Security protection method, device, storage medium and program product

By constructing a multi-source data association map of medical devices and a dynamic adaptive protection scheme, the risk perception and protection issues of medical imaging equipment in multi-device collaborative scenarios are solved, achieving a balance between overall risk perception and normal equipment operation, and improving safety protection capabilities.

CN122117207APending Publication Date: 2026-05-29NAT IND INFORMATION SECURITY DEV RES CENT

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NAT IND INFORMATION SECURITY DEV RES CENT
Filing Date
2026-03-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies for the security protection of medical imaging equipment suffer from fragmented risk perception, static protection strategies, lack of risk prediction capabilities, and insufficient compatibility between protection and diagnosis and treatment, failing to meet the needs of multi-device collaboration, dynamic protection, and overall risk perception.

Method used

By constructing a multi-source data association map of medical devices, and combining device operation data and diagnosis and treatment scenario data, risk intensity values ​​are identified and dynamic adaptive protection schemes are formulated to achieve overall risk perception in multi-device collaborative scenarios while ensuring normal device operation.

Benefits of technology

It improves the safety protection capabilities of medical equipment, ensures overall risk perception and dynamic protection of equipment in multi-device collaborative scenarios, takes into account the normal operation of equipment, and avoids interference of protective measures with the diagnosis and treatment process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122117207A_ABST
    Figure CN122117207A_ABST
Patent Text Reader

Abstract

The application discloses a safety protection method and device, a storage medium and a program product, and belongs to the medical safety field. The method comprises the following steps: acquiring multi-source data of a plurality of first medical devices, wherein the multi-source data comprises device running data, image communication data and diagnosis and treatment scene data; constructing a device correlation graph of the plurality of first medical devices according to the image communication data and the diagnosis and treatment scene data; determining a risk intensity value of one or more second medical devices according to the device running data; and determining a safety protection scheme according to the diagnosis and treatment scene data, the device correlation graph and the risk intensity value of the one or more second medical devices. According to the device correlation graph and the risk intensity value of the one or more second medical devices, the overall risk in a multi-device cooperative scene can be determined, and then, in combination with the diagnosis and treatment scene data, the determined safety protection scheme can guarantee the safety protection and normal operation of the devices. In this way, the safety protection capability of the devices can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of medical safety, and in particular to a safety protection method, device, storage medium, and program product. Background Technology

[0002] With the deep integration of IoT technology and the healthcare industry, medical imaging equipment has evolved from traditional standalone diagnostic terminals into core nodes in the Internet of Medical Things (IoMT), supporting the entire clinical diagnosis and treatment process through multi-device collaboration, remote operation and maintenance, and data sharing. In this context, improving the security of medical imaging equipment is a key issue that requires attention.

[0003] In related technologies, general-purpose vulnerability scanning tools are used to scan for vulnerabilities in medical imaging equipment in order to achieve security protection for the equipment. However, the security protection capabilities of this method are limited. Summary of the Invention

[0004] This application provides a security protection method, device, storage medium, and program product, which can improve security protection capabilities. The technical solution is as follows: Firstly, a security protection method is provided, the method comprising: Acquire multi-source data from multiple primary medical devices, including device operation data, image communication data, and diagnosis and treatment scenario data; A device association map of the multiple first medical devices is constructed based on the image communication data and the diagnosis and treatment scenario data; Based on the equipment operation data, determine the risk intensity value of one or more second medical devices among the plurality of first medical devices, wherein the second medical device is a first medical device that poses a safety risk; A safety protection scheme is determined based on the diagnosis and treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices.

[0005] In this application, the device association map constructed based on multi-source data can reflect the communication relationships, diagnostic and therapeutic function dependencies, and hardware connection relationships among multiple first medical devices in a multi-device collaborative scenario. By determining the risk intensity value of one or more second medical devices, the overall risk situation in the multi-device collaborative scenario can be determined based on the device association map and the risk intensity value of the one or more second medical devices. Furthermore, by combining this diagnostic and therapeutic scenario data, the determined security protection scheme can not only ensure the safety of device protection but also guarantee the normal operation of the devices. Thus, the security protection capability of medical devices can be improved.

[0006] Optionally, constructing the device association map of the plurality of first medical devices based on the image communication data and the diagnosis and treatment scenario data includes: Based on the image communication data and the diagnosis and treatment scenario data, determine the image data interaction links, diagnosis and treatment function dependency links, and physical deployment association links among the plurality of first medical devices; The device association strength among the plurality of first medical devices is determined based on the image communication data and the diagnostic and treatment function dependency link; Based on the image data interaction link, the diagnostic and treatment function dependency link, the physical deployment association link, and the device association strength, the device association map is constructed.

[0007] Optionally, determining the device association strength among the plurality of first medical devices based on the image communication data and the diagnostic and therapeutic function dependency link includes: The data interaction frequency and data interaction volume between the plurality of first medical devices are determined based on the image communication data. The degree of dependence of diagnostic and therapeutic functions among the plurality of first medical devices is determined based on the diagnostic and therapeutic function dependency link; The device association strength is determined based on the data interaction frequency, the data interaction volume, and the degree of dependence on the diagnostic and treatment functions.

[0008] Optionally, determining the risk intensity value of one or more second medical devices among the plurality of first medical devices based on the device operating data includes: For any one of the plurality of first medical devices, risk detection is performed on the first medical device based on the device operation data of the first medical device to obtain risk detection information of the first medical device; If the risk detection information of the first medical device indicates that the first medical device has a safety risk, the first medical device is identified as the second medical device, and the safety risk of the first medical device is assessed to obtain the risk intensity value of the first medical device.

[0009] Optionally, determining the safety protection scheme based on the diagnosis and treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices includes: For any one of the one or more second medical devices, based on the device association map and the risk detection information of the second medical device, one or more third medical devices are determined from the plurality of first medical devices, wherein the third medical device is a first medical device that may be affected by the safety risks present in the second medical device; Based on the device association strength between the second medical device and the one or more third medical devices in the device association map, determine one or more risk diffusion probabilities corresponding to the second medical device; The safety protection scheme is determined based on the diagnosis and treatment scenario data, the risk intensity value of each of the one or more second medical devices, and the corresponding one or more risk diffusion probabilities.

[0010] Optionally, determining the risk diffusion probability corresponding to the second medical device based on the device association strength between the second medical device and the one or more third medical devices in the device association map includes: Based on the medical protection completeness of the second medical device, the correction coefficient corresponding to the diagnosis and treatment scenario indicated by the diagnosis and treatment scenario data of the second medical device, the risk propagation characteristic coefficient corresponding to the safety risk indicated by the risk detection information of the second medical device, and the device association strength between the second medical device and the one or more third medical devices in the device association map, determine one or more risk diffusion probabilities corresponding to the second medical device.

[0011] Optionally, determining the safety protection scheme based on the diagnosis and treatment scenario data, the risk intensity value of each of the one or more second medical devices, and the corresponding one or more risk diffusion probabilities includes: The diffusion risk level is determined based on the risk intensity value of each of the one or more second medical devices and the corresponding one or more risk diffusion probabilities; The target treatment scenario coefficient is determined based on the treatment scenario data. The target treatment scenario coefficient is the coefficient corresponding to the highest priority target treatment scenario among the treatment scenarios of the plurality of first medical devices. The target risk score is determined based on the target risk intensity value, the target treatment scenario coefficient, and the diffusion risk level, wherein the target risk intensity value is the highest risk intensity value among the risk intensity values ​​of the one or more second medical devices; The safety protection scheme is determined based on the target risk score and the target diagnosis and treatment scenario.

[0012] Secondly, a safety protection device is provided, the device comprising: The acquisition module is used to acquire multi-source data from multiple first medical devices, including device operation data, image communication data, and diagnosis and treatment scenario data. The construction module is used to construct a device association map of the multiple first medical devices based on the image communication data and the diagnosis and treatment scenario data; The first determining module is used to determine the risk intensity value of one or more second medical devices among the plurality of first medical devices based on the device operation data, wherein the second medical device is a first medical device that has a safety risk; The second determining module is used to determine a safety protection scheme based on the diagnosis and treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices.

[0013] Thirdly, a computer device is provided, the computer device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the security protection method described in the first aspect.

[0014] Fourthly, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program, which, when executed by a processor, implements the security protection method described in the first aspect.

[0015] Fifthly, a computer program product is provided that, when the computer program product is run on a computer device, causes the computer device to perform the security protection method described in the first aspect.

[0016] It is understood that the beneficial effects of the second, third, fourth, and fifth aspects mentioned above can be found in the relevant descriptions in the first aspect above, and will not be repeated here. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the structure of a security protection system provided in an embodiment of this application; Figure 2 This is a flowchart of a security protection method provided in an embodiment of this application; Figure 3 This is a flowchart of another security protection method provided in the embodiments of this application; Figure 4 This is a schematic diagram of the structure of a safety protection device provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0018] In the following description, specific details such as particular system architectures and technologies are set forth for illustrative purposes and not for limiting purposes, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details.

