An electronic medical identity authentication protocol
By using hash functions, bilinear operations, and zero-knowledge proofs to generate credentials in the electronic medical identity authentication protocol, combined with a revocation algorithm, the efficiency problem of large attribute sets and the revocability of user attributes are solved, malicious users can be tracked, and the security and reliability of the electronic medical system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHAANXI NORMAL UNIV
- Filing Date
- 2023-05-05
- Publication Date
- 2026-04-24
AI Technical Summary
Existing attribute-based electronic medical identity authentication protocols are inefficient when dealing with large sets of attributes, cannot promptly revoke user attributes, and lack malicious user tracking capabilities, leading to information leaks and difficulties in resolving medical disputes.
An electronic medical identity authentication protocol is adopted, which generates credentials through hash functions and bilinear operations, and combines zero-knowledge proofs and revocation algorithms to achieve efficient processing of large attribute sets, attribute revocation and identity traceability. Treatment plan credentials are generated using access structures and private keys, and key management and user authentication are performed at an authoritative center.
It enables efficient processing of user attributes under a large attribute set, timely revocation of expired attributes, and tracking of malicious users in medical disputes, ensuring information security and system stability.
Smart Images

Figure CN116760550B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of electronic medical technology, and more specifically to an electronic medical identity authentication protocol. Background Technology
[0002] Most existing eHealth authentication protocols employ attribute-based technology. Attribute-based authentication protocols can use finer-grained attributes instead of user identities as unique identifiers. There are two types of attribute authentication protocols: Key-Based Attribute Encryption (KP-ABE) and Ciphertext Policy-Based Attribute Encryption (CP-ABE). KP-ABE embeds the access policy into the key and file attributes into the ciphertext. The receiver assigns a specific access policy upon receiving a message, making it suitable for video-on-demand and database access. CP-ABE embeds the access policy into the ciphertext and user attributes into the key, allowing the information owner to define the access policy and send user messages. In attribute-based eHealth systems, CP-ABE is the most commonly used implementation.
[0003] Existing attribute-based e-health systems suffer from several problems: First, they lack support for large attribute sets. When the user attribute set is large, most existing solutions are too inefficient to meet practical needs. Second, they lack user attribute revocation functionality. If a user attribute should be revoked but isn't, unauthorized users can decrypt messages that shouldn't be decrypted, potentially leading to information leaks and other losses for patients. Third, they lack malicious user tracking functionality. In the event of a medical dispute, it's necessary to locate the sender of the treatment plan; however, because attribute-based e-health systems don't use identity information, most solutions don't consider malicious user tracking.
[0004] Therefore, providing an electronic medical identity authentication protocol that can efficiently handle large attribute sets, has revocable attributes, and allows for traceable identity is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] In view of this, the present invention provides an electronic medical identity authentication protocol that can efficiently handle large attribute sets, whose attributes are revocable and whose identities are traceable.
[0006] To achieve the above objectives, the present invention adopts the following technical solution:
[0007] An electronic medical identity authentication protocol includes the following steps:
[0008] S1: The patient server sends the patient's health data m to the cloud server;
[0009] S2: The doctor server downloads the patient's health data m from the cloud server and generates a treatment plan;
[0010] The doctor server obtains an access structure from the cloud server. ;
[0011] S3: The doctor server utilizes health data m and access structures. Attribute set The private key SK is used to generate a certificate for the treatment plan, and the treatment plan and certificate are sent to the patient server.
