WO2020228304A1 - Information interaction method and apparatus, and computer device and readable storage medium - Google Patents

Information interaction method and apparatus, and computer device and readable storage medium Download PDF

Info

Publication number
WO2020228304A1
WO2020228304A1 PCT/CN2019/123141 CN2019123141W WO2020228304A1 WO 2020228304 A1 WO2020228304 A1 WO 2020228304A1 CN 2019123141 W CN2019123141 W CN 2019123141W WO 2020228304 A1 WO2020228304 A1 WO 2020228304A1
Authority
WO
WIPO (PCT)
Prior art keywords
node
information
ciphertext
interactive
interaction
Prior art date
Application number
PCT/CN2019/123141
Other languages
French (fr)
Chinese (zh)
Inventor
冯承勇
Original Assignee
深圳壹账通智能科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳壹账通智能科技有限公司 filed Critical 深圳壹账通智能科技有限公司
Publication of WO2020228304A1 publication Critical patent/WO2020228304A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0442Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0478Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload applying multiple layers of encryption, e.g. nested tunnels or encrypting the content with a first key and then with at least a second key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures

Abstract

The implementation of the present application is applicable to the technical field of data transmission. Provided are an information interaction method and apparatus, and a computer device and a readable storage medium. The method comprises: when it is detected that a user makes a request for information interaction, acquiring a second digital certificate of a second node, and using a second node public key in the second digital certificate to encrypt an identifier of information to be interacted with to generate a first initial ciphertext; acquiring a first node private key to encrypt the first initial ciphertext to generate an interaction ciphertext, and transmitting the interaction ciphertext to an electronic medical record storage device; receiving an information ciphertext, and using the second node public key to decrypt the information ciphertext; and if the decryption is successful, extracting interaction information from a second initial ciphertext obtained by means of decrypting the information ciphertext, and storing the interaction information. By means of using a multi-layer encryption form to ensure the security of interaction information during a transmission process, the privacy during an information interaction process is improved, information will not easily be leaked, and the security of information is better.

