Key negotiation method for emergency rescue systems based on 5G encrypted signals

By establishing authentication and key negotiation between users and hospital entities in the 5G network, temporary identities and adversary models are generated, solving the security problem of information transmission in the medical emergency system and achieving effective protection of user information and high system security.

CN115835200BActive Publication Date: 2026-01-30GUANGZHOU LANSWICK SOFTWARE DEV CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211672397.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-26
Publication Date
2026-01-30
Estimated Expiration
2042-12-26

AI Technical Summary

Technical Problem

In 5G network communication, the security of information transmission in medical emergency systems faces huge risks. Existing authentication and key negotiation protocols are difficult to effectively resist forgery attacks, resulting in user information leakage and insufficient system security.

Method used

The emergency medical system establishes mutual authentication and key negotiation between users and hospital entities. Temporary identities and key pairs are generated through the system management module. Adversary models are established to simulate attacks, calculate the probability of forging authentication messages and obtaining session keys, and use facial information verification and encrypted transmission to protect user information.

Benefits of technology

It improves the security of the emergency medical system, prevents unauthorized users from forging authentication messages, ensures the security of session keys, protects the privacy of user and medical information, and enhances the system's protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115835200B_ABST
    Figure CN115835200B_ABST
Patent Text Reader

Abstract

This invention discloses a key negotiation method for an emergency medical system based on 5G encrypted signal transmission, comprising: establishing two entities, a user and a hospital, within the emergency medical system for mutual authentication and key negotiation between the two entities in the 5G network, and obtaining a session key between the entities; establishing a system management module for identity management, key management, and encrypted transmission management of the user and hospital during the session; generating an encrypted signal when the user uses the emergency medical system, simultaneously establishing a temporary identity for the user, and forming a public key and a private key through the temporary identity for transmitting the encrypted signal; establishing an adversary model to calculate the probability of an adversary successfully forging authentication messages and successfully obtaining the session key when the emergency medical system is maliciously attacked. This key negotiation method for an emergency medical system based on 5G encrypted signal transmission prevents unauthorized users from forging authentication messages and resists forgery attacks, ensuring the security of the session key.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of encrypted information transmission, and particularly relates to a key negotiation method for an emergency system based on 5G encrypted signal transmission. BACKGROUND

[0002] With the development of network mobile communication, the requirement of information transmission on communication protocols is higher and higher, and low latency and high speed are new service characteristics in 5G network communication. The reform of mobile communication technology often brings huge potential security risks. The 5G technology brings new risks at the same time. Network security problems are one of the problems that the industry must pay attention to and improve. With the optimization of protocols, parameters, networks and access scenarios are continuously considered. The research on the authentication characteristics of security protocols is also an important field that attracts much attention.

[0003] For example, in a medical emergency system, the information of patients and hospitals needs to be transmitted and exchanged in time. However, due to various uncertain factors in the outside world, the security of user access to the network faces great risks. The authentication and key negotiation protocol is one of the important authentication methods in 5G communication. The method is based on strict mathematical basis and is within a controllable range. The 5G signal is encrypted and transmitted to achieve high security and high service quality of the emergency system. SUMMARY

[0004] The application provides a key negotiation method for an emergency system based on 5G encrypted signal transmission, so as to solve the above problems in the prior art.

[0005] The key negotiation method for the emergency system based on the 5G encrypted signal transmission has the characteristics that it comprises the following steps.

[0006] S100: two entities of a user and a hospital are established in an emergency system, which are used for mutual authentication and key negotiation between the two entities in a 5G network, and a session key between the entities is obtained.

[0007] S200: a system management module is established, which is used for identity management, session key management and encrypted transmission management of the user and the hospital in a session process.

[0008] S300: when the user uses the emergency system, an encrypted signal is generated, and a temporary identity of the user is established,

[0009] and a public key and a private key are formed through the temporary identity and used for transmission of the encrypted signal.

[0010] S400: an adversary model is established, and the probability of successfully forging an authentication message by an adversary and the probability of successfully obtaining a session key when the emergency system is subjected to malicious attacks are calculated.

[0011] Preferably, S100 comprises:

[0012] S101: initializing the emergency system, setting the master key and the public key, and publishing the key parameters of the emergency system;

[0013] S102: the user sends an identity information request for registration to the emergency system, and the emergency system generates a temporary identity for the user and calculates the public key and the private key of the user as a key pair after receiving the request information;

[0014] S103: sending the temporary identity and the key pair to the user through a secure channel in the system management module.

