WO2020186822A1 - 基于区块链的数据查询方法、装置、设备及可读存储介质 - Google Patents

基于区块链的数据查询方法、装置、设备及可读存储介质 Download PDF

Info

Publication number
WO2020186822A1
WO2020186822A1 PCT/CN2019/122574 CN2019122574W WO2020186822A1 WO 2020186822 A1 WO2020186822 A1 WO 2020186822A1 CN 2019122574 W CN2019122574 W CN 2019122574W WO 2020186822 A1 WO2020186822 A1 WO 2020186822A1
Authority
WO
WIPO (PCT)
Prior art keywords
queried
signature
certificate
registered
information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2019/122574
Other languages
English (en)
French (fr)
Inventor
冯承勇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
OneConnect Smart Technology Co Ltd
Original Assignee
OneConnect Smart Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by OneConnect Smart Technology Co Ltd filed Critical OneConnect Smart Technology Co Ltd
Publication of WO2020186822A1 publication Critical patent/WO2020186822A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/20Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
    • G06F16/24Querying
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/33User authentication using certificates
    • G06F21/335User authentication using certificates for accessing specific resources, e.g. using Kerberos tickets
    • GPHYSICS
    • G16INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR SPECIFIC APPLICATION FIELDS
    • G16HHEALTHCARE INFORMATICS, i.e. INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR THE HANDLING OR PROCESSING OF MEDICAL OR HEALTHCARE DATA
    • G16H10/00ICT specially adapted for the handling or processing of patient-related medical or healthcare data
    • G16H10/60ICT specially adapted for the handling or processing of patient-related medical or healthcare data for patient-specific data, e.g. for electronic patient records

