Infinitely extensible API (Application Program Interface) platform supporting user release and management

By providing an API platform that supports users to publish and manage unlimited scalable API management, the problems of decentralized API management, inconsistent access methods, lack of permission control and insufficient observability in traditional API management methods are solved, and unified API management and security control are realized, and management efficiency is improved.

CN119945743AInactive Publication Date: 2025-05-06BEIJING XINJUDA TECHNOLOGY CO LTD

Patent Information

Application Number
CN202411965245.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional API management methods have problems such as decentralized API management, inconsistent access methods, lack of perfect permission control and insufficient observability, resulting in security risks and inefficient management.

Method used

Provides an API platform that supports user publishing and management to unlimitedly expandable, including API gateway module, multi-tenant management module, API lifecycle management module, consumer permission control module and observability analysis module. Through these modules, unified API management, security control and full lifecycle management are realized.

Benefits of technology

It realizes unified management and security control of APIs, improves API management efficiency, solves technical problems in scalability, security and ease of use, and significantly reduces management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945743A_ABST
    Figure CN119945743A_ABST
Patent Text Reader

Abstract

The invention relates to an infinitely extensible API (Application Program Interface) platform supporting user release and management, which comprises an API gateway module used for receiving and forwarding API requests, dynamically adjusting request routing according to node weight and current load state, and uniformly distributing the requests to back-end service nodes; the multi-tenant management module is used for creating independent team spaces, endowing each team space with independent resource quotas and access permissions, and ensuring mutual isolation of resources among different teams; the API life cycle management module is used for API design, version management, release management and subscription management; the consumer authority control module is used for managing the access authority of the API, realizing fine-grained access control and supporting multiple authentication modes; and the observability analysis module is used for carrying out omnibearing API observability analysis from three dimensions of monitoring, log and call chain tracking. According to the method, the technical problems of a traditional API management platform in the aspects of expansibility, safety, usability and the like are solved, and the API management efficiency can be remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and in particular relates to an API platform that supports users to publish and manage unlimited extensions. Background Art

[0002] With the development of microservice architecture and AI technology, the number of APIs within enterprises has increased exponentially. Traditional API management methods have the following problems:

[0003] 1) API management is decentralized and lacks a unified management platform;

[0004] 2) The access methods of different types of APIs are inconsistent, which increases development and maintenance costs;

[0005] 3) Lack of a sound authority control mechanism, posing potential security risks;

[0006] 4) Insufficient observability makes it difficult to detect and solve problems in a timely manner. Summary of the invention

[0007] The purpose of the present invention is to provide a platform that supports users to publish and manage an infinitely scalable API to solve the above technical problems.

[0008] The present invention provides a platform that supports users to publish and manage an infinitely scalable API, including:

[0009] API gateway module, which is used to receive and forward API requests. Based on the weighted round-robin load balancing strategy, it dynamically adjusts the request routing according to the node weight and current load status, and evenly distributes the requests to the backend service nodes.

[0010] Multi-tenant management module, which is used to create independent team spaces, assign independent resource quotas and access permissions to each team space, and ensure that resources between different teams are isolated from each other;

[0011] API lifecycle management module, used for API design, version management, release management, and subscription management;

[0012] The consumer permission control module is used to manage API access rights, implement fine-grained access control, adopt a multi-level security authentication mechanism to ensure the security of API calls, and support multiple authentication methods;

[0013] The observability analysis module is used to conduct comprehensive API observability analysis from three dimensions: monitoring, logging, and call chain tracing.

[0014] Furthermore, the API gateway module supports unified management of REST API and AI API; for AI API, the API gateway module automatically handles interface differences among different AI vendors and converts requests into a standard format; the API gateway module adopts an asynchronous and non-blocking design pattern, handles concurrent requests through a coroutine pool, and improves response speed through multi-level caching; the API gateway module supports a flexible plug-in mechanism, and realizes on-demand expansion of functions by dynamically loading security authentication, current limiting and circuit breaking, and logging plug-ins in the request processing process.