[0015] Preferably, S102 comprises:

[0016] S1021: after the user registers, an encrypted session of the user in the emergency system and the hospital is established by using the temporary identity of the user;

[0017] S1022: a random number is selected at the user end, request information of the encrypted session is generated, and a unique digital signature is generated by calculating a digital signature algorithm;

[0018] S1023: the request information and the digital signature are broadcasted, and the emergency system verifies whether an equation formed by the key parameters and the public key of the user is established after receiving the broadcast message of the user; if the equation is established, the request information of the user is added to the encrypted session list, and the current public key is saved.

[0019] Preferably, S300 comprises:

[0020] S301: obtaining the session list of the user, and sending the request information of the encrypted session to the system management module;

[0021] S302: verifying whether the user identity in the request information is a legal registered identity; if the verification is no, the session request of the user is refused;

[0022] S303: if the verification is yes, the system management module creates a session group between the hospital and the legal user for the user, selects a random number as a session identifier, then creates a ring group according to the user identity by the system management module, and the multiple users in the ring group are mutually neighbors, and the information in the ring group is broadcasted.

[0023] Preferably, S304 comprises:

[0024] S3041: after receiving the response message of the encrypted session from the system management module, the user performs a second mutual authentication and key negotiation, and obtains a shared session key therefrom;

[0025] S3042: The user terminal generates a random secret number, and calculates the first negotiation information from the secret number, then the user calculates the first session signature according to the first negotiation information, and finally sends the first session signature and the first negotiation information to the neighbor users in the ring group;

[0026] S3043: The user verifies whether the user in the emergency system is a legal user according to the first session signature and the first negotiation information.

[0027] Preferably, S3042 comprises:

[0028] S30421: The neighbor user receives the first negotiation information sent, and verifies whether the first negotiation information in the neighbor user is consistent with the negotiation information held by the user, if not, the session is terminated;

[0029] S30422: If yes, it is verified whether the neighbor user is a legal registered identity and carries a preset sequence parameter, if not, the session is terminated;

[0030] S30423: The system management module receives the session information of the user, and calculates whether the negotiation information and the shared session key equation of the user and the neighbor user are established, if not, the user who fails the verification is requested again;

[0031] S30424: If yes, the second negotiation information of the user is generated, and the second signature is calculated according to the second negotiation information, and finally the second signature and the second negotiation information are broadcasted.

[0032] Preferably, after S30424, it further comprises:

[0033] S30425: The broadcast information of the user is received, and it is verified whether a plurality of neighbor users are legal registered identities in a loop, if yes, the session key is calculated in turn;

[0034] S30246: An encrypted session between the user and the hospital is established through the session key, if the user does not receive all the negotiation information in the process of the encrypted session, the temporary identity of the user who does not send the negotiation information is added to the failure information list, and is sent to the system management module at the same time;

[0035] S30247: If the system management module receives a plurality of failure information from different users, the corresponding temporary identity user in the failure information list is removed from the session group, and a new ring group is constructed; the negotiation information is sent to the user who is not removed again, and an encrypted session is established.

[0036] Preferably, S400 comprises:

[0037] S401: the adversary obtains a session key related to the temporary identity of the user, and the long-term key is a public key and a private key used for negotiation by the user;

[0038] S402: user modeling is performed on the data of the attacked user, and the negotiation information between the set to which the user belongs is eavesdropped to perform the process;

[0039] S403: the protocol is attacked to perform the session key, and the attack result is returned;

[0040] S404: the return result after the attack is obtained, and the probability of the adversary successfully forging the authentication message and the probability of successfully obtaining the session key are calculated.

[0041] Preferably, the key negotiation method of the emergency system based on 5G encrypted signal transmission has the characteristics that it further comprises:

[0042] S500: the information acquisition module is further included in the emergency system, which is used to acquire the face information of the user and process the face information as identity verification information;

[0043] S600: the user type is determined according to the face information of the user and the temporary identity, and a medical information data interface corresponding to the user type is obtained;

[0044] S700: whether the user information is correct is inquired in the preset user database, if the inquiry is successful, the data interface is obtained to call the medical information in the emergency system; the medical information includes hospital identity, department information and disease type identification selected by the user.

