API (Application Program Interface) management and security protection measure method and device and electronic equipment
By sorting out the asset catalog to form a data resource list, generating different types of shared data based on the attributes of the business data, publishing corresponding API interfaces, and combining user call information for security protection, the API interface is easily prone to data leakage and service interruption, and the security, compliance and effective utilization of data are achieved.
Patent Information
- Application Number
- CN202411970493.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
Due to the openness and accessibility of the API, the API interface is prone to serious consequences such as data leakage and service interruption.
By sorting out the asset catalog to form a data resource list, different types of shared data are generated based on the shared attributes, sensitivity and openness of the business data, and corresponding API interfaces are published based on different types of shared data, and security protection operations are carried out based on user call information and authentication information.
It has achieved comprehensive protection of data security, compliance and effective utilization from data identification, classification, grading to dynamic monitoring and sharing, and prevents data leakage and service interruption.
Smart Images

Figure CN119939650A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of interface data security management, and in particular to an API interface management and security protection measure method, device and electronic equipment. Background Art
[0002] With the popularization and development of the Internet, API technology has become the cornerstone of enterprise digital transformation. It connects various services, transmits data and controls systems, and has become an indispensable part of the modern digital business environment. API has expanded from the interface called internally by early software to the interface that provides external services on the Internet; by calling the API, the caller can obtain the various services provided by the interface.
[0003] With the widespread use of APIs, their security issues have become increasingly prominent and have become a challenge that companies have to face. Due to the openness and accessibility of APIs, they have become the main target of attackers. Once an API is attacked, it will not only lead to serious consequences such as data leakage and service interruption, but also cause huge losses to the company's reputation and interests. Summary of the invention
[0004] In view of this, it is necessary to provide an API interface management and security protection method, device and electronic device to solve the technical problems in the prior art that due to the openness and accessibility of the API, the API interface is prone to serious consequences such as data leakage and service interruption.
[0005] In order to solve the above problems, the present invention provides an API interface management and security protection method, please refer to Figure 1 ,include: Based on business data and data management rules, sort out the asset catalog to form a data resource list; Based on the data resource list, different types of shared data are generated according to the sharing attributes, sensitivity and openness of business data; Publish corresponding API interfaces according to different types of shared data; Based on the matching relationship between the user's call information and authentication information and the key rules set by the API interface, security protection operations are performed on the API and shared data.
[0006] In a possible implementation, combing the asset catalog and forming a data resource list according to the business data and data management rules includes: Obtain business data according to the basic information category of business data; Based on data security specifications and data classification regulations, classify business data according to the attributes of business data and build a business data classification model; Based on the classification and grading model and business data, the asset catalog is sorted out and a data resource list is formed.
[0007] In a possible implementation, combing the asset catalog and forming a data resource list according to the classification and grading model and business data includes: Based on the classification results, the data in the business database and its metadata are stored in the data warehouse; Use the preset machine learning analysis method to identify the stored data and divide the data assets to obtain the data asset catalog; According to the data asset catalog, obtain the data resource list; After obtaining the data resource list, the method further includes: enhancing the sensitive fields in the data resource list to obtain the target data resource list.
[0008] In a possible implementation, combing the asset catalog and forming a data resource list according to the business data and data management rules further includes: Acquire real-time data assets based on preset scanning cycles and scheduled tasks; Matching the real-time data assets with the business data classification and grading model to determine the sensitivity and classification of each real-time data asset; Dynamically update the business data classification and grading model and data resource list based on the sensitivity and classification results of real-time data assets.
[0009] In a possible implementation, after determining the sensitivity and classification of the real-time data asset, the following is further included: Process the text data of real-time data assets to determine valid information; Based on the effective information of real-time data assets, determine the relationship between the sensitivity level of real-time data assets and the sensitivity threshold; If the sensitivity level of the real-time data asset is greater than the sensitivity threshold, access control and encryption processing will be performed on the real-time data asset.
