Dynamic key driven medical terminal security self-adaptive remote control method

By using a dynamic key-driven secure adaptive remote control method, which combines terminal hardware identity and network status dynamic adjustment, the security and stability issues of remote control of medical terminals are solved, and efficient operation and maintenance and business continuity are achieved during network fluctuations.

CN120658383BActive Publication Date: 2025-11-18BEIJING HENGSHENG YUNTAI NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510745889.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-11-18
Estimated Expiration
2045-06-05

AI Technical Summary

Technical Problem

Existing remote control methods for medical terminals have shortcomings in communication security, command transmission stability, terminal status assessment, and service hierarchical management. They are vulnerable to attacks and their service execution is unstable when the network fluctuates, failing to meet the efficient operation and maintenance needs of large hospitals.

Method used

A secure adaptive remote control method driven by dynamic keys is adopted. Dynamic keys are generated by considering terminal hardware identity, environmental noise, and clock drift. Combined with real-time bandwidth integration and packet loss compensation algorithms, an exponentially weighted risk scoring model is constructed to enable the terminal to automatically switch between different modes, ensuring the security of high-risk services and the stability of low-risk services.

Benefits of technology

It improves the security, reliability, and operational continuity of medical terminals, enabling them to quickly freeze sensitive operations when the network deteriorates and restore them immediately after troubleshooting, significantly improving hospital operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658383B_ABST
    Figure CN120658383B_ABST
Patent Text Reader

Abstract

The application discloses a dynamic key driven medical terminal security adaptive remote control method and relates to the technical field of remote control. The method comprises the following steps: generating a dynamic session key for this communication; further calculating a security entropy for representing the security strength of this communication; calculating the length of a remote control instruction according to the medical service demand and the security entropy, calculating the expected comprehensive delay time of the remote control instruction reaching the medical terminal and starting to execute, executing a specified medical task according to the received remote control instruction, and controlling the medical terminal to enter different working modes according to the security risk score. The application can quickly freeze sensitive operations when the power supply is abnormal or the network is deteriorated without manual attendance, and can be restored immediately after the fault is eliminated, thereby significantly improving the security reliability, operation continuity and hospital operation efficiency of the self-service terminal.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of remote control, in particular to a dynamic key driven medical terminal security adaptive remote control method. BACKGROUND

[0002] Under the background of the rapid development of medical informatization, medical terminals, as an important part of the hospital intelligent service system, have been widely deployed in outpatient halls, pharmacy windows, inpatient departments, and other scenarios to provide services such as patient self-service registration, payment, printing of bills, report collection, drug dispensing, and electronic health card activation. The main advantages are to relieve the pressure on manual windows, shorten patient waiting time, and improve service efficiency. However, with the continuous expansion of terminal functions, the demand for remote management and remote control capabilities has also increased. In particular, after deploying a large number of self-service terminals in large hospitals, how to dynamically issue instructions, control device status, execute prescription tasks, and manage network security through remote methods has become an important technical issue in the medical operation and maintenance system.

[0003] In the prior art, the control and management of medical terminals mainly rely on timed scripts, batch commands, or remote desktop protocols (such as VNC, RDP) for manual intervention. Some terminals support integration with HIS, EMR, and other hospital core systems to accept business data through standard interfaces and perform automatic printing, code scanning, or dispensing actions. However, this type of remote control method generally has several key problems in design: first, existing solutions rely on fixed keys or timestamp-based authentication methods for communication link security and robustness, lack of introduction of non-clonable parameters such as terminal physical noise, hardware state, and temperature drift, resulting in insufficient randomness of session keys and vulnerability to bypass or man-in-the-middle attacks; second, control instructions are mostly statically encapsulated and cannot be dynamically packaged and optimized for transmission based on real-time network conditions (such as jitter, packet loss, bandwidth, etc.), which can cause instruction retention or loss during link fluctuations, affecting the stability of business execution; third, existing systems generally use fixed thresholds or static state switching control modes, and lack quantitative models for evaluating terminal running states, which cannot accurately reflect the risk level of devices under power criticality, hardware degradation, or network degradation; fourth, the task classification strategy is rough, usually only based on whether it is connected to the network or whether it is printing to open or limit functions, and cannot perform fine-grained business classification and control according to medical business risk levels, data irreversibility, and compliance requirements, resulting in potential gaps in security policy. SUMMARY

[0004] To solve the above technical problems, a full-dynamic key driven medical terminal security adaptive remote control method is provided, which proposes to generate a dynamic key together with terminal hardware identity, environmental noise and clock drift, to accurately estimate the instruction delay by combining real-time bandwidth integration and packet loss compensation algorithm, and to integrate network jitter, power consumption margin and hardware anomaly into an exponential weighted risk score through adaptive weight, so that the terminal can automatically switch between full function, degradation and offline security modes; while ensuring the safety of high-risk businesses such as prescription dispensing and medical insurance transactions, basic functions such as registration query and report reprint are continuously opened. This method can quickly freeze sensitive operations when power supply is abnormal or network is deteriorated without manual supervision, and can be restored immediately after the fault is eliminated, which significantly improves the security and reliability, operation continuity and hospital operation efficiency of the self-service terminal.

[0005] To achieve the above purposes, the technical scheme adopted by the present application is:

[0006] The dynamic key driven medical terminal security adaptive remote control method comprises:

[0007] Step 1: The medical terminal obtains the unique identification code preset in the terminal itself hardware, receives the control center identification code from the remote control center and the random prime number dynamically generated by the remote control center, and generates a dynamic session key for this communication; then the medical terminal further calculates the security entropy based on the dynamic session key, which is used to represent the security strength of this communication;

[0008] Step 2: Calculate the length of the remote control instruction according to the medical business demand and the security entropy, wherein the basic instruction length is the length of the fixed template of the medical business, and the complete instruction length is obtained by combining the security entropy, the theoretical delay of instruction transmission is calculated in the form of integral, and the expected comprehensive delay time of the remote control instruction to reach the medical terminal and start execution is calculated by considering the packet loss rate of the current network link, the time delay caused by network packet loss retransmission, the link network jitter caused by network path hop count and the clock synchronization error between the medical terminal and the network time source;

[0009] Step 3: The medical terminal executes the specified medical task according to the received remote control instruction;

[0010] Step 4: The medical terminal collects its real-time power consumption and compares it with the rated power consumption. Simultaneously, it counts the number of internal hardware anomalies and compares them with the anomaly tolerance threshold to construct an immediate risk indicator. At the same time, the medical terminal collects the current network jitter standard deviation and the network round-trip latency between the terminal and the remote control center in real time, and compares them with their respective thresholds. Combined with the packet loss rate, an adaptive adjustment factor based on the current network state is constructed. This adaptive adjustment factor is then used to fuse the immediate risk indicator and historical risk indicator using an exponentially weighted moving average algorithm to obtain a security risk score. Based on the security risk score, the medical terminal controls itself to enter different operating modes.

[0011] Furthermore, in step 3, when the security risk score exceeds the first preset security threshold, the medical terminal automatically enters offline security mode and only performs basic services; when the security risk score is between the first and second preset security thresholds, the medical terminal automatically enters degraded operation mode and only performs basic and low-risk services; when the security risk score is below the second preset security threshold, the medical terminal enters full-function online mode and can perform basic, low-risk, and high-risk services.

