Securing Wireless Neurostimulators

Securing Wireless Neurostimulators
复制标题

确保无线神经刺激器的安全

DOI:
10.1145/3176258.3176310
复制
发表时间:
2018
期刊:
Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
B. Preneel
B. Preneel
中科院分区:
--
文献类型:
--
作者:
Eduard Marin;Dave Singelée;Bohan Yang;V. Volskiy;G. Vandenbosch;B. Nuttin;B. Preneel

文献摘要

被引文献

相似文献

植入式医疗设备(IMD)通常依赖于专有协议与外部设备编程器进行无线通信。在本文中,我们完全逆向工程的专有协议之间的设备编程器和广泛使用的商业神经刺激器从一个领先的IMD制造商。对于逆向工程,我们遵循黑盒方法并使用廉价的硬件设备。我们的文件的消息格式和协议状态机,并表明,在空中发送的传输既不加密,也不验证。此外,我们进行了几个软件无线电为基础的攻击,可能会损害患者的安全和隐私,并调查在真实的情况下执行这些攻击的可行性。我们的研究结果的动机,我们提出了一个安全架构,允许设备程控仪和神经刺激器之间的安全数据交换。它依赖于使用患者的生理信号在神经刺激器中生成对称密钥,并通过秘密带外(OOB)通道将该密钥从神经刺激器传输到器械程控仪。我们的解决方案允许器械程控仪和神经刺激器就对称会话密钥达成一致,而这些器械无需共享任何先前的秘密;在紧急情况下提供安全性和许可访问之间的有效和实用平衡;仅需要对器械进行微小的硬件更改;增加最小的计算和通信开销;并提供前向和后向安全性。最后,我们实现了我们的解决方案的概念验证。
Implantable medical devices (IMDs) typically rely on proprietary protocols to wirelessly communicate with external device programmers. In this paper, we fully reverse engineer the proprietary protocol between a device programmer and a widely used commercial neurostimulator from one of the leading IMD manufacturers. For the reverse engineering, we follow a black-box approach and use inexpensive hardware equipment. We document the message format and the protocol state-machine, and show that the transmissions sent over the air are neither encrypted nor authenticated. Furthermore, we conduct several software radio-based attacks that could compromise the safety and privacy of patients, and investigate the feasibility of performing these attacks in real scenarios. Motivated by our findings, we propose a security architecture that allows for secure data exchange between the device programmer and the neurostimulator. It relies on using a patient»s physiological signal for generating a symmetric key in the neurostimulator, and transporting this key from the neurostimulator to the device programmer through a secret out-of-band (OOB) channel. Our solution allows the device programmer and the neurostimulator to agree on a symmetric session key without these devices needing to share any prior secrets; offers an effective and practical balance between security and permissive access in emergencies; requires only minor hardware changes in the devices; adds minimal computation and communication overhead; and provides forward and backward security. Finally, we implement a proof-of-concept of our solution.