[0010] In a possible implementation, based on the data resource list, different types of shared data are generated according to sharing attributes, sensitivity and openness, including: The sharing attributes include the sharing scope, access rights and usage conditions of the business data; The sensitivity level includes the importance and potential risks of business data; The degree of opening includes fully open, semi-open and fully closed; The sharing attributes, sensitivity and openness are arranged and combined to determine the type of shared data, where the type of shared data at least includes original data, desensitized data, encrypted data and watermarked data.
[0011] In a possible implementation, the method further includes: Monitor shared data in real time to determine API usage.
[0012] In a second aspect, the present invention further provides an API interface management and security protection device, comprising: The data asset list building module is used to sort out the asset catalog to form a data resource list based on business data and data management rules; A shared data generation module is used to generate different types of shared data based on the data resource list and according to the sharing attributes, sensitivity and openness of business data; API interface publishing module, used to publish corresponding API interfaces according to different types of shared data; The security protection module is used to perform security protection operations on the API and shared data based on the matching relationship between the user's call information and the user's authentication information and the key rules set by the API interface.
[0013] In a third aspect, the present invention further provides an electronic device, comprising: a processor and a memory; The memory stores a computer-readable program executable by the processor; When the processor executes the computer-readable program, the steps in the API interface management and security protection measures method as described above are implemented.
[0014] In a fourth aspect, the present invention also provides a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps in the API interface management and security protection measures method as described above.
[0015] The beneficial effects of the present invention are: first, according to the business data and data management rules, the asset catalog is sorted out and a data resource list is formed; by classifying and grading the business data, on the one hand, the data can be managed from the life cycle of the data asset, and on the other hand, by classifying and grading the data, it is convenient for visual observation and monitoring, and then based on the data resource list, different types of shared data are generated according to the sharing attributes, sensitivity and degree of openness; and corresponding API interfaces are released according to different types of shared data. This application achieves the purpose of comprehensively ensuring the security, compliance and effective use of data from identification, classification, grading to dynamic monitoring and sharing. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 A method flow chart of an embodiment of the API interface management and security protection method provided by the present invention; Figure 2 for Figure 1 In step S101, the asset list is updated in real time; Figure 3 It is a schematic diagram of an embodiment of the API interface management and security protection measure device provided by the present invention; Figure 4 It is a schematic diagram of the operating environment of an electronic device provided by the present invention. DETAILED DESCRIPTION
[0017] The preferred embodiments of the present invention are described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not used to limit the scope of the present invention.
[0018] A specific embodiment of the present invention discloses an API interface management and security protection method, please refer to Figure 1 ,include: S101. According to business data and data management rules, sort out the asset catalog to form a data resource list; S102. Based on the data resource list, generate different types of shared data according to the sharing attributes, sensitivity and openness of the business data; S103. Release corresponding API interfaces according to different types of shared data; S104: Perform security protection operations on the API and shared data according to the matching relationship between the user's calling information and the user's authentication information and the key rules set by the API interface.
[0019] In this embodiment, in order to effectively deal with the data security issues brought by the API in the application process, by dividing the directory according to the department, business, level, etc. to which the interface assets belong, the return data of the server is graded at different levels and granularities, and sensitive assets are actively identified and evaluated, so as to realize automatic identification of API assets and finally form an asset list. Real-time monitoring and analysis of API usage, strict implementation of identity authentication and identity verification mechanisms, through different permissions of the access subject, so that users with different permissions can get different data from the same interface service, solve the security and management problems related to API interface management. First, according to business data and data management rules, the asset directory is sorted out and a data resource list is formed; by classifying and grading business data, on the one hand, data can be managed from the life cycle of data assets, and on the other hand, by classifying and grading data, it is convenient for visual observation and monitoring, and then based on the data resource list, different types of shared data are generated according to shared attributes, sensitivity and openness; and according to different types of shared data, corresponding API interfaces are released. This application achieves the purpose of comprehensively ensuring the security, compliance and effective use of data from identification, classification, grading to dynamic monitoring and sharing. Finally, dynamic API keys are generated based on user identity, role, level, etc., and the API is encrypted, desensitized, watermarked, limited, and tamper-proofed with other technical means, which can ensure data security to a certain extent. At the same time, combined with identity authentication and identity verification mechanisms, users with the same permissions can obtain different data from the same interface service.
