A knowledge graph-based multi-source medical data security sharing method

CN122365569APending Publication Date: 2026-07-10YESU (SUZHOU) INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
YESU (SUZHOU) INTELLIGENT TECH CO LTD
Filing Date
2026-04-13
Publication Date
2026-07-10

Smart Images

  • Figure CN122365569A_ABST
    Figure CN122365569A_ABST
Patent Text Reader

Abstract

This invention discloses a method for secure sharing of multi-source medical data based on knowledge graphs, comprising the following steps: collecting multi-source medical data, sharing request data, and sharing execution behavior data; performing normalization processing on the multi-source medical data to generate a source partition medical knowledge graph; constructing a bridge box Query2Box model; generating source partition boxes and cross-mapping bridge boxes based on the source partition medical knowledge graph, and constructing a source partition box network; inputting the sharing request data into a query embedding unit to generate a sharing request query representation; inputting the sharing request query representation into a three-layer coupled box generation unit to construct a three-layer coupled box structure; generating a dynamic shared box based on the three-layer coupled box structure, cross-mapping bridge boxes, and sharing execution behavior data; performing post-execution shrinkage processing based on the dynamic shared box to generate a stable shared box, and outputting a secure sharing result. This invention achieves fine-grained control of sharing boundaries and dynamic risk constraints.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of medical informatics, and in particular to a method for secure sharing of multi-source medical data based on knowledge graphs. Background Technology

[0002] With the continuous advancement of healthcare informatization, medical records, laboratory data, imaging data, medication data, authorization records, ethical approval data, and shared log data are stored in different business systems, forming a multi-source medical data system characterized by dispersed sources, heterogeneous structures, and complex relationships. Existing medical data sharing technologies typically revolve around data aggregation, interface exchange, and access control, which can support basic data flow needs to a certain extent, but still have significant shortcomings in terms of refined sharing control under conditions of cross-system, cross-source, and multi-relationship scenarios.

[0003] In existing technologies, one type of approach focuses on organizing and managing medical entity relationships through knowledge graphs, which can improve the semantic association capabilities between multi-source data. However, it lacks sufficient constraint mapping between sharing requests and graph structures, making it difficult to stably characterize the shareable scope before sharing. Another type of approach focuses on pruning the sharing results based on authorization rules, approval status, and access policies. Although it can restrict the output of some unauthorized content, it lacks continuous constraint capabilities on cross-source association propagation, combined exposure risks, and dynamic risk changes during the sharing execution process. This can easily lead to problems such as static setting of sharing boundaries, delayed risk identification, and coarse-grained control.

[0004] Especially in multi-source medical data scenarios, there are patient associations, medical event associations, authorization associations, and time associations between different data sources. Multiple low-sensitivity data objects may still pose a risk of identity leakage after being combined across sources. Existing technologies generally lack technical means to integrate and couple the modeling of shared eligibility, visibility scope, and identity leakage risk, making it difficult to simultaneously consider sharing availability, boundary controllability, and risk mitigation. Therefore, new technical solutions are still needed to address this issue.

[0005] Therefore, how to provide a secure sharing method for multi-source medical data based on knowledge graphs is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0006] One objective of this invention is to propose a secure sharing method for multi-source medical data based on knowledge graphs. This invention constructs a source partitioned medical knowledge graph based on multi-source medical data, builds a Query2Box bridge box model, and utilizes a three-layer coupled box structure consisting of a source partition box, a cross-mapping bridge box, a shared request query representation, a shared qualification box, a data visibility box, and an identity leakage box. This structure performs pre-shared execution reasoning, in-shared execution reconstruction processing, and post-shared execution rollback processing, enabling the coordinated determination of the target shared data scope, target shared granularity, and target shared duration. This invention possesses advantages such as fine-grained shared boundary control, accurate identity leakage risk constraints, strong dynamic shared box adjustment capabilities, and stable secure sharing results.

[0007] A method for secure sharing of multi-source medical data based on knowledge graphs according to an embodiment of the present invention includes the following steps: Collect multi-source medical data, shared request data, and shared execution behavior data; perform standardized processing on the multi-source medical data; construct a multi-source medical knowledge graph; and generate source partition medical knowledge graphs according to the data source division. Construct the Query2Box bridge box model, including the source partition box construction unit, the cross-mapping bridge box construction unit, the query embedding unit, and the three-layer coupling box generation unit; Based on the source partition medical knowledge graph, the source partition box building unit and the cross-mapping bridge box building unit are called to perform partition box mapping processing, generate source partition boxes and cross-mapping bridge boxes, and construct the source partition box network. The shared request data is input into the query embedding unit to generate a shared request query representation, which is then associated with the source partition box network. Input the shared request query representation into the three-layer coupling box generation unit to construct a three-layer coupling box structure consisting of a shared qualification box, a data visibility box, and an identity disclosure box; Based on a three-layer coupled box structure, cross-mapping bridge box, and shared execution behavior data, perform pre-execution reasoning and in-execution reconstruction processing of shared execution to generate dynamic shared boxes; Based on the dynamic shared box, the sharing process is performed and then rolled back to generate a stable shared box, outputting a secure sharing result.

[0008] Optionally, the generation of the source partition medical knowledge graph includes: Collect multi-source medical data, sharing request data, and sharing execution behavior data. The multi-source medical data includes medical record data, test data, imaging data, medication data, authorization record data, ethical approval data, and shared log data. Perform standardization processing on multi-source medical data, including field unification, time alignment, relationship association, and source identification, to generate standardized multi-source medical data; Based on standardized multi-source medical data, patient relationships, medical event relationships, authorization relationships, time relationships, and data source relationships are extracted to construct a multi-source medical knowledge graph; Based on a multi-source medical knowledge graph, graph partitioning is performed. The graph is divided into partitions according to medical record data sources, test data sources, image data sources, medication data sources, authorization record data sources, ethics approval data sources, and shared log data sources. In each graph partition, the corresponding entity relationship distribution, time constraint distribution, authorization status distribution, entity type dispersion, relationship span, and source credibility fluctuation are retained to generate a source partition medical knowledge graph.

[0009] Optionally, the construction of the bridge box Query2Box model includes: Based on the original Query2Box model, the entity box initialization structure, relation projection structure, intersection aggregation structure, and box representation output structure are determined. Based on the entity box initialization structure and the source partition medical knowledge graph, a source partition box construction unit is constructed, and the graph partition input content is introduced into the entity box initialization structure. Based on the relational projection structure, source partition box building units, and source partition medical knowledge graph, a cross-mapping bridge box building unit is constructed, introducing cross-source related content and connection content between adjacent source partition boxes into the relational projection structure; Based on the box representation output structure and shared request data, a query embedding unit is constructed, and shared request data is introduced into the query input part of the box representation output structure. Based on the box representation output structure, intersection aggregation structure, query embedding unit, source partition box construction unit and cross mapping bridge box construction unit, a three-layer coupled box generation unit is constructed. In the box result generation part of the box representation output structure, shared request query representation, source partition box parameters and cross mapping bridge box parameters are introduced. The connection relationship is established based on the source partition box building unit, the cross mapping bridge box building unit, the query embedding unit, and the three-layer coupling box generation unit to generate the bridge box Query2Box model.