Definitions

  • This application relates to the field of Internet technology, in particular to a blockchain-based data query method, device, equipment and readable storage medium.
  • the health information platform uses electronic medical records to store all patient data and update the data in real time.
  • the currently established health information platforms usually rely on centralized information systems to carry them, and based on the centralized information systems to realize the data storage of electronic medical records And data query.
  • the centralized information system protects the user’s personal privacy through identity authentication and authorization, that is, the user’s electronic medical record is bound to store the user’s identity information, contact information, and other personal information.
  • identity authentication and authorization that is, the user’s electronic medical record is bound to store the user’s identity information, contact information, and other personal information.
  • the user provides personal information to the information system, and the information system determines the electronic medical record corresponding to the personal information provided by the user, and returns the corresponding electronic medical record directly to the user.
  • the data obtained by the information system is only the electronic medical records of the users in the hospitals it serves. If the user wants to query the electronic medical record data of other hospitals, he needs to apply for the query again from other hospitals, resulting in a large workload for the user to query the electronic medical records. A lot of resources are wasted.
  • the present application provides a blockchain-based data query method, device, equipment, and readable storage medium, the main purpose of which is to solve the problem that current users have a large workload for querying electronic medical records and waste a lot of resources.
  • the first aspect of the embodiments of the present application provides a blockchain-based data query method, which includes:
  • the verified data query request in this application is transmitted to those connected to the blockchain system.
  • Multiple information systems can return information cipher text that meets the data query request, so that when data query is performed, the data of multiple information systems can be queried. There is no need to request data query from multiple information systems multiple times, which reduces This saves a lot of resources for users to query electronic medical records.
  • FIG. 1A shows a schematic flowchart of a data query method based on blockchain provided by an embodiment of the present application
  • FIG. 1B shows a schematic flowchart of a data query method based on blockchain provided by an embodiment of the present application
  • FIG. 2A shows a schematic flow chart of a data query method based on blockchain provided by an embodiment of the present application
  • FIG. 2B shows a schematic flowchart of a data query method based on blockchain provided by an embodiment of the present application
  • FIG. 3A shows a schematic structural diagram of a block chain-based data query device provided by an embodiment of the present application
  • FIG. 3B shows a schematic structural diagram of a block chain-based data query device provided by an embodiment of the present application
  • FIG. 3C shows a schematic structural diagram of a block chain-based data query device provided by an embodiment of the present application
  • FIG. 4A shows a schematic structural diagram of a block chain-based data query device provided by an embodiment of the present application
  • FIG. 4B shows a schematic structural diagram of a block chain-based data query device provided by an embodiment of the present application
  • FIG. 4C shows a schematic structural diagram of a block chain-based data query device provided by an embodiment of the present application.
  • FIG. 5 shows a schematic structural diagram of a device provided by an embodiment of the present application.
  • the embodiment of the application provides a blockchain-based data query method, which can transmit the verified data query request to multiple information systems connected to the blockchain system, and multiple information systems can return data that meets the data query request
  • the ciphertext of information makes it possible to query the data of multiple information systems during data query, without having to request data query from multiple information systems multiple times, reducing the workload of users to query electronic medical records and saving a lot of resources
  • the method includes:
  • the data query request in order to enable the blockchain system to know which data needs to be queried when receiving a data query request, the data query request will carry the digital certificate to be queried, the personal information to be queried, and the data to be queried.
  • the signature of the query request so that the blockchain system can extract the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried in the data query request.
  • the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried are verified.
  • the blockchain system stores user information and digital certificates of registered users.
  • the blockchain system extracts the digital certificate to be queried, personal information to be queried, and After the signature of the request to be queried, the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried are verified.
  • the digital certificate to be queried if the digital certificate to be queried, the personal information to be queried, and the signature of the query to be queried are successfully verified, it means that the digital certificate to be queried is authentic and the data query request has not been tampered with during the transmission.
  • Data query is possible. Since there are multiple information systems connected to the blockchain system, each information system may store data that meets the data query request. Therefore, in order to make the data returned to the user complete, the blockchain system will pass The verified data query request is issued to each information system connected to the blockchain system so that the information system can query the data.
  • the information ciphertext carries the user's electronic medical record stored in the corresponding information system.
  • the blockchain system can At least one information ciphertext returned by the information system is received, and all the received information ciphertexts are returned to the user.
  • the user may not have visited any hospital before, so that each information system cannot query the data that meets the data query request. Therefore, the blockchain system may not receive any information ciphertext. At this time, the blockchain system can prompt the user.
  • the embodiment of the present application does not specifically limit the number of information ciphertexts received by the blockchain system.
  • the method provided by the embodiment of the application transmits the verified data query request to multiple information systems connected to the blockchain system, and multiple information systems can return information ciphertext that meets the data query request, so that the data query At the same time, the data of multiple information systems can be queried, and there is no need to request data query from multiple information systems multiple times, which reduces the workload for users to query electronic medical records and saves a lot of resources.
  • the embodiment of the application provides a data query method based on blockchain.
  • the information system receives the data query request sent by the blockchain system, it will return the data related to the data query request included in the information system to the block
  • the chain system enables the blockchain to query data from multiple information systems during data query, without requiring multiple information systems for data query multiple times, reducing the workload for users to query electronic medical records and saving a lot of resources
  • the method includes:
  • the information system when the information system receives the data query request transmitted by the blockchain system, since the data query request includes the personal information to be queried, the information system can determine the electronic medical record indicated by the data query request as the target Electronic medical records.
  • the information system may not obtain the target electronic medical record that matches the data query request. Therefore, if the information system obtains the target electronic medical record If it fails, the information system can directly return a no-data instruction to the blockchain system, terminate the execution of the following steps 106 and 107, and continue to receive other data query requests.
  • the information system can extract the digital certificate to be queried from the data query request and base it on this The digital certificate and the target electronic medical record are to be queried, the information ciphertext is generated, and the information ciphertext is subsequently transmitted.
  • the information ciphertext can be transmitted to the blockchain system, so that the blockchain system can return the received information ciphertext to the user.
  • the information system when the information system receives the data query request sent by the blockchain system, it will return the data related to the data query request included in the information system to the blockchain system, so that the blockchain is performing data
  • the blockchain When inquiring, data of multiple information systems can be queried, and there is no need to request data queries from multiple information systems multiple times, which reduces the workload for users to query electronic medical records and saves a lot of resources.
  • the embodiment of the application provides a blockchain-based data query method, which can transmit the verified data query request to multiple information systems connected to the blockchain system, and multiple information systems can return data that meets the data query request
  • the ciphertext of information makes it possible to query the data of multiple information systems during data query, without having to request data query from multiple information systems multiple times, reducing the workload of users to query electronic medical records and saving a lot of resources
  • the method includes:
  • the blockchain system receives a data query request from a user, and extracts the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried from the data query request.
  • the blockchain system is connected to the information systems of multiple hospitals, and each information system stores a large amount of user information.
  • the data query request needs to carry the digital certificate to be queried, the personal information to be queried, and the signature of the query to be queried.
  • the blockchain system can provide a client dedicated to provide users with various services, and users can enjoy the services provided by the blockchain system by downloading the client in a private terminal.
  • the client can provide a data query entry.
  • a data query page is displayed.
  • the data query page provides a digital certificate upload box, a personal information input box, and a request signature input box, etc. .
  • the user's confirmation of the data query page is detected, it is determined that the user's data query request is received, and the data query request is extracted, and the digital certificate to be queried, the personal information to be queried and the signature of the query to be queried carried in the data query request are obtained .
  • the data query request can also include the signature of the request to be queried.
  • the signature of the request to be queried is generated after decrypting the personal information to be queried using the public key of the certificate to be queried for the digital certificate to be queried. It can be generated by the terminal held by the user after receiving the personal information to be queried uploaded by the user and the digital certificate to be queried.
  • the blockchain system receives the data query request, it can sign the data based on the query request.
  • the query request is verified to determine whether the data query request has been tampered with during transmission.
  • the blockchain system verifies the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried. If the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried are successfully verified, the following steps 203 to 206 are executed ; If the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried fail to verify, the following step 207 is performed.
  • the information system of each hospital may exist
  • the blockchain can obtain the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried in the data query request, when verifying the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried, consider Users who have registered in the blockchain system will have their personal information stored in the blockchain system.
  • the digital certificate corresponding to the personal information can also be obtained, and the digital certificate to be queried is compared. True, the digital certificate to be queried passes the verification, and the verification of other objects is continued. It should be noted that when verifying the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried, the order of verification is not fixed. It does not matter which item is verified first. The order of verification in the embodiment of this application There is no specific limitation.
  • step 207 can only be performed.
  • the data query request can be issued to the access area.
  • Multiple information systems in the blockchain system so that the information system can query and return data according to the data query request.
  • the blockchain system can transmit data query requests to the blockchain through the data connection with the information system. Every information system in the system.
  • the information system receives the data query request of the blockchain system, extract the personal information to be queried in the data query request, and extract the target electronic medical record corresponding to the personal information to be queried based on the personal information to be queried.
  • the information system when the information system receives a data query request transmitted by the blockchain system, since the data query request carries the personal information to be queried, the information The system can extract the personal information to be queried in the data query request, query the electronic medical record corresponding to the personal information to be queried in the information system as the target electronic medical record based on the personal information to be queried, and extract the target electronic medical record for subsequent use The target electronic medical record is returned to the blockchain system.
  • the user may not have been treated in the hospital served by the current information system, so that the target electronic medical record cannot be determined in the information system. In this way, the information system can no longer execute the following other content.
  • the blockchain system in order for the blockchain system to know that there is no target electronic medical record in the current information system, if the information system does not obtain the target electronic medical record, it can generate a dataless instruction and return the dataless instruction to the blockchain system , So that the blockchain system can know that the user’s electronic medical record is not stored in the current information system, rather than the information system malfunctioning.
  • Extract the digital certificate to be queried from the data query request obtain the public key of the certificate to be queried of the digital certificate to be queried, and encrypt the target electronic medical record by using the public key of the certificate to be queried, generate information ciphertext, and transmit the information ciphertext to Blockchain system.
  • a user when a user applies for a digital certificate, he needs to first generate a certificate public-private key pair.
  • the certificate private key is saved by itself, and the certificate public key and user information are submitted to the certification authority.
  • the certification authority will associate the certificate public key with the user.
  • the personal information is bound and signed to issue a digital certificate so that the digital certificate contains the certificate public key.
  • the information system is transferring the target electronic medical record Before transmitting to the blockchain system, extract the public key of the certificate to be queried from the digital certificate to be queried, use the public key of the certificate to be queried to encrypt the target electronic medical record, generate information ciphertext, and transmit the information ciphertext to the blockchain System in order to ensure the security of the target electronic medical record during the transmission process and avoid the data in the target electronic medical record from being stolen.
  • the blockchain system receives at least one information ciphertext returned by multiple information systems after receiving the data query request, and returns at least one information ciphertext to the user.
  • each information system since the blockchain system sends the data query request to multiple information systems, each information system will query and obtain the corresponding user electronic medical record, and will also encrypt the electronic medical record Generate information ciphertext. Therefore, after the blockchain system transmits the query request to multiple information systems, it will receive the information ciphertext returned by multiple information systems, and considering that some information systems may not find the information that needs to be queried Therefore, at least one ciphertext of information may be received. At this time, the blockchain system can integrate at least one ciphertext of information and return it to the user. It should be noted that, considering that the user may not have checked in some hospitals, the hospital will not return the information ciphertext to the blockchain system, and may only return a no-data instruction to the blockchain system.
