A nurse station information interaction platform authentication management method and system
By using hash function to calculate the private key, the key store is stored in the blockchain center, encryption generates activation sequence files, smart card saving and identity hash value, session disconnection and failure mechanisms on the nurse station information interaction platform, the problem of incomplete data security and authentication processes in the existing technology is solved, and higher data security and system stability are achieved.
Patent Information
- Application Number
- CN202310822934.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-06
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2043-07-06
AI Technical Summary
The existing nurse station information interaction platform authentication management methods have weak data security, credibility and tamper-proof capabilities, resulting in reduced information leakage and system security, incomplete authentication process, resulting in data inconsistency, and unauthorized devices are activated during the activation of authentication, and the system security is weak.
The hash function is used to calculate the private key, which increases data security, and the key store is stored in the blockchain center to ensure the trustworthiness and tamper-proof ability of data, encrypted generation of activation sequence files, the storage of smart cards and identity hash values increase the reliability of identity authentication, and the disconnection and failure mechanism of session protects user information and system stability. Ensure the integrity and security of device activation authentication. Each step has specific calculations and verifications. It uses hash values and exclusive OR operations to process data, and introduces an authentication mechanism and a failure retry mechanism.
It improves data security and system stability, ensures the integrity and security of device activation authentication, reduces potential security risks and attacks, and improves the security and process stability of authentication.
Smart Images

Figure CN116781280B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of platform authentication, and specifically refers to an authentication management method and system for a nurse station information interaction platform. Background Art
[0002] With the rapid development of information technology, information security and user identity authentication have become important tasks for the management of nurse station platforms. However, the existing authentication management methods for nurse station information interaction platforms have problems such as information leakage due to weak data security, credibility and anti-tampering capabilities, reduced communication security, and thus reduced overall system security and stability; incomplete authentication process leads to inconsistent data at each node, which in turn leads to attackers tampering with transmitted data and impersonating identities, reducing data security and reliability, and data expiration due to improper transmission delay settings; unauthorized devices are activated during the device activation authentication process, the system security is weak, and authentication fails due to network problems and other errors. Summary of the invention
[0003] In view of the above situation, in order to overcome the defects of the prior art, the present invention provides a method and system for managing the authentication of a nurse station information interaction platform. In view of the problem that the security, credibility and tamper-proof ability of data are weak, which leads to information leakage, reduced communication security, and thus reduced overall system security and stability, this solution adopts a hash function to calculate the private key, which increases the security of the data. The key library is stored in the blockchain center, which ensures the credibility and tamper-proof ability of the data. The activation sequence file is generated by encryption to ensure the security of sensitive information and prevent information leakage. The storage of smart cards and identity hash values increase the reliability of identity authentication. The session disconnection and failure mechanism protects the security of user information and the stability of the system. In view of the problem that the data of each node is inconsistent due to the incomplete authentication process, and then the attacker tampers with the transmitted data and impersonates the identity, which reduces the security and reliability of the data, and the data expires due to improper transmission delay settings, this solution ensures the activation of the device. The integrity and security of authentication, each step has specific calculations and verifications to ensure the correctness and consistency of each node and data, and uses hash values and XOR operations to process data to ensure data integrity, prevent attackers from impersonating identities, and tamper with transmitted data. By comparing timestamps and setting the maximum allowable transmission delay, excessive delays and data expiration problems can be avoided. Multiple verification mechanisms are used to improve security and reliability, thereby reducing potential security risks and attacks. In response to the problems of unauthorized device activation, weak system security, and authentication failures due to network problems and other errors during the device activation authentication process, this solution introduces an identity authentication mechanism in the authentication process to ensure that the activation request comes from a legitimate device and prevent malicious activation requests, and adds a failure retry mechanism to ensure the correct transmission and storage of data. The dual mechanism increases the security of authentication and the stability of the process, thereby improving authentication security, enhancing fault tolerance, and making the authentication process clear and unambiguous, reducing errors and confusion.
[0004] The technical solution adopted by the present invention is as follows: The present invention provides a method for managing the authentication of a nurse station information interaction platform, the method comprising the following steps:
[0005] Step S1: Data preservation, using hash function to calculate private key and shared key, saving information to key library, and encrypting to generate activation sequence file;
[0006] Step S2: User registration, the user selects a unique ID and password, calculates the hash value of the user password and the identity hash value, and saves them to the smart card;
[0007] Step S3: User login, the user inserts the smart card into the reader and enters the ID and password, introduces the calculation of hash value and random number, session disconnection and failure mechanism, and the smart card sends a login request to the gateway node through the public channel;
[0008] Step S4: Device activation authentication in LAN state, using a complete authentication process, using hash values and XOR operations to encrypt, verify and tamper-proof data, avoiding excessive delays and data expiration by comparing timestamps and setting the maximum allowable transmission delay, and using multiple verification mechanisms;
[0009] Step S5: Device activation authentication in the Internet state, introduce an identity authentication mechanism in the authentication process to ensure that the activation request comes from a legitimate device and prevent malicious activation requests, and add a failure retry mechanism;
[0010] Step S6: Device activation authentication in the absence of a network, the authentication device scans and pairs via Bluetooth, uses a private key to encrypt and send the BLE protocol for activation device authentication, and introduces an identity authentication mechanism for authentication;
[0011] Step S7: Password change. The user inserts the smart card into the reader and enters the ID and password. The smart card calculates the relevant random value and hash value and performs identity authentication. If the authentication is successful, the user enters the new password and modifies the relevant information in the smart card. Otherwise, the session is interrupted.
[0012] Step S8: The new sensor device node is connected, the blockchain center selects the new sensor device node, calculates a new shared key, saves the relevant information and sends it to the gateway node, and the gateway node stores and updates the information in the key library.
[0013] Furthermore, in step S1, the data storage specifically includes the following steps:
[0014] Step S11: Calculate the gateway node private key using the following formula:
[0015] S g =h(ID g ||S BC );
[0016] In the formula, S g is the private key of the gateway node, h() is the hash function, ID g is the identifier of the gateway node, S BC is the private key of the blockchain center BC, || is the splicing operation;
[0017] Step S12: Calculate the shared key using the following formula:
[0018] S sn =h(ID sn ||S BC );
[0019] In the formula, S sn is the shared key between the gateway node and the sensor device node, IDsn is the identifier of the sensor device node;
[0020] Step S13: Save the keystore, {ID sn , S sn}Save by blockchain center BC in sensor device node SN k middle;
[0021] Step S14: The blockchain center saves and sends to the gateway node, and the blockchain center BC saves {ID g , S g , ID sn , S sn} and send it to the gateway node GW j ;
[0022] Step S15: Information storage. All nurse station hosts need to record batch and equipment hardware information into the equipment library when leaving the factory, and record the motherboard serial number key information into the library;
[0023] Step S16: Encrypt and generate an activation sequence file, which includes hardware information, platform module configuration content, and account encryption content.
[0024] Furthermore, in step S2, the user registration specifically includes the following steps:
[0025] Step S21: Calculate the hash value of the user's password. The user selects a unique ID and password, generates a random number r1, calculates the hash value of the password, and converts {ID i , HPW i}Sent to the gateway node GW j , the formula used is as follows:
[0026] HPW i =h(r1||PW i );
[0027] Where, HPW i is the hash value of user i's password, ID i is the ID of user i, PW i is the password of user i;
[0028] Step S22: Calculate the hash value, gateway node GW j Received {ID i , HPW i}, a random number r2 is generated using a pseudo-random number generator, and R1, R2, and R3 are calculated at timestamp T1 using the following formula:
[0029] R1=h(HPW i ||T1);
[0030] R2=h(HPW i ||ID g );
[0031] R3=h(R1||r2||S g )⊕h(HPW i ||T1);
[0032] In the formula, || is a string concatenation operation, ⊕ is an XOR operation, R1 is the hash value of the password of user i and the timestamp T1, and the hash value is calculated using a hash function, and R2 is the hash value of the password of user i and the identifier ID of the gateway node g The hash value is calculated by combining and performing XOR operation on R3.
[0033] Step S23: Smart card saves, gateway node GW j {r2, T1, ID g ,h(), R1, R2, R3} is saved in the smart card SC storing the user identification information and sent to user i;
[0034] Step S24: Calculate the identity hash value. User i receives {r2, T1, ID g , h(), R1, R2, R3}, calculate the identity hash value and write it into the smart card SC. The formula used is as follows:
[0035] HID i =h(PW i ||ID i )⊕r1;
[0036] In the formula, HID i is the identity hash value of user i.
[0037] Further, in step S3, the user login specifically includes the following steps:
[0038] Step S31: Smart card insertion: User i inserts the smart card SC into the reader and enters the ID i and PW i ;
[0039] Step S32: Obtaining data, user i selects a nearest gateway node, establishes a communication link with the sensor device node, and obtains the data required by the user;
[0040] Step S33: The smart card performs the first calculation using the following formula:
[0041] r1 * =HID i ⊕h(PW i ||IDi );
[0042] HPW i * =H(R1 * ||PW i );
[0043] R2 * =h(HPW i * ||ID g );
[0044] In the formula, r1 * is the random value calculated by the smart card SC, HPW i * is the hash value of the password of user i calculated by the smart card SC, R2 * It is a random number generated by the gateway node;
[0045] Step S34: Verification, the smart card SC checks R2 and R2 * Are they equal? If R2=R2 * , then verify the ID of user i i and PW i , otherwise, the session is terminated;
[0046] Step S35: The smart card performs a second calculation. The smart card SC generates a random number r3 and calculates F1, F2 and F3 at timestamp T2. The formula used is as follows:
[0047] F1=R3⊕h(HPW i ||T1);
[0048] F2=h(T2||r3||F1||ID g );
[0049] F3=h(r3||T2)⊕F1;
[0050] Where, F1 is the value obtained by XOR operation, F2 is the hash value calculated by the smart card SC, and F3 is the value obtained by XOR operation;
[0051] Step S36: Send a login request, the smart card SC sends a login request to the gateway node GW through a public channel. j Send a login request.
