A CA certificate dual authentication method for patients signing relevant agreements during the diagnosis and treatment process

Through the dual-factor authentication method of CA certificates, the problem of frequent identity authentication and difficulty in signing patients with no signing ability in traditional online agreement signing is solved, and efficient signing and multi-party management are achieved.

CN115333808BActive Publication Date: 2025-05-06GUIZHOU PRECISION HEALTH DATA CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210911274.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-30
Publication Date
2025-05-06
Estimated Expiration
2042-07-30

AI Technical Summary

Technical Problem

In traditional online agreement signing methods, patients need to frequently authenticate their identity, which wastes time and cannot sign the signing of patients without signing ability, and only the management party can manage the signing of the agreement.

Method used

The CA certificate dual-factor authentication method is adopted to connect the hospital terminal server, patient terminal camera and browser to the signing server, and use the certificate to perform dual-factor authentication, avoid repeated verification, and allow patients or their relatives to sign an agreement to achieve multi-party management.

Benefits of technology

It improves signing efficiency, avoids repeated verification, realizes signing of patients without signing ability, prompt signing, and allows patients and their relatives to manage signing agreements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115333808B_ABST
    Figure CN115333808B_ABST
Patent Text Reader

Abstract

The present invention discloses a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process, which belongs to the technical field of agreement signing and comprises the following steps: S1: an uploader and a signatory send a connection request; S2: a third-party platform sends a certificate; S3: the uploader and the signatory check the certificate; S4: the uploader and the signatory verify the certificate; S5: the third-party platform verifies the certificate; S6: obtaining the communication key of both parties; S7: the uploader encrypts and uploads the agreement; S8: the signatory encrypts and signs the agreement; S9: the third-party platform backs up the agreement; in the present invention, a patient signs multiple related agreements. If the patient does not leave the camera range during the process, the patient can keep signing, and the signing server will not repeatedly send the identity authentication information. If the patient leaves the camera range during the process, the signing server automatically terminates the signing process, and the identity authentication information must be sent before the signing can continue. Under the premise of ensuring safety, the problem of repeated verification is avoided, and the signing efficiency of the agreement is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of agreement signing, and specifically relates to a CA certificate dual authentication method used for patients signing relevant agreements during diagnosis and treatment processes. Background Art

[0002] In life, besides spending on food, clothing, housing and transportation, people also spend in many other areas, such as medical services. Although medical services are a kind of life consumption, they are different from general life consumption and have their own unique characteristics, which are manifested in: consumers' lack of medical knowledge and the huge risks borne by medical service providers. Based on the above characteristics, before the diagnosis and treatment process, medical personnel must try to explain the situation to the patient in an easy-to-understand manner, let the patient know the shortcomings and side effects, and even the dangers, of the diagnosis and treatment. In addition, in order to protect the patient's right to life and health and respect the patient's right to self-disposal, the patient must make a commitment with the patient's knowledge and sign the consent before the diagnosis and treatment can continue.

[0003] In the traditional diagnosis and treatment process, patients sign relevant agreements offline. The doctor gives the patient the relevant agreement that needs to be signed, the patient signs it, and then gives the signed relevant agreement to the doctor, who retains the relevant agreement. This method requires doctors to communicate frequently with different patients, which increases the doctor's workload. At the same time, doctors may miss signing relevant agreements after forgetting, leading to medical disputes. Therefore, with the development of the Internet, online agreement signing has emerged. Doctors upload the relevant agreements to be signed to the signing platform, and patients sign the relevant agreements through the signing platform identity authentication. Doctors maintain and manage the relevant agreements on the signing platform. This method has effectively solved the problem of medical disputes caused by doctors' heavy workload and forgetfulness.

[0004] However, the above-mentioned online signing method requires patients to undergo identity authentication before signing each agreement, and repeated identity authentication is time-consuming. At the same time, it does not take into account the signing problem of patients who are unable to sign. Moreover, only doctors and other management parties can maintain and manage the signed agreement, and patients cannot manage the signed agreement. Summary of the invention

[0005] To solve the problems raised in the above background technology, the present invention provides a CA certificate dual authentication method for patients signing related agreements in the diagnosis and treatment process, which has the characteristics of no need for repeated verification, improving signing efficiency, and being able to sign by multiple parties or by one party, and managing multiple parties.

