Real-time evacuation / restoration-based electronic medical chart data protection service provision system

A distributed ledger-based system addresses the challenges of protecting electronic medical records by providing real-time backup and restoration, ensuring data security and compliance, despite legal and quantum computer risks.

JP2025158049APending Publication Date: 2025-10-16西本 一也 +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024060502
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-03
Publication Date
2025-10-16

AI Technical Summary

Technical Problem

Existing electronic medical record systems face challenges in managing data due to legal restrictions on personal information protection, limited data capacity, risks of information leakage from quantum computers, and vulnerabilities to destructive attacks, especially in the context of high-level cyber threats and physical destruction.

Method used

A real-time backup and restoration system using distributed ledger technology, including blockchain and smart contracts, to securely manage and protect electronic medical records, enabling real-time data preservation, sharing, and restoration across different medical institutions, while ensuring data integrity and privacy.

Benefits of technology

The system effectively safeguards electronic medical records from cyber threats and physical destruction, ensuring real-time data protection and restoration, even in the face of quantum computer attacks, while adhering to legal data management requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025158049000001_ABST
    Figure 2025158049000001_ABST
Patent Text Reader

Abstract

To provide a system capable of preserving, in real time, electronic medical chart data different in formats, and robustly protecting critical information from cryptanalysis by a quantum computer, EMP attack or the like, and restoring such information.SOLUTION: The system is configured to: acquire consent information of both a patient and a doctor regarding evacuation of electronic medical chart data; encrypt data converted into a common format on the basis of the consent information and divide the data to plural pieces; sort the data in association with a plurality of preservation points; manage the data under a black-box environment; assign each data linked to information on the preservation points to be managed to a plurality of sets of distributed file management groups, each comprising node groups of a plurality of different bases in regions around the world that constitute the planet; distribute and record the data in the nodes of each base belonging to each distributed file management group; and create and encrypt index information on data each distributed and recorded, and record the index information in a node group at a specific base.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This invention relates to a real-time backup and restoration type electronic medical record data guard service provision system that protects (focuses on protecting from destruction) electronic medical record data linked to personal information in real time from risks such as high-level cyber attacks that exceed normal levels, severe natural disasters, or physical attacks that are expected in the future. In this specification, "system" refers to a computer system that is configured by combining elements such as computers, other electronic devices, software, communication networks, and data, and that specifically realizes software-based information processing using hardware resources. [Background technology]

[0002] Cyber ​​attacks (destruction, etc.) using ransomware and other methods on electronic medical record data managed by electronic medical record systems are becoming a problem. Currently, there are around 50 vendors (sellers) of electronic medical record systems, including several large and smaller companies, but these systems are not interconnected. As a result, medical institutions using different electronic medical record systems cannot share electronic medical record data, and they are unable to jointly build defense systems against cyber attacks on electronic medical record data.

[0003] However, a concept has emerged that aims to prevent tampering with electronic medical record data by managing it using a blockchain, enabling the sharing of medical information with other medical institutions, and by preventing doctors and medical institutions from editing or viewing the electronic medical record without using a key authenticated and authorized by the patient (see, for example, Patent Documents 1 to 5). [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] https: / / www.yuyama.co.jp / column / medicalrecord / electronicmedicalrecord-blockchain / , "Blockchain for Electronic Medical Records: Sharing Medical Data," [online], Yuyama Manufacturing Co., Ltd. [Non-patent document 2] https: / / baasinfo.net / ?p=4489, Baas info, "Can blockchain be used in the medical field? Introducing the case of electronic medical records", [online], digglue Inc. [Non-patent document 3] https: / / medicalchain.com / ja / , "Medicalchain", [online], Medicalchain [Non-patent document 4] https: / / www.pcronline.com / About-PCR / My-PCR, PCRonline, "MyPCR", [online], PCRonline Editorial Board [Non-Patent Document 5] https: / / www.alihealth.cn / , “Ali Health”, [online], Alibaba Health Summary of the Invention [Problem to be solved by the invention]

[0005] However, managing electronic medical record data using blockchain presents the following challenges:

[0006] (Issue 1) Restrictions on data management due to legal regulations from the perspective of personal information protection In general, it is difficult to construct a blockchain (especially a public chain, which is an open blockchain) in such a way that the chain between blocks can be cut. For this reason, if data is recorded on a blockchain, it becomes difficult to erase (or delete) that data when it becomes necessary. Electronic medical record data contains personal information, but there are legal restrictions on the management of personal information from the perspective of personal information protection. For this reason, there are many restrictions on the management of electronic medical record data in order to protect personal information.

[0007] (Issue 2) Restrictions on the amount of information that can be managed due to the data capacity of blocks in blockchain Furthermore, in a blockchain, the data capacity of the blocks that serve as the data management area is small, limiting the amount of information that can be managed. For example, in the case of electronic medical record data, the medical records that make up the main body of the electronic medical record data have a data volume that is smaller than the data volume of the block, so they can be managed within the block, but the data volume of the numerous photographs (X-ray information, etc.) that accompany the medical record is larger than the data volume of the block. For this reason, it is difficult to combine the medical records that make up the main body of the electronic medical record data and the information on the medical record itself, such as the medical records, into one and manage it on a blockchain.

[0008] (Issue 3) Concerns about information leakage due to cryptanalysis using quantum computers Furthermore, even if a system for managing electronic medical record data is constructed using a closed blockchain such as a private chain to enable the chain between blocks to be cut, there is a risk that the private key will be analyzed by public key analysis using a quantum computer, resulting in the risk of information leakage.

[0009] (Challenge 4) Destructive attacks on nodes Furthermore, if the node configuration of a private chain is leaked, a destructive attack on the node may occur. A single node is easily destroyed.

[0010] The present inventors first considered and examined measures to strongly and efficiently protect important information such as confidential information and personal information from high-level cyber attacks and physical destruction, and to restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis using a quantum computer or an EMP attack. First, they focused on the preservation processing of data for backup of in-house systems, etc., which is carried out periodically in batches.

[0011] However, unlike backup data held by in-house systems, electronic medical record data consists of small amounts of medical records linked to personal information, and requires real-time data preservation whenever necessary.

[0012] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a real-time backup and restoration type electronic medical record data guard service provision system that can preserve electronic medical record data linked to personal information in real time, which is provided to each medical institution by different vendors in different data formats, and that can strongly and efficiently protect important information such as confidential information and personal information from high-level cyber attacks and physical destruction, and can restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis using a quantum computer or an EMP attack. [Means for solving the problem]

[0013] In order to achieve the above-mentioned objectives, the real-time backup and restoration type electronic medical record data guard service provision system of the present invention is a real-time backup and restoration type electronic medical record data guard service provision system for protecting electronic medical record data from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, and at the same time, it is a system with a structure that uses open technology to share electronic medical record management data with specific individuals, and is constructed with multiple planets (a unit that combines blockchains and distributed file management functions, etc., and forms one unit that makes up a system for providing services that implement distributed smart contracts, server applications, etc.) that are mainly private or consortium type closed blockchains, and multiple chains that may include distributed ledgers, public blockchains, etc. the system comprises at least one distributed ledger structure composed of various applications, patient-side application software, an external patient authentication system, a patient ID management system, a patient-side doctor communication means or a smart contract (or server application) for patient-side doctor communication, and doctor-side application software, a doctor-side patient communication means or a smart contract (or server application) for doctor-side patient communication, an administrator-side file data real-time backup system, and an administrator-side file data real-time retrieval system, all of which are provided by an administrator of the electronic medical record data guard service; each of the nodes at each site is connected via a network to recording devices at multiple sites in different regions around the world to form a distributed file management group; the patient-side application software is provided in the patient's communication device and logs in to the patient ID management system and the patient-side doctor communication means or the smart contract (or server application) for patient-side doctor communication;The patient authentication system has a patient-side service application function for applying for the use of specified services related to the preservation of patients' electronic medical records, such as backup and restoration, and the external patient authentication system has a patient login ID, health insurance card number, and My Number etc. management means for managing patient login IDs, health insurance card numbers, My Number etc., and the patient ID management system has a patient ID, patient-side half key, and index information recording block chain address management means for managing patient IDs (to which health insurance card numbers, My Number information etc. are linked) linked to patient login IDs, respective half keys for patient-side encryption and decryption, and block chain addresses for index information recording; the patient-side application software includes: an authentication request means for requesting authentication by providing authentication information such as a patient login ID (personal identification information of the patient) and a password to the external patient authentication system when the patient applies for use of a predetermined service related to the preservation of the patient's electronic medical record via the patient-side application software; and a patient ID and half-key delivery means for delivering a patient ID and a patient-side half-key for encryption or decryption to the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application), after authentication by the external patient authentication system has been completed; When a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) receives the patient ID and patient-side encryption half-keys as patient ID information from the patient ID management system, and initially approves the evacuation transaction using the patient-side encryption half-key, and transfers the initially approved evacuation transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), while passing the patient-side encryption half-key to the doctor-side application software. When a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) has a function for initially approving the evacuation transaction.and a restoration transaction primary approval function that receives a patient ID and patient-side decryption half keys and the like as patient ID information from the patient ID management system, uses the patient-side decryption half key to give a primary approval to the restoration transaction, and transfers the primarily approved restoration transaction to the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication, while passing the patient-side decryption half key to the doctor-side application software. The doctor-side application software has an electronic medical record control application connection function that connects to electronic medical record control application software of a plurality of electronic medical record systems each having a different format, each of which is provided by a separate electronic medical record system provider, and when a patient has applied to use a patient electronic medical record evacuation service via the patient-side application software, receives the patient's electronic medical record data from the electronic medical record control application software of the electronic medical record system, and saves the data in a format specific to the electronic medical record system. a save process electronic medical record data common format conversion function that converts electronic medical record data in a format common to a plurality of electronic medical record systems each having a different format, into electronic medical record data in a common format that is common to a plurality of electronic medical record systems, each having a different format; a doctor-side login function that logs in to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application); when a patient logs in to the patient ID management system and the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) via the patient-side application software and the doctor logs in to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) via the doctor-side login function, a patient-side encryption or decryption half key is received from the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application);a two-way half key receiving function that receives a doctor-side encryption or decryption half key from the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication, and when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, an electronic medical record data encryption function during evacuation processing that encrypts the patient's electronic medical record data converted into a common format by the electronic medical record data common format conversion function during evacuation processing using the patient-side encryption half key and the doctor-side encryption half key received by the two-way half key receiving function, and when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, an electronic medical record data secret sharing and division function during evacuation processing that secret shares the patient's electronic medical record data encrypted by the electronic medical record data encryption function during evacuation processing and divides it into multiple file data, and when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, a file data upload function during evacuation processing that secret shares the electronic medical record data by the secret sharing and division function during evacuation processing and uploads each of the divided file data to a first temporary storage area; a file data integration function during restoration processing that, when a patient has applied to use the patient's electronic medical record restoration service via the patient-side application software, returns a group of multiple file data that have been secret shared and divided by the electronic medical record data secret sharing and division function during evacuation processing and sorted in association with conservation points, which have been received from the operator-side file data real-time retrieval system by the restoration file data receiving function of the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) and downloaded to a second temporary storage area, to an integrated state before secret sharing; and, when a patient has applied to use the patient's electronic medical record restoration service via the patient-side application software, returns the group of multiple file data to an integrated state before secret sharing by the file data integration function during restoration processing.an electronic medical chart data decryption function during restoration processing that decrypts file data encrypted by the electronic medical chart data encryption function during the saving processing into electronic medical chart data of the patient using the patient-side decryption half key and the doctor-side decryption half key received by the two-way half key receiving function; a second data erasure function that erases all file data that has been restored to the electronic medical chart data of the patient before saving by the electronic medical chart data decryption function during restoration processing and that has been secret shared and divided by the electronic medical chart data secret sharing and division function during the saving processing and that has been downloaded to the second temporary storage area; and when a patient applies for use of a patient electronic medical chart restoration service via the patient-side application software, reconverts the electronic medical chart data of the patient that has been decrypted by the electronic medical chart data decryption function during restoration processing and converted into a common format by the electronic medical chart data common format conversion function during the saving processing into a format specific to the control application software of the electronic medical chart before conversion, and and a function to reconvert the unique format at the time of restoration processing to pass it to the electronic medical record control application software of the electronic medical record system, and the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication has a doctor login ID, doctor ID or medical institution ID linked to the doctor login ID, patient ID, and each half key for doctor-side encryption and decryption linked to the patient ID, and has a doctor login ID, doctor ID or medical institution ID and doctor-side half key management function that passes the doctor-side encryption (or decryption) half key to the doctor-side application software, and when a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, the patient-side doctor communication means or the smart contract (or server application) for patient-side doctor communication has a final approval using the doctor-side encryption half key for the transaction of the evacuation processing that was primarily approved and transferred using the patient-side encryption half key, andA saving transaction final approval function that acquires agreement information between the patient and the doctor or medical institution, and when a patient applies for use of the saving service of the patient's electronic medical record via the patient-side application software, the file data upload function of the doctor-side application software during the saving process uploads the file data to a first temporary storage area, which is encrypted by the electronic medical record data encryption function during the saving process, and the saving, a file data preservation point association sorting function during evacuation processing that associates and sorts each of the divided file data that has been secretly shared by the electronic medical record data secret sharing and division function during processing in correspondence with a plurality of preservation points; a file data preservation point information management function that manages, in a black box environment, information on the preservation points for managing the file data sorted by the file data preservation point association sorting function during evacuation processing; and a file data transfer function for evacuation that, when a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, transfers each of the file data that has been sorted by the file data preservation point association sorting function during evacuation processing in correspondence with a plurality of preservation points to the operation manager-side file data real-time evacuation system for each group of file data that has been sorted in correspondence with each preservation point; and, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, a restoration transaction final approval function that uses the doctor-side decryption half-key to give final approval to the restoration transaction that has been primarily approved and transferred by the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) using the patient-side decryption half-key, and obtains agreement information between the patient and the doctor or medical institution regarding the restoration process of the patient's electronic medical record data to be restored; and a restoration file data receiving function that, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, receives from the operator-side file data real-time retrieval system the file data that has been sorted and distributed and saved in association with a plurality of conservation points, for each group of file data that has been sorted and saved in association with the conservation points, and downloads it to a second temporary storage area; and the operator-side file data real-time saving system is provided on each planet,a save file data receiving means or a save file data receiving smart contract (or server application) having a function of receiving save file data transferred for each group of file data sorted in correspondence with each conservation point by the save file data transfer function of the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication; a save file data modifying means or a save file data modifying smart contract (or server application) provided on each planet and having a function of modifying the save file data received by the save file data receiving means or the save file data receiving smart contract (or server application); and a save transaction final approval function of the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication, a modified file data distribution and evacuation means or a modified file data distribution and evacuation smart contract (or server application) having a function of sorting each of the file data modified by the file data modification means for evacuation or the smart contract for evacuation file data (or server application) based on information agreed upon between the patient and the doctor or medical institution regarding the evacuation processing of target data by the file data conservation point association sorting function at the time of the evacuation processing and linked to information of the conservation point managed in a black box environment by the file data conservation point information management function, to a plurality of distributed file management groups constructed by each base node constituting the planet corresponding to the conservation point and recording devices of multiple bases connected to the base nodes via a network, and distributing and evacuating the allocated modified file data for each conservation point to each base node belonging to the distributed file group corresponding to the conservation point and recording devices of multiple bases connected to the base nodes via a network;The key information is comprised of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID, which is included in the agreement information between the patient and the doctor or medical institution regarding the evacuation process of the electronic medical record data to be evacuated for the patient, which is obtained by the evacuation transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication; the file name information of each of the modified file data that has been distributed and saved by each of the modified file data distribution and saving means or the modified file data distribution and saving smart contract (or server application) and that is linked to the information of the preservation point that has been sorted by the file data preservation point association sorting function during the evacuation process of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication and that is managed in a black box environment by the file data preservation point information management function; and the destination of each of the modified file data. an index information creation means or a smart contract (or a server application) for creating index information in a black box environment, the index information comprising configuration information of each of the distributed file management groups; an encrypted index information recording means or a smart contract (or a server application) for recording encrypted index information, the index information being created by the index information creation means or the smart contract (or the server application) in a black box environment, and the index information being recorded in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each of the file data uploaded to the first temporary storage area by the file data upload function during the evacuation process of the doctor-side application software after the index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the encrypted index information recording means or the smart contract (or the server application).and the operation manager-side file data real-time retrieval system is provided in each planet, and includes an encrypted index information reading means or an encrypted index information reading unit having a function of reading index information of a patient's modified file data, which is encrypted and recorded in a node group of a specific location in the distributed ledger structure, based on key information formed using predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID in agreement information between the patient and the doctor or medical institution regarding the restoration process of the electronic medical record data to be restored for the patient, which is obtained by the restoration transaction final approval function, for each group of file data linked to information of each of the maintenance points managed in a black box environment by the file data maintenance point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, in the planet corresponding to the maintenance point. an index information decryption means or a smart contract for decrypting index information (or a server application) having a function of decrypting the encrypted index information read by the encrypted index information reading means or the smart contract for reading encrypted index information (or the server application) in a black box environment; a distributed save destination node analysis means or a smart contract for analyzing distributed save destination node (or a server application) having a function of analyzing the nodes of a distributed file management group linked to all the maintenance points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the index information decryption means or the smart contract for decrypting index information (or the server application);The system is characterized by having an altered file data extraction means or an altered file data extraction smart contract (or server application) having the function of extracting the patient's altered file data that has been saved in a distributed manner, a file data pre-alteration state restoration means or a file data pre-alteration state restoration smart contract (or server application) having the function of restoring the altered file data extracted by the altered file data extraction means or the altered file data extraction smart contract (or server application) to the state before the alteration, and a restoration file data transfer means or a restoration file data transfer smart contract (or server application) having the function of transferring the patient's restoration file data restored to the state before the alteration by the file data pre-alteration state restoration means or the file data pre-alteration state restoration smart contract (or server application) to the doctor's patient communication means or the doctor's patient communication smart contract (or server application).

[0014] Furthermore, the real-time backup and restoration type electronic medical record data guard service providing system of the present invention further comprises an administrator-side file data real-time deletion system, and when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, the patient-side communication means or the patient-side smart contract for communication with the doctor (or server application) receives the patient ID and patient-side encryption half keys as patient ID information from the patient ID management system, and uses the patient-side encryption half keys to primarily approve the deletion transaction, and transfers the primarily approved deletion transaction to the doctor-side communication means or the doctor-side smart contract for communication with the patient (or server application), and also passes the patient-side encryption half keys to the doctor-side application software. and the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) further has a function of final approval of the deletion transaction using a doctor-side half-key for encryption when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, and the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) uses a patient-side half-key for encryption to give final approval to the deletion transaction that has been primarily approved and transferred by the patient-side doctor communication means or the doctor-side smart contract for patient communication (or server application), and further has a function of final approval of the deletion transaction to obtain agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted for the patient, and the operation manager-side file data real-time deletion system is provided on each planet, and on the planet corresponding to the conservation point,and a deletion processing encrypted index information reading means or deletion processing encrypted index information reading means having a function of reading index information of modified file data of a patient that has been distributed and saved prior to a predetermined generation and that has been encrypted and recorded in a node group at a specific location in the distributed ledger structure, based on key information that uses predetermined information linked to the patient ID necessary for deleting electronic medical record data and predetermined information linked to the doctor ID or medical institution ID in agreement information between the patient and the doctor or medical institution regarding the deletion processing of the electronic medical record data to be deleted of the patient that is acquired by the deletion transaction final approval function, for each group of file data linked to information of each of the preservation points that are managed in a black box environment by the file data preservation point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication. a smart contract (or server application) for decrypting index information at the time of deletion, a smart contract (or server application) for decrypting index information at the time of deletion, having a function of decrypting the encrypted index information read by the smart contract (or server application) for reading encrypted index information at the time of deletion in a black box environment; a smart contract (or server application) for analyzing distributed backup destination nodes at the time of deletion, having a function of analyzing the nodes of the distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the smart contract (or server application) for decrypting index information at the time of deletion, andIt is preferable to have a modified file data deleting means during deletion processing or a smart contract (or server application) for deleting modified file data during deletion processing, which has the function of deleting modified file data of patients of a predetermined generation or earlier that has been saved in a distributed manner to nodes of a distributed file management group linked to all conservation points analyzed by the distributed save destination node analyzing means during deletion processing or the smart contract (or server application) for analyzing distributed save destination nodes during deletion processing.

[0015] Furthermore, the real-time backup and restore type electronic medical record data guard service providing system of the present invention further comprises an administrator-side file data real-time update system, and when a patient applies for use of the patient's electronic medical record update service via the patient-side application software, the patient-side doctor communication means or the patient-side smart contract (or server application) receives the patient ID and patient-side encryption half-keys as patient ID information from the patient ID management system, and primarily approves the update transaction using the patient-side encryption half-key, and transfers the primarily approved update transaction to the doctor-side patient communication means or the doctor-side smart contract (or server application) and passes the patient-side encryption half-key to the doctor-side application software, and the doctor-side application software further comprises an update transaction primary approval function, and when a patient applies for use of the patient's electronic medical record update service via the patient-side application software, the doctor-side application software further comprises an administrator-side file data real-time update transaction primary approval function, and an update processing time electronic medical record data common format conversion function that, when an application for use of a child medical record update service has been made, receives the patient's electronic medical record data from the electronic medical record control application software of the electronic medical record system and converts the electronic medical record data in a format specific to the electronic medical record system into electronic medical record data in a common format common to a plurality of electronic medical record systems, each with a different format; an update processing time electronic medical record data encryption function that, when an application for use of the patient's electronic medical record update service has been made by the patient-side application software, encrypts the patient's electronic medical record data converted into the common format by the update processing time electronic medical record data common format conversion function using the patient-side encryption half key and the doctor-side encryption half key received by the both-side half key reception function; and, when an application for use of the patient's electronic medical record update service has been made by the patient-side application software, secret-shares the patient's electronic medical record data encrypted by the update processing time electronic medical record data encryption function;The system further comprises an update processing time electronic medical record data secret sharing division function for dividing the data into multiple file data, and an update processing time file data upload function for, when a patient has applied to use the patient's electronic medical record update service via the patient-side application software, secret sharing by the update processing time electronic medical record data secret sharing division function and uploading each of the divided file data to a first temporary storage area, and when a patient has applied to use the patient's electronic medical record update service via the patient-side application software, the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) finalizes, using a doctor-side encryption half-key, the update processing transaction that has been primarily approved and transferred by the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application), and an update transaction final approval function that acquires agreement information from both medical institutions; an update process file data preservation point association sorting function that, when a patient has applied to use the patient's electronic medical record update service via the patient-side application software, sorts each of the divided file data that have been uploaded to a first temporary storage area by the update process file data upload function of the doctor-side application software, encrypted by the update process electronic medical record data preservation point association sorting function, and secret-shared by the update process electronic medical record data secret-shared-segmentation function; and an update process file data evacuation transfer function that, when a patient has applied to use the patient's electronic medical record update service via the patient-side application software, transfers each of the file data sorted by the update process file data preservation point association sorting function to the operation manager-side file data real-time update system for each group of file data sorted to correspond to each preservation point.The operation manager side file data real-time update system further comprises: a file data receiving means for saving during update processing or a smart contract (or server application) for receiving file data for saving during update processing, which is provided on each planet and has a function of receiving file data for saving during update processing that is transferred for each group of file data sorted in correspondence with each conservation point by the file data transfer function for saving during update processing of the doctor side patient communication means or the smart contract (or server application) for doctor side patient communication; a file data modification means for saving during update processing or a smart contract (or server application) for modifying file data for saving during update processing that is provided on each planet and has a function of modifying the file data for saving during update processing received by the file data receiving means for saving during update processing or the smart contract (or server application) for receiving file data for saving during update processing; The file data modification means for saving during update processing or the smart contract (or server application) for modifying file data for saving during update processing, which is provided in the planet and is sorted by the file data preservation point association sorting function based on the agreement information between the patient and the doctor or medical institution regarding the update process of the patient's data to be updated, obtained by the update transaction final approval function of the doctor's patient communication means or the smart contract (or server application) for doctor's patient communication, and which is linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function, is allocated to multiple distributed file management groups constructed by each base node constituting the planet corresponding to the preservation point and multiple base recording devices connected to the base nodes via a network, and the allocated modified file data is stored for each preservation point,a distributed backup means for file data modified during update processing or a smart contract (or server application) for distributed backup of file data modified during update processing, which has a function of distributing and saving to nodes of each base belonging to a distributed file group corresponding to the conservation point and to recording devices of a plurality of bases connected to the nodes of the base via a network; key information comprising predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID contained in agreement information between the patient and the doctor or medical institution regarding the backup processing of the electronic medical record data to be saved for the patient, which is acquired by the update transaction final approval function of the doctor-side patient communication means or smart contract (or server application) for doctor-side patient communication; an index information creation means for update processing or a smart contract (or server application) for creating index information at update processing, which has a function of creating, in a black box environment, index information comprising information on the file name of each of the modified file data that is sorted by the file data conservation point association sorting function at update processing of the smart contract (or server application) and linked to the information on the conservation point that is managed in a black box environment by the file data conservation point information management function, and configuration information of each of the distributed file management groups to which each of the modified file data is allocated; and an encrypted index information recording means for update processing or a smart contract (or server application) for recording encrypted index information at update processing, which has a function of encrypting, in a black box environment, the index information created by the index information creation means for update processing or the smart contract (or server application) for creating index information at update processing, and recording it in a node group at a specific location in the distributed ledger structure;a first data erasure means for erasing each file data uploaded to the first temporary storage area by the file data upload function of the doctor-side application software at the time of update processing, after the index information is encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure by the encrypted index information recording means at the time of update processing or the smart contract (or server application) for encrypted index information recording at the time of update processing; and a first data erasure means for erasing each file data uploaded to the first temporary storage area by the file data upload function of the doctor-side application software at the time of update processing, which is provided in each planet and which, in the planet corresponding to the conservation point, manages in a black box environment by the file data conservation point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, and which acquires agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted of the patient, which is acquired by the update transaction final approval function. In the method, an update-time encrypted index information reading means or an update-time encrypted index information reading smart contract (or server application) has a function of reading index information of modified file data of a patient that has been distributed and saved prior to a predetermined generation and that is encrypted and recorded in a node group of a specific site in the distributed ledger structure based on key information that uses predetermined information linked to the patient ID required for deleting electronic medical record data and predetermined information linked to the doctor ID or medical institution ID, and an update-time index information decryption means or an update-time index information decryption smart contract (or server application) has a function of decrypting the encrypted index information read by the update-time encrypted index information reading means or the update-time encrypted index information reading smart contract (or server application) in a black box environment, and based on the index information decrypted by the update-time index information decryption means or the update-time index information decryption smart contract (or server application),A distributed backup destination node analysis means for update processing or a smart contract (or server application) for analyzing distributed backup destination nodes for update processing, which has a function of analyzing the nodes of a distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner, and a distributed backup to the nodes of the distributed file management group linked to all the conservation points analyzed by the distributed backup destination node analysis means for update processing or the smart contract (or server application) for analyzing distributed backup destination nodes for update processing, and a file data deletion means for deleting modified file data during update processing or a smart contract (or server application) for deleting modified file data during update processing, which has a function of deleting modified file data of a patient prior to a predetermined generation that has been saved, and wherein the file data integration function during restoration processing of the doctor-side application software is configured to restore multiple file data that have been secret shared and split by the secret sharing and split function during saving processing or the secret sharing and split function during update processing, received from the administrator-side file data real-time retrieval system by the file data reception function for restoration, to an integrated state before secret sharing, when a patient has applied to use the patient's electronic medical record restoration service via the patient-side application software. The file data encrypted by the electronic medical record data encryption function during the saving process or the encryption function during the updating process, which has been restored to its previous integrated state, is decrypted into the electronic medical record data of the patient using the patient-side decryption half key and the doctor-side decryption half key received by the double half key receiving function, and the specific format reconversion function during the restoration process of the doctor-side application software is configured to, when a patient has applied for use of the patient's electronic medical record restoration service via the patient-side application software, reconvert the electronic medical record data of the patient that has been decrypted by the electronic medical record data decryption function during the restoration process and converted into a common format by the electronic medical record data common format conversion function during the saving process or the electronic medical record data common format conversion function during the updating process into a format specific to the electronic medical record control application software before conversion, and pass the electronic medical record data of the patient that has been reconverted into the specific format to the electronic medical record control application software of the electronic medical record system.The file data preservation point information management function of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) is preferably configured to manage, in a black box environment, information on the preservation points for managing the file data sorted by the file data preservation point association sorting function during the save process and the file data preservation point association sorting function during the update process.

