background to restrict the further display of sensitive medical information, thereby increasing the cost of illegal acquisition at the physical level.

[0035] As a preferred embodiment, the controlled peer-to-peer private library network architecture uses an asymmetric encryption algorithm for identity authentication between medical institution nodes.

[0036] Before joining the network, each medical institution node needs to apply for a certificate from the digital certificate management center within the local area network. During the link establishment phase, both parties verify the legitimacy of each other's digital certificates to confirm the true identity of the other medical institution and prevent man-in-the-middle attacks or unauthorized node access.

[0037] In one embodiment, the system's interactive interface adopts a web-based, plug-in-free design, where all online previews of medical knowledge objects are rendered on the server side, and only the rendered pixels are streamed back to the client.

[0038] This design keeps the original medical knowledge object files in a controlled storage area on the server side, and the client does not save the original files; the necessary display cache can be automatically cleared after the session ends or times out, thereby reducing the risk of medical data loss due to terminal virus infection or cache leakage.

[0039] Furthermore, when processing structured clinical diagnosis and treatment guidelines, the multimodal medical knowledge parsing and reconstruction engine automatically extracts the clinical triggering conditions, diagnosis and treatment operation suggestions and prognostic assessment indicators, and transforms them into clinical logic rules that can be executed by computers.

[0040] These clinical logic rules can be integrated into the hospital's clinical decision support system, enabling the transformation of medical knowledge from static storage to dynamic clinical application.

[0041] In an optional embodiment, the system also supports a consensus-based incentive model for medical knowledge contributions.

[0042] Each private database medical institution node receives contribution points based on the frequency and quality of the medical knowledge it shares is accessed, as well as the degree of assistance it provides to other medical institutions. These points can be used as the basis for the medical institution node to apply for higher-level access to medical knowledge or to obtain priority access to system resources in the network, thereby building a healthy medical knowledge sharing ecosystem.

[0043] Preferably, the content security gateway and the desensitization processing unit support custom desensitization templates.

[0044] Medical administrators can pre-configure multiple anonymization templates to meet the needs of different clinical research projects or clinical departments, achieving a balance between patient privacy and clinical research value.

[0045] In addition, the system also includes a one-click secure withdrawal mechanism.

[0046] When errors are found in shared medical knowledge objects or when there are sudden medical safety and compliance risks, the publishing medical institution node can initiate a retraction command. Provided that the receiving medical institution node has deployed a controlled client or a controlled execution agent, the controlled peer network will, based on the flow record, instruct the relevant receiving medical institution node to destroy the local copy or revoke access permissions, and return a record report containing the execution results. Attached Figure Description

[0047] Figure 1 This is a schematic diagram of the overall technical architecture of the private library local area network medical knowledge secure sharing system proposed in this invention; Figure 2 This is a schematic diagram of the core principle framework of the fine-grained dynamic access control matrix in this invention; Figure 3 This is a performance evaluation comparison chart of multimodal medical knowledge parsing and reconstruction in this invention, including the processing latency distribution of different knowledge types and the distribution and consistency of parsing quality scores; Figure 4 This is a network transmission performance analysis diagram of the controlled peer-to-peer switching link in this invention, including the comparison results of encrypted transmission throughput, end-to-end latency, and before and after the rate limiting policy is triggered; Figure 5 This is a security and availability trade-off analysis diagram of the dynamic desensitization strategy in this invention, including the relationship between desensitization intensity and information loss rate, as well as the trade-off curve between re-identification risk and data availability. Figure 6 This is a robustness analysis diagram of the invisible watermark and source tracing mechanism in this invention, including the watermark extraction success rate under attack scenarios such as screenshotting, compression, cropping and format conversion, as well as the trade-off analysis between image quality and watermark robustness. Detailed Implementation

[0048] A private database local area network (LAN) medical knowledge secure sharing system operates in an independent medical institution's LAN physical environment or virtual private network (VPN) environment. For example... Figure 1 As shown, the overall architecture of the system includes a data input layer, a multimodal knowledge parsing engine, a controlled peer-to-peer private library network, a dynamic access control matrix, a content security gateway, a knowledge fingerprint and traceability component, a secure shared output, and an audit center. The data input layer is responsible for accessing multi-source heterogeneous medical data, such as medical literature, clinical records, medical imaging data, and genomics data. After processing by the data adapter, feature extractor, semantic vectorization module, and standardized encapsulation module in the multimodal knowledge parsing engine, the quality assessment unit determines whether the data meets the standards. Qualified medical knowledge objects are stored and distributed in the controlled peer-to-peer private library network, while non-qualified data is returned for reprocessing. During knowledge flow, the dynamic access control matrix makes access decisions based on identity assessment, environment assessment, behavior monitoring, and permission calculation. After the content security gateway performs privacy detection, masking, generalization processing, and differential privacy desensitization operations, permitted knowledge objects enter the secure shared output stage, while requests for unauthorized access are rejected and logged. The knowledge fingerprint and traceability component achieves full lifecycle traceability of knowledge flow through watermark generation, DCT embedding, and leakage tracking. The audit center records access logs and operation records in real time and issues abnormal alarms.

