The invention discloses an Internet-of-Things
equipment safety protection system and method. The problems that in the prior art, security holes exist in hardware and
software of Internet-of-Things equipment, the security of communication
encryption and decryption is not high, and the efficiency ratio is low are solved. The
system comprises a device and a
server, the device comprises an MCU controller, the MCU controller comprises a secure area and a non-secure area, a trusted execution environment is deployed in the secure area, a non-secure environment is deployed in the non-secure area, and a startup loading module, a secure kernel module, a secure component module, a
trusted application and a secure API interface module are arranged in the trusted execution environment. A user application and a non-secure kernel module are arranged in the non-secure environment. Sensitive data storage access is protected through three-layer protection measures. Information
encryption and decryption between the equipment and the
server are verified by adopting an identity token. Security protection is carried out from equipment hardware,
software, storage access and communication, and hardware control,
software cracking and information stealing are prevented.