Medical system identity authentication and key negotiation system and method based on associated data encryption

Identity authentication and key negotiation in intelligent medical systems are implemented through AEGIS encryption and fuzzy feature extractor, which solves security threats in sensor data transmission, ensures data security and user privacy, resists multiple attacks, and achieves dynamic session keys and anonymity.

CN120358023APending Publication Date: 2025-07-22YANGZHOU POLYTECHNIC COLLEGE
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510503928.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the intelligent medical system, the patient privacy data collected by medical sensor devices are transmitted through public wireless channels and are susceptible to security threats such as unauthorized access, data interception and tampering, affecting the accuracy and timeliness of patient privacy and medical diagnosis.

Method used

AEGIS encryption technology and fuzzy feature extractor are used, combined with registration agencies, wearable devices and mobile terminals, and identity authentication and key negotiation are carried out on unsafe channels to generate dynamic session keys to prevent unauthorized access and data tampering.

Benefits of technology

Effectively resist replay attacks, steal attacks, man-in-the-middle attacks and desynchronization attacks, ensure data confidentiality and integrity, realize user anonymity and non-traceability, and prevent illegal access.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention discloses a medical system identity authentication and key negotiation system and method based on associated data encryption, and the system comprises a registration mechanism, a wearable device, a mobile terminal, and a medical server, and the registration mechanism completes the registration of a sensor device, the mobile terminal, and the medical server through a secure channel. And the sensor equipment, the mobile terminal and the medical server communicate with one another through an unsafe wireless public channel. In the initialization stage, the registration mechanism generates a master key for the medical server and selects a long-term identity ID and a temporary identity ID for the wearable device; in a mobile terminal registration stage, a registration mechanism stores and sends a secret certificate; in the user login stage, identity information is calculated, and service is provided according to a user request; in the identity authentication and key negotiation stage, mutual authentication among the mobile terminal, the medical server and the wearable device is executed, and session keys for future encrypted communication are negotiated and stored.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of medical service security, and particularly relates to a data encryption and authentication technology. Background Art

[0002] The rapid development of the Internet of Things technology has revolutionized the delivery mode of traditional healthcare services. Medical sensor devices represented by smart watches and health trackers collect patients' physiological data in real time, such as heart rate, blood oxygen, exercise volume, sleep quality, etc., and build the perception layer foundation of the intelligent medical system. Looking ahead, the intelligent medical system composed of various medical sensor devices, mobile terminals, and medical servers will become increasingly popular, further promoting the development of remote health monitoring, critical patient warning, and personalized diagnosis and treatment.

[0003] The security challenges faced by the intelligent medical system are becoming increasingly severe. The patient privacy data collected by sensor devices is transmitted between mobile terminals and medical servers through public wireless channels, and is extremely vulnerable to various security threats, including unauthorized access, data interception, tampering, etc. These threats not only seriously endanger the personal privacy of patients, but also may have a significant impact on the accuracy and timeliness of medical diagnosis, and even lead to medical accidents.

[0004] Identity authentication and key negotiation protocols are widely regarded as effective solutions. By verifying the identity legality of both communication parties, establishing a secure temporary session key, preventing illegal access by unauthorized users, providing end-to-end security protection for data transmission, and ensuring the confidentiality and integrity of data.

[0005] The encryption technology based on AEGIS can provide verification of data integrity and authenticity while protecting data confidentiality. AEGIS defines two core functions. (C, Tag) = E k (IV, AD, P) function: The AEGIS encryption function receives a key k, an initialization vector IV, associated data AD, and a plaintext P, and generates a ciphertext C and a corresponding authentication verification parameter Tag. (P, ⊥) = D k (IV, AD, C, Tag) function: The AEGIS decryption function uses the same key k, initialization vector IV, and associated data AD as encryption to decrypt the ciphertext C, and at the same time generates a new authentication verification parameter Tag'. This verification parameter is compared with the received Tag. If the authentication is successful, the plaintext P is returned; if the authentication fails, the error flag ⊥ is returned, indicating that the ciphertext may be tampered with or the associated data is inconsistent.

[0006] The fuzzy feature extractor is a tool for generating stable and reliable keys from biometric data with high noise or randomness, and is implemented through two main algorithms Gen(·) and Rep(·). (K, RD) = Gen(Data) algorithm: Given a fuzzy input data, Gen(·) generates a stable key K and corresponding auxiliary data RD. RD is only used as auxiliary information for key recovery and does not disclose any information about K. K = Rep(Data′, RD) algorithm: When the new input data Data′ has sufficient similarity to the original input Data, Rep(·) can use RD to recover the original key K. This process ensures that even if the input data changes to a certain extent, as long as the difference is within the allowable range, the system can still generate the same key. Summary of the Invention

[0007] To solve the technical problem of medical data being attacked during transmission over the wireless public channel, a technical solution is adopted where AEGIS is applied to encrypted communication between various entities and the fuzzy feature extractor calculates the biometric features input by the user.