[0010] Optionally, constructing the source partition box network includes: Based on the source partition medical knowledge graph, the source partition box construction unit is called to write the entity relationship distribution, time constraint distribution and authorization status distribution corresponding to each graph partition into the box center parameters, and the entity type dispersion, relationship span and source credibility fluctuation into the box boundary parameters to generate the source partition box corresponding to each graph partition. Based on the source partition boxes corresponding to each map partition, perform partition box parameter mapping to generate a set of source partition boxes; Based on the source partition box set, cross-source association content between different source partition boxes is extracted, cross-search is performed, and cross-source association content that simultaneously satisfies the establishment of common patient association, common medical event association, authorization association and time overlap relationship is identified as bridging candidate content. Based on the bridging candidate content, in the cross-mapping bridge box construction unit, the frequency of cross-source association, temporal proximity, degree of authorization consistency and source credibility of the bridging candidate content are comprehensively judged to determine the bridging weight. Based on the connection correspondence between different source partition boxes corresponding to the bridging candidate content, the cross-mapping bridge box is constructed and the cross-mapping bridge box is generated. Network connection processing is performed based on source partition boxes and cross-mapping bridge boxes. Each source partition box is used as a partition node, and the cross-mapping bridge box is used as a cross-source connection edge to construct a source partition box network.

[0011] Optionally, generating a shared request query representation and associating it with the source partition box network includes: Based on the shared request data, the query embedding unit is invoked to perform agency permission encoding on the requesting agency information and generate agency permission encoding results; to perform purpose constraint encoding on the request purpose information and generate purpose constraint encoding results; to perform authorization validity encoding on the authorization status information and generate authorization validity encoding results; to perform ethics approval encoding on the ethics approval information and generate ethics approval encoding results; to perform time validity interval encoding on the time validity interval information and generate time validity interval encoding results; and to perform source consistency encoding on the source consistency information and generate source consistency encoding results. In the query embedding unit, a combined mapping is performed to map the institutional permission coding result, the purpose constraint coding result, the authorization validity coding result, the ethical approval coding result, the time validity interval coding result, and the source consistency coding result to the box space corresponding to the source partition box network, thereby generating a shared request query representation; The shared request query representation is associated with the source partition box network based on the shared request query representation and the source partition box network.

[0012] Optionally, the construction of the three-layer coupled box structure includes: Based on the shared request query representation and the source partition box network, the three-layer coupled box generation unit is called to write the corresponding constraints in the shared request query representation into the source partition box network, determine the shareable decision range corresponding to each source partition box, and generate a shared qualification box. Boundary propagation is performed along patient associations, medical event associations, authorization associations, time associations, and data source relationships in the source partition box network. Data objects that meet the sharing request data within the coverage of the shared qualification box are identified as shareable fact boundaries, and data visibility boxes are generated. Based on the attribute combinations corresponding to the data visible box, and the associated paths and cross-source bridging paths in the source partition box network corresponding to the data visible box, the content of the identity leakage risk boundary analysis corresponding to the data visible box is determined by performing combination pointing analysis on attribute combinations, path aggregation analysis on associated paths, and cross-partition connection analysis on cross-source bridging paths. Based on the content of the identity leakage risk boundary analysis, the risk boundary is determined by writing the field combination identifiability corresponding to the attribute combination, the path aggregation reverse inference degree corresponding to the associated path, and the cross-source bridging reconfigurability corresponding to the cross-source bridging path into the identity leakage risk boundary to generate the identity leakage box. Based on the shared qualification box, data visibility box, and identity leakage box, a hierarchical coupling construction is performed, with the shared qualification box as the outer constraint box, the data visibility box as the middle propagation box, and the identity leakage box as the inner risk box, thus constructing a three-layer coupled box structure.

[0013] Optionally, the generation of the dynamic shared box includes: Based on the three-layer coupled box structure and cross-mapping bridge box, shared pre-execution inference is performed, the shared qualification box is determined as the cross-source propagation starting point, the cross-mapping bridge box is determined as the cross-source propagation channel, the bridging propagation path is determined, and the cross-source propagation of the shared qualification box is performed. Boundary propagation is performed based on the bridging propagation path. The initial boundary of the data visibility box is determined according to the propagation range of the shared qualification box on the bridging propagation path. The risk boundary of the identity leakage box is updated according to the coverage range of the data visibility box in the source partition box. Based on the identity leakage box, reverse compression is performed on the data visibility box, and synchronous pruning is performed on the shared qualification box to generate a pre-shared box; Based on shared execution behavior data, the pre-shared box is reconstructed during shared execution, and access trajectory density, call path length, cumulative call frequency, field combination co-occurrence strength, and cross-modal query strength are extracted. Based on access trajectory density, call path length, cumulative call frequency, field combination co-occurrence strength, and cross-modal query strength, risk expansion calculation is performed on the identity leakage box in the pre-shared box, and the cross-mapping bridge box is updated. Based on the updated identity leakage box, the data visibility box in the pre-shared box is compressed again, and the shared qualification box is reconstructed synchronously. Based on the updated cross-mapping bridge box, the recompressed data visibility box, and the synchronously reconstructed shared eligibility box, closed-loop correction is performed to generate a dynamic shared box after the three-layer coupled box structure is jointly reconstructed.

[0014] Optionally, the generation of a stable sharing box and the output of secure sharing results include: Based on the dynamic shared box, the retraction judgment after the shared execution is performed. The risk boundary of the identity leakage box in the dynamic shared box is compared with the shareable fact boundary defined by the shared qualification box. The out-of-bounds area where the risk boundary of the identity leakage box exceeds the limit of the shared qualification box is determined, and the retraction judgment result is generated. Based on the retraction determination result, the newly added visible data boundary identification is performed to locate the newly added visible data boundary in the dynamic shared box due to boundary reconstruction, and the visible data boundary falling into the over-boundary area is identified as the retraction object. Based on the shrinking object, perform over-boundary risk positioning, overlap the data content corresponding to the shrinking object with the risk boundary of the identity leakage box, determine the range of data content that exceeds the shareable fact boundary limited by the shared qualification box, and generate shrinking data content; Based on the shrunken data content, shrunken processing is performed. Priority is given to the boundary rollback of the data content corresponding to the newly added data visibility boundary. The shrunken data content is removed from the data visibility box coverage area in the dynamic shared box, and the shareable fact boundary corresponding to the shared qualification box is updated synchronously to generate the shrunken three-layer coupled box structure. Based on the retracted three-layer coupling box structure, when the risk boundary of the identity leakage box still exceeds the shareable fact boundary defined by the shared qualification box, the sharing granularity rollback is performed in the order of field level, event level and partition level. Based on the shared qualification box, data visibility box, and identity leakage box after the shared granularity rollback, perform boundary convergence to generate a stable shared box; Based on a stable sharing box, the target shared data range, target sharing granularity, and target sharing duration are determined and output as secure sharing results.