Description

信息交互方法、装置、计算机设备及可读存储介质Information interaction method, device, computer equipment and readable storage medium
本申请申明享有2019年05月10日递交的申请号为201910390295.0、名称为“信息交互方法、装置、计算机设备及可读存储介质”中国专利申请的优先权,该中国专利申请的整体内容以参考的方式结合在本申请中。This application affirms that it enjoys the priority of a Chinese patent application filed on May 10, 2019 with the application number 201910390295.0 and titled "Information interaction methods, devices, computer equipment and readable storage media". The entire content of the Chinese patent application is referred to The way is incorporated in this application.
技术领域Technical field
本申请属于数据传输技术领域,特别是涉及一种信息交互方法、装置、计算机设备及可读存储介质。This application belongs to the field of data transmission technology, and particularly relates to an information interaction method, device, computer equipment and readable storage medium.
背景技术Background technique
随着互联网技术的飞速发展,卫生与健康现代医疗卫生体系的建设规划也越来越成熟,预计到2020年,将建成全面的健康信息平台,实现所在地区各大医院之间信息的相互交互。健康信息平台中采用电子病历的形式存储患者的所有数据并实时更新数据,目前已经建立的健康信息平台通常依赖中心化的信息系统所搭载,并基于该中心化的信息系统实现电子病历的存储及更新。With the rapid development of Internet technology, the construction plan of the modern medical and health system of health and health is becoming more and more mature. It is expected that by 2020, a comprehensive health information platform will be built to realize the mutual exchange of information between major hospitals in the region. The health information platform uses electronic medical records to store all patient data and update the data in real time. The currently established health information platforms usually rely on a centralized information system to carry them, and based on the centralized information system to realize the storage and storage of electronic medical records. Update.
相关技术中,每个医院均建立了中心化的信息系统,对于每个医院来说,该医院的信息系统存储了该医院中涉及到的全部信息,例如,工作人员信息、病人治疗信息、医院运营信息等,为了使各大医院之间的信息实现互联互通,通常来说,医院之间都会进行信息交互。目前,医院在进行信息交互时,需要将待交互的信息从信息系统中提取出来,采用纸质或者电子版的形式将待交互的信息传输给其他医院。In related technologies, each hospital has established a centralized information system. For each hospital, the information system of the hospital stores all the information involved in the hospital, such as staff information, patient treatment information, and hospital Operational information, etc., in order to achieve interconnection of information between major hospitals, generally speaking, information exchanges between hospitals. At present, when hospitals conduct information interaction, they need to extract the information to be interacted from the information system, and transmit the information to be interacted to other hospitals in the form of paper or electronic versions.
在实现本申请的过程中,发明人发现相关技术至少存在以下问题:每个医院的信息系统中存储的信息仅是在本医院的相关信息,若采用纸质或者电子版的形式将待交互的信息传输给其他医院,会导致信息交互过程的私密性不好,信息容易泄露,信息的安全性较差。In the process of realizing this application, the inventor found that the related technology has at least the following problems: the information stored in the information system of each hospital is only relevant information in the hospital. If the paper or electronic version is used, the information to be interacted The transmission of information to other hospitals will result in poor privacy in the information interaction process, easy information leakage, and poor information security.
发明概述Summary of the invention
技术问题technical problem
有鉴于此,本申请提供了一种信息交互方法、装置、计算机设备及可读存储介 质,主要目的在于解决目前采用纸质或者电子版的形式将待交互的信息传输给其他医院,会导致信息交互过程的私密性不好,信息容易泄露,信息的安全性较差的问题。In view of this, this application provides an information interaction method, device, computer equipment, and readable storage medium. The main purpose is to solve the problem that the current use of paper or electronic version to transmit the information to be interacted to other hospitals will cause information The privacy of the interaction process is not good, the information is easy to leak, and the security of the information is poor.
问题的解决方案The solution to the problem
技术解决方案Technical solutions
为解决上述技术问题,本申请实施例采用的技术方案是:In order to solve the above technical problems, the technical solutions adopted in the embodiments of this application are:
第一方面,提供了一种信息交互方法,该方法包括:In the first aspect, an information exchange method is provided, which includes:
当检测到用户请求与第二节点进行信息交互时,第一节点获取第二节点的第二数字证书,采用第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文;When it is detected that the user requests information interaction with the second node, the first node obtains the second digital certificate of the second node, uses the second node public key in the second digital certificate to encrypt the identification of the information to be interacted, and generates the first initial Ciphertext
获取第一节点私钥,采用第一节点私钥对第一初始密文进行加密,生成交互密文,将交互密文传输至电子病历存储设备;Obtain the private key of the first node, encrypt the first initial ciphertext with the private key of the first node, generate an interactive ciphertext, and transmit the interactive ciphertext to the electronic medical record storage device;
接收电子病历存储设备返回的信息密文,采用第二节点公钥对信息密文进行解密,信息密文由第二节点接收到电子病历存储设备传输的交互密文后生成并传输至电子病历存储设备;Receive the information ciphertext returned by the electronic medical record storage device, and decrypt the information ciphertext using the public key of the second node. The information ciphertext is generated by the second node after receiving the interactive ciphertext transmitted by the electronic medical record storage device and transmitted to the electronic medical record storage equipment;
如果采用第二节点公钥对信息密文进行解密成功,则在对信息密文进行解密得到的第二初始密文中提取交互信息,存储交互信息,第二初始密文由第二节点基于交互信息加密得到。If the information ciphertext is successfully decrypted using the public key of the second node, the interactive information is extracted from the second initial ciphertext obtained by decrypting the information ciphertext, and the interactive information is stored. The second initial ciphertext is based on the interactive information by the second node Get encrypted.
第二方面,提供了提供了一种信息交互方法,该方法包括:In the second aspect, an information exchange method is provided, and the method includes:
当接收到第一节点传输的交互密文时,电子病历存储设备确定第一节点请求进行信息交互的第二节点,第一节点和第二节点为进行信息交互的节点,交互密文由第一节点基于携带待交互信息标识的信息交互请求生成的;When receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction. The first node and the second node are nodes for information interaction, and the interactive ciphertext is determined by the first node. The node is generated based on an information exchange request that carries an identification of the information to be exchanged;
将交互密文传输至第二节点;Transmit the interactive ciphertext to the second node;
如果接收到第二节点在接收到交互密文后返回的信息密文,则将信息密文返回给第一节点,信息密文由第二节点基于待交互信息标识指示的交互信息生成。If the information ciphertext returned by the second node after receiving the interactive ciphertext is received, the information ciphertext is returned to the first node, and the information ciphertext is generated by the second node based on the interactive information indicated by the information identifier to be interacted.
第三方面,一种信息交互方法,该方法包括:In the third aspect, an information exchange method includes:
当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点的第一数字证书,采用第一数字证书中的第一节点公钥对交互密文进行解密,交互密 文由第一节点基于携带待交互信息标识的信息交互请求生成的,第一节点为请求与第二节点进行信息交互的节点;When receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, and uses the public key of the first node in the first digital certificate to decrypt the interactive ciphertext. The first node is generated based on an information exchange request carrying an identification of the information to be exchanged, and the first node is a node that requests information exchange with the second node;
如果采用第一节点公钥对交互密文进行解密成功,则在解密后的交互密文中提取第一初始密文,第一初始密文由第一节点对信息交互请求加密后生成;If the interactive ciphertext is successfully decrypted using the public key of the first node, extract the first initial ciphertext from the decrypted interactive ciphertext, and the first initial ciphertext is generated by the first node after encrypting the information interaction request;
获取第二节点私钥,采用第二节点私钥对第一初始密文进行解密,得到待交互信息标识;Obtain the private key of the second node, decrypt the first initial ciphertext with the private key of the second node, and obtain the information identification to be interacted;
提取待交互信息标识指示的交互信息,基于交互信息生成信息密文,将信息密文传输至电子病历存储设备。The interactive information indicated by the identification of the information to be interactive is extracted, the information ciphertext is generated based on the interactive information, and the information ciphertext is transmitted to the electronic medical record storage device.
第四方面,提供了一种信息交互装置,该装置包括:In a fourth aspect, an information interaction device is provided, which includes:
第一加密模块,用于当检测到用户请求与第二节点进行信息交互时,第一节点获取第二节点的第二数字证书,采用第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文;The first encryption module is configured to, when detecting a user request for information interaction with the second node, the first node obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate to identify the information to be exchanged Encrypt and generate the first initial ciphertext;
第二加密模块,用于获取第一节点私钥,采用第一节点私钥对第一初始密文进行加密,生成交互密文,将交互密文传输至电子病历存储设备;The second encryption module is used to obtain the private key of the first node, encrypt the first initial ciphertext with the private key of the first node, generate the interactive ciphertext, and transmit the interactive ciphertext to the electronic medical record storage device;
解密模块,用于接收电子病历存储设备返回的信息密文,采用第二节点公钥对信息密文进行解密,信息密文由第二节点接收到电子病历存储设备传输的交互密文后生成并传输至电子病历存储设备;The decryption module is used to receive the information ciphertext returned by the electronic medical record storage device, and decrypt the information ciphertext using the public key of the second node. The information ciphertext is generated and combined by the second node after receiving the interactive ciphertext transmitted by the electronic medical record storage device Transfer to electronic medical record storage device;
存储模块,用于如果采用第二节点公钥对信息密文进行解密成功,则在对信息密文进行解密得到的第二初始密文中提取交互信息,存储交互信息,第二初始密文由第二节点基于交互信息加密得到。The storage module is used for extracting the interactive information from the second initial ciphertext obtained by decrypting the information ciphertext if the public key of the second node is used to successfully decrypt the information ciphertext, and storing the interactive information. The two nodes are encrypted based on the interactive information.
第五方面,提供了一种信息交互装置,该装置包括:In a fifth aspect, an information interaction device is provided, which includes:
确定模块,用于当接收到第一节点传输的交互密文时,电子病历存储设备确定第一节点请求进行信息交互的第二节点,第一节点和第二节点为进行信息交互的节点,交互密文由第一节点基于携带待交互信息标识的信息交互请求生成的;The determining module is configured to, when receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction. The first node and the second node are nodes for information interaction. The ciphertext is generated by the first node based on the information interaction request carrying the identification of the information to be exchanged;
第一传输模块,用于将交互密文传输至第二节点;The first transmission module is used to transmit the interactive ciphertext to the second node;
返回模块,用于如果接收到第二节点在接收到交互密文后返回的信息密文,则将信息密文返回给第一节点,信息密文由第二节点基于待交互信息标识指示的 交互信息生成。The return module is used to return the information ciphertext to the first node if the information ciphertext returned by the second node after receiving the interactive ciphertext is received, and the information ciphertext is interacted by the second node based on the information identifier to be interacted Information generation.
第六方面,提供了一种信息交互装置,该装置包括:In a sixth aspect, an information interaction device is provided, which includes:
第一解密模块,用于当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点的第一数字证书,采用第一数字证书中的第一节点公钥对交互密文进行解密,交互密文由第一节点基于携带待交互信息标识的信息交互请求生成的,第一节点为请求与第二节点进行信息交互的节点;The first decryption module is configured to, when receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, and uses the first node public key in the first digital certificate to interact with the ciphertext For decryption, the interactive ciphertext is generated by the first node based on an information exchange request carrying an information identification to be exchanged, and the first node is a node requesting information exchange with the second node;
提取模块,用于如果采用第一节点公钥对交互密文进行解密成功,则在解密后的交互密文中提取第一初始密文,第一初始密文由第一节点对信息交互请求加密后生成;The extraction module is used to extract the first initial ciphertext from the decrypted interactive ciphertext if the public key of the first node is used to successfully decrypt the interactive ciphertext, after the first node encrypts the information interaction request generate;
第二解密模块,用于获取第二节点私钥,采用第二节点私钥对第一初始密文进行解密,得到待交互信息标识;The second decryption module is configured to obtain the private key of the second node, and decrypt the first initial ciphertext by using the private key of the second node to obtain the information identification to be exchanged;
传输模块,用于提取待交互信息标识指示的交互信息,基于交互信息生成信息密文,将信息密文传输至电子病历存储设备。The transmission module is used to extract the interactive information indicated by the identifier of the information to be interacted, generate the information ciphertext based on the interactive information, and transmit the information ciphertext to the electronic medical record storage device.
第七方面,提供了一种计算机设备,包括存储器、处理器以及存储在存储器中并可在处理器上运行的计算机可读指令,处理器执行计算机可读指令时实现上述第一方面或第二方面或第三方面的方法的步骤。In a seventh aspect, a computer device is provided, including a memory, a processor, and computer-readable instructions stored in the memory and running on the processor. The processor implements the first aspect or the second aspect when the processor executes the computer-readable instructions. Aspect or steps of the method of the third aspect.
第八方面,提供了一种计算机非易失性可读存储介质,计算机非易失性可读存储介质存储有计算机可读指令,计算机可读指令被处理器执行时实现上述第一方面或第二方面或第三方面的方法的步骤。In an eighth aspect, a computer non-volatile readable storage medium is provided. The computer non-volatile readable storage medium stores computer readable instructions. The computer readable instructions implement the first aspect or the first aspect when executed by a processor. The steps of the method of the second or third aspect.
本申请提供的一种信息交互方法、装置、计算机设备及可读存储介质,与目前采用纸质或者电子版的形式将待交互的信息传输给其他医院的方式相比,本申请在需要进行信息交互时,第一节点对待交互信息标识进行加密,并将加密后的待交互信息标识传输给需要进行交互的第二节点,由第二节点在允许信息交互的情况下,将交互信息进行传输,使得采用多层加密的形式保证了交互信息在传输过程中的安全,提高信息交互过程中的私密性,信息不容易泄露,信息的安全性较好。The information interaction method, device, computer equipment and readable storage medium provided in this application are compared with the current way of transmitting the information to be interacted to other hospitals in the form of paper or electronic version. During the interaction, the first node encrypts the identifier of the information to be interacted, and transmits the encrypted information identifier to be interacted to the second node that needs to interact, and the second node transmits the interactive information when the information interaction is allowed. The use of multi-layer encryption ensures the security of the interactive information during the transmission process, improves the privacy in the information interaction process, and the information is not easy to leak, and the security of the information is better.
发明的有益效果The beneficial effects of the invention
对附图的简要说明Brief description of the drawings
附图说明Description of the drawings
图1A示出了本申请实施例提供的一种信息交互方法流程示意图;FIG. 1A shows a schematic flowchart of an information exchange method provided by an embodiment of the present application;
图1B示出了本申请实施例提供的一种信息交互方法流程示意图;FIG. 1B shows a schematic flowchart of an information exchange method provided by an embodiment of the present application;
图1C示出了本申请实施例提供的一种信息交互方法流程示意图;FIG. 1C shows a schematic flowchart of an information exchange method provided by an embodiment of the present application;
图2A示出了本申请实施例提供的一种信息交互方法流程示意图;2A shows a schematic flowchart of an information exchange method provided by an embodiment of the present application;
图2B示出了本申请实施例提供的一种信息交互方法流程示意图;2B shows a schematic flowchart of an information exchange method provided by an embodiment of the present application;
图3A示出了本申请实施例提供的一种信息交互方装置的结构示意图;FIG. 3A shows a schematic structural diagram of an information interaction device provided by an embodiment of the present application;
图4A示出了本申请实施例提供的一种信息交互方装置的结构示意图;FIG. 4A shows a schematic structural diagram of an information interaction party device provided by an embodiment of the present application;