[0008] The system includes a registration authority, a wearable device, a mobile terminal, and a medical server. The registration authority completes the registration of the sensor device, mobile terminal, and medical server through a secure channel, and the sensor device, mobile terminal, and medical server communicate through an insecure wireless public channel.

[0009] In the initialization phase, the registration authority initializes the system, generates a master key for the medical server, and selects a long-term identity ID and a temporary identity ID for the wearable device; in the mobile terminal registration phase, the registration authority registers the mobile terminal, stores and sends secret credentials; in the user login phase, according to the credentials pre-stored in the mobile terminal, the identity information is calculated, and after verifying the legal identity, the service is provided according to the user's request; in the identity authentication and key negotiation phase, mutual authentication is performed among the mobile terminal, medical server, and wearable device, the session key for future encrypted communication is negotiated and stored, and the temporary parameters are updated.

[0010] In the initialization phase, the registration authority publishes a secure one-way hash function and the AEGIS encryption / decryption function, calculates the first initialization verification parameter using the hash function, divides it into two parts, calculates the pseudo-identity ID of the wearable device using exclusive OR, and stores the medical server master key and the secret credentials of the wearable device in the database of the medical server; the wearable device stores the temporary identity ID and the pseudo-identity ID in the memory.

[0011] In the mobile terminal registration stage, the user sets a long-term identity ID and its corresponding password, and enters personal biometric characteristics; the mobile terminal uses a fuzzy feature extractor to calculate biometric information recovery data and a biometric key based on the personal biometric characteristics, generates a first random number for user registration, and calculates a first verification parameter and a second verification parameter for user registration using a hash function; divides the first verification parameter for user registration into two parts and calculates a pseudo identity ID through exclusive-or calculation; divides the second verification parameter for user registration into two parts and calculates a pseudo password through exclusive-or calculation, and sends the pseudo identity ID and the pseudo password to the registration institution through a secure channel to request registration.

[0012] After receiving the registration request, the registration institution assigns a temporary identity ID to the user and generates a second random number; calculates a third verification parameter, a fourth verification parameter, a fifth verification parameter, and a sixth verification parameter for user registration using a hash function and exclusive-or calculation; stores the user's secret credentials in the database of the medical server, where the user's secret credentials include the temporary identity ID, the pseudo identity ID, and the third verification parameter for user registration; sends the temporary identity ID verification parameter, the fourth verification parameter, the fifth verification parameter, and the sixth user verification parameter to the mobile terminal through a secure channel.

[0013] After receiving the registration credentials, the mobile terminal divides the fifth verification parameter for user registration into two parts, calculates a first AEGIS encryption key for user registration using a hash function based on the biometric key and the first random number for user registration; obtains a first ciphertext for user registration and a first authentication tag using the AEGIS encryption algorithm, and stores the identity information and credentials in the memory.

[0014] In the user login stage, the user enters the long-term identity ID and its corresponding password into the mobile terminal, and enters personal biometric information characteristics; the mobile terminal extracts the seventh verification parameter from the memory to calculate the first random number for user registration, uses the Rep(·) algorithm to recover the original biometric key from the biometric information characteristics, calculates a first verification parameter and a second verification parameter in the login stage, obtains a pseudo user ID and a pseudo password, calculates a second random number for user registration and a third login verification parameter based on the pseudo user ID and the pseudo password; divides the third login verification parameter into two parts, namely a first login initialization vector and a first login associated data; calculates a first AEGIS decryption key in the login stage, extracts the first ciphertext for user registration and the first authentication tag from the memory; performs AEGIS decryption, and if the login is successful, obtains the plaintext fourth user registration verification parameter; otherwise, the login fails and the current connection is terminated.

[0015] In the identity authentication and key negotiation phase, after the user logs in successfully, a first message is sent to the wearable device through an insecure public channel; after receiving the first message, the wearable device calculates the first verification parameter and the second verification parameter, constructs a second message, and sends it to the mobile terminal; after receiving the second message, the mobile terminal generates a third message and sends it to the medical server; after receiving the third message, the medical server verifies the user's identity; after the user passes the identity verification of the medical server, the legitimacy of the wearable device is verified; after the identity verification of the user and the wearable device is successful, the medical server constructs a fourth message and sends it to the mobile terminal; after receiving the fourth message, the mobile terminal verifies the legitimacy of the medical server, updates the user's temporary identity ID, constructs a fifth message, and sends it to the wearable device; after receiving the fifth message, the wearable device updates its temporary identity.

[0016] After the user logs in successfully, the mobile terminal generates a first random number, uses the current time as the first timestamp, and sends a first message to the wearable device through an insecure public channel. The first message includes a temporary user ID, the first random number, and the first timestamp.

[0017] After receiving the first message, the wearable device checks the message according to the timestamp. If the message is fresh, the wearable device generates a second random number, uses the current time as the second timestamp; calculates the first verification parameter and the second verification parameter, constructs a second message, and sends it to the mobile terminal. The second message includes the wearable device's temporary ID, the first authentication parameter, the second authentication parameter, and the second timestamp.

