Multi-disciplinary joint outpatient service security communication method for privacy protection
By using elliptic curve public key infrastructure, pseudonyms and physical protection parameters in the communication system of multidisciplinary joint outpatient clinics, the problem of linking and physical attacks between recipient identity and sender identity in the prior art is solved, achieving higher security and privacy protection.
Patent Information
- Application Number
- CN202510290625.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-13
AI Technical Summary
While ensuring the anonymity of the message, the existing broadcast signature method has the risk of linking the recipient identity and the sender identity, and the inability to effectively prevent key theft caused by physical attacks.
By establishing an elliptic curve public key infrastructure between medical centers and specialists, using pseudonyms and physical protection parameters to ensure patient anonymity and data unlinkability, and using timestamps and hash functions for data verification during transmission, preventing physical attacks.
It achieves higher security and privacy protection capabilities, prevents the recipient from tracing the sender's identity, and effectively resists physical attacks, ensuring safe and reliable application in sensitive environments.
Smart Images

Figure CN120151028A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of communication security, and particularly relates to a secure communication method for multi-disciplinary joint outpatient clinics with privacy protection. Background Art
[0002] In recent years, the Multidisciplinary Team (MDT) has developed vigorously and been widely applied in the medical field. MDT represents a revolutionary progress in healthcare practice, and its main goal is to provide highly comprehensive, professional, standardized and personalized diagnosis and treatment services for patients. Especially when dealing with diseases of specific organs or systems, its role is particularly significant. MDT brings together experts from different medical fields, including but not limited to doctors, surgeons, radiologists, nurses, psychiatrists, etc. These experts not only have excellent knowledge and experience, but also can work together to jointly evaluate the patient's condition and provide comprehensive medical advice.
[0003] The goal of MDT is to provide comprehensive medical care, and usually requires sharing key diagnosis and treatment information of patients, including but not limited to diagnosis results, imaging data, medical records, etc., so that multiple medical experts can jointly evaluate and develop personalized treatment plans.
[0004] In MDT, another key focus of medical diagnosis and treatment is privacy protection, especially when dealing with anonymous diagnoses of important figures, which requires higher privacy and security standards. In some cases, people may need to receive medical care from MDT, but due to privacy and security considerations, they expect the processing of medical information to be anonymous. Anonymous diagnosis helps prevent this situation from happening, ensuring that patients can receive professional medical care without being overly interfered with due to their identity. In addition, if patients do not believe that their medical information will be properly protected in terms of privacy, they may be reluctant to share key information. This will have a negative impact on the work of MDT. This not only involves regulatory compliance, but also the patient's right to privacy and trust, as well as the effective conduct of multi-disciplinary collaboration.
[0005] Although there are currently some broadcast signcryption methods, these methods still have some significant limitations. One of the main problems is that the recipient of the message can trace the source of the message through the sender's public key, which may affect the anonymity of the message and the privacy of the sender. Specifically, in the broadcast signature encryption method, the sender uses its private key to signcrypt the secret message, generates the corresponding ciphertext, and transmits it to the intended recipient. The recipient uses the sender's public key to decrypt the ciphertext and extracts the secret message. Although the ciphertext generated by the sender is random and cannot be traced back to the sender itself, the sender's public key remains unchanged, enabling any recipient to link it to the sender's identity.
[0006] The security of existing broadcast signcryption methods is based on an assumption that the secrets stored in devices exist for a long time and cannot be obtained by malicious attackers. However, in practical situations, attackers can still steal the secret information stored on the device through physical attacks, such as side-channel attacks, which pose a serious threat to communication security. Summary of the Invention
[0007] The technical problem to be solved by the present invention is to overcome the above-mentioned disadvantages of the prior art and provide a secure communication method for multidisciplinary joint outpatient clinics with privacy protection.
