Title :
Device interoperability and authentication for telemedical appliance based on the ISO/IEEE 11073 personal health device (PHD) standards
Author :
Caranguian, L.P.R. ; Pancho-Festin, S. ; Sison, L.G.
Author_Institution :
Electr. Eng. (Instrum. & Control) Program, Univ. of the Philippines Diliman, Quezon City, Philippines
fDate :
Aug. 28 2012-Sept. 1 2012
Abstract :
In this study, we focused on the interoperability and authentication of medical devices in the context of telemedical systems. A recent standard called the ISO/IEEE 11073 Personal Health Device (X73-PHD) Standards addresses the device interoperability problem by defining common protocols for agent (medical device) and manager (appliance) interface. The X73-PHD standard however has not addressed security and authentication of medical devices which is important in establishing integrity of a telemedical system. We have designed and implemented a security policy within the X73-PHD standards. The policy will enable device authentication using Asymmetric-Key Cryptography and the RSA algorithm as the digital signature scheme. We used two approaches for performing the digital signatures: direct software implementation and use of embedded security modules (ESM). The two approaches were evaluated and compared in terms of execution time and memory requirement. For the standard 2048-bit RSA, ESM calculates digital signatures only 12% of the total time for the direct implementation. Moreover, analysis shows that ESM offers more security advantage such as secure storage of keys compared to using direct implementation. Interoperability with other systems was verified by testing the system with LNI Healthlink, a manager software that implements the X73-PHD standard. Lastly, security analysis was done and the system´s response to common attacks on authentication systems was analyzed and several measures were implemented to protect the system against them.
Keywords :
IEEE standards; ISO standards; authorisation; biomedical equipment; cryptographic protocols; digital signatures; embedded systems; medical computing; open systems; personal computing; public key cryptography; telemedicine; ESM; ISO-IEEE 11073 personal health device standards; LNI Healthlink; RSA algorithm; X73-PHD standard; agent-manager interface; asymmetric-key cryptography; authentication systems; digital signature scheme; direct software implementation; embedded security modules; manager software; medical device authentication; medical device interoperability; protocols; security analysis; security policy; standard 2048-bit RSA; telemedical appliance; telemedical system; Authentication; ISO standards; Performance evaluation; Protocols; Computer Communication Networks; Computer Security; Equipment and Supplies; Humans; Telemedicine;
Conference_Titel :
Engineering in Medicine and Biology Society (EMBC), 2012 Annual International Conference of the IEEE
Conference_Location :
San Diego, CA
Print_ISBN :
978-1-4244-4119-8
Electronic_ISBN :
1557-170X
DOI :
10.1109/EMBC.2012.6346169