[0045] Preferably, S700 comprises:

[0046] S701: the encrypted signal needs to be generated when the user information is transmitted, and the encrypted signal is encrypted by the public key;

[0047] S702: the positions of different hospitals in the emergency system are positioned, and the positioning information is calculated as superimposed encrypted information; since the positions of different hospitals are different, the encrypted information formed according to the hospital position information is unique;

[0048] S703: when the hospital obtains the emergency information sent by the user through the emergency system, the superimposed encrypted information and the public key need to be decrypted by the private key; since the encrypted information is different, and the decrypted information is different according to different hospitals.

[0049] Compared with the prior art, the present application has the following advantages:

[0050] The application provides an emergency system key negotiation method based on 5G encrypted signal transmission, and the process of key negotiation is established by groups, and users use temporary identities for mutual authentication, so that illegal users cannot fake authentication messages, and resistance to fake attacks is achieved.

[0051] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the application. The objects and other advantages of the application will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings.

[0052] The technical solutions of the application will be further described in detail below with the help of the accompanying drawings and examples. BRIEF DESCRIPTION OF DRAWINGS

[0053] The accompanying drawings are included to provide a further understanding of the application, and constitute a part of the specification, illustrate the application, and are used to explain the application together with the embodiments of the application, and do not constitute a limitation on the application. In the drawings:

[0054] Figure 1 The steps of the emergency system key negotiation method based on 5G encrypted signal transmission in the embodiment of the application are shown in the figure;

[0055] Figure 2 The steps of the method for establishing an adversary model in the emergency system in the embodiment of the application are shown in the figure;

[0056] Figure 3 The steps of encryption and decryption when the user transmits information with the hospital in the embodiment of the application are shown in the figure. DETAILED DESCRIPTION

[0057] The preferred embodiments of the application will be described below with reference to the accompanying drawings, and it should be understood that the preferred embodiments described herein are only used to illustrate and explain the application, and do not limit the application.

[0058] Reference Figure 1 The embodiment of the application provides an emergency system key negotiation method based on 5G encrypted signal transmission, characterized in that it comprises:

[0059] S100: Establishing two entities of users and hospitals in the emergency system, for mutual authentication and key negotiation between the two entities in the 5G network, and obtaining the session key between the entities;

[0060] S200: Establishing a system management module for identity management, session key management and encrypted transmission management of users and hospitals in the session process;

[0061] S300: generating an encrypted signal when the user uses the emergency system, establishing a temporary identity of the user at the same time, and forming a public key and a private key through the temporary identity for transmitting the encrypted signal;

[0062] S400: establishing an adversary model, and calculating a probability of successfully forging an authentication message and a probability of successfully obtaining a session key of an adversary when the emergency system is subjected to a malicious attack.

[0063] The working principle of the above technical solution is that the scheme adopted in the embodiment is that, based on a 5G network, a user and a hospital are established in an emergency system, mutual authentication and key negotiation are performed between the user and the hospital, a session key is obtained, and a system management module is used for identity management, session key management, and encrypted transmission management of the user. It is responsible for generating a temporary identity and a common key and a private key for the user, and helps to establish a communication session between the user and the hospital. Each user has a real identity, and the user can perform key negotiation multiple times. Before the user performs key negotiation, the user needs to be initialized to obtain a common key and a private key and a unique temporary identity. Each user can obtain system parameters and a session list between the user and the hospital. Then, an adversary model is established to simulate an adversary attacking encrypted data transmission in the emergency system, and the probability of successfully forging an authentication message and the probability of successfully obtaining a session key without modifying any message are calculated.

[0064] The beneficial effects of the above technical solution are that, by establishing a key negotiation process in the emergency system, the medical information of the hospital and the privacy information of the user are better protected. By establishing an adversary model, the security of confidential transmission is improved.

[0065] In another embodiment, S100, comprising:

[0066] S101: initializing the emergency system, setting a master key and a public key, and publishing key parameters of the emergency system;

[0067] S102: the user sends an identity information request for registration to the emergency system, and the emergency system generates a temporary identity for the user after receiving the request information, and calculates a public key and a private key of the user as a key pair;

[0068] S103: sending the temporary identity and the key pair to the user through a secure channel in the system management module.