[0016] In addition, in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, it is preferable that the system further has a deletion target generation setting means that can change the setting of the generation of file data to be deleted by the file data deletion means modified during deletion processing or the smart contract (or server application) for deleting file data modified during deletion processing.

[0017] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, it is preferable that the means for deleting file data modified during update processing or the smart contract (or server application) for deleting file data modified during update processing is configured to automatically set all file data of past generations of the patient as file data to be deleted.

[0018] In addition, in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, it is preferable that the system further has a deletion target generation setting means that can change the setting of the generation of file data to be deleted by the file data deletion means modified during update processing or the smart contract (or server application) for deleting file data modified during update processing.

[0019] In addition, in the real-time backup and restore type electronic medical record data guard service providing system of the present invention, the index information includes file name information of each of the modified file data linked to the information of the conservation point, configuration information of each of the distributed file management groups to which each of the modified file data is allocated, addresses of the modified file data that have been distributed and saved, and hash values ​​of the modified file data that have been distributed and saved. Furthermore, for each conservation point, the index information includes hash values ​​of each modified file data that have been distributed and saved to each base node belonging to the distributed file group corresponding to the conservation point and to recording devices at multiple bases connected to the base node via a network, and encrypted index information reading means or a smart contract for reading encrypted index information (or server). It is preferable to have a file data consistency check and automatic recovery means or a file data consistency check and automatic recovery smart contract (or server application) that periodically checks the consistency of the modified file data with the hash value in the index information obtained via an index information decryption means or a smart contract for index information decryption (or server application), and if the check shows that the hash value of the modified file data that has been saved in a distributed manner differs from the hash value of the index information that manages the modified file data, it deletes the modified file data that has been saved in a distributed manner and copies the modified file data with a normal hash value to automatically perform recovery processing of the modified file data.

[0020] In addition, in the real-time backup / restore type electronic medical record data guard service providing system of the present invention, it is preferable that the at least two conservation points are at least two addresses in one blockchain.

[0021] In addition, in the real-time backup / restore type electronic medical record data guard service providing system of the present invention, it is preferable that the at least two conservation points are at least one address in each of at least two blockchains.

[0022] Furthermore, the real-time backup and restoration type electronic medical record data guard service provision system of the present invention preferably further comprises a second administrator-side file data real-time deletion system, and the second administrator-side file data real-time deletion system preferably comprises a file data preservation point information deletion means or a file data preservation point information deletion smart contract (or server application) having the function of deleting the preservation point information linked to the file data to be deleted, which is managed in a black box environment by the file data preservation point information management function, based on key information consisting of specified information linked to the patient ID and specified information linked to the doctor ID or medical institution ID in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted for the patient, obtained by the deletion transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication.

[0023] Furthermore, the real-time backup and restoration type electronic medical record data guard service provision system of the present invention preferably further comprises a second administrator-side file data real-time deletion system, and the second administrator-side file data real-time deletion system preferably comprises a file data preservation point information deletion means or a file data preservation point information deletion smart contract (or server application) having the function of deleting the preservation point information linked to the file data to be deleted, which is managed in a black box environment by the file data preservation point information management function, based on key information consisting of specified information linked to the patient ID and specified information linked to the doctor ID or medical institution ID in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted for the patient, obtained by the update transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication.

[0024] In addition, in the real-time backup / restore electronic medical record data guard service provision system of the present invention, it is preferable that each base node belonging to each of the distributed file management groups and the recording devices at multiple bases connected to the base nodes via a network are provided with multiple sub-configuration file servers (or a group of file servers accessible from each base node belonging to each of the file management groups) that are respectively connected to the base nodes and the recording devices at multiple bases connected to the base nodes via a network.

[0025] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, each of the modified file data distributed backup means or the modified file data distributed backup smart contract (or server application) checks the data recording capacity and usage status of each of the node at each of the bases belonging to each of the distributed file management groups and each of the file servers of the sub-components connected to the recording devices at multiple bases connected to the node at each of the bases via a network, and based on the confirmed data recording capacity, the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) sorts the encrypted and divided data that has been uploaded to the first temporary storage area by the file data preservation point association sorting function at the time of the backup process, and the file data preservation point information management function manages the large data linked to the information of the preservation point. It is preferable that the system has a function of selecting a file server of a specific sub-component having a data recording capacity capable of recording modified file data of the type, and recording the large modified file data, which has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area, on the selected file server of the specific sub-component, and which is sorted by the file data preservation point correspondence sorting function during the evacuation process of the doctor's patient communication means or the smart contract (or server application) for doctor's patient communication, and which is linked to information on the preservation point managed in a black box environment by the file data preservation point information management function, and recording information on the file server of the specific sub-component that is the recording destination for recording the large modified file data, which has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area, as second index information in the nodes of each base belonging to each of the distributed file management groups.

[0026] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, each of the modified file data distributed backup means or the modified file data distributed backup smart contract (or server application) is recorded in a predetermined sub-configuration file server connected to each base node belonging to each of the distributed file management groups and to a recording device at a plurality of bases connected to the base node via a network, and the encrypted and divided data is uploaded to the first temporary storage area. The file data is sorted by the file data preservation point association sorting function at the time of the backup process of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application), and the file data preservation point information management function manages the black box. When the large modified file data linked to the information of the conservation point managed under the environment exceeds the upper limit of the recording capacity of the file server, it is preferable to have a function to calculate the recording capacity of each base node belonging to each of the distributed file management groups and each of the other sub-configuration file servers connected to recording devices at multiple bases connected to the base node via a network for the modified file data that exceeds the upper limit of the recording capacity of the file server, select the file server of the sub-configuration that is the optimal recording destination based on the calculated recording capacity, record the data on the selected sub-configuration file server, and change the settings of the original file server to be in a dormant state, and record (update) the information of the sub-configuration file servers that are the recording destination as second index information on each base node belonging to each of the distributed file management groups.

[0027] Furthermore, in the real-time backup and restore type electronic medical record data guard service provision system of the present invention, the altered file data extraction means or the smart contract (or server application) for extracting altered file data refers to the second index information recorded in the node of each base belonging to each of the distributed file management groups, and the encrypted and divided data recorded as the second index information is sorted by the file data preservation point association sorting function at the time of the backup process of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, and is managed in a black box environment by the file data preservation point information management function. It is preferable that the system has a function to detect multiple sub-configuration file servers on which the large modified file data linked to the information of the conservation point to be stored, extract the modified file data recorded on the sub-configuration file server from the multiple sub-configuration file servers, combine the multiple extracted modified file data, and restore the large modified file data linked to the information of the conservation point that is sorted by the file data conservation point correspondence sorting function during the backup process of the doctor's patient communication means or the smart contract (or server application) for doctor's patient communication in its original encrypted and divided state, and managed in a black box environment by the file data conservation point information management function.

[0028] Furthermore, in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, it is preferable that the electronic medical record data secret sharing and division function during the backup process is a function that uses secret sharing technology based on a polynomial division processing method to secret share the electronic medical record data of the patient and divide it into multiple file data.

[0029] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, it is preferable that the electronic medical record data secret sharing and division function during the update process is a function that uses secret sharing technology based on a polynomial division processing method to secret share the electronic medical record data of the patient and divide it into multiple file data.

[0030] In addition, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the encrypted index information recording means or the smart contract (or server application) for recording encrypted index information has a function of encrypting the index information created by the index information creation means or the smart contract (or server application) for creating index information in a black box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, and the modified file data distributed backup means or the smart contract (or server application) for distributed backup of modified file data It is preferable that the system has a function of allocating each file data modified by the backup file data modification means or the backup file data modification smart contract (or server application) to multiple distributed file management groups constructed with each base node constituting the planet corresponding to the conservation point and multiple base recording devices connected to the base nodes via a network, and distributing and evacuating the allocated modified file data for each conservation point to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and multiple base recording devices connected to the base nodes via a network.

[0031] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the encrypted index information recording means or the smart contract (or server application) for recording encrypted index information has a function of encrypting the index information created by the index information creation means or the smart contract (or server application) for creating index information in a black box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, and the modified file data distributed backup means or the smart contract (or server application) for distributed backup of modified file data has the following function: It is preferable that the system has the function of distributing the file data modified by the file data modification means for backup or the smart contract (or server application) for modifying file data for backup to multiple distributed file management groups constructed with each base node that constitutes the planet corresponding to the conservation point and multiple base recording devices connected to the base nodes via a network, and distributing and evacuating the allocated modified file data for each conservation point to each base node that belongs to the distributed file group in a closed blockchain corresponding to the conservation point and multiple base recording devices connected to the base nodes via a network.

[0032] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the update processing encrypted index information recording means or the update processing encrypted index information recording smart contract (or server application) has a function of encrypting the index information created by the update processing index information creation means or the update processing index information creation smart contract (or server application) in a black box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, and the update processing modified file data distributed backup means or the update processing modified file data distributed backup smart contract (also It is preferable that the smart contract (or server application) has the function of distributing the file data modified by the update file data modification means or the update file data modification smart contract (or server application) to multiple distributed file management groups constructed with each base node that constitutes the planet corresponding to the conservation point and multiple base recording devices that are network-connected to the base nodes, and distributing and saving the allocated modified file data for each conservation point to each base node that belongs to a distributed file group that is configured separately from the blockchain and that corresponds to the conservation point, and to multiple base recording devices that are network-connected to the base nodes.

[0033] Furthermore, in the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, the update processing encrypted index information recording means or the update processing encrypted index information recording smart contract (or server application) has a function of encrypting the index information created by the update processing index information creation means or the update processing index information creation smart contract (or server application) in a black box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, and the update processing modified file data distributed backup means or the update processing modified file data distributed backup smart contract (or It is preferable that the smart contract (or server application) has the function of allocating each of the file data modified by the update file data modification means or the update file data modification smart contract (or server application) to a plurality of distributed file management groups constructed by each base node that constitutes the planet corresponding to the conservation point and multiple base recording devices connected to the base nodes via a network, and distributing and saving the allocated modified file data, for each conservation point, to each base node that belongs to the distributed file group in a closed blockchain corresponding to the conservation point and to multiple base recording devices connected to the base nodes via a network.

[0034] Furthermore, in the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, when the electronic medical record data consists of main information consisting of medical records whose data volume is less than the capacity of the block size, and sub-information consisting of images such as X-rays accompanying the medical records whose data volume exceeds the capacity of the block size, the electronic medical record data encryption function at the time of backup processing, the electronic medical record data secret sharing and division function at the time of backup processing, the file data upload function at the time of backup processing, the file data integration function at the time of restoration processing, the electronic medical record data decryption function at the time of restoration processing, the file data preservation point correspondence sorting function at the time of backup processing, the file data preservation point information management function, the backup file data transfer function, the restoration file data receiving function, and the backup file data receiving means in the operation manager side file data real-time backup system or a smart contract (or server application) for receiving file data to be saved, the file data modification means for saving or a smart contract (or server application) for modifying file data to be saved, the modified file data distributed saving means or a smart contract (or server application) for distributed saving of modified file data, the index information creation means or a smart contract (or server application) for creating index information, the encrypted index information recording means or a smart contract (or server application) for recording encrypted index information, the encrypted index information reading means or a smart contract (or server application) for reading encrypted index information in the administrator-side file data real-time retrieval system, the index information decryption means or a smart contract (or server application) for decrypting index information, the distributed saving destination node analysis means or a smart contract (or server application) for analyzing distributed saving destination nodes,It is preferable that the altered file data extraction means or the smart contract (or server application) for extracting altered file data, the file data pre-alteration state restoration means or the smart contract (or server application) for restoring file data to its pre-alteration state, and the restoration file data transfer means or the smart contract (or server application) for transferring restoration file data are configured to process the main information and sub-information of the electronic medical record separately.

[0035] Furthermore, in the real-time backup and restore type electronic medical record data guard service providing system of the present invention, when the electronic medical record data consists of main information consisting of medical records whose data volume is less than the capacity of the block size, and sub-information consisting of images such as X-rays that are attached to the medical records whose data volume exceeds the capacity of the block size, the electronic medical record data encryption function at the time of update processing, the electronic medical record data secret distribution and division function at the time of update processing, the file data upload function at the time of update processing, the file data integration function at the time of restoration processing, the electronic medical record data decryption function at the time of restoration processing, the file data preservation point correspondence sorting function at the time of update processing, the file data preservation point information management function, the file data transfer function for backup at the time of update processing, the file data reception function for restoration processing, the file data preservation point information management function, the file data for backup at the time of update processing in the doctor-side application software or the smart contract (or server application) for doctor-side patient communication, file data receiving means or a smart contract (or server application) for receiving file data to be saved during update processing, said file data modification means for saving during update processing or a smart contract (or server application) for modifying file data to be saved during update processing, said means for distributing and saving modified file data during update processing or a smart contract (or server application) for distributing and saving modified file data during update processing, said index information creation means for creating index information during update processing or a smart contract (or server application) for creating index information during update processing, said encrypted index information recording means for recording encrypted index information during update processing or a smart contract (or server application) for recording encrypted index information during update processing, said encrypted index information reading means or a smart contract (or server application) for reading encrypted index information in said system for retrieving file data on the administrator side in real time, said index information decryption means or a smart contract (or server application) for decrypting index information,It is preferable that the distributed save destination node analysis means or the smart contract (or server application) for analyzing the distributed save destination node, the modified file data extraction means or the smart contract (or server application) for extracting modified file data, the file data pre-modification state restoration means or the smart contract (or server application) for restoring file data to the pre-modification state, and the restoration file data transfer means or the smart contract (or server application) for transferring restoration file data are configured to process the main information and sub-information of the electronic medical record separately.

[0036] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the modified file data distributed backup means or the modified file data distributed backup smart contract (or server application) distributes and saves the modified file data of the main information of the electronic medical record to each of the nodes of the distributed file group in the closed blockchain corresponding to the respective conservation points and to recording devices of multiple locations connected to the nodes of the distributed file group via a network, and also distributes and saves the modified file data of the sub-information of the electronic medical record to each of the nodes of the blockchain corresponding to the respective conservation points. The data is distributed and saved to nodes at each location belonging to a distributed file group configured separately from the node at the location and to recording devices at multiple locations connected to the node at the location via a network, and it is preferable that the encrypted index information recording means or smart contract (or server application) for recording encrypted index information is configured to encrypt the index information of the main information and sub-information of the electronic medical record created by the index information creation means or smart contract (or server application) in a black box environment and record it in a group of nodes at a specific location in a closed or open blockchain of the distributed ledger structure.

[0037] In addition, in the real-time backup and restore type electronic medical record data guard service provision system of the present invention, the update processing modified file data distributed backup means or update processing modified file data distributed backup smart contract (or server application) distributes and saves the modified file data of the main information of the electronic medical record to each of the nodes of the distributed file group in the closed blockchain corresponding to the respective conservation points and to recording devices of multiple locations connected to the nodes of the respective locations via a network, and also distributes and saves the modified file data of the sub-information of the electronic medical record to each of the nodes of the distributed file group in the closed blockchain corresponding to the respective conservation points. The data is distributed and saved to the nodes of each location belonging to the distributed file group and to recording devices of multiple locations connected to the nodes of the location via a network, and it is preferable that the index information recording means for encryption during update processing or the smart contract (or server application) for recording encrypted index information during update processing is configured to encrypt the index information of the main information and sub-information of the electronic medical record created by the index information creation means for update processing or the smart contract (or server application) for creating index information during update processing in a black box environment and record it in a group of nodes of a specific location in a closed or open blockchain of the distributed ledger structure.

[0038] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the modified file data distribution backup means or the modified file data distribution backup smart contract (or server application) distributes and saves the modified file data of the main information of the electronic medical record to each of the nodes of the respective bases belonging to the distributed file group in the closed or open blockchain corresponding to the respective conservation points and to the recording devices of the respective bases connected to the nodes of the respective bases via a network, and also distributes and saves the modified file data of the sub-information of the electronic medical record to each of the nodes of the respective bases belonging to the distributed file group in the closed or open blockchain corresponding to the respective conservation points. The data is distributed and saved to nodes at each location belonging to a distributed file group configured separately from the chain and to recording devices at multiple locations connected to the nodes at the location via a network, and it is preferable that the encrypted index information recording means or smart contract (or server application) for recording encrypted index information is configured to encrypt the index information of the main information and sub-information of the electronic medical record created by the index information creation means or smart contract (or server application) in a black box environment and record it in a group of nodes at a specific location in a closed or open blockchain of the distributed ledger structure.

[0039] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the means for distributively saving modified file data during update processing or the smart contract (or server application) for distributively saving modified file data during update processing distributes and saves the modified file data of the main information of the electronic medical record to each of the nodes of each base belonging to a distributed file group in a closed or open blockchain corresponding to the relevant conservation point and to recording devices of multiple bases connected to the nodes of the base via a network, and distributively saves the modified file data of the sub-information of the electronic medical record to each of the nodes of the blockchain corresponding to the relevant conservation point. is distributed and saved to nodes at each location belonging to a separately configured distributed file group and to recording devices at multiple locations connected to the nodes at the location via a network, and the index information recording means for encryption during update processing or the smart contract (or server application) for recording encrypted index information during update processing is preferably configured to encrypt the index information of the main information and sub-information of the electronic medical record created by the index information creation means for update processing or the smart contract (or server application) for creating index information during update processing in a black box environment and record it in a group of nodes at a specific location in a closed or open blockchain of the distributed ledger structure.

[0040] Furthermore, in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, the modified file data distribution backup means or smart contract (or server application) for distributed backup of modified file data distributes and saves the modified file data of each of the electronic medical record's main information and electronic medical record's sub-information, for each conservation point, to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and to recording devices at multiple bases connected to the base nodes via a network, and it is preferable that the encrypted index information recording means or smart contract (or server application) for encrypted index information recording is configured to encrypt the index information of each of the electronic medical record's main information and sub-information created by the index information creation means or smart contract (or server application) in a black box environment and record it in a group of nodes at a specific base in the closed or open blockchain of the distributed ledger structure.

[0041] Furthermore, in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, the means for distributing and saving file data modified during update processing or the smart contract (or server application) for distributing and saving file data modified during update processing distributes and saves the modified file data of each of the electronic medical record's main information and electronic medical record's sub-information, for each conservation point, to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and to recording devices at multiple bases connected to the base nodes via a network, and the means for recording encrypted index information during update processing or the smart contract (or server application) for recording encrypted index information during update processing is preferably configured to encrypt the index information of each of the electronic medical record's main information and sub-information created by the means for creating index information during update processing or the smart contract (or server application) for creating index information during update processing in a black box environment and record it in a group of nodes at specific bases in the closed or open blockchain of the distributed ledger structure.

[0042] Furthermore, in the real-time backup and restore type electronic medical record data guard service providing system of the present invention, when the data of the electronic medical record is composed of main information consisting of medical records whose data volume is less than the capacity of the block size and sub-information consisting of images such as X-ray photographs attached to the medical records whose data volume exceeds the capacity of the block size, the encrypted index information reading means at the time of deletion processing or the smart contract (or server application) for reading the encrypted index information at the time of deletion processing, the index information decryption means at the time of deletion processing or the smart contract for decrypting the index information at the time of deletion processing in the file data real-time deletion system on the operation manager side It is preferable that the smart contract (or server application), the distributed backup destination node analysis means during deletion processing or the smart contract (or server application) for analyzing distributed backup destination nodes during deletion processing, the modified file data deletion means during deletion processing or the smart contract (or server application) for deleting modified file data during deletion processing, and the file data preservation point information deletion means or the smart contract (or server application) for deleting file data preservation point information in the second administrator-side file data real-time deletion system are configured to process the main information and sub-information of the electronic medical record separately.

[0043] Furthermore, in the real-time backup and restore type electronic medical record data guard service provision system of the present invention, when the electronic medical record data consists of main information consisting of medical records whose data volume is less than the capacity of the block size and sub-information consisting of images such as X-ray photographs attached to the medical records whose data volume exceeds the capacity of the block size, the encrypted index information reading means at the time of update processing or the smart contract (or server application) for reading encrypted index information at the time of update processing, the index information decryption means at the time of update processing or the smart contract for decrypting index information at the time of update processing in the file data real-time update system on the operation manager side It is preferable that the smart contract (or server application), the distributed backup destination node analysis means during update processing or the smart contract (or server application) for analyzing distributed backup destination nodes during update processing, the modified file data deletion means during update processing or the smart contract (or server application) for deleting modified file data during update processing, and the file data preservation point information deletion means or the smart contract (or server application) for deleting file data preservation point information in the second administrator-side file data real-time deletion system are configured to process the main information and sub-information of the electronic medical record separately.

[0044] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the means for deleting modified file data during deletion processing or the smart contract (or server application) for deleting modified file data during deletion processing in the file data real-time deletion system on the operator's side is preferably configured to delete, for each conservation point, the modified file data of the main information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group in a closed blockchain that corresponds to the conservation point and to multiple base recording devices that are network-connected to the base node, and to delete, for each conservation point, the modified file data of the sub-information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group that is configured separately from the blockchain and that corresponds to the conservation point and to multiple base recording devices that are network-connected to the base node.

[0045] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the means for deleting modified file data during update processing or the smart contract (or server application) for deleting modified file data during update processing in the file data real-time update system on the operator's side is preferably configured to delete, for each conservation point, the modified file data of the main information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group in a closed blockchain corresponding to the conservation point and to multiple base recording devices connected to the base node via a network, and to delete, for each conservation point, the modified file data of the sub-information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group configured separately from the blockchain corresponding to the conservation point and to multiple base recording devices connected to the base node via a network.

[0046] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the file data deletion means modified during deletion processing or the smart contract (or server application) for deleting file data modified during deletion processing in the file data real-time deletion system on the operator's side deletes, for each conservation point, the modified file data of the electronic medical record sub-information that is distributed and saved to the nodes of each base belonging to a distributed file group that is configured separately from the blockchain and that corresponds to the conservation point, and to recording devices at multiple bases that are connected to the nodes of the base via a network, and it is preferable that the file data conservation point information deletion means or the smart contract (or server application) for deleting file data conservation point information in the second file data real-time deletion system on the operator's side deletes the information of the conservation point linked to the file data of the main information of the electronic medical record to be deleted that is distributed and saved to the nodes of each base belonging to a distributed file group in a closed or open blockchain and to recording devices at multiple bases that are connected to the nodes of the base via a network, which are managed in a black box environment by the file data conservation point information management function.

[0047] In addition, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the file data deletion means modified during update processing or the smart contract (or server application) for deleting file data modified during update processing in the file data real-time update system on the operator's side deletes, for each conservation point, the modified file data of the electronic medical record sub-information that is distributed and saved to the nodes of each base belonging to a distributed file group that is configured separately from the blockchain and that corresponds to the conservation point, and to recording devices at multiple bases that are connected to the nodes of the base via a network, and it is preferable that the file data conservation point information deletion means or the smart contract (or server application) for deleting file data conservation point information in the second file data real-time deletion system on the operator's side deletes the information of the conservation point linked to the file data of the main information of the electronic medical record to be deleted that is distributed and saved to the nodes of each base belonging to a distributed file group in a closed or open blockchain and to recording devices at multiple bases that are connected to the nodes of the base via a network, which are managed in a black box environment by the file data conservation point information management function.

[0048] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, it is preferable that the means for deleting modified file data during deletion processing or the smart contract (or server application) for deleting modified file data during deletion processing in the file data real-time deletion system on the operator's side is configured to delete, for each conservation point, the modified file data of each of the main information and sub-information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and to recording devices at multiple bases connected to the base node via a network.

