they can hear your heartbeats: non-invasive security for implantable medical devices

19
They Can Hear Your Heartbeats: Non-Invasive Security for Implantable Medical Devices

Upload: ornice

Post on 24-Feb-2016

109 views

Category:

Documents


0 download

DESCRIPTION

They Can Hear Your Heartbeats: Non-Invasive Security for Implantable Medical Devices. Introduction. Implantable Medical Devices ( IMDs ) are vulnerable to exploitation (last paper) Unauthorized data retrieval Malicious commands Millions of IMDs are currently deployed This is a big problem. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

They Can Hear Your Heartbeats:

Non-Invasive Security for Implantable Medical Devices

Page 2: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Introduction

• Implantable Medical Devices (IMDs) are vulnerable to exploitation (last paper)– Unauthorized data retrieval– Malicious commands

• Millions of IMDs are currently deployed– This is a big problem

Page 3: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Implantable Medical Devices (IMDs)

http://wwwp.medtronic.com/newsroom/content/1150828881634.low_resolution.jpg

• Surgically Implanted into a patient’s body

• Facilitates Medical Treatment• i.e. pacemakers, defibrillators,

insulin pumps.

• Communicates Wirelessly• Sends vital sign information• Receives commands

• Battery Powered

Page 4: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

http://groups.csail.mit.edu/netmit/IMDShield/images/WIMD.png

Page 5: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

More IMD Properties

• Does not transmit unless…– It is responding to an IMD programmer– It detects a life-threatening condition

• Does not share channels with other IMDs

Page 6: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

IMD Programmer

http://henkboxma.com/casestudy/2090.gif

• Wirelessly configure IMDs • query IMD for data• send commands to IMD

• Requires no credentials• Good: settings can be changed in

an emergency without hassle• Bad: anyone can use it

• Communicates Wirelessly• Sends vital sign information• Receives commands

Page 7: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Commands Confidential Patient data

Page 8: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Unauthorized Commands

Confidential Patient data

Page 9: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Problems with using crypto

• Inalterability– IMDs last for up to 10 years– IMD replacement requires surgery– IMD hardware is inadequate

• Safety– Immediate access– False negatives

• Maintainability– Bugs/Recalls

Page 10: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Solution: The Shield

• Does not alter IMD

• Protects against Passive and Active Adversaries

• Does not inconvenience patient

• Does not reduce safety of IMD

Page 11: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

The shield passes legitimateCommands along to the IMD

Encrypted Channels

Page 12: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

The shield blocks unauthorized commands

Page 13: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Assumptions

• IMDs and Programmers are honest• The shield is a wearable device such as a

necklace• There is a secure channel between IMD and

the programmer

Page 14: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

http://groups.csail.mit.edu/netmit/IMDShield/images/IMDShield.png

Page 15: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

Jamming

• Jams Eavesdroppers during IMDs transmissions– Does this only when it knows the IMD will transmit

• Jams the IMD during programmer transmissions

• If a signal is detected while the shield is transmitting, it automatically starts jamming

Page 16: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

http://groups.csail.mit.edu/netmit/IMDShield/images/FULLDUPLEX.png

Page 17: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

http://groups.csail.mit.edu/netmit/IMDShield/images/ResultsAC1.png

Page 18: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

http://groups.csail.mit.edu/netmit/IMDShield/images/ResultsAC2.png

Page 19: They Can Hear Your Heartbeats: Non-Invasive Security for  Implantable Medical Devices

The End.