[0019] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or collections thereof. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0020] It should be understood that "one or more" as used in this application refers to one, two, or more, and "multiple" as used in this application refers to two or more. In the description of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. "And / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone.

[0021] To facilitate a clear description of the technical solutions of this application, the terms "first" and "second" are used to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and that the terms "first" and "second" do not necessarily imply that they are different.

[0022] The terms "one embodiment" or "some embodiments" used in this application mean that one or more embodiments of this application include the specific features, structures, or characteristics described in that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this application do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized.

[0023] The application scenarios involved in the embodiments of this application are described below.

[0024] With the deep integration of IoT technology and the healthcare industry, medical imaging equipment has evolved from traditional independent diagnostic terminals into core nodes in IoMT (Internet of Medical Devices), supporting the entire clinical diagnosis and treatment process through multi-device collaboration, remote operation and maintenance, and data sharing. Multimodal image fusion diagnosis and cross-device data linkage have become mainstream diagnostic and treatment models. In this business scenario, it is necessary not only to cover the security protection of individual devices but also to cover the overall security protection of "multi-device association, full-process collaboration, and treatment priority." Based on this, the demand for dynamic collaborative security protection of medical imaging equipment in the medical IoT environment is increasingly urgent—it requires not only accurate perception of risk diffusion in multi-device association scenarios but also dynamic protection strategies that adapt to changes in device operating status and treatment scenarios. Furthermore, it is crucial to achieve a balance between security protection and clinical diagnosis and treatment compatibility, ensuring the real-time transmission of image data and the accuracy of diagnostic parameters, and preventing protective operations from interfering with critical diagnostic and treatment processes such as emergency scans and intraoperative image guidance.

[0025] In related technologies, general-purpose vulnerability scanning tools, static risk assessment systems, and passive protection devices are used to detect vulnerabilities in medical imaging equipment, thereby achieving security protection for the equipment. However, these solutions all rely on general network security logic and are not customized for the specific business characteristics of medical imaging equipment. Therefore, they present several problems in medical IoT collaborative scenarios, as follows: 1. Fragmented risk perception, failing to cover risks associated with multi-device collaboration: Related technologies only perform independent detection on single devices; "single-point security ≠ overall security," failing to consider the risk correlation and diffusion characteristics in multi-device collaborative diagnosis and treatment scenarios (e.g., after one device is compromised, medical imaging data from related devices can be stolen through data interaction links, or cross-device collaborative attacks can be launched to tamper with diagnostic parameters). This is because the related technologies are not adapted to the business characteristics of medical imaging equipment—"multi-device collaboration, strong correlation of imaging data, and uninterrupted diagnostic and treatment links"—and lack the ability to analyze the correlation between device interaction links and functional dependencies, thus failing to form a holistic security situation awareness.

[0026] 2. Static protection strategies are ill-suited to dynamic security changes: The protection rules of related technologies are mostly preset, fixed configurations that can only intercept known attacks. They cannot dynamically adjust protection strength and strategies based on device operating status (e.g., firmware malfunctions, abnormal central processing unit (CPU) / memory usage), changes in the medical scenario (e.g., emergency care, routine care), or emerging threats. This is because they employ a "generalized, fixed" protection logic that fails to consider real-time operational data of medical imaging equipment and clinical scenario priorities (e.g., emergency > surgery > routine), leading to delayed responses to unknown attacks or sudden risks.

[0027] 3. Lack of risk prediction capabilities, hindering proactive protection: Related technologies primarily rely on "post-incident detection," passively responding only after vulnerabilities or attacks occur, lacking the ability to anticipate potential risks in advance (e.g., predicting security vulnerabilities caused by firmware failures based on device operating trends, or predicting protocol attacks based on data interaction patterns). This is because risk prediction models based on multi-source operational data have not been built, and the correlation between device operating status, image data interaction patterns, diagnostic and treatment operation characteristics, and security risks has not been explored, failing to meet the healthcare industry's security requirements for "prevention and proactive protection."

[0028] 4. Insufficient compatibility between protection and treatment, affecting clinical safety: Some existing protective measures (such as high-strength encryption and frequent security checks) do not consider the high real-time requirements of medical imaging equipment, which may lead to image data transmission delays, CT / MRI scan parameter loading delays, interruptions in intraoperative image guidance, and even abnormal equipment shutdowns, affecting clinical treatment processes. This is because the core demands of "security protection" and "treatment priority" in medical scenarios have not been balanced. The protection strategy design is not adapted to the operational characteristics of medical imaging equipment, such as "large image data volume, high real-time requirements of diagnostic and treatment operations, and uninterrupted critical processes," and the real-time needs of diagnostic and treatment services, resulting in a conflict between security protection and treatment.

[0029] In summary, the relevant technologies are not adapted to the core characteristics of medical imaging equipment, such as "multi-device collaboration, high real-time performance, priority of diagnosis and treatment, and high sensitivity of image data." This results in a serious disconnect between security protection and the actual needs of IoMT collaborative scenarios. They cannot meet the requirements of overall risk perception, dynamic protection, pre-emptive prediction, and security and diagnosis and treatment compatibility under multi-device collaboration, and their security protection capabilities are limited.

[0030] Therefore, this application provides a security protection method, which, for example, can be applied to the security protection system described below. In this method, multi-source data from multiple first medical devices is acquired, including device operation data, image communication data, and treatment scenario data. Then, a device association map of the multiple first medical devices is constructed based on the image communication data and the treatment scenario data. Next, the risk intensity value of one or more second medical devices among the multiple first medical devices is determined based on the device operation data. The second medical devices are the first medical devices with security risks. Finally, a security protection scheme is determined based on the treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices. Since the device association map constructed based on multi-source data can reflect the communication relationships, treatment function dependencies, and device hardware connection relationships among the multiple first medical devices in a multi-device collaborative scenario, the overall risk situation in the multi-device collaborative scenario can be determined based on the device association map and the risk intensity value of the one or more second medical devices, after determining the risk intensity value of the one or more second medical devices. Furthermore, by combining the treatment scenario data, the determined security protection scheme can not only ensure device protection security but also ensure the normal operation of the devices. This can improve the safety and protection capabilities of medical equipment.

[0031] The security protection system provided in the embodiments of this application will be described below.

[0032] Figure 1 This is a schematic diagram of the structure of a security protection system provided in an embodiment of this application. See also... Figure 1 The security protection system 10 may include a multi-source data real-time acquisition module 101, a medical imaging equipment association map construction module 102, a risk association analysis and diffusion path modeling module 103, an overall risk situation assessment module 104, and a dynamic adaptive protection strategy adjustment module 105.

[0033] The multi-source data real-time acquisition module 101 is used to acquire multi-source data from multiple medical devices (hereinafter referred to as the first medical device). This multi-source data includes device operation data, image communication data, and diagnostic and treatment scenario data. For example, a lightweight local acquisition module can be deployed in radiology CT scanners, MRI machines, diagnostic workstations, and picture archiving and communication systems (PACS). Dedicated traffic acquisition nodes using the Digital Imaging and Communications in Medicine (DICOM) / Health Level Seven (HL7) protocol can be deployed on the departmental network to construct a comprehensive data acquisition network for the medical imaging industry, enabling real-time acquisition of these three types of medical imaging data. For example, the acquisition frequency of multi-source data can be preset, such as according to the diagnostic and treatment scenario. For instance, in an emergency scenario, the acquisition frequency of multi-source data can be 1 second / time; in a routine scenario, the acquisition frequency can be 5 seconds / time.

[0034] The device's operational data can reflect the operational health of the diagnostic and treatment functions of the first medical device. For example, the device's operational data may include one or more of the following: CPU utilization, memory utilization, firmware status codes, hardware fault logs, device start / stop records, and image scan parameter loading status; however, this application embodiment does not limit this.

[0035] The image communication data can record the image data interaction behavior between the first medical devices. For example, the image communication data may include the interaction protocol type between the first medical devices, image data transmission rate / integrity, synchronous recording of diagnostic and treatment parameters, PACS server data read and write logs, transmission control protocol (TCP) / user datagram protocol (UDP) connection status, communication port usage, etc., but this application embodiment does not limit this.

[0036] For example, the data for this diagnosis and treatment scenario may include the type of diagnosis and treatment, the priority of the diagnosis and treatment scenario, the peak patient flow, the equipment collaboration mode (such as multimodal fusion diagnosis / single-device independent examination), and the progress of the diagnosis and treatment task (such as scanning / image transmission / diagnosis), etc., which are not limited in this embodiment. For example, the type of diagnosis and treatment may include one or more of emergency CT, intraoperative MRI, and conventional digital radiography (DR), etc., which are not limited in this embodiment. For example, the diagnosis and treatment scenario may include one or more of emergency diagnosis and treatment, routine diagnosis and treatment, and equipment standby / maintenance, etc., which are not limited in this embodiment. The diagnosis and treatment scenario has a priority. For example, the priority value of emergency diagnosis and treatment may be 1, the priority value of intraoperative MRI-guided diagnosis and treatment may be 0.9, and the priority value of routine imaging examination may be 0.7, etc., which are not limited in this embodiment.