[0012] S3 further includes:
[0013] S31: Combine the health data m with the access structure Perform a chaining to obtain a hash value. ;
[0014] Wherein, the access structure The corresponding access matrix is row y column ; , It is the transpose of matrix M, and H is a hash function;
[0015] S32: Calculate the first voucher Second certificate ;
[0016] in, and It is a group The two generators, group G is the order chosen by the authoritative center for the system during system initialization. cyclic group; It is part of the private key SK; and These are common parameters calculated by the authority center during system initialization. , , z represents the set of attributes The number of attributes included. , , Represents a finite field. , and All are random elements;
[0017] S33: Calculate intermediate variables , Third voucher Fourth voucher Fifth certificate and zero-knowledge proof evidence ;
[0018] in For intermediate parameters; The parameter is random. This indicates a specific attribute of the doctor. express In attribute collection Node-wise multiplication; , and This refers to the signature key obtained during doctor registration; The doctor's master private key. ; Indicates bilinear operation; Denotes a first-order bilinear mapping; group The authority center selects the order of the system during system initialization. The cyclic group; t represents the timestamp entered by the authoritative center when the doctor registers; Verify the algorithm in zero-knowledge proof. , and Does a certain relationship exist?
[0019] S34: The doctor's server will send the treatment plan and credentials. Give the server to the patient;
[0020] The method for obtaining the private key SK is as follows:
[0021] Step 1: The doctor server sends the set of attributes and public key of the registered doctor to the authority center server;
[0022] Step 2: The authoritative center server calculates the attribute key, update key, and partial key for each attribute of the registered doctor based on the received attribute set and public key, and sends the key set to the doctor server; the key set includes the attribute key, update key, and partial key for all attributes;
[0023] Step two further includes:
[0024] Computational attribute key and ;
[0025] in, Represented as a set of attributes Attributes in Choose a random number; Indicates existence leaf nodes on Represents leaf nodes Path to the root node; leaf nodes Indicates assignment to the property binary tree There are no leaf nodes defined in the table, which are used to store public keys. , Represents leaf nodes Data stored on it;
[0026] Run the revocation algorithm and calculate the update key. and , ;
[0027] in, Indicates the undo algorithm; This represents the set of nodes that represent the output of the undo algorithm. Representative attribute The tree structure; Indicates the list of items to be removed. Indicates the timestamp entered by the authoritative center; This represents a random number to be selected;
[0028] Compute partial key ;
[0029] Send key set Give it to the doctor's server;
[0030] Step 3: The doctor server calculates the signature key for all attributes based on the received key set to obtain the private key SK of the registered doctor;
[0031] Step three further includes:
[0032] Calculate the signature key , and ;
[0033] in, Represents a set and set The intersection of the nodes contains the node association product; Represents leaf nodes The set of nodes on the path to the root node; This represents the set of nodes that represent the output of the undo algorithm.
[0034] Obtain the private key of the registered doctor ;
[0035] S4: The patient server verifies whether the credentials for the treatment plan conform to the preset public access structure. If yes, the treatment plan is accepted; otherwise, the treatment plan is rejected.
[0036] S4 further includes:
[0037] S41: Verification Does the condition hold true? If it does, reject the treatment plan; if it does not hold true, proceed with S42.
[0038] in It is an algorithm in zero-knowledge proofs, used to verify evidence. Is it legal?
[0039] S42: Verification If the diagnosis is not valid, then the treatment plan should be rejected.
[0040] This indicates that the doctor's attributes for sending the treatment plan have expired; if this is true, execute S43.
[0041] S43: Verification Whether the request is accepted; if accepted, the treatment plan is accepted, indicating that the doctor who sent the treatment plan meets the access structure; if not accepted, the treatment plan is rejected.
[0042] Furthermore, it also includes: if leaf nodes If not defined, then in A random number is selected and stored in the leaf node n, and this random number is used as... ;
[0043] If leaf node If it has already been defined, then directly extract the data stored in leaf node n as... .
[0044] Furthermore, step one includes: the doctor server sending the attribute set and public key along with the identity... To the authoritative central server; leaf nodes It is also used to store identities. .
[0045] Furthermore, in the event of a medical dispute:
[0046] The patient server sends the treatment plan to the authoritative central server. ;
[0047] Authority Center Server Verification Equation Is this valid? If valid, then return the doctor's true identity. .
