A Strong Privacy Protection Method Based on Certificate-Free Signature for Medical Scenarios
By adopting key isolation, fake identity and key negotiation technology in medical sensor networks, the lack of certificate-free signature schemes in resisting malicious attacks and protecting privacy is solved, and high security and privacy of medical data transmission is achieved.
Patent Information
- Application Number
- CN202210693710.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-18
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-06-18
AI Technical Summary
Existing certificate-free signature solutions are difficult to effectively resist malicious attacks in medical sensor networks and cannot ensure the security and privacy of medical data.
Key isolation technology is used to update the signature key, reduce the risk of key leakage, and protect the patient's identity privacy through fake identity technology. At the same time, key negotiation technology is used to achieve the transmission of some private keys without relying on secure channels.
It effectively improves the security and privacy of medical data transmission, reduces the risk of key leakage, and meets various security needs in medical scenarios, such as message integrity, authentication, anonymity and traceability.
Smart Images

Figure CN114884665B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a strong privacy protection method based on certificateless signature applicable to medical scenarios. The strong privacy protection method based on certificateless signature is for the research on security and privacy among medical sensor nodes and various entities, and belongs to the field of information and communication in medical scenarios. Background Art
[0002] With the rapid development of wireless communication and the Internet of Things, the emergence of Wireless Medical Sensor Networks (WMSNs) has brought great convenience to human life. In WMSNs, medical sensor nodes on a patient's body can monitor the patient's physical data in real time and transmit the collected medical data to doctors in professional institutions for diagnosis. However, there are still many security and privacy issues in the seemingly complete WMSNs that need to be solved. In WMSNs, medical data is communicated over a wireless channel, and malicious adversaries can perform malicious operations such as eavesdropping and tampering on medical data through the public channel. In addition, the identity information of patients is often obtained by medical institutions, resulting in serious leakage of medical data. Therefore, how to ensure privacy and security in WMSNs is a current research hotspot.
[0003] Since certificateless signature can achieve the authentication and integrity of messages. Therefore, many scholars regard certificateless signature as the best solution to solve security and privacy problems. Wang et al. proposed a certificateless signature scheme that does not require the use of bilinear pair operations. However, the security proof of their scheme depends on an ideal random oracle and cannot ensure the practical security of the scheme. Soon, Huang et al. designed a certificateless signature scheme in a standard model and proved its strong unforgeability under adaptive chosen-message attacks. However, Wu et al. proved that the scheme of Huang et al. cannot resist the attack of a malicious key generation center. In addition, WU et al. also proposed an improved scheme and claimed that the scheme has strong unforgeability for type I adversaries (malicious sensor nodes) and type II adversaries (malicious key generation centers) in the random oracle model. However, Yang et al. analyzed the scheme of Wu et al. and found that it cannot meet strong unforgeability, and an adversary can easily forge a new signature using the public parameters; at the same time, it pointed out the attack of the malicious key generation center in the scheme of Wu et al. and gave a detailed attack process. Finally, Yang et al. designed an improved scheme with lower computational overhead and proved its strong unforgeability in the standard model.
[0004] In the process of constructing the above certificateless signature scheme, the security of the scheme is often ignored in order to reduce the overhead. Once the security of the scheme is missing, the authentication and integrity of the certificateless signature for messages cannot be achieved, and at the same time, communication security and privacy issues cannot be well solved. Therefore, the present invention introduces key isolation technology to ensure that the signature key is updated as the time period changes, which can reduce the risk of key leakage and resist two types of attackers at the same time. At the same time, the fake identity technology is adopted to replace the identity identifier to ensure the protection of the patient's identity privacy. Finally, the present invention also introduces key negotiation technology to realize that the transmission of part of the private key no longer depends on the secure channel, which greatly improves the robustness of the scheme. Summary of the Invention
[0005] The object of the present invention is to provide a method applicable to medical scenarios and capable of meeting various security and privacy requirements for the above problems. In order to meet the above conditions, the technical solution of the present invention adopts certificateless signature, which can securely transmit medical data to medical institutions for detection and diagnosis.