[0037] In some cases, after the multi-source data real-time acquisition module 101 acquires multi-source data, it can transmit the multi-source data in real time to the data processing center in the security protection system 10 via a low-latency encrypted link for deduplication, format standardization, and other operations to filter out redundant data unrelated to image diagnosis and treatment. In this way, high-quality data is provided for subsequent analysis without affecting the normal operation of the primary medical equipment.

[0038] The medical imaging equipment association map construction module 102 is used to construct an equipment association map of multiple primary medical devices based on image communication data and diagnostic and treatment scenario data from the multi-source data. Specifically, the module 102 can extract core association criteria for medical imaging devices from the image communication data and diagnostic and treatment scenario data, eliminate device associations unrelated to image diagnosis and treatment, and then, based on these core association criteria, sort and label the association links of three types of medical imaging to obtain image data interaction links, diagnostic and treatment function dependency links, and physical deployment association links. It quantifies the association strength between these multiple primary medical devices and finally constructs an equipment association map of multiple primary medical devices based on these image data interaction links, diagnostic and treatment function dependency links, physical deployment association links, and the association strength between these multiple primary medical devices. In this way, newly added medical imaging devices (such as CT scanners, MRI machines, ultrasound machines, etc.) can be automatically connected to a dedicated association map without redeploying the system, offering strong scalability and meeting the equipment iteration needs of medical institutions.

[0039] The core association criteria for medical imaging equipment can clearly define the exclusive connection basis between radiology equipment. For example, the medical imaging equipment association map construction module 102 can extract relationships between image communication data and diagnostic / treatment scenario data through deep packet inspection and protocol parsing to obtain the core association criteria for medical imaging equipment. For example, the core association criteria for medical imaging equipment may include one or more of the following: device Internet Protocol (IP) address, DICOM / HL7 protocol compatibility, collaborative diagnostic / treatment business links, etc., but this application embodiment does not limit this. For instance, the connection basis and interaction relationships between CT scanner > PACS server > diagnostic workstation can be extracted from image communication data and diagnostic / treatment scenario data.

[0040] For example, the medical imaging equipment association map construction module 102 can determine the association strength between the multiple first medical devices based on the frequency of image data interaction and the degree of dependence on diagnostic and treatment functions between the multiple first medical devices.

[0041] In some cases, the medical imaging equipment association map construction module 102 can construct an equipment association map of multiple first medical devices based on the image communication data and diagnosis and treatment scenario data in the multi-source data, using a medical imaging equipment-specific map construction algorithm. For example, a general algorithm (such as a knowledge graph construction algorithm) can be optimized by adding protocol adaptation and diagnosis and treatment link association dimensions to obtain a medical imaging equipment-specific map construction algorithm. This algorithm can automatically generate a network of association relationships among multiple radiology devices, constructing an equipment association map around the core medical imaging business link of "image acquisition-transmission-diagnosis-storage".

[0042] In other cases, the medical imaging device association map construction module 102 can input the image communication data and treatment scenario data from the multi-source data into the device association map model to obtain the device association map output by the device association map model. Since the image communication data can reflect the communication process and data interaction process between the first medical devices, and the treatment scenario data can reflect the functional dependence between the first medical devices, and the image communication data can also reflect the interaction frequency and data interaction volume between the first medical devices, the device association map model can construct a device association map based on the image communication data and treatment scenario data from the multi-source data.

[0043] The risk association analysis and diffusion path modeling module 103 is used to identify single-point risks for each of the multiple first medical devices, and to determine one or more second medical devices with safety risks among these first medical devices. Based on these one or more second medical devices and the device association map, association impact analysis is performed to obtain one or more third medical devices that each second medical device may affect. The risk diffusion probability of each second medical device to its corresponding one or more third medical devices is determined. Finally, the quantified diffusion probability is labeled in the image data or diagnostic and treatment function links of the device association map to construct a visualized medical imaging device risk diffusion path model.

[0044] For example, the risk association analysis and diffusion path modeling module 103 can perform vulnerability scanning and anomaly detection on the equipment operation data of the multiple first medical devices to obtain risk detection information (also known as single-point risk information) for each first medical device, and identify risks in the medical imaging industry (such as DICOM protocol parsing vulnerabilities, illegal modification of diagnostic parameters, unencrypted image data transmission, and unauthorized access to PACS servers).

[0045] For example, after obtaining the risk detection information for each first medical device, if the risk detection information indicates that the first medical device has a security risk, then the first medical device is identified as a second medical device, and the security risk of the first medical device is assessed to obtain the risk intensity value of the first medical device. For example, the risk intensity can be determined according to the scoring criteria of the Common Vulnerability Scoring System (CVSS) v3.1 and the impact coefficient of the medical scenario.

[0046] For example, the risk association analysis and diffusion path modeling module 103 can identify one or more third medical devices from multiple first medical devices based on the device association map and the risk detection information of the second medical devices. Specifically, based on the device association map, it can trace the associated devices that may be affected by a single point of risk, identify the core nodes on the image data link and the diagnosis and treatment function link, clarify the potential path of risk diffusion, and identify the one or more third medical devices. For example, a DICOM protocol vulnerability in an emergency CT scanner may affect the PACS image storage server and the emergency diagnostic workstation through the image data interaction link, thereby leading to the leakage or tampering of emergency image data.

[0047] For example, devices marked in red can be associated with high-risk transmission links in the network map, devices marked in yellow with medium-risk links, and devices marked in green with low-risk links. This identifies key protective nodes within primary medical equipment (such as PACS servers and emergency diagnostic workstations), providing precise guidance for subsequent protective strategies.

[0048] The overall risk situation assessment 104 is used to determine the comprehensive risk score (i.e., target risk score) under the current diagnosis and treatment scenario based on the priority of the diagnosis and treatment scenario, the risk intensity of each second device, and one or more risk diffusion probabilities corresponding to each second device.

[0049] The dynamic adaptive protection strategy adjustment module 105 is used to determine the security protection scheme based on the risk level corresponding to the target risk score and the priority of the diagnosis and treatment scenario. Through matching of risk level and diagnosis and treatment scenario priority in two dimensions, and with core differentiated design, it can break away from general protection logic, making the security protection scheme more suitable for the risks in the current medical scenario, thereby improving security protection capabilities.

[0050] The security protection method provided in the embodiments of this application will be explained in detail below.

[0051] Figure 2 This is a flowchart of a security protection method provided in an embodiment of this application. See also... Figure 2 The method may include the following steps: Step 201: The computer device acquires multi-source data from multiple primary medical devices, including device operation data, image communication data, and diagnosis and treatment scenario data.

[0052] The device operation data refers to the status, performance, and fault information generated during the operation of the first medical device. For example, the device operation data may include one or more of the following: CPU utilization, memory utilization, firmware status codes, hardware fault logs, device start / stop records, and image scan parameter loading status; however, this embodiment does not limit the specific data.

[0053] The image communication data refers to the data generated during the transmission and communication of medical image data between the first medical devices. For example, the image communication data may include one or more of the following: interaction protocol type, image data transmission rate, image data transmission integrity, synchronous recording of diagnostic and treatment parameters, PACS server data read / write logs, TCP / UDP connection status, and communication port usage. This application embodiment does not limit these aspects.

[0054] The diagnosis and treatment scenario data refers to data related to diagnosis and treatment generated in a medical diagnosis and treatment scenario. For example, the diagnosis and treatment scenario data may include one or more of the following: diagnosis and treatment type, diagnosis and treatment scenario priority, peak patient traffic, device collaboration mode, diagnosis and treatment task progress, etc., but this application embodiment does not limit this.

[0055] By acquiring equipment operation data, image communication data, and diagnosis and treatment scenario data from multiple primary medical devices, multi-dimensional data references are provided for the subsequent construction of device correlation maps. This provides data basis for conducting correlation analysis and determining safety protection schemes, which can solve the problem of one-sided risk perception caused by insufficient support from single points of data and improve the comprehensiveness of risk perception.

[0056] In some cases, after acquiring multi-source data from multiple first medical devices, the computer device can preprocess the multi-source data to improve its accuracy. For example, preprocessing may include deduplication, format standardization, etc., but this application embodiment does not limit this.

[0057] Step 202: The computer device constructs a device association map of the multiple first medical devices based on the image communication data and the diagnosis and treatment scenario data.

[0058] The correlation map of these multiple primary medical devices can reflect the relationships between them in terms of image data interaction, diagnostic and treatment function dependence, and physical connection links.

