[go: up one dir, main page]

TWI845966B - System and method for digital health information verification - Google Patents

System and method for digital health information verification Download PDF

Info

Publication number
TWI845966B
TWI845966B TW111123120A TW111123120A TWI845966B TW I845966 B TWI845966 B TW I845966B TW 111123120 A TW111123120 A TW 111123120A TW 111123120 A TW111123120 A TW 111123120A TW I845966 B TWI845966 B TW I845966B
Authority
TW
Taiwan
Prior art keywords
certificate
health information
digital health
holder
software product
Prior art date
Application number
TW111123120A
Other languages
Chinese (zh)
Other versions
TW202301365A (en
Inventor
朱原嘉
Original Assignee
臺北榮民總醫院
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 臺北榮民總醫院 filed Critical 臺北榮民總醫院
Publication of TW202301365A publication Critical patent/TW202301365A/en
Application granted granted Critical
Publication of TWI845966B publication Critical patent/TWI845966B/en

Links

Landscapes

  • Storage Device Security (AREA)
  • Testing, Inspecting, Measuring Of Stereoscopic Televisions And Televisions (AREA)

Abstract

The present invention provides a digital health information verification system for facilitating a holder to obtain a verification from a verifier, comprising a sever side storing a digital health information or certificate of the holder, and a first software product for the verifier’s use. The server side uses a private key to sign and encrypt the digital health information or certificate and provides it to the holder. The first software product reads the signed and encrypted digital health information or certificate presented by the holder and uses a public key to verify and decrypt said digital health information or certificate.

Description

數位健康資訊驗證系統及方法 Digital health information verification system and method

本發明係關於一種數位健康資訊驗證系統及相關操作方法。 The present invention relates to a digital health information verification system and related operating methods.

數位創新轉型正以快速的推動力帶領各行各業的顛覆性發展,在智慧醫療推動的速度也不遑多讓。從歐美國家的醫療創新腳步,數位醫療資料交換平台的推動一直是各界矚目的焦點。 Digital innovation and transformation are driving disruptive development in all walks of life with rapid momentum, and the pace of smart healthcare is no less impressive. From the pace of medical innovation in European and American countries, the promotion of digital medical data exchange platforms has always been the focus of attention from all walks of life.

在2020年3月9日,隸屬於美國衛生及公共服務部(Department of Health and Human Services[HHS])旗下的美國聯邦醫療保險和補助服務中心(The Centers for Medicare and Medicaid Services,CMS)和國家衛生資訊科技協調辦公室(ONC)公開發布了新規定,要求全美各健保計畫合約的醫療機構於2021年1月1日起,採用新一代國際醫療資料交換標準快速健保互動整合資源(Fast Healthcare Interoperability Resources,FHIR),來強化資料互通並最遲於2021年7月1日起強制執行,範圍不只涵蓋醫療機構、病歷、住出院和轉診記錄,更包括保險機構對保險機構的資料互通,以加速推動整個醫療生態系統的標準互操作性和數據交換。On March 9, 2020, the Centers for Medicare and Medicaid Services (CMS) and the Office of the National Health Information Technology Coordinator (ONC), both under the U.S. Department of Health and Human Services (HHS), announced new regulations requiring all health insurance contracted medical institutions in the United States to adopt the next-generation international medical data exchange standard Fast Healthcare Interoperability Resource (Fast Healthcare Interoperability Resource) from January 1, 2021. The FHIR standard will be used to strengthen data interoperability and will be enforced by July 1, 2021 at the latest. The scope not only covers medical institutions, medical records, admission and discharge records, and referral records, but also includes data interoperability between insurance institutions, in order to accelerate the promotion of standard interoperability and data exchange in the entire medical ecosystem.

國外法規推動之快速發展,以FHIR做為醫療資料交換平台的議題也逐漸被國內主管機關及各大醫療機構所重視,並與各產官學界合作積極推動施行。With the rapid development of foreign regulations, the issue of using FHIR as a medical data exchange platform has gradually been taken seriously by domestic competent authorities and major medical institutions, and they are actively promoting its implementation in collaboration with various industries, governments, and academia.

特別是,因應新冠肺炎疫情,台灣刻正需要建立一可與國際交互資訊及可認證之資訊交換平台,供醫療、管制出入境、防疫等之用。In particular, in response to the COVID-19 pandemic, Taiwan urgently needs to establish an internationally interactive and authentic information exchange platform for medical treatment, entry and exit control, and epidemic prevention.

在後疫情時代,安全旅行、吃飯、商務涉及各國利用一系列技術的多個利益相關者,其主要的挑戰包括:(1) 健康證明的真實性未經證實:沒有標準化的方式來接收和驗證憑證,尤其受感染者是否恢復到「正常」等級;(2) 不同的技術和國際標準採用:基於不同底層技術和標準的廣泛數據格式;及 (3) 不同的防疫要求:每個國家都有自己的要求要求,時時會根據疫情變化而變動。In the post-pandemic era, safe travel, dining, and business involve multiple stakeholders in different countries using a range of technologies. The main challenges include: (1) The authenticity of health certificates is unproven: there is no standardized way to receive and verify certificates, especially whether the infected person has returned to a "normal" level; (2) Different technologies and international standards are adopted: a wide range of data formats based on different underlying technologies and standards; and (3) Different epidemic prevention requirements: each country has its own requirements, which change from time to time according to the changes in the epidemic.

在一方面,本發明提供一種數位健康資訊驗證系統,用以促成一持證人取得一驗證方之驗證,該數位健康資訊驗證系統包含:一伺服器端,儲存有該持證人的一數位健康證書;及一第一軟體產品,供該驗證方使用;其中:該伺服器端使用一私鑰對該數位健康資訊或證書進行簽署及加密,並藉由一通訊方式將經簽署及加密的該數位健康資訊或證書提供予該持證人;該第一軟體產品讀取該持證人出示之經簽署及加密的該數位健康資訊或證書,並使用對應於該私鑰的一公鑰對經簽署及加密的該數位健康資訊或證書進行解密,以驗證其真偽並取得該數位健康資訊或證書之內容。On the one hand, the present invention provides a digital health information verification system for facilitating a certificate holder to obtain verification from a verifier, the digital health information verification system comprising: a server side storing a digital health certificate of the certificate holder; and a first software product for use by the verifier; wherein: the server side uses a private key to sign and encrypt the digital health information or certificate, and provides the signed and encrypted digital health information or certificate to the certificate holder via a communication method; the first software product reads the signed and encrypted digital health information or certificate presented by the certificate holder, and uses a public key corresponding to the private key to decrypt the signed and encrypted digital health information or certificate to verify its authenticity and obtain the content of the digital health information or certificate.

根據本發明之部分具體實施例,該伺服器端與一醫療資訊系統通訊連接,該數位健康資訊或證書來自於該醫療資訊系統。According to some specific embodiments of the present invention, the server is connected to a medical information system, and the digital health information or certificate comes from the medical information system.

根據本發明之部分具體實施例,所述數位健康資訊驗證系統更包含:一第二軟體產品,安裝於該持證人持有的一行動裝置,並用以顯示經簽署及加密的該數位健康資訊或證書。According to some specific embodiments of the present invention, the digital health information verification system further includes: a second software product installed on a mobile device held by the certificate holder and used to display the signed and encrypted digital health information or certificate.

