Intensive care identity intelligent management system

By integrating multimodal biometrics and dynamic context-aware identity management systems, the problem of chaotic identity information management in intensive care environments has been solved. This system enables automatic identity association and closed-loop verification across all time domains, processes, and devices, improving the reliability and stability of identity recognition and reducing medical error rates.

CN121902115APending Publication Date: 2026-04-21THE UNIVERSITY-TOWN HOSPITAL AFFILIATED TO CHONGQING MEDICAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
THE UNIVERSITY-TOWN HOSPITAL AFFILIATED TO CHONGQING MEDICAL UNIVERSITY
Filing Date
2025-12-30
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In the current intensive care environment, patient identity information management is chaotic, data from multiple heterogeneous devices cannot be coordinated and linked, medical staff have a heavy workload, and medical safety risks caused by identity recognition errors are high.

Method used

An intelligent identity management system based on multimodal biometric fusion and dynamic context awareness is constructed. Patient identity is obtained through a non-contact 3D facial imaging device and an electrocardiogram feature extraction terminal. Real-time perception is achieved by combining a distributed infrared array camera and a wireless physiological signal receiver. Identity matching is performed using a dual-channel parallel comparison mechanism and a dynamic time warping algorithm. Dynamic context modeling and a 3D authorization model are introduced for access control.

Benefits of technology

It achieves automatic identity association and closed-loop verification across all time domains, processes, and devices, improving the reliability and stability of identity recognition, reducing medical error rates, and ensuring operational safety and data accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121902115A_ABST
    Figure CN121902115A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of computers, particularly relates to an intensive care identity intelligent management system, and aims to solve the problems of disordered patient identity management, multi-device data disjunction and misrecognition risk in intensive care. The system generates a unique identity key by fusing a three-dimensional face point cloud and an electrocardio R-wave sequence, and realizes full-time-domain identity tracking by combining a real-time sensing unit and a dual-channel matching engine; dynamic context modeling and a three-dimensional authorization mechanism are introduced, so that the identity maintenance robustness and the operation safety are improved; and the linkage execution module ensures that each medical equipment data flow is bound with an effective identity tag to form closed-loop verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer technology, specifically relating to an intelligent management system for critical care identity. Background Technology

[0002] In the field of medical informatics, patient identification and management are core components for ensuring safe diagnosis and treatment and improving service quality. With the widespread application of Hospital Information Systems (HIS), Electronic Medical Records (EMR), and Intensive Care Units (ICUs), medical institutions have gradually transitioned from traditional paper-based records to digital management. Among these, patient identification information, as fundamental data throughout the entire clinical diagnosis and treatment process, directly impacts the execution of medical orders, medication safety, matching of test results, and data collaboration between multiple systems, due to its accuracy, uniqueness, and real-time nature. Especially in intensive care settings, patients are often unconscious and unable to speak, requiring frequent monitoring of vital signs, treatment interventions, and transfers, thus placing even higher demands on the reliability of identification.

[0003] Among these, intelligent identity management in intensive care environments has become a key technological direction for medical safety management. This system aims to achieve accurate binding, dynamic verification, and end-to-end traceability of patient identities through automated and intelligent means. It typically involves multimodal data collection (such as biometrics, wristband tags, and device access records), real-time data interaction, and risk warning mechanisms. An ideal intensive care identity management system should be able to continuously maintain the consistency of identity information in complex clinical environments, support information synchronization across devices, systems, and roles, and possess anti-interference, mismatch prevention, and auditability capabilities to cope with high-intensity, high-pressure medical work scenarios.

[0004] While some hospitals have deployed barcode wristband or RFID electronic tag-based identity recognition systems, combined with bedside terminals for manual verification, significant shortcomings remain: The single identity authentication method relies on physical carriers, making it susceptible to identification failures or impersonation risks due to tag detachment, damage, or replacement; the multi-source data fusion capability is weak, failing to effectively integrate behavioral logs from related terminals such as physiological monitoring equipment, infusion pumps, and ventilators for cross-verification; the system lacks a proactive anomaly detection mechanism, making it difficult to promptly detect identity misalignments or information gaps at high-risk points such as patient transfers, shift changes, and emergency resuscitation; furthermore, existing architectures generally lack dynamic identity confidence assessment models based on clinical context, failing to adaptively adjust verification strength according to environmental changes. These problems are particularly pronounced in intensive care, a scenario highly dependent on rapid response and precise execution, easily leading to serious medical accidents such as misdiagnosis and medication errors. Therefore, there is an urgent need to construct an intelligent identity management system for intensive care with multi-dimensional verification, intelligent judgment, and closed-loop management capabilities. Summary of the Invention

[0005] The purpose of this invention is to provide an intelligent identity management system for intensive care units (ICUs) to address the problems of chaotic patient identity information management, lack of collaborative data association among heterogeneous devices, heavy workload for medical staff, and medical safety risks caused by identity recognition errors in existing ICU environments. Currently, ICU units generally rely on manual verification and barcode scanning for identity confirmation. This method is prone to misreading and missed readings in high-load, multi-interference clinical scenarios. Furthermore, various vital sign monitoring devices, infusion pumps, ventilators, etc., operate independently, and the binding relationship between their collected data and specific patient identities is often broken due to human intervention, forming data silos. In addition, frequent patient transfers, equipment replacements, and multi-person collaborative operations during emergency rescue further exacerbate the difficulty of maintaining identity consistency, seriously threatening the continuity of diagnosis and treatment and the accuracy of medication.

