Lightweight post-quantum authentication key exchange method and device for smart electronic medical system, medium and product
Patent Information
- Application Number
- CN202610998372.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-06
- Publication Date
- 2026-09-22
AI Technical Summary
[0005](1)安全缺陷突出:多数方案无法抵御信号泄露攻击、离线口令猜测攻击、密钥泄露冒充攻击,难以满足用户匿名性、不可追溯性与完美前向安全要求,部分方案存在服务器静态密钥易被恢复、临时身份更新失效等问题
[0054](1)具备后量子安全能力:基于格的环上带误差学习(RLWE)困难问题构造,可抵抗Shor量子算法攻击,从根源上解决传统医疗认证协议易被量子破解的问题,实现医疗数据长期安全。
Smart Images

Figure CN122802229A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of encrypted communication technology, and in particular to a lightweight post-quantum authentication key exchange method, device, medium and product for smart electronic medical systems. Background Technology
[0002] With the rapid development of smart healthcare and the Medical Internet of Things (HIoT), smartphones, wearable devices, and medical monitoring terminals are widely used to collect sensitive physiological data such as patients' heart rate, blood pressure, and blood oxygen levels. This data is then uploaded to medical servers via wireless communication networks to enable remote monitoring, assisted diagnosis, and personalized medical services. However, medical data is highly sensitive and privacy-sensitive. Open wireless channels are vulnerable to security threats such as eavesdropping, tampering, replay attacks, and man-in-the-middle attacks, which could lead to the leakage of patient privacy and the falsification of medical data, seriously threatening the security of medical services and patients' rights.
[0003] The Authentication Key Exchange (AKE) protocol is a core technology for ensuring secure communication between medical terminals and servers, enabling authentication and negotiation of session keys between the communicating parties. Currently, most electronic medical systems use AKE protocols based on traditional public-key cryptosystems such as RSA (based on large prime number factorization) and ECC (based on elliptic curves) and bilinear mapping. Their security relies on mathematically challenging problems such as integer factorization and discrete logarithms. However, with the development of quantum computing technology, Shor's quantum algorithm can solve these problems in polynomial time, rendering traditional cryptographic protocols completely ineffective. Furthermore, attackers can implement "store-and-decrypt" attacks, stealing and retaining encrypted medical data for extended periods, only to crack it once quantum computers mature, resulting in permanent data leakage. Therefore, designing an AKE protocol with quantum attack resistance for intelligent electronic medical systems has become an urgent need to ensure the long-term security of medical communications.
[0004] In recent years, post-quantum cryptography based on the learning-with-error-on-rings (RLWE) problem in lattice cryptography has been used to build quantum-resistant authentication protocols due to its advantages such as provable security, high computational efficiency, and suitability for resource-constrained devices. However, existing post-quantum authentication key exchange schemes for medical applications still have significant shortcomings:
[0005] (1) Prominent security flaws: Most solutions cannot resist signal leakage attacks, offline password guessing attacks, and key leakage impersonation attacks, making it difficult to meet the requirements of user anonymity, untraceability and perfect forward security. Some solutions have problems such as the server static key being easily recovered and temporary identity updates failing.
[0006] (2) High performance overhead: Although some existing lattice cryptography-based protocols can resist quantum, they are designed for non-mobile scenarios such as smart meters. Their complex parameter synchronization and asymmetric optimization mechanisms still have drawbacks such as high computational overhead, strong pseudonym correlation, and inability to achieve complete anonymity when facing ultra-low power medical wearable devices.
[0007] (3) Weak authentication mechanism: Single password or single-factor authentication is easily broken. There is a lack of a two-factor authentication mechanism that combines biometrics and password, which cannot effectively prevent unauthorized access and illegal use after the device is stolen. Although the existing technology has introduced two-factor authentication, its core still relies on traditional cryptographic puzzles, does not have post-quantum security, and is overly dependent on the trusted execution environment hardware on the server side. Once the hardware environment is limited or there are side-channel vulnerabilities, the security of biometric credentials will be difficult to guarantee. Summary of the Invention
[0008] To address the aforementioned technical issues, this application proposes a lightweight post-quantum authentication key exchange method, apparatus, medium, and product for intelligent electronic medical systems.
