Portable remote medical teaching platform based on data flow sharing and dynamic privacy protection
By using portable integrated terminals and dynamic privacy protection algorithms, the shortcomings of remote medical teaching platforms in terms of device integration, data sharing, and privacy protection have been addressed. This has enabled secure sharing and real-time privacy protection of intranet medical terminal data, meeting the needs of remote teaching in multiple scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANXI PROVINCIAL PEOPLES HOSPITAL (AFFILIATED HOSPITAL OF SHANXI HEALTH VOCATIONAL COLLEGE)
- Filing Date
- 2026-03-31
- Publication Date
- 2026-05-29
AI Technical Summary
Existing telemedicine and teaching platforms are inadequate in terms of equipment structure integration, intranet data sharing, and dynamic privacy protection. They are unable to meet the needs of remote medical teaching for multi-source dynamic data stream sharing, highly portable integration, and rapid deployment in space-constrained environments. Furthermore, they lack the ability to identify and continuously desensitize patient privacy information in the dynamic data stream of medical terminals in real time.
By employing a portable integrated terminal, a remote conferencing system, and data stream sharing and privacy desensitization software, and through the collaborative design of a micro motherboard, projection display components, and an integrated audio-visual module, secure sharing and real-time privacy protection of intranet medical terminal data are achieved. Combined with trigger-based OCR and a custom desensitization algorithm, stable identification and continuous desensitization of multi-source data streams are realized.
It enables secure and stable sharing and real-time privacy protection of intranet medical terminal data without modifying the intranet, reducing deployment costs and compliance risks, and improving the quality and feasibility of remote teaching.
Smart Images

Figure CN122111968A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of telemedicine and education, specifically a portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection. Background Technology
[0002] In telemedicine and teaching practices, the structural integration and spatial adaptability of equipment directly affect deployment efficiency and usage effectiveness. While existing integrated devices such as remote conferencing terminals, all-in-one projector computers, or smart screens have made some progress in display integration and conferencing functions, they struggle to simultaneously meet the demands for remote data sharing and highly portable deployment. Several all-in-one projector computers or integrated projector devices have emerged in the current technology: Patent CN202661928U discloses an all-in-one machine with projection capabilities, achieving large-size display by integrating a projection module within the machine; Patent CN215895211U proposes a desktop all-in-one projector structure, focusing on device structural integration and desktop scene adaptation; Patent CN108287597A discloses a small projector computer system, improving portability by integrating the host and projection module. However, these technical solutions mainly focus on the physical structure integration and display form optimization of the equipment, and their application scenarios are mostly geared towards office or general display environments, without addressing the complex spatial conditions of remote medical teaching. In real-world medical scenarios, such as conference rooms, clinics, and teaching environments, limited space and strict restrictions on equipment placement place higher demands on equipment size, cable quantity, interface concentration, and rapid deployment capabilities. Existing all-in-one projectors or smart screen devices typically still rely on external signal sources, separate acquisition devices, or single interface inputs, failing to achieve unified access and centralized processing of multi-source intranet medical terminal data. Furthermore, their structural design does not fully consider the issues of rapid assembly / disassembly and spatial adaptation in telemedicine and mobile teaching scenarios, making it difficult to achieve a truly "portable, low-occupancy, and rapidly deployable" integrated solution. Therefore, existing all-in-one projectors and related integrated devices cannot yet meet the comprehensive technical requirements of telemedicine teaching for "multi-source dynamic data stream sharing, highly portable integration, and rapid deployment in space-constrained environments."
[0003] In telemedicine and teaching systems, real-time sharing of dynamic data streams generated by terminals such as Hospital Information Systems (HIS), Picture Archiving and Communication Systems (PACS), and ultrasound equipment is a crucial link in improving the quality of clinical teaching and the efficiency of remote diagnosis. However, due to network security and compliance requirements, most medical terminals are deployed in the hospital's internal LAN environment, strictly prohibiting access to the external network or the installation of unaudited third-party conferencing software. This makes it difficult to directly synchronize high-quality medical data from the internal network to remote teaching or consultation scenarios. Existing solutions mostly rely on high-cost dedicated video conferencing terminals or complex network bypass architectures, which not only make multi-system integration difficult and implementation time-consuming, but also lack flexibility and portability, making it difficult to meet the needs of remote teaching in multiple scenarios.