[0049] Furthermore, in the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, it is preferable that the means for deleting modified file data during update processing or the smart contract (or server application) for deleting modified file data during update processing in the file data real-time update system on the operator's side is configured to delete, for each conservation point, the modified file data of each of the main information and sub-information of the electronic medical record that is distributed and saved to the nodes of each base belonging to a distributed file group that is configured separately from the blockchain and corresponds to the conservation point, and to recording devices of multiple bases that are network-connected to the nodes of the base. [Effects of the Invention]

[0050] According to the present invention, a real-time backup and restoration type electronic medical record data guard service provision system is obtained that can preserve electronic medical record data linked to personal information in real time, which is provided to each medical institution by different vendors in different data formats, and can strongly and efficiently protect important information such as confidential information and personal information from high-level cyber attacks and physical destruction, and can restore important information without it being stolen by third parties even if it is subjected to cryptographic analysis using a quantum computer or an EMP attack. [Brief explanation of the drawings]

[0051] [Figure 1] 1 is an explanatory diagram showing in outline the overall configuration of a real-time save / restore type electronic medical record data guard service providing system according to a first embodiment of the present invention; [Figure 2] 1 is an explanatory diagram showing an outline of the configuration of patient-side application software in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 3] 1 is an explanatory diagram showing an outline of the configuration of a patient ID management system in a real-time save / restore type electronic medical record data guard service providing system according to a first embodiment. [Figure 4]This is an explanatory diagram showing the outline of the configuration of the blockchain address management means for recording patient ID, patient side half key, and index information in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 5] 1 is an explanatory diagram showing the outline of the configuration of an authentication request means in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 6] 1 is an explanatory diagram showing the outline of the configuration of the patient ID and half key delivery means in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 7] This is an explanatory diagram that shows a schematic configuration of a part of the patient-to-doctor communication means or the smart contract (or server application) for patient-to-doctor communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 8] This is an explanatory diagram that shows in outline the configuration of other parts of the patient-to-doctor communication means or the smart contract (or server application) for patient-to-doctor communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 9] 1 is an explanatory diagram showing in outline the configuration of part of the doctor-side application software in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 10] 1 is an explanatory diagram showing a schematic image of electronic medical record data in which the format specific to each company's electronic medical record system has been converted into a common format in the real-time backup / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 11] FIG. 10 is an explanatory diagram showing the general configuration of another part of the doctor-side application software in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 12]FIG. 10 is an explanatory diagram showing in outline the configuration of yet another part of the doctor-side application software in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 13] FIG. 10 is an explanatory diagram showing in outline the configuration of yet another part of the doctor-side application software in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 14] FIG. 10 is an explanatory diagram showing in outline the configuration of yet another part of the doctor-side application software in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 15] This is an explanatory diagram that shows a schematic configuration of a part of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 16] This is an explanatory diagram that shows in outline the configuration of the doctor-side patient communication means or other parts of the doctor-side smart contract (or server application) for patient communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 17] This is an explanatory diagram that shows in outline the configuration of another part of the doctor-patient communication means or the smart contract (or server application) for doctor-patient communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 18] 1 is an explanatory diagram showing the outline of the configuration of the administrator-side file data real-time saving system in the real-time saving / restoring electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 19]FIG. 1 is an explanatory diagram showing the outline of the configuration of the backup file data receiving means or the backup file data receiving smart contract (or server application) in the real-time backup / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 20] FIG. 1 is an explanatory diagram that shows in outline the configuration of the saving file data modification means or the saving file data modification smart contract (or server application) in the real-time saving / restoring electronic medical record data guard service providing system of the first embodiment. [Figure 21] This is an explanatory diagram that shows in outline the configuration of the modified file data distribution and evacuation means or the smart contract (or server application) for distributed evacuation of modified file data in the real-time evacuation and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 22] FIG. 1 is an explanatory diagram that shows in outline the configuration of the index information creation means or the smart contract (or server application) for creating index information in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 23] FIG. 1 is an explanatory diagram showing the outline of the configuration of the encrypted index information recording means or the smart contract (or server application) for recording encrypted index information in the real-time backup / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 24] 1 is an explanatory diagram showing in outline the configuration of a first data erasure means 7 in a real-time save / restore type electronic medical record data guard service providing system according to a first embodiment.

[0023] FIG. [Figure 25] 1 is an explanatory diagram showing the outline of the configuration of the administrator-side file data real-time retrieval system in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 26]FIG. 1 is an explanatory diagram showing the outline of the configuration of the encrypted index information reading means or the smart contract (or server application) for reading encrypted index information in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 27] FIG. 1 is an explanatory diagram showing in outline the configuration of the index information decryption means or the index information decryption smart contract (or server application) in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 28] This is an explanatory diagram that shows in outline the configuration of the distributed save destination node analysis means or the smart contract (or server application) for distributed save destination node analysis in the real-time save / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 29] FIG. 1 is an explanatory diagram that shows in outline the configuration of the altered file data extraction means or the smart contract (or server application) for extracting altered file data in the real-time backup / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 30] This is an explanatory diagram that shows the outline of the configuration of the file data pre-alteration state restoration means or the smart contract (or server application) for restoring file data to its pre-alteration state in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 31] FIG. 1 is an explanatory diagram showing in outline the configuration of a restoration file data transfer means or a restoration file data transfer smart contract (or server application) in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 32] 1 is an explanatory diagram showing the outline of the configuration of the administrator-side file data real-time deletion system in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 33]This is an explanatory diagram that shows in outline the configuration of the means for reading encrypted index information during deletion processing or the smart contract (or server application) for reading encrypted index information during deletion processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 34] This is an explanatory diagram that shows in outline the configuration of the index information decryption means during deletion processing or the smart contract (or server application) for decrypting index information during deletion processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 35] This is an explanatory diagram that shows in outline the configuration of the distributed backup destination node analysis means during deletion processing or the smart contract (or server application) for analyzing distributed backup destination nodes during deletion processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 36] This is an explanatory diagram that shows in outline the configuration of the means for deleting file data modified during deletion processing or the smart contract (or server application) for deleting file data modified during deletion processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 37] 1 is an explanatory diagram showing the outline of the configuration of the deletion target generation setting means in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment; [Figure 38] FIG. 1 is an explanatory diagram that shows in outline the configuration of the patient-doctor communication means or the smart contract (or server application) for patient-doctor communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 39] This is an explanatory diagram that shows in outline the configuration of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 40] 1 is an explanatory diagram showing the outline of the configuration of the administrator-side file data real-time update system in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 41] This is an explanatory diagram that shows in outline the configuration of the file data receiving means for saving during update processing or the smart contract (or server application) for receiving file data for saving during update processing in the real-time save / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 42] This is an explanatory diagram that shows in outline the configuration of the file data modification means for saving during update processing or the smart contract (or server application) for modifying file data for saving during update processing in the real-time save / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 43] This is an explanatory diagram that shows in outline the configuration of the means for distributing and saving modified file data during update processing or the smart contract (or server application) for distributing and saving modified file data during update processing in the real-time save / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 44] This is an explanatory diagram that shows in outline the configuration of the index information creation means at the time of update processing or the smart contract (or server application) for creating index information at the time of update processing in the real-time save / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 45] This is an explanatory diagram that shows in outline the configuration of the update processing encrypted index information recording means or the smart contract (or server application) for recording encrypted index information during update processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 46] 1 is an explanatory diagram showing the outline of the configuration of a first data erasure means during update processing in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 47]This is an explanatory diagram that shows in outline the configuration of the means for reading encrypted index information during update processing or the smart contract (or server application) for reading encrypted index information during update processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 48] This is an explanatory diagram that shows in outline the configuration of the index information decryption means during update processing or the smart contract (or server application) for decrypting index information during update processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 49] This is an explanatory diagram that shows in outline the configuration of the distributed backup destination node analysis means during update processing or the smart contract (or server application) for analyzing distributed backup destination nodes during update processing in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 50] This is an explanatory diagram that shows in outline the configuration of the means for deleting file data modified during update processing or the smart contract (or server application) for deleting file data modified during update processing in the real-time backup / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 51] 1 is an explanatory diagram showing the outline of the configuration of the deletion target generation setting means in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment; [Figure 52] FIG. 1 is an explanatory diagram that shows in outline the configuration of the patient-doctor communication means or the smart contract (or server application) for patient-doctor communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 53] FIG. 10 is an explanatory diagram showing in outline the configuration of still another part of the doctor-side application software 50 in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 54]FIG. 10 is an explanatory diagram showing in outline the configuration of still another part of the doctor-side application software 50 in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 55] This is an explanatory diagram that shows in outline the configuration of another part of the doctor-patient communication means or the smart contract (or server application) for doctor-patient communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 56] This is an explanatory diagram that shows in outline the configuration of another part of the doctor-patient communication means or the smart contract (or server application) for doctor-patient communication in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 57] 1 is an explanatory diagram showing an outline of the configuration of the file data integration function during the restoration process of the doctor-side application software in the real-time backup / restoration type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 58] 1 is an explanatory diagram showing an outline of the configuration of the electronic medical record data decryption function during the restoration process of the doctor-side application software in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 59] 1 is an explanatory diagram showing the outline of the configuration of the specific format reconversion function during restoration processing of the doctor-side application software in the real-time backup / restoration type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 60] This is an explanatory diagram that shows an outline of the configuration of the file data preservation point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication in the real-time backup and restore type electronic medical record data guard service provision system of the first embodiment. [Figure 61]This is an explanatory diagram that shows in outline the configuration of the file data consistency check and automatic recovery means or the smart contract (or server application) for file data consistency check and automatic recovery in the real-time backup and restore type electronic medical record data guard service provision system of the first embodiment. [Figure 62] FIG. 10 is an explanatory diagram showing the outline of the configuration of a second administrator-side file data real-time deletion system in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 63] This is an explanatory diagram that shows in outline the configuration of the file data preservation point information deletion means or the smart contract (or server application) for deleting file data preservation point information in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 64] FIG. 10 is an explanatory diagram showing the outline of the configuration of a second administrator-side file data real-time deletion system in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 65] This is an explanatory diagram that shows in outline the configuration of the file data preservation point information deletion means or the smart contract (or server application) for deleting file data preservation point information in the real-time backup / restore type electronic medical record data guard service provision system of the first embodiment. [Figure 66] This is an explanatory diagram that shows in outline the configuration of other parts of the modified file data distribution and evacuation means or the smart contract (or server application) for distributed evacuation of modified file data in the real-time evacuation and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 67] This is an explanatory diagram that shows in outline the configuration of yet another part of the modified file data distribution and evacuation means or the smart contract (or server application) for distributed evacuation of modified file data in the real-time evacuation and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 68]This is an explanatory diagram that shows in outline the configuration of yet another part of the modified file data distribution and evacuation means or the smart contract (or server application) for distributed evacuation of modified file data in the real-time evacuation and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 69] 1 is an explanatory diagram conceptually showing the characteristic technical elements of the real-time backup and restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 70] FIG. 70 is an explanatory diagram showing FIG. 69 in more detail. [Figure 71] An explanatory diagram of the secret sharing technology used in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment, where (a) is an explanatory diagram of the AONT method secret sharing technology, and (b) is an explanatory diagram of the exclusive OR and threshold sharing method secret sharing technology. [Figure 72] This is an explanatory diagram conceptually illustrating the difference in data obtained by the conventional AONT-based tally-based secret sharing technology and the polynomial fragmentation processing-based secret sharing technology. (a) is a diagram showing an image of data obtained by the AONT-based secret sharing technology, and (b) is a diagram showing an image of data obtained by the polynomial fragmentation processing-based secret sharing technology. [Figure 73] FIG. 10 is an explanatory diagram illustrating the concept of polynomial segmentation processing. [Figure 74] This is an explanatory diagram that shows, in an image, the concept of the process of backing up information fragmented by polynomial fragmentation processing on the user side on the electronic medical record data guard service operator side in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 75] 1 is an explanatory diagram showing, in an image form, the concept of the process of restoring fragmented information saved on the side of each operation manager on the side of the user in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 76]1 is an explanatory diagram conceptually showing the processing by a black-boxed program for each of the purposes of data evacuation and file data restoration in the real-time evacuation / restoration type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 77] 1 is an explanatory diagram conceptually illustrating an example of the overall processing image of real-time saving processing using the real-time saving / restoring electronic medical record data guard service providing system of the first embodiment.

[0032] FIG. [Figure 78] 1 is an explanatory diagram conceptually showing an example of a processing image of the consensus composite method in real-time saving processing using the real-time saving / restoring type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 79] 1 is an explanatory diagram conceptually showing an example of a processing image of the consensus composite method in real-time restoration processing using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 80] 1 is an explanatory diagram conceptually illustrating an example of a processing image of real-time deletion processing using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 81] 1 is an explanatory diagram conceptually showing an example of data deletion in a real-time deletion process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 82] This is an explanatory diagram conceptually showing a configuration with multi-chain, multi-cloud, and multi-address as a configuration for having multiple conservation points in the real-time backup and restoration type electronic medical record data guard service provision system of the first embodiment. [Figure 83] 1 is an explanatory diagram conceptually showing the communication function in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 84]1 is an explanatory diagram conceptually showing the manner of address management for managing personal information in a blockchain-type system that constitutes the first embodiment of the real-time backup and restoration type electronic medical record data guard service provision system, where (a) is a diagram showing the manner in which a business entity manages important information such as personal information and assets, (b) is a diagram showing the manner in which an individual manages important information such as personal information and assets, and (c) is a diagram showing the manner in which a business entity and an individual jointly manage important information such as personal information and assets. [Figure 85] FIG. 10 is an explanatory diagram conceptually showing another example of data management and data deletion on the administrator side in the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 86] FIG. 1 is an explanatory diagram conceptually illustrating an example of an image of the basic configuration when assuming near-real-time evacuation and restoration processing using the real-time evacuation and restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 87] This is an explanatory diagram conceptually showing an example of the basic configuration image when assuming real-time backup and restore processing of block-sized data using the real-time backup and restore type electronic medical record data guard service provision system of the first embodiment. [Figure 88] This is an explanatory diagram conceptually showing an example of the basic configuration image when assuming real-time backup and restore processing of large file size data using the real-time backup and restore type electronic medical record data guard service provision system of the first embodiment. [Figure 89] 1 is an explanatory diagram showing a part of an example of the flow of the electronic medical record evacuation process using the real-time evacuation / restoration type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 90] FIG. 89 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record evacuation process using the real-time evacuation / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 91]FIG. 90 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record evacuation process using the real-time evacuation / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 92] FIG. 91 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record evacuation process using the real-time evacuation / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 93] FIG. 92 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record evacuation process using the real-time evacuation / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 94] FIG. 93 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record evacuation process using the real-time evacuation / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 95] This is an explanatory diagram that shows a schematic image of the flow of encryption processing of electronic medical records in the electronic medical record evacuation process using the real-time evacuation and restoration type electronic medical record data guard service providing system of the first embodiment, from the perspective of managing file data. [Figure 96] This is an explanatory diagram that shows a schematic image of the flow of encryption processing of electronic medical records in the electronic medical record evacuation process using the real-time evacuation and restoration type electronic medical record data guard service providing system of the first embodiment, from the perspective of managing index information. [Figure 97] 1 is an explanatory diagram showing a schematic example of a link between the real-time save / restore type electronic medical record data guard service providing system of the first embodiment and existing electronic medical record services of various companies.

[0023] FIG. [Figure 98] 1 is an explanatory diagram showing a part of an example of the flow of the electronic medical record restoration process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 99] FIG. 10 is an explanatory diagram showing a continuation of FIG. Y7 illustrating an example of the flow of the electronic medical record restoration process using the real-time backup / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 100]FIG. 10 is an explanatory diagram showing a continuation of FIG. Y8 illustrating an example of the flow of the electronic medical record restoration process using the real-time backup / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 101] FIG. 10 is an explanatory diagram showing a continuation of FIG. Y9 illustrating an example of the flow of the electronic medical record restoration process using the real-time backup / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 102] FIG. 10 is an explanatory diagram showing a continuation of FIG. Y10 illustrating an example of the flow of the electronic medical record restoration process using the real-time backup / restoration type electronic medical record data guard service providing system of the first embodiment. [Figure 103] FIG. 1 is an explanatory diagram that shows a schematic image of the flow of the electronic medical record decryption process in the electronic medical record restoration process using the real-time backup / restore type electronic medical record data guard service providing system of the first embodiment, from the perspective of managing file data. [Figure 104] FIG. 1 is an explanatory diagram showing a schematic image of the flow of the electronic medical record decryption process in the electronic medical record restoration process using the real-time backup / restore type electronic medical record data guard service providing system of the first embodiment, from the perspective of managing index information. [Figure 105] 1 is an explanatory diagram showing a part of an example of the flow of the electronic medical record deletion process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 106] FIG. 105 is an explanatory diagram showing an example of the flow of the electronic medical record deletion process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 107] FIG. 106 is an explanatory diagram showing an example of the flow of the electronic medical record deletion process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 108] 1 is an explanatory diagram showing a schematic image of the flow of processing of the main parts in the deletion process of electronic medical records using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 109]1 is an explanatory diagram showing a part of an example of the flow of an electronic medical record update process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment.

[0023] FIG. [Figure 110] FIG. 109 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record update process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 111] 110 showing an example of the flow of the electronic medical record update process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. [Figure 112] FIG. 111 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record update process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 113] FIG. 112 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record update process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 114] FIG. 113 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record update process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 115] FIG. 114 is an explanatory diagram showing a continuation of an example of the flow of the electronic medical record update process using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 116] FIG. 10 is an explanatory diagram showing an example of the flow of a periodic consistency check process for saved data using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. [Figure 117] 1 is an explanatory diagram showing a schematic image of the flow of the process of periodically checking the consistency of saved data using the real-time save / restore type electronic medical record data guard service providing system of the first embodiment. FIG. DETAILED DESCRIPTION OF THE INVENTION

[0052] Before describing the embodiments, the circumstances under which the present invention was derived and the effects of the present invention will be described.

[0053] As mentioned above, cyber attacks (destruction, etc.) using ransomware and other methods on electronic medical record data managed by electronic medical record systems are becoming a problem. Currently, there are around 50 vendors (sellers) of electronic medical record systems, including several large and smaller companies, but these systems are not interconnected. As a result, medical institutions using different electronic medical record systems cannot share electronic medical record data, and they are unable to jointly build defense systems against cyber attacks on electronic medical record data.

[0054] Managing electronic medical record data using blockchain presents the following challenges:

[0055] (Issue 1) Restrictions on data management due to legal regulations from the perspective of personal information protection In general, it is difficult to construct a blockchain (especially a public chain, which is an open blockchain) in such a way that the chain between blocks can be cut. For this reason, if data is recorded on a blockchain, it becomes difficult to erase (or delete) that data when it becomes necessary. Electronic medical record data contains personal information, but there are legal restrictions on the management of personal information from the perspective of personal information protection. For this reason, there are many restrictions on the management of electronic medical record data in order to protect personal information.

[0056] (Issue 2) Restrictions on the amount of information that can be managed due to the data capacity of blocks in blockchain Furthermore, in a blockchain, the data capacity of the blocks that serve as the data management area is small, limiting the amount of information that can be managed. For example, in the case of electronic medical record data, the medical records that make up the main body of the electronic medical record data have a data volume that is smaller than the data volume of the block, so they can be managed within the block, but the data volume of the numerous photographs (X-ray information, etc.) that accompany the medical record is larger than the data volume of the block. For this reason, it is difficult to combine the medical records that make up the main body of the electronic medical record data and the information on the medical record itself, such as the medical records, into one and manage it on a blockchain.

[0057] (Issue 3) Concerns about information leakage due to cryptanalysis using quantum computers Furthermore, even if a system for managing electronic medical record data is constructed using a closed blockchain such as a private chain to enable the chain between blocks to be cut, there is a risk that the private key will be analyzed by public key analysis using a quantum computer, resulting in the risk of information leakage.

[0058] (Challenge 4) Destructive attacks on nodes Furthermore, if the node configuration of a private chain is leaked, a destructive attack on the node may occur. A single node is easily destroyed.

[0059] Therefore, the inventors of this invention have repeatedly considered and examined ways to solve the above-mentioned problems with electronic medical record data, which requires real-time data preservation, based on the "(batch data preservation type) digital asset guard service provision system."

[0060] The "(batch data preservation type) digital asset guard service provision system" encrypts and secretly distributes the electronic data to be preserved, dividing it into multiple file data, and then uses a dedicated file management function to distribute and record each file data (divided into multiple pieces by encryption and secretly distributing it) across multiple nodes (for example, by evacuation to countries around the world in overseas cloud regions), and is configured to manage index information for the file data distributed and recorded across multiple nodes in the blockchain.

[0061] In order to construct an electronic medical record data guard service provision system that can perform the data preservation processing currently performed in batches in the "(batch data preservation type) digital asset guard service provision system" in real time for electronic medical record data, the inventors considered implementing a configuration that can address the above-mentioned issues as follows.

[0062] (Countermeasures for issue 1) As a countermeasure to the above-mentioned problem 1, the inventors of the present invention have devised a method of turning data to be preserved into fragmented meaningless information by encrypting and secret sharing the data. Furthermore, each time each piece of file data that has become fragmented meaningless information by encryption and secret sharing is distributed and recorded on multiple nodes, index information of the file data is recorded on a blockchain to manage the history, and by distributively recording the file data on the nodes, when the file data recorded on the nodes is updated, predetermined old file data that may be deemed unnecessary can be (periodically) deleted based on the index information of the old file data that is managed in history.

[0063] (Measures for issue 2) Furthermore, as a countermeasure to the above-mentioned problem 2, the inventors have considered managing medical records, which form the main body of data in electronic medical records and whose data volume is smaller than the data capacity size of the block, using a blockchain, and preserving the sub-information of numerous photographs (X-ray information, etc.) accompanying medical records, which have a data volume larger than the data capacity size of the block, using a file management function similar to the function for distributing and recording large file data in the "(batch data preservation type) digital asset guard service provision system."

[0064] (Measures for issue 3) Furthermore, as a countermeasure to the above-mentioned issue 3, the inventors have decided to use a method for the electronic medical record data guard service that requires a "two-way agreement" similar to the "password method" (a method in which the data processing environments are separated, and the combination of the keys and parameters for decryption and restoration used in one system (the customer side) and the keys and parameters for decryption and restoration used in the system on the other side (the digital asset guard service operator / manager side, such as a consortium) is compatible (here, for convenience, referred to as the "first two-way agreement")), which is the basic concept of the "(batch data preservation type) digital asset guard service provision system." This will prevent the original preserved data from being analyzed by a malicious third party, even if the system environment on either the customer side or the electronic medical record data guard service operator / manager side is independently contaminated by a malicious third party.

[0065] (Measures for issue 4) Furthermore, as a countermeasure to the above-mentioned problem 4, the inventors of the present invention have decentralized the data to be preserved using a file management function similar to that of the "(batch data preservation type) digital asset guard service provision system" and recorded in a distributed manner at each node, and sorted the multiple file data that are divided by encryption and secret sharing to be distributedly recorded into multiple preservation points in a black box environment, and managed the multiple sorted preservation points in a black box environment. Even when a cloud is used as the preservation destination node that constitutes the preservation point of the file data, the inventors have considered that by using a multi-cloud or other method, multiple preservation points can be used to distribute the risk of data destruction and strengthen resistance to cryptanalysis by quantum computers.

[0066] The inventors have conceived of an electronic medical record data guard service provision system that is basically based on the processing of the "(batch data preservation type) digital asset guard service provision system," but which, in order to accommodate electronic medical record data that requires real-time data preservation, would extend the processing of the system on the side of the (batch data preservation type) digital asset guard service operator's side for the customer (patient), so that the "(data preservation) service user responsible person (doctor)" would act on behalf of the electronic medical record data guard service operator's side and become the other party to the two-way agreement with the customer (patient) when performing data evacuation (sorting of individual file data fragmented by encryption and secret distribution into preservation points, and distributive recording of the sorted preservation points) and restoration (decryption and integration of distributedly recorded file data) processing through a "second bilateral agreement" (i.e., the authority of the digital asset guard service operator in the "(batch data preservation type) digital asset guard service provision system" would be transferred to the doctor).

[0067] Furthermore, the inventors have devised two basic data preservation methods for real-time electronic medical record data preservation: a "blockchain-based" data preservation method for preserving medical records, which form the main body of the medical record and whose data volume is smaller than the data capacity size of the block, and a "blockchain sub" data preservation method for preserving sub-information such as numerous photographs (e.g., X-ray information) accompanying medical records, whose data volume is larger than the data capacity size of the block. Furthermore, as an expanded data preservation method, they have devised a hybrid data preservation method that differs in the file data preservation structure or file data preservation capacity for each data preservation method.

[0068] Regarding the "blockchain-based" data preservation method, we considered implementing a file management function in the blockchain on the electronic medical record data guard service operator's side, and configuring the smart contract of the system on the electronic medical record data guard service operator's side to have a file management function. Regarding the "blockchain sub" type data preservation method, the blockchain does not have a file management function, and we considered having the blockchain and file management functions configured completely independently.

[0069] The inventors also conceived the idea of ​​splitting the electronic medical record data to be protected into multiple file data through encryption and secret sharing via "doctor-side application software (provided by the electronic medical record data guard service operator / manager)." Because electronic medical record data contains personal patient information, the encryption and secret sharing process of the electronic medical record data itself is essentially a process that should be performed by the patient. Meanwhile, the multiple file data split by encrypting and secret sharing the electronic medical record data to be protected are managed by the "file management function of the electronic medical record data guard service operator / manager's system" (which, like the "(batch data preservation type) digital asset guard service provider system," primarily provides data preservation services and manages multiple file data (split by encryption and secret sharing of electronic medical record data) sent from the client side). For this reason, the inventors of this case came up with the idea that although the data management area of ​​the system on the side of the electronic medical record data guard service operator is an area that is normally managed by the doctor, the "doctor's application software (provided by the electronic medical record data guard service operator)" can auxiliary process the processing that should be performed by the patient (encryption of electronic medical record data and secret distribution processing). Furthermore, the inventor of this case considered it desirable that the "doctor's application software (provided by the Electronic Medical Record Data Guard Service Administrator)" and the "file management function of the Electronic Medical Record Data Guard Service Administrator's system" be created and provided by different vendors. The inventor also considered linking the "doctor's application software (provided by the electronic medical record data guard service operator)" to the "electronic medical record control application software (for the electronic medical record system) (provided to doctors by each vendor)."

