Electronic prescription operation method, device and system
Abstract
The invention discloses an electronic prescription operation method and device and an electronic prescription operation system. The electronic prescription operation method comprises the steps that a client side sends an electronic prescription operation request of a user to an electronic prescription management system; after the electronic prescription management system receives the operation request, by means of interaction with a hospital information system, the client side and/or a third party, the operation request is processed, wherein when both interaction parties taking part in processing the operation request transmit private data of the user, a sender uses a sharing quantum secrete for encryption, and a receiver uses a corresponding sharing quantum for decryption; the sharing quantum secretes are acquired by the sender and the receiver through a quantum secrete distribution protocol in a negotiation mode in advance. In this way, on one hand, the safety of the private data of the user is effectively guaranteed through the characters of the quantum secrete; on the other hand, anonymity authentication can be achieved, the certificate authority process is simplified, and the execution efficiency can be improved.
Term
8.8 yearsto projected expiry
Projected expiry 26 June 2035, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
49 claims: 26 independent, 23 dependent
- 1An electronic prescription operation method, which is characterized by comprising:a client sends a user's electronic prescription operation request to an electronic prescription management system;after receiving the operation request, the electronic prescription management system communicates with the hospital information system, the client and/or The interaction process between the third parties completes the processing of the operation request;wherein, when the two interacting parties involved in processing the operation request transmit user privacy data, the sender uses shared quantum key encryption, and the receiver uses the corresponding sharing Quantum key decryption;the shared quantum key is obtained by the sender and the receiver in advance through a quantum key distribution protocol. 1. 一种电子处方操作方法,其特征在于,包括: 客户端向电子处方管理系统发送用户的电子处方操作请求; 电子处方管理系统接收所述操作请求后,通过与医院信息系统、客户端和/或第三方 之间的交互过程,完成对所述操作请求的处理; 其中,参与处理所述操作请求的交互双方在传输用户隐私数据时,发送方采用共享量 子密钥加密,接收方采用相应的共享量子密钥解密;所述共享量子密钥是所述发送方与所 述接收方预先通过量子密钥分发协议协商获取的。
- 2023. 根据权利要求1-22任一项所述的电子处方操作方法,其特征在于,参与处理所述 操作请求的交互双方之间的数据传输是基于HTTPS连接的,并且交互双方各自所采用的数 字证书均为可信任第三方颁发。 twenty three. The electronic prescription operation method according to any one of claims 1-22, characterized in that the data transmission between the interactive parties involved in processing the operation request is based on HTTPS connection, and the digital certificates used by the interactive parties All are issued by a trusted third party.
- 2124. 根据权利要求1-22任一项所述的电子处方操作方法,其特征在于,参与处理所述 操作请求的交互双方之间在通过量子密钥分发协议协商共享量子密钥之前,执行双向身份 认证,并在认证通过后启动所述协商过程。 twenty four. The electronic prescription operation method according to any one of claims 1-22, wherein the two interacting parties involved in processing the operation request perform two-way identity authentication before negotiating to share a quantum key through a quantum key distribution protocol. , And start the negotiation process after the authentication is passed.
- 2225. An electronic prescription operation device, characterized by comprising:an operation request sending unit, used for a client to send a user's electronic prescription operation request to an electronic prescription management system;an operation request processing unit, used for an electronic prescription management system to receive the operation After the request, through the interaction process with the hospital information system, the client and/or the third party, the processing of the operation request is completed;wherein, the operation request sending unit and the operation request processing unit each include a quantum secret The key encryption and decryption sub-unit is used for both parties involved in processing the operation request when transmitting user privacy data, the sender uses the shared quantum key for encryption, and the receiver uses the corresponding shared quantum key for decryption;the shared quantum key It is obtained by the sender and the receiver through a quantum key distribution protocol negotiation in advance. 25. 一种电子处方操作装置,其特征在于,包括: 操作请求发送单元,用于客户端向电子处方管理系统发送用户的电子处方操作请求; 操作请求处理单元,用于电子处方管理系统接收所述操作请求后,通过与医院信息系 统、客户端和/或第三方之间的交互过程,完成对所述操作请求的处理; 其中,所述操作请求发送单元和所述操作请求处理单元各自包括量子密钥加解密子单 元,用于参与处理所述操作请求的交互双方在传输用户隐私数据时,发送方采用共享量子 密钥加密,接收方采用相应的共享量子密钥解密;所述共享量子密钥是所述发送方与所述 接收方预先通过量子密钥分发协议协商获取的。
- 2731. A request method for establishing a binding relationship, characterized in that the method is implemented on the client side, and includes:using a preset hash algorithm to calculate a hash value of user privacy data used to verify user identity, so The user refers to a user who initiates a binding relationship establishment request;a binding relationship establishment request is sent to an electronic prescription management system, and the request carries the user's identity, the hash value, and the information of the hospital for which the binding relationship is to be established The identification of the system and the identification of the patient of the user corresponding to the hospital information system, wherein at least the hash value is encrypted using a shared quantum key with the electronic prescription management system. 31. 一种用于建立绑定关系的请求方法,其特征在于,所述方法在客户端实施,包括: 采用预设的散列算法,计算用于验证用户身份的用户隐私数据的散列值,所述用户是 指发起绑定关系建立请求的用户; 向电子处方管理系统发送绑定关系建立请求,所述请求中携带所述用户的标识、所述 散列值、待建立绑定关系的医院信息系统的标识、以及所述用户对应于所述医院信息系统 的患者标识,其中,至少所述散列值是采用与所述电子处方管理系统之间的共享量子密钥 加密的。
- 2832. A request device for establishing a binding relationship, characterized in that the device is deployed on a client, and includes:a hash value calculation unit, configured to use a preset hash algorithm to calculate a user for verifying user identity The hash value of the private data;the binding request encryption sending unit, which sends a binding relationship establishment request to the electronic prescription management system, the request carrying the user's identity, the hash value, and the hospital whose binding relationship is to be established The identification of the information system and the patient identification of the user corresponding to the hospital information system, wherein at least the hash value is encrypted using a shared quantum key with the electronic prescription management system. 32. 一种用于建立绑定关系的请求装置,其特征在于,所述装置部署于客户端,包括: 散列值计算单元,用于采用预设的散列算法,计算用于验证用户身份的用户隐私数据 的散列值; 绑定请求加密发送单元,向电子处方管理系统发送绑定关系建立请求,所述请求中携 带所述用户的标识、所述散列值、待建立绑定关系的医院信息系统的标识、以及所述用户对 应于所述医院信息系统的患者标识,其中,至少所述散列值是采用与所述电子处方管理系 统之间的共享量子密钥加密的。
- 2933. A method for establishing a binding relationship, characterized in that the method is implemented in an electronic prescription management system, and includes:receiving a binding relationship establishment request sent by a client;using a shared quantum with the client The key performs corresponding decryption operations on the information carried in the request, and obtains the user ID, the hash value, the hospital information system ID, and the patient ID;according to the obtained hospital information system ID, the hash value, and The binding verification request of the patient identification is forwarded to the corresponding hospital information system, wherein at least the hash value is encrypted using a shared quantum key with the hospital information system;receiving the information sent by the hospital information system The verification passes the response, and the mapping relationship between the user ID, the hospital information system ID and the patient ID is established, and the binding operation is completed. 33. —种用于建立绑定关系的方法,其特征在于,所述方法在电子处方管理系统中实 施,包括: 接收客户端发送的绑定关系建立请求; 采用与所述客户端之间的共享量子密钥对所述请求中携带的信息执行相应的解密操 作,获取用户标识、散列值、医院信息系统标识、以及患者标识; 根据获取的医院信息系统标识,将携带所述散列值、以及所述患者标识的绑定验证请 求转发给相应的医院信息系统,其中至少所述散列值是采用与所述医院信息系统之间的共 享量子密钥加密的; 接收所述医院信息系统发送的验证通过应答,并建立所述用户标识、所述医院信息系 统标识与所述患者标识之间的映射关系,完成绑定操作。
- 3034. A device for establishing a binding relationship, characterized in that the device is deployed in an electronic prescription management system, and includes:a binding establishment request receiving unit, configured to receive a binding relationship establishment request sent by a client;and binding establishment The request decryption unit is configured to use the shared quantum key with the client to perform a corresponding decryption operation on the information carried in the request, and obtain a user ID, a hash value, a hospital information system ID, and a patient ID;The binding verification request encryption forwarding unit is configured to forward the binding verification request carrying the hash value and the patient identification to the corresponding hospital information system according to the acquired hospital information system identifier, wherein at least the hash value The value is encrypted using the shared quantum key with the hospital information system;the binding relationship establishment unit is used to receive the verification pass response sent by the hospital information system, and establish the user identification and the hospital information The mapping relationship between the system identifier and the patient identifier completes the binding operation. 34. 一种用于建立绑定关系的装置,其特征在于,所述装置部署于电子处方管理系统, 包括: 绑定建立请求接收单元,用于接收客户端发送的绑定关系建立请求; 绑定建立请求解密单元,用于采用与所述客户端之间的共享量子密钥对所述请求中 携带的信息执行相应的解密操作,获取用户标识、散列值、医院信息系统标识、以及患者标 识; 绑定验证请求加密转发单元,用于根据获取的医院信息系统标识,将携带所述散列值、 以及所述患者标识的绑定验证请求转发给相应的医院信息系统,其中至少所述散列值是采 用与所述医院信息系统之间的共享量子密钥加密的; 绑定关系建立单元,用于接收所述医院信息系统发送的验证通过应答,并建立所述用 户标识、所述医院信息系统标识与所述患者标识之间的映射关系,完成绑定操作。
- 3135. A method for verifying a binding relationship, characterized in that the method is implemented in a hospital information system, and includes:35. 一种用于验证绑定关系的方法,其特征在于,所述方法在医院信息系统中实施,包 括: Receiving a binding verification request sent by an electronic prescription management system;using the shared quantum key with the electronic prescription management system to perform a corresponding decryption operation on the information carried in the request to obtain a hash value and a patient identification;According to the received patient identification, look up the preset user privacy data used to verify the user identity, use the preset hash algorithm to calculate the hash value of the user privacy data found, and determine whether the calculated hash value is different from the Whether the hash values obtained in the request are consistent;if they are consistent, a verification pass response is sent to the electronic prescription management system. 接收电子处方管理系统发送的绑定验证请求; 采用与所述电子处方管理系统之间的共享量子密钥对所述请求中携带的信息执行相 应的解密操作,获取散列值、以及患者标识; 根据接收的患者标识查找预置的、用于验证用户身份的用户隐私数据,采用预设的散 列算法计算找到的用户隐私数据的散列值,并判断计算得到的散列值与从所述请求中获取 的散列值是否一致; 若一致,向所述电子处方管理系统发送验证通过应答。
- 3236. A device for verifying a binding relationship, characterized in that the method is deployed in a hospital information system and includes:a binding verification request receiving unit for receiving a binding verification request sent by an electronic prescription management system;binding verification The request decryption unit is configured to use the shared quantum key with the electronic prescription management system to perform corresponding decryption operations on the information carried in the request to obtain the hash value and the patient identification;hash value calculation and comparison The unit is used to find preset user privacy data used to verify user identity according to the received patient identification, calculate the hash value of the user privacy data found by using a preset hash algorithm, and determine the calculated hash value Whether it is consistent with the hash value obtained from the request;the verification pass response unit is used to send a verification pass response to the electronic prescription management system when the output of the hash value calculation and comparison unit is yes. 36. —种用于验证绑定关系的装置,其特征在于,所述方法部署于医院信息系统,包 括: 绑定验证请求接收单元,用于接收电子处方管理系统发送的绑定验证请求; 绑定验证请求解密单元,用于采用与所述电子处方管理系统之间的共享量子密钥对所 述请求中携带的信息执行相应的解密操作,获取散列值、以及患者标识; 散列值计算比对单元,用于根据接收的患者标识查找预置的、用于验证用户身份的用 户隐私数据,采用预设的散列算法计算找到的用户隐私数据的散列值,并判断计算得到的 散列值与从所述请求中获取的散列值是否一致; 验证通过应答单元,用于当所述散列值计算比对单元的输出为是时,向所述电子处方 管理系统发送验证通过应答。
- 3337. A request method for updating a shared key, characterized in that the method is implemented on a client side, and includes:generating a new shared key for the user to be updated with the shared key and the hospital information system, and using the user and the hospital information system to generate a new shared key. The shared key currently used by the hospital information system encrypts the new shared key;sends a shared key update request to the electronic prescription management system, the request carries the user's identity and the hospital information system's identity And the encrypted new shared key, wherein at least the encrypted new shared key is encrypted using a shared quantum key with the electronic prescription management system. 37. 一种用于更新共享密钥的请求方法,其特征在于,所述方法在客户端实施,包括: 为待更新共享密钥的用户和医院信息系统生成新共享密钥,并采用所述用户与所述医 院信息系统当前采用的共享密钥对所述新共享密钥加密; 向电子处方管理系统发送共享密钥更新请求,所述请求中携带所述用户的标识、所述 医院信息系统的标识、以及所述加密后的新共享密钥,其中至少所述加密后的新共享密钥 是采用与所述电子处方管理系统之间的共享量子密钥加密的。 3& A request device for updating a shared key, characterized in that the device is deployed on the client, and includes: a new shared key generating unit, used to generate a new shared key for the user and the hospital information system to be updated The shared key is used to encrypt the new shared key with the shared key currently used by the user and the hospital information system;the key update request encryption sending unit is used to send the shared key update to the electronic prescription management system Request, the request carries the identity of the user, the identity of the hospital information system, and the encrypted new shared key, wherein at least the encrypted new shared key is used with the electronic prescription The shared quantum key between management systems is encrypted. 3& —种用于更新共享密钥的请求装置,其特征在于,所述装置部署于客户端,包括: 新共享密钥生成单元,用于为待更新共享密钥的用户和医院信息系统生成新共享密 钥,并采用所述用户与所述医院信息系统当前采用的共享密钥对所述新共享密钥加密; 密钥更新请求加密发送单元,用于向电子处方管理系统发送共享密钥更新请求,所述 请求中携带所述用户的标识、所述医院信息系统的标识、以及所述加密后的新共享密钥,其 中至少所述加密后的新共享密钥是采用与所述电子处方管理系统之间的共享量子密钥加 密的。
- 3439. A method for forwarding a shared key update request, characterized in that the method is implemented in an electronic prescription management system, and includes:receiving a shared key update request sent by a client;The shared quantum key performs corresponding decryption operations on the information carried in the request, and obtains the ciphertext of the new shared key, the user ID, and the hospital information system ID;according to the pre-established binding between the user and the hospital information system Relationship, find the patient ID corresponding to the user ID and the hospital information system ID;according to the acquired hospital information system ID, update the ciphertext carrying the new shared key and the shared key of the patient ID The request is forwarded to the corresponding hospital information system, where at least the ciphertext of the new shared key is used and 39. 一种用于转发共享密钥更新请求的方法,其特征在于,所述方法在电子处方管理系 统中实施,包括: 接收客户端发送的共享密钥更新请求; 采用与所述客户端之间的共享量子密钥对所述请求中携带的信息执行相应的解密操 作,获取新共享密钥的密文、用户标识、以及医院信息系统标识; 根据预先建立的用户与医院信息系统之间的绑定关系,查找与所述用户标识和所述医 院信息系统标识对应的患者标识; 根据获取的医院信息系统标识,将携带所述新共享密钥的密文、以及所述患者标识的 共享密钥更新请求转发给相应的医院信息系统,其中至少所述新共享密钥的密文是采用与 The shared quantum key between the hospital information systems is encrypted. 所述医院信息系统之间的共享量子密钥加密的。
- 3540. A device for forwarding a shared key update request, characterized in that the device is deployed in an electronic prescription management system, and includes:a key update request receiving unit for receiving a shared key update request sent by a client;The key update request decryption unit is used to use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext of the new shared key, user identification, and hospital information System identification;The patient identification search unit is used to search for the patient identification corresponding to the user identification and the hospital information system identification according to the pre-established binding relationship between the user and the hospital information system;the key update request is encrypted and forwarded Unit for forwarding the ciphertext carrying the new shared key and the shared key update request of the patient identification to the corresponding hospital information system according to the acquired hospital information system identification, wherein at least the new shared secret The ciphertext of the key is encrypted using a shared quantum key with the hospital information system. 40. 一种用于转发共享密钥更新请求的装置,其特征在于,所述装置部署于电子处方管 理系统,包括: 密钥更新请求接收单元,用于接收客户端发送的共享密钥更新请求; 密钥更新请求解密单元,用于采用与所述客户端之间的共享量子密钥对所述请求中 携带的信息执行相应的解密操作,获取新共享密钥的密文、用户标识、以及医院信息系统标 识; 患者标识查找单元,用于根据预先建立的用户与医院信息系统之间的绑定关系,查找 与所述用户标识和所述医院信息系统标识对应的患者标识; 密钥更新请求加密转发单元,用于根据获取的医院信息系统标识,将携带所述新共享 密钥的密文、以及所述患者标识的共享密钥更新请求转发给相应的医院信息系统,其中至 少所述新共享密钥的密文是采用与所述医院信息系统之间的共享量子密钥加密的。
- 3641. A method for updating a shared key, characterized in that the method is implemented in a hospital information system, and includes:receiving a shared key update request sent by an electronic prescription management system;The shared quantum key performs corresponding decryption operations on the information carried in the request to obtain the ciphertext of the new shared key and the patient identification;the shared key corresponding to the patient identification is used to pair the new shared key Decrypt the ciphertext of, and obtain a new shared key corresponding to the patient identification, that is, a new shared key between users corresponding to the patient identification. 41. 一种用于更新共享密钥的方法,其特征在于,所述方法在医院信息系统中实施,包 括: 接收电子处方管理系统发送的共享密钥更新请求; 采用与所述电子处方管理系统之间的共享量子密钥对所述请求中携带的信息执行相 应的解密操作,获取新共享密钥的密文、以及患者标识; 采用与所述患者标识对应的共享密钥对所述新共享密钥的密文解密,获取与所述患者 标识对应的新共享密钥,即与所述患者标识对应用户之间的新共享密钥。