[0018] After receiving the second message, the mobile terminal checks the message according to the timestamp. If the message is fresh, it generates a third random number and a third timestamp; calculates the third verification parameter using a hash function, divides the fourth user registration verification parameter in memory into two parts, namely the first initialization vector and the first associated data; divides the third verification parameter into two parts, and obtains the first authentication AEGIS encryption key through exclusive OR calculation, constructs the first plaintext; obtains the first authentication ciphertext and the first authentication tag using the AEGIS encryption algorithm, constructs a third message, and sends it to the medical server. The third message includes the temporary user ID, the first authentication ciphertext, the first authentication tag, and the second and third timestamps.

[0019] After receiving the third message, the medical server checks the message according to the timestamp. If the message is fresh, it retrieves the database based on the user's temporary identity ID in the message. If there is no matching item, the message has been tampered with or comes from an illegal user, and the authentication process is terminated. If there is a matching item, the credentials related to the user's temporary identity ID are extracted, including the pseudo-user ID and the third user registration verification parameter. Calculate the second random number for user registration, the fourth verification parameter, and the fifth verification parameter. Divide the fourth verification parameter into two parts, namely the second initialization vector and the second correlation parameter. Divide the fifth verification parameter into two parts, and use exclusive OR calculation to obtain the third authentication AEGIS decryption key. According to the second initialization vector, the second correlation parameter, and the second decryption key, decrypt the first authentication ciphertext and the first authentication tag. If the decryption is successful, the user passes the server's identity verification and obtains the second plaintext, which includes the first verification parameter, the second verification parameter, the wearable device's temporary identity ID, the first random number, and the third random number. If the decryption fails, the server terminates the connection.

[0020] Furthermore, if the user's temporary identity ID matches the old user's temporary identity ID in the database, it means that the mobile terminal failed to correctly update the temporary identity in the previous authentication session. If the user's temporary identity ID matches the new user's temporary identity ID in the database, it means that the mobile terminal successfully completed the corresponding process and correctly updated the temporary identity in the previous authentication session.

[0021] After the user passes the medical server's identity verification, the cloud server retrieves the database based on the wearable device's temporary identity ID in the second plaintext. If there is no matching item, the message has been tampered with or comes from an illegal wearable device, and the connection is terminated. If there is a matching item, the long-term identity ID of the wearable device is extracted, the sixth verification parameter is calculated, and the pseudo-identity ID of the wearable device is obtained. Calculate the second random number and the second verification parameter. If they match the stored second verification parameter, the wearable device is legal; otherwise, the connection is terminated.

[0022] After the authentication of the user and the wearable device is successful, the medical server generates a fourth random number and uses the current time as the fourth timestamp; calculates the session key between the medical server and the mobile terminal and the session key between the mobile terminal and the wearable device; uses the exclusive-or calculation of the hash function to obtain the confused session key between the mobile terminal and the wearable device; the medical server generates new temporary identity IDs for the wearable device and the user and updates the secret credentials in the database; calculates the seventh verification parameter and the eighth verification parameter, divides the seventh verification parameter into two parts, namely the third initialization vector and the third associated data; divides the eighth authentication tag into two parts and uses the exclusive-or calculation to obtain the third AEGIS encryption key; splices the identity-related information into the third plaintext, uses it as the parameter for calculating the AEGIS encryption algorithm, encrypts it to obtain the third authentication ciphertext and the third authentication tag, and together with the fourth timestamp, forms the fourth message and sends it to the mobile terminal.

[0023] After receiving the fourth message, the mobile terminal checks the message according to the timestamp. If the message is fresh, it calculates the ninth verification parameter, the tenth verification parameter, the fourth initialization vector, the fourth associated data, and the fourth decryption key using the hash function, and decrypts the third authentication ciphertext and the third authentication tag; if the decryption is successful, the medical server is verified to be legal, and the mobile terminal obtains the fourth plaintext data, which includes the second random number, the fourth random number, the new temporary identity IDs of the user and the wearable device, and the confused session key between the wearable device and the mobile terminal; calculates the session key between the mobile terminal and the medical server and the session key between the mobile terminal and the wearable device, stores them in the memory, and updates the user's temporary identity ID.

[0024] The mobile terminal generates a new fifth random number and uses the current time as the fifth timestamp, calculates the eleventh verification parameter, the twelfth verification parameter, and the thirteenth verification parameter, divides them into two parts, calculates the parameters for executing the AEGIS encryption algorithm, the fifth initialization vector, the fifth associated data, and the fifth encryption key; constructs the fifth plaintext, which includes the fourth random number and the new temporary identity ID of the wearable device, executes the AEGIS encryption algorithm, and encrypts it to obtain the fifth authentication ciphertext and the fifth authentication tag; constructs the fifth message and sends it to the wearable device. The fifth message includes the fifth authentication ciphertext, the fifth authentication tag, the eleventh verification parameter, the fourth timestamp, and the fifth timestamp.