[0004] Furthermore, medical data is highly sensitive. During remote consultations and teaching, when displaying medical records and images via screen sharing or video streaming, the interface often contains personal identification information such as patient names, ID numbers, and home addresses. If this information is transmitted along with the real-time video stream, it can easily lead to privacy leaks and compliance risks. Current research and engineering practices primarily focus on offline de-identification of image data, such as anonymization methods for PACS / DICOM data in research sharing scenarios, privacy field removal strategies, and their application in data compliance. Numerous research papers have analyzed the relevant technical approaches and limitations (CN111767554B, CN106570408A, CN107071321B). However, these methods are mainly geared towards static files or offline exported data, and are difficult to apply directly to scenarios involving real-time display on terminals and dynamic screen output. They cannot provide real-time, automated privacy protection capabilities for "continuous video data streams generated by medical device screens." On the other hand, national patent documents also disclose various technical solutions for masking or desensitizing sensitive information in screen sharing or video content. For example, some patents propose masking sensitive areas during screen sharing, or using predefined rules to mask or blur specific areas during video output [1-3]; in the medical field, there are also patents involving solutions for masking or restricting the display of video output content from medical devices (CN112420214B). However, the above-mentioned existing technologies are mostly based on fixed interface structures, preset masking templates, or general video content features. Their technical implementation usually relies on static rules or simple image processing methods, which are difficult to adapt to the frequent changes in medical terminal interfaces, the non-fixed field layout, and dynamic operation scenarios such as window scrolling and switching. In addition, existing technologies mostly target general privacy objects (such as faces, documents, and fixed text areas), lacking the ability to stably identify and continuously locate "field-level patient identity information" in medical interfaces, and do not fully consider the requirements for information integrity and teaching readability in remote medical teaching scenarios, which can easily lead to problems such as excessive masking or unstable masking. In conclusion, how to achieve real-time identification, stable location, and continuous desensitization of patient privacy information in the dynamic data stream of medical terminals without affecting the presentation of medical teaching content remains a technical challenge that has not yet been effectively solved by existing technologies.
[0005] [1] Shahid A, et al. A Two-Stage De-Identification Process for Privacy-Preserving Medical Image AnalysisJJJ. 2022. [2] Rempe M, et al. De-identification of medical imaging dataJJJ.2025. [3] Rutherford M, et al. A DICOM dataset for evaluation of medicalimage de-identification algorithmsJJJ. Scientific Data, 2021. Summary of the Invention
[0006] This invention addresses the shortcomings of existing telemedicine and teaching platforms in terms of device integration, intranet data sharing, and dynamic privacy protection, and provides a portable telemedicine teaching platform based on data flow sharing and dynamic privacy protection.
[0007] This invention is achieved using the following technical solution: a portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection, comprising a portable integrated terminal, a remote conferencing system, and data stream sharing and privacy desensitization software. The portable integrated terminal includes a housing, within which a micro-motherboard and a projection display component are housed. The remote conferencing system and the data stream sharing and privacy desensitization software are deployed within the micro-motherboard. The micro-motherboard is equipped with a CPU, memory, a GPU, a network adapter, a power management unit, a cooling fan, a network port, and input / output interfaces. The projection display component is connected to the micro-motherboard via these interfaces.
[0008] After the intranet medical terminal is connected to the portable integrated terminal, the video stream is input to the portable integrated terminal, which integrates data stream sharing, privacy desensitization, and projection display. The video stream can be projected through the projection display component or remotely output by the remote conferencing system.
[0009] The aforementioned portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection has HDMI input and output interfaces on its micro motherboard, and also a USB interface.
[0010] The aforementioned portable telemedicine teaching platform, based on data stream sharing and dynamic privacy protection, also features an integrated audio-visual module on its portable terminal casing. This module includes a camera, microphone, and speaker, and is connected to a micro-motherboard. The integrated audio-visual module can capture live video and audio, which can be projected or remotely output as a video stream. This video stream can be overlaid and displayed in split-screen mode or switched with the video stream output from the intranet medical terminal to meet the needs of teaching, demonstration, and consultation discussions.
[0011] The aforementioned portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection includes a projection display component comprising a projection optical engine component, a video input and display control component, a focusing camera and a distance sensor, a heat dissipation component, a status indicator and control component, and a projection height adjustment knob. The projection optical engine component includes a light source, an imaging component, and a projection lens. The imaging component is connected to the micro motherboard through the video interface in the video input and display control component.
