A method and device for implementing API gateway based on SAAS cloud platform
By providing API gateway services to tenants on the SAAS cloud platform, the problem of low efficiency in API gateway management and deployment is solved, and efficient resource utilization and improved system security are achieved.
Patent Information
- Application Number
- CN202211499220.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-28
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2042-11-28
AI Technical Summary
With the development of cloud-native technologies, the importance and security of API gateways have increased significantly, but existing technologies make it difficult to efficiently manage and deploy API gateways on SAAS cloud platforms, resulting in low resource utilization and high costs.
Provide API gateway services to tenants through the SAAS cloud platform, allocate forwarding plane, control plane, network and database resources, implement configuration management and security protection of the API gateway, support elastic expansion and reduction, and perform traffic control and security testing through the API gateway.
It improves resource utilization, reduces resource deployment costs, and enhances system security and flexibility.
Smart Images

Figure CN115834481B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a method and device for implementing an API gateway based on a SAAS cloud platform. Background Art
[0002] APIs (Application Programming Interfaces) serve as a bridge for communication between programs and play a crucial role in data transmission. The development of cloud-native technologies, including containerization, orchestration, microservices, and service mesh, has made business architecture management more flexible. This has also led to a significant increase in the number of APIs used for communication between services and modules. To reduce coupling between services and enhance management flexibility, more and more basic service capabilities are being migrated to API gateways for unified processing.
[0003] API gateways serve as a unified entry point for north-south, east-west, and public / private APIs. With the rapid development of APIs, their importance and security have become increasingly prominent, and their additional functions have become increasingly numerous. SaaS cloud platforms, with their minimal deployment requirements and flexible management, have become the preferred deployment method for many software services. Summary of the Invention
[0004] In response to the above situation, the present invention provides an implementation method and device of an API gateway based on a SAAS cloud platform. Tenants can subscribe to related API gateway services according to their needs. This method and device provide tenants with unified API processing capabilities and security protection capabilities, facilitate tenants' use, and improve resource utilization and system security.
[0005] To achieve the above object, the present invention adopts the following technical solutions:
[0006] In one embodiment of the present invention, a method for implementing an API gateway based on a SAAS cloud platform is proposed, the method comprising:
[0007] Tenants subscribe to API gateway services from the SAAS cloud platform;
[0008] The SAAS cloud platform allocates API gateway forwarding plane resources, control plane resources, network resources, and database resources to tenants based on the API gateway services they subscribe to.
[0009] Tenants configure and manage the API gateway through the access method provided by the SAAS cloud platform, publish domain names and APIs through the control system of the SAAS cloud platform, and monitor the life cycle of the API.
[0010] The tenant's traffic is pulled to the API gateway based on the SAAS cloud platform through CNAME, and the API gateway implements proxy and security protection for the tenant's external API.
[0011] Furthermore, the control system of the SAAS cloud platform determines the business functions, resource information, security information, database resources, and network resource information required by the tenant based on the tenant information and the API gateway service information subscribed by the tenant.
[0012] Furthermore, the control system of the SAAS cloud platform transmits tenant information, resource information and security information to the resource management system of the SAAS cloud platform, transmits tenant information, database resources and security information to the database management system of the SAAS cloud platform, and transmits tenant information, network resource information and security information to the network management system of the SAAS cloud platform; the resource management system of the SAAS cloud platform creates the corresponding API gateway control system and API gateway forwarding system according to the API gateway service subscribed by the tenant; the database management system of the SAAS cloud platform creates the database and corresponding business tables according to the security information and database resources, and sets desensitization rules and encryption rules for the database data.
[0013] Furthermore, the control system and forwarding system of the API gateway are exclusive to a tenant or shared by multiple tenants, and are determined by the security level of the API gateway service subscribed by the tenant.