[0012] Furthermore, the dynamic session key K sess for:

[0013]

[0014] Among them, ID T A unique identifier for the medical terminal; ID C λ is the control center identifier of the remote control center; P is a 2048-bit system-published prime number; τ is the dynamic random prime number generated by the remote control center. sync For NTP / IEEE1588 clock drift; τ max To allow for maximum clock drift; η clk η is the RTC temperature drift coefficient. clk =(T amb -25) / 1000;T amb The ambient temperature.

[0015] Furthermore, the security entropy E sess for:

[0016] E sess =-log2[(K sess modP) / P+10 -15 ].

[0017] Furthermore, the expected overall delay time t exec for:

[0018]

[0019] Where B(u) represents the link bandwidth corresponding to the u-th bit during the transmission of remote control commands; p loss R represents the packet loss rate. reTx This is the average delay caused by each retransmission; Θ hop The hop count scheduling weight ranges from 1 to 10, with units of ms / hop; σ jit δ represents the standard deviation of link network jitter. NTP D represents the clock synchronization error between the medical terminal and the network time source; D represents the length of the complete instruction.

[0020] Furthermore, the complete instruction length D is:

[0021] D = L0 + βE sess ;

[0022] Wherein, β is the security entropy expansion coefficient, which represents the additional length required for each bit of entropy due to the encryption header, random padding, and MAC authentication. It is determined by the encryption algorithm family and takes a value of 1.125 or 1.25. When the encryption algorithm family is AES-GCM, β takes a value of 1.125. When the encryption algorithm family is ChaCha20-Poly1305, β takes a value of 1.25. L0 is the length of the fixed template for medical business.

[0023] Furthermore, the basic services include at least: registration information inquiry and reprinting, local display of patient queue information, system usage guidance, health education, and user feedback input; the low-risk services include at least: reprinting basic payment vouchers, historical report inquiry and printing, and registration information confirmation or reprinting of receipts; the high-risk services include at least: prescription drug dispensing, prescription printing, medical insurance registration, payment settlement, inpatient deposit recharge and deposit receipt printing, medical service authorization, and electronic health card writing and activation.

[0024] Furthermore, the adaptive adjustment factor α t for:

[0025]

[0026] Where, σ max Jitter tolerance threshold; RTT max The threshold for network round-trip time (RTT) is the network round-trip time.

[0027] Furthermore, the safety risk score R safe (t+1) is:

[0028]

[0029] Among them, Π nom For real-time power supply; Πpow R is the rated power consumption; safe (t) represents historical risk indicators; E err E represents the number of times the abnormal event occurred. crit This is the anomaly tolerance threshold.

[0030] A remote control system for a medical terminal.

[0031] Compared with existing technologies, the beneficial effects of this invention are as follows: The remote control method and system for medical terminals proposed in this invention, starting with dynamic key negotiation, couples terminal hardware identity, physical noise, clock drift, and ambient temperature into the same security entropy framework, achieving device-level non-cloning authentication under unattended conditions. Based on this, by directly mapping security entropy to instruction length, encryption header, and message authentication segment, it ensures the confidentiality and integrity of high-risk services while avoiding retransmission storms caused by excessively large packets in network-constrained scenarios. Internally, the method constructs a fine-grained delay model coupling bandwidth integration, packet loss compensation, and jitter timing, which can provide accurate time limit budgets for time-sensitive operations such as prescription printing and drug dispensing when link status fluctuates. An adaptive adjustment factor, combining packet loss rate, jitter amplitude, and round-trip latency, drives an exponentially weighted update of the risk score, enabling the terminal to rapidly increase alertness when the network deteriorates and smoothly decrease it when the link is stable, avoiding frequent oscillations. The risk scoring system integrates power consumption margin and hardware anomaly density, compressing them into a unified range through hyperbolic tangent mapping. Combined with a tiered business list, this forms three working modes: offline security, degraded operation, and full-function online, achieving end-side autonomy. The overall architecture eliminates reliance on manual intervention. In the event of a power outage, printer paper jam, or a surge in network packet loss, the terminal can freeze high-risk operations for a period while retaining basic query capabilities. This protects patient medication safety and medical insurance transaction compliance while maintaining uninterrupted basic information services. Once the fault is resolved, the system automatically restores full functionality, reducing maintenance intervention. Compared to traditional solutions relying on a single heartbeat or fixed thresholds, this invention significantly improves security awareness accuracy, recovery speed, and resource utilization efficiency, providing a feasible, scalable, and regulatory-friendly overall solution for large-scale deployment of self-service terminals in hospitals. Attached Figure Description

[0032] Figure 1 This is a schematic diagram of the method flow for the dynamic key-driven secure adaptive remote control method for medical terminals proposed in this invention.

[0033] Figure 2 A schematic diagram illustrating the experimental results of dynamic session key generation time under different encryption algorithm families;

[0034] Figure 3 This is a schematic diagram illustrating the experimental results of the expected overall latency under different network conditions. Detailed Implementation

[0035] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.

[0036] Reference Figure 1 As shown, a dynamic key-driven secure adaptive remote control method for medical terminals includes:

[0037] Step 1: The medical terminal obtains the unique identifier code preset in its own hardware, and receives the control center identifier code and the random prime number dynamically generated by the remote control center from the remote control center to generate a dynamic session key for this communication; then the medical terminal uses the dynamic session key as a basis to further calculate the security entropy, which is used to characterize the security strength of this communication.

[0038] In the remote control method for medical terminals of the present invention, the first step is to retrieve a unique serial number hard-coded in the hardware using the trusted computing module inside the terminal. This serial number is written during the manufacturing stage and cannot be tampered with, and is used for subsequent identity binding with the cloud control node. When the terminal powers on or receives a remote wake-up signal, the control node sends its own node identifier and a prime number seed generated in real time through an encrypted channel. The terminal performs a hybrid mapping of the two identifiers in a local secure execution environment, making the correlation between the identifiers far from the linear space. Then, it performs an exponential irreversible transformation in combination with the prime number seed to obtain an initial key fragment that is only effective in this session. At the same time, the terminal's sensor network performs millisecond-level sampling of physical random sources such as multi-point micro-vibration, fan noise, and power ripple in the cabinet. These sampled values ​​are processed by a debiasing algorithm and then concatenated to the end of the initial key fragment to improve the unpredictability of the key. The terminal then calls a high-precision real-time clock to calculate the instantaneous drift between the high-precision real-time clock and the cloud time server, and converts the drift... The key generation process injects time-dependent entropy to ensure the uniqueness of the key in the temporal dimension. The entire calculation process is completed within a secure execution area. After key generation, intermediate data is immediately erased, and a hash digest of the key derivation information is recorded in a secure register for subsequent security entropy auditing. After key generation, the terminal derives a multi-level symmetric encryption subkey, a message authentication subkey, and a handshake digest key based on the key, which are used for subsequent instruction confidentiality, integrity, and identity verification, respectively. Then, the terminal outputs a metric based on the key's randomness quality assessment model to dynamically adjust the encryption algorithm parameters used in the communication layer, such as deciding whether to enable longer random padding or higher-bit integrity checks, to balance performance and security in complex medical scenarios. Finally, the terminal sends a handshake confirmation message back to the control node along with a timestamp and a device health status digest. After comparison in the cloud, the session is activated, and the dynamic secure channel between the terminal and the control node is established.

