首页> 外文会议>International conference on security management >Towards Security Policy and Architecture for Managing Implantable Medical Devices
【24h】

Towards Security Policy and Architecture for Managing Implantable Medical Devices

机译:面向用于管理植入式医疗设备的安全策略和体系结构

获取原文

摘要

Implantable cardiac rhythm management devices (CRMDs) such as permanent pacemakers and internal car-dioverter defibrillators (ICDs) utilize embedded computers and radios to monitor chronic disorders and treat patients. Life-saving devices like ICDs, for instance, include pacemaker technology and are designed to communicate wirelessly with a nearby external device programmer (EDP) that can remotely read data and change settings without the need for surgery. An ICD implanted in a patient can sense a rapid heartbeat and administer an electric shock to restore normal heart rhythm. It is has been shown that current ICDs in the market can be reverse engineered and are prone to software radio-based attacks. The ICDs can be remotely disabled or be made to administer an electric shock at random. Existing defense mechanisms include a simple cryptographic approach where a symmetric-key based challenge-response protocol is used between the ICD and an authorized EDP. This approach does not scale. In the real world, large scale deployment and management of shared key material amongst various entities such as CRMDs, EDPs, hospitals, clinics, and ambulances is a major issue. In this paper, we investigate security policy issues applicable to the CRMD ecosystem and issues for architectures that enforce the policy. Given the nature of this domain, these solutions will need to balance security, privacy and risk. For instance, an unauthorized EDP may need to issue a command to the ICD in emergency situations.
机译:植入式心律管理设备(CRMD),例如永久性起搏器和内置式心律转复除颤器(ICD),都使用嵌入式计算机和无线电来监视慢性疾病并治疗患者。例如,诸如ICD之类的救生设备包括起搏器技术,旨在与附近的外部设备编程器(EDP)无线通信,该设备可以远程读取数据并更改设置,而无需进行手术。植入患者的ICD可以感觉到快速的心跳并进行电击,以恢复正常的心律。已经证明,当前市场上的ICD可以进行逆向工程,并且容易受到基于软件无线电的攻击。 ICD可以远程禁用,也可以随机进行电击。现有的防御机制包括一种简单的加密方法,其中在ICD和授权的EDP之间使用基于对称密钥的质询-响应协议。这种方法无法扩展。在现实世界中,在CRMD,EDP,医院,诊所和救护车等各种实体之间大规模部署和管理共享关键材料是一个主要问题。在本文中,我们调查了适用于CRMD生态系统的安全策略问题以及实施该策略的体系结构的问题。考虑到该域的性质,这些解决方案将需要平衡安全性,隐私性和风险。例如,在紧急情况下,未授权的EDP可能需要向ICD发出命令。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号