[0070] In addition, the inventors have conceived of a system in which a corresponding specified file management function in the system operated by the electronic medical record data guard service administrator distributes and records the fragmented file data (hereinafter referred to as "relevant file data") by encrypting and secretly distributing the relevant electronic medical record data on each node, and the blockchain on the system operated by the electronic medical record data guard service administrator manages index information regarding the preservation (distributed recording) of the relevant file data (in a "blockchain-based" data preservation method, in addition to the index information, also the relevant file data). In addition, with the "blockchain sub" type data preservation method, we considered preserving (distributed recording) the relevant file data on a node separate from the blockchain on the electronic medical record data guard service operator's side. In addition, we have considered making it possible to preserve (distributedly record) additional file data for the relevant file data. In addition, with regard to the blockchain and file management functions that make up the data preservation method for preserving electronic medical record data in real time, we have considered making it possible to configure physical nodes and management methods in a variety of ways, including multi-cloud.

[0071] The inventors also envisioned a system in which the "doctor's application software (provided by the electronic medical record data guard service operator)" would receive patient information (patient ID information: patient ID, patient keys) through interactions between the "patient's application software" on the patient's smartphone and the "patient's application software for communication with doctors" and "doctor's application software for communication with patients," which will be described below, and would then be able to encrypt the patient's electronic medical record data and perform secret distribution processing on behalf of the patient. Furthermore, the inventors have considered making it possible for the "doctor's application software (provided by the electronic medical record data guard service operator / manager)" to further perform approval processing (for preserving and restoring the relevant file data) separate from processing on behalf of the patient (encryption and secret distribution processing of the patient's electronic medical record data) as a sub-function of the electronic medical record data guard service operator / manager's system (when connected to the "doctor's application software for communication with patients").

[0072] The inventors also considered making the "application software for patient-doctor communication" have the functionality to link the patient login ID and patient ID authenticated by an external authentication company, create patient ID information (patient ID, patient keys), and manage blockchain addresses and various information related to patient ID information (My Number, health insurance card number). In addition, the inventor of this invention considered that the "application software for doctor-patient communication" should have the functions of linking doctor login IDs to doctor IDs, managing doctor login IDs, creating doctor ID information (doctor IDs, doctor keys), and managing various information related to doctor ID information (master information such as the doctor's affiliated hospital and doctor number).

[0073] The inventors also considered configuring the "application software for communication between patients and doctors" and the "application software for communication between doctors and patients" as separate systems created by different companies, with the services provided by both pieces of software, such as the creation and processing of ID information, being independent of each other. The inventors also considered configuring the "application software for communication between the patient and the doctor" and the "application software for communication between the doctor and the patient" so that each side notifies the other that a specified process has been performed on the patient side and the doctor side. In addition, the inventors of this invention considered that the sub-functions of the electronic medical record data guard service operator in the "application software for communication with patients on the doctor's side" and the "application software for the doctor's side (provided by the electronic medical record data guard service operator)" should be integrated in some parts of the processing (such as approving transactions for retrieving (reading) index information for saving and restoring the relevant file data).

[0074] Common Features The inventors of the present invention have conceived of providing a function for performing the following processing as a common function for preserving electronic medical record data in real time.

[0075] (Application for service use) The patient logs in to the system of the patient's ID management company (which is assumed to be a company that serves as the patient's system contact point and manages personal user login IDs (linked to My Number, health insurance card numbers, etc.)) and the "patient-side application software for communication with doctors" via the "patient-side application software for communication with doctors" on the patient's smartphone. The patient then applies to the patient ID management company's system for use of the patient ID information provision service. The patient ID management company provides the patient's personal identification information and authentication information, such as a password, to an external personal authentication system via the "patient-side application software for communication with doctors." After the patient's KYC (identity verification) is completed in the patient ID management company's system (using the external personal authentication system), the patient receives patient ID information, such as a patient ID (ideally linked to health insurance card numbers, My Number information, etc.) and decryption keys to be used by the patient, from the patient ID management company's system via the "patient-side application software for communication with doctors."

[0076] (Patient ID information) Patient ID information can be set as shared patient ID information or individual patient ID information. Individual patient ID information can be set independently by each medical institution. Shared patient ID information can be set so that it can be shared between medical institutions. From the perspective of the hassle of management for patients, it is considered desirable to unify patient ID information into shared patient ID information, as each individual patient ID information unit has a different key, making key management complicated.

[0077] Patient ID information (patient ID, patient keys) will be linked to personal identification information such as My Number and health insurance card number and a blockchain address (for index information).The blockchain address will then be converted using black box processing or other methods to become the management ID for the file data.

[0078] Patient ID information (patient ID, patient keys) can be managed by multiple "patient ID management companies" because individuals are identified by linked personal identification information such as My Number and health insurance card number. Individual patient ID information is set separately by each medical institution, and multiple patient IDs can exist for one patient, but shared patient ID information is set so that it can be shared between medical institutions, and so only one patient ID exists for one patient. In addition, checks to maintain consistency in patient ID information managed by multiple "patient ID management companies" for a single patient will be carried out using personal identification information such as My Number and health insurance card number.

[0079] (Electronic medical record data) Electronic medical record data is information that brings together the information in the medical record itself (medical records), as well as sub-information such as data on images and photographs such as X-rays, and clinical information, and is the unit of information management in electronic medical record systems (which can be replaced with existing electronic medical record systems). The information in the main medical record and each sub-information that make up the electronic medical record information can be managed separately based on patient ID information, and the management format for the information in the main medical record and each sub-information can be selected when setting up the shared data format (described below).

[0080] Electronic medical record data is associated with a management number that links with patient ID information, and the electronic medical record data itself is encrypted and split (into multiple file data) by the "doctor's application software (provided by the electronic medical record data guard service operator / manager)" at the medical institution, and sent to the system (file management function) on the electronic medical record data guard service operator / manager's side. The encryption and secret sharing process for electronic medical record data is carried out in the same way as the encryption and secret sharing process in the "(batch data integrity type) digital asset guard service provider system."

[0081] (index information) The blockchain index information is encrypted using programs such as smart contracts and server application software (hereinafter referred to as "smart contracts, etc.") when the electronic medical record data (file data that has been fragmented through encryption and secret distribution and sorted into multiple conservation points) sent to the system (file management function) of the electronic medical record data guard service operator / administrator is distributed and recorded (on multiple physical nodes) in the file management function, and logic that can only be decrypted by the encryption function (smart contract, etc.) is built into the smart contract, etc. The file data, whose index information (such as the actual file name and the node where it is stored) is managed in the blockchain, is sorted into multiple conservation points that make up the base file data group after at least encryption and secret distribution, and multiple copies (original or duplicate) of each file data are copied and recorded in a distributed manner on multiple nodes.

[0082] (tamper check, defense against data attacks) For each file data (distributedly recorded on nodes) for which index information is managed, the consistency of the hash value is checked periodically (for example, every 6 hours), and if there is an inconsistency in the hash value, it is determined that the corresponding file data has been tampered with or corrupted. In such cases, a smart contract for tamper checking (a smart contract for file data integrity checking and recovery, described below) will copy the contents of another normal file data (which is recorded in a distributed manner on nodes and whose index information is managed in the blockchain as file data of the same (distributed file management) group) and automatically restore it, thereby protecting against data destruction attacks.

[0083] In addition, some nodes that manage (distributedly record) the file data in the same (distributed file management) group are normally kept disconnected from communication via network lines, etc., and are only connected at certain times, thereby preventing them from being simply attacked.

[0084] Even if the secret-shared file data that is distributed and recorded on the nodes of one of multiple (distributed file management) groups is leaked, the file data will be fragmented into meaningless data by secret sharing using a polynomial sharing method such as the Shamir method. Moreover, each fragmented file data is sorted into multiple conservation points and associated with the (distributed file management) group corresponding to the sorted conservation point. For this reason, it is considered almost impossible to analyze and restore the original electronic medical record data from only the file data that is distributed and recorded in that one (distributed file management) group.

[0085] When a customer's key information is stolen, a new key is generated, the file data is regenerated using the new key, and the old information (file data, key) is forcibly erased (deleted).

[0086] Downstream processing in the "Electronic Medical Record Data Guard Service Provision System" (processing from the Electronic Medical Record Data Guard Service Administrator to the doctor) The inventors of this invention conceived a configuration in which the "application software for communication between patients and doctors" and the "application software for communication between doctors and patients" could exchange information with each other via an interface smart contract. When a doctor receives the electronic medical record data of a customer (patient) (the data is maintained by the system (file management function) of the electronic medical record data guard service administrator), for example, the doctor logs in to the "doctor's application software for communication with patients" via the "doctor's application software (provided by the electronic medical record data guard service administrator)." The doctor then inputs the patient's ID number (patient ID) into the "doctor's application software (provided by the electronic medical record data guard service administrator)" (by reading the patient's QR Code (registered trademark) displayed on the "patient's application software" and obtained in the "doctor's application software for communication with patients" via the interface smart contract), thereby receiving the patient ID information. At the same time, the patient enters the medical institution's ID number or the doctor's ID number (doctor ID) into the "patient's application software" on their smartphone (by reading the doctor's QR code (registered trademark) displayed on the "doctor's application software (provided by the electronic medical record data guard service operator)" and obtained in the "patient's application software for communication with the doctor" via the interface smart contract) and receives the doctor ID information. Additionally, the system (file management function) on the EMR Data Guard service administrator's side will communicate with the doctor via the "doctor's application software (provided by the EMR Data Guard service administrator)" which is connected to the "doctor's application software for communication with patients." At this time, the "doctor's application software for communication with patients" will match the patient information and doctor information obtained via the interface smart contract.

[0087] A "blockchain-based" method for receiving electronic medical record data The inventors of this invention have conceived the idea that when electronic medical record data (the medical records that form the core of the data) is evacuated in a "blockchain-based" format, for example, the electronic medical record data of the customer (patient) is divided by encryption and secret distribution, and file data sorted into multiple conservation points is distributed (distributedly recorded) to virtual nodes in the blockchain, while when receiving electronic medical record data from file data evacuated in a "blockchain-based" format, the index information of the allocated (distributedly recorded) file data is read from the blockchain, and a transaction to extract (read) the index information recorded in the blockchain is approved. Specifically, the "patient-side application software for communication with doctors" sends the transaction (retrieval (reading) of index information) information to the "patient-side application software." The patient then approves the transaction (reading of index information) using the private key recorded by the patient in the "patient-side application software," and the transaction is returned to the "patient-side application software for communication with doctors."

[0088] Once the transaction is approved, the system (file management function) on the electronic medical record data guard service operator's side will extract the file data recorded in the virtual node of the blockchain based on the index information read from the blockchain, and transfer the extracted file data to the "doctor's application software (provided by the electronic medical record data guard service operator's side)" via the "doctor's application software for patient communication." When a patient approves a transaction using a private key, there are several possible methods, such as approval using the private key via the "patient application software" on the customer's (patient's) smartphone or a hardware wallet, or a method in which the custodian manages the private key based on the customer's (patient's) ID and approves transactions using the private key on their behalf.

[0089] "Blockchain sub" type electronic medical record data reception method When evacuating electronic medical record data in a "blockchain sub" type, the inventors considered, for example, to encrypt the electronic medical record data of the client (patient) and distribute the file data, which has been sorted into multiple protection points, in a distributed manner on the system (file management function) of the electronic medical record data guard service operator, and record the index information of the distributedly managed file data in the blockchain in a similar manner to the "(batch data preservation type) digital asset guard service provision system" that the inventors have already derived separately. For this reason, when receiving electronic medical record data from file data that has been saved in the "blockchain sub" type, we have considered reading the index information in the system (file management function) on the side of the electronic medical record data guard service operator in the same way as the "(batch data preservation type) digital asset guard service provision system," returning the file data to a format that can be read from the decentralized management (decentralized recording) node, extracting and collecting the file, and after combining it, transferring it to the "doctor's application software (provided by the electronic medical record data guard service operator)." Furthermore, the instruction to carry out this processing will be given by the "doctor's application software for patient communication" receiving approval information for the transaction of retrieving (reading) index information from the "doctor's application software (provided by the electronic medical record data guard service operator / manager)," and the system (file management function) on the electronic medical record data guard service operator / manager's side will be put into operation.

[0090] The inventors of the present invention have also devised the following method for the above-mentioned approval process. When evacuation of electronic medical record data occurs, the system (file management function) on the operator side of the Electronic Medical Record Data Guard Service performs secondary data conversion on the sent file data. This secondary data conversion is performed using the doctor's encryption processing key (half key) and a key (half key) for sorting the multiple file data fragmented by encryption and secret sharing into multiple conservation points in a black box environment, and for approving transactions for distributed recording at the multiple sorted conservation points.

[0091] The two keys for this secondary data conversion are managed by the electronic medical record data guard service operator, but when the "doctor's application software (provided by the electronic medical record data guard service operator)" requests the reading of index information to receive electronic medical record data from the saved file data, the "doctor's application software for patient communication" confirms the doctor's ID (multi-factor) and uses the doctor's key linked to the doctor's ID on the electronic medical record data guard service operator's side to approve the transaction (reading of index information) on behalf of the doctor.

[0092] In addition, approval of transactions (reading of index information) using this key may be a modified multi-signature that combines a key linked to the patient's ID (half key; in some cases it is also possible to set a half key for the index information) and a key managed by the electronic medical record data guard service operator. The key managed by the Electronic Medical Record Data Guard Service operator is linked to the patient login ID information when the patient logs in to the "patient-side application software for communication with doctors," and when the doctor approves the Electronic Medical Record Data Guard Service operator's "doctor-side application software for communication with patients (smart contract)" separately via the "doctor-side application software (provided by the Electronic Medical Record Data Guard Service operator)," the key managed by the Electronic Medical Record Data Guard Service operator is called up and combined with the key linked to the patient's ID information to approve the request.

[0093] When one half of the patient's key (half key) managed by the Electronic Medical Record Data Guard Service operator is taken out and approval is given using the private key for the data read (read) transaction (reading of index information) from the patient, a second approval (the other half key) is given as a multi-signature. This allows the "doctor's application software (smart contract) for patient communication" to read the data (index information) from the blockchain, decrypt the index information internally (convert using black box processing, etc.), recognize the node where the file data is stored, retrieve the file data from the node where it is stored, combine (integrate) it, and transfer it to the "doctor's application software (provided by the Electronic Medical Record Data Guard Service operator)."

[0094] In the "doctor's application software (provided by the electronic medical record data guard service administrator)," multiple file data fragmented by secret sharing are decrypted, but the decrypted file data itself is still encrypted with the patient's key (and possibly the doctor's half-key). For this reason, the doctor must approve the customer's decryption key in the "doctor's application software (provided by the electronic medical record data guard service administrator)" (for example, the "patient's application software" on the customer's (patient's) smartphone displays the decryption key barcode, and the "doctor's application software (provided by the electronic medical record data guard service administrator)" reads the decryption key barcode and decrypts it; or, when the patient logs in to the "patient's application software for doctor communication" and the doctor logs in to the "doctor's application software for patient communication," the "doctor's application software for patient communication (smart contract)" temporarily manages and decrypts the patient's decryption key via the interface smart contract). This allows the customer's (patient's) electronic medical record data to be restored. The restored electronic medical record data of the customer (patient) is loaded into each "electronic medical record control application software (for the electronic medical record system) (provided to doctors by each vendor)" so that the contents can be displayed. Furthermore, even if the doctor or the "electronic medical record control application software (for the electronic medical record system) (provided to doctors by each vendor)" changes, it is believed that the loaded information can be used without any problems by using a shared data format (described below).

[0095] Upstream processing in the "Electronic Medical Record Data Guard Service Provision System" (processing from the doctor side to the Electronic Medical Record Data Guard Service Administrator side) The patient's electronic medical record data is encrypted by calling up the encryption key corresponding to the patient's ID (multi-signature encryption is also possible, combining the patient's key as a half key with the doctor's half key) in the ``doctor's application software (provided by the electronic medical record data guard service operator)'' which is connected to the ``electronic medical record control application software (for the electronic medical record system) (provided to the doctor by each vendor)'' on the doctor's side, which performs pre-processing, and then the secret distribution process is performed. The "doctor's application software (provided by the Electronic Medical Record Data Guard Service operator)" passes multiple file data that has been encrypted and secret-sharing processed, fragmented, and altered into meaningless data, and sorted into multiple conservation points, to the Electronic Medical Record Data Guard Service operator's system (file management function).At that time, the file data is further subjected to secondary data conversion (performed by the Electronic Medical Record Data Guard Service operator's black box processing, etc.) in the Electronic Medical Record Data Guard Service operator's system (file management function) using a smart contract, etc. for receiving file data on the Electronic Medical Record Data Guard Service operator's side.

[0096] A blockchain-based method for evacuation of electronic medical record data When evacuating electronic medical record data in a "blockchain-based" model, the inventors of this invention have envisioned that the file data of the customer (patient) that has been divided by encryption and secret distribution and sorted into multiple conservation points is distributed (distributed recording) to the nodes of the blockchain, and index information for that file data is recorded in the blockchain. However, with regard to approval of the transaction that records the index information in the blockchain, the "application software for communication with doctors on the patient's side" sends the transaction information to the "application software for communication with doctors on the patient's side," and the patient approves the transaction (recording of index information) using the private key recorded by the patient in the "application software for communication with doctors," and then sends a reply to the "application software for communication with doctors on the patient's side."

[0097] Once the transaction is approved, the system (file management function) on the Electronic Medical Record Data Guard Service operator side distributes (distributed recording) the file data, which has been divided by encrypting and secretly distributing the electronic medical record data of the customer (patient) and sorted into multiple conservation points, to the virtual nodes of the blockchain, and records index information about that file data on the blockchain. When a patient approves a transaction using a private key, there are several possible methods, such as approval using the private key via the "patient application software" on the customer's (patient's) smartphone or a hardware wallet, or a method in which the custodian manages the private key based on the customer's (patient's) ID and approves transactions using the private key on their behalf.

[0098] "Blockchain sub" type electronic medical record data evacuation method The electronic medical record data of the customer (patient) is encrypted and secretly distributed, and the file data sorted into multiple protection points is managed in a distributed manner by the system (file management function) of the electronic medical record data guard service operator. However, the index information of the distributedly managed file data is recorded on the blockchain in a similar manner to the "(batch data preservation type) digital asset guard service provision system" that the inventor has already derived separately. The instructions for this processing are given by the "doctor's application software for communication with patients" receiving approval information from the "doctor's application software (provided by the electronic medical record data guard service operator / manager)," causing the system (file management function) on the electronic medical record data guard service operator / manager's side to operate.

[0099] Regarding the above approval process, the following method was also considered. The system (file management function) on the administrator side of the Electronic Medical Record Data Guard service will perform secondary data conversion on the file data sent. After this secondary data conversion, key authentication (multi-signature using the customer's half key is also possible) will be performed to approve the processing transaction for recording the index information. This key is managed by the electronic medical record data guard service operator, but when an update (backup and deletion) processing request is made from the "doctor's application software (provided by the electronic medical record data guard service operator)", the "doctor's application software for patient communication" will confirm the doctor's ID (multi-factor) and, using the doctor's key linked to the doctor's ID, the electronic medical record data guard service operator can approve the transaction (recording of index information) on behalf of the doctor. Approval for transactions using these keys could be based primarily on the patient's ID in the early stages of the electronic medical record data evacuation process, with only that key, or based primarily on the doctor's ID in the later stages of the data evacuation process, with only that key. Alternatively, the entire data evacuation process could be a modified multi-signature that combines a key linked to the patient's ID and a key (managed by) the electronic medical record data guard service administrator (doctor). In this case, the index key managed by the Electronic Medical Record Data Guard service operator is linked to the patient login ID information when the patient logs in to the "patient-side application software for communication with doctors," and when the doctor approves the Electronic Medical Record Data Guard service operator's "doctor-side application software for communication with patients (smart contract)" via a separate "doctor-side application software (provided by the Electronic Medical Record Data Guard service operator)," the key managed by the Electronic Medical Record Data Guard service operator is called up and combined with the key linked to the patient's ID to perform approval.

[0100] How to delete preserved data in the "Electronic Medical Record Data Guard Service System" In some cases, it may be necessary to delete the medical records that form the main body of data in the electronic medical record, as well as secondary information such as photographs that accompany the medical records. Therefore, for example, even if the index information recorded in the blockchain is configured to be unable to be deleted, each file managed based on the index information can be deleted. When restoring electronic medical record data between a patient and a doctor, only the most recent file data is used as the object of reading based on the index information. If restoration from backup file data is required, a request to retrieve the original file data is made to the electronic medical record data guard service administrator, and the retrieved original file data is restored by the patient and doctor. History management is performed so that the original file data remains as backup file data for at least one generation and is not erased.

[0101] When updating (saving and deleting) electronic medical record data, first, the file data (before the update) that is managed (distributedly recorded on physical nodes) is deleted based on the read index information. For this purpose, the index information is handed over to the file data deletion processing means on the electronic medical record data guard service operator's side. The file data deletion processing means on the electronic medical record data guard service operator's side prevents the deletion of a set number of generations of file data (distributedly recorded on physical nodes), such as the first generation, and for file data of previous generations (distributedly recorded on physical nodes), it identifies the relevant file data (distributedly recorded on physical nodes) based on the received index information and deletes them all at once. Furthermore, the updated file data is in a state where it does not need to be checked by the file data consistency check and recovery smart contract, which periodically checks consistency with the hash value of the index information.Then, only the file data consistency check and recovery smart contract can search for the latest index information, and only the latest file data corresponding to the preserved data based on the latest index information is automatically restored, while file data corresponding to the preserved data based on old index information can be deleted.

[0102] Periodic consistency check of backup file data As index information, in addition to managing file names, addresses, etc., it is possible to manage hash values ​​of saved file data, etc. The saved file data is copied multiple times and saved to nodes around the world that make up the distributed file management group. The file data integrity check and recovery smart contract on the electronic medical record data guard service operator side periodically checks whether the hash value of each saved file data matches the hash value of the index information managing the saved file data. If the checked hash value of the saved file data differs from the hash value of the index information managing the saved file data (i.e., the saved file data is corrupted), the saved file data is deleted and the file data recovery process is automatically performed by copying saved file data with a normal hash value. Even if all saved file data in a distributed file management group is in a destroyed state, the saved file data can be decrypted by adopting a secret sharing method based on a polynomial sharing method such as the Shamir method, which can decrypt the saved file data even if all files are not available. In addition, the file data consistency check and recovery smart contract periodically checks the consistency of the hash value of the index information when saving file data, so that only the most recent data is checked.

[0103] Link with existing electronic medical record systems to provide electronic medical record services Although the electronic medical record data itself can be preserved in a batch format as a backup using a "(batch data preservation type) digital asset guard service provision system," the electronic medical record data guard service provision system considered and considered by the present inventors allows the electronic medical record data itself to be preserved in real time. Furthermore, by having multiple preservation points, the risk of data destruction can be dispersed and resistance to cryptanalysis using quantum computers can be strengthened. In addition, it will become possible to share electronic medical record data between medical institutions, and with the patient's consent, electronic medical record data will be able to be referenced between medical institutions. The number of existing vendors (sellers and suppliers) of electronic medical record systems has expanded to around 50 companies, including a few major companies and smaller businesses.

[0104] Incidentally, "electronic medical record systems" are used by specific medical institutions, but the data format of the electronic medical records varies depending on the vendor. As a result, the data format of the electronic medical records at each medical institution using electronic medical record systems provided by different vendors is different. This makes it difficult to share electronic medical record data among multiple medical institutions, and it is difficult to make the electronic medical record data guard service considered and considered by the present inventors available to all medical institutions.

[0105] To solve this problem, the inventors of the present invention came up with the idea of ​​aggregating the data formats of each electronic medical record in the electronic medical record systems provided by each vendor and creating a unified shared data format for the electronic medical records to be preserved in the electronic medical record data guard service provision system. Then, when managing each electronic medical record data as unified shared data for each medical institution in the electronic medical record data guard service provision system, they came up with the idea of ​​converting the data into unified shared data using information (electronic medical record common information and electronic medical record specific information) and functions that are mapped to the unified shared data format and managing it as a data matrix. In addition, we considered making it possible for data items (electronic medical record-specific information) that cannot be absorbed (that cannot be set as common columns (electronic medical record common information) for mapping to a shared data format) to exist multiple times in other columns. Although it is possible to display only the information recorded as common information in the electronic medical record, we considered making it possible to select the display items of electronic medical record-specific information in the electronic medical record data on a hospital-by-hospital and doctor-by-doctor basis. This electronic medical record data is managed by an electronic medical record data guard service provision system that the inventors have considered and are considering, but the function of calling up the electronic medical record data is to restore it to the format of each electronic medical record in the electronic medical record system provided by each vendor, and it is thought that the electronic medical records restored to their own unique electronic medical record data format can be used in ``electronic medical record control application software (for electronic medical record systems) (provided to doctors by each vendor).'' In addition, when updating (saving and deleting) electronic medical record data, we considered converting the electronic medical record data recorded in the electronic medical record system's unique electronic medical record data format into electronic medical record data in a shared data format by mapping it to a unified shared data format (electronic medical record common information and electronic medical record specific information).

[0106] The inventor then combined the measures derived from the above-mentioned considerations and studies, as appropriate, taking into account various cases, and after further consideration and investigation, he has come up with a real-time evacuation and restoration type electronic medical record data guard service provision system that can preserve electronic medical record data linked to personal information in real time, which is in different data formats provided to each medical institution by different vendors, and that can strongly and efficiently protect important information such as confidential information and personal information from high-level cyber attacks and physical destruction, and can restore important information without it being stolen by third parties even if it is subjected to quantum computer cryptanalysis or EMP attack.

