物联网多维度安全防御模型研究
网络安全与数据治理
黎珂
工业信息安全(四川)创新中心有限公司
摘要: 传统物联网“感知–网络–应用”三层架构在边缘侧存在防护盲区,而“六域模型”因实施成本高、域间协同机制缺失导致工程落地困难。基于物理域、网络域、服务域的威胁分析,重构“终端域–边缘域–核心网域–云应用域”四域架构,并引入数据面与控制面解耦的双层控制机制,提出“四域双层”安全框架。该框架系统揭示硬件渗透、协议缺陷、量子计算冲击及API语义冲突等多维威胁,构建了终端轻量化防护、量子增强传输、服务端主动防御及全生命周期安全管控模型。银行零信任场景与工业物联网场景的实测表明,该架构下攻击检出率≥98%,平均响应时间≤500 ms。研究结果可为规模化物联网安全工程提供可复用的体系化方法。
中图分类号:TP393.08;TP309文献标识码:ADOI:10.19358/j.issn.2097-1788.2025.12.004引用格式:黎珂. 物联网多维度安全防御模型研究[J].网络安全与数据治理,2025,44(12):26-33.
Research on a multi-dimensional security defense model for the Internet of Things
Li Ke
Sichuan Innovation Center of Industry Cyber Security Co., Ltd.
Abstract: The traditional "perception-network-application" three-layer architecture of the Internet of Things (IoT) exhibits security blind spots at the edge. Meanwhile, the "six-domain model" faces challenges in practical implementation due to high deployment costs and lack of inter-domain coordination mechanisms. Based on threat analysis across the physical, network, and service domains, this paper reconstructs a "terminal domain-edge domain-core network domain-cloud application domain" four-domain architecture and introduces a dual-layer control mechanism that decouples the data plane and control plane, proposing a "four-domain dual-layer" security framework. This framework systematically reveals multi-dimensional threats including hardware infiltration, protocol vulnerabilities, quantum computing impacts, and API semantic conflicts. It constructs models for terminal lightweight protection, quantum-enhanced transmission, server-side proactive defense, and full-lifecycle security management. Practical tests in banking zero-trust scenarios and industrial IoT scenarios demonstrate that the attack detection rate is ≥98%, and the average response time is ≤500 ms. The results provide a reusable, systematic methodology for large-scale IoT security engineering.
Key words : Internet of Things (IoT) security; four-domain duallayer architecture; zero trust; full-lifecycle defense; endogenous security
引言
物联网技术正深度融入智能家居、工业控制、智慧城市等领域,推动社会生产方式变革。国际数据公司(International Data Corporation, IDC)预测,到2027年全球物联网设备数量将超过400亿台。设备密度与数据流量的指数级增长促使攻击面向物理空间延伸,形成跨域协同威胁。传统“感知–网络–应用”三层架构[1]未对边缘计算节点进行安全定义,存在结构性盲区;六域模型[2]虽引入用户、目标对象等维度,但域间接口复杂、协同成本高昂,难以工程化落地。本研究结合最新威胁态势与技术演进,面向可部署、可扩展、可验证目标,提出“四域双层”安全框架,重构“终端–边缘–核心网–云应用”四域责任边界,细化各域威胁模型与对策;设计数据面与控制面解耦机制,实现策略计算与执行的分离;构建覆盖开发、部署、运维、退役全生命周期的安全管控模型,并在银行与工业场景完成验证。
本文详细内容请下载:
https://www.chinaaet.com/resource/share/2000006896
作者信息:
黎珂
(工业信息安全(四川)创新中心有限公司,四川成都610041)

此内容为AET网站原创,未经授权禁止转载。
