Emergency information management system and method based on mobile internet and two-dimensional code

Through dynamic data management and multi-dimensional security verification based on mobile Internet and QR codes, the information lag and security defects of traditional first aid information management system are solved, and the end-to-end trusted first aid information channel is realized, improving the accuracy and safety of pre-hospital first aid.

CN120433929APending Publication Date: 2025-08-05QINGDAO WEIDA SPORT CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510698231.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

There are defects such as information lag, privacy leakage and physical media vulnerability in traditional first aid information management systems, and it is impossible to break through the static data management paradigm.

Method used

The first aid information management method based on mobile Internet and QR code is adopted, and dynamic data management and multi-dimensional security verification are realized through dynamic UUID generation and encryption, dynamic QR code generation, near-field environment verification, and anti-copy and concurrency control.

Benefits of technology

Build an end-to-end trusted first aid information channel to ensure that first aid personnel can instantly obtain the latest medical files, improve the accuracy and integrity of pre-hospital first aid, prevent information lag and security defects, and have strong anti-attack capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433929A_ABST
    Figure CN120433929A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of first-aid information management, and discloses a first-aid information management system and method based on a mobile internet and a two-dimensional code, and the method comprises the following steps: obtaining a unique identifier of equipment from a security chip, generating a dynamic encryption UUID through a hybrid encryption algorithm in combination with a precise timestamp and geocoding data, and storing the dynamic encryption UUID in the security chip; a key derivation technology is adopted to ensure that each session key is independent, and finally a standardized encrypted identifier is output; the encrypted UUID, the timestamp and the metadata of the authority level are integrated with the digital signature, and the dynamic two-dimensional code containing the ultraviolet mark is generated through serialized coding, error correction enhancement and physical anti-counterfeiting processing. Through deep fusion of dynamic data anchoring and multi-dimensional security verification, an end-to-end trusted first-aid information channel is constructed, and information lag and security defects of a traditional static management mode are effectively overcome.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of emergency information management, and more specifically, to an emergency information management system and method based on mobile Internet and QR codes. Background Art

[0002] As campus safety issues become increasingly prominent, defects in traditional emergency information management, such as information lag, privacy leakage, and fragility of physical media, have seriously restricted the timeliness of emergency response.

[0003] At the same time, existing emergency information management systems mostly use static QR codes or physical cards as carriers, which have significant defects and cannot break through the static data management paradigm. Summary of the Invention

[0004] The present invention provides an emergency information management system and method based on mobile Internet and QR codes, which solves the technical problem that related technologies mostly use static QR codes or physical cards as carriers, have significant defects, and cannot break through the static data management paradigm.

[0005] The present invention provides a method for managing emergency information based on mobile Internet and QR code, comprising the following steps:

[0006] S100, dynamic UUID generation and encryption: obtains the device's unique identifier from the security chip, combines it with precise timestamp and geocoding data, generates a dynamic encrypted UUID through a hybrid encryption algorithm, and uses key derivation technology to ensure that each session key is independent, ultimately outputting a standardized encrypted identifier;

[0007] S200, dynamic QR code generation: This integrates the encrypted UUID, timestamp, and permission level metadata with the digital signature, and then undergoes serialization encoding, error correction enhancement, and physical anti-counterfeiting processing to generate a dynamic QR code with an embedded UV marker.

[0008] S300, near-field environment verification: Analyzes the QR code content in real time upon scanning, strictly verifies time validity, geographic location consistency, data integrity, and request uniqueness, and blocks access attempts in unconventional environments through a four-factor joint authentication mechanism;

[0009] S400, anti-duplication and concurrency control: Detects abnormal concurrent behavior based on request fingerprint characteristics, immediately abolishes the risky UUID and triggers secondary authentication with a dynamic verification code. At the same time, the attack characteristics are recorded in the distributed audit chain, achieving millisecond-level attack interception and tracing capabilities.

[0010] Furthermore, in S100, the following steps are specifically included:

[0011] S110, original UUID acquisition: read the device unique identifier from the security chip;

[0012] S120, timestamp generation: obtaining the current precise time;

[0013] S130, geolocation encoding: obtains longitude and latitude through GPS / Bluetooth beacon and converts it into GeoHash format;

[0014] S140, data splicing preprocessing: splicing the original data bit by bit;

[0015] S150, dynamic key derivation: Generate session keys based on the pre-set root key of the security chip;

[0016] S160, AES-256 encryption: encrypt the spliced data in groups;

[0017] S170, output encoding: convert the encryption result into a standard UUID format.

[0018] Furthermore, in S200, the following steps are specifically included:

[0019] S210, metadata combination: integrating dynamic UUID, timestamp, permission level and geographic location;

[0020] S220, digital signature generation: use HMAC-SHA256 for data integrity verification;

[0021] S230, data serialization: packaging metadata and signature into a binary stream;

[0022] S240, Base64URL conversion: convert to a URL-safe string format;

[0023] S250, error correction coding enhancement: added Reed-Solomon error correction code;

[0024] S260, Matrix Generation and Rendering: Generates QR code matrices and optimizes image recognition rates;

[0025] S270, physical anti-counterfeiting embedding: superimposed invisible UV fluorescent mark.