[0039] Step 2: Calculate the length of the remote control command based on medical business needs and security entropy. The basic command length is the length of the fixed template for medical business. Combined with security entropy, the complete command length is obtained. The theoretical delay of command transmission is calculated by integration. At the same time, the packet loss rate of the current network link, the delay caused by network packet loss retransmission, the link network jitter caused by the number of network path hops, and the clock synchronization error between the medical terminal and the network time source are considered to calculate the expected comprehensive delay time for the remote control command to reach the medical terminal and start execution.

[0040] After key and security entropy initialization, the remote control center generates an instruction template based on the user's current business request type in the hospital information system. This template contains only the minimum fields of operational semantics, such as printing a prescription, reprinting an invoice, activating a medicine cabinet compartment, or performing medical insurance deduction. Upon receiving the instruction template, the medical terminal will assess the confidentiality level requirements of this communication in real time based on the security entropy obtained in the previous step. It will then insert a randomly padded, integrity check tail, and anti-replay sequence of the corresponding length into the reserved area of ​​the template and simultaneously embed the status description of the local submodule, such as printer consumables balance, barcode scanner mode, remaining dosage of medicine box, and encryption chip firmware. Version and other information are recorded so that the control center can grasp the terminal's operational details before executing instructions. The terminal then initiates a bandwidth detection program to perform multiple rapid speed tests on the uplink, obtaining an instantaneous available bandwidth curve. This curve is sent to the instruction encapsulator to estimate the transmission window. Inside the encapsulator, the template length, encryption header length, and the measured bandwidth curve are combined into a dynamic segmented scheduling table. The scheduling table assigns a target transmission time to each data packet segment to avoid instantaneous congestion that could delay medical instructions, while ensuring that the overall instruction is transmitted within the specified service time limit. During the scheduling phase, the terminal monitors hundreds of devices in parallel through the kernel network stack. Packet loss rate and round-trip delay jitter: When the packet loss rate increases or jitter fluctuations exceed the threshold, the scheduler immediately reduces the data segment size and starts the compensation retransmission counter. Simultaneously, network degradation information is appended to subsequent data segments, allowing the control center to dynamically adjust retransmission strategies and priorities. Meanwhile, the terminal clock synchronization daemon continuously compares the local clock with the time server, performs a sliding average of the old and new time offsets, and writes the latest time drift value back to the scheduling table, ensuring the encrypted timestamp field remains strictly monotonically increasing to prevent the encryption layer from rejecting data due to timing errors. Once all data segments have been encrypted and signed according to the scheduling table, the terminal begins formal transmission. At the end of each transmission cycle, it reads the actual outbound byte count returned by the driver layer and compares it with the expected transmission volume. Then, it combines the retransmission count to fine-tune the rate and window for the next cycle. This cycle continues until all instruction data is safely delivered. This ensures that bandwidth is fully utilized to shorten queuing latency when network conditions are good, and that network fluctuations are quickly reduced to avoid continuous retransmission storms. This ensures that medical business instructions can reach the terminal in real time and securely, without causing prescription execution delays, medical insurance settlement failures, or incorrect invoice generation due to network congestion or link jitter. This maximizes the continuity, reliability, and compliance of the hospital's self-service chain. If the expected comprehensive delay time is less than the hospital's business timeout threshold for scenarios such as prescription printing or medical insurance payment, it means that the medical terminal can respond to the instruction in a timely manner, and the instruction can continue to be executed. If the delay exceeds the threshold, it means that link congestion, jitter, or packet loss has too great an impact, and the medical terminal may encounter blockage or failure during the operation execution phase. This will trigger automatic switching logic for security monitoring or service degradation during the execution of the actual task in step 3.

[0041] Step 3: The medical terminal executes the specified medical task according to the received remote control command;

[0042] After verifying the authenticity, decrypting the confidentiality, and confirming the timestamp validity of the remote control command, the medical terminal immediately enters the execution scheduling phase. The core control engine first parses the operation based on the business identifier within the command, classifying it as high-risk, low-risk, or a basic task. Then, it calls the terminal's internal microkernel message bus to break the command down into a series of hardware-driven atomic actions. These atomic actions are asynchronously queued into a real-time priority queue and mapped to corresponding functional modules. For example, when the business is dispensing prescription drugs, the control engine needs to sequentially drive the prescription database query submodule, the drug compartment positioning submodule, the motor control submodule, and the weight verification submodule to ensure that the medicine box fully conforms to the doctor's order in terms of physical trajectory and dosage. When the business is dispensing prescription drugs... When printing a prescription, the command first triggers a comparison of the prescription review results in the cloud. Once approved, the pre-formatted prescription template is sent to the thermal printer. Simultaneously, after printing, a photoelectric sensor verifies the paper length and QR code integrity to confirm output quality. For medical insurance registration or payment settlement, the terminal uses an encrypted security chip to establish a controlled session with the local medical insurance platform. The payment result is then written to local secure storage and sent back to the center, ensuring a closed loop for fund flow and medical insurance reimbursement. For inpatient deposit top-ups and deposit receipt printing, the terminal deducts funds from a virtual account (in the tens of thousands) via an encrypted channel, then drives a high-resolution laser printer to output a government invoice. A barcode scanner reads the invoice code for self-verification. For medical treatment items… During authorization, after receiving the doctor's employee ID and authorization code, the terminal calls the hospital's imaging or laboratory scheduling system to assign examination numbers and displays them on the screen in real time. When the service involves writing and activating an electronic health card, the RF module conducts short-range communication with the second-generation ID card or social security card to write the binding information into the electronic health card and return the activation status. When performing low-risk services such as querying and printing historical reports, reprinting basic payment vouchers, and reprinting registration information, the terminal mainly reads the local cache or read-only database, and no accounting entries are written after printing. When providing basic services such as displaying patient queue information, providing system usage guidance, health education, or inputting user feedback, the terminal only needs to call the UI rendering engine and local media player, along with the core data. The library can remain in read mode. Regardless of the task level, the control engine will collect feedback data from multiple sensors such as temperature, optics, weight, and current in real time throughout the execution process and continuously write it to the circular buffer. The quality monitoring thread will calculate the execution deviation and feedback delay in a sliding window manner. If an anomaly is detected, an alarm will be immediately synchronized to the remote control center and the local log system. After all hardware operations are completed, the terminal will generate an execution result package containing the task type, start and end times, key indicators, user interaction logs, and encrypted verification digest. This package will be sent back to the control center through the previously established secure channel. At the same time, only the irreversible hash digest will be retained locally to meet the requirements of medical compliance regulations for the principle of minimizing data storage.This closed-loop design ensures that high-risk tasks such as prescription drug dispensing, prescription printing, medical insurance transactions, deposit receipts, high-value consumable authorization, and electronic health card activation receive multiple layers of pharmaceutical, safety, and financial protection even in an unattended environment. It also ensures that low-risk or basic tasks such as reprinting historical reports, queuing inquiries, and health education can still be provided normally when the system network is unstable or degraded. This achieves highly reliable, traceable, and compliant operation of remote control of medical terminals throughout the entire process.

[0043] Step 4: The medical terminal collects its real-time power consumption and compares it with the rated power consumption. Simultaneously, it counts the number of internal hardware anomalies and compares them with the anomaly tolerance threshold to construct an immediate risk indicator. At the same time, the medical terminal collects the current network jitter standard deviation and the network round-trip latency between the terminal and the remote control center in real time, and compares them with their respective thresholds. Combined with the packet loss rate, an adaptive adjustment factor based on the current network state is constructed. This adaptive adjustment factor is then used to fuse the immediate risk indicator and historical risk indicator using an exponentially weighted moving average algorithm to obtain a security risk score. Based on the security risk score, the medical terminal controls itself to enter different operating modes.

