12 | Zero-trust solution baseline
Global Security & Governance:两条入口、三层工作负载、一套控制面
Web / mobile API 经 Front Door 与 WAF;设备消息直接进入 IoT Hub / DPS。身份、密钥、防护、观测和数据生命周期通过虚线控制面覆盖应用、设备、AI 与数据层。
CHANNELS & DEVICES
APPLICATION & DEVICE SERVICES
区域化工作负载
AI & DATA
最小权限 + 生命周期
TRUST OUTCOMES
Web / mobile API
device messaging
Consumer web / mobile
customer identity · TLS
global API entry
SwitchBot device fleet
device certificate · trusted update
local-first / event-level upload
Front Door + WAF
Web / API only
TLS · WAF · regional routing
Regional APIs
managed identity
private endpoints where needed
IoT Hub / DPS
device identity · messaging
allocation · twin · commands
Device operations
update · monitor
fleet risk signals
AI services
model / prompt / tool trace
evaluation + safety
Data services
classification · retention
region · encryption
Private access
network boundaries
service allowlists
Optional confidential
specific sensitive workloads
SKU / region / perf review
Cross-cutting security control plane
Entra ID · Key Vault · Defender for Cloud / IoT · Azure Monitor · policy-as-code · audit / deletion workflows
Global service trust
consistent identity
regional controls
Consumer privacy
local-first · minimal data
transparent lifecycle
Enterprise readiness
audit evidence
security review inputs
数据 / 事件 / API 流
控制 / 策略 / 治理
SwitchBot / edge
Microsoft Azure
业务结果
边界:Front Door 仅保护 Web / API;设备消息不经过 Front Door。Defender for IoT 仅面向适配的 B2B / OT / Enterprise IoT 网络。
Business outcome
用一致安全基线支持全球扩展、企业采购审查与消费者信任。
Azure role
Front Door / WAF、Entra、Key Vault、Defender for Cloud、Monitor 与数据策略形成控制面;机密计算仅按需评估。