图5A示出了本申请实施例提供的一种信息交互方装置的结构示意图;FIG. 5A shows a schematic structural diagram of an information interaction party device provided by an embodiment of the present application;
图6示出了本申请实施例提供的一种计算机设备的装置结构示意图。Fig. 6 shows a schematic diagram of a device structure of a computer device provided by an embodiment of the present application.
发明实施例Invention embodiment
本发明的实施方式Embodiments of the invention
本申请实施例提供了一种信息交互方法,如图1A所示,该方法包括:The embodiment of the present application provides an information exchange method. As shown in FIG. 1A, the method includes:
101、当检测到用户请求与第二节点进行信息交互时,第一节点获取第二节点的第二数字证书,采用第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文。101. When it is detected that the user requests information interaction with the second node, the first node obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate to encrypt the identification of the interactive information to generate the An initial ciphertext.
在本申请实施例中,当第一节点检测到用户请求进行信息交互时,为了保证请求进行信息交互的过程的安全性,第一节点获取待进行信息交互的第二节点的第二数字证书,并采用第二数字证书中的第二节点公钥对待交互信息标识进行加密,从而生成第一初始密文,以便后续基于该第一初始密文实现信息交互。In this embodiment of the application, when the first node detects that the user requests for information interaction, in order to ensure the security of the process of requesting information interaction, the first node obtains the second digital certificate of the second node to be information interaction, The second node public key in the second digital certificate is used to encrypt the identification of the information to be interacted, thereby generating a first initial ciphertext, so as to subsequently implement information interaction based on the first initial ciphertext.
102、第一节点获取第一节点私钥,采用第一节点私钥对第一初始密文进行加密,生成交互密文,将交互密文传输至电子病历存储设备。102. The first node obtains the first node private key, uses the first node private key to encrypt the first initial ciphertext, generates an interactive ciphertext, and transmits the interactive ciphertext to the electronic medical record storage device.
在本申请实施例中,为了给第二节点一个对进行信息交互的凭证的验证机会,且公私钥之间具有可以相互加密或者解密的特性,因此,第一节点获取自身的第一节点私钥,并采用该第一节点私钥对第一初始密文进行加密,生成交互密文,从而将该交互密文传输至电子病历存储设备。In the embodiment of this application, in order to give the second node an opportunity to verify the credential for information exchange, and the public and private keys have the characteristics of mutual encryption or decryption, therefore, the first node obtains its own first node private key , And use the private key of the first node to encrypt the first initial ciphertext to generate an interactive ciphertext, thereby transmitting the interactive ciphertext to the electronic medical record storage device.
103、第一节点接收电子病历存储设备返回的信息密文,采用第二节点公钥对信息密文进行解密,信息密文由第二节点接收到电子病历存储设备传输的交互 密文后生成并传输至电子病历存储设备。103. The first node receives the information ciphertext returned by the electronic medical record storage device, and uses the public key of the second node to decrypt the information ciphertext. The information ciphertext is generated by the second node after receiving the interactive ciphertext transmitted by the electronic medical record storage device. Transfer to the electronic medical record storage device.
在本申请实施例中,当第一节点接收到电子病历存储设备返回的信息密文时,采用第二节点公钥对信息密文进行解密,也即对接收到的信息密文进行验证,从而判断信息密文是否在传输的过程中被篡改。In the embodiment of the present application, when the first node receives the information ciphertext returned by the electronic medical record storage device, the second node public key is used to decrypt the information ciphertext, that is, to verify the received information ciphertext, thereby Determine whether the ciphertext of the information has been tampered with during transmission.
104、如果第一节点采用第二节点公钥对信息密文进行解密成功,则在对信息密文进行解密得到的第二初始密文中提取交互信息,存储交互信息,第二初始密文由第二节点基于交互信息加密得到。104. If the first node successfully decrypts the information ciphertext using the public key of the second node, extract the interactive information from the second initial ciphertext obtained by decrypting the information ciphertext, and store the interactive information. The two nodes are encrypted based on the interactive information.
在本申请实施例中,如果第一节点采用第二节点公钥对信息密文进行解密成功,则表示第二节点给第一节点传输的信息密文在传输的过程中并没有被篡改,第一节点可以接收并存储第二节点返回的交互信息。In the embodiment of this application, if the first node uses the public key of the second node to successfully decrypt the information ciphertext, it means that the information ciphertext transmitted by the second node to the first node has not been tampered with during the transmission. One node can receive and store the interactive information returned by the second node.
本申请实施例提供了另一种信息交互方法,如图1B所示,该方法包括:The embodiment of the present application provides another information exchange method. As shown in FIG. 1B, the method includes:
105、当接收到第一节点传输的交互密文时,电子病历存储设备确定第一节点请求进行信息交互的第二节点,第一节点和第二节点为进行信息交互的节点,交互密文由第一节点基于携带待交互信息标识的信息交互请求生成的。105. When receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction, the first node and the second node are nodes for information interaction, and the interactive ciphertext is determined by The first node is generated based on an information exchange request carrying an identification of the information to be exchanged.
在本申请实施例中,当电子病历存储设备接收到第一节点传输的交互密文时,便可以确定第一节点请求进行信息交互的第二节点,以便后续将交互密文传输至第二节点。In the embodiment of the present application, when the electronic medical record storage device receives the interactive ciphertext transmitted by the first node, it can determine the second node that the first node requests for information interaction, so as to subsequently transmit the interactive ciphertext to the second node .
106、电子病历存储设备将交互密文传输至第二节点。106. The electronic medical record storage device transmits the interactive ciphertext to the second node.
在本申请实施例中,电子病历存储设备将接收到的第一节点传输的交互密文传输至第二节点。In the embodiment of the present application, the electronic medical record storage device transmits the received interactive ciphertext transmitted by the first node to the second node.
107、如果电子病历存储设备接收到第二节点在接收到交互密文后返回的信息密文,则将信息密文返回给第一节点,信息密文由第二节点基于待交互信息标识指示的交互信息生成。107. If the electronic medical record storage device receives the information ciphertext returned by the second node after receiving the interactive ciphertext, it returns the information ciphertext to the first node, and the information ciphertext is indicated by the second node based on the information identification to be interacted. Interactive information generation.
在本申请实施例中,如果电子病历存储设备接收到第二节点在接收到交互密文后返回的信息密文,则表示第一节点与第二节点之间进行的信息交互成功,电子病历存储设备将信息密文返回给第一节点。In the embodiment of the present application, if the electronic medical record storage device receives the information ciphertext returned by the second node after receiving the interactive ciphertext, it means that the information interaction between the first node and the second node is successful, and the electronic medical record is stored The device returns the information ciphertext to the first node.
本申请实施例提供了另一种信息交互方法,如图1C所示,该方法包括:The embodiment of the present application provides another information exchange method. As shown in FIG. 1C, the method includes:
108、当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点 的第一数字证书,采用第一数字证书中的第一节点公钥对交互密文进行解密,交互密文由第一节点基于携带待交互信息标识的信息交互请求生成的,第一节点为请求与第二节点进行信息交互的节点。108. When receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, uses the public key of the first node in the first digital certificate to decrypt the interactive ciphertext, and the interactive encryption The text is generated by the first node based on the information exchange request carrying the identification of the information to be exchanged, and the first node is the node that requests information exchange with the second node.
在本申请实施例中,当第二节点接收到电子病历存储设备传输的交互密文时,第二节点通过获取第一节点的第一数字证书,采用第一数字证书中的第一节点公钥对交互密文进行解密,来实现对交互密文的验证,确定交互密文在传输的过程中是否被更改。In this embodiment of the application, when the second node receives the interactive ciphertext transmitted by the electronic medical record storage device, the second node uses the first node public key in the first digital certificate by obtaining the first digital certificate of the first node Decrypt the interactive ciphertext to verify the interactive ciphertext and determine whether the interactive ciphertext is changed during transmission.
109、如果第二节点采用第一节点公钥对交互密文进行解密成功,则在解密后的交互密文中提取第一初始密文,第一初始密文由第一节点对信息交互请求加密后生成。109. If the second node successfully decrypts the interactive ciphertext using the public key of the first node, extract the first initial ciphertext from the decrypted interactive ciphertext, and the first initial ciphertext is encrypted by the first node after the information interaction request generate.
在本申请实施例中,如果第二节点采用第一节点公钥对交互密文进行解密成功,则表示交互密文在传输的过程中并没有被篡改,第二节点可以在解密后的交互密文中提取第一初始密文。In the embodiment of this application, if the second node successfully decrypts the interactive ciphertext using the public key of the first node, it means that the interactive ciphertext has not been tampered with during transmission, and the second node can decrypt the interactive ciphertext after decryption. Extract the first initial ciphertext from the text.
110、第二节点获取第二节点私钥,采用第二节点私钥对第一初始密文进行解密,得到待交互信息标识。110. The second node obtains the second node private key, and uses the second node private key to decrypt the first initial ciphertext to obtain the information identification to be exchanged.
在本申请实施例中,第二节点在对交互密文进行解密成功后,便可以获取第二节点私钥,采用第二节点私钥对第一初始密文进行解密,得到待交互信息标识。In the embodiment of the present application, after the second node successfully decrypts the interactive ciphertext, it can obtain the second node private key, and use the second node private key to decrypt the first initial ciphertext to obtain the information identification to be interacted.
111、第二节点提取待交互信息标识指示的交互信息,基于交互信息生成信息密文,将信息密文传输至电子病历存储设备。111. The second node extracts the interaction information indicated by the identification of the information to be interacted, generates an information ciphertext based on the interaction information, and transmits the information ciphertext to the electronic medical record storage device.
在本申请实施例中,当第二节点获取到待交互信息标识后,第二节点便可以提取到该待交互信息标识指示的交互信息,并基于交互信息生成信息密文,将信息密文传输至电子病历存储设备,从而实现与第一节点之间进行信息交互。In the embodiment of the present application, after the second node obtains the identifier of the information to be interacted, the second node can extract the interactive information indicated by the identifier of the information to be interacted, and generate information ciphertext based on the interactive information, and transmit the information ciphertext To the electronic medical record storage device to realize information interaction with the first node.
本申请实施例提供了另一种信息交互方法,如图2A和图2B所示,该方法包括:The embodiment of the present application provides another information exchange method, as shown in FIG. 2A and FIG. 2B, the method includes:
201、第一节点基于第二节点的第二节点标识,生成证书查询请求,将证书查询请求传输至电子病历存储设备。201. The first node generates a certificate query request based on the second node identifier of the second node, and transmits the certificate query request to an electronic medical record storage device.
在本申请实施例中,电子病历存储设备是基于区块链技术实现电子病历存储的 设备,其中存储有大量用户的电子病历。由于通常来说只有医院才可以在用户治疗的过程中生成电子病历,因此,大量医院以节点的方式接入到电子病历存储设备中,且这些医院作为节点将用户的电子病历上传到电子病历存储设备中。在实际应用的过程中,为了实现对医院的认证,避免盲目的允许医院接入到电子病历存储设备中造成的信息不安全,电子病历存储设备会为接入其中的节点提供注册服务,并只有在电子病历存储设备中成功注册的节点才可以基于电子病历存储设备实现一系列的操作。在本申请实施例中,以交互的节点为第一节点和第二节点为例进行说明,第一节点和第二节点均为在电子病历存储设备中成功注册的节点。In the embodiment of the present application, the electronic medical record storage device is a device that realizes the storage of electronic medical records based on the blockchain technology, and stores the electronic medical records of a large number of users. Generally speaking, only hospitals can generate electronic medical records during user treatment. Therefore, a large number of hospitals are connected to electronic medical record storage devices in the form of nodes, and these hospitals are used as nodes to upload user electronic medical records to electronic medical record storage. In the device. In the actual application process, in order to realize the certification of the hospital and avoid the information insecurity caused by blindly allowing the hospital to access the electronic medical record storage device, the electronic medical record storage device will provide registration services for the nodes connected to it, and only Only nodes that have successfully registered in the electronic medical record storage device can implement a series of operations based on the electronic medical record storage device. In the embodiment of the present application, the first node and the second node are used as an example for description of the interacting nodes. Both the first node and the second node are nodes that are successfully registered in the electronic medical record storage device.
通常来说,指示节点在电子病历存储设备中注册成功的标志便是电子病历存储设备中存储有该节点的数字证书,也即电子病历存储设备中存储有每一个成功在电子病历存储设备中注册的节点的数字证书。节点的数字证书中通常包括证书公钥,该证书公钥与节点自身保留的证书私钥是相互对应的,采用证书公钥进行加密的信息可以采用证书私钥进行解密,且采用证书私钥加密的信息可以采用证书公钥解密,因此,为了保证在请求进行信息交互时各种信息的安全性,可以基于公私钥的特性对交互的信息进行加密,并基于加密后的信息进行交互。Generally speaking, the sign indicating that the node is successfully registered in the electronic medical record storage device is the digital certificate of the node stored in the electronic medical record storage device, that is, the electronic medical record storage device stores every successful registration in the electronic medical record storage device The digital certificate of the node. The digital certificate of the node usually includes the certificate public key, which corresponds to the certificate private key retained by the node itself. The information encrypted by the certificate public key can be decrypted by the certificate private key and encrypted by the certificate private key. The information can be decrypted using the certificate public key. Therefore, in order to ensure the security of various information when requesting information interaction, the interactive information can be encrypted based on the characteristics of the public and private keys, and the encrypted information can be interacted.
由于每个节点的数字证书都存储在电子病历存储设备中,因此,为了对交互过程涉及到的信息进行加密,当第一节点希望与第二节点进行信息交互时,需要向电子病历存储设备请求第二节点的第二数字证书,以便基于该第二数字证书中的第二证书公钥实现在交互过程中对信息的加密。其中,第一节点在向电子病历存储设备请求第二节点的第二数字证书时,由于电子病历存储设备中注册有大量的节点,使得电子病历存储设备中存储有大量的数字证书,因此,第一节点基于第二节点的第二节点标识,生成证书查询请求,也即生成包括第二节点标识的证书查询请求,并将该证书查询请求传输给电子病历存储设备,以便电子病历存储设备基于该证书查询请求为第一节点提供第二节点的数字证书。Since the digital certificate of each node is stored in the electronic medical record storage device, in order to encrypt the information involved in the interaction process, when the first node wants to interact with the second node, it needs to request the electronic medical record storage device The second digital certificate of the second node, so as to realize the encryption of information during the interaction process based on the second certificate public key in the second digital certificate. Wherein, when the first node requests the second digital certificate of the second node from the electronic medical record storage device, since a large number of nodes are registered in the electronic medical record storage device, a large number of digital certificates are stored in the electronic medical record storage device. Therefore, the first node A node generates a certificate query request based on the second node identifier of the second node, that is, generates a certificate query request including the second node identifier, and transmits the certificate query request to the electronic medical record storage device, so that the electronic medical record storage device is based on the The certificate query request provides the first node with the digital certificate of the second node.
202、当电子病历存储设备接收到第一节点传输的证书查询请求时,在证书查询请求中提取第二节点标识,获取第二节点标识指示的第二数字证书,将第二 数字证书传输至第一节点。202. When the electronic medical record storage device receives the certificate query request transmitted by the first node, it extracts the second node identifier from the certificate query request, obtains the second digital certificate indicated by the second node identifier, and transmits the second digital certificate to the first node. One node.
