A blockchain verification-based traceable ethical review conference voting method and system
By using blockchain-based identity verification, recusal judgment, anonymous voting, and data encryption, the system resolves the contradictions between anonymity and traceability, irregular recusal procedures, and data tampering issues in ethics review meetings, thus achieving an efficient and secure voting process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA AEROSPACE SCI & IND GRP 731 HOSPITAL
- Filing Date
- 2026-04-29
- Publication Date
- 2026-07-24
AI Technical Summary
Existing voting methods for ethics review meetings suffer from a lack of balance between anonymity and traceability, low efficiency in identity verification and security risks, susceptibility to errors in the implementation of recusal mechanisms, and vulnerability to data tampering, resulting in low meeting efficiency.
The system collects biometric information through handheld terminal devices for identity verification and check-in, automatically obtains a list of items to be avoided and determines whether to avoid them, locks the voting function, adopts anonymous voting and encrypts the voting data, and finally archives the data to the blockchain network to form an immutable electronic archive.
This achieves a balance between the authenticity of the voting entities and the anonymity of the voting content, ensuring that the data is tamper-proof and traceable, thereby improving meeting efficiency and reducing compliance risks.
Smart Images

Figure CN122457321A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of blockchain technology, and in particular to a traceable ethical review meeting voting method and system based on blockchain verification. Background Technology
[0002] Currently, when holding research project review meetings, medical institution ethics review committees usually use paper voting, show of hands voting, or ordinary electronic voting devices to vote on projects. Committee members sign in mainly by manually checking the list or using ordinary sign-in books. Some hospitals have begun to try using general-purpose devices such as tablet computers for electronic voting, but they lack professional functional design for ethics review scenarios, especially in terms of voting process traceability and data security archiving, which are obviously shortcomings and cannot meet the rigid requirements of ethics review for full traceability and immutability. The existing technology has the following main problems: (1) The anonymity and traceability of voting cannot be balanced: show of hands voting is completely public, paper voting has the risk of leakage during transmission and counting, and ordinary electronic voting devices are difficult to achieve effective separation of identity information and voting content, affecting the objectivity of committee members' independent judgment, and at the same time, they cannot balance anonymity and traceability. (2) Low efficiency and security risks in identity verification: Manual sign-in is difficult to accurately verify the identity of committee members, which poses a risk of impersonation and failure to keep track of the attendance of committee members in real time. The identity verification record cannot be effectively linked to the subsequent voting behavior, and the authenticity of the voter's identity cannot be confirmed when tracing back. (3) The "recusal" mechanism is prone to errors: When a committee member has a conflict of interest with the review project and needs to abstain from voting, the traditional method relies on the committee member's self-awareness or the moderator's reminder. This can easily lead to the committee member who should abstain voting incorrectly or the omission of abstention votes during the statistics. Moreover, the relevant abstention records cannot be retained, and it is difficult to verify the compliance of the abstention execution when tracing back. (4) Poor process traceability and easy data tampering: Paper ballots are not easy to preserve for a long time. If electronic voting records are not effectively encrypted and archived, it is difficult to meet the requirements of ethical review file management for process traceability and immutability. (5) Low meeting efficiency: Traditional paper ballots require manual distribution, collection and counting, which is time-consuming and laborious, and is prone to counting errors. Therefore, there is an urgent need for a voting method that can balance anonymous voting with full traceability, automated execution of avoidance mechanisms, ensure data immutability, and meet ethical review and compliance requirements. Summary of the Invention
[0003] To address the aforementioned problems, this invention provides a traceable ethics review meeting voting method and system based on blockchain verification to solve the core technical problems mentioned in the background art, such as the contradiction between anonymity and traceability, irregular implementation of avoidance, easy data tampering, and low efficiency in existing ethics review meeting voting.
[0004] A blockchain-based, traceable ethics review meeting voting method includes the following steps: The biometric information of the target participants is collected by handheld terminal devices, and the biometric information is compared with the identity information of the participants pre-stored in the hospital ethics review management system server to complete identity verification and check-in. After identity verification is passed, the system automatically obtains the list of items to be recused for the target member and automatically determines whether the target member needs to recuse themselves based on the list of items to be recused when entering the current voting item. If recusal is required, the voting function will be locked, the target committee member will be prohibited from entering the voting interface, and a record of the recusal behavior will be automatically generated and uploaded to the hospital ethics review and management system server. For other participating committee members who do not need to recuse themselves, the details of the current voting item and voting options are displayed through a display component. After other participating committee members select and confirm their voting options, the voting data is encrypted, and the encrypted anonymous committee member identifier and voting options are uploaded to the hospital ethics review management system server. The system automatically counts votes and generates voting results based on the voting data, pushes the results to various handheld terminal devices, and centrally encrypts and archives all identity verification records, avoidance behavior records, voting data, and operation logs. The root hash value of the archived data is then written into the blockchain network to form an immutable and traceable electronic archive.
[0005] Preferably, the step of collecting the biometric information of the target participating committee members through a handheld terminal device, comparing the biometric information with the committee member identity information pre-stored in the hospital ethics review management system server, and completing identity verification and check-in includes: In response to the check-in command initiated by the target participating committee members on their handheld terminal devices, the facial recognition camera and fingerprint reader are activated simultaneously. The system continuously collects multi-angle facial image sequences of the target participants using a facial recognition camera and collects fingerprint images of the target participants using a fingerprint scanner. The multi-angle facial image sequences and fingerprint images are then bound together with timestamps to generate a multimodal biometric data package. Liveness detection is performed on multi-angle face image sequences in multimodal biometric data packages. After the detection is successful, face feature vectors are extracted. Fingerprint minutiae features are extracted from fingerprint images. The face feature vectors and fingerprint minutiae features are fused to generate a fused feature code. The fusion feature code is uploaded to the hospital ethics review management system server and compared with the fusion feature templates of all pre-stored committee members at a 1:N ratio to calculate the similarity score. If a target fusion feature template has a similarity score that exceeds the preset score threshold, the identity verification is deemed successful, and the committee member's identity information corresponding to the target fusion feature template is retrieved. The system matches the member's identity information with the list of members who should attend the meeting. If the target member is on the list, a "successful check-in record" containing the member's identity identifier, verification time, and verification method is generated, and a successful check-in instruction is sent to the handheld terminal device.
[0006] Preferably, after identity verification is passed, the step of automatically obtaining the list of items to be recused corresponding to the target participating committee member, and automatically determining whether the target participating committee member needs to recuse themselves based on the list of items to be recused when entering the current voting item, includes: Identify the unique identifier of the target participating committee member, and retrieve and extract the list of projects to be avoided corresponding to the target participating committee member from the pre-stored committee member-project stake database based on the unique identifier; Obtain the current voting item identifier for the current voting item, and determine the voting authority level of the target participating committee member for the current voting item based on the current voting item identifier; Based on the voting authority level, a suitable set of reference item identifiers is selected from the list of items to be avoided, and the current voting item identifier is compared with the set of reference item identifiers one by one. If a match is found in the comparison results, it is determined that the target member should recuse themselves from voting on the current item; otherwise, it is determined that they do not need to recuse themselves.
[0007] Preferably, if recusal is required, the voting function is locked, preventing the target committee member from accessing the voting interface, and a recusal behavior record is automatically generated and uploaded to the hospital's ethics review management system server, including: Detect whether the handheld terminal device has switched to the voting option area interface. If so, cut off the touch signal input of the voting option area interface or cover the voting option area interface to a grayed-out unselectable state. If not, intercept the jump command in the voting options area interface, so that the target participating committee member cannot switch from the meeting agenda interface to the voting options area interface and display the forced avoidance prompt interface; Detect and record the avoidance decision time parameters, lock operation type, handheld terminal device number, and session identifier of this voting meeting; Based on the unique identifier of the target participating committee member, the current voting item identifier, the avoidance judgment time parameter, the lock operation type, the handheld terminal device number, and the session identifier of this voting meeting, an avoidance behavior record is generated and uploaded to the hospital ethics review management system server.
