Secure Key-Exchange Protocol for Implants Using Heartbeats

The cardiac interpulse interval (IPI) has recently been proposed tofacilitate key exchange for implantable medical devices (IMDs) using apatient's own heartbeats as a source of trust. While this form of key exchangeholds promise for IMD security, its feasibility is not fully understood due tothe simplified approaches found in related works. For example, previouslyproposed protocols have been designed without considering the limitedrandomness available per IPI, or have overlooked aspects pertinent to arealistic system, such as imperfect heartbeat detection or the energy overheadsimposed on an IMD. In this paper, we propose a new IPI-based key-exchangeprotocol and evaluate its use during medical emergencies. Our protocol employsfuzzy commitment to tolerate the expected disparity between IPIs obtained by anexternal reader and an IMD, as well as a novel way of tackling heartbeatmisdetection through IPI classification. Using our protocol, the expected timefor securely exchanging an 80-bit key with high probability (1-10−6) is roughlyone minute, while consuming only 88 μJ from an IMD.