Towards Strengthening the Security of Healthcare Devices using Secure Configuration Provenance

Towards Strengthening the Security of Healthcare Devices using Secure Configuration Provenance
复制标题

DOI:
10.1109/icdh55609.2022.00043
复制
发表时间:
2022-07
期刊:
2022 IEEE International Conference on Digital Health (ICDH)
影响因子:
--
通讯作者:
Ragib Hasan
Ragib Hasan
中科院分区:
其他
文献类型:
--
作者:
Ragib Hasan

文献摘要

相似文献

在现代医疗保健中,智能医疗设备用于确保更好和更明智的患者护理。这些设备能够通过wi-fi或蓝牙连接到医院网络或移动的应用程序并与之通信,从而允许医生远程配置它们、交换数据或更新固件。例如,心血管植入式电子设备(CIED),通常称为起搏器,越来越智能,连接到云或医疗信息系统,并能够远程编程。医疗保健提供者可以将新配置上传到此类设备以更改治疗。这样的配置通常被交换、重复使用和/或修改以匹配患者的特定健康场景。不幸的是,这种能力是有代价的。恶意实体可能为此类设备提供错误配置,导致患者死亡。对此类设备的状态或配置的任何更新都必须在将其应用于设备之前进行彻底审查。如果发生任何不良事件,我们还必须能够跟踪错误配置的沿袭和传播,以确定原因和责任问题。在高度分布式的环境中,例如今天的医院,确保配置和安全策略的完整性是困难的,并且通常需要复杂的设置。随着配置的传播,应用配置的健康护理提供者的传统访问控制和认证不足以防止恶意配置的安装。在本文中,我们认为,一个基于出处的方法可以提供一个有效的解决方案,加强这种医疗设备的安全性。在这种方法中,设备将保持可验证的出处链,其将允许不仅评估设备的当前状态,而且还评估设备的配置的过去历史。此外,任何配置更新都将伴随着其自己的安全出处链,允许验证配置的起源和血统。保护和验证设备和配置来源的能力将导致更好的患者护理,防止由于恶意配置导致的设备故障,并允许对设备配置问题进行事后调查。在本文中,我们提倡这种方法的好处,并勾勒出这样一个基于出处的系统的要求,实施挑战和部署策略。
In modern healthcare, smart medical devices are used to ensure better and informed patient care. Such devices have the capability to connect to and communicate with the hospital's network or a mobile application over wi-fi or Bluetooth, allowing doctors to remotely configure them, exchange data, or update the firmware. For example, Cardiovascular Implantable Electronic Devices (CIED), more commonly known as Pacemakers, are increasingly becoming smarter, connected to the cloud or healthcare information systems, and capable of being programmed remotely. Healthcare providers can upload new configurations to such devices to change the treatment. Such configurations are often exchanged, reused, and/or modified to match the patient's specific health scenario. Such capabilities, unfortunately, come at a price. Malicious entities can provide a faulty configuration to such devices, leading to the patient's death. Any update to the state or configuration of such devices must be thoroughly vetted before applying them to the device. In case of any adverse events, we must also be able to trace the lineage and propagation of the faulty configuration to determine the cause and liability issues. In a highly distributed environment such as today's hospitals, ensuring the integrity of configurations and security policies is difficult and often requires a complex setup. As configurations propagate, traditional access control and authentication of the healthcare provider applying the configuration is not enough to prevent installation of malicious configurations. In this paper, we argue that a provenance-based approach can provide an effective solution towards hardening the security of such medical devices. In this approach, devices would maintain a verifiable provenance chain that would allow assessing not just the current state, but also the past history of the configuration of the device. Also, any configuration update would be accompanied by its own secure provenance chain, allowing verification of the origin and lineage of the configuration. The ability to protect and verify the provenance of devices and configurations would lead to better patient care, prevent malfunction of the device due to malicious configurations, and allow after-the-fact investigation of device configuration issues. In this paper, we advocate the benefits of such an approach and sketch the requirements, implementation challenges, and deployment strategies for such a provenance-based system.