[0015] The beneficial effects of this invention are: First, this invention constructs a source partitioned medical knowledge graph based on multi-source medical data, and further builds a bridge box Query2Box model. A source partition box network is constructed through source partition boxes and cross-mapping bridge boxes. Then, combined with a shared request query representation, shared qualification boxes, data visibility boxes, and identity leakage boxes are generated, forming a three-layer coupled box structure. Compared to the existing technology that separately processes knowledge graph organization, shared request judgment, and privacy control, this invention can complete shared qualification determination, visibility limitation, and identity leakage risk constraint within the same technical link, thereby improving the boundary representation capability and constraint consistency in the secure sharing process of multi-source medical data.

[0016] Secondly, in the pre-execution reasoning and in-execution reconstruction processes of shared execution, this invention uses the shared qualification box as the starting point for cross-source propagation and the cross-mapping bridge box as the cross-source propagation channel, and dynamically adjusts the data visibility box and identity leakage box in conjunction with shared execution behavior data. Based on this technical solution, it can continuously reflect the risk changes brought about by the receiver's access trajectory data, call path data, call frequency data, field combination data, and cross-modal query data during the shared execution process, avoiding the problems of fixed sharing boundaries and delayed risk response under static sharing control methods, thereby improving the adaptability of the dynamic sharing box to actual sharing behavior and the accuracy of risk control.

[0017] Furthermore, this invention performs post-share execution retraction processing based on the dynamic shared box. When the risk boundary corresponding to the identity leakage box exceeds the shareable fact boundary defined by the shared qualification box, retraction processing is performed on the data content corresponding to the newly added data visibility boundary due to boundary reconstruction, generating a stable shared box, and determining the target shared data range, target sharing granularity, and target sharing period accordingly. Through this technical solution, the risk of exceeding boundaries can be further compressed before the sharing result is output, improving the stability of secure sharing results, and balancing the availability of multi-source medical data sharing with the controllability of identity leakage risk. Attached Figure Description

[0018] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is an overall flowchart of a knowledge graph-based method for secure sharing of multi-source medical data proposed in this invention. Figure 2 This is a schematic diagram of the Query2Box bridge box model in this invention; Figure 3 This is a schematic diagram of the three-layer coupled box structure consisting of the shared qualification box, the data visibility box, and the identity leakage box in this invention, as well as the dynamic shared box reconstruction process. Detailed Implementation

[0019] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0020] refer to Figures 1-3 A method for secure sharing of multi-source medical data based on knowledge graphs includes the following steps: This process involves collecting multi-source medical data, shared request data, and shared execution behavior data. The multi-source medical data undergoes standardized processing, including field unification, time alignment, relationship association, and source identification. A multi-source medical knowledge graph is constructed based on patient relationships, medical event relationships, authorization relationships, time relationships, and data source relationships. It is further divided into source partition medical knowledge graphs according to medical record data sources, laboratory data sources, imaging data sources, medication data sources, authorization record data sources, ethical approval data sources, and shared log data sources. The multi-source medical data includes medical record data, laboratory data, imaging data, medication data, authorization record data, ethical approval data, and shared log data. Shared request data includes information on the requesting institution, request purpose, authorization status, ethical approval information, valid time interval, and source consistency. Shared execution behavior data includes recipient access trajectory data, call path data, call frequency data, field combination data, and cross-modal query data. Construct a bridge box Query2Box model, which includes a source partition box construction unit, a cross-mapping bridge box construction unit, a query embedding unit, and a three-layer coupling box generation unit; Based on the source partition medical knowledge graph, the source partition box building unit and the cross-mapping bridge box building unit in the bridge box Query2Box model are called to perform partition box mapping processing. The source partition medical knowledge graph is input into the source partition box building unit, and source partition boxes are generated based on the entity relationship distribution corresponding to each data source. The cross-source association content between different source partition boxes is input into the cross-mapping bridge box building unit to generate cross-mapping bridge boxes. The source partition box network is constructed based on the source partition boxes and cross-mapping bridge boxes. Based on the shared request data and the source partition box network, the query embedding unit in the bridge box Query2Box model is called. The shared request data is input into the query embedding unit, and a shared request query representation is generated based on the requesting organization information, request purpose information, authorization status information, ethical approval information, time validity interval information, and source consistency information. The shared request query representation is then associated with the source partition box network. Based on the shared request query representation and the source partition box network, the three-layer coupled box generation unit in the bridge box Query2Box model is called. The shared request query representation is input into the three-layer coupled box generation unit, and a shared qualification box is generated in the source partition box network. A data visibility box is generated based on the shared qualification box mapping the shareable fact boundary. An identity leakage box is generated based on the attribute combination corresponding to the data visibility box and the association path and cross-source bridging path in the source partition box network. A three-layer coupled box structure consisting of a shared qualification box, a data visibility box, and an identity leakage box is constructed. Based on a three-layer coupled box structure, cross-mapping bridge boxes, and shared execution behavior data, pre-execution inference and in-execution reconstruction processes are performed. The shared qualification box is used as the starting point for cross-source propagation, and the cross-mapping bridge box is used as the cross-source propagation channel. Bridging propagation is performed between source partition boxes based on the cross-mapping bridge box. During the bridging propagation process, the initial boundary of the data visible box is determined based on the shared qualification box, the risk boundary of the identity leakage box is updated based on the data visible box, and the data visible box is compressed in reverse and the shared qualification box is pruned synchronously based on the identity leakage box to generate a pre-shared box. During the shared execution process, the boundary of the data visible box in the pre-shared box is reconstructed based on the shared execution behavior data, the risk expansion calculation is performed on the identity leakage box in the pre-shared box, the cross-mapping bridge box is updated, and the data visible box is compressed again based on the updated identity leakage box and the shared qualification box is reconstructed synchronously to generate a dynamic shared box. Based on the dynamic shared box, the sharing execution is followed by a retraction process. When the risk boundary corresponding to the identity leakage box in the dynamic shared box exceeds the shareable fact boundary defined by the shared qualification box, the data content corresponding to the data visibility boundary newly added due to boundary reconstruction in the dynamic shared box is retracted to generate a stable shared box. Based on the stable shared box, the target shared data range, target shared granularity, and target shared duration are determined, and the secure sharing result is output.