[0026] Furthermore, the calculation formula for matrix generation and rendering is as follows:

[0027] QR matrix =QRCode(QR ecc , Version=8, MaskPattern=3)

[0028] QR matrixIndicates the generated QR code matrix, suitable for printing and scanning, Version=8 indicates the QR code version, supporting 1,728 bits capacity, MaskPattern=3 indicates the optimal mask pattern selection, optimizing the readability of the QR code, QRCode indicates the function of generating the QR code matrix, QR ecc It is the input enhanced QR code data. Version determines the size and capacity of the QR code. MaskPattern is used to select the appropriate mask pattern to improve the readability of the QR code.

[0029] Furthermore, the calculation formula for physical anti-counterfeiting embedding is as follows:

[0030]

[0031] QR final Indicates the final generated QR code, including anti-counterfeiting mark, Indicates the random fluorescent dot distribution based on PUF material, which is used for physical anti-counterfeiting. represents the overlay operation, which overlays the random fluorescent point distribution onto the QR code matrix. (x, y) represents the coordinates on the two-dimensional plane, which is used to determine the position of the fluorescent point.

[0032] Furthermore, in S300, the following steps are specifically included:

[0033] S310, data decoding and extraction: parsing the QR code content and separating metadata;

[0034] S320, time validity verification: verifying that the timestamp is within the valid window;

[0035] S330, Geofence Verification: Verify the spatial consistency of the scanned location and the original location;

[0036] S340, signature authenticity verification: verify the integrity of the HMAC signature;

[0037] S350, anti-replay attack check: verify the uniqueness of Nonce;

[0038] S360, composite verification decision: generates verification results based on all conditions.

[0039] Furthermore, the calculation formula for data decoding and extraction is as follows:

[0040] R′=TLVDecode(Base64URL -1 (QR scan ))

[0041] R′=[DynamicUUID output′, t′, AccessLevel′, GeoHash′, Sig′, Nonce′]

[0042] QR scan Represents the original data obtained by scanning, including QR code information, R′ represents the decoded data, including dynamic UUID, timestamp, permission level, geographic location, digital signature and random number, where DynamicUUID output ' represents the decoded dynamic UUID, t' represents the decoded timestamp, AccessLevel' represents the decoded permission level, GeoHash' represents the decoded geographic location, Sig' represents the decoded digital signature, Nonce' represents the decoded random number, TLVDecode represents the Type-Length-Value decoding protocol, which is used to parse the structured binary data stream into raw metadata and signature, Base64URL -1 Represents a Base64URL decoding function that converts a URL-safe Base64-encoded string into binary data.

[0043] Furthermore, in S400, the following steps are specifically included:

[0044] S410, request fingerprint generation: construct a unique request identifier;

[0045] S420, concurrent access detection: controlling request frequency through distributed locks;

[0046] S430, dynamic UUID invalidation: immediately invalidate the copied UUID;

[0047] S440, secondary verification trigger: sending a dynamic verification code to the bound device;

[0048] S450, access control decision: update permissions based on the verification result;

[0049] S460, Audit tracking enhancement: Record abnormal events to the consortium chain.

[0050] Furthermore, the calculation formula for concurrent access detection is as follows:

[0051] LockStatus=Redis.SETNX(ReqID, Expire=5000ms)

[0052] LockStatus indicates the lock status, 0 indicates the presence of concurrent requests, and 1 indicates a successful request. Redis.SETNX indicates the Redis SETNX command, which is used to set a key-value pair. The setting succeeds only when the key does not exist. Expire = 5000ms indicates that the lock expires in 5000 milliseconds. ReqID is used as a Redis key to identify different requests. Expire ensures that the lock is automatically released after a certain period of time to avoid deadlock.

[0053] The present invention also proposes an emergency information management system based on mobile Internet and QR codes, which is used to perform the steps in the aforementioned emergency information management method based on mobile Internet and QR codes, including:

[0054] Dynamic Data Encryption Module: This module is responsible for generating a unique device identifier and implementing dynamic encryption. It integrates precise timestamps and geographic location information, generates a time-sensitive encrypted UUID through a hybrid encryption algorithm, and employs a hierarchical key management mechanism to ensure independent keys for each session, preventing system-wide risks caused by key leaks.

[0055] QR code generation and management module: This module combines encrypted data, permission-level metadata, and anti-counterfeiting features to generate dynamic QR codes with ultraviolet fluorescent markers. It also features a built-in self-destruct mechanism that automatically expires after expiration or an abnormal scan. It also supports remote QR code reset and emergency updates.

[0056] Real-time authentication module: Completes four-factor verification the moment the code is scanned: time validity check ensures data timeliness, geo-fence detection blocks cross-regional abuse, digital signature verification ensures data integrity, and device fingerprint comparison identifies illegal terminals;

[0057] Security protection and concurrency control module: This module detects high-frequency concurrent requests through a distributed lock mechanism, blocks abnormal access in real time and triggers secondary verification. It also establishes a dynamic blacklist system, implements intelligent flow control on risky devices, and records attack signatures to the blockchain for non-repudiation and traceability.

[0058] Medical Data Collaboration Module: Connects to the hospital's HIS / EMR system to achieve two-way data synchronization. In-depth information about patients' electronic medical records and imaging data can be retrieved in real time at the emergency scene. The intelligent matching engine automatically generates personalized emergency plans and provides visual guidance on emergency operations through AR devices.