  • the block The chain system only needs to return the obtained information ciphertext to the user, and it is not necessary for all hospitals to give feedback on the information ciphertext. In addition, there may also be cases where the user is not seeking medical attention in any hospital. At this time, any information ciphertext may not be obtained.
  • the blockchain system can generate a dataless instruction and return the dataless instruction to Users, this application does not specifically limit the number of information ciphertexts obtained or whether the information ciphertexts can be obtained.
  • the digital certificate to be queried, the personal information to be queried, and the signature of the query to be queried fail to verify, it means that the data query request has not passed the verification of the blockchain system.
  • the blockchain system cannot If the data query request is transmitted to the information system, the user needs to re-provide the digital certificate, personal information, and request signature. Therefore, a query failure response is generated and the query failure response is transmitted to the user so that the user can resend the data query request.
  • the blockchain system when it generates a query failure response, it can carry an error indication in the query request instruction, that is, to remind the user which information in the digital certificate to be queried, personal information to be queried, and the signature of the request to be queried An error has occurred, so that the user pays more attention to the input of this information to avoid recurring errors.
  • the embodiment of the present application does not specifically limit the content included in the query failure response.
  • the client of the blockchain system may provide a registration entry for the user.
  • the terminal held by the user detects that the user triggers the registration entry, it is determined that the user requests registration and the registration page is displayed.
  • the user’s identity is embodied based on a digital certificate
  • the user in order to verify the authenticity and security of the user’s identity, when the user registers, the user needs to provide his own digital certificate as the digital certificate to be registered, so as to be based on the digital certificate to be registered.
  • the certificate verifies the user's identity.
  • the terminal held by the user in order to further ensure the security of the digital certificate to be registered and the information of the user to be registered in the transmission process, the terminal held by the user usually uses the private key of the certificate to be registered in the digital certificate to be registered.
  • the digital signature to be registered obtained by the signature is essentially an encryption process, that is, the terminal held by the user uses the encrypted digital certificate to be registered as the digital signature to be registered, and the digital signature to be registered is also included in the user registration request , So that the blockchain system can receive the user registration request carrying the information of the user to be registered, the digital signature to be registered, and the digital certificate to be registered, so that subsequent verification of the digital certificate to be registered can be achieved by verifying the digital signature to be registered.
  • the blockchain system when the blockchain system receives the user registration request sent by the user based on the client downloaded from the terminal it holds, it can extract the user information to be registered, the digital signature to be registered, and the digital certificate to be registered in the user registration request.
  • Extract the certificate signature from the digital certificate to be registered compare the certificate signature with the preset signature, extract the public key of the certificate to be registered in the digital certificate to be registered, and use the public key of the certificate to be registered to decrypt the digital signature to be registered, if the certificate The signature is consistent with the preset signature, and if the public key of the certificate to be registered is used to successfully decrypt the digital signature to be registered, the following step 210 is performed; if the certificate signature is inconsistent with the preset signature, or the public key of the certificate to be registered is used to decrypt the digital signature to be registered, the decryption fails , Then perform the following step 211.
  • the preset signature is a signature provided by a certificate authority for verifying whether the certificate signature is valid. Since the certification authority will carry the certificate signature in the digital certificate when issuing the digital certificate, the certificate signature will be used as an anti-counterfeiting mark to prove that the digital certificate was issued by the certification authority. Therefore, the certificate signature can be extracted from the digital certificate to be registered , Compare the certificate signature with the preset signature provided by the certification authority, and determine whether the number to be registered is officially issued by the certification authority by judging whether the certificate signature is consistent with the preset signature, and is not forged by criminals.
  • the digital signature to be registered is obtained by signing the certificate to be registered based on the private key of the certificate to be registered. Therefore, the mutual encryption and decryption based on the public and private key Attribute, the public key of the certificate to be registered can be used to decrypt the signature of the certificate to be registered, and the authenticity of the digital signature to be registered can be determined according to whether the signature is successful.
  • the certificate signature is consistent with the preset signature, and the public key of the certificate to be registered is used to successfully decrypt the digital signature to be registered, it means that the digital signature to be registered and the digital certificate to be registered are verified, and the user can be registered in the blockchain system Therefore, to register the user, that is, perform the following step 210; if the certificate signature is inconsistent with the preset signature, or if the public key of the certificate to be registered is used to decrypt the digital signature to be registered, it means the digital signature to be registered and the digital signature to be registered.
  • the certificate has not passed the verification, the digital signature to be registered and the digital certificate to be registered are untrue or wrong, the user cannot be registered in the blockchain system, and the user needs to provide the real or correct digital signature to be registered and the digital certificate to be registered Digital certificate, that is, perform the following step 211.
  • the certificate signature is consistent with the preset signature, and the public key of the certificate to be registered is used to successfully decrypt the digital signature to be registered, the user information to be registered and the digital certificate to be registered are correspondingly stored in the blockchain system.
  • the blockchain The system correspondingly stores the information of the user to be registered and the digital certificate to be registered in the blockchain system to complete the registration of the user in the blockchain system.
  • the certificate signature is inconsistent with the preset signature, or the decryption of the digital signature to be registered using the public key of the certificate to be registered fails, it means that the user registration request is likely to be tampered with during transmission, and the authenticity cannot be verified. , Or the digital certificate to be registered and the digital signature to be registered provided by the user may be false or incorrect.
  • the user registration in the blockchain system cannot be realized, and the user needs to provide relevant information to register again. Therefore, Generate a failure response and return the failure response to the user so that the user can resend the user registration request after receiving the failure response.
  • the verified data query request is transmitted to multiple information systems connected to the blockchain system, and multiple information systems can return information ciphertext that meets the data query request, so that when performing data query , Can query data of multiple information systems, without multiple requests for data query from multiple information systems, reducing the workload of users to query electronic medical records and saving a lot of resources.
  • an embodiment of the present application provides a block chain-based data query device.
  • the device includes: a receiving module 301, a verification module 302, A transmission module 303 and a first return module 304.
  • the receiving module 301 is configured to receive a data query request from a user, and extract the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried from the data query request;
  • the verification module 302 is used to verify the digital certificate to be queried, the personal information to be queried, and the signature of the request to be queried based on the blockchain system.
  • the blockchain system stores user information and digital certificates of registered users;
  • the first transmission module 303 is configured to determine multiple information systems connected to the blockchain system if the digital certificate to be queried, personal information to be queried, and the signature of the query to be queried are successfully verified, and transmit the data query request to multiple information systems ;
  • the first return module 304 is configured to receive at least one information ciphertext returned by multiple information systems after receiving data query requests, and return at least one information ciphertext to the user, and the information ciphertext carries the user’s information in the corresponding information system Electronic medical records stored in.
  • the device further includes: an extraction module 305, a comparison module 306, a signature module 307, a storage module 308, and a second return module 309.
  • the extraction module 305 is configured to extract the information of the user to be registered, the digital signature to be registered and the digital certificate to be registered in the user registration request when a user registration request is received;
  • the comparison module 306 is configured to extract a certificate signature from the digital certificate to be registered, and compare the certificate signature with a preset signature, and the preset signature is provided by a certificate authority for verifying the certificate signature Whether the signature is valid;
  • the signature module 307 is configured to extract the public key of the certificate to be registered from the digital certificate to be registered, and use the public key of the certificate to be registered to decrypt the digital signature to be registered;
  • the storage module 308 is configured to, if the certificate signature is consistent with the preset signature, and the public key of the certificate to be registered is used to decrypt the digital signature to be registered successfully, then the user information to be registered and the The digital certificate to be registered is correspondingly stored in the blockchain system;
  • the second return module 309 is configured to generate and return a registration failure response if the certificate signature is inconsistent with the preset signature, or if the public key of the certificate to be registered fails to decrypt the digital signature to be registered.
  • the verification module 302 is used to query whether there is personal information consistent with the personal information to be queried in the blockchain system; to obtain the public key of the certificate to be queried for the digital certificate to be queried , Using the public key of the certificate to be queried to decrypt the signature of the request to be queried;
  • the storage module 308 is used when personal information consistent with the personal information to be queried exists in the blockchain system, and the public key of the certificate to be queried is used to successfully decrypt the signature of the request to be queried , Determining that the signature verification of the digital certificate to be queried, the personal information to be queried, and the signature to be queried is successful;
  • the first return module 304 is used for when there is no personal information consistent with the personal information to be queried in the blockchain system, or when the public key of the certificate to be queried fails to decrypt the signature of the request to be queried , It is determined that the verification of the signature of the digital certificate to be queried, the personal information to be queried, and the request to be queried fails.
  • the device further includes: a second transmission module 310.
  • the second transmission module 310 is configured to generate a query failure response if the signature verification of the digital certificate to be queried, the personal information to be queried, and the request to be queried fails, and to transmit the query failure response to the user.
  • the device provided in the embodiment of the application transmits the verified data query request to multiple information systems connected to the blockchain system, and multiple information systems can return information cipher text that meets the data query request, so that the data query is At the same time, the data of multiple information systems can be queried, and there is no need to request data query from multiple information systems multiple times, which reduces the workload for users to query electronic medical records and saves a lot of resources.
  • an embodiment of the present application provides a blockchain-based data query device.
  • the device includes: a determination module 401, a generation module 402, and a transmission Module 403.
  • the determining module 401 is configured to determine the target electronic medical record indicated by the data query request when a data query request of the blockchain system is received;
  • the generating module 402 is configured to extract the digital certificate to be queried from the data query request, and generate information ciphertext based on the digital certificate to be queried and the target electronic medical record;
  • the transmission module 403 is used to transmit the information ciphertext to the blockchain system.
  • the determining module 401 includes an extraction submodule 4011 and a query submodule 4012.
  • the extraction sub-module 4011 is used to extract personal information to be queried from the data query request when the data query request of the blockchain system is received;
  • the query submodule 4012 is configured to extract the target electronic medical record corresponding to the personal information to be queried in the blockchain system based on the personal information to be queried.
  • the generating module 402 includes an acquiring sub-module 4021 and a generating sub-module 4022.
  • the obtaining submodule 4021 is configured to extract the digital certificate to be queried in the data query request, and obtain the public key of the certificate to be queried of the digital certificate to be queried;
  • the generating sub-module 4022 is configured to use the public key of the certificate to be queried to encrypt the target electronic medical record to generate the information ciphertext.
  • the device when the information system receives the data query request sent by the blockchain system, it will return the data related to the data query request included in the information system to the blockchain system, so that the blockchain is performing data
  • the information system when it receives the data query request sent by the blockchain system, it will return the data related to the data query request included in the information system to the blockchain system, so that the blockchain is performing data
  • the blockchain When inquiring, data of multiple information systems can be queried, and there is no need to request data queries from multiple information systems multiple times, which reduces the workload for users to query electronic medical records and saves a lot of resources.
  • the device 500 includes a communication bus, a processor, a memory, and a communication interface, and may also include an input and output interface, and a display device, wherein one of the functional units The communication between each other can be completed through the bus.
  • the memory stores computer-readable instructions, and the processor is used to execute the programs stored in the memory, and execute the blockchain-based data query method in the foregoing embodiment.
  • a computer-readable storage medium has computer-readable instructions stored thereon, and when the computer-readable instructions are executed by a processor, the steps of the blockchain-based data query method are realized.
  • the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, U disk, mobile hard disk, etc.), including several
  • the instructions are used to make a computer device (which may be a personal computer, a server, or a network device, etc.) execute the methods described in each implementation scenario of this application.
  • modules in the device in the implementation scenario can be distributed in the device in the implementation scenario according to the description of the implementation scenario, or can be changed to be located in one or more devices different from the implementation scenario.
  • the modules of the above implementation scenarios can be combined into one module or further divided into multiple sub-modules.
  • Non-volatile memory may include read only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory.
  • Volatile memory may include random access memory (RAM) or external cache memory.
  • RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous chain Channel (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • Epidemiology (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Primary Health Care (AREA)
  • Public Health (AREA)
  • Computational Linguistics (AREA)
  • Data Mining & Analysis (AREA)
  • Databases & Information Systems (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Storage Device Security (AREA)