[0009] The technical solution adopted in this application is: a lightweight post-quantum authentication key exchange method for intelligent electronic medical systems, including the following steps:
[0010] S1: System setup phase, during which the medical server... Perform offline steps to generate its private key and global public system parameters;
[0011] S2: Registration phase, during which users... Send to the medical server via secure channel or offline mode During the registration phase, users... Need to send to your mobile device Enter your identity information Password and biological characteristics After that, the user and medical servers Registration is completed via encrypted communication;
[0012] S3: Login and Identity Authentication Phase. After completing the registration phase, the user... With medical server Perform mutual authentication and negotiate the same session key, including for users. To their own mobile device The input identity verification, password validity verification, and user... With medical server Mutual authentication.
[0013] Furthermore, step S1 specifically includes:
[0014] S1.1: Medical Server Choose large prime numbers and integers ,in , It is a set of positive integers;
[0015] S1.2: Medical Server Define a polynomial ring and in Choose a standard deviation as Discrete Gaussian distribution ,in Let represent the ring of integers modulo q, which is the set of residue classes {0,1,…,q−1} obtained by taking all integers modulo q. It is a polynomial. It is a variable used to represent the unknowns in a polynomial. Indicates the quotient ring;
[0016] S1.3: Medical Server Randomly select ring elements And sample secret polynomials sum of error polynomials ,in As a medical server The private key is then used to calculate the corresponding public key. ;
[0017] S1.4: Medical Server Define a hash function Finally, the medical server Publish global public system parameters and the private key Securely store in memory.
[0018] Furthermore, step S2 specifically includes:
[0019] S2.1: User To their own mobile device Enter your identity information Password and biological characteristics Then the user Generate a random number And using biological hash functions Computing biometric keys Then calculate
[0020] Then the user Random sampling secret polynomial sum of error polynomials ,in ,calculate ,in As a user private key, For this user The corresponding public key;
[0021] Finally, the user Will Send to medical server ;
[0022] S2.2: Medical Server Upon receiving from the user News Then, a registration timestamp is generated. and calculate and Then the medical server Will Stored in its own database, and Send to user ;
[0023] S2.3: User Upon receiving the message Then, calculate , and End user Will Securely store on your mobile device .
[0024] Furthermore, step S3 specifically includes:
[0025] S3.1: User To their own mobile device Enter your identity information Password and biological characteristics Then the user Using biological hash functions Computing biometric keys Then calculate:
[0026] ;
[0027] ;
[0028] ;
[0029] And judge Is it equal to If they are equal, it indicates that the user Input identity identifier Password It is valid; otherwise, the session terminates.
[0030] S3.2: User Random sampling after successful login and calculate , ,in For temporary random private key polynomials, It is a random error polynomial; then the signal function is applied. calculate Simultaneously using modular functions calculate Next, the user Calculate dynamic kana and generate the current timestamp. Then calculate:
[0031] ;
[0032] Authentication value ;
[0033] Finally, the user Authentication message Send to medical server ;
[0034] S3.3: Medical Server Upon receiving user News Then, through judgment Verify received timestamp The freshness, among which The current time when the message was received. Indicates the maximum transmission delay associated with the message; if If invalid, the session is terminated; if valid, the medical server... calculate Simultaneously, the modular function is used to calculate... Then calculate:
[0035] ;
[0036] ;
[0037] ;
[0038] Subsequently, the medical server verify Is it equal to If verification fails, the session is terminated; otherwise, the medical server... Perform asymmetric load transfer operations and randomly sample. and calculate and Then, the signal function is applied to calculate... Simultaneously using modular function calculation Next, the medical server Generate current timestamp Then calculate with the user mobile terminals Shared session key and authentication value :
[0039] ;
[0040] ;
[0041] Finally, the medical server Authentication message Send to user ;
[0042] S3.4: User At the current time Received from medical server News Then, first determine whether it satisfies To verify the received timestamp The novelty; if effective, then users calculate:
[0043] ;
[0044] ;
[0045] Session key ;
[0046] ;
[0047] Subsequently, the user verify Is it equal to If verification fails, the session is terminated; otherwise, the user... Successful authentication of the medical server ;
[0048] At this point, the user and medical servers Mutual authentication has been completed, and the same session key has been negotiated. .