[0008] The technical solution adopted to solve the above technical problem is: a secure communication method for multidisciplinary joint outpatient clinics with privacy protection, including the following specific steps:
[0009] Step 1: System initialization:
[0010] According to the preset security parameters, the medical center generates the master private key s of the system and the system public parameters par = {G, P, P pub , H 1 , H 2 , H 3 , H 4 , H 5}, then, the medical center publishes these public parameters and at the same time ensures the confidentiality of the master key s;
[0011] Step 2: Specialist doctor registration:
[0012] The specialist doctor first generates its key pair (sk j , pk j ) and challenge-response pair (C j , R j ), and at the same time sets the physical protection parameter Check j , then, the doctor publishes its identity identifier ID j and public key pk j , and stores the challenge C j , private key sk j , and physical protection parameter Check j ;
[0013] Step 3: Patient registration:
[0014] The patient sends the real identity identifier ID i to the medical center to complete the registration process. The medical center generates the corresponding pseudonym i and partial private key ppk = (λ i , Y i , Y i), and then send these parameters to the patient. The patient generates a challenge-response pair (C i , R i ) according to the received parameters, and at the same time sets the physical protection parameter Check i . Subsequently, the patient stores the pseudonym partial private key ppk i = (λ i , Y i ), the challenge C i and the physical protection parameter Check i ;
[0015] Step Four: Broadcast Signcryption:
[0016] The patient ID i needs to send his / her diagnosis information m to the specialists Team of the Multidisciplinary Clinic s = {ID 1 , ID 2 , …, ID s}. First, the patient needs to verify whether a physical attack has occurred;
[0017] When no attack is detected, the patient generates his / her own signcryption key pair and uses this key pair to generate the ciphertext of the diagnosis information m. Then, the patient broadcasts the ciphertext ξ i and his / her pseudonym PID i to the specialists of the Multidisciplinary Clinic;
[0018] When the patient detects a physical attack, the patient re-registers to cope with the physical key theft that has occurred;
[0019] Step Five: Unsigncryption:
[0020] After receiving the ciphertext ξ i and the patient's pseudonym PID i , the specialist needs to perform security checks in sequence:
[0021] First, verify whether a physical attack has occurred. When no physical attack trace is found, check the validity of the timestamp t i :
[0022] When the timestamp t i has expired, the specialist regards the message as invalid and discards it. When the timestamp t i is valid, the specialist will use his / her private key for decryption and signature verification operations;
[0023] Only when the authentication is successful will the specialist accept and process the message m; when the authentication fails, the message will be immediately discarded.
[0024] Through the above technical solutions, the problems of linking the identities of the receiver and the sender and preventing physical attacks are solved; it has higher security and privacy protection capabilities, and can effectively resist various potential physical attacks to ensure its safe and reliable application in sensitive environments.
[0025] Further, the system initialization in Step 1 includes:
[0026] First, given the security parameters, the medical center first creates an elliptic curve G with P as the generator and order q.
[0027] Then, the medical center randomly selects a master key and uses it to calculate the public key P pub = s·P;
[0028] After that, the medical center selects five one-way hash functions, namely H 1 :{0,1} * →{0,1} |ID| , H 2 : H 3 : H 4 :{0,1} * →{0,1} 2|G|+|m| , and H 5 :
[0029] Finally, the medical center publishes the system parameters:
[0030] par = {G, P, P pub , H 1 , H 2 , H 3 , H 4 , H 5}.
[0032] Through the above technical solutions, the system is initialized, improving security.
[0033] Further, the registration of specialist doctors in Step 2 includes:
[0034] The specialist doctor first randomly selects a private key Then calculates the corresponding public key pk j = sk j ·P;
[0035] Next, the doctor generates a challenge-response pair (C j , R j ), where R j = PUF(C j );
[0036] Subsequently, the doctor calculates the physical protection parameter Check j = H 2 (C j , R j , sk j , pk j );
[0037] Finally, the doctor makes the public key pk j public and stores the challenge C j , the private key sk j and the physical protection parameter Check j .
[0038] Through the above technical solution, it is ensured that the specialist doctor can accurately receive the patient's information.
[0039] Furthermore, the patient registration in step three includes:
[0040] First, the patient sends their true identity identifier to the medical center;
[0041] After the medical center receives the ID i , it randomly selects a value Then it calculates and This process enables the medical center to generate the corresponding pseudonym, that is
[0042] Next, the medical center selects another random value and calculates Y i = y i · p, h i = H 2 (PID i , Y i , P pub ), and λ i = y i + s · h i , then, the medical center returns the partial private key ppk i = (λ i , Y i ) to the patient;
[0043] Subsequently, the patient generates a challenge-response pair (C i , R i ), where R i = PUF(C i ), then, the patient calculates the physical protection parameter Check i = H 2 (Ci , R i , PID i , ppk i );
[0044] Finally, the patient stores the challenge C i , the pseudonym PID i , the partial private key ppk i and the physical protection parameter Check i , usually, each patient needs to obtain a set of pseudonyms and partial private keys to achieve anonymity and unlinkability. After using the pseudonyms and partial private keys, the patient deletes them from the pool. At the same time, before the pseudonyms and partial private keys are exhausted, the patient replenishes new pseudonyms and partial private keys.