- 3742. A device for updating a shared key, characterized in that the device is deployed in a hospital information system and includes:a forwarding request receiving unit for receiving a shared key update request sent by an electronic prescription management system;a forwarding request decryption unit , Used to use the shared quantum key with the electronic prescription management system to perform corresponding decryption operations on the information carried in the request, to obtain the ciphertext of the new shared key and the patient identification;new key acquisition unit , Used to decrypt the ciphertext of the new shared key by using the shared key corresponding to the patient identification, and obtain the new shared key corresponding to the patient identification, that is, the exchange between users corresponding to the patient identification New shared key. 42. —种用于更新共享密钥的装置,其特征在于,所述装置部署于医院信息系统,包 括: 转发请求接收单元,用于接收电子处方管理系统发送的共享密钥更新请求; 转发请求解密单元,用于采用与所述电子处方管理系统之间的共享量子密钥对所述请 求中携带的信息执行相应的解密操作,获取新共享密钥的密文、以及患者标识; 新密钥获取单元,用于采用与所述患者标识对应的共享密钥对所述新共享密钥的密文 解密,获取与所述患者标识对应的新共享密钥,即与所述患者标识对应用户之间的新共享 密钥。
- 3843. A request method for obtaining an electronic prescription, characterized in that the method is implemented on a client side, and includes:sending an electronic prescription obtaining request to an electronic prescription management system, the request carrying the identification of the user who initiated the request, The identification of the hospital information system that provides the electronic prescription and the identification of the electronic prescription;receiving the electronic prescription sent by the electronic prescription management system;using the shared quantum key with the electronic prescription management system to decrypt the received electronic prescription, and The decrypted electronic prescription is decrypted again by using the shared key between the user and the hospital information system to obtain the original information of the electronic prescription. 43. 一种用于获取电子处方的请求方法,其特征在于,所述方法在客户端实施,包括: 向电子处方管理系统发送电子处方获取请求,所述请求中携带发起所述请求的用户的 标识、提供电子处方的医院信息系统的标识、以及电子处方标识; 接收所述电子处方管理系统发送的电子处方; 采用与所述电子处方管理系统之间的共享量子密钥对接收的电子处方解密,并采用所 述用户与所述医院信息系统之间的共享密钥对解密后的电子处方再次解密,获取所述电子 处方的原始信息。
- 3944. A request device for obtaining an electronic prescription, characterized in that the device is deployed on a client side, and includes:a prescription obtaining request sending unit for sending an electronic prescription obtaining request to an electronic prescription management system, the request carrying an initiation The identification of the requested user, the identification of the hospital information system that provides the electronic prescription, and the identification of the electronic prescription;a prescription information receiving unit for receiving the electronic prescription sent by the electronic prescription management system;44. 一种用于获取电子处方的请求装置,其特征在于,所述装置部署于客户端,包括: 处方获取请求发送单元,用于向电子处方管理系统发送电子处方获取请求,所述请求 中携带发起所述请求的用户的标识、提供电子处方的医院信息系统的标识、以及电子处方 标识; 处方信息接收单元,用于接收所述电子处方管理系统发送的电子处方; The original prescription acquisition unit is used to decrypt the received electronic prescription using the shared quantum key with the electronic prescription management system, and to decrypt the received electronic prescription using the shared key between the user and the hospital information system The electronic prescription is decrypted again, and the original information of the electronic prescription is obtained. 原始处方获取单元,用于采用与所述电子处方管理系统之间的共享量子密钥对接收的 电子处方解密,并采用所述用户与所述医院信息系统之间的共享密钥对解密后的电子处方 再次解密,获取所述电子处方的原始信息。
- 4045. A method for forwarding electronic prescriptions, characterized in that the method is implemented in an electronic prescription management system, including:receiving an electronic prescription acquisition request sent by a client, and acquiring the user identification and hospital information system carried in the request Identification and electronic prescription identification;determine whether the electronic prescription corresponding to the user identification and the electronic prescription identification is stored, if yes, obtain the stored electronic prescription, if not, obtain the electronic prescription from the hospital information system Using the shared quantum key with the client to encrypt the acquired electronic prescription and send it to the client;wherein, the acquiring the electronic prescription from the hospital information system includes: Establish the binding relationship between the user and the hospital information system, search for the patient ID corresponding to the user ID and the hospital information system ID;and according to the hospital information system ID, carry the patient ID and the hospital information system ID The electronic prescription acquisition request of the electronic prescription identification is sent to the corresponding hospital information system;the electronic prescription corresponding to the user identification and the electronic prescription identification sent by the hospital information system is received;Decrypt the received electronic prescription as the electronic prescription obtained from the hospital information system, and store the electronic prescription. 45. —种用于转发电子处方的方法,其特征在于,所述方法在电子处方管理系统中实 施,包括: 接收客户端发送的电子处方获取请求,获取所述请求中携带的用户标识、医院信息系 统标识、以及电子处方标识; 判断是否存储了与所述用户标识和所述电子处方标识对应的电子处方,若是,获取所 述已存储的电子处方,若否,从医院信息系统获取所述电子处方; 采用与所述客户端之间的共享量子密钥,对所述获取的电子处方加密、并发送给所述 客户端; 其中,所述从医院信息系统获取所述电子处方,包括: 根据预先建立的用户与医院信息系统之间的绑定关系,查找与所述用户标识和所述医 院信息系统标识对应的患者标识;并根据所述医院信息系统标识,将携带所述患者标识和 所述电子处方标识的电子处方获取请求发送给相应的医院信息系统; 接收所述医院信息系统发送的、与所述用户标识和所述电子处方标识对应的电子处 方; 采用与所述医院信息系统之间的共享量子密钥对接收的所述电子处方解密,作为所述 从医院信息系统获取的电子处方,并存储所述电子处方。
- 4146. A device for forwarding electronic prescriptions, characterized in that the device is deployed in an electronic prescription management system, and includes:a prescription acquisition request receiving unit, configured to receive an electronic prescription acquisition request sent by a client, and the request carries The user ID, the hospital information system ID, and the electronic prescription ID of the electronic prescription;the electronic prescription acquisition unit is used to determine whether the electronic prescription corresponding to the user ID and the electronic prescription ID is stored, and if so, to obtain the stored electronic prescription. Prescription, if not, obtain the electronic prescription from the hospital information system;the electronic prescription encryption forwarding unit is used to use the shared quantum key with the client to encrypt the obtained electronic prescription and send it to the The client. 46. 一种用于转发电子处方的装置,其特征在于,所述装置部署于电子处方管理系统, 包括: 处方获取请求接收单元,用于接收客户端发送的电子处方获取请求,获取所述请求中 携带的用户标识、医院信息系统标识、以及电子处方标识; 电子处方获取单元,用于判断是否存储了与所述用户标识和所述电子处方标识对应的 电子处方,若是,获取所述已存储的电子处方,若否,从医院信息系统获取所述电子处方; 电子处方加密转发单元,用于采用与所述客户端之间的共享量子密钥,对所述获取的 电子处方加密、并发送给所述客户端。
- 4247. A method for providing electronic prescriptions, characterized in that the method is implemented in a hospital information system, and includes:receiving an electronic prescription acquisition request sent by an electronic prescription management system, and acquiring the patient identification and the electronic prescription carried in the request Identification;find the electronic prescription corresponding to the patient identification and the electronic prescription identification;use the shared key corresponding to the patient identification to encrypt the electronic prescription, and use the shared quantum with the electronic prescription management system The encrypted electronic prescription is re-encrypted by the key and sent to the electronic prescription management system. 47. 一种用于提供电子处方的方法,其特征在于,所述方法在医院信息系统中实施,包 括: 接收电子处方管理系统发送的电子处方获取请求,获取所述请求中携带的患者标识和 电子处方标识; 查找与所述患者标识和所述电子处方标识对应的电子处方; 采用与所述患者标识对应的共享密钥对所述电子处方加密,采用与所述电子处方管 理系统之间的共享量子密钥对加密后的电子处方再次加密,并发送给所述电子处方管理系 统。 4& A device for providing electronic prescriptions, characterized in that the device is deployed in a hospital information system, and includes: a forwarding prescription acquisition request receiving unit, configured to receive an electronic prescription acquisition request sent by an electronic prescription management system, and obtain the The patient identification and electronic prescription identification carried in the request;4&一种用于提供电子处方的装置,其特征在于,所述装置部署于医院信息系统,包 括: 转发处方获取请求接收单元,用于接收电子处方管理系统发送的电子处方获取请求, 获取所述请求中携带的患者标识和电子处方标识; The electronic prescription search unit is used to search for the electronic prescription corresponding to the patient identification and the electronic prescription identification;the electronic prescription encryption sending unit is used to encrypt the electronic prescription by using the shared key corresponding to the patient identification, The encrypted electronic prescription is re-encrypted by using the shared quantum key with the electronic prescription management system and sent to the electronic prescription management system. 电子处方查找单元,用于查找与所述患者标识和所述电子处方标识对应的电子处方; 电子处方加密发送单元,用于采用与所述患者标识对应的共享密钥对所述电子处方加 密,采用与所述电子处方管理系统之间的共享量子密钥对加密后的电子处方再次加密,并 发送给所述电子处方管理系统。
- 4349. A request method for authorizing a third party, characterized in that the method is implemented on a client terminal, and includes:sending a request for authorizing a third party to an electronic prescription management system, the request carrying the identity of the user who initiated the request, The third-party identification and the electronic prescription identification authorized to view by the third party;receiving the electronic prescription sent by the electronic prescription management system;using the shared quantum key with the electronic prescription management system to decrypt the received electronic prescription, and using The shared key between the user and the hospital information system that provides the electronic prescription decrypts the decrypted electronic prescription again to obtain the original information of the electronic prescription;adopts the first third party with a corresponding decryption key The encryption key encrypts the original information of the electronic prescription, and sends the electronic prescription forwarding request carrying the third-party identification and the ciphertext of the electronic prescription to the electronic prescription management system, wherein at least the electronic prescription The ciphertext is encrypted using a shared quantum key with the electronic prescription management system. 49. 一种用于授权第三方的请求方法,其特征在于,所述方法在客户端实施,包括: 向电子处方管理系统发送授权第三方请求,所述请求中携带发起所述请求的用户的标 识、第三方标识、以及授权第三方查看的电子处方标识; 接收所述电子处方管理系统发送的电子处方; 采用与所述电子处方管理系统之间的共享量子密钥对接收的电子处方解密,并采用所 述用户与提供所述电子处方的医院信息系统之间的共享密钥对解密后的电子处方再次解 密,获取所述电子处方的原始信息; 采用所述第三方具有对应解密密钥的第一加密密钥对所述电子处方的原始信息加密, 并将携带所述第三方标识、以及所述电子处方密文的电子处方转发请求发送给所述电子处 方管理系统,其中,至少所述电子处方密文是采用与所述电子处方管理系统之间的共享量 子密钥加密的。
- 4450. A request device for authorizing a third party, characterized in that the device is deployed on a client, and includes:an authorized third party request sending unit for sending a request for authorizing a third party to an electronic prescription management system, and the request carries The identification of the user who initiated the request, the third-party identification, and the electronic prescription identification authorized for the third party to view;an electronic prescription receiving unit for receiving the electronic prescription sent by the electronic prescription management system;an original prescription acquiring unit for using The shared quantum key with the electronic prescription management system decrypts the received electronic prescription, and uses the shared key between the user and the hospital information system that provides the electronic prescription to decrypt the decrypted electronic prescription again , Obtain the original information of the electronic prescription;an electronic prescription encryption sending unit for encrypting the original information of the electronic prescription by using the first encryption key of the third party with a corresponding decryption key, and carrying the first encryption key The tripartite identification and the electronic prescription forwarding request of the electronic prescription ciphertext are sent to the electronic prescription management system, wherein at least the electronic prescription ciphertext is encrypted using a shared quantum key with the electronic prescription management system of. 50. 一种用于授权第三方的请求装置,其特征在于,所述装置部署于客户端,包括: 授权第三方请求发送单元,用于向电子处方管理系统发送授权第三方请求,所述请求 中携带发起所述请求的用户的标识、第三方标识、以及授权第三方查看的电子处方标识; 电子处方接收单元,用于接收所述电子处方管理系统发送的电子处方; 原始处方获取单元,用于采用与所述电子处方管理系统之间的共享量子密钥对接收的 电子处方解密,并采用所述用户与提供所述电子处方的医院信息系统之间的共享密钥对解 密后的电子处方再次解密,获取所述电子处方的原始信息; 电子处方加密发送单元,用于采用所述第三方具有对应解密密钥的第一加密密钥对所 述电子处方的原始信息加密,并将携带所述第三方标识、以及所述电子处方密文的电子处 方转发请求发送给所述电子处方管理系统,其中,至少所述电子处方密文是采用与所述电 子处方管理系统之间的共享量子密钥加密的。
- 4551. An electronic prescription forwarding method for authorizing a third party, characterized in that the method is implemented in an electronic prescription management system, and includes:receiving a third-party authorization request sent by a client, obtaining a user identification carried in the request, Third-party identification and electronic prescription identification;using the shared quantum key with the client to encrypt the electronic prescription corresponding to the user identification and the electronic prescription identification, and sending to the client;receiving The electronic prescription forwarding request sent by the client;using the shared quantum key with the client to perform the corresponding decryption operation on the information carried in the request to obtain the third-party identification and the electronic prescription;using the shared quantum key with the client The shared quantum key between the three parties encrypts the electronic prescription, and sends the encrypted electronic prescription to the corresponding third party according to the third-party identification. 51. 一种用于授权第三方的电子处方转发方法,其特征在于,所述方法在电子处方管理 系统中实施,包括: 接收客户端发送的授权第三方请求,获取所述请求中携带的用户标识、第三方标识、以 及电子处方标识; 采用与所述客户端之间的共享量子密钥,对与所述用户标识和所述电子处方标识对应 的电子处方加密,并发送给所述客户端; 接收客户端发送的电子处方转发请求; 采用与所述客户端之间的共享量子密钥对所述请求中携带的信息执行相应的解密操 作,获取第三方标识、以及电子处方; 采用与所述第三方之间的共享量子密钥对所述电子处方加密,并根据所述第三方标 识,将加密后的电子处方发送给相应的第三方。
- 4652. An electronic prescription forwarding device for authorizing a third party, characterized in that the device is deployed in an electronic prescription management system, and includes:52. 一种用于授权第三方的电子处方转发装置,其特征在于,所述装置部署于电子处方 管理系统,包括: The authorized third-party request receiving unit is used to receive the authorized third-party request sent by the client, and obtain the user ID, the third-party ID, and the electronic prescription ID carried in the request;the electronic prescription encryption forwarding unit is used to use the The shared quantum key between the clients encrypts the electronic prescription corresponding to the user ID and the electronic prescription ID, and sends it to the client;the prescription forwarding request receiving unit is used to receive the electronic prescription sent by the client Prescription forwarding request;prescription forwarding request decryption unit, configured to use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request to obtain a third-party identification and electronic prescription;electronic prescription The third-party sending unit is configured to encrypt the electronic prescription using the shared quantum key with the third party, and send the encrypted electronic prescription to the corresponding third party according to the third-party identifier. 授权第三方请求接收单元,用于接收客户端发送的授权第三方请求,获取所述请求中 携带的用户标识、第三方标识、以及电子处方标识; 电子处方加密转发单元,用于采用与所述客户端之间的共享量子密钥,对与所述用户 标识和所述电子处方标识对应的电子处方加密,并发送给所述客户端; 处方转发请求接收单元,用于接收客户端发送的电子处方转发请求; 处方转发请求解密单元,用于采用与所述客户端之间的共享量子密钥对所述请求中携 带的信息执行相应的解密操作,获取第三方标识、以及电子处方; 电子处方发送第三方单元,用于采用与所述第三方之间的共享量子密钥对所述电子处 方加密,并根据所述第三方标识,将加密后的电子处方发送给相应的第三方。
- 4753. A method for obtaining an authorized prescription, characterized in that the method is implemented in a third party, and includes:receiving an electronic prescription sent by an electronic prescription management system;using a shared quantum key pair with the electronic prescription management system The received electronic prescription is decrypted, and the decrypted electronic prescription is decrypted again by using the decryption key corresponding to the first encryption key used by the client that initiated the authorization operation to obtain the original information of the electronic prescription. 53. 一种用于获取授权处方的方法,其特征在于,所述方法在第三方实施,包括: 接收电子处方管理系统发送的电子处方; 采用与所述电子处方管理系统之间的共享量子密钥对接收的电子处方解密,并采用与 发起授权操作的客户端所采用的第一加密密钥对应的解密密钥对解密后的电子处方再次 解密,获取所述电子处方的原始信息。
- 4854. A device for obtaining an authorized prescription, characterized in that the device is deployed in a third party, and includes:a third party receiving electronic prescription unit for receiving an electronic prescription sent by an electronic prescription management system;a third party decrypting an electronic prescription unit, Used for decrypting the received electronic prescription using the shared quantum key with the electronic prescription management system, and using the decryption key corresponding to the first encryption key used by the client that initiated the authorization operation to decrypt the The electronic prescription is decrypted again, and the original information of the electronic prescription is obtained. 54. 一种用于获取授权处方的装置,其特征在于,所述装置部署于第三方,包括: 第三方接收电子处方单元,用于接收电子处方管理系统发送的电子处方; 第三方解密电子处方单元,用于采用与所述电子处方管理系统之间的共享量子密钥对 接收的电子处方解密,并采用与发起授权操作的客户端所采用的第一加密密钥对应的解密 密钥对解密后的电子处方再次解密,获取所述电子处方的原始信息。
Independent claims26
478 paragraphs, as filed
Electronic prescription operation method, device and system technical field
[0001] This application relates to the field of electronic prescriptions, and in particular to an electronic prescription operation method and device. This application also relates to a request method and device for establishing a binding relationship, a method and device for establishing a binding relationship, a method and device for verifying a binding relationship, and a method and device for updating sharing Key request method and device, a method and device for forwarding a shared key update request, a method and device for updating a shared key, a request method and device for obtaining an electronic prescription, one A method and device for forwarding electronic prescriptions, a method and device for providing electronic prescriptions, a request method and device for authorizing a third party, and an electronic prescription forwarding method and device for authorizing a third party , A method and device for obtaining authorized prescriptions, and an electronic prescription operating system.