[0107] The real-time backup and restoration type electronic medical record data guard service provision system of the present invention is a real-time backup and restoration type electronic medical record data guard service provision system for protecting electronic medical record data from high-level cyber attacks, constructed with a distributed ledger in distributed ledger technology such as blockchain, and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, and at the same time, is a system that has a structure that allows electronic medical record management data to be shared with specific individuals by using open technology, and is constructed with multiple planets (a unit that combines blockchains and distributed file management functions, etc., and forms one unit that makes up a system for providing services that implement distributed smart contracts, server applications, etc.) that are composed of a node group that combines nodes from multiple locations in different regions around the world, and is mainly composed of closed blockchains such as private or consortium types, and is composed of multiple chains that may include distributed ledgers, public blockchains, etc. the system comprises at least one distributed ledger structure, patient-side application software, an external patient authentication system, a patient ID management system, a patient-side doctor communication means or a smart contract (or server application) for patient-side doctor communication, and doctor-side application software, doctor-side patient communication means or a smart contract (or server application) for doctor-side patient communication, an operator-side file data real-time backup system, and an operator-side file data real-time retrieval system, all of which are provided by an operator of the electronic medical record data guard service; each of the nodes at each site is connected via a network to recording devices at multiple sites in different regions around the world to form a distributed file management group; the patient-side application software is provided in the patient's communication device and logs in to the patient ID management system and the patient-side doctor communication means or the smart contract (or server application) for patient-side doctor communication;The patient authentication system has a patient-side service application function for applying for the use of specified services related to the preservation of patients' electronic medical records, such as backup and restoration, and the external patient authentication system has a patient login ID, health insurance card number, and My Number etc. management means for managing patient login IDs, health insurance card numbers, My Number etc., and the patient ID management system has a patient ID, patient-side half key, and index information recording block chain address management means for managing patient IDs (to which health insurance card numbers, My Number information etc. are linked) linked to patient login IDs, respective half keys for patient-side encryption and decryption, and block chain addresses for index information recording; the patient-side application software includes: an authentication request means for requesting authentication by providing authentication information such as a patient login ID (personal identification information of the patient) and a password to the external patient authentication system when the patient applies for use of a predetermined service related to the preservation of the patient's electronic medical record via the patient-side application software; and a patient ID and half-key delivery means for delivering a patient ID and a patient-side half-key for encryption or decryption to the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application), after authentication by the external patient authentication system has been completed; When a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) receives the patient ID and patient-side encryption half-keys as patient ID information from the patient ID management system, and initially approves the evacuation transaction using the patient-side encryption half-key, and transfers the initially approved evacuation transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), while passing the patient-side encryption half-key to the doctor-side application software. When a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) has a function for initially approving the evacuation transaction.and a restoration transaction primary approval function that receives a patient ID and patient-side decryption half keys and the like as patient ID information from the patient ID management system, uses the patient-side decryption half key to give a primary approval to the restoration transaction, and transfers the primarily approved restoration transaction to the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication, while passing the patient-side decryption half key to the doctor-side application software. The doctor-side application software has an electronic medical record control application connection function that connects to electronic medical record control application software of a plurality of electronic medical record systems each having a different format, each of which is provided by a separate electronic medical record system provider, and when a patient has applied to use a patient electronic medical record evacuation service via the patient-side application software, receives the patient's electronic medical record data from the electronic medical record control application software of the electronic medical record system, and saves the data in a format specific to the electronic medical record system. a save process electronic medical record data common format conversion function that converts electronic medical record data in a format common to a plurality of electronic medical record systems each having a different format, into electronic medical record data in a common format that is common to a plurality of electronic medical record systems, each having a different format; a doctor-side login function that logs in to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application); when a patient logs in to the patient ID management system and the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) via the patient-side application software and the doctor logs in to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) via the doctor-side login function, a patient-side encryption or decryption half key is received from the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application);a two-way half key receiving function that receives a doctor-side encryption or decryption half key from the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication, and when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, an electronic medical record data encryption function during evacuation processing that encrypts the patient's electronic medical record data converted into a common format by the electronic medical record data common format conversion function during evacuation processing using the patient-side encryption half key and the doctor-side encryption half key received by the two-way half key receiving function, and when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, an electronic medical record data secret sharing and division function during evacuation processing that secret shares the patient's electronic medical record data encrypted by the electronic medical record data encryption function during evacuation processing and divides it into multiple file data, and when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, a file data upload function during evacuation processing that secret shares the electronic medical record data by the secret sharing and division function during evacuation processing and uploads each of the divided file data to a first temporary storage area; a file data integration function during restoration processing that, when a patient has applied to use the patient's electronic medical record restoration service via the patient-side application software, returns a group of multiple file data that have been secret shared and divided by the electronic medical record data secret sharing and division function during evacuation processing and sorted in association with conservation points, which have been received from the operator-side file data real-time retrieval system by the restoration file data receiving function of the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication and downloaded to a second temporary storage area, to an integrated state before secret sharing; and, when a patient has applied to use the patient's electronic medical record restoration service via the patient-side application software, returns the group of multiple file data to an integrated state before secret sharing by the file data integration function during restoration processing.an electronic medical chart data decryption function during restoration processing that decrypts file data encrypted by the electronic medical chart data encryption function during the saving processing into electronic medical chart data of the patient using the patient-side decryption half key and the doctor-side decryption half key received by the two-way half key receiving function; a second data erasure function that erases all file data that has been restored to the electronic medical chart data of the patient before saving by the electronic medical chart data decryption function during restoration processing and that has been secret shared and divided by the electronic medical chart data secret sharing and division function during the saving processing and that has been downloaded to the second temporary storage area; and when a patient applies for use of a patient electronic medical chart restoration service via the patient-side application software, reconverts the electronic medical chart data of the patient that has been decrypted by the electronic medical chart data decryption function during restoration processing and converted into a common format by the electronic medical chart data common format conversion function during the saving processing into a format specific to the control application software of the electronic medical chart before conversion, and and a function to reconvert the unique format at the time of restoration processing to pass it to the electronic medical record control application software of the electronic medical record system, and the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication has a doctor login ID, doctor ID or medical institution ID linked to the doctor login ID, patient ID, and each half key for doctor-side encryption and decryption linked to the patient ID, and has a doctor login ID, doctor ID or medical institution ID and doctor-side half key management function that passes the doctor-side encryption (or decryption) half key to the doctor-side application software, and when a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, the patient-side doctor communication means or the smart contract (or server application) for patient-side doctor communication has a final approval using the doctor-side encryption half key for the transaction of the evacuation processing that was primarily approved and transferred using the patient-side encryption half key, anda saving transaction final approval function for acquiring agreement information between the patient and the doctor or medical institution; and, when a patient has applied for the use of the patient's electronic medical record saving service via the patient-side application software, the electronic medical record data encryption function for saving the electronic medical record data uploaded to a first temporary storage area by the file data upload function for saving the electronic medical record data, and the confidential portion of the electronic medical record data for saving the electronic medical record data. a file data preservation point associating and sorting function at the time of evacuation processing, which associates each of the divided file data by a fragmentation and division function with a plurality of preservation points and sorts them; a file data preservation point information management function, which manages, in a black box environment, information on the preservation points for managing the file data sorted by the file data preservation point associating and sorting function at the time of evacuation processing; a file data for evacuation transfer function, which, when a patient applies for use of a patient electronic medical record evacuation service via the patient-side application software, transfers each of the file data sorted by the file data preservation point associating and sorted by a plurality of preservation points to the operation manager-side file data real-time evacuation system for each group of file data sorted by corresponding to each preservation point, when a patient applies for use of a patient electronic medical record restoration service via the patient-side application software, a restoration transaction final approval function that uses the doctor-side decryption half-key to give final approval to a restoration transaction that has been primarily approved and transferred using the patient-side decryption half-key by the doctor communication means or the patient-side smart contract (or server application) for communication with the doctor, and obtains agreement information between the patient and the doctor or medical institution regarding the restoration process of the patient's electronic medical record data that is the target of restoration; and a restoration file data receiving function that, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, receives from the administrator-side file data real-time retrieval system each group of file data that has been sorted in association with a plurality of conservation points and dispersedly saved, and downloads the file data to a second temporary storage area; and the administrator-side file data real-time saving system is provided on each planet,a save file data receiving means or a save file data receiving smart contract (or server application) having a function of receiving save file data transferred for each group of file data sorted in correspondence with each conservation point by the save file data transfer function of the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication; a save file data modifying means or a save file data modifying smart contract (or server application) provided on each planet and having a function of modifying the save file data received by the save file data receiving means or the save file data receiving smart contract (or server application); and a save transaction final approval function of the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication, a modified file data distribution and evacuation means or a modified file data distribution and evacuation smart contract (or server application) having a function of sorting each of the file data modified by the file data modification means for evacuation or the smart contract for evacuation file data (or server application) based on information agreed upon between the patient and the doctor or medical institution regarding the evacuation processing of target data by the file data conservation point association sorting function at the time of the evacuation processing and linked to information of the conservation point managed in a black box environment by the file data conservation point information management function, to a plurality of distributed file management groups constructed by each base node constituting the planet corresponding to the conservation point and recording devices of multiple bases connected to the base nodes via a network, and distributing and evacuating the allocated modified file data for each conservation point to each base node belonging to the distributed file group corresponding to the conservation point and recording devices of multiple bases connected to the base nodes via a network;The key information is comprised of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID, which is included in the agreement information between the patient and the doctor or medical institution regarding the evacuation process of the electronic medical record data to be evacuated for the patient, which is obtained by the evacuation transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication; the file name information of each of the modified file data that has been distributed and saved by each of the modified file data distribution and saving means or the modified file data distribution and saving smart contract (or server application) and that is linked to the information of the preservation point that has been sorted by the file data preservation point association sorting function during the evacuation process of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication and that is managed in a black box environment by the file data preservation point information management function; and the destination of each of the modified file data. an index information creation means or a smart contract (or a server application) for creating index information in a black box environment, the index information comprising configuration information of each of the distributed file management groups; an encrypted index information recording means or a smart contract (or a server application) for recording encrypted index information, the index information being created by the index information creation means or the smart contract (or the server application) in a black box environment, and the index information being recorded in a group of nodes at a specific location in the distributed ledger structure; and a first data erasure means for erasing each of the file data uploaded to the first temporary storage area by the file data upload function during the evacuation process of the doctor-side application software after the index information has been encrypted and recorded in the group of nodes at a specific location in the distributed ledger structure by the encrypted index information recording means or the smart contract (or the server application).and the operation manager-side file data real-time retrieval system is provided in each planet, and includes an encrypted index information reading means or an encrypted index information reading unit having a function of reading index information of a patient's modified file data, which is encrypted and recorded in a node group of a specific location in the distributed ledger structure, based on key information formed using predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID in agreement information between the patient and the doctor or medical institution regarding the restoration process of the electronic medical record data to be restored for the patient, which is obtained by the restoration transaction final approval function, for each group of file data linked to information of each of the maintenance points managed in a black box environment by the file data maintenance point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, in the planet corresponding to the maintenance point. an index information decryption means or a smart contract for decrypting index information (or a server application) having a function of decrypting the encrypted index information read by the encrypted index information reading means or the smart contract for reading encrypted index information (or the server application) in a black box environment; a distributed save destination node analysis means or a smart contract for analyzing distributed save destination node (or a server application) having a function of analyzing the nodes of a distributed file management group linked to all the maintenance points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the index information decryption means or the smart contract for decrypting index information (or the server application); andThe system comprises an altered file data extraction means or an altered file data extraction smart contract (or server application) having the function of extracting the patient's altered file data that has been saved in a distributed manner, a file data pre-alteration state restoration means or a file data pre-alteration state restoration smart contract (or server application) having the function of restoring the altered file data extracted by the altered file data extraction means or the altered file data extraction smart contract (or server application) to the state before the alteration, and a restoration file data transfer means or a restoration file data transfer smart contract (or server application) having the function of transferring the patient's restoration file data restored to the state before the alteration by the file data pre-alteration state restoration means or the file data pre-alteration state restoration smart contract (or server application) to the doctor's patient communication means or the doctor's patient communication smart contract (or server application).

[0108] As in the real-time save / restore type electronic medical record data guard service providing system of the present invention, the doctor-side application software is defined as having "an electronic medical record data common format conversion function during save processing, which, when a patient applies for use of the patient's electronic medical record save service via the patient-side application software, receives the patient's electronic medical record data from the electronic medical record control application software of the electronic medical record system and converts the electronic medical record data in a format specific to the electronic medical record system into electronic medical record data in a common format common to a plurality of electronic medical record systems, each of which has a different format," and "a function for converting the patient's ... from the electronic medical record control application software of the patient-side application software." If an application for use of the medical record restoration service is made, the system will be configured to have a "specific format reconversion function during restoration processing" which reconverts the patient's electronic medical record data, which has been decrypted by the electronic medical record data decryption function during restoration processing and converted to a common format by the electronic medical record data common format conversion function during backup processing, into a format specific to the control application software of the electronic medical record before conversion, and passes the patient's electronic medical record data, which has been reconverted into the specific format, to the electronic medical record control application software of the electronic medical record system, making it possible to back up and restore electronic medical record data linked to personal information which is provided to each medical institution by different vendors in different data formats.

[0109] Furthermore, as in the real-time evacuation / restoration type electronic medical record data guard service provision system of the present invention, if the doctor-side application software is configured to have "an electronic medical record data encryption function during evacuation processing, which, when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, encrypts the patient's electronic medical record data converted into a common format by the electronic medical record data common format conversion function during evacuation processing using the patient-side encryption half-key and the doctor-side encryption half-key received by the both-side half-key reception function," and "an electronic medical record data secret sharing and division function during evacuation processing, which, when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, secret shares the patient's electronic medical record data encrypted by the electronic medical record data encryption function during evacuation processing and divides it into multiple file data," then personal information can be rendered meaningless when the electronic medical record is evacuated, making it possible to manage electronic medical record data while complying with restrictions from the perspective of protecting personal information.

[0110] Furthermore, as in the real-time save / restore type electronic medical record data guard service providing system of the present invention, the patient-side means of communication with doctors or the smart contract (or server application) for patient-side communication with doctors may be defined as "a save transaction primary approval function which, when a patient applies for use of the patient's electronic medical record save service via the patient-side application software, receives a patient ID and patient-side encryption half-keys and the like as patient ID information from the patient ID management system, uses the patient-side encryption half-key to primarily approve the save processing transaction, and transfers the primarily approved save processing transaction to the doctor-side means of communication with patients or the smart contract (or server application) for doctor-side communication with patients, and passes the patient-side encryption half-key to the doctor-side application software," and "a real-time save / restore type electronic medical record data guard service providing system of the present invention, and further, and a restoration transaction primary approval function that receives the patient ID and patient-side decryption half keys, etc. as information, and uses the patient-side decryption half key to give primary approval to the restoration transaction, and transfers the primarily approved restoration transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and passes the patient-side decryption half key to the doctor-side application software. The doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) also has the following function: "When a patient applies for the use of the patient's electronic medical record evacuation service via the patient-side application software, the doctor-side patient communication means or the patient-side smart contract for patient communication (or server application) gives final approval to the evacuation transaction that was primarily approved and transferred using the patient-side encryption half key by the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application), andIf the system is configured with a "save transaction final approval function that obtains agreement information between the patient and the doctor or medical institution regarding the evacuation process of the patient's electronic medical record data to be evacuated," and "if the patient has applied to use the patient's electronic medical record restoration service via the patient-side application software, a restore transaction final approval function that uses the doctor-side decryption half-key to give final approval to the restoration process transaction that was initially approved and transferred using the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application), and obtains agreement information between the patient and the doctor or medical institution regarding the restoration process of the patient's electronic medical record data to be restored," it will be extremely difficult for malicious third parties to understand the content of the agreement information between the patient, doctor, and medical institution, and to decrypt and restore the preserved file data.

[0111] Furthermore, as in the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication may be defined as "a file data preservation point association sorting function at the time of backup processing, which associates and sorts each of the divided file data encrypted by the electronic medical record data encryption function at the time of backup processing, secret-shared by the electronic medical record data secret-shared and splitting function at the time of backup processing, and saves the data," and "a file data preservation point information management function that manages, in a black-box environment, information on the preservation points for managing the file data sorted by the file data preservation point association sorting function at the time of backup processing." By configuring the system to include a "data management function," and a "data transfer function for transfer, when a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, each file data sorted by the file data preservation point association function during evacuation processing to the operator-side file data real-time evacuation system for each group of file data sorted by each preservation point," even if file data saved to some preservation points is stolen and analyzed by a malicious third party, it becomes impossible to restore the original electronic medical record data unless file data saved to other preservation points is stolen and analyzed. Furthermore, by managing the information on the preservation points used to manage the file data sorted by the file data preservation point association function in a black-box environment, the electronic medical record data is encrypted and secret-shared, making it nearly impossible for a malicious third party to find the multiple preservation points for the sorted file data. This makes it possible to enhance resistance to cryptanalysis using quantum computers.

[0112] Furthermore, as in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, "the patient-side application software is provided in the patient's communication device, and has a patient-side service application function for logging in to the patient ID management system and the patient-to-doctor communication means or the patient-to-doctor communication smart contract (or server application) and applying for the use of predetermined services related to the preservation of the patient's electronic medical record, such as backup / restore," "the external patient authentication system has a patient login ID, health insurance card number, and My Number etc. management means for managing the patient login ID, health insurance card number, My Number etc.," and "the patient ID management system has a patient ID / patient-side half key / index information recording block chain address management means for managing the patient ID linked to the patient login ID (linked to the health insurance card number, My Number information etc.), the patient-side half keys for encryption and decryption, and the block chain address for recording index information, and a patient-side application software for the patient side. and a patient ID and half key delivery means for delivering a patient ID and a patient-side encryption or decryption half key to the patient-side communication means or the patient-side smart contract (or server application) for communication with a doctor after authentication by the external patient authentication system has been completed. "When a patient applies for use of a specified service related to the preservation of the patient's electronic medical record via the patient-side application software, the patient-side communication means or the patient-side smart contract (or server application) for communication with a doctor receives the patient ID and the patient-side encryption half key as patient ID information from the patient ID management system, and uses the patient-side encryption half key to initially approve the transaction of the evacuation process,and a save transaction primary approval function that transfers the transaction of the save process that has been primarily approved to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) and passes the patient-side encryption half-key to the doctor-side application software, and a restore transaction primary approval function that, when a patient applies for use of a patient's electronic medical record restoration service via the patient-side application software, receives a patient ID and patient-side decryption half-keys as patient ID information from the patient ID management system, uses the patient-side decryption half-key, and primarily approves the transaction of the restore process, and transfers the transaction of the restore process that has been primarily approved to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and passes the patient-side decryption half-key to the doctor-side application software. a doctor-side login function for logging in to the patient ID management system and the patient-side doctor-communication means or the patient-side smart contract for doctor-communication (or server application) via the patient-side application software, and a bilateral half-key receiving function for receiving a patient-side encryption or decryption half-key from the patient-side doctor-communication means or the patient-side smart contract for doctor-communication (or server application) and receiving a doctor-side encryption or decryption half-key from the doctor-side patient-communication means or the doctor-side smart contract for patient-communication (or server application) when a patient logs in to the patient ID management system and the patient-side doctor-communication means or the patient-side smart contract for doctor-communication (or server application) via the patient-side application software and a doctor logs in to the doctor-side patient-communication means or the doctor-side smart contract for patient-communication (or server application) via the doctor-side login function;The doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication manages the doctor login ID, the doctor ID or medical institution ID linked to the doctor login ID, the patient ID, and the respective half keys for doctor-side encryption and decryption linked to the patient ID, and passes the doctor-side encryption (or decryption) half key to the doctor-side application software. When a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, the doctor login ID, doctor ID or medical institution ID, and doctor-side half key management function uses the patient-side encryption half key to give final approval to the transaction of the evacuation process that was primarily approved and transferred by the patient-side doctor communication means or the patient-side smart contract (or server application) for communication with the doctor, using the patient-side encryption half key, and also provides final approval to the electronic medical record of the patient to be evacuated. If the system is configured to have a final approval function for the evacuation transaction that obtains agreement information from both the patient and the doctor or medical institution regarding the data evacuation process, and, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, a final approval function for the restoration process that uses the doctor-side decryption half-key to give final approval to the restoration process transaction that was initially approved and transferred using the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application), and obtains agreement information from both the patient and the doctor or medical institution regarding the restoration process of the patient's electronic medical record data that is to be restored, it will be possible to easily perform the process for obtaining agreement information from both the patient and the doctor / medical institution regarding the evacuation and restoration process of the patient's electronic medical record data that is to be evacuated in real time.

[0113] Furthermore, like the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, "a system that has a plurality of planets (a unit that combines blockchains and distributed file management functions, etc., and forms one unit that constitutes a system for providing services that implement distributed smart contracts, server applications, etc.) that are constructed with a plurality of planets that are made up of a node group that combines nodes at multiple locations in different regions around the world, is based on a closed blockchain such as a private or consortium type, has at least one distributed ledger structure that is made up of a plurality of chains that may include a distributed ledger group and a public blockchain, etc., and the nodes at each location connect to recording devices at multiple locations in different regions around the world. By configuring the system so that "a distributed file management group is constructed by connecting the data over a network," "the electronic medical record data to be evacuated is divided into multiple file data," and "each of the divided file data is distributed and evacuated to the nodes of each base belonging to the distributed file management group and to recording devices at multiple bases connected to the base nodes over a network," even if a node at one base belonging to the distributed file management group or a recording device connected to the node over a network is attacked by an EMP and the divided file data of the patient to be evacuated is lost, the nodes at other bases belonging to the distributed file management group or recording devices connected to the node over a network will be able to avoid the attack and preserve the file data.

[0114] Furthermore, like the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, the administrator-side file data real-time backup system may be configured as follows: "a backup file data receiving means or a backup file data receiving smart contract (or server application) that is provided on each planet and has a function to receive the backup file data that has been transferred for each group of file data that has been sorted in correspondence with each conservation point by the backup file data transfer function of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application)", "a backup file data modifying means or a backup file data modifying smart contract (or server application) that is provided on each planet and has a function to modify the backup file data received by the backup file data receiving means or the backup file data receiving smart contract (or server application)", The file data modification means for saving or the smart contract for modifying file data for saving (or the server application for modifying file data for saving) is provided in each planet, and based on the agreement information between the patient and the doctor or the medical institution regarding the evacuation processing of the patient's data to be evacuated, which is obtained by the evacuation transaction final approval function of the doctor's patient communication means or the smart contract for patient communication (or the server application for the doctor's patient communication), the file data is sorted by the file data preservation point correspondence sorting function during the evacuation processing and linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function, and each of the file data modified by the file data modification means for saving or the smart contract for modifying file data for saving (or the server application) is allocated to a plurality of the distributed file management groups constructed by the nodes of each base constituting the planet corresponding to the preservation point and the recording devices of multiple bases connected to the nodes of the base via a network, and the allocated modified file data is sorted by the file data preservation point correspondence sorting function during the evacuation processing and linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function, andIf a configuration is provided with a "modified file data distributed evacuation means or a smart contract (or server application) for distributed evacuation of modified file data" that has the function of distributing and evacuation to each base node belonging to the distributed file group corresponding to the conservation point and to recording devices at multiple bases connected to the base node via a network, it will be possible to evacuate patient file data while strengthening resistance to cyber attacks using quantum computers, as follows:

[0115] (X1) By modifying the file data for evacuation, which has been transferred by the file data for evacuation transfer function of the patient-side communication means or the smart contract (or server application) for evacuation file data modification, in groups of file data that have been sorted in correspondence with each conservation point, the file data to be evacuated becomes even more difficult to decipher. (X2) To determine to which of the multiple distributed file management groups, consisting of the nodes at multiple locations that make up a planet and the storage devices at multiple locations that are networked with the nodes at those locations, a malicious third party must understand the content of the agreement between the patient and the doctor or medical institution regarding the evacuation process of the patient's data, obtained through the final approval function of the evacuation transaction in the doctor's patient communication means or the doctor's smart contract (or server application) for patient communication. Furthermore, it is necessary to understand that the allocation destination and distributed evacuation destination of the modified file data distributed evacuation means or the modified file data distributed evacuation smart contract (or server application) are determined by the agreement between the patient and the doctor or medical institution regarding the evacuation process of the patient's data, obtained through the final approval function of the evacuation transaction in the doctor's patient communication means or the doctor's smart contract (or server application). However, such understanding is difficult. (X3) Furthermore, if the doctor's patient communication means or the doctor's patient communication smart contract (or server application) is equipped with a "file data preservation point association sorting function during evacuation processing" that associates and sorts file data into one of at least two preservation points for managing file data, even if file data saved to one preservation point is stolen and analyzed by a malicious third party, it will be impossible to restore the original electronic medical record data unless the file data saved to another preservation point is stolen and analyzed. Also, by providing a "file data preservation point information management function that manages in a black-box environment the information on the preservation points for managing the file data sorted by the file data preservation point association sorting function during evacuation processing," electronic medical record data will be encrypted and secretly distributed, making it nearly impossible for a malicious third party to find multiple preservation points for the sorted file data.