[0006] The object of the present invention is achieved as follows: A strong privacy protection method based on certificateless signature applicable to medical scenarios, comprising the following steps:
[0007] Step 1): System initialization generation, the key generation center is responsible for generating the system master key and the master public key, constructing a secure hash function, and finally publicly releasing the system parameters;
[0008] Step 2): Secret value generation, the medical sensor node generates a fake identity of the medical sensor node and part of the public key through a randomly selected secret value;
[0009] Step 3): Generation of temporary partial private key, the key generation center generates a temporary partial private key through a randomly selected value, the system master key, and the public key of the medical sensor node;
[0010] Step 4): Initial key generation, the medical sensor node calculates the complete partial private key, the public and private key pairs of two assistants, and the initial key;
[0011] Step 5): Update key generation, the assistant generates an update key through its own private key and the fake identity of the medical sensor node;
[0012] Step 6): Signature generation, the medical sensor node generates a signature through a linear combination of the update key and the initial key;
[0013] Step 7): Signature verification, the medical server verifies whether the signature transmitted by the medical sensor node is legal, and if it is legal, it accepts it, otherwise it rejects it.
[0014] In step 1), the system initialization process includes the following steps:
[0015] Step 1-1): Input the security parameter v and the total number of time segments N. The group G is an elliptic curve additive group of order q, and P is a generator of the group G. Here, v is the security parameter, N is the total number of time segments, G is the elliptic curve additive group, q is the order of the elliptic curve additive group, and P is the generator of the elliptic curve additive group;
[0016] Step 1-2): The key generation center randomly selects s ∈ Z q * as the system master key, and calculates P pub = sP as the system master public key, where s is the system master key, and P pub is the system master public key, and P is the generator of the elliptic curve additive group;
[0017] Step 1-3): The KGC selects 4 secure and collision-resistant hash functions H, H 1 , H 2 , H 3 , where: H: G → Z q * , H 1 : G × {0, 1} * × G → Z q * , H 2 : {0, 1} * × G × {0, 1} * → Z q * , H 3 : {0, 1} * × {0, 1} * × G × G × G × G → Z q * , where H, H 1 , H 2 , H 3 are four hash functions, Z q * is the integer domain, G is the elliptic curve additive group, and {0, 1} * is an arbitrary-length string composed of 0 and 1;
[0018] Step 1-4): The key generation center publishes the system parameters params = {G, q, P, P pub , H, H 1 , H 2 , H 3}, where G is the elliptic curve additive group, q is the order of the elliptic curve additive group, P is the generator of the elliptic curve additive group, P pub is the system master public key, and H, H1 ,H 2 ,H 3 are four hash functions.
[0019] In step 2), the secret value generation process includes the following steps:
[0020] Step 2-1): The medical sensor node randomly selects a secret value x i ∈Z q * , and calculates the partial public key X i = x i P, where x i is the secret value, Z q * is the integer domain, and X i is the public key based on the secret value;
[0021] Step 2-2): The medical sensor node calculates the fake identity where PID i
[0022] is the fake identity of the medical sensor node, RID i is the real identity of the medical sensor node, x i is the secret value, and P pub is the system master public key;
[0023] Step 2-3): The medical sensor node sends the fake identity PID i and the public key X i to the key generation center, where PID i is the fake identity of the medical sensor node, and X i is the public key based on the secret value.
[0024] In step 3), the temporary partial private key generation process includes the following steps:
[0025] Step 3-1): The key generation center randomly selects u i ∈Z q * , calculates U i = u i P, where u i is a random number, Z q * is the integer domain, P is the generator of the elliptic curve additive group, and U i is the public key based on the random number;
[0026] Step 3-2): The key generation center calculates h i = H 1 (U i , PID i , Ppub ), the system master key s and the public key X i Generate a temporary partial private key l i = [u i + sh i + H(sX i )] mod q, where h i is the hash value of the hash function H 1 is the public key based on a random number, PID i is the false identity of the medical sensor node, X i is the public key based on a secret value, P i is the system master public key, s is the system master key, l pub is the temporary partial private key, and q is the order of the elliptic curve additive group; i is the temporary partial private key, q is the order of the elliptic curve additive group;
[0027] Step 3-3): The key generation center sends (U i , l i ) to the corresponding medical sensor node, where U i is the public key based on a random number, and l i is the temporary partial private key.
