Feeds

Boffins use heartbeat to thwart wireless implant hack

Chinese cardiac crypto

Beginner's guide to SSL certificates

Interfering with wireless medical implants sounds like a movie threat plot rather than a real risk - but if there is a threat, Chinese boffins have come up with an ingenious solution for combating it.

Researchers from the Chinese University of Hong Kong have developed a technique for using a patient's heartbeat as the source for an encryption key for authenticating communications between medical technicians and implanted devices such as insulin pumps and pacemakers, Heise Security reports.

Two sensors would be involved: one in an implanted device and one in a control kit. A pulse taken from a patient's finger is put into the control device. The interval between 16 successive heartbeats is then used to derive a 64-bit code. With the implanted device and the control kit keying off the same source, an identical key would be produced.

Minor differences in the measurement of heart rates taken from different locations in the body can be accommodated. Proto-type test systems have a 6.5 per cent code pair rejection rate, comparable with the 4.2 per cent rejection rate derived from fingerprint systems. Unlike conventional biometric systems, minor variations in heart rate intervals mean that potential attackers would not be able to use recorded data to derive a key.

Chinese medical boffins are yet to try out the technology with real implants. Instead they used test systems where they recorded heart rate data taken off sensors on the right and left index fingers of subjects. Two types of sensors were used: an electrocardiogram, which measures electrical pulses, and a photoplethysmograph (PPG), which works out a heart rate from variation in light absorption under the skin.

The research was presented in a paper published by the IEEE's Transactions on Information Technology in Biomedicine journal. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
Ello? ello? ello?: Facebook challenger in DDoS KNOCKOUT
Gets back up again after half an hour though
Desperate VXers enslave FREEZERS in DDoS bot
Updated Spike malware targets Asia
Heatmiser digital thermostat users: For pity's sake, DON'T SWITCH ON the WI-FI
A stranger turns up YOUR heat with default password 1234
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.