On a Security-oriented Design Framework for Medical IoT Devices: The Hardware Security Perspective

Konstantinos Nomikos, Athanasios Papadimitriou, G. Stergiopoulos, D. Koutras, M. Psarakis, P. Kotzanikolaou
{"title":"On a Security-oriented Design Framework for Medical IoT Devices: The Hardware Security Perspective","authors":"Konstantinos Nomikos, Athanasios Papadimitriou, G. Stergiopoulos, D. Koutras, M. Psarakis, P. Kotzanikolaou","doi":"10.1109/DSD51259.2020.00056","DOIUrl":null,"url":null,"abstract":"As medical devices more and more use Internet of Things based technologies, serious concerns are raised about their security and the privacy of patient’s personal health data. To address these concerns, while maintaining reasonable overheads, designers of medical devices need to take security into account from the beginning until the completion of their designs. In this work we identify the relevant security domains and focus to the Hardware Security perspective. Additionally, we present a secure design and evaluation framework which can assist designers towards more secure medical devices. The framework integrates a complete insulin pump architecture containing all the basic components used in such applications. To illustrate the advantages of the proposed framework we perform a Side Channel Analysis attack against the embedded encryption algorithm of the device to obtain the secret encryption key. Then, we make use of the framework to identify all the components of the system which are either directly or indirectly affected by the attack. This analysis leads us to determine more complex combined attacks which may complement the SCA attack into compromising the overall security of the system.","PeriodicalId":128527,"journal":{"name":"2020 23rd Euromicro Conference on Digital System Design (DSD)","volume":"4 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 23rd Euromicro Conference on Digital System Design (DSD)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/DSD51259.2020.00056","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

As medical devices more and more use Internet of Things based technologies, serious concerns are raised about their security and the privacy of patient’s personal health data. To address these concerns, while maintaining reasonable overheads, designers of medical devices need to take security into account from the beginning until the completion of their designs. In this work we identify the relevant security domains and focus to the Hardware Security perspective. Additionally, we present a secure design and evaluation framework which can assist designers towards more secure medical devices. The framework integrates a complete insulin pump architecture containing all the basic components used in such applications. To illustrate the advantages of the proposed framework we perform a Side Channel Analysis attack against the embedded encryption algorithm of the device to obtain the secret encryption key. Then, we make use of the framework to identify all the components of the system which are either directly or indirectly affected by the attack. This analysis leads us to determine more complex combined attacks which may complement the SCA attack into compromising the overall security of the system.
医疗物联网设备面向安全的设计框架:硬件安全视角
随着医疗设备越来越多地采用基于物联网的技术,其安全性和患者个人健康数据的隐私性引起了人们的严重关注。为了解决这些问题,在保持合理的管理费用的同时,医疗设备的设计者需要从一开始就考虑到安全性,直到他们的设计完成。在这项工作中,我们确定了相关的安全领域,并将重点放在硬件安全方面。此外,我们提出了一个安全的设计和评估框架,可以帮助设计人员实现更安全的医疗设备。该框架集成了一个完整的胰岛素泵架构,包含此类应用中使用的所有基本组件。为了说明所提出的框架的优点,我们对设备的嵌入式加密算法进行了侧信道分析攻击,以获得秘密加密密钥。然后,我们利用该框架来识别系统中所有直接或间接受到攻击影响的组件。此分析使我们确定更复杂的组合攻击,这些攻击可能会补充SCA攻击,从而危及系统的整体安全性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信