《电子技术应用》
您所在的位置:首页 > 通信与网络 > 设计应用 > 工业互联网供应链安全治理研究
工业互联网供应链安全治理研究
网络安全与数据治理
李正文1,2,董良遇1,2
1.国家工业信息安全发展研究中心; 2.工业信息安全感知与评估技术工业和信息化部重点实验室
摘要: 针对工业互联网供应链面临的新型安全威胁与治理困境,系统分析了供应链攻击面的结构性特征、典型攻击类型及其演进趋势,识别出供应链透明度不足、工业环境固有约束、跨组织信任缺失及检测能力局限等核心技术挑战。在此基础上,构建供应链安全风险量化评估模型,并设计涵盖技术防护、供应商管控与监管合规的三层治理框架,以评估模型输出结果驱动供应商分级管控决策。该框架以零信任架构向供应链延伸及安全左移为设计原则,从完整性保障、身份访问控制、威胁检测响应、供应商分级准入、合同标准化、第四方风险穿透管理及法规协同等方面构建纵深防御体系。研究成果可为工业互联网平台运营方、设备制造商及行业监管机构提供系统化的安全治理参考路径。
中图分类号:TP393.08文献标志码:ADOI:10.19358/j.issn.2097-1788.2026.06.004中文引用格式:李正文,董良遇.工业互联网供应链安全治理研究[J].网络安全与数据治理,2026,45(6):24-30.
英文引用格式:Li Zhengwen,Dong Liangyu.Research on supply chain security governance of industrial internet[J].Cyber Security and Data Governance,2026,45(6):24-30.
Research on supply chain security governance of industrial internet
Li Zhengwen1,2,Dong Liangyu1,2
1. China Industrial Control Systems Cyber Emergency Response Team; 2. Key Laboratory of Industrial Information Security Perception and Evaluation Technology, Ministry of Industry and Information Technology
Abstract: Addressing the emerging security threats and governance challenges faced by the industrial internet supply chains,this paper systematically analyzes the structural characteristics of supply chain attack surfaces,typical attack patterns,and their evolutionary trends,identifying four core technical challenges:insufficient supply chain transparency,inherent constraints of industrial environments,absence of crossorganizational trust mechanisms,and limited threat detection capabilities.Building on this analysis,a quantitative supply chain security risk assessment model is constructed,and a threelayer governance framework encompassing technical protection,supplier management,and regulatory compliance is proposed,with modelderived risk indices driving tiered supplier control decisions.The framework adopts the extension of zerotrust architecture to supply chains and securitybydesign as its core principles,establishing a defenseindepth system that spans integrity assurance,identity and access control,threat detection and response,tiered supplier admission,contract standardization,fourthparty risk penetration management,and regulatory coordination.The findings provide a systematic security governance reference for industrial internet platform operators,equipment manufacturers,and industry regulators.
Key words : industrial internet; supply chain security; security governance

引言

在“工业4.0”与“中国制造2025”战略的双重驱动下,工业互联网作为新一代信息通信技术与工业经济深度融合形成的新型基础设施、应用模式和工业生态[1],既是承载新质生产力实践价值的关键领域,也是推动新质生产力培育成型的核心支撑,对推进经济高质量发展具有重要意义。随着工业互联网发展加速向纵深拓展,其供应链日益呈现出数字化、全球化发展趋势[2],从原材料采购到硬件制造,从固件分发到软件集成,再到云端服务与数据流转,每一环节都涉及数量庞大、来源多元的供应主体,导致供应链潜在攻击面持续扩大,硬件篡改、软件后门注入、开源组件投毒等新型供应链安全威胁频发,亟须构建覆盖设计、开发、集成、运维全生命周期,由技术防护、安全管控、监管合规共同构成的韧性安全治理框架。


本文详细内容请下载:

http://www.chinaaet.com/resource/share/2000007123


作者信息:

李正文1,2,董良遇1,2

(1.国家工业信息安全发展研究中心,北京100040;

2.工业信息安全感知与评估技术工业和信息化部重点实验室,北京100040)

2.jpg

此内容为AET网站原创,未经授权禁止转载。