[0021] In this embodiment, generating the source partition medical knowledge graph includes: Collect multi-source medical data, shared request data, and shared execution behavior data. Multi-source medical data includes medical record data, test data, imaging data, medication data, authorization record data, ethical approval data, and shared log data. Shared request data includes information on the requesting institution, the purpose of the request, authorization status, ethical approval information, valid time interval, and source consistency. Shared execution behavior data includes data on the recipient's access trajectory, call path, call frequency, field combination data, and cross-modal query data. Standardize the processing of multi-source medical data by unifying fields, aligning time, associating relationships, and identifying sources for medical records, laboratory data, imaging data, medication data, authorization records, ethical approval data, and shared log data to generate standardized multi-source medical data. Based on standardized multi-source medical data, patient relationships, medical event relationships, authorization relationships, time relationships, and data source relationships are extracted. Data objects in the standardized multi-source medical data are used as entity nodes, and patient relationships, medical event relationships, authorization relationships, time relationships, and data source relationships are used as relationship edges to construct a multi-source medical knowledge graph. Based on a multi-source medical knowledge graph, graph partitioning is performed. The graph is divided into partitions according to medical record data sources, test data sources, image data sources, medication data sources, authorization record data sources, ethics approval data sources, and shared log data sources. In each graph partition, the corresponding entity relationship distribution, time constraint distribution, authorization status distribution, entity type dispersion, relationship span, and source credibility fluctuation are retained to generate a source partition medical knowledge graph. Among them, the entity relationship distribution represents the corresponding distribution of entity nodes composed of data objects and their relationships with patients, medical events, authorization, time, and data sources within each graph partition; the time constraint distribution represents the distribution of time intervals, temporal sequences, and temporal overlaps corresponding to each data object within each graph partition; the authorization status distribution represents the distribution of authorization status information, ethical approval information, and valid time interval information corresponding to authorization record data and ethical approval data within each graph partition; the entity type dispersion represents the dispersion of entity node categories corresponding to different data objects within each graph partition; the relationship span represents the connection range of entity nodes connected by each relationship edge within each graph partition on the relationship link; and the source credibility fluctuation represents the change in the credibility of the data source relationships corresponding to medical record data sources, laboratory data sources, imaging data sources, medication data sources, authorization record data sources, ethical approval data sources, and shared log data sources within each graph partition.

[0022] In this embodiment, constructing the bridge box Query2Box model includes: Based on the original Query2Box model, the entity box initialization structure, relation projection structure, intersection aggregation structure, and box representation output structure are determined. The entity box initialization structure is used to represent entities as box representations, the relation projection structure is used to perform box representation updates along relation paths, the intersection aggregation structure is used to perform aggregation on multiple box representations, and the box representation output structure is used to output the query box representation. Based on the entity box initialization structure and the source partition medical knowledge graph, a source partition box construction unit is constructed. The graph partition input content is introduced into the entity box initialization structure, and the entity relationship distribution corresponding to the graph partition is written into the box center generation part and the box boundary generation part. Based on the relational projection structure, source partition box construction unit, and source partition medical knowledge graph, a cross-mapping bridge box construction unit is constructed. Cross-source related content and connection content between adjacent source partition boxes are introduced into the relational projection structure. Cross-source related content is written into the cross-source alignment part, the bridging weight calculation part, and the bridging condition filtering part. Based on the box representation output structure and shared request data, a query embedding unit is constructed. Shared request data is introduced into the query input part of the box representation output structure, and the requesting organization information, request purpose information, authorization status information, ethical approval information, time validity interval information and source consistency information are written into the request field encoding part, time constraint encoding part and authorization consistency fusion part. Based on the box representation output structure, intersection aggregation structure, query embedding unit, source partition box construction unit and cross mapping bridge box construction unit, a three-layer coupled box generation unit is constructed. In the box result generation part of the box representation output structure, the shared request query representation, source partition box parameters and cross mapping bridge box parameters are introduced. The intersection aggregation structure is written into the shared qualification box generation part, the data visibility box generation part and the identity leakage box generation part. Based on the source partition box building unit, cross-mapping bridge box building unit, query embedding unit, and three-layer coupled box generation unit, establish connection relationships, connect the source partition box building unit to the cross-mapping bridge box building unit and the three-layer coupled box generation unit, connect the cross-mapping bridge box building unit to the three-layer coupled box generation unit, and connect the query embedding unit to the three-layer coupled box generation unit to generate the bridge box Query2Box model.

[0023] In this embodiment, constructing the source partition box network includes: Based on the source partition medical knowledge graph, the source partition box building unit in the bridge box Query2Box model is called to extract the entity relationship distribution, time constraint distribution, authorization status distribution, entity type dispersion, relationship span, and source credibility fluctuation degree of the graph partitions corresponding to medical record data source, test data source, image data source, medication data source, authorization record data source, ethics approval data source, and shared log data source, respectively. The entity relationship distribution, time constraint distribution, and authorization status distribution corresponding to each graph partition are written into the box center parameter, and the entity type dispersion, relationship span, and source credibility fluctuation degree corresponding to each graph partition are written into the box boundary parameter to generate the source partition box corresponding to each graph partition. Based on the source partition boxes corresponding to each map partition, partition box parameter mapping is performed. The box center parameters are uniformly mapped in dimension, and the box boundary parameters are uniformly mapped in scale. The box center parameters after uniform dimension mapping and the box boundary parameters after uniform scale mapping are written into the corresponding source partition boxes to generate a set of source partition boxes that can be used for cross-source connections. Based on the source partition box set, cross-source association content between different source partition boxes is extracted. The patient association, medical event association, authorization association and time association between different source partition boxes are cross-searched. Cross-source association content that simultaneously satisfies the establishment of common patient association, common medical event association, authorization association and time overlap relationship is identified as bridging candidate content. Among them, cross-source association content refers to the cross-partition relationship connection content between the graph partitions corresponding to different source partition boxes, which is formed by the cross-partition relationship between data objects corresponding to the same patient, data objects corresponding to the same medical event, data objects corresponding to the same authorization scope and data objects corresponding to mutually overlapping time intervals. Based on bridging candidate content, in the cross-mapping bridge box construction unit of the Query2Box model, the cross-source association frequency, temporal proximity, authorization consistency, and source credibility of the bridging candidate content are comprehensively judged to determine the cross-source relationship strength, temporal consistency, and source consistency. The bridging weight is determined based on the cross-source relationship strength, temporal consistency, and source consistency. Cross-mapping bridge boxes are constructed based on the connection correspondence between different source partition boxes corresponding to the bridging candidate content. Here, the cross-source association frequency represents the number of times the bridging candidate content appears in different graph partitions; the temporal proximity represents the proximity between the time intervals corresponding to the bridging candidate content; the authorization consistency represents the consistency between the authorization status information and ethical approval information corresponding to the bridging candidate content; the source credibility represents the change in the credibility of the data source relationship corresponding to the bridging candidate content; and the connection correspondence between different source partition boxes represents the corresponding connection relationship formed between different source partition boxes of the bridging candidate content. Network connection processing is performed based on source partition boxes and cross-mapping bridge boxes. Each source partition box is treated as a partition node, and the cross-mapping bridge box is treated as a cross-source connection edge. Source partition boxes with cross-mapping bridge box connection relationships are connected to construct a source partition box network.