[0025] After receiving the fifth message, the wearable device checks the message according to the timestamp. If the message is fresh, it calculates the fifth random number, the fourteenth verification parameter, and the fifteenth verification parameter, calculates the sixth initialization vector, the sixth associated data, and the sixth decryption key according to the fourteenth verification parameter and the fifteenth verification parameter, and decrypts the fifth authentication ciphertext and the fifth authentication tag; if the decryption is successful, the wearable device obtains the fifth plaintext, calculates the session key between the wearable device and the mobile terminal, and stores and updates the temporary identity of the wearable device.

[0026] The transmitted message contains a timestamp, a temporary identity, and an encrypted credential calculated from temporary and long-term parameters of a specific session and communication entity. The receiver determines the freshness of the message by verifying the timestamp and ciphertext validity, which can effectively resist replay attacks.

[0027] Authorized users are authenticated locally using long-term user IDs, passwords, and biometrics. Without these key information, decryption and login are impossible, making the system robust against mobile terminal theft attacks.

[0028] Even if the wearable device is stolen and the session key between it and the user is compromised, the session keys between other devices and the user will not be leaked, effectively preventing potential security risks caused by the theft of physical devices.

[0029] The medical server stores the temporary identities of the user and the wearable device in the latest and previous round of sessions. Even if the fourth or fifth message is intercepted, causing the user and the wearable device to fail to update the temporary identity, the medical server can still identify the identity of the user and the wearable device from subsequent authentication sessions and find the corresponding credentials, effectively resisting the threat of desynchronization attacks.

[0030] The message contains a temporary identity related to the session and communication entity, a timestamp, and credentials generated through AEGIS encryption. The temporary identity of each authentication cycle will be dynamically updated. Even if all messages are intercepted and the temporary user ID is extracted from them, the user cannot be tracked for a long time, which gives it strong non-traceability.

[0031] In the absence of long-term and short-term secret credentials, the encrypted credentials cannot be decrypted, the sensitive information contained therein cannot be obtained, and the user's long-term identity ID cannot be inferred, thus cleverly achieving user anonymity.

[0032] In the absence of long-term parameters and temporary session parameters, AEGIS encryption credentials that can be verified by the recipient cannot be generated. Even if the entire message is intercepted, it cannot be tampered with, preventing man-in-the-middle attacks.

[0033] Even if the mobile terminal is obtained, the user's long-term identity ID and password cannot be derived. In the absence of biometric information, local login through the mobile terminal cannot be performed, and information cannot be extracted to launch attacks, showing strong robustness against privileged user attacks.

[0034] The session key is composed of multiple parameters such as temporary identity, random number, timestamp, and long-term credentials. It is independent for different communication entities and each session, ensuring the uniqueness of each session key. Even if some session keys are leaked, it will not affect the security of other sessions. DETAILED DESCRIPTION

[0035] The technical solution of the present invention will be specifically described below.

[0036] A system is constructed by using a registration institution, a wearable device, a mobile terminal, and a medical server. The registration institution completes the registration of the sensor device, the mobile terminal, and the medical server through a secure channel, and the sensor device, the mobile terminal, and the medical server communicate through an insecure wireless public channel.

[0037] In the initialization phase, the registration institution initializes the system, generates a master key for the medical server, and selects a long-term identity ID and a temporary identity ID for the wearable device.

[0038] The registration institution publishes a secure one-way hash function and an AEGIS encryption / decryption function, calculates the first initialization verification parameter using the hash function, divides it into two parts, calculates the pseudo-identity ID of the wearable device using exclusive OR, stores the master key of the medical server and the secret credentials of the wearable device in the database of the medical server; the wearable device stores the temporary identity ID and the pseudo-identity ID in the memory.

[0039] In the mobile terminal registration phase, the registration institution registers the mobile terminal, stores and sends the secret credentials.

[0040] The user sets the long-term identity ID and its corresponding password, and enters personal biometric features; the mobile terminal uses a fuzzy feature extractor to calculate the biometric information recovery data and the biometric key according to the personal biometric features, generates the first random number for user registration, and calculates the first verification parameter and the second verification parameter for user registration using the hash function; divides the first verification parameter for user registration into two parts, and calculates the pseudo-identity ID through exclusive OR; divides the second verification parameter for user registration into two parts, and calculates the pseudo-password through exclusive OR, and sends the pseudo-identity ID and the pseudo-password to the registration institution through a secure channel to request registration.

[0041] After receiving the registration request, the registration institution assigns a temporary identity ID to the user and generates a second random number; calculates the third verification parameter, the fourth verification parameter, the fifth verification parameter, and the sixth verification parameter for user registration using the hash function and exclusive OR; stores the user's secret credentials in the database of the medical server, and the user's secret credentials include the temporary identity ID, the pseudo-identity ID, and the third verification parameter for user registration; sends the temporary identity ID verification parameter, the fourth verification parameter, the fifth verification parameter, and the sixth user verification parameter to the mobile terminal through a secure channel.