[0052] Further, in step S4, the device activation authentication in the local area network state specifically includes the following steps:
[0053] Step S41: The gateway node performs the first calculation. When the gateway node GW j After receiving the login request, F1 is calculated at timestamp T3 *、F1 * ⊕F3, the formula used is as follows:
[0054] r3 * =h(PW i ||ID i )⊕r3⊕h(PW i ||ID i )
[0055] T2 * =h(T2);
[0056] F1 * =h(R1||R2||S g );
[0057] F1 * ⊕F3=h(r3 * ||T2 * ); where F1 * It is the gateway node GW j The calculated value, F1 * ⊕F3 is the gateway node GW j The calculated hash value, r3 * is the value obtained by XOR operation, T2 * is the hash value obtained by hashing the timestamp T2;
[0058] Step S42: First check, gateway node GW j Check whether (T3-T2) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T3-T2) < ΔT, proceed to the next step. Otherwise, terminate the session.
[0059] Step S43: First verification, gateway node GW j Calculate F2 * , and verify that F2 * Is it equal to F2? If F2 * =F2, then user i is authenticated, otherwise, the session is interrupted. The formula used is as follows:
[0060] F2 * =h(T2 * ||r3 * ||F1 * ||ID g );
[0061] Where, F2 * It is the gateway node GW j The calculated hash value;
[0062] Step S44: The gateway node performs a second calculation, and the gateway node GWj Generate a random number r4 and calculate R4, R5 and R6 using the following formula:
[0063] R4=h(ID sn ||R1||S sn ||r4||T3);
[0064] R5=(R3 * ||T3||r4)⊕S sn ;
[0065] R6=R1⊕h(ID sn ||h(r4)||r3 * );
[0066] Where R4 is the gateway node GW j The calculated hash value, R5 is the value obtained by XOR operation, and R6 is the value obtained by XOR operation;
[0067] Step S45: the gateway node sends a request for the first time;
[0068] Step S46: The sensor device node performs the first calculation, and calculates h(r3 ** ||r4 * ||T3 * ), the formula used is as follows:
[0069] r3 ** =h(HPW i * ||ID i )⊕r3⊕h(HPW i * ||ID i )
[0070] r4 * =h(PW i ||ID i )⊕r4⊕h(PW i ||ID i )
[0071] T3 * =h(T3);
[0072] h(r3 ** ||r4 * ||T3 * )=R5⊕S sn ;
[0073] In the formula, h(r3 ** ||r4 * ||T3 * ) is the value obtained by XOR operation, r3** Is the value obtained by XOR operation, r4 * is the value obtained by XOR operation, T3 * is the hash value obtained by hashing the timestamp T3;
[0074] Step S47: Second check, sensor device node SN k Check whether (T4-T3) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T4-T3) < ΔT, proceed to the next step. Otherwise, terminate the session.
[0075] Step S48: The sensor device node performs a second calculation using the following formula:
[0076] R1 * =R6⊕h(ID sn ||h(r4 * )||r3 ** );
[0077] R4 * =h(ID sn ||R1 * ||S sn ||r4 * ||T3 * );
[0078] Where R1 * is the value obtained by XOR operation, R4 * It is the sensor device node SN k The calculated hash value;
[0079] Step S49: Third check, sensor device node SN k Check R4 * Is it equal to R4? If R4 * =R4, then proceed to the next step, otherwise, terminate the session;
[0080] Step S410: The sensor device node performs a third calculation, and the sensor device node SN k Generate a random number r5 and calculate SK i , B1 and B2, the formula used is as follows:
[0081] SK i =h(R1 * ||r3 ** ||r4 * ||r5);
[0082] B1=h(T4||r5||S sn ||ID sn ||T3||SK i);
[0083] B2=h(r5||T4)⊕r4 * ;
[0084] In the formula, SK i It is the sensor device node SN k The key of B1 is used to verify and identify the identity, and B2 is used to verify the data integrity.
[0085] Step S411: the sensor device node sends a message;
[0086] Step S412: The gateway node performs the third calculation and calculates h(r5) at timestamp T5. * ||T4 * ), the formula used is as follows:
[0087] r5 * =h(PW i ||ID i )⊕r5⊕h(PW i ||ID i )
[0088] T4 * =h(T4);
[0089] h(r5 * ||T4 * ) = B2 ⊕ r4;
[0090] In the formula, h(r5 * ||T4 * ) is the value obtained by XOR operation, r5 * is the value obtained by XOR operation, T4 * is the hash value obtained by hashing the timestamp T4;
[0091] Step S413: Fourth check, gateway node GW j Check whether (T5-T4) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T5-T4) < ΔT, proceed to the next step; otherwise, terminate the session.
[0092] Step S414: Second verification, gateway node GW j Calculate B1 * , and verify that B1 * Is it equal to B1? If B1 * =B1, then for the sensor device node SN k Verify, otherwise, terminate the session. The formula used is as follows:
[0093] B1 * =h(T4* ||r5 * ||S sn ||ID sn ||T3 * ||SK i );
[0094] Where B1 * It is the gateway node GW j The calculated hash value;
[0095] Step S415: The gateway node performs the fourth calculation, and the formula used is as follows:
[0096] R7=h(SK i ||R1||r4||T5||R4);
[0097] R8=h(R5 * ||r4||T5)⊕r3 * ;
[0098] Where R7 is the gateway node GW j The calculated hash value, R8 is the value obtained by XOR operation;
[0099] Step S416: the gateway node sends a request for the second time;
[0100] Step S417: The smart card performs a third calculation, and calculates h(r5 ** ||r4 * ||T5 * ), the formula used is as follows:
[0101] r5 ** =HID i ⊕h(PW i ||ID i );
[0102] T5 * =h(T5);
[0103] h(r5 ** ||r4 * ||T5 * ) = R8 ⊕ r3;
[0104] In the formula, h(r5 ** ||r4 * ||T5 * ) is the value obtained by XOR operation, r5 ** is the value obtained by XOR operation, T5 * is the hash value obtained by hashing timestamp T5;
[0105] Step S418: The fifth check, the smart card SC checks whether (T6-T5) is less than the maximum allowable transmission delay ΔT between the transmitter and the receiver. If (T6-T5) < ΔT, proceed to the next step, otherwise, terminate the session.
[0106] Step S419: Third verification, smart card SC calculates R7 * , and verify R7 * Is it equal to R7? If R7 * =R7, the authentication is successful and the device is activated. Otherwise, the session is terminated. The formula used is as follows:
[0107] R7 * =h(SK i ||h(HPW i ||T1)||r4 * ||T5 * ||R4);
[0108] Where R7 * It is the hash value calculated by the smart card SC.
[0109] Further, in step S5, the device activation authentication in the Internet state specifically includes the following steps:
[0110] Step S51: The platform device is turned on and the main program is ensured to work normally;
[0111] Step S52: The main program generates a device information dynamic code through an encryption algorithm according to the public key content stored in the device in a normal networking state;
[0112] Step S53: The server inputs the dynamic code, decrypts the private key file to obtain the hardware device information and IP address gateway content, and sends the activation invitation protocol ① to the platform device through the UDP communication protocol;
[0113] Step S54: the platform device receives the activation invitation protocol ①, responds and provides device information to the nurse station server to authenticate and activate the UDP protocol ②, and introduces an identity authentication mechanism;
[0114] Step S55: After receiving the authentication activation UDP protocol ②, the nurse station server records and sends the authentication sequence content TCP protocol ③ to the designated device;
[0115] Step S56: After the platform device receives the authentication sequence content TCP protocol ③, it saves the sequence file content to the internal storage shared directory and sets the file to read-only mode. After successfully saving the file, it sends a confirmation authentication activation protocol ④ and adds a failure retry mechanism;
[0116] Step S57: After the nurse station server confirms receipt of the confirmation authentication activation agreement ④, it records the current device information and sequence file information to the database to complete the authentication;
[0117] Step S58: After the authentication device is restarted, the system main program will check the authentication sequence file stored in step S56, use the sequence file content to complete the platform system function initialization, and request the server to complete the token content registration and activation, complete the authentication, read the platform system function configuration and start running the platform multi-application system; if the file read fails or the file is invalid, re-enter step S53 and wait.