[0059] Since the image communication data can reflect the interaction relationship, image data transmission relationship and communication process between the multiple first medical devices, and the diagnosis and treatment scenario data can reflect the functional dependence between the multiple first medical devices, a device association map of the multiple first medical devices in the current diagnosis and treatment scenario can be constructed based on the image communication data and the diagnosis and treatment scenario data.

[0060] By constructing a device association map, we can overcome the limitations of single-point detection, thereby gaining a more intuitive understanding of the overall risks in multi-device collaborative scenarios, identifying the risk diffusion paths of image data links and diagnostic and treatment function links, and solving the fragmented perception problem of multi-device association in related technologies.

[0061] In some implementations, step 202 may involve: determining the image data interaction links, diagnostic function dependency links, and physical deployment association links among the plurality of first medical devices based on the image communication data and the diagnostic and treatment scenario data; determining the device association strength among the plurality of first medical devices based on the image communication data and the diagnostic and treatment function dependency links; and constructing the device association map based on the image data interaction links, the diagnostic and treatment function dependency links, the physical deployment association links, and the device association strength.

[0062] This image data interaction link is the transmission link between multiple primary medical devices. For example, the primary medical devices in the image communication data and diagnostic scenario data can be labeled using traffic feature analysis and rule matching to obtain the image data interaction order between the primary medical devices. Then, the image data interaction link is determined by combining the core association criteria of the medical imaging devices and the image data interaction order between the primary medical devices. For instance, this image data interaction link could be an image data transmission path from an emergency CT scanner to a PACS image storage server, or a diagnostic parameter synchronization path from an MRI scanner to a diagnostic workstation.

[0063] This diagnostic and treatment function dependency link refers to the data flow and functional dependencies between different primary medical devices. For example, heuristic mining algorithms can be used to mine the functional dependencies between primary medical devices in diagnostic and treatment scenario data to obtain the diagnostic and treatment function dependency link. For instance, this dependency link could be the dependency of a diagnostic workstation on the raw image data of a CT / MRI machine, or the dependency of an MRI-guided surgical device on the image data of a surgical navigation system.

[0064] The physical deployment association links are the connections formed by the actual physical locations and network relationships of multiple primary medical devices. For example, the physical location attributes between these multiple primary medical devices can be determined through network topology discovery and business rule clustering. Then, cluster analysis of the physical location attributes is performed using business rule clustering to obtain the physical deployment association links. For instance, these physical deployment association links could be the network relationship between a CT scanner and its supporting workstation in a radiology emergency examination room, or the network relationship between multiple DR devices in a routine examination area.

[0065] The image communication data can reflect the frequency of interaction, the amount of data exchange, and the degree of dependence among the multiple first medical devices, reflecting the activity of interaction between the devices. The diagnostic and treatment function dependency link can reflect the necessity of functional dependence between the first medical devices, reflecting the necessity of business collaboration between the devices. Therefore, based on the image communication data and the diagnostic and treatment function dependency link, the correlation strength between the multiple first medical devices can be determined relatively accurately.

[0066] The image data interaction link can represent the interaction relationship of image data, the diagnostic and treatment function dependency link can reflect the dependence of the device's diagnostic and treatment functions on image data, the physical deployment association link can reflect the physical connection relationship between the multiple first medical devices, and the association strength between the multiple first medical devices can reflect the association between the devices. Therefore, based on the image data interaction link, the diagnostic and treatment function dependency link, the physical deployment association link, and the device association strength, a device association map reflecting the collaborative diagnosis and treatment of the multiple first medical devices can be constructed.

[0067] Optionally, the operation of the computer device to determine the device association strength among the plurality of first medical devices based on the image communication data and the diagnostic and treatment function dependency link can be as follows: determining the data interaction frequency and data interaction amount among the plurality of first medical devices based on the image communication data; determining the degree of diagnostic and treatment function dependency among the plurality of first medical devices based on the diagnostic and treatment function dependency link; and determining the device association strength based on the data interaction frequency, the data interaction amount, and the degree of diagnostic and treatment function dependency.

[0068] This data interaction frequency It can quantify the frequency of interactions between devices.

[0069] This data interaction volume It can quantify the degree of data dependence between primary medical devices.

[0070] Dependence on diagnostic and treatment functions The necessity of business collaboration between devices can be quantified, reflecting whether the execution of the core function of one first medical device depends on the output of another first medical device. For example, the degree of dependence on diagnostic and treatment functions can include one or more of strong functional dependence, moderate functional dependence, and no functional dependence, which is not limited in this embodiment. Strong functional dependence means that the core function of one first medical device can only complete its diagnostic and treatment functions by relying on the input of another first medical device (e.g., an image storage server depends on the image data input of an ultrasound device). For example, strong functional dependence... The value can be 1. This moderate functional dependency indicates that the operation of a core function of a primary medical device requires at least the output data of two other primary medical devices (e.g., a diagnostic workstation relies on image data from a CT scanner and can also receive data from an MRI scanner). For example, moderate functional dependency... The value can be 0.5. This "no functional dependency" indicates that there is no direct business relationship between one medical device and another (e.g., ultrasound equipment and electrocardiograph). For example, no functional dependency... The value of can be 0.

[0071] For example, the frequency of data interaction, the amount of data interaction, and the degree of dependence on diagnostic and treatment functions can be normalized values.

[0072] For example, for any one of the multiple first medical devices, the actual number of communications (such as the number of TCP connection establishments, DICOM data transmission requests, etc.) between the communicating first medical device and the first medical device can be determined based on the image communication data of that first medical device. Then, the actual number of communications can be divided by the maximum number of communications among the multiple first medical devices to obtain the data interaction frequency. For example, the number of communications can be counted based on the image communication data of the multiple first medical devices within one hour.

[0073] For example, the computer device can determine the data interaction frequency using the following formula, based on the actual number of communications and the maximum number of communications.

[0074]

[0075] in, Let i be the data interaction frequency, i be the first medical device, and j be the first medical device communicating with the first medical device.

[0076] For example, if the ultrasound device (i) communicates with the image storage server (j) 800 times per hour, and the maximum number of communications among the multiple first medical devices is 1000 times per hour, then the data interaction frequency between the ultrasound device (i) and the image storage server (j) is 0.8.

[0077] For example, for any one of the plurality of first medical devices, the actual amount of data between the first medical device and the first medical device communicating with it can be determined based on the image communication data of the first medical device. Then, the actual amount of data interaction is divided by the maximum amount of data among the plurality of first medical devices to obtain the amount of data interaction.

[0078] For example, the computer device can determine the amount of data interaction based on the actual amount of data and the maximum amount of data using the following formula.

[0079]

[0080] in, Let i be the data interaction frequency, i be the first medical device, and j be the first medical device communicating with the first medical device.

[0081] For example, if ultrasound device (i) transmits 6 gigabytes (GB) of data to image storage server (j) within 1 hour, and the maximum data exchange volume among the multiple first medical devices is 10 GB within 1 hour, then the data exchange frequency is 0.6.

[0082] For example, the computer device can determine the device association strength using the following formula based on the data interaction frequency, the data interaction volume, and the degree of dependence on the diagnostic function.

[0083]

[0084] in, For equipment correlation strength, This is a weighting coefficient for the frequency of data interaction. This is the weighting coefficient for the amount of data interaction. For example, the weighting coefficients for the degree of dependence on this diagnostic and treatment function. , , .

[0085] In some implementations, after determining the association strength of the devices, the computer device can mark the association map to indicate the association strength and risk diffusion priority between the first medical devices.

[0086] For example, as shown in Table 1 below, if the device association strength is greater than or equal to 0.7, a solid line can be used to mark the first medical device i and the second medical device j to indicate a strong association between them and a high risk diffusion priority from the first medical device i to the second medical device j. If the device association strength is greater than or equal to 0.3 and less than 0.7, a dashed line can be used to mark the first medical device i and the second medical device j to indicate a moderate association between them and a medium risk diffusion priority from the first medical device i to the second medical device j. If the device association strength is less than 0.3, a dotted line can be used to mark the first medical device i and the second medical device j to indicate a weak or no association between them and a low risk diffusion priority from the first medical device i to the second medical device j.

[0087] Table 1

[0088] Step 203: The computer device determines the risk intensity value of one or more second medical devices among the plurality of first medical devices based on the device's operating data. The second medical device is a first medical device that poses a safety risk.

[0089] The operational data of the primary medical device can reflect its current operational security status. For example, if the operational data indicates an abnormal spike in CPU / memory usage, it suggests that the primary medical device may be executing malicious code or suffering a denial-of-service attack. Furthermore, if the firmware status code in the operational data is incorrect, it indicates that the primary medical device may have had its firmware tampered with, be subject to unauthorized access, or have vulnerabilities being triggered.

[0090] The risk intensity value of a second medical device reflects the degree of technical hazard posed by the safety risks currently present in that device. A higher risk intensity value indicates a higher level of safety risk and a greater impact on the device; conversely, a lower risk intensity value indicates a lower level of safety risk and a smaller impact on the device.