[0006] The technical solution of this invention is to construct an intelligent identity management system based on multimodal biometric fusion and dynamic context awareness, enabling automatic association and closed-loop verification of the identity of critically ill patients across all time domains, processes, and devices. The system consists of an identity registration unit, a real-time sensing unit, an identity matching engine, an access control center, and a linkage execution module. Upon patient admission, the identity registration unit acquires initial facial point cloud data using a non-contact 3D facial imaging device and simultaneously collects their electrocardiogram (ECG) R-wave sequence features as dual biometric identifiers. These two types of features are hashed and encrypted to generate a unique identity key, which is then stored in a secure database. The real-time sensing unit is deployed around the patient's bed and includes a distributed infrared array camera, a wireless physiological signal receiver, and a near-field communication sensing loop, continuously capturing changes in facial contours, ECG signal fluctuations, and movement trajectories of active objects within the area. The identity matching engine employs a dual-channel parallel comparison mechanism. The first channel performs geometric deformation matching between real-time captured low-light facial images and point cloud models in the registry, calculating a spatial similarity score. The second channel extracts the R-wave interval sequence from the received electrocardiogram signal, uses a dynamic time warping algorithm to perform waveform alignment analysis with registered features, and outputs a physiological consistency index. When the scores from both channels exceed a preset threshold, the identity is considered validly activated. The access control center dynamically generates access policies based on the identity matching results, allowing only medical records corresponding to authenticated identities to be accessed. All operating terminals must complete a consistency check between locally cached data and the central identity key before displaying patient information. The linkage execution module is responsible for broadcasting identity status information to all connected smart medical devices, including monitors, infusion pumps, blood analyzers, and electronic medical order systems, ensuring that each device's data stream is accompanied by a valid identity tag.

[0007] Furthermore, the system introduces a dynamic context modeling mechanism to enhance the robustness of identity maintenance. The context modeling module collects environmental parameters in real time, including bed occupancy pressure distribution, lighting mode switching sequence, equipment usage frequency curve, and personnel entry and exit logs, constructing a time-series feature vector of the current ward status. When visual or physiological signals decrease in matching confidence due to occlusion or interference at a certain moment, the system initiates a context inference process, evaluating the similarity between the current state vector and historical normal behavior patterns. If it is determined to be within a reasonable range of variation, the original identity association is maintained without interruption; if a significant deviation is detected, such as the disappearance of bed pressure but the physiological signal still appears in its original position, an anomaly alarm is triggered and secondary verification is required. As one embodiment of the invention, the context modeling uses a long short-term memory network structure for training. The input layer receives raw time-series data from various sensors, the hidden layer extracts cross-modal association features, and the output layer predicts the most likely identity state at the next moment. The prediction result is used to compensate for the instantaneous failure of the main matching channel.

[0008] Furthermore, the access control center integrates a three-dimensional authorization model of role-task-context. The role dimension categorizes access levels based on the professional qualifications of medical personnel; the task dimension is bound to specific clinical operation types, such as medication administration, intubation, or imaging examinations; and the context dimension is determined by the current patient's critical condition, the physical location, and the time window. These three dimensions combine to form a fine-grained access control matrix, ensuring that any data access request simultaneously meets the constraints of all three dimensions. For example, a resident physician can only perform vasoactive drug dosage adjustments for patients with blood pressure below 90 / 60 mmHg during night shifts, within the ICU ward; otherwise, the system will lock the relevant functional interfaces. This model supports online updates and rollbacks of policies, and all change records are immutably stored using blockchain technology.

[0009] Furthermore, the linkage execution module establishes a device-level identity synchronization protocol. Each medical device connected to the system has a built-in lightweight identity agent program that periodically reports its own ID, the identity key of the current service object, and the timestamp of the last communication to the central server. The server-side is equipped with a heartbeat monitoring mechanism. If a device fails to update its status for three consecutive cycles or if the reported identity key does not match the latest confirmation result for that bed, a disconnection command is immediately issued and the nursing station is notified. At the same time, all monitoring data packets output by all devices must embed a currently valid identity signature during encapsulation. The receiving end must verify the validity of the signature before parsing to prevent data mismatch. As one embodiment of the present invention, the identity signature is generated using an elliptic curve digital signature algorithm, and the private key is stored in a hardware security module. Each signature operation is accompanied by random number perturbation to resist side-channel attacks.

[0010] Furthermore, the system is equipped with an emergency offline working mode. When the network is interrupted or the main server fails, each terminal device automatically switches to local caching mode to continue collecting and temporarily storing the original data with timestamps. At this time, authentication is downgraded to short-range radio frequency identification (RFID) assisted confirmation based on the most recent successful authentication. Medical staff need to approach the device with an authorized card to complete the operation and unlock it. All data generated during the offline period is uploaded in batches according to time sequence after communication is restored, and the background performs consistency audits, marking potentially conflicting items for manual review. In this mode, critical operations are still subject to a two-person confirmation mechanism, that is, any modification to drug dosage or adjustment of treatment parameters must be swiped by two people with the corresponding permissions in succession to take effect.

[0011] Furthermore, the system incorporates an active learning feedback loop. The results of each identity matching process, including successful confirmation, failed rejection, and manual intervention correction, are recorded as training samples. The background machine learning module performs incremental training weekly to optimize the facial recognition model's generalization ability under extreme poses and adjusts the ECG feature extraction window length to adapt to the signal characteristics of patients with different arrhythmias. Before model updates, offline simulation testing is required, and only models with an accuracy improvement of at least 5% can be deployed in clinical settings.