[0044] While the terminal performs medical tasks, the system daemon thread schedules the safety monitoring process at a fixed interval of once per second. First, it reads the ratio of the UPS output power to the rated power consumption after temperature correction within the cabinet from the power measurement module, and writes this value to the instantaneous power consumption buffer through the hardware abstraction layer. In parallel, the anomaly collection thread counts the number of hardware fault log entries in the past minute, such as printer paper shortage, medicine cabinet blockage, card reader overheating, and motor overcurrent, and records this information synchronously in the anomaly count buffer. The network probing thread performs four high-precision round-trip delay measurements on the keep-alive channel maintained by the control center, analyzes the latest round-trip delay and latency jitter, and reads the packet loss rate from the kernel protocol stack sliding window. These data are then processed in a unified manner. The structure is written to the network state buffer; subsequently, the risk control core scheduler extracts the latest observations from the three buffers and performs natural logarithmic compression on five indicators: power consumption ratio, anomaly count, latency, jitter, and packet loss, bringing the amplitude differences to the same order of magnitude. Then, it calculates the Euclidean distance to obtain the instantaneous risk amplitude. Within the same period, the scheduler generates adaptive weights based on the three network state observations. Higher weights indicate poorer network quality, and the system should detect risk changes more quickly. Then, it performs an exponentially weighted moving average of the instantaneous risk amplitude and the historical risk value persisted from the previous period, according to the adaptive weights, to obtain a new comprehensive risk score. This score is compressed to between zero and one using a hyperbolic tangent mapping. The security risk score is written to shared memory and triggers a mode determination routine. If the score is higher than the high threshold, the terminal immediately sends a broadcast signal to stop the operation of the drug dispensing motor and the invoice printer motor, closes the encrypted session related to medical insurance settlement, and switches to read-only database mode. The screen simultaneously displays an "Offline Security Mode" prompt, and the user can still query registration information or reprint historical reports. If the score is in the middle range, the terminal stops prescription printing and dispensing tasks, but retains low-risk operations such as reprinting payment vouchers and printing reports. At the same time, it continuously pushes a status summary to the control center in the background every ten seconds. If the score is lower than the low threshold, all terminal functions are unlocked and the status light is updated to green to indicate operation. Regardless of the mode entered, the risk control core... The system writes the current score, various observation values, and mode switching results into a local circular log, and incrementally synchronizes them to the cloud operation and maintenance platform through an established encrypted channel. The operation and maintenance platform executes policy distribution or manual intervention based on the information aggregated from multiple terminals. This cycle repeats, with each cycle's calculation and mode switching completed in milliseconds. This ensures that when power consumption surges, hardware failures increase, or network quality deteriorates sharply, the terminal can automatically enter safe mode within one cycle. This avoids medical risks and economic disputes caused by medication mis-dispensing, prescription printing failures, or interruptions in medical insurance transactions. At the same time, it can quickly restore full functionality after the risks are resolved, ensuring that the hospital's self-service maintains a dynamic balance between security, compliance, and availability.

[0045] Furthermore, in step 3, when the security risk score exceeds the first preset security threshold, the medical terminal automatically enters offline security mode and only performs basic services; when the security risk score is between the first and second preset security thresholds, the medical terminal automatically enters degraded operation mode and only performs basic and low-risk services; when the security risk score is below the second preset security threshold, the medical terminal enters full-function online mode and can perform basic, low-risk, and high-risk services.

[0046] refer to Figure 2 Furthermore, the dynamic session key K sess for:

[0047]

[0048] Among them, ID T A unique identifier for the medical terminal; ID C λ is the control center identifier of the remote control center; P is a 2048-bit system-published prime number; τ is the dynamic random prime number generated by the remote control center. sync For NTP / IEEE1588 clock drift; τ max To allow for maximum clock drift; η clk η is the RTC temperature drift coefficient. clk =(T amb -25) / 1000;T amb The ambient temperature.

[0049] First multiplier Selected a hardware serial number ID that cannot be changed on the terminal side. T Unique Identifier ID of Cloud Control Node C A bitwise XOR operation is performed, which breaks down the linear correlation between the two identifiers in constant time, preventing direct inference during RF detection or bypass analysis. Subsequently, a prime number λ randomly generated by the remote control center is used for modular exponentiation. Modular exponentiation not only amplifies the dispersion of the identifier space, but its exponential operation path also varies with λ, causing the key distribution of the same terminal in different sessions to spread exponentially, further increasing the difficulty of exhaustive search. The modulus P is a 2048-bit secure prime, conforming to the TLS-level security strength commonly used in current hospital information systems, compatible with dedicated acceleration instruction sets, and easy to interface with existing CA systems. The second multiplier in the formula... A time consistency constraint is introduced: τ sync τ, measured by NTP or IEEE 1588, is the drift value between the control node and the terminal's local clock; maxThis is the maximum allowable drift set by the hospital's operations and maintenance side based on the real-time requirements of the application. The closer the drift value is to the threshold, the closer the output of the exponential function is to zero, causing the overall amplitude of the key to decrease sharply and eventually be judged as invalid. This design can automatically block the session in scenarios of hardware clock aging or malicious delay injection, thereby preventing the instructions used for prescription verification or medical insurance payment from being maliciously replayed.

[0050] The third multiplier (1+η) clk This reflects the non-replicable temperature dependence of the equipment at the physical level; η clk =(T amb -25) / 1000 represents the real-time ambient temperature T inside the terminal cabinet. amb Transformed into a tiny linear increment, a temperature deviation of 25°C from the manufacturing calibration point will cause a frequency drift of approximately 10-40ppm to the RTC crystal oscillator. This drift is manifested in the key space as a unique noise fingerprint of the device through a product, making it difficult for attackers to reproduce the same key under different thermal environments, even if they copy the terminal firmware and hardware serial number. Simultaneously, the introduction of the temperature term meets the long-term security requirements under dynamic conditions such as day-night temperature differences, air conditioning operation, and cabinet heat dissipation in medical scenarios. By multiplying the three results, this invention establishes an inseparable correlation between logical identity, time series, and physical environment: any single-dimensional anomaly will compress the key amplitude to the system-recognized failure range, ensuring that only terminals with authentic hardware, accurate timing, and cabinet temperature within a reasonable range can establish an encrypted session with the control center. Furthermore, the terminal generates K... sess Immediately afterwards, three independent keys—a data encryption subkey, an integrity verification subkey, and a handshake signature key—are derived using a hardware random number diffusion algorithm. In a trusted execution environment, intermediate variables and original sampled values ​​are zeroed out to ensure that even if the terminal is subsequently attacked by a power outage, historical session information cannot be recovered. The control center performs secondary verification on the handshake digest returned by the terminal. Only when the key derivation path is completely consistent with the recorded temperature, clock drift, and hardware serial number is it written into the session table. At this point, the data channel used for high-risk remote operations such as prescription printing, medicine cabinet control, and medical insurance deduction can be activated. This design not only meets the compliant encryption requirements of medical data but also utilizes the physical noise of the hospital environment to enhance the randomness and uncopyability of the session keys, laying a solid cryptographic and hardware dual-trust foundation for the remote control process of this invention.