[0049] Furthermore, it also includes a formal analysis phase, which proves the provable security of the method based on the Random Oracle model.
[0050] This application also proposes a computer device including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method.
[0051] This application also proposes a computer-readable storage medium having a computer program / instructions stored thereon, which, when executed by a processor, implements the steps of the method.
[0052] This application also proposes a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the method.
[0053] The advantages of this application over the prior art are as follows:
[0054] (1) Possesses post-quantum security capabilities: Based on the difficult problem of learning errors on rings (RLWE) in lattices, it can resist Shor's quantum algorithm attack, fundamentally solving the problem that traditional medical authentication protocols are easily cracked by quantum mechanics, and realizing long-term security of medical data.
[0055] (2) Lightweight computing: In response to the ultra-low power consumption requirements unique to smart healthcare, the asymmetric load transfer technology is used to concentrate time-consuming operations such as polynomial sampling on the server side, thereby further reducing the energy consumption of medical wearable devices compared to existing lattice cryptographic protocols.
[0056] (3) Two-factor authentication enhances login security: It integrates password, biometrics and biometric hash technology to achieve two-factor login authentication. It does not require storing original biometric data and effectively prevents attacks such as device theft, unauthorized access and offline password guessing. Its security is higher than that of single-factor protocols.
[0057] (4) Complete security attributes: Through formal proof, the solution can resist various attacks such as replay, man-in-the-middle, impersonation, signal leakage, and key leakage simulation, while meeting the core security requirements of medical scenarios such as user anonymity, untraceability, and perfect forward security.
[0058] (5) Comprehensive anti-attack capabilities: It has protective designs against internal attacks, equipment theft attacks and temporary key leakage attacks that are unique to medical scenarios. Even if the key is leaked in the long term, the historical session key is still safe, and the privacy and communication reliability are higher.
[0059] (6) Biometric security without special hardware: This solution achieves strong protection of biometric features at the software level through biometric hashing and noise injection at the algorithm level, reducing system deployment costs and hardware risks. Attached Figure Description
[0060] The following description, in conjunction with the accompanying drawings, further illustrates this application:
[0061] Figure 1 A flowchart illustrating the method provided in this application embodiment;
[0062] Figure 2 This is a schematic diagram illustrating the login and authentication phases provided in an embodiment of this application. Detailed Implementation
[0063] like Figure 1 and Figure 2 As shown, this application addresses the problems of current post-quantum authentication key exchange schemes used in smart electronic medical systems. It proposes a lightweight, provably secure post-quantum two-factor authentication key exchange scheme for smart electronic medical systems. This scheme employs biometric + password two-factor authentication, anti-signal leakage design, and a two-round interaction mechanism. Rigorous formal security proofs are achieved under the Random Oracle (ROR) model, and long-term quantum-resistant security is guaranteed based on the intractability of the RLWE problem. This scheme achieves strong privacy protection, perfect forward security, and full attack defense while reducing the computational and communication overhead of medical terminals, providing an efficient, secure, and practical communication security solution for smart medical IoT.
[0064] The symbols and their meanings used in the authentication key exchange scheme of this application are shown in Table 1 below.
[0065] Table 1: Symbol Meaning Table.
[0066]
[0067] The lightweight post-quantum authentication key exchange method for intelligent electronic medical systems proposed in this application mainly includes the following steps:
[0068] S1: System setup phase, during which the medical server... Perform the following offline steps to generate its private key and global public system parameters (including large prime numbers, integers, polynomial ring elements, public key, discrete Gaussian distribution on the polynomial ring, and hash function):
[0069] S1.1: Medical Server Choose large prime numbers and integers ,in , It is a set of positive integers;
[0070] S1.2: Medical Server Define a polynomial ring and in Choose a standard deviation as Discrete Gaussian distribution ,in Let represent the ring of integers modulo q, which is the set of residue classes {0,1,…,q−1} obtained by taking all integers modulo q. It is a polynomial. It is a variable used to represent the unknowns in a polynomial. Indicates the quotient ring, that is If two polynomials in the modulus If the elements below are equal, they are considered to be the same element;
[0071] S1.3: Medical Server Randomly select ring elements And sample secret polynomials ( As a medical server (private key) and error polynomial Then calculate the corresponding public key. ;
[0072] S1.4: Medical Server Define a hash function Finally, the medical server Publish global public system parameters and the private key Securely store in memory.
