Technical Brief: Encryption Characteristics of Two USB-based Personal Health Record Devices

نویسندگان

  • Adam Wright
  • Dean F. Sittig
چکیده

Personal health records (PHRs) hold great promise for empowering patients and increasing the accuracy and completeness of health information. We reviewed two small USB-based PHR devices that allow a patient to easily store and transport their personal health information. Both devices offer password protection and encryption features. Analysis of the devices shows that they store their data in a Microsoft Access database. Due to a flaw in the encryption of this database, recovering the user's password can be accomplished with minimal effort. Our analysis also showed that, rather than encrypting health information with the password chosen by the user, the devices stored the user's password as a string in the database and then encrypted that database with a common password set by the manufacturer. This is another serious vulnerability. This article describes the weaknesses we discovered, outlines three critical flaws with the security model used by the devices, and recommends four guidelines for improving the security of similar devices.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

USB/IP - A Peripheral Bus Extension for Device Sharing over IP Network (Awarded FREENIX Track Best Paper Award!)

As personal computing becomes more popular and affordable, the availability of peripheral devices is also increasing rapidly. However, these peripheral devices can usually only be connected to a single machine at time. The ability to share peripheral devices between computers without any modification of existing computing environments is, consequently, a highly desirable goal, as it improves th...

متن کامل

Design of a Data Acquisition System for USB Devices over Gigabit Ethernet

The Universal Serial Bus (USB) is one of the most widespread technical innovations in personal computer and home consumer applications over the past few years. Keyboards, mouse devices, printers, webcams, and several other computer peripherals are available with this type of connection. This success is due to some bus characteristics, such as simplicity, plug & play features, hot plug support, ...

متن کامل

Efficient and Secure Sharing of Personal Health Records Using Attribute-Based Encryption in Cloud Computing

Recently, personal health record (PHR) has emerged as a patient-centric model of health information exchange, which features storing PHRs electronically in one centralized place, such as a third-party cloud service provider. Personal Health Record is web based application that allows users to directly enter their information such as diagnosis, medications, laboratory tests, immunizations and ot...

متن کامل

Multi User Access Control and Key Management Mechanism for Personal Health Records

Cloud computing technology helps the individuals to store their essential information over the internet. The users can acquire the information from anywhere whenever needed. Due to the advances in computer technology, Cloud computing has gained an eminent deal of recognition among users. However the users should also be conscious of the privacy issues of having information cached on the cloud. ...

متن کامل

Survey on Multi Authority Attribute Based Encryption for Personal Health Record in Cloud Computing

Personal Health Record (PHR) service is an emerging model for health information exchange. PHR system allows patients to create, control manage, and share their health information with other users as well as healthcare providers like Google eHealth. A PHR service is likely to be hosted by third-party cloud service providers in order to enhance its interoperability. The access control and privac...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Journal of the American Medical Informatics Association : JAMIA

دوره 14 4  شماره 

صفحات  -

تاریخ انتشار 2007