[0091] By determining the risk intensity value of one or more second medical devices, the degree of safety risk posed by these devices can be known in a timely manner, and the potential danger to these multiple first medical devices can be understood, thus providing a reference for determining subsequent safety protection plans.

[0092] In some implementations, step 203 may be performed as follows: for any one of the plurality of first medical devices, risk detection is performed on the first medical device based on the device operation data of the first medical device to obtain risk detection information of the first medical device; if the risk detection information of the first medical device indicates that the first medical device has a safety risk, the first medical device is determined to be the second medical device, and the safety risk of the first medical device is assessed to obtain the risk intensity value of the first medical device.

[0093] For example, the computer device can perform dedicated vulnerability scanning and anomaly detection on the device operation data of the first medical device to obtain risk detection information of the first medical device. For example, the risk detection information of the first medical device may include vulnerability type or risk type.

[0094] For example, the vulnerability type or risk type in the risk detection information can be evaluated by combining the CVSSv3.1 scoring criteria and the medical scenario impact coefficient to obtain the risk intensity value of the first medical device. Different vulnerability types or risk types have different degrees of impact on the security risk of the first medical device. For example, the risk intensity of tampering with diagnostic parameters is much higher than that of general port vulnerabilities. For example, the risk intensity value of the second medical device has a risk level and a range. For example, the range of the risk intensity value of the second medical device can be 0-10. Thus, given the highly sensitive nature of medical imaging equipment image data, risk identification and protection can prioritize core risks such as image data theft and tampering, which can better meet the data security needs of the medical industry compared to general protection solutions.

[0095] For example, as shown in Table 2 below, when the risk type is firmware remote code execution vulnerability or device control privilege leakage, the risk level is critical, and the risk intensity value ranges from 9.0 to 10.0; when the risk type is unauthorized access to the DICOM protocol or hard-coded credentials, the risk level is high, and the risk intensity value ranges from 7.0 to 8.9; when the risk type is misconfiguration or low-risk vulnerability, the risk level is medium, and the risk intensity value ranges from 4.0 to 6.9; when the risk type is redundant code or log information leakage, the risk level is low, and the risk intensity value ranges from 0.1 to 3.9; when there is no risk type, the risk level is zero, and the risk intensity value ranges from 0.0.

[0096] Table 2

[0097] If the risk detection information indicates that the first medical device has no security risks, it means that the first medical device does not have vulnerabilities or other abnormalities. Therefore, it is not necessary to identify the first medical device as the second medical device, nor is it necessary to assess the security risks of the first medical device. If the risk detection information indicates that the first medical device has security risks, it means that the first medical device may have vulnerabilities or other abnormalities. Therefore, the first medical device can be identified as the second medical device. However, since the security risks of the first medical device may affect its own operation and the normal operation of other first medical devices, the security risks of the first medical device can be assessed to obtain the risk intensity value of the current security risks of the first medical device.

[0098] Step 204: The computer device determines a security protection scheme based on the diagnosis and treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices.

[0099] The diagnostic and treatment scenario data can reflect the current diagnostic and treatment scenario of the first medical device. For example, the diagnostic and treatment scenario indicated by the diagnostic and treatment scenario data may include one or more of the following: emergency diagnostic and treatment scenario, routine diagnostic and treatment scenario, equipment standby or maintenance, etc., and this application embodiment does not limit this.

[0100] Different safety protection schemes may employ protective measures that could affect the normal operation of the primary medical device and even the normal diagnosis and treatment of patients. Furthermore, the risk intensity value of the secondary medical device reflects the severity of the current risks associated with it. Therefore, a safety protection scheme that aligns with the diagnosis and treatment scenario data can be determined based on the data, the device correlation map, and the risk intensity values ​​of the one or more secondary medical devices. In this way, while ensuring the safe operation of the one or more secondary medical devices, it is possible to avoid affecting their normal operation (such as interfering with core diagnostic processes like image acquisition, transmission, and diagnosis), thereby addressing the issues of static protection strategies and insufficient compatibility with clinical practice, and achieving a dynamic balance between safety protection and clinical treatment.

[0101] In some implementations, step 204 may include steps (1) to (3) as follows.

[0102] Step (1): For any one of the one or more second medical devices, the computer device determines one or more third medical devices from the multiple first medical devices based on the device association map and the risk detection information of the second medical devices. The third medical device is a first medical device that may be affected by the security risks of the second medical devices.

[0103] For example, by combining the device association map and the risk detection information of the second medical device, an association impact analysis can be performed on the second medical device. This allows for tracing the related devices that the second medical device may be radiated from, identifying core nodes in the image data link and diagnostic function link related to the second medical device, and clarifying potential paths for risk spread. For instance, a vulnerability in the DICOM protocol of an emergency CT scanner could affect the PACS image storage server and emergency diagnostic workstation through the image data interaction link, leading to the leakage or tampering of emergency image data.

[0104] The device association map includes the image data interaction link and diagnosis and treatment function link related to the second medical device, and includes one or more first medical devices associated with the second medical device and the corresponding device association strength. The risk monitoring information can reflect the risks existing in the second medical device. Different risks have different transmission capabilities and impact levels. Therefore, based on the device association map and the risk detection information of the second medical device, one or more third medical devices can be accurately identified from the multiple third medical devices.

[0105] Step (2): The computer device determines one or more risk diffusion probabilities corresponding to the second medical device based on the device association strength between the second medical device and the one or more third medical devices in the device association map.

[0106] The probability of one or more risk diffusions associated with the second medical device is the probability that the second medical device will diffuse risk to the one or more third medical devices. A stronger device association between the third medical device and the second medical device indicates a higher communication frequency, larger data exchange volume, and greater functional dependence between them, thus increasing the probability of risk diffusion to the third medical device. Conversely, a lower device association between the third medical device and the second medical device indicates a lower communication frequency, smaller data exchange volume, and lower functional dependence, thus decreasing the probability of risk diffusion to the third medical device.

[0107] By determining one or more risk diffusion probabilities corresponding to the second medical device, the impact and diffusion extent of the risk of the second medical device on the third medical device can be quantified, which is beneficial for subsequent overall risk assessment and improves the accuracy of determining safety protection plans.

[0108] In some implementations, the operation of the computer device determining one or more risk diffusion probabilities corresponding to the second medical device based on the device association strength between the second medical device and the one or more third medical devices in the device association map can be as follows: determining one or more risk diffusion probabilities corresponding to the second medical device based on the medical protection completeness corresponding to the second medical device, the correction coefficient corresponding to the diagnosis and treatment scenario indicated by the diagnosis and treatment scenario data of the second medical device, the risk propagation characteristic coefficient corresponding to the safety risk indicated by the risk detection information of the second medical device, and the device association strength between the second medical device and the one or more third medical devices in the device association map.

[0109] The medical protection completeness of a second medical device can quantify its security level. For example, if a PACS server enables image encryption and identity authentication, its medical protection completeness is 0.8.

[0110] For example, if the diagnosis and treatment scenario indicated by the diagnosis and treatment scenario data is an emergency or surgical scenario, the correction factor can be 1.2; if the diagnosis and treatment scenario indicated by the diagnosis and treatment scenario data is a routine scenario, the correction factor can be 1.0.

[0111] For example, if the security risk indicated by the risk detection information of the second medical device is a DICOM / HL7 protocol vulnerability, the risk propagation characteristic coefficient can be 0.9; if the security risk indicated by the risk detection information of the second medical device is a general hardware vulnerability, the risk propagation characteristic coefficient can be 0.3.

[0112] For example, based on the medical protection completeness, the correction coefficient, the risk propagation characteristic coefficient, and the equipment association strength between the one or more third medical devices, the probability of one or more risk diffusions corresponding to the second medical device can be determined by the following formula.

[0113]

[0114] in, Let i represent the risk diffusion probability, i be the second medical device, and j be the third medical device. For equipment correlation strength, This is the risk propagation characteristic coefficient. To ensure the completeness of medical protection, Correction coefficients for medical scenarios.

[0115] In some implementations, after the computer device determines one or more risk diffusion probabilities corresponding to the second medical device, it can mark the one or more risk diffusion probabilities in the image data link or diagnosis and treatment function link of the device association map to construct a visualized medical imaging device risk diffusion path model.

[0116] For example, high-risk transmission links can be marked in red, medium-risk transmission links in yellow, and low-risk transmission links in green, clearly identifying key protection nodes such as PACS servers and emergency diagnostic workstations, providing precise guidance for subsequent adjustments to protection strategies.

[0117] In this way, key protection nodes (such as PACS servers and emergency diagnostic workstations) in the device association map can be clearly identified, providing precise guidance for subsequent protection strategies. Furthermore, by quantifying and labeling the device association strength and risk diffusion probability, the diffusion risk of core nodes among multiple primary medical devices can be intuitively and accurately identified, solving the problem of missing risk diffusion identification that "single-point security ≠ overall security".

