| Literature DB >> 32055092 |
Somayeh Nasiri1, Farahnaz Sadoughi2, Mohammad Hesam Tadayon3, Afsaneh Dehnad4.
Abstract
INTRODUCTION: Internet of Things (IoT), which provides smart services and remote monitoring across healthcare systems according to a set of interconnected networks and devices, is a revolutionary technology in this domain. Due to its nature to sensitive and confidential information of patients, ensuring security is a critical issue in the development of IoT-based healthcare system. AIM: Our purpose was to identify the features and concepts associated with security requirements of IoT in healthcare system.Entities:
Keywords: Healthcare System; Internet of Things; Requirement; Security
Year: 2019 PMID: 32055092 PMCID: PMC7004290 DOI: 10.5455/aim.2019.27.253-258
Source DB: PubMed Journal: Acta Inform Med ISSN: 0353-8109
Inclusion criteria and exclusion criteria for selection studies
| I/E | Criteria | Explanation |
|---|---|---|
| Inclusion | Language type | Studies written in English |
| Publication year | Studies published from 2005 up to September 2019 | |
| Publication venue | -Digital search in electronic databases: studies published in peer-reviewed journals, and conferences | |
| Research scope | Studies related to security requirements and IoT in healthcare | |
| Exclusion | Without full-text | The full-text of the study is not accessible. |
| Non-related publication source | Publication source of the study is a book, editorial letter, commentary, short communication and poster. | |
| Wrong or non-related categorization | The study is misclassified, incomplete and unclear in terms of content and concept of security requirements. |
Cyber security requirements for IoT-based healthcare
| Cyber security requirements | Description | ||
|---|---|---|---|
| Features | References | ||
| CIA | Confidentiality | ( | Confidentiality ensures that IoT system prohibits unauthorized entities (users and devices) from disclosing medical information ( |
| Integrity | ( | Integrity refers to data completeness and accuracy in entire lifecycle of system. Integrity ensures that patients’ medical data are not manipulated or removed or corrupted by adversary leading to mistaken diagnosis or wrong prescription ( | |
| Availability | ( | Availability ensures that medical data and devices are accessible to authorized users when needed ( | |
| Non-CIA | Identification and authentication | ( | Identification guarantees the identity of all the entities (patients, doctors, devices, etc.) before permitting them to interact with the resources of the IoT system ( |
| Authorization (access control) | ( | After user identity verification, access rights or privileges to resources should be determined so that different users can only access to the resources required based on their tasks ( | |
| Privacy | ( | Privacy means that secretes and personal data of patients should not be disclosed without the consent ( | |
| Accountability | ( | In health IoT system, accountability should ensure that the organization or individual are obliged to be answerable or responsible for their actions in case of theft or abnormal event ( | |
| Non-repudiation | ( | Non-repudiation ensures that someone cannot deny an action that has already been done ( | |
| Auditing | ( | Auditing is the ability of a system to continuously track and monitor actions. In an IoT-based healthcare system, all user activities should be recorded in sequential orders such as login time to system and data modifying ( | |
| Data Freshness | ( | Data freshness means that data should be recent ensuring that no old messages are replayed ( | |
Cyber resiliency requirements for IoT-based healthcare
| Requirements cyber resiliency | Description | |||
|---|---|---|---|---|
| Features | References | |||
| Reliability | ( | Reliability is an important aspect of the IoT network when devices are data sensing, collecting and transmitting under any high risk environmental conditions (e.g., dust, walls, win, rain, heat, etc). Therefore, reliability refers to continuity of a service correctly in spite of heterogeneous networks, system failures and various environmental conditions ( | ||
| Maintainability | Modifiability | ( | The modifiability is the ability of IoT system to update and add new capabilities or modify existing capabilities during the design and implementation of a system ( | |
| Reparability | ( | The reparability is the ability to detect and correct the system faults, and attempt to restore the system to the normal operational state ( | ||
| Configurability | ( | The configurability occurs when the system can adjust parameters for a set of procedures in a way that the system can function properly in different operational situations ( | ||
| Adaptability | ( | The adaptability means the system is enabled to quickly alter and perform correct function during phases of its designing and implementing under different operating circumstances ( | ||
| Autonomy (autonomic computing) | Self-healing | ( | The autonomy is that the IoT system is able to properly adapt itself under different operating conditions ( | |
| Self-optimizing | ||||
| Self-protecting | ||||
| Self-configuring | ||||
| Safety | ( | It refers to issues associated with functions and safety of devices, nodes and machines to augment safety of the entire IoT environment ( | ||
| Survivability | ( | Survivability requirements guarantee that the system still protects the IoT network and completes its mission in a timely manner if some devices or nodes are compromised and data are dropped intentionally, | ||
| Performability | ( | Performability is defined as a performance measure (such as speed, accuracy, or memory) of a system or component that performs its designated functions correctly within given constraint situations ( | ||
Figure 1.Security requirements in cyber space (13)