[0051] Figure 2This chart compares the dynamic session key generation time across different encryption algorithm families. The bar chart illustrates the time performance of three different encryption algorithms in the dynamic session key generation process. The horizontal axis represents different encryption algorithm families, and the vertical axis represents the key generation time in milliseconds. Specifically, when using the AES encryption algorithm with a security entropy expansion coefficient of 1.125, the dynamic session key generation time is 12.5 milliseconds; when using the ChaCha20 encryption algorithm with a security entropy expansion coefficient of 1.25, the dynamic session key generation time is 15.8 milliseconds; while using the traditional RSA algorithm, the dynamic session key generation time reaches 28.3 milliseconds. Figure 2 It is clear that the dynamic key generation method used in this invention has significant performance advantages across different encryption algorithm families. Among them, the AES encryption algorithm performs best with the shortest generation time; the ChaCha20 encryption algorithm is second best; while the traditional RSA algorithm has the longest generation time, approximately 2.26 times that of the AES algorithm.

[0052] Furthermore, the security entropy E sess for:

[0053] E sess =-log2[(K sess modP) / P+10 -15 ].

[0054] The expression first passes through (K) sess The modulo P) / P map the key value to the (0,1) interval, achieving a normalized comparison with the modulus P, thus measuring keys of different lengths or from different sources on a uniform scale; subsequently, a very small constant 10 is added to the normalized result. -15 Used as a numerical stabilizer, it avoids the logarithm becoming zero in extreme cases where the key is exactly divisible by the modulus, while ensuring the compensation term is small enough not to significantly dilute the entropy carried by the key itself. Taking the negative logarithm to base 2 directly maps the sparsity of the probability domain to the number of bits, expressing the average size of the key space an attacker needs to try; the higher the entropy value, the stronger the unpredictability brought about by terminal physical noise, clock drift, and identity mixing, and the computational complexity required for cryptanalysis increases exponentially. The terminal will obtain the E value in real time. sessAs a security level signal, the entropy value is written into the communication stack and task scheduler. If the entropy value is lower than the threshold set by the hospital, the scheduler will automatically increase the random padding length, increase the integrity check bits, and shorten the instruction validity period to compensate for the potential risks caused by insufficient key entropy. If the entropy value is in a high range, the system allows the use of higher throughput encryption algorithm parameters to ensure timely response to latency-sensitive services such as medical insurance transactions and prescription printing. Throughout the session, the entropy value is periodically recalculated to detect the impact of temperature jumps, network latency fluctuations, or hardware aging on randomness. Once a rapid drop in entropy value is detected, the terminal will trigger a key rolling process and request a new random prime number seed from the control center to prevent statistical deviations caused by prolonged use of the same key from being captured by attackers.

[0055] Further reference Figure 3 Expected overall delay time t exec for:

[0056]

[0057] Where B(u) represents the link bandwidth corresponding to the u-th bit during the transmission of remote control commands; p loss R represents the packet loss rate. reTx This is the average delay caused by each retransmission; Θ hop The hop count scheduling weight ranges from 1 to 10, with units of ms / hop; σ jit δ represents the standard deviation of link network jitter. NTP D represents the clock synchronization error between the medical terminal and the network time source; D represents the length of the complete instruction.

[0058] The first integral term describes the cumulative time consumed in bit-by-bit transmission under variable link bandwidth scenarios: the instruction, after secure encapsulation, has a length of D, and the function B(u) dynamically measured by the system represents the instantaneous available bandwidth at the u-th bit. The bandwidth varies with the load fluctuations of the WLAN or 5G network within the facility, and the integral maps continuous fluctuations to a precise time budget; the second term... Revealing the exponential additive effect of packet loss on latency: Packet loss rate p obtained from sliding window statistics loss Once increased, it will cause the average retransmission cost R to... reTx The data is amplified, and the terminal scheduler proactively reduces the data segment size and triggers congestion avoidance earlier, thereby ensuring that prescription instructions are not caught in a retransmission storm; the third item Simultaneously considering the cumulative impact of queuing delays and timing errors caused by cross-network segment forwarding: the route from the hospital to the cloud often traverses several levels of routers or SD-WAN nodes, with an average queuing time per hop of Θ... hop Quantization; while high-speed networks exhibit jitter standard deviation σ when micro-bursts occur. jit It will increase rapidly if there is a drift δ between the terminal's local clock and the time source. NTPJitter and timing error work together through a square root approach to avoid ignoring potential latency when either is excessively large or cancels each other out. The entire formula is a linear superposition of three parts, each of which can be obtained from real-time terminal measurements or protocol stack statistics, without relying on external empirical coefficients. Therefore, it can provide an approximate upper bound latency prediction value before instruction encapsulation. Based on this, the control center allocates queue priorities for services with different risk levels: for example, if the predicted value of a prescription drug dispensing instruction is close to the response threshold of the medical insurance system, the center will force the terminal to adopt a configuration with shorter segments, higher severity thresholds, and higher encryption efficiency; if the predicted value is low and the network is stable, the terminal is allowed to batch process patient payments or result printing in the same session, improving throughput. This latency model is also embedded in the security risk assessment link: when real-time observation of p loss σ jit or δ NTP The abnormal surge caused the calculated t exec If the service SLA is continuously exceeded, the system will simultaneously increase the security risk score, thereby triggering step four's mode downgrade or offline protection to prevent the forced push of high-risk commands when the network is unstable. Through this refined latency model, this invention ensures the bottom line of service real-time performance while enabling bandwidth adaptation, retransmission compensation, and timing calibration to work in tandem, achieving predictability, schedulability, and auditability of the medical terminal remote control link in complex wireless and wired hybrid network environments.

[0059] Figure 3 This is a line graph analyzing the expected overall latency under different network conditions. It illustrates the impact of packet loss rate on expected overall latency under various network environments. The horizontal axis represents the packet loss rate, ranging from 0 to 1.2; the vertical axis represents the expected overall latency in milliseconds, ranging from 0 to 200 milliseconds. The graph contains three characteristic curves: the first solid line represents latency changes under normal network conditions, where network jitter is low and latency growth is relatively gradual; the second long dashed line represents latency changes under high packet loss rate network conditions, where frequent retransmissions cause significantly faster latency growth; the third short dashed line represents latency changes under high jitter network conditions, where network instability leads to larger and faster latency fluctuations. Figure 3The analysis results show that as the packet loss rate increases, the expected overall latency under all three network conditions exhibits an upward trend, but the magnitude of the increase differs significantly. Under normal network conditions, when the packet loss rate increases from 0 to 1.2, the latency increases from approximately 45 milliseconds to approximately 80 milliseconds; while under high packet loss rate and high jitter network conditions, the latency increases from approximately 50 milliseconds to approximately 180 milliseconds and approximately 170 milliseconds, respectively, within the same range of packet loss rate variation. This result indicates that the expected overall latency calculation method of this invention can accurately reflect the impact of different network states on system performance, providing a reliable theoretical basis for adaptive control of medical terminals.

[0060] Furthermore, the complete instruction length D is:

[0061] D = L0 + βE sess ;

[0062] Wherein, β is the security entropy expansion coefficient, which represents the additional length required for each bit of entropy due to the encryption header, random padding, and MAC authentication. It is determined by the encryption algorithm family and takes a value of 1.125 or 1.25. When the encryption algorithm family is AES-GCM, β takes a value of 1.125. When the encryption algorithm family is ChaCha20-Poly1305, β takes a value of 1.25. L0 is the length of the fixed template for medical business.