[0049] This system uses a multimodal medical knowledge parsing and reconstruction engine as its core processing unit to achieve unified semantic parsing, automatic conversion, and standardized reconstruction of multi-source heterogeneous medical knowledge, including medical images, clinical records, medical literature, and scientific research data. Building upon this, the system ensures controlled sharing of medical knowledge among multiple medical institutions within the local area network and protects patient privacy through the coordinated operation of a controlled peer-to-peer private repository network architecture, a fine-grained dynamic access control matrix, a content security gateway and de-identification processing unit, and knowledge fingerprinting and flow tracing components.

[0050] The multimodal medical knowledge parsing and reconstruction engine is responsible for feature extraction and standardized encapsulation of multi-source heterogeneous medical knowledge units accessed by the system, generating medical knowledge objects in a unified format. This engine integrates a heterogeneous medical data access module. This module accesses medical image data through medical digital imaging and communication protocol interfaces, reading image metadata, pixel matrices, and diagnostic conclusions; it accesses clinical diagnosis and treatment data through a standardized electronic health record interface, obtaining treatment pathways, medication recommendations, and clinical triggering conditions; and it adapts to full-text medical literature through a pre-defined text stream parsing interface, extracting character encoding and formatting information. For scientific research experimental data, this module utilizes a data exchange interface to obtain experimental parameters, sample information, and observation indicators. All accessed medical data units are temporarily stored in the system's internal high-speed buffer storage area.

[0051] The engine also includes a medical semantic feature extraction module. Based on a pre-defined medical ontology knowledge graph, this module utilizes natural language processing techniques to perform part-of-speech tagging, named entity recognition, and semantic vectorization mapping on text-based medical knowledge. It extracts core medical concepts such as disease names, drug names, anatomical locations, surgical terms, and physiological indicators, and further extracts the logical relationships between these core medical concepts. The medical semantic feature extraction module first segments the original medical text, removes stop words, and performs root word restoration. Then, using the pre-defined medical ontology knowledge graph, the module identifies named entities such as disease names, drug names, anatomical locations, surgical terms, and physiological indicators in the text. For the identified medical entities, the module uses a deep learning model to map them into a high-dimensional semantic space, calculating the semantic distance and association strength between entities. The extracted logical relationships between core medical concepts include disease diagnostic criteria, contraindications for treatment plans, and the interaction logic between drugs.

[0052] The medical metadata standardization and encapsulation module encapsulates extracted medical semantic features and raw data units according to a predefined medical knowledge object description specification, generating standardized medical knowledge objects containing a unique global identifier, a medical knowledge type tag, version information, and sensitivity and security metadata. The unique global identifier is generated using a hash algorithm based on the data content to ensure the uniqueness of the medical knowledge object within the entire medical institution's local area network environment. The medical knowledge type tag distinguishes the clinical origin and purpose of the medical knowledge object. The version information records the update and iteration history of the medical knowledge object. The sensitivity and security metadata includes the sensitivity assessment results of the medical knowledge object, the identifier of the affiliated medical institution, and the initial access policy.

[0053] The multimodal medical knowledge parsing and reconstruction engine automatically extracts clinical triggering conditions, treatment suggestions, and prognostic assessment indicators from structured clinical practice guidelines, transforming them into computer-executable clinical logic rules. These rules are stored in a rule base and can be integrated into hospital clinical decision support systems, enabling the transformation of medical knowledge from static storage to dynamic clinical application. Furthermore, the engine features medical knowledge evolution tracking. When a clinical practice guideline or medical research report is updated, the system automatically identifies the differences between the old and new versions, calculates the difference vector, and sends update reminders to healthcare professionals who have downloaded or referenced the older version. The system establishes a medical knowledge version evolution chain in a private repository, recording the evolution path of medical knowledge through a directed acyclic graph structure, improving the timeliness and clinical accuracy of medical knowledge.

[0054] Furthermore, the multimodal medical knowledge parsing and reconstruction engine also integrates a medical knowledge quality assessment module. During the medical knowledge ingestion phase, the system quantitatively scores the professionalism, completeness, and logical consistency of medical knowledge units by comparing them with authoritative medical ontology databases and standardized medical terminology sets. Professionalism scoring is based on the coverage and accuracy of medical terminology within the medical knowledge content. Completeness scoring is based on whether the medical knowledge object contains necessary metadata fields. Logical consistency scoring uses a logical reasoning engine to detect whether there are contradictory treatment recommendations within the medical knowledge. Only medical knowledge units with scores higher than a preset quality score threshold are allowed to enter the shared sequence.

