A Privacy-Preserving Handshake Method Based on Medical Conditions in a Medical Social Network
By designing a disease-based privacy protection handshake method in medical social networks, the problem of insufficient user privacy protection in the prior art is solved, the anonymity and security are improved, and the function of tracking malicious users is provided.
Patent Information
- Application Number
- CN202211573832.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-08
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-12-08
AI Technical Summary
There is a lack of effective privacy protection handshake methods in existing medical social networks, especially when patients interact with patients with the same disease, they cannot effectively protect the user's true identity and key, pose security risks and cannot track malicious users.
A privacy-protected handshake method based on the disease is designed. Through the steps of system initialization, disease group initialization, registration, key generation and handshake, etc., it ensures that patients are anonymous during interaction, and can only shake hands with patients in the same disease group to generate a session key. At the same time, through the registration and key management of trusted institutions, tracking and identity revocation of malicious users can be achieved.
It realizes effective protection of user privacy in medical social networks, ensures patient anonymity and security, can track and deal with malicious users, and improves the security and reliability of the system.
Smart Images

Figure CN116389022B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of medical social networks, and particularly to a privacy protection handshake method based on diseases in a medical social network. Background Art
[0002] With the continuous development of the medical industry and the Internet, medical social networks have developed rapidly on this basis and are a crucial part in the construction of modern medical systems. A medical social network includes a trusted authority, medical centers, and legitimate patients registered at the trusted authority. The medical information of patients is stored at the medical centers. Doctors and patients at a long distance can share medical information through the medical social network. In the medical system, if a patient wants to establish contact with other patients having the same disease and communicate about the disease condition, such a need can also be realized by using the medical social network.
[0003] Medical social networks face many attacks and threats. At the same time, when a patient interacts with another patient having the same disease in a medical social network, the interactive medical information involves user privacy information. In a medical social network, it is necessary to design a solution for protecting privacy information such as the true identity, subordination relationship, and user's secret key of a user.
[0004] Although there are many privacy protection handshake solutions in medical social networks in recent years, some existing privacy protection handshake solutions do not conduct a detailed security analysis. Some solutions cannot provide a privacy protection handshake function based on the same disease for patients. Some solutions do not protect the secret keys of patients, bringing some security risks to the system and not providing a function for tracking malicious users. Therefore, the present invention designs a privacy protection handshake method based on diseases in a medical social network. Summary of the Invention
[0005] In order to overcome the deficiencies of the above-mentioned prior art, the present invention provides a privacy protection handshake method based on diseases in a medical social network.
[0006] The technical solution adopted by the present invention is as follows: A privacy protection handshake method based on diseases in a medical social network, comprising the following steps:
[0007] System initialization, initializing system patients and a trusted authority TA;
[0008] Disease group initialization, initializing disease groups in the system;
[0009] Registration, the trusted authority TA registers for a patient and generates a list of pseudonyms for the patient;
[0010] Secret key generation, the trusted authority TA generates a public-private key pair for the patient;
[0011] Handshake, an anonymous patient performs a privacy-preserving handshake based on symptoms with another anonymous patient without revealing his or her own symptoms. If the two patients belong to the same symptom group, a session key is generated after the handshake. Otherwise, the handshake fails, and the two parties in the handshake cannot know each other's true identity and the privacy information of the symptom group.
[0012] Specifically, the system initialization specifically includes: the trusted institution TA selects a secure elliptic curve E(F p ), select a point P on the curve as a generator, and two cyclic groups G of order q 1 and G 2 , bilinear map e:G 1 ×G 1 →G 2 , let g = e(P,P), TA selects three secure hash functions H 1 : Divide the system life cycle into N time slices of length ΔT, and the disease set M = {M 1 ,M 2 ,M 3 …}, where M i ∈{0,1} * Finally, the system public parameters params = {q, G 1 ,G 2 ,P,e,g,H 1 ,H 2 ,H 3 ,N,ΔT,M}.