[0008] Preferably, for other participating committee members who do not need to recuse themselves, the details and voting options of the current voting item are displayed through a display component. After other participating committee members select and confirm their voting options, the voting data is encrypted, and the encrypted anonymous committee member identifier and voting options are uploaded to the hospital ethics review management system server, including: In response to the meeting host's command to start the current voting item via the hospital ethics review management system server, the voting interaction interface of the handheld terminal devices of other participating committee members is activated; The display component receives and highlights the currently selected voting option in real time by other participating committee members through touch. After other committee members click the confirmation button, record the final voting options of each other participating committee member and generate the raw voting data; The temporary identity identifier of the committee members in the original voting data is replaced with a one-time anonymous voting token. An asymmetric encryption algorithm is used to encrypt the data packet containing the anonymous voting token, the current voting item identifier, the final voting option and the timestamp, to generate an encrypted voting data packet. The encrypted voting data packets are uploaded in real time to the hospital's ethics review and management system server via the encrypted communication module of the handheld terminal device.
[0009] Preferably, the step of automatically counting votes and generating voting results based on voting data, pushing the voting results to each handheld terminal device, and simultaneously centrally encrypting and archiving all identity verification records, avoidance behavior records, voting data, and operation logs, and writing the root hash value of the archived data into an immutable and traceable electronic archive into the blockchain network includes: Decrypt all voting data to extract the number of votes for each voting option, calculate the total number of valid votes for each voting option based on the number of votes for each voting option, and generate the voting result for the current voting item based on the total number of valid votes; The voting results are structured and packaged, and then pushed to each handheld terminal device using an encrypted transmission protocol for result confirmation and vote approval. After the judgment is passed, the full data archiving process is triggered to collect multiple types of record data, and the record data of each type is structured and organized to generate an archive data package; The archived data packets are encrypted using international standard encryption algorithms to generate encrypted archive files. These encrypted archive files are then stored in a dedicated encrypted storage area on the hospital ethics review and management system server, and a hash value is calculated to generate a root hash value. The root hash value is written into the blockchain network, and a distributed consensus mechanism is used to ensure that the hash value cannot be tampered with, so as to form an immutable and traceable electronic record.
[0010] Preferably, the step of obtaining the current voting item identifier and determining the voting authority level of the target participating committee member for the current voting item based on the current voting item identifier includes: In response to the meeting host's instruction to start the current voting item, the current unique item identifier of the current voting item is parsed and extracted from the instruction. Read the permission configuration file of the target participant pre-stored in the local encrypted storage module, and obtain the project-specific permission exception list of the target participant based on the permission configuration file; The voting authority level of the target participating committee member for the current voting item is determined by comparing the current unique item identifier with the list of item-specific permission exceptions, according to the following priority order: First priority: If the project-specific permission exception list clearly states that the target participating committee member has "prohibited voting" or "observer" permissions for the current voting item, then the final permission level is determined to be "no voting rights"; Second priority: If the project-specific permission exception list clearly states that the target participating committee member has "full voting rights" for the current voting item without any restrictions, then the final permission level is determined to be "full voting rights"; Third priority: If the current voting item is not recorded in the project-specific permission exception list, the final permission level is determined according to the global permission level of the target participating committee member. The global permission level includes "full voting rights", "restricted voting rights" and "observer rights". Fourth priority: If the target member's global permission level is "restricted voting rights", further check whether the current voting item belongs to the type of item authorized for voting by the target member. If it does, grant "full voting rights"; otherwise, grant "observer rights".
[0011] Preferably, during the process of other participating committee members voting via handheld terminal devices, the following is also included: Collect multi-dimensional behavioral characteristic data of each other participating committee member during the voting process; Based on multidimensional operational behavior characteristic data, the tactile modality, motor modality, biological modality, and environmental modality of each other participating committee member during the voting process were determined; Tactile modal features, motion modal features, biological modal features, and environmental modal features are spatiotemporally aligned according to a unified timestamp benchmark to generate a multimodal original high-dimensional behavioral feature tensor containing multi-channel time-series data; The original high-dimensional behavioral feature tensor of multimodal behavior is encoded by a pre-trained autoencoder neural network to generate a low-dimensional behavioral feature latent vector. The low-dimensional behavioral feature latent vector is input into the preset integrated anomaly voting detection engine, and the individual anomaly confidence score of each other participating committee member is output through the engine's preset individual spatiotemporal pattern detection function. Retrieve historical normal voting behavior feature data for each other participating committee member, extract the normal voting behavior feature latent vector from the historical normal voting behavior feature data, and determine the individual behavior baseline distribution of each other participating committee member based on the normal voting behavior feature latent vector; The individual behavioral baseline distribution is input into the preset integrated abnormal voting detection engine. The engine’s preset individual historical baseline deviation detection function outputs the deviation of each other’s current operational behavior characteristics from the individual baseline. A comprehensive anomaly score is determined based on the individual anomaly confidence level of each other participating committee member and the deviation of that participating committee member's current operational behavior characteristics from their personal baseline. Determine the review type, risk level, and voting data quality requirements for the current voting project, and determine the basic anomaly scoring threshold based on the review type, risk level, and voting data quality requirements; A personalized correction coefficient is generated based on the historical credit score of each other participating committee member, and a dynamic intervention score threshold is determined for each other participating committee member based on the personalized correction coefficient and the basic abnormal score threshold. The comprehensive abnormality score is compared with the dynamic intervention score threshold, and a multi-level intervention strategy is implemented to intervene in the voting results based on the comparison results.
[0012] Preferably, after decrypting all voting data to extract the number of votes for each voting option, calculating the total number of valid votes for each voting option based on the number of votes for each voting option, and generating the voting result for the current voting item based on the total number of valid votes, the method further includes: The initial approval rate for each voting option in the current voting project is determined based on the voting results; Obtain the job identifier of each other participating committee member, and determine the voting weighting weight of each other participating committee member based on the job identifier; The effective weighted votes for each voting option are calculated based on the weighted average of the votes cast by each of the other participating committee members: ; in, Let represent the valid weighted votes for the i-th voting option, N represent the total number of other participating committee members who voted, and j represent the j-th other participating committee member. Let represent the weighted vote of the j-th participating committee member, and e represent the natural constant with a value of 2.72. This represents the preset attenuation constant, which defaults to 0.01. This represents the time difference between the submission time of the vote of the j-th other participating committee member for the i-th voting option and the voting deadline. This indicates the valid voting time; The weighted number of votes for each voting option is determined based on the valid weighted number of votes for each voting option, as well as the basic and minimum approval percentages for the current voting item. Determine whether the number of valid weighted votes for each voting option is greater than or equal to the number of weighted votes in favor. If so, the vote is passed; otherwise, the weighted approval rate is determined based on the number of valid weighted votes. The weighted approval rate and the original approval rate for each voting item will be uploaded to the meeting initiator for reference and decision-making.
[0013] A traceable ethics review meeting voting system based on blockchain verification, the system comprising: The comparison module is used to collect the biometric information of the target participating committee members through a handheld terminal device, and compare the biometric information with the committee member identity information pre-stored in the hospital ethics review management system server to complete identity verification and check-in. The judgment module is used to automatically obtain the list of items to be recused for the target participating committee member after the identity verification is passed, and automatically determine whether the target participating committee member needs to recuse himself / herself based on the list of items to be recused when entering the current voting item. The locking module is used to lock the voting function if recusal is required, preventing the target member from entering the voting interface, and automatically generating a record of recusal behavior and uploading it to the hospital ethics review and management system server. The upload module is used to display the details and voting options of the current voting item to other participating committee members who do not need to recuse themselves. After other participating committee members select and confirm their voting options, the voting data is encrypted, and the encrypted anonymous committee member identifier and voting options are uploaded to the hospital ethics review management system server. The push module is used to automatically count votes and generate voting results based on voting data, and push the voting results to various handheld terminal devices. At the same time, it centrally encrypts and archives all identity verification records, avoidance behavior records, voting data and operation logs, and writes the root hash value of the archived data into the blockchain network to form an immutable and traceable electronic archive.