[0012] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0013] This solution integrates two physiological features—3D facial point cloud and ECG R-wave sequence—to construct a robust and difficult-to-forge composite biometric system. Even when a patient's face is covered by dressings or they are unconscious, continuous identity tracking based on cardiac electrical activity is achieved, fundamentally overcoming the limitations of single-modal recognition in critical care scenarios. The dynamic context modeling mechanism designed in this solution infers identity continuity by combining environmental behavioral patterns, maintaining stable system operation even when the primary sensor signal is temporarily missing. This avoids identity resets and duplicate verifications caused by brief occlusion, significantly improving user experience and system reliability. The implemented 3D authorization model precisely controls personnel permissions down to specific time, location, and clinical context, effectively preventing unauthorized operations and misoperations. To mitigate risks and ensure the safe execution of high-risk medical procedures, this solution establishes a device-level identity synchronization protocol that forces all smart terminals to bind valid identity tags at the data generation source. It also establishes a two-way closed-loop verification system through heartbeat monitoring and signature verification, completely eliminating data mismatch incidents caused by device switching or line crossings. The integrated emergency offline mode ensures basic functionality while introducing dual-person confirmation and post-event auditing mechanisms, balancing operational continuity and security in extreme situations. Furthermore, the active learning feedback loop in this solution enables the system to adaptively evolve, continuously optimizing recognition performance with actual clinical use and maintaining a high level of matching accuracy over the long term. This provides solid technical support for building an intelligent and highly reliable modern intensive care environment. Attached Figure Description

[0014] Figure 1 This is a schematic diagram of the overall technical architecture of the intelligent identity management system for critical care proposed in this invention. Detailed Implementation

[0015] Example 1

[0016] Please refer to Figure 1 This invention provides an intelligent identity management system for intensive care units, enabling automatic, real-time, and device-wide verification of patient identity in high-interference, high-load clinical environments. The system comprises an identity registration unit, a real-time sensing unit, an identity matching engine, a permission control center, a linkage execution module, a context modeling module, a 3D authorization model, a device-level identity synchronization protocol, an emergency offline working mode, and an active learning feedback loop. These functional units work collaboratively to construct a complete technical chain from biometric data collection to data stream binding, and from dynamic permission control to abnormal state response, solving core problems inherent in traditional manual verification mechanisms such as identity misreading, data silos, heavy operational burden, and high medical security risks.

[0017] The system's overall technical process begins with the patient's identity initialization and registration upon admission, followed by a continuous multi-source sensing and dynamic matching phase. Through dual-channel biometric comparison combined with contextual reasoning, a stable identity activation state is maintained. Based on this, the access control center generates fine-grained access policies according to the authentication results and the current clinical context. The linked execution module then broadcasts the identity status to all connected devices, ensuring that every vital sign data point and every treatment operation is accurately bound to the correct patient. When the main sensing channel fails due to obstruction or interference, the system activates a context compensation mechanism to maintain continuity. In extreme cases such as network anomalies, the system switches to offline operation mode while retaining auditing capabilities. Simultaneously, the system continuously optimizes the recognition model performance through periodic incremental training, forming a closed-loop, evolving technological ecosystem.

[0018] The identity registration unit aims to establish a unique and unforgeable composite biometric system for each admitted patient. The unit integrates a non-contact 3D facial imaging device and an electrocardiogram (ECG) feature extraction terminal, simultaneously collecting both types of physiological characteristics when the patient first enters the intensive care unit. The 3D facial imaging device is deployed 2 meters directly above the patient's bed, using structured light projection technology to emit a coded infrared pattern onto the patient's face. A high-resolution infrared sensor array captures the reflected deformation image, and using triangulation principles, reconstructs a facial point cloud dataset containing over 50,000 spatial points. This point cloud data accurately records the spatial distribution of key anatomical structures such as brow bone height, nasal bridge curvature, and cheekbone contour, exhibiting extremely high individual distinguishability. To prevent liveness detection attacks, the system simultaneously detects dynamic fluctuations in the point cloud caused by micro-expression muscle movements during imaging, recognizing only subtle tremors consistent with physiological patterns as genuine human faces.

[0019] While acquiring facial point clouds, the system collects the patient's surface electrocardiogram (ECG) signals via wireless patch electrodes. The electrodes, made of flexible conductive gel material, adhere to standard chest lead locations, continuously acquiring raw ECG waveforms without interfering with routine monitoring. After being preamplified to remove power frequency interference and electromyographic noise, the signals are sent to the QRS wave detection algorithm module. This module, based on an improved Pan-Tompkins algorithm, achieves precise R-wave localization and extracts a time series of all RR intervals within a continuous 60-second interval, denoted as {T1, T2, ..., Tn}, where n is the number of heartbeats during that time period. This sequence characterizes the patient-specific rhythm variability, exhibiting highly individualized characteristics, with significant differences even among identical twins.

[0020] After data acquisition, the system performs hash encryption on the two types of raw features. Facial point cloud data is first downsampled and normalized to convert it into a fixed-dimensional feature vector V_face. This vector is then input into the SHA-3-512 hash function to generate a 512-bit first key K1. The ECG RR interval sequence is first Z-score normalized to eliminate the influence of baseline heart rate. Then, local fluctuation patterns are extracted using a sliding window to construct a two-dimensional Gram angular field matrix (GAF). Finally, this matrix is ​​convolutionally encoded and input into the same hash function to generate a second key K2. Ultimately, the system performs an XOR operation on K1 and K2, outputting a unique identity key K_patient = K1⊕K2 (⊕ being the XOR operation). This key, along with the original feature template, is encrypted and stored in a central database protected by a hardware security module. This dual encryption mechanism ensures that even if a single feature is leaked, the identity information cannot be recovered, greatly enhancing its anti-cracking capabilities.