Abstract

本申请公开了一种基于区块链的数据查询方法、装置、设备及可读存储介质,涉及基于区块链的数据查询方法、装置、设备及可读存储介质领域,将数据查询请求传输给多个信息系统,并接收多个信息系统返回的信息密文,使得可查询到多个信息系统的数据,无需多次请求数据查询,减少了用户查询数据的工作量,节省了大量资源。所述方法包括:接收用户的数据查询请求,提取待查询数字证书、待查询个人信息以及待查询请求签名;对待查询数字证书、待查询个人信息以及待查询请求签名进行验证;如果验证成功,则将数据查询请求传输至多个信息系统;接收多个信息系统在接收到数据查询请求后返回的至少一个信息密文,将至少一个信息密文返回至用户。

Description

基于区块链的数据查询方法、装置、设备及可读存储介质
本申请申明享有2019年03月21日递交的申请号为201910219136.4、名称为“基于区块链的数据查询方法、装置、设备及可读存储介质”中国专利申请的优先权,该中国专利申请的整体内容以参考的方式结合在本申请中。
技术领域
本申请涉及互联网技术领域,特别是涉及一种基于区块链的数据查询方法、装置、设备及可读存储介质。
背景技术
随着互联网技术的飞速发展,卫生与健康现代医疗卫生体系的建设规划也越来越成熟,预计到2020年,将建成全面的健康信息平台,实现所在地区各大医院之间信息的互联互通。健康信息平台中采用电子病历的形式存储患者的所有数据并实时更新数据,目前已经建立的健康信息平台通常依赖中心化的信息系统所搭载,并基于该中心化的信息系统实现电子病历的数据存储及数据查询。
相关技术中,中心化的信息系统是通过身份认证和授权来保护用户的个人隐私的,也即将用户的电子病历与用户的身份信息、联系方式信息等个人信息绑定存储,在进行电子病历的数据查询时,用户将个人信息提供给信息系统,信息系统确定用户提供的个人信息对应的电子病历,将对应的电子病历直接返回给用户。
在实现本申请的过程中,申请人发现相关技术至少存在以下问题:
信息系统获取到的数据仅为其所服务的医院中用户的电子病历,如果用户想要查询其他医院的电子病历数据,需要再次向其他医院申请查询,导致用户查询电子病历的工作量较大,浪费了大量资源。
技术问题
有鉴于此,本申请提供了一种基于区块链的数据查询方法、装置、设备及可读存储介质,主要目的在于解决目前用户查询电子病历的工作量较大,浪费了大量资源的问题。
技术解决方案
本申请实施例的第一方面提供了一种基于区块链的数据查询方法,该方法包括:
接收用户的数据查询请求,在所述数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名;
基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,所述区块链系统中存储有注册用户的用户信息以及数字证书;
如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功,则确定接入所述区块链系统的多个信息系统,将所述数据查询请求传输至所述多个信息系统;
接收所述多个信息系统在接收到所述数据查询请求后返回的至少一个信息密文,将所述至少一个信息密文返回至所述用户,所述信息密文携带所述用户的在对应的信息系统中存储的电子病历。
有益效果
在本申请实施例中,与目前信息系统获取到的数据仅为其所服务的医院中用户的电子病历的方式相比,本申请通过验证的数据查询请求传输给接入区块链系统的多个信息系统,多个信息系统均可以返回符合数据查询请求的信息密文,使得在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,减少了用户查询电子病历的工作量,节省了大量资源。
附图说明
图1A示出了本申请实施例提供的一种基于区块链的数据查询方法流程示意图;
图1B示出了本申请实施例提供的一种基于区块链的数据查询方法流程示意图;
图2A示出了本申请实施例提供的一种基于区块链的数据查询方法流程示意图;
图2B示出了本申请实施例提供的一种基于区块链的数据查询方法流程示意图;
图3A示出了本申请实施例提供的一种基于区块链的数据查询装置的结构示意图;
图3B示出了本申请实施例提供的一种基于区块链的数据查询装置的结构示意图;
图3C示出了本申请实施例提供的一种基于区块链的数据查询装置的结构示意图;
图4A示出了本申请实施例提供的一种基于区块链的数据查询装置的结构示意图;
图4B示出了本申请实施例提供的一种基于区块链的数据查询装置的结构示意图;
图4C示出了本申请实施例提供的一种基于区块链的数据查询装置的结构示意图;
图5示出了本申请实施例提供的一种设备的装置结构示意图。
本发明的实施方式
本申请实施例提供了一种基于区块链的数据查询方法,可以将通过验证的数据查询请求传输给接入区块链系统的多个信息系统,多个信息系统均可以返回符合数据查询请求的信息密文,使得在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,达到减少了用户查询电子病历的工作量,节省了大量资源的目的,如图1A所示,该方法包括:
101、接收用户的数据查询请求,在数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名。
在本申请实施例中,为了使区块链系统在接收到数据查询请求时,可以获知需要请求查询哪一种数据,因此,数据查询请求中会携带待查询数字证书、待查询个人信息以及待查询请求签名,这样,区块链系统便可以在数据查询请求中提取到待查询数字证书、待查询个人信息以及待查询请求签名。
102、基于区块链系统,对待查询数字证书、待查询个人信息以及待查询请求签名进行验证,区块链系统中存储有注册用户的用户信息以及数字证书。
在本申请实施例中,为了确定该数据查询请求在传输的过程中是否被篡改,以及用户提供的待查询数字证书是否真实,区块链系统在提取到待查询数字证书、待查询个人信息以及待查询请求签名后,对待查询数字证书、待查询个人信息以及待查询请求签名进行验证。
103、如果对待查询数字证书、待查询个人信息以及待查询请求签名验证成功,则确定接入区块链系统的多个信息系统,将数据查询请求传输至多个信息系统。
在本申请实施例中,如果对待查询数字证书、待查询个人信息以及待查询请求签名验证成功,则表示该待查询数字证书是真实的,该数据查询请求在传输的过程中并没有被篡改,是可以进行数据查询的。由于区块链系统中接入有多个信息系统,每个信息系统中均可能存储有符合数据查询请求的数据,因此,为了使返回给用户的数据是完整的,区块链系统会将通过验证的数据查询请求下发给接入到区块链系统中的每一个信息系统,以便信息系统对数据进行查询。
104、接收多个信息系统在接收到数据查询请求后返回的至少一个信息密文,将至少一个信息密文返回至用户,信息密文携带用户的在对应的信息系统中存储的电子病历。
在本申请实施例中,由于信息系统在接收到数据查询请求后均会进行数据查询,且查询到数据的信息系统会将查询到的数据返回给区块链系统,因此,区块链系统可以接收到信息系统返回的至少一个信息密文,并将接收到的全部信息密文返回给用户。
在实际应用的过程中,可能用户之前并没有在任何的医院就医,使得每一个信息系统均不能查询到符合数据查询请求的数据,因此,区块链系统还可能不会接收到任何信息密文,这时,区块链系统对用户进行提示即可。本申请实施例对区块链系统接收到信息密文的个数不进行具体限定。
本申请实施例提供的方法,将通过验证的数据查询请求传输给接入区块链系统的多个信息系统,多个信息系统均可以返回符合数据查询请求的信息密文,使得在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,减少了用户查询电子病历的工作量,节省了大量资源。
本申请实施例提供了一种基于区块链的数据查询方法,可以当信息系统接收到区块链系统发送的数据查询请求时,会将自身包括的与数据查询请求相关的数据返回给区块链系统,使得区块链在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,达到减少了用户查询电子病历的工作量,节省了大量资源的目的,如图1B所示,该方法包括:
105、当接收到区块链系统的数据查询请求时,确定数据查询请求指示的目标电子病历。
在本申请实施例中,当信息系统接收到区块链系统传输的数据查询请求时,由于数据查询请求中包括了待查询个人信息,因此,信息系统可以确定数据查询请求指示的电子病历作为目标电子病历。
需要说明的是,考虑到用户可能并没有在信息系统所服务的医院中就医,使得信息系统中可能并不会获取到与数据查询请求匹配的目标电子病历,因此,如果信息系统获取目标电子病历失败了,则信息系统可以直接向区块链系统返回无数据指令,并终止执行下述步骤106和步骤107,继续接收其他的数据查询请求。
106、在数据查询请求中提取待查询数字证书,基于待查询数字证书和目标电子病历,生成信息密文。
在本申请实施例中,由于数据查询请求中还会携带待查询数字证书,为了保证目标电子病历在传输过程中的安全性,信息系统可以在数据查询请求中提取待查询数字证书,并基于该待查询数字证书和目标电子病历,生成信息密文,并在后续将该信息密文传输。
107、将信息密文传输至区块链系统。
在本申请实施例中,当信息系统生成了信息密文后,便可以将信息密文传输给区块链系统,以便区块链系统将接收到的信息密文返回给用户。
本申请实施例提供的方法,当信息系统接收到区块链系统发送的数据查询请求时,会将自身包括的与数据查询请求相关的数据返回给区块链系统,使得区块链在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,减少了用户查询电子病历的工作量,节省了大量资源。
本申请实施例提供了一种基于区块链的数据查询方法,可以将通过验证的数据查询请求传输给接入区块链系统的多个信息系统,多个信息系统均可以返回符合数据查询请求的信息密文,使得在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,达到减少了用户查询电子病历的工作量,节省了大量资源的目的,如图2A所示,该方法包括:
201、区块链系统接收用户的数据查询请求,在数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名。
在本申请实施例中,区块链系统中接入有多个医院的信息系统,每个信息系统中都存储有大量的用户信息,为了确定具体用户请求查询哪种信息,以便根据用户的需求为用户提供信息查询的服务,数据查询请求中需要携带待查询数字证书、待查询个人信息以及待查询请求签名。