[0069] The working principle of the technical solution is as follows: the scheme adopted by the embodiment is that, first, the emergency system is initialized, a random number is selected as the master key of the emergency system, and the public key of the emergency system is generated, and finally the emergency system parameters are published; when a user sends an identity information request for registration to the system management module, the system management module generates a temporary identity for the user after receiving the request information, and then calculates the public key and the private key of the user as a key pair according to the emergency system parameters, and finally the system management module sends the temporary identity and the key pair to the user through a secure channel.

[0070] Let the master key be a serial number (i0, i1, i2, …, i k ), the sequence of the public key be (k0, k1, k2, …), and the key parameter sequence (e0, e1, e2, …, e k ) be obtained by calculation, then the formula is as follows:

[0071]

[0072] Among them, the initial state of the key coefficient (c1, c2, …, c n ) is (s1, s2, …, s n ), and c n =1; let the parameter m=m1m2m3…, and the ciphertext be c=e1e2e3…, and through the key parameter calculation algorithm, the user and the hospital can be transmitted end to end, and the receiving end can be the same key sequence.

[0073] The beneficial effects of the technical solution are that, by establishing a temporary identity for the user, the user's identity can be used only temporarily, avoiding the risk of user information leakage due to long-term storage of user information, and greatly improving the security of the emergency system.

[0074] In another embodiment, S102, comprising:

[0075] S1021: after the user registers, the user's temporary identity is used to establish an encrypted session between the user and the hospital in the emergency system;

[0076] S1022: a random number is selected at the user end, request information of the encrypted session is generated, and a unique digital signature is generated through a digital signature algorithm;

[0077] S1023: the request information and the digital signature are broadcasted, and the emergency system verifies whether the equation formed by the secret key parameter and the public key of the user is established after receiving the broadcast message of the user; if the equation is established, the request information of the user is added to the encrypted session list, and the current public key is saved.

[0078] The working principle of the technical solution is that: the scheme adopted by the embodiment is that, after the user completes the registration, the user transmits the session by using the temporary identity, first selects a random number at the user end, generates request information, each user calculates a digital signature according to a specific service request, and finally broadcasts the request information and the digital signature. When the system management module receives the broadcast information, it verifies whether the equation formed by the secret key parameter and the public key of the user is established, if the equation is established, the request information is added to the session list, and the public key is saved, and if multiple users broadcast through the above process, the system management module obtains multiple session lists.

[0079] In another embodiment, S300 comprises:

[0080] S301: Obtain the session list of the user, and send the request information of the encrypted session to the system management module;

[0081] S302: Verify whether the user identity in the request information is a legal registered identity, if not, refuse the session request of the user;

[0082] S303: If yes, the system management module creates a session group between the hospital and the legal user for the user, selects a random number as a session identifier, then creates a ring group according to the user identity by the system management module, and the multiple users in the ring group are neighbors of each other, and the information in the ring group is broadcasted.

[0083] The working principle of the technical solution is that: the scheme adopted by the embodiment is that, after the user completes the registration, the user transmits the session by using the temporary identity, first selects a random number at the user end, generates request information, each user calculates a digital signature according to a specific service request, and finally broadcasts the request information and the digital signature. When the system management module receives the broadcast information, it verifies whether the equation formed by the secret key parameter and the public key of the user is established, if the equation is established, the request information is added to the session list, and the public key is saved, and if multiple users broadcast through the above process, the system management module obtains multiple session lists.

[0084] The beneficial effects of the technical solution are that: by adopting the scheme provided by the embodiment, the user information can be protected in a closed environment by creating a ring group, and when the emergency system calls the user information, the user information can be directly searched in the ring group.

[0085] In another embodiment, S304 comprises:

[0086] S3041: After receiving the response message from the system management module encrypted session, the user carries out the second mutual authentication and key agreement, and obtains the shared session key therefrom;

[0087] S3042: The user terminal generates a random secret number, and generates the first negotiation information from the secret number, then the user calculates the first session signature according to the first negotiation information, and finally sends the first session signature and the first negotiation information to the neighbor users in the ring group;

[0088] S3043: The user verifies whether the user in the emergency system is a legal user according to the first session signature and the first negotiation information.