[0055] To verify the processing efficiency and quality control capabilities of the multimodal medical knowledge parsing and reconstruction engine, 80 publicly available PubMed medical literature abstracts and simulated MIMIC format clinical records were selected for testing. The statistical results are shown in Table 1. Figure 3 As shown, Figure 3 Part (a) shows the processing latency distribution of literature data and clinical data. The median processing latency of clinical data is higher than that of literature data, but the dispersion is lower, indicating that the parsing process of clinical records is more stable. Figure 3 Part (b) shows the scatter distribution of the analytical quality scores for 80 samples. The average quality score for literature data is approximately 0.598, and the average quality score for clinical data is approximately 0.652. The quality threshold is set at 0.6. The quality pass rate of clinical records is significantly higher than that of literature abstracts.

[0056] Table 1. Prototype Test Results of the Multimodal Medical Knowledge Parsing and Reconstruction Engine

[0057] The controlled peer-to-peer private library network architecture is used to construct multiple logically isolated private storage nodes within a medical institution's local area network and establish bidirectional controlled exchange links between nodes. This architecture employs distributed hash table technology for node discovery and location. Each private storage node has an independent encrypted storage space for storing the medical knowledge assets of the medical institution to which it belongs. The distributed hash table assigns a unique node identifier to each medical institution node and maps the global identifier of medical knowledge objects to the corresponding node. When a medical institution node needs to retrieve medical knowledge, it uses the distributed hash table to find the storage node where the target medical knowledge object resides.

[0058] The establishment of a bidirectional controlled exchange link is collaboratively completed by the sending and receiving medical institution nodes. First, the sending medical institution node initiates a sharing request to the receiving medical institution node, carrying a metadata digest of the medical knowledge object to be shared and the sending node's digital signature. The receiving medical institution node verifies the request's legitimacy, including verifying the validity of the digital signature and checking if the sending medical institution node is on the authorized whitelist. After successful verification, the receiving medical institution node returns a reception confirmation signal and an asymmetric encrypted packet containing the symmetric encryption key. The sending medical institution node uses its private key to decrypt the packet to obtain the symmetric encryption key, then uses this key to fully encrypt the medical knowledge object and transmits it to the receiving medical institution node through an encrypted tunnel within the local area network. The transmission process is controlled by a traffic monitoring module, which monitors the data transmission rate and bandwidth utilization in real time. When instantaneous traffic exceeds a preset traffic threshold, the system automatically implements a rate-limiting strategy, adjusting the data packet transmission interval to ensure the stability of the medical institution's local area network bandwidth.

[0059] The controlled peer-to-peer private repository network architecture employs asymmetric encryption algorithms for authentication between healthcare institution nodes. Each healthcare institution node must apply for a certificate from the local area network's digital certificate management center before joining the network. During the link establishment phase, both parties verify the legitimacy of each other's digital certificates to confirm the true identity of the other healthcare institution. The controlled peer-to-peer private repository network architecture also supports multi-level healthcare management models. Within large healthcare groups, each member hospital acts as a Level 2 node managing its own private repository, while the group headquarters acts as a Level 1 node. Level 1 nodes, through a pre-defined global retrieval strategy, achieve indexing and controlled scheduling of the entire group's medical knowledge assets without accessing the original data from Level 2 healthcare institution nodes. Level 1 nodes only store the metadata index uploaded by each Level 2 healthcare institution node, ensuring that ownership of the original medical data remains with the generating institution.

[0060] Building upon this foundation, the controlled peer-to-peer private repository network architecture also supports a consensus-based incentive model for medical knowledge contributions. Each private repository's medical institution nodes receive contribution points based on the frequency of access to their shared medical knowledge, its quality rating, and the degree of assistance they provide to other medical institutions. The system records the point changes for each medical institution node through a distributed ledger. These contribution points can be used as the basis for a medical institution node to apply for higher-level access to medical knowledge or to obtain priority access to system resources within the network. Furthermore, the system includes a one-click secure withdrawal mechanism. When errors are found in shared medical knowledge objects or when there are unforeseen medical safety and compliance risks, the publishing medical institution node can initiate a withdrawal command. Provided that the receiving medical institution node has deployed a controlled client or a controlled execution agent, the controlled peer-to-peer network will, based on the flow record, instruct the relevant receiving medical institution node to destroy its local copy or revoke access permissions, and return a record report containing the execution results.

[0061] To verify the effectiveness of the encrypted transmission and rate limiting strategies in the controlled peer-to-peer private library network architecture, 50 controlled switching link transmission tests were conducted. The rate limiting strategy reduced congestion and retransmissions by smoothing burst traffic; exemplary statistical results are shown in Table 2. Figure 4 As shown, Figure 4 Part (a) in the paper compares the changes in average throughput before and after the rate limiting strategy is triggered. After rate limiting, the average throughput increased from about 86 megabytes per second to about 101 megabytes per second, indicating that the rate limiting strategy effectively improved transmission efficiency by reducing congestion retransmission. Figure 4 Part (b) shows the relationship between data size and transmission latency. The latency of both normal transmission and rate-limited transmission increases with the increase of data size. Rate-limited transmission has slightly lower latency in large data size scenarios. The trend line shows that both have an approximately linear growth relationship.