[0014] Furthermore, the control system of the API gateway determines the tenant information based on the email address or mobile phone number used by the user to log in. The database management system of the SAAS cloud platform obtains the tenant's management rights to the database based on the tenant information, and performs addition, deletion, modification and query of the API gateway policy data.
[0015] Furthermore, tenants configure routing matching rules, manage API versions, and manage API traffic control and security detection policies through the API gateway's control system.
[0016] Furthermore, the control system of the SAAS cloud platform automatically generates a CNAME based on the tenant's domain name information, and publishes the CNAME and the corresponding public address information to the cloud DNS system of the SAAS cloud platform, which then publishes the CNAME and public address information of the corresponding domain name to the outside world.
[0017] Furthermore, the API gateway's forwarding system offloads SSL based on SNI information, implements API forwarding through tenant-configured routing matching rules, and combines other value-added services to achieve API traffic control and security protection.
[0018] In one embodiment of the present invention, a device for implementing an API gateway based on a SAAS cloud platform is also proposed, the device comprising:
[0019] The control system of the SAAS cloud platform is used to determine the business functions, resource information, security information, database resources, and network resource information required by the tenant based on the tenant information and the API gateway service information subscribed by the tenant, transmit the tenant information, resource information, and security information to the resource management system of the SAAS cloud platform, transmit the tenant information, network resource information, and security information to the network management system of the SAAS cloud platform, and transmit the tenant information, database resources, and security information to the database management system of the SAAS cloud platform;
[0020] The resource management system of the SAAS cloud platform is used to allocate resources to tenants based on resource allocation applications submitted by the control system of the SAAS cloud platform;
[0021] The network management system of the SAAS cloud platform is used to manage tenant networks, establish communication channels between the control plane and forwarding plane of the tenant's API gateway, and allocate public network addresses for the tenant's external services;
[0022] The database management system of the SAAS cloud platform is used to create databases and corresponding business tables based on security information and data resource information, and set desensitization and encryption rules for database data;
[0023] The cloud DNS system of the SAAS cloud platform is used to publish the CNAME and public network address information corresponding to the tenant's domain name;
[0024] The API gateway's control system is used to configure routing matching rules, manage API versions, and manage API traffic control and security detection policies for tenants. It also publishes tenants' domain names and APIs and monitors the API lifecycle.
[0025] The API gateway's forwarding system is used to forward, control, and secure API traffic based on the policies configured by the API gateway's control system.
[0026] Furthermore, the resource management system of the SAAS cloud platform is also used to create a corresponding API gateway control system and an API gateway forwarding system based on the API gateway service subscribed by the tenant.
[0027] Furthermore, the control system and forwarding system of the API gateway are exclusive to a tenant or shared by multiple tenants, and are determined by the security level of the API gateway service subscribed by the tenant.
[0028] Furthermore, the database management system of the SAAS cloud platform is also used to obtain the tenant's management rights to the database based on the tenant information, and to add, delete, modify and query the API gateway policy data; the tenant information is determined by the control system of the API gateway based on the email address or mobile phone number used by the user to log in.
[0029] Furthermore, the control system of the SAAS cloud platform is also used to automatically generate a CNAME based on the tenant's domain name information, and publish the CNAME and the corresponding public network address information to the cloud DNS system of the SAAS cloud platform; the tenant's traffic is pulled to the forwarding system of the API gateway through the CNAME.
[0030] Furthermore, the API gateway's forwarding system is specifically used to:
[0031] SSL is unloaded based on SNI information, API traffic is forwarded through tenant-configured routing matching rules, and combined with other value-added services, API traffic control and security protection are achieved.
[0032] In one embodiment of the present invention, a computer device is also proposed, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the aforementioned API gateway based on the SAAS cloud platform is implemented.
[0033] In one embodiment of the present invention, a computer-readable storage medium is further proposed, which stores a computer program for executing the implementation of an API gateway based on a SAAS cloud platform.