[0013] Furthermore, the initialization of the disease group specifically includes: the trusted institution TA is different disease groups M i Pick a random number As the group private key of the disease group The disease group public key is TA is different symptoms M i Generated group public and private key pair
[0014] Furthermore, the registration specifically includes: patient U i When ∈U wants to register as a legitimate user of this system, in order to ensure the anonymity of the patient, TA i Select a pseudonym list Sent to patient, patientU i Select a random value from the pseudonym list, such as At MC Medical Center i Medical examination at MC i Determine what condition the patient has i , and send Give it to TA, and TA restores the patient's true identity ID i , and bind the ID i with the disease M i , and store it in the user table UserList.
[0015] Further, the key generation specifically includes: The patient U i inputs the current system time t 0 , and the expected privacy protection handshake communication duration j·ΔT, where ΔT represents a time slice and j∈{1,2,…,N}. TA uses the group public and private keys of this disease group and the input of the patient U i to calculate the public key of the patient Calculate the private key of the patient using the group private key of the group to which the patient belongs
[0016] Further, the handshake specifically includes:
[0017] Two legally registered patients U A , U B , whose diseases are M A and M B , and the group keys are respectively and where Let the pseudo-identities of the two patients be ID A , ID B , the public keys of the two patients are and the private keys are Before starting the privacy protection handshake protocol, the two patients exchange their anonymous identities and the public keys of the patients and The specific steps for the patient privacy protection handshake key negotiation are as follows:
[0018] Let the patient U A be the initiator of the privacy protection handshake. U A secretly selects a random number to calculate the partial session key Then calculate c A = H 2 (params, gpk A ) and Finally, U A sends (r A , d A ) to U B ;
[0019] The patient U B secretly selects a random number Calculate the partial session key Calculate again c B =H 2 (params, gpk B ) and U B Send (r B , d B ) to U A ;
[0020] When U A receives (r B , d B ), it needs to restore the partial session key from r B U U A Use its own group public key and the public key of U B to calculate According to the formula Restore Then calculate Finally, U A Sends Auth A to U B ;
[0021] U B Calculate Restore Calculate U B Sends Auth B to U A ;
[0022] When U A receives Auth from U B , verify the equation B Whether it holds. If the equation holds, it means that the Restored by U A That is, U A and U B belong to the same disease group, and calculate the session key If the equation does not hold, it means that U A and U B do not belong to the same disease group and cannot negotiate the session key;
[0023] U B Verify the equation Whether it holds. If the equation holds, it means that the Restored by U B That is, U A and U B belong to the same disease group, and calculate the session key If the equation does not hold, it indicates that U A and U B do not belong to the same disease group and cannot negotiate a session key.
[0024] In the above solution, it also includes tracing the real identity of malicious users in the tracking system, specifically including: when a patient joins the system, they need to register at TA, and TA generates public and private keys for them. TA stores the real identity of the patient and the corresponding pseudonym list and the public and private keys generated based on the pseudonym During the secret handshake process, if there is a malicious user violating the protocol, TA can find the real identity of the malicious user by looking up the pseudonym list corresponding to the real identity.
[0025] In the above solution, it also includes identity revocation. When a malicious user appears in the system or a user logs out of the system, the trusted agency revokes the user and sends a notice to the legitimate users in the system, reminding them not to interact with the revoked user to avoid being maliciously attacked; specifically including: TA maintains a user revocation list URL. After TA traces a malicious user, TA removes the pseudonym identity bound to the user and the user's key and sends a warning message to other users, reminding them not to perform a privacy protection handshake with any user using When a legitimate user logs out of the system, TA also performs the same operation to revoke the user's identity.
[0026] In the above solution, it also includes key update to achieve key independence. The trusted agency updates the public and private keys for the patient, specifically including: the system cycle is divided into N equal-length time slices. Before performing the privacy protection handshake, A assigns a key with a survival period of (t 0 +j·ΔT) to the patient. When the key validity period has passed and the patient cannot perform the privacy protection handshake to negotiate a session key, the patient needs to request a key allocation from TA again. Let t 1 =t 0 +j·ΔT, and then apply to TA to allocate a key with a starting time of t 1 and a valid time of j·ΔT for performing the privacy protection handshake.