[0062] Table 2. Prototype Test Results of Transmission Performance in Controlled Peer-to-Peer Switching Link Network

[0063] Fine-grained dynamic access control matrices achieve precise determination of medical knowledge access requests by constructing an access control model based on medical attributes. For example... Figure 2As shown, upon receiving an access request, the fine-grained dynamic access control matrix performs parallel evaluations by the identity attribute evaluation module, the environment attribute evaluation module, and the knowledge sensitivity evaluation module. The identity attribute evaluation module assesses the access subject's professional title, department type, qualifications, and reputation score, outputting an identity score. The environment attribute evaluation module assesses network location, time period, device security status, and threat level, outputting an environment score. The knowledge sensitivity evaluation module assesses the privacy level, data type, source organization, and usage restrictions of the target knowledge object, outputting a sensitivity coefficient. These three factors are then integrated into the permission calculation module to obtain the access permission score. When permissions are sufficient, the system further monitors behavioral deviations; if the behavior is normal, full access is granted; if the behavior is abnormal, an alarm is triggered. When permissions are insufficient, the system determines whether downgrading is possible; if downgrading is possible, restricted access (partially anonymized) is granted; otherwise, access is denied. This matrix calculates the access permission score in real time based on medical role attributes, clinical environment context, and medical knowledge sensitivity level, executing dynamic access control. The calculation process for the access permission score is as follows: First, the medical role attributes of the access subject are obtained, including the medical staff's professional title, affiliated clinical department, and historical integrity score. Higher professional titles and integrity scores result in higher scores for medical role attributes. Secondly, the clinical environment context is obtained, including the security level of the medical area where the access terminal is located, the time period of access, and the security hardening status of the terminal device. Clinical environment contexts originating from a medical security intranet address, occurring during clinical work hours, and with the latest security patches installed on the device receive higher scores. Finally, the sensitivity level of the target medical knowledge object is obtained. The sensitivity level is automatically assessed by the content security gateway based on the density of patient privacy features contained in the medical knowledge content.

[0064] The formula for calculating the access permission score P is as follows:

[0065] In the above formula, Represents real-time access permission scores; Represents the identity attribute weight vector. Represents a vector of quantified identity attributes; Represents the environmental attribute weight vector. Represents a vector of quantified environmental attributes; The numerical value representing the sensitivity level of the target knowledge object. Represents the sensitivity penalty coefficient; This represents the deviation score obtained based on the behavior deviation monitoring logic. This represents the deviation penalty coefficient. This formula, by comprehensively considering identity credibility, environmental risk, content sensitivity, and behavioral deviation, yields a quantitative indicator reflecting the security of the current access behavior.

[0066] Access permissions rating When the threshold is exceeded, the system grants full access, allowing the user to view and download the original knowledge object; when... When the system is in a preset downgrade zone, it only grants restricted access after de-identification; when... When access requests fall below a preset blocking threshold, the system denies the request and logs the security event. The fine-grained dynamic access control matrix also includes behavior deviation monitoring logic: the system continuously analyzes the user's operation sequence on the shared platform, uses a Hidden Markov Model to construct a baseline of normal user behavior, and calculates a deviation score. ;when When the deviation exceeds a preset threshold, the penalty is increased. make Reduced, and triggering two-factor authentication or temporary bans.

[0067] In 100 permission assessments, the average permission score was 1.199 and the standard deviation was 0.263; the decision distribution was: full access 96 times, restricted access 4 times, and blocked access 0 times.

[0068] The content security gateway and desensitization processing unit identify sensitive privacy information during knowledge flow and perform dynamic desensitization and masking processing according to security policies. This unit executes before knowledge objects are output from the private library to the display terminal or shared with other nodes. The dynamic desensitization process first performs a full scan of the knowledge objects using a preset medical privacy feature library. The medical privacy feature library contains a large number of regular expressions, keyword lists, and deep learning recognition models. The scanning process identifies Class 1 direct identifiers, including patient names, ID numbers, detailed addresses, and contact numbers, as well as Class 2 quasi-identifiers, including dates of birth, consultation times, and descriptions of specific rare diseases.

[0069] For Category 1 direct identifiers, the content security gateway employs irreversible masking techniques for overlay processing, such as replacing the middle digits of an ID number with specific characters. For Category 2 quasi-identifiers, generalization techniques or differential privacy algorithms are used for perturbation processing. Generalization techniques convert specific values ​​into range values, such as converting a precise birth date into a range of birth years. Differential privacy algorithms, under a preset privacy budget, add random noise to statistical data. The de-identification strength is controlled by access permission scores; the higher the score, the lower the de-identification strength, and the more information details are retained. The content security gateway and de-identification processing unit support custom de-identification templates. Administrators can pre-configure multiple de-identification templates to achieve a balance between security and research value, tailored to different research projects or clinical department needs.

