《電子技術(shù)應(yīng)用》
您所在的位置:首頁(yè) > 通信與網(wǎng)絡(luò) > 設(shè)計(jì)應(yīng)用 > 物聯(lián)網(wǎng)多維度安全防御模型研究
物聯(lián)網(wǎng)多維度安全防御模型研究
網(wǎng)絡(luò)安全與數(shù)據(jù)治理
黎珂
工業(yè)信息安全(四川)創(chuàng)新中心有限公司
摘要: 傳統(tǒng)物聯(lián)網(wǎng)“感知–網(wǎng)絡(luò)–應(yīng)用”三層架構(gòu)在邊緣側(cè)存在防護(hù)盲區(qū),而“六域模型”因?qū)嵤┏杀靖?、域間協(xié)同機(jī)制缺失導(dǎo)致工程落地困難。基于物理域、網(wǎng)絡(luò)域、服務(wù)域的威脅分析,重構(gòu)“終端域–邊緣域–核心網(wǎng)域–云應(yīng)用域”四域架構(gòu),并引入數(shù)據(jù)面與控制面解耦的雙層控制機(jī)制,提出“四域雙層”安全框架。該框架系統(tǒng)揭示硬件滲透、協(xié)議缺陷、量子計(jì)算沖擊及API語(yǔ)義沖突等多維威脅,構(gòu)建了終端輕量化防護(hù)、量子增強(qiáng)傳輸、服務(wù)端主動(dòng)防御及全生命周期安全管控模型。銀行零信任場(chǎng)景與工業(yè)物聯(lián)網(wǎng)場(chǎng)景的實(shí)測(cè)表明,該架構(gòu)下攻擊檢出率≥98%,平均響應(yīng)時(shí)間≤500 ms。研究結(jié)果可為規(guī)模化物聯(lián)網(wǎng)安全工程提供可復(fù)用的體系化方法。
中圖分類號(hào):TP393.08;TP309文獻(xiàn)標(biāo)識(shí)碼:ADOI:10.19358/j.issn.2097-1788.2025.12.004引用格式:黎珂. 物聯(lián)網(wǎng)多維度安全防御模型研究[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2025,44(12):26-33.
Research on a multidimensional security defense model for the Internet of Things
Li Ke
Sichuan Innovation Center of Industry Cyber Security Co., Ltd.
Abstract: The traditional "perceptionnetworkapplication" threelayer architecture of the Internet of Things (IoT) exhibits security blind spots at the edge. Meanwhile, the "sixdomain model" faces challenges in practical implementation due to high deployment costs and lack of interdomain coordination mechanisms. Based on threat analysis across the physical, network, and service domains, this paper reconstructs a "terminal domainedge domaincore network domaincloud application domain" fourdomain architecture and introduces a duallayer control mechanism that decouples the data plane and control plane, proposing a "fourdomain duallayer" security framework. This framework systematically reveals multidimensional threats including hardware infiltration, protocol vulnerabilities, quantum computing impacts, and API semantic conflicts. It constructs models for terminal lightweight protection, quantumenhanced transmission, serverside proactive defense, and fulllifecycle security management. Practical tests in banking zerotrust scenarios and industrial IoT scenarios demonstrate that the attack detection rate is ≥98%, and the average response time is ≤500 ms. The results provide a reusable, systematic methodology for largescale IoT security engineering.
Key words : Internet of Things (IoT) security; four-domain duallayer architecture; zero trust; full-lifecycle defense; endogenous security

引言

物聯(lián)網(wǎng)技術(shù)正深度融入智能家居、工業(yè)控制、智慧城市等領(lǐng)域,推動(dòng)社會(huì)生產(chǎn)方式變革。國(guó)際數(shù)據(jù)公司(International Data Corporation, IDC)預(yù)測(cè),到2027年全球物聯(lián)網(wǎng)設(shè)備數(shù)量將超過(guò)400億臺(tái)。設(shè)備密度與數(shù)據(jù)流量的指數(shù)級(jí)增長(zhǎng)促使攻擊面向物理空間延伸,形成跨域協(xié)同威脅。傳統(tǒng)“感知–網(wǎng)絡(luò)–應(yīng)用”三層架構(gòu)[1]未對(duì)邊緣計(jì)算節(jié)點(diǎn)進(jìn)行安全定義,存在結(jié)構(gòu)性盲區(qū);六域模型[2]雖引入用戶、目標(biāo)對(duì)象等維度,但域間接口復(fù)雜、協(xié)同成本高昂,難以工程化落地。本研究結(jié)合最新威脅態(tài)勢(shì)與技術(shù)演進(jìn),面向可部署、可擴(kuò)展、可驗(yàn)證目標(biāo),提出“四域雙層”安全框架,重構(gòu)“終端–邊緣–核心網(wǎng)–云應(yīng)用”四域責(zé)任邊界,細(xì)化各域威脅模型與對(duì)策;設(shè)計(jì)數(shù)據(jù)面與控制面解耦機(jī)制,實(shí)現(xiàn)策略計(jì)算與執(zhí)行的分離;構(gòu)建覆蓋開(kāi)發(fā)、部署、運(yùn)維、退役全生命周期的安全管控模型,并在銀行與工業(yè)場(chǎng)景完成驗(yàn)證。


本文詳細(xì)內(nèi)容請(qǐng)下載:

http://ihrv.cn/resource/share/2000006896


作者信息:

黎珂

(工業(yè)信息安全(四川)創(chuàng)新中心有限公司,四川成都610041)


官方訂閱.jpg

此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。