[0028] In Step 4), the initial key generation process includes the following steps:
[0029] Step 4-1): The medical sensor node calculates the complete partial private key d i = l i - H(x i P pub ) mod q, where d i is the complete partial private key, l i is the temporary partial private key, x i is the secret value, P pub is the system master public key, q is the order of the elliptic curve additive group, and H is the hash function;
[0030] Step 4-2): The medical sensor node verifies the equation d i P = U i + h i P pub to see if it holds. If it holds, the MSN accepts the partial private key d i ; otherwise, it re-applies for the partial private key. Here, d i is the complete partial private key, P is the generator of the elliptic curve additive group, U i is the public key based on a random number, h i is the hash value of the hash function H 1 and P pub is the system master public key;
[0031] Step 4-3): The medical sensor node randomly selects s 0 , s 1 ∈Z q * , and sets HSK 0 = s 0 , HSK 1 = s 1 , and calculates HPK 0 = s 0 P, HPK 1 = s 1 P, where (HSK 0 , HSK 1 ) is used as the private key of the two helpers, and (HPK 0 , HPK 1 ) is used as the public key of the two helpers. Here, s 0 , s 1 are the private keys of the two helpers, HPK 0 , HPK 1 are the public keys of the two helpers, and P is the generator of the elliptic curve additive group;
[0032] Step 4-4): The medical sensor node generates the initial key , of the medical sensor node through . Among them, is the hash value of the hash function H 2 , U i is the public key based on the random number, PID i is the fake identity of the medical sensor node, -1, 0 are the time segments at times -1 and 0, is the initial key, s 1 , s 2 are the private keys of the two helpers with time segments 1 and 2, d i is the complete partial private key, and x i is the secret value.
[0033] In Step 5), the key update generation process includes the following steps:
[0034] The helper calculates the update key within the time period t. Among them, is the update key, s i is the private key of the helper, is the hash value of the hash function H 2 with time segments t, t - 2, and q is the order of the elliptic curve additive group.
[0035] In Step 6), the signature generation process includes the following steps:
[0036] Step 6-1): The medical sensor node calculates the signature key where \(v\equiv t\bmod 2\) and \(v'\equiv(t - 1)\bmod 2\), where is the signature key, \(d\) i is the complete partial private key, \(x\) i is the secret value, \(s\) v , \(s\) v' is the private key of the helper for time segments \(v\) and \(v'\), is the hash value of the hash function \(H\) for time segments \(t,t - 1\) 2 ;
[0037] Step 6-2): The medical sensor node randomly selects \(y\) i \(\in\mathbb{Z}\) q * , and generates a signature by calculating \(Y\) i \(=y\) i P and \(a\) i \(=H\) 3 (m i , PID i , U i , X i , Y i , P pub , T i ) where \(y\) i is the random value, \(Y\) i is the public key based on the random value, \(a\) i is the hash value of the hash function \(H\) 3 , \(m\) i is the message, \(U\) i is the public key based on the random number, PID i is the fake identity of the medical sensor node, \(Y\) i is the public key based on the random value, \(X\) i is the public key based on the secret value, \(P\) pub is the system master public key, \(T\) i is the timestamp, \(\omega\) i is the signature element based on the elliptic curve, \(q\) is the order of the elliptic curve additive group, and \(P\) is the generator of the elliptic curve additive group;
[0038] Step 6-3): The medical sensor node takes \(\sigma\) i \(=(Y\) i , \(\omega\) i ) as the signature on \(m\) i ||T i and takes \(\lt\sigma\) i , \(m\) i , \(T\) i , PID i , \(X\)i , U i , HPK 0 , HPK 1 > is sent to the medical server via a common channel, where σ i is the signature, Y i is the public key based on a random value, ω i is the signature element based on an elliptic curve, m i is the message, T i is the timestamp, PID i is the false identity of the medical sensor node, X i is the public key based on a secret value, U i is the public key based on a random number, HPK 0 , HPK 1 are the public keys of two assistants.
[0039] In step 7), the signature verification process includes the following steps:
[0040] Step 7-1): The medical server calculates a i = H 3 (m i , PID i , U i , X i , Y i , P pub , T i ), h i = H 1 (U i , PID i , P pub ), where Y i is the public key based on a random value, a i is the hash value of the hash function H 3 m i is the message, U i is the public key based on a random number, PID i is the false identity of the medical sensor node, Y i is the public key based on a random value, X i is the public key based on a secret value, P pub is the system master public key, T i is the timestamp, h i is the hash value of the hash function H 1 ; is the hash value of the hash function H 2 for the time segment t;
[0041] Step 7-2): The medical server verifies the equation Whether it holds. If the equation holds, MES receives the signature; otherwise, it rejects the received signature. Here, P is the generator of the elliptic curve additive group, Y i is the public key based on a random value, a i is the hash value of the hash function H 3 , ω i is the signature element based on the elliptic curve, PID i is the fake identity of the medical sensor node, X i is the public key based on a secret value, U i is the public key based on a random number, HPK v , HPK v' are the public keys of two assistants, h i is the hash value of the hash function H 1 . is the hash value of the hash function H for time segments t and t - 1 2 .