[0059] Privacy protection and audit module: Implements dynamic field-level desensitization, displays sensitive information by permission level, uses virtual number relay technology in the communication process to establish an anonymous communication channel between patients and emergency personnel, and encrypts and stores full-link operation logs in the consortium chain to support compliance audits;

[0060] Emergency response and equipment linkage module: Integrates IoT device control functions. First aid kits and AED devices are automatically unlocked based on patient information and provide voice prompts for usage steps. Data from life monitoring equipment is synchronized to the cloud in real time, building a pre-hospital and in-hospital emergency data fusion channel.

[0061] The beneficial effects of the present invention are:

[0062] This invention builds an end-to-end trusted emergency information channel through the deep integration of dynamic data anchoring and multi-dimensional security verification, effectively solving the information lag and security flaws of traditional static management methods;

[0063] This invention also provides real-time guarantees, enabling emergency personnel to instantly access the latest medical records. The encrypted indexing mechanism and virtualized communication technology build a multi-layered protection barrier for medical privacy, while cross-system intelligent collaboration significantly improves the accuracy and integrity of pre-hospital emergency care.

[0064] The present invention also gives the system strong anti-attack capabilities and service continuity through anti-duplication design and distributed disaster recovery architecture, and overall realizes the paradigm upgrade of emergency information management from passive response to active protection, thus gaining a critical technical window for life-saving. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 This is a flow chart of the first aid information management method based on mobile Internet and QR code proposed by the present invention;

[0066] Figure 2 This is a structural block diagram of the first aid information management system based on mobile Internet and QR code proposed by the present invention.

[0067] In the figure: 101, dynamic data encryption module; 102, QR code generation and management module; 103, real-time authentication and verification module; 104, security protection and concurrency control module; 105, medical data collaboration module; 106, privacy protection and audit module; 107, emergency response and equipment linkage module. DETAILED DESCRIPTION

[0068] The subject matter described herein will now be discussed with reference to exemplary embodiments. It should be understood that these embodiments are discussed solely to enable those skilled in the art to better understand and implement the subject matter described herein, and that the functions and arrangements of the elements discussed may be varied without departing from the scope of this specification. Various examples may omit, substitute, or add various processes or components as needed. Furthermore, features described for some examples may be combined in other examples.

[0069] like Figure 1 As shown, the emergency information management method based on mobile Internet and QR code includes the following steps:

[0070] S100, dynamic UUID generation and encryption: obtains the device's unique identifier from the security chip, combines it with precise timestamp and geocoding data, generates a dynamic encrypted UUID through a hybrid encryption algorithm, and uses key derivation technology to ensure that each session key is independent, ultimately outputting a standardized encrypted identifier;

[0071] In one embodiment of the present invention, the following steps are specifically included:

[0072] S110, original UUID acquisition: read the device unique identifier from the security chip;

[0073] OriginalUUID∈{0, 1} 128 ;

[0074] OriginalUUID represents the unique identifier of the device. The identifier is encoded in 16 bytes HEX to ensure the uniqueness of each device in the network.

[0075] S120, timestamp generation: obtaining the current precise time (millisecond level);

[0076]

[0077] Where t represents the timestamp of the current time, expressed in milliseconds, and UnixTime represents the number of seconds since January 1, 1970 00:00:00 UTC, that is, the precise time. Indicates a round-down operation, which takes the calculated result as the largest integer not greater than the result;

[0078] S130, geolocation encoding: obtains longitude and latitude through GPS / Bluetooth beacon and converts it into GeoHash format;

[0079]

[0080] Where lat represents latitude, which indicates the north-south position of a point on the earth, lat∈[-90, 90]; lon represents longitude, which indicates the east-west position of a point on the earth, lon∈[-180, 180]; precision=6 indicates the encoding accuracy (about 5 meters error), that is, the accuracy of GeoHash. Represents a function that converts longitude and latitude into GeoHash encoding;

[0081] S140, data splicing preprocessing: splicing the original data bit by bit;

[0082] D concat =OriginalUUID||t||GeoHash;

[0083] Among them D concat Represents the concatenated data, including the device UUID, timestamp, and geolocation code. || represents the binary concatenation operator, which concatenates different data bits in sequence. OriginalUUID represents the unique identifier of the device, and GeoHash represents the geolocation code.

[0084] S150, dynamic key derivation: Generate session keys based on the pre-set root key of the security chip;

[0085] K session =HKDF(K root , Salt=t, Info=GeoHash);

[0086] where K session Represents the generated session key, which is used for subsequent encryption operations, K root Indicates the preset master key, stored in the security chip, K root ∈{0, 1} 256 , Salt represents a random value used to enhance the key derivation process. Here, the timestamp t is used to increase the randomness and security of the key. Info represents additional information. Here, it refers to the geographic location code GeoHash, which provides additional context information for key derivation. HKDF represents the HMAC-based key derivation function, which is used to derive the session key from the master key.

