首页> 美国卫生研究院文献>Journal of the American Medical Informatics Association : JAMIA >Encryption Characteristics of Two USB-based Personal Health Record Devices
【2h】

Encryption Characteristics of Two USB-based Personal Health Record Devices

机译:两个基于USB的个人健康记录设备的加密特性

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Personal health records (PHRs) hold great promise for empowering patients and increasing the accuracy and completeness of health information. We reviewed two small USB-based PHR devices that allow a patient to easily store and transport their personal health information. Both devices offer password protection and encryption features. Analysis of the devices shows that they store their data in a Microsoft Access database. Due to a flaw in the encryption of this database, recovering the user’s password can be accomplished with minimal effort. Our analysis also showed that, rather than encrypting health information with the password chosen by the user, the devices stored the user’s password as a string in the database and then encrypted that database with a common password set by the manufacturer. This is another serious vulnerability. This article describes the weaknesses we discovered, outlines three critical flaws with the security model used by the devices, and recommends four guidelines for improving the security of similar devices.
机译:个人健康记录(PHR)在赋予患者权力并提高健康信息的准确性和完整性方面具有广阔的前景。我们回顾了两个基于USB的小型PHR设备,这些设备使患者能够轻松存储和传输其个人健康信息。两种设备均提供密码保护和加密功能。对设备的分析表明,它们将数据存储在Microsoft Access数据库中。由于该数据库的加密存在缺陷,因此可以轻松完成恢复用户密码的操作。我们的分析还显示,设备没有使用用户选择的密码来加密健康信息,而是将用户的密码作为字符串存储在数据库中,然后使用制造商设置的通用密码来加密该数据库。这是另一个严重的漏洞。本文介绍了我们发现的弱点,概述了设备所使用的安全模型的三个关键缺陷,并建议了四项准则来提高类似设备的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号