Computer System Security and Medical Devices Kevin Fu - - PowerPoint PPT Presentation

computer system security
SMART_READER_LITE
LIVE PREVIEW

Computer System Security and Medical Devices Kevin Fu - - PowerPoint PPT Presentation

Computer System Security and Medical Devices Kevin Fu kevinfu@cs.umass.edu Department of Computer Science University of Massachusetts at Amherst, USA http://prisms.cs.umass.edu/ October 27, 2006 Computer Science 1 Whats special about


slide-1
SLIDE 1

Computer Science

Department of Computer Science University of Massachusetts at Amherst, USA http://prisms.cs.umass.edu/

October 27, 2006

Kevin Fu

kevinfu@cs.umass.edu

Computer System Security

and Medical Devices

1

slide-2
SLIDE 2

Computer Science

What’s special about security?

2

slide-3
SLIDE 3

Kevin Fu, Computer System Security

Computer Science

Correctness is easy. Security is hard.

3

slide-4
SLIDE 4

Kevin Fu, Computer System Security

Computer Science

Research in System Security

  • Design, build, measure secure systems
  • Analyze existing systems

4

slide-5
SLIDE 5

RFID Security & Privacy

5

slide-6
SLIDE 6

Kevin Fu, Computer System Security

Computer Science

RFID tags

  • Originally simple UPC replacement
  • Now are miniature, low-power computers
  • Applications
  • e-commerce
  • public transportation
  • anti-counterfeiting medicine
  • medical applications

6

slide-7
SLIDE 7

Kevin Fu, Computer System Security

Computer Science

500 Euros in wallet

Serial numbers: 597387,389473…

Wig

model #4456

(cheap polyester)

30 items

  • f lingerie

Das Kapital and Communist-party handbook

Replacement hip

medical part #459382

RFID tags will be everywhere…

Credit: Ari Juels 7

slide-8
SLIDE 8

Credit: MGH

8

slide-9
SLIDE 9

Hospital Bracelet?

9

slide-10
SLIDE 10

Kevin Fu, Computer System Security

Computer Science

Prevent tag duplication

  • Don’t copy my car key!
  • How to prevent

reverse-engineering?

  • Side channel analysis?

10

slide-11
SLIDE 11

Kevin Fu, Computer System Security

Computer Science

Secure RFID

11

slide-12
SLIDE 12

Kevin Fu, Computer System Security

Computer Science

Contactless Credit Cards Insecure?

12

slide-13
SLIDE 13

Kevin Fu, Computer System Security

Computer Science

Privacy for Public Transit

13

slide-14
SLIDE 14

Secure Software Updates

14

slide-15
SLIDE 15

15

slide-16
SLIDE 16

Kevin Fu, Computer System Security

Computer Science

Survey of Update Security

16

slide-17
SLIDE 17

http://www.cs.umass.edu/~kevinfu/secureupdates/

17

slide-18
SLIDE 18

Automotive Updates

http://www.soultek.com/clean_energy/hybrid_cars/toyota_prius_hybrid_car_shut_down_or_stall_problems.htm 18

slide-19
SLIDE 19

Updates in Voting Machines

http://www.nytimes.com/2006/05/12/us/12vote.html?ex=1305086400&en=1b3554af6e2d524a&ei=5088&partner=rssnyt&emc=rss 19

slide-20
SLIDE 20

Implanted medical devices use updates too

What stops a computer viruses from infecting implants? A common wireless command on an ICD induces ventricular fibrillation. How is it authenticated?

20

slide-21
SLIDE 21

Embedded Medical Software

21

slide-22
SLIDE 22

Kevin Fu, Computer System Security

Computer Science

Discussion

  • Technical
  • What are the threat models for wirelessly

reprogrammable medical implants?

  • How to balance safety, privacy, security?
  • Philosophical
  • What is the role of FDA for future

implanted medical devices?

  • Biggest challenges for next-generation

implanted devices?

22

slide-23
SLIDE 23

Kevin Fu, Computer System Security

Computer Science

System Security at UMass Amherst

Faculty and affiliates Graduate Students

www.rfid-cusp.org

23

slide-24
SLIDE 24

Computer Science

Computer Science at UMass/Amherst

http://www.cs.umass.edu

43 faculty, ~230 graduate students, ~300 undergraduate students

24