[0042] After the mobile terminal receives the registration credential, it divides the user registration fifth verification parameter into two parts. Based on the biometric key and the user registration first random number, it calculates the user registration first AEGIS encryption key using a hash function; it obtains the user registration first ciphertext and the user registration first authentication tag using the AEGIS encryption algorithm, and stores the identity information and the credential in the memory.

[0043] In the user login stage, based on the credential pre-stored in the mobile terminal, it calculates the identity information. After verifying the legitimacy of the identity, it provides services according to the user request.

[0044] The user inputs the long-term identity ID and its corresponding password to the mobile terminal and enters the personal biometric information characteristics; the mobile terminal extracts the seventh verification parameter from the memory to calculate the user registration first random number, uses the Rep(·) algorithm to recover the original biometric key from the biometric information characteristics, calculates the first verification parameter and the second verification parameter in the login stage, obtains the pseudo-user ID and the pseudo-password, and calculates the user registration second random number and the third login verification parameter according to the pseudo-user ID and the pseudo-password; it divides the third login verification parameter into two parts, namely the first login initialization vector and the first login associated data; it calculates the first AEGIS decryption key in the login stage, extracts the user registration first ciphertext and the user registration first authentication tag from the memory; it performs AEGIS decryption. If the login is successful, it obtains the plaintext fourth user registration verification parameter; otherwise, the login fails and this connection is terminated.

[0045] In the identity authentication and key negotiation stage, it performs mutual authentication among the mobile terminal, the medical server, and the wearable device, negotiates and stores the session key for future encrypted communication, and updates the temporary parameters.

[0046] After the user logs in successfully, it sends the first message to the wearable device through an insecure public channel; after the wearable device receives the first message, it calculates the first verification parameter and the second verification parameter, constructs the second message, and sends it to the mobile terminal; after the mobile terminal receives the second message, it generates the third message and sends it to the medical server; after the medical server receives the third message, it verifies the user's identity; after the user passes the identity verification of the medical server, it verifies the legitimacy of the wearable device; after the identity verification of the user and the wearable device is successful, the medical server constructs the fourth message and sends it to the mobile terminal; after the mobile terminal receives the fourth message, it verifies the legitimacy of the medical server, updates the user's temporary identity ID, constructs the fifth message, and sends it to the wearable device; after the wearable device receives the fifth message, it updates the temporary identity of the wearable device.

[0047] After the user logs in successfully, the mobile terminal generates a first random number, uses the current time as the first timestamp, and sends the first message to the wearable device through an insecure public channel. The first message includes the temporary user ID, the first random number, and the first timestamp.

[0048] After the wearable device receives the first message, it verifies the message according to the timestamp. If the message is fresh, the wearable device generates a second random number and uses the current time as the second timestamp; calculates the first verification parameter and the second verification parameter, constructs the second message, and sends it to the mobile terminal. The second message includes the wearable device temporary ID, the first authentication parameter, the second authentication parameter, and the second timestamp.

[0049] After the mobile terminal receives the second message, it verifies the message according to the timestamp. If the message is fresh, it generates a third random number and a third timestamp; calculates the third verification parameter using a hash function, divides the fourth user registration verification parameter in the memory into two parts, namely the first initialization vector and the first associated data; divides the third verification parameter into two parts, and obtains the first authentication AEGIS encryption key through exclusive OR calculation, constructs the first plaintext; obtains the first authentication ciphertext and the first authentication tag using the AEGIS encryption algorithm, constructs the third message, and sends it to the medical server. The third message includes the temporary user ID, the first authentication ciphertext, the first authentication tag, and the second and third timestamps.

[0050] After the medical server receives the third message, it verifies the message according to the timestamp. If the message is fresh, it retrieves the database according to the user temporary identity ID in the message; if there is no matching item, the message has been tampered with or comes from an illegal user, and the authentication process is terminated; if there is a matching item, it extracts the credentials related to the user temporary identity ID, including the pseudo user ID and the third user registration verification parameter; calculates the second random number, the fourth verification parameter, and the fifth verification parameter for user registration, divides the fourth verification parameter into two parts, namely the second initialization vector and the second associated parameter; divides the fifth verification parameter into two parts, and obtains the third authentication AEGIS decryption key through exclusive OR calculation. According to the second initialization vector, the second associated parameter, and the second decryption key, it decrypts the first authentication ciphertext and the first authentication tag; if the decryption is successful, the user passes the server authentication and obtains the second plaintext, which includes the first verification parameter, the second verification parameter, the wearable device temporary identity ID, the first random number, and the third random number; if the decryption fails, the server terminates the connection.

[0051] If the user temporary identity ID is consistent with the old user temporary identity ID in the database, it means that the mobile terminal failed to correctly update the temporary identity in the previous authentication session; if the user temporary identity ID is consistent with the new user temporary identity ID in the database, it means that the mobile terminal successfully completed the corresponding process and correctly updated the temporary identity in the previous authentication session.