[0118] Step (3): The computer device determines the security protection scheme based on the diagnosis and treatment scenario data, the risk intensity value of each of the one or more second medical devices and the corresponding one or more risk diffusion probabilities.

[0119] Since the data from this diagnosis and treatment scenario can reflect the current diagnosis and treatment scenario, know the individual risk level of each of the one or more second medical devices, and know the probability of one or more risk diffusions corresponding to each second medical device in a collaborative scenario, a safety protection scheme that matches the current diagnosis and treatment scenario and meets the current risk level can be determined relatively accurately.

[0120] In some implementations, the computer device may determine the operation of the security protection scheme based on the diagnosis and treatment scenario data, the risk intensity value of each of the one or more second medical devices, and the corresponding one or more risk diffusion probabilities, including steps A to D.

[0121] Step A: The computer device determines the diffusion risk level based on the risk intensity value of each of the one or more second medical devices and the corresponding one or more risk diffusion probabilities.

[0122] The risk diffusion level is the sum of the risk diffusion rates of the one or more second medical devices. For example, the risk intensity value of each of the one or more second medical devices can be iterated over, multiplied by one or more risk diffusion probabilities corresponding to that second medical device, and finally all products are summed to obtain the risk diffusion level. For instance, if the risk intensity value of ultrasound device (i) is 8.0, and the associated devices are image storage server j1 and diagnostic workstation j2, with risk diffusion rates of 0.209 and 0.25 respectively, then the risk diffusion level is 8.0 × 0.209 + 8.0 × 0.25 = 4.172. For example, the range of values ​​for this risk diffusion level is... In real-world scenarios, the range of values ​​for this risk diffusion level can be... .

[0123] Step B: The computer device determines the target treatment scenario coefficient based on the treatment scenario data. The target treatment scenario coefficient is the coefficient corresponding to the highest priority target treatment scenario among the multiple treatment scenarios of the first medical devices.

[0124] For example, as shown in Table 3 below, if the diagnosis and treatment scenario data indicates that the diagnosis and treatment scenario is an emergency diagnosis and treatment scenario, the diagnosis and treatment scenario coefficient can be 1.0; if the diagnosis and treatment scenario data indicates that the diagnosis and treatment scenario is a routine diagnosis and treatment scenario, the diagnosis and treatment scenario coefficient can be 0.7; and if the diagnosis and treatment scenario data indicates that the diagnosis and treatment scenario is a device standby / maintenance scenario, the diagnosis and treatment scenario coefficient can be 0.3.

[0125] Table 3

[0126] Step C: The computer device determines the target risk score based on the target risk intensity value, the target treatment scenario coefficient, and the diffusion risk level. The target risk intensity value is the highest risk intensity value among the risk intensity values ​​of the one or more second medical devices.

[0127] The target risk score is a risk score obtained by assessing the overall security status in a multi-device collaborative scenario.

[0128] For example, the computer device can determine the target risk score using the following formula, based on the target risk intensity value, the target treatment scenario coefficient, and the diffusion risk level.

[0129]

[0130] in, Score the target risk. The target risk intensity value, To assess the level of risk of spread, Coefficient for the target diagnosis and treatment scenario. The weighting coefficients for the target risk score. The weighting coefficients for the level of diffusion risk. The weighting coefficients for the target diagnosis and treatment scenario coefficients. , , The sum of is 1. , , This can be preset. For example, it can be determined using the analytic hierarchy process (AHP). , , The value that can be taken. For example, It can take the value 0.4. It can take the value 0.4. It can take the value 0.2.

[0131] By combining the target risk intensity value, the target treatment scenario coefficient, and the level of diffusion risk, a target risk score representing the overall risk of multiple primary medical devices in the current treatment scenario can be determined. This score is directly linked to the core business of the treatment scenario, enabling an upgrade in perception from single-point risk to overall situation, and providing a quantitative basis for dynamic protection decisions.

[0132] For example, the target risk score has a situation level, a response priority, and corresponding response measures. For instance, as shown in Table 4 below, if the target risk score is greater than or equal to 8, the situation level is determined to be high-risk, the response priority is urgent, and the response measures can be to immediately suspend non-critical treatments, activate emergency protection, and block high-risk transmission paths; if the target risk score is greater than or equal to 6 and less than 8, the situation level is determined to be medium-high-risk, the response priority is high, and the response measures can be to prioritize the repair of high-risk equipment, strengthen monitoring of related equipment, and prevent risk spread; if the target risk score is greater than or equal to 4 and less than 6, the situation level is determined to be medium, the response priority is medium, and the response measures can be to arrange for risk repair during treatment breaks and routinely monitor the overall situation; if the target risk score is less than 4, the situation level is determined to be low-risk, the response priority is low, and the response measures can be to conduct regular inspections, no emergency response is required, and continuous tracking of risk changes is necessary.

[0133] Table 4

[0134] Step D: The computer device determines the security protection plan based on the target risk score and the target diagnosis and treatment scenario.

[0135] The target risk score reflects the overall safety status in a multi-device collaborative scenario, while the target treatment scenario reflects the urgency of the current treatment situation. Based on the target risk score and the target treatment scenario, a solution that can effectively ensure the safety of one or more primary medical devices can be determined while taking into account the current treatment scenario, thus balancing safety protection and treatment needs.

[0136] By leveraging the overall security situation assessment results (i.e., target risk score) and the priority of treatment scenarios, the strength and type of protection strategies can be adaptively determined. This follows the medical industry principle of "minimizing protection in emergency / surgical scenarios, standardizing protection in routine scenarios, and refining protection in high-risk scenarios," ensuring equipment safety while avoiding interference with core treatment processes such as image acquisition, transmission, and diagnosis. This approach not only addresses the issues of static protection strategies and insufficient treatment compatibility but also achieves a dynamic balance between security protection and clinical treatment.

[0137] Optionally, the computer device can determine the security protection scheme by matching the protection strategy based on the situation level of the target risk score and the target diagnosis and treatment scenario.

[0138] For example, the target risk score indicates a high-risk or medium-to-high-risk situation.

[0139] If the target treatment scenario is an emergency or surgical scenario, a security protection solution with an enhanced protection mode specifically for emergency situations can be adopted. This security protection solution may include blocking only high-risk diffusion links (without touching the emergency imaging data link), enabling DICOM protocol lightweight deep packet inspection (low latency), restricting communication between non-essential devices and emergency equipment, and pushing hot-patching vulnerability emergency repair solutions (without requiring device restart), without interrupting the image scanning or guidance process.

[0140] If the target medical scenario is a routine scenario, a security protection scheme with a standard enhanced protection mode can be adopted. This security protection scheme may include blocking all high-risk propagation links, enabling full-volume deep packet inspection, restricting communication between unnecessary devices, and pushing out complete vulnerability remediation solutions.

[0141] For example, the target risk score indicates a medium-level situation.

[0142] The security protection solution adopts a precise protection mode, which may include deploying protection rules only for non-core diagnosis and treatment links with high probability of spread, strengthening medical-grade identity authentication (such as multi-factor authentication) of key equipment such as PACS servers, and improving the encryption level of image data transmission, without affecting the continuity of any diagnosis and treatment process.

[0143] For example, the target risk score indicates a low-risk situation.

[0144] The security protection scheme adopts the conventional protection mode. This security protection scheme may include synchronously updating the medical imaging-specific threat and vulnerability signature database (such as adding DICOM protocol vulnerability signatures), continuously monitoring the equipment operation status and image data interaction behavior, and regularly conducting image data security inspections on the PACS server.

[0145] In some cases, after determining the situation level, the computer device can output a risk situation report. This report may include risk identification information for each of the multiple secondary medical devices, the risk propagation path, and the overall security situation. In this case, users can understand detailed information about the existing risks based on the risk situation report, which helps them make informed decisions.

[0146] In some implementations, after a security protection scheme is determined, the computer device can collect the device operation data of the first medical device in real time. If the device operation data (such as data transmission delay) exceeds the operation threshold, the security protection scheme can be adjusted until the first medical device returns to normal diagnostic and treatment operation.

[0147] Optionally, the computer device can update the protection strategy library in real time based on changes in the clinical diagnosis and treatment needs of medical institutions and new medical imaging threats, add new medical imaging-specific protection rules, and achieve continuous iterative optimization of protection strategies.

[0148] To facilitate understanding, the following will be combined with... Figure 3 The security protection methods provided in the embodiments of this application are illustrated by way of example.

[0149] See Figure 3 , Figure 3 This is a flowchart of a security protection method provided in an embodiment of this application. The process includes steps 301 to 310.

[0150] Step 301: The computer equipment collects equipment operation data, image communication data, and diagnosis and treatment scenario data from multiple primary medical devices.

[0151] For example, the device's operating data may include CPU, memory, fault codes, etc.

[0152] For example, the image communication data may include protocol type, data volume, connection status, etc.