[0006] To achieve the above object, the present invention provides the following technical solution: a CA certificate dual authentication method applied to patients signing relevant agreements in the diagnosis and treatment process, comprising the following steps:

[0007] S1: The hospital terminal server, the patient terminal camera and the browser each send a connection request to the signing server;

[0008] S2: The signing server sends its own certificate and information related to the certificate to the hospital terminal server, the patient terminal camera and the browser respectively;

[0009] S3: The hospital terminal server, the patient terminal camera and the browser check whether the certificate sent by the signing server is issued by the CA center they trust. If so, they continue to execute the agreement. If not, the hospital terminal server, the patient terminal camera and the browser give a warning message to the doctor and the patient respectively.

[0010] S4: The hospital terminal server, the patient terminal camera and the browser respectively verify the message in the certificate and determine whether it is consistent with the relevant message sent by the signing server. If they are consistent, the hospital terminal server, the patient terminal camera and the browser respectively complete the verification of the legal identity of the signing server and continue to execute the agreement. If they are inconsistent, the identity verification fails;

[0011] S5: The hospital terminal server, the patient terminal camera and the browser send their own certificates to the signing server respectively. The signing server verifies the message in the certificate respectively. If the verification is successful, the signing server obtains the public key of the doctor and the patient respectively and continues to execute the protocol. If the verification fails, the connection is rejected.

[0012] S6: The hospital terminal server, the patient terminal camera and the browser respectively send the communication symmetric encryption schemes that they can support to the signing server. The signing server selects the corresponding symmetric encryption scheme from the sent schemes, encrypts it with the public keys of the doctor and the patient, and sends it to the hospital terminal server, the patient terminal camera and the browser respectively. The hospital terminal server, the patient terminal camera and the browser respectively select a call key for the symmetric encryption scheme, and then encrypts it with the public key of the signing server and sends it to the signing server respectively. The signing server decrypts it with its own private key to obtain the communication key between the hospital terminal server, the patient terminal camera and the browser and the signing terminal;

[0013] S7: The hospital terminal server encrypts and uploads the relevant agreement to be signed to the signing server through the communication key;

[0014] S8: The patient terminal server obtains the relevant agreement through the communication key and signs and encrypts it and uploads it to the signing server. During the patient signing the agreement, the camera collects audio data in real time to the signing server. If the patient signs multiple related agreements and does not leave the camera range during the process, the signing server will not send identity verification information. If the patient leaves the camera range during the process, the signing server will automatically terminate the signing process and send identity verification information before continuing to sign;

[0015] S9: The patient completes the signature and signs the server backup agreement.

[0016] Preferably, in step S1, before the hospital terminal server, the patient terminal camera and the browser send a connection request, the certificate content for signing the server certificate authentication has been installed in the hospital terminal server, the patient terminal camera and the browser.

[0017] Preferably, in step S3, the warning message given to the doctor and the patient includes: the certificate is not trustworthy, and whether to continue.

[0018] Preferably, in step S7, upload permissions are set in the hospital terminal server, and doctors can only upload protocols related to their own patients.

[0019] Preferably, in step S7, the hospital terminal server can also upload the information of relatives who accompany the patient for diagnosis and treatment to the signing server through communication key encryption, so that when the patient does not have the signing ability, relatives who have the same signing ability as the patient can sign in time through the communication key established with the signing server.

[0020] Preferably, in step S7, even if the patient has been treated before and the information of the relatives who accompanied the patient for treatment and registered is the same, it needs to be uploaded to the signing server again.

[0021] Preferably, in step S9, the signing server backs up the three agreements respectively, and the backed-up three agreements are respectively sent to the signing server, the patient terminal browser and the hospital terminal server for storage, so that doctors and patients can view and manage the signed agreements.

[0022] Preferably, in step S9, the doctor's protocol viewing and management are also set with permissions.

[0023] Compared with the prior art, the present invention has the following beneficial effects:

[0024] 1. When the patient of the present invention signs the relevant agreement, the terminal camera synchronously records the audio. If the patient signs multiple relevant agreements and does not leave the camera range during the process, he can continue to sign, and the signing server will not repeatedly send the identity verification information. If the patient leaves the camera range during the process, the signing server automatically terminates the signing process, and the signing can only continue after the identity verification information is sent. Under the premise of ensuring safety, the problem of repeated verification is avoided, and the signing efficiency of the agreement is improved.