[0042] The method of the present invention is advanced and scientific. Through the present invention, a strong privacy protection method based on certificateless signature applicable to medical scenarios is provided. By using key negotiation technology, the transmission of part of the private key no longer requires a medical security channel. At the same time, a fake identity is used to transmit data instead of the patient's identity identifier, ensuring that an adversary cannot trace the patient's true identity information. In addition, the present invention introduces certificateless signature and key isolation technologies, which can not only achieve message integrity and authenticity, but also greatly reduce the risk of key leakage. Finally, the invention can fully meet the security requirements such as traceability and anonymity required in medical scenarios.
[0043] As an important part of intelligent healthcare, wireless medical sensor networks have attracted more and more attention from domestic and foreign research scholars. In today's big data era, how to ensure security and privacy is an issue that major research institutions are highly concerned about. Although there is no unified protocol policy at home and abroad yet, how to achieve strong privacy protection of medical data will surely become an important part of the development of intelligent healthcare, with a broader development space and good market prospects.
[0044] To achieve the security and privacy of medical data, the present invention develops a strong privacy protection method based on certificateless signature applicable to medical scenarios. Medical sensor nodes can collect physiological data in real time from medical detection devices worn by patients. After the key generation center distributes part of the private key to the medical sensor nodes, these medical sensor nodes will combine their own secret values and part of the private key to form a complete private key, and generate a signature key pair with the help of two assistants to sign medical messages. Among them, the signature key is updated with the change of time period, which greatly reduces the risk of key leakage. The present invention uses the fake identity technology to replace the identity identifier to ensure the protection of the patient's identity privacy, and at the same time introduces the key negotiation technology to realize that the transmission of part of the private key no longer depends on a secure channel. In addition, the present invention adopts the certificateless signature technology to ensure the secure transmission of medical data, and the invention can meet the security requirements such as message integrity, authentication, anonymity, and traceability.
[0045] The present invention has the following characteristics:
[0046] 1. The present invention can achieve communication security between various entities. During the communication process of various entities, it can effectively ensure the integrity and authentication of messages.
[0047] 2. The present invention has the characteristic of strong privacy protection. The present invention introduces the idea of key isolation to reduce the frequency of key leakage, and uses the fake identity technology to replace the identity identifier to ensure the protection of the patient's identity privacy.
[0048] 3. The present invention has traceability. For malicious medical sensor nodes, the present invention can quickly trace the malicious nodes and restore their true identities through the calculation of the key generation center.
[0049] 4. The present invention does not rely on a secure channel to transmit part of the private key, making the present invention highly robust. Description of the Drawings
[0050] Figure 1 is the structure of the wireless medical sensor network and the main communication method.
[0051] Figure 2 is the flowchart of the certificateless signature in the present invention.
[0052] Figure 3 is the algorithm flowchart of the present invention. Detailed Implementation Manner
[0053] The following further describes the present invention in detail with reference to the above drawings. It should be understood that after reading the content taught by the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent forms also fall within the scope defined by the appended claims of this application.
[0054] As Figure 1 shown, the wireless medical sensor network mainly includes four entities: medical sensor nodes (MSN), key generation center (Key Generation Center, KGC), helper, and medical server (Medical Server, MS). In the present invention, the KGC is responsible for generating public parameters, partial private keys, and tracing malicious medical sensor nodes; the MSN is responsible for generating secret values, initial keys, signature keys, and generating corresponding signatures; the helper is responsible for generating update keys; and the medical server is responsible for verifying signatures.
[0055] Figure 2 is the flowchart of the certificateless signature in the present invention, and the generation and verification processes of the signature are as Figure 2 shown.
[0056] Figure 3 is the algorithm flowchart of the present invention.
