Point of Care (PoC) devices and systems can be categorized into three broad classes (CAT 1, CAT 2, and CAT 3) based on the context of operation and usage. In this paper, the categories are defined to address certain usage models of the PoC device. PoC devices that are used for PoC testing and diagnostic applications are defined CAT 1 devices; PoC devices that are used for patient monitoring are defined as CAT 2 devices (PoCM); PoC devices that are used for as interfacing with other devices are defined as CAT 3 devices (PoCI). The PoCI devices provide an interface gateway for collecting and aggregating data from other medical devices. In all categories, data security is an important aspect. This paper presents a security framework concept, which is applicable for all of the classes of PoC operation. It outlines the concepts and security framework for preventing security challenges in unauthorized access to data, unintended data flow, and data tampering during communication between system entities, the user, and the PoC system. The security framework includes secure layering of basic PoC system architecture, protection of PoC devices in the context of application and network. Developing the security framework is taken into account of a thread model of the PoC system. A proposal for a low-level protocol is discussed. This protocol is independent of communications technologies, and it is elaborated in relation to providing security. An algorithm that can be used to overcome the threat challenges has been shown using the elements in the protocol. The paper further discusses the vulnerability scanning process for the PoC system interconnected network. The paper also presents a four-step process of authentication and authorization framework for providing the security for the PoC system. Finally, the paper concludes with the machine to machine (M2M) security viewpoint and discusses the key stakeholders within an actual deployment of the PoC system and its security challenges.
KeywordsPoint of Care TestingData SecuritySecurity FrameworkThreat Model
Tulasidas, S., Mackay, R., Craw, P., Hudson, C., Gkatzidou, V. and Balachandran, W. (2013) Process of Designing Robust, Dependable, Safe and Secure Software for Medical Devices: Point of Care Testing Device as a Case Study. Journal of Software Engineering and Applications, 6, 1-13. https://doi.org/10.4236/jsea.2013.69A001
Boswarthick, D., Elloumi, O. and Hersent, O. (2013) Securing Networks through the Internet. Health Management Technology. https://www.healthmgttech.com/securing-networks-through-the-internet.php
Ymeti, A., Nederkoorn, P.H.J., Dudia, A., Subramaniam, V. and Kanger, J.S. (2009) Rapid, Ultrasensitive Detection of Microorganisms Based on Interferometry and Lab-on-a-Chip Nanotechnology. Proceedings of the International Society for Optical Engineering, 7306, 73060J-1-73060J-7. https://doi.org/10.1117/12.818466
Akamai’s State of the Internet Q1 2014 Report. https://www.akamai.com/kr/ko/multimedia/documents/state-of-the-internet/akamai- state-of-the-internet-report-q3-2014.pdf
TCP and UPD Ports. http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers
Srinivas, J., Mukhopadhyay, S. and Mishra, D. (2017) Secure and Efficient User Authentication Scheme for Multi-Gateway Wireless Sensor Networks. Ad Hoc Networks, 54, 147-169. https://doi.org/10.1016/j.adhoc.2016.11.002
Han, K.-H. and Bae, W.-S. (2016) Proposing and Verifying a Security-Enhanced Protocol for IoT-Based Communication for Medical Devices. Cluster Computing, 19, 2335-2341. https://doi.org/10.1007/s10586-016-0669-3
Huang, X., Craig, P., Lin, H. and Yan, Z. (2016) SecIoT: A Security Framework for the Internet of Things. Security and Communication Networks, 9, 3083-3094. https://doi.org/10.1002/sec.1259
Karimian, N., Wortman, P.A. and Tehranipoor, F. (2016) Evolving Authentication Design Considerations for the Internet of Biometric Things (IoBT). Proceedings of the 11th IEEE/ACM/IFIP International Conference on Hardware/Software Codesign and System Synthesis, Pittsburgh, 1-7 October 2016, 1-10. https://doi.org/10.1145/2968456.2973748
Cao, X., Shila, D.M., Cheng, Y., Yang, Z., Zhou, Y. and Chen, J. (2016) Ghost-in-ZigBee: Energy Depletion Attack on ZigBee-Based Wireless Networks. IEEE Internet of Things, 3, 816-829. https://doi.org/10.1109/JIOT.2016.2516102
Custodio, V., Herrera, F.J., López, G. and Moreno, J.I. (2012) A Review on Architectures and Communications Technologies for Wearable Health-Monitoring Systems. Sensors, 12, 13907-1346. https://doi.org/10.3390/s121013907
Cam-Winget, N., Sadeghi, A.-R. and Jin, Y. (2016) INVITED: Can IoT Be Secured: Emerging Challenges in Connecting the Unconnected.
