Heartbeats could soon be used as passwords to increase the security of medical devices vulnerable to cyber-attack, according to research by the Rice University. The paper shows that implanted medical devices shouldnâ€™t be secured as Wi-Fi routers are, as the system would prevent medical staff from quickly accessing the information.
The innovative system dubbed â€œHeart-to-Heart (H2H)â€ would rely on an external â€œtouch-to-accessâ€ device. The programmer would be used by medical technicians to pick up EKG signatures from the patientâ€™s beating heart.
â€œThe signal from your heartbeat is different every second, so the password is different each time,â€ researcher Masoud Rostami told Softpedia. â€œYou canâ€™t use it even a minute later,â€Â
â€œTo our knowledge, this is the first fully secure solution that has small overhead and can work with legacy systems,â€ electrical and computer engineer Farinaz Koushanfar added. â€œLike any device that has wireless access, we can simply update the software.â€Â
After the US government warned the Food and Drug Administration to take medical device hacking seriously, the organization called on manufacturers and health care facilities to address existing vulnerabilities.
In May 2012, a Bitdefender infographic also showed how smart devices including medical equipment are vulnerable to cyber-attacks. The antivirus software pointed out the most common malware attacks targeting heart and diabetics patients.
In the US, over 100,000 patients receive implantable cardioverter defibrillators that detect dangerous heart rhythms and administer electric shocks to restore normal activity. Other implantable medical devices include pacemakers, neurostimulators and insulin or other drug pumps.Â
Researchers at the Rice University will present the authentication system in Berlin, at the Conference on Computer and Communications Security in November. A security company recently madeÂ public a similar authentication method in the form of a bracelet.Â