[0087] S160, AES-256 encryption: encrypt the spliced data in groups;

[0088] DynamicUUID=AES-256-CBC(K session , IV, D concat );

[0089] Where DynamicUUID represents the encrypted dynamic UUID to ensure data security, and IV represents the dynamically generated initialization vector, IV∈{0,1} 128 , used in the encryption process. In CBC mode, the first plaintext block is XORed with the IV to increase the randomness of the encryption. CBC stands for Cipher Block Chaining mode, which ensures that the same plaintext block produces different ciphertext after encryption. AES-256-CB indicates the Advanced Encryption Standard (AES) algorithm using a 256-bit key and Cipher Block Chaining (CBC) mode for encryption;

[0090] S170, output encoding: converting the encryption result into a standard UUID format;

[0091] DynamicUUID output =HexEncode(DynamicUUID);

[0092] Among them, DynamicUUID output The final output dynamic UUID is in hexadecimal encoding format. HexEncode represents a method for converting binary data into a printable character representation and is used to encode binary data into a hexadecimal string.

[0093] S200, dynamic QR code generation: This integrates metadata such as encrypted UUID, timestamp, and permission level with a digital signature. After serialization encoding, error correction enhancement, and physical anti-counterfeiting treatment, it generates a dynamic QR code with an embedded UV marker, ensuring single-use validity and anti-copying properties.

[0094] In one embodiment of the present invention, the following steps are specifically included:

[0095] S210, metadata combination: integrating dynamic UUID, timestamp, permission level and geographic location;

[0096] D meta =DynamicUUID output ||t||AccessLevel||GeoHash;

[0097] Among them D meta Represents the combined metadata, including dynamic UUID, timestamp, permission level and geographic location. AccessLevel represents the permission level. AccessLevel∈{1,2}(1=basic, 2=full), indicating the user's access rights. || represents the field separator (ASCII 0x1E), which is used to separate different fields in metadata.

[0098] S220, digital signature generation: use HMAC-SHA256 for data integrity verification;

[0099] Sig=HMAC(K hmac , D meta ||Nonce);

[0100] Where Sig represents the generated digital signature, which is used to verify the integrity of the data, and K hmac ∈{0, 1} 256 represents a signature key independent of S150, Nonce∈{0,1}^64 represents a random number (anti-replay attack) to ensure the uniqueness of each signature, HMAC represents a hash-based message authentication code algorithm, and the SHA256 hash function is used here; D meta ||Nonce means concatenating the combined metadata and random number according to the field separator as the input of the HMAC algorithm.

[0101] S230, data serialization: packaging metadata and signature into a binary stream;

[0102] D pack =TLVEncode(D meta )||Sig;

[0103] Among them D pack Represents the serialized data stream, including metadata and signature. TLVEncode represents the Type-Length-Value encoding protocol, which is used for structured representation of data. It divides data into three parts: type, length, and value. Sig represents the generated digital signature. || here means that the TLV-encoded metadata and digital signature are concatenated bit by bit.

[0104] S240, Base64URL conversion: convert to a URL-safe string format;

[0105] QR raw =Base64URL(D pack );

[0106] QR raw Represents the converted raw QR code data, suitable for use in URLs. Base64URL converts binary data into a URL-safe Base64 encoding format, replacing the + / in standard Base64 with -_ to ensure URL security.

[0107] S250, error correction coding enhancement: Add Reed-Solomon error correction code (30% redundancy);

[0108] QR ecc =RSEncode(QR raw , ECCLevel = H);

[0109] QR ecc Indicates enhanced QR code data, including error correction information. ECCLevel=H indicates high error correction level (can recover 30% data loss), ensuring that the QR code can still be read even if it is partially damaged. RSEncode indicates the Reed-Solomon encoding function, which is used to add error correction code. raw It is the input original QR code data. ECCLevel=H means selecting a high error correction level for Reed-Solomon encoding.

[0110] S260, Matrix Generation and Rendering: Generates QR code matrices and optimizes image recognition rates;

[0111] QR matrix =QRCode(QR ecc, Version=8, MaskPattern=3);

[0112] QR matrix Indicates the generated QR code matrix, suitable for printing and scanning, Version=8 indicates the QR code version, supporting 1,728 bits of capacity, MaskPattern=3 indicates the optimal mask pattern selection, optimizing the readability of the QR code, QRCode indicates the function of generating the QR code matrix; QR ecc It is the input enhanced QR code data. Version determines the size and capacity of the QR code. MaskPattern is used to select the appropriate mask pattern to improve the readability of the QR code.

[0113] S270, physical anti-counterfeiting embedding: superimposed invisible UV fluorescent mark;

[0114]

[0115] QR final Indicates the final generated QR code, including anti-counterfeiting mark, Indicates the random fluorescent dot distribution based on PUF (Physically Unclonable Function) material, used for physical anti-counterfeiting. represents the superposition operation, which superimposes the random fluorescent point distribution onto the two-dimensional code matrix; (x, y) represents the coordinates on the two-dimensional plane, which is used to determine the position of the fluorescent point.