[0020] It should be noted that a data asset inventory is a detailed document or database that records the relevant information of all data assets within an organization. The following are the main contents usually included in a data asset inventory: 1. Basic information of data assets Data asset name: The unique identification name of the data asset.
[0021] Data asset identifier: An internal code or number used to uniquely identify a data asset.
[0022] Data type: The type of data (such as text, image, video, audio, structured data, etc.).
[0023] Data format: The storage format of the data (such as CSV, JSON, XML, binary file, etc.).
[0024] Data source: the source of the data (such as database, file system, API interface, etc.).
[0025] Data usage: The primary purpose of the data (e.g. business analysis, customer service, internal management, etc.).
[0026] 2. Data storage information Storage location: The specific storage location of the data (such as database name, table name, file path, etc.).
[0027] Storage device: A physical or virtual device that stores data (such as a server, cloud storage, disk array, etc.).
[0028] Storage capacity: The storage capacity of data (such as file size, database capacity, etc.).
[0029] Backup strategy: data backup frequency and backup location.
[0030] Archiving strategy: data archiving strategy and archiving location.
[0031] 3. Data access information Access permissions: Access permissions for data (such as roles, user groups, and specific users).
[0032] Access method: the method of accessing data (such as API interface, database query, file access, etc.).
[0033] Access control: data access control policy (such as authentication, authorization, auditing, etc.).
[0034] Access frequency: How often the data is accessed (e.g. daily, weekly, monthly, etc.).
[0035] 4. Data classification and classification information Data classification: classification of data (such as user data, business data, system data, etc.).
[0036] Data sensitivity level: The sensitivity of the data (such as low, medium, and high sensitivity).
[0037] Classification basis: specific basis and standards for data classification.
[0038] Classification basis: the specific basis and standards for data classification.
[0039] 5. Data Security Information Security policy: data security policy (such as encryption, desensitization, access control, etc.).
[0040] Encryption information: data encryption method and encryption key management.
[0041] Desensitized information: data desensitization methods and desensitization rules.
[0042] Security Audit: Data security audit records and audit policies.
[0043] 6. Data life cycle information Data creation time: the time when the data was created.
[0044] Data update time: The time when the data was last updated.
[0045] Data validity period: the expected validity period or retention period of the data.
[0046] Data deletion policy: data deletion policy and deletion time.
[0047] 7. Data Compliance Information Compliance standards: Compliance standards that data needs to comply with (such as GDPR, HIPAA, CCPA, etc.).
[0048] Compliance review: data compliance review records and review results.
[0049] Compliance measures: Specific steps taken to ensure compliance.
[0050] 8. Data liability information Data Owner: The owner or person responsible for data assets.
[0051] Data Administrator: An administrator responsible for the day-to-day management of data.
[0052] Data custodian: A custodian responsible for data storage and security.
[0053] Data consumers: the users or systems that actually use the data.
[0054] 9. Data value information Data value assessment: data value assessment results (such as commercial value, operational value, etc.).
[0055] Data importance: the importance of data (such as core data, key data, general data, etc.).
[0056] 10. Data version information Data version number: The version number or revision number of the data.
[0057] Version change record: data version change record and change reasons.
[0058] In some embodiments, combing the asset catalog and forming a data resource list according to the business data and data management rules includes: Obtain business data according to the basic information category of business data; Based on data security specifications and data classification regulations, classify business data according to the attributes of business data and build a business data classification model; Based on the classification and grading model and business data, the asset catalog is sorted out and a data resource list is formed.
[0059] In this embodiment, through the combination of data collection, questionnaire survey, customer provision and tool combing, the basic information required for classification and grading is obtained according to the six dimensions of "people, places, things, emotions, and organizations", and the classification and grading guidelines for the system services in a certain area are formed with reference to GB_T 35273-2020 "Information Security Technology Personal Information Security Specification", Personal Information Protection Law, Data Security Law, and GB_T 43697-2024 "Data Security Technology and Other Data Classification and Grading Rules". During the implementation process, according to the business attributes, implementation specifications and specific business attributes, a combination of active and passive methods is adopted to define the basic business attributes into 1-4 security levels to form a classification and grading model system.