[0063] L0 corresponds to the minimum template of business semantics. For example, a prescription printing task includes fixed fields such as patient identifier, prescription number, and pharmacist signature, while a medicine cabinet control task includes fixed fields such as compartment number, dosage value, and check digit. These fields are strictly defined by the hospital information system, and their length does not change with security level or network status. Therefore, L0 can be determined at compile time and stored in the terminal instruction description table. The second term βE in the formula... sess Used to describe the stretching effect of key security entropy on the cryptographic bearer space: when the session entropy E sess At higher entropy levels, random padding, initialization vectors, message authentication codes, and additional data all require longer bit widths to avoid statistical bias or truncation analysis. Therefore, the system introduces a linear expansion coefficient β to map the entropy value to the increment of the actual message length. The expansion coefficient depends on the internal block structure and integrity verification strategy of the selected encryption algorithm family. If the terminal and control center negotiate to use AES-GCM, then β is set to 1.125 because the GCM tag is fixed at 128 bits and the random padding requirement is relatively moderate. If ChaCha20-Poly1305 is negotiated, then β is increased to 1.25 because the stream cipher version requires a longer random counter and a larger 128-bit tag to resist replay attacks. When generating instructions, the terminal first queries the encryption parameter table to obtain the corresponding β, and then reads the latest security entropy value E. sessThe required additional length is calculated, then padding space is reserved in the buffer and filled with truly random bytes. Finally, a Poly1305 tag or GCM authentication field is written to the end of the message, resulting in a final instruction that meets cryptographic requirements and closely corresponds to the current entropy value. The control center uses the same β value to verify the random padding and tag length during unpacking. If the length does not match the session entropy, the message is immediately discarded and a security event is marked to prevent attackers from forging low-entropy data to bypass verification. By linearly combining the business template length with the entropy-driven security additional length, this invention achieves real-time coupling of business semantics and security levels. The control center can accurately calculate link occupancy and transmission window based on the full length D within the instruction queue scheduler. Terminals can also automatically compress messages to improve delivery speed or reduce retransmission risk when the network is limited by adjusting the entropy value or switching algorithm families to change β, thereby maintaining good throughput and real-time response while ensuring the correctness of prescription execution.

[0064] Furthermore, the basic services include at least: registration information inquiry and reprinting, local display of patient queue information, system usage guidance, health education, and user feedback input; the low-risk services include at least: reprinting basic payment vouchers, historical report inquiry and printing, and registration information confirmation or reprinting of receipts; the high-risk services include at least: prescription drug dispensing, prescription printing, medical insurance registration, payment settlement, inpatient deposit recharge and deposit receipt printing, medical service authorization, and electronic health card writing and activation.

[0065] In the remote control method for medical terminals proposed in this invention, to achieve secure adaptive management of terminal operation modes, all service tasks that can be issued by the remote control center or triggered by the user are divided into three levels: basic services, low-risk services, and high-risk services, based on their sensitivity to medical security, data consistency, transaction irreversibility, and compliance audit requirements. Basic services refer to service content that does not involve modification of core diagnostic and treatment data, does not generate changes to accounts or prescriptions, and has read operations or user feedback attributes. These include registration information inquiry and reprinting, local display of patient queue information, system usage guidance prompts, playback of health education content, and user satisfaction evaluation or feedback entry. These functions can still operate when the terminal is in a network degradation, service restriction, or offline security mode. The purpose is to ensure that patients can still obtain basic medical guidance and information services during peak hospital hours, network fluctuations, or equipment degradation. Low-risk services involve reprinting or confirming historical medical records or receipts without directly altering medical insurance reimbursement, drug dispensing, or fund settlement. These include reprinting basic payment vouchers, querying and printing historical examination and test reports, and confirming, reprinting, or repeating registration information. While these services involve retrieving and outputting data within the system, they do not trigger new accounting statuses or write to prescription data. Therefore, they can be offered in degraded operation mode on the terminal, provided the network is available but the system detects a risk score within the middle range. High-risk services involve irreversible core operations such as patient prescription execution, changes in fund flows, initiation of medical insurance transaction links, or changes to electronic health identities. These include prescription drug dispensing, printing prescription documents, medical insurance registration and settlement processes, inpatient deposit top-ups and printing of fiscal receipts, authorization activation for specific imaging or testing items, and writing patient identity binding information into electronic health cards and completing activation operations. Errors in this type of service can directly impact patient medication safety, the accuracy of medical insurance settlements, or the continuity of treatment processes. Therefore, it is only permitted to execute in a fully functional online mode when the terminal is in normal condition, the security score is below the threshold, and the communication link is stable. Through the above-mentioned hierarchical definition, the control center can dynamically select which type of service to enable based on the risk score when assessing the current risk status of the terminal. This maximizes terminal availability while ensuring compliance with treatment data and secure operation, supporting hospitals in maintaining patient service continuity and technically controlling the integrity of data assets in unattended and self-service scenarios.

[0066] Furthermore, the adaptive adjustment factor α t for:

[0067]

[0068] Where, σ max Jitter tolerance threshold; RTT max The threshold for network round-trip time (RTT) is the network round-trip time.

[0069] The numerator of the formula aggregates three link degradation metrics: actual packet loss rate p loss The ratio σ of the standard deviation of network jitter to its tolerance threshold jit / σ max And the ratio of the latest round-trip time to the allowed limit, RTT / RTT. max All three indicators are directly summed in a dimensionless form to avoid weight bias caused by differences in measurement units; the denominator is the same as the sum plus one, so that the overall value is strictly limited to between zero and one. The worse the network quality, the larger the numerator, and the higher the α value. t A tendency towards 1 means that the system almost entirely adopts the current observed risk and ignores historical values ​​in subsequent exponentially weighted moving average updates, enabling a rapid response to sudden jitter or packet loss; when the network is stable, the above ratio tends to decrease, α t With a value close to zero, historical risks are preserved, avoiding frequent mode switching triggered by occasional minor fluctuations. Specifically, the terminal extracts the number of lost data packets from the past 100 packets per second from the protocol stack sliding window to calculate p. loss The jitter standard deviation σ is calculated using the delay difference sequence defined in RFC3393. jit Threshold σ max The acceptable jitter limit for real-time services is determined by the hospital; RTT is obtained by averaging four timestamps measured on the continuous keep-alive channel. max This is determined by the hospital's network service level agreement. This design ensures that when a sudden surge in packet loss, latency spikes, or jitter occurs in the link, the adaptive factor increases rapidly, causing the risk score to almost immediately impact the hardware execution logic. The terminal can then promptly degrade to an operating mode that only executes low-risk or basic services, preventing high-risk commands such as prescription drug dispensing and medical insurance deductions from being mistakenly executed in an unreliable network. Conversely, when the network returns to normal and all indicators are far below the threshold, the adaptive factor decreases, the risk score update focus returns to historical levels, and the terminal will not frequently enter offline mode due to brief and harmless fluctuations, thus ensuring the continuity of the patient's medical process and the lifespan of the terminal hardware. Due to α... t The calculation relies on real-time observations and completely eliminates manual empirical weighting. The system can directly reuse this formula in different hospital network environments, requiring only adjustment of the threshold σ. max With RTT max It can be matched with local link characteristics without modifying the software logic, meeting the dual requirements of convenient deployment and robust security in medical scenarios.