[0116] S300, near-field environment verification: Analyzes the QR code content in real time upon scanning, strictly verifies time validity, geographic location consistency, data integrity, and request uniqueness, and blocks access attempts in unconventional environments through a four-factor joint authentication mechanism;

[0117] In one embodiment of the present invention, the following steps are specifically included:

[0118] S310, data decoding and extraction: parsing the QR code content and separating metadata;

[0119] R′=TLVDecode(Base64URL -1 (QR scan ));

[0120] R′=[DynamicUUID output ′, t′, AccessLevel′, GeoHash′, Sig′, Nonce′];

[0121] QR scanRepresents the original data obtained by scanning, including QR code information, R′ represents the decoded data, including dynamic UUID, timestamp, permission level, geographic location, digital signature and random number, where DynamicUUID output ' represents the decoded dynamic UUID, t' represents the decoded timestamp, AccessLevel' represents the decoded permission level, GeoHash' represents the decoded geographic location, Sig' represents the decoded digital signature, Nonce' represents the decoded random number, TLVDecode represents the Type-Length-Value decoding protocol, which is used to parse the structured binary data stream into raw metadata and signature; Base64URL -1 Represents the Base64URL decoding function, which converts a URL-safe Base64 encoded string into binary data;

[0122] S320, time validity verification: verifying that the timestamp is within the valid window;

[0123]

[0124] Where TimeValid indicates the time validity flag, 1 indicates valid, 0 indicates invalid, t current Indicates the timestamp when the code is scanned, T valid Indicates the effective time window, which is 60 seconds, that is, T valid = 60000ms; |·| represents the absolute value operation, which is used to calculate the absolute value of the difference between the timestamp of the scanned code and the timestamp in the QR code.

[0125] S330, Geofence Verification: Verify the spatial consistency of the scanned location and the original location;

[0126]

[0127] GeoValid indicates the geographic validity flag, 1 indicates valid, 0 indicates invalid, and d indicates the Haversine distance formula, which is used to calculate the spherical distance between two points on the earth. max Indicates the maximum allowable deviation, which is the spatial consistency requirement of 5 meters, D max =5m, Indicates the inverse function of converting GeoHash code to longitude and latitude. scan Indicates the GeoHash code corresponding to the geographic location obtained during scanning; Indicates converting the decoded geographic location code into longitude and latitude coordinates. Indicates converting the geographic location code during scanning into longitude and latitude coordinates.

[0128] S340, signature authenticity verification: verify the integrity of the HMAC signature;

[0129]

[0130] SigValid indicates the signature validity flag, 1 indicates valid, 0 indicates invalid. Indicates an indicator function that returns 1 if the condition in the brackets is true, otherwise it returns 0. meta ′ represents the reorganized metadata, including dynamic UUID, timestamp, permission level and geographic location. HMAC represents the hash-based message authentication code algorithm, using the SHA256 hash function. K hmac Indicates the signature key independent of S150, K hmac ∈{0, 1} 256 , D meta '||Nonce' means concatenating the reassembled metadata and random number according to the field separator as the input of the HMAC algorithm for comparison with the decoded digital signature.

[0131] S350, anti-replay attack check: verify the uniqueness of Nonce;

[0132]

[0133] NonceValid indicates the Nonce validity flag, 1 indicates valid, 0 indicates invalid. Indicates that the blockchain storage of Nonce has been used to ensure the uniqueness of Nonce. Indicates an indicator function, which returns 1 if the condition in the brackets is true, otherwise it returns 0; Indicates checking whether the decoded random number is not in the list of used random numbers.

[0134] S360, composite verification decision: generates verification results by integrating all conditions;

[0135] AuthResult=TimeValid∧GeoValid∧SigValid∧NonceValid;

[0136] AuthResult represents the final authentication result. If all conditions are true, it is 1, indicating that the authentication is successful. ∧ represents the logical AND operator.

[0137] S400, anti-duplication and concurrency control: Detects abnormal concurrent behavior based on request fingerprint characteristics, immediately abolishes the risky UUID and triggers dynamic verification code secondary authentication. At the same time, the attack characteristics are recorded in the distributed audit chain, achieving millisecond-level attack interception and traceability capabilities;

[0138] In one embodiment of the present invention, the following steps are specifically included:

[0139] S410, request fingerprint generation: construct a unique request identifier;

[0140] ReqID = SHA3-256 (Dynamic UUID output ′||t current ||DeviceID);

[0141] ReqID represents a unique request identifier, which is used to identify each request. DeviceID represents the unique identifier of the scanning device (IMEI / MEID), which ensures the uniqueness of the request source. SHA3-256 represents the 256-bit version of the SHA3 hash algorithm, which is used to generate a unique hash value. DynamicUUID output ′||t current ||DeviceID means the decoded dynamic UUID, the scan timestamp, and the unique identifier of the scanning device are concatenated bit by bit as the input of the SHA3-256 hash algorithm;

[0142] S420, concurrent access detection: controlling request frequency through distributed locks;

[0143] LockStatus=Redis.SETNX(ReqID, Expire=5000ms);

[0144] LockStatus indicates the lock status, 0 indicates a concurrent request, and 1 indicates a successful request. Redis.SETNX indicates the Redis SETNX command, which is used to set a key-value pair. The setting succeeds only if the key does not exist. Expire = 5000ms indicates that the lock expires in 5000 milliseconds. ReqID is a Redis key used to identify different requests. Expire ensures that the lock is automatically released after a certain period of time to avoid deadlock.