[0073] S2: Registration phase, during which users... Send to the medical server via secure channel or offline mode The registration process is as follows:
[0074] S2.1: User To their own mobile device Enter your identity information Password and biological characteristics Then the user Generate a random number And using biological hash functions Computing biometric keys Then calculate Then the user Random sampling secret polynomial sum of error polynomials ,in ,calculate ,in As a user private key, For this user The corresponding public key. Finally, the user... Will Send to medical server .
[0075] S2.2: Medical Server Upon receiving from the user News Then, a registration timestamp is generated. and calculate and Then the medical server Will Stored in its own database, and Send to user .
[0076] S2.3: User Upon receiving the message Then, calculate , and End user Will Securely store on your mobile device .
[0077] S3: Login and Identity Authentication Phase. After completing the registration phase, the user... With medical server Mutual authentication is performed, and the same session key is negotiated to achieve secure and reliable communication in a post-quantum environment. The detailed process is as follows:
[0078] S3.1: User To their own mobile device Enter your identity information Password and biological characteristics Then the user Using biological hash functions Computing biometric keys Then calculate:
[0079] ;
[0080] ;
[0081] ;
[0082] And judge Is it equal to If they are equal, it indicates that the user Input identity identifier Password It is valid; otherwise, the session terminates.
[0083] S3.2: User Random sampling after successful login and calculate , ,in For temporary random private key polynomials, It is a random error polynomial. Then the signal function is applied. calculate Simultaneously using modular functions calculate Next, the user Calculate dynamic kana and generate the current timestamp. Then calculate:
[0084] ;
[0085] Authentication value .
[0086] Finally, the user Authentication message Send to medical server .
[0087] S3.3: Medical Server Upon receiving user News Then, through judgment (in The current time when the message was received. (Indicates the maximum transmission delay associated with the message) Verify the received timestamp The freshness. If If invalid, the session is terminated; if valid, the medical server... calculate Simultaneously, the modular function is used to calculate... Then calculate:
[0088] ;
[0089] ;
[0090] .
[0091] Subsequently, the medical server verify Is it equal to If verification fails, the session is terminated; otherwise, the medical server... Perform asymmetric load transfer operations and randomly sample. and calculate and Then, the signal function is applied to calculate... Simultaneously using modular function calculation Then the medical server Generate current timestamp Then calculate with the user mobile terminals Shared session key and authentication value :
[0092] ;
[0093] ;
[0094] Finally, the medical server Authentication message Send to user .
[0095] S3.4: User At the current time Received from medical server News Then, first determine whether it satisfies To verify the received timestamp The novelty. If effective, then users... calculate:
[0096] ;
[0097] ;
[0098] Session key ;
[0099] ;
[0100] Subsequently, the user verify Is it equal to If verification fails, the session is terminated; otherwise, the user... Successful authentication of the medical server .
[0101] At this point, the user and medical servers Mutual authentication has been completed, and the same session key has been negotiated. .
[0102] This embodiment also provides a formal analysis of the above method. At this stage, the provable security of the method is proven based on the Random Oracle model. The security of the proposed method can be expressed as the probability that an adversary A can distinguish between a uniformly random number and the actual real key SK. Let... To test the bits guessed by adversary A in the query, consider a series of security games, the specific process of which is as follows:
[0103] (1) Games Simulating a real protocol execution environment, adversary A interacts with protocol participants through a random oracle. The adversary's advantage is defined as: ,in, For adversary A, this AKA authentication key negotiation protocol The security advantages of session keys The polynomial computation time for opponent A. For the game The probability of adversary A successfully breaching the agreement and challenging the guessing game. Represents in real games If the adversary correctly guesses the challenge bit (distinguishing the real session key from the random string) and the attack is successful, other games involving this... and The meaning is explained in the context of this game.
[0104] (2) Games This game simulates passive attack. Opponent A initiates... Inquiry, eavesdropping on users and medical servers Messages exchanged between and Then adversary A uses Reveal and Test queries to determine whether it is the real session key. Or a random key. However, adversary A cannot obtain the user's... and medical servers With secret parameters, eavesdropping alone cannot increase the advantage of adversary A. Therefore, and They are indistinguishable, that is: .