在本申请实施例中,当电子病历存储设备接收到第一节点传输的证书查询请求时,便可以基于该证书查询请求获取到第二节点的第二数字证书,并将该第二数字证书提供给第一节点。其中,由于证书查询请求中携带了第二节点标识,因此,首先,电子病历存储设备在证书查询请求中提取第二节点标识;随后,基于该第二节点标识进行查询,从而获取到该第二节点标识指示的第二数字证书,并将该第二数字证书传输至第一节点。In this embodiment of the application, when the electronic medical record storage device receives the certificate query request transmitted by the first node, it can obtain the second digital certificate of the second node based on the certificate query request, and provide the second digital certificate To the first node. Among them, because the certificate query request carries the second node identifier, first, the electronic medical record storage device extracts the second node identifier from the certificate query request; then, it performs a query based on the second node identifier to obtain the second node identifier. The second digital certificate indicated by the node identifier, and the second digital certificate is transmitted to the first node.
203、第一节点接收电子病历存储设备在接收到证书查询请求后返回的第二数字证书。203. The first node receives the second digital certificate returned by the electronic medical record storage device after receiving the certificate query request.
在本申请实施例中,由于电子病历存储设备会将获取到的第二节点的数字证书返回给第一节点,因此,第一节点会接收到电子病历存储设备在接收到证书查询请求后返回的第二数字证书。In this embodiment of the application, since the electronic medical record storage device will return the acquired digital certificate of the second node to the first node, the first node will receive the return from the electronic medical record storage device after receiving the certificate query request The second digital certificate.
204、当第一节点检测到用户请求与第二节点进行信息交互时,获取第二节点的第二数字证书,采用第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文。204. When the first node detects that the user requests information interaction with the second node, it obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate to encrypt the identification of the information to be interacted, to generate a An initial ciphertext.
在本申请实施例中,为了给第一节点的用户提供请求进行信息交互的机会,第一节点所搭载的终端中可以提供信息交互入口,当检测到用户触发该信息交互入口时,确定检测到用户请求进行信息交互,此时,便可以显示交互信息输入页面,并在检测到用户对该交互信息输入页面确认时,获取用户填入交互信息输入页面中的待交互信息标识,以便交互该待交互信息标识指示的交互信息。具体地,该待交互信息标识可为病历信息标识、员工信息标识以及学术文件标识等,本申请实施例对待交互信息标识具体包括哪些内容不进行限定。In the embodiment of the present application, in order to provide the user of the first node with an opportunity to request information interaction, the terminal mounted on the first node may provide an information interaction portal. When it is detected that the user triggers the information interaction portal, it is determined to be detected The user requests information interaction. At this time, the interactive information input page can be displayed, and when it is detected that the user confirms the interactive information input page, obtain the information identification to be interacted in the interactive information input page filled in by the user, so as to interact with the waiting information. The interactive information indicated by the interactive information identifier. Specifically, the identification of the information to be interacted may be a medical record information identification, an employee information identification, an academic document identification, etc. The embodiment of the present application does not limit the specific content of the interactive information identification.
为了保证信息交互过程的安全性,第一节点在向第二节点传输希望进行信息交互的待交互信息标识时,基于第二节点的第二数字证书对该待交互信息标识进行加密。考虑到每个节点的数字证书都会包括该节点的证书公钥,因此,当第一节点检测到用户请求进行信息交互时,便可以在获取到的第二节点的第二数字证书中提取到该第二节点的第二节点公钥。由于每一个节点均具有一对证书公钥和证书私钥,且证书公钥和证书私钥具有采用证书公钥加密后的信息可以 采用证书私钥进行解密的特性,为了避免待交互信息标识在传输的过程中被篡改,第一节点在获取到第二节点的第二节点公钥后,便可以将该第二节点公钥作为加密公钥,采用第二节点公钥对待交互信息标识进行加密,从而生成第一初始密文。In order to ensure the security of the information exchange process, when the first node transmits to the second node the information identification to be exchanged that it wishes to exchange information, the information identification to be exchanged is encrypted based on the second digital certificate of the second node. Taking into account that the digital certificate of each node will include the certificate public key of the node, when the first node detects that the user requests for information interaction, it can extract the second digital certificate from the second node. The second node public key of the second node. Since each node has a pair of certificate public key and certificate private key, and the certificate public key and certificate private key have the characteristics that the information encrypted by the certificate public key can be decrypted by the certificate private key, in order to avoid the identification of the information to be exchanged It is tampered with during transmission. After the first node obtains the second node public key of the second node, it can use the second node public key as the encryption public key, and use the second node public key to encrypt the interactive information identifier , Thereby generating the first initial ciphertext.
205、第一节点获取第一节点私钥,采用第一节点私钥对第一初始密文进行加密,生成交互密文,将交互密文传输至电子病历存储设备。205. The first node obtains the first node private key, uses the first node private key to encrypt the first initial ciphertext, generates an interactive ciphertext, and transmits the interactive ciphertext to the electronic medical record storage device.
在本申请实施例中,在生成了第一初始密文后,考虑到第一初始密文仍旧存在在传输过程中被篡改的可能,且第一节点的第一数字证书中包括的第一证书公钥是公开的,为了在后续给第二节点提供一个可以验证接收到的密文是否未被篡改的机会,因此,第一节点在生成第一初始密文后,还可以采用自身的第一节点私钥对该第一初始密文进行签名,生成查询密文,并将该查询密文传输给电子病历存储设备,以便电子病历存储设备将该查询密文传输给第二节点,使得第二节点可以基于第二节点公开的第一证书公钥对该交互密文进行验证,既保证了信息交互过程的安全性,还给第二节点提供了对交互密文进行验证的机会,实现了双重保护。In this embodiment of the application, after the first initial ciphertext is generated, it is considered that the first initial ciphertext may still be tampered with during transmission, and the first certificate included in the first digital certificate of the first node The public key is public. In order to provide the second node with an opportunity to verify whether the received ciphertext has not been tampered with, the first node can also use its own first ciphertext after generating the first initial ciphertext. The node private key signs the first initial ciphertext, generates the query ciphertext, and transmits the query ciphertext to the electronic medical record storage device, so that the electronic medical record storage device transmits the query ciphertext to the second node, so that the second node The node can verify the interactive ciphertext based on the first certificate public key disclosed by the second node, which not only ensures the security of the information interaction process, but also provides the second node with an opportunity to verify the interactive ciphertext, realizing double protection.
在实际应用的过程中,为了使电子病历存储设备在接收到交互密文时,可以确定将该交互密文传输给哪一个节点,第一节点还可以采用第二节点标识对交互密文进行标记,以便电子病历存储设备在接收到交互密文时,可以确定将该交互密文传输给第二节点,避免电子病历存储设备将交互密文传输错误。In the actual application process, in order for the electronic medical record storage device to determine which node to transmit the interactive ciphertext to when receiving the interactive ciphertext, the first node can also use the second node ID to mark the interactive ciphertext , So that when the electronic medical record storage device receives the interactive ciphertext, it can determine to transmit the interactive ciphertext to the second node, so as to prevent the electronic medical record storage device from transmitting the interactive ciphertext error.
206、当电子病历存储设备接收到第一节点传输的交互密文时,确定第一节点请求进行信息交互的第二节点,将交互密文传输至第二节点。206. When the electronic medical record storage device receives the interactive ciphertext transmitted by the first node, it determines the second node that the first node requests for information interaction, and transmits the interactive ciphertext to the second node.
在本申请实施例中,当电子病历存储设备接收到第一节点传输的交互密文时,便可以确定第一节点请求进行信息交互的第二节点,并直接将该交互密文传输至第二节点。其中,如果第一节点采用了第二节点标识对交互密文进行了标记,则电子病历存储设备在接收到交互密文时,可以根据交互密文标记的第二节点标识来确定第二节点,并直接将该交互密文传输至第二节点。In the embodiment of the present application, when the electronic medical record storage device receives the interactive ciphertext transmitted by the first node, it can determine the second node that the first node requests for information interaction, and directly transmit the interactive ciphertext to the second node. node. Wherein, if the first node uses the second node identifier to mark the interactive ciphertext, when the electronic medical record storage device receives the interactive ciphertext, it can determine the second node according to the second node identifier marked by the interactive ciphertext, And directly transmit the interactive ciphertext to the second node.
207、当第二节点接收到电子病历存储设备传输的交互密文时,获取第一节点的第一数字证书,采用第一数字证书中的第一节点公钥对交互密文进行解密, 如果采用第一节点公钥对交互密文进行解密成功,则执行下述步骤208至步骤211;如果采用第一节点公钥对交互密文进行解密失败,则执行下述步骤215至步骤216。207. When the second node receives the interactive ciphertext transmitted by the electronic medical record storage device, obtains the first digital certificate of the first node, and decrypts the interactive ciphertext using the first node public key in the first digital certificate. If the first node public key successfully decrypts the interactive ciphertext, the following steps 208 to 211 are executed; if the first node public key is used to decrypt the interactive ciphertext failed, then the following steps 215 to 216 are executed.
在本申请实施例中,由于交互密文是采用第一节点的第一节点私钥进行加密生成的,因此,在第二节点接收到交互密文后,第二节点可以采用第一节点公钥对交互密文进行解密,并通过解密是否成功来实现对交互密文的验证,从而确定交互密文是否被篡改。其中,第一节点的第二节点公钥是公开的,且是以第一数字证书的形式存储在电子病历存储设备中的,因此,第二节点在获取第一节点公钥时,可以请求电子病历存储设备提供,具体过程与上述步骤201至步骤202中第一节点向电子病历存储设备请求第二节点公钥的过程一致,此处不再进行赘述。In the embodiment of this application, since the interactive ciphertext is generated by using the first node private key of the first node for encryption, after the second node receives the interactive ciphertext, the second node can use the first node public key Decrypt the interactive ciphertext, and verify the interactive ciphertext by whether the decryption is successful, so as to determine whether the interactive ciphertext has been tampered with. Among them, the public key of the second node of the first node is public and is stored in the electronic medical record storage device in the form of the first digital certificate. Therefore, when the second node obtains the public key of the first node, it can request the electronic The medical record storage device is provided, and the specific process is consistent with the process in which the first node requests the public key of the second node from the electronic medical record storage device in steps 201 to 202 described above, and will not be repeated here.
其中,如果第二节点采用第一节点公钥对交互密文进行解密成功,则表示交互密文并没有被篡改,这时,第二节点便可以对该交互密文进行解密,得到该交互密文中的第一初始密文,并基于该第一初始密文为第一节点提供交互信息,也即执行下述步骤208至步骤211。如果第二节点采用第一节点公钥对交互密文进行签名失败,则表示该交互密文在传输的过程中很可能被篡改了,需要第一节点重新发送交互密文才可以进行信息的交互,也即执行下述步骤215至步骤216。Among them, if the second node uses the public key of the first node to successfully decrypt the interactive ciphertext, it means that the interactive ciphertext has not been tampered with. At this time, the second node can decrypt the interactive ciphertext to obtain the interactive ciphertext. The first initial ciphertext in the text, and the interactive information is provided for the first node based on the first initial ciphertext, that is, the following steps 208 to 211 are executed. If the second node fails to sign the interactive ciphertext using the public key of the first node, it means that the interactive ciphertext is likely to be tampered with during transmission, and the first node needs to re-send the interactive ciphertext before the information can be exchanged. That is, the following steps 215 to 216 are executed.
在实际应用的过程中,当第二节点接收到交互密文时,如果第二节点并不希望与第一节点进行信息交互,则第二节点无需执行采用第一节点公钥对交互密文进行解密的过程,直接执行下述步骤215至步骤216的过程,告知第一节点信息交互失败即可。In the actual application process, when the second node receives the interactive ciphertext, if the second node does not want to exchange information with the first node, then the second node does not need to perform the interactive ciphertext using the public key of the first node. In the decryption process, the following steps 215 to 216 are directly executed to inform the first node that the information interaction fails.
208、如果第二节点采用第一节点公钥对交互密文进行解密成功,则在解密后的交互密文中提取第一初始密文,获取第二节点私钥,采用第二节点私钥对第一初始密文进行解密,得到待交互信息标识。208. If the second node successfully decrypts the interactive ciphertext using the public key of the first node, extract the first initial ciphertext from the decrypted interactive ciphertext, obtain the second node private key, and use the second node private key to An initial ciphertext is decrypted to obtain the information identification to be exchanged.
在本申请实施例中,如果第二节点采用第一节点公钥对交互密文进行签名成功,则表示交互密文并没有被篡改,这时,第二节点便可以通过对交互密文进行解密,在解密后的交互密文中提取第一初始密文。另外,由于第一初始密文采 用第二节点的第二节点公钥加密生成,基于公私钥互相加密解密的特性,因此,第二节点可以采用第二节点私钥对第一初始密文进行解密,得到第一初始密文中包括的待查询信息标识,以便第二节点后续可以根据该待查询信息标识确定目标信息,并基于该目标信息,生成信息密文。In the embodiment of this application, if the second node successfully signs the interactive ciphertext with the public key of the first node, it means that the interactive ciphertext has not been tampered with. At this time, the second node can decrypt the interactive ciphertext by , Extract the first initial ciphertext from the decrypted interactive ciphertext. In addition, since the first initial ciphertext is encrypted and generated by the public key of the second node of the second node, based on the mutual encryption and decryption characteristics of the public and private keys, the second node can use the private key of the second node to decrypt the first initial ciphertext , Obtain the identification of the information to be queried included in the first initial ciphertext, so that the second node can subsequently determine the target information according to the identification of the information to be queried, and generate an information ciphertext based on the target information.
209、第二节点根据待交互信息标识进行信息查询,获取待交互信息标识指示的交互信息,采用第一节点公钥对交互信息进行加密,生成第二初始密文,并采用第二节点私钥对第二初始密文进行加密,生成信息密文,并将信息密文传输给电子病历存储设备。209. The second node performs information query according to the identifier of the information to be interacted, obtains the interactive information indicated by the identifier of the information to be interacted, uses the public key of the first node to encrypt the interactive information, generates a second initial ciphertext, and uses the private key of the second node The second initial ciphertext is encrypted, the information ciphertext is generated, and the information ciphertext is transmitted to the electronic medical record storage device.
在本申请实施例中,当第二节点获取到待交互信息标识后,便可以基于该待交互信息标识进行信息查询,获取该待交互信息标识指示的交互信息。为了保证将交互信息交互给第一节点的过程中交互信息的安全性,第二节点在将交互信息传输给第一节点之前,可以对交互信息进行加密。由于第一节点的第一节点公钥是公开的,且第二节点已经获取到了第一节点的第一证书公钥,因此,为了保证交互信息的安全性,第二节点可以采用第一节点公钥对交互信息进行加密,生成第二初始密文。随后,为了使第一节点在接收到第二初始密文时可以验证该第二初始密文是否未被其他的恶意节点篡改,第二节点可给第一节点提供对接收到的密文进行验证的机会,也即第二节点采用自身的第二节点私钥,对第二初始密文进行加密,生成信息密文,并将该信息密文传输给电子病历存储设备,使得电子病历存储可以将该信息密文传输给第一节点。In the embodiment of the present application, after the second node obtains the identifier of the information to be interacted, it can perform information query based on the identifier of the information to be interacted, and obtain the interaction information indicated by the identifier of the information to be interacted. In order to ensure the security of the interactive information in the process of exchanging the interactive information to the first node, the second node may encrypt the interactive information before transmitting the interactive information to the first node. Since the first node public key of the first node is public, and the second node has already obtained the first certificate public key of the first node, in order to ensure the security of the exchange information, the second node can use the first node public key. The key encrypts the interactive information to generate the second initial ciphertext. Subsequently, in order to enable the first node to verify whether the second initial ciphertext has not been tampered with by other malicious nodes when receiving the second initial ciphertext, the second node may provide the first node to verify the received ciphertext Opportunity, that is, the second node uses its own second node private key to encrypt the second initial ciphertext, generates the information ciphertext, and transmits the information ciphertext to the electronic medical record storage device, so that the electronic medical record storage can The ciphertext of the information is transmitted to the first node.
