Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
information security technology security requirements iot perception layer access information security technology-security requirements communication network access systems security access abrasive particle size composition hysteresis alloy parts data date
GB/T 37093-2018 in English

GB/T 37093-2018 in English

VALID

Information security technology-Security requirements for IoT sensing layer access to communication network

  • Issued on:2018-12-28
  • Implemented on:2019-07-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $250.00
$243.00

《GB/T 37093-2018信息安全技术 物联网感知层接入通信网的安全要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。


Introduction

Overview of security requirements for IoT perception layer access to communication network

GB/T 37093-2018 "Information Security Technology Security Requirements for IoT Perception Layer Access to Communication Network" is a national standard of the People's Republic of China, which aims to regulate the data security between IoT perception layer and communication network. This standard specifies in detail the security technical requirements for perception layer access entities, information transmission networks and communication network access systems, and is divided into two levels: basic and enhanced.


Comparative Analysis of Standard Frameworks

Specification Dimensions Basic Requirements Enhanced Requirements
Device Identification Management It should have a unique identifier (such as device ID, serial number, MAC address, etc.) that can be used for communication identification in IoT systems. The unique identifier should be tamper-proof to ensure its security.
Authentication mechanism Support one-way authentication based on the access entity identifier and access password of the perception layer or two-way authentication based on pre-shared keys. Support access authentication based on public key infrastructure, and require the use of cryptographic algorithms such as digital signatures to ensure data source authentication.
Data transmission security Ensure data confidentiality and integrity, and support time series verification to ensure data freshness. Use cryptographic algorithms (such as AES, SHA-256) to achieve end-to-end encryption and integrity verification of data, and protect time series from tampering.

Typical application scenario analysis

1. Short-range wireless network applications

Short-range wireless communication perception layer networks generally use self-organized wireless networking and communication protocols. For example, the application of wireless sensor networks in environmental monitoring faces security threats in open wireless environments.

2. Wired/wireless broadband access applications

Application scenarios that use wired/wireless public networks or dedicated broadband networks for data transmission (such as information interaction in the Internet of Vehicles) are vulnerable to threats from the public network and need to follow this standard to ensure the security of sensitive data.

3. RFID communication access applications

RFID reader/writer terminals are easily controlled or counterfeited in the perception layer open network, and their security access must comply with the enhanced level protection measures required by Chapter 8.


Implementation Recommendations

  1. Device Identification Management Optimization: Ensure that all perception layer access entities have unique device identification and implement tamper-proof protection under enhanced level requirements.
  2. Multi-level authentication mechanism: Combine pre-shared keys and public key infrastructure to build a multi-level access authentication system to enhance security protection capabilities.
  3. Data transmission encryption strategy: Under enhanced level requirements, use strong encryption algorithms such as AES-256 to protect data confidentiality, and implement integrity verification through SHA-256.
  4. Log auditing and monitoring: Establish a complete security event log recording system to monitor abnormal behavior in real time and issue alarms in a timely manner to ensure that security issues can be traced.

Sample only — not a preview of GB/T 37093-2018
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend