API access control method and API access agent device

An access control and access agent technology, applied in the computer field, can solve the problem of lack of dynamic access identity adaptive access control, etc., and achieve the effect of enhancing security

Active Publication Date: 2019-10-01
BEIJING QIANXIN TECH
View PDF7 Cites 6 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Most of the existing API access control is based on the anti-access authentication method based on static rules, and lacks adaptive access control based on dynamic access identities. When the identity of the anti-access subject changes, it is difficult to perceive it in time and make a corresponding response

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • API access control method and API access agent device
  • API access control method and API access agent device
  • API access control method and API access agent device

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0024] In order to make the purpose, features and advantages of the present invention more obvious and understandable, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described The embodiments are only some of the embodiments of the present invention, but not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts belong to the protection scope of the present invention.

[0025] In the embodiment of the present invention, the access proxy device takes an API access proxy device as an example. The API access proxy device is a mandatory policy enforcement point when accessing the data service API, referred to as "API proxy". The API proxy cooperates with the access control system to verify and prevent Asking the...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

An API access control method is applied to the technical field of computers and comprises the steps that in the process of when a user accesses controlled API resources through a front application, intercepting an access request sent by the user through the front application; identifying an access main body of the access request, wherein the access main body comprises identification of identity information of the front application, server equipment information of the front application, and / or a user identity for accessing the front application and equipment information of a user terminal; performing continuous evaluation based on the time information, the space information and the environment information of the access request and / or the access behavior of the access subject; and when the time information, the space information, the environment information and / or the behavior track of the access request are / is changed, responding to the access request based on a preset access authentication mode and / or a preset access control strategy. The invention further discloses an API access agent device.

Description

technical field [0001] The invention relates to the field of computer technology, in particular to an API access control method and an API access agent device. Background technique [0002] With the development of the Internet, more and more platforms open their application programming interfaces (Application Programming Interface, API) for third-party applications (application, APP) to call. Most of the existing API access control is based on anti-access authentication methods based on static rules, and lacks adaptive access control based on dynamic access identities. When the identity of the anti-access subject changes, it is difficult to perceive it in time and make a corresponding response. Contents of the invention [0003] The main purpose of the present invention is to provide an API access control method and an API access proxy device, which can make continuous authorization decisions when the user's access environment changes, and execute responses according to th...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
CPCH04L63/0807H04L63/0876H04L63/0884H04L63/102
Inventor 简明魏勇张泽洲左英男
Owner BEIJING QIANXIN TECH
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products