[0089] In another embodiment, S3042, comprising:

[0090] S30421: The neighbor user receives the first negotiation information sent, verifies whether the first negotiation information in the neighbor user is consistent with the negotiation information held by the user, if not, the session is terminated;

[0091] S30422: If yes, it is verified whether the neighbor user is a legal registered identity and carries a preset sequence parameter, if not, the session is terminated;

[0092] S30423: The system management module receives the session information of the user, and calculates whether the negotiation information and the shared session key equation of the user and the neighbor user are established, if not, the user who fails to pass the verification is requested again;

[0093] S30424: If yes, the second negotiation information of the user is generated, and the second signature is calculated according to the second negotiation information, and finally the second signature and the second negotiation information are broadcasted.

[0094] The working principle of the above technical solution is that: the scheme adopted in this embodiment is that after receiving the session response message from the system management module, the user carries out the second mutual authentication and key agreement process, and obtains the shared session key; first, the user generates a random secret number, and calculates the first negotiation information, then the user generates the first signature for the first negotiation information, and finally sends the first negotiation information and the first signature to the neighbor users; after receiving the first negotiation information sent by the neighbor user, it is verified whether the random secret number in the first negotiation information is the same as the secret number held by the user, if the same, continue to verify, if different, terminate the verification; it is verified whether the neighbor user is a legal registered identity and the sequence number is 0, if yes, continue to verify, if not, terminate the verification; after receiving the message of the neighbor user, it is verified whether the first signature and the public key and the private key of the user are established, if the equation is established, continue, otherwise, the user who fails to pass the verification is requested to connect again.

[0095] After the authentication is successful, the user continues to select a random number, and generates second negotiation information, then the user generates a second signature for the second negotiation information, and finally the system management module broadcasts the second negotiation information and the second signature; after the user receives the second negotiation information, the user continues to verify whether the second negotiation information is the same as the negotiation information of the neighbor user, if yes, the verification continues, if no, the verification is terminated; the user continues to verify whether the user is a legal registered identity and whether the sequence parameter is 1, if yes, the verification continues, if no, the verification is stopped; the user continues to verify whether the second signature information of the user and the equation of the common key and the private key are established, if yes, the verification continues, if no, the verification is terminated. After the authentication is successful, the shared session key is calculated.

[0096] After the authentication is successful, the process of calculating the shared session key is calculated by the formula:

[0097]

[0098] Wherein, L is the common key of a plurality of users, e is the calculation result of calculating the signature and the user selecting the random number, containing the internal P j is the private key of the user, Y j is the negotiation information of the user and the hospital information transmission, m is the number of users, g is the system parameter, x is the secret number, L j is the shared session key calculated.

[0099] In another embodiment, further comprising:

[0100] S30425: receiving the broadcast information of the user, and verifying whether a plurality of neighbor users are legal registered identities in a loop, if yes, calculating the session key in turn;

[0101] S30246: establishing an encrypted session between the user and the hospital through the session key, if the user does not receive all the negotiation information in the process of the encrypted session, adding the temporary identity of the user who does not send the negotiation information to the failure information list, and sending to the system management module at the same time;

[0102] S30247: if the system management module receives a plurality of failure information from different users, removing the corresponding temporary identity user in the failure information list from the session group, and regenerating the session identification and constructing a new ring group; re-sending the negotiation information to the user who is not removed, and establishing an encrypted session.

[0103] The working principle of the technical solution is that in the process of establishing a session, if a user does not receive all negotiation information, the user who has not sent negotiation information is temporarily added to a failure information list, and the system management module is sent, if the system management module receives failure information from different users, the user identity of the failure information is removed from the ring group, and the remaining users are regenerated to form a ring group of session identifiers and information, and then sent to normal users, and finally the session establishment process is executed.

[0104] Referring to Figure 2 In another embodiment, S400, comprising:

[0105] S401: an adversary obtains a session key related to the temporary identity of the user, and the long-term key is a public key and a private key used by the user for negotiation;

[0106] S402: user modeling is performed on the data of the attacked user, and the negotiation information execution process between the set of users is eavesdropped;

[0107] S403: the protocol execution and the session key are attacked, and the attack result is returned;

[0108] S404: the return result after the attack is obtained, the probability of the adversary successfully forging the authentication message and the probability of successfully obtaining the session key are calculated.

[0109] The working principle of the technical solution is that the scheme adopted in this embodiment is that it is assumed that an adversary completely controls the communication channel and can obtain the key pair of the user's temporary identity, the adversary models the attack information, eavesdrops the protocol execution process between the users, and backs up the protocol execution record, and allows the adversary to send request information to the system management module in the emergency system, after the system management module receives the inquiry of the adversary, the system management module generates a reply and returns it to the adversary, the adversary continues to attack the key pair of the user, and performs key modeling, when the adversary inquires the system management module, the system management module returns the key pair of the user to the adversary.