[0045] Through the above technical solutions, the anonymity of the patient and the security of the data are ensured, while allowing the medical center to provide the required pseudonyms and partial private keys for each patient to maintain the unlinkability of the data.
[0046] Furthermore, the broadcast signcryption in step four includes:
[0047] The patient ID i needs to send his / her diagnosis information m to the specialist doctor team Team of the multidisciplinary joint outpatient clinic s ={ID 1 , ID 2 , …, ID s};
[0048] First, the patient needs to perform a physical attack detection, calculate R' i =PUF(C i ) and Check' i =H 2 (C i , R' i , PID i , ppk i ). If Check' i =Check i , then proceed to the next step; otherwise, re-register to cope with the physical attack.
[0049] Next, the patient randomly selects a private key and then calculates the corresponding public key pk i =sk i ·P;
[0050] Subsequently, the patient selects a random number and calculates R i =r i ·P;
[0051] Then, for each ID j ∈ Team s , the following calculations are performed respectively: ω j = r i · pk j , k j = H 3 (ω j , pk j , ID j , PID i , R i ), β j = α i / k j ;
[0052] After that, the patient calculates again: θ j , such that β j × θ j ≡ 1 mod k j , var j = β j × θ j , and
[0053] Next, the patient selects a transmission key and calculates: γ i = TK i × sum i , C i = H 4 (TK i , PID i )⊕(pk i || Y i || m);
[0054] After that, the patient generates a timestamp t i , and calculates:
[0055] h 1 = H 5 (PID i , t i , m, pk i , Y i , R i , 1)
[0056] h 2 = H 5 (PID i , t i , m, pk i , Y i , R i , 2)
[0057] ρi = r i + h 1 λ i + h 2 sk i
[0058] to obtain the ciphertext ξ i = {C i , ρ i , t i , R i , γ i};
[0059] Finally, the patient broadcasts the ciphertext ξ i along with their pseudonym PID i to the specialist doctor team Team of the multidisciplinary outpatient clinic s = {ID 1 , ID 2 , …, ID s}.
[0060] Through the above technical solution, the patient can quickly and accurately send their information to the specialist doctor.
[0061] Furthermore, the decryption and signature verification in step five includes:
[0062] First, after receiving the ciphertext ξ i = {C i , ρ i , t i , R i , γ i} and the patient's pseudonym PID i , the specialist doctor first needs to verify whether the data has been physically attacked, including calculating R' j = PUF(C j ) and Check′ j = H 2 (C j , R' j , sk j , pk j ). If Check' j = Check j , it means the data is complete and the next step can be continued. Otherwise, re-registration is performed to deal with physical theft;
[0063] Next, the specialist doctor needs to check the validity of the timestamp t i . If the timestamp has expired, the message is considered invalid and discarded. If the timestamp is valid, the specialist doctor can continue with the subsequent operations;
[0064] Then, the specialist doctor calculates
[0065] ω j = sk j ·R i
[0066] k j = H 3 (ω j , pk j , ID j , PID i , R i )
[0067] Next, calculate:
[0068] TK i = γ i mod k j
[0069] pk i ||Y i ||m = H 4 (TK i , PDI i ) ⊕ C i
[0070] By calculating:
[0071] h 1 = H 5 (PID i , t i , m, pk i , Y i , R i , 1)
[0072] h 2 = H 5 (PID i , t i , m, pk i , Y i , R i , 2)
[0073] Perform further verification;
[0074] Finally, the specialist doctor checks the equation ρ i P = R i + h 1 Y i + h 1 h i P pub + h 2 pk i to see if it holds. If it holds, the message m is received, indicating that the message is complete and from a legitimate source. Otherwise, the message is discarded.
[0075] Through the above technical solution, a specialist doctor can ensure that the messages received from patients are not damaged or tampered with during transmission and come from a legitimate sender. This helps to maintain the integrity of medical data and protect patient privacy.