[0105] (3) Games In this game, opponent A simulates an active attack by initiating Send, Execute, and Hash queries. The game is terminated if either of the following two conditions is met:
[0106] 1) Hash query ( , Collisions in the output;
[0107] 2) Random sample ( The collision.
[0108] According to the birthday paradox, in the first scenario, the probability of a hash output collision is at most 1 / 3. ;because( () is a discrete Gaussian distribution Since the samples are generated from random samples, the probability of the second scenario occurring is at most [missing value]. Therefore, we can obtain: .
[0109] in, For adversary A, a random oracle hash function H( Total number of queries initiated. For hash function H( The output bit length, Total number of Send oracle queries initiated for the adversary The total number of times the Execute oracle query was initiated for the adversary. Let be the modulus of the polynomial ring in the lattice cryptography scheme.
[0110] (4) Games This game simulates the corrupting abilities of enemy A. Enemy A initiates... The query yielded the user's information. Long-term secret parameters held Next, adversary A attempts to calculate... Therefore, adversary A must simultaneously and correctly guess the user's... password and biological keys ;
[0111] 1) Opponent A passes The query guessed the biometric key. Its success probability is ;
[0112] 2) Opponent A attempts to pass through The query correctly guessed the password. .
[0113] The probability of success for this event is: ,therefore and They are indistinguishable unless opponent A can obtain them simultaneously. and ,Right now: .
[0114] in, To corrupt oracle query commands, an adversary can invoke the oracle to carry out a long-term key theft attack on the user. For users A collection of local private states For biometric keys The output bit length, For password dictionary-related constants, representing fixed coefficients for a single round of password probing. This represents the total number of Send oracle probes initiated by the adversary against the password.
[0115] (5) Games In this game, opponent A can guess the session key without using a hash lookup. . Depend on The calculated result is that, and If adversary A can successfully guess the session key... Therefore, the challenger can solve the RLWE problem. Thus, we can obtain: ,in, This represents a breakthrough advantage for polynomial-time adversary A in solving the difficult problem of cyclic fault-tolerant learning (RLWE) with computational resources t.
[0116] (6) Games The game and Similar, the only difference is that the opponent is General A. As input for the hash query. Therefore, according to the birthday paradox, we can obtain: .
[0117] (7) After completing the above game, opponent A initiates a Test query. The challenger selects a challenge bit. And the opponent A outputs a counter The guess of bit However, adversary A is able to distinguish the real session keys. It offers no advantage over random keys. Therefore, .
[0118] (8) Therefore, by accumulating game differences, the opponent's advantage is limited to:
[0119] .
[0120] Since the RLWE problem is intractable in polynomial time, the adversary advantage is negligible, proving the protocol is secure.
[0121] This application also proposes a computer device comprising: a memory and a processor, wherein the memory stores instructions executable on the processor. When the processor executes the instructions, it implements the methods described in the above embodiments. The number of memories and processors can be one or more. This computer device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The computer device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein.
[0122] The computer device may also include a communication interface for communicating with external devices and exchanging data. The devices are interconnected using different buses and can be mounted on a common motherboard or otherwise installed as needed. The processor processes instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as a display device coupled to the interface). In other embodiments, multiple processors and / or multiple buses can be used with multiple memories, if desired. Similarly, multiple electronic devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). The bus can be divided into address buses, data buses, control buses, etc.
[0123] Optionally, in a specific implementation, if the memory, processor, and communication interface are integrated on a single chip, then the memory, processor, and communication interface can communicate with each other through an internal interface.
[0124] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processor. It is worth noting that the processor can be a processor supporting advanced RISC machines (ARM) architecture.
[0125] This application also provides a computer-readable storage medium (such as the memory described above) that stores computer instructions that, when executed by a processor, implement the methods provided in this application.