[0110] The beneficial effects of the technical solution are that the scheme provided in this embodiment can establish an adversary model to forge authentication messages or impersonate legitimate users, and obtain messages in key negotiation; and by calculating the probability of the adversary successfully forging the authentication message and the probability of the adversary successfully obtaining the key pair without modifying any message, the emergency system can be maximally avoided from being invaded.

[0111] In another embodiment, the key negotiation method of the emergency system based on 5G encrypted signal transmission, characterized in that, further comprising:

[0112] S500: The information collection module in the emergency system is further configured to collect face information of a user and process the face information as identity verification information;

[0113] S600: Determine a user type according to the face information of the user and obtain a medical information data interface corresponding to the user type;

[0114] S700: Query whether the user information in a preset user database is correct, and if the query is successful, obtain the data interface to call medical information in the emergency system; the medical information includes hospital identity information, department information and disease type identification selected by the user.

[0115] The working principle of the above technical solution is that the information collection module in the emergency system is configured to collect face information of a user, and when the user registers information, face recognition is required, and the face recognition result is included in the user database, and when the user uses the emergency system, the user can directly log in and use the emergency system according to the face information, and after the user logs in successfully, the user selects medical information in the emergency system, for example, the user needs to be treated for fever, first selects a hospital, enters a fever clinic of a certain hospital client, selects doctor information and selects disease type identification according to the prompt, and finally obtains a treatment result.

[0116] The beneficial effects of the above technical solution are that the scheme provided in the embodiment can accelerate the speed of the user entering the emergency system, and the face is a unique identification method, which can improve the security of the system and protect the personal information of the user. Through the accurate selection method, the user can quickly obtain diagnosis and treatment, and the medical efficiency is improved.

[0117] Reference Figure 3 In another embodiment, S700 includes:

[0118] S701: When the user information is transmitted, an encrypted signal needs to be generated, and the encrypted signal is encrypted by a public key;

[0119] S702: The positions of different hospitals in the emergency system are located, and the positioning information is calculated as superimposed encrypted information; since the positions of different hospitals are different, the encrypted information formed according to the hospital position information is unique;

[0120] S703: When the hospital obtains the emergency information sent by the user through the emergency system, the superimposed encrypted information and the public key need to be decrypted by a private key; since the encrypted information is different, and the decrypted information is different according to different hospitals.

[0121] The working principle of the technical solution is that: the scheme adopted by the embodiment is that when a user transmits information, the user information needs to be encrypted, and a public key is generated as an encryption method of the user; the position of a hospital in the emergency system is positioned, and the position information of the hospital is calculated as superimposed encrypted information, and the encrypted information forms unique encrypted information according to the different positions; when the user uses the emergency system, the superimposed encrypted information and the private key need to be decrypted by the private key.

[0122] The beneficial effects of the technical solution are that: by using the scheme provided by the embodiment, the user information is encrypted by the public key and the private key, and the user information is decrypted by the hospital, so that the user and the hospital information are protected.

[0123] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the claims of the present application and their equivalents, the present application also intends to include these modifications and variations.

Claims

1. The key agreement method of the emergency system based on 5G encrypted signal transmission, characterized in that, Comprise: S100: Establish a system management module for identity management of users and hospitals in the session process, shared session key management and encrypted transmission management; S200: Initialize the emergency system, generate an encrypted signal when the user uses the emergency system, and establish a temporary identity of the user, and form a user public key and private key through the temporary identity for transmission of the encrypted signal; S300: Establish two entities of users and hospitals in the emergency system, which are mutually authenticated and key negotiated in the 5G network, and obtain the shared session key between the entities; S300, comprising: S301: Obtain the encrypted session list of the user, and send the request information of the encrypted session to the system management module; S302: Verify whether the user identity in the request information is a legal registered identity; if not, refuse the session request of the user; S303: If yes, the system management module creates a session group between the hospital and the legal user for the user, selects a random number as the session identifier, and then creates a ring group according to the user identity, and the multiple users in the ring group are mutually neighbors, and the information in the ring group is broadcasted; S304, comprising: S3041: After receiving the response message of the encrypted session from the system management module, the user performs mutual authentication and key negotiation, and obtains the shared session key therefrom; S3042: The user end generates a random secret number, and calculates the first negotiation information from the secret number, then the user calculates the first session signature according to the first negotiation information, and finally sends the first session signature and the first negotiation information to the neighbor users in the ring group; S3043: The neighbor user verifies whether the user in the emergency system is a legal user according to the first session signature and the first negotiation information; S400: Establish an enemy model to calculate the probability of the enemy successfully forging an authentication message and the probability of successfully obtaining the shared session key when the emergency system is attacked maliciously.

