security and privacy for implantable medical devices presented by : dilip simha.c.r

28
Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R.

Upload: berniece-hunt

Post on 12-Jan-2016

218 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Security and Privacy for Implantable Medical Devices

Presented by : Dilip Simha.C.R.

Page 2: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Authors and Publication

• Daniel Halperin, Thomas S. Heydt-Benjamin, Kevin Fu, Tadayoshi Kohno, and William H. Maisel

• Pervasive Computing, IEEE  (Volume:7, Issue: 1 )

Page 3: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Topics

• What are IMD’s?.• Need of Security and Privacy.• Design issues• Types of intruders• Methods to deal with security issues• Tensions• Future research

Page 4: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

What are Implantable Medical Devices

• Monitor and treat physiological conditions.• Placed inside the body• Examples

• Pacemakers• ICD’s(Implantable cardiac defibrillators)• Drug delivery systems• Neurostimulators

Page 5: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Importance of IMD’s

• Used in treatment of diseases like• Cardiac arrhythmia• Diabetes • Parkinson’s disease

• Over 25 million US citizens are dependent on IMD’s.

Page 6: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Modern day IMD’s

• Enable remote monitoring over long-range• Communicate with other interoperating

IMD’s

Page 7: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Criteria for design of IMD’s

• Safety and Utility goals• Security and Privacy goals

Page 8: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Safety and Utility goals

• Data accuracy• Device Identification• Configurability• Updatable Software• Multidevice Coordination• Auditable

Page 9: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Data accuracy

• Measured and stored data should be accurate.

• Incudes data about physiological conditions and timing.

Page 10: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Device Identification

• Authorized personnel must detect the presence of IMD’s.

• Example- ICD’s removal before heart surgery• FDA considered attaching RFID(Radio

Frequency ID) to IMD’s.

Page 11: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Configurability

• Authorized personnel must be able to change IMD settings.

• ICD’s and Open loop Insulin pumps.

Page 12: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Updatable Software

• Appropriately engineered updates are necessary

• Updates need to come from authorized personnel

Page 13: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Multidevice Coordination

• Current IMD’s have some examples of coordination• CROS(Contralateral routing of signals) hearing Aid.

• Projected future devices use more coordination• closed loop insulin delivery system

Page 14: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Auditable

• In case of failure• Device’s operational history to manufacturers.

• Might differ from the data received by healthcare professionals.

Page 15: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Resource Efficient

• Power consumption• More energy for wireless communications.• Must minimize computation and communication.

• Data storage requirements

Page 16: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Security and Privacy Goals

• Authorization• Availability• Device software and settings• Device Existence Privacy• Device-type privacy• Specific Device ID privacy• Measurement and Log privacy• Bearer privacy• Data integrity

Page 17: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Authorization

• Personal Authorization• Specific basic rights are granted• Patients and primary-care physicians

• Role-based authorization• Authorized for a set of tasks• Physician or Ambulance Computer

• IMD selection• Only interact with intended devices.

Page 18: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Availability

• DoS attack prevention• Intruder should not be able to

• Drain battery• Overflow data storage• Jam the communication

Page 19: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Device software and settings

• Authorized personnel should only modify IMD’s.

• Avoid accidental malfunctions.

Page 20: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Device existence privacy

• IMD’s are expensive.• Avoid detection by unauthorized personnel.

Page 21: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Specific device ID privacy

• Attacker should not be able to track IMD’s.• Location privacy.

Page 22: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Measurement and log privacy

• Private information about measurements and audit log data.

Page 23: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Bearer Privacy

• Private information of patient• Name• Medical history• Detailed diagnoses.

Page 24: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Data integrity

• Avoid tampering of past data.• Avoid inducing modifications to future data.

Page 25: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Classes of adversaries

• Passive adversaries• Active adversaries• Coordinated adversaries• Insiders

Page 26: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Tensions

• Security v/s Accessibility• Security v/s Device resources• Security v/s Usability

Page 27: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

Research directions

• Fine grained access control• Open access with revocation and second-

factor authentication• Accountability• Patient awareness via secondary channels• Authorization via secondary channels • Shift computation to external devices

Page 28: Security and Privacy for Implantable Medical Devices Presented by : Dilip Simha.C.R

QUESTIONS?