[0076] The beneficial effects of the present invention are as follows: The broadcast signcryption method disclosed by the present invention has physical security and unlinkability, solves the problems of linking the identities of the receiver and the sender and preventing physical attacks; has higher security and privacy protection capabilities, and can also effectively resist various potential physical attacks to ensure its safe and reliable application in sensitive environments. And in the broadcast signcryption method, the sender first signcrypts the sensitive information and converts it into ciphertext to ensure the confidentiality and integrity of the information. This guarantees that the information during transmission will not be accessed or tampered with without authorization. The ciphertext is then transmitted to multiple potential receivers, but only the receivers who meet the preset conditions of the sender have the decryption permission to obtain the original secret information. This ensures the authenticity, integrity, and confidentiality of the message, while improving the transmission efficiency. To protect the privacy of the sender, the sender updates its key pair before each broadcast signcryption to ensure the freshness of its public key. This means that no receiver can trace the identity of the sender, thus providing a high level of sender privacy protection. The present invention also adopts a pseudonym mechanism, effectively hiding the true identity of the sender using the pseudonym, thereby preventing it from being associated with its true identity, which enhances the anonymity of the sender. To resist the threat of potential physical theft attacks, the present invention deploys an unclonable function in the storage device, further enhancing the physical security of the communication. This ensures that even if the device is stolen, the sensitive information is still effectively protected. BRIEF DESCRIPTION OF THE DRAWINGS
[0077] Figure 1 is a flowchart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0078] In order to make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0079] As Figure 1 shown, a secure communication method for a privacy-protected multidisciplinary joint outpatient clinic in this embodiment includes the following specific steps:
[0080] Step 1: System initialization:
[0081] According to the preset security parameters, the medical center generates the master private key s of the system and the system public parameters par = {G, P, P pub , H1 ,H 2 ,H 3 ,H 4 ,H 5} Then, the medical center will release these public parameters while ensuring the confidentiality of the master key s;
[0082] Step 2: Specialist doctor registration:
[0083] The specialist doctor first generates his key pair (sk j , pk j ), as well as a challenge-response pair (C j , R j ), and at the same time sets the physical protection parameter Check j . Subsequently, the doctor makes his identity ID j and public key pk j public, and stores the challenge C j , private key sk j , and the physical protection parameter Check j ;
[0084] Step 3: Patient registration:
[0085] The patient sends his true identity ID i to the medical center to complete the registration process. The medical center generates the corresponding pseudonym i and partial private key ppk = (λ i , Y i , Y i ) according to the patient's true identity ID i , R i ), and at the same time sets the physical protection parameter check i . Subsequently, the patient stores the pseudonym , partial private key ppk i = (λ i , Y i ), challenge C i and the physical protection parameter Check j ;
[0086] Step 4: Broadcast signcryption:
[0087] The patient ID i needs to send his diagnosis information m to the specialist doctor team Team s = {ID 1 , ID 2 , …, ID s} of the multidisciplinary outpatient clinic group. First, the patient needs to verify whether he has been physically attacked;
[0088] When not under attack, the patient generates their own signcryption key pair and uses this key pair to generate the ciphertext of the diagnostic information m. Then, the patient broadcasts the ciphertext ξ i along with their pseudonym PID i to the specialists in the multidisciplinary outpatient clinic group;
[0089] When the patient detects a physical attack, the patient re-registers to counter the physical key theft that has occurred;
[0090] Step Five: Unsigncrypt:
[0091] Upon receiving the ciphertext ξ i along with the patient's pseudonym PID i the specialist needs to perform security checks in sequence:
[0092] First, verify if there has been a physical attack. When no physical attack traces are found, check the validity of the timestamp t i :
[0093] When the timestamp t i has expired, the specialist deems the message invalid and discards it. When the timestamp t i is valid, the specialist uses their private key to perform decryption and signature verification operations;
[0094] Only when the authentication is successful will the specialist accept and process the message m; when the authentication fails, the message will be immediately discarded.
[0095] The system initialization in the said Step One includes:
[0096] First, given the security parameters, the medical center first creates an elliptic curve G with P as the generator and order q;
[0097] Then, the medical center randomly selects a master key and uses it to calculate the public key P pub = s·P;
[0098] After that, the medical center selects five one-way hash functions, namely H 1 :{0,1} * →{0,1} |ID| , H 2 : H 3 : H 4 :{0,1} * →{0,1} 2|G|+|m| , and H 5 :
[0099] Finally, the medical center discloses system parameters:
[0100] par = {G, P, P pub , H 1 , H 2 , H 3 , H 4 , H 5}.