根據本發明之部分具體實施例,經簽署及加密的該數位健康資訊或證書包括一二維條碼。According to some specific embodiments of the present invention, the signed and encrypted digital health information or certificate includes a two-dimensional barcode.

根據本發明之部分具體實施例,該數位健康資訊包括該持證人的疫苗注射紀錄、篩檢紀錄、醫療紀錄、用藥紀錄、病歷或前述之任意組合。According to some specific embodiments of the present invention, the digital health information includes the holder's vaccination record, screening record, medical record, medication record, medical history, or any combination of the foregoing.

另一方面,本發明提供一種用以促成一持證人取得一驗證方之驗證之方法,其包含:提供一伺服器端,儲存有該持證人的一數位健康資訊或證書;提供一第一軟體產品,供該驗證方使用; 該伺服器端使用一私鑰對該數位健康資訊或證書進行簽署及加密,並藉由一通訊方式將經簽署及加密的該數位健康資訊或證書提供予該持證人;及該第一軟體產品讀取該持證人出示之經簽署及加密的該數位健康資訊或證書,並使用對應於該私鑰的一公鑰對經簽署及加密的該數位健康資訊或證書進行解密,以驗證其真偽並取得該數位健康資訊或證書之內容。On the other hand, the present invention provides a method for facilitating a certificate holder to obtain verification from a verifier, which comprises: providing a server side storing digital health information or certificate of the certificate holder; providing a first software product for use by the verifier; the server side uses a private key to sign and encrypt the digital health information or certificate, and provides the signed and encrypted digital health information or certificate to the certificate holder via a communication method; and the first software product reads the signed and encrypted digital health information or certificate presented by the certificate holder, and uses a public key corresponding to the private key to decrypt the signed and encrypted digital health information or certificate to verify its authenticity and obtain the content of the digital health information or certificate.

根據本發明之部分具體實施例,該伺服器端與一醫療資訊系統通訊連接,該數位健康資訊或證書來自於該醫療資訊系統。According to some specific embodiments of the present invention, the server is connected to a medical information system, and the digital health information or certificate comes from the medical information system.

根據本發明之部分具體實施例,所述方法更包含:提供一第二軟體產品,其安裝於該持證人持有的一行動裝置,並用以顯示經簽署及加密的該數位健康資訊或證書。According to some specific embodiments of the present invention, the method further includes: providing a second software product, which is installed on a mobile device held by the certificate holder and is used to display the signed and encrypted digital health information or certificate.

根據本發明之部分具體實施例,經簽署及加密的該數位健康資訊或證書包括一二維條碼。According to some specific embodiments of the present invention, the signed and encrypted digital health information or certificate includes a two-dimensional barcode.

根據本發明之部分具體實施例,該數位健康資訊或證書包括該持證人的疫苗注射紀錄、篩檢紀錄、醫療紀錄、用藥紀錄、病歷或前述之任意組合。According to some specific embodiments of the present invention, the digital health information or certificate includes the holder's vaccination record, screening record, medical record, medication record, medical history, or any combination of the foregoing.

根據本發明之一特定實施例,該數位健康資訊或證書包括嚴重特殊性肺炎(Covid-19)之疫苗注射紀錄、快篩結果紀錄及聚合酶連鎖反應(PCR)核酸檢測結果紀錄。According to a specific embodiment of the present invention, the digital health information or certificate includes a COVID-19 vaccination record, a rapid screening result record, and a polymerase chain reaction (PCR) nucleic acid test result record.

根據本發明之一特定實施例,該數位健康資訊包括兒童疫苗注射紀錄,亦即提供數位兒童健康手冊。According to a specific embodiment of the present invention, the digital health information includes children's vaccination records, that is, a digital children's health handbook is provided.

本發明之其他目的及優點一部分記載於下述說明中,或者可透過本發明的實施例而理解。應了解前文之發明內容及下文之實施方式僅為例示性及闡釋性之說明,而非如申請專利範圍般限定本發明。Other purposes and advantages of the present invention are partially described in the following description, or can be understood through the embodiments of the present invention. It should be understood that the invention content of the foregoing text and the following embodiments are only exemplary and explanatory descriptions, and do not limit the present invention as the scope of the patent application.

除非另有指明,所有在此處使用的技術性和科學性術語具有如同本發明所屬技術領域中之具有通常知識者一般所瞭解的意義。Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

本文所使用的「一」乙詞,如未特別指明,係指至少一個(一個或一個以上)之數量。The terms "a" or "an" as used herein, unless otherwise specified, refer to a quantity of at least one (one or more than one).

本文所使用的「包含(comprise)」或「包含(comprising)」通常以包括(include)/包括(including)的意義使用,其表示允許存在一種或多種特徵、成分或組成分。「包含(comprise)」或「包含(comprising)」涵蓋用語「由……組成(consists)」或「由……組成(consisting of)」。As used herein, "comprise" or "comprising" is generally used in the sense of include/including, which indicates that one or more features, ingredients or components are allowed to be present. "Comprise" or "comprising" encompasses the terms "consists of" or "consisting of".

本發明提供一種數位健康資訊驗證系統,用以促成一持證人取得一驗證方之驗證,該數位健康資訊驗證系統包含: 一伺服器端,儲存有該持證人的一數位健康資訊或證書;及 一第一軟體產品,供該驗證方使用; 其中: 該伺服器端使用一私鑰對該數位健康資訊進行簽署及加密,並藉由一通訊方式將經簽署及加密的該數位健康資訊或證書提供予該持證人;及 該第一軟體產品讀取該持證人出示之經簽署及加密的該數位健康資訊或證書,並使用對應於該私鑰的一公鑰對經簽署及加密的該數位健康資訊或證書進行解密,以驗證其真偽並取得該數位健康資訊或證書之內容。 The present invention provides a digital health information verification system for facilitating a certificate holder to obtain verification from a verification party, the digital health information verification system comprising: A server end storing a digital health information or certificate of the certificate holder; and A first software product for use by the verification party; Wherein: The server end uses a private key to sign and encrypt the digital health information, and provides the signed and encrypted digital health information or certificate to the certificate holder through a communication method; and The first software product reads the signed and encrypted digital health information or certificate presented by the certificate holder, and uses a public key corresponding to the private key to decrypt the signed and encrypted digital health information or certificate to verify its authenticity and obtain the content of the digital health information or certificate.

另外,本發明亦提供一種用以促成一持證人取得一驗證方之驗證之方法。所述方法包含以下步驟: 提供一伺服器端,儲存有該持證人的一數位健康資訊或證書;提供一第一軟體產品,供該驗證方使用; 該伺服器端使用一私鑰對該數位健康資訊或證書進行簽署及加密,並藉由一通訊方式將經簽署及加密的該數位健康資訊或證書提供予該持證人;及 該第一軟體產品讀取該持證人出示之經簽署及加密的該數位健康資訊,並使用對應於該私鑰的一公鑰對經簽署及加密的該數位健康資訊或證書進行解密,以驗證其真偽並取得該數位健康資訊或證書之內容。 In addition, the present invention also provides a method for facilitating a certificate holder to obtain verification from a verification party. The method comprises the following steps: Providing a server end storing a digital health information or certificate of the certificate holder; providing a first software product for use by the verification party; The server end uses a private key to sign and encrypt the digital health information or certificate, and provides the signed and encrypted digital health information or certificate to the certificate holder through a communication method; and The first software product reads the signed and encrypted digital health information presented by the certificate holder, and uses a public key corresponding to the private key to decrypt the signed and encrypted digital health information or certificate to verify its authenticity and obtain the content of the digital health information or certificate.

