《電子技術(shù)應(yīng)用》
您所在的位置:首頁 > 通信与网络 > 设计应用 > 物联网多维度安全防御模型研究
物联网多维度安全防御模型研究
网络安全与数据治理
黎珂
工业信息安全(四川)创新中心有限公司
摘要: 传统物联网“感知–网络–应用”三层架构在边缘侧存在防护盲区,而“六域模型”因实施成本高、域间协同机制缺失导致工程落地困难。基于物理域、网络域、服务域的威胁分析,重构“终端域–边缘域–核心网域–云应用域”四域架构,并引入数据面与控制面解耦的双层控制机制,提出“四域双层”安全框架。该框架系统揭示硬件渗透、协议缺陷、量子计算冲击及API语义冲突等多维威胁,构建了终端轻量化防护、量子增强传输、服务端主动防御及全生命周期安全管控模型。银行零信任场景与工业物联网场景的实测表明,该架构下攻击检出率≥98%,平均响应时间≤500 ms。研究结果可为规模化物联网安全工程提供可复用的体系化方法。
中圖分類號:TP393.08;TP309文獻(xiàn)標(biāo)識碼:ADOI:10.19358/j.issn.2097-1788.2025.12.004引用格式:黎珂. 物聯(lián)網(wǎng)多維度安全防御模型研究[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2025,44(12):26-33.
Research on a multi-dimensional security defense model for the Internet of Things
Li Ke
Sichuan Innovation Center of Industry Cyber Security Co., Ltd.
Abstract: The traditional "perception-network-application" three-layer architecture of the Internet of Things (IoT) exhibits security blind spots at the edge. Meanwhile, the "six-domain model" faces challenges in practical implementation due to high deployment costs and lack of inter-domain coordination mechanisms. Based on threat analysis across the physical, network, and service domains, this paper reconstructs a "terminal domain-edge domain-core network domain-cloud application domain" four-domain architecture and introduces a dual-layer control mechanism that decouples the data plane and control plane, proposing a "four-domain dual-layer" security framework. This framework systematically reveals multi-dimensional threats including hardware infiltration, protocol vulnerabilities, quantum computing impacts, and API semantic conflicts. It constructs models for terminal lightweight protection, quantum-enhanced transmission, server-side proactive defense, and full-lifecycle security management. Practical tests in banking zero-trust scenarios and industrial IoT scenarios demonstrate that the attack detection rate is ≥98%, and the average response time is ≤500 ms. The results provide a reusable, systematic methodology for large-scale IoT security engineering.
Key words : Internet of Things (IoT) security; four-domain duallayer architecture; zero trust; full-lifecycle defense; endogenous security

引言

物聯(lián)網(wǎng)技術(shù)正深度融入智能家居、工業(yè)控制、智慧城市等領(lǐng)域,推動社會生產(chǎn)方式變革。國際數(shù)據(jù)公司(International Data Corporation, IDC)預(yù)測,到2027年全球物聯(lián)網(wǎng)設(shè)備數(shù)量將超過400億臺。設(shè)備密度與數(shù)據(jù)流量的指數(shù)級增長促使攻擊面向物理空間延伸,形成跨域協(xié)同威脅。傳統(tǒng)“感知–網(wǎng)絡(luò)–應(yīng)用”三層架構(gòu)[1]未對邊緣計(jì)算節(jié)點(diǎn)進(jìn)行安全定義,存在結(jié)構(gòu)性盲區(qū);六域模型[2]雖引入用戶、目標(biāo)對象等維度,但域間接口復(fù)雜、協(xié)同成本高昂,難以工程化落地。本研究結(jié)合最新威脅態(tài)勢與技術(shù)演進(jìn),面向可部署、可擴(kuò)展、可驗(yàn)證目標(biāo),提出“四域雙層”安全框架,重構(gòu)“終端–邊緣–核心網(wǎng)–云應(yīng)用”四域責(zé)任邊界,細(xì)化各域威脅模型與對策;設(shè)計(jì)數(shù)據(jù)面與控制面解耦機(jī)制,實(shí)現(xiàn)策略計(jì)算與執(zhí)行的分離;構(gòu)建覆蓋開發(fā)、部署、運(yùn)維、退役全生命周期的安全管控模型,并在銀行與工業(yè)場景完成驗(yàn)證。


本文詳細(xì)內(nèi)容請下載:

http://ihrv.cn/resource/share/2000006896


作者信息:

黎珂

(工業(yè)信息安全(四川)創(chuàng)新中心有限公司,四川成都610041)


官方訂閱.jpg

此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。