[0034] Beneficial effects:
[0035] The present invention realizes API gateway based on SAAS cloud platform, improves resource utilization and reduces resource deployment cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 This is a flowchart of the implementation method of the API gateway based on the SAAS cloud platform of the present invention;
[0037] Figure 2 This is a schematic diagram of the structure of the implementation device of the API gateway based on the SAAS cloud platform of the present invention;
[0038] Figure 3 It is a schematic diagram of the computer device structure of the present invention. DETAILED DESCRIPTION
[0039] The principles and spirit of the present invention will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are provided solely to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.
[0040] Those skilled in the art will appreciate that embodiments of the present invention may be implemented as an apparatus, device, apparatus, method, or computer program product. Therefore, the present disclosure may be implemented in the following forms: entirely in hardware, entirely in software (including firmware, resident software, microcode, etc.), or in a combination of hardware and software.
[0041] According to the implementation mode of the present invention, a method and device for implementing an API gateway based on a SAAS cloud platform are proposed. The method and device provide tenants with API gateway services based on a SAAS cloud platform. Tenants publish APIs to the outside world through the subscribed API gateway services, and perform traffic control and security protection on the API traffic passing through the API gateway in accordance with the subscribed API gateway services. The API gateway can also be elastically expanded and reduced in capacity according to the needs of the tenants.
[0042] The principles and spirit of the present invention are explained in detail below with reference to several representative embodiments of the present invention.
[0043] Figure 1 This is a flow chart of the implementation method of the API gateway based on the SAAS cloud platform of the present invention. Figure 1 As shown, the method includes:
[0044] S1. The tenant subscribes to the API gateway service from the SAAS cloud platform;
[0045] Tenants purchase API gateway services through the SAAS cloud platform's subscription system, including the API gateway version, concurrency, SLA, subscription duration, security level, security services, and other value-added services.
[0046] S2. The SAAS cloud platform allocates API gateway forwarding resources, control plane resources, network resources, and database resources to tenants based on the API gateway service they subscribe to.
[0047] The control system of the SAAS cloud platform determines the business functions, resource information, security information, database resources, and network resource information required by the tenant based on the tenant information and the API gateway service information subscribed by the tenant.
[0048] Security information includes security level, data isolation level and security protection function;
[0049] Resource information includes API concurrency, latency, data capacity, and infrastructure resources required for the forwarding system, such as CPU, memory, and network cards.
[0050] Network resource information includes the public network address of the API corresponding business and intranet configuration information.
[0051] The control system of the SAAS cloud platform transmits tenant information, resource information and security information to the resource management system of the SAAS cloud platform, transmits tenant information, database resources and security information to the database management system of the SAAS cloud platform, and transmits tenant information, network resource information and security information to the network management system of the SAAS cloud platform.
[0052] The database management system of the SAAS cloud platform creates a database and corresponding business tables based on security information and data resource information, and sets desensitization rules and encryption rules for database data.
[0053] The resource management system of the SAAS cloud platform creates the corresponding API gateway control system and API gateway forwarding system based on the API gateway service subscribed by the tenant.
[0054] The control system of the API gateway can be deployed independently from the forwarding system of the API gateway. In cluster mode or under the same tenant, the forwarding systems of multiple API gateways can be managed by one API gateway control system.
[0055] The control system and forwarding system of the API gateway can be exclusive to a tenant or shared by multiple tenants, and are determined by the security level of the API gateway service subscribed by the tenant.
[0056] After successful resource allocation, database creation, and network configuration, that is, successful API gateway instantiation, the SAAS cloud platform provides tenants with access to API configuration management, generally web access, which provides access paths and login methods.
[0057] The forwarding system of API gateway is classified according to different classification methods, which can be divided into cluster type and single instance, exclusive type and shared type. It can also be classified according to different versions and the type of infrastructure.
[0058] The SAAS cloud platform can expand and shrink the API gateway according to the needs of tenants.
