物联网多维度安全防御模型研究
网络安全与数据治理
黎珂
工业信息安全(四川)创新中心有限公司
摘要: 传统物联网“感知–网络–应用”三层架构在边缘侧存在防护盲区,而“六域模型”因实施成本高、域间协同机制缺失导致工程落地困难。基于物理域、网络域、服务域的威胁分析,重构“终端域–边缘域–核心网域–云应用域”四域架构,并引入数据面与控制面解耦的双层控制机制,提出“四域双层”安全框架。该框架系统揭示硬件渗透、协议缺陷、量子计算冲击及API语义冲突等多维威胁,构建了终端轻量化防护、量子增强传输、服务端主动防御及全生命周期安全管控模型。银行零信任场景与工业物联网场景的实测表明,该架构下攻击检出率≥98%,平均响应时间≤500 ms。研究结果可为规模化物联网安全工程提供可复用的体系化方法。
中图分类号:TP393.08;TP309文献标识码:ADOI:10.19358/j.issn.2097-1788.2025.12.004引用格式:黎珂. 物联网多维度安全防御模型研究[J].网络安全与数据治理,2025,44(12):26-33.
Research on a multidimensional security defense model for the Internet of Things
Li Ke
Sichuan Innovation Center of Industry Cyber Security Co., Ltd.
Abstract: The traditional "perceptionnetworkapplication" threelayer architecture of the Internet of Things (IoT) exhibits security blind spots at the edge. Meanwhile, the "sixdomain model" faces challenges in practical implementation due to high deployment costs and lack of interdomain coordination mechanisms. Based on threat analysis across the physical, network, and service domains, this paper reconstructs a "terminal domainedge domaincore network domaincloud application domain" fourdomain architecture and introduces a duallayer control mechanism that decouples the data plane and control plane, proposing a "fourdomain duallayer" security framework. This framework systematically reveals multidimensional threats including hardware infiltration, protocol vulnerabilities, quantum computing impacts, and API semantic conflicts. It constructs models for terminal lightweight protection, quantumenhanced transmission, serverside proactive defense, and fulllifecycle security management. Practical tests in banking zerotrust scenarios and industrial IoT scenarios demonstrate that the attack detection rate is ≥98%, and the average response time is ≤500 ms. The results provide a reusable, systematic methodology for largescale IoT security engineering.
Key words : Internet of Things (IoT) security; four-domain duallayer architecture; zero trust; full-lifecycle defense; endogenous security
引言
物联网技术正深度融入智能家居、工业控制、智慧城市等领域,推动社会生产方式变革。国际数据公司(International Data Corporation, IDC)预测,到2027年全球物联网设备数量将超过400亿台。设备密度与数据流量的指数级增长促使攻击面向物理空间延伸,形成跨域协同威胁。传统“感知–网络–应用”三层架构[1]未对边缘计算节点进行安全定义,存在结构性盲区;六域模型[2]虽引入用户、目标对象等维度,但域间接口复杂、协同成本高昂,难以工程化落地。本研究结合最新威胁态势与技术演进,面向可部署、可扩展、可验证目标,提出“四域双层”安全框架,重构“终端–边缘–核心网–云应用”四域责任边界,细化各域威胁模型与对策;设计数据面与控制面解耦机制,实现策略计算与执行的分离;构建覆盖开发、部署、运维、退役全生命周期的安全管控模型,并在银行与工业场景完成验证。
本文详细内容请下载:
https://www.chinaaet.com/resource/share/2000006896
作者信息:
黎珂
(工业信息安全(四川)创新中心有限公司,四川成都610041)

此内容为AET网站原创,未经授权禁止转载。