[0048] As can be seen from the above technical solutions, compared with the prior art, the electronic medical identity authentication protocol disclosed in this invention can achieve the following beneficial technical effects:
[0049] 1. The electronic medical identity authentication protocol provided by this invention can still be processed efficiently even when the user attribute set is large;
[0050] 2. The authentication protocol of this invention can revoke expired user attributes, so that the revoked attributes cannot participate in the authentication process;
[0051] 3. This invention can track malicious users and issue evidence in the event of a medical dispute. Attached Figure Description
[0052] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0053] Figure 1 A flowchart of an electronic medical identity authentication protocol provided by the present invention.
[0054] Figure 2 This is a schematic diagram of a binary tree node for the cancellation algorithm in one embodiment. Detailed Implementation
[0055] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0056] like Figure 1 As shown, this embodiment of the invention discloses an electronic medical identity authentication protocol, including the following steps:
[0057] S1: The patient server sends the patient's health data m to the cloud server;
[0058] S2: The doctor server downloads the patient's health data m from the cloud server and generates a treatment plan;
[0059] The doctor server obtains an access structure from the cloud server. ;
[0060] S3: The doctor server utilizes health data m and access structures. Attribute set The private key SK is used to generate a certificate for the treatment plan, and the treatment plan and certificate are sent to the patient server.
[0061] S4: The patient server verifies whether the credentials for the treatment plan conform to the preset public access structure. If yes, the treatment plan is accepted; otherwise, the treatment plan is rejected.
[0062] S3 includes:
[0063] S31: Combine the health data m with the access structure Perform a chaining to obtain a hash value. ;
[0064] Wherein, the access structure The corresponding access matrix is row y column ; , It is the transpose of matrix M, and H is a hash function;
[0065] S32: Calculate the first voucher Second certificate ;
[0066] in, and It is a group The two generators, group G is the order chosen by the authoritative center for the system during system initialization. cyclic group; It is part of the private key SK; and These are common parameters calculated by the authority center during system initialization. , , z represents the set of attributes The number of attributes included. , , Represents a finite field. , and All are random elements;
[0067] S33: Calculate intermediate variables , Third voucher Fourth voucher Fifth certificate and zero-knowledge proof evidence ;
[0068] in For intermediate parameters; The parameter is random. This indicates a specific attribute of the doctor. express In attribute collection Node multiplication in the middle; , and This refers to the signature key obtained during doctor registration; The doctor's master private key. ; Indicates bilinear operation; Denotes a first-order bilinear mapping; group The authority center selects the order of the system during system initialization. The cyclic group; t represents the timestamp entered by the authoritative center when the doctor registers; Verify the algorithm in zero-knowledge proof. , and Does a certain relationship exist?
[0069] S34: The doctor's server will send the treatment plan and credentials. Server for patients.
[0070] S4 further includes:
[0071] S41: Verification Does the condition hold true? If it does, reject the treatment plan; if it does not hold true, proceed with S42.
[0072] in It is an algorithm in zero-knowledge proofs, used to verify evidence. Is it legal?
[0073] S42: Verification If the diagnosis is not valid, then the treatment plan should be rejected.
[0074] This indicates that the doctor's attributes for sending the treatment plan have expired; if this is true, execute S43.
[0075] S43: Verification Whether the request is accepted; if accepted, the treatment plan is accepted, indicating that the doctor who sent the treatment plan meets the access structure; if not accepted, the treatment plan is rejected.
[0076] Furthermore, the method for obtaining the private key SK is as follows:
[0077] Step 1: The doctor server sends the registered doctor's attribute set and public key to the authority center server;
[0078] Step 2: The authoritative center server calculates the attribute key, update key, and partial key for each attribute of the registered doctor based on the received attribute set and public key, and sends the key set to the doctor server; the key set includes the attribute key, update key, and partial key for all attributes.
[0079] Step 3: The doctor server calculates the signature key for all attributes based on the received key set to obtain the private key SK of the registered doctor.