[0024] In this embodiment, generating a shared request query representation and associating it with the source partition box network includes: Based on the shared request data, the query embedding unit in the Query2Box model is invoked. The requesting organization information, request purpose information, authorization status information, ethical approval information, time validity interval information, and source consistency information are input into the query embedding unit. The requesting organization information is encoded with organization authority, generating an organization authority encoding result. The request purpose information is encoded with purpose constraint, generating a purpose constraint encoding result. The authorization status information is encoded with authorization validity, generating an authorization validity encoding result. The ethical approval information is encoded with ethical approval, generating an ethical approval encoding result. The time validity interval information is encoded with time validity interval, generating a time validity interval encoding result. The source consistency information is encoded with source consistency, generating a source consistency encoding result. Based on the coding results of institutional authority, usage constraint, authorization validity, ethical approval, time validity interval, and source consistency, a combined mapping is performed in the query embedding unit to map these results to the box space corresponding to the source partition box network, generating a shared request query representation. The shared request query representation includes a query center representation and a query boundary representation. The query center representation is used to characterize the query position corresponding to the shared request data, and the query boundary representation is used to characterize the query constraint range corresponding to the shared request data. Based on the shared request query representation and the source partition box network, the query center representation in the shared request query representation is mapped to the source partition box in the source partition box network, the query boundary representation in the shared request query representation is mapped to the boundary of the cross-mapping bridge box in the source partition box network, and the shared request query representation is associated with the source partition box network.

[0025] In this embodiment, constructing the three-layer coupled box structure includes: Based on the shared request query representation and the source partition box network, the three-layer coupled box generation unit in the bridge box Query2Box model is called. The shared request query representation is input into the three-layer coupled box generation unit. The constraints corresponding to the requesting organization information, request purpose information, authorization status information, ethical approval information, time validity interval information, and source consistency information in the shared request query representation are written into the authorization association relationship, time association relationship, and data source relationship in the source partition box network. The shareable judgment range corresponding to each source partition box is determined, and a shared qualification box is generated. Based on the shared qualification box, the shareable fact boundary is mapped. Boundary propagation is performed along patient association, medical event association, authorization association, time association, and data source relationship in the source partition box network. Data objects within the coverage of the shared qualification box that meet the requirements of requesting institution information, request purpose information, authorization status information, ethical approval information, time validity interval information, and source consistency information are identified as shareable fact boundaries. Data visibility boxes are generated based on the shareable fact boundaries. The boundary of the data visibility box is jointly defined by the data content range corresponding to the authorization range, the connection range corresponding to the medical event association, and the data source range corresponding to the source consistency information. Based on the attribute combinations corresponding to the data visible boxes, and the associated paths and cross-source bridging paths in the source partition box network corresponding to the data visible boxes, the content of the identity leakage risk boundary analysis corresponding to the data visible boxes is determined by performing combination pointing analysis on attribute combinations, path aggregation analysis on associated paths, and cross-partition connection analysis on cross-source bridging paths. Among them, attribute combinations represent the combined content of multiple data objects in the data visible box in terms of patient association, medical event association, authorization association, and time association. Associated paths represent the path connection content in the source partition box network formed by patient association, medical event association, authorization association, time association, and data source relationship, and falling within the coverage of the data visible boxes. Cross-source bridging paths represent the path connection content in the source partition box network that connects different source partition boxes through cross-mapping bridge boxes and falls within the coverage of the data visible boxes. Based on the analysis of identity leakage risk boundaries, risk boundaries are determined by writing the identifiability of field combinations corresponding to attribute combinations, the reverse inference of path aggregation corresponding to association paths, and the reconstructability of cross-source bridging paths into the identity leakage risk boundaries. An identity leakage box is generated based on the identity leakage risk boundaries. Among them, the identifiability of field combinations indicates the degree to which the combination of multiple data objects in the data visibility box forms an identification direction for the patient association relationship; the reverse inference of path aggregation indicates the degree to which the aggregation of association paths forms a reverse location for the patient association relationship, medical event association relationship, and authorization association relationship; and the reconstructability of cross-source bridging indicates the degree to which the cross-source bridging path reconstructs the same patient association relationship and the same medical event association relationship after connecting multiple source partition boxes. Based on the shared qualification box, data visibility box, and identity leakage box, a hierarchical coupling construction is performed. The shared qualification box is used as the outer constraint box, the data visibility box as the middle propagation box, and the identity leakage box as the inner risk box. According to the hierarchical dependency relationship that the shared qualification box limits the data visibility box, the data visibility box supports the identity leakage box, and the identity leakage box reflects the risk boundary of the data visibility box, a three-layer coupled box structure consisting of the shared qualification box, data visibility box, and identity leakage box is constructed.

[0026] In this embodiment, generating a dynamic shared box includes: Based on the three-layer coupled box structure and cross-mapping bridge box, shared pre-execution inference is performed. The shared qualification box is determined as the cross-source propagation starting point, and the cross-mapping bridge box is determined as the cross-source propagation channel. The bridging path connected by the cross-mapping bridge box is extracted between the source partition boxes. The propagation threshold is determined for the bridging path according to the bridging weight. The bridging path that simultaneously meets the authorization validity condition, time overlap condition, and source consistency condition is determined as the bridging propagation path. The cross-source propagation of the shared qualification box is performed on the bridging propagation path. Boundary propagation is performed based on the bridging propagation path. The initial boundary of the data visibility box is determined according to the propagation range of the shared qualification box on the bridging propagation path. The risk boundary of the identity leakage box is updated according to the coverage range of the data visibility box in the source partition box. The initial boundary of the data visibility box corresponds to the range of data objects that the shared qualification box can reach on the bridging propagation path, and the risk boundary of the identity leakage box corresponds to the range of identity leakage risk of each data object within the coverage range of the data visibility box. Based on the identity leakage box, reverse compression is performed on the data visible box, and synchronous pruning is performed on the shared qualification box. This includes overlapping the risk boundary of the identity leakage box with the initial boundary of the data visible box, shrinking the boundary of the data visible box in the overlapping area, and synchronously pruning the boundary of the shared qualification box corresponding to the shrunken data visible box to generate a pre-shared box. Based on shared execution behavior data, the pre-shared box is reconstructed during shared execution. Access trajectory density is extracted from receiver access trajectory data, call path length is extracted from call path data, cumulative call frequency value is extracted from call frequency data, field combination co-occurrence strength is extracted from field combination data, and cross-modal query strength is extracted from cross-modal query data. Among them, access trajectory density represents the degree of aggregation of access trajectories within the coverage of the pre-shared box, call path length represents the number of data objects crossed by the call path within the coverage of the pre-shared box, cumulative call frequency value represents the cumulative degree of call count within the coverage of the pre-shared box, field combination co-occurrence strength represents the degree of aggregation of multiple field combinations appearing simultaneously within the coverage of the pre-shared box, and cross-modal query strength represents the degree of association between joint retrieval of medical record data, test data, and image data within the coverage of the pre-shared box. Based on access trajectory density, call path length, cumulative call frequency, field combination co-occurrence strength, and cross-modal query strength, risk expansion calculation is performed on the identity leakage box in the pre-shared box. The incremental risks corresponding to access trajectory density, call path length, cumulative call frequency, field combination co-occurrence strength, and cross-modal query strength are written into the risk boundary of the identity leakage box, and the cross-mapping bridge box is updated. Updating the cross-mapping bridge box includes adjusting the bridging weight and bridging propagation path coverage of the cross-mapping bridge box according to the expanded identity leakage box risk boundary. Based on the updated identity leakage box, the data visible box in the pre-shared box is compressed again, and the shared qualification box is reconstructed synchronously. This includes re-overlapping the risk boundary of the updated identity leakage box with the boundary of the data visible box in the pre-shared box, re-shrinking the boundary of the data visible box in the re-overlapping area, and reconstructing the boundary of the shared qualification box corresponding to the re-shrinked data visible box. Based on the updated cross-mapping bridge box, the recompressed data visibility box, and the synchronously reconstructed shared qualification box, closed-loop correction is performed. The updated cross-mapping bridge box is fed back to the boundary correspondence between the shared qualification box and the data visibility box. The boundary consistency of the shared qualification box, the data visibility box, and the identity leakage box is corrected, and a dynamic shared box is generated after the three-layer coupled box structure is jointly reconstructed.