[0012] The aforementioned portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection, the data stream sharing software's working process includes: S301: Intranet Medical Terminal Access: Connect the video output port of the intranet medical terminal to the input interface of the portable integrated terminal; S302: Video signal acquisition and format adaptation: The portable integrated terminal acquires the input video signal in real time and adaptively matches the resolution, frame rate, and color space parameters; for diverse video formats output by different terminals, compatibility is achieved through acquisition adaptation and a unified abstraction layer; S303: Desensitization Coding and Conference Output Mapping: The acquired video stream is desensitized and encoded in real time, and mapped to an output source that can be recognized and shared by the remote conferencing system. The desensitized rendered screen is output as a shared source. S304: Remote Conferencing Transmission and Display: Through a remote conferencing system, a shared source is published to a remote location, enabling remote doctors / students to view the intranet medical data stream in real time.
[0013] The aforementioned portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection, and its privacy desensitization software, operates as follows: S401: Initialization and Mode Configuration: After starting the data stream sharing software, the privacy protection configuration interface is entered. The user selects the de-identification mode: Off, Automatic De-identification A, Custom De-identification B, or Automatic + Custom Fusion De-identification A + B; When the user selects the mode that includes custom desensitization B, the user enters the sensitive field information of the subject of this teaching / consultation, or enters key fragments / last four-digit features; the system generates a custom sensitive feature library, including a string dictionary, a set of key fragments and a set of number rules, and sets the desensitization strategy and teaching retention area; S402: Data stream frame acquisition and page status monitoring: acquire image frames frame by frame from the acquired video stream, or extract frames by time window; at the same time, perform page status analysis on adjacent frames to determine whether the page is stable or has changed, and at least detect: window switching, pop-up changes, interface scrolling / displacement, resolution / scaling changes. S403: Trigger Condition Determination: Based on the page status analysis results and recognition consistency, determine whether the OCR trigger conditions are met. The OCR confirmation process will be triggered if any of the following conditions are met: Page structure changes; Interface scrolling or overall displacement; There is existing loss of tracking in sensitive areas or increased coordinate mapping errors; Automatic desensitization A has low confidence or is inconsistent with historical data; Custom-defined de-identification B quickly verifies inconsistencies with historical data; The periodic survival trigger condition is met; If the triggering conditions are not met, the process will proceed to S408 to perform area reuse and tracking, without initiating the OCR confirmation process. S404: Candidate Region ROI Generation: When the OCR confirmation process is triggered, candidate region ROIs are generated first based on the page structure and keyword anchors. The candidate region ROIs should at least include high-probability PII (person identifiable information) areas in the patient's basic information field, contact information / address area, and patient information card area; or candidate region ROIs can be generated through text density detection and layout rules to reduce the OCR scope and computational overhead. S405: OCR Recognition and Text Block Extraction: Perform OCR recognition on the candidate region ROI to obtain a set of text blocks. Each text block includes at least: text content, location information, confidence level, and spatial relationship with neighboring labels. S406: A+B Fusion Matching and Sensitivity Determination: Perform fusion matching on each text block and calculate the comprehensive sensitivity score or comprehensive determination result: Automatic desensitization feature A: whether it hits the neighborhood of the "name / ID number / phone number / address" label, whether it conforms to the regular expression and validation rules of ID number / phone number, and whether it is in a high-probability layout area; Automatic desensitization feature B: Whether it matches the sensitive field entered by the user precisely or fuzzily, and whether it hits the key fragment / last four features; Historical consistency: consistency with existing sensitive areas in terms of spatial location and textual content; When the fusion result meets the sensitivity judgment conditions, the coordinates of the sensitive area corresponding to the text block are output; at the same time, the sensitivity judgment priority of the content in the teaching retention area / whitelist is reduced to avoid excessive occlusion. S407: Sensitive Region Coordinate Generation and Time Consistency Control: The coordinates of text blocks identified as sensitive are merged, expanded, or normalized to generate a final set of sensitive regions; and a time consistency threshold is introduced. Occlusion is only enabled after the sensitive area is hit by ≥P frames consecutively. The occlusion is lifted only after ≥Q consecutive misses; P and Q are configurable parameters; S408: Continuous tracking and reuse of sensitive areas: When the page state is stable and OCR is not triggered, perform continuous tracking and coordinate reuse on the sensitive areas from the previous moment to keep the occluded areas stable during scrolling / slight changes; when tracking fails or the page state changes significantly, return to S403 to re-trigger OCR confirmation. S409: Desensitized Rendering and Conference Output: Perform masking, blurring, or field replacement rendering on the final sensitive areas according to the desensitization strategy to generate desensitized video frames; map the desensitized video stream to a video source or shared source that can be recognized by the conferencing software, and output it to the remote conferencing system to enable real-time viewing and compliant display on the remote end.
