Physiological Information Leakage: A New Frontier in Health Information Security

被引:33
作者
Nia, Arsalan Mohsen [1 ]
Sur-Kolay, Susmita [2 ]
Raghunathan, Anand [3 ]
Jha, Niraj K. [1 ]
机构
[1] Princeton Univ, Dept Elect Engn, Princeton, NJ 08544 USA
[2] Indian Stat Inst, Adv Comp & Microelect Unit, Kolkata 700108, India
[3] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
基金
美国国家科学基金会;
关键词
Healthcare; information leakage; information security; medical devices; privacy;
D O I
10.1109/TETC.2015.2478003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information security has become an important concern in healthcare systems, owing to the increasing prevalence of medical devices and the growing use of wearable and mobile computing platforms for health and lifestyle monitoring. The previous work in the area of health information security has largely focused on attacks on the wireless communication channel of medical devices, or on health data stored in online databases. In this paper, we pursue an entirely different angle to health information security, motivated by the insight that the human body itself is a rich source (acoustic, visual, and electromagnetic) of data. We propose a new class of information security attacks that exploit physiological information leakage, i.e., various forms of information that naturally leak from the human body, to compromise privacy. As an example, we demonstrate attacks that exploit acoustic leakage from the heart and lungs. The medical devices deployed within or on our bodies also add to natural sources of physiological information leakage, thereby increasing opportunities for attackers. Unlike previous attacks on medical devices, which target the wireless communication to/from them, we propose privacy attacks that exploit information leaked by the very operation of these devices. As an example, we demonstrate how the acoustic leakage from an insulin pump can reveal important information about its operation, such as the duration and dosage of insulin injection. Moreover, we show how an adversary can estimate blood pressure (BP) by capturing and processing the electromagnetic radiation of an ambulatory BP monitoring device.
引用
收藏
页码:321 / 334
页数:14
相关论文
共 33 条
[21]  
Jiang L. J., 2005, Journal of Medical Engineering & Technology, V29, P257, DOI 10.1080/03091900512331333158
[22]  
Luo X., 2011, HTTPOS SEALING INFOR
[23]  
Mercer J.B., 2009, THERMOL INT, V19, P67
[24]  
Mokhayeri F., 2011, 2011 18th Iranian Conference of Biomedical Engineering (ICBME), P232, DOI 10.1109/ICBME.2011.6168563
[25]   Respiratory sounds - Advances beyond the stethoscope [J].
Pasterkamp, H ;
Kraman, SS ;
Wodicka, GR .
AMERICAN JOURNAL OF RESPIRATORY AND CRITICAL CARE MEDICINE, 1997, 156 (03) :974-987
[26]   Securing Sensor Nodes Against Side Channel Attacks [J].
Pongaliur, Kanthakumar ;
Abraham, Zubin ;
Liu, Alex X. ;
Xiao, Li ;
Kempel, Leo .
11TH IEEE HIGH ASSURANCE SYSTEMS ENGINEERING SYMPOSIUM, PROCEEDINGS, 2008, :353-+
[27]  
Shulman H., 2014, PRETTY BAD PRIVACY P, P191, DOI DOI 10.1145/2665943.2665959
[28]   Design and Evaluation of a Capacitively Coupled Sensor Readout Circuit, toward Contact-less ECG and EEG [J].
Svard, Daniel ;
Cichocki, Andrzej ;
Alvandpour, Atila .
2010 BIOMEDICAL CIRCUITS AND SYSTEMS CONFERENCE (BIOCAS), 2010, :302-305
[29]   Evaluation of information leakage via electromagnetic emanation and effectiveness of Tempest [J].
Tanaka, Hidema .
IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2008, E91D (05) :1439-1446
[30]  
Tanaka H, 2007, LECT NOTES COMPUT SC, V4812, P167