[0027] In this embodiment, generating a stable sharing box and outputting secure sharing results includes: Based on the dynamic shared box, the retraction judgment after the shared execution is performed. The risk boundary of the identity leakage box in the dynamic shared box is compared with the shareable fact boundary defined by the shared qualification box. The out-of-bounds area where the risk boundary of the identity leakage box exceeds the limit of the shared qualification box is determined, and the retraction judgment result is generated. Based on the retraction determination result, the newly added visible data boundary identification is performed. The newly added visible data boundary in the dynamic shared box due to boundary reconstruction is located. The visible data boundary falling into the over-boundary area is determined as the retraction object. The newly added visible data boundary represents the range of the visible data boundary increased by the dynamic shared box relative to the pre-shared box. Based on the shrinking object, perform over-boundary risk positioning, overlap the data content corresponding to the shrinking object with the risk boundary of the identity leakage box, determine the range of data content that exceeds the shareable fact boundary limited by the shared qualification box, and generate shrinking data content; Based on the shrunken data content, shrunken processing is performed. Priority is given to the boundary rollback of the data content corresponding to the newly added data visibility boundary. The shrunken data content is removed from the data visibility box coverage area in the dynamic shared box, and the shareable fact boundary corresponding to the shared qualification box is updated synchronously to generate the shrunken three-layer coupled box structure. Based on the shrunken three-layer coupling box structure, a shared granularity rollback is performed. When the risk boundary of the identity leakage box still exceeds the shareable fact boundary defined by the shared qualification box, a shared granularity rollback is performed in the order of field level, event level, and partition level. Field-level rollback means shrinking the field content in the data object, event-level rollback means shrinking the range of data objects corresponding to the medical event association, and partition-level rollback means shrinking the range of the graph partition corresponding to the source partition box. Based on the shared qualification box, data visibility box, and identity leakage box after the shared granularity rollback, perform boundary convergence until the risk boundary of the identity leakage box falls back to the shareable fact boundary defined by the shared qualification box, and generate a stable shared box. Based on a stable sharing box, the target shared data scope, target sharing granularity, and target sharing duration are determined. The target shared data scope is determined by the data content covered by the stable sharing box. The target sharing granularity is determined by the field-level, event-level, and partition-level shrinkage results corresponding to the stable sharing box. The target sharing duration is jointly determined by authorization status information, ethical approval information, time validity interval information, and risk changes during the sharing execution period. The target shared data scope, target sharing granularity, and target sharing duration are output as the secure sharing result.

[0028] Example 1: To verify the feasibility of this invention in practice, it was applied to a regional medical data collaborative sharing scenario involving medical records, laboratory data, imaging data, medication data, authorization records, ethical approval data, and shared log data. In this scenario, multiple business systems operate independently for extended periods, with differences in data sources, field structures, authorization status recording methods, and time recording methods between different systems. During joint medical research, cross-departmental consultations, follow-up visits, and quality control analysis, it is often necessary to retrieve multi-source medical data within a limited authorization scope. Existing processing methods mostly rely on fixed field anonymization, static permission table matching, and single-result pruning, which can complete some sharing tasks. However, once the sharing request involves cross-source related content, multiple low-sensitivity data objects may still expose patient identities after association. Furthermore, changes in the recipient's access trajectory, call path, and field combinations during the sharing process continuously alter the risk boundary, easily leading to problems such as an excessively large sharing scope, overly fine sharing granularity, and delayed subsequent rollback.

[0029] In this embodiment, multi-source medical data, shared request data, and shared execution behavior data are first collected. Medical record data, test data, imaging data, medication data, authorization record data, ethical approval data, and shared log data are then processed with field unification, time alignment, relationship association, and source identification to construct a multi-source medical knowledge graph. Source partitioned medical knowledge graphs are then generated according to data sources. Subsequently, a bridge box Query2Box model is constructed. Using source partitioned box construction units and cross-mapping bridge box construction units, entity relationship distributions within different data sources are mapped to source partitioned boxes, and cross-source related content is mapped to cross-mapping bridge boxes. A source partitioned box network is then formed based on the source partitioned boxes and cross-mapping bridge boxes. After a shared request enters the query embedding unit, the system converts the requesting organization information, request purpose information, authorization status information, ethical approval information, time validity interval information, and source consistency information into a shared request query representation and establishes a corresponding relationship with the source partitioned box network. Then, the shared request query representation is input into a three-layer coupling box generation unit, which sequentially constructs a shared qualification box, a data visibility box, and an identity disclosure box, forming a three-layer coupling box structure.

[0030] In the pre-shared execution phase, the shared eligibility box defines the boundaries of shareable facts, the data visibility box defines the currently visible data range, and the identity leakage box defines the boundary of identity leakage risks arising from attribute combinations, association paths, and cross-source bridging paths. The system uses the shared eligibility box as the starting point for cross-source propagation and the cross-mapping bridge box as the propagation channel, performing bridging propagation between source partition boxes to obtain the pre-shared box. After entering the shared execution phase, the system continuously receives receiver access trajectory data, call path data, call frequency data, field combination data, and cross-modal query data. If the receiver continuously makes frequent joint calls to the same patient association, the same medical event association, and data objects near the same time interval, the risk boundary of the identity leakage box will expand. If the risk boundary overlaps more significantly with the data visibility box, the system will further compress the data visibility box and simultaneously reconstruct the shared eligibility box to obtain the dynamic shared box. After the sharing is completed, the system continues to perform post-sharing shrinkage processing based on the dynamic sharing box. It shrinks the data content corresponding to the data visible boundary newly added due to boundary reconstruction, generates a stable sharing box, and determines the target shared data range, target sharing granularity and target sharing period accordingly, and outputs the secure sharing result.

[0031] This embodiment employs three methods for comparison. Method 1 is a traditional sharing method based on fixed de-identification rules and static permission matching; Method 2 is a conventional knowledge graph sharing method based on multi-source medical knowledge graphs and static authorization trimming; Method 3 is the method of this invention. The test task was set to 1200 sharing requests, covering four types of sharing tasks: cross-departmental consultation, joint research and analysis, follow-up visits, and quality control verification. The total number of data objects involved in sharing was 486,000, and the total number of cross-source related content was 94,000 sets. The comparison indicators include the successful completion rate of sharing tasks, the exposure rate of unauthorized data, the number of identity leakage risk events, the accuracy rate of sharing boundary contraction, the target sharing granularity matching rate, the average single sharing response time, and the boundary contraction ratio after dynamic adjustment triggering. The obtained data is shown in the table below.