[0025] 2. The present invention uploads the information of relatives who accompany patients for diagnosis and treatment to the signing server through the hospital terminal server. The hospital itself completes the relationship authentication between the signatory and the patient, solving the problem that signatories other than the patient themselves need to spend a lot of time to provide proof to the signing server, so that when the patient does not have the signing ability, relatives who have the same signing ability as the patient can sign in time, thereby improving the signing process.

[0026] 3. After the patient of the present invention or a relative with the same signing ability as the patient signs the agreement, the signed agreement with legal significance is backed up in three copies by the signing server and sent to the signing server, the patient's terminal browser and the hospital terminal server for storage respectively, thus realizing the function of unilateral signing and multi-party preservation of the agreement. In this way, not only can the doctor upload the relevant agreements to be signed and manage the relevant agreements after signing, but the patient can also manage the relevant agreements he has signed. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 The present invention is a flow chart of the CA certificate dual authentication method used by the present invention for patients in the diagnosis and treatment process to sign relevant agreements. DETAILED DESCRIPTION

[0028] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0029] Example 1

[0030] See also Figure 1 The present invention provides the following technical solution: A CA certificate dual authentication method applied to patients signing relevant agreements during the diagnosis and treatment process, comprising the following steps:

[0031] S1: When the hospital terminal server, patient terminal camera and browser access the signing server, the certificate content authenticated by the signing server certificate is installed into the hospital terminal server, patient terminal camera and browser, and the hospital terminal server, patient terminal camera and browser respectively send a connection request to the signing server;

[0032] S2: The signing server sends its own certificate and information related to the certificate to the hospital terminal server, the patient terminal camera and the browser respectively;

[0033] S3: The hospital terminal server, the patient terminal camera and the browser check whether the certificate sent by the signing server is issued by the CA center they trust. If so, they continue to execute the agreement. If not, the hospital terminal server, the patient terminal camera and the browser give the doctor and the patient a warning message including "The certificate is not trustworthy. Do you need to continue?";

[0034] S4: The hospital terminal server, the patient terminal camera and the browser respectively verify the message in the certificate and determine whether it is consistent with the relevant message sent by the signing server. If they are consistent, the hospital terminal server, the patient terminal camera and the browser respectively complete the verification of the legal identity of the signing server and continue to execute the agreement. If they are inconsistent, the identity verification fails;

[0035] S5: The hospital terminal server, the patient terminal camera and the browser send their own certificates to the signing server respectively. The signing server verifies the message in the certificate respectively. If the verification is successful, the signing server obtains the public key of the doctor and the patient respectively and continues to execute the protocol. If the verification fails, the connection is rejected.

[0036] S6: The hospital terminal server, the patient terminal camera and the browser respectively send the communication symmetric encryption schemes that they can support to the signing server. The signing server selects the corresponding symmetric encryption scheme from the sent schemes, encrypts it with the public keys of the doctor and the patient, and sends it to the hospital terminal server, the patient terminal camera and the browser respectively. The hospital terminal server, the patient terminal camera and the browser respectively select a call key for the symmetric encryption scheme, and then encrypts it with the public key of the signing server and sends it to the signing server respectively. The signing server decrypts it with its own private key to obtain the communication key between the hospital terminal server, the patient terminal camera and the browser and the signing terminal;

[0037] S7: Due to the permission setting, the hospital terminal server can only encrypt and upload the relevant agreements to be signed related to its own patients to the signing server through the communication key;

[0038] S8: The patient terminal server obtains the relevant agreement through the communication key and signs and encrypts it and uploads it to the signing server. During the patient signing the agreement, the camera collects audio data in real time to the signing server. If the patient signs multiple related agreements and does not leave the camera range during the process, the signing server will not send identity verification information. If the patient leaves the camera range during the process, the signing server will automatically interrupt the signing process and need to send identity verification information before continuing to sign;

[0039] S9: The patient completes the signature and signs the server backup agreement.

[0040] Example 2

[0041] The difference between this embodiment and embodiment 1 is that:

[0042] Specifically, in step S7, the hospital terminal server can also upload the information of relatives who accompany the patient for diagnosis and treatment to the signing server through communication key encryption, so that when the patient does not have the ability to sign, relatives who have the same signing ability as the patient can sign in time through the communication key established with the signing server.

[0043] Specifically, in step S7, even if the patient has been treated before and the information of the relatives who accompanied the patient for treatment and registered is the same, it needs to be uploaded to the signing server again.