Background technique
[0002] The development of cloud computing and Internet technology has created conditions for telemedicine: among medical institutions, especially those with relatively poor conditions and low medical standards, some remotely seek experts from some specialized or large hospitals with relatively strong comprehensive strength. The need for help; patients have the need to use cloud computing and Internet technology to purchase prescription drugs in pharmacies with the help of the hospitals authoritative prescriptions to reduce the cost of medical treatment; in addition, patients in backward and remote areas also need to seek telemedicine services from medical institutions in large cities .
[0003] In the above context, an electronic prescription management system (also known as an electronic prescription platform) came into being. Through the electronic prescription platform, users can associate their logo registered on the electronic prescription platform with the hospital information system (patient management provided by medical institutions). System) The registered patient ID is bound to obtain the electronic prescription provided by the hospital information system, and can also authorize a third party to view the electronic prescription, etc. In the above-mentioned operation process, there are mainly problems in the protection of user privacy data and the authentication and authorization of the electronic prescription management system.
[0004] In order to prevent user privacy data, such as user name, certificate number, mobile phone number and other information contained in electronic prescriptions, from being maliciously attacked or stolen, currently, encryption methods based on classic keys are usually used to encrypt electronic prescriptions and electronic prescriptions transmitted through the network. Other user privacy information is protected. The specific implementation has the following shortcomings: if symmetric key protection is used, there is a problem of difficulty in key distribution; if public key encryption is used, although the key distribution process is not required, the calculation speed is slow and the efficiency is difficult to meet practical requirements; and the above are all It belongs to a privacy protection method based on classic passwords. With the rapid increase in computing power such as cloud computing and quantum computing, there are hidden security risks of being cracked.
[0005] In order to ensure the safety of the operation, the electronic prescription management system needs to authenticate and authorize all parties involved in the operation of the electronic prescription. For the purpose of privacy protection, the electronic prescription management system usually does not store the real-name information of the user or other participants. It cannot perform real-name authentication by itself, so the current electronic prescription management system usually adopts the method of asking a third-party authority for authentication. Since there are more interactive operations between the electronic prescription management system and the parties in the electronic prescription operation, if the electronic prescription management system adopts the above-mentioned method for authentication, the steps are cumbersome and the efficiency is relatively low.
Summary of the invention
[0006] The embodiments of the present application provide an electronic prescription operation method and device to solve the problems of the prior art in terms of privacy data protection and authentication and authorization. The embodiment of the present application also provides a request method and device for establishing a binding relationship, a method and device for establishing a binding relationship, a method and device for verifying a binding relationship,
A request method and device for updating a shared key, a method and device for forwarding a shared key update request, a method and device for updating a shared key, and a device for obtaining an electronic prescription Request method and device, a method and device for forwarding electronic prescriptions, a method and device for providing electronic prescriptions, a request method and device for authorizing a third party, and a method and device for authorizing a third party An electronic prescription forwarding method and device, a method and device for obtaining an authorized prescription, and an electronic prescription operating system.
[0007] This application provides an electronic prescription operation method, including:
[0008] The client sends the user's electronic prescription operation request to the electronic prescription management system;
[0009] After receiving the operation request, the electronic prescription management system completes the processing of the operation request through the interaction process with the hospital information system, the client and/or the third party;
[0010] Wherein, when the two interactive parties involved in processing the operation request transmit user privacy data, the sender uses a shared quantum key for encryption, and the receiver uses a corresponding shared quantum key for decryption; the shared quantum key is the Obtained by the sender and the receiver in advance through a quantum key distribution protocol.
[0011] Optionally, the user privacy data includes one or a combination of the following elements: a shared key between the user and the hospital information system, an electronic prescription of the user, and a shared key between the user and a third party.
[0012] Optionally, before the client or the hospital information system uses the shared quantum key to encrypt the users privacy data to be sent to the electronic prescription management system, the user may be decrypted by the electronic prescription management system in a manner that cannot be decrypted. Private data encryption;
[0013] The manner in which the electronic prescription management system cannot be decrypted includes one of the following methods:
[0014] Using a preset hash algorithm to encrypt the user privacy data;
[0015] The encryption key encryption of the corresponding decryption key cannot be obtained using the electronic prescription management system.
[0016] Optionally, when the electronic prescription operation request is a binding relationship establishment request, the client sending the user's electronic prescription operation request to the electronic prescription management system includes:
[0017] The client uses a preset hash algorithm, calculates the hash value of the user privacy data used to verify the user identity, and sends the binding relationship establishment carrying the hash value to the electronic prescription management system request;
[0018] Correspondingly, the electronic prescription management system completes the processing of the operation request through the interaction process with the hospital information system, the client and/or the third party, including:
[0019] After receiving the binding relationship establishment request, the electronic prescription management system sends a binding verification request carrying the hash value to the hospital information system to which the binding relationship is to be established;
[0020] The hospital information system verifies the user identity according to the hash value obtained from the received request, and sends a verification pass response to the electronic prescription management system after the verification is passed;
[0021] The electronic prescription management system establishes a binding relationship between the user and the hospital information system according to the received verification pass response.
[0022] Optionally, the binding relationship establishment request sent by the client to the electronic prescription management system not only carries the hash value, but also carries the identity of the user and the hospital where the binding relationship is to be established An information system identifier, and a patient identifier of the user corresponding to the hospital information system;
[0023] Correspondingly, the electronic prescription management system sends a binding verification request carrying the hash value to the hospital information system to be established for the verification relationship, including: the electronic prescription management system according to the received request The acquired hospital information system identifier, forwarding the binding verification request carrying the hash value and the patient identifier to the corresponding hospital information system;
[0024] The hospital information system verifies the user identity according to the hash value obtained from the received request, including: the hospital information system searches for preset user privacy for verifying the user identity according to the received patient identity Data, using a preset hash algorithm to calculate the hash value of the user's private data found, and determine whether the calculated hash value is consistent with the received hash value, and if they are consistent, it is determined that the user passes the identity verification;
[0025] Establishing the binding relationship between the user and the hospital information system by the electronic prescription management system includes: establishing a mapping relationship between the user ID, the hospital information system ID, and the patient ID, Complete the binding operation.
[0026] Optionally, the user privacy data used to verify the identity of the user includes: a shared key between the user and the hospital information system for which a binding relationship is to be established.
[0027] Optionally, the method includes:
[0028] After the electronic prescription management system completes the binding operation, it returns a binding success response to the client.
[0029] Optionally, the binding relationship establishment request sent by the client to the electronic prescription management system also carries locally generated auxiliary authentication information;
[0030] Correspondingly, the binding verification request forwarded by the electronic prescription management system to the hospital information system also carries the auxiliary authentication information;
[0031] The hospital information system sending a verification response to the electronic prescription management system after the verification is passed includes: generating corresponding variant information according to the auxiliary authentication information obtained from the received request; and adopting the user Encrypting the variant information with a preset shared key with the hospital information system; sending the verification containing the encrypted variant information to the electronic prescription management system through a response;
[0032] The electronic prescription management system returning a binding success response to the client means that the electronic prescription management system returns a binding success response containing the encrypted variant information to the client;
[0033] The method further includes:
[0034] The client obtains the encrypted variant information from the received binding success response, and uses the preset shared key between the user and the hospital information system to pair the variant The information is decrypted, and it is judged whether the variant information obtained after decryption is consistent with the variant information of the auxiliary authentication information generated locally; if they are consistent, it is confirmed that this binding operation is successful.
[0035] Optionally, the variant information of the auxiliary authentication information includes:
[0036] The auxiliary authentication information itself; or,
[0037] The result obtained by processing the auxiliary authentication information using a preset mathematical transformation method.
[0038] Optionally, when the electronic prescription operation request is a shared key update request, the client sending the user's electronic prescription operation request to the electronic prescription management system includes:
[0039] The client generates a new shared key between the user and the hospital information system to be updated, and uses the shared key currently used by the user and the hospital information system to pair the new shared key Shared key encryption, and sending a shared key update request carrying the encrypted new shared key to the electronic prescription management system;
[0040] Correspondingly, the electronic prescription management system completes the processing of the operation request through the interaction process with the hospital information system, the client and/or the third party, including:
[0041] After receiving the shared key update request, the electronic prescription management system forwards the shared key update request carrying the encrypted new shared key to the hospital information system;
[0042] The hospital information system uses the shared key currently adopted by the hospital information system and the user to decrypt the received encrypted new shared key, and obtain the new shared key with the user.
[0043] Optionally, the shared key update request sent by the client to the electronic prescription management system not only carries the encrypted new shared key, but also carries the user's identity and the The identification of the hospital information system; [0044] Correspondingly, the electronic prescription management system forwards the shared key update request carrying the encrypted new shared key to the hospital information system, including: the electronic prescription management According to the hospital information system identification obtained from the received request, the system will carry the encrypted new shared key and the shared secret of the patient identification corresponding to the user identification and the hospital information system identification. The key update request is forwarded to the corresponding hospital information system; [0045] The hospital information system uses the shared key currently used by the hospital information system and the user to decrypt the received encrypted new shared key, and obtain the The new shared key between users includes: the hospital information system uses the shared key corresponding to the patient identification to decrypt the received encrypted new shared key, and obtains the information corresponding to the patient identification The new shared key is the new shared key with the user.
[0046] Optionally, the electronic prescription management system forwards the shared key update request carrying the encrypted new shared key and the patient identification corresponding to the user identification and the hospital information system identification to the corresponding The hospital information system includes:
[0047] The electronic prescription management system searches for the patient identification corresponding to the user identification and the hospital information system identification according to the pre-established binding relationship between the user and the hospital information system;
[0048] forwarding the shared key update request carrying the encrypted new shared key and the patient identification to the hospital information system.
[0049] Optionally, the client generates the new shared key by generating a random number.
[0050] Optionally, when the electronic prescription operation request is an electronic prescription acquisition request, the electronic prescription management system completes the process of interaction with the hospital information system, the client and/or the third party. Processing of operation requests, including:
[0051] After receiving the request, the electronic prescription management system sends the electronic prescription obtained from the hospital information system to the client, where the electronic prescription is the use of the user and the hospital that provided the electronic prescription Shared key encryption between information systems;
[0052] The client uses the shared key between the user and the hospital information system to decrypt the received electronic prescription, and obtain the original information of the electronic prescription.
[0053] Optionally, the shared key between the user and the hospital information system that provides the electronic prescription is updated in the following manner:
[0054] Under the protection of a shared quantum key between the client and the electronic prescription management system, and between the electronic prescription management system and the hospital information system, forwarded by the electronic prescription management system Way to update.
[0055] Optionally, the electronic prescription acquisition request sent by the client to the electronic prescription management system carries the identification of the user, the identification of the hospital information system that provides the electronic prescription, and the identification of the electronic prescription;
[0056] The electronic prescription management system sends the electronic prescription obtained from the hospital information system to the client, including: the electronic prescription management system obtains the electronic prescription from the hospital information system, and communicates with the user ID and the location. The electronic prescription corresponding to the electronic prescription identifier is sent to the client.
[0057] Optionally, the electronic prescription management system obtains from the hospital information system and associates it with the user identification
The electronic prescription corresponding to the electronic prescription identifier is sent to the client, including:
[0058] The electronic prescription management system searches whether the electronic prescription corresponding to the user identification and the electronic prescription identification is stored, and if so, obtains the electronic prescription and sends it to the client.
[0059] Optionally, when the result of searching whether the electronic prescription corresponding to the user identification and the electronic prescription identification is stored by the electronic prescription management system is no, the following operations are performed:
[0060] The electronic prescription management system searches for the patient ID corresponding to the user ID and the hospital information system ID according to the pre-established binding relationship between the user and the hospital information system; and according to the hospital information system Identification, sending an electronic prescription acquisition request carrying the patient identification and the electronic prescription identification to the corresponding hospital information system;
[0061] The hospital information system searches for the corresponding electronic prescription according to the patient identification and the electronic prescription identification carried in the received request, and uses the shared key between it and the user to encrypt the electronic prescription found and send it To the electronic prescription management system;
[0062] The electronic prescription management system stores the received electronic prescription corresponding to the user identification and the electronic prescription identification, and sends it to the client.
[0063] Optionally, when the electronic prescription operation request is a third-party authorization request, the electronic prescription management system completes the process of interacting with the hospital information system, the client and/or the third party. Processing of operation requests, including:
[0064] After receiving the third-party authorization request, the electronic prescription management system sends the electronic prescription authorized to the third party to be viewed to the client, and the electronic prescription is used by the user and the hospital that provided the electronic prescription. Shared key encryption between information systems;
[0065] The client uses the shared key between the user and the hospital information system to decrypt the received electronic prescription, obtains the original information of the electronic prescription, and uses the third party with a corresponding decryption key. An encryption key encrypts the original information of the electronic prescription, and sends the electronic prescription forwarding request carrying the encrypted electronic prescription to the electronic prescription management system;
[0066] The electronic prescription management system sends the received encrypted electronic prescription to the third party;
[0067] The third party decrypts the received electronic prescription by using the decryption key corresponding to the first encryption key to obtain the original information of the electronic prescription.
[0068] Optionally, the first encryption key that the third party has a corresponding decryption key includes: a public key of the third party;
[0069] Correspondingly, the decryption key corresponding to the first encryption key includes: a private key of the third party.
[0070] Optionally, the third-party authorization request sent by the client to the electronic prescription management system carries the identification of the user, the identification of the third party, and the identification of the electronic prescription that is authorized to be viewed by the third party;
[0071] Correspondingly, the electronic prescription management system sends the electronic prescription authorized to the third party to be viewed to the client, including: the electronic prescription management system will obtain the electronic prescription from the hospital information system that provides the electronic prescription, and Sending the user identification and the electronic prescription corresponding to the electronic prescription identification to the client;
[0072] The electronic prescription forwarding request sent by the client to the electronic prescription management system not only carries the encrypted electronic prescription, but also carries the third-party identifier;
[0073] The electronic prescription management system sends the received encrypted electronic prescription to the third party, including:
The electronic prescription management system sends the received electronic prescription according to the third-party identification obtained from the received information
Give it to the corresponding third party.
[0074] Optionally, after the client receives the electronic prescription sent by the electronic prescription management system, the client further performs the following operations:
[0075] A new shared key between the user and the third party is generated as the first encryption key used in the next processing of a third-party authorization request with the third party, and The new shared key is encrypted in the same way as the electronic prescription and then sent to the electronic prescription management system;
[0076] Correspondingly, what the electronic prescription management system sends to the third party includes not only the electronic prescription, but also the new shared key;
[0077] After the third party uses the decryption key corresponding to the first encryption key to decrypt the received information, what is obtained includes not only the original information of the electronic prescription, but also the new shared key as the next time The decryption key corresponding to the first encryption key used when decrypting the user's electronic prescription.
[0078] Optionally, the data transmission between the two interacting parties involved in processing the operation request is based on an HTTPS connection, and the digital certificates adopted by each of the interacting parties are issued by a trusted third party.
[0079] Optionally, the two interacting parties involved in processing the operation request perform two-way identity authentication before negotiating a shared quantum key through the quantum key distribution protocol, and start the negotiation process after the authentication is passed.
[0080] Correspondingly, this application also provides an electronic prescription operation device, including:
[0081] The operation request sending unit is used for the client to send the user's electronic prescription operation request to the electronic prescription management system;
[0082] The operation request processing unit is used to complete the processing of the operation request through the interaction process with the hospital information system, the client and/or the third party after the electronic prescription management system receives the operation request;
[0083] Wherein, the operation request sending unit and the operation request processing unit each include a quantum key encryption and decryption subunit, which is used for both parties involved in processing the operation request when transmitting user privacy data, the sender adopts sharing In quantum key encryption, the receiver uses a corresponding shared quantum key to decrypt; the shared quantum key is obtained by the sender and the receiver in advance through a quantum key distribution protocol.
[0084] Optionally, the operation request processing unit is further configured to use an electronic prescription before the client or the hospital information system uses the shared quantum key to encrypt user privacy data to be sent to the electronic prescription management system The user privacy data is encrypted in a way that the management system cannot decrypt.
[0085] Optionally, when the electronic prescription operation request is a binding relationship establishment request, the operation request sending unit further includes:
[0086] The binding establishment request sending subunit is used for the client to use a preset hash algorithm to calculate the hash value of the user privacy data used to verify the user's identity, and to send the carry to the electronic prescription management system The request for establishing the binding relationship of the hash value;
[0087] Correspondingly, the operation request processing unit further includes:
[0088] The binding verification request sending subunit is used for the electronic prescription management system to send the binding verification carrying the hash value to the hospital information system to which the binding relationship is to be established after receiving the binding relationship establishment request request;
[0089] The binding relationship verification subunit is used for the hospital information system to verify the user identity according to the hash value obtained from the received request, and send a verification pass response to the electronic prescription management system after the verification is passed ;
[0090] The binding relationship establishment subunit is used for the electronic prescription management system to establish the binding relationship between the user and the hospital information system according to the received verification pass response.
[0091] Optionally, when the electronic prescription operation request is a shared key update request, the operation request sending unit further includes:
[0092] The key update request sending sub-unit is used for the client to generate a new shared key between the user and the hospital information system to be updated with the shared key, using the user and the hospital information system The currently used shared key encrypts the new shared key, and sends a shared key update request carrying the encrypted new shared key to the electronic prescription management system;
[0093] Correspondingly, the operation request processing unit further includes:
[0094] The update request forwarding subunit is used for the electronic prescription management system to forward the shared key update request carrying the encrypted new shared key to the hospital information after receiving the shared key update request system;
[0095] The new key decryption acquisition subunit is used for the hospital information system to decrypt the received encrypted new shared key using the shared key currently used by the hospital information system and the user to obtain The new shared key between.
[0096] Optionally, when the electronic prescription operation request is an electronic prescription acquisition request, the operation request sending unit further includes:
[0097] The prescription acquisition request sending subunit is used for the client to send an electronic prescription acquisition request to the electronic prescription management system;
[0098] Correspondingly, the operation request processing unit further includes:
[0099] The electronic prescription sending sub-unit is used to send the electronic prescription obtained from the hospital information system to the client after the electronic prescription management system receives the request, wherein the electronic prescription uses the user Encrypted with a shared key between the hospital information system that provides the electronic prescription;
[0100] The electronic prescription decryption and acquisition subunit is used for the client to decrypt the received electronic prescription by using the shared key between the user and the hospital information system to obtain the original information of the electronic prescription.
[0101] Optionally, when the electronic prescription operation request is a third-party authorization request, the operation request sending unit further includes:
[0102] The third-party authorization request sending subunit is used for the client to send a third-party authorization request to the electronic prescription management system;
[0103] Correspondingly, the operation request processing unit further includes:
[0104] The authorized prescription sending sub-unit is used for the electronic prescription management system to send the electronic prescription authorized to the third party to view to the client after receiving the third-party authorization request, and the electronic prescription uses the user Encrypted with a shared key between the hospital information system that provides the electronic prescription;
[0105] Authorized prescription encryption and decryption subunit for the client to use the shared key between the user and the hospital information system to decrypt the received electronic prescription, obtain the original information of the electronic prescription, and use the The third party has a first encryption key corresponding to the decryption key to encrypt the original information of the electronic prescription, and sends the electronic prescription forwarding request carrying the encrypted electronic prescription to the electronic prescription management system;
[0106] Authorized prescription forwarding sub-unit for the electronic prescription management system to send the received encrypted electronic prescription to the third party;
[0107] The authorized prescription obtaining subunit is used for the third party to decrypt the received electronic prescription by using the decryption key corresponding to the first encryption key to obtain the original information of the electronic prescription.
[0108] In addition, this application also provides a request method for establishing a binding relationship. The method is implemented on the client and includes:
[0109] A preset hash algorithm is used to calculate the hash value of user privacy data used to verify the identity of the user, and the user refers to the user who initiates the binding relationship establishment request;
[0110] Send a binding relationship establishment request to the electronic prescription management system, the request carrying the user's identification, the hash value, the identification of the hospital information system to be established for the binding relationship, and the user corresponding to The patient identification of the hospital information system, wherein at least the hash value is encrypted using a shared quantum key with the electronic prescription management system.
[0111] Correspondingly, this application also provides a request device for establishing a binding relationship. The device is deployed on a client and includes:
[0112] The hash value calculation unit is configured to use a preset hash algorithm to calculate the hash value of user privacy data used to verify the user's identity;
[0113] The binding request encryption sending unit sends a binding relationship establishment request to the electronic prescription management system, and the request carries the identity of the user, the hash value, and the identity of the hospital information system for which the binding relationship is to be established And the user is corresponding to the patient identification of the hospital information system, wherein at least the hash value is encrypted using a shared quantum key with the electronic prescription management system.
[0114] In addition, this application also provides a method for establishing a binding relationship. The method is implemented in an electronic prescription management system and includes:
[0115] receiving a binding relationship establishment request sent by the client;
[0116] Use the shared quantum key with the client to perform a corresponding decryption operation on the information carried in the request, and obtain a user ID, a hash value, a hospital information system ID, and a patient ID;
[0117] According to the acquired hospital information system identification, the binding verification request carrying the hash value and the patient identification is forwarded to the corresponding hospital information system, wherein at least the hash value is used with the hospital Shared quantum key encryption between information systems;
[0118] Receive a verification pass response sent by the hospital information system, and establish a mapping relationship between the user ID, the hospital information system ID, and the patient ID, and complete the binding operation.
[0119] Correspondingly, this application also provides a device for establishing a binding relationship. The device is deployed in an electronic prescription management system and includes:
[0120] The binding establishment request receiving unit is configured to receive a binding relationship establishment request sent by the client;
[0121] The binding establishment request decryption unit is configured to use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request to obtain user identification, hash value, and hospital information system Identification, and patient identification;
[0122] The binding verification request encryption forwarding unit is configured to forward the binding verification request carrying the hash value and the patient identification to the corresponding hospital information system according to the acquired hospital information system identification, wherein at least The hash value is encrypted using a shared quantum key with the hospital information system;
[0123] The binding relationship establishment unit is configured to receive the verification pass response sent by the hospital information system, and establish the mapping relationship between the user ID, the hospital information system ID, and the patient ID to complete the binding operating.
[0124] In addition, the present application also provides a method for verifying the binding relationship. The method is implemented in a hospital information system and includes:
[0125] receiving a binding verification request sent by an electronic prescription management system;
[0126] Using the shared quantum key with the electronic prescription management system to execute the information carried in the request
Perform the corresponding decryption operation to obtain the hash value and the patient ID;
[0127] According to the received patient identification, search for preset user privacy data used to verify user identity, use a preset hash algorithm to calculate the hash value of the user privacy data found, and determine the calculated hash value and Whether the hash values obtained from the request are consistent;
[0128] If they are consistent, send a verification pass response to the electronic prescription management system.
[0129] Correspondingly, this application also provides a device for verifying a binding relationship. The device is deployed in a hospital information system and includes:
[0130] The binding verification request receiving unit is configured to receive the binding verification request sent by the electronic prescription management system;
[0131] The binding verification request decryption unit is configured to use the shared quantum key with the electronic prescription management system to perform corresponding decryption operations on the information carried in the request to obtain the hash value and the patient identification;
[0132] The hash value calculation and comparison unit is used to find preset user privacy data used to verify the user identity according to the received patient identification, and calculate the hash value of the found user privacy data using a preset hash algorithm , And judge whether the calculated hash value is consistent with the hash value obtained from the request;
[0133] The verification pass response unit is configured to send a verification pass response to the electronic prescription management system when the output of the hash value calculation and comparison unit is yes.
[0134] In addition, this application also provides a request method for updating a shared key. The method is implemented on the client and includes:
[0135] Generate a new shared key for the user whose shared key is to be updated and the hospital information system, and encrypt the new shared key with the shared key currently used by the user and the hospital information system;
[0136] Send a shared key update request to the electronic prescription management system, the request carries the user's identity, the hospital information system's identity, and the encrypted new shared key, wherein at least the encrypted The latter new shared key is encrypted using the shared quantum key with the electronic prescription management system.
[0137] Correspondingly, this application also provides a request device for updating a shared key. The device is deployed on a client and includes:
[0138] The new shared key generating unit is used to generate a new shared key for the user whose shared key is to be updated and the hospital information system, and use the shared key currently used by the user and the hospital information system to pair the New shared key encryption; [0139] The key update request encryption sending unit is used to send a shared key update request to the electronic prescription management system, where the request carries the identity of the user, the identity of the hospital information system, And the encrypted new shared key, wherein at least the encrypted new shared key is encrypted using a shared quantum key with the electronic prescription management system.
[0140] In addition, this application also provides a method for forwarding a shared key update request. The method is implemented in an electronic prescription management system and includes:
[0141] receiving a shared key update request sent by the client;
[0142] Use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext of the new shared key, the user ID, and the hospital information system ID;
[0143] According to the pre-established binding relationship between the user and the hospital information system, search for the patient ID corresponding to the user ID and the hospital information system ID;
[0144] According to the acquired hospital information system identification, the ciphertext carrying the new shared key and the shared key update request of the patient identification are forwarded to the corresponding hospital information system, wherein at least the new shared key The ciphertext is
Encrypted with a shared quantum key with the hospital information system.
[0145] Correspondingly, this application also provides a device for forwarding a shared key update request. The device is deployed in an electronic prescription management system and includes:
[0146] a key update request receiving unit, configured to receive a shared key update request sent by the client;
[0147] The key update request decryption unit is configured to use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext and user ID of the new shared key , And the hospital information system logo;
[0148] The patient identification search unit is configured to search for a patient identification corresponding to the user identification and the hospital information system identification according to the pre-established binding relationship between the user and the hospital information system;
[0149] The key update request encryption forwarding unit is configured to forward the ciphertext carrying the new shared key and the shared key update request of the patient identification to the corresponding hospital information according to the acquired hospital information system identification The system, wherein at least the ciphertext of the new shared key is encrypted with the shared quantum key with the hospital information system.
[0150] In addition, this application also provides a method for updating a shared key. The method is implemented in a hospital information system and includes:
[0151] Receive a shared key update request sent by the electronic prescription management system;
[0152] Use the shared quantum key with the electronic prescription management system to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext of the new shared key and the patient identification;
[0153] Use the shared key corresponding to the patient identification to decrypt the ciphertext of the new shared key, and obtain the new shared key corresponding to the patient identification, that is, the exchange between users corresponding to the patient identification New shared key.
[0154] Correspondingly, this application also provides a device for updating a shared key. The device is deployed in a hospital information system and includes:
[0155] A forwarding request receiving unit for receiving a shared key update request sent by an electronic prescription management system;
[0156] The forwarding request decryption unit is configured to use the shared quantum key with the electronic prescription management system to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext of the new shared key and the patient Logo
[0157] The new key acquisition unit is configured to use the shared key corresponding to the patient identification to decrypt the ciphertext of the new shared key, and to obtain the new shared key corresponding to the patient identification, that is, the shared key corresponding to the patient identification. The patient identification corresponds to a new shared key between users.
[0158] In addition, this application also provides a request method for obtaining an electronic prescription. The method is implemented on the client and includes:
[0159] sending an electronic prescription acquisition request to the electronic prescription management system, the request carrying the identification of the user who initiated the request, the identification of the hospital information system that provided the electronic prescription, and the identification of the electronic prescription;
[0160] receiving the electronic prescription sent by the electronic prescription management system;
[0161] Use the shared quantum key with the electronic prescription management system to decrypt the received electronic prescription, and use the shared key between the user and the hospital information system to decrypt the decrypted electronic prescription again To obtain the original information of the electronic prescription.
[0162] Correspondingly, this application also provides a request device for obtaining an electronic prescription. The device is deployed on the client and includes:
[0163] The prescription acquisition request sending unit is used to send an electronic prescription acquisition request to the electronic prescription management system, and the request carries the identity of the user who initiated the request, the identity of the hospital information system that provided the electronic prescription, and the electronic prescription.
Prescription identification;
[0164] The prescription information receiving unit is used to receive the electronic prescription sent by the electronic prescription management system;
[0165] The original prescription acquisition unit is used to decrypt the received electronic prescription using the shared quantum key with the electronic prescription management system, and to use the shared key pair between the user and the hospital information system The decrypted electronic prescription is decrypted again to obtain the original information of the electronic prescription.
[0166] In addition, this application also provides a method for forwarding electronic prescriptions. The method is implemented in an electronic prescription management system and includes:
[0167] receiving an electronic prescription acquisition request sent by the client, and acquiring the user identification, hospital information system identification, and electronic prescription identification carried in the request;
[0168] Determine whether the electronic prescription corresponding to the user identification and the electronic prescription identification is stored, if yes, obtain the stored electronic prescription, if not, obtain the electronic prescription from the hospital information system;
[0169] Using the shared quantum key with the client, encrypt the acquired electronic prescription, and send it to the client;
[0170] Wherein, the obtaining the electronic prescription from the hospital information system includes:
[0171] According to the pre-established binding relationship between the user and the hospital information system, search for the patient ID corresponding to the user ID and the hospital information system ID; and according to the hospital information system ID, carry the The patient identification and the electronic prescription acquisition request of the electronic prescription identification are sent to the corresponding hospital information system;
[0172] receiving an electronic prescription sent by the hospital information system and corresponding to the user ID and the electronic prescription ID;
[0173] Use the shared quantum key with the hospital information system to decrypt the received electronic prescription as the electronic prescription obtained from the hospital information system, and store the electronic prescription.
[0174] Correspondingly, this application also provides a device for forwarding electronic prescriptions. The device is deployed in an electronic prescription management system and includes:
[0175] The prescription acquisition request receiving unit is configured to receive the electronic prescription acquisition request sent by the client, and acquire the user identification, the hospital information system identification, and the electronic prescription identification carried in the request;
[0176] The electronic prescription acquisition unit is used to determine whether the electronic prescription corresponding to the user identification and the electronic prescription identification is stored; if so, to acquire the stored electronic prescription; if not, to acquire the electronic prescription from the hospital information system. The electronic prescription;
[0177] The electronic prescription encryption and forwarding unit is configured to use the shared quantum key with the client to encrypt the acquired electronic prescription and send it to the client.
[0178] In addition, this application also provides a method for providing electronic prescriptions. The method is implemented in a hospital information system and includes:
[0179] receiving an electronic prescription acquisition request sent by an electronic prescription management system, and acquiring the patient identification and electronic prescription identification carried in the request;
[0180] searching for an electronic prescription corresponding to the patient identification and the electronic prescription identification;
[0181] Use the shared key corresponding to the patient identification to encrypt the electronic prescription, and use the shared quantum key with the electronic prescription management system to encrypt the encrypted electronic prescription again, and send it to the Electronic prescription management system.
[0182] Correspondingly, this application also provides a device for providing electronic prescriptions, the device being deployed in the hospital information
System, including:
[0183] The forwarding prescription acquisition request receiving unit is configured to receive the electronic prescription acquisition request sent by the electronic prescription management system, and acquire the patient identification and the electronic prescription identification carried in the request;
[0184] An electronic prescription search unit for searching for an electronic prescription corresponding to the patient identification and the electronic prescription identification;
[0185] The electronic prescription encryption sending unit is configured to encrypt the electronic prescription by using a shared key corresponding to the patient identification, and use the shared quantum key with the electronic prescription management system to encrypt the electronic prescription It is encrypted again and sent to the electronic prescription management system.
[0186] In addition, this application also provides a request method for authorizing a third party. The method is implemented on the client and includes:
[0187] Sending a third-party authorization request to the electronic prescription management system, the request carrying the identification of the user who initiated the request, the third-party identification, and the electronic prescription identification that the third party is authorized to view;
[0188] receiving the electronic prescription sent by the electronic prescription management system;
[0189] The shared quantum key with the electronic prescription management system is used to decrypt the received electronic prescription, and the shared key between the user and the hospital information system that provides the electronic prescription is used to decrypt the The electronic prescription is decrypted again to obtain the original information of the electronic prescription;
[0190] Encrypt the original information of the electronic prescription by using the first encryption key of the third party with a corresponding decryption key, and forward the request for the electronic prescription carrying the third-party identification and the ciphertext of the electronic prescription Sent to the electronic prescription management system, wherein at least the electronic prescription ciphertext is encrypted using a shared quantum key with the electronic prescription management system.
[0191] Correspondingly, this application also provides a request device for authorizing a third party. The device is deployed on the client and includes:
[0192] Authorized third-party request sending unit, configured to send a third-party authorization request to the electronic prescription management system, the request carrying the identification of the user who initiated the request, the third-party identification, and the electronic prescription identification that the third-party is authorized to view ;
[0193] An electronic prescription receiving unit for receiving an electronic prescription sent by the electronic prescription management system;
[0194] The original prescription acquisition unit is used to decrypt the received electronic prescription using the shared quantum key with the electronic prescription management system, and to use the communication between the user and the hospital information system that provides the electronic prescription The shared key decrypts the decrypted electronic prescription again to obtain the original information of the electronic prescription;
[0195] The electronic prescription encryption sending unit is configured to encrypt the original information of the electronic prescription by using the first encryption key of the third party with a corresponding decryption key, and carry the third-party identification and the electronic prescription. The electronic prescription forwarding request of the prescription ciphertext is sent to the electronic prescription management system, wherein at least the electronic prescription ciphertext is encrypted using a shared quantum key with the electronic prescription management system.
[0196] In addition, this application also provides an electronic prescription forwarding method for authorizing a third party. The method is implemented in an electronic prescription management system and includes:
[0197] receiving a third-party authorization request sent by the client, and obtaining the user identification, third-party identification, and electronic prescription identification carried in the request;
[0198] Using the shared quantum key with the client, encrypt the electronic prescription corresponding to the user ID and the electronic prescription ID, and send it to the client;
[0199] receiving the electronic prescription forwarding request sent by the client;
[0200] Using the shared quantum key with the client to perform a corresponding decryption operation on the information carried in the request to obtain a third-party identification and an electronic prescription;
[0201] The electronic prescription is encrypted using the shared quantum key with the third party, and the encrypted electronic prescription is sent to the corresponding third party according to the third-party identification.
