《電子技術(shù)應(yīng)用》
您所在的位置:首頁(yè) > 通信与网络 > 设计应用 > 物联网多维度安全防御模型研究
物联网多维度安全防御模型研究
网络安全与数据治理
黎珂
工业信息安全(四川)创新中心有限公司
摘要: 传统物联网“感知–网络–应用”三层架构在边缘侧存在防护盲区,而“六域模型”因实施成本高、域间协同机制缺失导致工程落地困难。基于物理域、网络域、服务域的威胁分析,重构“终端域–边缘域–核心网域–云应用域”四域架构,并引入数据面与控制面解耦的双层控制机制,提出“四域双层”安全框架。该框架系统揭示硬件渗透、协议缺陷、量子计算冲击及API语义冲突等多维威胁,构建了终端轻量化防护、量子增强传输、服务端主动防御及全生命周期安全管控模型。银行零信任场景与工业物联网场景的实测表明,该架构下攻击检出率≥98%,平均响应时间≤500 ms。研究结果可为规模化物联网安全工程提供可复用的体系化方法。
中圖分類號(hào):TP393.08;TP309文獻(xiàn)標(biāo)識(shí)碼:ADOI:10.19358/j.issn.2097-1788.2025.12.004引用格式:黎珂. 物聯(lián)網(wǎng)多維度安全防御模型研究[J].網(wǎng)絡(luò)安全與數(shù)據(jù)治理,2025,44(12):26-33.
Research on a multi-dimensional security defense model for the Internet of Things
Li Ke
Sichuan Innovation Center of Industry Cyber Security Co., Ltd.
Abstract: The traditional "perception-network-application" three-layer architecture of the Internet of Things (IoT) exhibits security blind spots at the edge. Meanwhile, the "six-domain model" faces challenges in practical implementation due to high deployment costs and lack of inter-domain coordination mechanisms. Based on threat analysis across the physical, network, and service domains, this paper reconstructs a "terminal domain-edge domain-core network domain-cloud application domain" four-domain architecture and introduces a dual-layer control mechanism that decouples the data plane and control plane, proposing a "four-domain dual-layer" security framework. This framework systematically reveals multi-dimensional threats including hardware infiltration, protocol vulnerabilities, quantum computing impacts, and API semantic conflicts. It constructs models for terminal lightweight protection, quantum-enhanced transmission, server-side proactive defense, and full-lifecycle security management. Practical tests in banking zero-trust scenarios and industrial IoT scenarios demonstrate that the attack detection rate is ≥98%, and the average response time is ≤500 ms. The results provide a reusable, systematic methodology for large-scale IoT security engineering.
Key words : Internet of Things (IoT) security; four-domain duallayer architecture; zero trust; full-lifecycle defense; endogenous security

引言

物聯(lián)網(wǎng)技術(shù)正深度融入智能家居、工業(yè)控制、智慧城市等領(lǐng)域,推動(dòng)社會(huì)生產(chǎn)方式變革。國(guó)際數(shù)據(jù)公司(International Data Corporation, IDC)預(yù)測(cè),到2027年全球物聯(lián)網(wǎng)設(shè)備數(shù)量將超過(guò)400億臺(tái)。設(shè)備密度與數(shù)據(jù)流量的指數(shù)級(jí)增長(zhǎng)促使攻擊面向物理空間延伸,形成跨域協(xié)同威脅。傳統(tǒng)“感知–網(wǎng)絡(luò)–應(yīng)用”三層架構(gòu)[1]未對(duì)邊緣計(jì)算節(jié)點(diǎn)進(jìn)行安全定義,存在結(jié)構(gòu)性盲區(qū);六域模型[2]雖引入用戶、目標(biāo)對(duì)象等維度,但域間接口復(fù)雜、協(xié)同成本高昂,難以工程化落地。本研究結(jié)合最新威脅態(tài)勢(shì)與技術(shù)演進(jìn),面向可部署、可擴(kuò)展、可驗(yàn)證目標(biāo),提出“四域雙層”安全框架,重構(gòu)“終端–邊緣–核心網(wǎng)–云應(yīng)用”四域責(zé)任邊界,細(xì)化各域威脅模型與對(duì)策;設(shè)計(jì)數(shù)據(jù)面與控制面解耦機(jī)制,實(shí)現(xiàn)策略計(jì)算與執(zhí)行的分離;構(gòu)建覆蓋開發(fā)、部署、運(yùn)維、退役全生命周期的安全管控模型,并在銀行與工業(yè)場(chǎng)景完成驗(yàn)證。


本文詳細(xì)內(nèi)容請(qǐng)下載:

http://m.tom3567.com/resource/share/2000006896


作者信息:

黎珂

(工業(yè)信息安全(四川)創(chuàng)新中心有限公司,四川成都610041)


官方訂閱.jpg

此內(nèi)容為AET網(wǎng)站原創(chuàng),未經(jīng)授權(quán)禁止轉(zhuǎn)載。
主站蜘蛛池模板: 日韩一区二区久久久| 奇米影视首页 狠狠色丁香婷婷久久综合 | 亚洲一区二区自拍| 欧美日本精品在线| 婷婷五月综合缴情在线视频| 久久韩国免费视频| 久久中文字幕视频| 欧美精品免费观看二区| 日本精品一区二区三区不卡无字幕| 国产欧亚日韩视频| 久久精品免费一区二区| 日韩av不卡播放| 日韩中文字幕精品| 亚洲制服欧美久久| 亚洲精品欧美日韩专区| 国产精品盗摄久久久| 国产成人精品日本亚洲专区61 | 久久视频在线观看中文字幕| 日韩精品视频在线观看视频| 日韩视频免费观看| 亚洲精品日韩在线观看| 亚洲va国产va天堂va久久| 亚洲狠狠婷婷综合久久久| 91久久国产综合久久91精品网站| 丁香五月网久久综合| 91av在线国产| 亚洲日本无吗高清不卡| 91精品国产高清| 伊人色综合久久天天五月婷 | 在线观看亚洲视频啊啊啊啊| 不卡av在线网站| 91精品国自产在线观看| 日韩视频在线观看视频| 日韩精品无码一区二区三区| 欧美在线视频a| 久久精品国产成人精品| 国产欧美综合一区| 国产精品毛片a∨一区二区三区|国| 国产精品成人一区二区| 伊人久久大香线蕉精品| 欧美在线中文字幕|