[0070] Furthermore, the safety risk score R safe (t+1) is:

[0071]

[0072] Among them, Π nom For real-time power supply; Π pow R is the rated power consumption; safe (t) represents historical risk indicators; E err E represents the number of times the abnormal event occurred. crit This is the anomaly tolerance threshold.

[0073] Among them, the historical risk indicator R safe (t) Stores the accumulated environmental and hardware state memory from the previous cycle, with an adaptive adjustment factor α. t The calculation is based on real-time data from link packet loss, jitter, and round-trip time. When the network deteriorates, the value approaches one, allowing for rapid model updates; when the network stabilizes, the value approaches zero, reducing the contribution of new risks and preventing score jitter. The energy consumption section uses... The deviation between the UPS output power and rated power consumption is measured. If the real-time power is close to the load limit, the positive value increases after taking the logarithm, thus increasing the overall risk. When the power is sufficient, the numerator is smaller than the denominator, the logarithm is negative, and the squared value still contributes a positive value but the magnitude decreases, reflecting redundancy. Anomaly density item The ratio of hardware fault count to tolerance threshold over the past minute is mapped to a logarithmic increment. The more faults, the larger the ratio. The logarithmic growth shows diminishing marginal returns. The squared value is then combined with the power term to form the Euclidean norm, which avoids the dominance of a single indicator and ensures that both types of physical risks are manifested simultaneously. The entire result is then mapped to the (0,1) interval using tanh, resulting in a continuous, differentiable output that converges to extreme inputs, facilitating rapid threshold determination in software: when the score is greater than the high threshold, the terminal immediately enters an offline security mode that retains only basic services such as registration inquiry and queue display; when the score falls between the two thresholds, operations such as prescription printing are locked, and only low-risk services are enabled; when the score is lower than the low threshold, the terminal resumes full-function online operation, allowing high-risk commands such as drug dispensing and medical insurance settlement to be issued normally. The entire update process cycles once per second, with power consumption and fault values ​​directly sampled from onboard sensors. t The score is then refreshed asynchronously by a network thread, and the two processes are merged atomically within shared memory. This ensures that in scenarios involving sudden power drops or frequent hardware failures, the score can jump up and trigger protection within a single cycle. After brief network jitter or occasional minor faults, adaptive weights allow the score to smoothly decline, avoiding frequent system mode switching. Through this dynamic scoring mechanism, this invention enables terminals to achieve real-time assessment and automatic self-regulation of their own safety status in unattended public healthcare environments with minimal human intervention, effectively supporting multiple objectives such as prescription security, medical insurance compliance, and patient experience.

[0074] A remote control system for a medical terminal includes a medical terminal and a remote control center. The medical terminal acquires a unique identifier pre-set within its own hardware and receives a control center identifier and a dynamically generated random prime number from the remote control center to generate a dynamic session key for the current communication. Subsequently, the medical terminal uses the dynamic session key to further calculate a security entropy, which characterizes the security strength of the current communication. The length of the remote control command is calculated based on medical service requirements and the security entropy, where the basic command length is the length of a fixed template for the medical service, and the complete command length is obtained by combining the security entropy. The theoretical delay of command transmission is calculated using an integral method, taking into account the packet loss rate of the current network link, the delay caused by network packet loss and retransmission, the network jitter caused by the number of network hops, and the clock synchronization between the medical terminal and the network time source. Error is calculated to determine the expected overall delay time for remote control commands to reach the medical terminal and begin execution. The medical terminal executes the designated medical task according to the received remote control commands. The medical terminal collects its real-time power supply and compares it with the rated power consumption. At the same time, it counts the number of internal hardware abnormal events and compares them with the abnormality tolerance threshold to construct an immediate risk indicator. Simultaneously, the medical terminal collects the current network jitter standard deviation and the network round-trip delay between the terminal and the remote control center in real time, and compares them with their respective thresholds. Combined with the packet loss rate, an adaptive adjustment factor based on the current network state is constructed. This adaptive adjustment factor is used to fuse the immediate risk indicator and historical risk indicator using an exponentially weighted moving average algorithm to obtain a security risk score. Based on the security risk score, the medical terminal controls itself to enter different working modes.

[0075] At 9:00 AM sharp, after completing its power-on self-test, the medical terminal numbered T-01 in the outpatient hall initiated the remote handshake process. The trusted execution environment first read the hardware serial number burned into the TPM. T =0xABCD1234eF567890, the control center node returns its own identifier ID. C =0x1234567890ABCDEF and an instant-generated 16-bit random prime number λ = 65537. The system publicly discloses prime numbers as 2048 bits in the official deployment; this example reduces it to P = 2147483647 for ease of calculation. The terminal XORs the two flags to obtain 0xB9F95A5E7F1BD67F = 13367087013507369471, then calculates the exponentiation and modulo to obtain...

[0076]

[0077] Next, read the instantaneous drift τ recorded by the timing daemon. sync = 4.00ms, maximum allowable drift τ max=50.00ms. The rack temperature sensor displays the ambient temperature T. amb =28.4℃, therefore the temperature drift coefficient η clk =(28.4-25.0) / 1000=0.0034. Substitute the value into...

[0078]

[0079] To calculate the session entropy, we first need to calculate...

[0080]

[0081] Adding the stability constant, we get 0.827559836000001, then we calculate the binary negative logarithm.

[0082] E sess =-log2(0.827559836000001)≈0.278330bit.

[0083] The control center inserts a fixed operation template for this patient's prescription dispensing process, with a length L0 = 512 bits. Both parties agree to use AES-GCM, therefore the security expansion factor is set to β = 1.125. The complete instruction length is calculated as follows:

[0084] D = L0 + βE sess =512+1.125×0.278330=512.313616bit.

[0085] Then, link performance probing began. The terminal used three rounds of ICMP echo and BBR rate probing to determine that the available bandwidth remained approximately constant over time.

[0086] B(u) = 5.00 × 10 6 bit / s (0≤u≤D);

[0087] Therefore, the first integral

[0088]

[0089] Two out of 100 packets within the sliding window are lost; the packet loss rate is p. loss =0.02. The average retransmission time R measured by the network layer. reTx =50ms. Therefore, the packet loss compensation delay is...

[0090]

[0091] The link reaches the cloud-side SD-WAN via four hops, with a routing hop weight Θ. hop =5ms / hop = 0.005s / hop. The standard deviation of the delay jitter σ is calculated in real time. jit=3.042ms, the difference δ between the terminal clock and the time server NTP = 0.976ms. Taking the square root of the sum of the squares of the two values ​​gives... Therefore, the third item

[0092] 0.005 × 3.196 ms = 0.01598 ms;

[0093] The sum of the three items yields the expected overall delay.

[0094] t exec =0.102463+1.020408+0.015980≈1.138851ms.

[0095] This value is far below the hospital SLA's 100ms limit for the prescription dispensing link, so the scheduler immediately marks the instruction as a high-priority message.

[0096] Within the same period, network threads aggregate link degradation factors. This is based on the threshold σ specified in the campus IT planning document. max =5ms, RTT max =200ms. The current average round-trip time (RTT) is measured to be 30.6ms. Therefore...

[0097]

[0098] Power monitoring board uploads UPS output power Π pow =82.4W, nameplate power consumption Π nom =100.0W.

