arXiv:2509.14657cs.CRcs.AI2025-09中稿 · Computing Conferen…

为物联网音频设备设计分层安全框架,防范数据泄露与篡改。

Threat Modeling for Enhancing Security of IoT Audio Classification Devices under a Secure Protocols Framework

  • 分三信任域构建防御体系,用TPM远程证明与互认证TLS 1.3保障通信安全。
  • 设备启动时逐级测量并验证,未通过云验签则无法解密存储分区。
  • 支持后量子加密与模型签名,适合高安全需求的智能音频终端。

配备麦克风且具备本地音频分类能力的物联网节点快速普及,但在资源受限环境下暴露敏感数据。为此,我们提出一种纵深防御架构,将边缘设备、蜂窝网络和云端后端划分为三个独立信任域,通过基于TPM的远程证明和相互认证的TLS 1.3连接。采用STRIDE威胁建模与攻击树分析指导设计。启动时各引导阶段均测量至TPM PCR。设备仅在云端验证TPM凭证并释放一次性解锁密钥后,方可解密其LUKS密封分区,确保恶意或篡改设备无法运行。传输中数据使用TLS 1.3保护,并融合Kyber与Dilithium实现后量子安全性。端到端加密与完整性哈希守护提取的音频特征。已签名且防回滚的AI模型及抗篡改传感器加固固件与硬件。静态数据遵循3-2-1策略:固态硬盘以LUKS密封,离线冷存档使用混合后量子加密,云端副本加密存储。最后,提出评估该协议物理与逻辑安全性的方案。

原文摘要 · Abstract (English)

The rapid proliferation of IoT nodes equipped with microphones and capable of performing on-device audio classification exposes highly sensitive data while operating under tight resource constraints. To protect against this, we present a defence-in-depth architecture comprising a security protocol that treats the edge device, cellular network and cloud backend as three separate trust domains, linked by TPM-based remote attestation and mutually authenticated TLS 1.3. A STRIDE-driven threat model and attack-tree analysis guide the design. At startup, each boot stage is measured into TPM PCRs. The node can only decrypt its LUKS-sealed partitions after the cloud has verified a TPM quote and released a one-time unlock key. This ensures that rogue or tampered devices remain inert. Data in transit is protected by TLS 1.3 and hybridised with Kyber and Dilithium to provide post-quantum resilience. Meanwhile, end-to-end encryption and integrity hashes safeguard extracted audio features. Signed, rollback-protected AI models and tamper-responsive sensors harden firmware and hardware. Data at rest follows a 3-2-1 strategy comprising a solid-state drive sealed with LUKS, an offline cold archive encrypted with a hybrid post-quantum cipher and an encrypted cloud replica. Finally, we set out a plan for evaluating the physical and logical security of the proposed protocol.

物联网安全音频分类后量子加密TPM

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。