[0060] In step S104, according to the matching relationship between the user's call information and the user's authentication information and the key rules set by the API interface, security protection operations are performed on the API and shared data, specifically including: through the user's call information and matching the user's authentication information, whether the API interface key rules are met, the number of interface calls, authentication information, call time, total number of restrictions, frequency, IP and other information, to determine whether the current API interface is within the normal threshold range, if it encounters an attack, whether to adopt a fuse strategy and a blacklist and whitelist strategy. Among them, a key management system (KMS) or a custom algorithm is used to generate an encryption key containing API interface information, combined with identity authentication and identity verification mechanisms to ensure that only legitimate users can access the API, and return corresponding data according to user permissions. Thereby achieving personalized data access control and ensuring data security and compliance.
[0061] In some embodiments, combing the asset catalog and forming a data resource list according to the classification and grading model and business data includes: Based on the classification results, the data in the business database and its metadata are stored in the data warehouse; Use the preset machine learning analysis method to identify the stored data and divide the data assets to obtain the data asset catalog; According to the data asset catalog, obtain the data resource list; After obtaining the data resource list, the method further includes: enhancing the sensitive fields in the data resource list to obtain the target data resource list.
[0062] In this embodiment, through policy interpretation, specification sorting and business research, the business database and metadata are registered and stored, and the stored data is learned and analyzed through machine learning and integrated learning methods to understand and utilize the data, automatically identify data assets, sort out and profile the asset catalog, and combine the classified and graded business attributes. If the resource involves sensitive fields, a data resource list is formed according to the field data volume and field security level. As shown in Table 1.
[0063] Table 1: List of data resources
[0064] It should be noted that the role of a data inventory is to help organizations systematically manage their data assets and ensure data security, compliance, and availability. A data inventory is a detailed list of all types of data held and used by an organization. It usually includes the following: Data type: structured data (such as databases), unstructured data (such as documents, images).
[0065] Data source: the data acquisition channel and source system.
[0066] Data usage: application scenarios of data in business processes.
[0067] Data field: the name and data type of each field in the data structure.
[0068] Data volume: data storage capacity, number of records, etc.
[0069] Update frequency: the time period for data update.
[0070] The security level and sensitivity of the data, the classification of the data (such as personal data and business data), the person responsible for data management, the user and access rights, and the life cycle management of the data (such as creation, storage, use, archiving, and destruction).
[0071] Furthermore, processing data fields containing sensitive information requires the use of a variety of technologies and strategies to ensure data security. Data desensitization, encryption, access control, data anonymization, and real-time monitoring and auditing can effectively protect data from unauthorized access and leakage. These methods not only enhance data security, but also help meet the requirements of relevant regulations and standards.
[0072] In some embodiments, combing the asset catalog and forming a data resource list according to the business data and data management rules further includes: Acquire real-time data assets based on preset scanning cycles and scheduled tasks; Matching the real-time data assets with the business data classification and grading model to determine the sensitivity and classification of each real-time data asset; Dynamically update the business data classification and grading model and data resource list based on the sensitivity and classification results of real-time data assets.
[0073] In this example, see Figure 2As shown in Table 2, through periodic scanning, scheduled tasks are dynamically generated to match the identified data assets with classification and grading rules, dynamically update the classification and grading rules and asset lists, combine NLP technology, and issue early warnings for data with a data security level greater than level 2, and perform data management and control. Implementation personnel perform desensitization, encryption and other processing based on the classification and grading specifications; if the registered data resource changes in the subsequent production process, the newly added or deleted fields are marked on the basis of the original resource directory, and subsequent processing is performed based on the recommended rules.
[0074] Table 2: Dynamically updated classification rules and asset list
[0075] In this embodiment, the sensitivity threshold is a sensitivity level of 2.
[0076] It should be noted that in order to discover newly added data assets and identify changes in existing data assets, the system regularly performs a comprehensive scan of data assets. In this embodiment, an automated tool or script is usually used to regularly scan storage devices such as databases and file systems to generate a list of data assets.