[0202] Correspondingly, this application also provides an electronic prescription forwarding device for authorizing a third party. The device is deployed in an electronic prescription management system and includes:
[0203] The authorized third-party request receiving unit is configured to receive the authorized third-party request sent by the client, and obtain the user identification, third-party identification, and electronic prescription identification carried in the request;
[0204] The electronic prescription encryption and forwarding unit is configured to use the shared quantum key with the client to encrypt the electronic prescription corresponding to the user ID and the electronic prescription ID, and send it to the client ;
[0205] The prescription forwarding request receiving unit is configured to receive the electronic prescription forwarding request sent by the client;
[0206] The prescription forwarding request decryption unit is configured to use the shared quantum key with the client to perform a corresponding decryption operation on the information carried in the request, and obtain a third-party identification and an electronic prescription;
[0207] The electronic prescription sending third-party unit is used to encrypt the electronic prescription by using the shared quantum key with the third party, and send the encrypted electronic prescription to the corresponding third-party identifier according to the third-party identification. Third party.
[0208] In addition, this application also provides a method for obtaining an authorized prescription, which is implemented by a third party, and includes:
[0209] Receiving the electronic prescription sent by the electronic prescription management system;
[0210] The shared quantum key with the electronic prescription management system is used to decrypt the received electronic prescription, and the decryption key corresponding to the first encryption key used by the client that initiates the authorization operation is used to decrypt the received electronic prescription. The electronic prescription is decrypted again to obtain the original information of the electronic prescription.
[0211] Correspondingly, this application also provides a device for obtaining an authorized prescription, the device being deployed in a third party, including:
[0212] The third-party receiving electronic prescription unit is used to receive the electronic prescription sent by the electronic prescription management system;
[0213] The third-party decryption electronic prescription unit is used to decrypt the received electronic prescription using the shared quantum key with the electronic prescription management system, and to use the first encryption key used by the client that initiated the authorization operation. The decryption key corresponding to the key decrypts the decrypted electronic prescription again to obtain the original information of the electronic prescription.
[0214] In addition, this application also provides an electronic prescription operating system, including: one or any combination of the following groups:
[0215] The request device for establishing a binding relationship according to any one of the above, the device for establishing a binding relationship according to any one of the above, and the device for verifying according to any one of the above [0216] The requesting device for updating a shared key according to any one of the above, the device for forwarding a shared key update request according to any one of the above, and the device according to any one of the above A device for updating a shared key as described in one item;
[0217] The request device for obtaining an electronic prescription according to any one of the above, the device for forwarding an electronic prescription according to any one of the above, and the device for providing an electronic prescription according to any one of the above [0218] The request device for authorizing a third party according to any one of the above, the electronic prescription forwarding device for authorizing a third party according to any one of the above, and the device according to any one of the above For obtaining authorized prescriptions
Device.
[0219] Compared with the prior art, this application has the following advantages:
[0220] In the electronic prescription operation method provided in this application, in the process of performing the electronic prescription operation through interaction between the client, the electronic prescription management system, the hospital information system, and/or the third party, the interactive parties adopt the privacy data of the user. Both parties are protected by the shared quantum key obtained through the quantum key distribution protocol negotiation in advance. Using the above method, on the one hand, because the quantum key as a symmetric key has good encryption and decryption execution efficiency, and based on the basic principles of quantum mechanics, the security of the key distribution process is guaranteed, and there is no security that the classic password may be cracked. Therefore, the security of user privacy data can be effectively guaranteed; on the other hand, since the shared quantum key is obtained by the interacting parties through the quantum key distribution protocol, only the two parties with the shared quantum key can perform correct encryption, The decryption operation can play a role in verifying the identities of the interacting parties, which not only realizes anonymous authentication, but also simplifies the authentication and authorization process and improves execution efficiency.
Description of the drawings
[0221] FIG. 1 is a flowchart of an embodiment of an electronic prescription operation method of the present application;
[0222] FIG. 2 is a processing flowchart for establishing a binding relationship between a user and the HIS system provided by an embodiment of the present application;
[0223] FIG. 3 is a schematic diagram of data interaction of a binding operation provided by an embodiment of the present application;
[0224] FIG. 4 is a processing flowchart for updating the shared key between the user and the HIS system provided by an embodiment of the present application;
[0225] FIG. 5 is a schematic diagram of data interaction of the update shared key operation provided by an embodiment of the present application;
[0226] FIG. 6 is a process flow chart of a user obtaining an electronic prescription according to an embodiment of the present application;
[0227] FIG. 7 is a data interaction diagram of obtaining an electronic prescription operation provided by an embodiment of the present application, wherein the electronic prescription management system does not store the electronic prescription;
[0228] FIG. 8 is a data interaction diagram of obtaining an electronic prescription operation provided by an embodiment of the present application, in which the electronic prescription management system has stored the electronic prescription;
[0229] FIG. 9 is a processing flowchart for a user to authorize a third party to view an electronic prescription according to an embodiment of the present application;
[0230] FIG. 10 is a schematic diagram of data interaction for a user to authorize a third party to view an electronic prescription for the first time according to an embodiment of the present application;
[0231] FIG. 11 is a schematic diagram of data interaction for a user to subsequently authorize a third party to view an electronic prescription according to an embodiment of the present application;
[0232] FIG. 12 is a schematic diagram of an embodiment of an electronic prescription operation device of the present application;
[0233] FIG. 13 is a flowchart of an embodiment of a request method for establishing a binding relationship according to the present application;
[0234] FIG. 14 is a schematic diagram of an embodiment of a request device for establishing a binding relationship according to the present application;
[0235] FIG. 15 is a flowchart of an embodiment of a method for establishing a binding relationship according to the present application;
[0236] FIG. 16 is a schematic diagram of an embodiment of an apparatus for establishing a binding relationship according to the present application; [0237] FIG. 17 is a flowchart of an embodiment of a method for verifying a binding relationship according to the present application [0238] FIG. 18 is a schematic diagram of an embodiment of an apparatus for verifying a binding relationship according to the present application; [0239] FIG. 19 is a schematic diagram of an embodiment of a request method for updating a shared key according to the present application Flow chart; [0240] FIG. 20 is a schematic diagram of an embodiment of a request device for updating a shared key of the present application; [0241] FIG. 21 is a method for forwarding a shared key update request of the present application A flowchart of an embodiment; [0242] FIG. 22 is a schematic diagram of an embodiment of an apparatus for forwarding a shared key update request according to the present application;
[0243] FIG. 23 is a flowchart of an embodiment of a method for updating a shared key of the present application;
[0244] FIG. 24 is a schematic diagram of an embodiment of an apparatus for updating a shared key of the present application;
[0245] FIG. 25 is a flowchart of an embodiment of a request method for obtaining an electronic prescription of the present application;
[0246] FIG. 26 is a schematic diagram of an embodiment of a request device for obtaining an electronic prescription according to the present application;
[0247] FIG. 27 is a flowchart of an embodiment of a method for forwarding an electronic prescription of the present application;
[0248] FIG. 28 is a schematic diagram of an embodiment of a device for forwarding electronic prescriptions of the present application;
[0249] FIG. 29 is a flowchart of an embodiment of a method for providing electronic prescriptions of the present application;
[0250] FIG. 30 is a schematic diagram of an embodiment of a device for providing electronic prescriptions according to the present application;
[0251] FIG. 31 is a flowchart of an embodiment of a request method for authorizing a third party of the present application;
[0252] FIG. 32 is a schematic diagram of an embodiment of a request device for authorizing a third party according to the present application;
[0253] FIG. 33 is a flowchart of an embodiment of an electronic prescription forwarding method for authorizing a third party of the present application;
[0254] FIG. 34 is a schematic diagram of an embodiment of an electronic prescription forwarding device for authorizing a third party according to the present application;
[0255] FIG. 35 is a flowchart of an embodiment of a method for obtaining an authorized prescription of the present application;
[0256] FIG. 36 is a schematic diagram of an embodiment of a device for obtaining an authorized prescription of the present application;
[0257] FIG. 37 is a schematic diagram of an embodiment of an electronic prescription operating system of the present application.
Detailed ways
[0258] In the following description, many specific details are set forth in order to fully understand the present application. However, this application can be implemented in many other ways different from those described here, and those skilled in the art can make similar promotion without violating the connotation of this application. Therefore, this application is not limited by the specific implementation disclosed below.
[0259] In this application, an electronic prescription operation method and device, a request method and device for establishing a binding relationship, a method and device for establishing a binding relationship, and a device are provided respectively. Method and device for verifying a binding relationship, a request method and device for updating a shared key, a method and device for forwarding a shared key update request, a method for updating a shared key, and Device, a request method and device for obtaining an electronic prescription, a method and device for forwarding an electronic prescription, a method and device for providing an electronic prescription, a request method for authorizing a third party, and The device, an electronic prescription forwarding method and device for authorizing a third party, a method and device for obtaining an authorized prescription, and an electronic prescription operating system are described in detail in the following embodiments one by one. Before describing the embodiments in detail, a brief description of the entities involved in the technical solution and related backgrounds will be given.
[0260] The technical solution of the present application provides a method for performing an electronic prescription operation between a client, an electronic prescription management system, a hospital information system, and a third party under the protection of a shared quantum key. The client refers to the party that initiates the electronic prescription operation request according to the user's needs, and corresponds to the user who initiates the electronic prescription operation request; the electronic prescription management system, that is, the commonly described electronic prescription platform ( Electronic Prescription Platform (EPP), usually used to store user electronic prescriptions obtained from the hospital information system, and provide electronic prescriptions to users or third parties according to the needs of the client; the Hospital Information System (HIS), Usually refers to a system that runs inside a medical institution (such as a hospital) and is used to store user information for receiving medical care services (such as medical visits, health checkups). The user information includes user personal information and is related to receiving medical care services. For example, an electronic prescription issued by a doctor; the third party usually refers to a participant who needs to view a user's electronic prescription through an electronic prescription platform, such as pharmacies, medical regulatory agencies, etc.
[0261] When a user receives a medical care service in a medical institution, he usually performs an initial registration at the medical institution, and stores the provided personal real information in the HIS system of the medical institution. Accordingly, the HIS system can generate a unique identifier for the user Patient_ID, referred to as patient ID in this application. In the initial registration process, the initial secret verification information can be preset, that is, the shared key between the user and the HIS system described in this application, and the shared key is usually stored in the HIS system corresponding to the Patient_ID. After completing the initial registration, the HIS system can usually generate the corresponding electronic prescription and save it in the HIS system every time the user receives medical care services in a medical institution.
[0262] Users can register in the electronic prescription management system. The registered user has a unique user ID User_ID and login password in the electronic prescription management system. The HIS system of medical institutions and third parties can also register in the electronic prescription management system. Registered users can log in to the electronic prescription management system through the client. The client, HIS system, and third parties can negotiate with the electronic prescription management system to obtain the shared quantum key through the quantum key distribution protocol, and use the shared quantum key pair. Protect the privacy data in the operation of electronic prescriptions. The embodiments of the present application will be described in detail below.
[0263] Please refer to FIG. 1, which is a flowchart of an embodiment of an electronic prescription operation method of this application. The method includes the following steps:
[0264] Step 101: The client sends a user's electronic prescription operation request to the electronic prescription management system.
[0265] Step 102. After receiving the operation request, the electronic prescription management system completes the processing of the operation request through the interaction process with the hospital information system, the client and/or the third party; The two interacting parties of the operation request adopt a shared quantum key for protection when transmitting user privacy data.
[0266] Between the two interactive parties involved in processing the electronic prescription operation request, for the transmitted user privacy data, the sender can use a shared quantum key to encrypt, and the receiver uses a corresponding shared quantum key to decrypt; the shared quantum key The key is obtained by the sender and the receiver in advance through a quantum key distribution protocol. In this embodiment, the user privacy data includes one or a combination of the following elements: the shared key between the user and the hospital information system, the users electronic prescription, the shared key between the user and a third party, and other implementations In the method, the user privacy data that needs to be protected can also be set according to specific needs.
[0267] The technical solution of the present application uses a quantum key to protect user privacy data during transmission. As a symmetric key, the quantum key has good encryption and decryption execution efficiency, and the key is guaranteed based on the basic principles of quantum mechanics. The security of the distribution process, and there is no security risk that the classic password may be cracked, so the security of the user's private data can be effectively protected. In addition, since the shared quantum key is negotiated by the interacting parties through the quantum key distribution protocol, and only the two parties with the shared quantum key can perform correct encryption and decryption operations, it can play a role in verifying the identities of the interacting parties. Anonymous authentication is realized, the authentication and authorization process is simplified, and the execution efficiency is improved.
[0268] Further, before using the shared quantum key to encrypt the user privacy data to be sent to the electronic prescription management system, the client or the hospital information system may encrypt the user privacy data in a manner that cannot be decrypted by the electronic prescription management system. Therefore, the electronic prescription management system will not learn the user's private data during the storage or forwarding process, so as to avoid the leakage of the user's private data. For example, the HIS system sends an electronic prescription to the client via the electronic prescription management system. The HIS system can first encrypt the electronic prescription with the shared key between it and the user, and then use the shared quantum secret between it and the electronic prescription management system. Key encryption, so that after the electronic prescription management system receives it, it uses the corresponding shared quantum key to decrypt and obtains the electronic prescription ciphertext, and it is impossible to know the private data contained in the electronic prescription, which further protects the user's private data during the operation of the electronic prescription Security.
[0269] In addition, in order to further ensure the safety of the electronic prescription operation process, participate in the interactive dual operation of processing operation requests.
The data transmission between the parties can be based on HTTPS connection, and the digital certificates used by the two interacting parties are issued by a trusted third party; the two interacting parties involved in processing the operation request agree to share through the quantum key distribution protocol. Before the quantum key, you can also perform two-way identity authentication (for example, using a preset digital certificate), and start the quantum key agreement process after the authentication is passed. This part of the content will not be repeated in the follow-up.
[0270] In specific implementation, the operations related to electronic prescriptions mainly include the following four: binding of the user to the HIS system, update of the shared key between the user and the HIS system, the user to obtain the electronic prescription, and the user to authorize a third party to view Electronic prescription. The specific operation procedures in the above 4 are described in detail below. In other embodiments, the operations related to the electronic prescription may not be limited to the above 4 types, and may also include other operations, which is not specifically limited in this application.
[0271] It should be noted that the core of the technical solution of the present application is that a shared quantum key is used to protect user privacy data during the interaction. On this basis, for non-private data, it can be agreed in advance whether to use a shared quantum key. Key protection, so that both parties to the interaction perform corresponding encryption and decryption operations as agreed. For example, if it is agreed in advance to also use shared quantum key protection for non-private data, then the sender uses shared quantum key encryption for both types of data, and the receiver correspondingly uses the corresponding quantum key to decrypt both types of data. ; If it is agreed in advance that non-private data is not protected by quantum keys, then the sender only uses shared quantum key encryption for private data, and the receiver accordingly only uses the corresponding shared quantum key to decrypt the received private data, non-private data No need to decrypt.
[0272] In order to simplify the description, this embodiment adopts a way of protecting both user privacy data and non-private data with a shared quantum key, that is, after the sender of the two interacting parties prepares the data to be sent, it uses the same method as the receiver. The shared quantum key encryption between the receivers, after receiving it, first uses the corresponding shared quantum key to decrypt, and then further processes the acquired information. In the four electronic prescription operations listed in this embodiment, this part of the operation is the same, and this part of the process is shown in Figure 3, Figure 5, Figure 7, Figure 8, Figure 10, and Figure 11. Therefore, This part of the text description is omitted in the following embodiments.
[0273] The following specifically describes the four types of electronic prescription operation procedures listed previously. In the following description, User_ID represents the user ID "Patient" obtained by the user after registration in the electronic prescription management system. D represents the user's unique identification in the HIS system, also known as the patient ID, B_ID represents the third-party ID, and P_ID represents the user ID provided by the HIS system. Electronic prescription identification, HIS_ID represents the hospital information system identification, Kue represents the shared quantum key between the client and the electronic prescription management system, Keh represents the shared quantum key between the electronic prescription management system and the HIS system, and Kuh represents the client and The shared quantum key between HIS systems represents the shared quantum key between the client and the third party, {message} key represents the encryption of the message with the key, and hash () represents the hash function.
[0274] (1) Establish a binding relationship between the user and the HIS system.
[0275] Please refer to FIG. 2, which is a processing flowchart for establishing a binding relationship between a user and a HIS system provided by an embodiment of the application. The processing flow includes the following steps:
[0276] Step 201, the client uses a preset hash algorithm to calculate the hash value of the user privacy data used to verify the user identity, and sends the binding relationship carrying the hash value to the electronic prescription management system Create request.
[0277] The client can receive user privacy data used to verify user identity input by the user, and can also obtain preset user privacy data used to verify user identity from locally stored user information after the user logs in. The preset hash algorithm includes: SHA-1, SHA-2, or SHA-3 algorithm.
[0278] In this embodiment, the shared key between the user and the HIS system whose binding relationship is to be established is used as the user privacy data. For example, hash(KJ<sub>o</sub>Other modification implementation methods can also be used, for example, hash (Patient_ID, Κ<sub>υΗ</sub>, η), that is, calculate Patient_ID, Κ<sub>υΗ</sub>> And the hash of the string composed of n spliced together
value. Among them, Patient_ID is the identification of the patient whose binding relationship is to be established, and n is the auxiliary authentication information generated by the client for implementing mutual authentication, for example, it may be a random number input by the user.
[0279] The binding relationship establishment request sent by the client to the electronic prescription management system not only carries the hash value obtained by the above calculation, but also the user ID User_ID that initiated the request, the HIS_ID to be established for the binding relationship, and the user status Patient_ID in the corresponding HIS system<sub>o</sub>
[0280] Preferably, in order to achieve efficient and secure two-way verification, the binding relationship establishment request sent by the client to the electronic prescription management system may also carry auxiliary authentication information n generated locally by the client. In this embodiment, a preferred two-way verification process is adopted. In other implementation manners, two-way verification may not be used, so the client may not carry the auxiliary authentication information η in the binding relationship establishment request.