[0118] Further, in step S6, the device activation authentication in the no-network state specifically includes the following steps:
[0119] Step S61: The platform device is turned on and the main program is ensured to work normally;
[0120] Step S62: Ensure that the Bluetooth module is normal and undamaged, and record the authentication device public key file and the authentication sequence table file in the system storage location through a transmission tool;
[0121] Step S63: The authentication device is paired through Bluetooth scanning, and the private key is encrypted and sent to activate the device authentication BLE protocol ①, and the identity authentication mechanism is introduced at the same time;
[0122] Step S64: The platform device continuously saves the device authentication BLE protocol ①, and when encountering the specified ending content, stops parsing and receiving the content, and introduces an error handling mechanism;
[0123] Step S65: the platform device uses the public key file to parse the protocol content and intercept the specified byte content;
[0124] Step S66: If the platform device has completed authentication and activation, save the sender device information parsed by the specified bytes in the device authentication BLE protocol ①, add the authentication sequence table file, and splice the device information feedback to confirm the activation of the BLE protocol ②, then disconnect the Bluetooth link, and return to step S63 after a fixed interval;
[0125] Step S67: If the platform device is not authenticated and activated, the splicing device information feedback confirms the activation of the BLE protocol②;
[0126] Step S68: The authentication device key box receives the BLE protocol ②, parses and intercepts the specified byte content according to its own private key file, and if it corresponds to the device information saved in step S66, then the authentication device is recorded, added to the authentication sequence table file, and the step is directly stopped to disconnect Bluetooth. After a fixed interval, it returns to step S63; if it corresponds to the device authentication sequence generated by step S67, then go to step S69; if the BLE protocol ② is not received within the specified time, then the device is removed from the authentication sequence table file, Bluetooth is disconnected, and after a fixed interval, it returns to step S63, and the identity authentication mechanism is added in the process;
[0127] Step S69: The authentication device concatenates the private key file content and the device authentication sequence content, encrypts and sends the authentication activation BLE protocol ③;
[0128] Step S610: The platform device saves the BLE protocol ③, encounters the specified ending content, stops content parsing and receiving, uses the public key content to parse the protocol content, completes the authentication sequence content and public key content saving, and records the current sending end authentication device to join the authentication sequence table file, disconnects the Bluetooth link, and adopts an error handling mechanism in the process;
[0129] Step S611: All platform devices that have completed authentication start the blockchain algorithm, replace the authentication device key box to proceed to step S63, and perform BLE protocol ③ on all nearby devices in step S62;
[0130] Step S612: The above operation can be consolidated from step S63 to step S610 through the Bluetooth base station, which only serves as data transfer and does not affect the actual authentication result;
[0131] Step S613: When the device is in a local area network or Internet state, the authentication sequence table file of any authentication device is randomly imported into the information exchange server, and the registration and initialization of all devices can be directly completed;
[0132] Step S614: Add logging and monitoring functions to regularly check the system's operating status.
[0133] Furthermore, in step S7, the password change specifically includes the following steps:
[0134] Step S71: Smart card insertion: User i inserts the smart card SC into the reader and enters the ID i and PW i ;
[0135] Step S72: The smart card performs the first calculation using the following formula:
[0136] r1 * =HID i ⊕h(PW i||ID i );
[0137] HPW i * =H(R1 * ||PW i );
[0138] R2 * =h(HPW i * ||ID g );
[0139] h(R1||r2||S g ) = R3⊕h(HPW i ||T1);
[0140] In the formula, r1 * is the random value calculated by the smart card SC, HPW i * is the hash value of the password of user i calculated by the smart card SC, R2 * is a random number generated by the gateway node, h(R1||r2||S g ) is the value obtained by XOR operation;
[0141] Step S73: Verification, the smart card SC checks R2 and R2 * Are they equal? If R2=R2 * , then verify the ID of user i i and PW i , otherwise, the session is terminated;
[0142] Step S74: Enter a new password. User i enters the new password PW i new ;
[0143] Step S75: The smart card performs a second calculation, and the smart card SC generates a new random number r1 using a pseudo-random number generator. new , the formula used is as follows:
[0144] HID i new =r1 new ⊕h(PW i new ||ID i );
[0145] HPW i new =H(R1 * ||PW i new );
[0146] R2new =h(HPW i new ||ID g );
[0147] R3 new =h(R1||R2||S g )⊕h(PW i new ||T1);
[0148] In the formula, HID i new is the new identity hash value of user i, HPW i new is the new hash value of the password of user i calculated by the smart card SC, R2 new is the new random number, R3 new It is the value obtained by XOR operation;
[0149] Step S76: Replacement, the smart card SC replaces R2, R3 and HID with the corresponding new value R2 new 、R3 new and HID i new , the password was changed successfully.
[0150] Furthermore, in step S8, the new sensor device node connection specifically includes the following steps:
[0151] Step S81: Calculate and save the shared key, and the blockchain center BC selects a new sensor device node SN k , calculate the new shared key and store {SN k , S sn}, the formula used is as follows:
[0152] S sn =h(ID sn ||S BC );
[0153] In the formula, S sn is the shared key between the gateway node and the new sensor device node, ID sn is the identifier of the new sensor device node;
[0154] Step S82: The blockchain center sends to the gateway node, and the blockchain center BC sends {SN k , S sn} to gateway node GW j ;
[0155] Step S83: The gateway node stores and updates the key library. j Storage {SNk , S sn} and update the information in the keystore.
[0156] The present invention provides a nurse station information interaction platform authentication management system, including a data storage module, a user registration module, a user login module, a device activation authentication module in a local area network state, a device activation authentication module in an Internet state, a device activation authentication module in a non-network state, a password change module and a new sensor device node connection module;
[0157] The data storage module uses a hash function to calculate a private key and a shared key, saves the information to a key library, encrypts and generates an activation sequence file, and sends the activation sequence file to a user registration module;
[0158] The user registration module receives the activation sequence file sent by the data storage module, the user selects a unique ID and password, calculates the hash value of the user password and the identity hash value, and saves them to the smart card;
[0159] The user login module inserts the smart card into the reader and enters the ID and password, provides the reliability of security authentication through the calculation of hash values and random numbers, session disconnection and failure mechanisms, and sends the login request to the device activation authentication module in the LAN state, the device activation authentication module in the Internet state, and the device activation authentication module in the no-network state;
[0160] The device activation authentication module receives the login request sent by the user login module in the local area network state, adopts a complete authentication process, uses hash values and XOR operations to encrypt, verify and prevent tampering of data, avoids excessive delays and data expiration problems by comparing timestamps and setting maximum allowable transmission delays, uses multiple verification mechanisms to improve security and reliability, and sends the authentication results to the password change module;
[0161] The device activation authentication module in the Internet state receives the login request sent by the user login module, introduces an identity authentication mechanism in the authentication process to ensure that the activation request comes from a legitimate device and prevents malicious activation requests, adds a failure retry mechanism to ensure the correct transmission and storage of data, and the dual mechanism increases the security of authentication and the stability of the process, and sends the authentication result to the password change module;
[0162] The device activation authentication module receives the login request sent by the user login module in the no-network state, performs authentication using the BLE protocol and identity authentication mechanism, and sends the authentication result to the password change module;
[0163] The password change module receives the authentication results sent by the device activation authentication module in the LAN state, the device activation authentication module in the Internet state, and the device activation authentication module in the no-network state. The user inserts the smart card into the reader, enters the ID and password, and the smart card calculates the relevant random value and hash value and performs identity authentication. If the verification is passed, the new password is entered and the relevant information in the smart card is modified. Otherwise, the session is interrupted;
[0164] The new sensor device node connection module selects a new sensor device node, calculates a new shared key, saves relevant information and sends it to the gateway node, and the gateway node stores and updates the information in the key library to complete the new sensor device node connection.
[0165] The beneficial effects achieved by the present invention using the above scheme are as follows:
[0166] (1) In order to solve the problem that the security, credibility and tamper-proof ability of data are weak, which leads to information leakage and reduced communication security, and then reduces the overall security and stability of the system, this solution uses a hash function to calculate the private key, which increases the security of the data. The key library is stored in the blockchain center to ensure the credibility and tamper-proof ability of the data. The activation sequence file is encrypted to ensure the security of sensitive information and prevent information leakage. The storage of smart cards and identity hash values increases the reliability of identity authentication. The session disconnection and failure mechanism protects the security of user information and the stability of the system.
[0167] (2) In order to address the problems of inconsistent data at each node due to an incomplete authentication process, which may lead to attackers tampering with the transmitted data and impersonating the identity, reducing the security and reliability of the data, and causing data expiration due to improper transmission delay settings, this solution ensures the integrity and security of device activation authentication. Each step has specific calculations and verifications to ensure the correctness and consistency of each node and data. Hash values and XOR operations are used to process data to ensure data integrity and prevent attackers from impersonating the identity and tampering with the transmitted data. By comparing timestamps and setting the maximum allowable transmission delay, excessive delays and data expiration can be avoided. Multiple verification mechanisms are used to improve security and reliability, thereby reducing potential security risks and attacks.
[0168] (3) To address the problems of unauthorized device activation, weak system security, and authentication failures due to network problems and other errors during the device activation authentication process, this solution introduces an identity authentication mechanism into the authentication process to ensure that activation requests come from legitimate devices and prevent malicious activation requests. A failure retry mechanism is also added to ensure the correct transmission and storage of data. The dual mechanisms increase the security of authentication and the stability of the process, thereby improving authentication security, enhancing fault tolerance, and making the authentication process clear and unambiguous, reducing errors and confusion. BRIEF DESCRIPTION OF THE DRAWINGS
[0169] Figure 1 A flowchart of a method for managing the authentication of a nurse station information interaction platform provided by the present invention;
[0170] Figure 2 A flowchart of a nurse station information interaction platform authentication management system provided by the present invention;
[0171] Figure 3 is a schematic flow chart of step S1;
[0172] Figure 4 is a schematic flow chart of step S2;
[0173] Figure 5 is a schematic flow chart of step S3;
[0174] Figure 6 It is a flowchart diagram of step S7.