[0027] The present invention also discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the method for privacy protection handshake based on diseases in the medical social network as described above.
[0028] The advantages and beneficial effects of the present invention are as follows:
[0029] (1) Anonymity: When a legitimate registered patient wants to initiate a disease-based privacy protection handshake, they need to request the TA to allocate the patient's public and private keys for the privacy protection handshake. The TA will generate a list of pseudonyms corresponding to the patient and generate the public and private keys corresponding to the pseudonyms. During the patient's privacy protection handshake, the identity sent is also an anonymous identity. Neither party in the interaction can know the other party's true identity, and there is no information in the interaction that reveals the patient's disease. Therefore, illegal users cannot identify the other party's true identity and the affiliation of the disease group.
[0030] (2) Traceability: Every legitimate patient in the system needs to register with the TA. The TA has the registration information of each patient. If there are malicious users in the system, the malicious users in the system can be traced through the identity tracing algorithm.
[0031] (3) Key independence: The key update algorithm of the system can update the patient's keys regularly. If the patient's key is leaked in the previous time period, the adversary cannot use this key to obtain the session key in the current time period, and the leakage of the key in the current time period will not affect the security of the previous session key. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 is the system model diagram of the present invention;
[0033] Figure 2 is the flow chart of the privacy protection handshake module of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0034] The technical solutions in the embodiments of the present invention will be clearly and detailedly described below with reference to the accompanying drawings in the embodiments of the present invention. The described embodiments are only a part of the embodiments of the present invention.
[0035] Some symbol definitions of the present invention are as follows in the table:
[0036]
[0037] Referring to Figure 1 - Figure 2 , the specific implementation manner of the present invention is as follows:
[0038] 1. In the initial stage of the system, the medical social network system is initialized. First, the trusted authority TA selects a secure elliptic curve E(F p ), selects a point P on the curve as the generator, and two cyclic groups G 1 and G 2 of order q. The bilinear mapping e: G 1 × G 1 → G 2 , and let g = e(P, P). The TA selects three secure Hash functions H1 : Divide the system life cycle into N time slices of length ΔT. The disease set M = {M 1 , M 2 , M 3 …}, where M i ∈{0, 1} * . Finally, publish the system public parameters params = {q, G 1 , G 2 , P, e, g, H 1 , H 2 , H 3 , N, ΔT, M}.
[0039] 2. Initialization of the disease group M i in the system. The trusted authority TA selects a random number i as the group private key of this disease group . The group public key of the disease group is . The group public and private key pairs generated by TA for different diseases M i
[0040] 3. TA registers patients and generates a list of pseudonyms for patients. When patient U i ∈U wants to register as a legitimate user of this system, to ensure the anonymity of patients, TA selects a list of pseudonyms i for each patient U and sends it to the patient. Patient U i selects a random value from the list of pseudonyms, such as selecting to have a medical examination at the Medical Center (MC i ). MC i determines what diseases M i the patient has, and sends to TA. TA can recover the real identity ID i of the patient, bind ID i with the disease M i and store it in the user table UserList.
[0041] 4. The trusted authority TA generates a public and private key pair for patient U i . Patient U i inputs the current system time t 0 , and the expected privacy protection handshake communication duration j·ΔT, where ΔT represents the time slice and j ∈ {1, 2, …, N}. TA uses the patient's pseudonym and the input of patient U i to calculate the patient's public key and calculates the patient's private key using the group private key of the group to which the patient belongs
[0042] 5. When an anonymous user in the system performs a privacy - protected handshake based on a medical condition, a session key SK is generated after the handshake is successful. Assume there are two legally registered patients U A , U B in the system. They hope to perform a privacy - protected handshake based on the same medical condition without revealing their privacy and negotiate a session key for subsequent communication about their medical conditions. Their medical conditions are M A and M B respectively. The group keys are and respectively. Among them, assume the pseudo - identities of the two patients are ID A , ID B , and the public keys of the two patients are and the private keys are Before starting the privacy - protected handshake protocol, the two patients exchange their anonymous identities and the public keys of the patients and The specific steps for the key negotiation of the patients' privacy - protected handshake are as follows:
[0043] Assume patient U A is the initiator of the privacy - protected handshake. U A secretly selects a random number calculates the partial session key and then calculates the response value c A = H 2 (params, gpk A ) and the check value Finally, U A sends (r A , d A ) to U B .