210、电子病历存储设备将信息密文返回给第一节点。210. The electronic medical record storage device returns the information ciphertext to the first node.
在本申请实施例中,当电子病历存储设备接收到第二节点传输的信息密文后,便可以将该信息密文传输给第一节点,以便第二节点基于该信息密文获取到第二节点为第一节点提供的交互信息。In the embodiment of the present application, after the electronic medical record storage device receives the information ciphertext transmitted by the second node, it can transmit the information ciphertext to the first node, so that the second node can obtain the second information based on the information ciphertext. The node is the interactive information provided by the first node.
211、第一节点接收电子病历存储设备返回的信息密文,采用第二节点公钥对信息密文进行解密,如果采用第二节点公钥对信息密文进行解密成功,则执行下述步骤212;如果采用第二节点公钥对信息密文进行解密失败,则执行下述步骤213至步骤214。211. The first node receives the information ciphertext returned by the electronic medical record storage device, and uses the second node public key to decrypt the information ciphertext. If the second node public key is used to successfully decrypt the information ciphertext, the following step 212 is executed ; If the use of the public key of the second node to decrypt the information ciphertext fails, perform the following steps 213 to 214.
在本申请实施例中,当第一节点接收到电子病历存储设备返回的信息密文后, 由于信息密文是由第二节点获取交互信息,并首先采用第一节点的第一节点公钥加密,随后采用自身的第二节点私钥进行加密生成的,因此,第一节点可以先采用第二节点公钥对信息密文进行解密,实现对信息密文的验证,并仅在基于第二节点公钥对信息密文进行解密成功后,再继续进行其他的操作。如果采用第二节点公钥对信息密文进行解密成功,则表示信息密文在传输的过程中并没有被篡改,因此,第一节点便可以通过对信息密文进行解密,在解密后的信息密文中提取第二初始密文,也即执行下述步骤212;如果第一节点采用第二节点公钥对信息密文进行解密失败,则表示信息密文很可能在传输的过程中内容被篡改,因此,该信息密文便无法正常使用,此时,需要第二节点重新发送信息密文,也即执行下述步骤213至步骤214。In the embodiment of this application, after the first node receives the information ciphertext returned by the electronic medical record storage device, since the information ciphertext is obtained by the second node, the interactive information is first encrypted using the first node public key of the first node , And then use its own private key of the second node to generate encryption. Therefore, the first node can first use the public key of the second node to decrypt the information ciphertext to achieve verification of the information ciphertext, and only based on the second node After the public key successfully decrypts the information ciphertext, other operations can be continued. If the public key of the second node is used to decrypt the information ciphertext successfully, it means that the information ciphertext has not been tampered with during transmission. Therefore, the first node can decrypt the information ciphertext, and the information after decryption Extract the second initial ciphertext from the ciphertext, that is, perform the following step 212; if the first node uses the second node public key to decrypt the information ciphertext and fails, it means that the information ciphertext is likely to be tampered with during transmission Therefore, the information ciphertext cannot be used normally. At this time, the second node needs to resend the information ciphertext, that is, the following steps 213 to 214 are executed.
212、如果第一节点采用第二节点公钥对信息密文进行解密成功,则获取对信息密文解密后的第二初始密文,采用第一节点私钥对第二初始密文进行解密,得到交互信息,并存储交互信息。212. If the first node successfully decrypts the information ciphertext using the second node public key, obtain the second initial ciphertext after decrypting the information ciphertext, and use the first node private key to decrypt the second initial ciphertext. Obtain interactive information and store the interactive information.
在本申请实施例中,如果采用第二节点公钥对信息密文进行解密成功,则表示信息密文在传输的过程中并没有被篡改,因此,第一节点便可以通过对信息密文进行解密,在解密后的信息密文中提取第二初始密文。其中,由于第二初始密文由第二节点采用第一节点的第一节点公钥对交互信息进行加密生成的,因此,在提取到第二初始密文后,第一节点便可以采用自身的第一节点私钥对该第二初始密文进行解密,从而得到交互信息,并将得到的交互信息进行存储,从而完成与第二节点之间进行的信息交互。In the embodiment of this application, if the public key of the second node is used to successfully decrypt the information ciphertext, it means that the information ciphertext has not been tampered with during the transmission process. Therefore, the first node can perform the Decryption, extracting the second initial ciphertext from the decrypted information ciphertext. Among them, because the second initial ciphertext is generated by the second node using the first node public key of the first node to encrypt the interactive information, after extracting the second initial ciphertext, the first node can use its own The private key of the first node decrypts the second initial ciphertext, thereby obtaining interactive information, and storing the obtained interactive information, so as to complete the information interaction with the second node.
213、如果第一节点采用第二节点公钥对信息密文进行解密失败,则生成第一失败响应,将第一失败响应返回至电子病历存储设备。213. If the first node fails to decrypt the information ciphertext using the second node public key, it generates a first failure response, and returns the first failure response to the electronic medical record storage device.
在本申请实施例中,如果第一节点采用第二节点公钥对信息密文进行解密失败,则表示信息密文很可能在传输的过程中内容被篡改,因此,该信息密文便无法正常使用,此时,需要第二节点重新发送信息密文。为了提醒第二节点重新发送信息密文,第一节点生成第一失败响应,并将第二失败响应返回给电子病历存储设备,以便电子病历存储设备将该第一失败响应传输给第二节点。In the embodiment of this application, if the first node uses the public key of the second node to decrypt the information ciphertext and fails, it means that the content of the information ciphertext is likely to be tampered with during transmission. Therefore, the information ciphertext cannot be normal. In use, at this time, the second node is required to resend the information ciphertext. In order to remind the second node to resend the information ciphertext, the first node generates a first failure response and returns the second failure response to the electronic medical record storage device, so that the electronic medical record storage device transmits the first failure response to the second node.
其中,为了使第二节点在接收到第一失败响应时可以确定哪一个信息密文交互 失败了,第一节点生成的第一失败响应中可以携带待交互信息标识,以便第二节点根据第一失败响应携带的待交互信息标识重新发送对应的信息密文。Wherein, in order to enable the second node to determine which information ciphertext interaction failed when receiving the first failure response, the first failure response generated by the first node may carry the information identification to be exchanged, so that the second node can follow the first The information identifier to be exchanged carried in the failure response resends the corresponding information ciphertext.
214、电子病历存储设备将第一失败响应返回至第二节点。214. The electronic medical record storage device returns the first failure response to the second node.
在本申请实施例中,当电子病历存储设备接收到第一失败响应后,便可以将该第一失败响应返回给第二节点,以便第二节点在接收到第一失败响应后可以重新发送信息密文。In the embodiment of the present application, after the electronic medical record storage device receives the first failure response, it can return the first failure response to the second node so that the second node can resend the information after receiving the first failure response Ciphertext.
215、如果第二节点采用第一节点公钥对交互密文进行解密失败,则生成第二失败响应,将第二失败响应传输至电子病历存储设备。215. If the second node fails to decrypt the interactive ciphertext using the public key of the first node, a second failure response is generated, and the second failure response is transmitted to the electronic medical record storage device.
在本申请实施例中,如果第二节点采用第一节点公钥对交互密文进行解密失败,则表示该交互密文在传输的过程中很可能被篡改了,需要第一节点重新发送交互密文,因此,第二节点生成第二失败响应,并将该第二失败响应传输给电子病历存储设备,以便电子病历存储设备将该第二失败响应传输给第一节点,使得第一节点可以重新生成并发送交互密文。In the embodiment of this application, if the second node fails to decrypt the interactive ciphertext using the public key of the first node, it means that the interactive ciphertext is likely to have been tampered with during transmission, and the first node needs to resend the interactive ciphertext. Therefore, the second node generates a second failure response and transmits the second failure response to the electronic medical record storage device, so that the electronic medical record storage device transmits the second failure response to the first node, so that the first node can restart Generate and send interactive ciphertext.
216、电子病历存储设备将第二失败响应返回至第一节点。216. The electronic medical record storage device returns the second failure response to the first node.
在本申请实施例中,电子病历存储设备在接收到第二节点传输的第二失败响应后,便可将该第二失败响应传输给第一节点,使得第一节点在接收到第二失败响应后可以重新生成并发送交互密文。In the embodiment of the present application, after receiving the second failure response transmitted by the second node, the electronic medical record storage device can transmit the second failure response to the first node, so that the first node receives the second failure response You can then regenerate and send the interactive ciphertext.
通过执行上述步骤201至步骤216中的过程,便可以实现第一节点与第二节点之间进行的信息交互。而在实际应用的过程中,为了防止不法分子的节点也可以在电子病历存储设备中与其他节点进行信息交互,从而导致节点中存储的数据被盗取,接入到电子病历存储设备中的节点均需要进行注册,并且只有成功注册的节点才可以基于电子病历存储设备实现与其他节点进行信息交互。其中,以第一节点为例,第一节点在电子病历存储设备中进行注册的过程如图2B所示,该方法包括:By performing the process from step 201 to step 216 above, the information interaction between the first node and the second node can be realized. In the actual application process, in order to prevent criminals from interacting with other nodes in the electronic medical record storage device, the data stored in the node may be stolen and connected to the node in the electronic medical record storage device. Both need to be registered, and only the successfully registered node can realize information interaction with other nodes based on the electronic medical record storage device. Taking the first node as an example, the process of registering the first node in the electronic medical record storage device is shown in FIG. 2B, and the method includes:
217、当第一节点检测到用户请求注册时,将第一节点身份信息以及第一节点公钥传输至电子病历存储设备。217. When the first node detects that the user requests registration, it transmits the identity information of the first node and the public key of the first node to the electronic medical record storage device.
在本申请实施例中,第一节点所依赖的终端中可以为用户提供注册入口,当该终端检测到用户触发该注册入口时,确定检测到用户请求注册,显示注册页面 。其中,由于电子病历存储设备中为节点提供注册服务所依赖的凭证是数字证书,而电子病历存储设备为节点生成数字证书时是基于每个节点的节点公钥的,因此,第一节点在检测到用户请求注册时,将第一节点身份信息以及自身的第一节点公钥传输至电子病历存储设备,以便电子病历存储设备基于第一节点身份信息以及第一节点公钥为第一节点提供注册服务。In the embodiment of the present application, the terminal on which the first node relies may provide a registration entry for the user. When the terminal detects that the user triggers the registration entry, it determines that the user requests registration and displays the registration page. Among them, because the electronic medical record storage device relies on the digital certificate to provide the registration service for the node, and the electronic medical record storage device generates the digital certificate for the node based on the node public key of each node, the first node is detecting When the user requests registration, the first node identity information and its own first node public key are transmitted to the electronic medical record storage device, so that the electronic medical record storage device provides registration for the first node based on the first node identity information and the first node public key service.
具体地,第一节点身份信息可以包括医院名称信息、医院属性信息等,这样,还可为相同属性的医院提供更加便捷且清晰的信息交互服务。第一节点公钥可由第一节点自身生成或者获取到,一般来说,第一节点可以将自身可以公开的信息作为第一节点公钥,例如,医院编号、医院股票代码等;或者还可以随机生成一串字符串,将该字符串作为第一节点公钥。本申请实施例对第一节点获取第一节点公钥的方法不进行限定。Specifically, the identity information of the first node may include hospital name information, hospital attribute information, etc. In this way, more convenient and clear information interaction services can also be provided for hospitals with the same attribute. The first node public key can be generated or obtained by the first node itself. Generally speaking, the first node can use information that can be disclosed by itself as the first node public key, for example, hospital number, hospital stock code, etc.; or it can be random Generate a string of characters and use this string as the public key of the first node. The embodiment of the present application does not limit the method for the first node to obtain the public key of the first node.
218、当电子病历存储设备接收到第一节点传输的第一节点身份信息以及第一节点公钥时,将第一节点身份信息以及第一节点公钥进行绑定。218. When the electronic medical record storage device receives the first node identity information and the first node public key transmitted by the first node, bind the first node identity information and the first node public key.
在本申请实施例中,当电子病历存储设备接收到第一节点传输的第一节点身份信息以及第一节点公钥时,由于可能存在大量的节点在同一时间向电子病历存储设备请求注册的情况,使得电子病历存储设备可能在同一时间接收到大量的节点身份信息以及节点公钥,因此,为了区分接收到的节点身份信息以及节点公钥,电子病历存储设备将接收到的第一节点身份信息以及第一节点公钥进行绑定,以便后续基于该第一节点身份信息以及第一节点公钥实现对第一节点的注册。In the embodiment of the present application, when the electronic medical record storage device receives the first node identity information and the first node public key transmitted by the first node, because there may be a large number of nodes requesting registration from the electronic medical record storage device at the same time , So that the electronic medical record storage device may receive a large amount of node identity information and node public key at the same time. Therefore, in order to distinguish the received node identity information and the node public key, the electronic medical record storage device will receive the first node identity information And the public key of the first node is bound, so as to subsequently register the first node based on the identity information of the first node and the public key of the first node.
219、电子病历存储设备采用第一节点公钥对绑定后的第一节点身份信息以及第一节点公钥进行签名,生成并注册第一数字证书,将第一数字证书传输至第一节点,并将第一节点身份信息以及第一数字证书对应存储。219. The electronic medical record storage device uses the public key of the first node to sign the bound identity information of the first node and the public key of the first node, generates and registers the first digital certificate, and transmits the first digital certificate to the first node. And correspondingly store the identity information of the first node and the first digital certificate.
在本申请实施例中,当电子病历存储设备将接收到的第一节点身份信息和第一节点公钥进行绑定后,为了给每一个节点生成与其相关的数字证书,并在后续可以基于数字证书对节点的身份进行验证,电子病历存储设备采用第一节点公钥对绑定后的第一节点身份信息以及第一节点公钥进行签名,生成第一数字证书,并基于该第一数字证书实现对第一节点的注册。在实际应用的过程中,为 了避免数字证书与节点之间对应关系的混淆,电子病历存储设备将生成的第一节点身份信息与第一数字证书对应存储,或者采用第一节点身份信息对第一数字证书进行标记,从而建立第一节点身份信息与第一数字证书之间的对应关系。In the embodiment of the present application, after the electronic medical record storage device binds the received identity information of the first node with the public key of the first node, in order to generate a digital certificate related to each node, it can be based on the digital The certificate verifies the identity of the node, and the electronic medical record storage device uses the public key of the first node to sign the bound identity information of the first node and the public key of the first node to generate a first digital certificate, and based on the first digital certificate Realize the registration of the first node. In the actual application process, in order to avoid the confusion of the corresponding relationship between the digital certificate and the node, the electronic medical record storage device stores the generated first node identity information corresponding to the first digital certificate, or uses the first node identity information to compare the first The digital certificate is marked, thereby establishing a corresponding relationship between the identity information of the first node and the first digital certificate.
在完成了给第一节点生成数字证书后,为了使第一节点可以获知自身已经完成了在电子病历存储设备中的注册,电子病历存储设备将第一数字证书传输至第一节点。After completing the generation of the digital certificate for the first node, in order for the first node to know that it has completed registration in the electronic medical record storage device, the electronic medical record storage device transmits the first digital certificate to the first node.
220、第一节点接收电子病历存储设备在基于接收到第一节点身份信息以及第一节点公钥完成注册后返回的第一数字证书,并存储第一数字证书。220. The first node receives the first digital certificate returned by the electronic medical record storage device after completing registration based on the received first node identity information and the first node public key, and stores the first digital certificate.