根據本發明之部分具體實施例,該伺服器端與一醫療資訊系統(HIS)通訊連接。該數位健康資訊或證書中的相關資料可來自於該醫療資訊系統。一般而言,所述醫療資訊系統儲存有病歷資料(結構化之電子病歷),以及,例如,疫苗接種記錄。According to some specific embodiments of the present invention, the server is connected to a medical information system (HIS). The digital health information or relevant data in the certificate may come from the medical information system. Generally speaking, the medical information system stores medical records (structured electronic medical records) and, for example, vaccination records.

根據本發明之一特定實施例,該數位健康資訊包括嚴重特殊性肺炎(Covid-19)之疫苗注射紀錄及聚合酶連鎖反應(PCR)核酸檢測結果,其中該疫苗注射紀錄對應於現有紙本黃卡。According to a specific embodiment of the present invention, the digital health information includes a COVID-19 vaccination record and a polymerase chain reaction (PCR) nucleic acid test result, wherein the vaccination record corresponds to an existing paper yellow card.

根據本發明之一特定實施例,該數位健康資訊包括兒童疫苗注射紀錄,其中該疫苗注射紀錄對應於兒童健康手冊,亦即提供數位兒童健康手冊。According to a specific embodiment of the present invention, the digital health information includes children's vaccination records, wherein the vaccination records correspond to the children's health handbook, that is, a digital children's health handbook is provided.

本文中所述的「通訊連接」包括但不限於透過網際網路連線。The "communication connection" mentioned in this article includes but is not limited to connection via the Internet.

所述伺服器端可設有一或多個伺服器,且一般而言,所述伺服器端係為一發證方所有,該發證方可為醫療院所或衛生部門。若伺服器端包含複數個伺服器,伺服器可兩兩或彼此電性連接。根據本發明,醫療資訊系統上的各類紀錄及資訊可上傳至該伺服器端,並整合為快速健保互動整合資源(Fast Healthcare Interoperability Resources,FHIR)之資料格式,並儲存於該伺服器端的一或多個伺服器中。The server side may be provided with one or more servers, and generally speaking, the server side is owned by a certificate issuer, which may be a medical institution or a health department. If the server side includes a plurality of servers, the servers may be electrically connected in pairs or to each other. According to the present invention, various records and information on the medical information system may be uploaded to the server side, integrated into the data format of Fast Healthcare Interoperability Resources (FHIR), and stored in one or more servers of the server side.

在本發明的構思中,可由一管理機構負責授權發證方(醫療院所或衛生部門)並控制經由系統提供的健康資訊或證書類型呈現(例如,測試證書的結構、疫苗接種紀錄或證書或其他)。所述管理機構可為一個國家的衛生福利部、地方或國家政府或其他更高級別的醫療健康管理機構。在某些應用場景中,驗證方(例如,商家、出入境管理機構、及其驗證者)需要獲得所述管理機構的許可才能使用系統。In the conception of the present invention, a management agency may be responsible for authorizing the issuing party (medical institution or health department) and controlling the presentation of health information or certificate types provided by the system (e.g., the structure of a test certificate, vaccination record or certificate, or other). The management agency may be a country's Ministry of Health and Welfare, a local or national government, or other higher-level medical and health management agency. In some application scenarios, the verifier (e.g., a merchant, an entry-exit management agency, and its verifier) needs to obtain permission from the management agency before using the system.

所述發證方可為由一健康資訊或證書之管理機構授權得核發特定類型的健康資訊證書的實體。所述類型可包括,例如,疫苗接種證書、COVID-19之PCR 檢測證明、COVID-19痊癒證明、治療方式紀錄及後遺症紀錄…等。發證方可為醫院、篩檢及疫苗接種中心、藥房及類似醫療保健提供者的醫療代表(例如,醫師)。The issuer may be an entity authorized by a health information or certificate management agency to issue a specific type of health information certificate. The types may include, for example, vaccination certificates, COVID-19 PCR test certificates, COVID-19 recovery certificates, treatment records and sequelae records, etc. The issuer may be a medical representative (e.g., a doctor) of a hospital, screening and vaccination center, pharmacy, and similar healthcare providers.

在一些較佳具體實施例中,本發明之數位健康資訊驗證系統可進一步包含一第二軟體產品。該第二軟體產品適於安裝在行動裝置上,並用以顯示經簽署及加密的該數位健康資訊或證書。持證人可在其行動裝置上安裝所述第二軟體產品,並於驗證方需進行相關檢視及驗證時,出示第二軟體產品透過行動裝置的螢幕顯示的數位健康資訊或證書,供驗證方的裝置∕軟體讀取及驗證該數位健康資訊或證書。In some preferred specific embodiments, the digital health information verification system of the present invention may further include a second software product. The second software product is suitable for installation on a mobile device and is used to display the signed and encrypted digital health information or certificate. The holder may install the second software product on his/her mobile device, and when the verifier needs to conduct relevant inspection and verification, the holder may present the digital health information or certificate displayed by the second software product on the screen of the mobile device for the verifier's device/software to read and verify the digital health information or certificate.

較佳地,如上述的經簽署及加密的該數位健康資訊或證書中可含一二維條碼,該二維條碼包括但不限於一QR code。Preferably, the signed and encrypted digital health information or certificate as described above may contain a two-dimensional barcode, which includes but is not limited to a QR code.

所述行動裝置的非限制性實例包括智慧型手錶、智慧型手機及平版電腦。Non-limiting examples of the mobile device include smart watches, smart phones, and tablet computers.

在一實例中,持證人出示智慧型手機上第二軟體產品顯示的QR code(經簽署及加密的該數位健康資訊或證書,由所述伺服器端以一私鑰簽署及加密),驗證方可使用安裝有第一軟體產品的智慧型手機掃描該QR code(讀取數位健康資訊或證書),第一軟體產品再使用對應的公鑰進行解密及驗證其真偽,並可取得數位健康資訊或證書。In one example, the certificate holder presents the QR code displayed by the second software product on the smartphone (the digital health information or certificate that has been signed and encrypted, signed and encrypted by the server with a private key). The verifier can then use the smartphone with the first software product installed to scan the QR code (to read the digital health information or certificate). The first software product then uses the corresponding public key to decrypt and verify its authenticity, and can obtain the digital health information or certificate.

根據本發明之部分具體實施例,所述第二軟體產品可透過行動裝置提供一使用者介面,供持證者進行相關操作,以及出示數位健康資訊或證書。顯示在使用者介面上的數位健康資訊或證書可包括一QR code及一辨識顏色。在一實例中,綠色表示安全(例如,完整接種疫苗或篩檢結果為陰性),而紅色表示有疑慮(例如,未完整接種疫苗或篩檢結果為陽性)。According to some specific embodiments of the present invention, the second software product can provide a user interface through a mobile device for the certificate holder to perform related operations and present digital health information or certificates. The digital health information or certificate displayed on the user interface may include a QR code and an identification color. In one example, green means safe (e.g., complete vaccination or negative screening result), while red means doubtful (e.g., incomplete vaccination or positive screening result).