[0021] The real-time sensing unit aims to achieve 24 / 7, non-intrusive monitoring of all objects moving within the ward space. The unit consists of three types of sensors: a distributed infrared array camera, a wireless physiological signal receiver, and a near-field communication sensing loop. These sensors are arranged in a mesh pattern on the ward ceiling, walls, and bed frame, forming a three-dimensional sensing field with a coverage radius of up to 3 meters. The infrared array camera operates in the 850nm wavelength band and features low-light enhancement capabilities, enabling it to clearly capture changes in facial contours even when the main lighting is off at night. Each camera is equipped with a wide-angle lens and a motorized pan-tilt head, supporting adaptive adjustment of the field of view between 60° and 120°. It dynamically focuses on the target area based on bed occupancy status, preventing unauthorized personnel from entering the field of view and causing interference.

[0022] The wireless physiological signal receiver employs ultra-wideband radio technology, with a center frequency set at 6.8 GHz and a bandwidth of 1.4 GHz, possessing centimeter-level ranging accuracy and strong penetration capability. The receiver array is positioned on both sides of the bedside, continuously monitoring physiological signal broadcast packets from the patch electrodes. Each broadcast packet contains a fragment of the original ECG waveform, device ID, timestamp, and CRC checksum. Upon acquisition, the receiver immediately performs channel equalization and multipath suppression processing to recover high-quality ECG signals for subsequent analysis. To enhance anti-interference capabilities, the system uses a frequency-hopping spread spectrum communication protocol, changing the carrier frequency every 200 milliseconds. The sequence is centrally scheduled by a server to prevent external signal hijacking.

[0023] A near-field communication sensing loop, embedded within the mattress and constructed from multiple turns of copper wire, forms a closed electromagnetic field loop approximately 1 meter in diameter. When a healthcare worker wearing an active RFID wristband approaches within 1 meter of the bed, the sensing loop triggers the wristband's built-in chip, returning their unique identification code and access level. This design enables proximity detection without requiring active card swiping, providing crucial input for contextual modeling. All sensor nodes are connected to an edge computing gateway via industrial-grade Ethernet, with raw data uploaded at a frequency of at least 100Hz, ensuring a time synchronization error of less than 1 millisecond.

[0024] The identity matching engine aims to achieve highly reliable and low-latency verification of patient identities. The engine employs a dual-channel parallel comparison mechanism, processing visual and physiological signals separately. Only when the scores of both independent channels exceed preset thresholds is the identity considered validly activated. The first channel is responsible for facial feature matching, receiving real-time video streams from an infrared camera, extracting the facial ROI region frame by frame, and using an iterative nearest-point algorithm to backproject the current 2D image into 3D space, performing geometric deformation matching with point cloud models in the registry. The matching process considers posture change compensation, constructing a transformation matrix T by estimating head rotation angles (pitch ±45°, yaw ±60°, roll ±30°), and minimizing the Euclidean distance between the two sets of point clouds.

[0025]

[0026] in, Indicates the first point in the registered point cloud One point, This represents the corresponding point in the currently observed point cloud. The number of valid points participating in the matching. This involves rigid body transformation operations, including rotation and translation components. The system employs a random sample-consensus algorithm to eliminate mismatched point pairs, improving robustness. The final output is a spatial similarity score. The value ranges from 0 to 1. A value ≥ 0.85 is considered as passing through the visual channel.

[0027] The second channel is responsible for ECG feature matching. It receives the raw ECG signal from the wireless receiver, filters and corrects the baseline, and then runs the QRS detection algorithm again to extract the RR interval sequence. Due to factors such as respiration and movement, the actual acquired sequence length *m* may differ from the registered template length *n*. Therefore, the system employs a dynamic time warping algorithm to perform nonlinear alignment between the two sequences. The DTW algorithm constructs an M×N cost matrix C, where the elements... , representing the The registration period and the first The squared differences of each measured interval. The optimal path P* is found using dynamic programming to minimize the total cumulative cost:

[0028]

[0029] The final output is the physiological consistency index. ,in The attenuation coefficient is 0.02. This represents the total cost of the optimal path. The value range is from 0 to 1, when A value ≥ 0.82 is considered a physiological pathway passage. The dual-channel decision logic follows an "AND" relationship, meaning that passage only occurs when... ≥ 0.85 and The system only confirms the validity of the current object's identity and updates its online status timestamp when the value is ≥ 0.82.

[0030] The access control hub aims to achieve refined control over access to and operation of medical information. Based on identity matching results, the hub dynamically generates access policies. All terminal devices must complete a consistency verification between locally cached data and the central identity key before displaying patient information. The verification process employs a challenge-response mechanism: when any terminal initiates a data request, the central server randomly generates a 64-bit nonce value, encrypts it, and sends it to the terminal; the terminal decrypts it using a locally stored temporary session key, concatenates it with the currently displayed patient identity key, inputs it into the HMAC-SHA256 function to generate a message authentication code (MAC), and sends the MAC back to the server; the server performs the same calculation and compares it with the expected result. If they match, data refresh is allowed; otherwise, the interface is locked and an alarm is triggered.

[0031] The central system further integrates a three-dimensional authorization model of role-task-context to construct a fine-grained permission matrix. The role dimension categorizes medical staff into five types: resident physicians, attending physicians, nurses, pharmacists, and technicians, each assigned a different default permission level. The task dimension defines nine clinical operation types, including medication administration, infusion rate adjustment, ventilator parameter modification, hemodialysis initiation, imaging examination request, vital sign entry, nursing record completion, and doctor's orders and critical value reporting. The context dimension is jointly determined by three sub-variables: the severity of the patient's vital signs (divided into 1-5 levels based on MEWS score), the physical location (ICU ward, during transport, emergency room, etc.), and the time window (7:00-19:00 for normal shifts, 19:00-7:00 for night shifts).