[0052] After the user passes the authentication of the medical server, the cloud server retrieves the database according to the wearable device temporary identity ID in the second plaintext; if there is no matching item, the message is tampered with or from an illegal wearable device, and the connection is terminated; if there is a matching item, the long-term identity ID of the wearable device is extracted, the sixth verification parameter is calculated, and the pseudo-identity ID of the wearable device is obtained; the second random number and the second verification parameter are calculated, and if they match the stored second verification parameter, the wearable device is legal, otherwise the connection is terminated.

[0053] After the authentication of the user and the wearable device is successful, the medical server generates a fourth random number and uses the current time as the fourth timestamp; calculates the session key between the medical server and the mobile terminal, and the session key between the mobile terminal and the wearable device; uses the exclusive OR calculation of the hash function to obtain the confused session key between the mobile terminal and the wearable device; the medical server generates new temporary identity IDs for the wearable device and the user, and updates the secret credentials in the database; calculates the seventh verification parameter and the eighth verification parameter, divides the seventh verification parameter into two parts, namely the third initialization vector and the third associated data; divides the eighth authentication tag into two parts, and uses the exclusive OR calculation to obtain the third AEGIS encryption key; splices the identity-related information into the third plaintext, which is used as the parameter for calculating the AEGIS encryption algorithm, encrypts to obtain the third authentication ciphertext and the third authentication tag, and together with the fourth timestamp, forms the fourth message and sends it to the mobile terminal.

[0054] After receiving the fourth message, the mobile terminal checks the message according to the timestamp. If the message is fresh, it calculates the ninth verification parameter, the tenth verification parameter, the fourth initialization vector, the fourth associated data, and the fourth decryption key using the hash function, and decrypts the third authentication ciphertext and the third authentication tag; if the decryption is successful, the medical server is verified to be legal, and the mobile terminal obtains the fourth plaintext data, including the second random number, the fourth random number, the new temporary identity IDs of the user and the wearable device, and the confused session key between the wearable device and the mobile terminal; calculates the session key between the mobile terminal and the medical server, and the session key between the mobile terminal and the wearable device, stores them in the memory, and updates the user temporary identity ID.

[0055] The mobile terminal generates a new fifth random number, uses the current time as the fifth timestamp, calculates the eleventh verification parameter, the twelfth verification parameter, and the thirteenth verification parameter, divides them into two parts, calculates the parameters, the fifth initialization vector, the fifth associated data, and the fifth encryption key for performing the AEGIS encryption algorithm; constructs the fifth plaintext, including the fourth random number and the new temporary identity ID of the wearable device, performs the AEGIS encryption algorithm, and encrypts to obtain the fifth authentication ciphertext and the fifth authentication tag; constructs the fifth message and sends it to the wearable device. The fifth message includes the fifth authentication ciphertext, the fifth authentication tag, the eleventh verification parameter, the fourth timestamp, and the fifth timestamp.

[0056] After receiving the fifth message, the wearable device verifies the message according to the timestamp. If the message is fresh, it calculates the fifth random number, the fourteenth verification parameter, and the fifteenth verification parameter, calculates the sixth initialization vector, the sixth associated data, and the sixth decryption key according to the fourteenth verification parameter and the fifteenth verification parameter, and decrypts the fifth authentication ciphertext and the fifth authentication tag. If the decryption is successful, the wearable device obtains the fifth plaintext, calculates the session key between the wearable device and the mobile terminal, and stores and updates the temporary identity of the wearable device.

[0057] The above are embodiments of the present invention and do not limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.

Claims

1. A medical system identity authentication and key negotiation system based on associated data encryption, characterized in that, Including: A registration institution, a wearable device, a mobile terminal, and a medical server. The registration institution completes the registration of the sensor device, the mobile terminal, and the medical server through a secure channel, and the sensor device, the mobile terminal, and the medical server communicate with each other through an insecure wireless public channel.

2. A method for identity authentication and key negotiation of a medical system based on associated data encryption, characterized in that, The medical system identity authentication and key negotiation system based on associated data encryption according to claim 1, including: an initialization phase, where the registration institution initializes the system, generates a master key for the medical server, and selects a long-term identity ID and a temporary identity ID for the wearable device; a mobile terminal registration phase, where the registration institution registers the mobile terminal, stores and sends secret credentials; a user login phase, where, according to the credentials pre-stored in the mobile terminal, the identity information is calculated, and after verifying the legitimacy of the identity, services are provided according to the user's request; an identity authentication and key negotiation phase, where mutual authentication among the mobile terminal, the medical server, and the wearable device is performed, the session key for future encrypted communication is negotiated and stored, and the temporary parameters are updated.

3. The method for medical system identity authentication and key negotiation based on associated data encryption according to claim 2, wherein the initialization phase includes: The registration institution discloses a secure one-way hash function and an AEGIS encryption / decryption function, calculates the first initialization verification parameter using the hash function, divides it into two parts, calculates the pseudo-identity ID of the wearable device using exclusive OR, and stores the medical server master key and the secret credential of the wearable device in the database of the medical server; the wearable device stores the temporary identity ID and the pseudo-identity ID in the memory.