[0044] Example 3

[0045] The difference between this embodiment and embodiment 2 is that:

[0046] Specifically, in step S9, the signing server backs up the three agreements respectively, and the three backed-up agreements are sent to the signing server, the patient terminal browser and the hospital terminal server for storage, so that doctors and patients can view and manage the signed agreements.

[0047] Specifically, in step S9, the doctor's protocol viewing and management are also set with permissions.

[0048] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A CA certificate dual authentication method for patients signing relevant agreements during the diagnosis and treatment process, characterized in that: The following steps are involved: S1: The hospital terminal server, the patient terminal camera and the browser each send a connection request to the signing server; S2: The signing server sends its own certificate and information related to the certificate to the hospital terminal server, the patient terminal camera and the browser respectively; S3: The hospital terminal server, the patient terminal camera and the browser check whether the certificate sent by the signing server is issued by the CA center they trust. If so, they continue to execute the agreement. If not, the hospital terminal server and the patient terminal browser give a warning message to the doctor and the patient respectively. S4: The hospital terminal server, the patient terminal camera and the browser respectively verify the message in the certificate and determine whether it is consistent with the relevant message sent by the signing server. If they are consistent, the hospital terminal server, the patient terminal camera and the browser respectively complete the verification of the legal identity of the signing server and continue to execute the agreement. If they are inconsistent, the identity verification fails; S5: The hospital terminal server, the patient terminal camera and the browser send their own certificates to the signing server respectively. The signing server verifies the message in the certificate respectively. If the verification is successful, the signing server obtains the public key of the doctor and the patient respectively and continues to execute the protocol. If the verification fails, the connection is rejected. S6: The hospital terminal server, the patient terminal camera and the browser respectively send the communication symmetric encryption schemes that they can support to the signing server. The signing server selects the corresponding symmetric encryption scheme from the sent schemes, encrypts it with the public keys of the doctor and the patient, and sends it to the hospital terminal server, the patient terminal camera and the browser respectively. The hospital terminal server, the patient terminal camera and the browser respectively select a call key for the symmetric encryption scheme, and then encrypts it with the public key of the signing server and sends it to the signing server respectively. The signing server decrypts it with its own private key to obtain the communication key between the hospital terminal server, the patient terminal camera and the browser and the signing server; S7: The hospital terminal server encrypts and uploads the relevant agreement to be signed to the signing server through the communication key; S8: The patient's terminal browser obtains the relevant agreement through the communication key and signs and encrypts it and uploads it to the signing server. During the patient's signing process, the camera collects audio data in real time to the signing server. If the patient signs multiple related agreements and does not leave the camera range during the process, the signing server will not send identity verification information. If the patient leaves the camera range during the process, the signing server will automatically interrupt the signing process and need to send identity verification information before continuing to sign. S9: The patient completes the signature and signs the server backup agreement.

2. According to claim 1, a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process is characterized by: In step S1, before the hospital terminal server, the patient terminal camera and the browser send a connection request, the certificate content for signing the server certificate authentication has been installed in the hospital terminal server, the patient terminal camera and the browser.

3. According to claim 1, a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process is characterized by: In step S3, the warning message given to the doctor and the patient includes: the certificate is not trustworthy, and whether to continue.

4. According to claim 1, a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process is characterized by: In step S7, upload permissions are set in the hospital terminal server, and doctors can only upload protocols related to their own patients.

5. According to claim 1, a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process is characterized by: In step S7, the hospital terminal server can also upload the information of relatives who accompany the patient for diagnosis and treatment to the signing server through communication key encryption, so that when the patient does not have the ability to sign, relatives who have the same signing ability as the patient can sign in time through the communication key established with the signing server.

6. According to claim 5, a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process is characterized by: In step S7, even if the patient has been treated before and the information of the relatives who accompanied the patient for treatment and registered is the same, it needs to be uploaded to the signing server again.

7. According to claim 1, a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process is characterized by: In step S9, the signing server backs up the three agreements respectively, and the backed-up three agreements are sent to the signing server, the patient terminal browser and the hospital terminal server for storage respectively, so that doctors and patients can view and manage the signed agreements.

8. According to claim 7, a CA certificate dual authentication method for patients signing relevant agreements in the diagnosis and treatment process is characterized by: In step S9, the doctor's protocol viewing and management are also set with permissions.

Citation Information

Patent Citations

  • Identity authentication method and system

    CN106453330A

  • Key exchange protocol establishment method based on double authentication preventing signatures

    CN108809656A