[0032] Any operation request must simultaneously meet three-dimensional weighted thresholds to be allowed. For example, if a resident physician wants to perform a norepinephrine pump rate adjustment, the system needs to determine: whether the physician is qualified to administer vasoactive drugs (Yes), whether the current task falls under the category of high-risk drug administration (Yes), whether the patient's MEWS score is ≥4 (Yes), whether the operation location is within the ICU ward (Yes), and whether the time is during the on-call period (Yes). If all the above conditions are met, the operation is allowed; if any condition is not met, such as occurring in an unauthorized area or outside of on-call time, the system rejects the request and records the unauthorized attempt event in the background. All policy changes are published through blockchain smart contracts, and each update generates a unique transaction hash, stored in a distributed ledger, supporting post-event traceability and auditing.

[0033] The linkage execution module aims to achieve synchronous propagation and mandatory binding of identity status across the entire device network. This module is responsible for broadcasting identity matching results to all registered smart medical devices, including multi-parameter monitors, infusion workstations, ventilators, blood gas analyzers, bedside ultrasound, and electronic medical order terminals. Each device has a built-in lightweight identity agent program with three core functions: identity monitoring, tag embedding, and signature verification. The agent program receives identity status update messages from the central server by subscribing to a message queue. These messages contain the patient's identity key, effective timestamp, and validity period fields.

[0034] Upon receiving a valid identity message, the device immediately writes it into the operating context and appends an identity tag to the header of all subsequent data packets. For example, a monitor outputs a set of vital sign data packets per second, with the following structure: Start character (2 bytes) + Data type code (1 byte) + Timestamp (8 bytes) + Identity tag (64 bytes) + Original data body (variable length) + CRC32 checksum (4 bytes). The identity tag is the ciphertext of the currently valid identity key encrypted with AES-GCM, which can only be decrypted and verified by an authorized recipient. A digital signature must also be embedded in the data packet before transmission; the signature generation process is as follows:

[0035]

[0036] in, H is the device private key stored in the hardware security module, where H is the SHA-3-384 hash function. The data body to be signed. This is a UTC timestamp. Before parsing the data, the receiving end first verifies the signature validity by performing a signature verification operation using a pre-configured device public key certificate chain. If the verification fails, the data packet is discarded and an exception is reported. This mechanism prevents unauthorized devices from forging data and injecting it into the system, ensuring the trustworthiness of the data source.

[0037] The module also establishes a device-level heartbeat monitoring mechanism. The identity agent program sends a status heartbeat packet to the central server every 10 seconds, containing the device ID, the current service recipient's identity key, the last data collection time, and network latency metrics. The server-side status monitor maintains the set of devices corresponding to each bed and their latest communication timestamps. If a device fails to update its heartbeat for three consecutive cycles, or if the reported identity key does not match the currently confirmed identity for that bed, it is immediately identified as an abnormal state. The system automatically issues a disconnect command, prohibiting the device from continuing to upload data, and notifies the nurse station to check the physical connection status via audible and visual alarms.

[0038] The context modeling module aims to enhance the robustness of identity maintenance and prevent identity reset due to brief signal interruptions. The module collects multi-dimensional environmental parameters in real time to construct a time-series feature vector of the current ward status. ,in A mattress pressure distribution matrix (16×16 pixels) quantifies the body contact area and center of gravity position. This is a sequence of lighting mode switching operations, recording the operation trajectory of light switching and brightness adjustment over the past 5 minutes. To generate a device usage frequency curve, count the number of times each medical device was started and stopped in the past hour; The personnel entry and exit log records the sequence of RFID card swipe events through the access control system.

[0039] When the score of any channel in the identity matching engine falls below the confidence threshold, the system initiates the contextual inference process. The inference process is implemented using a Long Short-Term Memory (LSTM) network structure, which has been pre-trained on historical datasets. The input layer receives the raw temporal vector. After normalization, the data is fed into a two-layer LSTM hidden layer, each containing 128 memory units, using the tanh activation function and sigmoid gating mechanism. The first layer captures short-term dependencies (<30 seconds), and the second layer models long-term patterns (>5 minutes). The output layer is a fully connected layer that predicts the most likely identity state Y_{t+1} ∈ {hold, switch, lose} at the next time step, and outputs three probability distributions through the softmax function.

[0040] If the prediction result is "Keep" and the probability value is ≥0.9, the system maintains the original identity association unchanged to avoid repeated verification caused by temporary occlusion (such as the face being obscured by medical staff) or signal interference. If the prediction is "Switch" and the probability is ≥0.85, it indicates that there may be patient transfer or equipment misconnection, requiring manual verification. If the prediction is "Lost" and lasts for more than 10 seconds, a full re-authentication process is triggered. The model receives newly collected labeled samples for incremental training every week, using mini-batch stochastic gradient descent to update the weights, with a learning rate of 0.001, a batch size of 32, and a training cycle of 50 rounds to ensure that the model continuously adapts to new behavioral patterns.

[0041] The emergency offline working mode aims to ensure basic availability and security of the system under extreme failures. When a network interruption or main server failure is detected, each terminal device automatically switches to local caching mode. In this mode, the authentication mechanism is downgraded to short-range RFID-assisted verification based on the most recent successful authentication. Medical personnel must hold an authorized IC card close to the device's card reader (distance ≤10 cm). The device reads the encrypted permission token stored in the card and binds it to the last valid identity key cached locally for verification. After successful verification, viewing basic patient information and historical data is allowed, but any modification operations are prohibited.