在实际应用的过程中,区块链系统可以提供专门为用户提供各项服务的客户端,用户通过在私人终端中下载该客户端来享受区块链系统提供的服务。其中,该客户端中可以提供数据查询入口,当检测到用户触发该数据查询入口时,显示数据查询页面,在该数据查询页面中提供数字证书上传框、个人信息输入框以及请求签名输入框等。在检测到用户对数据查询页面的确认时,确定接收到用户的数据查询请求,在数据查询请求中进行提取,获取到数据查询请求携带的待查询数字证书、待查询个人信息以及待查询请求签名。其中,由于只有在区块链系统中注册过的用户才会将电子病历上传到区块链系统中,而在区块链中注册过的用户都会拥有数字证书,因此,在进行数据查询时,用户需要在数据查询请求中携带待查询数字证书,以便区块链系统根据该待查询数字证书来确定用户是否在区块链系统中注册过。
另外,为了避免数据查询请求在传输的过程中被篡改,数据查询请求中还可以包括待查询请求签名,待查询请求签名是采用待查询数字证书的待查询证书公钥对待查询个人信息解密后生成的,可由用户所持的终端在接收到用户上传的待查询个人信息以及待查询数字证书后自行生成,这样,当区块链系统接收到数据查询请求时,便可以基于该待查询请求签名对数据查询请求进行验证,从而确定该数据查询请求是否在传输的过程中被篡改。
202、区块链系统对待查询数字证书、待查询个人信息以及待查询请求签名进行验证,如果对待查询数字证书、待查询个人信息以及待查询请求签名验证成功,则执行下述步骤203至步骤206;如果对待查询数字证书、待查询个人信息以及待查询请求签名验证失败,则执行下述步骤207。
在本申请实施例中,当获取到待查询数字证书、待查询个人信息以及待查询请求签名后,为了避免将不法分子的恶意请求下发给各个医院的信息系统,导致各个医院的信息系统存在安全隐患,需要先对获取到的待查询数字证书、待查询个人信息以及待查询请求签名进行验证,并在通过验证后才可以进一步的将数据查询请求下发给各个信息系统。
由于区块链在数据查询请求中可以获取到待查询数字证书、待查询个人信息以及待查询请求签名,因此,在对待查询数字证书、待查询个人信息以及待查询请求签名进行验证时,考虑到在区块链系统中注册过的用户会有个人信息存储在区块链系统,这样,首先,在区块链系统中查询是否存在与待查询个人信息一致的个人信息,通过查询区块链系统中是否包括待查询个人信息来确定该用户是否在区块链系统中注册过;随后;考虑到待查询请求签名是基于待查询数字证书的待查询证书公钥生成的,因此,获取待查询数字证书的待查询证书公钥,采用待查询证书公钥对待查询请求签名解密,通过解密的方式对待查询请求签名进行验证,从而判断该待查询请求签名的真实性。需要说明的是,由于在区块链系统中成功注册的用户的数字证书也会存储在区块链系统中,因此,在进行验证时,如果区块链系统中存储有与待查询个人信息一致的个人信息,则还可以获取该个人信息对应的数字证书,将该数字证书与待查询数字证书进行比对,如果确定该数字证书与该待查询数字证书一致,则确定该待查询数字证书是真实的,该待查询数字证书通过验证,继续对其他对象进行验证。需要说明的是,在对待查询数字证书、待查询个人信息以及待查询请求签名进行验证时,验证的顺序并不是固定的,先对哪一项进行验证都可以,本申请实施例对验证的顺序不进行具体限定。
通过上述对待查询数字证书、待查询个人信息以及待查询请求签名的验证,当区块链系统中存在与待查询个人信息一致的个人信息,且采用待查询证书公钥对待查询请求签名解密成功时,表明数据查询请求中携带的待查询数字证书、待查询个人信息以及待查询请求签名均通过了验证,这时,便可以确定对待查询数字证书、待查询个人信息以及待查询请求签名验证成功,继续执行下述步骤203至步骤206;当区块链系统中不存在与待查询个人信息一致的个人信息,或采用待查询证书公钥对待查询请求签名解密失败时,表明数据查询请求中携带的待查询数字证书、待查询个人信息以及待查询请求签名没有通过验证,这时,便可以确定对待查询数字证书、待查询个人信息以及待查询请求签名验证失败,继续执行下述步骤207。需要说明的是,只要待查询数字证书、待查询个人信息以及待查询请求签名中有任一项没有通过验证,则即可确定整个数据查询请求都没有通过验证,只能执行下述步骤207。
203、如果对待查询数字证书、待查询个人信息以及待查询请求签名验证成功,则确定接入区块链系统的多个信息系统,区块链系统将数据查询请求传输至多个信息系统。
在本申请实施例中,如果对待查询数字证书、待查询个人信息以及待查询请求签名验证成功,则表示该数据查询请求通过验证,此时,便可以将数据查询请求下发给接入到区块链系统中的多个信息系统,以便信息系统按照数据查询请求查询并返回数据。
其中,多个信息系统是以节点的形式接入到区块链系统中的,因此,区块链系统可以通过与信息系统之间的数据连接,将数据查询请求传输给接入到区块链系统中的每一个信息系统。
204、当信息系统接收到区块链系统的数据查询请求时,在数据查询请求中提取待查询个人信息,基于待查询个人信息,提取待查询个人信息对应的目标电子病历。
在本申请实施例中,对于多个信息系统中的任一信息系统,当信息系统接收到区块链系统传输的数据查询请求时,由于数据查询请求中携带了待查询个人信息,因此,信息系统可以在数据查询请求中提取待查询个人信息,根据待查询个人信息在信息系统中查询该待查询个人信息对应的电子病历作为目标电子病历,并将该目标电子病历提取出来,以便后续将该目标电子病历返回给区块链系统。
在实际应用的过程中,可能用户没有在当前的信息系统所服务的医院中进行过治疗,使得该信息系统中无法确定目标电子病历,这样,信息系统便可以不再执行下述的其他内容。另外,为了使区块链系统可以知晓当前的信息系统中不存在目标电子病历,如果信息系统没有获取到目标电子病历,则可以生成无数据指令,并将该无数据指令返回给区块链系统,以便区块链系统可以获知当前信息系统中没有存储该用户的电子病历,而非信息系统发生故障。
205、在数据查询请求中提取待查询数字证书,获取待查询数字证书的待查询证书公钥,采用待查询证书公钥,对目标电子病历进行加密,生成信息密文,将信息密文传输至区块链系统。
在本申请实施例中,由于用户在申请数字证书时,需要先生成证书公私钥对,证书私钥自己保存,将证书公钥和用户信息提交给认证机构,由认证机构将证书公钥与用户的个人信息绑定并进行签名,从而签发数字证书,使得数字证书中包含有证书公钥。这样,在获取到目标电子病历后,考虑到采用证书公钥加密后的密文可以采用证书私钥进行解密,因此,为了保证目标电子病历在传输过程中的安全,信息系统在将目标电子病历传输给区块链系统之前,在待查询数字证书中提取待查询证书公钥,采用待查询证书公钥对目标电子病历进行加密,生成信息密文,并将该信息密文传输给区块链系统,以便保证目标电子病历在传输过程中的安全性,避免目标电子病历中的数据被人窃取。
206、区块链系统接收多个信息系统在接收到数据查询请求后返回的至少一个信息密文,将至少一个信息密文返回至用户。
在本申请实施例中,由于区块链系统在将数据查询请求下发给多个信息系统后,每个信息系统均会查询并获取到对应的用户电子病历,且还会对电子病历进行加密生成信息密文,因此,在区块链系统将查询请求传输给多个信息系统后,会接收到多个信息系统返回的信息密文,而考虑到有些信息系统可能没有查询到需要查询的信息,因此,可能接收到至少一个信息密文,这时,区块链系统便可以将至少一个信息密文整合起来返回给用户。需要说明的是,考虑到用户可能没有在某些医院检查过,使得该医院不会给区块链系统返回信息密文,可能仅会给区块链系统返回一个无数据指令,因此,区块链系统仅需将获取到的信息密文返回给用户即可,无需一定要全部的医院均给予信息密文的回馈。另外,还可能存在用户未在任何医院就医的情况,这时,可能不会获取到任何的信息密文,这时,区块链系统便可以生成无数据指令,并将该无数据指令返回给用户,本申请对得到的信息密文的个数或者是否能够获取到信息密文不进行具体限定。
207、如果对待查询数字证书、待查询个人信息以及待查询请求签名验证失败,则生成查询失败响应,将查询失败响应传输至用户。
在本申请实施例中,如果对待查询数字证书、待查询个人信息以及待查询请求签名验证失败,则表示该数据查询请求没有通过区块链系统的验证,此时,区块链系统是不能将该数据查询请求传输给信息系统的,需要用户重新提供数字证书、个人信息以及请求签名,因此,生成查询失败响应,将该查询失败响应传输给用户,以便用户重新发送数据查询请求。
需要说明的是,区块链系统在生成查询失败响应时,可以在查询请求指令中携带错误指示,也即提醒用户待查询数字证书、待查询个人信息以及待查询请求签名中的哪一项信息发生了错误,以便用户更加注意该项信息的输入,避免再次发生错误。本申请实施例对查询失败响应包括的内容不进行具体限定。
在实际应用的过程中,为了防止不法分子随意向区块链系统下发各种指令,导致区块链系统的瘫痪以及数据的丢失,用户在使用区块链系统提供的各项服务之前,需要在区块链系统中进行注册,并在注册成功后,方可向区块链系统下发指令,参见图2B,该方法包括:
208、当接收到用户注册请求时,在用户注册请求中提取待注册用户信息、待注册数字签名以及待注册数字证书。
在本申请实施例中,区块链系统的客户端中可以为用户提供注册入口,当用户所持的终端检测到用户触发该注册入口时,确定检测到用户请求注册,显示注册页面。其中,由于用户的身份是基于数字证书体现的,为了验证用户身份的真实性以及安全性,在用户进行注册时,需要用户提供自身所持的数字证书作为待注册数字证书,以便基于该待注册数字证书对用户的身份进行验证。在实际应用的过程中,用户所持的终端为了进一步保证待注册数字证书以及待注册用户信息在传输过程中的安全性,通常会采用待注册数字证书中的待注册证书私钥对待注册数字证书进行签名得到的待注册数字签名,签名的过程实质为加密的过程,也即用户所持的终端将加密后的待注册数字证书作为待注册数字签名,并将该待注册数字签名也携带在用户注册请求中,使得区块链系统可以接收到携带待注册用户信息、待注册数字签名以及待注册数字证书的用户注册请求,以便在后续可以通过验证该待注册数字签名实现对待注册数字证书的验证。
这样,当区块链系统接收到用户基于所持终端中下载的客户端发送的用户注册请求后,便可以在该用户注册请求中提取到待注册用户信息、待注册数字签名以及待注册数字证书。
209、在待注册数字证书中提取证书签名,将证书签名与预设签名进行比对,在待注册数字证书中提取待注册证书公钥,采用待注册证书公钥对待注册数字签名解密,如果证书签名与预设签名一致,且采用待注册证书公钥对待注册数字签名解密成功,则执行下述步骤210;如果证书签名与预设签名不一致,或采用待注册证书公钥对待注册数字签名解密失败,则执行下述步骤211。
