|
ABSTRACT
A medical sensor network can wirelessly monitor vital signs of humans, making it useful for long-term health care without sacrificing patient comfort and mobility. For such a network to be viable, its design must protect data privacy and authenticity given that medical data are highly sensitive. We identify the unique security challenges facing such a sensor network and propose a set of resource-efficient mechanisms to address these challenges. Our solution includes (1) a novel two-tier scheme for verifying the authenticity of patient data; (2) an ECC-based secure key exchange protocol to set up shared keys between sensor nodes and base stations; and (3) symmetric encryption/decryption for protecting data confidentiality and integrity. We have implemented the proposed mechanisms on a wireless mote platform and our results confirm their feasibility.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
M. Morris, S. S. Intille, and J. S. Beaudin, "Embedded assessment: Overcoming barriers to early detection with pervasive computing," in Proc. of PERVASIVE 2005, H. W. Gellersen, R. Want, and A. Schmidt, Eds. Springer-Verlag, 2005, pp. 333--346.
|
| |
2
|
S. Stern and D. Tzivoni, "Early detection of silent ischaemic heart disease by 24-hour electrocardiographic monitoring of active subjects," British Heart Journal, vol. 36, pp. 481--486, 1974.
|
| |
3
|
R. Fischer, L. Ohno-Machado, D. Curtis, R. Greenes, T. Stair, and J. Guttag, "SMART: Scalable medical alert response technology," in Smart Medical Technologies Summit (SMT), 2004.
|
| |
4
|
V. Shnayder, B.-R. Chen, K. Lorincz, T. R. F. Fulford-Jones, and M. Welsh, "Sensor networks for medical care," Harvard University, Tech. Rep. TR-08-05, Apr. 2005.
|
| |
5
|
C. Park, P. H. Chou, Y. Bai, R. Matthews, and A. Hibbs, "An Ultra-Wearable, Wireless, Low Power ECG Monitoring System," Proceedings of IEEE BioCAS, Nov. 2006.
|
| |
6
|
A. Wood, G. Virone, T. Doan, Q. Cao, L. Selavo, Y. Wu, L. Fang, Z. He, S. Lin, and J. Stankovic, "ALARM-NET: Wireless Sensor Networks for Assisted-Living and Health Monitoring," University of Virginia, Tech. Rep. CS-2006-01, 2006.
|
| |
7
|
T. Gao, C. Pesto, L. Selavo, Y. Chen, J. Ko, J. Lim, A. Terzis, A. Watt, J. Jeng, B.-R. Chen, K. Lorincz, and M. Welsh, "Wireless medical sensor networks in emergency response: Implementation and pilot results," in Proc. 2008 IEEE Int. Conf. Technologies for Homeland Security, Waltham, MA, 2008.
|
| |
8
|
Crossbow Technology, "MPR/MIB mote hardware users manual," Jan. 2006, http://www.xbow.com/Support/manuals.htm.
|
| |
9
|
Office for Civil Rights, United State Department of Health and Human Services, "Medical Privacy - National Standards to Protect the Privacy of Personal Health Information," http://hhs.gov/ocr/hipaa/finalreg.html.
|
| |
10
|
K. K. Venkatasubramanian and S. K. S. Gupta, "Security solutions for pervasive healthcare," in Security in Distributed, Grid, Mobile, and Pervasive Computing, Y. Xiao, Ed., 2007.
|
| |
11
|
Moteiv Corporation, "Tmote Sky," 2007, http://www.moteiv.com/products/tmotesky.php.
|
| |
12
|
N. Gura, A. Patel, A. Wander, H. Eberle, and S. C. Shantz, "Comparing Elliptic Curve Cryptography and RSA on 8-bit CPUs," in Workshop on Cryptographic Hardware and Embedded Systems, Aug. 2004.
|
| |
13
|
D. Chaum and E. van Heijst, "Group Signatures," in Advances in Cryptology - Eurocrypt '91, 1991, pp. 257--265.
|
| |
14
|
"Fujitsu MBF200 Solid State Fingerprint Sensor," http://www.fujitsu.com/emea/services/microelectronics/sensors/.
|
| |
15
|
ODI Security, "Embedded Fingerprint Matching Module Utilizing Fujitsu Array Sensor," http://www.odisecurity.com/.