上述的第一軟體產品及第二軟體產品較佳為行動軟體(App),但不以此為限。例如,第一軟體產品及∕或第二軟體產品亦可為適用於桌上型電腦或筆記型電腦之軟體。The first software product and the second software product are preferably mobile software (App), but are not limited thereto. For example, the first software product and/or the second software product may also be software applicable to a desktop computer or a laptop computer.

較佳地,所述的私鑰及其對應之公鑰係由一可信任的註冊方(trusted registry)發出。更具體而言,所述的私鑰及其對應之公鑰係由該可信任的註冊方之一或多伺服器所發出。所述可信任的註冊方可由一或多個憑證管理中心或機構(certificate authority)組成,其角色是維護及根據請求提供發證方(伺服器端)的公鑰元資料(metadata),以及對疫苗接種證明的安全驗證至關重要的健康資訊或證書撤銷資訊。可信任的註冊方可維護有一可信任的註冊表,該註冊表保存與發證方及數位健康資訊或證書撤銷有關的元資料。可信任的註冊方在獲得適當授權的請求後實施以下功能:發證方(伺服器端)加入,藉由為經授權之發證方建立數位證明,更新經授權之發證方的公開資訊;提供與發證方相關的公開資訊;設置及更新經授權之發證方的健康資訊或證書撤銷列表 (CRL),提供特定發證方的 CRL,設置及更新授權的健康資訊證明類型。Preferably, the private key and its corresponding public key are issued by a trusted registry. More specifically, the private key and its corresponding public key are issued by one or more servers of the trusted registry. The trusted registry may be composed of one or more certificate management centers or institutions (certificate authority), whose role is to maintain and provide public key metadata of the issuer (server side) upon request, as well as health information or certificate revocation information that is critical to the secure verification of vaccination certificates. The trusted registry may maintain a trusted registry that stores metadata related to the issuer and digital health information or certificate revocation. A trusted registrar performs the following functions after receiving a request with appropriate authorization: Issuer (server) joins, updates the public information of authorized issuers by creating digital certificates for authorized issuers; provides public information related to issuers; sets and updates the health information or certificate revocation list (CRL) of authorized issuers, provides CRLs for specific issuers, and sets and updates authorized health information certificate types.

在特定具體實施例中,本發明之數位健康資訊驗證系統可進一步包含可信任的註冊方之一或多伺服器,其與所述數位健康資訊驗證系統之伺服器端及第一軟體產品分別通訊連接,例如,透過網際網路連線。In a specific embodiment, the digital health information verification system of the present invention may further include one or more servers of a trusted registrant, which are respectively communicated with the server side of the digital health information verification system and the first software product, for example, via an Internet connection.

發證方的伺服器端可使用一私鑰對數位健康資訊或證書進行簽署及加密,並藉由一通訊方式將經簽署及加密的數位健康資訊或證書提供予對應的持證人。如上所述,該私鑰可由一可信任的註冊方發出。提供數位健康資訊或證書的通訊方式包括但不限於:電子郵件、手機簡訊或透過行動裝置的App提供(例如,透過第二軟體產品提供)。The server of the issuing party may use a private key to sign and encrypt the digital health information or certificate, and provide the signed and encrypted digital health information or certificate to the corresponding certificate holder through a communication method. As mentioned above, the private key may be issued by a trusted registrant. The communication method for providing digital health information or certificates includes but is not limited to: email, mobile phone text message or through an App on a mobile device (for example, provided through a second software product).

根據本發明,該數位健康資訊或證書可為持證人的疫苗注射紀錄、特定疾病的篩檢紀錄(例如,COVID-19的PCR檢測紀錄)、醫療紀錄、用藥紀錄、病歷或前述資料中二或多者的任意組合。According to the present invention, the digital health information or certificate may be the holder's vaccination record, screening record for a specific disease (e.g., PCR test record for COVID-19), medical record, medication record, medical history, or any combination of two or more of the aforementioned data.

根據本發明之一特定實施例,該數位健康資訊包括由具公信力之醫療單位核發之嚴重特殊性肺炎(Covid-19)之疫苗注射紀錄,快篩結果紀錄及聚合酶連鎖反應(PCR)核酸檢測結果紀錄。According to a specific embodiment of the present invention, the digital health information includes a record of vaccination for severe specific pneumonia (Covid-19) issued by a credible medical unit, a record of rapid screening results, and a record of polymerase chain reaction (PCR) nucleic acid test results.

根據本發明之一特定具體實施例中,該數位健康資訊或證書為嬰幼兒或兒童預防注射紀錄。所述預防注射可包括B型肝炎疫苗、五合一疫苗、卡介苗、流感疫苗及水痘疫苗…等,例如,可參考衛生福利部疾病管制署之現行兒童預防接種時程網頁(https://www.cdc.gov.tw/Category/List/IpWZqtnmkJfQPfgnaP4lnw)。According to a specific embodiment of the present invention, the digital health information or certificate is a record of infant or child vaccination. The vaccination may include hepatitis B vaccine, five-in-one vaccine, BCG vaccine, influenza vaccine, and varicella vaccine, etc. For example, the current child vaccination schedule of the Centers for Disease Control, Ministry of Health and Welfare can be found on the website (https://www.cdc.gov.tw/Category/List/IpWZqtnmkJfQPfgnaP4lnw).

另一方面,本發明提供一種數位健康資訊驗證系統,特別是供現今嚴重特殊性肺炎防疫之需,其包含疫苗注射紀錄、篩檢紀錄、醫療病歷等數位資料之保存及交換,可擴充至各種疫苗及使用者健康數據資料之交換平台,甚至與國際接軌。具體而言,本發明提供一種數位健康資訊驗證系統,包含使用者資料、病歷、疫苗注射紀錄、篩檢紀錄、查詢模組、資料交換模組、資料庫及大數據分析中心系統。On the other hand, the present invention provides a digital health information verification system, especially for the current severe special pneumonia epidemic prevention needs, which includes the preservation and exchange of digital data such as vaccination records, screening records, and medical records, which can be expanded to various vaccine and user health data exchange platforms, and even connected with the international. Specifically, the present invention provides a digital health information verification system, including user data, medical records, vaccination records, screening records, query modules, data exchange modules, databases, and big data analysis center systems.

又一方面,本發明提供一種數位健康資訊驗證系統,包含一伺服器、一行動裝置、一終端機及一資料庫;其中該終端機將使用者資料、病歷、疫苗注射紀錄、篩檢紀錄等上傳該伺服器,經整合後存入該資料庫中,透過該行動裝置介面提出查詢要求,以該查詢模組進行查詢後查詢結果傳回該行動裝置,且其中上傳資料經該資料交換模組與一國際疫苗護照系統資料交換,數據並可由大數據分析中心分析。On the other hand, the present invention provides a digital health information verification system, comprising a server, a mobile device, a terminal and a database; wherein the terminal uploads user data, medical records, vaccination records, screening records, etc. to the server, which are integrated and stored in the database, and a query request is made through the mobile device interface, and the query module performs the query and the query result is returned to the mobile device, and the uploaded data is exchanged with an international vaccine passport system through the data exchange module, and the data can be analyzed by a big data analysis center.