在本申请实施例中,预设签名为证书机构提供的用于验证证书签名是否有效的签名。由于认证机构在下发数字证书时,都会在数字证书中携带证书签名,将该证书签名作为防伪标志,从而证明数字证书是由认证机构下发的,因此,可以在待注册数字证书中提取证书签名,将该证书签名与认证机构提供的预设签名进行比对,通过判断该证书签名与预设签名是否一致来确定该待注册数字正式是否是认证机构下发的,而不是不法分子伪造的。另外,由于用户注册请求中还携带待注册数字签名,待注册数字签名是基于待注册数字证书的待注册证书私钥对待注册证书进行签名得到的,因此,基于公私钥对可以相互加密和解密的属性,可以采用待注册证书公钥对待注册证书签名解密,并根据是否签名成功来确定待注册数字签名的真实性。
综上所述,在对待注册数字签名以及待注册数字证书进行验证时,首先,在待注册数字证书中提取证书签名,将证书签名与预设签名进行比对;随后,在待注册数字证书中提取待注册证书公钥,采用待注册证书公钥对待注册数字签名解密,从而实现对待注册数字签名以及待注册数字证书的验证。本申请实施例对验证待注册数字签名以及待注册数字证书的先后顺序不进行具体限定。
其中,如果证书签名与预设签名一致,且采用待注册证书公钥对待注册数字签名解密成功,则表示待注册数字签名以及待注册数字证书通过验证,该用户是可以在区块链系统中注册的,因此,为用户进行注册,也即执行下述步骤210;如果证书签名与预设签名不一致,或采用待注册证书公钥对待注册数字签名解密失败,则表示待注册数字签名以及待注册数字证书没有通过验证,待注册数字签名以及待注册数字证书不真实或者是错误的,该用户是不可以在区块链系统中注册的,需要用户提供真实的或者正确的待注册数字签名以及待注册数字证书,也即执行下述步骤211。
210、如果证书签名与预设签名一致,且采用待注册证书公钥对待注册数字签名解密成功,则将待注册用户信息和待注册数字证书对应存储至区块链系统。
在本申请实施例中,如果证书签名与预设签名一致,且采用待注册证书公钥对待注册数字签名解密成功,则表示该用户是可以在区块链系统中注册的,因此,区块链系统将该待注册用户信息以及待注册数字证书对应存储在区块链系统中,完成该用户在区块链系统中的注册。
211、如果证书签名与预设签名不一致,或采用待注册证书公钥对待注册数字签名解密失败,则生成并返回注册失败响应。
在本申请实施例中,如果证书签名与预设签名不一致,或采用待注册证书公钥对待注册数字签名解密失败,则表示该用户注册请求很可能在传输的过程中被篡改,真实性无法验证,或者用户提供的待注册数字证书和待注册数字签名可能是虚假的或者不正确的,此时,便不能实现用户在区块链系统中的注册,需要用户重新提供相关信息进行注册,因此,生成失败响应,并将该失败响应返回给用户,以便用户接收到失败响应可以重新发送用户注册请求。
本申请实施例提供的方法,通过验证的数据查询请求传输给接入区块链系统的多个信息系统,多个信息系统均可以返回符合数据查询请求的信息密文,使得在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,减少了用户查询电子病历的工作量,节省了大量资源。
进一步地,作为图1A所述方法的具体实现,本申请实施例提供了一种基于区块链的数据查询装置,如图3A所示,所述装置包括:接收模块301,验证模块302,第一传输模块303和第一返回模块304。
该接收模块301,用于接收用户的数据查询请求,在所述数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名;
该验证模块302,用于基于区块链系统,对待查询数字证书、待查询个人信息以及待查询请求签名进行验证,区块链系统中存储有注册用户的用户信息以及数字证书;
该第一传输模块303,用于如果对待查询数字证书、待查询个人信息以及待查询请求签名验证成功,则确定接入区块链系统的多个信息系统,将数据查询请求传输至多个信息系统;
该第一返回模块304,用于接收多个信息系统在接收到数据查询请求后返回的至少一个信息密文,将至少一个信息密文返回至用户,信息密文携带用户的在对应的信息系统中存储的电子病历。
在具体的应用场景中,如图3B所示,该装置还包括:提取模块305,比对模块306,签名模块307,存储模块308和第二返回模块309。
该提取模块305,用于当接收到用户注册请求时,在所述用户注册请求中提取待注册用户信息、待注册数字签名以及待注册数字证书;
该比对模块306,用于在所述待注册数字证书中提取证书签名,将所述证书签名与预设签名进行比对,所述预设签名为证书机构提供的用于验证所述证书签名是否有效的签名;
该签名模块307,用于在所述待注册数字证书中提取待注册证书公钥,采用所述待注册证书公钥对所述待注册数字签名解密;
该存储模块308,用于如果所述证书签名与所述预设签名一致,且采用所述待注册证书公钥对所述待注册数字签名解密成功,则将所述待注册用户信息和所述待注册数字证书对应存储至所述区块链系统;
该第二返回模块309,用于如果所述证书签名与所述预设签名不一致,或采用所述待注册证书公钥对所述待注册数字签名解密失败,则生成并返回注册失败响应。
在具体的应用场景中,该验证模块302,用于在所述区块链系统中查询是否存在与所述待查询个人信息一致的个人信息;获取所述待查询数字证书的待查询证书公钥,采用所述待查询证书公钥对所述待查询请求签名解密;
相应地,该存储模块308,用于当所述区块链系统中存在与所述待查询个人信息一致的个人信息,且采用所述待查询证书公钥对所述待查询请求签名解密成功时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功;
该第一返回模块304,用于当所述区块链系统中不存在与所述待查询个人信息一致的个人信息,或采用所述待查询证书公钥对所述待查询请求签名解密失败时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败。
在具体的应用场景中,如图3C所示,该装置还包括:第二传输模块310。
该第二传输模块310,用于如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败,则生成查询失败响应,将所述查询失败响应传输至所述用户。
本申请实施例提供的装置,将通过验证的数据查询请求传输给接入区块链系统的多个信息系统,多个信息系统均可以返回符合数据查询请求的信息密文,使得在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,减少了用户查询电子病历的工作量,节省了大量资源。
进一步地,作为图1B所述方法的具体实现,本申请实施例提供了一种基于区块链的数据查询装置,如图4A所示,所述装置包括:确定模块401,生成模块402和传输模块403。
该确定模块401,用于当接收到区块链系统的数据查询请求时,确定所述数据查询请求指示的目标电子病历;
该生成模块402,用于在所述数据查询请求中提取待查询数字证书,基于所述待查询数字证书和所述目标电子病历,生成信息密文;
该传输模块403,用于将所述信息密文传输至所述区块链系统。
在具体的应用场景中,如图4B所示,该确定模块401,包括提取子模块4011和查询子模块4012。
该提取子模块4011,用于当接收到所述区块链系统的数据查询请求时,在所述数据查询请求中提取待查询个人信息;
该查询子模块4012,用于基于所述待查询个人信息,在所述区块链系统中提取所述待查询个人信息对应的目标电子病历。
在具体的应用场景中,如图4C所示,该生成模块402,包括获取子模块4021和生成子模块4022。
该获取子模块4021,用于在所述数据查询请求中提取待查询数字证书,获取所述待查询数字证书的待查询证书公钥;
该生成子模块4022,用于采用所述待查询证书公钥,对所述目标电子病历进行加密,生成所述信息密文。
本申请实施例提供的装置,当信息系统接收到区块链系统发送的数据查询请求时,会将自身包括的与数据查询请求相关的数据返回给区块链系统,使得区块链在进行数据查询时,可以查询到多个信息系统的数据,无需多次向多个信息系统请求数据查询,减少了用户查询电子病历的工作量,节省了大量资源。
需要说明的是,本申请实施例提供的一种基于区块链的数据查询装置所涉及各功能单元的其他相应描述,可以参考图1A至图1B和图2A至图2B中的对应描述,在此不再赘述。
在示例性实施例中,参见图5,还提供了一种设备,该设备500包括通信总线、处理器、存储器和通信接口,还可以包括、输入输出接口和显示设备,其中,各个功能单元之间可以通过总线完成相互间的通信。该存储器存储有计算机可读指令,处理器,用于执行存储器上所存放的程序,执行上述实施例中的基于区块链的数据查询方法。
一种计算机可读存储介质,其上存储有计算机可读指令,所述计算机可读指令被处理器执行时实现所述的基于区块链的数据查询方法的步骤。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到本申请可以通过硬件实现,也可以借助软件加必要的通用硬件平台的方式来实现。基于这样的理解,本申请的技术方案可以以软件产品的形式体现出来,该软件产品可以存储在一个非易失性存储介质(可以是CD-ROM,U盘,移动硬盘等)中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施场景所述的方法。
本领域技术人员可以理解附图只是一个优选实施场景的示意图,附图中的模块或流程并不一定是实施本申请所必须的。
本领域技术人员可以理解实施场景中的装置中的模块可以按照实施场景描述进行分布于实施场景的装置中,也可以进行相应变化位于不同于本实施场景的一个或多个装置中。上述实施场景的模块可以合并为一个模块,也可以进一步拆分成多个子模块。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机可读指令来指令相关的硬件来完成,所述的计算机可读指令可存储于一计算机非易失性可读取存储介质中,该计算机可读指令在执行时,可包括如上述各方法的实施例的流程。其中,本申请所提供的各实施例中所使用的对存储器、存储、数据库或其它介质的任何引用,均可包括非易失性和/或易失性存储器。非易失性存储器可包括只读存储器(ROM)、可编程ROM(PROM)、电可编程ROM(EPROM)、电可擦除可编程ROM(EEPROM)或闪存。易失性存储器可包括随机存取存储器(RAM)或者外部高速缓冲存储器。作为说明而非局限,RAM以多种形式可得,诸如静态RAM(SRAM)、动态RAM(DRAM)、同步DRAM(SDRAM)、双数据率SDRAM(DDRSDRAM)、增强型SDRAM(ESDRAM)、同步链路(Synchlink) DRAM(SLDRAM)、存储器总线(Rambus)直接RAM(RDRAM)、直接存储器总线动态RAM(DRDRAM)、以及存储器总线动态RAM(RDRAM)等。
以上所述实施例仅用以说明本申请的技术方案,而非对其限制;尽管参照前述实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的精神和范围,均应包含在本申请的保护范围之内。