[0015] Furthermore, the load balancing strategy based on weighted polling dynamically adjusts the request routing according to the node weight and the current load status to evenly distribute the requests to the backend service nodes, including:

[0016] 1) Initialize the weight and status of the backend service node;

[0017] 2) Calculate the weight ratio of each node. The formula is as follows:

[0018]

[0019] Among them, Wi represents the weight ratio of the i-th node, indicating the proportion of requests assigned to this node; Ci represents the performance score of node i, quantifying the node processing capacity, such as CPU, memory, etc.; n represents the total number of backend service nodes;

[0020] 3) Dynamically adjust weights based on real-time load;

[0021] 4) Allocate traffic by weight and monitor the status of nodes.

[0022] Furthermore, the multi-tenant management module is specifically used to:

[0023] In terms of data storage, a shared database architecture is adopted to distinguish the data of different tenants by tenant ID. The tenant ID is parsed and dynamically injected through SQL query to ensure strict isolation of resource access for each tenant.

[0024] In terms of resource isolation, fine-grained resource quota management is used to set limits for each tenant, including the number of API calls, storage space, and the number of concurrent requests. Resource usage statistics and alarm functions are also provided. When a tenant's resource usage approaches the quota limit, an alarm notification is automatically sent.

[0025] In terms of permission control, roles and permissions are flexibly defined based on the RBAC permission model to ensure that tenants can only access authorized resources, and by combining the RBAC and ABAC models, fine-grained control of API access rights can be achieved.

[0026] Furthermore, the API lifecycle management module is specifically used to:

[0027] In terms of API design, it provides a visual API design tool that supports the OpenAPI specification, supports intuitive definition of API request parameters, response format, error code information, automatically generates API documents, and supports export in multiple formats;

[0028] In terms of version management, semantic version management is implemented, which supports recording API modification history, version rollback and comparison, and automatically prompts and recommends version upgrades when incompatible API modifications occur.

[0029] In terms of release management, a strict release control mechanism is implemented, multi-environment deployment is supported, and different release strategies can be set;

[0030] In terms of subscription management, it provides a complete subscription approval process, supports automatic or manual approval, and provides subscription status query and notification functions.

[0031] Furthermore, the consumer authority control module is specifically used to:

[0032] Through attribute-based access control, access policies are formulated based on multiple dimensions including user identity, time, and IP address:

[0033] Support dynamic access control rules and adjust access policies based on real-time monitoring data;

[0034] Implement complete audit log records, including detailed information on security events such as authentication failures and unauthorized access;

[0035] Supports real-time push of audit logs to external log systems for security analysis and tracing;

[0036] Realize encrypted transmission of API calls, support TLS / SSL protocol, and ensure the security of data transmission.

[0037] Furthermore, the observability analysis module is specifically used to:

[0038] In terms of monitoring, it collects multiple indicator data, including API call volume, response time, and error rate, and supports custom monitoring indicators. It uses a time series database to store monitoring data and supports flexible query and analysis.

[0039] In terms of log management, structured log collection is implemented, multiple log storage solutions are supported, and log retrieval and analysis are facilitated;

[0040] In terms of call chain tracing, the distributed call chain is used to record the processing process of each request, record the complete link of the API call, including the processing time and exception information of each node, and analyze the performance bottleneck. The specific process is as follows:

[0041] 1) Generate a unique tracking ID for each request;

[0042] 2) Attach the parent node ID when requesting forwarding;

[0043] 3) Record the processing time of each node. The formula is as follows:

[0044]

[0045] Where Ttotal represents the total response time of the request, Ti represents the processing time of node i, and n represents the number of nodes involved in the request link.

[0046] 4) Summarize call chain data and generate performance reports.

[0047] Furthermore, in terms of call chain tracing, it also supports exporting tracing data to professional APM tools for in-depth analysis.

[0048] Furthermore, the API platform also includes:

[0049] The performance monitoring module is used to implement all-round performance monitoring by using distributed tracing and multi-dimensional indicator collection.