[0014] This invention constructs an integrated data flow platform with hardware and software co-design to achieve secure sharing and compliant display of multi-source medical data. The platform has a high degree of integration, is suitable for space-constrained environments, supports multi-source medical terminal data access, can achieve remote sharing of data flow under intranet isolation conditions, and has real-time dynamic privacy protection capabilities. Attached Figure Description
[0015] Figure 1 Portable integrated terminal isometric measurement of the present invention Figure 1 .
[0016] Figure 2 Portable integrated terminal isometric of the present invention Figure 2 .
[0017] Figure 3 This is a diagram of the internal structure of the portable integrated terminal of the present invention.
[0018] In the diagram: 1-Front cover of the housing; 2-Projection optical engine assembly; 3-Projector infrared and focus camera; 4-Projection display assembly power switch; 5-Micro motherboard power switch; 6-Top cover of the housing; 7-Integrated audio-visual module; 8-Network adapter interface; 9-Power interface; 10-HDMI output interface; 11-Extension interface; 12-HDMI input interface; 13-USB interface; 14-Audio output interface; 15-Microphone input interface; 16-Rear cover of the housing; 17-Processor CPU; 18-HDMI output 1 to 2 module; 19-Acquisition / decoding controller; 20-Power transformer; 21-Projection display assembly. Detailed Implementation
[0019] This invention provides a portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection. Through a three-layer collaboration of "portable integrated hardware, intranet data stream capture and conferencing software sharing, and dynamic privacy identification and continuous desensitization algorithms," it achieves secure and stable sharing of dynamic data streams generated by intranet medical terminals such as HIS (Hospital Information System), PACS (Picture Archiving and Communication System), and ultrasound to remote conferences without modifying the intranet or installing third-party conferencing software on intranet medical terminals. Furthermore, it performs real-time desensitization processing on patient personal identification information in the video stream. The aforementioned intranet medical terminals include, but are not limited to, HIS, PACS, ultrasound workstations, and radiology / endoscopy workstations, which output display images via video output interfaces (such as HDMI).
[0020] The overall architecture is as follows: This invention platform comprises two parts: hardware and software. (1) The hardware includes: Portable integrated terminal (platform host): includes a micro motherboard, projection display components, and an integrated audio-visual module; (2) The software includes: 1) Remote conferencing system: including commonly used conferencing software such as DingTalk and Tencent Meeting, and conferencing terminals that run on the external network or have access to the network; 2) Data stream sharing and privacy desensitization software: Deployed in a portable integrated terminal, responsible for data stream acquisition, encoding, conference output and privacy desensitization rendering.
[0021] The component relationships are as follows: intranet medical terminal → (HDMI, etc.) → portable integrated terminal integrating data stream sharing, privacy desensitization and projection display → (network) → remote conferencing system; at the same time, the portable integrated terminal can overlay or switch the output of on-site images and audio (audio-visual integrated module) to meet the needs of teaching, demonstration, consultation and discussion scenarios.
[0022] Portable integrated terminal structure The portable integrated terminal adopts an integrated structural design and includes at least the following modules and their connection relationships: (1) Micro motherboard The miniature motherboard is electrically connected to various interfaces / peripherals, including: a. Processor (CPU): used to execute instructions for data stream acquisition, encoding, privacy identification, and desensitized rendering; b. Memory: volatile RAM for runtime data caching, frame caching, and storing intermediate results of model inference; non-volatile ROM / Flash / SSD / eMMC for storing the operating system, data stream sharing program, privacy desensitization program, and model parameters; c. Video input / acquisition interface and controller: including an HDMI input interface and its acquisition / decoding controller, used to receive video signals output from the intranet medical terminal and convert them into processable video frame data; d. HD MI Output Interface: Supports connection to other display devices for video output; e. Graphics Processing Unit (GPU): Used to accelerate video encoding / decoding, image processing, and privacy recognition inference calculations; f. Network Adapter: Includes wired Ethernet interface and / or wireless communication module (Wi-Fi / 4G / 5G, etc.) for establishing network connections and transmitting data streams with remote conferencing systems; g. Peripheral Interface Unit: Includes USB, serial port, or other expansion interfaces for connecting cameras, storage devices, or control peripherals; f. Power Management Unit (PMU): Used for power supply, voltage regulation, overcurrent and overtemperature protection, and power consumption management for each hardware module; i. Cooling Fan: Used for cooling the micro motherboard.