Claims (20)

  1. 一种基于区块链的数据查询方法,其特征在于,包括:
    接收用户的数据查询请求,在所述数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名;
    基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,所述区块链系统中存储有注册用户的用户信息以及数字证书;
    如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功,则确定接入所述区块链系统的多个信息系统,将所述数据查询请求传输至所述多个信息系统;
    接收所述多个信息系统在接收到所述数据查询请求后返回的至少一个信息密文,将所述至少一个信息密文返回至所述用户,所述信息密文携带所述用户的在对应的信息系统中存储的电子病历。
  2. 根据权利要求1所述的方法,其特征在于,所述接收用户的数据查询请求,在所述数据查询请求中提取待查询数据标识、待查询数字证书、待查询个人信息以及待查询请求签名之前,包括:
    当接收到用户注册请求时,在所述用户注册请求中提取待注册用户信息、待注册数字签名以及待注册数字证书;
    在所述待注册数字证书中提取证书签名,将所述证书签名与预设签名进行比对,所述预设签名为证书机构提供的用于验证所述证书签名是否有效的签名;
    在所述待注册数字证书中提取待注册证书公钥,采用所述待注册证书公钥对所述待注册数字签名解密;
    如果所述证书签名与所述预设签名一致,且采用所述待注册证书公钥对所述待注册数字签名解密成功,则将所述待注册用户信息和所述待注册数字证书对应存储至所述区块链系统;
    如果所述证书签名与所述预设签名不一致,或采用所述待注册证书公钥对所述待注册数字签名解密失败,则生成并返回注册失败响应。
  3. 根据权利要求1所述的方法,其特征在于,所述基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,包括:
    在所述区块链系统中查询是否存在与所述待查询个人信息一致的个人信息;
    获取所述待查询数字证书的待查询证书公钥,采用所述待查询证书公钥对所述待查询请求签名解密;
    相应地,当所述区块链系统中存在与所述待查询个人信息一致的个人信息,且采用所述待查询证书公钥对所述待查询请求签名解密成功时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功;
    当所述区块链系统中不存在与所述待查询个人信息一致的个人信息,或采用所述待查询证书公钥对所述待查询请求签名解密失败时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败。
  4. 根据权利要求1所述的方法,其特征在于,所述基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证之后,所述方法还包括:
    如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败,则生成查询失败响应,将所述查询失败响应传输至所述用户。
  5. 一种基于区块链的数据查询方法,其特征在于,包括:
    当接收到区块链系统的数据查询请求时,确定所述数据查询请求指示的目标电子病历;
    在所述数据查询请求中提取待查询数字证书,基于所述待查询数字证书和所述目标电子病历,生成信息密文;
    将所述信息密文传输至所述区块链系统。
  6. 根据权利要求5所述的方法,其特征在于,所述当接收到区块链系统的数据查询请求时,确定所述数据查询请求指示的目标电子病历,包括:
    当接收到所述区块链系统的数据查询请求时,在所述数据查询请求中提取待查询个人信息;
    基于所述待查询个人信息,在所述区块链系统中提取所述待查询个人信息对应的目标电子病历。
  7. 根据权利要求5所述的方法,其特征在于,所述在所述数据查询请求中提取待查询数字证书,基于所述待查询数字证书和所述目标电子病历,生成信息密文,包括:
    在所述数据查询请求中提取待查询数字证书,获取所述待查询数字证书的待查询证书公钥;
    采用所述待查询证书公钥,对所述目标电子病历进行加密,生成所述信息密文。
  8. 一种基于区块链的数据查询装置,其特征在于,包括:
    接收模块,用于接收用户的数据查询请求,在所述数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名;
    验证模块,用于基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,所述区块链系统中存储有注册用户的用户信息以及数字证书;
    第一传输模块,用于如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功,则确定接入区块链系统的多个信息系统,将所述数据查询请求传输至所述多个信息系统;
    第一返回模块,用于接收所述多个信息系统在接收到所述数据查询请求后返回的至少一个信息密文,将所述至少一个信息密文返回至所述用户,所述信息密文携带所述用户的在对应的信息系统中存储的电子病历。
  9. 如权利要求8所述的数据查询装置,其特征在于,还包括:
    提取模块,用于当接收到用户注册请求时,在所述用户注册请求中提取待注册用户信息、待注册数字签名以及待注册数字证书;
    比对模块,用于在所述待注册数字证书中提取证书签名,将所述证书签名与预设签名进行比对,所述预设签名为证书机构提供的用于验证所述证书签名是否有效的签名;
    比对模块,用于在所述待注册数字证书中提取待注册证书公钥,采用所述待注册证书公钥对所述待注册数字签名解密;
    存储模块,用于如果所述证书签名与所述预设签名一致,且采用所述待注册证书公钥对所述待注册数字签名解密成功,则将所述待注册用户信息和所述待注册数字证书对应存储至所述区块链系统;
    第二返回模块,用于如果所述证书签名与所述预设签名不一致,或采用所述待注册证书公钥对所述待注册数字签名解密失败,则生成并返回注册失败响应。
  10. 一种基于区块链的数据查询装置,其特征在于,包括:
    确定模块,用于当接收到区块链系统的数据查询请求时,确定所述数据查询请求指示的目标电子病历;
    生成模块,用于在所述数据查询请求中提取待查询数字证书,基于所述待查询数字证书和所述目标电子病历,生成信息密文;
    传输模块,用于将所述信息密文传输至所述区块链系统。
  11. 一种终端设备,其特征在于,所述终端设备包括存储器、处理器以及存储在所述存储器中并可在所述处理器上运行的计算机可读指令,所述处理器执行所述计算机可读指令时执行以下步骤:
    接收用户的数据查询请求,在所述数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名;
    基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,所述区块链系统中存储有注册用户的用户信息以及数字证书;
    如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功,则确定接入所述区块链系统的多个信息系统,将所述数据查询请求传输至所述多个信息系统;
    接收所述多个信息系统在接收到所述数据查询请求后返回的至少一个信息密文,将所述至少一个信息密文返回至所述用户,所述信息密文携带所述用户的在对应的信息系统中存储的电子病历。
  12. 根据权利要求11所述的终端设备,其特征在于,所述接收用户的数据查询请求,在所述数据查询请求中提取待查询数据标识、待查询数字证书、待查询个人信息以及待查询请求签名之前,所述处理器执行所述计算机可读指令时还执行以下步骤:
    当接收到用户注册请求时,在所述用户注册请求中提取待注册用户信息、待注册数字签名以及待注册数字证书;
    在所述待注册数字证书中提取证书签名,将所述证书签名与预设签名进行比对,所述预设签名为证书机构提供的用于验证所述证书签名是否有效的签名;
    在所述待注册数字证书中提取待注册证书公钥,采用所述待注册证书公钥对所述待注册数字签名解密;
    如果所述证书签名与所述预设签名一致,且采用所述待注册证书公钥对所述待注册数字签名解密成功,则将所述待注册用户信息和所述待注册数字证书对应存储至所述区块链系统;
    如果所述证书签名与所述预设签名不一致,或采用所述待注册证书公钥对所述待注册数字签名解密失败,则生成并返回注册失败响应。
  13. 根据权利要求11所述的中的终端设备,其特征在于,所述基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,包括:
    在所述区块链系统中查询是否存在与所述待查询个人信息一致的个人信息;
    获取所述待查询数字证书的待查询证书公钥,采用所述待查询证书公钥对所述待查询请求签名解密;
    相应地,当所述区块链系统中存在与所述待查询个人信息一致的个人信息,且采用所述待查询证书公钥对所述待查询请求签名解密成功时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功;
    当所述区块链系统中不存在与所述待查询个人信息一致的个人信息,或采用所述待查询证书公钥对所述待查询请求签名解密失败时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败。
  14. 根据权利要求11所述的终端设备,其特征在于,所述基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证之后,所述处理器执行所述计算机可读指令时还执行以下步骤:
    如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败,则生成查询失败响应,将所述查询失败响应传输至所述用户。
  15. 一种终端设备,其特征在于,所述终端设备包括存储器、处理器以及存储在所述存储器中并可在所述处理器上运行的计算机可读指令,所述处理器执行所述计算机可读指令时执行以下步骤:
    当接收到区块链系统的数据查询请求时,确定所述数据查询请求指示的目标电子病历;
    在所述数据查询请求中提取待查询数字证书,基于所述待查询数字证书和所述目标电子病历,生成信息密文;
    将所述信息密文传输至所述区块链系统。
  16. 一种计算机非易失性可读存储介质,所述计算机非易失性可读存储介质存储有计算机可读指令,其特征在于,所述计算机可读指令被处理器执行时实现如下步骤:
    接收用户的数据查询请求,在所述数据查询请求中提取待查询数字证书、待查询个人信息以及待查询请求签名;
    基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,所述区块链系统中存储有注册用户的用户信息以及数字证书;
    如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功,则确定接入所述区块链系统的多个信息系统,将所述数据查询请求传输至所述多个信息系统;
    接收所述多个信息系统在接收到所述数据查询请求后返回的至少一个信息密文,将所述至少一个信息密文返回至所述用户,所述信息密文携带所述用户的在对应的信息系统中存储的电子病历。
  17. 根据权利要求16所述的计算机非易失性可读存储介质,其特征在于,所述接收用户的数据查询请求,在所述数据查询请求中提取待查询数据标识、待查询数字证书、待查询个人信息以及待查询请求签名之前,所述计算机可读指令被处理器执行时还实现如下步骤:
    当接收到用户注册请求时,在所述用户注册请求中提取待注册用户信息、待注册数字签名以及待注册数字证书;
    在所述待注册数字证书中提取证书签名,将所述证书签名与预设签名进行比对,所述预设签名为证书机构提供的用于验证所述证书签名是否有效的签名;
    在所述待注册数字证书中提取待注册证书公钥,采用所述待注册证书公钥对所述待注册数字签名解密;
    如果所述证书签名与所述预设签名一致,且采用所述待注册证书公钥对所述待注册数字签名解密成功,则将所述待注册用户信息和所述待注册数字证书对应存储至所述区块链系统;
    如果所述证书签名与所述预设签名不一致,或采用所述待注册证书公钥对所述待注册数字签名解密失败,则生成并返回注册失败响应。
  18. 根据权利要求16所述的计算机非易失性可读存储介质,其特征在于,所述基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证,包括:
    在所述区块链系统中查询是否存在与所述待查询个人信息一致的个人信息;
    获取所述待查询数字证书的待查询证书公钥,采用所述待查询证书公钥对所述待查询请求签名解密;
    相应地,当所述区块链系统中存在与所述待查询个人信息一致的个人信息,且采用所述待查询证书公钥对所述待查询请求签名解密成功时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证成功;
    当所述区块链系统中不存在与所述待查询个人信息一致的个人信息,或采用所述待查询证书公钥对所述待查询请求签名解密失败时,确定对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败。
  19. 根据权利要求16所述的计算机非易失性可读存储介质,其特征在于,所述基于区块链系统,对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名进行验证之后,所述计算机可读指令被处理器执行时还实现如下步骤:
    如果对所述待查询数字证书、所述待查询个人信息以及所述待查询请求签名验证失败,则生成查询失败响应,将所述查询失败响应传输至所述用户。
  20. 一种计算机非易失性可读存储介质,所述计算机非易失性可读存储介质存储有计算机可读指令,其特征在于,所述计算机可读指令被处理器执行时实现如下步骤:
    当接收到区块链系统的数据查询请求时,确定所述数据查询请求指示的目标电子病历;
    在所述数据查询请求中提取待查询数字证书,基于所述待查询数字证书和所述目标电子病历,生成信息密文;
    将所述信息密文传输至所述区块链系统。
PCT/CN2019/122574 2019-03-21 2019-12-03 基于区块链的数据查询方法、装置、设备及可读存储介质 Ceased WO2020186822A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910219136.4A CN110070926A (zh) 2019-03-21 2019-03-21 基于区块链的数据查询方法、装置、设备及可读存储介质
CN201910219136.4 2019-03-21