[0057] A strong privacy protection method applicable to the medical scenario based on certificateless signature includes the following steps:
[0058] A strong privacy protection method applicable to the medical scenario based on certificateless signature, which mainly includes the following steps:
[0059] Step 1): System initialization generation. The key generation center is responsible for generating the system master key and the system public key, constructing a secure hash function, and finally publishing the system parameters. The system initialization process includes the following steps:
[0060] Step 1-1): Input the security parameter v and the total number of time segments N. The group G is an elliptic curve addition group of order q, and P is a generator of the group G;
[0061] Step 1-2): The key generation center randomly selects s ∈ Z q * as the system master key, and calculates P pub = sP as the system public key;
[0062] Step 1-3): The KGC selects 4 secure and collision-resistant hash functions H, H 1 , H 2 , H 3 , where: H: G → Z q * , H 1 : G × {0, 1} * × G → Z q * , H 2 : {0, 1} * × G × {0, 1}* →Z q * ,H 3 :{0,1} * ×{0,1} * ×G×G×G×G→Z q * ;
[0063] Step 1-4): The key generation center publicly discloses the system parameters params = {G, q, P, P pub ,H,H 1 ,H 2 ,H 3}.
[0064] Step 2): Generation of the secret value. The medical sensor node generates a false identity of the medical sensor node and a partial public key through the randomly selected secret value. The secret value generation process includes the following steps:
[0065] Step 2-1): The medical sensor node randomly selects a secret value x i ∈Z q * , and calculates the partial public key X i =x i P;
[0066] Step 2-2): The medical sensor node calculates the false identity
[0067] Step 2-3): The medical sensor node sends the false identity PID i and the public key X i to the key generation center.
[0068] Step 3): Generation of the temporary partial private key. The key generation center generates a temporary partial private key through the selected random value, the system master key, and the public key of the medical sensor node. The temporary partial private key generation process includes the following steps:
[0069] Step 3-1): The key generation center randomly selects u i ∈Z q * , and calculates U i =u i P;
[0070] Step 3-2): The key generation center generates the temporary partial private key l i =H 1 (U i ,PID i ,P pub ), the system master key s, and the public key X i i = [u i + sh i + H(sX i )] mod q;
[0071] Step 3 - 3): The key generation center sends (U i , l i ) to the corresponding medical sensor node.
[0072] Step 4): Initial key generation. The medical sensor node calculates the complete partial private key, the public - private key pairs of the two helpers, and the initial key. The initial key generation process includes the following steps:
[0073] Step 4 - 1): The medical sensor node calculates the complete partial private key d i = l i - H(x i P pub ) mod q;
[0074] Step 4 - 2): The medical sensor node verifies the equation d i P = U i + h i P pub Whether it holds. If it holds, the MSN accepts the partial private key d i ; otherwise, re - apply for the partial private key.
[0075] Step 4 - 3): The medical sensor node randomly selects s 0 , s 1 ∈ Z q * , sets HSK 0 = s 0 , HSK 1 = s 1 , and calculates HPK 0 = s 0 P, HPK 1 = s 1 P, where (HSK 0 , HSK 1 ) is used as the private keys of the two helpers, and (HPK 0 , HPK 1 ) is used as the public keys of the two helpers.
[0076] Step 4 - 4): The medical sensor node generates the initial key of the medical sensor node through ,
[0077] Step 5): Update key generation. The helper generates an update key using its own private key and the false identity of the medical sensor node. The update key generation process includes the following steps:
[0078] The helper calculates the update key within the time period t
[0079] Step 6): Signature generation. The medical sensor node generates a signature through a linear combination of the update key and the initial key. The signature generation process includes the following steps:
[0080] Step 6-1): The medical sensor node calculates the signature key where v ≡ t mod 2 and v' ≡ (t - 1) mod 2.
[0081] Step 6-2): The medical sensor node randomly selects y i ∈ Z q * , and calculates Y i = y i P and a i = H 3 (m i , PID i , U i , X i , Y i , P pub , T i ) to generate the signature
[0082] Step 6-3): The medical sensor node takes σ i = (Y i , ω i ) as the signature on m i ||T i , and sends <σ i , m i , T i , PID i , X i , U i , HPK 0 , HPK 1 > to the medical server through the common channel.
[0083] Step 7): Signature verification. The medical server verifies whether the signature transmitted by the medical sensor node is legal. If it is legal, it accepts it; otherwise, it rejects it. The signature verification process includes the following steps:
[0084] Step 7-1): The medical server calculates a i = H 3 (m i , PIDi ,U i ,X i ,Y i ,P pub ,T i ),h i =H 1 (U i ,PID i ,P pub ),
[0085] Step 7-2): The medical server verifies whether the equation holds. If the equation holds, MES receives the signature; otherwise, it rejects the received signature.