[0145] S430, dynamic UUID invalidation: immediately invalidate the copied UUID;

[0146]

[0147] BlacklistUpdate represents the operation of updating the blacklist to ensure that the copied UUID is no longer valid. Represents a distributed UUID blacklist, storing invalid UUIDs. HyperLogLog.Add represents the addition operation of Redis's HyperLogLog data structure, which is used to efficiently record and count unique elements. DynamicUUID output' is the decoded dynamic UUID that needs to be added to the blacklist;

[0148] S440, secondary verification trigger: sending a dynamic verification code to the bound device;

[0149]

[0150] VC represents the generated dynamic verification code, which is used for secondary verification. The verification code is sent instantly via SMS / push to ensure that the user receives it in time. CRC32 represents the 32-bit cyclic redundancy check algorithm, which is used to generate the check value, mod 10 6 Indicates modulo operation, the check value is compared with 10 6 Modulo, get a 6-bit integer; Nonce′||t current Indicates that the decoded random number and the scan timestamp are concatenated bit by bit as the input of the CRC32 algorithm.

[0151] S450, access control decision: update permissions based on the verification result;

[0152]

[0153] Among them, AccessGrant represents the access authorization result, indicating whether the user has obtained access rights, and OriginalAL′ represents the original permission level. If the verification is passed, it is returned. VC input Represents the dynamic verification code entered by the user, and ∧ represents the logical AND operator;

[0154] S460, Audit tracking enhancement: record abnormal events to the consortium chain;

[0155] BlockData=MerkleTree(ReqID||GeoHash scan ||AuthResult);

[0156] BlockData represents the recorded audit data, ensuring that all abnormal events are traceable. MerkleTree represents the hash tree used to build data. The input data is hashed layer by layer to obtain a root hash value to ensure data integrity and consistency. scan ||AuthResult represents the bitwise concatenation of the unique request identifier, the geolocation code at the time of scanning, and the final authentication result as the input for Merkle tree construction.

[0157] like Figure 2 As shown, according to the above management method, a corresponding emergency information management system based on mobile Internet and QR code is also proposed, and the management method is executed through the following modules, including:

[0158] Dynamic Data Encryption Module 101: Responsible for generating a unique device identifier and implementing dynamic encryption, integrating precise timestamps and geographic location information, generating a time-sensitive encrypted UUID through a hybrid encryption algorithm, and employing a hierarchical key management mechanism to ensure independent keys for each session, preventing system-wide risks caused by key leaks.

[0159] QR code generation and management module 102: combines metadata such as encryption data and permission levels with anti-counterfeiting features to generate a dynamic QR code with an ultraviolet fluorescent marker. It has a built-in self-destruct mechanism that automatically expires after the expiration date or an abnormal scan. It also supports remote QR code reset and emergency update.

[0160] Real-time authentication module 103: Completes four-factor verification at the moment of scanning: time validity check to ensure data timeliness, geo-fence detection to block cross-regional abuse, digital signature verification to ensure data integrity, and device fingerprint comparison to identify illegal terminals;

[0161] Security protection and concurrency control module 104: Detects high-frequency concurrent requests through a distributed lock mechanism, blocks abnormal access in real time and triggers secondary verification, establishes a dynamic blacklist system, implements intelligent flow control for risky devices, and records attack signatures to the blockchain for non-repudiation and traceability.

[0162] Medical Data Collaboration Module 105: Connects to the hospital's HIS / EMR system for two-way data synchronization. Emergency patients can access in-depth information such as electronic medical records and imaging data in real time at the scene. The intelligent matching engine automatically generates personalized emergency plans and provides visual guidance on emergency operations through AR devices.

[0163] Privacy Protection and Audit Module 106: Implements dynamic field-level desensitization, displays sensitive information by permission level, uses virtual number relay technology in the communication process to establish an anonymous communication channel between patients and emergency personnel, and encrypts and stores full-link operation logs in the consortium chain to support compliance audits.

[0164] Emergency response and equipment linkage module 107: Integrates IoT device control functions. First aid kits, AEDs, and other equipment are automatically unlocked based on patient information and voice prompts for usage instructions. Data from life monitoring equipment is synchronized to the cloud in real time, establishing a pre-hospital and in-hospital emergency data fusion channel.

[0165] Based on the above management method and system, the following example of a first aid information management method using mobile Internet and QR code is given - taking a campus allergy first aid scenario as an example.

[0166] Scene background:

[0167] A middle school student, Mr. Li (UUID: 7A3E…F291), suffered a severe allergic reaction in the cafeteria. Upon arrival, the school doctor immediately scanned the first aid QR code embedded in his uniform. The system then executed the following process:

[0168] 1. Dynamic information retrieval

[0169] Scan code trigger: The school doctor scans the QR code through the mini program, and the client automatically captures the current time (13:05:23.456GMT+8) and device location (GeoHash: wx4erg);

[0170] Real-time decryption: The system decrypts and obtains the dynamic UUID, pulling the latest medical files from Alibaba Cloud (penicillin allergy records updated 5 minutes ago);

[0171] Permission adaptation: The school doctor's identity token activates the core layer permissions, displaying: "Allergy history: penicillin (diagnosed in March 2024), emergency contact: Mr. Li 138****5678";

[0172] 2. Cross-system collaboration

[0173] Hospital pre-notification: The system pushes an early warning to the emergency department of the municipal hospital through the Open API, and the HIS system automatically generates an allergy emergency plan;

[0174] Device linkage: The first aid kit has a built-in IoT terminal that receives instructions, automatically pops out the adrenaline pen, and plays instructions for use;

[0175] Life monitoring: Synchronizes data from the patient's smart bracelet (heart rate: 142 bpm, blood oxygen: 91%) to generate pre-hospital emergency digital records;