[0023] (2) Projection display component Includes: a. Projection optical engine assembly: used to generate the projection beam and output the projected image, preferably including a light source, imaging component, and projection lens; wherein, the light source can be a 10,000 ANSI high-brightness LED light source, and the imaging component is an LCD imaging component, connected to the micro motherboard, for local large-screen display in space-constrained environments such as conference rooms / clinics / wards; this module works in conjunction with the micro motherboard to achieve a parallel working mode of "local projection display + remote shared output"; b. Video input and display control assembly: used to receive video signals from the micro motherboard and drive the projection optical engine assembly to display, including: video interfaces (such as HDMI, USB, VGA, and other interfaces); c. Focusing camera and distance sensor: automatically adjusts focus when the projection display component moves. The system performs resolution adaptation, frame rate synchronization, color / brightness adjustment, and keystone correction. d. Heat dissipation components: These are used to dissipate heat from the light source and imaging components, preferably including heat sinks, thermal conductivity structures, and / or fan components to ensure stable continuous operation. e. Status indication and control components: These are used for switching, mode switching, and status indication of the projection display components, preferably including buttons / touch units, indicator lights, and control interfaces; optional support for linkage control with a micro-motherboard (e.g., brightness, on / off, and mode control via I2C / serial / USB). f. Projection height adjustment knob: This adjusts the vertical height of the projected image according to the environment.
[0024] (3) Audio-visual integrated module Includes: a. 4K wide-angle camera: used to capture images of remote medical or teaching sites, with built-in AI portrait tracking and intelligent C-position perspective; b. Dual array microphones: used to capture audio for explanations and discussions; c. High-fidelity speakers: used for playing conference audio; The audio-visual integrated module connects to a micro motherboard and can output picture-in-picture, split-screen, or scene switching data streams with intranet medical terminals to enhance the remote audio-visual experience.
[0025] The data flow sharing software is deployed on a micro motherboard, and its operation includes: S301: Intranet Terminal Access: Connect the video output port (such as HDMI) of the intranet medical terminal to the HDMI input interface of the portable integrated terminal, so that the intranet medical terminal can output display screen without installing any third-party conferencing software or plugins.
[0026] S302: Video signal acquisition and format adaptation: The portable integrated terminal acquires the input video signal in real time and adaptively matches parameters such as resolution, frame rate, and color space; for the diverse formats output by different terminals, compatibility is achieved through acquisition adaptation and a unified abstraction layer.
[0027] S303: Desensitization Encoding and Conference Output Mapping: The acquired video stream is desensitized and encoded in real time, and mapped to an output source that can be recognized and shared by the remote conferencing system. The desensitized rendered screen is output as a shared source.
[0028] S304: Remote Meeting Transmission and Display: Publish the shared source to the remote end through remote meeting systems such as DingTalk and Tencent Meeting, enabling remote doctors / students to view the intranet medical data stream in real time.
[0029] This solution enables cross-network data sharing without modifying the intranet network structure or installing conferencing software on intranet medical terminals at the system level, reducing deployment costs and implementation cycle, and meeting the needs of remote medical teaching in multiple scenarios.
[0030] The privacy desensitization procedure is deployed on a micro-motherboard, and its operation includes: S401: Initialization and Mode Configuration: After starting the data stream sharing software, enter the privacy protection configuration interface, where the user selects the de-identification mode: Off, Automatic De-identification A, Custom De-identification B, or Automatic + Custom Fusion A + B.
[0031] When the user selects the mode that includes custom desensitization B, the user enters sensitive field information of the subject of this teaching / consultation (such as name, ID number, mobile phone number, home address), or enters key fragments / last four digits and other features; the system generates a custom sensitive feature library, including a string dictionary, a set of key fragments and a set of number rules, and sets desensitization strategies (masking / blurring / replacement) and teaching retention areas (whitelist).
[0032] S402: Data stream frame acquisition and page status monitoring: Acquire image frames frame by frame from the acquired video stream, or extract image frames by time window; at the same time, perform page status analysis on adjacent frames to determine whether the page is stable or has changed, and detect at least: window switching, pop-up changes, interface scrolling / displacement, resolution / scaling changes, etc.