[0116] Furthermore, like the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, the file data real-time backup system on the administrator side can be implemented as follows: "key information consisting of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID, which is included in the agreement information between the patient and the doctor or medical institution regarding the backup processing of the electronic medical record data to be saved for the patient, which is obtained by the backup transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, and which is necessary for the backup of the electronic medical record data, and which has been distributed and saved by the respective modified file data distribution and saving means or the modified file data distribution and saving smart contract (or server application), and which has been sorted by the file data preservation point association sorting function at the time of the backup processing of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, and By configuring the system to include an index information creation means or a smart contract (or server application) for creating index information in a black box environment, which creates index information containing file name information for each modified file data linked to the information of the maintenance point managed in a black box environment by the file data maintenance point information management function, and configuration information for each distributed file management group to which each modified file data is allocated, and an encrypted index information recording means or a smart contract (or server application) for recording encrypted index information, which has the function of encrypting the index information created by the index information creation means or smart contract (or server application) in a black box environment and recording it in a group of nodes at a specific location in the distributed ledger structure, the system will be more resistant to cyber attacks using quantum computers and will be able to evacuate patient file data, as follows:

[0117] (X4) The index information created by the index information creation means or the smart contract (or server application) for creating index information is information necessary for decrypting data, but is encrypted by the encrypted index information recording means or the smart contract (or server application) for recording encrypted index information. Therefore, a malicious third party needs to decrypt the encrypted index information. (X5) Furthermore, in order for a malicious third party to decrypt the encrypted index information, the malicious third party must decipher the processing details used for the encryption. (X6) Index information is recorded in a group of nodes at a specific location in the distributed ledger structure, but the electronic medical record data guard service operator cannot grasp what kind of information it is because the information recorded in the group of nodes at the specific location is encrypted. A malicious third party needs to identify information that the electronic medical record data guard service operator cannot grasp as index information for the file data of a specified user (patient, doctor, or medical institution). For this reason, even with the use of a quantum computer, it will be even more impossible to decipher the original electronic medical record data from the saved file data. (X7) Furthermore, if the file name information of each modified file data included in the index information in the index information creation smart contract (or server application) and the configuration information of each distributed file management group to which each modified file data is allocated are defined as "file name information of each modified file data linked to the information of the conservation point sorted by the file data conservation point association sorting function during the save process and managed in a black box environment by the file data conservation point information management function, which are distributed and saved by each modified file data distributed save means or modified file data distributed save smart contract (or server application), and the configuration information of each distributed file management group to which each modified file data is allocated," then no information other than the information of the conservation point will be created in the index information. This makes it virtually impossible for a malicious third party to identify the index information of a user's file data for all conservation points. Therefore, even if a malicious third party uses a quantum computer, it will be nearly impossible to decipher the original electronic medical record data from the saved file data.

[0118] Furthermore, like the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, the administrator-side file data real-time retrieval system is configured as "an encrypted index information system provided in each planet, which has a function of reading index information of the patient's modified file data, which is encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, based on key information consisting of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID required for restoring the electronic medical record data in the agreement information between the patient and the doctor or medical institution regarding the restoration process of the electronic medical record data to be restored for the patient, which is obtained by the restoration transaction final approval function for each group of file data linked to the information of each of the preservation points managed in a black box environment by the file data preservation point information management function of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) in the planet corresponding to the preservation point. "an index information reading means or an encrypted index information reading smart contract (or server application)", "an index information decryption means or an index information decryption smart contract (or server application) having a function of decrypting the encrypted index information read by the encrypted index information reading means or the encrypted index information reading smart contract (or server application) in a black box environment", "a distributed save destination node analysis means or a distributed save destination node analysis smart contract (or server application) having a function of analyzing nodes of a distributed file management group linked to all conservation points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the index information decryption means or the index information decryption smart contract (or server application)", "from the nodes of the distributed file management group linked to all conservation points analyzed by the distributed save destination node analysis means or the distributed save destination node analysis smart contract (or server application),If the system is configured to have an altered file data extraction means or an altered file data extraction smart contract (or server application) having the function of extracting the patient's altered file data that has been saved in a distributed manner, and an "unaltered file data state restoration means or an unaltered file data state restoration smart contract (or server application) having the function of restoring the altered file data extracted by the altered file data extraction means or the altered file data extraction smart contract (or server application) to the state before the alteration," it will be possible to strengthen the resistance to cyber-attacks using quantum computers and restore the file data that the patient wishes to restore to the state before the alteration by the saved file data modification means or the saved file data modification smart contract (or server application), as follows:

[0119] (X8) The extraction of encrypted index information recorded in a group of nodes at a specific location in the distributed ledger structure via the encrypted index information reading means or the smart contract (or server application) for reading encrypted index information, the index information decryption means or the smart contract (or server application) for decrypting index information, the encrypted index information reading means or the smart contract (or server application) for reading encrypted index information, the index information decryption means or the smart contract (or server application) for decrypting index information, and the modified file data extraction means or the smart contract (or server application) for extracting modified file data is based on the agreement between the patient and the doctor or medical institution regarding the restoration process of the patient's data to be restored, which was obtained by the restoration transaction final approval function of the doctor's patient communication means or the doctor's patient communication smart contract (or server application). Therefore, a malicious third party needs to understand the content of the agreement between the patient and the doctor or medical institution regarding the restoration process of the patient's data to be restored, which was obtained by the restoration transaction final approval function. Furthermore, it is necessary to understand that the distribution destinations and distributed evacuation destinations of the modified file data distributed evacuation means or the modified file data distributed evacuation smart contract (or server application) are determined by the agreement information between the patient and the doctor or medical institution regarding the evacuation process of the patient's data to be evacuated, obtained by the doctor's means of communication with patients or the evacuation transaction final approval function of the doctor's smart contract (or server application) for communication with patients. However, this understanding is difficult. (X9) Furthermore, by defining the file name information of each modified file data included in the index information in the index information creation smart contract (or server application) and the configuration information of each distributed file management group to which each modified file data is allocated as "file name information of each modified file data linked to the information of the conservation point sorted by the file data conservation point association sorting function during the save process and managed in a black box environment by the file data conservation point information management function, which are distributed and saved by each of the modified file data distributed save means or the modified file data distributed save smart contract (or server application), and the configuration information of each distributed file management group to which each modified file data is allocated," no information other than the information of the conservation point is created in the index information. This makes it impossible for a malicious third party to identify the index information of a patient's file data for all conservation points. Therefore, even if a malicious third party uses a quantum computer, it will be nearly impossible to decipher the original electronic medical record data from the saved file data.

[0120] Furthermore, the real-time backup and restoration type electronic medical record data guard service providing system of the present invention preferably further comprises an administrator-side file data real-time deletion system, and when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, the patient-side communication means with doctor or the patient-side smart contract for doctor communication (or server application) receives the patient ID and patient-side encryption half-keys and the like as patient ID information from the patient ID management system, and uses the patient-side encryption half-keys to primarily approve the deletion transaction, and transfers the primarily approved deletion transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and also passes the patient-side encryption half-key to the doctor-side application software. and the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) further has a function of first approving a deletion transaction, and when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) uses a patient-side encryption half-key to give final approval to the deletion transaction that has been first approved and transferred by the patient-side doctor communication means or the doctor-side smart contract for patient communication (or server application) using a patient-side encryption half-key, and further has a function of final approval of the deletion transaction to obtain agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted for the patient, and the operation manager-side file data real-time deletion system is provided on each planet, and on the planet corresponding to the conservation point,and a deletion processing encrypted index information reading means or deletion processing encrypted index information reading means having a function of reading index information of modified file data of a patient that has been distributed and saved prior to a predetermined generation and that has been encrypted and recorded in a node group at a specific location in the distributed ledger structure, based on key information that uses predetermined information linked to the patient ID necessary for deleting electronic medical record data and predetermined information linked to the doctor ID or medical institution ID in agreement information between the patient and the doctor or medical institution regarding the deletion processing of the electronic medical record data to be deleted of the patient that is acquired by the deletion transaction final approval function, for each group of file data linked to information of each of the preservation points that are managed in a black box environment by the file data preservation point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication. a smart contract (or server application) for decrypting index information at the time of deletion, a smart contract (or server application) for decrypting index information at the time of deletion, having a function of decrypting the encrypted index information read by the smart contract (or server application) for reading encrypted index information at the time of deletion in a black box environment; a smart contract (or server application) for analyzing distributed backup destination nodes at the time of deletion, having a function of analyzing the nodes of the distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the smart contract (or server application) for decrypting index information at the time of deletion, andand a modified file data deleting means for deleting modified file data during deletion processing or a smart contract (or server application) for deleting modified file data during deletion processing, which has the function of deleting modified file data of patients of a predetermined generation or earlier that is saved in a distributed manner to nodes of a distributed file management group linked to all conservation points analyzed by the distributed save destination node analyzing means for deletion processing or the smart contract (or server application) for analyzing distributed save destination nodes for deletion processing.

[0121] Like the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, the patient-side means of communication with doctors or the smart contract (or server application) for patient-side communication with doctors has a "deletion transaction primary approval function, which, when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, receives the patient ID and patient-side encryption half-keys as patient ID information from the patient ID management system, uses the patient-side encryption half-keys to primarily approve the deletion transaction, and transfers the primarily approved deletion transaction to the doctor-side means of communication with patients or the smart contract (or server application) for doctor-side communication with patients, while also passing the patient-side encryption half-keys to the doctor-side application software." In addition, if the doctor's means of communication with patients or the doctor's smart contract (or server application) for communication with patients is configured to have a deletion transaction final approval function that, when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, will use the patient's half-key for encryption to initially approve and transfer the deletion transaction that was transferred using the patient's half-key for encryption, and will also obtain agreement between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted, it will be extremely difficult for malicious third parties to understand the content of the agreement between the patient and the doctor / medical institution.

[0122] Furthermore, as in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, "the patient-side application software is provided in the patient's communication device, and has a patient-side service application function for logging in to the patient ID management system and the patient-to-doctor communication means or the patient-to-doctor communication smart contract (or server application) and applying for the use of predetermined services related to the preservation of the patient's electronic medical record, such as backup / restore," "the external patient authentication system has a patient login ID, health insurance card number, and My Number etc. management means for managing the patient login ID, health insurance card number, My Number etc.," and "the patient ID management system has a patient ID / patient-side half key / index information recording block chain address management means for managing the patient ID linked to the patient login ID (linked to the health insurance card number, My Number information etc.), the patient-side half keys for encryption and decryption, and the block chain address for recording index information, and a patient-side application software for the patient side. and a patient ID and half key delivery means for delivering a patient ID and a patient-side encryption or decryption half key to the patient-side communication means or the patient-side smart contract (or server application) for communication with a doctor after authentication by the external patient authentication system has been completed. "When a patient applies for use of a specified service related to the preservation of a patient's electronic medical record via the patient-side application software, the patient-side communication means or the patient-side smart contract (or server application) for communication with a doctor receives the patient ID and the patient-side encryption half key as patient ID information from the patient ID management system, and uses the patient-side encryption half key to initially approve the transaction of the deletion process."The doctor-side application software has a deletion transaction primary approval function that transfers the transaction of the deletion process that has been primarily approved to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) and passes the patient-side encryption half-key to the doctor-side application software," and "The doctor-side application software has a doctor-side login function that logs in to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and a function that logs in by a patient to the patient ID management system and the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) via the patient-side application software, and a function that logs in by a doctor to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) via the doctor-side login function." and a bilateral half-key receiving function for receiving a patient-side encryption or decryption half-key from the patient-side doctor communication means or the patient-side smart contract (or server application) and for receiving a doctor-side encryption or decryption half-key from the doctor-side patient communication means or the doctor-side smart contract (or server application)." The doctor-side patient communication means or the doctor-side smart contract (or server application) has a doctor login ID, doctor ID or medical institution ID / doctor-side half-key management function for managing a doctor login ID, a doctor ID or medical institution ID linked to the doctor login ID, a patient ID, and each of the doctor-side encryption and decryption half-keys linked to the patient ID, and passing the doctor-side encryption (or decryption) half-key to the doctor-side application software, and when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software,By configuring the system to have a deletion transaction final approval function that uses the doctor's encryption half key to give final approval to the deletion transaction that was initially approved and transferred using the patient's side's doctor-to-doctor communication means or the patient's side's smart contract (or server application) for doctor-to-doctor communication, and that obtains agreement information from both the patient and the doctor or medical institution regarding the deletion process of the patient's electronic medical record data that is to be deleted, it becomes possible to easily perform the process of obtaining agreement information from both the patient and the doctor / medical institution regarding the deletion process of the patient's electronic medical record data that is to be deleted in real time.

[0123] Furthermore, like the real-time backup and restoration type electronic medical record data guard service provision system of the present invention, the administrator-side file data real-time deletion system is provided in each planet, and in the planet corresponding to the preservation point, for each group of file data linked to the information of each preservation point managed in a black box environment by the file data preservation point information management function of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application), the system is configured to perform an index of modified file data of patients that have been distributed and saved prior to a predetermined generation, which is encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, based on key information consisting of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted of the patient, which is obtained by the deletion transaction final approval function. "Deletion-time encrypted index information reading means or deletion-time encrypted index information reading smart contract (or server application) having a function to read encrypted index information," "deletion-time index information decryption means or deletion-time index information decryption smart contract (or server application) having a function to decrypt encrypted index information read by the deletion-time encrypted index information reading means or deletion-time encrypted index information reading smart contract (or server application) in a black box environment," "deletion-time distributed backup destination node analysis means or deletion-time distributed backup destination node analysis smart contract (or server application) having a function to analyze nodes of a distributed file management group linked to all conservation points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the deletion-time index information decryption means or deletion-time index information decryption smart contract (or server application),"If the configuration has "a means for deleting modified file data during deletion processing or a smart contract (or server application) for deleting modified file data during deletion processing that has the function of deleting modified file data of a patient of a predetermined generation or earlier that is saved in a distributed manner to nodes of a distributed file management group linked to all conservation points analyzed by the means for analyzing distributed save destination nodes during deletion processing or the smart contract (or server application) for analyzing distributed save destination nodes during deletion processing," it will be possible to further strengthen resistance to cyber-attacks using quantum computers and delete file data that the patient wishes to delete, as follows:

[0124] (X10) The extraction of encrypted index information recorded in a group of nodes at a specific location in the distributed ledger structure via the encrypted index information reading means or the smart contract (or server application) for reading encrypted index information, the index information decryption means or the smart contract (or server application) for decrypting index information, the encrypted index information reading means or the smart contract (or server application) for reading encrypted index information, the index information decryption means or the smart contract (or server application) for decrypting index information, and the modified file data extraction means or the smart contract (or server application) for extracting modified file data is based on the agreement information between the patient and the doctor or medical institution regarding the deletion process of the patient's data to be deleted, which was obtained by the deletion transaction final approval function of the doctor's patient communication means or the doctor's patient communication smart contract (or server application). Therefore, a malicious third party needs to understand the content of the agreement information between the patient and the doctor or medical institution regarding the deletion process of the patient's data to be deleted, which was obtained by the deletion transaction final approval function. Furthermore, it is necessary to understand that the distribution destinations and distributed storage destinations of the modified file data distribution storage means or the modified file data distribution storage smart contract (or server application) are determined by the agreement information between the patient and the doctor or medical institution regarding the deletion process of the patient's data that is subject to deletion and that is obtained by the deletion transaction final approval function of the doctor's patient communication means or the doctor's patient communication smart contract (or server application).However, this understanding is difficult. (X11) Furthermore, by defining the file name information of each modified file data included in the index information in the index information creation smart contract (or server application) and the configuration information of each distributed file management group to which each modified file data is allocated as "file name information of each modified file data linked to the information of the conservation point sorted by the file data conservation point association sorting function during the save process and managed in a black box environment by the file data conservation point information management function, which are distributed and saved by each of the modified file data distributed save means or the modified file data distributed save smart contract (or server application), and the configuration information of each distributed file management group to which each modified file data is allocated," no information other than the information of the conservation point is created in the index information. This makes it impossible for a malicious third party to identify the index information of a patient's file data for all conservation points. Therefore, even if a malicious third party uses a quantum computer, it will be nearly impossible to decipher the original electronic medical record data from the saved file data.

[0125] Furthermore, the real-time backup and restore type electronic medical record data guard service providing system of the present invention preferably further comprises an administrator-side file data real-time update system, and the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) further comprises an update transaction primary approval function, which, when a patient applies for use of the patient's electronic medical record update service via the patient-side application software, receives a patient ID and patient-side encryption half-keys as patient ID information from the patient ID management system, uses the patient-side encryption half-keys to primarily approve the update transaction, and transfers the primarily approved update transaction to the doctor-side patient communication means or the doctor-side doctor communication smart contract (or server application), while passing the patient-side encryption half-key to the doctor-side application software, and the doctor-side application software further comprises an update transaction primary approval function, an update processing time electronic medical record data common format conversion function that, when an application for use of a patient's electronic medical record update service has been made via the patient-side application software, receives the patient's electronic medical record data from the electronic medical record control application software of the electronic medical record system and converts the electronic medical record data in a format specific to the electronic medical record system into electronic medical record data in a common format that is common to a plurality of electronic medical record systems, each with a different format; an update processing time electronic medical record data encryption function that, when an application for use of a patient's electronic medical record update service has been made via the patient-side application software, encrypts the patient's electronic medical record data converted into the common format by the update processing time electronic medical record data common format conversion function using the patient-side encryption half key and the doctor-side encryption half key received by the both-side half key receiving function; and, when a patient has applied for use of the patient's electronic medical record update service via the patient-side application software,The system further comprises an update processing time electronic medical record data secret sharing and division function that secret shares the electronic medical record data of the patient encrypted by the update processing time electronic medical record data encryption function and divides it into multiple file data, and an update processing time file data upload function that, when a patient has applied for use of the patient's electronic medical record update service via the patient-side application software, secret shares the electronic medical record data by the update processing time electronic medical record data secret sharing and division function and uploads each of the divided file data to a first temporary storage area, and the doctor-side patient communication means or the doctor-side smart contract (or server application) uses a patient-side encryption half-key to process the update processing transaction that has been primarily approved and transferred by the patient-side doctor communication means or the patient-side smart contract (or server application) when a patient has applied for use of the patient's electronic medical record update service via the patient-side application software. an update transaction final approval function that uses a doctor-side encryption half-key to give final approval to the update transaction, and obtains agreement information between the patient and the doctor or medical institution regarding the update process of the electronic medical record data to be updated for the patient; an update process file data preservation point association sorting function that, when a patient has applied to use the patient's electronic medical record update service via the patient-side application software, associates and sorts each of the file data that has been encrypted by the update process file data encryption function, secret-shared by the update process electronic medical record data secret-shared division function, and divided by the update process file data preservation point association sorting function, when a patient has applied to use the patient's electronic medical record update service via the patient-side application software,and a file data transfer function for saving during update processing, which transfers each group of file data sorted in association with each conservation point to the operator-side file data real-time update system, and the operator-side file data real-time update system includes a file data receiving means for saving during update processing or a smart contract (or server application) for receiving file data for saving during update processing, which is provided on each planet and has a function to receive the file data for saving during update processing transferred for each group of file data sorted in association with each conservation point by the file data transfer function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, and a file data receiving means for saving during update processing or a smart contract (or server application) for receiving file data for saving during update processing, which is provided on each planet and has a function to modify the file data for saving during update processing received by the file data receiving means for saving during update processing or the smart contract (or server application) for receiving file data for saving during update processing. and a file data modification means or a smart contract (or server application) for modifying file data to be saved during update processing, which is provided on each planet and is obtained by the update transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for modifying file data to be saved during update processing, and based on the agreement information between the patient and the doctor or medical institution regarding the update process of the data to be updated for the patient, the file data is sorted by the file data preservation point correspondence sorting function during update processing and linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function, and the file data modified by the file data modification means for file data to be saved during update processing or the smart contract (or server application) for modifying file data to be saved during update processing is distributed to the multiple distributed file management groups constructed by the nodes of each base constituting the planet corresponding to the preservation point and recording devices of multiple bases connected to the nodes of the base via a network;a distributed backup means for modified file data at update processing or a smart contract (or server application) for distributed backup of modified file data at update processing, which has a function of distributing and saving the allocated modified file data for each conservation point to each base node belonging to a distributed file group corresponding to the conservation point and to recording devices at multiple bases connected to the base node via a network; key information formed using predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID contained in agreement information between the patient and the doctor or medical institution regarding the backup processing of the electronic medical record data to be saved for the patient, which is obtained by the update transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication; and a smart contract (or server application) for index information creation at update processing, which has a function of creating, in a black box environment, index information comprising information on the file name of each of the modified file data linked to the information on the conservation point that is sorted by the file data conservation point association sorting function at update processing of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication and managed in a black box environment by the file data conservation point information management function, and configuration information of each of the distributed file management groups to which each of the modified file data is to be allocated; and the index information created by the index information creation means at update processing or the smart contract (or server application) for index information creation at update processing,an encrypted index information recording means at update processing or a smart contract (or server application) for recording encrypted index information at update processing, which has a function of encrypting the index information in a black box environment and recording it in a node group at a specific location in the distributed ledger structure; a first data erasure means at update processing, which erases each file data uploaded to the first temporary storage area by the file data upload function at update processing of the doctor-side application software after the index information has been encrypted and recorded in the node group at a specific location in the distributed ledger structure by the encrypted index information recording means at update processing or the smart contract (or server application) for recording encrypted index information at update processing; and a first data erasure means at update processing, which is provided in each planet and which, in the planet corresponding to the conservation point, an update processing encrypted index information reading means or an update processing encrypted index information reading smart contract (or server application) having a function of reading index information of modified file data of a patient that has been distributed and saved prior to a predetermined generation and that is encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, based on key information consisting of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID required for deleting electronic medical record data in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data of the patient to be deleted obtained by the update transaction final approval function, for each group of file data linked to information of each of the preservation points managed in a black box environment by the file data preservation point information management function of the smart contract (or server application);an update processing time index information decryption means or an update processing time index information decryption smart contract (or server application) having a function of decrypting the encrypted index information read by the update processing time encrypted index information reading means or update processing time encrypted index information reading smart contract (or server application) in a black box environment; an update processing time distributed save destination node analysis means or an update processing time distributed save destination node analysis smart contract (or server application) having a function of analyzing the nodes of the distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the update processing time index information decryption means or update processing time smart contract (or server application); and a modified file data deletion means or a smart contract (or server application) for deleting modified file data during update processing, which has a function of deleting modified file data of a patient of a predetermined generation or earlier that is saved in a distributed manner in a database, and the file data integration function during restoration processing of the doctor-side application software is configured to restore multiple file data that have been secret shared and split by the secret sharing split function during saving processing or the secret sharing split function during update processing, received from the administrator-side file data real-time retrieval system by the file data reception function for restoration, to an integrated state before secret sharing, when a patient has applied to use the patient's electronic medical record restoration service via the patient-side application software. The file data encrypted by the electronic medical record data encryption function during the evacuation process or the encryption function during the update process, which has been restored to the integrated state before decentralization, is decrypted into the electronic medical record data of the patient using the patient-side decryption half key and the doctor-side decryption half key received by the double half key receiving function, and the specific format reconversion function during the restoration process of the doctor-side application software is configured to, when a patient has applied for use of the patient's electronic medical record restoration service via the patient-side application software, reconvert the electronic medical record data of the patient that has been decrypted by the electronic medical record data decryption function during the restoration process and converted into a common format by the electronic medical record data common format conversion function during the evacuation process or the electronic medical record data common format conversion function during the update process into a format specific to the electronic medical record control application software before conversion, and pass the electronic medical record data of the patient that has been reconverted into the specific format to the electronic medical record control application software of the electronic medical record system,The file data preservation point information management function of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) is configured to manage, in a black box environment, information on the preservation points for managing the file data sorted by the file data preservation point association sorting function during the save process and the file data preservation point association sorting function during the update process.

[0126] Like the real-time backup and restoration type electronic medical record data guard service providing system of the present invention, the patient-side means of communication with doctors or the smart contract (or server application) for patient-side communication with doctors has an update transaction primary approval function that, when a patient applies for use of the patient's electronic medical record update service via the patient-side application software, receives the patient ID and patient-side encryption half-keys as patient ID information from the patient ID management system, uses the patient-side encryption half-keys to primarily approve the update transaction, and transfers the primarily approved update transaction to the doctor-side means of communication with patients or the smart contract (or server application) for doctor-side communication with patients, while also passing the patient-side encryption half-keys to the doctor-side application software. In addition, if the doctor's means of communication with patients or the doctor's smart contract (or server application) for communication with patients is configured to have an update transaction final approval function that, when a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, will use the patient's half-key for encryption to initially approve and transfer the update processing transaction that was transferred using the patient's half-key for encryption, and will also obtain agreement between the patient and the doctor or medical institution regarding the update processing of the electronic medical record data that is the target of update for that patient, it will be extremely difficult for malicious third parties to understand the content of the agreement between the patient and the doctor / medical institution.

[0127] Furthermore, as in the real-time backup / restore type electronic medical record data guard service provision system of the present invention, "the patient-side application software is provided in the patient's communication device, and has a patient-side service application function for logging in to the patient ID management system and the patient-to-doctor communication means or the patient-to-doctor communication smart contract (or server application) and applying for the use of predetermined services related to the preservation of the patient's electronic medical record, such as backup / restore," "the external patient authentication system has a patient login ID, health insurance card number, and My Number etc. management means for managing the patient login ID, health insurance card number, My Number etc.," and "the patient ID management system has a patient ID / patient-side half key / index information recording block chain address management means for managing the patient ID linked to the patient login ID (linked to the health insurance card number, My Number information etc.), the patient-side half keys for encryption and decryption, and the block chain address for recording index information, and a patient-side application software for the patient side. and a patient ID and half key delivery means for delivering a patient ID and a patient-side encryption or decryption half key to the patient-side communication means or the patient-side smart contract (or server application) for communication with a doctor after authentication by the external patient authentication system has been completed. "When a patient applies for use of a specified service related to the preservation of the patient's electronic medical record via the patient-side application software, the patient-side communication means or the patient-side smart contract (or server application) for communication with a doctor receives the patient ID and the patient-side encryption half key as patient ID information from the patient ID management system, and uses the patient-side encryption half key to give a primary approval to the transaction of the update process,"The doctor-side application software has an update transaction primary approval function that transfers the transaction of the update process that has been primarily approved to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) and passes the patient-side encryption half-key to the doctor-side application software," and "The doctor-side application software has a doctor-side login function that logs in to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and a function that logs in by a patient to the patient ID management system and the patient-side doctor communication means or the patient-side smart contract for doctor communication (or server application) via the patient-side application software, and a function that logs in by a doctor to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) via the doctor-side login function." and a bilateral half-key receiving function for receiving a patient-side encryption or decryption half-key from the patient-side doctor communication means or the patient-side smart contract (or server application) and for receiving a doctor-side encryption or decryption half-key from the doctor-side patient communication means or the doctor-side smart contract (or server application)." The doctor-side patient communication means or the doctor-side smart contract (or server application) has a doctor login ID, doctor ID or medical institution ID / doctor-side half-key management function for managing a doctor login ID, a doctor ID or medical institution ID linked to the doctor login ID, a patient ID, and each of the doctor-side encryption and decryption half-keys linked to the patient ID, and passing the doctor-side encryption (or decryption) half-key to the doctor-side application software, and when a patient applies for use of the patient's electronic medical record update service via the patient-side application software,By configuring the system to have a function for final approval of the update transaction using the half-key for patient encryption, which is the update transaction that was initially approved and transferred using the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) using the half-key for patient encryption, and for obtaining agreement information between the patient and the doctor or medical institution regarding the update process of the electronic medical record data that is the target of update for the patient, it becomes possible to easily perform the process for obtaining agreement information between the patient and the doctor / medical institution regarding the update process of the electronic medical record data that is the target of update for the patient in real time.