4. The method for identity authentication and key negotiation of a medical system based on associated data encryption according to claim 2, wherein the mobile terminal registration stage includes: The user sets the long-term identity ID and its corresponding password, and enters personal biometric features. The mobile terminal uses a fuzzy feature extractor to calculate the biometric information recovery data and the biometric key according to the personal biometric features, generates the first random number for user registration, and calculates the first verification parameter and the second verification parameter for user registration using the hash function; divides the first verification parameter for user registration into two parts, and calculates the pseudo-identity ID through exclusive OR. Divides the second verification parameter for user registration into two parts, calculates the pseudo-password through exclusive OR, and sends the pseudo-identity ID and the pseudo-password to the registration institution through a secure channel to request registration.

5. The method for medical system identity authentication and key negotiation based on associated data encryption according to claim 4 further includes: After receiving the registration request, the registration institution assigns a temporary identity ID to the user and generates a second random number. Calculates the third verification parameter, the fourth verification parameter, the fifth verification parameter, and the sixth verification parameter for user registration using the hash function and exclusive OR; stores the user's secret credential in the database of the medical server, and the user's secret credential includes the temporary identity ID, the pseudo-identity ID, and the third verification parameter for user registration; sends the temporary identity ID verification parameter, the fourth verification parameter, the fifth verification parameter, and the sixth user verification parameter to the mobile terminal through a secure channel.

6. The method for medical system identity authentication and key negotiation based on associated data encryption according to claim 4 further includes: After receiving the registration credential, the mobile terminal divides the fifth verification parameter for user registration into two parts, calculates the first AEGIS encryption key for user registration according to the biometric key and the first random number for user registration using the hash function; obtains the first ciphertext for user registration and the first authentication tag using the AEGIS encryption algorithm, and stores the identity information and the credential in the memory.

7. The method for medical system identity authentication and key negotiation based on associated data encryption according to claim 2, wherein the user login phase includes: The user inputs the long-term identity ID and its corresponding password to the mobile terminal, and enters personal biometric information features. The mobile terminal extracts the seventh verification parameter from the memory to calculate the first random number for user registration, uses the Rep(·) algorithm to recover the original biological key from the biometric features, calculates the first verification parameter and the second verification parameter in the login stage, obtains the pseudo-user ID and the pseudo-password, and calculates the second random number for user registration and the third login verification parameter according to the pseudo-user ID and the pseudo-password; divides the third login verification parameter into two parts, namely the first login initialization vector and the first login associated data; Calculates the first AEGIS decryption key for the login stage, and extracts the first user registration ciphertext and the first user registration authentication tag from the memory; Performs AEGIS decryption. If the login is successful, the plaintext fourth user registration verification parameter is obtained; Otherwise, the login fails and this connection is terminated.

8. The method for medical system identity authentication and key negotiation based on associated data encryption according to claim 2, wherein the identity authentication and key negotiation phase includes: After the user logs in successfully, the mobile terminal sends the first message to the wearable device through an insecure public channel; After receiving the first message, the wearable device calculates the first verification parameter and the second verification parameter, constructs the second message, and sends it to the mobile terminal; After receiving the second message, the mobile terminal generates the third message and sends it to the medical server; After receiving the third message, the medical server verifies the user's identity; after the user passes the identity verification of the medical server, the legitimacy of the wearable device is verified; after the identity verification of the user and the wearable device is successful, the medical server constructs the fourth message and sends it to the mobile terminal; after receiving the fourth message, the mobile terminal verifies the legitimacy of the medical server, updates the user's temporary identity ID, constructs the fifth message, and sends it to the wearable device; after receiving the fifth message, the wearable device updates its temporary identity.