[0033] S403: Trigger Condition Determination (OCR Confirmation Activation): Based on page status monitoring results and recognition consistency, determine whether the OCR trigger conditions are met. The OCR confirmation process is triggered if any of the following conditions are met: Page structure changes (window switching / pop-ups / layout rearrangement); Page scrolling or overall displacement; There is existing loss of tracking in sensitive areas or increased coordinate mapping errors; Automatic desensitization A has low confidence or is inconsistent with historical data; Automatic desensitization A quickly verifies inconsistencies with historical data; The periodic keep-alive trigger condition is met (once every N seconds / once every K frames); If the triggering conditions are not met, proceed to S408 to execute "continuous tracking and reuse of sensitive areas" without starting full OCR recognition.
[0034] S404: Candidate Region ROI Generation (Local Priority): When the OCR confirmation process is triggered, candidate region ROIs are generated first based on the page structure and keyword anchors. Candidate region ROIs should include at least high-probability PII areas such as the patient's basic information field, contact information / address area, and patient information card area; or candidate region ROIs can be generated through text density detection and layout rules to reduce the scope of OCR confirmation and computational overhead.
[0035] S405: OCR Recognition and Text Block Extraction: Perform OCR recognition on candidate regions (ROIs) to obtain a set of text blocks. Each text block includes at least: text content, location information (rectangular or polygonal coordinates), confidence level, and spatial relationship with neighboring labels.
[0036] S406: A+B Fusion Matching and Sensitivity Determination: Perform fusion matching on each text block and calculate the comprehensive sensitivity score or comprehensive determination result: Automatic desensitization feature A: whether it hits the neighborhood of tags such as "name / ID number / phone number / address", whether it conforms to regular expressions and validation rules such as ID number / phone number, and whether it is in a high-probability layout area; Automatic desensitization feature B: Whether it matches the sensitive field entered by the user precisely or fuzzily, whether it hits the key fragment / last four characters, etc. Historical consistency: consistency with existing sensitive areas in terms of spatial location and textual content; When the fusion result meets the sensitivity judgment conditions, the coordinates of the sensitive area corresponding to the text block are output; at the same time, the sensitivity judgment priority of the content in the "teaching retention area / whitelist" is reduced to avoid excessive occlusion.
[0037] S407: Sensitive Region Coordinate Generation and Time Consistency Control: The coordinates of text blocks identified as sensitive are merged, expanded, or normalized to generate a final set of sensitive regions; and a time consistency threshold is introduced. Occlusion is only enabled after the sensitive area is hit by ≥P frames consecutively. The occlusion is lifted only after ≥Q consecutive misses; P and Q are configurable parameters used to suppress flickering caused by OCR jitter.
[0038] S408: Continuous tracking and reuse of sensitive areas: When the page state is stable and OCR is not triggered, perform continuous tracking and coordinate reuse (e.g., based on area displacement or template matching) on the last sensitive area of the previous moment to keep the occluded area stable during scrolling / slight changes; when tracking fails or the page state changes significantly, return to S403 to re-trigger OCR confirmation.
[0039] S409: Desensitized Rendering and Meeting Output: Perform masking, blurring, or field replacement rendering on sensitive areas according to the desensitization strategy to generate desensitized video frames; map the desensitized video stream to a video source or shared source that can be recognized by the remote conferencing system, and output it to remote conferencing systems such as DingTalk and Tencent Meeting to achieve real-time viewing and compliant display on remote terminals.
[0040] The structure of the portable integrated terminal is as follows Figure 1 , 2As shown in Figure 3, an independent dual switch is arranged in the upper right corner of the front cover 1 of the housing: a micro-motherboard switch 5 that independently controls the micro-motherboard and a projection display component switch 4 that independently controls the projection display component. The projection optical engine component 2 is also located on the front cover 1 of the housing. A focusing camera and a distance sensor 3 are arranged in the upper left corner of the front cover 1 of the housing. The audio-visual integrated module 7 is arranged on the upper cover 6 of the housing, and the orientation of the audio-visual integrated module 7 is opposite to that of the projection optical engine component 2. The rear cover 16 of the housing realizes the centralized arrangement of interfaces, specifically including a network adapter interface 8, a power interface 9, an HDMI output interface 10, an expansion interface 11, an HDMI input interface 12, a USB interface 13, an audio output interface 14, and a microphone input interface 15. The micro-motherboard inside the housing is equipped with a processor CPU 17, an HDMI output 1 to 2 module 18, an acquisition / decoding controller 19, and a power transformer 20. The projection display component 21 is located below the micro-motherboard inside the housing.