第一数字证书由电子病历存储设备对第一节点身份信息以及第一节点公钥进行签名后生成。The first digital certificate is generated after the electronic medical record storage device signs the identity information of the first node and the public key of the first node.
在本申请实施例中,第一节点接收到电子病历存储设备返回的第一数字证书后,便可以存储第一数字证书,从而完成在电子病历存储设备中的注册。In this embodiment of the application, after the first node receives the first digital certificate returned by the electronic medical record storage device, it can store the first digital certificate, thereby completing the registration in the electronic medical record storage device.
本申请实施例提供的方法,在需要进行信息交互时,第一节点对待交互信息标识进行加密,并将加密后的待交互信息标识传输给需要进行交互的第二节点,由第二节点在允许信息交互的情况下,将交互信息进行传输,使得采用多层加密的形式保证了交互信息在传输过程中的安全,提高信息交互过程中的私密性,信息不容易泄露,信息的安全性较好。In the method provided by the embodiments of the present application, when information interaction is required, the first node encrypts the identifier of the information to be interacted, and transmits the encrypted information identifier to be interacted to the second node that needs to interact, and the second node allows In the case of information interaction, the interactive information is transmitted, so that the form of multi-layer encryption ensures the security of the interactive information during the transmission process, improves the privacy of the information interaction process, and the information is not easy to leak, and the information security is better .
需要说明的是,上述实施例中各步骤的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。It should be noted that the size of the sequence number of each step in the above embodiment does not mean the order of execution. The execution sequence of each process should be determined by its function and internal logic, and should not constitute any implementation process of the embodiments of this application. limited.
进一步地,作为图1A所述方法的具体实现,本申请实施例提供了一种信息交互装置,如图3A所示,所述装置包括:Further, as a specific implementation of the method described in FIG. 1A, an embodiment of the present application provides an information interaction device. As shown in FIG. 3A, the device includes:
第一加密模块301,用于当检测到用户请求与第二节点进行信息交互时,第一节点获取第二节点的第二数字证书,采用第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文;The first encryption module 301 is configured to, when it is detected that the user requests to exchange information with the second node, the first node obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate to treat the interactive information The logo is encrypted to generate the first initial ciphertext;
第二加密模块302,用于获取第一节点私钥,采用第一节点私钥对第一初始密文进行加密,生成交互密文,将交互密文传输至电子病历存储设备;The second encryption module 302 is configured to obtain the private key of the first node, encrypt the first initial ciphertext with the private key of the first node, generate an interactive ciphertext, and transmit the interactive ciphertext to the electronic medical record storage device;
解密模块303,用于接收电子病历存储设备返回的信息密文,采用第二节点公钥对信息密文进行解密,信息密文由第二节点接收到电子病历存储设备传输的交互密文后生成并传输至电子病历存储设备;The decryption module 303 is used to receive the information ciphertext returned by the electronic medical record storage device, and decrypt the information ciphertext using the public key of the second node. The information ciphertext is generated after the second node receives the interactive ciphertext transmitted by the electronic medical record storage device And transfer to the electronic medical record storage device;
存储模块304,用于如果采用第二节点公钥对信息密文进行解密成功,则在对信息密文进行解密得到的第二初始密文中提取交互信息,存储交互信息,第二初始密文由第二节点基于交互信息加密得到。The storage module 304 is configured to, if the information ciphertext is successfully decrypted using the public key of the second node, extract the interactive information from the second initial ciphertext obtained by decrypting the information ciphertext, and store the interactive information. The second node is encrypted based on the interactive information.
在具体的应用场景中,该装置还包括:In specific application scenarios, the device also includes:
传输模块305,用于当检测到用户请求注册时,将第一节点身份信息以及第一节点公钥传输至所述电子病历存储设备,所述第一节点身份信息至少包括医院名称信息、医院属性信息;The transmission module 305 is configured to transmit the identity information of the first node and the public key of the first node to the electronic medical record storage device when it is detected that the user requests registration, and the identity information of the first node includes at least hospital name information and hospital attributes information;
接收模块306,用于接收所述电子病历存储设备返回的第一数字证书,并存储所述第一数字证书,所述第一数字证书由所述电子病历存储设备对所述第一节点身份信息以及所述第一节点公钥进行签名后生成。The receiving module 306 is configured to receive the first digital certificate returned by the electronic medical record storage device and store the first digital certificate. The first digital certificate is used by the electronic medical record storage device to verify the identity information of the first node. And the public key of the first node is generated after signing.
在具体的应用场景中,该第一加密模块301,包括:In a specific application scenario, the first encryption module 301 includes:
生成单元3011,用于基于第二节点的第二节点标识,生成证书查询请求,将证书查询请求传输至电子病历存储设备;The generating unit 3011 is configured to generate a certificate query request based on the second node identifier of the second node, and transmit the certificate query request to the electronic medical record storage device;
接收单元3012,用于接收电子病历存储设备在接收到证书查询请求后返回的第二数字证书。The receiving unit 3012 is configured to receive the second digital certificate returned by the electronic medical record storage device after receiving the certificate query request.
在具体的应用场景中,该装置还包括:In specific application scenarios, the device also includes:
生成模块307,用于如果采用所述第二节点公钥对所述信息密文进行解密失败,则生成第一失败响应,将所述第一失败响应返回至所述电子病历存储设备。The generating module 307 is configured to generate a first failure response if the decryption of the information ciphertext using the second node public key fails, and return the first failure response to the electronic medical record storage device.
在具体的应用场景中,该存储模块304,包括:In a specific application scenario, the storage module 304 includes:
该获取单元3041,用于如果采用所述第二节点公钥对所述信息密文进行解密成功,则获取对所述信息密文解密后的所述第二初始密文;The obtaining unit 3041 is configured to obtain the second initial ciphertext after decrypting the information ciphertext if the information ciphertext is successfully decrypted by using the second node public key;
该解密单元3042,用于采用所述第一节点私钥对所述第二初始密文进行解密,得到所述交互信息,并存储所述交互信息。The decryption unit 3042 is configured to decrypt the second initial ciphertext using the first node private key to obtain the interaction information, and store the interaction information.
进一步地,作为图1B所述方法的具体实现,本申请实施例提供了一种信息交互装置,如图4A所示,所述装置包括:Further, as a specific implementation of the method described in FIG. 1B, an embodiment of the present application provides an information interaction device. As shown in FIG. 4A, the device includes:
确定模块401,用于当接收到第一节点传输的交互密文时,电子病历存储设备确定所述第一节点请求进行信息交互的第二节点,所述第一节点和所述第二节点为进行信息交互的节点,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的;The determining module 401 is configured to, when receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction, and the first node and the second node are A node for information interaction, where the interaction ciphertext is generated by the first node based on an information interaction request carrying an identification of the information to be interacted;
第一传输模块402,用于将所述交互密文传输至所述第二节点;The first transmission module 402 is configured to transmit the interactive ciphertext to the second node;
返回模块403,用于如果接收到所述第二节点在接收到所述交互密文后返回的信息密文,则将所述信息密文返回给所述第一节点,所述信息密文由所述第二节点基于所述待交互信息标识指示的交互信息生成。The return module 403 is configured to return the information ciphertext to the first node if the information ciphertext returned by the second node after receiving the interactive ciphertext is received, and the information ciphertext is determined by The second node is generated based on the interaction information indicated by the to-be-interaction information identifier.
在具体的应用场景中,该装置还包括:In specific application scenarios, the device also includes:
绑定模块404,用于当接收到所述第一节点传输的第一节点身份信息以及第一节点公钥时,将所述第一节点身份信息以及所述第一节点公钥进行绑定;The binding module 404 is configured to bind the first node identity information and the first node public key when the first node identity information and the first node public key transmitted by the first node are received;
签名模块405,用于采用所述第一节点公钥对绑定后的所述第一节点身份信息以及所述第一节点公钥进行签名,生成并注册第一数字证书;The signature module 405 is configured to use the first node public key to sign the bound first node identity information and the first node public key, and generate and register a first digital certificate;
存储模块406,用于将所述第一数字证书传输至所述第一节点,并将所述第一节点身份信息以及所述第一数字证书对应存储。The storage module 406 is configured to transmit the first digital certificate to the first node, and correspondingly store the first node identity information and the first digital certificate.
在具体的应用场景中,该装置还包括:In specific application scenarios, the device also includes:
提取模块407,用于当接收到所述第一节点传输的证书查询请求时,在所述证书查询请求中提取第二节点标识;The extraction module 407 is configured to extract a second node identifier from the certificate query request when the certificate query request transmitted by the first node is received;
第二传输模块408,用于获取所述第二节点标识指示的第二数字证书,将所述第二数字证书传输至所述第一节点。The second transmission module 408 is configured to obtain a second digital certificate indicated by the second node identifier, and transmit the second digital certificate to the first node.
在具体的应用场景中,该返回模块403,还用于如果接收到所述第一节点返回的第一失败响应,则将所述第一失败响应返回至所述第二节点;或,如果接收到所述第二节点返回的第二失败响应,则将所述第二失败响应返回至所述第一节点。In a specific application scenario, the return module 403 is also configured to return the first failure response to the second node if the first failure response returned by the first node is received; or, if the first failure response is received If the second failure response is returned to the second node, the second failure response is returned to the first node.
进一步地,作为图1C所述方法的具体实现,本申请实施例提供了一种信息交互装置,如图5A所示,所述装置包括:Further, as a specific implementation of the method described in FIG. 1C, an embodiment of the present application provides an information interaction device. As shown in FIG. 5A, the device includes:
第一解密模块501,用于当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点的第一数字证书,采用所述第一数字证书中的第一节点公钥 对所述交互密文进行解密,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的,所述第一节点为请求与所述第二节点进行信息交互的节点;The first decryption module 501 is configured to, when receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, and uses the first node public key pair in the first digital certificate The interactive ciphertext is decrypted, the interactive ciphertext is generated by the first node based on an information interaction request carrying an identification of the information to be interacted, and the first node is a node requesting information interaction with the second node ;
提取模块502,用于如果采用所述第一节点公钥对所述交互密文进行解密成功,则在解密后的所述交互密文中提取第一初始密文,所述第一初始密文由所述第一节点对所述信息交互请求加密后生成;The extraction module 502 is configured to, if the interactive ciphertext is successfully decrypted using the first node public key, extract a first initial ciphertext from the decrypted interactive ciphertext, and the first initial ciphertext is Generated after the first node encrypts the information exchange request;
第二解密模块503,用于获取第二节点私钥,采用所述第二节点私钥对所述第一初始密文进行解密,得到所述待交互信息标识;The second decryption module 503 is configured to obtain a second node private key, and use the second node private key to decrypt the first initial ciphertext to obtain the information identification to be interacted;
传输模块504,用于提取所述待交互信息标识指示的交互信息,基于所述交互信息生成信息密文,将所述信息密文传输至所述电子病历存储设备。The transmission module 504 is configured to extract the interaction information indicated by the identification of the information to be interacted, generate an information ciphertext based on the interaction information, and transmit the information ciphertext to the electronic medical record storage device.
在具体的应用场景中,该传输模块504,包括:In a specific application scenario, the transmission module 504 includes:
查询单元5041,用于根据所述待交互信息标识进行信息查询,获取所述待交互信息标识指示的交互信息;The query unit 5041 is configured to perform information query according to the identifier of the information to be interacted, and obtain the interactive information indicated by the identifier of the information to be interacted;
第一加密单元5042,用于采用所述第一节点公钥对所述交互信息进行加密,生成第二初始密文;The first encryption unit 5042 is configured to use the first node public key to encrypt the interaction information to generate a second initial ciphertext;
第二加密单元5043,用于采用所述第二节点私钥对所述第二初始密文进行加密,生成所述信息密文。The second encryption unit 5043 is configured to use the second node private key to encrypt the second initial ciphertext to generate the information ciphertext.
在具体的应用场景中,该装置还包括:In specific application scenarios, the device also includes:
生成模块505,用于如果采用所述第一节点公钥对所述交互密文进行解密失败,则生成第二失败响应,将所述第二失败响应传输至所述电子病历存储设备。The generating module 505 is configured to generate a second failure response if the decryption of the interactive ciphertext using the first node public key fails, and transmit the second failure response to the electronic medical record storage device.
需要说明的是,本申请实施例提供的一种信息交互装置所涉及各功能单元的其他相应描述,可以参考图1A至图1C和图2A至图2B中的对应描述,在此不再赘述。It should be noted that, for other corresponding descriptions of the functional units involved in the information interaction device provided in the embodiments of the present application, reference may be made to the corresponding descriptions in FIGS. 1A to 1C and FIGS. 2A to 2B, which will not be repeated here.
在示例性实施例中,参见图6,还提供了一种设备,该设备600包括通信总线、处理器、存储器和通信接口,还可以包括、输入输出接口和显示设备,其中,各个功能单元之间可以通过总线完成相互间的通信。该存储器存储有计算机可读指令,处理器,用于执行存储器上所存放的程序,执行上述实施例中任一实施例中第一节点、电子病历存储设备或第二节点分别对应的信息交互方法。In an exemplary embodiment, referring to FIG. 6, a device is also provided. The device 600 includes a communication bus, a processor, a memory, and a communication interface, and may also include an input/output interface, and a display device, wherein one of the functional units The communication between each other can be completed through the bus. The memory stores computer-readable instructions, and the processor is used to execute programs stored in the memory and execute the information interaction method corresponding to the first node, the electronic medical record storage device, or the second node in any of the above embodiments. .
一种计算机非易失性可读存储介质,其上存储有计算机可读指令,所述计算机可读指令被处理器执行时实现所述任一实施例中第一节点、电子病历存储设备或第二节点分别对应的信息交互方法的步骤。A computer non-volatile readable storage medium, on which computer readable instructions are stored, when the computer readable instructions are executed by a processor, the first node, the electronic medical record storage device, or the first node in any of the embodiments are implemented The two nodes respectively correspond to the steps of the information interaction method.
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到本申请可以通过硬件实现,也可以借助软件加必要的通用硬件平台的方式来实现。基于这样的理解,本申请的技术方案可以以软件产品的形式体现出来,该软件产品可以存储在一个非易失性存储介质(可以是CD-ROM,U盘,移动硬盘等)中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施场景所述的方法。Through the description of the above implementation manners, those skilled in the art can clearly understand that this application can be implemented by hardware, or by software plus a necessary general hardware platform. Based on this understanding, the technical solution of this application can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, U disk, mobile hard disk, etc.), including several The instructions are used to make a computer device (which may be a personal computer, a server, or a network device, etc.) execute the methods described in each implementation scenario of this application.
本领域技术人员可以理解附图只是一个优选实施场景的示意图,附图中的模块或流程并不一定是实施本申请所必须的。上述实施场景的模块可以合并为一个模块,也可以进一步拆分成多个子模块。Those skilled in the art can understand that the accompanying drawings are only schematic diagrams of preferred implementation scenarios, and the modules or processes in the accompanying drawings are not necessarily necessary for implementing this application. The modules of the above implementation scenarios can be combined into one module or further divided into multiple sub-modules.