[0044] Patient U B and patient U A perform similar operations. U B secretly selects a random number calculates the partial session key and then calculates the response value c B = H 2 (params, gpk B ) and the check value U B sends (r B , d B ) to U A .
[0045] When U A receives (r B , d B ), it is necessary to restore part of the session key from r B U A uses its own group public key and the public key of U B to calculate the auxiliary value According to the formula Restore Then calculate the authentication code to verify the accuracy of the restored part of the session key. Finally, U A sends Auth A to U B .
[0046] Due to the symmetry of the protocol, U B performs operations similar to those of U A Calculate the auxiliary value Restore Calculate the authentication code Finally, U B sends Auth B to U A .
[0047] When U A receives Auth from U B B , verify the equation Whether it holds. If the equation holds, it means that the A restored by U i.e., U A and U B belong to the same disease group, and calculate the session key If the equation does not hold, it means that U A and U B do not belong to the same disease group and cannot negotiate the session key.
[0048] U B performs operations similar to those of U A to verify the equation Whether it holds. If the equation holds, it means that the B restored by U i.e., U A and U B belong to the same disease group, and calculate the session key If the equation does not hold, it means that U A and U B do not belong to the same disease group and cannot negotiate the session key.
[0049] 6. When there is a malicious user in the system, the real identity of the patient and the corresponding list of pseudonyms and the public and private keys generated based on the pseudonyms are stored at TA. During the secret handshake process, if a malicious user violates the protocol, TA can find the real identity of the malicious user by looking up the list of pseudonyms corresponding to the real identity.
[0050] 7. When the system revokes a malicious user or a user exits the system, TA removes the pseudonym identity bound to the user and the user's key and sends a warning message to other users, reminding them not to perform a privacy protection handshake with any user who uses . When a legitimate user exits the system, TA also performs the same operation to revoke the user's identity.
[0051] 8. When the validity period of the key has passed and the patient cannot perform a secret handshake to negotiate a session key, the patient needs to submit a key distribution request to TA again. Let t 1 = t 0 + j·ΔT, and then apply to TA to allocate a key with a starting time of t 1 and a validity period of j·ΔT for the secret handshake, and update the user's public and private keys to and
[0052] The above embodiments should be understood as being only for illustrative purposes of the present invention and not for limiting the protection scope of the present invention. After reading the content described in the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.
Claims
1. A privacy - protected handshake method based on diseases in a medical social network, characterized in that, it includes the following steps: System initialization, initializing system patients and trusted authority TA, specifically including: The trusted authority TA selects a secure elliptic curve E(F p ), selects a point P on the curve as the generator, two cyclic groups G 1 and G 2 , a bilinear mapping e: G 1 × G 1 → G 2 , let g = e(P, P), TA selects three secure Hash functions H 1 : H 2 : H 3 : represents the set of secure prime numbers, represents an element in the cyclic group G 1 , divides the system lifetime into N time slices of length ΔT, the disease set M = {M 1 , M 2 , M 3 ...}, where M i ∈ {0, 1} * , finally, publishes the system public parameters params = {q, G 1 , G 2 , P, e, g, H 1 , H 2 , H 3 , N, ΔT, M}; Disease group initialization, initializing the disease groups in the system, specifically including: the trusted authority TA for different disease groups M i Select a random number As the group private key of this disease group The group public key of the disease group is TA for different diseases M i Generated group public and private key pairs Registration, the trusted institution TA registers the patient and generates a pseudonym list for the patient, including: i ∈U wants to register as a legitimate user of this system, TA will i Select a pseudonym list Sent to patient, patientU i Select a random value from the pseudonym list, such as At MC Medical Center i Medical examination at MC i Determine what condition the patient has i , and send Give it to TA, TA will restore the patient's real ID i , and the ID i With disease M i Bind and store in the user table UserList; Key generation: The trusted authority TA generates a public-private key pair for the patient, specifically including: patient U i Input the current time t of the system 0 , the expected privacy protection handshake communication duration