Voiceprint-Based Access Control for Wireless Insulin Pump Systems

Bin Hao, X. Hei, Yazhou Tu, Xiaojiang Du, Jie Wu
{"title":"Voiceprint-Based Access Control for Wireless Insulin Pump Systems","authors":"Bin Hao, X. Hei, Yazhou Tu, Xiaojiang Du, Jie Wu","doi":"10.1109/MASS.2018.00046","DOIUrl":null,"url":null,"abstract":"Insulin pumps have been widely used by patients with diabetes. Insulin pump systems adopt wireless channel with few cryptographic mechanisms, which makes them vulnerable to many attacks. In this paper, we focus on the wireless channel between Carelink USB and insulin pump on which the attackers can launch message eavesdropping and/or therapy manipulation attacks, which may put the patient in a life-threatening situation. Some prior solutions such as certificate-based or token-based schemes need either complicated key management or additional devices. We propose a novel voiceprint-based access control scheme comprising anti-replay speaker verification and voiceprint-based key agreement to secure the channel between the Carelink USB and insulin pump. Our scheme does not need permanent key sharing or additional devices. The anti-replay speaker verification adopts cascaded fusion of speaker verification and anti-replay countermeasure to ensure the insulin pump can be accessed by Carelink USB only after the legitimate user passes the identity verification. The evaluation on ASVspoof 2017 datasets shows that our scheme achieves a 4.02% Equal Error Rate (EER) with the existence of replay impostors. Besides, our scheme uses energy-difference-based voiceprint extraction and secure multi-party computing to generate a common cryptography (temporary) key between the Carelink USB and insulin pump, which can be used to encrypt the subsequent communication, and protect the insulin pump from eavesdropping and therapy manipulation attacks. By appropriately setting the similarity threshold of voiceprints, our key agreement scheme allows the insulin pump to establish a secure channel only with the device in its close proximity.","PeriodicalId":146214,"journal":{"name":"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)","volume":"95 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MASS.2018.00046","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Insulin pumps have been widely used by patients with diabetes. Insulin pump systems adopt wireless channel with few cryptographic mechanisms, which makes them vulnerable to many attacks. In this paper, we focus on the wireless channel between Carelink USB and insulin pump on which the attackers can launch message eavesdropping and/or therapy manipulation attacks, which may put the patient in a life-threatening situation. Some prior solutions such as certificate-based or token-based schemes need either complicated key management or additional devices. We propose a novel voiceprint-based access control scheme comprising anti-replay speaker verification and voiceprint-based key agreement to secure the channel between the Carelink USB and insulin pump. Our scheme does not need permanent key sharing or additional devices. The anti-replay speaker verification adopts cascaded fusion of speaker verification and anti-replay countermeasure to ensure the insulin pump can be accessed by Carelink USB only after the legitimate user passes the identity verification. The evaluation on ASVspoof 2017 datasets shows that our scheme achieves a 4.02% Equal Error Rate (EER) with the existence of replay impostors. Besides, our scheme uses energy-difference-based voiceprint extraction and secure multi-party computing to generate a common cryptography (temporary) key between the Carelink USB and insulin pump, which can be used to encrypt the subsequent communication, and protect the insulin pump from eavesdropping and therapy manipulation attacks. By appropriately setting the similarity threshold of voiceprints, our key agreement scheme allows the insulin pump to establish a secure channel only with the device in its close proximity.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于声纹的无线胰岛素泵系统访问控制
胰岛素泵已被糖尿病患者广泛使用。胰岛素泵系统采用无线信道,加密机制较少,容易受到多种攻击。在本文中,我们重点研究了Carelink USB与胰岛素泵之间的无线通道,攻击者可以在该通道上发起消息窃听和/或治疗操纵攻击,这可能会使患者处于危及生命的境地。以前的一些解决方案(如基于证书或基于令牌的方案)需要复杂的密钥管理或额外的设备。我们提出了一种新的基于声纹的访问控制方案,该方案包括防重放说话者验证和基于声纹的密钥协议,以确保Carelink USB和胰岛素泵之间的通道安全。我们的方案不需要永久密钥共享或额外的设备。防重放扬声器验证采用扬声器验证与防重放对策级联融合,确保合法用户通过身份验证后,Carelink USB才能访问胰岛素泵。对ASVspoof 2017数据集的评估表明,在存在重放冒名顶替者的情况下,我们的方案达到了4.02%的等错误率(EER)。此外,我们的方案利用基于能量差的声纹提取和安全多方计算,在Carelink USB和胰岛素泵之间生成一个通用的加密(临时)密钥,用于加密后续通信,保护胰岛素泵免受窃听和治疗操纵攻击。通过适当设置声纹的相似阈值,我们的密钥协议方案允许胰岛素泵仅与靠近的设备建立安全通道。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Deep Learning Based Urban Post-Accidental Congestion Prediction BF-IoT: Securing the IoT Networks via Fingerprinting-Based Device Authentication Achieving Energy Efficiency Through Dynamic Computing Offloading in Mobile Edge-Clouds A Fusion Method of Multiple Sensors Data on Panorama Video for Airport Surface Surveillance Theoretical Round Modification Fault Analysis on AEGIS-128 with Algebraic Techniques
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1