[0042] All devices continue to collect raw data and temporarily store it in local solid-state storage. The data packet format is consistent with online mode, but the identity tag is marked as "offline mode," and the signature field is left blank. Critical treatment operations are still subject to a dual-confirmation mechanism: any modification to drug dosage or adjustment of life support parameters must be authorized by two qualified medical personnel swiping their cards sequentially. The system records the dual IDs, operation time, and device status, generating a joint operation log. After communication is restored, the edge gateway automatically scans the buffers of each device, uploads offline data in batches according to timestamp order, and initiates a consistency audit process.

[0043] The audit process compares the time series data of the central database with local logs to identify potential conflicting entries. For example, if two infusion pumps are found to have recorded infusion operations of the same drug within the same time period, the system will mark the event as a "data race," generate an alert report, and submit it to the quality control department for manual review. All operation records during offline periods are affixed with a special watermark and permanently archived for use as evidence in subsequent medical disputes.

[0044] The active learning feedback loop aims to achieve adaptive evolution of the system's recognition capabilities. The result of each identity matching process is fully recorded as a structured training sample, including input features (facial image, ECG waveform, context vector), output decision (pass / reject), manual intervention label (whether manual correction is needed), and final confirmation result. The backend machine learning platform starts an incremental training task every Sunday at 2 AM, extracting approximately 20,000 new samples from the database over the past 7 days, which are then combined with the original training set to form an updated set.

[0045] The platform prioritizes optimizing the facial recognition model's generalization ability under extreme poses. To address common issues such as excessively high overhead angles, overly prominent side profiles, or partial occlusion, the system employs a deep convolutional generative adversarial network (GAN) for data augmentation. The generator G(z,c) takes random noise z and pose label c as input to synthesize realistic side profile images; the discriminator D(x) judges the image's authenticity. The two are trained adversarially until the generated images are indistinguishable. After adding new samples to the training set, the ResNet-50 backbone network is fine-tuned, freezing the weights of the first four residual blocks and updating only the last two blocks and the classification head. The training loss function uses weighted cross-entropy, with a focus on increasing the weights of difficult samples.

[0046] Simultaneously, the system dynamically adjusts the ECG feature extraction window length. The traditional fixed 60-second window is prone to introducing noise in atrial fibrillation patients; therefore, an adaptive truncation mechanism is introduced: if the coefficient of variation (CV_RR) of the RR interval is detected in real time > 0.15, it is determined to be an arrhythmia state, automatically shortening the feature extraction time to 30 seconds and enabling wavelet denoising preprocessing. Before updating the model, offline testing must be completed in a simulation environment, with the evaluation set covering 1000 typical cases. Only when the average matching accuracy improves by ≥5% and the false positive rate decreases by ≥1% is the new model pushed to clinical devices for gray-scale release. The first batch updates 10% of devices, and after observing no abnormalities for 24 hours, the scope is gradually expanded to ensure that system stability is not affected.

[0047] This embodiment, through the close collaboration of the aforementioned units, constructs a complete intelligent identity management technology system for intensive care. The system no longer relies on a single modality for identity recognition, but instead integrates three-dimensional facial geometric features and electrocardiographic signals to form a highly complementary and anti-interference composite verification mechanism. By introducing dynamic context modeling, the system can maintain identity continuity based on environmental behavior patterns when the main sensor signal is temporarily missing, avoiding frequent restarts of the verification process. The three-dimensional authorization model refines access control to specific times, locations, and clinical contexts, fundamentally eliminating the possibility of unauthorized operations. The device-level identity synchronization protocol forces all data to be bound to valid identity tags at the source, and forms a two-way closed-loop verification through heartbeat monitoring and signature verification, completely eliminating the risk of data mismatch. The emergency offline mode ensures the continuation of basic functions while introducing dual-person confirmation and post-event auditing, taking into account operational safety in extreme situations. The active learning mechanism enables the system to continuously optimize and maintain a high level of matching accuracy over the long term.

[0048] Current technologies generally use barcode wristbands in conjunction with handheld scanners for identity verification. This method is prone to false scans and missed scans in emergency situations, multi-person collaboration, or poor lighting conditions, and it cannot achieve automatic data association between devices. Some advanced systems have attempted to introduce facial recognition technology, but it fails when the patient is unconscious, intubated, or has their face covered by dressings, lacking a backup verification path. This solution achieves a dual-mode verification architecture by fusing facial point cloud and ECG R-wave sequences, two independent physiological features that serve as backups. Even if the patient's face is completely covered by gauze, as long as the heart is still beating, the system can continuously capture their unique heart rhythm characteristics via wireless electrodes to complete identity tracking, truly achieving full-time coverage.

[0049] Furthermore, most existing systems neglect the value of environmental context information. They immediately determine identity loss once the main identification channel is blocked, leading to frequent pop-up verification interfaces that disrupt clinical work. This solution innovatively constructs an LSTM-based contextual reasoning model that can comprehensively analyze multi-source signals such as bed pressure, equipment usage, and lighting changes to determine whether the current state conforms to normal behavioral patterns. For example, when a patient turns over, causing their face to temporarily deviate from the camera's field of view, but the mattress pressure distribution continues to evolve, the monitor data remains stable, and there are no records of personnel entering or leaving the room, the system infers that the patient is still in their original position, maintaining uninterrupted identity association and greatly improving user experience and system stability.

[0050] Regarding access control, traditional electronic medical record systems typically assign permissions based solely on user roles, failing to restrict actions in specific contexts. Theoretically, a single attending physician could access all patient data anytime, anywhere, posing risks of privacy breaches and accidental misuse. This proposed three-dimensional authorization model binds roles, tasks, and contexts, enabling precise access control down to the granular level of "who, when, where, to whom, and what." For example, even experts with advanced privileges will be blocked by the system when attempting to remotely adjust ventilator parameters for critically ill patients outside of their shifts; they must swipe their card on-site and pass secondary biometric verification before proceeding, effectively preventing remote misuse and malicious tampering.