[0070] A total of 624 personally identifiable information (PII) items (an average of 15.6 items per item) were detected in 40 clinical records, all of which were masked; the average risk was reduced to 0.726. The information loss rates for different levels of desensitization were: low 0.005±0.001, medium 0.005±0.001, high 0.010±0.001, and complete 0.010±0.001.

[0071] like Figure 5 As shown, Figure 5 Part (a) shows the relationship between different desensitization intensities (low, medium, high, and complete) and the information loss rate. As the desensitization intensity gradually increases from low to complete, the information loss rate shows a slow upward trend, but remains at a low level overall, indicating that the desensitization treatment has a limited impact on the integrity of medical knowledge information. Figure 5 Part (b) shows the trade-off between re-identification risk and data availability under different desensitization intensities. The residual re-identification risk decreases continuously with increasing desensitization intensity, and has dropped below the safety threshold of 0.1 under high desensitization intensity and complete desensitization. Although data availability decreases with increasing desensitization intensity, it remains at a high level under complete desensitization mode.

[0072] The content security gateway is also responsible for the secure display of the interactive interface. The system's interactive interface adopts a web-based, plug-in-free design, and all online previews of knowledge objects are rendered on the server side. The server-side rendering engine converts documents or images into pixel streams and only sends the rendered pixel streams back to the client, thereby reducing the risk of the original knowledge objects being copied or leaked on the terminal side.

[0073] The knowledge fingerprint and flow tracing components are used to embed invisible watermarks and behavioral fingerprints into each flowing knowledge object, enabling full lifecycle flow tracking and secondary distribution auditing. The invisible watermark embedding process begins with the system generating a highly attack-resistant watermark sequence based on the unique hardware identifier, access timestamp, and operator number of the receiving node. The watermark sequence undergoes redundant encoding to improve robustness.

[0074] Embedding strength coefficient of invisible watermark The calculation follows the formula:

[0075] In the above formula, The embedding strength coefficient represents the invisible watermark; The content complexity function representing the carrier to be embedded is used to measure the redundancy space that the knowledge object can carry watermark information. This represents the preset parameters for robustness against attacks; The quality maintenance constraint function representing the knowledge object. Its reciprocal term is used to reduce the embedding strength when the carrier quality constraint is more stringent (i.e., more sensitive to embedding distortion). This formula is used to comprehensively balance the watermark's concealment, anti-attack robustness, and carrier quality constraint in different types of medical knowledge objects, ensuring that the watermark remains extractable after common compression, cropping, and other processing.

[0076] The knowledge fingerprinting and flow tracing component utilizes spread spectrum hiding technology or transform domain coefficient fine-tuning technology to embed the watermark sequence into non-critical diagnostic areas of medical images or redundant areas of full-text document layout. The embedding process makes the watermark invisible to the naked eye. The system also possesses proactive defense capabilities. When unauthorized screen recording software or illegal packet capture tools are detected in the terminal environment, the system automatically overlays a dynamically visible watermark of a preset density on the display interface and triggers an alert in the background.

[0077] After embedding invisible watermarks into 10 medical images, the average PSNR was 39.94 dB; and the watermark extraction accuracy was tested under various attack scenarios. Exemplary statistical results are shown in Table 3. Figure 6 As shown, Figure 6 Part (a) shows the comparison of watermark extraction success rates under various attack scenarios. The watermark extraction success rate is 100% under no-attack scenarios and remains at around 99.8% when the JPEG compression quality is 90. As the compression quality decreases to 50, the noise intensity increases to 0.05, or the cropping ratio increases to 10%, the extraction success rate gradually decreases. Among them, cropping and scaling attacks have the most significant impact on watermark extraction. Figure 6 Part (b) shows the trade-off between image quality (PSNR) and watermark robustness. Embedding schemes with higher PSNR correspond to lower embedding strength, resulting in a relatively lower watermark extraction success rate but better image quality. Schemes with lower PSNR have higher embedding strength, resulting in stronger watermark robustness but a decrease in image quality, reflecting a comprehensive trade-off between watermark concealment and anti-attack capability.

[0078] Table 3. Prototype test results of the robustness of the invisible watermark

[0079] The full lifecycle security audit module records every step of the medical knowledge object process in real time, from its entry into the database, retrieval, preview, download, to sharing and exchange between medical institutions. Audit records include the operation time, the medical operator, the operation behavior, the identifier of the medical knowledge object involved, and the operation result. The system uses blockchain technology to hash the audit logs. At preset time intervals, the system generates a Merkle root hash for the audit logs within that period and writes it to the blockchain to improve the tamper-proof nature of the audit data. In the event of a medical data breach, the tracing component extracts the hidden watermark from the leaked files to obtain the identifier of the medical institution node and the medical operator's number from the source of the breach, and performs closed-loop verification by combining this information with the blockchain audit logs.