[0175] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention. DETAILED DESCRIPTION
[0176] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments; based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0177] In the description of the present invention, it should be understood that terms such as “upper”, “lower”, “front”, “back”, “left”, “right”, “top”, “bottom”, “inside” and “outside” indicating directions or positional relationships are based on the directions or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore should not be understood as limiting the present invention.
[0178] Example 1, see Figure 1 The present invention provides a method for managing the authentication of a nurse station information interaction platform, the method comprising the following steps:
[0179] Step S1: Data preservation, using hash function to calculate private key and shared key, saving information to key library, and encrypting to generate activation sequence file;
[0180] Step S2: User registration, the user selects a unique ID and password, calculates the hash value of the user password and the identity hash value, and saves them to the smart card;
[0181] Step S3: User login, the user inserts the smart card into the reader and enters the ID and password, introduces the calculation of hash value and random number, session disconnection and failure mechanism, and the smart card sends a login request to the gateway node through the public channel;
[0182] Step S4: Device activation authentication in LAN state, using a complete authentication process, using hash values and XOR operations to encrypt, verify and tamper-proof data, avoiding excessive delays and data expiration by comparing timestamps and setting the maximum allowable transmission delay, and using multiple verification mechanisms;
[0183] Step S5: Device activation authentication in the Internet state, introduce an identity authentication mechanism in the authentication process to ensure that the activation request comes from a legitimate device and prevent malicious activation requests, and add a failure retry mechanism;
[0184] Step S6: Device activation authentication in the absence of a network, the authentication device scans and pairs via Bluetooth, uses a private key to encrypt and send the BLE protocol for activation device authentication, and introduces an identity authentication mechanism for authentication;
[0185] Step S7: Password change. The user inserts the smart card into the reader and enters the ID and password. The smart card calculates the relevant random value and hash value and performs identity authentication. If the authentication is successful, the user enters the new password and modifies the relevant information in the smart card. Otherwise, the session is interrupted.
[0186] Step S8: The new sensor device node is connected, the blockchain center selects the new sensor device node, calculates a new shared key, saves the relevant information and sends it to the gateway node, and the gateway node stores and updates the information in the key library.
[0187] Example 2, see Figure 1 and Figure 3 This embodiment is based on the above embodiment. In step S1, data saving specifically includes the following steps:
[0188] Step S11: Calculate the gateway node private key using the following formula:
[0189] S g =h(ID g ||S BC );
[0190] In the formula, S g is the private key of the gateway node, h() is the hash function, ID g is the identifier of the gateway node, S BCis the private key of the blockchain center BC, || is the splicing operation;
[0191] Step S12: Calculate the shared key using the following formula:
[0192] S sn =h(ID sn ||S BC );
[0193] In the formula, S sn is the shared key between the gateway node and the sensor device node, ID sn is the identifier of the sensor device node;
[0194] Step S13: Save the keystore, {ID sn , S sn}Save by blockchain center BC in sensor device node SN k middle;
[0195] Step S14: The blockchain center saves and sends to the gateway node, and the blockchain center BC saves {ID g , S g , ID sn , S sn} and send it to the gateway node GW j ;
[0196] Step S15: Information storage. All nurse station hosts need to record batch and equipment hardware information into the equipment library when leaving the factory, and record the motherboard serial number key information into the library;
[0197] Step S16: Encrypt and generate an activation sequence file, which includes hardware information, platform module configuration content, and account encryption content.
[0198] Example 3, see Figure 1 and Figure 4 This embodiment is based on the above embodiment. In step S2, user registration specifically includes the following steps:
[0199] Step S21: Calculate the hash value of the user's password. The user selects a unique ID and password, generates a random number r1, calculates the hash value of the password, and converts {ID i , HPW i}Sent to the gateway node GW j , the formula used is as follows:
[0200] HPW i =h(r1||PW i );
[0201] Where, HPW i is the hash value of user i's password, IDi is the ID of user i, PW i is the password of user i;
[0202] Step S22: Calculate the hash value, gateway node GW j Received {ID i , HPW i}, a random number r2 is generated using a pseudo-random number generator, and R1, R2, and R3 are calculated at timestamp T1 using the following formula:
[0203] R1=h(HPW i ||T1);
[0204] R2=h(HPW i ||ID g );
[0205] R3=h(R1||r2||S g )⊕h(HPW i ||T1);
[0206] In the formula, || is a string concatenation operation, ⊕ is an XOR operation, R1 is the hash value of the password of user i and the timestamp T1, and the hash value is calculated using a hash function, and R2 is the hash value of the password of user i and the identifier ID of the gateway node g The hash value is calculated by combining and performing XOR operation on R3.
[0207] Step S23: Smart card saves, gateway node GW j {r2, T1, ID g ,h(), R1, R2, R3} is saved in the smart card SC storing the user identification information and sent to user i;
[0208] Step S24: Calculate the identity hash value. User i receives {r2, T1, ID g , h(), R1, R2, R3}, calculate the identity hash value and write it into the smart card SC. The formula used is as follows:
[0209] HID i =h(PW i ||ID i )⊕r1;
[0210] In the formula, HID i is the identity hash value of user i.
[0211] Example 4, see Figure 1 and Figure 5 This embodiment is based on the above embodiment. In step S3, user login specifically includes the following steps:
[0212] Step S31: Smart card insertion: User i inserts the smart card SC into the reader and enters the ID i and PW i ;
[0213] Step S32: Obtaining data, user i selects a nearest gateway node, establishes a communication link with the sensor device node, and obtains the data required by the user;
[0214] Step S33: The smart card performs the first calculation using the following formula:
[0215] r1 * =HID i ⊕h(PW i ||ID i );
[0216] HPW i * =H(R1 * ||PW i );
[0217] R2 * =h(HPW i * ||ID g );
[0218] In the formula, r1 * is the random value calculated by the smart card SC, HPW i * is the hash value of the password of user i calculated by the smart card SC, R2 * It is a random number generated by the gateway node;
[0219] Step S34: Verification, the smart card SC checks R2 and R2 * Are they equal? If R2=R2 * , then verify the ID of user i i and PW i , otherwise, the session is terminated;
[0220] Step S35: The smart card performs a second calculation. The smart card SC generates a random number r3 and calculates F1, F2 and F3 at timestamp T2. The formula used is as follows:
[0221] F1=R3⊕h(HPW i ||T1);
[0222] F2=h(T2||r3||F1||ID g );
[0223] F3=h(r3||T2)⊕F1;
[0224] Where, F1 is the value obtained by XOR operation, F2 is the hash value calculated by the smart card SC, and F3 is the value obtained by XOR operation;
[0225] Step S36: Send a login request, the smart card SC sends a login request to the gateway node GW through a public channel. j Send a login request.
[0226] By performing the above operations, in order to solve the problem that the security, credibility and tamper-proof ability of data lead to information leakage, the security of communication is reduced, and the overall security and stability of the system are reduced, this solution uses a hash function to calculate the private key, which increases the security of the data. The key library is stored in the blockchain center to ensure the credibility and tamper-proof ability of the data. The activation sequence file is encrypted to ensure the security of sensitive information and prevent information leakage. The storage of smart cards and identity hash values increases the reliability of identity authentication. The session disconnection and failure mechanism protects the security of user information and the stability of the system.
[0227] Example 5, see Figure 1 This embodiment is based on the above embodiment. In step S4, the device activation authentication in the local area network state specifically includes the following steps:
[0228] Step S41: The gateway node performs the first calculation. When the gateway node GW j After receiving the login request, F1 is calculated at timestamp T3 * 、F1 * ⊕F3, the formula used is as follows:
[0229] r3 * =h(PW i ||ID i )⊕r3⊕h(PW i ||ID i )
[0230] T2 * =h(T2);
[0231] F1 * =h(R1||R2||S g );
[0232] F1 * ⊕F3=h(r3 * ||T2 * );
[0233] Where F1 * It is the gateway node GW j The calculated value, F1 * ⊕F3 is the gateway node GW jThe calculated hash value, r3 * is the value obtained by XOR operation, T2 * is the hash value obtained by hashing the timestamp T2;
[0234] Step S42: First check, gateway node GW j Check whether (T3-T2) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T3-T2) < ΔT, proceed to the next step. Otherwise, terminate the session.
