Kill Switch For Pacemakers (And Countermeasures)
Medical device security researchers have figured out how to turn off a pacemaker via remote control.
(Pacemaker implantation diagram)
A pacemaker is a small, battery-operated electronic device which is inserted under the skin to help the heart beat regularly and at an appropriate rate. The pacemaker has leads that travel through a large vein to the heart, where the wires are anchored. The leads send the electrical impulses to the heart to tell it to beat.
Kevin Fu, an associate professor at the University of Massachusetts at Amherst and director of the Medical Device Security Center, said that his team and researchers at the University of Washington spent two years working on the challenge.
William H. Maisel, a doctor at Beth Israel Deaconess Hospital and Harvard Medical School, granted Fu access for the project. Fu received an old pacemaker as the doctor installed a new one in a patient. The team had to use complicated procedures to take apart the pacemaker and reverse engineer its processes. Halperin said that the devices have a built-in test mechanism which turns out to be a bug that can be exploited by hackers. There is no cryptographic key used to secure the wireless communication between the control device and the pacemaker.
A computer acts as a control mechanism for programming the pacemaker so that it can be set to deal with a patientís particular defribrillation needs. Pacemakers administer small shocks to the heart to restore a regular heartbeat. The devices have the ability to induce a fatal shock to a heart.
The authors of the study presented several different zero-power approaches to improve the security of implanted medical devices:
Our contributions include three zero-power defenses and
prototype implementations, one of which we evaluated for
effectiveness in a substance approximating the radio properties
of human tissue. Zero-power notiﬁcation harvests induced RF
energy to wirelessly power a piezo-element that audibly alerts
the patient of security-sensitive events at no cost to the battery.
Zero-power authentication similarly harvests RF energy to
power a cryptographically strong protocol that authenticates
requests from an external device programmer. Finally, sensible
key exchange combines techniques from both zero-power
notiﬁcation and zero-power authentication for vibration-based
key distribution that a patient can sense through audible and
tactile feedback. While we implemented prototypes of our
proposed defenses, we did not incorporate our prototypes into
a real IMD. (We use the term zero-power only to emphasize
that no expenditure of energy from the primary battery is
necessary. Zero-power defenses are also a step beyond the
use of a secondary battery for security-only or other auxiliary
I'm sure someone can think of a better sfnal reference for the idea of turning a person off by remote control; I do recall the "heartplugs" installed by the evil Baron Harkonnen in the (awful) movie version of Dune.
From Defcon: Excuse me while I turn off your pacemaker; see also the author's paper Pacemakers and Implantable Cardiac Deﬁbrillators:
Software Radio Attacks and Zero-Power Defenses [pdf].
Scroll down for more stories in the same category. (Story submitted 8/10/2008)
Follow this kind of news @Technovelgy.
| Email | RSS | Blog It | Stumble | del.icio.us | Digg | Reddit |
you like to contribute a story tip?
Get the URL of the story, and the related sf author, and add
Comment/Join discussion ( 3 )
Related News Stories -
Sleeep PRO Earplug For Maximum Rest
'Merton... placed the electrodes of the sleep-inducer on his forehead.' - Arthur C. Clarke, 1963.
You'll Regrow That Limb, One Day
'... forcing the energy transfer which allowed him to regrow his lost fingers.' - Frank Herbert, 1972.
First 3D Printed Human Corneas From Stem Cells
Just what we need! Lots of spare parts.
Nanorobots Roam Your Bloodstream, Cleaning It
Too bad they won't have lasers, though...
Technovelgy (that's tech-novel-gee!)
is devoted to the creative science inventions and ideas of sf authors. Look for
the Invention Category that interests
you, the Glossary, the Invention
Timeline, or see what's New.
SWEEPER Robot Peter Piper Picking Peppers
'... little machines, that went from plant to plant, apparently on caterpillar tracks, cutting off the ripe fruit.'
Oil from Algae - Can It Be Done?
'We dump everything that's waste into the tanks, pump the oil off the top.'
Moving Whole Planets, Revisited
There was a lot of work done on this idea over the years.
Disney Keeps Backups Of Star Wars Franchise Actors
'She is a personality-construct, a congeries of software agents...'
Farming In Space Starts With Mycorrhiza
'The inner leaves were beginning to curl faster than the outer leaves.'
Jaguar I-Pace Audible Vehicle Alert System For EVs
'Of course not a vehicle moved by means of internal explosions of a derivative of rock oil...'
Autonomous 'Fiberbots' Weave Large Structures
'It extrudes material like a spider.'
Birds Aren't Real - Wake Up, California! (With Bird Watching Guide)
'When he had first built them, they had been crude indeed, flying mechanisms with little more than a reflex-response unit.'
Self-Healing Material Pulls Carbon Out Of The Air
'... could seal the punctures.'
IRL Glasses Block Screens, Limit Vision To Real Life
'If you couldn't see the ads, how would you know what was fashionable?'
Testing The Single-Person Spacecraft
'...the lower part of the suit was simply a rigid cylinder.'
Shapeshifting Materials Transform By Light
'Its lines wavered, flowed, and then painfully reformed.'
Fully Automated Farm Iron Ox Hydroponics
'Had these machines in some incredible fashion been provided with brains?'
BrainNet Social Network Of Brains
'I used my implant to tell MILLIE what we wanted and she took care of it'
Phil Nuyttnn's City Under The Sea
'Under the lower roof there was no water, but a clear and luminous atmosphere...'
IONITY Opens First 10 Fast-Charging Stations
'Recharge the batteries... in almost every town and village...'
More SF in the News Stories
More Beyond Technovelgy science news stories