Claims
1. A strong privacy protection method based on certificateless signature applicable to medical scenarios, characterized in that, it includes the following steps: Step 1): System initialization generation. The key generation center is responsible for generating the system master key and the master public key, constructing a secure hash function, and finally publishing the system parameters; Step 2): Secret value generation. The medical sensor node generates a false identity of the medical sensor node and a partial public key through a randomly selected secret value; Step 3): Generation of temporary partial private key. The key generation center generates a temporary partial private key through a selected random value, the system master key, and the public key of the medical sensor node; Step 4): Initial key generation. The medical sensor node calculates the complete partial private key, the public and private key pairs of two assistants, and the initial key; Step 5): Update key generation. The assistant generates an update key through its own private key and the false identity of the medical sensor node; Step 6): Signature generation. The medical sensor node generates a signature through a linear combination of the update key and the initial key; Step 7): Signature verification. The medical server verifies whether the signature transmitted by the medical sensor node is legal. If it is legal, it accepts it, otherwise it rejects it; In Step 1), the system initialization process includes the following steps: Step 1-1): Input the security parameter v and the total number of time segments N. The group G is an elliptic curve additive group of order q, and P is a generator of the group G. Among them, v is the security parameter, N is the total number of time segments, G is the elliptic curve additive group, q is the order of the elliptic curve additive group, and P is the generator of the elliptic curve additive group; Step 1-2): The key generation center randomly selects s ∈ Z q * as the system master key, and calculates P pub = sP as the system master public key, where s is the system master key and P pub is the system master public key, and P is the generator of the elliptic curve additive group; Step 1-3): KGC selects 4 secure and collision-resistant hash functions H, H 1 , H 2 , H 3 , where: H: G → Z q * , H 1 : G × {0, 1} * × G → Z q * , H 2 : {0, 1} * × G × {0, 1} * → Z q * , H 3 : {0, 1} * × {0, 1} * × G × G × G × G → Z q * , where, H, H 1 , H 2 , H 3 are four hash functions, Z q * is the integer domain, G is the elliptic curve additive group, {0, 1} * is an arbitrarily long string composed of 0 and 1; Step 1-4): The key generation center publicly discloses the system parameters params = {G, q, P, P pub , H, H 1 , H 2 , H 3}, where G is an elliptic curve additive group, q is the order of the elliptic curve additive group, P is the generator of the elliptic curve additive group, and P pub is the system master public key, and H, H 1 , H 2 , H 3 are four hash functions; In Step 2), the secret value generation process includes the following steps: Step 2-1): The medical sensor node randomly selects a secret value x i ∈Z q * , and calculates a partial public key X i =x i P, where x i is the secret value, Z q * is the integer domain, and X i is the public key based on the secret value; Step 2-2): The medical sensor node calculates a false identity wherein, PID i is the false identity of the medical sensor node, RID i is the true identity of the medical sensor node, x i is the secret value, and P pub is the system master public key; Step 2-3): The medical sensor node sends the false identity PID i and the public key X i to the key generation center, where PID i is the false identity of the medical sensor node, and X i is the public key based on the secret value; In Step 3), the temporary partial private key generation process includes the following steps: Step 3-1): The key generation center randomly selects u i ∈Z q * , calculates U i = u i P, where u i is a random number, Z q * is the integer domain, P is the generator of the elliptic curve additive group, and U i is the public key based on the random number; Step 3-2): The key generation center generates a temporary partial private key l i = H 1 (U i , PID i , P pub ), the system master key s, and the public key X i by h i = [u i + sh i + H(sX i )] mod q, where h i is the hash value of the hash function H 1 , U i is the random number-based public key, PID i is the fake identity of the medical sensor node, X i is the secret value-based public key, P pub is the system master public key, s is the system master key, l i is the temporary partial private key, and q is the order of the elliptic curve additive group; Step 3-3): The key generation center sends (U i , l i ) to the corresponding medical sensor node, where U i is a public key based on a random number, and l i is a temporary partial private key; In Step 4), the initial key generation process includes the following steps: Step 4-1): The medical sensor node calculates the complete partial private key d i = l i - H(x i P pub ) mod q, where d i is the complete partial private key, l i is the temporary partial private key, x i is the secret value, P pub is the system master public key, q is the order of