Skip to main content
. 2022 Jul 11;12(7):e057281. doi: 10.1136/bmjopen-2021-057281

Table 2.

List of roles, functions and data rights of the main institutions in the system

Main institutions (node) The role Function Main rights for personal data, blockchain
Municipal government System design, construction and maintenance
  • Establish standard specifications for system operation and use.

  • Lead the implementation of system networking and management networks.

  • Establish various institutions and the corresponding subrole classification authority directory, and implement and supervise them, and punish illegal institutions.

  • Develop personal privacy (sensitive) information encryption methods and personal identity dynamic anonymous identifier and use key database, spatial location dynamic anonymous identifier and use key database. Provide different dynamic anonymous identifier and use key databases about personal identity and spatial location for different units.

  • Build and manage all kinds of dynamic anonymous identifier and use key database, backup public cloud systems, record blockchain and use blockchain systems, but cannot directly call (query) to the record blockchain and the use blockchain.

District-level government System operation and use
  • According to the role authorisation, use the personal identity dynamic anonymous identifier database and the spatial location dynamic anonymous identifier database provided by the municipal government, compare the personal record information by storing your personal mobile phone (health code) with the backup cloud and write to the blockchain through the personal identity information desensitisation.

  • Monitor and manage the antiepidemic situation in the region according to the role authorisation.

  • Use smart contracts to release information and requirements such as the epidemic and personal vaccination to the holder, and dynamically adjust the holder's personal health code.

  • According to the role authorisation, in cooperation with health departments, use smart contracts to use record blockchain to carry out vaccine effectiveness monitoring and relevant scene application.

  • Write the usage of the holder’s personal records into the record blockchain.

  • Establish two types of blocks (the record blockchain and the use blockchain).

  • Use various personal data in the record blockchain based on two types of use key databases according to the antiepidemic emergency.

  • Cannot directly access personal privacy information.

Health departments, medical (scientific research) institutions, etc System operation and use
  • Monitor the holder’s health, vaccination status according to the role authorisation and combined with the health code, and feed it back to the holder’s personal mobile phone (health code).

  • Use personal identity dynamic anonymous identifier database provided by the municipal government to upload personal identifiable information after desensitisation of health and vaccination information to a separate public cloud for backup.

  • According to the role authorisation, with the cooperation of district-level governments, carry out epidemic prevention and control, and use the smart contract and the record blockchain to carry out the vaccine effectiveness monitoring and the application of relevant scenarios.

  • Write the usage of the holder’s personal records into the record blockchain.

  • Provide desensitisation personal health and vaccination record information.

  • Use various personal data in the record blockchain based on two types of use key databases according to the antiepidemic emergency.

  • Cannot directly access personal privacy information.

Transportation departments (communication departments, social institutions), etc System operation
  • Use health code and other methods to collect the action trajectory (protection status) of the holder based on the role authorisation, and feedback to the public’s personal mobile phone (health code).

  • Use the personal identity dynamic anonymous identifier and spatial location dynamic anonymous identifier database provided by the municipal government to upload the action trajectory and protection status of the holder’s personal identity information and spatial location information after desensitisation to a separate public cloud for backup, and shall not retain the record information.

  • Provide record information on personal action trajectory after desensitisation.

Internet (blockchain, big data) companies System technical support and maintenance
  • Provide and update various technical support required by the system to maintain its normal operation.

  • Provide training for system users (holders).

Person System use and supervision
  • Monitor own health status and action trajectory (protection status) using health code.

  • Use mobile phone (health code) to receive personal health and action trajectory information collected by relevant departments and institutions, and to manage all kinds of encrypted personal information.

  • Use smart contracts to know the epidemic dynamics and take corresponding epidemic prevention measures.

  • Use smart contracts to master the use of personal record information, especially privacy (sensitive) information, and report relevant problems to the special supervisory organisation.

  • Access personal data in various public clouds.

  • Access the individual-related data in the record blockchain and the use blockchain.

  • Can question the correction of the personal data in the public cloud and in the record blockchain, and request an amendment.

Specialised supervisory organisation System supervision
  • Supervise the whole system according to the role authorisation to ensure the safe operation of the system.

  • Supervise the illegal authorisation of all institutions.

  • Accept the holder’s request to investigate the illegal use of personal information and report the findings to the municipal government.

  • Supervise and question the illegal use of personal data, the record blockchain and the use blockchain.