[0080] In actual operation, when a new medical knowledge unit, such as a medical imaging report containing a rare disease case, enters the system, the multimodal medical knowledge parsing and reconstruction engine first parses it. The heterogeneous medical data access module identifies its image format through the medical digital imaging and communication protocol interface, and the medical semantic feature extraction module identifies disease feature words in the image report based on the medical ontology knowledge graph. The medical metadata standardization and encapsulation module assigns a global identifier to the report and sets its sensitivity to a high level based on its content characteristics. The medical knowledge object is then stored in the private storage node of the affiliated hospital.

[0081] When a researcher from another medical institution attempts to access the case report, a fine-grained dynamic access control matrix is ​​activated. The system obtains the researcher's medical professional title, affiliated clinical department, and current clinical environment context. If the researcher holds a senior professional title and is currently within the medical institution's intranet environment, their access permission score may exceed the admission threshold. However, due to the report's high sensitivity, the content security gateway invoked by the system performs dynamic anonymization. The patient's name and hospital number are masked, and non-critical diagnostic areas in the medical image are embedded with an invisible watermark containing the researcher's identity information. When the researcher previews the report on the webpage, they see a pixel stream rendered on the server side. If the researcher attempts to take a screenshot, the knowledge fingerprint and flow tracing components record this action. If the screenshot is subsequently published to an external network, under preset robustness conditions, the system can extract the hidden watermark sequence from the screenshot to help locate the relevant access subject and time range of the leak.

[0082] If the medical institution node where the researcher works needs to download the medical knowledge object to its local machine for in-depth clinical research calculations, the controlled peer-to-peer private repository network architecture will initiate a bidirectional controlled exchange link. The sending and receiving medical institution nodes mutually recognize digital certificates and then establish an encrypted tunnel. The traffic monitoring module is used to monitor and regulate the impact of the transmission process on the network bandwidth of other business systems of the medical institution. After the transmission is completed, an encrypted copy is added to the private repository of the receiving medical institution node, while the full lifecycle security audit module records the complete medical knowledge transfer process on the blockchain.

[0083] When new clinical follow-up results or diagnostic corrections emerge from the case report, the medical knowledge evolution tracking function of the multimodal medical knowledge parsing and reconstruction engine will identify version differences. The system automatically sends an update notification to the researcher and guides them to obtain the latest standardized medical knowledge object. If subsequent audits reveal legal compliance risks associated with the medical knowledge object, the publishing medical institution node, through a one-click secure revocation mechanism, and provided that a controlled client or controlled execution agent is deployed on the receiving medical institution node, instructs the receiving medical institution node to destroy the copy or revoke access permissions, and the system generates a record containing evidence of the execution result.

[0084] Through the close collaboration of the aforementioned modules, the entire system constructs an open yet tightly controlled medical knowledge sharing ecosystem within the medical institution's local area network. Multimodal medical knowledge parsing ensures the availability of medical knowledge, the peer-to-peer architecture maintains the data sovereignty of the medical institution, dynamic access control enables refined clinical permissions, anonymization protects patient privacy, and the fingerprint tracing and auditing module provides fundamental protection for medical knowledge copyright and medical data security.

[0085] In another implementation, the private library LAN medical knowledge secure sharing system is optimized for cross-regional LAN environments within large-scale medical consortia. In this embodiment, the controlled peer-to-peer private library network architecture introduces a relay forwarding mechanism to handle complex medical network topologies. When a direct point-to-point encrypted tunnel cannot be established between two medical institution private storage nodes, the system automatically selects a relay node with bandwidth redundancy for data forwarding. The relay node is only responsible for the transparent transmission of encrypted data packets and cannot decrypt them to obtain the medical knowledge content.

[0086] In this embodiment, a fine-grained dynamic access control matrix is ​​added, incorporating access constraints based on a medical geofence. The system utilizes location services within the local area network (LAN) to obtain the physical location of the accessing terminal. If an access request originates from an unauthorized physical area, such as outside the medical facility or a non-clinical office area, the system automatically lowers the access permission score below the blocking threshold, regardless of the medical role's attribute score. This location-based mandatory access logic further enhances the physical security of medical knowledge within the medical facility's LAN.

[0087] In this embodiment, the content security gateway and desensitization processing unit integrate a graphics processor acceleration engine. For massive amounts of medical image data, the rendering engine utilizes the parallel computing capabilities of the graphics processor to complete the slice rendering and watermark embedding of 3D medical images within a preset time budget. Simultaneously, the desensitization processing unit can introduce synthetic clinical data generation technology based on generative adversarial networks. For clinical research data that needs to retain statistical characteristics, the system generates synthetic data with a statistical distribution consistent with the original clinical data to replace some patient privacy-sensitive items. This reduces patient privacy risks while providing usable simulated data for training clinical research models.

[0088] In this embodiment, the knowledge fingerprinting and flow tracing component employs a multi-level watermarking nesting technique. A first-level medical institution-level watermark is embedded during the medical knowledge object generation stage, and a second-level user-level watermark is embedded when the medical knowledge object flows to a specific medical user. This nested structure allows the tracing process to clearly distinguish between leaks from medical institutions and leaks from individuals. Furthermore, the proactive defense function adds detection of virtual machine environments and remote desktop connections. When the system detects that a user is running the medical knowledge sharing platform within a virtual machine, it automatically triggers a high-intensity de-identification mode, displaying only the metadata summary of the medical knowledge object.