[0176] 3. Attack and Defense Demonstration

[0177] 3.1, Copy attack attempt: A malicious person copies the QR code and scans it simultaneously from 5 kilometers away;

[0178] The system detected:

[0179] Geographic deviation: The deviation between the scanned location GeoHash (wq3yt5) and the original value is greater than 3km;

[0180] Time anomaly: continuous request interval < 200ms;

[0181] Defensive moves:

[0182] ①Immediately abolish the current dynamic UUID;

[0183] ②Send a safety warning SMS to the guardian;

[0184] ③Generate a new QR code and send it to the class teacher’s mobile phone via the school affairs APP;

[0185] 3.2,Data tampering attack: The attacker intercepts and modifies the allergy history data in transit;

[0186] The system detected: HMAC signature verification failed (p < 0.0001);

[0187] The request is initiated from an untrusted IP address;

[0188] Defensive moves:

[0189] ① Block the request and start VPN tunnel reconnection;

[0190] ②Activate the backup encryption channel to transmit critical data.

[0191] Life channel construction: In Mr. Li's case, the time from scanning the code to receiving adrenaline was shortened, saving more valuable time compared to traditional manual consultations;

[0192] Security system innovation: The defense system successfully blocked multiple cyberattacks and physical copy attempts, resulting in zero data leaks;

[0193] Ecosystem expansion capabilities: The time required to connect data with hospital EMR systems has been reduced from the industry average to less than half, enabling seamless integration of emergency care and diagnosis and treatment.

[0194] This example verifies the technical feasibility of this method in a real emergency scenario, and reconstructs the emergency information management paradigm through the triple mechanism of "dynamic data + active defense + intelligent linkage".

[0195] The above describes the embodiments of the present invention, but the present invention is not limited to the above specific implementation methods. The above specific implementation methods are merely illustrative and not restrictive. Ordinary technicians in this field can also make many forms under the guidance of the present invention, all of which are protected by the present invention.

Claims

1. A method for managing emergency information based on mobile Internet and QR code, characterized in that: The following steps are involved: S100, dynamic UUID generation and encryption: obtains the device's unique identifier from the security chip, combines it with precise timestamp and geocoding data, generates a dynamic encrypted UUID through a hybrid encryption algorithm, and uses key derivation technology to ensure that each session key is independent, ultimately outputting a standardized encrypted identifier; S200, dynamic QR code generation: This integrates the encrypted UUID, timestamp, and permission level metadata with the digital signature, and then undergoes serialization encoding, error correction enhancement, and physical anti-counterfeiting processing to generate a dynamic QR code with an embedded UV marker. S300, near-field environment verification: Analyzes the QR code content in real time upon scanning, strictly verifies time validity, geographic location consistency, data integrity, and request uniqueness, and blocks access attempts in unconventional environments through a four-factor joint authentication mechanism; S400, anti-duplication and concurrency control: Detects abnormal concurrent behavior based on request fingerprint characteristics, immediately abolishes the risky UUID and triggers secondary authentication with a dynamic verification code. At the same time, the attack characteristics are recorded in the distributed audit chain, achieving millisecond-level attack interception and tracing capabilities.

2. The method for managing emergency information based on mobile Internet and QR code according to claim 1, characterized in that: In S100, the following steps are specifically included: S110, original UUID acquisition: read the device unique identifier from the security chip; S120, timestamp generation: obtaining the current precise time; S130, geolocation encoding: obtains longitude and latitude through GPS / Bluetooth beacon and converts it into GeoHash format; S140, data splicing preprocessing: splicing the original data bit by bit; S150, dynamic key derivation: Generate session keys based on the pre-set root key of the security chip; S160, AES-256 encryption: encrypt the spliced data in groups; S170, output encoding: convert the encryption result into a standard UUID format.

3. The method for managing emergency information based on mobile Internet and QR code according to claim 2, characterized in that: In S200, the following steps are specifically included: S210, metadata combination: integrating dynamic UUID, timestamp, permission level and geographic location; S220, digital signature generation: use HMAC-SHA256 for data integrity verification; S230, data serialization: packaging metadata and signature into a binary stream; S240, Base64URL conversion: convert to a URL-safe string format; S250, error correction coding enhancement: added Reed-Solomon error correction code; S260, Matrix Generation and Rendering: Generates QR code matrices and optimizes image recognition rates; S270, physical anti-counterfeiting embedding: superimposed invisible UV fluorescent mark.

4. The method for managing emergency information based on mobile Internet and QR code according to claim 3, characterized in that: The calculation formula for matrix generation and rendering is as follows: QR matrix =QRCode(QR ecc ,Version=8,MaskPattern=3); QR matrix Indicates the generated QR code matrix, suitable for printing and scanning, Version=8 indicates the QR code version, supporting 1,728 bits capacity, MaskPattern=3 indicates the optimal mask pattern selection, optimizing the readability of the QR code, QRCode indicates the function of generating the QR code matrix, QR ecc It is the enhanced QR code data input, Versio n Determines the size and capacity of the QR code. MaskPattern is used to select an appropriate mask pattern to improve the readability of the QR code.