[0128] Furthermore, like the real-time save / restore type electronic medical record data guard service providing system of the present invention, the administrator-side file data real-time update system may be implemented by "a file data receiving means for saving at update processing or a smart contract (or server application) for receiving file data for saving at update processing, which is provided on each planet and has a function to receive the file data for saving at update processing that has been transferred for each group of file data sorted in correspondence with each conservation point by the file data transfer function for saving at update processing of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication," or "a file data modification means for saving at update processing or a smart contract (or server application) for modifying file data for saving at update processing that is provided on each planet and has a function to modify the file data for saving at update processing received by the file data receiving means for saving at update processing or the smart contract (or server application) for receiving file data for saving at update processing." and "a file data modification means for saving during update processing or a smart contract (or server application) for modifying file data for saving during update processing, which is provided on each planet and is sorted by the file data preservation point association sorting function based on the agreement information between the patient and the doctor or medical institution regarding the update process of the patient's data to be updated, obtained by the update transaction final approval function of the doctor's patient communication means or the doctor's patient communication smart contract (or server application), and which is linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function, and which is modified by the file data modification means for saving during update processing or the smart contract (or server application) for modifying file data for saving during update processing, is sorted by the file data preservation point association sorting function, and is linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function, and which is sorted to a plurality of distributed file management groups constructed by each base node constituting the planet corresponding to the preservation point and recording devices of a plurality of bases connected to the base nodes via a network, and the sorted modified file data is stored for each preservation point,a distributed backup means for file data modified during update processing or a smart contract (or server application) for distributed backup of file data modified during update processing, which has a function of distributing and saving to nodes at each base belonging to a distributed file group corresponding to the conservation point and to recording devices at multiple bases connected to the nodes at the base via a network; key information comprising predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID, which is included in the agreement information between the patient and the doctor or medical institution regarding the backup processing of the electronic medical record data to be saved for the patient, obtained by the update transaction final approval function of the doctor-side patient communication means or smart contract (or server application) for doctor-side patient communication; "an index information creation means or a smart contract (or a server application) for creating index information at the time of update processing, which has a function of creating, in a black box environment, index information comprising information on the file name of each of the modified file data that is sorted by the file data conservation point association sorting function at the time of update processing of the client (or server application) and that is linked to information on the conservation point that is managed in a black box environment by the file data conservation point information management function, and configuration information of each of the distributed file management groups to which each of the modified file data is allocated; "an encrypted index information recording means or a smart contract (or a server application) for recording encrypted index information at the time of update processing, which has a function of encrypting, in a black box environment, the index information created by the index information creation means or the smart contract (or server application) for creating index information at the time of update processing and recording it in a node group of a specific location in the distributed ledger structure; and "a means for recording encrypted index information at the time of update processing, which is provided on each planet,and a file data encryption function for updating the encrypted index information read means or the encrypted index information read means for updating ... "a smart contract (or server application) for reading encrypted index information during update processing," "an index information decryption means during update processing or a smart contract (or server application) for decrypting index information during update processing having a function of decrypting the encrypted index information read by the index information reading means during update processing or the smart contract (or server application) for reading encrypted index information during update processing in a black box environment," "a distributed backup destination node analysis means during update processing or a smart contract (or server application) for analyzing distributed backup destination nodes during update processing having a function of analyzing the nodes of the distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner based on the index information decrypted by the index information decryption means during update processing or the smart contract (or server application) for decrypting index information during update processing,"If the configuration has "a means for deleting modified file data during update processing or a smart contract (or server application) for deleting modified file data during update processing that has the function of deleting modified file data of a patient of a predetermined generation or earlier that has been saved in a distributed manner to the nodes of the distributed file management group linked to all the conservation points analyzed by the means for analyzing distributed save destination nodes during update processing or the smart contract (or server application) for analyzing distributed save destination nodes during update processing," it will be possible to further strengthen resistance to cyber-attacks using quantum computers and update the file data that the patient wishes to update, as follows:

[0129] (X12) By having the file data modification means for saving during update processing or the smart contract (or server application) for modifying file data for saving during update processing modify the file data for saving during update processing that is transferred by the file data transfer function for saving during update processing of the patient communication means on the patient side or the smart contract (or server application) for patient communication on the doctor side for each group of file data sorted in correspondence with each conservation point, the file data to be saved during update processing becomes even more difficult to decipher. (X13) To determine which of the multiple distributed file management groups, consisting of the nodes at multiple locations that make up a planet and the storage devices at multiple locations that are networked to the nodes at those locations, a malicious third party must understand the content of the agreement between the patient and the doctor or medical institution regarding the update process of the patient's data, obtained through the update transaction final approval function of the doctor's patient communication means or the doctor's patient communication smart contract (or server application). Furthermore, it is necessary to understand that the allocation destination and distributed evacuation destination of the update process modified file data distributed evacuation means or the update process modified file data distributed evacuation smart contract (or server application) are determined by the agreement between the patient and the doctor or medical institution regarding the evacuation process of the patient's data, obtained through the update transaction final approval function of the doctor's patient communication means or the doctor's patient communication smart contract (or server application). However, this understanding is difficult. (X14) Furthermore, if the doctor's patient communication means or the doctor's patient communication smart contract (or server application) is equipped with a "file data preservation point association sorting function during update processing" that associates and sorts file data into one of at least two preservation points for managing file data, even if file data saved in one preservation point is stolen and analyzed by a malicious third party, it will be impossible to restore the original electronic medical record data unless the file data saved in another preservation point is stolen and analyzed. Furthermore, by providing a "file data preservation point information management function" that manages, in a black-box environment, the information on the preservation points for managing the file data sorted by the file data preservation point association sorting function during update processing, the electronic medical record data will be encrypted and secretly distributed, making i...

Claims

1. A real-time backup and restoration type electronic medical record data guard service providing system for protecting electronic medical record data from high-level cyber attacks, which is constructed with a distributed ledger in distributed ledger technology such as blockchain and a smart contract or server application for performing predetermined processing using the data managed in the distributed ledger, and at the same time, is a system that has a structure that allows electronic medical record management data to be shared with specific individuals by using open technology, At least one distributed ledger structure consisting of multiple chains that may include distributed ledgers, public blockchains, etc., and is primarily a private or consortium type closed blockchain, constructed with multiple planets (a unit that combines blockchains, distributed file management functions, etc., and forms one unit that constitutes a system for providing services that implement distributed smart contracts, server applications, etc.) that are made up of a group of nodes that combine nodes from multiple locations in different regions around the world; patient-side application software; External patient authentication systems and a patient ID management system; A means of communication between patients and doctors or a smart contract (or server application) for patient-doctor communication; Doctor-side application software provided by the operator of the electronic medical record data guard service; A doctor-patient communication means or a smart contract (or server application) for doctor-patient communication; A real-time file data evacuation system for the administrator side, A real-time file data retrieval system for the administrator side, and Each node in each location connects to recording devices in multiple locations around the world via a network to create a distributed file management group. The patient-side application software is provided in the patient's communication device, and has a patient-side service application function for logging in to the patient ID management system and the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) and applying for the use of predetermined services related to the preservation of the patient's electronic medical record, such as evacuation and restoration; The external patient authentication system has a patient login ID, health insurance card number, and My Number management means for managing patient login IDs, health insurance card numbers, My Numbers, etc., The patient ID management system includes: A patient ID / patient side half key / index information recording block chain address management means for managing the patient ID linked to the patient login ID (linked to the health insurance card number, My Number information, etc.), the patient side half keys for encryption and decryption, and the block chain address for recording index information; an authentication request means for requesting authentication by providing authentication information such as a patient login ID (personal identification information of the patient) and a password to the external patient authentication system when a patient applies for use of a predetermined service related to the preservation of the patient's electronic medical record via the patient-side application software; a patient ID and half-key transfer means for transferring a patient ID and a patient-side encryption or decryption half-key to the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) after authentication by the external patient authentication system is completed; and The patient-doctor communication means or the smart contract (or server application) for patient-doctor communication is: a save transaction primary approval function that, when a patient applies for use of a patient electronic medical record save service via the patient-side application software, receives the patient ID and patient-side encryption half keys and the like as patient ID information from the patient ID management system, uses the patient-side encryption half keys to primarily approve the save processing transaction, transfers the primarily approved save processing transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and passes the patient-side encryption half keys to the doctor-side application software; a restoration transaction primary approval function that, when a patient applies for use of a restoration service for the patient's electronic medical record via the patient-side application software, receives the patient ID and patient-side decryption half keys as patient ID information from the patient ID management system, uses the patient-side decryption half keys to primarily approve the restoration transaction, transfers the primarily approved restoration transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and passes the patient-side decryption half keys to the doctor-side application software; and The doctor-side application software includes: an electronic medical record control application connection function that connects to electronic medical record control application software for a plurality of electronic medical record systems, each with a different format, provided by each electronic medical record system provider; When a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, an electronic medical record data common format conversion function during evacuation processing receives the patient's electronic medical record data from the electronic medical record control application software of the electronic medical record system and converts the electronic medical record data in a format specific to the electronic medical record system into electronic medical record data in a common format common to multiple electronic medical record systems, each with a different format; A doctor-side login function for logging in to the doctor-side patient communication means or the doctor-side smart contract (or server application) for patient communication; a bilateral half key receiving function for receiving a patient-side encryption or decryption half key from the patient-side doctor communication means or the patient-side smart contract for communication with a doctor (or the server application) and for receiving a doctor-side encryption or decryption half key from the doctor-side patient communication means or the doctor-side smart contract for communication with a doctor (or the server application) when a patient logs in to the patient ID management system and the patient-side doctor communication means or the patient-side smart contract for communication with a doctor (or the server application) via the patient-side application software and a doctor logs in to the doctor-side patient communication means or the doctor-side smart contract for communication with a doctor (or the server application) via the doctor-side login function; an electronic medical record data encryption function during evacuation processing that, when a patient has applied to use the patient's electronic medical record evacuation service via the patient-side application software, encrypts the patient's electronic medical record data converted into a common format by the electronic medical record data common format conversion function during evacuation processing using the patient-side encryption half key and the doctor-side encryption half key received by the both-side half key receiving function; When a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, a secret sharing and division function for electronic medical record data during evacuation processing, which secretly shares the patient's electronic medical record data encrypted by the electronic medical record data encryption function during evacuation processing and divides it into multiple file data; a file data upload function during the evacuation process that, when a patient has applied for use of the patient's electronic medical record evacuation service via the patient-side application software, performs secret sharing using the electronic medical record data secret sharing and division function during the evacuation process and uploads each of the divided file data to a first temporary storage area; When a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, a file data integration function during restoration processing restores a group of multiple file data that has been received from the administrator-side file data real-time retrieval system by the restoration file data receiving function of the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application) and downloaded to a second temporary storage area, and that has been secret-shared and divided by the electronic medical record data secret-shared division function during evacuation processing, and that has been sorted in accordance with the conservation points, to the integrated state before secret sharing; When a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, an electronic medical record data decryption function during restoration processing decrypts the file data encrypted by the electronic medical record data encryption function during saving processing, which has been restored to the integrated state before secret sharing by the file data integration function during restoration processing, into the electronic medical record data of the patient using the patient-side decryption half key and the doctor-side decryption half key received by the both-side half key receiving function; a second data erasure function that erases all file data that has been restored to the electronic medical record data of the patient before the evacuation by the electronic medical record data decryption function during the restoration process and then downloaded to the second temporary storage area and that has been secret-shared and divided by the electronic medical record data secret-share and division function during the evacuation process; a specific format reconversion function during restoration processing, which, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, reconverts the patient's electronic medical record data, which has been decrypted by the electronic medical record data decryption function during restoration processing and converted into a common format by the electronic medical record data common format conversion function during evacuation processing, into a format specific to the electronic medical record control application software before conversion, and passes the patient's electronic medical record data, which has been reconverted into the specific format, to the electronic medical record control application software of the electronic medical record system; and The doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) A doctor login ID, doctor ID or medical institution ID and doctor side half key management function that manages doctor login IDs, doctor IDs or medical institution IDs linked to the doctor login IDs, patient IDs and respective half keys for encryption and decryption linked to the patient IDs on the doctor side, and passes the doctor side half keys for encryption (or decryption) to the doctor side application software; When a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, a final approval function for the evacuation transaction uses a doctor-side half-key to give final approval to the transaction of the evacuation process that was initially approved and transferred using the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) using the patient-side encryption half-key, and obtains agreement information between the patient and the doctor or medical institution regarding the evacuation process of the patient's electronic medical record data to be evacuated; a file data preservation point association sorting function during evacuation processing, which, when a patient applies for use of the patient's electronic medical record evacuation service via the patient-side application software, associates and sorts each of the divided file data that has been uploaded to a first temporary storage area by the file data upload function during evacuation processing of the doctor-side application software, encrypted by the electronic medical record data encryption function during evacuation processing, secret-shared by the electronic medical record data secret-shared division function during evacuation processing, and divided into multiple preservation points; a file data preservation point information management function that manages, in a black box environment, information on the preservation points for managing the file data sorted by the file data preservation point association sorting function during the save processing; a file data transfer function for transfer of each file data sorted by the file data conservation point association function during the evacuation process in association with a plurality of conservation points to the operation manager side file data real-time evacuation system in the case where a patient has applied for use of the patient's electronic medical record evacuation service via the patient side application software; When a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, a restoration transaction final approval function uses the doctor-side decryption half key to give final approval to the restoration processing transaction that was initially approved and transferred using the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) using the patient-side decryption half key, and obtains agreement information between the patient and the doctor or medical institution regarding the restoration processing of the electronic medical record data to be restored for the patient; a restoration file data receiving function that, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, receives from the administrator-side file data real-time retrieval system each group of file data that has been sorted and distributed and saved in association with a plurality of preservation points, and downloads the file data to a second temporary storage area; and The administrator-side file data real-time evacuation system includes: a backup file data receiving means or a backup file data receiving smart contract (or server application) that is provided on each planet and has a function of receiving backup file data that has been transferred for each group of file data that has been sorted in association with each conservation point by the backup file data transfer function of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application); A save file data modification means or a save file data modification smart contract (or a server application) that is provided on each planet and has a function of modifying the save file data received by the save file data receiving means or the save file data receiving smart contract (or a server application); The file data modification means for evacuation or the smart contract for modifying file data for evacuation (or server application) is provided on each planet, and is sorted by the file data preservation point association sorting function during the evacuation process based on the agreement information between the patient and the doctor or medical institution regarding the evacuation process of the patient's data to be evacuated, which is obtained by the evacuation transaction final approval function of the doctor's patient communication means or the smart contract for patient communication (or server application), and is linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function. a modified file data distribution and evacuation means or a modified file data distribution and evacuation smart contract (or server application) having a function of distributing and evacuating, for each conservation point, each of the file data modified by a server application (or a server application) to a plurality of distributed file management groups constructed by each of the base nodes constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, and distributing and evacuating the allocated modified file data to each of the base nodes belonging to the distributed file group corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network; The data evacuation process of the electronic medical record data to be evacuated for the patient, which is acquired by the save transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication, includes key information that uses predetermined information linked to the patient ID required for the evacuation of the electronic medical record data and predetermined information linked to the doctor ID or the medical institution ID, and the data evacuation process of the electronic medical record data to be evacuated for the patient, which is acquired by the save transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication. and an index information creating means or a smart contract (or server application) for index information creating, in a black box environment, index information including information on the file name of each of the modified file data linked to the information on the conservation point sorted by the file data conservation point association sorting function during the save processing of the communication means or the smart contract (or server application) for communication with patients on the doctor side, and information on the configuration of each of the distributed file management groups to which each of the modified file data is to be allocated; an encrypted index information recording means or an encrypted index information recording smart contract (or a server application) that has a function of encrypting the index information created by the index information creation means or the index information creation smart contract (or a server application) in a black box environment and recording the index information in a node group at a specific location in the distributed ledger structure; a first data erasure means for erasing each file data uploaded to the first temporary storage area by the file data upload function during the evacuation process of the doctor-side application software after the index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by the encrypted index information recording means or the encrypted index information recording smart contract (or server application); and The system for retrieving file data in real time on the administrator side is an encrypted index information reading means or a smart contract (or server application) for reading encrypted index information, which is provided in each planet and has a function of reading index information of a patient's modified file data, which is encrypted and recorded in a node group at a specific location in the distributed ledger structure, based on key information consisting of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID required for restoring the electronic medical record data in the agreement information between the patient and the doctor or medical institution regarding the restoration process of the electronic medical record data to be restored for the patient, which is obtained by the restoration transaction final approval function, for each group of file data linked to the information of each of the maintenance points managed in a black box environment by the file data maintenance point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication in the planet corresponding to the maintenance point; an index information decryption means or a smart contract for decrypting index information (or a server application) having a function of decrypting the encrypted index information read by the encrypted index information reading stage or the smart contract for reading encrypted index information (or a server application) in a black box environment; a distributed save destination node analysis means or a smart contract (or server application) for analyzing distributed save destination nodes, which has a function of analyzing the nodes of the distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner, based on the index information decrypted by the index information decryption means or the smart contract (or server application) for decrypting index information; a modified file data extraction means or a smart contract (or server application) for extracting modified file data, which has a function of extracting modified file data of a patient that has been distributed and saved from the nodes of a distributed file management group linked to all the conservation points analyzed by the distributed save destination node analysis means or the smart contract (or server application) for analyzing distributed save destination node; A file data pre-modification state restoration means or a file data pre-modification state restoration smart contract (or server application) having a function of restoring the modified file data extracted by the modified file data extraction means or the modified file data extraction smart contract (or server application) to the state before the modification; a restoration file data transfer means or a restoration file data transfer smart contract (or server application) having a function of transferring the patient's restoration file data restored to the state before the alteration by the file data restoration means or the file data restoration smart contract (or server application) to the doctor's patient communication means or the doctor's patient communication smart contract (or server application); A real-time backup and restoration type electronic medical record data guard service providing system comprising:

2. It also has a system for deleting file data in real time on the administrator side, The patient-doctor communication means or the smart contract (or server application) for patient-doctor communication is: The system further has a deletion transaction primary approval function that, when a patient applies for use of a deletion service for the patient's electronic medical record via the patient-side application software, receives a patient ID and patient-side encryption half keys as patient ID information from the patient ID management system, uses the patient-side encryption half keys to primarily approve the deletion transaction, transfers the primarily approved deletion transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and passes the patient-side encryption half keys to the doctor-side application software; The doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) When a patient applies for use of the patient's electronic medical record deletion service via the patient-side application software, the deletion transaction that has been initially approved and transferred using the patient-side encryption half key by the patient-doctor communication means or the doctor-side smart contract (or server application) for patient communication is finally approved using the doctor-side encryption half key, and the deletion transaction final approval function is further provided, which obtains agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted for the patient, The administrator-side file data real-time deletion system is an encrypted index information reading means for deletion processing or a smart contract (or server application) for reading encrypted index information for deletion processing, which is provided in each planet and has a function of reading index information of modified file data of a patient that has been distributed and saved prior to a predetermined generation and that is encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, based on key information consisting of predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted of the patient, which is obtained by the deletion transaction final approval function, for each group of file data linked to the information of each of the conservation points managed in a black box environment by the file data conservation point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication in the planet corresponding to the conservation point; a means for decrypting index information during deletion processing or a smart contract (or server application) for decrypting index information during deletion processing, which has a function of decrypting the encrypted index information read by the means for reading encrypted index information during deletion processing or the smart contract (or server application) for reading encrypted index information during deletion processing in a black box environment; a means for analyzing distributed backup destination nodes during deletion processing or a smart contract (or server application) for analyzing distributed backup destination nodes during deletion processing, which has a function of analyzing the nodes of the distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner, based on the index information decrypted by the means for decrypting index information during deletion processing or the smart contract (or server application) for decrypting index information during deletion processing; A modified file data deletion means during deletion processing or a smart contract (or server application) for deleting modified file data during deletion processing, which has a function of deleting modified file data of patients of a predetermined generation or earlier that is distributed and saved to nodes of a distributed file management group linked to all conservation points analyzed by the distributed save destination node analysis means during deletion processing or the smart contract (or server application) for analyzing distributed save destination nodes during deletion processing; have 2. The electronic medical record data guard service providing system according to claim 1.

3. It also has a file data real-time update system on the administrator side, The patient-doctor communication means or the smart contract (or server application) for patient-doctor communication is: The system further has an update transaction primary approval function that, when a patient applies for use of an update service for the patient's electronic medical record via the patient-side application software, receives a patient ID and patient-side encryption half keys as patient ID information from the patient ID management system, uses the patient-side encryption half keys to primarily approve the update transaction, transfers the primarily approved update transaction to the doctor-side patient communication means or the doctor-side smart contract for patient communication (or server application), and passes the patient-side encryption half keys to the doctor-side application software; The doctor-side application software includes: an update process electronic medical record data common format conversion function that, when a patient applies for use of the patient's electronic medical record update service via the patient-side application software, receives the patient's electronic medical record data from the electronic medical record control application software of the electronic medical record system and converts the electronic medical record data in a format specific to the electronic medical record system into electronic medical record data in a common format common to multiple electronic medical record systems, each with a different format; an electronic medical record data encryption function during update processing that, when a patient has applied to use the patient's electronic medical record update service via the patient-side application software, encrypts the patient's electronic medical record data converted into a common format by the electronic medical record data common format conversion function during update processing using the patient-side encryption half key and the doctor-side encryption half key received by the both-side half key receiving function; When a patient applies for use of the patient's electronic medical record update service via the patient-side application software, an update processing electronic medical record data secret sharing and division function secretly shares the patient's electronic medical record data encrypted by the update processing electronic medical record data encryption function and divides it into multiple file data; a file data upload function during update processing that, when a patient has applied for use of an update service for the patient's electronic medical record via the patient-side application software, secret-shares the electronic medical record data using the secret-shared and splitting function during update processing and uploads each of the split file data to a first temporary storage area; and The doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) When a patient applies for use of the patient's electronic medical record update service via the patient-side application software, an update transaction final approval function uses a doctor-side encryption half-key to give final approval to the update processing transaction that was initially approved and transferred using the patient-side doctor communication means or the patient-side doctor communication smart contract (or server application) using the patient-side encryption half-key, and obtains agreement information between the patient and the doctor or medical institution regarding the update processing of the electronic medical record data to be updated for the patient; When a patient applies for use of an update service for updating the patient's electronic medical record via the patient-side application software, an update process file data preservation point association sorting function sorts each of the divided file data that has been uploaded to a first temporary storage area by the update process file data upload function of the doctor-side application software, encrypted by the update process electronic medical record data preservation point association function, and secret-shared by the update process electronic medical record data secret-shared division function, in association with a plurality of preservation points; a file data transfer function for evacuation during update processing, which transfers each group of file data sorted in association with each conservation point by the file data conservation point association sorting function during update processing to the file data real-time update system on the operation manager side, when a patient applies for use of the update service for the patient's electronic medical record via the patient-side application software; and The administrator-side file data real-time update system includes: a file data receiving means for saving during update processing or a smart contract (or server application) for receiving file data for saving during update processing, which is provided on each planet and has a function of receiving file data for saving during update processing that is transferred for each group of file data sorted in association with each conservation point by the file data transfer function for saving during update processing of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication; A file data modification means for saving during update processing or a smart contract (or server application) for modifying file data for saving during update processing, which is provided on each planet and has a function of modifying the file data for saving during update processing received by the file data receiving means for saving during update processing or the smart contract (or server application) for receiving file data for saving during update processing; The file data modification means for saving during update processing or the smart contract for modifying file data for saving during update processing (or server application) is provided on each planet and is sorted by the file data preservation point association sorting function during update processing based on the agreement information between the patient and the doctor or medical institution regarding the update processing of the data to be updated for the patient, which is obtained by the update transaction final approval function of the doctor-side patient communication means or the smart contract for patient communication on the doctor side (or server application), and is linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function. a distributed backup means for modified file data during update processing or a smart contract (or server application) for distributed backup of modified file data during update processing, which has the function of distributing and saving, for each conservation point, each of the file data modified by a server application (or a server application) to a plurality of distributed file management groups constructed by each of the base nodes constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, and distributing and saving the allocated modified file data to each of the base nodes belonging to the distributed file group corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network; The data evacuation process of the electronic medical record data to be evacuated for the patient, which is acquired by the update transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication, includes key information using predetermined information linked to the patient ID required for the evacuation of the electronic medical record data and predetermined information linked to the doctor ID or the medical institution ID, which is included in the agreement information between the patient and the doctor or the medical institution, and the data evacuation process of the electronic medical record data to be evacuated for the patient, which is acquired by the update transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication, an index information creation means for update processing or a smart contract (or server application) for creating index information for update processing, which has a function of creating, in a black box environment, index information including information on the file name of each of the modified file data linked to the information on the conservation point sorted by the file data conservation point association sorting function for the update processing of the communication means or the smart contract (or server application) for patient communication on the doctor side and managed in a black box environment by the file data conservation point information management function, and configuration information of each of the distributed file management groups to which each of the modified file data is allocated; an encrypted index information recording means for updating or a smart contract (or server application) for recording encrypted index information for updating, which has a function of encrypting the index information created by the index information creating means for updating or the smart contract (or server application) for creating index information for updating in a black-box environment and recording the encrypted index information in a node group at a specific location in the distributed ledger structure; a first data erasure means for erasing each file data uploaded to the first temporary storage area by the file data upload function for the update process of the doctor-side application software after the index information is encrypted and recorded in a node group at a specific location in the distributed ledger structure by the update process encrypted index information recording means or the update process encrypted index information recording smart contract (or server application); an update processing encrypted index information reading means or update processing encrypted index information reading smart contract (or server application) that is provided in each planet and has a function of reading index information of modified file data of a patient that has been distributed and saved prior to a predetermined generation and that is encrypted and recorded in a group of nodes at a specific location in the distributed ledger structure, based on key information that uses predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID that are necessary for deleting electronic medical record data in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted of the patient that is obtained by the update transaction final approval function, for each group of file data linked to information of each of the conservation points that is managed in a black box environment by the file data conservation point information management function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication in the planet that corresponds to the conservation point; an index information decryption means for updating or a smart contract (or server application) for decrypting index information for updating, which has a function of decrypting the encrypted index information read by the encrypted index information reading means for updating or the smart contract (or server application) for reading encrypted index information for updating, in a black box environment; a distributed save destination node analysis means for update processing or a smart contract (or server application) for analyzing distributed save destination nodes for update processing, which has a function of analyzing the nodes of the distributed file management group linked to all the conservation points where the patient's modified file data is saved in a distributed manner, based on the index information decrypted by the index information decryption means for update processing or the smart contract (or server application) for decrypting index information for update processing; A modified file data deletion means during update processing or a smart contract (or server application) for deleting modified file data during update processing has a function of deleting modified file data of patients of a predetermined generation or earlier that is distributed and saved to nodes of a distributed file management group linked to all conservation points analyzed by the distributed save destination node analysis means during update processing or the smart contract (or server application) for analyzing distributed save destination nodes during update processing; and the file data integration function at the time of restoration processing of the doctor-side application software is configured to, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, restore a plurality of file data that have been secret-shared and divided by the secret-shared and dividing function at the time of saving processing or the secret-shared and dividing function at the time of updating processing, received by the file data reception function for restoration from the administrator-side file data real-time retrieval system, to an integrated state prior to secret sharing; The electronic medical record data decryption function at the time of restoration processing of the doctor-side application software is configured to, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, decrypt the file data encrypted by the electronic medical record data encryption function at the time of evacuation processing or the encryption function at the time of update processing, which has been restored to the integrated state before secret sharing by the file data integration function at the time of restoration processing, into the data of the patient's electronic medical record, using the patient-side decryption half key and the doctor-side decryption half key received by the both-side half key receiving function; The specific format reconversion function at the time of restoration processing of the doctor-side application software is configured to, when a patient applies for use of the patient's electronic medical record restoration service via the patient-side application software, reconvert the patient's electronic medical record data, which has been decrypted by the electronic medical record data decryption function at the time of restoration processing and converted to a common format by the electronic medical record data common format conversion function at the time of evacuation processing or the electronic medical record data common format conversion function at the time of update processing, into a format specific to the electronic medical record control application software before conversion, and pass the patient's electronic medical record data reconverted into the specific format to the electronic medical record control application software of the electronic medical record system; The file data preservation point information management function of the doctor-side patient communication means or the doctor-side patient communication smart contract (or server application) is configured to manage, in a black box environment, information on the preservation points for managing the file data sorted by the file data preservation point association sorting function at the time of the save processing and the file data preservation point association sorting function at the time of the update processing.