[0077] In some embodiments, during the data sharing process, different types of shared data are generated based on the data's sharing attributes, sensitivity, and openness, and are published as API interfaces. The specific steps are as follows: The sharing attributes of data refer to the sharing scope, access rights and usage conditions of data, including internal sharing: only employees within the organization are allowed to access and use data; external sharing: partners, suppliers or other external entities are allowed to access and use data; and public sharing: the public is allowed to access and use data.
[0078] The sensitivity of data refers to the importance and potential risks of the data. Depending on the sensitivity, the data protection measures will also be different. Generally, it includes low-sensitivity data: such as general business data, which can be shared more loosely. Sensitive data: such as basic customer information, requires a certain degree of protection. High-sensitivity data: such as personal privacy information, requires strict protection and can only be accessed by authorized personnel.
[0079] The degree of data openness refers to the accessibility and scope of data. The more open the data is, the fewer restrictions on its access and use. It includes the following dimensions: Fully open: data is completely public with no access restrictions. Semi-open: access requires certain authentication or authorization. Closed: access is limited to specific users or systems.
[0080] According to the above-mentioned sharing attributes, sensitivity and openness, different types of shared data can be generated, including internal shared data, external shared data and public shared data, to adapt to different usage scenarios and needs. Among them: Internal shared data refers to data that is only shared within an organization, and is usually used for internal business processes and management. External shared data refers to data that is shared with partners, suppliers, or other external entities, and is usually used for collaborative projects or service provision. Public shared data refers to data that is open to the public, and is usually used for public information services or data analysis.
[0081] Different types of shared data are generated by sharing attributes, sensitivity, and openness, and published as API interfaces to achieve flexible sharing and access of data. This process not only improves the availability of data, but also ensures the security and compliance of data in different sharing scenarios.
[0082] The present invention provides feasibility for data security protection from the perspective of technology and process. Before data sharing, different types of data such as original, desensitized, encrypted, and watermarked data are generated through classified and graded asset lists, shared attributes, sensitivity, openness, and importance label attributes. The data is classified and shared, which ensures that the original data is not leaked and actively promotes the flow and sharing of data. On the other hand, the shared data is monitored in real time, and through active identity recognition technology, abnormal alarms and other measures, as well as an active intelligent log tracing system, all-round data security protection is achieved to meet the needs of different business departments and different business scenarios.
[0083] Based on the above API interface management and security protection measures method, the embodiment of the present invention also provides an API interface management and security protection measures device, please refer to Figure 3 ,include: The data asset list building module 310 is used to sort out the asset catalog to form a data resource list according to the business data and data management rules; A shared data generation module 320 is used to generate different types of shared data based on the data resource list and according to the sharing attributes, sensitivity and openness of the business data; The API interface publishing module 330 is used to publish corresponding API interfaces according to different types of shared data; The security protection module 340 is used to perform security protection operations on the API and shared data according to the matching relationship between the user's calling information and the user's authentication information and the key rules set by the API interface.
[0084] like Figure 4As shown, based on the above API interface management and security protection measures method, the present invention also provides an electronic device, which can be a computing electronic device such as a mobile terminal, a desktop computer, a notebook, a palm computer, and a server. The electronic device includes a processor 410, a memory 420, and a display 430. Figure 4 Only some components of the electronic device are shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.
[0085] In some embodiments, the memory 420 may be an internal storage unit of the electronic device, such as a hard disk or memory of the electronic device. In other embodiments, the memory 420 may also be an external storage electronic device of the electronic device, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (SecureDigital, SD) card, a flash card (Flash Card), etc. equipped on the electronic device. Furthermore, the memory 420 may also include both an internal storage unit of the electronic device and an external storage electronic device. The memory 420 is used to store application software and various types of data installed in the electronic device, such as program codes for installing the electronic device. The memory 420 may also be used to temporarily store data that has been output or is to be output. In one embodiment, an API interface management and security protection measure program 440 is stored on the memory 420, and the API interface management and security protection measure program 440 can be executed by the processor 410, thereby realizing the API interface management and security protection measure method of each embodiment of the present application.
[0086] In some embodiments, the processor 410 may be a central processing unit (CPU), a microprocessor or other data processing chip, used to run program codes or process data stored in the memory 420, such as executing API interface management and security protection measures.
