Bluetooth security analysis of general and intimate health IoT devices and apps: the case of FemTech


연구 분야: Infrastructure



학회: International Journal of Information Security


초록

The number of digital health products is increasing faster than ever. These technologies (e.g. mobile apps and connected devices) collect massive amounts of data about their users, including health, medical, sex life, and other intimate data. In this paper, we study a set of 21 Internet of Things (IoT) devices advertised for general and intimate health purposes of female bodies (aka female-oriented technologies or FemTech). We focus on the security of the Bluetooth connection and communications between the IoT device and the mobile app. Our results highlight serious security issues in the current off-the-shelf FemTech devices. These include unencrypted Bluetooth traffic, unknown Bluetooth services and insecure Bluetooth authentication when connecting to the app. We implement Bluetooth attacks on the communication between these devices and apps, resulting in malfunctioning of the device and app. We discuss our results and provide recommendations for different stakeholders to improve the security practices of Bluetooth-enabled IoT devices in such a sensitive and intimate domain.


Author Profile
Stephen Cook

Royal Holloway University of London Egham UK

정보 없음
Author Profile
Maryam Mehrnezhad

Royal Holloway University of London Egham UK

정보 없음
Author Profile
Ehsan Toreini

University of Surrey Guildford UK

정보 없음

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가
사이트 Springer
좋아요 수 0

연관 논문 목록 (167건)