[0102] The registration of specialist doctors in the second step includes:
[0103] The specialist doctor first randomly selects a private key Then calculates the corresponding public key pk j = sk j ·P;
[0104] Next, the doctor generates a challenge - response pair (C j , R j ), where R j = PUF(C j );
[0105] Subsequently, the doctor calculates the physical protection parameter Check j = H 2 (C j , R j , sk j , pk j );
[0106] Finally, the doctor discloses the public key pk j and stores the challenge C j , the private key sk j and the physical protection parameter Check j .
[0107] The registration of patients in the third step includes:
[0108] First, the patient sends their true identity identifier to the medical center;
[0109] After the medical center receives the ID i , it randomly selects a value Then calculates and This process enables the medical center to generate the corresponding pseudonym, that is
[0110] Next, the medical center selects another random value and calculates y i = y i ·P, hi = H 2 (PID i , Y i , P pub ), and λ i = y i + s·h i , then the medical center returns the partial private key ppk i = (λ i , Y i ) to the patient;
[0111] Subsequently, the patient generates a challenge-response pair (C i , R i ), where R i = PUF(C i ), then the patient calculates the physical protection parameter Check i = H 2 (C i , R i , PID i , ppk i );
[0112] Finally, the patient stores the challenge C i , the pseudonym PID i , the partial private key ppk i and the physical protection parameter Check i . Generally, each patient needs to obtain a set of pseudonyms and partial private keys to achieve anonymity and unlinkability. After using the pseudonyms and partial private keys, the patient deletes them from the pool. At the same time, before the pseudonyms and partial private keys are exhausted, the patient replenishes new pseudonyms and partial private keys.
[0113] The fourth step of broadcast signcryption described above includes:
[0114] The patient ID i needs to send his / her diagnosis information m to the specialist doctor team Team of the multidisciplinary joint outpatient clinic s = {ID 1 , ID 2 , …, ID s};
[0115] First, the patient needs to perform a physical attack detection, calculate R' i = PUF(C i ) and Check' i = H 2 (Ci, R' i , PID i , ppk i ). If Check' i = Check i, then proceed to the next step; otherwise, re-register to counter physical attacks.
[0116] Next, the patient randomly selects a private key Then calculate the corresponding public key pk i = sk i ·P;
[0117] Subsequently, the patient selects another random number And calculate R i = r i ·P;
[0118] Then, for each ID j ∈ Team s , perform the following calculations respectively: ω j = r i ·pk j , k j = H 3 (ω j , pk j , ID j , PID i , R i ), β j = α i / k j ;
[0119] After that, the patient calculates: θ j , such that β j ×θ j ≡ 1 mod k j , var j = β j ×θ j , and
[0120] Next, the patient selects a transmission key And calculates: γ i = TK i ×sum i , C i = H 4 (TK i , PID i ) ⊕ (pk i ||Y i ||m);
[0121] After that, the patient generates a timestamp t i , and calculates:
[0122] h 1 = H 5 (PID i , ti , m, pk i , Y i , R i , 1)
[0123] h 2 = H 5 (PID i , t i , m, pk i , Y i , R i , 2)
[0124] ρ i = r i + h 1 λ i + h 2 sk i
[0125] Thus, the ciphertext ξ is obtained i = {C i , ρ i , t i , R i , γ i};
[0126] Finally, the patient broadcasts the ciphertext ξ i along with their pseudonym PID i to the specialists Team in the multidisciplinary outpatient clinic s = {ID 1 , ID 2 , …, ID s}.