Publications (1)

Publication Number Publication Date
WO2020186822A1 true WO2020186822A1 (zh) 2020-09-24

Family

ID=67366515

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/122574 Ceased WO2020186822A1 (zh) 2019-03-21 2019-12-03 基于区块链的数据查询方法、装置、设备及可读存储介质

Country Status (2)

Country Link
CN (1) CN110070926A (zh)
WO (1) WO2020186822A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113779325A (zh) * 2020-12-25 2021-12-10 北京沃东天骏信息技术有限公司 数据查询方法、装置、存储介质和电子设备

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110070926A (zh) * 2019-03-21 2019-07-30 深圳壹账通智能科技有限公司 基于区块链的数据查询方法、装置、设备及可读存储介质
CN110719264B (zh) * 2019-09-18 2022-07-22 平安科技(深圳)有限公司 一种信息处理方法、装置、电子设备和存储介质
CN111147447A (zh) * 2019-12-03 2020-05-12 苏宁云计算有限公司 一种数据的保护方法及系统
CN111046061B (zh) * 2019-12-13 2023-08-25 医渡云(北京)技术有限公司 数据查询方法、装置、系统、设备及存储介质
CN111145850A (zh) * 2019-12-23 2020-05-12 支付宝(杭州)信息技术有限公司 基于区块链的医疗数据查询方法以及装置
CN111209313B (zh) * 2020-01-03 2023-10-27 腾讯科技(深圳)有限公司 基于区块链的医疗项目数据的查询方法及装置
CN113542194B (zh) * 2020-04-16 2023-04-07 中国联合网络通信集团有限公司 用户行为追溯方法、装置、设备及存储介质
CN112102908A (zh) * 2020-09-22 2020-12-18 合肥易康达医疗卫生信息科技有限公司 一种电子病历可信云签名方法
CN112733121B (zh) 2021-01-13 2024-09-20 京东科技信息技术有限公司 数据获取方法、装置、设备及存储介质
CN112995205B (zh) * 2021-04-13 2021-08-20 北京百度网讯科技有限公司 基于区块链的查询方法、装置、设备和存储介质

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106682530A (zh) * 2017-01-10 2017-05-17 杭州电子科技大学 一种基于区块链技术的医疗信息共享隐私保护方法及装置
CN107391944A (zh) * 2017-07-27 2017-11-24 北京太云科技有限公司 一种基于区块链的电子病历共享系统
CN107579979A (zh) * 2017-09-07 2018-01-12 成都理工大学 基于区块链技术的电子病历的共享查询方法
CN107766574A (zh) * 2017-11-13 2018-03-06 天津开心生活科技有限公司 数据查询方法及装置、数据存储方法及装置
US20180227119A1 (en) * 2017-02-09 2018-08-09 International Business Machines Corporation Managing a database management system using a blockchain database
CN110070926A (zh) * 2019-03-21 2019-07-30 深圳壹账通智能科技有限公司 基于区块链的数据查询方法、装置、设备及可读存储介质

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106354994B (zh) * 2016-08-22 2019-01-18 布比(北京)网络技术有限公司 处理医疗数据的方法及系统
JP6801922B2 (ja) * 2017-06-05 2020-12-16 Necソリューションイノベータ株式会社 診療記録管理システム、装置、方法およびプログラム
CN108665946B (zh) * 2018-05-08 2023-01-17 创新先进技术有限公司 一种业务数据的访问方法和装置
CN109243553A (zh) * 2018-06-28 2019-01-18 平安科技(深圳)有限公司 医疗数据处理方法、系统、计算机设备及可读存储介质
CN109243559A (zh) * 2018-09-03 2019-01-18 南京旭颢信息科技有限公司 基于区块链技术的个人健康电子病历共享及查询方法

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106682530A (zh) * 2017-01-10 2017-05-17 杭州电子科技大学 一种基于区块链技术的医疗信息共享隐私保护方法及装置
US20180227119A1 (en) * 2017-02-09 2018-08-09 International Business Machines Corporation Managing a database management system using a blockchain database
CN107391944A (zh) * 2017-07-27 2017-11-24 北京太云科技有限公司 一种基于区块链的电子病历共享系统
CN107579979A (zh) * 2017-09-07 2018-01-12 成都理工大学 基于区块链技术的电子病历的共享查询方法
CN107766574A (zh) * 2017-11-13 2018-03-06 天津开心生活科技有限公司 数据查询方法及装置、数据存储方法及装置
CN110070926A (zh) * 2019-03-21 2019-07-30 深圳壹账通智能科技有限公司 基于区块链的数据查询方法、装置、设备及可读存储介质

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113779325A (zh) * 2020-12-25 2021-12-10 北京沃东天骏信息技术有限公司 数据查询方法、装置、存储介质和电子设备
CN113779325B (zh) * 2020-12-25 2024-04-05 北京沃东天骏信息技术有限公司 数据查询方法、装置、存储介质和电子设备

Also Published As

Publication number Publication date
CN110070926A (zh) 2019-07-30

Similar Documents

Publication Publication Date Title
WO2020186822A1 (zh) 基于区块链的数据查询方法、装置、设备及可读存储介质
CN110086608B (zh) 用户认证方法、装置、计算机设备及计算机可读存储介质
CN109862041B (zh) 一种数字身份认证方法、设备、装置、系统及存储介质
US11165757B2 (en) Method and apparatus for securing communications using multiple encryption keys
US8589442B2 (en) Intersystem single sign-on
US11134069B2 (en) Method for authorizing access and apparatus using the method
WO2020168772A1 (zh) 一种电子病历存储方法、系统、装置、设备及介质
CN111212084B (zh) 一种面向边缘计算的属性加密访问控制方法
WO2018050081A1 (zh) 设备身份认证的方法、装置、电子设备及存储介质
US20200412554A1 (en) Id as service based on blockchain
WO2019109097A1 (en) Identity verification document request handling utilizing a user certificate system and user identity document repository
WO2020062668A1 (zh) 一种身份认证方法、身份认证装置及计算机可读介质
WO2020186823A1 (zh) 区块链的数据查询方法、装置、系统、设备及存储介质
US20230071022A1 (en) Zero-knowledge proof-based certificate service method using blockchain network, certification support server using same, and user terminal using same
CN109495490A (zh) 一种基于区块链的统一身份认证方法
CN106326763A (zh) 获取电子文件的方法及装置
CN111444492A (zh) 一种基于医疗区块链的数字身份验证的方法
CN114629713A (zh) 身份验证方法、装置及系统
JP2001186122A (ja) 認証システム及び認証方法
CN113343201A (zh) 注册请求处理方法、用户身份信息管理方法及设备
CN101582876A (zh) 用户生成内容的注册方法、装置和系统
CN113726523A (zh) 一种基于Cookie和DR身份密码体制的多重身份认证方法及装置
CN113676332B (zh) 二维码认证方法、通信设备及存储介质
CN115460228B (zh) 一种医疗数据的访问控制方法及系统
WO2020228304A1 (zh) 信息交互方法、装置、计算机设备及可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19919740

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 14/02/2022)

122 Ep: pct application non-entry in european phase

Ref document number: 19919740

Country of ref document: EP

Kind code of ref document: A1