[0014] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.
[0015] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0016] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof.
[0017] Figure 1A flowchart illustrating the workflow of a traceable ethics review meeting voting method based on blockchain verification provided by this invention; Figure 2 Another flowchart of a traceable ethics review meeting voting method based on blockchain verification provided by the present invention; Figure 3 This is another flowchart illustrating a traceable ethics review meeting voting method based on blockchain verification provided by the present invention. Figure 4 This is a schematic diagram of the structure of a traceable ethics review meeting voting system based on blockchain verification provided by the present invention. Detailed Implementation
[0018] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0019] A traceable ethics review meeting voting method based on blockchain verification, such as... Figure 1 As shown, it includes the following steps: Step S101: Collect the biometric information of the target participating committee members through a handheld terminal device, compare the biometric information with the committee member identity information pre-stored in the hospital ethics review management system server, and complete the identity verification and check-in. Step S102: After identity verification is passed, the list of items to be recused corresponding to the target participating committee member is automatically obtained, and when entering the current voting item, it is automatically determined whether the target participating committee member needs to recuse himself / herself based on the list of items to be recused. Step S103: If recusal is required, lock the voting function, prevent the target member from entering the voting interface, and automatically generate a recusal behavior record and upload it to the hospital ethics review management system server. Step S104: For other participating committee members who do not need to recuse themselves, display the details and voting options of the current voting item through the display component. After other participating committee members select and confirm the voting options, encrypt the voting data and upload the encrypted anonymous committee member identifier and voting options to the hospital ethics review management system server. Step S105: Automatically complete the vote count and generate voting results based on the voting data, push the voting results to each handheld terminal device, and at the same time centrally encrypt and archive all identity verification records, avoidance behavior records, voting data and operation logs, and write the root hash value of the archived data into an immutable and traceable electronic file into the blockchain network.
[0020] In this embodiment, the anonymous committee member identifier refers to a temporary identifier issued by the hospital ethics review and management system server that is not directly related to the committee member's real identity, preferably a one-time anonymous voting token.
[0021] In this embodiment, the list of items to be recused refers to the list of items that need to be recused from voting if there is a conflict of interest with the target committee member, which is pre-stored in the hospital ethics review management system server; this list is pre-entered by the ethics committee office based on the information submitted by the committee members.
[0022] The working principle of the above technical solution is as follows: the biometric features of the participating committee members are collected by a handheld terminal and compared with the information pre-stored on the server to complete identity verification and check-in. After the verification is passed, the list of items that the committee member should avoid is automatically obtained, and when entering each voting item, it is automatically determined whether the member should avoid the voting. If the member should avoid the voting, the voting function is immediately locked and an avoidance record is generated and uploaded to the server. If the member should not avoid the voting, the project details and voting options are displayed to the committee member. After the member confirms the voting, the voting data is uploaded after being replaced with an anonymous token and asymmetric encryption. The server automatically counts the votes, pushes the results, and centrally encrypts and archives all data such as identity verification, avoidance, voting, and operation logs. At the same time, blockchain technology is used to solidify the hash value, thereby forming an immutable and fully traceable electronic archive.
[0023] The beneficial effects of the above technical solution are as follows: Through a five-step closed-loop process of "identity verification → recusal judgment → vote locking → anonymous voting → encrypted archiving," it comprehensively solves the core technical problems in existing ethics review meeting voting, such as the contradiction between anonymity and traceability, irregular recusal execution, easy data tampering, and low efficiency. Its effects are reflected in: achieving a balance between the authenticity of the voting subject and the anonymity of the voting content; mandatory automated recusal blocking; encrypted transmission and blockchain solidification of voting data, ensuring the entire process is tamper-proof and traceable; and significantly improving meeting efficiency.
[0024] In one embodiment, the step of collecting the biometric information of the target participating committee members through a handheld terminal device, comparing the biometric information with the committee member identity information pre-stored in the hospital ethics review management system server, and completing identity verification and check-in includes: In response to the check-in command initiated by the target participating committee members on their handheld terminal devices, the facial recognition camera and fingerprint reader are activated simultaneously. The system continuously collects multi-angle facial image sequences of the target participants using a facial recognition camera and collects fingerprint images of the target participants using a fingerprint scanner. The multi-angle facial image sequences and fingerprint images are then bound together with timestamps to generate a multimodal biometric data package. Liveness detection is performed on multi-angle face image sequences in multimodal biometric data packages. After the detection is successful, face feature vectors are extracted. Fingerprint minutiae features are extracted from fingerprint images. The face feature vectors and fingerprint minutiae features are fused to generate a fused feature code. The fusion feature code is uploaded to the hospital ethics review management system server and compared with the fusion feature templates of all pre-stored committee members at a 1:N ratio to calculate the similarity score. If a target fusion feature template has a similarity score that exceeds the preset score threshold, the identity verification is deemed successful, and the committee member's identity information corresponding to the target fusion feature template is retrieved. The system matches the member's identity information with the list of members who should attend the meeting. If the target member is on the list, a "successful check-in record" containing the member's identity identifier, verification time, and verification method is generated, and a successful check-in instruction is sent to the handheld terminal device.
[0025] In this embodiment, the multi-angle face image sequence includes the frontal face image, left side face image, right side face image, and blinking action image of the target meeting member. The acquisition time is 1-3 seconds, which is used for subsequent liveness detection and feature extraction.
[0026] In this embodiment, when acquiring fingerprint images, the target meeting member is required to press the fingerprint reader continuously for 0.5-2 seconds, and acquire fingerprint images 2-4 times in a row. The image with the highest quality is selected as the fingerprint feature extraction source.
[0027] In this embodiment, liveness detection determines whether a face is a real face by analyzing micro-expressions, skin texture changes, and reflective features in multi-angle facial image sequences.
[0028] In this embodiment, the fusion feature code generation method is as follows: inputting multi-angle facial feature vectors and fingerprint minutiae features into a pre-trained multimodal fusion model, and outputting a fixed-dimensional fusion feature vector. This fusion feature vector contains biometric information of both face and fingerprint, and cannot be reversibly decomposed and restored to the original face image or fingerprint image.
[0029] In this embodiment, the multimodal biometric data package refers to packaging a face image sequence, fingerprint image, and their respective timestamps into a structured data unit, while also recording the device number and acquisition parameters.
[0030] In this embodiment, the preset score threshold refers to the lower limit of the similarity score for determining whether they are the same person. The value range is usually 0.7-0.95, and the default value is 0.85.
[0031] The beneficial effects of the above technical solution are as follows: Through multimodal biometric (facial image sequence + fingerprint) fusion acquisition, local liveness detection, 1:N rapid comparison, and attendance record generation, highly secure, real-time, and traceable identity verification is achieved. Its effects include: dual biometric fusion effectively resists single-feature forgery; liveness detection prevents photo / video attacks; millisecond-level comparison meets the real-time requirements of meeting attendance; and attendance records are fully traceable, providing reliable evidence for subsequent voting behavior correlation and auditing.
[0032] In one embodiment, such as Figure 2 As shown, after identity verification is passed, the system automatically obtains the list of items to be recused for the target participating committee member, and automatically determines whether the target participating committee member needs to recuse themselves based on the list of items to be recused when entering the current voting item, including: Step S201: Determine the unique identity of the target participating committee member, and retrieve and extract the list of projects to be avoided corresponding to the target participating committee member from the pre-stored committee member-project interest database based on the unique identity. Step S202: Obtain the current voting item identifier for the current voting item, and determine the voting authority level of the target participating committee member for the current voting item based on the current voting item identifier; Step S203: Based on the voting permission level, select the appropriate set of reference item identifiers from the list of avoidable items, and compare the current voting item identifier with the set of reference item identifiers one by one; Step S204: If a matching item is found in the comparison results, it is determined that the target participating committee member needs to recuse themselves from the current voting item; if no matching item is found, it is determined that no recusement is required.