[0032] Table 1 Comparison of Experiments on Secure Sharing of Multi-Source Medical Data

[0033] As shown in Table 1, the method of this invention outperforms the other two methods in terms of successful completion rate of shared tasks, effective completion rate of cross-source association tasks, accuracy of shared boundary retraction, target sharing granularity matching rate, and target sharing deadline matching rate. However, the response time is slightly increased, which is directly related to the introduction of dynamic shared box reconstruction and post-shared execution retraction processing in this invention. The traditional sharing method has the lowest average single-share response time of 412ms, but its unauthorized data exposure rate reaches 1.82%, and the number of identity leakage risk events is 37, indicating that static desensitization and fixed permission matching are difficult to continuously constrain risks in cross-source association scenarios. The conventional knowledge graph sharing method improves the successful completion rate of shared tasks through graph association, and the unauthorized data exposure rate decreases to 1.07%. However, due to the lack of progressive constraints between the shared qualification box, data visibility box, and identity leakage box, the risk boundary is still not updated sufficiently when facing changes in shared execution behavior, and the number of identity leakage risk events is still 24.

[0034] The average single-share response time of the method in this invention is 528ms, which is 116ms longer than traditional sharing methods and 65ms longer than conventional knowledge graph sharing methods. This overhead is within an acceptable range for medical data sharing systems. Correspondingly, the unauthorized data exposure rate decreased to 0.46%, and the number of identity leakage risk events decreased to 11. This indicates that the present invention does not rely on simply reducing the amount of shared data to achieve security. Instead, it defines the boundaries of shareable facts by the sharing qualification box, controls the visibility range by the data visibility box, and tracks and combines exposure risks by the identity leakage box, forming a more stable constraint link. The boundary contraction ratio after dynamic adjustment reaches 16.2%, which is higher than the 6.8% of traditional sharing methods and the 11.4% of conventional knowledge graph sharing methods. This indicates that the present invention can more timely identify the new risks brought about by the recipient's access trajectory, call path, field combination, and cross-modal query during the sharing execution process, and feed these risks back to the sharing boundary compression process.

[0035] From the results of manual review, the return rate for manual review after sharing using traditional sharing methods was 9.6%, while that of conventional knowledge graph sharing methods was 6.1%, and the method of this invention reduced it to 2.8%. This result indicates that the stable sharing box output by this invention can more accurately correspond to actual compliance requirements, reducing the need for manual supplementation and correction. The target sharing granularity matching rate reached 93.1%, and the target sharing period matching rate reached 94.2%, indicating that this invention can not only control whether to share, but also impose more granular constraints on the extent of sharing and the duration of sharing. The performance improvement of this invention is due to the fact that instead of handing all requests over to static rules for pruning, it combines the sharing request query representation with the source partition box network, and then continuously adjusts the shareable boundary through a three-layer coupled box structure and a dynamic sharing box reconstruction process. This results in a more balanced effect between sharing availability and controllable identity leakage risks in the secure sharing results.

[0036] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A method for secure sharing of multi-source medical data based on knowledge graphs, characterized in that, Includes the following steps: Collect multi-source medical data, shared request data, and shared execution behavior data; perform standardized processing on the multi-source medical data; construct a multi-source medical knowledge graph; and generate source partition medical knowledge graphs according to the data source division. Construct the Query2Box bridge box model, including the source partition box construction unit, the cross-mapping bridge box construction unit, the query embedding unit, and the three-layer coupling box generation unit; Based on the source partition medical knowledge graph, the source partition box building unit and the cross-mapping bridge box building unit are called to perform partition box mapping processing, generate source partition boxes and cross-mapping bridge boxes, and construct the source partition box network. The shared request data is input into the query embedding unit to generate a shared request query representation, which is then associated with the source partition box network. Input the shared request query representation into the three-layer coupling box generation unit to construct a three-layer coupling box structure consisting of a shared qualification box, a data visibility box, and an identity disclosure box; Based on a three-layer coupled box structure, cross-mapping bridge box, and shared execution behavior data, perform pre-execution reasoning and in-execution reconstruction processing of shared execution to generate dynamic shared boxes; Based on the dynamic shared box, the sharing process is performed and then rolled back to generate a stable shared box, outputting a secure sharing result.

2. The method for secure sharing of multi-source medical data based on knowledge graphs according to claim 1, characterized in that, The generated source partition medical knowledge graph includes: Collect multi-source medical data, sharing request data, and sharing execution behavior data. The multi-source medical data includes medical record data, test data, imaging data, medication data, authorization record data, ethical approval data, and shared log data. Perform standardization processing on multi-source medical data, including field unification, time alignment, relationship association, and source identification, to generate standardized multi-source medical data; Based on standardized multi-source medical data, patient relationships, medical event relationships, authorization relationships, time relationships, and data source relationships are extracted to construct a multi-source medical knowledge graph; Based on a multi-source medical knowledge graph, graph partitioning is performed. The graph is divided into partitions according to medical record data sources, test data sources, image data sources, medication data sources, authorization record data sources, ethics approval data sources, and shared log data sources. In each graph partition, the corresponding entity relationship distribution, time constraint distribution, authorization status distribution, entity type dispersion, relationship span, and source credibility fluctuation are retained to generate a source partition medical knowledge graph.

3. The method for secure sharing of multi-source medical data based on knowledge graphs according to claim 1, characterized in that, The construction of the bridge box Query2Box model includes: Based on the original Query2Box model, the entity box initialization structure, relation projection structure, intersection aggregation structure, and box representation output structure are determined. Based on the entity box initialization structure and the source partition medical knowledge graph, a source partition box construction unit is constructed, and the graph partition input content is introduced into the entity box initialization structure. Based on the relational projection structure, source partition box building units, and source partition medical knowledge graph, a cross-mapping bridge box building unit is constructed, introducing cross-source related content and connection content between adjacent source partition boxes into the relational projection structure; Based on the box representation output structure and shared request data, a query embedding unit is constructed, and shared request data is introduced into the query input part of the box representation output structure. Based on the box representation output structure, intersection aggregation structure, query embedding unit, source partition box construction unit and cross mapping bridge box construction unit, a three-layer coupled box generation unit is constructed. In the box result generation part of the box representation output structure, shared request query representation, source partition box parameters and cross mapping bridge box parameters are introduced. The connection relationship is established based on the source partition box building unit, the cross mapping bridge box building unit, the query embedding unit, and the three-layer coupling box generation unit to generate the bridge box Query2Box model.