|
| |
16
|
A. L. Goldberger, L. A. N. Amaral, L. Glass, J. M. Hausdorff, P. C. Ivanov, R. G. Mark, J. E. Mietus, G. B. Moody, C.-K. Peng, and H. E. Stanley, "PhysioBank, PhysioToolkit, and PhysioNet: Components of a new research resource for complex physiologic signals," Circulation, vol. 101, no. 23, pp. e215--e220, 2000 (June 13).
|
| |
17
|
N. Koblitz, "Elliptic curve cryptosystems," Mathematics of Computation, vol. 48, pp. 203--209, 1987.
|
| |
18
|
|
| |
19
|
Certicom Research, "Standards for Efficient Cryptography (SEC) 1: Elliptic Curve Cryptography," Sept. 2000.
|
| |
20
|
"TinyOS Website," http://www.tinyos.net/.
|
| |
21
|
A. Liu, P. Kampanakis, and P. Ning, "TinyECC: Elliptic Curve Cryptography for Sensor Networks," http://discovery.csc.ncsu.edu/software/TinyECC/.
|
| |
22
|
|
| |
23
|
Certicom Research, "Standards for Efficient Cryptography (SEC) 2: Recommended Elliptic Curve Domain Parameters," Sept. 2000.
|
| |
24
|
H. Wang, B. Sheng, C. C. Tan, and Q. Li, "WM-ECC: an Elliptic Curve Cryptography Suite on Sensor Motes," Dept. of Computer Science, College of William and Mary, Tech. Rep. WM-CS-2007-11, 2007.
|
| |
25
|
|
| |
26
|
|
| |
27
|
|
| |
28
|
D. J. Malan, M. Welsh, and M. D. Smith, "A Public-Key Infrastructure for TinyOS Based on Elliptic Curve Cryptography," in Proceedings of the IEEE International Conference on Sensor and Ad Hoc Communications and Networks, Oct. 2004.
|
| |
29
|
Q. Wang, W. Shin, X. Liu, Z. Zeng, C. Oh, B. Al-Shebli, M. Caccamo, C. Gunter, E. Gunter, J. Hou, K. Karahalios, and L. Sha, "I-Living: An open system architecture for assisted living," in Proceedings of the IEEE SMC, 2006.
|
| |
30
|
Jennifer C. Hou , Qixin Wang , Bedoor K. AlShebli , Linda Ball , Stanley Birge , Marco Caccamo , Chin-Fei Cheah , Eric Gilbert , Carl A. Gunter , Elsa Gunter , Chang-Gun Lee , Karrie Karahalios , Min-Young Nam , Narasimhan Nitya , Chaudhri Rohit , Lui Sha , Wook Shin , Sammy Yu , Yang Yu , Zheng Zeng, PAS: A Wireless-Enabled, Sensor-Integrated Personal Assistance System for Independent and Assisted Living, Proceedings of the 2007 Joint Workshop on High Confidence Medical Devices, Software, and Systems and Medical Device Plug-and-Play Interoperability, p.64-75, June 25-27, 2007
[doi> 10.1109/HCMDSS-MDPnP.2007.13]
|
| |
31
|
M. Aydos, B. Sunar, and C. K. Koc, "An elliptic curve cryptography based authentication and key agreement protocol for wireless communication," in Proceedings of the 2nd International Workshop on Discrete Algorithms and Methods for Mobile Computing and Communications, 1998.
|
 |
32
|
Qiang Huang , Johnas Cukier , Hisashi Kobayashi , Bede Liu , Jinyun Zhang, Fast authenticated key establishment protocols for self-organizing sensor networks, Proceedings of the 2nd ACM international conference on Wireless sensor networks and applications, September 19-19, 2003, San Diego, CA, USA
[doi> 10.1145/941350.941371]
|
 |
33
|
Adrian Perrig , Robert Szewczyk , Victor Wen , David Culler , J. D. Tygar, SPINS: security protocols for sensor networks, Proceedings of the 7th annual international conference on Mobile computing and networking, p.189-199, July 2001, Rome, Italy
[doi> 10.1145/381677.381696]
|
 |
34
|
|
| |
35
|
NIST, "Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography, Special Publication 800-56A," 2007, http://csrc.nist.gov/publications/nistpubs/800-56A/SP800-56A_Revision1_Mar08-2007.pdf.
|
|