[0033] In this embodiment, the voting permission levels include: full voting rights: able to vote on all non-avoidance items; limited voting rights: only have voting rights on specific types of items, and other items are automatically considered as abstentions; observer rights: can only view the voting process and have no right to perform any voting operations.
[0034] In this embodiment, the committee member-project stakeholder database includes the following fields: committee member unique identifier, project unique identifier, stakeholder type, explanation of recusal reasons, relationship effective time, relationship expiration time, and the person who entered the data and the entry time.
[0035] In this embodiment, the reference item identifier set refers to the set of item identifiers selected from the list of items to be avoided based on the voting authority level of the committee member. For example, when voting rights are full, the reference item set includes all items to be avoided; when voting rights are restricted, it only includes items belonging to the authorized type.
[0036] The beneficial effects of the above technical solution are as follows: by automatically retrieving the stake database based on the unique identifier of the committee member, and by combining the voting permission level (full / restricted / observer) to filter the reference project identifier set and perform precise comparison, the recusal judgment is automated and refined. Its effects include: completely eliminating omissions and errors caused by manual reporting or reminders; linking permission levels with recusal, supporting complex project-level exception configurations; and ensuring that recusal judgments are real-time, accurate, and traceable, significantly reducing compliance risks for medical institutions.
[0037] In one embodiment, such as Figure 3 As shown, if recusal is required, the voting function will be locked, preventing the target committee member from accessing the voting interface, and an automatic recusal record will be generated and uploaded to the hospital's ethics review management system server, including: Step S301: Detect whether the handheld terminal device has been switched to the voting option area interface. If so, cut off the touch signal input of the voting option area interface or cover the voting option area interface to a grayed-out unselectable state. Step S302: If not, intercept the jump command of the voting option area interface, so that the target participating committee member cannot switch from the meeting agenda interface to the voting option area interface and display the forced avoidance prompt interface. Step S303: Detect and record the avoidance judgment time parameters, lock operation type, handheld terminal device number, and session identifier of this voting meeting; Step S304: Generate an avoidance behavior record based on the unique identity of the target participating committee member, the current voting item identifier, the avoidance judgment time parameter, the lock operation type, the handheld terminal device number, and the session identifier of this voting meeting, and upload it to the hospital ethics review management system server.
[0038] In this embodiment, the mandatory avoidance prompt interface includes the following information: the name or identifier of the project that needs to be avoided; a brief description of the reason for avoidance; the prompt text: "You need to avoid the current voting project and are not entitled to participate in the voting"; and a confirmation button for the committee member to click to confirm that they are aware of the avoidance requirement. During the display of the mandatory avoidance prompt interface, all voting-related interactive functions of the handheld terminal are locked, and the committee member cannot perform any voting operations.
[0039] In this embodiment, after receiving the record of avoidance behavior, the hospital ethics review and management system server performs the following operations: Calculate the hash value of the received avoidance behavior record data and compare it with the uploaded verification value; Check whether the target participating committee member and the current voting item actually have a matching item in the server-side avoidance list; If the verification is successful, the server stores the avoidance behavior record and returns a "avoidance behavior record confirmed" response to the handheld terminal device; If the verification fails, the server returns an error response, and the handheld terminal device displays "Avoidance behavior record reporting failed. Please check the network or contact the administrator." After receiving a confirmation response, the handheld terminal device marks the avoidance behavior record as "synchronized" locally. If no confirmation response is received, it will automatically retry uploading after the network is restored.
[0040] In this embodiment, the avoidance behavior record also includes the following extended fields: the time when the target member confirmed the avoidance; whether the target member initiated an appeal and the result of the appeal; the execution time of the locking operation (the time interval from determining avoidance to completing the locking); and the battery level and network signal strength of the handheld terminal device.
[0041] In this embodiment, the voting options area interface refers to the graphical user interface area on the handheld terminal device specifically used to display voting options (such as agree / disagree / abstain) and receive the selections clicked by the committee members.
[0042] In this embodiment, the specific execution method of avoiding locking includes: touch signal cut-off type (disabling touch response), interface overlay type (gray overlay to block clicks), and jump interception type (preventing entry into the voting interface).
[0043] The beneficial effects of the above technical solution are as follows: By detecting the terminal interface status and adopting a multi-level forced locking strategy, it automatically generates and uploads a record of avoidance behavior containing complete information such as committee member identifier, project identifier, timestamp, and operation type in real time, thus achieving rigid blocking of avoidance execution and retention of the entire chain of evidence. Its effects are: it completely prevents committee members from voting illegally at the interaction level; the avoidance record is double-verified and solidified by the server, making it non-repudiable; and it supports network interruption fault tolerance, ensuring that records are not lost.
[0044] In one embodiment, for other participating committee members who do not need to recuse themselves, the details and voting options of the current voting item are displayed via a display component. After other participating committee members select and confirm their voting options, the voting data is encrypted, and the encrypted anonymous committee member identifier and voting options are uploaded to the hospital ethics review management system server, including: In response to the meeting host's command to start the current voting item via the hospital ethics review management system server, the voting interaction interface of the handheld terminal devices of other participating committee members is activated; The display component receives and highlights the currently selected voting option in real time by other participating committee members through touch. After other committee members click the confirmation button, record the final voting options of each other participating committee member and generate the raw voting data; The temporary identity identifier of the committee members in the original voting data is replaced with a one-time anonymous voting token. An asymmetric encryption algorithm is used to encrypt the data packet containing the anonymous voting token, the current voting item identifier, the final voting option and the timestamp, to generate an encrypted voting data packet. The encrypted voting data packets are uploaded in real time to the hospital's ethics review and management system server via the encrypted communication module of the handheld terminal device.
[0045] In this embodiment, the voting interface displays the following information: complete details of the current voting item, including the item name, item number, and a brief introduction to the review points; voting options, including at least three standard options: "agree," "disagree," and "abstain," as well as an optional "avoid" option; voting operation prompts, including the voting confirmation method and the remaining voting time (if there is a time limit); the display components adopt a high-contrast color scheme and large font design to adapt to the visual needs of committee members of different age groups.
[0046] In this embodiment, the original voting data includes: temporary identity identifier of the committee member, current voting item identifier, selected voting option, and voting confirmation timestamp.
[0047] In this embodiment, after receiving the data packet, the hospital ethics review and management system server performs the following operations: decrypts the data packet and extracts the anonymous voting token, the current voting item identifier, the final voting option, and the timestamp; Verify the validity of the anonymous voting token: Check that the anonymous voting token exists in the server-side whitelist pool and has not been reused; If all verifications pass, the server stores the vote record in a temporary vote pool and returns a "vote received" confirmation response to the handheld terminal; If any verification fails, the server returns an error response, and the handheld terminal displays "Vote upload failed, please confirm again or contact the administrator"; After receiving the confirmation response, the handheld terminal marks the voting data as "uploaded" locally and displays a "voting successful" message on the display component. At the same time, it locks the voting interface to prevent duplicate voting.
[0048] In this embodiment, asymmetric encryption algorithms refer to data encryption using public-key cryptography, such as RSA or ECC. Encryption is performed using the server's public key, and decryption is performed using the server's private key.
[0049] In this embodiment, the encrypted communication module refers to the software / hardware unit in the handheld terminal device that implements the TLS 1.2 or higher protocol, and is used to establish a secure communication channel with the hospital ethics review and management system server.