[0281] Step 202: After receiving the binding relationship establishment request, the electronic prescription management system sends a binding verification request carrying the hash value to the hospital information system to which the binding relationship is to be established.
[0282] After receiving the binding relationship establishment request, the electronic prescription management system can forward the binding verification request carrying the hash value, Patient_ID, and auxiliary authentication information n to the corresponding HIS_ID according to the HIS_ID obtained from the received request. HIS system.
[0283] Step 203: The hospital information system verifies the user identity according to the hash value obtained from the received request, and sends a verification pass response to the electronic prescription management system after the verification is passed.
[0284] The HIS system can search for preset user privacy data used to verify the user's identity according to the received Patient_ID. In this embodiment, the HIS system searches for the shared key stored corresponding to the Patient_ID, that is, the user and Shared key Kuh between HIS systems. Then the hash value is calculated in the same way as the client. For example, if the client calculates hash(KG, then the HIS system also calculates the hash value of the heart found locally; if the client calculates hash(Patient_ID, K<sub>UH</sub>, η), then the HIS system also uses the locally found and received information to calculate the corresponding hash value. Finally, compare the calculated hash value with the received hash value. If they are consistent, it means that the Patient_ID provided by the user is valid and legal, and the user knows the shared key corresponding to the Patient_ID, so it can be determined that the After the user passes the identity verification, the binding relationship between the user and the HIS system can be established.
[0285] After the verification is passed, the HIS system sends a verification pass response to the electronic prescription management system. In order to perform two-way identity verification, the HIS system can generate corresponding variant information according to the received auxiliary authentication information, encrypt the variant information with blood, and then send it to the electronic prescription management system in the verification pass response. The variant of the auxiliary authentication information refers to the information generated based on the auxiliary authentication information, for example, it may be the auxiliary authentication information itself; or it is obtained by processing the auxiliary authentication information using a preset mathematical transformation method Result, for example nl ο
[0286] Step 204: The electronic prescription management system establishes a binding relationship between the user and the hospital information system according to the received verification pass response.
[0287] After the electronic prescription management system receives the verification pass response, it can establish User_ID, HIS_ID and Patient_
The mapping relationship between IDs completes the binding operation. The binding success response can then be returned to the client.
[0288] In order to achieve two-way identity verification, the electronic prescription management system can carry the variant information received from the HIS system (the variant information encrypted by Kuh) when it returns a binding success response to the client. After the client receives the successful binding response, it extracts the encrypted variant information from it, uses Kuh to decrypt it, and judges whether the variant information obtained after decryption is consistent with the variant information of the auxiliary authentication information generated locally. The HIS system can not only successfully decrypt and restore the auxiliary authentication information η, and its algorithm for generating variant information is consistent with that of the client, but also uses Kuh, which can only be known by a legal HIS system, to encrypt the variant information, thereby The client also verified the identity of the HIS system, thus realizing
Two-way authentication in the binding process has been implemented. After completing the above two-way verification process, the client can confirm that the binding operation is successful. [0289] Please refer to FIG. 3, which is a schematic diagram of data interaction of a binding operation provided in an embodiment of the application.
[0290] It can be seen from the above description that through the binding process, the electronic prescription management system establishes the mapping relationship between the user identification User_ID of the system and the patient identification Patient_ID of the HIS system. To complete the above-mentioned binding operation in the prior art, the electronic prescription management system needs to obtain user privacy data from the client and the HIS system, and compare them, so as to verify the user's identity. In this process, the electronic prescription management system needs to obtain User privacy data may also be stolen during the transmission of privacy data, thereby exposing user privacy.
[0291] The binding process provided by this technical solution is not only protected by the shared quantum key during the transmission of private data, but the client also uses a secondary encryption method, that is, before using the shared quantum key Kue encryption, The client uses a hash algorithm to encrypt the private data once. During the process of forwarding the binding verification request, the electronic prescription management system cannot know the user's private data through a decryption. Therefore, the user's private data is safe during the entire processing. , No unnecessary leakage will occur. In addition, by returning the auxiliary authentication information encrypted by the shared key Kuh, the client can confirm that it is the information fed back by the legal hospital whose binding relationship is to be established, thus realizing efficient two-way authentication.
[0292] (2) Update the shared key between the user and the HIS system.
[0293] The shared key Ku" between the user and the hospital information system is usually generated offline when the user registers for the first time in a medical institution. The shared key can be used as a two-way authentication when the binding relationship between the HIS system and the user is established. Basically, it can also be used to protect the private data in the electronic prescription (for this part, please refer to the relevant instructions on the user to obtain the electronic prescription), so it can be updated to ensure security.
[0294] The client and the HIS system can directly use the quantum key distribution protocol to negotiate to obtain the new shared key KuHnw between the user and the HIS system. This method requires the client to negotiate a quantum key with each HIS system, which will increase Overhead, this technical solution uses quantum keys Kue and Keh shared between the client and the HIS system and the electronic prescription management system to update the shared key between the user and the HIS system based on the forwarding method of the electronic prescription management system. Achieved the purpose of saving costs.
[0295] Please refer to FIG. 4, which is a processing flowchart for updating the shared key between the user and the HIS system provided by an embodiment of the application. The processing flow includes the following steps:
[0296] Step 401: The client uses the shared key currently used by the user and the hospital information system to encrypt the generated new shared key, and sends a shared key update request carrying the encrypted new shared key to the electronic prescription Management system.
[0297] In specific implementation, the client can generate a random number to generate a new shared key Kuh Hush between the user and the hospital information system to be updated, and use the user and the hospital information system Currently using K|JH to K UH new encryption°
[0298] The shared key update request sent by the client to the electronic prescription management system can not only carry the new shared key Km n® encrypted by Kuh, but also the user ID User_ID that initiated the request and the shared secret to be updated. The ID of the key's HIS system HIS_ID<sub>O</sub>
[0299] Step 402: After receiving the shared key update request, the electronic prescription management system forwards the shared key update request carrying the encrypted new shared key to the hospital information system.
[0300] After the electronic prescription management system obtains User_ID, HIS_ID, and encrypted KuHn® from the received shared key update request, according to the pre-established binding relationship between the user and the hospital information system, it searches for the corresponding User_ID and HIS_ID Patient_ID, and then according to the obtained HIS_ID, it will carry the encrypted K<sub>UH new</sub>,as well as
The shared key update request of Patient_ID is forwarded to the corresponding HIS system.
[0301] Step 403: The hospital information system uses the shared key currently used by the hospital information system to decrypt the received encrypted new shared key, and obtains the new shared key with the user .
[0302] After obtaining the encrypted Kuh Hush and Patient ID from the received shared key update request, the HIS system searches for the shared key K stored corresponding to Patient_ID.<sub>UH</sub>, And then decrypt the received encrypted Kuh to obtain the new shared key K corresponding to the Patient_ID<sub>UH new</sub>, Which is the new shared key between it and the user corresponding to Patient_ID. Thereafter, the HIS system may return a confirmation response for obtaining the new shared key to the electronic prescription management system, and the electronic prescription management system may return a confirmation response to the client.
[0303] Please refer to FIG. 5, which is a schematic diagram of data interaction of a shared key update operation provided by an embodiment of the application.
[0304] The shared key update process provided by this technical solution realizes the end-to-end shared secret between the user and the hospital information system through the forwarding of the electronic prescription management system under the secure transmission protection provided by the quantum keys Kue and K eh. The key update process reduces the update cost while ensuring the secure transmission of private data. It also solves the problem of difficulty in symmetric key distribution, and avoids the problem that the calculation speed of public key encryption is difficult to meet practical requirements. It is realized by using symmetric keys. Anonymous storage of user privacy data (such as e-prescriptions) provides convenience.
[0305] Further, since the client uses a secondary encryption method, that is, before adopting Kue encryption, the new shared key is encrypted and protected by the existing shared key between the user and the HIS system, thereby the electronic prescription management The system cannot learn the new shared key information during the forwarding process, avoiding the leakage of user privacy data and ensuring the security of user privacy data.
[0306] (3) The user obtains an electronic prescription.
[0307] Please refer to FIG. 6, which is a processing flowchart for a user to obtain an electronic prescription according to an embodiment of the application. The processing flow includes the following steps:
[0308] Step 601: The client sends the user's electronic prescription acquisition request to the electronic prescription management system.
[0309] The electronic prescription acquisition request sent by the client to the electronic prescription management system may carry the user ID User_ID that initiated the request, the ID HIS_ID of the hospital information system that provided the electronic prescription, and the electronic prescription ID P_ID.<sub>O </sub>[0310] Step 602. After receiving the request, the electronic prescription management system sends the electronic prescription obtained from the hospital information system to the client, where the electronic prescription is the information of the user and the hospital that provided the electronic prescription. The shared key between the systems is encrypted.
[0311] After obtaining the User_ID, HIS_ID, and P_ID from the received electronic prescription acquisition request, the electronic prescription management system can first verify whether there is a binding relationship between the user involved in the electronic prescription acquisition request and the hospital information system, that is, whether There is a Patient_ID corresponding to the User_ID and the HIS_ID. If there is, it means that the corresponding binding relationship has been established, and the operation of obtaining the electronic prescription can be performed; otherwise, a response that the binding relationship has not been established can be returned to the client.
[0312] The electronic prescription management system searches whether the electronic prescription corresponding to User_ID and P_ID is stored, and if so, obtains the electronic prescription and sends it to the client.
[0313] If the electronic prescription management system has not stored the electronic prescription, perform the following operations:
[0314] 1) The electronic prescription management system searches for the Patient_ID corresponding to User_ID and HIS_ID according to the pre-established binding relationship between the user and the hospital information system, and sends the electronic prescription acquisition request carrying the Patient_ID and P_ID to the corresponding according to the HIS_ID HIS system.
[0315] 2) The HIS system searches for the correspondence according to the Patient_ID and P_ID carried in the received electronic prescription acquisition request
And use the shared key corresponding to Patient_ID to encrypt the found electronic prescription, and then send it to the electronic prescription management system.
[0316] 3) After the electronic prescription management system receives the electronic prescription sent by the HIS system, it sends it to the client. The electronic prescription platform can also store the electronic prescription and establish the corresponding relationship between User_ID, P_ID and the electronic prescription. Then the next time the user obtains or authorizes a third party to view the electronic prescription, the electronic prescription management system can directly return The electronic prescription has been stored.
[0317] From the above description of this step, it can be seen that the electronic prescription obtained by the electronic prescription management system from the hospital information system is the electronic prescription encrypted by the shared key Kuh between the user and the HIS system, that is, the ciphertext of the electronic prescription , The corresponding electronic prescription management system also stores the ciphertext of the electronic prescription.
[0318] Further, the shared key between the user and the HIS system may be under the protection of the shared quantum key between the client and the electronic prescription management system, and between the electronic prescription management system and the hospital information system. , Updated through the electronic prescription management system forwarding method. During specific implementation, the operation procedure of updating the shared key between the user and the HIS system provided in this embodiment can be used, and the shared key is updated under the protection of the shared quantum keys Kue and Keh.
[0319] Step 603: The client uses the shared key between the user and the hospital information system to decrypt the received electronic prescription, and obtain the original information of the electronic prescription.
[0320] Please refer to FIG. 7, which is the data interaction process of obtaining the electronic prescription operation when the electronic prescription management system provided by the embodiment of the application does not store the electronic prescription. Please refer to FIG. 8, which is the electronic prescription provided by the embodiment of the application. The management system has stored the data interaction process of obtaining the electronic prescription operation when the electronic prescription is stored.
[0321] From the above description, it can be seen that while the electronic prescription platform obtains the electronic prescription from the HIS system and provides it to the client, it can also store the electronic prescription to simplify the next process of providing the electronic prescription. Since the electronic prescription contains user privacy data, it should not be known by the relevant personnel of the electronic prescription management system, and user privacy data should not be leaked even when information is leaked in the electronic platform management system.
[0322] The operation process of obtaining electronic prescriptions provided by this technical solution realizes the function of users obtaining electronic prescriptions through the client through the storage and forwarding of the electronic prescription management system under the secure transmission protection provided by the quantum keys Kue and K eh, While ensuring the secure transmission of private data, the HIS system uses a secondary encryption method for the electronic prescription, that is, before adopting Keh encryption, the shared key Kuh between the user and the HIS system is used to encrypt the electronic prescription, so The electronic prescription management system obtains and stores the ciphertext of the electronic prescription, which cannot obtain the original information contained in the electronic prescription, realizes the anonymous storage of the electronic prescription, avoids the leakage of user privacy data, and ensures the security of user privacy data.
[0323] Further, the shared key Kuh used to encrypt the electronic prescription can also be updated under the protection of the shared quantum key core and Keh, thereby avoiding the difficulty of symmetric key distribution in the process of anonymously storing the electronic prescription. It also avoids the problem that the operation speed of the public key encryption method is difficult to meet the practical requirements.
[0324] (4) The user authorizes a third party to view the electronic prescription.
[0325] In some cases, users also need to authorize other participants to view electronic prescriptions, such as pharmacies, other medical institutions, or medical regulatory agencies. In this technical solution, other participants who are authorized to view electronic prescriptions are collectively referred to as the first Three parties, these third parties can usually also be registered in the electronic prescription management system to become a trusted third party recognized by the electronic prescription management system.
[0326] Under normal circumstances, the user can first perform the operation of obtaining the electronic prescription described before, so that the electronic prescription can be managed
The management system obtains the electronic prescription to be authorized by a third party to be viewed from the HIS system in advance, and stores the electronic prescription.
[0327] Please refer to FIG. 9, which is a processing flowchart of a user authorizing a third party to view an electronic prescription according to an embodiment of the application. The processing flow includes the following steps:
[0328] Step 901: The client sends a third-party authorization request of the user to the electronic prescription management system.
[0329] The third-party authorization request sent by the client to the electronic prescription management system may carry the identification User_ID of the user who initiated the request, the identification B_ID of the authorized third party, and the electronic prescription identification P_ID that the third party is authorized to view.
[0330] Step 902: After receiving the authorization request from the third party, the electronic prescription management system sends the electronic prescription authorized to the third party to be viewed to the client.
[0331] After the electronic prescription management system obtains User_ID, B_ID, and P_ID from the received third-party authorization request, it can first verify whether the user involved in the request has the authority to authorize a third party to view the corresponding electronic prescription, that is, the User_ID and Whether the P_ID has a corresponding relationship, if so, it means that the electronic prescription is the user's own electronic prescription, the user has the authority to authorize a third party to view, and the electronic prescription has been stored in the electronic prescription management system, and then the electronic prescription can be stored in the electronic prescription management system. The electronic prescription corresponding to the User_ID and the P_ID is sent to the client.
[0332] It should be noted that the electronic prescription stored in the electronic prescription management system is encrypted using a shared key between the user and the HIS system that provides the electronic prescription.
[0333] If the electronic prescription management system has not stored the electronic prescription, that is, the corresponding relationship between the User_ID and the P_ID and the electronic prescription has not been established, the electronic prescription management system may return a response that the electronic prescription is not found to the client , Prompt the client to perform the operation of obtaining the electronic prescription first, and then perform the operation of authorizing the third party to view the electronic prescription.
[0334] Step 903: The client uses the shared key between the user and the hospital information system that provides the electronic prescription to decrypt the received electronic prescription, obtains the original information of the electronic prescription, and uses the third party to have corresponding information. The first encryption key of the decryption key encrypts the original information of the electronic prescription, and sends the electronic prescription forwarding request carrying the encrypted electronic prescription to the electronic prescription management system.
[0335] The client first uses Kuh to decrypt the received electronic prescription, obtains the original information of the electronic prescription, and then uses the first encryption key of the third party with a corresponding decryption key to encrypt the original information of the electronic prescription, and Send an electronic prescription forwarding request to the electronic prescription management system, the request carries the electronic prescription encrypted with the first encryption key, and the third-party identifier B_ID<sub>O</sub>The first encryption key may be the public key "ρ of the third party, then the corresponding decryption key possessed by the third party is its private key Kbs. In this case, in order to facilitate the client to perform encryption processing , In step 902, the electronic prescription management system may send the third-party digital certificate to the client.
[0336] Adopting the above public key encryption method can prevent the electronic prescription management system from learning electronic prescription information, but the public key encryption method has low calculation efficiency. In order to improve calculation efficiency, this embodiment also provides a preferred embodiment: receiving electronic prescription information at the client After the electronic prescription sent by the prescription management system, a new shared key between the user and the third party is also generated, for example, a random number is generated as a third-party authorization between the next processing and the third party The first encryption key used in the request is encrypted and the new shared key is encrypted in the same way as the electronic prescription, and then sent to the electronic prescription management system.
[0337] With the above preferred embodiment, when the user authorizes the third party to view the electronic prescription for the first time, the client uses the third-party public key "ρ to encrypt the electronic prescription and the new shared key K blood, and pass the electronic prescription management system Forwarded to said
The third party, so that the third party has also obtained Kub by decrypting with its private key Kbs; in the second and subsequent times when the third party is authorized to view the electronic prescription, the client can use the current use between the user and the third party The shared key Kub is encrypted, and a new shared key Kub is generated at the same time as the shared key used in the next processing of the third-party authorization request with the third party, that is, the first encryption key. , The third party uses Kub to decrypt the information forwarded by the electronic prescription management system, and obtains the Kub trace as the shared key used to decrypt the users electronic prescription next time, that is, the shared key corresponding to the first encryption key The decryption key realizes the dynamic update of the shared key between the user and the third party.