[0153] For example, data related to medical scenarios may include the type of medical service and patient flow.

[0154] Step 302: The computer device extracts the device association features of the multiple first medical devices.

[0155] For example, the device-related features may include image data interaction links, diagnostic and treatment function-dependent links, and physical deployment-related links.

[0156] Step 303: The computer device calculates the correlation strength between the plurality of first medical devices.

[0157] Step 304: The computer device constructs a device association map based on the device association characteristics and the association strength between the multiple first medical devices.

[0158] For example, the strength of the association between devices can be labeled as strong / medium / weak in the device association map.

[0159] Step 305: The computer device inputs the risk identification information for each first medical device and identifies one or more.

[0160] For example, the risk identification information may include the risk type and risk intensity.

[0161] Step 306: The computer device calculates the risk diffusion probability based on the risk identification information of each first medical device.

[0162] Step 307: The computer device constructs a risk diffusion path model based on the diffusion rate of each second medical device and its corresponding third medical device.

[0163] For example, the risk of diffusion in the device association map can be labeled as high / medium / low diffusion risk.

[0164] Step 308: The computer device calculates the target risk score.

[0165] Step 309: The computer device determines the situation level based on the target risk score.

[0166] Step 300: The computer device determines a security protection plan based on the situation level of the target risk score and the diagnosis and treatment scenario data.

[0167] For example, the radiology department of a tertiary hospital is equipped with 2 emergency CT scanners, 1 intraoperative MRI machine, 5 conventional DR machines, 1 PACS image storage server, and 8 diagnostic workstations. A security protection system (also known as a medical Internet of Things collaborative system) is constructed, and the devices exchange image data through the DICOM protocol.

[0168] At 2:00 PM one day, the emergency room received a patient with cerebral hemorrhage who needed to undergo an emergency CT scan immediately (treatment scenario priority Sc=1.0). At this time, the system activated the safety protection process.

[0169] Complete implementation process: (1) Identify that the current scenario is an emergency CT diagnosis and treatment scenario (Sc=1.0), adjust the acquisition frequency to 1 second / time, and collect the equipment operation data, image communication data and diagnosis and treatment scenario data of the emergency CT machine once per second.

[0170] The equipment operation data of the emergency CT scanner includes CPU usage of 30% and normal loading of image scanning parameters.

[0171] The image communication data of this emergency CT scanner includes normal DICOM protocol interaction and an image data transmission rate of 100MB / s.

[0172] The diagnostic and treatment scenario data of this emergency CT scanner includes emergency cerebral hemorrhage CT, Sc=1.0, and scanning status.

[0173] (2) Based on the image data interaction links in the radiology medical imaging equipment association map, locate the core association links of the emergency CT machine and determine the association strength with the medical imaging equipment in the core association links.

[0174] The core connection chain of this emergency CT scanner is: Emergency CT Scanner > PACS Server > Emergency Diagnostic Workstation. The association strength R with the PACS Server and Emergency Diagnostic Workstation is... ij It is 0.95.

[0175] (3) The vulnerability detection module detected a DICOM protocol parsing vulnerability in the emergency CT machine, with a risk intensity Vi=9.0 (after adding the medical scenario impact coefficients). The probability P of the vulnerability spreading to the PACS server was calculated using the diffusion probability formula. ij =0.95×0.9×(1-0.8)×1.2=0.2052, the probability P of diffusion to the emergency diagnosis workstation is... ij =0.95×0.9×(1-0.7)×1.2=0.3078.

[0176] (4) Calculate the overall safety situation value S=0.4×9.0+0.4×(9.0×0.2052+9.0×0.3078)+0.2×1.0=3.6+0.4×4.617+0.2=5.6468, and determine it as a medium-risk situation (medium risk in emergency scenarios).

[0177] (5) Match safety protection plans according to the medium-risk situation and emergency scenarios.

[0178] For example, this security solution enables lightweight deep data packet detection (latency <50ms) for the DICOM protocol of the emergency CT scanner, adds temporary medical-grade identity authentication for the emergency diagnostic workstation, and strengthens end-to-end encryption of image data between the emergency CT scanner and the PACS server, ensuring that the CT scan process for patients with cerebral hemorrhage is not interrupted throughout the entire process.

[0179] (6) After adjusting the security protection plan, the equipment operation data of the emergency CT machine is collected. The image transmission delay of the emergency CT machine is 80ms (less than the 100ms threshold). The diagnosis and treatment process is continuous. Maintain this protection strategy and push vulnerability repair reminders to the equipment administrator. It is recommended to perform hot patch repair during the off-peak period of the emergency department.

[0180] In this embodiment, the computer device acquires multi-source data from multiple first medical devices, including device operation data, image communication data, and treatment scenario data. Then, based on the image communication data and the treatment scenario data, a device association map of the multiple first medical devices is constructed. Next, based on the device operation data, the risk intensity value of one or more second medical devices among the multiple first medical devices is determined. These second medical devices are considered first medical devices with security risks. Finally, a security protection scheme is determined based on the treatment scenario data, the device association map, and the risk intensity values ​​of the one or more second medical devices. Since the device association map constructed based on multi-source data can reflect the communication relationships, treatment function dependencies, and device hardware connection relationships among the multiple first medical devices in a multi-device collaborative scenario, the overall risk situation in the multi-device collaborative scenario can be determined based on the device association map and the risk intensity values ​​of the one or more second medical devices, after determining the risk intensity values ​​of these devices. Furthermore, by combining the treatment scenario data, the determined security protection scheme can not only ensure device protection security but also guarantee the normal operation of the devices. Thus, the security protection capability of medical devices can be improved.

[0181] Figure 4 This is a schematic diagram of a security protection device provided in an embodiment of this application. The device can be implemented as part or all of a computer device by software, hardware, or a combination of both, and this computer device can be as described below. Figure 5 The computer equipment shown. See also Figure 4 The device includes: an acquisition module 401, a construction module 402, a first determination module 403, and a second determination module 404.

[0182] The acquisition module 401 is used to acquire multi-source data from multiple first medical devices, including device operation data, image communication data, and diagnosis and treatment scenario data. Module 402 is used to construct a device association map of the multiple first medical devices based on the image communication data and the diagnosis and treatment scenario data; The first determining module 403 is used to determine the risk intensity value of one or more second medical devices among the plurality of first medical devices based on the device operation data, wherein the second medical device is a first medical device that has a safety risk; The second determining module 404 is used to determine a safety protection scheme based on the diagnosis and treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices.

[0183] Optionally, the building module 402 is used for: Based on the image communication data and the diagnosis and treatment scenario data, determine the image data interaction links, diagnosis and treatment function dependency links, and physical deployment association links among the multiple first medical devices; The strength of the device association between the multiple first medical devices is determined based on the image communication data and the diagnostic and treatment function dependency link. Based on the image data interaction link, the diagnostic function dependency link, the physical deployment association link, and the device association strength, a device association map is constructed.

[0184] Optionally, the building module 402 is used for: The frequency and amount of data interaction between the multiple first medical devices are determined based on the image communication data. The degree of dependence of diagnostic and therapeutic functions among the multiple first medical devices is determined based on the diagnostic and therapeutic function dependency link. The strength of the association between the device and the diagnostic and treatment functions is determined based on the frequency of data interaction, the amount of data interaction, and the degree of dependence on the diagnostic and treatment functions.

[0185] Optionally, the first determining module 403 is used for: For any one of the multiple first medical devices, risk detection is performed on the first medical device based on the device operation data to obtain the risk detection information of the first medical device. If the risk detection information of the first medical device indicates that the first medical device has a safety risk, the first medical device is identified as the second medical device, and the safety risk of the first medical device is assessed to obtain the risk intensity value of the first medical device.

[0186] Optionally, the second determining module 404 is used for: For any one of the one or more second medical devices, based on the device association map and the risk detection information of the second medical device, one or more third medical devices are determined from the multiple first medical devices. The third medical device is a first medical device that may be affected by the safety risks of the second medical device. Based on the device association strength between the second medical device and the one or more third medical devices in the device association map, determine one or more risk diffusion probabilities corresponding to the second medical device; Based on the data of the diagnosis and treatment scenario, the risk intensity value of each of the one or more second medical devices, and the corresponding one or more risk diffusion probabilities, the safety protection scheme is determined.

[0187] Optionally, the second determining module 404 is used for: Based on the medical protection completeness of the second medical device, the correction coefficient of the diagnosis and treatment scenario indicated by the diagnosis and treatment scenario data of the second medical device, the risk propagation characteristic coefficient of the safety risk indicated by the risk detection information of the second medical device, and the device association strength between the second medical device and the one or more third medical devices in the device association map, determine one or more risk diffusion probabilities corresponding to the second medical device.