[0235] Step S43: First verification, gateway node GW j Calculate F2 * , and verify that F2 * Is it equal to F2? If F2 * =F2, then user i is authenticated, otherwise, the session is interrupted. The formula used is as follows:
[0236] F2 * =h(T2 * ||r3 * ||F1 * ||ID g );
[0237] Where, F2 * It is the gateway node GW j The calculated hash value;
[0238] Step S44: The gateway node performs a second calculation, and the gateway node GW j Generate a random number r4 and calculate R4, R5 and R6 using the following formula:
[0239] R4=h(ID sn ||R1||S sn ||r4||T3);
[0240] R5=(R3 * ||T3||r4)⊕S sn ;
[0241] R6=R1⊕h(ID sn ||h(r4)||r3 * );
[0242] Where R4 is the gateway node GW j The calculated hash value, R5 is the value obtained by XOR operation, and R6 is the value obtained by XOR operation;
[0243] Step S45: the gateway node sends a request for the first time;
[0244] Step S46: The sensor device node performs the first calculation, and calculates h(r3 ** ||r4 * ||T3 * ), the formula used is as follows:
[0245] r3 ** =h(HPW i * ||ID i )⊕r3⊕h(HPW i * ||ID i )
[0246] r4 * =h(PW i ||ID i )⊕r4⊕h(PW i ||ID i )
[0247] T3 * =h(T3);
[0248] h(r3 ** ||r4 * ||T3 * )=R5⊕S sn ;
[0249] In the formula, h(r3 ** ||r4 * ||T3 * ) is the value obtained by XOR operation, r3 ** Is the value obtained by XOR operation, r4 * is the value obtained by XOR operation, T3 * is the hash value obtained by hashing the timestamp T3;
[0250] Step S47: Second check, sensor device node SN k Check whether (T4-T3) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T4-T3) < ΔT, proceed to the next step. Otherwise, terminate the session.
[0251] Step S48: The sensor device node performs a second calculation using the following formula:
[0252] R1 * =R6⊕h(ID sn ||h(r4 * )||r3 ** );
[0253] R4 * =h(ID sn||R1 * ||S sn ||r4 * ||T3 * );
[0254] Where R1 * is the value obtained by XOR operation, R4 * It is the sensor device node SN k The calculated hash value;
[0255] Step S49: Third check, sensor device node SN k Check R4 * Is it equal to R4? If R4 * =R4, then proceed to the next step, otherwise, terminate the session;
[0256] Step S410: The sensor device node performs a third calculation, and the sensor device node SN k Generate a random number r5 and calculate SK i , B1 and B2, the formula used is as follows:
[0257] SK i =h(R1 * ||r3 ** ||r4 * ||r5);
[0258] B1=h(T4||r5||S sn ||ID sn ||T3||SK i );
[0259] B2=h(r5||T4)⊕r4 * ;
[0260] In the formula, SK i It is the sensor device node SN k The key of B1 is used to verify and identify the identity, and B2 is used to verify the data integrity.
[0261] Step S411: the sensor device node sends a message;
[0262] Step S412: The gateway node performs the third calculation and calculates h(r5) at timestamp T5. * ||T4 * ), the formula used is as follows:
[0263] r5 * =h(PW i ||ID i )⊕r5⊕h(PW i ||IDi )
[0264] T4 * =h(T4);
[0265] h(r5 * ||T4 * ) = B2 ⊕ r4;
[0266] In the formula, h(r5 * ||T4 * ) is the value obtained by XOR operation, r5 * is the value obtained by XOR operation, T4 * is the hash value obtained by hashing the timestamp T4;
[0267] Step S413: Fourth check, gateway node GW j Check whether (T5-T4) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T5-T4) < ΔT, proceed to the next step; otherwise, terminate the session.
[0268] Step S414: Second verification, gateway node GW j Calculate B1 * , and verify that B1 * Is it equal to B1? If B1 * =B1, then for the sensor device node SN k Verify, otherwise, terminate the session. The formula used is as follows:
[0269] B1 * =h(T4 * ||r5 * ||S sn ||ID sn ||T3 * ||SK i );
[0270] Where B1 * It is the gateway node GW j The calculated hash value;
[0271] Step S415: The gateway node performs the fourth calculation, and the formula used is as follows:
[0272] R7=h(SK i ||R1||r4||T5||R4);
[0273] R8=h(R5 * ||r4||T5)⊕r3 * ;
[0274] Where R7 is the gateway node GW jThe calculated hash value, R8 is the value obtained by XOR operation;
[0275] Step S416: the gateway node sends a request for the second time;
[0276] Step S417: The smart card performs a third calculation, and calculates h(r5 ** ||r4 * ||T5 * ), the formula used is as follows:
[0277] r5 ** =HID i ⊕h(PW i ||ID i );
[0278] T5 * =h(T5);
[0279] h(r5 ** ||r4 * ||T5 * ) = R8 ⊕ r3;
[0280] In the formula, h(r5 ** ||r4 * ||T5 * ) is the value obtained by XOR operation, r5 ** is the value obtained by XOR operation, T5 * is the hash value obtained by hashing timestamp T5;
[0281] Step S418: The fifth check, the smart card SC checks whether (T6-T5) is less than the maximum allowable transmission delay ΔT between the transmitter and the receiver. If (T6-T5) < ΔT, proceed to the next step, otherwise, terminate the session.
[0282] Step S419: Third verification, smart card SC calculates R7 * , and verify R7 * Is it equal to R7? If R7 * =R7, the authentication is successful and the device is activated. Otherwise, the session is terminated. The formula used is as follows:
[0283] R7 * =h(SK i ||h(HPW i ||T1)||r4 * ||T5 * ||R4);
[0284] Where R7 * It is the hash value calculated by the smart card SC.
[0285] By performing the above operations, this solution ensures the integrity and security of device activation authentication to address the problems of inconsistent data at each node due to incomplete authentication process, which may lead to attackers tampering with transmitted data and impersonating identities, reducing data security and reliability, and data expiration due to improper transmission delay settings. Each step has specific calculations and verifications to ensure the correctness and consistency of each node and data. Hash values and XOR operations are used to process data to ensure data integrity, prevent attackers from impersonating identities and tampering with transmitted data, avoid excessive delays and data expiration by comparing timestamps and setting the maximum allowable transmission delay, and use multiple verification mechanisms to improve security and reliability, thereby reducing potential security risks and attacks.
[0286] Example 6, see Figure 1 This embodiment is based on the above embodiment. In step S5, the device activation authentication in the Internet state specifically includes the following steps:
[0287] Step S51: The platform device is turned on and the main program is ensured to work normally;
[0288] Step S52: The main program generates a device information dynamic code through an encryption algorithm according to the public key content stored in the device in a normal networking state;
[0289] Step S53: The server inputs the dynamic code, decrypts the private key file to obtain the hardware device information and IP address gateway content, and sends the activation invitation protocol ① to the platform device through the UDP communication protocol;
[0290] Step S54: the platform device receives the activation invitation protocol ①, responds and provides device information to the nurse station server to authenticate and activate the UDP protocol ②, and introduces an identity authentication mechanism;
[0291] Step S55: After receiving the authentication activation UDP protocol ②, the nurse station server records and sends the authentication sequence content TCP protocol ③ to the designated device;
[0292] Step S56: After the platform device receives the authentication sequence content TCP protocol ③, it saves the sequence file content to the internal storage shared directory and sets the file to read-only mode. After successfully saving the file, it sends a confirmation authentication activation protocol ④ and adds a failure retry mechanism;
[0293] Step S57: After the nurse station server confirms receipt of the confirmation authentication activation agreement ④, it records the current device information and sequence file information to the database to complete the authentication;
[0294] Step S58: After the authentication device is restarted, the system main program will check the authentication sequence file stored in step S56, use the sequence file content to complete the platform system function initialization, and request the server to complete the token content registration and activation, complete the authentication, read the platform system function configuration and start running the platform multi-application system; if the file read fails or the file is invalid, re-enter step S53 and wait.
[0295] By performing the above operations, this solution introduces an identity authentication mechanism in the authentication process to address the problems of unauthorized device activation, weak system security, and authentication failures due to network problems and other errors during the device activation authentication process. This ensures that activation requests come from legitimate devices and prevents malicious activation requests. A failure retry mechanism is added to ensure the correct transmission and storage of data. The dual mechanisms increase the security of authentication and the stability of the process, thereby improving authentication security, enhancing fault tolerance, and making the authentication process clear and unambiguous, reducing errors and confusion.
[0296] Embodiment 7, see Figure 1 This embodiment is based on the above embodiment. In step S6, the device activation authentication in the absence of a network specifically includes the following steps:
[0297] Step S61: The platform device is turned on and the main program is ensured to work normally;
[0298] Step S62: Ensure that the Bluetooth module is normal and undamaged, and record the authentication device public key file and the authentication sequence table file in the system storage location through a transmission tool;
[0299] Step S63: The authentication device is paired through Bluetooth scanning, and the private key is encrypted and sent to activate the device authentication BLE protocol ①, and the identity authentication mechanism is introduced at the same time;
[0300] Step S64: The platform device continuously saves the device authentication BLE protocol ①, and when encountering the specified ending content, stops parsing and receiving the content, and introduces an error handling mechanism;
[0301] Step S65: the platform device uses the public key file to parse the protocol content and intercept the specified byte content;
[0302] Step S66: If the platform device has completed authentication and activation, save the sender device information parsed by the specified bytes in the device authentication BLE protocol ①, add the authentication sequence table file, and splice the device information feedback to confirm the activation of the BLE protocol ②, then disconnect the Bluetooth link, and return to step S63 after a fixed interval;
[0303] Step S67: If the platform device is not authenticated and activated, the splicing device information feedback confirms the activation of the BLE protocol②;
[0304] Step S68: The authentication device key box receives the BLE protocol ②, parses and intercepts the specified byte content according to its own private key file, and if it corresponds to the device information saved in step S66, then the authentication device is recorded, added to the authentication sequence table file, and the step is directly stopped to disconnect Bluetooth. After a fixed interval, it returns to step S63; if it corresponds to the device authentication sequence generated by step S67, then go to step S69; if the BLE protocol ② is not received within the specified time, then the device is removed from the authentication sequence table file, Bluetooth is disconnected, and after a fixed interval, it returns to step S63, and the identity authentication mechanism is added in the process;
[0305] Step S69: The authentication device concatenates the private key file content and the device authentication sequence content, encrypts and sends the authentication activation BLE protocol ③;
[0306] Step S610: The platform device saves the BLE protocol ③, encounters the specified ending content, stops content parsing and receiving, uses the public key content to parse the protocol content, completes the authentication sequence content and public key content saving, and records the current sending end authentication device to join the authentication sequence table file, disconnects the Bluetooth link, and adopts an error handling mechanism in the process;
[0307] Step S611: All platform devices that have completed authentication start the blockchain algorithm, replace the authentication device key box to proceed to step S63, and perform BLE protocol ③ on all nearby devices in step S62;
[0308] Step S612: The above operation can be consolidated from step S63 to step S610 through the Bluetooth base station, which only serves as data transfer and does not affect the actual authentication result;
[0309] Step S613: When the device is in a local area network or Internet state, the authentication sequence table file of any authentication device is randomly imported into the information exchange server, and the registration and initialization of all devices can be directly completed;
[0310] Step S614: Add logging and monitoring functions to regularly check the system's operating status.