[0126] Optionally, the memory may include a stored program area and a stored data area, wherein the stored program area may store the operating system and application programs required for at least one function; the stored data area may store data created based on the use of the computer device for mapping. Furthermore, the memory may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory may optionally include memory remotely located relative to the processor, which can be connected to the computer device for mapping via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0127] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A lightweight post-quantum authentication key exchange method for intelligent electronic medical systems, characterized in that: Includes the following steps: S1: System setup phase, during which the medical server... Perform offline steps to generate its private key and global public system parameters; S2: Registration phase, during which users... Send to the medical server via secure channel or offline mode During the registration phase, users... Need to send to your mobile device Enter your identity information Password and biological characteristics After that, the user and medical servers Registration is completed via encrypted communication; S3: Login and Identity Authentication Phase. After completing the registration phase, the user... With medical server Perform mutual authentication and negotiate the same session key, including for users. To their own mobile device The input identity verification, password validity verification, and user... With medical server Mutual authentication.
2. The lightweight post-quantum authentication key exchange method for intelligent electronic medical systems according to claim 1, characterized in that: Step S1 specifically includes: S1.1: Medical Server Choose large prime numbers and integers ,in , It is a set of positive integers; S1.2: Medical Server Define a polynomial ring and in Choose a standard deviation as Discrete Gaussian distribution ,in Let represent the ring of integers modulo q, which is the set of residue classes {0,1,…,q−1} obtained by taking all integers modulo q. It is a polynomial. It is a variable used to represent the unknowns in a polynomial. Indicates the quotient ring; S1.3: Medical Server Randomly select ring elements And sample secret polynomials sum of error polynomials ,in As a medical server The private key is then used to calculate the corresponding public key. ; S1.4: Medical Server Define a hash function Finally, the medical server Publish global public system parameters and the private key Securely store in memory.
3. The lightweight post-quantum authentication key exchange method for intelligent electronic medical systems according to claim 2, characterized in that: Step S2 specifically includes: S2.1: User To their own mobile device Enter your identity information Password and biological characteristics Then the user Generate a random number And using biological hash functions Computing biometric keys Then calculate Then the user Random sampling secret polynomial sum of error polynomials ,in ,calculate ,in As a user private key, For this user The corresponding public key; Finally, the user Will Send to medical server ; S2.2: Medical Server Upon receiving from the user News Then, a registration timestamp is generated. and calculate and Then the medical server Will Stored in its own database, and Send to user ; S2.3: User Upon receiving the message Then, calculate , and End user Will Securely store on your mobile device .
4. A lightweight post-quantum authentication key exchange method for intelligent electronic medical systems according to claim 3, characterized in that: Step S3 specifically includes: S3.1: User To their own mobile device Enter your identity information Password and biological characteristics Then the user Using biological hash functions Computing biometric keys Then calculate: ; ; ; And judge Is it equal to If they are equal, it indicates that the user Input identity identifier Password It is valid; otherwise, the session terminates. S3.2: User Random sampling after successful login and calculate , ,in For temporary random private key polynomials, It is a random error polynomial; then the signal function is applied. calculate Simultaneously using modular functions calculate Next, the user Calculate dynamic kana and generate the current timestamp. Then calculate: ; Authentication value ; Finally, the user Authentication message Send to medical server ; S3.3: Medical Server Upon receiving user News Then, through judgment Verify received timestamp The freshness, among which The current time when the message was received. Indicates the maximum transmission delay associated with the message; if If invalid, the session is terminated; if valid, the medical server... calculate Simultaneously, the modular function is used to calculate... Then calculate: ; ; ; Subsequently, the medical server verify Is it equal to If verification fails, the session is terminated; otherwise, the medical server... Perform asymmetric load transfer operations and randomly sample. and calculate and Then, the signal function is applied to calculate... Simultaneously using modular function calculation Next, the medical server Generate current timestamp Then calculate with the user mobile terminals Shared session key and authentication value : ; ; Finally, the medical server Authentication message Send to user ; S3.4: User At the current time Received from medical server News Then, first determine whether it satisfies To verify the received timestamp The novelty; if effective, then users calculate: ; ; Session key ; ; Subsequently, the user verify Is it equal to If verification fails, the session is terminated; otherwise, the user... Successful authentication of the medical server ; At this point, the user and medical servers Mutual authentication has been completed, and the same session key has been negotiated. .
5. A lightweight post-quantum authentication key exchange method for intelligent electronic medical systems according to any one of claims 1-4, characterized in that: It also includes a formal analysis phase, which proves the provable security of the method based on the Random Oracle model.
6. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1-5.
7. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that: When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1-5.
8. A computer program product comprising a computer program / instructions, characterized in that: When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1-5.