[0127] The fifth step of decryption and signature verification includes:
[0128] First, upon receiving the ciphertext ξ i = {C i , ρ i , t i , R i , γ i} and the patient's pseudonym PID i , the specialist first needs to verify whether the data has been physically attacked, including calculating R' j = PUF(C j ) and Check' j = H 2 (C j , R' j , sk j , pk j ), if Check' j = Check j, indicating that the data is complete and the next step can be continued; otherwise, re-registration is performed to counter physical theft;
[0129] Next, the specialist doctor needs to check the validity of the timestamp t i . If the timestamp has expired, the message is considered invalid and discarded. If the timestamp is valid, the specialist doctor can continue with the subsequent operations;
[0130] Then, the specialist doctor calculates
[0131] ω j = sk j ·R i
[0132] k j = H 3 (ω j , pk j , ID j , PID i , R i )
[0133] Then, calculate:
[0134] TK i = γ i mod k j
[0135] pk i || Y i || m = H 4 (TK i , PID i ) ⊕ C i
[0136] By calculating:
[0137] h 1 = H 5 (PID i , t i , m, pk i , Y i , R i , 1)
[0138] h 2 = H 5 (PID i , t i , m, pk i , Y i , R i , 2)
[0139] Further verification is performed;
[0140] Finally, the specialist doctor checks the equation ρ iP = R i + h 1 Y i + h 1 h i P pub + h 2 pk i Whether it holds. If it holds, the message m is received, indicating that the message is complete and from a legitimate source. Otherwise, the message is discarded. A specialist doctor can ensure that the message received from the patient has not been damaged or tampered with during transmission and is from a legitimate sender. This helps to maintain the integrity of medical data and protect patient privacy.
[0141] The above is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention.
Claims
1. A privacy-preserving multidisciplinary joint clinic secure communication method, characterized in that: The specific steps include: Step 1: System initialization: According to the preset security parameters, the medical center generates the system's master private key s and system public parameters par = {G, P, P pub ,H1,H2,H3,H4,H5},Then, the medical center will publish these public parameters and at the same time ensure the confidentiality of the master key s; Step 2: Register with a specialist doctor: The specialist first generates his key pair (sk j ,pk j ) and the challenge-response pair (C j ,R j ), and set the physical protection parameter Check j , then the doctor will send his ID j and public key pk j Public and store challenge C j , private key sk j , and physical protection parameters Check j ; Step 3: Patient Registration: Patient sends real ID to medical center i To complete the registration process, the medical center will use the patient's real ID i Generate corresponding pseudonyms and partial private key ppk i =(λ i ,Y i ), and then sends these parameters to the patient, who generates a challenge-response pair (C i ,R i ), and set the physical protection parameter Check i , then the patient stores the pseudonym Partial private key ppk i =(λ i ,Y i ), Challenge C i And physical protection parameter Cheak i ; Step 4: Broadcast signcryption: Patient ID i Need to send your diagnosis information to the multidisciplinary team of specialists s ={ID1,ID2,…,ID s },First, the patient needs to verify whether he has been physically attacked; When there is no attack, the patient generates his own signcryption key pair and uses the key pair to generate the ciphertext of the diagnosis information m. Then, the patient sends the ciphertext ξ i and its pseudonym PID i Broadcast to specialists in multidisciplinary clinic teams; When the patient detects a physical attack, the patient re-registers to counteract the physical key theft that has already occurred; Step 5: Decrypt the signature: Upon receiving the ciphertext i and the patient's pseudonym PID i Afterwards, the specialist needs to perform safety checks in order: First verify whether there has been a physical attack. If no physical attack traces are found, check the timestamp t i Effectiveness: When the timestamp t i When the timestamp t i When valid, the specialist will use his or her own private key for decryption and signature verification operations; Only if the authentication is successful will the specialist accept and process the message m; when the authentication fails, the message will be discarded immediately.
2. According to the privacy-preserving multidisciplinary joint outpatient secure communication method of claim 1, it is characterized in that: The step 1 system initialization includes: First, given the security parameters, the medical center first creates an elliptic curve G, which uses P as a generator and has an order of q; The medical center then randomly selects a master key and use it to calculate the system's public key P pub =s·P; Afterwards, the medical center selected five one-way hash functions, namely H1:{0,1} * →{0,1} |ID| , H4:{0,1} * →{0,1} 2|G|+|m| ,and Finally, the medical center exposes system parameters: par={G,P,P pub ,H1,H2,H3,H4,H5}。 3. According to the privacy-preserving multidisciplinary joint clinic secure communication method of claim 1, it is characterized in that: The second step of specialist registration includes: The specialist first randomly selects a private key Then calculate the corresponding public key pk j =sk j ·P; Next, the doctor generates a challenge-response pair (C j ,R j ), where R j =PUF(C j ); The doctor then calculates the physical protection parameter Check j =H2(C j ,R j ,sk j ,pk j ); Finally, the doctor will use the public key pk j Public and store challenge C j , private key sk j And physical protection parameter Check j .