[0050] The beneficial effects of the above technical solution are as follows: By replacing the real identity of committee members with a one-time anonymous voting token, and combining it with an asymmetric encryption algorithm to encrypt and transmit data packets containing the token, project identifier, voting options, and timestamps, the entire voting process is made anonymous and data is secure. Its effects are: the mapping between the token and the real identity exists only in the server's secure area, with no associated information on the terminal's local machine, thus preventing identity leakage at the source; encrypted transmission prevents man-in-the-middle attacks; and the one-time use mechanism of the token effectively prevents replay and duplicate voting.
[0051] In one embodiment, the automatic vote counting and generation of voting results based on voting data, the push of voting results to various handheld terminal devices, and the centralized encryption and archiving of all identity verification records, avoidance behavior records, voting data, and operation logs, along with the writing of the root hash value of the archived data into an immutable and traceable electronic archive into the blockchain network, include: Decrypt all voting data to extract the number of votes for each voting option, calculate the total number of valid votes for each voting option based on the number of votes for each voting option, and generate the voting result for the current voting item based on the total number of valid votes; The voting results are structured and packaged, and then pushed to each handheld terminal device using an encrypted transmission protocol for result confirmation and vote approval. After the judgment is passed, the full data archiving process is triggered to collect multiple types of record data, and the record data of each type is structured and organized to generate an archive data package; The archived data packets are encrypted using international standard encryption algorithms to generate encrypted archive files. These encrypted archive files are then stored in a dedicated encrypted storage area on the hospital ethics review and management system server, and a hash value is calculated to generate a root hash value. The root hash value is written into the blockchain network, and a distributed consensus mechanism is used to ensure that the hash value cannot be tampered with, so as to form an immutable and traceable electronic record.
[0052] In this embodiment, the total number of valid votes refers to the sum of the votes for all valid voting options (usually "agree" and "disagree", and "abstention" may be included depending on the meeting rules).
[0053] In this embodiment, the decision to pass the vote refers to the passing rules preset in the medical institution's ethics review charter, such as: the number of votes in favor ≥ 2 / 3 of the total number of valid votes, and the number of votes in favor exceeding half of the total number of committee members, etc. These rules can be preset through meeting configuration.
[0054] In this embodiment, the international standard encryption algorithm refers to AES (Advanced Encryption Standard, 256-bit key length) or SM4, etc., which are used to encrypt archived data packets.
[0055] In this embodiment, the root hash value refers to the hash value calculated for the entire encrypted file generated after encrypting the archived data packets. This value serves as the unique digital fingerprint of all the data from this meeting.
[0056] In this embodiment, the blockchain network refers to a blockchain platform such as a consortium blockchain or Ethereum, which writes the root hash value into blocks and stores it through consensus among multiple nodes to ensure that the hash value cannot be tampered with.
[0057] The beneficial effects of the above technical solution are as follows: by automatically decrypting and counting votes, encrypting and pushing results to various terminals, triggering the archiving and encryption of all data (identity verification, recusal, voting, and operation logs), calculating the root hash value and writing it to the blockchain, real-time reliable publication of voting results and the immutability and solidification of all data are achieved. Its effects include: fully automated vote counting eliminates human error; encrypted archiving ensures confidentiality; and blockchain / hash chain technology enables rapid detection of any historical tampering, meeting the long-term compliant evidence preservation requirements for ethical review archives.
[0058] In one embodiment, obtaining the current voting item identifier and determining the voting authority level of the target participating committee member for the current voting item based on the current voting item identifier includes: In response to the meeting host's instruction to start the current voting item, the current unique item identifier of the current voting item is parsed and extracted from the item start instruction; Read the target participant's permission configuration file pre-stored in the local encrypted storage module, and obtain the target participant's project-specific permission exception list based on the permission configuration file; The voting authority level of the target participating committee member for the current voting item is determined by comparing the current unique item identifier with the list of item-specific permission exceptions, according to the following priority order: First priority: If the project-specific permission exception list clearly states that the target participating committee member has "prohibited voting" or "observer" permissions for the current voting item, then the final permission level is determined to be "no voting rights"; Second priority: If the project-specific permission exception list clearly states that the target participating committee member has "full voting rights" for the current voting item without any restrictions, then the final permission level is determined to be "full voting rights"; Third priority: If the current voting item is not recorded in the project-specific permission exception list, the final permission level is determined according to the global permission level of the target participating committee member. The global permission level includes "full voting rights", "restricted voting rights" and "observer rights". Fourth priority: If the target member's global permission level is "restricted voting rights", further check whether the current voting item belongs to the type of item authorized for voting by the target member. If it does, grant "full voting rights"; otherwise, grant "observer rights".
[0059] In this embodiment, the project-specific permission exception list refers to the record of special project permissions that are pre-configured for the current committee member and exceed the global permissions.
[0060] In this embodiment, the global permission level refers to the default voting permissions of committee members in the entire ethics committee, which are divided into three categories: full voting rights (can vote on all non-avoidance items), limited voting rights (can vote only on specific types of items), and observer rights (cannot vote, can only observe).
[0061] In this embodiment, the project type for authorized voting refers to a pre-defined classification of voteable projects based on their research field, risk level, or ethical review category (such as drug clinical trials, device clinical trials, stem cell research, etc.). Committee members with restricted voting rights are only authorized to vote on specific types of projects.
[0062] The beneficial effects of the above technical solution are as follows: by parsing the project identifier from the voting initiation command, reading the locally pre-stored permission configuration file, and determining the voting permission level step by step according to the four-level priority, a fine, clear, and unambiguous determination of voting permission levels is achieved. Its advantages include: supporting flexible combinations of global permissions and project-specific exceptions; clear rule priorities to avoid disputes; local pre-stored permissions to support rapid offline judgment; and automatically matching and downgrading project types for committee members with restricted voting rights, effectively preventing unauthorized voting.
[0063] In one embodiment, the process of other participating committee members voting via handheld terminal devices also includes: Collect multi-dimensional behavioral characteristic data of each other participating committee member during the voting process; Based on multidimensional operational behavior characteristic data, the tactile modality, motor modality, biological modality, and environmental modality of each other participating committee member during the voting process were determined; Tactile modal features, motion modal features, biological modal features, and environmental modal features are spatiotemporally aligned according to a unified timestamp benchmark to generate a multimodal original high-dimensional behavioral feature tensor containing multi-channel time-series data; The original high-dimensional behavioral feature tensor of multimodal behavior is encoded by a pre-trained autoencoder neural network to generate a low-dimensional behavioral feature latent vector. The low-dimensional behavioral feature latent vector is input into the preset integrated anomaly voting detection engine, and the individual anomaly confidence score of each other participating committee member is output through the engine's preset individual spatiotemporal pattern detection function. Retrieve historical normal voting behavior feature data for each other participating committee member, extract the normal voting behavior feature latent vector from the historical normal voting behavior feature data, and determine the individual behavior baseline distribution of each other participating committee member based on the normal voting behavior feature latent vector; The individual behavioral baseline distribution is input into the preset integrated abnormal voting detection engine. The engine’s preset individual historical baseline deviation detection function outputs the deviation of each other’s current operational behavior characteristics from the individual baseline. A comprehensive anomaly score is determined based on the individual anomaly confidence level of each other participating committee member and the deviation of that participating committee member's current operational behavior characteristics from their personal baseline. Determine the review type, risk level, and voting data quality requirements for the current voting project, and determine the basic anomaly scoring threshold based on the review type, risk level, and voting data quality requirements; A personalized correction coefficient is generated based on the historical credit score of each other participating committee member, and a dynamic intervention score threshold is determined for each other participating committee member based on the personalized correction coefficient and the basic abnormal score threshold. The comprehensive abnormality score is compared with the dynamic intervention score threshold, and a multi-level intervention strategy is implemented to intervene in the voting results based on the comparison results.