[0338] Using the above method to generate and update the shared key between the user and the third party can not only use the symmetric key to save calculation costs, but also because the shared key is updated in each authorization process, the security of the shared key can be improved. Sex.
[0339] Step 904: The electronic prescription management system sends the received electronic prescription to a corresponding third party.
[0340] The electronic prescription management system obtains the third-party identification B_ID from the received electronic prescription forwarding request, and sends the received electronic prescription to a corresponding third party according to the B_ID. Wherein, the electronic prescription is encrypted by the client using the first encryption key.
[0341] If the preferred embodiment of dynamically updating the shared key is adopted in step 903, then in this step the electronic prescription management system sends to the third party not only the electronic prescription, but also the user and the third party. The new shared key between the three parties.
[0342] Step 905: The third party decrypts the received electronic prescription by using the decryption key corresponding to the first encryption key, and obtains the original information of the electronic prescription.
[0343] The decryption key corresponding to the first encryption key may be the private key Kbs of the third party. If the preferred embodiment of dynamically updating the shared key is adopted in step 903, the third party adopts the decryption key corresponding to the first encryption key (Kbs for the first authorization, and subsequent ones obtained last time. Shared key) After decrypting the received information, the obtained information includes not only the original information of the electronic prescription, but also the new shared key Kub, which is used as the first encryption for the next decryption of the users electronic prescription. The decryption key corresponding to the key.
[0344] Please refer to FIG. 10 and FIG. 11, which show a schematic diagram of data interaction based on the above-mentioned preferred embodiment. FIG. 10 is a schematic diagram of data interaction for a user to authorize a third party to view an electronic prescription for the first time according to an embodiment of the application. FIG. 11 is a schematic diagram of data interaction for a user to subsequently authorize a third party to view an electronic prescription according to an embodiment of the application.
[0345] The operation process of the user authorizing a third party to view the electronic prescription provided by this technical solution, under the secure transmission protection provided by the quantum key Kue and Keb, realizes that the user authorizes the third party to view the electronic prescription through the forwarding of the electronic prescription management system. Function, while ensuring the secure transmission of user privacy data, because the client uses a secondary encryption method for the electronic prescription, that is, before adopting the "blood encryption, the first encryption key between the user and the third party is used to pair the electronic prescription Encryption protection is performed. Therefore, the electronic prescription management system obtains and forwards the ciphertext of the electronic prescription. It cannot obtain the original information contained in the electronic prescription, avoiding the leakage of user privacy data and ensuring the security of user privacy data.
[0346] Further, since each time the third party is authorized, the shared key between the user and the third party can be updated under the protection of the shared quantum key core and Keb, as the client in the next authorization operation As well as the symmetric key used by the third party, the symmetric key can be used to save calculation costs, and at the same time, the security of the shared key can be improved.
[0347] In the above-mentioned embodiment, an electronic prescription operation method is provided. Correspondingly, this application also provides an electronic prescription operation device. Please refer to FIG. 12, which is a schematic diagram of an embodiment of an electronic prescription operation device of this application. Since the device embodiment is basically similar to the method embodiment, the description is relatively simple, and the relevant part can refer to the part of the description of the method embodiment. The device embodiments described below are merely illustrative.
[0348] An electronic prescription operation device of this embodiment includes: an operation request sending unit 1201, used for the client to send a user's electronic prescription operation request to the electronic prescription management system; an operation request processing unit 1202, used for electronic prescription management After the system receives the operation request, it completes the processing of the operation request through the interaction process with the hospital information system, the client and/or the third party; wherein, the operation request sending unit and the operation request processing The units each include a quantum key encryption and decryption subunit, which is used for both parties involved in processing the operation request when transmitting user privacy data, the sender uses the shared quantum key for encryption, and the receiver uses the corresponding shared quantum key for decryption; The shared quantum key is obtained by the sender and the receiver in advance through a quantum key distribution protocol.
[0349] Optionally, the operation request processing unit is further configured to use an electronic prescription before the client or the hospital information system uses the shared quantum key to encrypt user privacy data to be sent to the electronic prescription management system The user privacy data is encrypted in a way that the management system cannot decrypt.
[0350] Optionally, when the electronic prescription operation request is a binding relationship establishment request, the operation request sending unit further includes:
[0351] The binding establishment request sending subunit is used for the client to use a preset hash algorithm to calculate the hash value of the user privacy data used to verify the user's identity, and to send the carry to the electronic prescription management system. The request for establishing the binding relationship of the hash value;
[0352] Correspondingly, the operation request processing unit further includes:
[0353] The binding verification request sending subunit is used for the electronic prescription management system, after receiving the binding relationship establishment request, to send the binding verification carrying the hash value to the hospital information system where the binding relationship is to be established request;
[0354] The binding relationship verification subunit is used for the hospital information system to verify the user identity according to the hash value obtained from the received request, and send a verification pass response to the electronic prescription management system after the verification is passed ;
[0355] The binding relationship establishment subunit is used for the electronic prescription management system to establish the binding relationship between the user and the hospital information system according to the received verification pass response .
[0356] Optionally, when the electronic prescription operation request is a shared key update request, the operation request sending unit further includes:
[0357] The key update request sending subunit is used for the client to generate a new shared key between the user and the hospital information system to be updated with the shared key, using the user and the hospital information system The currently used shared key encrypts the new shared key, and sends a shared key update request carrying the encrypted new shared key to the electronic prescription management system;
[0358] Correspondingly, the operation request processing unit further includes:
[0359] The update request forwarding subunit is used to forward the shared key update request carrying the encrypted new shared key to the hospital information after the electronic prescription management system receives the shared key update request system;
[0360] The new key decryption acquisition subunit is used for the hospital information system to decrypt the received encrypted new shared key using the shared key currently used by the hospital information system and the user to obtain The new shared key between.
[0361] Optionally, when the electronic prescription operation request is an electronic prescription acquisition request, the operation request sending unit further includes:
[0362] The prescription acquisition request sending subunit is used for the client to send an electronic prescription acquisition request to the electronic prescription management system;
[0363] Correspondingly, the operation request processing unit further includes:
[0364] The electronic prescription sending sub-unit is used for the electronic prescription management system to receive the request from the hospital
The electronic prescription obtained by the information system is sent to the client, wherein the electronic prescription is encrypted using a shared key between the user and the hospital information system that provides the electronic prescription;
[0365] The electronic prescription decryption and acquisition subunit is used for the client to decrypt the received electronic prescription using the shared key between the user and the hospital information system to obtain the original information of the electronic prescription.
[0366] Optionally, when the electronic prescription operation request is a third-party authorization request, the operation request sending unit further includes:
[0367] The third-party authorization request sending subunit is used for the client to send a third-party authorization request to the electronic prescription management system;
[0368] Correspondingly, the operation request processing unit further includes:
[0369] The authorized prescription sending sub-unit is used for the electronic prescription management system to send the electronic prescription authorized to the third party to view to the client after receiving the third-party authorization request, and the electronic prescription uses the user Encrypted with a shared key between the hospital information system that provides the electronic prescription;
[0370] Authorized prescription encryption and decryption subunit for the client to use the shared key between the user and the hospital information system to decrypt the received electronic prescription, obtain the original information of the electronic prescription, and use the The third party has a first encryption key corresponding to the decryption key to encrypt the original information of the electronic prescription, and sends the electronic prescription forwarding request carrying the encrypted electronic prescription to the electronic prescription management system;
[0371] Authorized prescription forwarding subunit for the electronic prescription management system to send the received encrypted electronic prescription to the third party;
[0372] The authorized prescription obtaining subunit is used for the third party to decrypt the received electronic prescription by using the decryption key corresponding to the first encryption key to obtain the original information of the electronic prescription.
[0373] In addition, this application also provides a request method for establishing a binding relationship, and the method is implemented on the client. Please refer to FIG. 13, which is a flowchart of an embodiment of a request method for establishing a binding relationship provided by this application. The parts with the same content in this embodiment and the first embodiment will not be repeated. The following focuses on the differences. Place. A request method for establishing a binding relationship provided by this application includes:
[0374] Step 1301, using a preset hash algorithm, calculate a hash value of user privacy data used to verify the identity of the user, and the user refers to the user who initiates the binding relationship establishment request.
[0375] Step 1302, sending a binding relationship establishment request to the electronic prescription management system, the request carrying the user's identification, the hash value, the identification of the hospital information system to which the binding relationship is to be established, and the The user corresponds to the patient identification of the hospital information system, wherein at least the hash value is encrypted using a shared quantum key with the electronic prescription management system.
[0376] In the foregoing embodiment, a request method for establishing a binding relationship is provided. Correspondingly, this application also provides a request device for establishing a binding relationship. Please refer to FIG. 14, which is a schematic diagram of an embodiment of a request device for establishing a binding relationship according to this application. The device embodiments described below are merely illustrative.
[0377] A request device for establishing a binding relationship in this embodiment, the device is deployed on a client, and includes: a hash value calculation unit 1401, configured to use a preset hash algorithm to calculate for verification The hash value of the user privacy data of the user identity; the binding request encryption sending unit 1402 sends a binding relationship establishment request to the electronic prescription management system, and the request carries the user's identity, the hash value, and the to-be-established The identification of the hospital information system in the binding relationship and the patient identification of the user corresponding to the hospital information system, wherein at least the hash value is encrypted using a shared quantum key with the electronic prescription management system of.
[0378] In addition, this application also provides a method for establishing a binding relationship, and the method is implemented in an electronic prescription management system. Please refer to FIG. 15, which is a flowchart of an embodiment of a method for establishing a binding relationship provided by this application. The parts with the same content in this embodiment and the first embodiment will not be described again, and the differences will be mainly described below. . A method for establishing a binding relationship provided by this application includes:
[0379] Step 1501. Receive a binding relationship establishment request sent by a client.
[0380] Step 1502, using the shared quantum key with the client to perform a corresponding decryption operation on the information carried in the request, and obtain a user ID, a hash value, a hospital information system ID, and a patient ID.
[0381] Step 1503, according to the acquired hospital information system identification, forward the binding verification request carrying the hash value and the patient identification to the corresponding hospital information system, wherein at least the hash value is used and The shared quantum key between the hospital information systems is encrypted.
[0382] Step 1504: Receive a verification pass response sent by the hospital information system, and establish a mapping relationship between the user ID, the hospital information system ID, and the patient ID, and complete the binding operation.
[0383] In the foregoing embodiment, a method for establishing a binding relationship is provided. Correspondingly, this application also provides a device for establishing a binding relationship. Please refer to FIG. 16, which is a schematic diagram of an embodiment of an apparatus for establishing a binding relationship according to this application. The device embodiments described below are merely illustrative.
[0384] A device for establishing a binding relationship in this embodiment, the device is deployed in an electronic prescription management system, and includes: a binding establishment request receiving unit 1601, configured to receive a binding relationship establishment request sent by a client Binding establishment request decryption unit 1602, configured to use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request, and obtain the user ID, hash value, and hospital information system ID , And patient identification; a binding verification request encryption forwarding unit 1603, configured to forward the binding verification request carrying the hash value and the patient identification to the corresponding hospital information system according to the acquired hospital information system identification, Wherein at least the hash value is encrypted using a shared quantum key with the hospital information system; the binding relationship establishment unit 1604 is configured to receive the verification pass response sent by the hospital information system, and establish the The mapping relationship between the user ID, the hospital information system ID and the patient ID completes the binding operation.
[0385] In addition, this application also provides a method for verifying the binding relationship, and the method is implemented in a hospital information system. Please refer to FIG. 17, which is a flowchart of an embodiment of a method for verifying a binding relationship provided by this application. The parts with the same content in this embodiment and the first embodiment will not be described again, and the differences will be mainly described below. . A method for verifying the binding relationship provided by this application includes:
[0386] Step 1701, receiving a binding verification request sent by an electronic prescription management system.
[0387] Step 1702, using the shared quantum key with the electronic prescription management system to perform a corresponding decryption operation on the information carried in the request to obtain a hash value and a patient identification.
[0388] Step 1703: Search for preset user privacy data used to verify user identity according to the received patient identification, calculate the hash value of the found user privacy data using a preset hash algorithm, and determine the calculated hash value. Whether the column value is consistent with the hash value obtained from the request, if they are consistent, step 1704 is executed.
[0389] Step 1704: Send a verification pass response to the electronic prescription management system.
[0390] In the foregoing embodiment, a method for verifying a binding relationship is provided. Correspondingly, the present application also provides a device for verifying a binding relationship. Please refer to FIG. 18, which is a schematic diagram of an embodiment of a device for verifying a binding relationship according to this application. The device embodiments described below are merely illustrative.
[0391] A device for verifying a binding relationship of this embodiment, the device being deployed in a hospital information system, includes:
The binding verification request receiving unit 1801 is used to receive the binding verification request sent by the electronic prescription management system; the binding verification request decryption unit 1802 is used to use the shared quantum key pair with the electronic prescription management system to The information carried in the request performs the corresponding decryption operation to obtain the hash value and the patient ID; the hash value calculation and comparison unit 1803 is used to find the preset user privacy data used to verify the user identity according to the received patient ID , Using a preset hash algorithm to calculate the hash value of the user privacy data found, and determine whether the calculated hash value is consistent with the hash value obtained from the request; the verification pass response unit 1804 is used for when When the output of the hash value calculation and comparison unit is yes, a verification pass response is sent to the electronic prescription management system.
[0392] In addition, this application also provides a request method for updating the shared key, which is implemented on the client. Please refer to FIG. 19, which is a flowchart of an embodiment of a request method for updating a shared key provided by this application. The parts that are the same in this embodiment and the first embodiment will not be repeated. The following focuses on the differences. Place. A request method for updating a shared key provided in this application includes:
[0393] Step 1901: Generate a new shared key for the user whose shared key is to be updated and the hospital information system, and use the shared key currently used by the user and the hospital information system to encrypt the new shared key.
[0394] Step 1902: Send a shared key update request to the electronic prescription management system, where the request carries the user's identity, the hospital information system's identity, and the encrypted new shared key, where at least The encrypted new shared key is encrypted using the shared quantum key with the electronic prescription management system.
[0395] In the foregoing embodiment, a request method for updating a shared key is provided. Correspondingly, this application also provides a request device for updating a shared key. Please refer to FIG. 20, which is a schematic diagram of an embodiment of a request device for updating a shared key according to this application. The device embodiments described below are merely illustrative.
[0396] A requesting device for updating a shared key of this embodiment, the device is deployed on the client, and includes: a new shared key generating unit 2001 for providing information about the user and the hospital whose shared key is to be updated The system generates a new shared key, and uses the shared key currently used by the user and the hospital information system to encrypt the new shared key; the key update request encryption sending unit 2002 is used to send to the electronic prescription management system Shared key update request, the request carries the user's identification, the hospital information system's identification, and the encrypted new shared key, wherein at least the encrypted new shared key is used with The shared quantum key between the electronic prescription management systems is encrypted.
[0397] In addition, this application also provides a method for forwarding a shared key update request, and the method is implemented in an electronic prescription management system. Please refer to FIG. 21, which is a flowchart of an embodiment of a method for forwarding a shared key update request provided by this application. The parts that are the same in this embodiment and the first embodiment will not be repeated. The following focuses on the differences. Place. A method for forwarding a shared key update request provided in this application includes:
[0398] Step 2101. Receive a shared key update request sent by a client.
[0399] Step 2102: Use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext, user ID, and hospital information system ID of the new shared key .
[0400] Step 2103: According to the pre-established binding relationship between the user and the hospital information system, search for a patient ID corresponding to the user ID and the hospital information system ID.
[0401] Step 2104. According to the acquired hospital information system identification, forward the ciphertext carrying the new shared key and the shared key update request of the patient identification to the corresponding hospital information system, where at least the new The ciphertext of the shared key is encrypted using the shared quantum key with the hospital information system.
[0402] In the foregoing embodiment, a method for forwarding a shared key update request is provided. Correspondingly, this application also provides a device for forwarding a shared key update request. Please refer to Figure 22, which is a part of this application
A schematic diagram of an embodiment of an apparatus for forwarding a shared key update request. The device embodiments described below are merely illustrative.
[0403] An apparatus for forwarding a shared key update request of this embodiment, the apparatus is deployed in an electronic prescription management system, and includes: a key update request receiving unit 2201, configured to receive a shared key sent by a client Update request; the key update request decryption unit 2202, configured to use the shared quantum key with the client to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext of the new shared key and the user Identification and hospital information system identification; a patient identification search unit 2203, configured to search for a patient identification corresponding to the user identification and the hospital information system identification according to the pre-established binding relationship between the user and the hospital information system; The key update request encryption forwarding unit 2204 is configured to forward the ciphertext carrying the new shared key and the shared key update request of the patient identification to the corresponding hospital information system according to the acquired hospital information system identification, Wherein, at least the ciphertext of the new shared key is encrypted with the shared quantum key with the hospital information system.
[0404] In addition, this application also provides a method for updating a shared key, which is implemented in a hospital information system. Please refer to FIG. 23, which is a flowchart of an embodiment of a method for updating a shared key provided by this application. The parts that have the same content in this embodiment and the first embodiment will not be repeated, and the differences will be mainly described below. A method for updating a shared key provided by this application includes:
[0405] Step 2301, receiving a shared key update request sent by an electronic prescription management system.
[0406] Step 2302, using the shared quantum key with the electronic prescription management system to perform a corresponding decryption operation on the information carried in the request, and obtain the ciphertext of the new shared key and the patient identification.
[0407] Step 2303: Use the shared key corresponding to the patient identification to decrypt the ciphertext of the new shared key, and obtain a new shared key corresponding to the patient identification, that is, the user corresponding to the patient identification The new shared key between.
[0408] In the foregoing embodiment, a method for updating a shared key is provided. Correspondingly, this application also provides a device for updating a shared key. Please refer to FIG. 24, which is a schematic diagram of an embodiment of an apparatus for updating a shared key according to this application. The device embodiments described below are merely illustrative.