4. The method for secure sharing of multi-source medical data based on knowledge graphs according to claim 1, characterized in that, The construction of the source partition box network includes: Based on the source partition medical knowledge graph, the source partition box construction unit is called to write the entity relationship distribution, time constraint distribution and authorization status distribution corresponding to each graph partition into the box center parameters, and the entity type dispersion, relationship span and source credibility fluctuation into the box boundary parameters to generate the source partition box corresponding to each graph partition. Based on the source partition boxes corresponding to each map partition, perform partition box parameter mapping to generate a set of source partition boxes; Based on the source partition box set, cross-source association content between different source partition boxes is extracted, cross-search is performed, and cross-source association content that simultaneously satisfies the establishment of common patient association, common medical event association, authorization association and time overlap relationship is identified as bridging candidate content. Based on the bridging candidate content, in the cross-mapping bridge box construction unit, the frequency of cross-source association, temporal proximity, degree of authorization consistency and source credibility of the bridging candidate content are comprehensively judged to determine the bridging weight. Based on the connection correspondence between different source partition boxes corresponding to the bridging candidate content, the cross-mapping bridge box is constructed and the cross-mapping bridge box is generated. Network connection processing is performed based on source partition boxes and cross-mapping bridge boxes. Each source partition box is used as a partition node, and the cross-mapping bridge box is used as a cross-source connection edge to construct a source partition box network.

5. A method for secure sharing of multi-source medical data based on knowledge graphs according to claim 1, characterized in that, The generation of the shared request query representation and its association with the source partition box network includes: Based on the shared request data, the query embedding unit is invoked to perform agency permission encoding on the requesting agency information and generate agency permission encoding results; to perform purpose constraint encoding on the request purpose information and generate purpose constraint encoding results; to perform authorization validity encoding on the authorization status information and generate authorization validity encoding results; to perform ethics approval encoding on the ethics approval information and generate ethics approval encoding results; to perform time validity interval encoding on the time validity interval information and generate time validity interval encoding results; and to perform source consistency encoding on the source consistency information and generate source consistency encoding results. In the query embedding unit, a combined mapping is performed to map the institutional permission coding result, the purpose constraint coding result, the authorization validity coding result, the ethical approval coding result, the time validity interval coding result, and the source consistency coding result to the box space corresponding to the source partition box network, thereby generating a shared request query representation; The shared request query representation is associated with the source partition box network based on the shared request query representation and the source partition box network.

6. The method for secure sharing of multi-source medical data based on knowledge graphs according to claim 1, characterized in that, The construction of the three-layer coupled box structure includes: Based on the shared request query representation and the source partition box network, the three-layer coupled box generation unit is called to write the corresponding constraints in the shared request query representation into the source partition box network, determine the shareable decision range corresponding to each source partition box, and generate a shared qualification box. Boundary propagation is performed along patient associations, medical event associations, authorization associations, time associations, and data source relationships in the source partition box network. Data objects that meet the sharing request data within the coverage of the shared qualification box are identified as shareable fact boundaries, and data visibility boxes are generated. Based on the attribute combinations corresponding to the data visible box, and the associated paths and cross-source bridging paths in the source partition box network corresponding to the data visible box, the content of the identity leakage risk boundary analysis corresponding to the data visible box is determined by performing combination pointing analysis on attribute combinations, path aggregation analysis on associated paths, and cross-partition connection analysis on cross-source bridging paths. Based on the content of the identity leakage risk boundary analysis, the risk boundary is determined by writing the field combination identifiability corresponding to the attribute combination, the path aggregation reverse inference degree corresponding to the associated path, and the cross-source bridging reconfigurability corresponding to the cross-source bridging path into the identity leakage risk boundary to generate the identity leakage box. Based on the shared qualification box, data visibility box, and identity leakage box, a hierarchical coupling construction is performed, with the shared qualification box as the outer constraint box, the data visibility box as the middle propagation box, and the identity leakage box as the inner risk box, thus constructing a three-layer coupled box structure.

7. A method for secure sharing of multi-source medical data based on knowledge graphs according to claim 1, characterized in that, The generation of the dynamic shared box includes: Based on the three-layer coupled box structure and cross-mapping bridge box, shared pre-execution inference is performed, the shared qualification box is determined as the cross-source propagation starting point, the cross-mapping bridge box is determined as the cross-source propagation channel, the bridging propagation path is determined, and the cross-source propagation of the shared qualification box is performed. Boundary propagation is performed based on the bridging propagation path. The initial boundary of the data visibility box is determined according to the propagation range of the shared qualification box on the bridging propagation path. The risk boundary of the identity leakage box is updated according to the coverage range of the data visibility box in the source partition box. Based on the identity leakage box, reverse compression is performed on the data visibility box, and synchronous pruning is performed on the shared qualification box to generate a pre-shared box; Based on shared execution behavior data, the pre-shared box is reconstructed during shared execution, and access trajectory density, call path length, cumulative call frequency, field combination co-occurrence strength, and cross-modal query strength are extracted. Based on access trajectory density, call path length, cumulative call frequency, field combination co-occurrence strength, and cross-modal query strength, risk expansion calculation is performed on the identity leakage box in the pre-shared box, and the cross-mapping bridge box is updated. Based on the updated identity leakage box, the data visibility box in the pre-shared box is compressed again, and the shared qualification box is reconstructed synchronously. Based on the updated cross-mapping bridge box, the recompressed data visibility box, and the synchronously reconstructed shared eligibility box, closed-loop correction is performed to generate a dynamic shared box after the three-layer coupled box structure is jointly reconstructed.

8. A method for secure sharing of multi-source medical data based on knowledge graphs according to claim 1, characterized in that, The generation of a stable sharing box, and the output of secure sharing results, include: Based on the dynamic shared box, the retraction judgment after the shared execution is performed. The risk boundary of the identity leakage box in the dynamic shared box is compared with the shareable fact boundary defined by the shared qualification box. The out-of-bounds area where the risk boundary of the identity leakage box exceeds the limit of the shared qualification box is determined, and the retraction judgment result is generated. Based on the retraction determination result, the newly added visible data boundary identification is performed to locate the newly added visible data boundary in the dynamic shared box due to boundary reconstruction, and the visible data boundary falling into the over-boundary area is identified as the retraction object. Based on the shrinking object, perform over-boundary risk positioning, overlap the data content corresponding to the shrinking object with the risk boundary of the identity leakage box, determine the range of data content that exceeds the shareable fact boundary limited by the shared qualification box, and generate shrinking data content; Based on the shrunken data content, shrunken processing is performed. Priority is given to the boundary rollback of the data content corresponding to the newly added data visibility boundary. The shrunken data content is removed from the data visibility box coverage area in the dynamic shared box, and the shareable fact boundary corresponding to the shared qualification box is updated synchronously to generate the shrunken three-layer coupled box structure. Based on the retracted three-layer coupling box structure, when the risk boundary of the identity leakage box still exceeds the shareable fact boundary defined by the shared qualification box, the sharing granularity rollback is performed in the order of field level, event level and partition level. Based on the shared qualification box, data visibility box, and identity leakage box after the shared granularity rollback, perform boundary convergence to generate a stable shared box; Based on a stable sharing box, the target shared data range, target sharing granularity, and target sharing duration are determined and output as the secure sharing result.