[0080] Furthermore, step two further includes:
[0081] Computational attribute key and ;
[0082] in, Represented as a set of attributes Attributes in Choose a random number; It indicates that it exists leaf nodes on Represents leaf nodes Path to the root node; leaf nodes Indicates assignment to the property binary tree There are no leaf nodes defined in the table, which are used to store public keys. , Represents leaf nodes Data stored on it;
[0083] Run the revocation algorithm and calculate the update key. and , ;
[0084] in, Indicates the undo algorithm; This represents the set of nodes that represent the output of the undo algorithm. Representative attribute The tree structure; This indicates the list of items to be removed. Indicates the timestamp entered by the authoritative center; This represents a random number to be selected;
[0085] Compute partial key ;
[0086] Send key set Give it to the doctor's server;
[0087] Furthermore, step three further includes:
[0088] Calculate the signature key , and ;
[0089] in, Represents a set and set The intersection of the nodes contains the node association product; Represents leaf nodes The set of nodes on the path to the root node; This represents the set of nodes that represent the output of the undo algorithm.
[0090] Obtain the private key of the registered doctor .
[0091] Furthermore, if leaf nodes If not defined, then in Randomly select a number and store it in the leaf.
[0092] In node n, and use this random number as ;
[0093] If leaf node If it has already been defined, then directly extract the data stored in leaf node n as... .
[0094] Furthermore, step one includes the doctor server sending the attribute set and public key along with the identity information. To the authoritative central server; leaf nodes It is also used to store identities. ;
[0095] Furthermore, in the event of a medical dispute:
[0096] The patient server sends its treatment plan to the authoritative central server. ;
[0097] Authority Center Server Verification Equation Is this valid? If valid, then return the doctor's true identity. .
[0098] The following is combined Figure 2 The authentication protocol with revocation function of this invention is described in detail below:
[0099] Nodes marked with a checkmark indicate that the undo algorithm has been run. The node that needs to be modified;
[0100] The nodes marked with errors are represented by the undo algorithm. Nodes that need to be revoked;
[0101] Suppose a doctor's attributes Needs to be revoked:
[0102] Attributes found in the authority center The corresponding binary tree and the leaf nodes storing identity information (assumed to be in this embodiment) );
[0103] The authority center runs the revocation algorithm. Cancel all of them Nodes in the path; i.e., removing leaf nodes. Leaf nodes and root node These three nodes;
[0104] When the cancellation is completed, and a new user needs to be registered, and their attributes... The identity information is precisely stored in the node In this context, the process of generating a new user's private key SK is as follows:
[0105] 1) Authoritative center compute attribute private key
[0106]
[0107]
[0108]
[0109]
[0110] in, Represents the root node Data stored on it; and Representing nodes respectively and Data stored on it;
[0111] 2) The authoritative center calculates and updates the key:
[0112] Undo algorithm in this embodiment The output set of nodes includes nodes and nodes , That is, the node that needs to be modified by running the undo algorithm is the node. and nodes .
[0113] Therefore, the formula for calculating the updated key is:
[0114]
[0115]
[0116]
[0117]
[0118] in, , , and All values are random values selected by an authoritative center;
[0119] 3) The authoritative center calculates a portion of the key. ;
[0120] 4) The authoritative center sends the key set. For the doctor; among them For new
[0121] The set of attributes for registered doctors;
[0122] 5) Calculate the signature key:
[0123] In this embodiment, the cancellation algorithm Output node set and leaf nodes The set of nodes on the path to the root node The intersection of the leaf nodes ,Right now ;
[0124] Therefore, the formula for calculating the signature key is:
[0125] ; ; ;
[0126] in, It is a random value.
[0127] 6) Newly registered doctors receive their own private keys. .