[0409] A device for updating a shared key of this embodiment, which is deployed in a hospital information system, includes: a forwarding request receiving unit 2401, configured to receive a shared key update request sent by an electronic prescription management system; The forwarding request decryption unit 2402 is configured to use the shared quantum key with the electronic prescription management system to perform corresponding decryption operations on the information carried in the request, and obtain the ciphertext of the new shared key and the patient identification; The new key obtaining unit 2403 is configured to use the shared key corresponding to the patient identification to decrypt the ciphertext of the new shared key, and to obtain the new shared key corresponding to the patient identification, that is, with the patient Identifies the new shared key between the corresponding users.
[0410] In addition, this application also provides a request method for obtaining an electronic prescription, and the method is implemented on the client. Please refer to FIG. 25, which is a flowchart of an embodiment of a request method for obtaining an electronic prescription provided by this application. The parts with the same content in this embodiment and the first embodiment will not be repeated, and the differences will be mainly described below. . A request method for obtaining an electronic prescription provided by this application includes:
[0411] Step 2501, sending an electronic prescription acquisition request to an electronic prescription management system, the request carrying the identification of the user who initiated the request, the identification of the hospital information system that provided the electronic prescription, and the electronic prescription identification.
[0412] Step 2502, receive the electronic prescription sent by the electronic prescription management system.
[0413] Step 2503. Use the shared quantum key with the electronic prescription management system to decrypt the received electronic prescription, and use the shared key between the user and the hospital information system to decrypt the electronic prescription. The prescription is decrypted again, and the original information of the electronic prescription is obtained.
[0414] In the foregoing embodiment, a request method for obtaining an electronic prescription is provided. Correspondingly, this application also provides a request device for obtaining an electronic prescription. Please refer to FIG. 26, which is a schematic diagram of an embodiment of a request device for obtaining an electronic prescription according to this application. The device embodiments described below are merely illustrative.
[0415] A request device for obtaining an electronic prescription of this embodiment is deployed on a client and includes: a prescription obtaining request sending unit 2601 for sending an electronic prescription obtaining request to an electronic prescription management system. The request carries the identification of the user who initiated the request, the identification of the hospital information system that provided the electronic prescription, and the identification of the electronic prescription; the prescription information receiving unit 2602 is used to receive the electronic prescription sent by the electronic prescription management system; the original prescription is obtained Unit 2603, for decrypting the received electronic prescription using the shared quantum key with the electronic prescription management system, and using the shared key between the user and the hospital information system to decrypt the electronic prescription Decrypt again to obtain the original information of the electronic prescription.
[0416] In addition, this application also provides a method for forwarding electronic prescriptions, and the method is implemented in an electronic prescription management system. Please refer to FIG. 27, which is a flowchart of an embodiment of a method for forwarding an electronic prescription provided by this application. The parts with the same content in this embodiment and the first embodiment will not be repeated, and the differences will be mainly described below. A method for forwarding electronic prescriptions provided in this application includes:
[0417] Step 2701, receive an electronic prescription acquisition request sent by a client, and acquire the user identification, hospital information system identification, and electronic prescription identification carried in the request.
[0418] Step 2702, determine whether the electronic prescription corresponding to the user identification and the electronic prescription identification is stored, if yes, obtain the stored electronic prescription, if not, obtain the electronic prescription from the hospital information system.
[0419] The obtaining of the electronic prescription from the hospital information system includes the following processing procedures:
[0420] 1) According to the pre-established binding relationship between the user and the hospital information system, search for the patient ID corresponding to the user ID and the hospital information system ID; and according to the hospital information system ID, carry The patient identification and the electronic prescription acquisition request of the electronic prescription identification are sent to the corresponding hospital information system;
[0421] 2) Receive an electronic prescription sent by the hospital information system and corresponding to the user ID and the electronic prescription ID;
[0422] 3) Use the shared quantum key with the hospital information system to decrypt the received electronic prescription as the electronic prescription obtained from the hospital information system, and store the electronic prescription.
[0423] Step 2703: Use the shared quantum key with the client to encrypt the obtained electronic prescription and send it to the client.
[0424] In the foregoing embodiment, a method for forwarding an electronic prescription is provided. Correspondingly, this application also provides a device for forwarding an electronic prescription. Please refer to FIG. 28, which is a schematic diagram of an embodiment of an apparatus for forwarding electronic prescriptions according to this application. The device embodiments described below are merely illustrative.
[0425] A device for forwarding electronic prescriptions of this embodiment is deployed in an electronic prescription management system and includes: a prescription acquisition request receiving unit 2801, configured to receive an electronic prescription acquisition request sent by a client, and obtain The user identification, the hospital information system identification, and the electronic prescription identification carried in the request; the electronic prescription acquisition unit 2802 is used to determine whether the electronic prescription corresponding to the user identification and the electronic prescription identification is stored, and if so, obtain all the electronic prescriptions. The stored electronic prescription, if not, obtain the electronic prescription from the hospital information system; the electronic prescription encryption and forwarding unit 2803 is used to use the shared quantum key with the client to compare the obtained electronic prescription Encrypt and send to the client.
[0426] In addition, this application also provides a method for providing electronic prescriptions, the method is in the hospital information system
Implement. Please refer to FIG. 29, which is a flowchart of an embodiment of a method for providing electronic prescriptions provided by this application. The parts that are the same in this embodiment and the first embodiment will not be repeated, and the differences will be mainly described below. A method for providing electronic prescriptions provided in this application includes:
[0427] Step 2901: Receive an electronic prescription acquisition request sent by an electronic prescription management system, and acquire the patient identification and electronic prescription identification carried in the request.
[0428] Step 2902, search for an electronic prescription corresponding to the patient identification and the electronic prescription identification.
[0429] Step 2903. Use the shared key corresponding to the patient identification to encrypt the electronic prescription, and use the shared quantum key with the electronic prescription management system to encrypt the encrypted electronic prescription again, and send it To the electronic prescription management system.
[0430] In the above-mentioned embodiment, a method for providing an electronic prescription is provided. Correspondingly, this application also provides a device for providing an electronic prescription. Please refer to FIG. 30, which is a schematic diagram of an embodiment of an apparatus for providing electronic prescriptions according to this application. The device embodiments described below are merely illustrative.
[0431] An apparatus for providing electronic prescriptions of this embodiment, which is deployed in a hospital information system, includes: a forwarding prescription acquisition request receiving unit 3001, configured to receive an electronic prescription acquisition request sent by an electronic prescription management system, Obtain the patient identification and the electronic prescription identification carried in the request; the electronic prescription search unit 3002 is used to search for the electronic prescription corresponding to the patient identification and the electronic prescription identification; the electronic prescription encryption sending unit 3003 is used to use and The shared key corresponding to the patient identification encrypts the electronic prescription, and uses the shared quantum key with the electronic prescription management system to encrypt the encrypted electronic prescription again, and sends it to the electronic prescription management system.
[0432] In addition, this application also provides a request method for authorizing a third party, and the method is implemented on the client. Please refer to FIG. 31, which is a flowchart of an embodiment of a request method for authorizing a third party provided by this application. The parts with the same content in this embodiment and the first embodiment will not be repeated, and the differences will be mainly described below. . A request method for authorizing a third party provided in this application includes:
[0433] Step 3101, send a third-party authorization request to the electronic prescription management system, where the request carries the identification of the user who initiated the request, the third-party identification, and the electronic prescription identification that the third party is authorized to view.
[0434] Step 3102, receive the electronic prescription sent by the electronic prescription management system.
[0435] Step 3103: Use the shared quantum key with the electronic prescription management system to decrypt the received electronic prescription, and use the shared key pair between the user and the hospital information system that provides the electronic prescription The decrypted electronic prescription is decrypted again to obtain the original information of the electronic prescription.
[0436] Step 3104. Use the first encryption key of the third party with a corresponding decryption key to encrypt the original information of the electronic prescription, and encrypt the electronic prescription that carries the third-party identifier and the ciphertext of the electronic prescription. The prescription forwarding request is sent to the electronic prescription management system, wherein at least the electronic prescription ciphertext is encrypted using a shared quantum key with the electronic prescription management system.
[0437] In the foregoing embodiment, a request method for authorizing a third party is provided. Correspondingly, this application also provides a request device for authorizing a third party. Please refer to FIG. 32, which is a schematic diagram of an embodiment of a request device for authorizing a third party in this application. The device embodiments described below are merely illustrative.
[0438] A request device for authorizing a third party of this embodiment, the device is deployed on the client, and includes: an authorized third party request sending unit 3201, configured to send an authorized third party request to an electronic prescription management system, so The request carries the identification of the user who initiated the request, the third-party identification, and the identification of the electronic prescription that is authorized to be viewed by the third party; the electronic prescription receiving unit 3202 is used to receive the electronic prescription sent by the electronic prescription management system; the original prescription is obtained unit
3203. Used to decrypt the received electronic prescription using the shared quantum key with the electronic prescription management system, and use the shared key pair between the user and the hospital information system that provides the electronic prescription after decryption The electronic prescription is decrypted again to obtain the original information of the electronic prescription; the electronic prescription encryption sending unit 3204 is used to encrypt the original information of the electronic prescription using the first encryption key of the third party with a corresponding decryption key, And send the electronic prescription forwarding request carrying the third-party identification and the electronic prescription ciphertext to the electronic prescription management system, wherein at least the electronic prescription ciphertext is used between the electronic prescription management system and the electronic prescription management system. The shared quantum key is encrypted.
[0439] In addition, this application also provides an electronic prescription forwarding method for authorizing a third party, and the method is implemented in an electronic prescription management system. Please refer to FIG. 33, which is a flowchart of an embodiment of an electronic prescription forwarding method for authorizing a third party provided by this application. The parts with the same content in this embodiment and the first embodiment will not be repeated. The following focuses on the differences. Place. An electronic prescription forwarding method for authorizing a third party provided in this application includes:
[0440] Step 3301, receiving a third-party authorization request sent by a client, and obtaining a user identification, a third-party identification, and an electronic prescription identification carried in the request.
[0441] Step 3302, using the shared quantum key with the client, encrypt the electronic prescription corresponding to the user ID and the electronic prescription ID, and send it to the client.
[0442] Step 3303: Receive an electronic prescription forwarding request sent by the client.
[0443] Step 3304: Use the shared quantum key with the client to perform a corresponding decryption operation on the information carried in the request, and obtain a third-party identification and an electronic prescription.
[0444] Step 3305: Use the shared quantum key with the third party to encrypt the electronic prescription, and send the encrypted electronic prescription to the corresponding third party according to the third-party identifier.
[0445] In the foregoing embodiment, an electronic prescription forwarding method for authorizing a third party is provided. Correspondingly, this application also provides an electronic prescription forwarding device for authorizing a third party. Please refer to FIG. 34, which is a schematic diagram of an embodiment of an electronic prescription forwarding device for authorizing a third party according to this application. The device embodiments described below are merely unintended.
[0446] An electronic prescription forwarding device for authorizing a third party in this embodiment, the device is deployed in an electronic prescription management system, and includes: an authorized third party request receiving unit 3401, configured to receive an authorized third party sent by a client Request, obtain the user identification, third-party identification, and electronic prescription identification carried in the request; electronic prescription encryption and forwarding unit 3402, configured to use the shared quantum key with the client to pair with the user identification The electronic prescription corresponding to the electronic prescription identification is encrypted and sent to the client; the prescription forwarding request receiving unit 3403 is used to receive the electronic prescription forwarding request sent by the client; the prescription forwarding request decryption unit 3404 is used to use the The shared quantum key between the clients performs corresponding decryption operations on the information carried in the request, obtains the third-party identification and the electronic prescription; the electronic prescription sending third-party unit 3405 is used to communicate with the third-party The shared quantum key between them encrypts the electronic prescription, and sends the encrypted electronic prescription to a corresponding third party according to the third-party identification.
[0447] In addition, this application also provides a method for obtaining an authorized prescription, and the method is implemented by a third party. Please refer to FIG. 35, which is a flowchart of an embodiment of a method for obtaining an authorized prescription provided by this application. The parts with the same content in this embodiment and the first embodiment will not be repeated, and the following will focus on the differences. A method for obtaining authorized prescriptions provided by this application includes:
[0448] Step 3501. Receive an electronic prescription sent by an electronic prescription management system.
[0449] Step 3502, using the shared quantum key with the electronic prescription management system to decrypt the received electronic prescription, and using the decryption key corresponding to the first encryption key used by the client that initiated the authorization operation Decrypted
The electronic prescription is decrypted again, and the original information of the electronic prescription is obtained.
[0450] In the foregoing embodiment, a method for obtaining an authorized prescription is provided. Correspondingly, this application also provides a device for obtaining an authorized prescription. Please refer to FIG. 36, which is a schematic diagram of an embodiment of a device for obtaining an authorized prescription according to this application. The device embodiments described below are merely illustrative.
[0451] A device for obtaining authorized prescriptions of this embodiment is deployed in a third party and includes: a third party receiving electronic prescription unit 3601 for receiving electronic prescriptions sent by an electronic prescription management system; third party decryption The electronic prescription unit 3602 is configured to use the shared quantum key with the electronic prescription management system to decrypt the received electronic prescription, and use the decryption key corresponding to the first encryption key used by the client that initiates the authorization operation The key decrypts the decrypted electronic prescription again to obtain the original information of the electronic prescription.
[0452] In addition, this application also provides an electronic prescription operating system, please refer to FIG. 37, which is a schematic diagram of an embodiment of an electronic prescription operating system provided in this application. The system includes the following 4 sets of devices:
[0453] 1) A requesting device 3701 for establishing a binding relationship, a device 3702 for establishing a binding relationship, and a device 3703 for verifying a binding relationship;
[0454] 2) A requesting device 3704 for updating a shared key, a device 3705 for forwarding a request for updating a shared key, and a device 3706 for updating a shared key;
[0455] 3) A request device 3707 for obtaining an electronic prescription, a device 3708 for forwarding an electronic prescription, and a device 3709 for providing an electronic prescription;
[0456] 4) A requesting device 3710 for authorizing a third party, an electronic prescription forwarding device 3711 for authorizing a third party, a device 3712 for obtaining an authorized prescription<sub>O</sub>
[0457] It should be noted that the above four groups of devices are included in the electronic prescription operating system provided in this embodiment, which respectively correspond to the establishment of binding relationships, update of shared keys, and acquisition of electronic components described in the first embodiment. Prescription and authorizing a third party to view the four operations of e-prescription. In other embodiments, the electronic prescription operating system may include devices that are different from this embodiment. For example, it may include some of the above four sets of devices according to specific needs. For example, it may only include the first set of devices and the first set of devices. Three sets of devices are also possible.
[0458] Although the application is disclosed as above in preferred embodiments, it is not intended to limit the application. Any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of the application. Therefore, the protection scope of this application shall be subject to the scope defined by the claims of this application.
[0459] In a typical configuration, the computing device includes one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
[0460] The memory may include non-permanent memory in a computer readable medium, random access memory (RAM) and/or non-volatile memory, etc., such as read-only memory (ROM) or flash memory (flash RAM). Is an example of a computer readable medium.
[0461] 1. Computer-readable media includes permanent and non-permanent, removable and non-removable media, and information storage can be realized by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical storage, Magnetic cassettes, magnetic tape storage or other magnetic storage devices or any other non-transmission media can be used to store information that can be accessed by computing devices. according to
As defined in this article, computer-readable media does not include non-transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0462] 2. Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems or computer program products. Therefore, this application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage>CD-ROM, optical storage, etc.) containing computer-usable program codes.
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| CN113067699A | Cited by | China | – | Search report | – |
| CN107896213A | Cited by | China | – | Search report | – |
| CN108737323A | Cited by | China | – | Search report | – |
| CN107317681A | Cited by | China | – | Search report | – |
| CN111385266A | Cited by | China | – | Search report | – |
| CN114095183A | Cited by | China | – | Search report | – |
| CN112786143A | Cited by | China | – | Search report | – |
| WO2020228304A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| CN109242591A | Cited by | China | – | Search report | – |
| WO2020228304A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| CN108877882A | Cited by | China | – | Search report | – |
| CN102833246A | Cites | China | A | Search report | 1-52 |
| CN103475474A | Cites | China | A | Search report | 1-55 |
| CN104348838A | Cites | China | X | Search report | 1-30 |
| CN1447558A | Cites | China | A | Search report | 1-52 |
| US2014115337A1 | Cites | United States of America | A | Search report | 1-52 |
5 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201510362427 | China | A | |
| CN20151362427 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| US2016378949A1 | United States of America | A1 | |
| WO2016210347A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201701226A | Taiwan Province of China | A | |
| CN106295393AThis record | China | A | |
| CN106295393B | China | B |
4 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Change of inventor or designer informationCB03 | CB03 | CN | |
| Requests to designate patent in hong kongDE | DE | HK | |
| Entry into substantive examinationC10 | C10 | CN | |
| PublicationC06 | C06 | CN |
Numbers
- Publication
- 106295393
- Publication, DOCDB
- 106295393
- Publication, EPODOC
- CN106295393
- Application
- 103624270
- Application, DOCDB
- 201510362427
- Application, EPODOC
- CN201510362427
Titles2
- Chinese
- 电子处方操作方法、装置及系统
- English
- Electronic prescription operation method, device and system
Classification
- CPC, 11
- G06F21/6245
- G06F40/197
- G06F2221/2141
- G06F40/131
- G06Q2220/00
- G06F40/166
- G16H10/60
- G16H20/10
- H04L9/0852
- H04L63/06
- H04L63/10
- IPC, 3
- G06F21 62
- G16H10 60
- G16H20 10