Title :
Adrasteia: A Smartphone App for Securing Legacy Mobile Medical Devices
Author :
Pournaghshband, Vahab ; Meyer, David ; Holyland, Michael ; Sarrafzadeh, Majid ; Reiher, Peter
Author_Institution :
Comput. Sci. Dept., California State Univ., Northridge, CA, USA
Abstract :
For a variety of reasons, Bluetooth-enabled mobile medical devices are often not designed with security in mind. As a result, many of them are open to malicious attacks, notably man-in-the-middle (MITM) attacks. For some classes of mobile medical devices, such as pulse oximeters, a MITM attack may have little impact on the safety and privacy of the patient. For more essential devices, such as pacemakers and insulin pumps, protection against MITM attacks can have fatal consequences. Though future medical devices may be designed more securely, a significant portion of existing medical devices still use an overly trusting procedure to communicate with their desired access point. Thus, these legacy devices are still at risk of attack. This paper presents the design and implementation of an Android application to act as a personal security device (PSD) that defends against MITM attacks. To the best of our knowledge, this is the first smartphone application designed for this purpose. The use of this PSD requires no changes to either the medical device or its monitoring software, offers protection for millions of existing devices, and adds an insignificant amount of overhead to the original functionality of the medical device. Furthermore, the PSD is easily obtainable by anyone with an Android smartphone. We evaluate our defence approach by analyzing its robustness against various attacks, and we conclude with a discussion of future applications of our defense mechanism.
Keywords :
data privacy; medical computing; mobile computing; security of data; smart phones; Adrasteia; Android application; MITM attack; PSI; insulin pumps; malicious attacks; man-in-the-middle attacks; mobile medical devices; pacemakers; personal security device; smartphone application; Androids; Bluetooth; Humanoid robots; IEEE 802.11 Standards; Mobile communication; Monitoring; Security; Man-in-the-middle attack; Medical device security;
Conference_Titel :
Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4799-7980-6
DOI :
10.1109/CSE.2014.156