根據本發明之部分具體實施例,所述數位健康資訊驗證系統之數位資料可供保存及交換。根據本發明之部分具體實施例,使用者(持證者)以該行對裝置下載App介面操作。根據本發明之部分具體實施例,是否疫苗注射紀錄查詢結果得以顏色區分表示是否符合規範。根據本發明之部分具體實施例,所述數位健康資訊驗證系統可進一步包含是否感染之篩檢紀錄,包括快篩紀錄及聚合酶連鎖反應(PCR)核酸檢測結果紀錄。根據本發明之部分具體實施例,所述系統可視需要包含使用者之疫苗注射紀錄、篩檢紀錄、醫療紀錄、用藥紀錄及病歷治療紀錄、用藥紀錄或病歷。根據本發明之部分具體實施例,所述系統可進一步包含使用者之足跡紀錄。根據本發明之部分具體實施例,所述系統可進一步包含使用者之實聯制紀錄。According to some specific embodiments of the present invention, the digital data of the digital health information verification system can be stored and exchanged. According to some specific embodiments of the present invention, the user (certificate holder) uses the line to download the App interface operation to the device. According to some specific embodiments of the present invention, the result of the vaccination record query can be color-coded to indicate whether it meets the standards. According to some specific embodiments of the present invention, the digital health information verification system can further include screening records of infection, including rapid screening records and polymerase chain reaction (PCR) nucleic acid test result records. According to some specific embodiments of the present invention, the system may include the user's vaccination record, screening record, medical record, medication record and medical history treatment record, medication record or medical history as needed. According to some specific embodiments of the present invention, the system may further include the user's footprint record. According to some specific embodiments of the present invention, the system may further include the user's physical contact record.

根據本發明,為因應未來國人出國需出示施打嚴重特殊性肺炎(Covid-19)疫苗接種紀錄卡之需求,在既有的技術架構之下,結合HIS中的新冠肺炎疫苗接種紀錄平台、國際醫療資料交換標準FHIR技術等創新技術,甚至利用安全的區塊鏈技術紀錄,建立出國內首款健康資訊驗證系統,可提供作為疫苗護照App,其使用應用情境包括醫院端、使用者端、查驗端等3個測試場景,該App亦可整合至醫院的預約掛號App內,提供民眾出示COVID-19疫苗注射紀錄證明之用。亦或與各衛生局、醫療機構及健保資料結合提供數位兒童健康手冊。According to the present invention, in order to meet the need for Taiwanese to present COVID-19 vaccination record cards when traveling abroad in the future, the existing technical framework is combined with the COVID-19 vaccination record platform in HIS, the international medical data exchange standard FHIR technology and other innovative technologies, and even the use of secure blockchain technology records to establish the first health information verification system for traveling abroad. It can be used as a vaccine passport App, and its application scenarios include three test scenarios such as the hospital side, the user side, and the inspection side. The App can also be integrated into the hospital's appointment registration App to provide citizens with proof of COVID-19 vaccination records. Or it can be combined with various health bureaus, medical institutions and health insurance data to provide a digital child health handbook.

現參照圖1說明本發明之數位健康資訊驗證系統的一具體實施例如下。A specific implementation example of the digital health information verification system of the present invention is described below with reference to FIG1 .

如圖1所示,用以促成持證人取得驗證方之驗證的數位健康資訊驗證系統包含:伺服器端100、第一軟體產品200及第二軟體產品300。屬於發證方所有的伺服器端100由彼此(直接或間接)電性連接的複數個伺服器所組成,並儲存有持證人的數位健康資訊或證書,其資料係來自發證方(例如,醫療院所或衛生部門)。第一軟體產品200係供驗證方使用,且與可信任的註冊方之伺服器400通訊連接。第二軟體產品300安裝於持證人持有的行動裝置(圖中未示)。伺服器端100則分別與第二軟體產品300及可信任的註冊方之伺服器400通訊連接。As shown in FIG1 , the digital health information verification system for facilitating the holder to obtain verification from the verifier includes: a server 100, a first software product 200, and a second software product 300. The server 100, which belongs to the issuing party, is composed of a plurality of servers electrically connected to each other (directly or indirectly), and stores the digital health information or certificate of the holder, whose data comes from the issuing party (e.g., a medical institution or health department). The first software product 200 is for use by the verifier and is connected to the server 400 of the trusted registrant. The second software product 300 is installed on the mobile device held by the holder (not shown in the figure). The server end 100 is connected to the second software product 300 and the server 400 of the trusted registrant for communication.

伺服器端100向可信任的註冊方之伺服器400取得一私鑰,並使用該私鑰對持證人的數位健康資訊或證書進行簽署及加密。接著,伺服器端100透過第二軟體產品300將經簽署及加密的該數位健康資訊或證書提供予持證人。The server 100 obtains a private key from a trusted registrant's server 400 and uses the private key to sign and encrypt the digital health information or certificate of the certificate holder. Then, the server 100 provides the signed and encrypted digital health information or certificate to the certificate holder through the second software product 300.

當有需要時,持證人可使用其行動裝置,於第二軟體產品300的使用者介面進行操作,向驗證方的查驗人員出示數位健康資訊或證書,其包括一QR code。驗證方的查驗人員可使用一掃描裝置或具有照像功能的行動裝置掃描該QR code,使第一軟體產品200可讀取經簽署及加密的該數位健康資訊或證書。另外,第一軟體產品200向可信任的註冊方之伺服器400取得對應上述私鑰之公鑰,並使用該公鑰對經簽署及加密的該數位健或證書康資訊或證書進行解密,以驗證其真偽並取得該數位健康資訊或證書。When necessary, the certificate holder can use his mobile device to operate on the user interface of the second software product 300 to show the digital health information or certificate, which includes a QR code, to the verification personnel of the verification party. The verification personnel of the verification party can use a scanning device or a mobile device with a camera function to scan the QR code so that the first software product 200 can read the signed and encrypted digital health information or certificate. In addition, the first software product 200 obtains the public key corresponding to the above-mentioned private key from the server 400 of the trusted registrant, and uses the public key to decrypt the signed and encrypted digital health information or certificate to verify its authenticity and obtain the digital health information or certificate.

現參照圖2說明本發明之用以促成持證人取得驗證方之驗證之方法的一具體實施例如下。A specific implementation example of the method of the present invention for facilitating a certificate holder to obtain certification by a certifying party is described below with reference to FIG. 2 .

首先,提供伺服器端及第一軟體產品,伺服器端儲存有持證人的數位健康資訊或證書,第一軟體產品則供該驗證方進行查驗時使用(步驟S110)。First, a server and a first software product are provided. The server stores the digital health information or certificate of the certificate holder, and the first software product is used by the verification party for verification (step S110).