[0311] Embodiment 8, see Figure 1 and Figure 6 This embodiment is based on the above embodiment. In step S7, password change specifically includes the following steps:
[0312] Step S71: Smart card insertion: User i inserts the smart card SC into the reader and enters the ID i and PW i ;
[0313] Step S72: The smart card performs the first calculation using the following formula:
[0314] r1* =HID i ⊕h(PW i ||ID i );
[0315] HPW i * =H(R1 * ||PW i );
[0316] R2 * =h(HPW i * ||ID g );
[0317] h(R1||r2||S g ) = R3⊕h(HPW i ||T1);
[0318] In the formula, r1 * is the random value calculated by the smart card SC, HPW i * is the hash value of the password of user i calculated by the smart card SC, R2 * is a random number generated by the gateway node, h(R1||r2||S g ) is the value obtained by XOR operation;
[0319] Step S73: Verification, the smart card SC checks R2 and R2 * Are they equal? If R2=R2 * , then verify the ID of user i i and PW i , otherwise, the session is terminated;
[0320] Step S74: Enter a new password. User i enters the new password PW i new ;
[0321] Step S75: The smart card performs a second calculation, and the smart card SC generates a new random number r1 using a pseudo-random number generator. new , the formula used is as follows:
[0322] HID i new =r1 new ⊕h(PW i new ||ID i );
[0323] HPW i new =H(R1 * ||PW inew );
[0324] R2 new =h(HPW i new ||ID g );
[0325] R3 new =h(R1||R2||S g )⊕h(PW i new ||T1);
[0326] In the formula, HID i new is the new identity hash value of user i, HPW i new is the new hash value of the password of user i calculated by the smart card SC, R2 new is the new random number, R3 new It is the value obtained by XOR operation;
[0327] Step S76: Replacement, the smart card SC replaces R2, R3 and HID with the corresponding new value R2 new 、R3 new and HID i new , the password was changed successfully.
[0328] Embodiment 9, see Figure 1 This embodiment is based on the above embodiment. In step S8, the new sensor device node connection specifically includes the following steps:
[0329] Step S81: Calculate and save the shared key, and the blockchain center BC selects a new sensor device node SN k , calculate the new shared key and store {SN k , S sn}, the formula used is as follows:
[0330] S sn =h(ID sn ||S BC );
[0331] In the formula, S sn is the shared key between the gateway node and the new sensor device node, ID sn is the identifier of the new sensor device node;
[0332] Step S82: The blockchain center sends to the gateway node, and the blockchain center BC sends {SN k , S sn} to gateway node GW j ;
[0333] Step S83: The gateway node stores and updates the key library. j Storage {SN k , S sn} and update the information in the keystore.
[0334] Embodiment 10, see Figure 2 , this embodiment is based on the above embodiment, and the present invention provides a nurse station information interaction platform authentication management system, including a data storage module, a user registration module, a user login module, a device activation authentication module in a local area network state, a device activation authentication module in an Internet state, a device activation authentication module in a non-network state, a password change module and a new sensor device node connection module;
[0335] The data storage module uses a hash function to calculate a private key and a shared key, saves the information to a key library, encrypts and generates an activation sequence file, and sends the activation sequence file to a user registration module;
[0336] The user registration module receives the activation sequence file sent by the data storage module, the user selects a unique ID and password, calculates the hash value of the user password and the identity hash value, and saves them to the smart card;
[0337] The user login module inserts the smart card into the reader and enters the ID and password, provides the reliability of security authentication through the calculation of hash values and random numbers, session disconnection and failure mechanisms, and sends the login request to the device activation authentication module in the LAN state, the device activation authentication module in the Internet state, and the device activation authentication module in the no-network state;
[0338] The device activation authentication module receives the login request sent by the user login module in the local area network state, adopts a complete authentication process, uses hash values and XOR operations to encrypt, verify and prevent tampering of data, avoids excessive delays and data expiration problems by comparing timestamps and setting maximum allowable transmission delays, uses multiple verification mechanisms to improve security and reliability, and sends the authentication results to the password change module;
[0339] The device activation authentication module in the Internet state receives the login request sent by the user login module, introduces an identity authentication mechanism in the authentication process to ensure that the activation request comes from a legitimate device and prevents malicious activation requests, adds a failure retry mechanism to ensure the correct transmission and storage of data, and the dual mechanism increases the security of authentication and the stability of the process, and sends the authentication result to the password change module;
[0340] The device activation authentication module receives the login request sent by the user login module in the no-network state, performs authentication using the BLE protocol and identity authentication mechanism, and sends the authentication result to the password change module;
[0341] The password change module receives the authentication results sent by the device activation authentication module in the LAN state, the device activation authentication module in the Internet state, and the device activation authentication module in the no-network state. The user inserts the smart card into the reader, enters the ID and password, and the smart card calculates the relevant random value and hash value and performs identity authentication. If the verification is passed, the new password is entered and the relevant information in the smart card is modified. Otherwise, the session is interrupted;
[0342] The new sensor device node connection module selects a new sensor device node, calculates a new shared key, saves relevant information and sends it to the gateway node, and the gateway node stores and updates the information in the key library to complete the new sensor device node connection.
[0343] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.
[0344] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
[0345] The present invention and its embodiments are described above, and such description is not restrictive. The drawings show only one embodiment of the present invention, and the actual structure is not limited thereto. In short, if ordinary technicians in the field are inspired by it, without departing from the purpose of the invention, they can design a structure and embodiment similar to the technical solution without creativity, which should belong to the protection scope of the present invention.
