Security Specification and Implementation for Mobile e-Health Services
Ramon Martí, Jaime Delgado, Xavier Perramon Universitat Pompeu Fabra (UPF), Barcelona, Spain {ramon.marti, jaime.delgado, xavier.perramon}@upf.edu Abstract
Different IT applications require different Security
- Services. We have been working in the area of e-
health applications in a mobile environment, and we have needed to integrate specific Security Services. The paper presents those Security Services for Mobile e-Health Services and how we have implemented
- them. First, the different security threats specially
- riented to the e-health applications are described,
like patients’ data eavesdropping and manipulation. Afterwards, the different security mechanisms to address these specific security threats are described, e.g. data confidentiality and integrity, together with the restrictions of dynamic IP addresses. Following, the specification of security services requirements and the implementation possibilities to address them in the Mobile e-Health Services are described. As an example of security services integrated into an e- health system, the paper includes the description of the mobile e-health service MobiHealth, an application developed under the MobiHealth Project, co-funded by the European Commission (IST-2001- 36006), focused on the security services added to it.
- 1. Introduction
In a digital society, one of the services that will contribute to improve the citizens’ quality of life is electronic healthcare, or e-health. A further step is the use of mobile communication technologies to provide the so-called m-health service: mobile e-health
- service. Depending on the severity of their diseases,
patients will not need to stay at hospitals, but they will be able to lead a normal life while their medical data are being monitored by healthcare professionals. In this context, data protection and security is a key aspect in order to increase users’ acceptance of these new technologies, given the highly sensitive nature of personal health data to be transmitted to and from mobile terminals. We present in this paper an architecture for an m- health system, based on the concept of a BAN (Body Area Network) linked via mobile telephony with a hospital or a healthcare centre. Then we focus on the security services that must be provided by this m- health system and how to implement them.
- 2. A Mobile e-Health System Architecture
Mobile e-Health Systems provide medical staff (doctors and nurses at a hospital or healthcare centre) with real-time remote access to patients’ health data. This section gives an overview of an architecture for Mobile e-Health Services, including the description of all the components and the communications between
- them. Figure 1 presents the components of this mobile
e-health architecture and the communication interactions between them, which are described in the following subsections.
Mobile Telephony Sens
- r
Fr ont -End Wir ed/ Wir eless Act u at or mobile t er minal Mobile Communic. Oper at or
I nt ernet / LAN I nt ernet / LAN
e-Healt h Ser ver End-User Applicat ion Body Ar ea Net wor k
- Fig. 1. Overview of a mobile e-health service
2.1. Mobile e-Health Application Components
According to this architecture, an m-health system consists of a BAN (Body Area Network) linked to a hospital or healthcare centre via mobile telephony. The concept of Body Area Network is a specialization
- f Personal Area Network that has recently been