[0059] S3. Tenants configure and manage the API gateway through the access method provided by the SAAS cloud platform, publish domain names and APIs through the control system of the SAAS cloud platform, and monitor the life cycle of the API.
[0060] The control system of the API gateway determines the tenant information based on the email address or mobile phone number used by the user to log in. The database management system of the SAAS cloud platform obtains the tenant's management rights to the database based on the tenant information, and performs addition, deletion, modification and query of API gateway policy data.
[0061] Tenants use the API gateway's control system to configure routing matching rules, manage API versions, control API traffic, and manage security detection policies.
[0062] S4. The tenant's traffic is pulled to the API gateway based on the SAAS cloud platform through CNAME (alias record), and the API gateway implements proxy and security protection for the tenant's external API.
[0063] The control system of the SAAS cloud platform automatically generates a CNAME based on the tenant's domain name information, and publishes the CNAME and the corresponding public address information to the cloud DNS system of the SAAS cloud platform. The cloud DNS system of the SAAS cloud platform then publishes the CNAME and public address information of the corresponding domain name to the outside world.
[0064] The API gateway's forwarding system performs SSL offloading based on SNI (Server Name Indication, server name, the domain name configured by the tenant is SNI) information, implements API traffic forwarding through the routing matching rules configured by the tenant, and combines other value-added services to achieve API traffic control and security protection.
[0065] It should be noted that although the operations of the method of the present invention are described in a specific order in the above embodiments and drawings, this does not require or imply that these operations must be performed in this specific order, or that all illustrated operations must be performed to achieve the desired results. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0066] Based on the same inventive concept, the present invention also proposes an implementation device for an API gateway based on a SAAS cloud platform. The implementation of the device can refer to the implementation of the above method, and the repeated parts will not be repeated. The term "module" used below can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.
[0067] Figure 2 This is a schematic diagram of the implementation structure of the API gateway based on the SAAS cloud platform of the present invention. Figure 2 As shown, the device includes:
[0068] The control system 101 of the SAAS cloud platform is used to determine the business functions, resource information, security information, database resources and network resource information required by the tenant based on the tenant information and the API gateway service information subscribed by the tenant, and transmit the tenant information, resource information and security information to the resource management system of the SAAS cloud platform, transmit the tenant information, network resource information and security information to the network management system of the SAAS cloud platform, and transmit the tenant information, database resources and security information to the database management system of the SAAS cloud platform; it is also used to automatically generate CNAME based on the tenant's domain name information, and publish the CNAME and the corresponding public network address information to the cloud DNS system of the SAAS cloud platform; the tenant's traffic is pulled to the forwarding system of the API gateway through the CNAME.
[0069] The resource management system 102 of the SAAS cloud platform is used to allocate resources to tenants based on the resource allocation application submitted by the control system of the SAAS cloud platform; it is also used to create a corresponding API gateway control system and an API gateway forwarding system based on the API gateway service subscribed by the tenant.
[0070] The control system and forwarding system of the API gateway are exclusive to the tenant or shared by multiple tenants, and are determined by the security level of the API gateway service subscribed by the tenant.
[0071] The network management system 103 of the SAAS cloud platform is used to manage the tenant network, establish a communication channel between the control plane and the forwarding plane of the tenant's API gateway, and allocate public network addresses for the tenant's external services.
[0072] The database management system 104 of the SAAS cloud platform is used to create a database and corresponding business tables based on security information and data resource information, and set desensitization rules and encryption rules for database data; it is also used to obtain the tenant's management rights to the database based on the tenant information, and to add, delete, modify and query API gateway policy data; the tenant information is determined by the control system of the API gateway based on the email address or mobile phone number used by the user to log in.
[0073] The cloud DNS system 105 of the SAAS cloud platform is used to publish the CNAME and public network address information corresponding to the tenant's domain name.
[0074] The control system 106 of the API gateway is used to provide tenants with configuration of routing matching rules, API version management, and management of API flow control and security detection policies, and to publish tenants' domain names and APIs externally, while monitoring the API life cycle.