2. The 5G encryption signal transmission based first-aid system key agreement method of claim 1, wherein, S200, comprising: S201: Initialize the emergency system, set the master key and the system public key, and publish the key parameters of the emergency system; S202: The user sends an identity information request for registration to the emergency system, and the emergency system generates a temporary identity for the user after receiving the request information, and calculates the public key and private key of the user as a key pair; S203: Send the temporary identity and the key pair to the user through the secure channel in the system management module.

3. The 5G encryption signal transmission based first-aid system key agreement method of claim 2, wherein, S202, comprising: S2021: After the user registers, establish an encrypted session between the user and the hospital in the emergency system using the temporary identity of the user; S2022: Select a random number at the user end, generate the request information of the encrypted session, and generate a unique digital signature by calculating the digital signature algorithm; S2023: broadcast the request information with digital symbols, and verify whether the equation formed by the key parameter and the public key of the user is established after the emergency system receives the broadcast message of the user; if the equation is established, the request information of the user is added to the encrypted session list, and the current public key is saved.

4. The 5G encryption signal transmission based first-aid system key agreement method of claim 1, wherein, S3042, comprising: S30421: the neighbor user receives the first negotiation information, verifies whether the first negotiation information in the neighbor user is consistent with the first negotiation information held by the user, if not, the session is terminated; S30422: if yes, verify whether the neighbor user is a legal registered identity and carries a preset sequence parameter, if not, terminate the session; S30423: the system management module receives the session information of the user, and calculates whether the negotiation information of the user and the neighbor user and the shared session key equation are established, if not, reissue a request to the user who fails to pass the verification; S30424: if yes, generate the second negotiation information of the user, and calculate the second signature according to the second negotiation information, and finally broadcast the second signature and the second negotiation information.

5. The 5G encryption signal transmission based first-aid system key agreement method of claim 4, wherein, Also comprising: S30425: the system management module receives the broadcast information of the user, and cyclically verifies whether a plurality of neighbor users are legal registered identities, if yes, the shared session key is calculated in turn; S30246: an encrypted session is established between the user and the hospital through the shared session key, if the user does not receive all the negotiation information in the process of the encrypted session, the temporary identity of the user who does not send the negotiation information is added to the failure information list, and is sent to the system management module at the same time; S30247: if the system management module receives a plurality of failure information from different users, the user with the corresponding temporary identity in the failure information list is removed from the session group, and a new ring group is generated and constructed; The negotiation information is retransmitted to the user who is not removed, and an encrypted session is established.

6. The 5G encryption signal transmission based first-aid system key agreement approach of claim 1, wherein, Also comprising: S500: the information acquisition module in the emergency system is used to acquire the face information of the user, and the face information is processed as identity verification information; S600: determine the user type according to the face information of the user and the temporary identity, and obtain the medical information data interface corresponding to the user type; S700: query whether the user information in the preset user database is correct, if the query is successful, call the medical information in the emergency system through the data interface; the medical information includes hospital identity recognition, department information and disease type identification selected by the user.

7. The 5G encryption signal transmission based first-aid system key agreement method of claim 6, wherein, S700, comprising: S701: an encrypted signal needs to be generated when the user information is transmitted, and the encrypted signal is encrypted by the public key of the user; S702: the positions of different hospitals in the emergency system are located, and the positioning information is calculated as superimposed encrypted information; because the positions of different hospitals are different, the encrypted information formed according to the hospital position information is unique; S703: when the hospital obtains the emergency information sent by the user through the emergency system, the superimposed encrypted information needs to be decrypted through the private key of the user.

Citation Information

Patent Citations

  • Anti-leakage group key negotiation system and method in group communication

    CN108259185A

  • Pre-hospital first-aid intelligent calling software system

    CN112165524A

  • Certificateless two-party authenticated key agreement method, device, and data storage medium

    WO2017202161A1