[0089] In this embodiment, the multimodal medical knowledge parsing and reconstruction engine enhances its ability to process multilingual medical literature. The system incorporates a multilingual medical dictionary and translation model, enabling the unified mapping of medical concepts from heterogeneous languages ​​to a standardized Chinese medical terminology set, thus achieving cross-language medical knowledge retrieval and reconstruction. The medical knowledge quality assessment module also includes a peer review feedback mechanism, allowing healthcare users to provide professional scoring and annotations for shared medical knowledge objects. This feedback is fed back into the assessment algorithm, dynamically adjusting the quality scores of the medical knowledge objects.

[0090] In this embodiment, the full lifecycle security audit module employs a sharded consensus algorithm to improve the write performance of blockchain audit logs. For the large number of audit entries generated by the medical consortium, the system distributes audit tasks across different consensus shards for parallel processing, ensuring that audit records are still accurately and in real-time anchored to the blockchain even under high concurrency. The system also provides a visual medical security situational awareness interface, allowing medical administrators to monitor the topology of medical knowledge flow within the entire medical institution's local area network, access risk trends, and potential leakage warnings in real time, thereby achieving proactive medical security management.

[0091] In this embodiment, the one-click secure withdrawal mechanism supports cascading withdrawal logic. When a source medical institution node initiates a withdrawal command, provided that a controlled client or controlled execution agent is deployed at the receiving medical institution node, the system not only withdraws the copy from the direct receiving end but also tracks and withdraws the copy from the indirect receiving end along the propagation path recorded by the tracing component. Each withdrawal step generates a timestamped evidence report, which is then aggregated at the source medical institution node for auditing and verification of the withdrawal process. Through the synergistic effect of these enhanced functions, the system ensures secure sharing of medical knowledge while improving scalability and flexibility, enabling it to adapt to the needs of medical institutions of varying sizes and complexities.

Claims

1. A secure local area network medical knowledge sharing system with a private database, characterized in that, include: The multimodal medical knowledge parsing and reconstruction engine, as the core processing unit of the system, is used to perform clinical semantic parsing, medical concept association extraction and standardized reconstruction on the multi-source heterogeneous medical knowledge units accessed by the system, and generate standardized medical knowledge objects in a unified format. The multimodal medical knowledge parsing and reconstruction engine integrates a heterogeneous medical data access module, a medical semantic feature extraction module, a clinical decision rule transformation module, a medical knowledge quality assessment module and a medical metadata standardization encapsulation module. Based on the aforementioned multimodal medical knowledge parsing and reconstruction engine, the system also includes: The controlled peer-to-peer private library network architecture is used to build multiple logically isolated private storage nodes within the local area network of a medical institution and establish bidirectional controlled exchange links between nodes. Each private storage node has an independent encrypted storage space, which is hierarchically indexed and organized according to clinical disciplines, disease spectrums and medical knowledge sensitivity levels. Each node completes identity recognition through the digital certificate of the medical institution within the local area network. A fine-grained dynamic access control matrix is ​​used to calculate access permission scores in real time and execute dynamic access control based on medical role attributes, clinical environment context, and medical knowledge sensitivity level through a preset permission evaluation algorithm. The fine-grained dynamic access control matrix includes behavior deviation monitoring logic, which is used to increase the risk weight coefficient when the user's operation deviates from the normal operation behavior benchmark of the clinical diagnosis and treatment process, thereby reducing the access permission score. The content security gateway and desensitization processing unit are used to identify patient identifiable information based on a preset medical privacy feature database and perform dynamic desensitization and masking processing during the flow of medical knowledge. The desensitization intensity of the dynamic desensitization is inversely correlated with the access permission score calculated by the fine-grained dynamic access control matrix. The higher the score, the lower the desensitization intensity. The knowledge fingerprint and flow tracing component is used to embed invisible watermarks and behavioral fingerprints into each flowing medical knowledge object. It adaptively selects the embedding strategy according to the content type of the medical knowledge object, so as to realize the flow tracking and secondary distribution audit of medical knowledge assets throughout their entire life cycle.