[0075] The forwarding system 107 of the API gateway is used to forward, control, and protect API traffic according to the policies configured by the control system of the API gateway. The details are as follows:
[0076] SSL is unloaded based on SNI information, API traffic is forwarded through tenant-configured routing matching rules, and combined with other value-added services, API traffic control and security protection are achieved.
[0077] It should be noted that although several modules of the implementation device of the API gateway based on the SAAS cloud platform are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to an embodiment of the present invention, the features and functions of two or more modules described above can be concretized in one module. Conversely, the features and functions of one module described above can be further divided into multiple modules for concretization.
[0078] Based on the above invention concept, Figure 3 As shown, the present invention also proposes a computer device 200, including a memory 210, a processor 220 and a computer program 230 stored in the memory 210 and executable on the processor 220. When the processor 220 executes the computer program 230, the aforementioned API gateway based on the SAAS cloud platform is implemented.
[0079] Based on the aforementioned inventive concept, the present invention further proposes a computer-readable storage medium, which stores a computer program for executing the aforementioned implementation of the API gateway based on the SAAS cloud platform.
[0080] The present invention proposes a method and device for implementing an API gateway based on a SAAS cloud platform, which implements an API gateway based on a SAAS cloud platform, thereby improving resource utilization and reducing resource deployment costs.
[0081] Although the spirit and principles of the present invention have been described with reference to several specific embodiments, it should be understood that the present invention is not limited to the specific embodiments disclosed, and the division into various aspects does not mean that the features of these aspects cannot be combined to benefit. Such division is only for the convenience of expression. The present invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
[0082] Regarding the limitation of the protection scope of the present invention, those skilled in the art should understand that, based on the technical solution of the present invention, various modifications or variations that can be made by those skilled in the art without creative work are still within the protection scope of the present invention.
Claims
1. A method for implementing an API gateway based on a SAAS cloud platform, characterized in that: The method includes: Tenants subscribe to API gateway services from the SAAS cloud platform; The SAAS cloud platform allocates API gateway forwarding plane resources, control plane resources, network resources, and database resources to tenants based on the API gateway services they subscribe to. Tenants configure and manage the API gateway through the access method provided by the SAAS cloud platform, publish domain names and APIs through the control system of the SAAS cloud platform, and monitor the life cycle of the API. The control system of the SAAS cloud platform determines the business functions, resource information, security information, database resources, and network resource information required by the tenant based on the tenant information and the API gateway service information subscribed by the tenant; The control system of the SAAS cloud platform transmits tenant information, resource information, and security information to the resource management system of the SAAS cloud platform, transmits tenant information, database resources, and security information to the database management system of the SAAS cloud platform, and transmits tenant information, network resource information, and security information to the network management system of the SAAS cloud platform; the resource management system of the SAAS cloud platform creates the corresponding API gateway control system and API gateway forwarding system based on the API gateway service subscribed by the tenant; the database management system of the SAAS cloud platform creates the database and corresponding business tables based on the security information and database resources, and sets desensitization rules and encryption rules for the database data; The tenant's traffic is pulled to the API gateway based on the SAAS cloud platform through CNAME, and the API gateway implements proxy and security protection for the tenant's external API.
2. The method for implementing the API gateway based on the SAAS cloud platform according to claim 1, characterized in that: The control system and forwarding system of the API gateway are exclusive to a tenant or shared by multiple tenants, and are determined by the security level of the API gateway service subscribed by the tenant.
3. The method for implementing an API gateway based on a SAAS cloud platform according to claim 1, characterized in that: The control system of the API gateway determines the tenant information based on the email address or mobile phone number used by the user to log in. The database management system of the SAAS cloud platform obtains the tenant's management authority over the database based on the tenant information, and performs addition, deletion, modification and query of API gateway policy data.