Claims (20)

  1. 一种信息交互方法,其特征在于,包括:An information interaction method, characterized in that it comprises:
    当检测到用户请求与第二节点进行信息交互时,第一节点获取所述第二节点的第二数字证书,采用所述第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文;When detecting that the user requests information interaction with the second node, the first node obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate to encrypt the information identification to be interacted, Generate the first initial ciphertext;
    获取第一节点私钥,采用所述第一节点私钥对所述第一初始密文进行加密,生成交互密文,将所述交互密文传输至电子病历存储设备;Acquiring a first node private key, encrypting the first initial ciphertext using the first node private key, generating an interactive ciphertext, and transmitting the interactive ciphertext to an electronic medical record storage device;
    接收所述电子病历存储设备返回的信息密文,采用所述第二节点公钥对所述信息密文进行解密,所述信息密文由所述第二节点接收到所述电子病历存储设备传输的所述交互密文后生成并传输至所述电子病历存储设备;Receive the information ciphertext returned by the electronic medical record storage device, decrypt the information ciphertext using the public key of the second node, and the information ciphertext is received by the second node and transmitted by the electronic medical record storage device After the interactive ciphertext is generated and transmitted to the electronic medical record storage device;
    如果采用所述第二节点公钥对所述信息密文进行解密成功,则在对所述信息密文进行解密得到的第二初始密文中提取交互信息,存储所述交互信息,所述第二初始密文由所述第二节点基于所述交互信息加密得到。If the second node public key is used to decrypt the information ciphertext successfully, then the interactive information is extracted from the second initial ciphertext obtained by decrypting the information ciphertext, the interactive information is stored, and the second The initial ciphertext is encrypted by the second node based on the interaction information.
  2. 根据权利要求1所述的方法,其特征在于,所述当检测到用户请求与第二节点进行信息交互时,第一节点获取所述第二节点的第二数字证书,采用所述第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文之前,所述方法还包括:The method according to claim 1, wherein the first node obtains the second digital certificate of the second node when it is detected that the user requests to exchange information with the second node, and uses the second digital certificate. Before the public key of the second node in the certificate encrypts the identification of the interactive information, and before generating the first initial ciphertext, the method further includes:
    当检测到用户请求注册时,将第一节点身份信息以及第一节点公钥传输至所述电子病历存储设备,所述第一节点身份信息至少包括医院名称信息、医院属性信息;When it is detected that the user requests registration, the first node identity information and the first node public key are transmitted to the electronic medical record storage device, and the first node identity information includes at least hospital name information and hospital attribute information;
    接收所述电子病历存储设备返回的第一数字证书,并存储所述第一数字证书,所述第一数字证书由所述电子病历存储设备对所述第一节点身份信息以及所述第一节点公钥进行签名后生成。Receive the first digital certificate returned by the electronic medical record storage device, and store the first digital certificate. The first digital certificate is used by the electronic medical record storage device to verify the identity information of the first node and the first node The public key is generated after signing.
  3. 根据权利要求1所述的方法,其特征在于,所述第一节点获取所述第二节点的第二数字证书,包括:The method according to claim 1, wherein the first node obtaining the second digital certificate of the second node comprises:
    基于所述第二节点的第二节点标识,生成证书查询请求,将所述证书查询请求传输至所述电子病历存储设备;Generate a certificate query request based on the second node identifier of the second node, and transmit the certificate query request to the electronic medical record storage device;
    接收所述电子病历存储设备在接收到所述证书查询请求后返回的所述第二数字证书。Receiving the second digital certificate returned by the electronic medical record storage device after receiving the certificate query request.
  4. 根据权利要求1所述的方法,其特征在于,所述接收所述电子病历存储设备返回的信息密文,采用所述第二节点公钥对所述信息密文进行解密之后,所述方法还包括:The method according to claim 1, wherein after receiving the information ciphertext returned by the electronic medical record storage device, and decrypting the information ciphertext using the second node public key, the method further include:
    如果采用所述第二节点公钥对所述信息密文进行解密失败,则生成第一失败响应,将所述第一失败响应返回至所述电子病历存储设备。If the decryption of the information ciphertext using the second node public key fails, a first failure response is generated, and the first failure response is returned to the electronic medical record storage device.
  5. 根据权利要求1所述的方法,其特征在于,所述如果采用所述第二节点公钥对所述信息密文进行解密成功,则在对所述信息密文进行解密得到的第二初始密文中提取交互信息,存储所述交互信息,包括:The method according to claim 1, wherein if the second node public key is used to decrypt the information ciphertext successfully, then the second initial ciphertext obtained by decrypting the information ciphertext is successfully Extracting interactive information from the text and storing the interactive information includes:
    如果采用所述第二节点公钥对所述信息密文进行解密成功,则获取对所述信息密文解密后的所述第二初始密文;If the information ciphertext is successfully decrypted by using the second node public key, obtaining the second initial ciphertext after decrypting the information ciphertext;
    采用所述第一节点私钥对所述第二初始密文进行解密,得到所述交互信息,并存储所述交互信息。Use the first node private key to decrypt the second initial ciphertext to obtain the interactive information, and store the interactive information.
  6. 一种信息交互方法,其特征在于,包括:An information interaction method, characterized in that it comprises:
    当接收到第一节点传输的交互密文时,电子病历存储设备确定所述第一节点请求进行信息交互的第二节点,所述第一节点和所述第二节点为进行信息交互的节点,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的;When receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction, and the first node and the second node are nodes for information interaction, The interaction ciphertext is generated by the first node based on an information interaction request carrying an information identifier to be interacted;
    将所述交互密文传输至所述第二节点;Transmitting the interactive ciphertext to the second node;
    如果接收到所述第二节点在接收到所述交互密文后返回的信息密文,则将所述信息密文返回给所述第一节点,所述信息密文由所述第二节点基于所述待交互信息标识指示的交互信息生成。If the information ciphertext returned by the second node after receiving the interactive ciphertext is received, the information ciphertext is returned to the first node, and the information ciphertext is based on the second node The interaction information indicated by the to-be-interaction information identifier is generated.
  7. 根据权利要求6所述的方法,其特征在于,所述方法还包括:The method according to claim 6, wherein the method further comprises:
    当接收到所述第一节点传输的第一节点身份信息以及第一节点公钥时,将所述第一节点身份信息以及所述第一节点公钥进行绑定;Binding the first node identity information and the first node public key when receiving the first node identity information and the first node public key transmitted by the first node;
    采用所述第一节点公钥对绑定后的所述第一节点身份信息以及所述第一节点公钥进行签名,生成并注册第一数字证书;Use the first node public key to sign the bound first node identity information and the first node public key, and generate and register a first digital certificate;
    将所述第一数字证书传输至所述第一节点,并将所述第一节点身份信息以及所述第一数字证书对应存储。The first digital certificate is transmitted to the first node, and the first node identity information and the first digital certificate are correspondingly stored.
  8. 根据权利要求6所述的方法,其特征在于,所述当接收到第一节点传输的交互密文时,电子病历存储设备确定所述第一节点指示的第二节点之前,所述方法还包括:The method according to claim 6, wherein when the interactive ciphertext transmitted by the first node is received, before the electronic medical record storage device determines the second node indicated by the first node, the method further comprises :
    当接收到所述第一节点传输的证书查询请求时,在所述证书查询请求中提取第二节点标识;When receiving the certificate query request transmitted by the first node, extract the second node identifier from the certificate query request;
    获取所述第二节点标识指示的第二数字证书,将所述第二数字证书传输至所述第一节点。Obtain a second digital certificate indicated by the second node identifier, and transmit the second digital certificate to the first node.
  9. 根据权利要求6所述的方法,其特征在于,所述方法还包括:The method according to claim 6, wherein the method further comprises:
    如果接收到所述第一节点返回的第一失败响应,则将所述第一失败响应返回至所述第二节点;或,If the first failure response returned by the first node is received, return the first failure response to the second node; or,
    如果接收到所述第二节点返回的第二失败响应,则将所述第二失败响应返回至所述第一节点。If the second failure response returned by the second node is received, the second failure response is returned to the first node.
  10. 一种信息交互方法,其特征在于,包括:An information interaction method, characterized in that it comprises:
    当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点的第一数字证书,采用所述第一数字证书中的第一节点公钥对所述交互密文进行解密,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的,所述第一节点为请求与所述第二节点进行信息交互的节点;When receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, and uses the first node public key in the first digital certificate to decrypt the interactive ciphertext, The interaction ciphertext is generated by the first node based on an information interaction request carrying an information identifier to be interacted, and the first node is a node that requests information interaction with the second node;
    如果采用所述第一节点公钥对所述交互密文进行解密成功,则在解密后的所述交互密文中提取第一初始密文,所述第一初始密文由所述第一节点对所述信息交互请求加密后生成;If the first node public key is used to successfully decrypt the interactive ciphertext, a first initial ciphertext is extracted from the decrypted interactive ciphertext, and the first initial ciphertext is paired by the first node The information exchange request is generated after encryption;
    获取第二节点私钥,采用所述第二节点私钥对所述第一初始密文进行解密,得到所述待交互信息标识;Acquiring a second node private key, decrypting the first initial ciphertext using the second node private key, to obtain the information identification to be interacted;
    提取所述待交互信息标识指示的交互信息,基于所述交互信息生成信息密文,将所述信息密文传输至所述电子病历存储设备。The interaction information indicated by the identification of the information to be interacted is extracted, an information ciphertext is generated based on the interaction information, and the information ciphertext is transmitted to the electronic medical record storage device.
  11. 一种信息交互装置,其特征在于,包括:An information interaction device, characterized by comprising:
    第一加密模块,用于当检测到用户请求与第二节点进行信息交互时,第一节点获取所述第二节点的第二数字证书,采用所述第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文;The first encryption module is configured to, when it is detected that the user requests to exchange information with the second node, the first node obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate Encrypt the identification of the interactive information to generate the first initial ciphertext;
    第二加密模块,用于获取第一节点私钥,采用所述第一节点私钥对所述第一初始密文进行加密,生成交互密文,将所述交互密文传输至电子病历存储设备;The second encryption module is configured to obtain the private key of the first node, encrypt the first initial ciphertext with the private key of the first node, generate an interactive ciphertext, and transmit the interactive ciphertext to an electronic medical record storage device ;
    解密模块,用于接收所述电子病历存储设备返回的信息密文,采用所述第二节点公钥对所述信息密文进行解密,所述信息密文由所述第二节点接收到所述电子病历存储设备传输的所述交互密文后生成并传输至所述电子病历存储设备;The decryption module is configured to receive the information ciphertext returned by the electronic medical record storage device, and decrypt the information ciphertext using the second node public key, and the information ciphertext is received by the second node The interactive ciphertext transmitted by the electronic medical record storage device is generated and transmitted to the electronic medical record storage device;
    存储模块,用于如果采用所述第二节点公钥对所述信息密文进行解密成功,则在对所述信息密文进行解密得到的第二初始密文中提取交互信息,存储所述交互信息,所述第二初始密文由所述第二节点基于所述交互信息加密得到。A storage module, configured to extract interactive information from the second initial ciphertext obtained by decrypting the information ciphertext, and store the interactive information if the information ciphertext is successfully decrypted using the second node public key , The second initial ciphertext is obtained by encrypting the second node based on the interaction information.
  12. 一种信息交互装置,其特征在于,包括:An information interaction device, characterized by comprising:
    确定模块,用于当接收到第一节点传输的交互密文时,电子病历存储设备确定所述第一节点请求进行信息交互的第二节点,所述第一节点和所述第二节点为进行信息交互的节点,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的;The determining module is configured to, when receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction, and the first node and the second node are An information interaction node, where the interaction ciphertext is generated by the first node based on an information interaction request carrying an identification of the information to be interacted;
    第一传输模块,用于将所述交互密文传输至所述第二节点;A first transmission module, configured to transmit the interactive ciphertext to the second node;
    返回模块,用于如果接收到所述第二节点在接收到所述交互密文 后返回的信息密文,则将所述信息密文返回给所述第一节点,所述信息密文由所述第二节点基于所述待交互信息标识指示的交互信息生成。The return module is configured to return the information ciphertext to the first node if the information ciphertext returned by the second node after receiving the interactive ciphertext is received, and the information ciphertext is The second node is generated based on the interaction information indicated by the to-be-interaction information identifier.
  13. 一种信息交互装置,其特征在于,包括:An information interaction device, characterized by comprising:
    第一解密模块,用于当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点的第一数字证书,采用所述第一数字证书中的第一节点公钥对所述交互密文进行解密,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的,所述第一节点为请求与所述第二节点进行信息交互的节点;The first decryption module is configured to, when receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, and uses the public key of the first node in the first digital certificate to Decrypting the interactive ciphertext, the interactive ciphertext is generated by the first node based on an information interaction request carrying an identification of the information to be interacted, and the first node is a node that requests information interaction with the second node;
    提取模块,用于如果采用所述第一节点公钥对所述交互密文进行解密成功,则在解密后的所述交互密文中提取第一初始密文,所述第一初始密文由所述第一节点对所述信息交互请求加密后生成;The extraction module is configured to extract a first initial ciphertext from the decrypted interactive ciphertext if the public key of the first node is used to decrypt the interactive ciphertext, and the first initial ciphertext is The first node encrypts the information exchange request and generates it;
    第二解密模块,用于获取第二节点私钥,采用所述第二节点私钥对所述第一初始密文进行解密,得到所述待交互信息标识;The second decryption module is configured to obtain a second node private key, and use the second node private key to decrypt the first initial ciphertext to obtain the information identification to be interacted;
    传输模块,用于提取所述待交互信息标识指示的交互信息,基于所述交互信息生成信息密文,将所述信息密文传输至所述电子病历存储设备。The transmission module is configured to extract the interaction information indicated by the identification of the information to be interacted, generate an information ciphertext based on the interaction information, and transmit the information ciphertext to the electronic medical record storage device.
  14. 一种计算机设备,包括存储器、处理器以及存储在所述存储器中并可在所述处理器上运行的计算机可读指令,其特征在于,所述处理器执行所述计算机可读指令时实现如下步骤:A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and capable of running on the processor, wherein the processor executes the computer-readable instructions as follows step:
    当检测到用户请求与第二节点进行信息交互时,第一节点获取所述第二节点的第二数字证书,采用所述第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文;When detecting that the user requests information interaction with the second node, the first node obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate to encrypt the information identification to be interacted, Generate the first initial ciphertext;
    获取第一节点私钥,采用所述第一节点私钥对所述第一初始密文进行加密,生成交互密文,将所述交互密文传输至电子病历存储设备;Acquiring a first node private key, encrypting the first initial ciphertext using the first node private key, generating an interactive ciphertext, and transmitting the interactive ciphertext to an electronic medical record storage device;
    接收所述电子病历存储设备返回的信息密文,采用所述第二节点 公钥对所述信息密文进行解密,所述信息密文由所述第二节点接收到所述电子病历存储设备传输的所述交互密文后生成并传输至所述电子病历存储设备;Receive the information ciphertext returned by the electronic medical record storage device, decrypt the information ciphertext using the public key of the second node, and the information ciphertext is received by the second node and transmitted by the electronic medical record storage device After the interactive ciphertext is generated and transmitted to the electronic medical record storage device;
    如果采用所述第二节点公钥对所述信息密文进行解密成功,则在对所述信息密文进行解密得到的第二初始密文中提取交互信息,存储所述交互信息,所述第二初始密文由所述第二节点基于所述交互信息加密得到。If the second node public key is used to decrypt the information ciphertext successfully, then the interactive information is extracted from the second initial ciphertext obtained by decrypting the information ciphertext, the interactive information is stored, and the second The initial ciphertext is encrypted by the second node based on the interaction information.
  15. 根据权利要求14所述的计算机设备,其特征在于,所述处理器执行所述计算机可读指令时还实现如下步骤:The computer device according to claim 14, wherein the processor further implements the following steps when executing the computer-readable instruction:
    当检测到用户请求注册时,将第一节点身份信息以及第一节点公钥传输至所述电子病历存储设备,所述第一节点身份信息至少包括医院名称信息、医院属性信息;When it is detected that the user requests registration, the first node identity information and the first node public key are transmitted to the electronic medical record storage device, and the first node identity information includes at least hospital name information and hospital attribute information;
    接收所述电子病历存储设备返回的第一数字证书,并存储所述第一数字证书,所述第一数字证书由所述电子病历存储设备对所述第一节点身份信息以及所述第一节点公钥进行签名后生成。Receive the first digital certificate returned by the electronic medical record storage device, and store the first digital certificate. The first digital certificate is used by the electronic medical record storage device to verify the identity information of the first node and the first node The public key is generated after signing.
  16. 一种计算机设备,包括存储器、处理器以及存储在所述存储器中并可在所述处理器上运行的计算机可读指令,其特征在于,所述处理器执行所述计算机可读指令时实现如下步骤:A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and capable of running on the processor, wherein the processor executes the computer-readable instructions as follows step:
    当接收到第一节点传输的交互密文时,电子病历存储设备确定所述第一节点请求进行信息交互的第二节点,所述第一节点和所述第二节点为进行信息交互的节点,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的;When receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction, and the first node and the second node are nodes for information interaction, The interaction ciphertext is generated by the first node based on an information interaction request carrying an information identifier to be interacted;
    将所述交互密文传输至所述第二节点;Transmitting the interactive ciphertext to the second node;
    如果接收到所述第二节点在接收到所述交互密文后返回的信息密文,则将所述信息密文返回给所述第一节点,所述信息密文由所述第二节点基于所述待交互信息标识指示的交互信息生成。If the information ciphertext returned by the second node after receiving the interactive ciphertext is received, the information ciphertext is returned to the first node, and the information ciphertext is based on the second node The interaction information indicated by the to-be-interaction information identifier is generated.
  17. 一种计算机设备,包括存储器、处理器以及存储在所述存储器中并可在所述处理器上运行的计算机可读指令,其特征在于,所述 处理器执行所述计算机可读指令时实现如下步骤:A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and capable of running on the processor, wherein the processor executes the computer-readable instructions as follows step:
    当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点的第一数字证书,采用所述第一数字证书中的第一节点公钥对所述交互密文进行解密,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的,所述第一节点为请求与所述第二节点进行信息交互的节点;When receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, and uses the first node public key in the first digital certificate to decrypt the interactive ciphertext, The interaction ciphertext is generated by the first node based on an information interaction request carrying an information identifier to be interacted, and the first node is a node that requests information interaction with the second node;
    如果采用所述第一节点公钥对所述交互密文进行解密成功,则在解密后的所述交互密文中提取第一初始密文,所述第一初始密文由所述第一节点对所述信息交互请求加密后生成;If the first node public key is used to successfully decrypt the interactive ciphertext, a first initial ciphertext is extracted from the decrypted interactive ciphertext, and the first initial ciphertext is paired by the first node The information exchange request is generated after encryption;
    获取第二节点私钥,采用所述第二节点私钥对所述第一初始密文进行解密,得到所述待交互信息标识;Acquiring a second node private key, decrypting the first initial ciphertext using the second node private key, to obtain the information identification to be interacted;
    提取所述待交互信息标识指示的交互信息,基于所述交互信息生成信息密文,将所述信息密文传输至所述电子病历存储设备。The interaction information indicated by the identification of the information to be interacted is extracted, an information ciphertext is generated based on the interaction information, and the information ciphertext is transmitted to the electronic medical record storage device.
  18. 一种计算机非易失性可读存储介质,所述计算机非易失性可读存储介质存储有计算机可读指令,其特征在于,所述计算机可读指令被处理器执行时实现如下步骤:A computer non-volatile readable storage medium, the computer non-volatile readable storage medium storing computer readable instructions, wherein the computer readable instructions are executed by a processor to implement the following steps:
    当检测到用户请求与第二节点进行信息交互时,第一节点获取所述第二节点的第二数字证书,采用所述第二数字证书中的第二节点公钥对待交互信息标识进行加密,生成第一初始密文;When detecting that the user requests information interaction with the second node, the first node obtains the second digital certificate of the second node, and uses the second node public key in the second digital certificate to encrypt the information identification to be interacted, Generate the first initial ciphertext;
    获取第一节点私钥,采用所述第一节点私钥对所述第一初始密文进行加密,生成交互密文,将所述交互密文传输至电子病历存储设备;Acquiring a first node private key, encrypting the first initial ciphertext using the first node private key, generating an interactive ciphertext, and transmitting the interactive ciphertext to an electronic medical record storage device;
    接收所述电子病历存储设备返回的信息密文,采用所述第二节点公钥对所述信息密文进行解密,所述信息密文由所述第二节点接收到所述电子病历存储设备传输的所述交互密文后生成并传输至所述电子病历存储设备;Receive the information ciphertext returned by the electronic medical record storage device, decrypt the information ciphertext using the public key of the second node, and the information ciphertext is received by the second node and transmitted by the electronic medical record storage device After the interactive ciphertext is generated and transmitted to the electronic medical record storage device;
    如果采用所述第二节点公钥对所述信息密文进行解密成功,则在对所述信息密文进行解密得到的第二初始密文中提取交互信息, 存储所述交互信息,所述第二初始密文由所述第二节点基于所述交互信息加密得到。If the information ciphertext is successfully decrypted by using the second node public key, the interactive information is extracted from the second initial ciphertext obtained by decrypting the information ciphertext, and the interactive information is stored. The initial ciphertext is encrypted by the second node based on the interactive information.
  19. 一种计算机非易失性可读存储介质,所述计算机非易失性可读存储介质存储有计算机可读指令,其特征在于,所述计算机可读指令被处理器执行时实现如下步骤:A computer non-volatile readable storage medium, the computer non-volatile readable storage medium storing computer readable instructions, wherein the computer readable instructions are executed by a processor to implement the following steps:
    当接收到第一节点传输的交互密文时,电子病历存储设备确定所述第一节点请求进行信息交互的第二节点,所述第一节点和所述第二节点为进行信息交互的节点,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的;When receiving the interactive ciphertext transmitted by the first node, the electronic medical record storage device determines the second node that the first node requests for information interaction, and the first node and the second node are nodes for information interaction, The interaction ciphertext is generated by the first node based on an information interaction request carrying an information identifier to be interacted;
    将所述交互密文传输至所述第二节点;Transmitting the interactive ciphertext to the second node;
    如果接收到所述第二节点在接收到所述交互密文后返回的信息密文,则将所述信息密文返回给所述第一节点,所述信息密文由所述第二节点基于所述待交互信息标识指示的交互信息生成。If the information ciphertext returned by the second node after receiving the interactive ciphertext is received, the information ciphertext is returned to the first node, and the information ciphertext is based on the second node The interaction information indicated by the to-be-interaction information identifier is generated.
  20. 一种计算机非易失性可读存储介质,所述计算机非易失性可读存储介质存储有计算机可读指令,其特征在于,所述计算机可读指令被处理器执行时实现如下步骤:A computer non-volatile readable storage medium, the computer non-volatile readable storage medium storing computer readable instructions, wherein the computer readable instructions are executed by a processor to implement the following steps:
    当接收到电子病历存储设备传输的交互密文时,第二节点获取第一节点的第一数字证书,采用所述第一数字证书中的第一节点公钥对所述交互密文进行解密,所述交互密文由所述第一节点基于携带待交互信息标识的信息交互请求生成的,所述第一节点为请求与所述第二节点进行信息交互的节点;When receiving the interactive ciphertext transmitted by the electronic medical record storage device, the second node obtains the first digital certificate of the first node, and uses the first node public key in the first digital certificate to decrypt the interactive ciphertext, The interaction ciphertext is generated by the first node based on an information interaction request carrying an information identifier to be interacted, and the first node is a node that requests information interaction with the second node;
    如果采用所述第一节点公钥对所述交互密文进行解密成功,则在解密后的所述交互密文中提取第一初始密文,所述第一初始密文由所述第一节点对所述信息交互请求加密后生成;If the first node public key is used to successfully decrypt the interactive ciphertext, a first initial ciphertext is extracted from the decrypted interactive ciphertext, and the first initial ciphertext is paired by the first node The information exchange request is generated after encryption;
    获取第二节点私钥,采用所述第二节点私钥对所述第一初始密文进行解密,得到所述待交互信息标识;Acquiring a second node private key, decrypting the first initial ciphertext using the second node private key, to obtain the information identification to be interacted;
    提取所述待交互信息标识指示的交互信息,基于所述交互信息生成信息密文,将所述信息密文传输至所述电子病历存储设备。The interaction information indicated by the identification of the information to be interacted is extracted, an information ciphertext is generated based on the interaction information, and the information ciphertext is transmitted to the electronic medical record storage device.
PCT/CN2019/123141 2019-05-10 2019-12-05 Information interaction method and apparatus, and computer device and readable storage medium WO2020228304A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910390295.0 2019-05-10
CN201910390295.0A CN110224989B (en) 2019-05-10 2019-05-10 Information interaction method and device, computer equipment and readable storage medium

