《电子技术应用》
您所在的位置:首页 > 通信与网络 > 设计应用 > 物联网多维度安全防御模型研究
物联网多维度安全防御模型研究
网络安全与数据治理
黎珂
工业信息安全(四川)创新中心有限公司
摘要: 传统物联网“感知–网络–应用”三层架构在边缘侧存在防护盲区,而“六域模型”因实施成本高、域间协同机制缺失导致工程落地困难。基于物理域、网络域、服务域的威胁分析,重构“终端域–边缘域–核心网域–云应用域”四域架构,并引入数据面与控制面解耦的双层控制机制,提出“四域双层”安全框架。该框架系统揭示硬件渗透、协议缺陷、量子计算冲击及API语义冲突等多维威胁,构建了终端轻量化防护、量子增强传输、服务端主动防御及全生命周期安全管控模型。银行零信任场景与工业物联网场景的实测表明,该架构下攻击检出率≥98%,平均响应时间≤500 ms。研究结果可为规模化物联网安全工程提供可复用的体系化方法。
中图分类号:TP393.08;TP309文献标识码:ADOI:10.19358/j.issn.2097-1788.2025.12.004引用格式:黎珂. 物联网多维度安全防御模型研究[J].网络安全与数据治理,2025,44(12):26-33.
Research on a multidimensional security defense model for the Internet of Things
Li Ke
Sichuan Innovation Center of Industry Cyber Security Co., Ltd.
Abstract: The traditional "perceptionnetworkapplication" threelayer architecture of the Internet of Things (IoT) exhibits security blind spots at the edge. Meanwhile, the "sixdomain model" faces challenges in practical implementation due to high deployment costs and lack of interdomain coordination mechanisms. Based on threat analysis across the physical, network, and service domains, this paper reconstructs a "terminal domainedge domaincore network domaincloud application domain" fourdomain architecture and introduces a duallayer control mechanism that decouples the data plane and control plane, proposing a "fourdomain duallayer" security framework. This framework systematically reveals multidimensional threats including hardware infiltration, protocol vulnerabilities, quantum computing impacts, and API semantic conflicts. It constructs models for terminal lightweight protection, quantumenhanced transmission, serverside proactive defense, and fulllifecycle security management. Practical tests in banking zerotrust scenarios and industrial IoT scenarios demonstrate that the attack detection rate is ≥98%, and the average response time is ≤500 ms. The results provide a reusable, systematic methodology for largescale IoT security engineering.
Key words : Internet of Things (IoT) security; four-domain duallayer architecture; zero trust; full-lifecycle defense; endogenous security

引言

物联网技术正深度融入智能家居、工业控制、智慧城市等领域,推动社会生产方式变革。国际数据公司(International Data Corporation, IDC)预测,到2027年全球物联网设备数量将超过400亿台。设备密度与数据流量的指数级增长促使攻击面向物理空间延伸,形成跨域协同威胁。传统“感知–网络–应用”三层架构[1]未对边缘计算节点进行安全定义,存在结构性盲区;六域模型[2]虽引入用户、目标对象等维度,但域间接口复杂、协同成本高昂,难以工程化落地。本研究结合最新威胁态势与技术演进,面向可部署、可扩展、可验证目标,提出“四域双层”安全框架,重构“终端–边缘–核心网–云应用”四域责任边界,细化各域威胁模型与对策;设计数据面与控制面解耦机制,实现策略计算与执行的分离;构建覆盖开发、部署、运维、退役全生命周期的安全管控模型,并在银行与工业场景完成验证。


本文详细内容请下载:

https://www.chinaaet.com/resource/share/2000006896


作者信息:

黎珂

(工业信息安全(四川)创新中心有限公司,四川成都610041)


官方订阅.jpg

此内容为AET网站原创,未经授权禁止转载。