4. The method for implementing an API gateway based on a SAAS cloud platform according to claim 1, characterized in that: Tenants use the API gateway's control system to configure routing matching rules, manage API versions, and manage API traffic control and security detection policies.
5. The method for implementing the API gateway based on the SAAS cloud platform according to claim 1, characterized in that: The control system of the SAAS cloud platform automatically generates a CNAME based on the tenant's domain name information, and publishes the CNAME and the corresponding public address information to the cloud DNS system of the SAAS cloud platform. The cloud DNS system of the SAAS cloud platform publishes the CNAME and public address information of the corresponding domain name to the outside world.
6. The method for implementing an API gateway based on a SAAS cloud platform according to claim 1, characterized in that: The forwarding system of the API gateway performs SSL unloading based on SNI information, implements API forwarding through routing matching rules configured by tenants, and combines other value-added services to achieve API traffic control and security protection.
7. An implementation device of an API gateway based on a SAAS cloud platform, characterized in that: The device includes: The control system of the SAAS cloud platform is used to determine the business functions, resource information, security information, database resources, and network resource information required by the tenant based on the tenant information and the API gateway service information subscribed by the tenant, transmit the tenant information, resource information, and security information to the resource management system of the SAAS cloud platform, transmit the tenant information, network resource information, and security information to the network management system of the SAAS cloud platform, and transmit the tenant information, database resources, and security information to the database management system of the SAAS cloud platform; The resource management system of the SAAS cloud platform is used to allocate resources to tenants based on resource allocation applications submitted by the control system of the SAAS cloud platform; The network management system of the SAAS cloud platform is used to manage tenant networks, establish communication channels between the control plane and forwarding plane of the tenant's API gateway, and allocate public network addresses for the tenant's external services; The database management system of the SAAS cloud platform is used to create databases and corresponding business tables based on security information and data resource information, and set desensitization and encryption rules for database data; The cloud DNS system of the SAAS cloud platform is used to publish the CNAME and public network address information corresponding to the tenant's domain name; The API gateway's control system is used to configure routing matching rules, manage API versions, and manage API traffic control and security detection policies for tenants. It also publishes tenants' domain names and APIs and monitors the API lifecycle. The API gateway's forwarding system is used to forward, control, and secure API traffic based on the policies configured by the API gateway's control system.
8. The implementation device of the API gateway based on the SAAS cloud platform according to claim 7 is characterized in that: The resource management system of the SAAS cloud platform is also used to create a corresponding API gateway control system and an API gateway forwarding system according to the API gateway service subscribed by the tenant.
9. The implementation device of the API gateway based on the SAAS cloud platform according to claim 8, characterized in that: The control system and forwarding system of the API gateway are exclusive to a tenant or shared by multiple tenants, and are determined by the security level of the API gateway service subscribed by the tenant.
10. The implementation device of the API gateway based on the SAAS cloud platform according to claim 7, characterized in that: The database management system of the SAAS cloud platform is also used to obtain the tenant's management rights to the database based on the tenant information, and to add, delete, modify and query the API gateway policy data; the tenant information is determined by the control system of the API gateway based on the email address or mobile phone number used by the user to log in.
11. The implementation device of the API gateway based on the SAAS cloud platform according to claim 7, characterized in that: The control system of the SAAS cloud platform is also used to automatically generate a CNAME based on the tenant's domain name information, and publish the CNAME and the corresponding public address information to the cloud DNS system of the SAAS cloud platform; the tenant's traffic is pulled to the forwarding system of the API gateway through the CNAME.
12. The implementation device of the API gateway based on the SAAS cloud platform according to claim 7, characterized in that: The forwarding system of the API gateway is specifically used to: SSL is unloaded based on SNI information, API traffic is forwarded through tenant-configured routing matching rules, and combined with other value-added services, API traffic control and security protection are achieved.
13. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.
14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program for executing the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
API gateway implementation method suitable for public cloud platform
CN114221949A
Message processing method and gateway
WO2015096005A1