Research on a multi-dimensional security defense model for the Internet of Things
Li Ke
Sichuan Innovation Center of Industry Cyber Security Co., Ltd.
Abstract: The traditional "perception-network-application" three-layer architecture of the Internet of Things (IoT) exhibits security blind spots at the edge. Meanwhile, the "six-domain model" faces challenges in practical implementation due to high deployment costs and lack of inter-domain coordination mechanisms. Based on threat analysis across the physical, network, and service domains, this paper reconstructs a "terminal domain-edge domain-core network domain-cloud application domain" four-domain architecture and introduces a dual-layer control mechanism that decouples the data plane and control plane, proposing a "four-domain dual-layer" security framework. This framework systematically reveals multi-dimensional threats including hardware infiltration, protocol vulnerabilities, quantum computing impacts, and API semantic conflicts. It constructs models for terminal lightweight protection, quantum-enhanced transmission, server-side proactive defense, and full-lifecycle security management. Practical tests in banking zero-trust scenarios and industrial IoT scenarios demonstrate that the attack detection rate is ≥98%, and the average response time is ≤500 ms. The results provide a reusable, systematic methodology for large-scale IoT security engineering.
Key words : Internet of Things (IoT) security; four-domain duallayer architecture; zero trust; full-lifecycle defense; endogenous security
引言
物聯(lián)網(wǎng)技術(shù)正深度融入智能家居、工業(yè)控制、智慧城市等領(lǐng)域,推動社會生產(chǎn)方式變革。國際數(shù)據(jù)公司(International Data Corporation, IDC)預(yù)測,到2027年全球物聯(lián)網(wǎng)設(shè)備數(shù)量將超過400億臺。設(shè)備密度與數(shù)據(jù)流量的指數(shù)級增長促使攻擊面向物理空間延伸,形成跨域協(xié)同威脅。傳統(tǒng)“感知–網(wǎng)絡(luò)–應(yīng)用”三層架構(gòu)[1]未對邊緣計算節(jié)點(diǎn)進(jìn)行安全定義,存在結(jié)構(gòu)性盲區(qū);六域模型[2]雖引入用戶、目標(biāo)對象等維度,但域間接口復(fù)雜、協(xié)同成本高昂,難以工程化落地。本研究結(jié)合最新威脅態(tài)勢與技術(shù)演進(jìn),面向可部署、可擴(kuò)展、可驗(yàn)證目標(biāo),提出“四域雙層”安全框架,重構(gòu)“終端–邊緣–核心網(wǎng)–云應(yīng)用”四域責(zé)任邊界,細(xì)化各域威脅模型與對策;設(shè)計數(shù)據(jù)面與控制面解耦機(jī)制,實(shí)現(xiàn)策略計算與執(zhí)行的分離;構(gòu)建覆蓋開發(fā)、部署、運(yùn)維、退役全生命周期的安全管控模型,并在銀行與工業(yè)場景完成驗(yàn)證。