[0064] In this embodiment, the tactile modal features include the X / Y coordinate sequence of the touch point of the participating committee member on the handheld terminal device, the touch pressure value sequence, the touch area change sequence, and the touch point movement speed and acceleration sequence; Motion modal characteristics include the device attitude angles (pitch, roll, yaw) and their angular velocity and linear acceleration time series data output by the three-axis accelerometer, three-axis gyroscope and three-axis magnetometer of the handheld terminal device; Biological modal features include changes in facial expressions of participating committee members, and extraction of facial action unit intensity sequences, eye movement trajectories (fixation point, saccades, blink frequency), and head posture change sequences. Environmental modal characteristics include ambient light intensity, ambient noise level in decibels, and estimated distance between the terminal and the committee member's face.
[0065] In this embodiment, the multi-layered intervention strategy specifically includes: If the overall abnormal score is less than the difference between the dynamic intervention score threshold and the preset lag coefficient, it is marked as "normal", immediately included in the vote count, and the personal behavior baseline of the participating committee members is updated. If the difference between the dynamic intervention scoring threshold and the preset lag coefficient is less than or equal to the comprehensive abnormal score and less than the dynamic intervention scoring threshold, it is recorded as "suspicious" and a lightweight soft intervention is triggered: a non-blocking pop-up prompt is displayed on the meeting initiator's terminal, and the participating committee members are required to make a simple secondary confirmation on the terminal. If the overall abnormal score is greater than or equal to the dynamic intervention score threshold, it is marked as "abnormal" and a hard intervention is triggered: the vote is rejected, the terminal voting interface is locked, and the participating committee members are required to undergo dual biometric verification (face + fingerprint). After the verification is passed, the voting interface is displayed again for the participating committee members to vote again. If the overall abnormal score still exceeds the threshold after the re-vote, the case is submitted to the meeting initiator for manual adjudication and recorded as a "serious abnormal event".
[0066] In this embodiment, the multimodal original high-dimensional behavioral feature tensor refers to a four-dimensional tensor with dimensions of (time step, number of modalities, number of feature channels, and number of samples). The time step is determined by the sampling frequency and window duration; the number of modalities is four (tactile, motion, biological, and environmental); each modality contains multiple feature channels (e.g., the tactile modality has six channels: X-coordinate, Y-coordinate, pressure, area, velocity, and acceleration). The dimensions of the tensor are spatiotemporally aligned, meaning that the features of each modality are synchronously arranged at the same time stamp.
[0067] In this embodiment, the pre-trained autoencoder neural network refers to an unsupervised learning neural network comprising an encoder and a decoder. The encoder compresses the high-dimensional input into a low-dimensional latent vector, and the decoder reconstructs the input from the latent vector. The network structure can be a multi-layer fully connected or convolutional autoencoder. During training, normal voting behavior data is used with the goal of minimizing reconstruction error. After training, only the encoder part is used for dimensionality reduction.
[0068] In this embodiment, the low-dimensional behavioral feature latent vector refers to a fixed-length, low-dimensional feature representation obtained after encoding by an autoencoder, typically with 16-64 dimensions. This latent vector is a compressed representation of the original high-dimensional behavioral features, retaining the core discriminative information of voting behavior, and possessing a continuous and smooth manifold structure.
[0069] In this embodiment, the individual anomaly confidence score refers to the probability value calculated by the individual spatiotemporal pattern detection function, representing the degree of anomalousness of the current voting behavior under the overall normal behavior model. The closer the value is to 1, the more anomalous it is.
[0070] In this embodiment, historical normal voting behavior characteristic data refers to the operational behavior characteristic data of each other participating committee member in the past multiple votes, which has been manually reviewed or automatically marked as "no abnormality" by the system.
[0071] In this embodiment, the baseline distribution of individual behavior refers to a statistical distribution model based on the latent vector of the historical normal voting behavior characteristics of participating committee members. It is usually assumed to be a multidimensional Gaussian distribution, and the mean vector and covariance matrix are calculated; or a nonparametric distribution is obtained by kernel density estimation. It is used to measure the degree of deviation between current behavior and one's own habits.
[0072] In this embodiment, the comprehensive anomaly score refers to the weighted combination of an individual's anomaly confidence level and deviation.
[0073] In this embodiment, the basic anomaly scoring threshold is determined jointly based on the review type of the voting item (e.g., initial review, re-review, serious adverse event review), risk level (low / medium / high), and voting data quality requirements (e.g., whether absolute accuracy is required). For example, the threshold is set at 0.4 for high-risk items, 0.6 for medium-risk items, and 0.8 for low-risk items.
[0074] In this embodiment, the historical credit score refers to the reliability score based on the past voting behavior of participating committee members, with an initial value of 100 points. Each vote judged as "normal" with no interference record increases the credit score by 1 point (maximum 100); each instance of "suspicious" or "abnormal" interference deducts 5 points; a "serious abnormal event" deducts 20 points. For committee members with a credit score below 60, the personalized correction coefficient κ=0.8; for 60-80 points, κ=1.0; and for above 80 points, κ=1.2.
[0075] The beneficial effects of the above technical solution are as follows: By collecting multimodal operational behavior characteristics of committee members during the voting process, including tactile, motor, biological, and environmental factors, a behavioral feature tensor is constructed and latent vectors are extracted using an autoencoder for dimensionality reduction. Then, combined with individual spatiotemporal pattern detection and personal historical baseline deviation analysis, a comprehensive anomaly score is generated. At the same time, the intervention threshold is dynamically determined based on the project risk level and the committee member's historical credit score, and a multi-layered intervention strategy from soft prompts and hard verification to manual adjudication is implemented. This achieves intelligent anomaly detection and graded response for voting behavior, effectively identifying abnormal voting situations such as coercion, substitution, misoperation, or external interference by participating committee members. While ensuring the fairness and authenticity of voting, it avoids excessive interference with normal committee members, significantly improving the voting quality and anti-fraud capabilities of ethics review meetings.
[0076] In one embodiment, after decrypting all voting data to extract the number of votes for each voting option, calculating the total number of valid votes for each voting option based on the number of votes for each voting option, and generating the voting result for the current voting item based on the total number of valid votes, the method further includes: The initial approval rate for each voting option in the current voting project is determined based on the voting results; Obtain the job identifier of each other participating committee member, and determine the voting weighting weight of each other participating committee member based on the job identifier; The effective weighted votes for each voting option are calculated based on the weighted average of the votes cast by each of the other participating committee members: ; in, Let represent the valid weighted votes for the i-th voting option, N represent the total number of other participating committee members who voted, and j represent the j-th other participating committee member. Let represent the weighted vote of the j-th participating committee member, and e represent the natural constant with a value of 2.72. This represents the preset attenuation constant, which defaults to 0.01. This represents the time difference between the submission time of the vote of the j-th other participating committee member for the i-th voting option and the voting deadline. This indicates the valid voting time; The weighted number of votes for each voting option is determined based on the valid weighted number of votes for each voting option, as well as the basic and minimum approval percentages for the current voting item. Determine whether the number of valid weighted votes for each voting option is greater than or equal to the number of weighted votes in favor. If so, the vote is passed; otherwise, the weighted approval rate is determined based on the number of valid weighted votes. The weighted approval rate and the original approval rate for each voting item will be uploaded to the meeting initiator for reference and decision-making.
[0077] In this embodiment, the job title identifier refers to the category of position held by the participating committee member in the ethics review committee, including but not limited to: chairperson, vice-chairperson, ordinary member, and invited member. The job title identifier is used to map different voting weights.
[0078] In this embodiment, the voting weighting weight of the chairperson is 1.5, the voting weighting weight of the vice chairperson is 1.2, the voting weighting weight of ordinary members is 1.0, and the voting weighting weight of specially invited members is 0.8; the voting weighting weights can be configured by the administrator before the meeting.
[0079] In this embodiment, the preset decay constant refers to a dimensionless exponential decay rate coefficient, which is used to control the decay rate of the influence of the voting submission time on the number of votes.
