They can hear your heartbeats: non-invasive security for implantable medical devices

They can hear your heartbeats: non-invasive security for implantable medical devices
复制标题

DOI:
10.1145/2018436.2018438
复制
发表时间:
2011-08
期刊:
Proceedings of the ACM SIGCOMM 2011 conference
影响因子:
--
通讯作者:
Shyamnath Gollakota;Haitham Hassanieh;Benjamin Ransford;D. Katabi;Kevin Fu
Shyamnath Gollakota;Haitham Hassanieh;Benjamin Ransford;D. Katabi;Kevin Fu
中科院分区:
其他
文献类型:
--
作者:
Shyamnath Gollakota;Haitham Hassanieh;Benjamin Ransford;D. Katabi;Kevin Fu

文献摘要

被引文献

相似文献

无线通信已成为现代植入式医疗设备(IMD)的固有部分。然而,最近的工作表明,无线连接可以被利用来破坏IMD传输数据的机密性,或者向IMD发送未经授权的命令-甚至是导致设备向患者提供电击的命令。解决这些攻击的关键挑战来自于修改或更换已经植入的IMD的困难。因此,在本文中,我们探讨了保护植入式设备免受此类攻击的可行性,而无需修改设备本身。我们提出了一个物理层的解决方案,代表IMD的安全性个人基站称为盾牌。该防护罩采用了一种新颖的无线电设计,可以充当干扰机兼接收机。这种设计允许它干扰IMD的消息,防止其他人解码它们,同时能够解码它们。它还允许屏蔽干扰未经授权的命令---甚至是那些试图改变屏蔽本身传输的命令。我们实现我们的设计在一个软件无线电和商业IMD进行评估。我们发现,它有效地提供了保密性的私人数据,并保护IMD未经授权的命令。
Wireless communication has become an intrinsic part of modern implantable medical devices (IMDs). Recent work, however, has demonstrated that wireless connectivity can be exploited to compromise the confidentiality of IMDs' transmitted data or to send unauthorized commands to IMDs---even commands that cause the device to deliver an electric shock to the patient. The key challenge in addressing these attacks stems from the difficulty of modifying or replacing already-implanted IMDs. Thus, in this paper, we explore the feasibility of protecting an implantable device from such attacks without modifying the device itself. We present a physical-layer solution that delegates the security of an IMD to a personal base station called the shield. The shield uses a novel radio design that can act as a jammer-cum-receiver. This design allows it to jam the IMD's messages, preventing others from decoding them while being able to decode them itself. It also allows the shield to jam unauthorized commands---even those that try to alter the shield's own transmissions. We implement our design in a software radio and evaluate it with commercial IMDs. We find that it effectively provides confidentiality for private data and protects the IMD from unauthorized commands.