[0087] In some embodiments, the display 430 may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, an OLED (Organic Light-Emitting Diode) touch device, etc. The display 430 is used to display information of the electronic device for the API interface management and safety protection measures and to display a visual user interface. The components 410-430 of the electronic device communicate with each other via a system bus.
[0088] Those skilled in the art will appreciate that all or part of the processes of the above-mentioned embodiments can be implemented by instructing related hardware through a computer program, and the program can be stored in a computer-readable storage medium, wherein the computer-readable storage medium is a disk, an optical disk, a read-only storage memory, or a random access memory, etc.
[0089] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.
Claims
1. An API interface management and security protection method, characterized in that: include: Based on business data and data management rules, sort out the asset catalog to form a data resource list; Based on the data resource list, different types of shared data are generated according to the sharing attributes, sensitivity and openness of business data; Publish corresponding API interfaces according to different types of shared data; Based on the matching relationship between the user's call information and authentication information and the key rules set by the API interface, security protection operations are performed on the API and shared data.
2. The API interface management and security protection method according to claim 1 is characterized in that: According to the business data and data management rules, the asset catalog is sorted out and a data resource list is formed, including: Obtain business data according to the basic information category of business data; Based on data security specifications and data classification regulations, classify business data according to the attributes of business data and build a business data classification model; Based on the classification and grading model and business data, the asset catalog is sorted out and a data resource list is formed.
3. The API interface management and security protection method according to claim 2 is characterized in that: The asset catalog is sorted out and a data resource list is formed based on the classification and grading model and business data, including: Based on the classification results, the data in the business database and its metadata are stored in the data warehouse; Use the preset machine learning analysis method to identify the stored data and divide the data assets to obtain the data asset catalog; According to the data asset catalog, obtain the data resource list; After obtaining the data resource list, the method further includes: enhancing the sensitive fields in the data resource list to obtain the target data resource list.
4. The API interface management and security protection method according to claim 2 is characterized in that: The process of combing the asset catalog and forming a data resource list based on business data and data management rules also includes: Acquire real-time data assets based on preset scanning cycles and scheduled tasks; Matching the real-time data assets with the business data classification and grading model to determine the sensitivity and classification of each real-time data asset; Dynamically update the business data classification and grading model and data resource list based on the sensitivity and classification results of real-time data assets.
5. The API interface management and security protection method according to claim 4 is characterized in that: After determining the sensitivity and classification of real-time data assets, also include: Process the text data of real-time data assets to determine valid information; Based on the effective information of real-time data assets, determine the relationship between the sensitivity level of real-time data assets and the sensitivity threshold; If the sensitivity level of the real-time data asset is greater than the sensitivity threshold, access control and encryption processing will be performed on the real-time data asset.
6. The API interface management and security protection method according to claim 4 is characterized in that: Based on the data resource list, different types of shared data are generated according to sharing attributes, sensitivity and openness, including: The sharing attributes include the sharing scope, access rights and usage conditions of the business data; The sensitivity level includes the importance and potential risks of business data; The degree of opening includes fully open, semi-open and fully closed; The sharing attributes, sensitivity and openness are arranged and combined to determine the type of shared data, where the type of shared data at least includes original data, desensitized data, encrypted data and watermarked data.
7. The API interface management and security protection method according to claim 4 is characterized in that: Also includes: Monitor shared data in real time to determine API usage.
8. An API interface management and security protection device, characterized in that: include: The data asset list building module is used to sort out the asset catalog to form a data resource list based on business data and data management rules; A shared data generation module is used to generate different types of shared data based on the data resource list and according to the sharing attributes, sensitivity and openness of business data; API interface publishing module, used to publish corresponding API interfaces according to different types of shared data; The security protection module is used to perform security protection operations on the API and shared data based on the matching relationship between the user's call information and the user's authentication information and the key rules set by the API interface.
9. An electronic device, characterized in that: include: Processor and memory; The memory stores a computer-readable program executable by the processor; When the processor executes the computer-readable program, the steps in the API interface management and security protection measures method as described in any one of claims 1-7 are implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps in the API interface management and security protection method as described in any one of claims 1-7.