[0080] In this embodiment, the effective voting time refers to the length of time from the start of the voting project to the end of the voting period.
[0081] In this embodiment, the weighted voting approval rate refers to the proportion of valid weighted votes for a certain voting option to the total valid weighted votes.
[0082] In this embodiment, the original voting approval rate refers to the approval rate calculated according to the traditional one person, one vote method, which is the number of people who approve / the total number of valid votes.
[0083] In this embodiment, the effective weighted votes refer to the result of summing the original votes of each participating committee member according to their weight coefficient and submission time decay factor, and may be a non-integer.
[0084] The beneficial effects of the above technical solution are as follows: By introducing a position-based weighting and a vote submission time decay factor on the basis of conventional vote counting, the effective weighted votes are calculated for each voting option, and the weighted passing votes and weighted voting approval rate are determined accordingly. At the same time, these are presented to the meeting initiator in sync with the original voting approval rate. This achieves a precise measurement of the differences in committee members' qualifications and the timeliness of voting, making the opinions of key positions such as the chairperson more influential. It also encourages committee members to vote independently as early as possible and avoids herd mentality or wait-and-see behavior, thereby improving the scientific nature, rationality, and decision-making reference value of the ethical review voting results. It also provides the meeting initiator with multi-dimensional and weighable voting data support.
[0085] In one embodiment, this embodiment also discloses a traceable ethics review meeting voting system based on blockchain verification, such as... Figure 4 As shown, the system includes: The comparison module 401 is used to collect the biometric information of the target participating committee members through a handheld terminal device, compare the biometric information with the committee member identity information pre-stored in the hospital ethics review management system server, and complete the identity verification and check-in. The judgment module 402 is used to automatically obtain the list of items to be recused corresponding to the target participating committee member after the identity verification is passed, and automatically determine whether the target participating committee member needs to recuse himself / herself based on the list of items to be recused when entering the current voting item; The locking module 403 is used to lock the voting function if recusal is required, prohibiting the target participating committee member from entering the voting interface, and automatically generating a recusal behavior record and uploading it to the hospital ethics review management system server. The upload module 404 is used to display the details and voting options of the current voting item to other participating committee members who do not need to recuse themselves through a display component. After other participating committee members select and confirm their voting options, the voting data is encrypted, and the encrypted anonymous committee member identifier and voting options are uploaded to the hospital ethics review management system server. The push module 405 is used to automatically complete the vote count and generate voting results based on the voting data, push the voting results to each handheld terminal device, and centrally encrypt and archive all identity verification records, avoidance behavior records, voting data and operation logs. The root hash value of the archived data is used to form an immutable and traceable electronic archive and write it into the blockchain network.
[0086] The working principle and beneficial effects of the above technical solution have been explained in the method embodiments, and will not be repeated here.
[0087] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.
[0088] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
Claims
1. A traceable ethics review meeting voting method based on blockchain verification, characterized in that, Includes the following steps: The biometric information of the target participants is collected by handheld terminal devices, and the biometric information is compared with the identity information of the participants pre-stored in the hospital ethics review management system server to complete identity verification and check-in. After identity verification is passed, the system automatically obtains the list of items to be recused for the target member and automatically determines whether the target member needs to recuse themselves based on the list of items to be recused when entering the current voting item. If recusal is required, the voting function will be locked, the target committee member will be prohibited from entering the voting interface, and a record of the recusal behavior will be automatically generated and uploaded to the hospital ethics review and management system server. For other participating committee members who do not need to recuse themselves, the details of the current voting item and voting options are displayed through a display component. After other participating committee members select and confirm their voting options, the voting data is encrypted, and the encrypted anonymous committee member identifier and voting options are uploaded to the hospital ethics review management system server. The system automatically counts votes and generates voting results based on the voting data, pushes the results to various handheld terminal devices, and centrally encrypts and archives all identity verification records, avoidance behavior records, voting data, and operation logs. The root hash value of the archived data is then written into the blockchain network to form an immutable and traceable electronic archive.
2. The blockchain-based traceable ethics review meeting voting method according to claim 1, characterized in that, The process of collecting biometric information of target meeting participants via handheld terminal devices, comparing this biometric information with pre-stored member identity information in the hospital's ethics review management system server, and completing identity verification and check-in includes: In response to the check-in command initiated by the target participating committee members on their handheld terminal devices, the facial recognition camera and fingerprint reader are activated simultaneously. The system continuously collects multi-angle facial image sequences of the target participants using a facial recognition camera and collects fingerprint images of the target participants using a fingerprint scanner. The multi-angle facial image sequences and fingerprint images are then bound together with timestamps to generate a multimodal biometric data package. Liveness detection is performed on multi-angle face image sequences in multimodal biometric data packages. After the detection is successful, face feature vectors are extracted. Fingerprint minutiae features are extracted from fingerprint images. The face feature vectors and fingerprint minutiae features are fused to generate a fused feature code. The fusion feature code is uploaded to the hospital ethics review management system server and compared with the fusion feature templates of all pre-stored committee members at a 1:N ratio to calculate the similarity score. If a target fusion feature template has a similarity score that exceeds the preset score threshold, the identity verification is deemed successful, and the committee member's identity information corresponding to the target fusion feature template is retrieved. The system matches the member's identity information with the list of members who should attend the meeting. If the target member is on the list, a "successful check-in record" containing the member's identity identifier, verification time, and verification method is generated, and a successful check-in instruction is sent to the handheld terminal device.
3. The blockchain-based traceable ethics review meeting voting method according to claim 1, characterized in that, After identity verification is passed, the system automatically obtains the list of items to be recused for the target participating committee member, and automatically determines whether the target participating committee member needs to recuse themselves based on the list of items to be recused when entering the current voting item, including: Identify the unique identifier of the target participating committee member, and retrieve and extract the list of projects to be avoided corresponding to the target participating committee member from the pre-stored committee member-project stake database based on the unique identifier; Obtain the current voting item identifier for the current voting item, and determine the voting authority level of the target participating committee member for the current voting item based on the current voting item identifier; Based on the voting authority level, a suitable set of reference item identifiers is selected from the list of items to be avoided, and the current voting item identifier is compared with the set of reference item identifiers one by one. If a match is found in the comparison results, it is determined that the target member should recuse themselves from voting on the current item; otherwise, it is determined that they do not need to recuse themselves.
4. The blockchain-based traceable ethics review meeting voting method according to claim 3, characterized in that, If recusal is required, the voting function will be locked, preventing the target committee member from accessing the voting interface, and a recusal behavior record will be automatically generated and uploaded to the hospital's ethics review management system server, including: Detect whether the handheld terminal device has switched to the voting option area interface. If so, cut off the touch signal input of the voting option area interface or cover the voting option area interface to a grayed-out unselectable state. If not, intercept the jump command in the voting options area interface, so that the target participating committee member cannot switch from the meeting agenda interface to the voting options area interface and display the forced avoidance prompt interface; Detect and record the avoidance decision time parameters, lock operation type, handheld terminal device number, and session identifier of this voting meeting; Based on the unique identifier of the target participating committee member, the current voting item identifier, the avoidance judgment time parameter, the lock operation type, the handheld terminal device number, and the session identifier of this voting meeting, an avoidance behavior record is generated and uploaded to the hospital ethics review management system server.
