摘要: |
伴随着物联网的产生和发展,IoT智能设备越来越多地出现,其大规模普及的同时,也给用户个人资产安全与隐私保护带来了极大地冲击和挑战。本文围绕智能设备,基于智能设备终端、云服务端和用户控制终端三端系统架构,综述目前智能设备安全威胁的主要来源和技术攻击手段,并针对性地梳理已有防护技术和安全研究现状。然后,针对现有IoT智能设备安全防护体系缺失和安全设计不足的问题,本文讨论提出了全生命周期的IoT智能设备系统防护模型设计思路。 |
关键词: 智能设备安全 安全威胁和防护综述 系统防护模型设计 |
DOI:10.19363/j.cnki.cn10-1380/tn.2018.01.004 |
Received:April 10, 2017Revised:May 18, 2017 |
基金项目:本课题得到中国科学院青年创新促进会(1105CX0105),信息安全国家标准项目(智能互联设备信息安全技术要求),国家重点研发计划(2017YFB0801900)资助。 |
|
A Survey of Security Threats and Defending Technologies on IoT Smart Devices |
WANG Yazhe,ZHANG Chengyi,HUO Dongdong,LI Jialin |
State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China;Engineering Laboratory of the Internet Smart Device Information Security, Beijing 100093, China;School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China |
Abstract: |
With the emergence and development of Internet of things, IoT smart devices increasingly appear and its large-scale popularity also has brought great impact and challenges on the user's personal assets security and privacy protection. In this paper, based on the smart device terminal, cloud server and user control terminal this three-terminal system architecture, we first summarize the main sources and technical attack methods of smart device security threats and combs the corresponding protection technologies and security research. Then, aiming at the problem of the lack of security protection system and the lack of security design on the existing IoT smart devices, this paper discusses and puts forward full life-cycle IoT smart device protection system model designing. |
Key words: Smart device security summary of threat and protection protection system model designing |