4. According to the privacy-preserving multidisciplinary joint clinic secure communication method of claim 1, it is characterized in that: The step three of patient registration includes: First, the patient identifies his / her real identity Send to a medical center; Medical center receives ID i Then, randomly select a value Then calculate and This process enables the medical center to generate corresponding pseudonyms, i.e. Next, the medical center selects another random value And calculate Y i =y i ·P, h i =H2(PID i ,Y i ,P pub ), and λ i =y i +s·h i Then, the medical center will send part of the private key ppk i =(λ i ,Y i ) returned to the patient; The patient then generates a challenge-response pair (C i ,R i ), where R i =PUF(C i ), then the patient calculates the physical protection parameter Check i =H2(C i ,R i ,PID i ,ppk i ); Finally, patient storage challenges C i 、Pseudonym PID i , part of the private key ppk i And physical protection parameter Check i ,Usually, each patient needs to obtain a set of pseudonyms and partial private keys to achieve anonymity and ,unlinkability. After using the pseudonyms and partial private keys, ,the patient deletes them from the pool. At the same time, before the pseudonyms and partial private keys are ,exhausted, the patient will replenish new pseudonyms and partial private keys.
5. According to the privacy-preserving multidisciplinary joint clinic secure communication method of claim 1, it is characterized in that: The step 4 of broadcasting signcryption includes: Patient ID i Need to send your diagnosis information to the specialist team of the multidisciplinary joint outpatient team s ={ID1,ID2,…,ID s }; First, the patient needs to undergo a physical attack test and calculate R′ i =PUF(C i ) and Check′ i =H2(C i ,R' i ,PID i ,ppk i ), if Check' i =Check i , then proceed to the next step; otherwise, re-register to deal with physical attacks; Next, the patient randomly selects a private key Then calculate the corresponding public key pk i =sk i ·P; The patient then selects a random number And calculate R i =r i ·P; Then, for each ID j ∈Team s , respectively, the following calculations are performed: ω j =r i ·pk j , k j =H3(ω j ,pk j ,ID j ,PID i ,R i ), β j =α i / k j ; Afterwards, the patient calculates: θ j , so that β j ×θ j ≡1mod k j , var j =β j ×θ j ,as well as Next, the patient selects a transmission key And calculate: γ i =TK i ×sum i , Afterwards, the patient generates a timestamp t i ,calculate: h1=H5(PID i ,t i ,m,pk i ,Y i ,R i ,1) h2=H5(PID i ,t i ,m,pk i ,Y i ,R i ,2) r i =r i +h1λ i +h2sk i So as to obtain the ciphertext ξ i ={C i ,ρ i ,t i ,R i ,γ i }; Finally, the patient sends the ciphertext ξ i Its pseudonym PID i Broadcast to the multidisciplinary team of doctors s ={ID1,ID2,…,ID s }.
6. A privacy-protected multidisciplinary joint clinic secure communication method according to claim 1, characterized in that: The step 5 of decrypting the signcryption comprises: First, after receiving the ciphertext ξ i ={C i ,ρ i ,t i ,R i ,γ i } and the patient's pseudonym PID i After that, the specialist first needs to verify whether the data has been physically attacked, including calculating R' j =PUF(C j ) and Check' j =H2(C j ,R′ j ,sk j ,pk j ), if Check' j =Check j , indicating that the data is complete and you can proceed to the next step. Otherwise, re-register to prevent physical theft; Next, the specialist needs to check the timestamp t i If the timestamp is invalid, the message is considered invalid and discarded. If the timestamp is valid, the specialist can continue with the subsequent operation. The specialist then calculates ω j =en j ·R i k j =H3(ω j ,pk j ,ID j ,PID i ,R i ) Next, calculate: TK i =γ i modk j By calculating: h1=H5(PID i ,t i ,m,pk i ,Y i ,R i ,1) h2=H5(PID i ,t i ,m,pk i ,Y i ,R i ,2) Conduct further verification; Finally, the specialist checks the equation ρ i P=R i +h1Y i +h1h i P pub +h2pk i Is it true? If so, the message m is received, indicating that the message is complete and comes from a legitimate source. Otherwise, the message is discarded.