屬於發證方所有的伺服器端可由彼此(直接或間接)電性連接的複數個伺服器所組成,且其儲存的數位健康資訊或證書係來自發證方(例如,醫療院所或衛生部門)。第一軟體產品與可信任的註冊方之伺服器通訊連接。另可提供第二軟體產品,安裝於持證人持有的行動裝置。伺服器端分別與第二軟體產品及可信任的註冊方之伺服器通訊連接。The server side owned by the certificate issuer may be composed of multiple servers that are electrically connected to each other (directly or indirectly), and the digital health information or certificates stored therein are from the certificate issuer (e.g., a medical institution or health department). The first software product communicates with the server of the trusted registrant. A second software product may also be provided and installed on the mobile device held by the certificate holder. The server side communicates with the second software product and the server of the trusted registrant respectively.

伺服器端向可信任的註冊方之伺服器取得私鑰後,可使用私鑰對數位健康資訊或證書進行簽署及加密,並藉由一通訊方式(透過第二軟體產品)將經簽署及加密的該數位健康資訊或證書提供予該持證人(步驟S120)。After the server obtains the private key from the trusted registrant's server, it can use the private key to sign and encrypt the digital health information or certificate, and provide the signed and encrypted digital health information or certificate to the certificate holder via a communication method (through the second software product) (step S120).

接著,驗證方可要求持證人提供數位健康資訊或證書,並使用第一軟體產品讀取該持證人出示之該數位健康資訊或證書,並使用對應於該私鑰的公鑰(從可信任的註冊方取得)進行解密,以驗證其真偽並取得數位健康資訊或證書之內容(步驟S130)。Next, the verifier may request the certificate holder to provide digital health information or certificate, and use the first software product to read the digital health information or certificate presented by the certificate holder, and use the public key corresponding to the private key (obtained from a trusted registrant) to decrypt it to verify its authenticity and obtain the content of the digital health information or certificate (step S130).

實例1:COVID-19數位疫苗注射紀錄證書Example 1: COVID-19 digital vaccination record certificate

數位健康資訊驗證系統涉及角色可包括持證人(Holder)、可信任的註冊方(例如,憑證中心(CA))及驗證方(Verifier),在本實例中,其相關作業或動作之時序如下: 1.       CA:處理Issuer的私鑰及公鑰並儲存白名單; 2.       驗證方(Verifier)間隔24小時向CA索取並更新公鑰清單,以離線驗證數位疫苗注射紀錄之證書; 3.       持證人(Holder)出示數位疫苗注射紀錄之證書供Verifier 掃描查驗內容; 4.       Verifier 根據發行數位疫苗注射紀錄之證書的發證方(Issuer)之簽章邏輯辨識資料封包(Payload),識別成功將能查驗數位疫苗注射紀錄之持證人(Holder)之個人基本資訊、注射紀錄、篩檢紀錄;及 5.       謹慎起見,可以請持證人出示個人身份證件,雙重查核數位疫苗注射紀錄之證書識別之個人資訊。 The roles involved in the digital health information verification system may include the holder, the trusted registrant (e.g., the certification authority (CA)) and the verifier. In this example, the sequence of related operations or actions is as follows: 1.       CA: processes the Issuer's private key and public key and stores the whitelist; 2.       The Verifier requests and updates the public key list from the CA every 24 hours to verify the certificate of the digital vaccination record offline; 3.       The holder presents the certificate of the digital vaccination record for the Verifier to scan and verify the content; 4.       Verifier According to the signature logic of the issuer of the digital vaccination record certificate, the data package (Payload) is identified. If the identification is successful, the basic personal information, injection record, and screening record of the holder of the digital vaccination record (Holder) can be checked; and 5.       For the sake of caution, the holder can be asked to show his personal identity document to double-check the personal information identified by the digital vaccination record certificate.

持證人(Holder)可下載並安裝疫苗護照應用程式(App)(第二軟體產品),同時持證人的疫苗注射紀錄也將從HIS系統內透過資料標準化API進入FHIR伺服器,這時持證人手機的數位健康資訊驗證系統之護照App將以FHIR API將相關資料呈現於手機介面上,此時經過數位化的COVID-19疫苗接種紀錄卡資料就以QR code呈現於手機App介面,使用者可透過掃描認證QR code呈現已接種的疫苗紀錄資訊並核准進出管制場所。The holder can download and install the vaccine passport application (App) (second software product). At the same time, the holder's vaccination records will also enter the FHIR server from the HIS system through the data standardization API. At this time, the passport app of the digital health information verification system on the holder's mobile phone will use the FHIR API to present the relevant data on the mobile phone interface. At this time, the digitized COVID-19 vaccination record card data will be presented in the form of a QR code on the mobile app interface. Users can scan and authenticate the QR code to present the vaccination record information and approve entry and exit of controlled places.

如圖3A所示,疫苗護照App(第二軟體產品)可顯示持證人(Holder)資料及疫苗注射之紀錄,進一步可再點選每次疫苗注射之紀錄,以顯示詳細資訊(參見圖3B)。此外,疫苗護照App(第二軟體產品)亦可包含篩檢紀錄,如圖4所示。As shown in Figure 3A, the Vaccine Passport App (second software product) can display the holder's information and vaccination records, and further click on the record of each vaccination to display detailed information (see Figure 3B). In addition, the Vaccine Passport App (second software product) can also include screening records, as shown in Figure 4.

發證方(Issuer)(醫療院所、衛生部門)核發之數位疫苗注射紀錄之證書以FHIR 資料格式保存於資料庫(伺服器端),於日後跨醫療院所、國際醫療資訊交換,及其醫療資訊應用平台整合使用。首先將FHIR文件以簡明二進制表示法包裝(CBOR),而後CA(PKI)憑證中心提供X509 憑證私鑰將CBOR物件簽署和加密(COSE),產生COSE文件。使用Zlib將COSE文件壓縮,再將此壓縮資料轉換Base45格式,產成數位疫苗注射證書之QR code。此數位疫苗注射證書之QR code 無法於一般QR掃描器識別內容,需使用此平台驗證應用程式(Verifier App) 才能辨別真偽及查驗內容。Verifier App 於每日向CA(PKI)憑證中心更新公鑰名單,即可離線驗證之持證人(Holder)持有之數位疫苗證書。The digital vaccination record certificate issued by the issuer (Issuer) (medical institution, health department) is stored in the database (server side) in the FHIR data format, and will be integrated and used across medical institutions, international medical information exchange, and medical information application platforms in the future. First, the FHIR file is packaged in concise binary representation (CBOR), and then the CA (PKI) certificate center provides the X509 certificate private key to sign and encrypt the CBOR object (COSE) to generate a COSE file. Use Zlib to compress the COSE file, and then convert the compressed data to Base45 format to generate the QR code of the digital vaccination certificate. The QR code of this digital vaccination certificate cannot be recognized by ordinary QR scanners. You need to use this platform verification application (Verifier App) to identify the authenticity and verify the content. The Verifier App updates the public key list to the CA (PKI) certificate center every day, and can verify the digital vaccination certificate held by the holder offline.