Claims
1. A method for managing the authentication of a nurse station information interaction platform, characterized in that: The method comprises the following steps: Step S1: Data preservation, using hash function to calculate private key and shared key, saving information to key library, and encrypting to generate activation sequence file; Step S2: User registration, the user selects a unique ID and password, calculates the hash value of the user password and the identity hash value, and saves them to the smart card; Step S3: User login, the user inserts the smart card into the reader and enters the ID and password, introduces the calculation of hash value and random number, session disconnection and failure mechanism, and the smart card sends a login request to the gateway node through the public channel; Step S4: Device activation authentication in LAN state, using a complete authentication process, using hash values and XOR operations to encrypt, verify and tamper-proof data, avoiding excessive delays and data expiration by comparing timestamps and setting the maximum allowable transmission delay, and using multiple verification mechanisms; Step S5: Device activation authentication in the Internet state, introduce an identity authentication mechanism in the authentication process to ensure that the activation request comes from a legitimate device and prevent malicious activation requests, and add a failure retry mechanism; Step S6: Device activation authentication in the absence of a network, the authentication device scans and pairs via Bluetooth, uses a private key to encrypt and send the BLE protocol for activation device authentication, and introduces an identity authentication mechanism for authentication; Step S7: Password change. The user inserts the smart card into the reader and enters the ID and password. The smart card calculates the relevant random value and hash value and performs identity authentication. If the authentication is successful, the user enters the new password and modifies the relevant information in the smart card. Otherwise, the session is interrupted. Step S8: The new sensor device node is connected, the blockchain center selects the new sensor device node, calculates a new shared key, saves the relevant information and sends it to the gateway node, and the gateway node stores and updates the information in the key library; In step S1, the data storage specifically includes the following steps: Step S11: Calculate the gateway node private key using the following formula: S g =h(ID g ||S BC ); In the formula, S g is the private key of the gateway node, h() is the hash function, ID g is the identifier of the gateway node, S BC is the private key of the blockchain center BC, || is the splicing operation; Step S12: Calculate the shared key using the following formula: S sn =h(ID sn ||S BC ); In the formula, S sn is the shared key between the gateway node and the sensor device node, ID sn is the identifier of the sensor device node; Step S13: Save the keystore, {ID sn , S sn }Save by blockchain center BC in sensor device node SN k middle; Step S14: The blockchain center saves and sends to the gateway node, and the blockchain center BC saves {ID g , S g , ID sn , S sn } and send it to the gateway node GW j ; Step S15: Information storage. All nurse station hosts need to record batch and equipment hardware information into the equipment library when leaving the factory, and record the motherboard serial number key information into the library; Step S16: Encrypt and generate an activation sequence file, which contains hardware information, platform module configuration content, and account encryption content; In step S2, the user registration specifically includes the following steps: Step S21: Calculate the hash value of the user's password. The user selects a unique ID and password, generates a random number r1, calculates the hash value of the password, and converts {ID i , HPW i }Sent to gateway node GW j , the formula used is as follows: HPW i =h(r1||PW i ); Where, HPW i is the hash value of user i's password, ID i is the ID of user i, PW i is the password of user i; Step S22: Calculate the hash value, gateway node GW j Received {ID i , HPW i }, a random number r2 is generated using a pseudo-random number generator, and R1, R2, and R3 are calculated at timestamp T1 using the following formula: R1=h(HPW i ||T1); R2=h(HPW i ||ID g ); R3=h(R1||r2||S g )⊕h(HPW i ||T1); In the formula, || is a string concatenation operation, ⊕ is an XOR operation, R1 is the hash value of the password of user i and the timestamp T1, and the hash value is calculated using a hash function, and R2 is the hash value of the password of user i and the identifier ID of the gateway node g The hash value is calculated by combining and performing an XOR operation on R3. Step S23: Smart card saves, gateway node GW j {r2, T1, ID g ,h(), R1, R2, R3} is saved in the smart card SC storing the user identification information and sent to user i; Step S24: Calculate the identity hash value. User i receives {r2, T1, ID g , h(), R1, R2, R3}, calculate the identity hash value and write it into the smart card SC. The formula used is as follows: HID i =h(PW i ||ID i )⊕r1; In the formula, HID i is the identity hash value of user i; In step S3, the user login specifically includes the following steps: Step S31: Smart card insertion: User i inserts the smart card SC into the reader and enters the ID i and PW i ; Step S32: Obtaining data, user i selects a nearest gateway node, establishes a communication link with the sensor device node, and obtains the data required by the user; Step S33: The smart card performs the first calculation using the following formula: r1 * =HID i ⊕h(PW i ||ID i ); HPW i * =h(r1 * ||PW i ); R2 * =h(HPW i * ||ID g ); In the formula, r1 * is the random value calculated by the smart card SC, HPW i * is the hash value of the password of user i calculated by the smart card SC, R2 * It is a random number generated by the gateway node; Step S34: Verification, the smart card SC checks R2 and R2 * Are they equal? If R2=R2 * , then verify the ID of user i i and PW i , otherwise, the session is terminated; Step S35: The smart card performs a second calculation. The smart card SC generates a random number r3 and calculates F1, F2 and F3 at timestamp T2. The formula used is as follows: F1=R3⊕h(HPW i ||T1); <h2 style=";text-align:left;direction:ltr">F2=h(T2||r3||F1||ID<h2 style=";text-align:left;direction:ltr"> g <h2 style=";text-align:left;direction:ltr"> ); F3=h(r3||T2)⊕F1; Where, F1 is the value obtained by XOR operation, F2 is the hash value calculated by the smart card SC, and F3 is the value obtained by XOR operation; Step S36: Send a login request, the smart card SC sends a login request to the gateway node GW through a public channel. j Send a login request; In step S4, the device activation authentication in the local area network state specifically includes the following steps: Step S41: The gateway node performs the first calculation. When the gateway node GW j After receiving the login request, F1 is calculated at timestamp T3 * 、F1 * ⊕F3, the formula used is as follows: r3 * =h(PW i ||ID i )⊕r3⊕h(PW i ||ID i ); T2 * =h(T2); F1 * =h(R1||r2||S g ); F1 * ⊕F3=h(r3 * ||T2 * ); Where F1 * It is the gateway node GW j The calculated value, F1 * ⊕F3 is the gateway node GW j The calculated hash value, r3 * is the value obtained by XOR operation, T2 * is the hash value obtained by hashing the timestamp T2; Step S42: First check, gateway node GW j Check whether (T3-T2) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T3-T2) < ΔT, proceed to the next step. Otherwise, terminate the session. Step S43: First verification, gateway node GW j Calculate F2 * , and verify that F2 * Is it equal to F2? If F2 * =F2, then user i is authenticated, otherwise, the session is interrupted. The formula used is as follows: <h2 style=";text-align:left;direction:ltr">F2<h2 style=";text-align:left;direction:ltr"> * <h2 style=";text-align:left;direction:ltr"> =h(T2)<h2 style=";text-align:left;direction:ltr"> * <h2 style=";text-align:left;direction:ltr"> ||r3<h2 style=";text-align:left;direction:ltr"> * <h2 style=";text-align:left;direction:ltr"> ||F1<h2 style=";text-align:left;direction:ltr"> * <h2 style=";text-align:left;direction:ltr"> ||ID<h2 style=";text-align:left;direction:ltr"> g <h2 style=";text-align:left;direction:ltr"> ); In the formula, F2 * It is the gateway node GW j The calculated hash value; Step S44: The gateway node performs a second calculation, and the gateway node GW j Generate a random number r4 and calculate R4, R5 and R6 using the following formula: R4=h(ID sn ||R1||S sn ||r4||T3); R5=(r3) * ||T3||r4)⊕S sn ; R6=R1⊕h(ID sn ||h(r4)||r3 * ); Where R4 is the gateway node GW j The calculated hash value, R5 is the value obtained by XOR operation, and R6 is the value obtained by XOR operation; Step S45: the gateway node sends a request for the first time; Step S46: The sensor device node performs the first calculation, and calculates h(r3 ** ||r4 * ||T3 * ), the formula used is as follows: r3 ** =h(HPW i * ||ID i )⊕r3⊕h(HPW i * ||ID i ) r4 * =h(PW i ||ID i )⊕r4⊕h(PW i ||ID i ) <h2 style=";text-align:left;direction:ltr">T3<h2 style=";text-align:left;direction:ltr"> * <h2 style=";text-align:left;direction:ltr"> =h(T3) h(r3 ** ||r4 * ||T3 * )=R5⊕S sn 4 In the formula, h(r3 ** ||r4 * ||T3 * ) is the value obtained by XOR operation, r3 ** is the value obtained by XOR operation, r4 * is the value obtained by XOR operation, T3 * is the hash value obtained by hashing the timestamp T3; Step S47: Second check, sensor device node SN k Check whether (T4-T3) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T4-T3) < ΔT, proceed to the next step. Otherwise, terminate the session. Step S48: The sensor device node performs a second calculation using the following formula: R1 * =R6⊕h(ID sn ||h(r4 * )||r3 ** ); R4 * =h(ID sn ||R1 * ||S sn ||r4 * ||T3 * ); Where R1 * is the value obtained by XOR operation, R4 * It is the sensor device node SN k The calculated hash value; Step S49: Third check, sensor device node SN k Check R4 * Is it equal to R4? If R4 * =R4, then proceed to the next step, otherwise, terminate the session; Step S410: The sensor device node performs a third calculation, and the sensor device node SN k Generate a random number r5 and calculate SK i , B1 and B2, the formula used is as follows: SK i =h(R1 * ||r3 ** ||r4 * ||r5); B1=h(T4||r5||S sn ||ID sn ||T3||SK i ); B2=h(r5||T4)⊕r4 * ; In the formula, SK i It is the sensor device node SN k The key of B1 is used to verify and identify the identity, and B2 is used to verify the data integrity. Step S411: the sensor device node sends a message; Step S412: The gateway node performs the third calculation and calculates h(r5) at timestamp T5. * ||T4 * ), the formula used is as follows: r5 * =h(PW i ||ID i )⊕r5⊕h(PW i ||ID i ) T4 * =h(T4); h(r5 * ||T4 * )=B2⊕r4; In the formula, h(r5 * ||T4 * ) is the value obtained by XOR operation, r5 * is the value obtained by XOR operation, T4 * is the hash value obtained by hashing the timestamp T4; Step S413: Fourth check, gateway node GW j Check whether (T5-T4) is less than the maximum allowed transmission delay ΔT between the sender and the receiver. If (T5-T4) < ΔT, proceed to the next step; otherwise, terminate the session. Step S414: Second verification, gateway node GW j Calculate B1 * , and verify that B1 * Is it equal to B1? If B1 * =B1, then for the sensor device node SN k Verify, otherwise, terminate the session. The formula used is as follows: B1 * =h(T4 * ||r5 * ||S sn ||ID sn ||T3 * ||SK i ); Where, B1 * It is the gateway node GW j The calculated hash value; Step S415: The gateway node performs the fourth calculation using the following formula: R7=h(SK i ||R1||r4||T5||R4); R8=h(r5 * ||r4||T5)⊕r3 * ; Where R7 is the gateway node GW j The calculated hash value, R8 is the value obtained by XOR operation; Step S416: the gateway node sends a request for the second time; Step S417: The smart card performs a third calculation, and calculates h(r5 ** ||r4 * ||T5 * ), the formula used is as follows: r5 ** =HID i ⊕h(PW i ||ID i ); T5 * =h(T5); h(r5 ** ||r4 * ||T5 * )=R8⊕r3; In the formula, h(r5 ** ||r4 * ||T5 * ) is the value obtained by XOR operation, r5 ** is the value obtained by XOR operation, T5 * is the hash value obtained by hashing timestamp T5; Step S418: The fifth check, the smart card SC checks whether (T6-T5) is less than the maximum allowable transmission delay ΔT between the transmitter and the receiver. If (T6-T5) < ΔT, proceed to the next step, otherwise, terminate the session. Step S419: Third verification, smart card SC calculates R7 * , and verify R7 * Is it equal to R7? If R7 * =R7, the authentication is successful and the device is activated. Otherwise, the session is terminated. The formula used is as follows: R7 * =h(SK i ||h(HPW i ||T1)||r4 * ||T5 * ||R4); Where R7 * It is the hash value calculated by the smart card SC; In step S5, the device activation authentication in the Internet state specifically includes the following steps: Step S51: The platform device is turned on and the main program is ensured to work normally; Step S52: The main program generates a device information dynamic code through an encryption algorithm according to the public key content stored in the device in a normal networking state; Step S53: The server inputs the dynamic code, decrypts the private key file to obtain the hardware device information and IP address gateway content, and sends the activation invitation protocol ① to the platform device through the UDP communication protocol; Step S54: the platform device receives the activation invitation protocol ①, responds and provides device information to the nurse station server to authenticate and activate the UDP protocol ②, and introduces an identity authentication mechanism; Step S55: After receiving the authentication activation UDP protocol ②, the nurse station server records and sends the authentication sequence content TCP protocol ③ to the designated device; Step S56: After the platform device receives the authentication sequence content TCP protocol ③, it saves the sequence file content to the internal storage shared directory and sets the file to read-only mode. After successfully saving the file, it sends a confirmation authentication activation protocol ④ and adds a failure retry mechanism; Step S57: After the nurse station server confirms receipt of the confirmation authentication activation agreement ④, it records the current device information and sequence file information to the database to complete the authentication; Step S58: After the authentication device is restarted, the system main program will check the authentication sequence file stored in step S56, use the sequence file content, complete the platform system function initialization, and request the server to complete the token content registration and activation, complete the authentication, read the platform system function configuration and start running the platform multi-application system; if the file reading fails or the file is invalid, re-enter step S53 to wait; In step S6, the device activation authentication in the no-network state specifically includes the following steps: Step S61: The platform device is turned on and the main program is ensured to work normally; Step S62: Ensure that the Bluetooth module is normal and undamaged, and record the authentication device public key file and the authentication sequence table file in the system storage location through a transmission tool; Step S63: The authentication device is paired through Bluetooth scanning, and the private key is encrypted and sent to activate the device authentication BLE protocol ①, and the identity authentication mechanism is introduced at the same time; Step S64: The platform device continuously saves the device authentication BLE protocol ①, and when encountering the specified ending content, stops parsing and receiving the content, and introduces an error handling mechanism; Step S65: the platform device uses the public key file to parse the protocol content and intercept the specified byte content; Step S66: If the platform device has completed authentication and activation, save the sender device information parsed by the specified bytes in the device authentication BLE protocol ①, add the authentication sequence table file, and splice the device information feedback to confirm the activation of the BLE protocol ②, then disconnect the Bluetooth link, and return to step S63 after a fixed interval; Step S67: If the platform device is not authenticated and activated, the splicing device information feedback confirms the activation of the BLE protocol②; Step S68: The authentication device key box receives the BLE protocol ②, parses and intercepts the specified byte content according to its own private key file, and if it corresponds to the device information saved in step S66, the authentication device is recorded, added to the authentication sequence table file, and the step is directly stopped to disconnect Bluetooth. After a fixed interval, it returns to step S63; if it corresponds to the device authentication sequence generated by step S67, it goes to step S69; if the BLE protocol ② is not received within the specified time, the device is removed from the authentication sequence table file, Bluetooth is disconnected, and after a fixed interval, it returns to step S63, and an identity authentication mechanism is added in the process; Step S69: The authentication device concatenates the private key file content and the device authentication sequence content, encrypts and sends the authentication activation BLE protocol ③; Step S610: The platform device saves the BLE protocol ③, encounters the specified ending content, stops content parsing and receiving, uses the public key content to parse the protocol content, completes the authentication sequence content and public key content saving, and records the current sending end authentication device to join the authentication sequence table file, disconnects the Bluetooth link, and adopts an error handling mechanism in the process; Step S611: All platform devices that have completed authentication start the blockchain algorithm, replace the authentication device key box to proceed to step S63, and perform BLE protocol ③ on all nearby devices in step S62; Step S612: The above operation can be consolidated from step S63 to step S610 through the Bluetooth base station, which only serves as data transfer and does not affect the actual authentication result; Step S613: When the device is in a local area network or Internet state, the authentication sequence table file of any authentication device is randomly imported into the information exchange server, and the registration and initialization of all devices can be directly completed; Step S614: Add logging and monitoring functions to regularly check the system's operating status.
2. A method for managing the authentication of a nurse station information interaction platform according to claim 1, characterized in that: In step S7, the password change specifically includes the following steps: Step S71: Smart card insertion: User i inserts the smart card SC into the reader and enters the ID i and PW i ; Step S72: The smart card performs the first calculation, and the formula used is as follows: r1 * =HID i ⊕h(PW i ||ID i ); HPW i * =h(r1 * ||PW i ); R2 * =h(HPW i * ||ID g ); h(R1||r2||S g )=R3⊕h(HPW i ||T1); In the formula, r1 * is the random value calculated by the smart card SC, HPW i * is the hash value of the password of user i calculated by the smart card SC, R2 * is a random number generated by the gateway node, h(R1||r2||S g ) is the value obtained by XOR operation; Step S73: Verification, the smart card SC checks R2 and R2 * Are they equal? If R2=R2 * , then verify the ID of user i i and PW i , otherwise, the session is terminated; Step S74: Enter a new password. User i enters the new password PW i new ; Step S75: The smart card performs a second calculation, and the smart card SC generates a new random number r1 using a pseudo-random number generator. new , the formula used is as follows: HID i new =r1 new ⊕h(PW i new ||ID i ); HPW i new =h(r1 * ||PW i new ); R2 new =h(HPW i new ||ID g ); R3 new =h(R1||r2||S g )⊕h(PW i new ||T1); In the formula, HID i new is the new identity hash value of user i, HPW i new is the new hash value of the password of user i calculated by the smart card SC, R2 new is the new random number, R3 new is the value obtained by XOR operation; Step S76: Replacement, the smart card SC replaces R2, R3 and HID with the corresponding new value R2 new 、R3 new and HID i new , the password was changed successfully.
3. A method for managing the authentication of a nurse station information interaction platform according to claim 1, characterized in that: In step S8, the new sensor device node connection specifically includes the following steps: Step S81: Calculate and save the shared key, and the blockchain center BC selects a new sensor device node SN k , calculate the new shared key and store {SN k , S sn }, the formula used is as follows: S sn =h(ID sn ||S BC ); In the formula, S sn is the shared key between the gateway node and the new sensor device node, ID sn is the identifier of the new sensor device node; Step S82: The blockchain center sends to the gateway node, and the blockchain center BC sends {SN k , S sn } to gateway node GW j ; Step S83: The gateway node stores and updates the key library. j Storage k , S sn } and update the information in the keystore.
4. A nurse station information interaction platform authentication management system, used to implement a nurse station information interaction platform authentication management method as described in any one of claims 1 to 3, characterized in that: It includes data saving module, user registration module, user login module, device activation authentication module under LAN state, device activation authentication module under Internet state, device activation authentication module under no network state, password change module and new sensor device node connection module.
5. A nurse station information interaction platform authentication management system according to claim 4, characterized in that: The data storage module uses a hash function to calculate a private key and a shared key, saves the information to a key library, encrypts and generates an activation sequence file, and sends the activation sequence file to a user registration module; The user registration module receives the activation sequence file sent by the data storage module, the user selects a unique ID and password, calculates the hash value of the user password and the identity hash value, and saves them to the smart card; The user login module inserts the smart card into the reader and enters the ID and password, provides the reliability of security authentication through the calculation of hash values and random numbers, session disconnection and failure mechanisms, and sends the login request to the device activation authentication module in the LAN state, the device activation authentication module in the Internet state, and the device activation authentication module in the no-network state; The device activation authentication module receives the login request sent by the user login module in the local area network state, adopts a complete authentication process, uses hash values and XOR operations to encrypt, verify and prevent tampering of data, avoids excessive delays and data expiration problems by comparing timestamps and setting maximum allowable transmission delays, uses multiple verification mechanisms to improve security and reliability, and sends the authentication results to the password change module; The device activation authentication module in the Internet state receives the login request sent by the user login module, introduces an identity authentication mechanism in the authentication process to ensure that the activation request comes from a legitimate device and prevents malicious activation requests, adds a failure retry mechanism to ensure the correct transmission and storage of data, and the dual mechanism increases the security of authentication and the stability of the process, and sends the authentication result to the password change module; The device activation authentication module receives the login request sent by the user login module in the no-network state, performs authentication using the BLE protocol and identity authentication mechanism, and sends the authentication result to the password change module; The password change module receives the authentication results sent by the device activation authentication module in the LAN state, the device activation authentication module in the Internet state, and the device activation authentication module in the no-network state. The user inserts the smart card into the reader, enters the ID and password, and the smart card calculates the relevant random value and hash value and performs identity authentication. If the verification is passed, the new password is entered and the relevant information in the smart card is modified. Otherwise, the session is interrupted; The new sensor device node connection module selects a new sensor device node, calculates a new shared key, saves relevant information and sends it to the gateway node, and the gateway node stores and updates the information in the key library to complete the new sensor device node connection.
Citation Information
Patent Citations
Two-factor authentication key agreement protocol suitable for multi-gateway wireless sensor network
CN110234111A