[0128] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0129] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An electronic medical identity authentication protocol, characterized in that, Includes the following steps: S1: The patient server sends the patient's health data m to the cloud server; S2: The doctor server downloads the patient's health data m from the cloud server and generates a treatment plan; The doctor server obtains an access structure from the cloud server. ; S3: The doctor server utilizes health data m and access structures. Attribute set The private key SK is used to generate a certificate for the treatment plan, and the treatment plan and certificate are sent to the patient server. S3 further includes: S31: Combine the health data m with the access structure Perform a chaining to obtain a hash value. ; Wherein, the access structure The corresponding access matrix is row y column ; , It is the transpose of matrix M, and H is a hash function; S32: Calculate the first voucher Second certificate ; in, and It is a group The two generators, group G is the order chosen by the authoritative center for the system during system initialization. cyclic group; It is part of the private key SK; and These are common parameters calculated by the authority center during system initialization. , , z represents the set of attributes The number of attributes included. , , Represents a finite field. , and All are random elements; S33: Calculate intermediate variables , Third voucher Fourth voucher Fifth certificate and zero-knowledge proof evidence ; in For intermediate parameters; The parameter is random. This indicates a specific attribute of the doctor. express In attribute collection Node-wise multiplication; , and This refers to the signature key obtained during doctor registration; The doctor's master private key. ; Indicates bilinear operation; Denotes a first-order bilinear mapping; group The authority center selects the order of the system during system initialization. The cyclic group; t represents the timestamp entered by the authoritative center when the doctor registers; Verify the algorithm in zero-knowledge proof. , and Does a certain relationship exist? S34: The doctor's server will send the treatment plan and credentials. Give the server to the patient; The method for obtaining the private key SK is as follows: Step 1: The doctor server sends the registered doctor's attribute set and public key to the authority center server; Step 2: The authoritative center server calculates the attribute key, update key, and partial key for each attribute of the registered doctor based on the received attribute set and public key, and sends the key set to the doctor server; the key set includes the attribute key, update key, and partial key for all attributes; Step two further includes: Computational attribute key and ; in, Represented as a set of attributes Attributes in Choose a random number; Indicates existence leaf nodes on Represents leaf nodes Path to the root node; leaf nodes Indicates assignment to the property binary tree There are no leaf nodes defined in the table, which are used to store public keys. , Represents leaf nodes Data stored on it; Run the revocation algorithm and calculate the update key. and , ; in, Indicates the undo algorithm; This represents the set of nodes that represent the output of the undo algorithm. Representative attribute The tree structure; This indicates the list of items to be removed. Indicates the timestamp entered by the authoritative center; This represents a random number to be selected; Compute partial key ; Send key set Give it to the doctor's server; Step 3: The doctor server calculates the signature key for all attributes based on the received key set to obtain the private key SK of the registered doctor; Step three further includes: Calculate the signature key , and ; in, Represents a set and set The intersection of the nodes contains the node association product; Represents leaf nodes The set of nodes on the path to the root node; This represents the set of nodes that represent the output of the undo algorithm. Obtain the private key of the registered doctor ; S4: The patient server verifies whether the credentials for the treatment plan conform to the preset public access structure. If yes, the treatment plan is accepted; otherwise, the treatment plan is rejected. S4 further includes: S41: Verification Does the condition hold true? If it does, reject the treatment plan; if it does not hold true, proceed with S42. in It is an algorithm in zero-knowledge proofs, used to verify evidence. Is it legal? S42: Verification If the diagnosis is not valid, then the treatment plan should be rejected. This indicates that the doctor's attributes for sending the treatment plan have expired; if this is true, execute S43. S43: Verification Whether the request is accepted; if accepted, the treatment plan is accepted, indicating that the doctor who sent the treatment plan meets the access structure; if not accepted, the treatment plan is rejected.
2. The electronic medical identity authentication protocol according to claim 1, characterized in that, Further steps include: If leaf node If not defined, then in A number is randomly selected and stored in the leaf node n. And use the random number as ; If leaf node If it has already been defined, then directly extract the data stored in leaf node n as... .
3. The electronic medical identity authentication protocol according to claim 1, characterized in that, Step one further includes the doctor server sending the attribute set and public key along with the identity. To the authoritative central server; leaf nodes It is also used to store identities. .
4. The electronic medical identity authentication protocol according to claim 3, characterized in that, like Medical disputes occur: The patient server sends the treatment plan to the authoritative central server. ; Authority Center Server Verification Equation Is this valid? If valid, then return the doctor's true identity. .
Citation Information
Patent Citations
System and method for controlling anonymous hospitalizing and security access of medical information based on property
CN104683351A
Edge cloud-oriented electronic health record traceable generation and access control method
CN113849843A