5. The blockchain-based traceable ethics review meeting voting method according to claim 1, characterized in that, For other participating committee members who do not need to recuse themselves, the details and voting options of the current voting item are displayed via a display component. After other participating committee members select and confirm their voting options, the voting data is encrypted. The encrypted anonymous committee member identifier and voting options are then uploaded to the hospital ethics review management system server, including: In response to the meeting host's command to start the current voting item via the hospital ethics review management system server, the voting interaction interface of the handheld terminal devices of other participating committee members is activated; The display component receives and highlights the currently selected voting option in real time by other participating committee members through touch. After other committee members click the confirmation button, record the final voting options of each other participating committee member and generate the raw voting data; The temporary identity identifier of the committee members in the original voting data is replaced with a one-time anonymous voting token. An asymmetric encryption algorithm is used to encrypt the data packet containing the anonymous voting token, the current voting item identifier, the final voting option and the timestamp, to generate an encrypted voting data packet. The encrypted voting data packets are uploaded in real time to the hospital's ethics review and management system server via the encrypted communication module of the handheld terminal device.
6. The blockchain-based traceable ethics review meeting voting method according to claim 1, characterized in that, The process automatically counts votes and generates voting results based on voting data, pushes the results to various handheld terminal devices, and simultaneously centrally encrypts and archives all identity verification records, avoidance behavior records, voting data, and operation logs. The root hash value of the archived data is then written into the blockchain network to form an immutable and traceable electronic archive, including: Decrypt all voting data to extract the number of votes for each voting option, calculate the total number of valid votes for each voting option based on the number of votes for each voting option, and generate the voting result for the current voting item based on the total number of valid votes; The voting results are structured and packaged, and then pushed to each handheld terminal device using an encrypted transmission protocol for result confirmation and vote approval. After the judgment is passed, the full data archiving process is triggered to collect multiple types of record data, and the record data of each type is structured and organized to generate an archive data package; The archived data packets are encrypted using international standard encryption algorithms to generate encrypted archive files. These encrypted archive files are then stored in a dedicated encrypted storage area on the hospital ethics review and management system server, and a hash value is calculated to generate a root hash value. The root hash value is written into the blockchain network, and a distributed consensus mechanism is used to ensure that the hash value cannot be tampered with, so as to form an immutable and traceable electronic record.
7. The blockchain-based traceable ethics review meeting voting method according to claim 3, characterized in that, The step of obtaining the current voting item identifier and determining the voting authority level of the target participating committee member for the current voting item based on the current voting item identifier includes: In response to the meeting host's instruction to start the current voting item, the current unique item identifier of the current voting item is parsed and extracted from the item start instruction; Read the target participant's permission configuration file pre-stored in the local encrypted storage module, and obtain the target participant's project-specific permission exception list based on the permission configuration file; The voting authority level of the target participating committee member for the current voting item is determined by comparing the current unique item identifier with the list of item-specific permission exceptions, according to the following priority order: First priority: If the project-specific permission exception list clearly states that the target participating committee member has "prohibited voting" or "observer" permissions for the current voting item, then the final permission level is determined to be "no voting rights"; Second priority: If the project-specific permission exception list clearly states that the target participating committee member has "full voting rights" for the current voting item without any restrictions, then the final permission level is determined to be "full voting rights"; Third priority: If the current voting item is not recorded in the project-specific permission exception list, the final permission level is determined according to the global permission level of the target participating committee member. The global permission level includes "full voting rights", "restricted voting rights" and "observer rights". Fourth priority: If the target member's global permission level is "restricted voting rights", further check whether the current voting item belongs to the type of item authorized for voting by the target member. If it does, grant "full voting rights"; otherwise, grant "observer rights".
8. The blockchain-based traceable ethics review meeting voting method according to claim 1, characterized in that, The process of other participating committee members voting via handheld devices also included: Collect multi-dimensional behavioral characteristic data of each other participating committee member during the voting process; Based on multidimensional operational behavior characteristic data, the tactile modality, motor modality, biological modality, and environmental modality of each other participating committee member during the voting process were determined; Tactile modal features, motion modal features, biological modal features, and environmental modal features are spatiotemporally aligned according to a unified timestamp benchmark to generate a multimodal original high-dimensional behavioral feature tensor containing multi-channel time-series data; The original high-dimensional behavioral feature tensor of multimodal behavior is encoded by a pre-trained autoencoder neural network to generate a low-dimensional behavioral feature latent vector. The low-dimensional behavioral feature latent vector is input into the preset integrated anomaly voting detection engine, and the individual anomaly confidence score of each other participating committee member is output through the engine's preset individual spatiotemporal pattern detection function. Retrieve historical normal voting behavior feature data for each other participating committee member, extract the normal voting behavior feature latent vector from the historical normal voting behavior feature data, and determine the individual behavior baseline distribution of each other participating committee member based on the normal voting behavior feature latent vector; The individual behavioral baseline distribution is input into the preset integrated abnormal voting detection engine. The engine’s preset individual historical baseline deviation detection function outputs the deviation of each other’s current operational behavior characteristics from the individual baseline. A comprehensive anomaly score is determined based on the individual anomaly confidence level of each other participating committee member and the deviation of that participating committee member's current operational behavior characteristics from their personal baseline. Determine the review type, risk level, and voting data quality requirements for the current voting project, and determine the basic anomaly scoring threshold based on the review type, risk level, and voting data quality requirements; A personalized correction coefficient is generated based on the historical credit score of each other participating committee member, and a dynamic intervention score threshold is determined for each other participating committee member based on the personalized correction coefficient and the basic abnormal score threshold. The comprehensive abnormality score is compared with the dynamic intervention score threshold, and a multi-level intervention strategy is implemented to intervene in the voting results based on the comparison results.
9. The blockchain-based traceable ethics review meeting voting method according to claim 1, characterized in that, After decrypting all voting data to extract the number of votes for each voting option, calculating the total number of valid votes for each voting option based on the number of votes for each voting option, and generating the voting result for the current voting item based on the total number of valid votes, the process also includes: The initial approval rate for each voting option in the current voting project is determined based on the voting results; Obtain the job identifier of each other participating committee member, and determine the voting weighting weight of each other participating committee member based on the job identifier; The effective weighted votes for each voting option are calculated based on the weighted average of the votes cast by each of the other participating committee members: ; in, Let represent the valid weighted votes for the i-th voting option, N represent the total number of other participating committee members who voted, and j represent the j-th other participating committee member. Let represent the weighted vote of the j-th participating committee member, and e represent the natural constant with a value of 2.
72. This represents the preset attenuation constant, which defaults to 0.
01. This represents the time difference between the submission time of the vote of the j-th other participating committee member for the i-th voting option and the voting deadline. This indicates the valid voting time; The weighted number of votes for each voting option is determined based on the valid weighted number of votes for each voting option, as well as the basic and minimum approval percentages for the current voting item. Determine whether the number of valid weighted votes for each voting option is greater than or equal to the number of weighted votes in favor. If so, the vote is passed; otherwise, the weighted approval rate is determined based on the number of valid weighted votes. The weighted approval rate and the original approval rate for each voting item will be uploaded to the meeting initiator for reference and decision-making.
10. A traceable ethics review meeting voting system based on blockchain verification, characterized in that, The system includes: The comparison module is used to collect the biometric information of the target participating committee members through a handheld terminal device, and compare the biometric information with the committee member identity information pre-stored in the hospital ethics review management system server to complete identity verification and check-in. The judgment module is used to automatically obtain the list of items to be recused for the target participating committee member after the identity verification is passed, and automatically determine whether the target participating committee member needs to recuse himself / herself based on the list of items to be recused when entering the current voting item. The locking module is used to lock the voting function if recusal is required, preventing the target member from entering the voting interface, and automatically generating a record of recusal behavior and uploading it to the hospital ethics review and management system server. The upload module is used to display the details and voting options of the current voting item to other participating committee members who do not need to recuse themselves. After other participating committee members select and confirm their voting options, the voting data is encrypted, and the encrypted anonymous committee member identifier and voting options are uploaded to the hospital ethics review management system server. The push module is used to automatically count votes and generate voting results based on voting data, and push the voting results to various handheld terminal devices. At the same time, it centrally encrypts and archives all identity verification records, avoidance behavior records, voting data and operation logs, and writes the root hash value of the archived data into the blockchain network to form an immutable and traceable electronic archive.