GB/T 37093-2018 in English
VALIDInformation security technology-Security requirements for IoT sensing layer access to communication network
- Issued on:2018-12-28
- Implemented on:2019-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$243.00
《GB/T 37093-2018信息安全技术 物联网感知层接入通信网的安全要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Overview of security requirements for IoT perception layer access to communication network
GB/T 37093-2018 "Information Security Technology Security Requirements for IoT Perception Layer Access to Communication Network" is a national standard of the People's Republic of China, which aims to regulate the data security between IoT perception layer and communication network. This standard specifies in detail the security technical requirements for perception layer access entities, information transmission networks and communication network access systems, and is divided into two levels: basic and enhanced.
Comparative Analysis of Standard Frameworks
| Specification Dimensions | Basic Requirements | Enhanced Requirements |
|---|---|---|
| Device Identification Management | It should have a unique identifier (such as device ID, serial number, MAC address, etc.) that can be used for communication identification in IoT systems. | The unique identifier should be tamper-proof to ensure its security. |
| Authentication mechanism | Support one-way authentication based on the access entity identifier and access password of the perception layer or two-way authentication based on pre-shared keys. | Support access authentication based on public key infrastructure, and require the use of cryptographic algorithms such as digital signatures to ensure data source authentication. |
| Data transmission security | Ensure data confidentiality and integrity, and support time series verification to ensure data freshness. | Use cryptographic algorithms (such as AES, SHA-256) to achieve end-to-end encryption and integrity verification of data, and protect time series from tampering. |
Typical application scenario analysis
1. Short-range wireless network applications
Short-range wireless communication perception layer networks generally use self-organized wireless networking and communication protocols. For example, the application of wireless sensor networks in environmental monitoring faces security threats in open wireless environments.
2. Wired/wireless broadband access applications
Application scenarios that use wired/wireless public networks or dedicated broadband networks for data transmission (such as information interaction in the Internet of Vehicles) are vulnerable to threats from the public network and need to follow this standard to ensure the security of sensitive data.
3. RFID communication access applications
RFID reader/writer terminals are easily controlled or counterfeited in the perception layer open network, and their security access must comply with the enhanced level protection measures required by Chapter 8.
Implementation Recommendations
- Device Identification Management Optimization: Ensure that all perception layer access entities have unique device identification and implement tamper-proof protection under enhanced level requirements.
- Multi-level authentication mechanism: Combine pre-shared keys and public key infrastructure to build a multi-level access authentication system to enhance security protection capabilities.
- Data transmission encryption strategy: Under enhanced level requirements, use strong encryption algorithms such as AES-256 to protect data confidentiality, and implement integrity verification through SHA-256.
- Log auditing and monitoring: Establish a complete security event log recording system to monitor abnormal behavior in real time and issue alarms in a timely manner to ensure that security issues can be traced.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29 -

GB/T 41266-2022 in English
Security testing methods for critical network devices—Switch
2022-03-09 -

GB/T 31495.1-2015 in English
Information security technology―Indicator system of information security assurance and evaluation methods―Part 1:Concepts and model
2015-05-15 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30