驗證方App(第一軟體產品)前端提供掃描及驗證數位疫苗證明的功能,其掃描base45編碼的QR code,提取 COSE簽名,並將 CBOR 解碼回 JSON 格式。然後使用CA(PKI)憑證中心提供的公鑰驗證COSE簽名,並驗證CBOR內容。所有掃描或處理的數位疫苗證書不會存儲於驗證方裝置。在標準驗證工作流程中僅會最小限度地向驗證方App(第一軟體產品)的使用者顯示訊息。在成功驗證的情況下,訊息應僅限於表明真實性及有效性已被成功驗證(以綠色表示),並且顯示持證人之最小個人訊息,以及疫苗施打、採檢證明之訊息。如果驗證失敗(以紅色表示),驗證方App(第一軟體產品)只顯示失敗的原因。The front end of the Verifier App (the first software product) provides the function of scanning and verifying digital vaccine certificates. It scans the base45-encoded QR code, extracts the COSE signature, and decodes the CBOR back to JSON format. The COSE signature is then verified using the public key provided by the CA (PKI) certificate center, and the CBOR content is verified. All scanned or processed digital vaccine certificates will not be stored on the Verifier device. In the standard verification workflow, only minimal messages will be displayed to users of the Verifier App (the first software product). In the case of successful verification, the message should be limited to indicating that the authenticity and validity have been successfully verified (indicated in green), and displaying the certificate holder's minimal personal information, as well as information on vaccination and testing certificates. If the verification fails (indicated by red), the Verifier App (First Software Product) only displays the reason for the failure.

本發明系統中之數位健康資訊可透過以w3c開放標準為基礎的去中心化身份架構,重新構想如何交換人與人的健康資訊數據。與傳統數據交換不同(個人提供同意分享的資訊,但根本上將其個資排除在數據交換之外),分散的身份架構允許個人成為積極的參與者,使他們可以控制自己的數據,並由代理機構選擇如何進行數據交換。分散的身份可以使組織可以向個人發布可驗證的數據,該個人可以共享該數據或子集,並且可以由接收組織來驗證有效性。通過嚴格的管理實踐和簽名驗證,可以通過分散式記帳本來實現對交換數據的信任。Digital health information in the system of the present invention can reimagine how health information data is exchanged between people through a decentralized identity architecture based on w3c open standards. Unlike traditional data exchange (individuals provide information that they agree to share, but their personal information is fundamentally excluded from the data exchange), a decentralized identity architecture allows individuals to become active participants, allowing them to control their own data and let the agency choose how the data is exchanged. Decentralized identity allows organizations to issue verifiable data to individuals, who can share that data or a subset, and the validity can be verified by the receiving organization. Trust in the exchanged data can be achieved through a decentralized ledger through strict management practices and signature verification.

隨著國內嚴重特殊性肺炎疫苗的全面施打,在可預見的未來各國間進行階段性的解封後,許多人可能需要證明自己的健康狀況或依苗注射紀錄,或於出國洽公或旅遊前,在返回學校校園、工作場所、搭機、入境或減少隔離時間之需,可以利用本發明健康護照系統出示自己的數位疫苗注射紀錄或篩檢結果,本發明健康護照系統可發揮其用途提供便利的驗證方式。With the full implementation of the COVID-19 vaccine in the country, after the phased lifting of lockdowns between countries in the foreseeable future, many people may need to prove their health status or vaccination records, or before going abroad for business or travel, when returning to school, workplace, flying, entering the country, or reducing the need for isolation time, they can use the health passport system of the present invention to present their digital vaccination records or screening results. The health passport system of the present invention can play its role in providing a convenient verification method.

100:伺服器端 200:第一軟體產品 300:第二軟體產品 400:可信任的註冊方 S110~S130:步驟 100: Server side 200: First software product 300: Second software product 400: Trusted registrant S110~S130: Steps

圖1為根據本發明之數位健康資訊驗證系統的一具體實施例所繪示的系統架構圖。FIG1 is a system architecture diagram illustrating a specific implementation example of the digital health information verification system of the present invention.

圖2為根據本發明之用以促成一持證人取得一驗證方之驗證之方法的一具體實施例所繪示的流程圖。FIG. 2 is a flow chart showing a specific embodiment of the method for facilitating a certificate holder to obtain certification from a certifying party according to the present invention.

圖3A為第二軟體產品之使用者介面示意圖,其顯示數位健康證書及持證人資料等資訊。FIG3A is a schematic diagram of the user interface of the second software product, which displays information such as the digital health certificate and the certificate holder's information.

圖3B為第二軟體產品之使用者介面示意圖,其顯示特定疫苗注射紀錄之檢視。FIG3B is a schematic diagram of the user interface of the second software product, which shows the review of a specific vaccination record.

圖4為第二軟體產品之使用者介面示意圖,其顯示各種畫面及紀錄,包括疫苗紀錄及篩檢紀錄。FIG4 is a schematic diagram of the user interface of the second software product, which displays various screens and records, including vaccination records and screening records.

without

100:伺服器端 100: Server side

200:第一軟體產品 200: First software product

300:第二軟體產品 300: Second software product

400:可信任的註冊方 400: Trusted registrant

S110~S130:步驟 S110~S130: Steps

Claims (4)

一種數位健康資訊驗證系統,用以促成一持證人取得一驗證方之驗證,該數位健康資訊驗證系統包含:一醫療資訊系統,儲存有該持證人的一數位健康資訊或證書;及一第一軟體產品,安裝於該驗證方持有的一行動裝置,並用以讀取及驗證該數位健康資訊或證書;一第二軟體產品,安裝於該持證人持有的一行動裝置,並用以儲存及顯示該數位健康資訊或證書;其中:該醫療資訊系統使用一私鑰對該數位健康資訊或證書進行簽署及加密,並藉由一通訊方式將經簽署及加密的該數位健康資訊或證書提供予該持證人;該第一軟體產品讀取該持證人出示之經簽署及加密的該數位健康資訊或證書,並使用對應於該私鑰的一公鑰對經簽署及加密的該數位健康資訊或證書進行解密,以驗證其真偽並取得該數位健康資訊或證書之內容;該數位健康資訊或證書之資料來自於該醫療資訊系統,包括該持證人的疫苗注射紀錄、篩檢紀錄、醫療紀錄、用藥紀錄、病歷或前述之任意組合。 A digital health information verification system is used to facilitate a certificate holder to obtain verification from a verification party, the digital health information verification system comprising: a medical information system storing the digital health information or certificate of the certificate holder; and a first software product installed on a mobile device held by the verification party and used to read and verify the digital health information or certificate; a second software product installed on a mobile device held by the certificate holder and used to store and display the digital health information or certificate; wherein: the medical information system uses a private key to sign and encrypt the digital health information or certificate , and provide the signed and encrypted digital health information or certificate to the holder through a communication method; the first software product reads the signed and encrypted digital health information or certificate presented by the holder, and uses a public key corresponding to the private key to decrypt the signed and encrypted digital health information or certificate to verify its authenticity and obtain the content of the digital health information or certificate; the data of the digital health information or certificate comes from the medical information system, including the holder's vaccination record, screening record, medical record, medication record, medical history or any combination of the foregoing. 如請求項1所述之數位健康資訊驗證系統,其中經簽署及加密的該數位健康資訊或證書包括一二維條碼。 A digital health information verification system as described in claim 1, wherein the signed and encrypted digital health information or certificate includes a two-dimensional barcode. 一種用以促成一持證人取得一驗證方之驗證之方法,其包含:提供一醫療資訊系統,儲存有該持證人的一數位健康資訊或證書;提供一第一軟體產品,安裝於該驗證方持有的一行動裝置,並用以讀取及驗證該數位健康資訊或證書; 提供一第二軟體產品,安裝於該持證人持有的一行動裝置,並用以儲存及顯示該數位健康資訊或證書;該醫療資訊系統使用一私鑰對該數位健康資訊或證書進行簽署及加密,並藉由一通訊方式將經簽署及加密的該數位健康資訊或證書提供予該持證人;及該第一軟體產品讀取該持證人出示之經簽署及加密的該數位健康資訊或證書,並使用對應於該私鑰的一公鑰對經簽署及加密的該數位健康資訊或證書進行解密,以驗證其真偽並取得該數位健康資訊或證書之內容;其中該數位健康資訊或證書之資料來自於該醫療資訊系統,包括該持證人的疫苗注射紀錄、篩檢紀錄、醫療紀錄、用藥紀錄、病歷或前述之任意組合。 A method for facilitating a certificate holder to obtain a certificate from a verification party, comprising: providing a medical information system storing digital health information or a certificate of the certificate holder; providing a first software product installed on a mobile device held by the verification party and used to read and verify the digital health information or certificate; providing a second software product installed on a mobile device held by the certificate holder and used to store and display the digital health information or certificate; the medical information system uses a private key to sign and encrypt the digital health information or certificate, and uses a communication method to The signed and encrypted digital health information or certificate is provided to the certificate holder; and the first software product reads the signed and encrypted digital health information or certificate presented by the certificate holder, and uses a public key corresponding to the private key to decrypt the signed and encrypted digital health information or certificate to verify its authenticity and obtain the content of the digital health information or certificate; wherein the data of the digital health information or certificate comes from the medical information system, including the certificate holder's vaccination record, screening record, medical record, medication record, medical history or any combination of the foregoing. 如請求項3所述之方法,其中經簽署及加密的該數位健康資訊或證書包括一二維條碼。 The method as described in claim 3, wherein the signed and encrypted digital health information or certificate includes a two-dimensional barcode.
TW111123120A 2021-06-21 2022-06-21 System and method for digital health information verification TWI845966B (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
TW110122656 2021-06-21
TW110122656 2021-06-21

Publications (2)

Publication Number Publication Date
TW202301365A TW202301365A (en) 2023-01-01
TWI845966B true TWI845966B (en) 2024-06-21

Family

ID=86658179

Family Applications (2)

Application Number Title Priority Date Filing Date
TW111123120A TWI845966B (en) 2021-06-21 2022-06-21 System and method for digital health information verification
TW111206559U TWM639583U (en) 2021-06-21 2022-06-21 Digital health information verification system

Family Applications After (1)

Application Number Title Priority Date Filing Date
TW111206559U TWM639583U (en) 2021-06-21 2022-06-21 Digital health information verification system

Country Status (1)

Country Link
TW (2) TWI845966B (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI845966B (en) * 2021-06-21 2024-06-21 臺北榮民總醫院 System and method for digital health information verification
TWI831646B (en) * 2023-03-15 2024-02-01 臺灣網路認證股份有限公司 Certificate issuance and document signing system and method thereof
TWI858927B (en) * 2023-09-19 2024-10-11 國泰金融控股股份有限公司 Systems and methods for implementing medical data exchange and claims settlement

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI242966B (en) * 2004-05-25 2005-11-01 Chung Shan Inst Of Science Security transmitting method and system of digital medical information
US8498941B2 (en) * 2000-07-06 2013-07-30 David Paul Felsher Information record infrastructure, system and method
TWI614636B (en) * 2013-06-10 2018-02-11 Jie Chen Content verification method based on digital signature code
US9928379B1 (en) * 2008-09-08 2018-03-27 Steven Miles Hoffer Methods using mediation software for rapid health care support over a secured wireless network; methods of composition; and computer program products therefor
WO2020000825A1 (en) * 2018-06-28 2020-01-02 平安科技(深圳)有限公司 Medical treatment data processing method and system, computer device and readable storage medium
TW202020889A (en) * 2018-11-28 2020-06-01 臺北醫學大學 Method and system for sharing electronic medical and health records
TWM639583U (en) * 2021-06-21 2023-04-11 臺北榮民總醫院 Digital health information verification system

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8498941B2 (en) * 2000-07-06 2013-07-30 David Paul Felsher Information record infrastructure, system and method
TWI242966B (en) * 2004-05-25 2005-11-01 Chung Shan Inst Of Science Security transmitting method and system of digital medical information
US9928379B1 (en) * 2008-09-08 2018-03-27 Steven Miles Hoffer Methods using mediation software for rapid health care support over a secured wireless network; methods of composition; and computer program products therefor
TWI614636B (en) * 2013-06-10 2018-02-11 Jie Chen Content verification method based on digital signature code
WO2020000825A1 (en) * 2018-06-28 2020-01-02 平安科技(深圳)有限公司 Medical treatment data processing method and system, computer device and readable storage medium
TW202020889A (en) * 2018-11-28 2020-06-01 臺北醫學大學 Method and system for sharing electronic medical and health records
TWM639583U (en) * 2021-06-21 2023-04-11 臺北榮民總醫院 Digital health information verification system

Also Published As

Publication number Publication date
TWM639583U (en) 2023-04-11
TW202301365A (en) 2023-01-01

Similar Documents

Publication Publication Date Title
TWI845966B (en) System and method for digital health information verification
US20210287770A1 (en) Electronic patient credentials
US10923216B1 (en) Health status system, platform, and method
CA3013603C (en) Dynamically managing exchanges of data using a distributed ledger and homomorphic commitments
US11335441B2 (en) Health safety system, service, and method
CN109509287B (en) Electronic voting system and control method
US12074973B2 (en) Digital notarization using a biometric identification service
US20160020909A1 (en) A method, a system, a computer system and a computer program product for certifying a procedure of signature of an electronic file relating to an agreement between at least two parties
EP3429122A1 (en) Methods and apparatuses for controlling electronic voting
US11503026B2 (en) Email address with identity string and methods of use
WO2021203064A1 (en) Systems and methods for accelerated epidemic recovery
US20130036057A1 (en) Web-based electronic controlled substance transfer management system and method
US9218589B2 (en) Issuance, conveyance and management of endorsements
KR20220128813A (en) Method and system for providing certification of vaccination and follow-up after vaccination
US20240314562A1 (en) Information processing device and method, and program
EP1938505A1 (en) Method, apparatus and system for generating a digital signature linked to a biometric identifier
US11968526B2 (en) Identity management on a mobile device
US20230326611A1 (en) Systems and methods for controlling illness risk information
US20240106834A1 (en) Computer-readable recording medium storing information management program, information management method, information processing device, and information sharing system
JP2002139997A (en) Electronic stamping system
Sadikin et al. Implementing digital signature for the secure electronic prescription using QR-code based on android smartphone
ES2200853T3 (en) METHOD, ARTICLE AND APPLIANCE TO REGISTER EMPADRONATED, SUCH AS EMBEDDED VOTERS.
WO2023233173A1 (en) Implementing self-sovereign identity (ssi) based on configurable individual profiles generated real-time from private attributes stored in the personal secure elements of the users
KR102478963B1 (en) A system and method for issuing and verifying digital vaccination certificates
EP3890237A1 (en) Personal data ecosystems