9. The method for medical system identity authentication and key negotiation based on associated data encryption according to claim 8 further includes: After the user logs in successfully, the mobile terminal generates the first random number, uses the current time as the first timestamp, and sends the first message to the wearable device through an insecure public channel. The first message includes the temporary user ID, the first random number, and the first timestamp; After receiving the first message, the wearable device checks the message according to the timestamp. If the message is fresh, the wearable device generates the second random number and uses the current time as the second timestamp; Calculates the first verification parameter and the second verification parameter, constructs the second message, and sends it to the mobile terminal. The second message includes the wearable device temporary ID, the first authentication parameter, the second authentication parameter, and the second timestamp; After receiving the second message, the mobile terminal checks the message according to the timestamp. If the message is fresh, it generates the third random number and the third timestamp; calculates the third verification parameter using the hash function, divides the fourth user registration verification parameter in the memory into two parts, namely the first initialization vector and the first associated data; divides the third verification parameter into two parts, and obtains the first authentication AEGIS encryption key through exclusive OR calculation, constructs the first plaintext; obtains the first authentication ciphertext and the first authentication tag using the AEGIS encryption algorithm, constructs the third message, and sends it to the medical server. The third message includes the temporary user ID, the first authentication ciphertext, the first authentication tag, and the second and third timestamps; After the medical server receives the third message, it verifies the message according to the timestamp. If the message is fresh, it retrieves the database based on the user's temporary identity ID in the message. If there is no matching item, the message has been tampered with or comes from an illegal user, and the authentication process is terminated. If there is a matching item, the credentials related to the user's temporary identity ID are extracted, including the pseudo-user ID and the third user registration verification parameter. The second random number for user registration, the fourth verification parameter, and the fifth verification parameter are calculated. The fourth verification parameter is divided into two parts, namely the second initialization vector and the second correlation parameter. The fifth verification parameter is divided into two parts, and the third authentication AEGIS decryption key is obtained through exclusive OR calculation. Based on the second initialization vector, the second correlation parameter, and the second decryption key, the first authentication ciphertext and the first authentication tag are decrypted. If the decryption is successful, the user passes the server's identity verification and obtains the second plaintext, which includes the first verification parameter, the second verification parameter, the wearable device's temporary identity ID, the first random number, and the third random number. If the decryption fails, the server terminates the connection. After the user passes the medical server's identity verification, the cloud server retrieves the database based on the wearable device's temporary identity ID in the second plaintext. If there is no matching item, the message has been tampered with or comes from an illegal wearable device, and the connection is terminated. If there is a matching item, the long-term identity ID of the wearable device is extracted, the sixth verification parameter is calculated, and the pseudo-identity ID of the wearable device is obtained. The second random number and the second verification parameter are calculated. If they match the stored second verification parameter, the wearable device is legal; otherwise, the connection is terminated. After the identity verification of the user and the wearable device is successful, the medical server generates the fourth random number and uses the current time as the fourth timestamp. The session key between the medical server and the mobile terminal and the session key between the mobile terminal and the wearable device are calculated. Through exclusive OR calculation using the hash function, the confused session key between the mobile terminal and the wearable device is obtained. The medical server generates new temporary identity IDs for the wearable device and the user and updates the secret credentials in the database. The seventh verification parameter and the eighth verification parameter are calculated. The seventh verification parameter is divided into two parts, namely the third initialization vector and the third correlation data. The eighth authentication tag is divided into two parts, and the third AEGIS encryption key is obtained through exclusive OR calculation. The identity-related information is assembled into the third plaintext, which is used as the parameter for the AEGIS encryption algorithm. After encryption, the third authentication ciphertext and the third authentication tag are obtained, and together with the fourth timestamp, they form the fourth message, which is sent to the mobile terminal. After the mobile terminal receives the fourth message, it verifies the message according to the timestamp. If the message is fresh, the ninth verification parameter, the tenth verification parameter, the fourth initialization vector, the fourth correlation data, and the fourth decryption key are calculated using the hash function to decrypt the third authentication ciphertext and the third authentication tag. If the decryption is successful, the medical server is verified to be legal, and the mobile terminal obtains the fourth plaintext data, which includes the second random number, the fourth random number, the new temporary identity IDs of the user and the wearable device, and the confused session key between the wearable device and the mobile terminal. Calculate the session keys between the mobile terminal and the medical server, and between the mobile terminal and the wearable device, store them in the memory, and update the user's temporary identity ID. The mobile terminal generates a new fifth random number, uses the current time as the fifth timestamp, calculates the eleventh verification parameter, the twelfth verification parameter, and the thirteenth verification parameter, divides them into two parts, and calculates the parameters for executing the AEGIS encryption algorithm, the fifth initialization vector, the fifth associated data, and the fifth encryption key; constructs the fifth plaintext, which includes the fourth random number and the new temporary identity ID of the wearable device, and executes the AEGIS encryption algorithm to encrypt and obtain the fifth authentication ciphertext and the fifth authentication tag. Construct the fifth message and send it to the wearable device. The fifth message includes the fifth authentication ciphertext, the fifth authentication tag, the eleventh verification parameter, the fourth timestamp, and the fifth timestamp. After receiving the fifth message, the wearable device checks the message according to the timestamp. If the message is fresh, it calculates the fifth random number, the fourteenth verification parameter, and the fifteenth verification parameter, and calculates the sixth initialization vector, the sixth associated data, and the sixth decryption key according to the fourteenth verification parameter and the fifteenth verification parameter, and decrypts the fifth authentication ciphertext and the fifth authentication tag. If the decryption is successful, the wearable device obtains the fifth plaintext, calculates the session key between the wearable device and the mobile terminal, and stores and updates the temporary identity of the wearable device.

10. The method for medical system identity authentication and key negotiation based on associated data encryption according to claim 9, wherein the medical server receives the third message, including: If the user's temporary identity ID matches the old user's temporary identity ID in the database, it means that the mobile terminal failed to correctly update the temporary identity in the previous authentication session. If the user's temporary identity ID matches the new user's temporary identity ID in the database, it means that the mobile terminal successfully completed the corresponding process and correctly updated the temporary identity in the previous authentication session.

Citation Information

Cited By

  • Medical device group one-time safe access method for medical rounds

    CN122640253A