2. The real-time save / restore type electronic medical record data guard service providing system according to claim 1.

4. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 2, further comprising a deletion target generation setting means that can change the setting of the generation of file data to be deleted by the file data deletion means modified during deletion processing or the smart contract (or server application) for deleting file data modified during deletion processing.

5. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 3, characterized in that the means for deleting file data modified during update processing or the smart contract (or server application) for deleting file data modified during update processing is configured to automatically set all file data of past generations of the patient as file data to be deleted.

6. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 3, characterized in that it further has a deletion target generation setting means that can change the setting of the generation of file data to be deleted by the means for deleting modified file data during update processing or the smart contract (or server application) for deleting modified file data during update processing.

7. The index information includes information on the file name of each of the modified file data linked to the information on the conservation point, configuration information of each of the distributed file management groups to which each of the modified file data is allocated, addresses of the modified file data that have been distributed and saved, and hash values ​​of the modified file data that have been distributed and saved, Furthermore, the system includes a file data consistency check and automatic recovery means or a file data consistency check and automatic recovery smart contract (or server application) that periodically checks the consistency between the hash value of each modified file data that is distributed and saved to each base node belonging to the distributed file group corresponding to the maintenance point and to recording devices at multiple bases connected to the base node via a network, and the hash value of the index information of the modified file data obtained via the encrypted index information reading means or the smart contract (or server application) for reading encrypted index information, and the index information decryption means or the smart contract (or server application) for decrypting index information, and if the check shows that the hash value of the modified file data that is distributed and saved differs from the hash value of the index information that manages the modified file data, the file data consistency check and automatic recovery means or the smart contract (or server application) has the function of deleting the modified file data that is distributed and saved, and copying the modified file data with a normal hash value to automatically recover the modified file data.

2. The real-time save / restore type electronic medical record data guard service providing system according to claim 1.

8. A real-time backup and restoration type electronic medical record data guard service provision system as described in any one of claims 1 to 3, characterized in that the at least two conservation points are at least two addresses in one blockchain.

9. A real-time backup and restoration type electronic medical record data protection service provision system as described in any one of claims 1 to 3, characterized in that the at least two conservation points are at least one address in each of at least two blockchains.

10. Further, a second administrator-side file data real-time deletion system is provided, The second administrator-side file data real-time deletion system comprises: The system has a file data preservation point information deletion means or a file data preservation point information deletion smart contract (or server application) that has a function of deleting the preservation point information linked to the file data to be deleted, which is managed in a black box environment by the file data preservation point information management function, based on key information that uses predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID that are necessary for deleting the electronic medical record data of the patient to be deleted, in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted of the patient, which is acquired by the deletion transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication.

3. The real-time save / restore type electronic medical record data guard service providing system according to claim 2.

11. Further, a second administrator-side file data real-time deletion system is provided, The second administrator-side file data real-time deletion system comprises: and a file data preservation point information deletion means or a file data preservation point information deletion smart contract (or server application) having a function of deleting the preservation point information linked to the file data to be deleted, which is managed in a black box environment by the file data preservation point information management function, based on key information formed using predetermined information linked to the patient ID and predetermined information linked to the doctor ID or medical institution ID required for deleting the electronic medical record data of the patient to be deleted, in the agreement information between the patient and the doctor or medical institution regarding the deletion process of the electronic medical record data to be deleted of the patient, which is acquired by the update transaction final approval function of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication.

4. The real-time save / restore type electronic medical record data guard service providing system according to claim 3.

12. A real-time backup and restoration type electronic medical record data guard service provision system as described in any one of claims 1 to 3, characterized in that each base node belonging to each of the distributed file management groups and each of the recording devices at multiple bases connected to the base node via a network are provided with multiple sub-configuration file servers (or a group of file servers accessible from each of the base nodes belonging to each of the file management groups) that are respectively connected to the base node and each of the recording devices at multiple bases connected to the base node via a network.

13. Each of the modified file data distributed save means or smart contract (or server application) for modified file data distributed save checks the data storage capacity and usage status of each of the sub-component file servers connected to the node of each base belonging to each of the distributed file management groups and the recording devices of multiple bases connected to the node of the base via a network, and based on the checked data storage capacity, selects a specific sub-component file server having a data storage capacity capable of recording the large modified file data linked to the information of the storage point that is sorted by the file data preservation point association sorting function of the doctor-side patient communication means or smart contract (or server application) for doctor-side patient communication in a state where the data has been encrypted, divided into multiple parts, and uploaded to the first temporary storage area, and that is managed in a black box environment by the file data preservation point information management function. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 12, characterized in that it has a function of recording the large modified file data linked to the information of the conservation point managed in a black box environment by the file data conservation point information management function, which is sorted by the file data conservation point correspondence sorting function during the backup process of the doctor's patient communication means or the doctor's patient communication smart contract (or server application) in a state where the large modified file data has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area on a selected file server of a specific sub-component, and the information of the specific sub-component file server where the large modified file data has been encrypted, divided into multiple pieces, and uploaded to the first temporary storage area is recorded as second index information on the nodes of each base belonging to each of the distributed file management groups.

14. Each of the modified file data distribution saving means or the smart contract (or server application) for the modified file data distribution saving records the encrypted and divided data in a predetermined sub-configuration file server connected to the node of each base belonging to each of the distributed file management groups and the recording device of a plurality of bases connected to the node of the base via a network. The encrypted and divided data is uploaded to the first temporary storage area, and the file data is sorted by the file data preservation point association sorting function at the time of saving processing of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication. The large modified file data linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function is sorted by the file data preservation point association sorting function at the time of saving processing of the doctor-side patient communication means or the smart contract (or server application) for the doctor-side patient communication. When the upper limit of the server's recording capacity is exceeded, for the modified file data that exceeds the upper limit of the file server's recording capacity, the recording capacity available at each base node belonging to each of the distributed file management groups and at each of the other sub-configuration file servers connected to recording devices at multiple bases connected to the base node via a network is calculated, and based on the calculated recording capacity, the file server of the sub-configuration that is the optimal recording destination is selected, the data is recorded on the selected sub-configuration file server, and the original file server is changed to a dormant state, and the information of the sub-configuration file servers that are the recording destination is recorded (updated) as second index information on each base node belonging to each of the distributed file management groups.

15. The modified file data extraction means or the smart contract (or server application) for extracting modified file data refers to the second index information recorded in the node of each base belonging to each of the distributed file management groups, and sorts the encrypted and divided file data recorded as the second index information by the file data preservation point association sorting function at the time of evacuation processing of the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, and sorts the large modified file data linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 14 has the function of detecting a file server, extracting modified file data recorded on the sub-configuration file server from the multiple sub-configuration file servers, combining the multiple extracted modified file data, and sorting the original encrypted and divided multiple pieces by the file data preservation point correspondence sorting function during the backup process of the doctor's patient communication means or the doctor's patient communication smart contract (or server application), and restoring the large modified file data linked to the information of the preservation point managed in a black box environment by the file data preservation point information management function.

16. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 1, characterized in that the electronic medical record data secret sharing and division function during the backup process is a function that uses polynomial division processing secret sharing technology to secret share the electronic medical record data of the patient and divide it into multiple file data.

17. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 3, characterized in that the electronic medical record data secret sharing and division function during the update process is a function that uses polynomial division processing secret sharing technology to secret share the electronic medical record data of the patient and divide it into multiple file data.

18. The encrypted index information recording means or the smart contract (or server application) for recording encrypted index information has a function of encrypting the index information created by the index information creation means or the smart contract (or server application) for creating index information in a black-box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, The modified file data distributed saving means or the smart contract (or server application) for distributed saving of modified file data has a function of allocating each of the file data modified by the file data modification means for saving or the smart contract (or server application) for modifying file data for saving to a plurality of distributed file management groups constructed by each base node constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, and distributing and saving the allocated modified file data for each conservation point to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and recording devices at multiple bases connected to the base nodes via a network.

11. A real-time save / restore type electronic medical record data guard service providing system according to claim 1, 2 or 10.

19. The encrypted index information recording means or the smart contract (or server application) for recording encrypted index information has a function of encrypting the index information created by the index information creation means or the smart contract (or server application) for creating index information in a black-box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, The modified file data distributed saving means or the smart contract (or server application) for distributed saving of modified file data has a function of allocating each of the file data modified by the file data modification means for saving or the smart contract (or server application) for modifying file data for saving to a plurality of distributed file management groups constructed by each base node constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, and distributing and saving the allocated modified file data for each conservation point to each base node belonging to the distributed file group in a closed blockchain corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network.

11. A real-time save / restore type electronic medical record data guard service providing system according to claim 1, 2 or 10.

20. The update processing encrypted index information recording means or the update processing encrypted index information recording smart contract (or server application) has a function of encrypting the index information created by the update processing index information creation means or the update processing index information creation smart contract (or server application) in a black box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, The update processing modified file data distributed evacuation means or update processing modified file data distributed evacuation smart contract (or server application) has a function of allocating each of the file data modified by the update file data modification means or update file data modification smart contract (or server application) to a plurality of the distributed file management groups constructed by each base node constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, and distributing and saving the allocated modified file data for each conservation point to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and recording devices at multiple bases connected to the base nodes via a network.

12. The real-time save / restore type electronic medical record data guard service providing system according to claim 3 or 11.

21. The update processing encrypted index information recording means or the update processing encrypted index information recording smart contract (or server application) has a function of encrypting the index information created by the update processing index information creation means or the update processing index information creation smart contract (or server application) in a black box environment and recording it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure, The update processing modified file data distributed evacuation means or update processing modified file data distributed evacuation smart contract (or server application) has a function of allocating each of the file data modified by the update file data modification means or update file data modification smart contract (or server application) to a plurality of the distributed file management groups constructed by each base node constituting the planet corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network, and distributing and evacuating the allocated modified file data for each conservation point to each base node belonging to the distributed file group in a closed blockchain corresponding to the conservation point and recording devices at multiple bases connected to the base nodes via a network.

12. The real-time save / restore type electronic medical record data guard service providing system according to claim 3 or 11.

22. When the data of the electronic medical record consists of main information consisting of medical records, the data volume of which is less than the capacity of the block size, and sub-information consisting of images such as X-rays accompanying the medical records, the data volume of which exceeds the capacity of the block size, The electronic medical record data encryption function at the time of the saving process, the electronic medical record data secret distribution and division function at the time of the saving process, the file data upload function at the time of the saving process, the file data integration function at the time of the restoration process, the electronic medical record data decryption function at the time of the restoration process, the file data preservation point correspondence sorting function at the time of the saving process in the doctor-side patient communication means or the smart contract (or server application) for doctor-side patient communication, the file data preservation point information management function, the file data transfer function for saving, the file data receiving function for restoring, the file data receiving means for saving or the smart contract (or server application) for receiving file data for saving, the file data modification means for saving or the smart contract (or server application) for modifying file data for saving, the modified file data distribution saving means or the modified file data distribution a smart contract (or server application) for saving, the index information creation means or a smart contract (or server application) for creating index information, the encrypted index information recording means or a smart contract (or server application) for recording encrypted index information, the encrypted index information reading means or a smart contract (or server application) for reading encrypted index information in the operator-side file data real-time retrieval system, the index information decryption means or a smart contract (or server application) for decrypting index information, the distributed save destination node analysis means or a smart contract (or server application) for analyzing distributed save destination nodes, the modified file data extraction means or a smart contract (or server application) for extracting modified file data, the file data pre-modification state restoration means or a smart contract (or server application) for restoring file data to its pre-modification state,The real-time save / restore type electronic medical record data guard service providing system according to any one of claims 1, 2 and 10, characterized in that the restoration file data transfer means or the restoration file data transfer smart contract (or server application) is configured to process the main information and sub-information of the electronic medical record separately.

23. When the data of the electronic medical record consists of main information consisting of medical records, the data volume of which is less than the capacity of the block size, and sub-information consisting of images such as X-rays accompanying the medical records, the data volume of which exceeds the capacity of the block size, the electronic medical record data encryption function at the time of update processing, the electronic medical record data secret distribution and division function at the time of update processing, the file data upload function at the time of update processing, the file data integration function at the time of restoration processing, the electronic medical record data decryption function at the time of restoration processing, the file data preservation point correspondence sorting function at the time of update processing, the file data preservation point information management function, the file data transfer function for saving at the time of update processing, the file data reception function for restoration, the file data reception means for saving at the time of update processing or a smart contract (or server application) for receiving file data for saving at the time of update processing, the file data modification means for saving at the time of update processing or a smart contract (or server application) for modifying file data for saving at the time of update processing, the modified file data distribution and evacuation means for updating processing or a smart contract (or server application) for modifying file data for saving at the time of update processing, a smart contract (or server application) for distributed backup of file data, the index information creation means at update processing or a smart contract (or server application) for creating index information at update processing, the encrypted index information recording means at update processing or a smart contract (or server application) for recording encrypted index information at update processing, the encrypted index information reading means or a smart contract (or server application) for reading encrypted index information in the operator-side file data real-time retrieval system, the index information decryption means or a smart contract (or server application) for decrypting index information, the distributed backup destination node analysis means or a smart contract (or server application) for analyzing distributed backup destination nodes, the modified file data extraction means or a smart contract (or server application) for extracting modified file data, the file data pre-modification state restoration means or a smart contract (or server application) for restoring file data to its pre-modification state,The real-time save / restore type electronic medical record data guard service providing system according to claim 3 or 11, characterized in that the restoration file data transfer means or the restoration file data transfer smart contract (or server application) is configured to process the main information and sub-information of the electronic medical record separately.

24. The modified file data distribution and evacuation means or the smart contract (or server application) for distributed evacuation of modified file data distributes and evacuates the modified file data of the main information of the electronic medical record to each base node belonging to a distributed file group in a closed blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the base node via a network, and distributes and evacuates the modified file data of the sub-information of the electronic medical record to each base node belonging to a distributed file group configured separately from the blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the base node via a network, The encrypted index information recording means or the smart contract (or server application) for recording encrypted index information encrypts the index information of the main information and sub-information of the electronic medical record created by the index information creation means or the smart contract (or server application) for creating index information in a black box environment and records it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure.

23. The real-time save / restore type electronic medical record data guard service providing system according to claim 22, which is configured as follows:

25. The update processing modified file data distribution and evacuation means or update processing modified file data distribution and evacuation smart contract (or server application) distributes and evacuation of the modified file data of the main information of the electronic medical record to each base node belonging to a distributed file group in a closed blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the base node via a network, and distributes and evacuation of the modified file data of the sub-information of the electronic medical record to each base node belonging to a distributed file group configured separately from the blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the base node via a network, The update processing encrypted index information recording means or the update processing encrypted index information recording smart contract (or server application) encrypts the index information of the main information and sub-information of the electronic medical record created by the update processing index information creation means or the update processing index information creation smart contract (or server application) in a black box environment and records it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure.

24. The real-time save / restore type electronic medical record data guard service providing system according to claim 23, which is configured as follows:

26. The modified file data distribution and evacuation means or the smart contract (or server application) for distributed evacuation of modified file data distributes and evacuates the modified file data of the main information of the electronic medical record to each base node belonging to a distributed file group in a closed or open blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the base node via a network, and distributes and evacuates the modified file data of the sub-information of the electronic medical record to each base node belonging to a distributed file group configured separately from the blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the base node via a network, The encrypted index information recording means or the smart contract (or server application) for recording encrypted index information encrypts the index information of the main information and sub-information of the electronic medical record created by the index information creation means or the smart contract (or server application) for creating index information in a black box environment and records it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure.

23. The real-time save / restore type electronic medical record data guard service providing system according to claim 22, which is configured as follows:

27. The means for distributing and saving modified file data during update processing or the smart contract (or server application) for distributing and saving modified file data during update processing distributarily saves the modified file data of the main information of the electronic medical record to each base node belonging to a distributed file group in a closed or open blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the node of the base via a network, and also distributes and saves the modified file data of the sub-information of the electronic medical record to each base node belonging to a distributed file group configured separately from the blockchain corresponding to the maintenance point and to recording devices at multiple bases connected to the node of the base via a network, The update processing encrypted index information recording means or the update processing encrypted index information recording smart contract (or server application) encrypts the index information of the main information and sub-information of the electronic medical record created by the update processing index information creation means or the update processing index information creation smart contract (or server application) in a black box environment and records it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure.

24. The real-time save / restore type electronic medical record data guard service providing system according to claim 23, which is configured as follows:

28. The modified file data distribution and evacuation means or the smart contract (or server application) for distributed evacuation of modified file data distributes and evacuates the modified file data of each of the main information of the electronic medical record and the sub-information of the electronic medical record for each conservation point to each base node belonging to a distributed file group configured separately from the blockchain and connected to the base node via a network, The encrypted index information recording means or the smart contract (or server application) for recording encrypted index information encrypts the index information of the main information and sub-information of the electronic medical record created by the index information creation means or the smart contract (or server application) for creating index information in a black box environment and records it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure.

23. The real-time save / restore type electronic medical record data guard service providing system according to claim 22, which is configured as follows:

29. The update processing modified file data distribution and evacuation means or the update processing modified file data distribution and evacuation smart contract (or server application) distributes and evacuates the modified file data of the main information of the electronic medical record and the sub-information of the electronic medical record for each conservation point to each base node belonging to a distributed file group configured separately from the blockchain and connected to the base node via a network, The update processing encrypted index information recording means or the update processing encrypted index information recording smart contract (or server application) encrypts the index information of the main information and sub-information of the electronic medical record created by the update processing index information creation means or the update processing index information creation smart contract (or server application) in a black box environment and records it in a node group at a specific location in the closed or open blockchain of the distributed ledger structure.

24. The real-time save / restore type electronic medical record data guard service providing system according to claim 23, which is configured as follows:

30. When the data of the electronic medical record consists of main information consisting of medical records, the data volume of which is less than the capacity of the block size, and sub-information consisting of images such as X-rays accompanying the medical records, the data volume of which exceeds the capacity of the block size, A real-time backup and restoration type electronic medical record data guard service providing system as described in any one of claims 24, 26 and 28, characterized in that the encrypted index information reading means at the time of deletion processing or a smart contract (or server application) for reading encrypted index information at the time of deletion processing, the index information decryption means at the time of deletion processing or a smart contract (or server application) for decrypting index information at the time of deletion processing, the distributed backup destination node analysis means at the time of deletion processing or a smart contract (or server application) for analyzing distributed backup destination nodes at the time of deletion processing, the modified file data deletion means at the time of deletion processing or a smart contract (or server application) for deleting modified file data at the time of deletion processing, and the file data preservation point information deletion means or a smart contract (or server application) for deleting file data preservation point information in the second operator side file data real-time deletion system are configured to process the main information and sub-information of the electronic medical record separately.

31. When the data of the electronic medical record consists of main information consisting of medical records, the data volume of which is less than the capacity of the block size, and sub-information consisting of images such as X-rays accompanying the medical records, the data volume of which exceeds the capacity of the block size, A real-time backup and restoration type electronic medical record data guard service providing system as described in any one of claims 25, 27, and 29, characterized in that the update processing encrypted index information reading means or smart contract (or server application) for reading encrypted index information during update processing, the update processing index information decryption means or smart contract (or server application) for decrypting index information during update processing, the update processing distributed backup destination node analysis means or smart contract (or server application) for analyzing distributed backup destination nodes during update processing, the update processing modified file data deletion means or smart contract (or server application) for deleting file data modified during update processing, and the file data preservation point information deletion means or smart contract (or server application) for deleting file data preservation point information in the second operation manager side file data real-time deletion system are configured to process the main information and sub-information of the electronic medical record separately.

32. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 24, characterized in that the modified file data deletion means during deletion processing or the smart contract (or server application) for deleting modified file data during deletion processing in the operator-side file data real-time deletion system is configured to delete, for each conservation point, the modified file data of the main information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group in a closed blockchain corresponding to the conservation point and to multiple base recording devices connected to the base node via a network, and to delete, for each conservation point, the modified file data of the sub-information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group configured separately from the blockchain corresponding to the conservation point and to multiple base recording devices connected to the base node via a network.

33. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 25, characterized in that the means for deleting modified file data during update processing or the smart contract (or server application) for deleting modified file data during update processing in the operating manager side file data real-time update system is configured to delete, for each conservation point, the modified file data of the main information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group in a closed blockchain corresponding to the conservation point and to multiple base recording devices connected to the base node via a network, and to delete, for each conservation point, the modified file data of the sub-information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group configured separately from the blockchain corresponding to the conservation point and to multiple base recording devices connected to the base node via a network.

34. The means for deleting modified file data during deletion processing or the smart contract (or server application) for deleting modified file data during deletion processing in the system for real-time file data deletion on the administrator side deletes, for each conservation point, the modified file data of the sub-information of the electronic medical record that is distributed and saved to the nodes of each base belonging to a distributed file group configured separately from the blockchain and connected to the nodes of the base via a network, The file data preservation point information deletion means or the smart contract (or server application) for deleting file data preservation point information in the second operator-side file data real-time deletion system is configured to delete the preservation point information linked to the file data of the main information of the electronic medical record to be deleted, which is distributed and saved to the nodes of each location belonging to a distributed file group in a closed or open blockchain and to recording devices of multiple locations connected to the nodes of the location via a network, and is managed in a black box environment by the file data preservation point information management function.

35. The means for deleting file data modified during update processing or the smart contract (or server application) for deleting file data modified during update processing in the file data real-time update system on the administrator side deletes, for each conservation point, the modified file data of the sub-information of the electronic medical record that is distributed and saved to the nodes of each base belonging to a distributed file group configured separately from the blockchain and connected to the nodes of the base via a network, The real-time backup and restoration type electronic medical record data guard service provision system described in claim 27, characterized in that the file data preservation point information deletion means or file data preservation point information deletion smart contract (or server application) in the second operator side file data real-time deletion system is configured to delete the preservation point information linked to the file data of the main information of the electronic medical record to be deleted, which is distributed and saved to each base node belonging to a distributed file group in a closed or open blockchain and to multiple base recording devices connected to the base node via a network, and which is managed in a black box environment by the file data preservation point information management function.

36. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 28, characterized in that the modified file data deletion means during deletion processing or the smart contract (or server application) for deleting modified file data during deletion processing in the operator's side file data real-time deletion system is configured to delete, for each conservation point, the modified file data of each of the main information and sub-information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and to recording devices at multiple bases connected to the base node via a network.

37. The real-time backup and restoration type electronic medical record data guard service provision system described in claim 29, characterized in that the means for deleting modified file data during update processing or the smart contract (or server application) for deleting modified file data during update processing in the file data real-time update system on the operator's side is configured to delete, for each conservation point, the modified file data of each of the main information and sub-information of the electronic medical record that is distributed and saved to each base node belonging to a distributed file group configured separately from the blockchain and corresponding to the conservation point, and to recording devices at multiple bases connected to the base node via a network.