[0051] At the device collaboration level, existing monitoring devices are mostly independent "information silos," whose output data relies on manual verification and subsequent integration, making them highly susceptible to misclassification. This solution uses a device-level identity synchronization protocol to forcibly embed a valid identity tag during the data generation process of each device, and monitors the correspondence between devices and patients in real time through a heartbeat monitoring mechanism. Once it is found that the identity key reported by the infusion pump does not match the current bed confirmation result, the system immediately cuts off its communication link and alarms, fundamentally eliminating the possibility of "administering the wrong medication."

[0052] In terms of extreme disaster recovery capabilities, most systems become completely paralyzed and lose basic functionality after a network outage. This solution's offline working mode not only retains data acquisition capabilities but also introduces a dual-person confirmation and post-event auditing mechanism, ensuring operational continuity while strictly adhering to safety standards. All offline operations are traceable, forming a complete chain of evidence and providing solid support for medical quality management.

[0053] Regarding system evolution mechanisms, most medical information systems lack self-optimization capabilities; once deployed, their models remain static and difficult to adapt to real-world clinical changes. This solution's active learning feedback loop implements a closed-loop mechanism of "training as you use." The system automatically collects matching results from real-world scenarios weekly, specifically optimizing the facial recognition model's performance under complex poses, and dynamically adjusting ECG feature extraction parameters to adapt to the physiological characteristics of patients with different arrhythmias, ensuring a long-term overall matching accuracy of over 98%.

[0054] In summary, the technical solution described in this embodiment constructs an intelligent identity management system for critical care, integrating multimodal biometrics, dynamic contextual reasoning, fine-grained access control, device-level data binding, disaster recovery backup, and adaptive learning. The system forms a complete closed loop from bottom-level perception to top-level decision-making, not only solving the problems of chaotic identity management and data mismatch in current clinical practice, but also providing a scalable and replicable technical paradigm for the construction of future intelligent critical care environments. The implementation of this solution can significantly reduce the incidence of medical errors, improve diagnostic and treatment efficiency and patient safety, and promote the development of critical care medicine towards high reliability and high intelligence.

[0055] Example 2

[0056] This embodiment further optimizes the dynamic time warping algorithm in the identity matching engine based on the above embodiments to improve the stability and computational efficiency of ECG feature matching in high-noise environments. Although the traditional DTW algorithm can handle non-uniform time sequences, it faces two major challenges in intensive care scenarios: first, ECG signals are often affected by respiratory movements, limb tremors, or electromagnetic interference, leading to misjudgments or missed detections in R-wave detection, resulting in sequence distortion; second, the original DTW computational complexity is O(m×n), making it difficult to guarantee real-time performance under high-frequency sampling conditions.

[0057] To address this, the system introduces a constrained dynamic time warping algorithm, setting a diagonal band width to limit the search space. Specifically, the optimal alignment path must lie within a band-shaped region centered on the diagonal and with a width of w, i.e., |ij| ≤ w / 2. This constraint is based on medical facts: human heart rate does not undergo drastic changes in a short period, and the changes in adjacent RR intervals are continuous. Experimental data show that the standard deviation of the difference between adjacent intervals ΔRR in healthy adults is approximately 8 milliseconds, while it can reach 15 milliseconds in critically ill patients due to stress response. Therefore, w = 30 milliseconds is set to accommodate reasonable variation while excluding obvious mismatches.

[0058] Based on this, the system adopts the fast DTW approximation algorithm to transform the original recursive calculation into an iterative process. The first row and first column of the cost matrix C are initialized to infinity, and C[0][0] = 0; then the matrix is ​​filled in row-major order, and only elements within the band region are calculated. For each position (i,j), its cumulative cost is determined by the minimum value among the left, top, and top-left neighbors:

[0059]

[0060] The final path cost cost(P*) = C[m][n], and the alignment result can be obtained by backtracking the path. This optimization reduces the time complexity from O(m×n) to O(w×max(m,n)), which is about 4 times faster under typical parameters (m=n=60, w=30), meeting the requirement of real-time response in the 100-millisecond range.

[0061] To further suppress the impact of noise, a robust preprocessing step is added before DTW calculation. First, a moving median filter is applied to the measured RR interval sequence with a window size of 5 periods to eliminate single-point outliers. Then, the first-order difference of the sequence is calculated. If | If the time interval is greater than 200 milliseconds, it is determined to be a premature beat or a missed beat, and linear interpolation is used for repair. The repaired sequence is then input into the DTW algorithm for comparison. Experiments show that this combined strategy can improve the accuracy of ECG matching under strong interference conditions from 76% to 91%, significantly enhancing the robustness of the system.

[0062] Furthermore, this embodiment instantiates and expands the three-dimensional authorization model in the access control center. A new physical area category, "Isolation Ward," is added, suitable for infectious disease prevention and control scenarios. When a patient is admitted to a negative pressure isolation ward, the system automatically activates additional protective strategies: all remote access requests that do not involve direct contact with medical staff must be approved by the head of the infection control department; any operation involving bodily fluid samples must be performed by designated personnel wearing full protective gear; and data export permissions are temporarily centralized at the department head level. These strategies are dynamically loaded through the rule engine, adapting to the needs of public health emergencies without modifying the core code.