[0188] Optionally, the second determining module 404 is used for: The diffusion risk level is determined based on the risk intensity value of each of the one or more second medical devices and the corresponding one or more risk diffusion probabilities; The target treatment scenario coefficient is determined based on the treatment scenario data. The target treatment scenario coefficient is the coefficient corresponding to the highest priority target treatment scenario among the multiple treatment scenarios of the first medical devices. The target risk score is determined based on the target risk intensity value, the target treatment scenario coefficient, and the level of diffusion risk. The target risk intensity value is the highest risk intensity value among the risk intensity values ​​of the one or more second medical devices. The safety protection plan is determined based on the target risk score and the target treatment scenario.

[0189] In this embodiment, multi-source data from multiple first medical devices is acquired, including device operation data, image communication data, and treatment scenario data. Then, a device association map of the multiple first medical devices is constructed based on the image communication data and the treatment scenario data. Next, the risk intensity value of one or more second medical devices among the multiple first medical devices is determined based on the device operation data. These second medical devices are considered first medical devices with potential safety risks. Finally, a security protection scheme is determined based on the treatment scenario data, the device association map, and the risk intensity values ​​of the one or more second medical devices. Since the device association map constructed based on multi-source data can reflect the communication relationships, treatment function dependencies, and device hardware connection relationships among the multiple first medical devices in a multi-device collaborative scenario, the overall risk situation in the multi-device collaborative scenario can be determined based on the device association map and the risk intensity values ​​of the one or more second medical devices, after determining the risk intensity values ​​of these devices. Furthermore, by combining the treatment scenario data, the determined security protection scheme can not only ensure device protection security but also guarantee the normal operation of the devices. Thus, the security protection capability of medical devices can be improved.

[0190] It should be noted that the safety protection device provided in the above embodiments is only illustrated by the division of the above functional modules when performing safety protection. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0191] The functional modules in the above embodiments can be integrated into one processing unit, or each functional module can exist as a separate physical processing unit, or two or more functional modules can be integrated into one processing unit. The processing unit can be implemented in hardware or software. Furthermore, the specific names of the functional modules are only for easy differentiation and are not intended to limit the scope of protection of the embodiments of this application.

[0192] The safety protection device and safety protection method embodiments provided in the above embodiments belong to the same concept. The specific working process and technical effects of the functional modules in the above embodiments can be found in the method embodiment section, and will not be repeated here.

[0193] Figure 5 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 5 As shown, the computer device 5 includes: a processor 50, a memory 51, and a computer program 52 stored in the memory 51 and executable on the processor 50. When the processor 50 executes the computer program 52, it implements the steps in the security protection method in the above embodiments.

[0194] Computer device 5 can be a general-purpose computer device or a special-purpose computer device. In specific implementations, computer device 5 can be a desktop computer, portable computer, network server, handheld computer, mobile phone, tablet computer, wireless terminal device, communication device, or embedded device. This application embodiment does not limit the type of computer device 5. Those skilled in the art will understand that... Figure 5 The computer device 5 is merely an example and does not constitute a limitation on the computer device 5. It may include more or fewer components than shown in the figure, or combine certain components, or different components, such as input / output devices, network access devices, etc.

[0195] Processor 50 can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0196] In some embodiments, memory 51 may be an internal storage unit of the computer device 5, such as a hard disk or RAM of the computer device 5. In other embodiments, memory 51 may be an external storage device of the computer device 5, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device 5. Furthermore, memory 51 may include both internal storage units and external storage devices of the computer device 5. Memory 51 is used to store the operating system, applications, boot loader, data, and other programs. Memory 51 may also be used to temporarily store data that has been output or will be output.

[0197] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0198] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0199] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the steps in the various method embodiments described above.

[0200] This application provides a computer program product that, when run on a computer, causes the computer to perform the steps described in the various method embodiments above.

[0201] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above method embodiments of this application can be implemented by a computer program. This computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate form. The computer-readable storage medium can include at least: any entity or device capable of carrying computer program code to a computer device, recording media, computer memory, read-only memory (ROM), random access memory (RAM), compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage devices. The computer-readable storage medium mentioned in this application can be a non-volatile storage medium; in other words, it can be a non-transient storage medium.

[0202] It should be understood that all or part of the steps of the above embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented in whole or in part as a computer program product. The computer program product includes one or more computer instructions. The computer instructions can be stored in the above-described computer-readable storage medium.

[0203] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0204] In the embodiments provided in this application, it should be understood that the disclosed apparatus / computer devices and methods can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms. Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, i.e., they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this application according to actual needs.

[0205] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0206] The embodiments described above are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A security protection method, characterized in that, The method includes: Acquire multi-source data from multiple primary medical devices, including device operation data, image communication data, and diagnosis and treatment scenario data; A device association map of the multiple first medical devices is constructed based on the image communication data and the diagnosis and treatment scenario data; Based on the equipment operation data, determine the risk intensity value of one or more second medical devices among the plurality of first medical devices, wherein the second medical device is a first medical device that poses a safety risk; A safety protection scheme is determined based on the diagnosis and treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices.

2. The method as described in claim 1, characterized in that, The step of constructing a device association map of the multiple first medical devices based on the image communication data and the diagnosis and treatment scenario data includes: Based on the image communication data and the diagnosis and treatment scenario data, determine the image data interaction links, diagnosis and treatment function dependency links, and physical deployment association links among the plurality of first medical devices; The device association strength among the plurality of first medical devices is determined based on the image communication data and the diagnostic and treatment function dependency link; Based on the image data interaction link, the diagnostic and treatment function dependency link, the physical deployment association link, and the device association strength, the device association map is constructed.

3. The method as described in claim 2, characterized in that, Determining the device association strength among the plurality of first medical devices based on the image communication data and the diagnostic and treatment function dependency link includes: The data interaction frequency and data interaction volume between the plurality of first medical devices are determined based on the image communication data. The degree of dependence of diagnostic and therapeutic functions among the plurality of first medical devices is determined based on the diagnostic and therapeutic function dependency link; The device association strength is determined based on the data interaction frequency, the data interaction volume, and the degree of dependence on the diagnostic and treatment functions.

4. The method as described in claim 1, characterized in that, The step of determining the risk intensity value of one or more second medical devices among the plurality of first medical devices based on the device operating data includes: For any one of the plurality of first medical devices, risk detection is performed on the first medical device based on the device operation data of the first medical device to obtain risk detection information of the first medical device; If the risk detection information of the first medical device indicates that the first medical device has a safety risk, the first medical device is identified as the second medical device, and the safety risk of the first medical device is assessed to obtain the risk intensity value of the first medical device.

5. The method according to any one of claims 1 to 4, characterized in that, The step of determining a safety protection scheme based on the diagnosis and treatment scenario data, the device association map, and the risk intensity value of the one or more second medical devices includes: For any one of the one or more second medical devices, based on the device association map and the risk detection information of the second medical device, one or more third medical devices are determined from the plurality of first medical devices, wherein the third medical device is a first medical device that may be affected by the safety risks present in the second medical device; Based on the device association strength between the second medical device and the one or more third medical devices in the device association map, determine one or more risk diffusion probabilities corresponding to the second medical device; The safety protection scheme is determined based on the diagnosis and treatment scenario data, the risk intensity value of each of the one or more second medical devices, and the corresponding one or more risk diffusion probabilities.

6. The method as described in claim 5, characterized in that, The step of determining one or more risk diffusion probabilities corresponding to the second medical device based on the device association strength between the second medical device and the one or more third medical devices in the device association map includes: Based on the medical protection completeness of the second medical device, the correction coefficient corresponding to the diagnosis and treatment scenario indicated by the diagnosis and treatment scenario data of the second medical device, the risk propagation characteristic coefficient corresponding to the safety risk indicated by the risk detection information of the second medical device, and the device association strength between the second medical device and the one or more third medical devices in the device association map, determine one or more risk diffusion probabilities corresponding to the second medical device.

7. The method as described in claim 5, characterized in that, The step of determining the safety protection scheme based on the diagnosis and treatment scenario data, the risk intensity value of each of the one or more second medical devices, and the corresponding one or more risk diffusion probabilities includes: The diffusion risk level is determined based on the risk intensity value of each of the one or more second medical devices and the corresponding one or more risk diffusion probabilities; The target treatment scenario coefficient is determined based on the treatment scenario data. The target treatment scenario coefficient is the coefficient corresponding to the highest priority target treatment scenario among the treatment scenarios of the plurality of first medical devices. The target risk score is determined based on the target risk intensity value, the target treatment scenario coefficient, and the diffusion risk level, wherein the target risk intensity value is the highest risk intensity value among the risk intensity values ​​of the one or more second medical devices; The safety protection scheme is determined based on the target risk score and the target diagnosis and treatment scenario.

8. A computer device, characterized in that, The computer device includes a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the computer program, when executed by the processor, implements the method as claimed in any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method as described in any one of claims 1 to 7.

10. A computer program product, characterized in that, When the computer program product is run on a computer device, it causes the computer device to perform the method as described in any one of claims 1 to 7.