2. The private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, The heterogeneous medical data access module reads image metadata, pixel matrices, and diagnostic conclusions from medical images through a medical digital imaging and communication protocol interface. It obtains clinical treatment pathways, medication recommendations, and clinical triggering conditions through a standardized electronic health record interface, and adapts to full-text medical literature through a pre-defined text stream parsing interface. The medical semantic feature extraction module performs named entity recognition and semantic vectorization mapping on textual medical knowledge based on a pre-defined medical ontology knowledge graph. It extracts disease names, drug names, anatomical locations, surgical terms, physiological indicators, laboratory indicators, symptoms and signs, and imaging features as core medical concepts, and extracts the logical relationships between these core medical concepts. These logical relationships include disease diagnostic criteria and treatment plans. The system includes contraindications and drug interaction logic; the clinical decision rule conversion module automatically extracts clinical triggering conditions and treatment operation suggestions from structured clinical diagnosis and treatment guidelines and converts them into computer-executable clinical logic rules; the medical knowledge quality assessment module quantifies the professionalism, completeness, and logical consistency of medical knowledge units, and only medical knowledge units with scores higher than a preset threshold are allowed to enter the shared sequence; the medical metadata standardization and encapsulation module encapsulates the extracted medical semantic features and original data units according to preset medical knowledge object description specifications to generate standardized medical knowledge objects containing a unique global identifier, medical knowledge type label, clinical discipline classification label, version information, and sensitivity and security metadata.

3. A private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, The establishment process of the bidirectional controlled exchange link includes: the sending medical institution node initiates a sharing request to the receiving medical institution node, the request carrying a metadata digest of the medical knowledge object to be shared and the digital signature of the sending end; the receiving medical institution node verifies the validity of the request, and after the verification is successful, returns a reception confirmation signal and an asymmetric encrypted package containing a symmetric encryption key; the sending medical institution node uses the symmetric encryption key to fully encrypt the medical knowledge object and transmits it to the receiving medical institution node through an encrypted tunnel within the local area network; the transmission process is controlled by the traffic monitoring module, and when the instantaneous traffic exceeds the preset traffic threshold, the system automatically executes a traffic limiting strategy.

4. A private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, The calculation process for the access permission score includes: obtaining the medical role attributes of the accessing subject, including the professional title of the medical staff, the clinical department to which they belong, and their historical integrity score; obtaining the clinical environment context, including the security level of the medical area where the accessing terminal is located, the access time period, and the security hardening status of the terminal device; obtaining the sensitivity level of the target medical knowledge object, which is automatically assessed by the content security gateway based on the density of patient privacy features contained in the medical knowledge content; and inputting the medical role attributes, the clinical environment context, and the sensitivity level into a preset permission evaluation algorithm to calculate the real-time access permission score.

5. A private library local area network medical knowledge secure sharing system according to claim 4, characterized in that, The execution logic of the dynamic access control is as follows: when the access permission score is higher than the preset access threshold, the system grants full access permission; when the access permission score is in the preset downgrade range, the system only grants desensitized restricted access permission; when the access permission score is lower than the preset blocking threshold, the system rejects the access request and records the clinical safety event.

6. A private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, The dynamic desensitization process includes: the content security gateway performs a full scan of medical knowledge objects using a preset medical privacy feature library, identifying a first type of direct identifier containing the patient's name, ID number, detailed address, and contact number, and a second type of quasi-identifier containing the date of birth, consultation time, and description of a specific rare disease; irreversible masking technology is used to cover the first type of direct identifier; and generalization technology or differential privacy algorithm is used to perturb the second type of quasi-identifier, reducing the risk of re-identification of specific patients through link attacks while maintaining clinical research reference value.

7. A private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, The embedding strength coefficient of the invisible watermark is determined based on the content complexity function of the medical knowledge carrier to be embedded, the preset anti-attack robustness requirement parameters, and the quality maintenance constraint function of the medical knowledge object. The knowledge fingerprint and flow tracing component uses spread spectrum hiding technology or transform domain coefficient fine-tuning technology to embed the watermark sequence into the non-critical diagnostic area of ​​the medical image or the specific layout spacing of the full-text medical document.

8. A private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, It also includes a full lifecycle security audit module, which is used to record in real time the operation links of medical knowledge objects from storage, retrieval, preview, download to sharing and exchange between medical institutions. The audit records include operation time, medical operation subject, operation behavior, identification of medical knowledge objects involved and operation results. Distributed anti-tampering evidence storage technology is used to anchor and store the medical knowledge flow audit log to meet the non-repudiation requirements of medical data security audit.

9. A private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, The system's interactive interface adopts a web-based, plug-in-free design. All online previews of medical knowledge objects are rendered on the server side. The server then streams the rendered pixels back to the client, ensuring that the original medical knowledge object files remain in a controlled storage area on the medical institution's server, preventing original medical data containing patient privacy from remaining on the terminal side.

10. A private library local area network medical knowledge secure sharing system according to claim 1, characterized in that, It also includes a one-click secure withdrawal mechanism, which, when a medical institution node initiates a withdrawal instruction, instructs all receiving medical institution nodes to destroy their local copies of medical knowledge or revoke access permissions through a controlled execution agent, based on the flow record, and returns a record report containing the execution results.

Citation Information

Patent Citations

  • Intelligent medical data security sharing system based on block chain

    CN121389195A

  • Intelligent data processing method for clinical research

    CN121506527A

  • Data sharing method and system for metabolic acidosis patients

    CN121636469A

  • System, method and computer program for supplying / obtaining medical information through bidirectional communication network

    JP2004227608A