j·ΔT, where ΔT represents a time slice and j ∈ {1, 2, …, N}. TA uses the group public and private keys of this disease group and the input of patient U i to calculate the public key of the patient Calculate the private key of the patient using the group private key of the group to which the patient belongs Handshake: An anonymous patient conducts a privacy - protected handshake based on diseases with another anonymous patient without exposing their own diseases. If the two patients belong to the same disease group, a session key is generated after the handshake; otherwise, the handshake fails. Specifically, it includes: Two legally registered patients U A , U B , whose diseases are M A and M B , and the group keys are respectively and Among them Let the pseudo-identities of the two patients be ID A , ID B , and the public keys of the two patients are The private keys are Before starting the privacy protection handshake protocol, the two patients exchange their anonymous identities and the public keys of the patients and The specific steps of the key negotiation for the patient privacy protection handshake are as follows: Let patient U A be the initiator of the privacy - protected handshake. U A secretly selects a random number to calculate a partial session key and then calculates c A = H 2 (params, gpk A ) and Finally, U A sends (r A , d A ) to U B ; Patient U B Randomly select a secret number Calculate a partial session key Then calculate c B = H 2 (params, gpk B ) and U B Send (r B , d B ) to U A ; When U A receives (r B , d B ), it is necessary to restore part of the session key from r B . U A uses its own group public key and the public key of U B to calculate According to the formula restore Then calculate Finally, U A sends Auth A to U B ; U B Calculate Restore Calculate U B Send Auth B to U A ; When U A receives Auth B from U B , verify whether the equation holds. If the equation holds, it means that the A restored by U , that is, U A and U B belong to the same disease group, and calculate the session key If the equation does not hold, it means that U A and U B do not belong to the same disease group and cannot negotiate the session key; U B Verify the equation to see if it holds. If the equation holds, it means that U B restored i.e., U A and U B belong to the same disease group, and calculate the session key If the equation does not hold, it means that U A and U B do not belong to the same disease group and cannot negotiate the session key.
2. The privacy - protected handshake method based on diseases in a medical social network according to claim 1, characterized in that: It also includes tracing the real identity of malicious users in the system. When a patient joins the system, they need to register at TA. TA generates public and private keys for them and stores the patient's real identity and the corresponding list of pseudonyms at TA. and the public and private keys generated based on the pseudonyms During the secret handshake process, if a malicious user violates the protocol, TA can find the real identity of the malicious user by looking up the list of pseudonyms corresponding to the real identity.
3. The privacy - protected handshake method based on diseases in a medical social network according to claim 1, characterized in that: It also includes identity revocation. The TA maintains a user revocation list URL. After the TA traces a malicious user, the TA removes the pseudonymous identity bound to that user and the user's secret key and sends a warning message to other users, reminding them not to perform a privacy protection handshake with any user who uses . When a legitimate user exits the system, the TA also performs the same operation to revoke the user's identity.
4. The privacy - protected handshake method based on diseases in a medical social network according to claim 1, characterized in that: It also includes key update. The system cycle is divided into N equal-length time slices. Before performing the privacy protection handshake, the TA assigns a key with a survival period of (t 0 +j·ΔT) to the patient. When the key's validity period has passed and the patient cannot perform the privacy protection handshake to negotiate the session key, the patient needs to request a key distribution from the TA again. Let t 1 =t 0 +j·ΔT, and then apply to the TA to assign a key with a starting time of t 1 and a validity period of j·ΔT for the privacy protection handshake.
5. A computer - readable storage medium, characterized in that: The computer - readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the privacy - protected handshake method based on diseases in a medical social network according to any one of claims 1 - 4.
Citation Information
Patent Citations
Symptom-based cross-domain dynamic anonymous Authentication group key management method and system
CN107231230A
Identity authentication and data security transmission method in medical sensor network environment
CN111083150A