5. The method for managing emergency information based on mobile Internet and QR code according to claim 4, characterized in that: The calculation formula for physical anti-counterfeiting embedding is as follows: QR final Indicates the final generated QR code, including anti-counterfeiting mark, Indicates the random fluorescent dot distribution based on PUF material, which is used for physical anti-counterfeiting. represents the overlay operation, which overlays the random fluorescent point distribution onto the QR code matrix. (x, y) represents the coordinates on the two-dimensional plane, which is used to determine the position of the fluorescent point.

6. The method for managing emergency information based on mobile Internet and QR code according to claim 5, characterized in that: In S300, the following steps are specifically included: S310, data decoding and extraction: parsing the QR code content and separating metadata; S320, time validity verification: verifying that the timestamp is within the valid window; S330, Geofence Verification: Verify the spatial consistency of the scanned location and the original location; S340, signature authenticity verification: verify the integrity of the HMAC signature; S350, anti-replay attack check: verify the uniqueness of Nonce; S360, composite verification decision: generates verification results based on all conditions.

7. The method for managing emergency information based on mobile Internet and QR code according to claim 6, characterized in that: The calculation formula for data decoding and extraction is as follows: R′=TLVD ecode (Base64URL -1 (QR scan )); R′=[DynamicUUID output ′,t′,AccessLevel′,GeoHash′,Sig′,Nonce′]; QR scan Represents the original data obtained by scanning, including QR code information, R′ represents the decoded data, including dynamic UUID, timestamp, permission level, geographic location, digital signature and random number, where DynamicUUID output ' represents the decoded dynamic UUID, t' represents the decoded timestamp, AccessLevel' represents the decoded permission level, GeoHash' represents the decoded geographic location, Sig' represents the decoded digital signature, Nonce' represents the decoded random number, TLVDecode represents the Type-Length-Vahe decoding protocol, which is used to parse the structured binary data stream into raw metadata and signature, Base64URL -1 Represents a Base64URL decoding function that converts a URL-safe Base64-encoded string into binary data.

8. The method for managing emergency information based on mobile Internet and QR code according to claim 7, characterized in that: In S400, the following steps are specifically included: S410, request fingerprint generation: construct a unique request identifier; S420, concurrent access detection: controlling request frequency through distributed locks; S430, dynamic UUID invalidation: immediately invalidate the copied UUID; S440, secondary verification trigger: sending a dynamic verification code to the bound device; S450, access control decision: update permissions based on the verification result; S460, Audit tracking enhancement: Record abnormal events to the consortium chain.

9. The method for managing emergency information based on mobile Internet and QR code according to claim 8, characterized in that: The calculation formula for concurrent access detection is as follows: LockStatus=Redis.SETNX(ReqID, Expire=5000ms); LockStatus indicates the lock status, 0 indicates the presence of concurrent requests, and 1 indicates a successful request. Redis.SETNX indicates the Redis SETNX command, which is used to set a key-value pair. The setting succeeds only when the key does not exist. Expire = 5000ms indicates that the lock expires in 5000 milliseconds. ReqID is used as a Redis key to identify different requests. Expire ensures that the lock is automatically released after a certain period of time to avoid deadlock.

10. The emergency information management system based on mobile Internet and QR code is characterized by: The method for executing the steps of the method for managing emergency information based on mobile Internet and QR code according to any one of claims 1 to 9 comprises: Dynamic Data Encryption Module: This module is responsible for generating a unique device identifier and implementing dynamic encryption. It integrates precise timestamps and geographic location information, generates a time-sensitive encrypted UUID through a hybrid encryption algorithm, and employs a hierarchical key management mechanism to ensure independent keys for each session, preventing system-wide risks caused by key leaks. QR code generation and management module: This module combines encrypted data, permission-level metadata, and anti-counterfeiting features to generate dynamic QR codes with ultraviolet fluorescent markers. It also features a built-in self-destruct mechanism that automatically expires after expiration or an abnormal scan. It also supports remote QR code reset and emergency updates. Real-time authentication module: Completes four-factor verification the moment the code is scanned: time validity check ensures data timeliness, geo-fence detection blocks cross-regional abuse, digital signature verification ensures data integrity, and device fingerprint comparison identifies illegal terminals; Security protection and concurrency control module: This module detects high-frequency concurrent requests through a distributed lock mechanism, blocks abnormal access in real time and triggers secondary verification. It also establishes a dynamic blacklist system, implements intelligent flow control on risky devices, and records attack signatures to the blockchain for non-repudiation and traceability. Medical Data Collaboration Module: Connects to the hospital's HIS / EMR system to achieve two-way data synchronization. In-depth information about patients' electronic medical records and imaging data can be retrieved in real time at the emergency scene. The intelligent matching engine automatically generates personalized emergency plans and provides visual guidance on emergency operations through AR devices. Privacy protection and audit module: Implements dynamic field-level desensitization, displays sensitive information by permission level, uses virtual number relay technology in the communication process to establish an anonymous communication channel between patients and emergency personnel, and encrypts and stores full-link operation logs in the consortium chain to support compliance audits; Emergency response and equipment linkage module: Integrates IoT device control functions. First aid kits and AED devices are automatically unlocked based on patient information and provide voice prompts for usage steps. Data from life monitoring equipment is synchronized to the cloud in real time, building a pre-hospital and in-hospital emergency data fusion channel.

Citation Information

Cited By

  • Harmless network attack validity testing method and system

    CN121664451A