the elliptic curve additive group, and H is the hash function; Step 4-2): The medical sensor node verifies the equation d i P = U i + h i P pub to check if it holds. If it holds, the MSN accepts the partial private key d i ; otherwise, it requests a new partial private key. Here, d i is the complete partial private key, P is the generator of the elliptic curve additive group, U i is the public key based on a random number, h i is the hash value of the hash function H 1 and P pub is the system master public key; Step 4-3): The medical sensor node randomly selects s 0 , s 1 ∈Z q * , sets HSK 0 = s 0 , HSK 1 = s 1 , and calculates HPK 0 = s 0 P, HPK 1 = s 1 P, where (HSK 0 , HSK 1 ) is used as the private keys of the two helpers, and (HPK 0 , HPK 1 ) is used as the public keys of the two helpers. Here, s 0 , s 1 are the private keys of the two helpers with time segments 0 and 1, and HPK 0 , HPK 1 are the public keys of the two helpers with time segments 0 and 1, and P is the generator of the elliptic curve additive group; Step 4-4): The medical sensor node generates an initial key for the medical sensor node through where is the hash value of the hash function H , U 2 is the public key based on a random number, PID i is the false identity of the medical sensor node, -1 and 0 are time segments at times -1 and 0, i is the initial key, s , s 1 , s 2 are the private keys of two helpers with time segments 1 and 2, d i is the complete partial private key, x i is the secret value; In Step 5), the update key generation process includes the following steps: The helper calculates the update key within the time period t where is the update key, s i is the private key of the helper, is the hash value of the hash function H for the time segments t, t - 2 2 and q is the order of the elliptic curve additive group; In Step 6), the signature generation process includes the following steps: Step 6-1): The medical sensor node calculates the signature key where v ≡ t mod 2 and v' ≡ (t - 1) mod 2, and where is the signature key, d i is the complete partial private key, x i is the secret value, s v , s v' is the private key of the helper for time segments v and v', is the hash value of the hash function H for time segments t, t - 1 2 ; Step 6-2): The medical sensor node randomly selects y i ∈Z q * , and calculates Y i =y i P and a i =H 3 (m i , PID i , U i , X i , Y i , P pub , T i ) to generate a signature where y i is a random value, Y i is the public key based on the random value, a i is the hash value of the hash function H 3 , m i is the message, U i is the public key based on the random number, PID i is the false identity of the medical sensor node, Y i is the public key based on the random value, X i is the public key based on the secret value, P pub is the system master public key, T i is the timestamp, ω i is the signature element based on the elliptic curve, q is the order of the elliptic curve additive group, and P is the generator of the elliptic curve additive group; Step 6-3): The medical sensor node takes σ i =(Y i , ω i ) as the signature on m i ||T i and sends <σ i , m i , T i , PID i , X i , U i , HPK 0 , HPK 1 > to the medical server via the common channel, where σ i is the signature, Y i is the public key based on the random value, ω i is the signature element based on the elliptic curve, m i is the message, T i is the timestamp, PID i is the fake identity of the medical sensor node, X i is the public key based on the secret value, U i is the public key based on the random number, HPK 0 , HPK 1 are the public keys of the two helpers; In Step 7), the signature verification process includes the following steps: Step 7-1): The medical server calculates a i = H 3 (m i , PID i , U i , X i , Y i , P pub , T i ), h i = H 1 (U i , PID i , P pub ), where Y i is the public key based on a random value, a i is the hash value of the hash function H 3 , m i is the message, U i is the public key based on a random number, PID i is the false identity of the medical sensor node, Y i is the public key based on a random value, X i is the public key based on a secret value, P pub is the system master public key, T i is the timestamp, h i is the hash value of the hash function H 1 , is the hash value of the hash function H 2 for the time segment t; Step 7-2): The medical server verifies the equation to check if it holds. If the equation holds, the MES receives the signature; otherwise, it rejects the received signature. Here, P is the generator of the elliptic curve additive group, Y i is the public key based on a random value, a i is the hash value of the hash function H 3 ω i is the signature element based on the elliptic curve, PID i is the false identity of the medical sensor node, X i is the public key based on a secret value, U i is the public key based on a random number, HPK v , HPK v' are the public keys of two helpers with time segments v≡tmod2 and v'≡(t - 1)mod2, h i is the hash value of the hash function H 1 , are the hash values of the hash function H 2 for time segments t and t - 1.
Citation Information
Patent Citations
Certificateless anonymous multi-receiver signcryption method without secure channel
CN108809650A
Privacy protection and secure communication method suitable for wireless medical sensor network
CN114339728A