摘要
在异构接入与无线协议并存的物联网(Internet of Things,IoT)环境中,传统静态认证已难以构建有效防线。对此,分析ZigBee协议下中间人重放攻击的流程和漏洞,研究基于物理不可克隆函数熵源的动态密钥生成策略、多因子行为-环境融合认证模型以及轻量化可信执行环境(Trusted Execution Environment,TEE)构建策略,提出零信任防御体系构建路径,实现认证过程动态化与计算区域隔离化。
In Internet of Things(IoT)with heterogeneous access and coexisting wireless protocols,traditional static authentication fails to defend effectively.This paper analyzes man-in-the-middle replay attacks and their flaws under ZigBee,studies dynamic key generation via physical unclonable function entropy sources,multi-factor behavior-environment fusion authentication,and lightweight Trusted Execution Environment(TEE)construction,then proposes a zero-trust defense path to realize dynamic authentication and computing region isolation.
作者
夏可强
金宇翔
XIA Keqiang;JIN Yuxiang(Jiangsu Future Networks Innovation Institute,Nanjing 100076,China;61516 Force,Beijing 100076,China)
出处
《智能物联技术》
2025年第4期105-108,共4页
Technology of Io T& AI