[0063] Meanwhile, the system enhances its situational awareness capabilities. It integrates with the hospital's building automation system to acquire real-time data on ward temperature and humidity, air pressure gradients, and the operational status of HEPA filters. When an abnormal pressure is detected in an isolation ward (expected to be -5Pa but measured > -2Pa), the system determines a leakage risk, immediately restricts access for unauthorized personnel, and sends an alert to the infection control monitoring platform. This cross-system linkage mechanism improves environmental safety management and demonstrates the solution's excellent integrability and scalability.

[0064] This embodiment further enhances the system's practicality and adaptability in complex clinical environments by optimizing the core algorithm and expanding the licensing model. The constrained DTW algorithm significantly reduces computational overhead while ensuring matching accuracy, enabling efficient ECG feature comparison on resource-constrained edge devices. Robust preprocessing effectively addresses signal quality fluctuations, improving the system's usability in real-world critical care scenarios. The expanded 3D licensing model supports refined management in special contexts such as infectious disease control, demonstrating the solution's strong scenario adaptability and policy compliance. These improvements collectively strengthen the engineering feasibility and clinical value of the entire technical system.

Claims

1. A critical care intelligent identity management system, characterized in that, include: The identity registration unit is used to collect three-dimensional facial point cloud data and electrocardiogram R-wave sequence features when patients are admitted to the department, and to generate a unique identity key based on the two and store it in a secure database. The real-time sensing unit is used to continuously capture changes in facial contours, fluctuations in electrocardiogram signals on the body surface, and movement trajectories of active objects in the area surrounding the hospital bed. The identity matching engine employs a dual-channel parallel comparison mechanism. The first channel performs geometric deformation matching between the real-time captured facial image and the point cloud model in the registration library to calculate the spatial similarity score. The second channel extracts the R-wave interval sequence from the real-time electrocardiogram signal and performs waveform alignment analysis with the registered features to output the physiological consistency index. When the scores of both channels exceed the preset threshold, it is determined to be a valid identity activation state. The access control center is used to dynamically generate access policies based on identity matching results and force all operating terminals to complete the consistency verification between local cached data and the central identity key before displaying patient information. The linkage execution module is used to broadcast identity status information to all connected smart medical devices, ensuring that the data stream processed by each device is attached with a valid identity tag.

2. The intensive care unit identity intelligent management system according to claim 1, characterized in that, It also includes a context modeling module, which is used to collect bed occupancy pressure distribution, lighting mode switching sequence, equipment usage frequency curve and personnel entry and exit logs in real time to construct a time series feature vector of ward status; when the score of any channel of the identity matching engine is lower than the confidence threshold, the context modeling module starts the context reasoning process, evaluates the similarity between the current status vector and the historical normal behavior pattern, and maintains or interrupts the original identity association based on the evaluation result.

3. The intensive care unit identity intelligent management system according to claim 2, characterized in that, The context modeling module is trained using a long short-term memory network structure. Its input layer receives raw time-series data from various sensors, its hidden layer extracts cross-modal correlation features, and its output layer predicts the most likely identity state at the next moment. The prediction results are used to compensate for the instantaneous failure of the main matching channel.

4. The intensive care unit identity intelligent management system according to claim 1, characterized in that, The access control center integrates a three-dimensional authorization model of role-task-context. The role dimension classifies access levels based on the professional qualifications of medical staff, the task dimension is bound to the specific clinical operation type, and the context dimension is determined by the current patient's critical condition, physical area, and time window. Any data access request must meet the constraints of all three dimensions simultaneously to be approved.

5. The intensive care unit identity intelligent management system according to claim 4, characterized in that, The access control center supports online updates and rollbacks of policies, and all change records are stored immutably using blockchain technology.

6. The intensive care unit identity intelligent management system according to claim 1, characterized in that, The linkage execution module establishes a device-level identity synchronization protocol. Each medical device connected to the system has a built-in lightweight identity agent program, which is used to periodically report its own ID, the identity key of the current service object, and the timestamp of the last communication to the central server. The server is equipped with a heartbeat monitoring mechanism. If a device has not updated its status for several consecutive cycles or the reported identity key does not match the latest confirmation result of the bed, a disconnection command will be issued immediately.

7. The intensive care unit identity intelligent management system according to claim 6, characterized in that, All monitoring data packets output by all devices must embed a currently valid identity signature during encapsulation. The receiving end must verify the validity of the signature before parsing. The identity signature is generated using the elliptic curve digital signature algorithm, and the private key is stored in the hardware security module.

8. The intensive care unit identity intelligent management system according to claim 1, characterized in that, The system is equipped with an emergency offline working mode. When the network is interrupted or the main server fails, each terminal device automatically switches to local cache mode, and the authentication is downgraded to short-range radio frequency identification assisted confirmation based on the most recent successful authentication. Medical staff need to hold the authorization card close to the device to complete the operation and unlock it.

9. The intensive care unit identity intelligent management system according to claim 8, characterized in that, In emergency offline working mode, critical operations are subject to a two-person confirmation mechanism. Any modification to drug dosage or adjustment of treatment parameters must be made by two people with the corresponding permissions swiping their cards in sequence to take effect. All data generated during offline operation is uploaded in batches according to time sequence after communication is restored, and the background performs consistency audit.

10. The intensive care unit identity intelligent management system according to claim 1, characterized in that, The system has an active learning feedback loop. The result of each identity matching process is recorded as a training sample. The background machine learning module performs incremental training to optimize the generalization ability of the facial recognition model under extreme postures and adjusts the length of the ECG feature extraction window to adapt to the signal characteristics of patients with different arrhythmias. Before the model is updated, it must undergo offline simulation testing and the accuracy improvement must reach a preset threshold before it can be pushed to the clinical environment for deployment.