[0099] Instantaneous power risk item

[0100]

[0101] The hardware anomaly log has accumulated 4 entries in the last 60 seconds, exceeding the tolerance threshold E. crit =10. Abnormal Risk Items

[0102]

[0103] Euclid synthesis

[0104]

[0105] Previous period historical risk value record Substitute all data

[0106]

[0107] The hospital set an offline protection threshold of 0.70 and a degradation threshold of 0.40, so the terminal remained fully online, and the control center allowed the prescription drug dispensing process to proceed. The entire dispensing action was completed in 6.8 seconds. The quality monitoring thread wrote indicators such as weight deviation of 0.18g and QR code integrity of 100% into the traceability record, and pushed the signed execution result to the cloud.

[0108] At 11:23 AM, network congestion began, with terminal monitoring showing a packet loss rate jump to 0.17, jitter surging to 12.5ms, and RTT soaring to 176ms. Repeated calculations yielded...

[0109]

[0110] Within the same minute, the printer jammed twice, the barcode scanner overheated once, the anomaly count rose to 7, and the UPS output power increased to 94W due to the cooling fan running at full speed. The risk Euclidean term changed.

[0111]

[0112] Update rating

[0113]

[0114] If the score exceeds the 0.40 downgrade threshold but has not yet reached the 0.70 high threshold, the terminal immediately enters downgrade operation mode: prescription dispensing, new medical insurance deductions, and deposit receipt printing are all frozen, but users can still print examination reports and reprint payment invoices; a yellow warning bar appears at the top of the screen, informing users that network instability restricts services. In this mode, the instruction template length is limited to 256 bits, the retransmission window is reduced, and the system continuously monitors the network and hardware status.

[0115] Network recovery occurred at 12:02 PM. Packet loss dropped to 0.01ms, jitter decreased to 4.3ms, and RTT dropped to 42ms. Simultaneously, maintenance personnel cleared the printer paper jam and replaced the cooling filter. The anomaly count returned to 1. Recalculation

[0116]

[0117] The score dropped below 0.40 again, the system automatically unlocked the downgrade lock, and the electronic screen at the counter turned green to indicate that all functions were enabled. The full-process example, from key entropy generation to instruction encapsulation, latency budgeting, network weight calculation, risk scoring iteration, and operational mode changes, demonstrates the dynamic adaptive and automatic self-healing capabilities of this invention under real hospital network, power supply, and hardware anomalies. This fully verifies that the method can ensure patient medication safety, invoice compliance, and continuity of care without relying on manual intervention.

[0118] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.

Claims

1. A dynamic key-driven secure adaptive remote control method for medical terminals, characterized in that, The method includes: Step 1: The medical terminal obtains the unique identifier code preset in its own hardware, and receives the control center identifier code and the random prime number dynamically generated by the remote control center from the remote control center to generate a dynamic session key for this communication; then the medical terminal calculates the security entropy based on the dynamic session key, which is used to characterize the security strength of this communication. Step 2: Calculate the length of the remote control command based on medical business needs and security entropy. The basic command length is the length of the fixed template for medical business. Combined with security entropy, the complete command length is obtained. The theoretical delay of command transmission is calculated by integration. At the same time, the packet loss rate of the current network link, the delay caused by network packet loss retransmission, the link network jitter caused by the number of network path hops, and the clock synchronization error between the medical terminal and the network time source are considered to calculate the expected comprehensive delay time for the remote control command to reach the medical terminal and start execution. Step 3: The medical terminal executes the specified medical task according to the received remote control command; Step 4: The medical terminal collects its real-time power consumption and compares it with the rated power consumption. Simultaneously, it counts the number of internal hardware anomalies and compares them with the anomaly tolerance threshold to construct an immediate risk indicator. At the same time, the medical terminal collects the current network jitter standard deviation and the network round-trip latency between the terminal and the remote control center in real time, and compares them with their respective thresholds. Combined with the packet loss rate, an adaptive adjustment factor based on the current network state is constructed. This adaptive adjustment factor is then used to fuse the immediate risk indicator and historical risk indicator using an exponentially weighted moving average algorithm to obtain a security risk score. Based on the security risk score, the medical terminal controls itself to enter different operating modes.

2. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 1, characterized in that, In step 3, when the security risk score exceeds the first preset security threshold, the medical terminal automatically enters offline security mode and only performs basic services; when the security risk score is between the first and second preset security thresholds, the medical terminal automatically enters degraded operation mode and only performs basic and low-risk services; when the security risk score is below the second preset security threshold, the medical terminal enters full-function online mode and performs basic, low-risk, or high-risk services.

3. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 2, characterized in that, Dynamic Session Key K sess for: Among them, ID T A unique identifier for the medical terminal; ID C λ is the control center identifier of the remote control center; P is a 2048-bit system-published prime number; τ is the dynamic random prime number generated by the remote control center. sync For NTP / IEEE1588 clock drift; τ max To allow for maximum clock drift; η clk η is the RTC temperature drift coefficient. clk =(T amb -25) / 1000;T amb The ambient temperature.

4. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 3, characterized in that, Security entropy E sess for: E sess =-log2[(K sess modP) / P+10 -15 ]。 5. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 4, characterized in that, Expected overall delay time t exec for: Where B(u) represents the link bandwidth corresponding to the u-th bit during the transmission of remote control commands; p loss R represents the packet loss rate. reTx This is the average delay caused by each retransmission; Θ hop The hop count scheduling weight ranges from 1 to 10, with units of ms / hop; σ jit δ represents the standard deviation of link network jitter. NTP D represents the clock synchronization error between the medical terminal and the network time source; D represents the length of the complete instruction.

6. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 5, characterized in that, The full instruction length D is: D=L0+βE sess ; Wherein, β is the security entropy expansion coefficient, which represents the additional length required for each bit of entropy due to the encryption header, random padding, and MAC authentication. It is determined by the encryption algorithm family and takes a value of 1.125 or 1.

25. When the encryption algorithm family is AES-GCM, β takes a value of 1.

125. When the encryption algorithm family is ChaCha20-Poly1305, β takes a value of 1.

25. L0 is the length of the fixed template for medical business.

7. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 6, characterized in that, The basic services include at least: registration information inquiry and reprinting, local display of patient queue information, system usage guidance, health education, and user feedback input; the low-risk services include at least: reprinting basic payment vouchers, inquiry and printing of historical reports, and confirmation or reprinting of registration information slips; the high-risk services include at least: prescription drug dispensing, prescription printing, medical insurance registration, payment settlement, inpatient deposit recharge and deposit receipt printing, authorization of medical services, and writing and activation of electronic health cards.

8. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 7, characterized in that, Adaptive adjustment factor α t for: Where, σ max Jitter tolerance threshold; RTT max The threshold for network round-trip time (RTT) is the network round-trip time.

9. The dynamic key-driven secure adaptive remote control method for medical terminals as described in claim 8, characterized in that, Safety Risk Score R safe (t+1) is: Among them, Π nom For real-time power supply; Π pow R is the rated power consumption; safe (t) represents historical risk indicators; E err E represents the number of times the abnormal event occurred. crit This is the anomaly tolerance threshold.

10. A remote control system for a medical terminal, used to implement the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Verification method and device for Internet hospital registration

    CN116720173A

  • Trusted measurement and control network authentication method based on double cryptographic values and chaotic encryption

    US20210367753A1