Wang, H., Li, K., Ota, K. and Shen, J. (2016) Remote Data Integrity Checking and Sharing in Cloud-Based Health Internet of Things. IEICE Transactions on Information and Systems, E99-D, 1966-1973. https://doi.org/10.1587/transinf.2015INI0001
Guo, Z., Karimian, N., Tehranipoor, M.M. and Forte, D. (2016) Hardware Security Meets Biometrics for the Age of IoT. 2016 IEEE International Symposium on Circuits and Systems, Montreal, 22-25 May 2016, 1318-1321. https://doi.org/10.1109/ISCAS.2016.7527491
Ding, D., Conti, M. and Solanas, A. (2016) A Smart Health Application and Its Related Privacy Issues. 2016 Smart City Security and Privacy Workshop, Vienna, 11-14 April 2016, 1-5. https://doi.org/10.1109/SCSPW.2016.7509558
Attila, A., Garai, A. and Pentek, I. (2016) Common Open Telemedicine Hub and Infrastructure with Interface Recommendation. IEEE 11th International Symposium on Applied Computational Intelligence and Informatics, Timisoara, 12-14 May 2016, 385-390. https://doi.org/10.1109/saci.2016.7507407
Seo, S. Preserving Patient’s Anonymity for Mobile Healthcare System in IoT Environment. Vol. 5.
El-Hadary, H. and El-Kassas, S. (2014) Capturing Security Requirements for Software Systems. Journal of Advanced Research, 5, 463-472. https://doi.org/10.1016/j.jare.2014.03.001
Application and Network Attacks. http://sl.sierracollege.edu/cis147/TextBook/CIS147-TextbookChapter3.pdf
Malik, M. and Agrawal, D.P. (2012) Secure Web Framework for Mobile Devices. 2012 IEEE Globecom Workshops, Anaheim, 3-7 December 2012, 781-786. https://doi.org/10.1109/GLOCOMW.2012.6477674
Proceedings of the 2009 ACM Workshop on Cloud Computing Security, Co-Located with the 16th ACM Computer and Communications Security Conference, Proceedings of the ACM Conference on Computer and Communications Security.
Weingart, S.N., Hamrick, H.E., Tutkus, S., Carbo, A., Sands, D.Z., Tess, A., Davis, R.B., Bates, D.W. and Phillips, R.S. (2008) Medication Safety Messages for Patients via the Web Portal: The MedCheck Intervention. International Journal of Medical Informatics, 77, 161-168. https://doi.org/10.1016/j.ijmedinf.2007.04.007
Gupta, V., Millard, M., Fung, S., Zhu, Y., Gura, N., Eberle, H. and Shantz, S.C. (2005) Sizzle: A Standards-Based End-to-End Security Architecture for the Embedded Internet. 3rd IEEE International Conference on Pervasive Computing and Communications, Kauai Island, 8-12 March 2005, 247-256. https://doi.org/10.1109/PERCOM.2005.41
Geva, M., Herzberg, A. and Gev, Y. (2014) Bandwidth Distributed Denial of Service: Attacks and Defenses. IEEE Security & Privacy, 12, 54-61. https://doi.org/10.1109/MSP.2013.55
Rontti, T., Juuso, A.-M. and Takanen, A. (2012) Preventing DoS Attacks in NGN Networks with Proactive Specification-Based Fuzzing. IEEE Communications Magazine, 50, 164-170. https://doi.org/10.1109/MCOM.2012.6295728
DHCP Consumption Attack and Mitigation Techniques White Paper. http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-6500-series-switches/white_Paper_C11_603833.html
Mobile Equipment Identifier. http://en.wikipedia.org/wiki/Mobile_equipment_identifier
3GPP TS 22.016: International Mobile Equipment Identities (IMEI) (2009).
Boswarthick, D., Elloumi, O. and Hersent, O. (2012) M2M Communications: A Systems Approach. Wiley, Hoboken, 221-240. https://doi.org/10.1002/9781119974031
AT&T M2M Solutions. Machine to Machine. M2M Communications. http://www.business.att.com/enterprise/Family/mobility-services/machine-to-machine/#fbid=-7OUq7Bu73_
Wen, J., Severa, M., Zeng, W., Luttrell, M. and Jin, W. (2001) A Format-Compliant Configurable Encryption Framework for Access Control of Multimedia. 2001 IEEE 4th Workshop on Multimedia Signal Processing, Cannes, 3-5 October 2001, 435-440.
Boswarthick, D., Elloumi, O. and Hersent, O. (2012) M2M Communications: A Systems Approach. Wiley, Hoboken, 233. https://doi.org/10.1002/9781119974031
M2M Communication: A System Approach. Section 8.3.5.
Compliance Guides for Small Businesses. FCC.gov. https://www.fcc.gov/encyclopedia/compliance-guides-small-businesses
Safe for Network Certification. Verizon Wireless. https://odi-device.verizonwireless.com/Info/Open%20Development%20Device%20Docs/Certification%20 Process%20Documentation/ODDeviceCertificationProcess.pdf