Publications (1)

Publication Number Publication Date
WO2020228304A1 true WO2020228304A1 (en) 2020-11-19

Family

ID=67820994

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/123141 WO2020228304A1 (en) 2019-05-10 2019-12-05 Information interaction method and apparatus, and computer device and readable storage medium

Country Status (2)

Country Link
CN (1) CN110224989B (en)
WO (1) WO2020228304A1 (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110224989B (en) * 2019-05-10 2022-01-28 深圳壹账通智能科技有限公司 Information interaction method and device, computer equipment and readable storage medium
CN111526128B (en) * 2020-03-31 2022-07-19 中国建设银行股份有限公司 Encryption management method and device

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160277374A1 (en) * 2011-10-31 2016-09-22 Reid Consulting Group System and method for securely storing and sharing information
WO2016180264A1 (en) * 2015-05-13 2016-11-17 阿里巴巴集团控股有限公司 Method and apparatus for acquiring an electronic file
CN106295393A (en) * 2015-06-26 2017-01-04 阿里巴巴集团控股有限公司 Electronic prescription operational approach, Apparatus and system
CN109544331A (en) * 2018-10-12 2019-03-29 深圳壹账通智能科技有限公司 Supply chain financial application method, apparatus and terminal device based on block chain
CN110049016A (en) * 2019-03-21 2019-07-23 深圳壹账通智能科技有限公司 Data query method, apparatus, system, equipment and the storage medium of block chain
CN110224989A (en) * 2019-05-10 2019-09-10 深圳壹账通智能科技有限公司 Information interacting method, device, computer equipment and readable storage medium storing program for executing

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103220295A (en) * 2013-04-26 2013-07-24 福建伊时代信息科技股份有限公司 Document encryption and decryption method, device and system
CN104022883B (en) * 2014-06-17 2017-03-15 烟台大学 A kind of personal information protection shopping at network technology based on logistics network
CN105471826B (en) * 2014-09-04 2019-08-20 中电长城网际系统应用有限公司 Ciphertext data query method, apparatus and cryptogram search server
CN106533665B (en) * 2016-10-31 2018-08-07 北京百度网讯科技有限公司 Mthods, systems and devices for storing website private key plaintext
CN106789008B (en) * 2016-12-16 2020-02-28 北京瑞卓喜投科技发展有限公司 Method, device and system for decrypting sharable encrypted data
CN106713338A (en) * 2017-01-03 2017-05-24 上海金融云服务集团安全技术有限公司 Long connection tunnel establishment method based on server hardware information
CN107896213B (en) * 2017-11-16 2021-07-20 重庆顺利科技有限公司 Electronic prescription data storage method
CN109299149B (en) * 2018-10-09 2020-07-14 北京腾云天下科技有限公司 Data query method, computing device and system
CN109587132B (en) * 2018-11-29 2021-03-26 南京苏宁软件技术有限公司 Data transmission method and device based on alliance chain

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160277374A1 (en) * 2011-10-31 2016-09-22 Reid Consulting Group System and method for securely storing and sharing information
WO2016180264A1 (en) * 2015-05-13 2016-11-17 阿里巴巴集团控股有限公司 Method and apparatus for acquiring an electronic file
CN106295393A (en) * 2015-06-26 2017-01-04 阿里巴巴集团控股有限公司 Electronic prescription operational approach, Apparatus and system
CN109544331A (en) * 2018-10-12 2019-03-29 深圳壹账通智能科技有限公司 Supply chain financial application method, apparatus and terminal device based on block chain
CN110049016A (en) * 2019-03-21 2019-07-23 深圳壹账通智能科技有限公司 Data query method, apparatus, system, equipment and the storage medium of block chain
CN110224989A (en) * 2019-05-10 2019-09-10 深圳壹账通智能科技有限公司 Information interacting method, device, computer equipment and readable storage medium storing program for executing

Also Published As

Publication number Publication date
CN110224989B (en) 2022-01-28
CN110224989A (en) 2019-09-10

Similar Documents

Publication Publication Date Title
CN110086608B (en) User authentication method, device, computer equipment and computer readable storage medium
WO2020192773A1 (en) Digital identity authentication method, device, apparatus and system, and storage medium
WO2018050081A1 (en) Device identity authentication method and apparatus, electric device, and storage medium
CN110049016B (en) Data query method, device, system, equipment and storage medium of block chain
Jiang et al. A privacy enhanced authentication scheme for telecare medical information systems
EP3611871B1 (en) Technologies for synchronizing and restoring reference templates
Li et al. A secure chaotic maps and smart cards based password authentication and key agreement scheme with user anonymity for telecare medicine information systems
CN103595703B (en) Linux safety file transmission system based on OpenSSL and Linux safety file transmission method based on OpenSSL
US11134069B2 (en) Method for authorizing access and apparatus using the method
WO2020186822A1 (en) Blockchain-based data querying method, device and apparatus, and readable storage medium
WO2020168772A1 (en) Electronic medical record storing method, system, apparatus, and device, and medium
WO2016202207A1 (en) Method and device for obtaining electronic document
US20110167263A1 (en) Wireless connections to a wireless access point
JP2001186122A (en) Authentication system and authentication method
WO2020228304A1 (en) Information interaction method and apparatus, and computer device and readable storage medium
EP4096160A1 (en) Shared secret implementation of proxied cryptographic keys
Sethia et al. Smart health record management with secure NFC-enabled mobile devices
CN102143190B (en) Safe login method and device
CN103916237B (en) Method and system for managing user encrypted-key retrieval
CN111225001A (en) Block chain decentralized communication method, electronic equipment and system
CN113545004A (en) Authentication system with reduced attack surface
US8312277B2 (en) Method and system for secure communication between computers
CN112637128B (en) Identity mutual trust method and system for data center host
KR100993333B1 (en) Method for enrollment and authentication using private internet access devices and system
JP2005086428A (en) Method of obtaining authentication and performing crypto communication, authenticating system and authenticating method

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19928895

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205 DATED 01/03/2022)

122 Ep: pct application non-entry in european phase

Ref document number: 19928895

Country of ref document: EP

Kind code of ref document: A1