[0041] The present invention has the following advantages: (1) Portable, highly integrated hardware architecture enables the system to be deployed quickly in space-constrained environments. This invention integrates a micro-motherboard, projection display component, and audio-visual module into a single terminal. By centralizing interfaces and using dual-switch independent control, it reduces the number of cables and peripherals in the field, structurally lowering deployment complexity and space requirements. Its mechanism lies in integrating the previously dispersed micro-motherboard, projection display component, and audio-visual module with a fixed connection, reducing external coupling points and interface conversion needs. This enables rapid access, quick startup, and stable operation in restricted environments such as clinics, bedside locations, and conference rooms, improving the accessibility and consistency of mobile teaching / consultation.
[0042] (2) Data stream capture and conference output mechanism under intranet isolation conditions without network modification or conference control software installation This invention acquires display signals from intranet HIS / PACS / ultrasound terminals via HDMI input, performs resolution / frame rate / color space adaptation and encoding on a portable integrated terminal, and then maps them to a shared source output recognizable by conferencing software. The key function of this mechanism is to transform "software installation and network external connection constraints on intranet medical terminals" into a physical interface access for "terminal-side video output." This avoids compliance obstacles associated with installing third-party conferencing software on intranet medical terminals at the system level, and also avoids the high costs and long integration cycles associated with dedicated video conferencing terminals / bypass modifications, thereby improving the feasibility of cross-departmental, cross-hospital, and multi-scenario remote teaching.
[0043] (3) Triggered OCR A+B fusion recognition achieves "real-time, stable and controllable" field-level privacy desensitization. Compared to solutions based on fixed templates or full frame-by-frame OCR, this invention introduces page state monitoring and trigger-based OCR into the dynamic privacy module: OCR is triggered only when the page is stable and historical coordinates are reused. The mechanism reduces the time-consuming OCR computation from "must be done every frame" to "event-triggered / periodic keep-alive," reducing computational power consumption and minimizing occlusion and flickering. Automatic desensitization A (automatic rules / context) + custom desensitization B (custom fields) fusion judgment: Automatic desensitization A provides structured constraints through tag anchors and regular expression validation (ID card / phone number, etc.), while custom desensitization B provides strong directional evidence through user-inputted target patient fields (or key fragments). Fusion reduces the risk of false occlusion (e.g., doctor's name / fixed prompts) and missed occlusion (occasional OCR misidentification). The mechanism is multi-source evidence consistency judgment and historical consistency constraints, thereby achieving stable positioning and continuous occlusion of field-level PII. Teaching Retention Area / Whitelist Strategy: Key teaching areas such as image annotations and conclusion areas are retained or downgraded to avoid "excessive desensitization" affecting collaboration in the teaching rendering process, thus achieving "covering privacy without harming teaching".
[0044] By combining the above mechanisms, this invention unifies "cross-network sharing" and "dynamic privacy protection" into the same data flow pipeline without changing the intranet boundary conditions, thereby reducing compliance risks and improving the stability of remote teaching quality from an engineering implementation perspective.
Claims
1. A portable remote medical teaching platform based on data stream sharing and dynamic privacy protection, characterized in that: The system includes a portable integrated terminal, a remote conferencing system, and data stream sharing and privacy desensitization software. The portable integrated terminal includes a housing, within which a micro motherboard and a projection display component are housed. The remote conferencing system and the data stream sharing and privacy desensitization software are deployed within the micro motherboard. The micro motherboard includes a CPU, memory, a GPU, a network adapter, a power management unit, a cooling fan, a network port, and input / output interfaces. The projection display component is connected to the micro motherboard via these interfaces.
2. The portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection according to claim 1, characterized in that: The micro motherboard has HDMI input and HDMI output interfaces, and also has a USB interface.
3. The portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection according to claim 1 or 2, characterized in that: The portable integrated terminal also has an audio-visual integrated module on its casing, which includes a camera, microphone and speaker, and is connected to a micro motherboard.
4. The portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection according to claim 1 or 2, characterized in that: The projection display component includes a projection optical engine component, a video input and display control component, a focusing camera and a distance sensor, a heat dissipation component, a status indicator and control component, and a projection height adjustment knob. The projection optical engine component includes a light source, an imaging component, and a projection lens. The imaging component is connected to the micro motherboard through the video interface in the video input and display control component.
5. The portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection according to claim 1 or 2, characterized in that: The working process of data flow sharing software includes: S301: Intranet Medical Terminal Access: Connect the video output port of the intranet medical terminal to the input interface of the portable integrated terminal; S302: Video signal acquisition and format adaptation: The portable integrated terminal acquires the input video signal in real time and adaptively matches the resolution, frame rate, and color space parameters; for diverse video formats output by different terminals, compatibility is achieved through acquisition adaptation and a unified abstraction layer; S303: Desensitization Coding and Conference Output Mapping: The acquired video stream is desensitized and encoded in real time, and mapped to an output source that can be recognized and shared by the remote conferencing system. The desensitized rendered screen is output as a shared source. S304: Remote Conferencing Transmission and Display: Through a remote conferencing system, a shared source is published to a remote location, enabling remote doctors / students to view the intranet medical data stream in real time.
6. The portable telemedicine teaching platform based on data stream sharing and dynamic privacy protection according to claim 5, characterized in that: The working process of privacy de-identification software includes: S401: Initialization and Mode Configuration: After starting the data stream sharing software, the privacy protection configuration interface is entered. The user selects the de-identification mode: Off, Automatic De-identification A, Custom De-identification B, or Automatic + Custom Fusion De-identification A + B; When the user selects the mode that includes custom desensitization B, the user enters the sensitive field information of the subject of this teaching / consultation, or enters key fragments / last four-digit features; the system generates a custom sensitive feature library, including a string dictionary, a set of key fragments and a set of number rules, and sets the desensitization strategy and teaching retention area; S402: Data stream frame acquisition and page status monitoring: acquire image frames frame by frame from the acquired video stream, or extract frames by time window; at the same time, perform page status analysis on adjacent frames to determine whether the page is stable or has changed, and at least detect: window switching, pop-up changes, interface scrolling / displacement, resolution / scaling changes. S403: Trigger Condition Determination: Based on the page status analysis results and recognition consistency, determine whether the OCR trigger conditions are met. The OCR confirmation process will be triggered if any of the following conditions are met: Page structure changes; Interface scrolling or overall displacement; There is existing loss of tracking in sensitive areas or increased coordinate mapping errors; Automatic desensitization A has low confidence or is inconsistent with historical data; Custom-defined de-identification B quickly verifies inconsistencies with historical data; The periodic survival trigger condition is met; If the triggering conditions are not met, the process will proceed to S408 to perform area reuse and tracking, without initiating the OCR confirmation process. S404: Candidate Region ROI Generation: When the OCR confirmation process is triggered, candidate region ROIs are generated first based on the page structure and keyword anchors. The candidate region ROIs should include at least the high-probability PII areas of the patient's basic information field, contact information / address area, and patient information card area; or candidate region ROIs can be generated through text density detection and layout rules to reduce the OCR range and computational overhead. S405: OCR Recognition and Text Block Extraction: Perform OCR recognition on the candidate region ROI to obtain a set of text blocks. Each text block includes at least: text content, location information, confidence level, and spatial relationship with neighboring labels. S406: A+B Fusion Matching and Sensitivity Determination: Perform fusion determination on each text block and calculate the comprehensive sensitivity score or comprehensive determination result: Automatic desensitization feature A: whether it hits the neighborhood of the "name / ID number / phone number / address" tag, whether it conforms to the regular expression and validation rules of ID number / phone number, and whether it is in a high-probability layout area; Automatic desensitization feature B: Whether it matches the sensitive field entered by the user precisely or fuzzily, and whether it hits the key fragment / last four features; Historical consistency: consistency with existing sensitive areas in terms of spatial location and textual content; When the fusion result meets the sensitivity judgment conditions, the coordinates of the sensitive area corresponding to the text block are output; at the same time, the sensitivity judgment priority of the content in the teaching retention area / whitelist is reduced to avoid excessive occlusion. S407: Sensitive Region Coordinate Generation and Time Consistency Control: The coordinates of text blocks identified as sensitive are merged, expanded, or normalized to generate a final set of sensitive regions; and a time consistency threshold is introduced. Occlusion is only enabled after the sensitive area is hit by ≥P frames consecutively. The occlusion is lifted only after ≥Q consecutive misses; P and Q are configurable parameters; S408: Continuous tracking and reuse of sensitive areas: When the page state is stable and OCR is not triggered, perform continuous tracking and coordinate reuse on the sensitive areas from the previous moment to keep the occluded areas stable during scrolling / slight changes; when tracking fails or the page state changes significantly, return to S403 to re-trigger OCR confirmation. S409: Desensitized Rendering and Conference Output: Perform masking, blurring, or field replacement rendering on the final sensitive areas according to the desensitization strategy to generate desensitized video frames; map the desensitized video stream to a video source or shared source that can be recognized by the conferencing software, and output it to the remote conferencing system to enable real-time viewing and compliant display on the remote end.