[0050] Through the above solution, by supporting users to publish and manage an infinitely scalable API platform, adopting a reasonable system architecture design, supporting users to quickly access and manage multiple API services, achieving unified API publishing, subscription and calling, and providing complete API life cycle management, it solves the technical problems of traditional API management platforms in scalability, security and ease of use, and can significantly improve API management efficiency.

[0051] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention and implement it according to the contents of the specification, the following is a detailed description of the preferred embodiments of the present invention in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 The overall architecture diagram of the API platform that supports users to publish and manage infinitely scalable APIs in this invention;

[0053] Figure 2 This is a flowchart of the API request processing of the present invention;

[0054] Figure 3 This is a structural diagram of the multi-tenant management module of the present invention;

[0055] Figure 4 This is the authority control model diagram of the present invention. DETAILED DESCRIPTION

[0056] The specific implementation of the present invention is further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.

[0057] Ginseng Figure 1 As shown, this embodiment provides a platform that supports users to publish and manage an infinitely scalable API, including:

[0058] API gateway module, which is used to receive and forward API requests. Based on the weighted round-robin load balancing strategy, it dynamically adjusts the request routing according to the node weight and current load status, and evenly distributes the requests to the backend service nodes.

[0059] Multi-tenant management module, which is used to create independent team spaces, assign independent resource quotas and access permissions to each team space, and ensure that resources between different teams are isolated from each other;

[0060] API lifecycle management module, used for API design, version management, release management, and subscription management;

[0061] The consumer permission control module is used to manage API access rights, implement fine-grained access control, adopt a multi-level security authentication mechanism to ensure the security of API calls, and support multiple authentication methods;

[0062] The observability analysis module is used to conduct comprehensive API observability analysis from three dimensions: monitoring, logging, and call chain tracing.

[0063] The present invention is described in further detail below.

[0064] 1. API Gateway Module

[0065] This embodiment designs a high-performance API gateway system that can uniformly handle request forwarding for REST APIs and AI APIs. The API gateway adopts a modular architecture design, including core components such as request parsing, protocol conversion, security authentication, and load balancing. In terms of request processing, the gateway first performs unified format verification and protocol parsing on the inbound request, extracts the target service, interface information, and request parameters of the request. Then, based on the service configuration information, the request is converted into the protocol format supported by the target service. Figure 2 shown.

[0066] The request routing of the API gateway module needs to distribute traffic efficiently and evenly to improve response speed and system stability. Traditional polling algorithms have difficulty handling node performance differences and dynamic loads. To solve this problem, this embodiment uses a load balancing strategy based on weighted polling in the API gateway module to evenly distribute requests to backend service nodes. This strategy dynamically adjusts request routing based on node weights and current load status. The specific steps are as follows:

[0067] 1) Initialize the weight and status of the backend service node.

[0068] 2) Calculate the weight ratio of each node, the formula is as follows:

[0069]

[0070] Among them, Wi represents the weight ratio of the i-th node, indicating the proportion of requests assigned to this node; Ci represents the performance score of node i, quantifying the node processing capacity, such as CPU, memory, etc.; n represents the total number of backend service nodes.

[0071] 3) Dynamically adjust weights based on real-time load.

[0072] 4) Allocate traffic by weight and monitor the status of nodes.

[0073] For AI APIs, the system automatically handles the interface differences of different AI vendors and converts requests into a standard format. In terms of performance, the gateway adopts an asynchronous non-blocking design mode, handles concurrent requests through a coroutine pool, and implements multi-level caching to improve response speed. In addition, the gateway also supports a flexible plug-in mechanism, which can dynamically load plug-ins such as security authentication, current limiting and fusing, and logging in the request processing process to achieve on-demand expansion of functions. This unified gateway design greatly simplifies the management difficulty of the API and significantly improves the maintainability and scalability of the system.

[0074] In one specific implementation, the system implements a unified request processing pipeline, including the following key steps:

[0075] 1. Request preprocessing stage:

[0076] The system first parses the request header and body of the inbound request;

[0077] Extract key information such as request target, caller information, request parameters, etc.

[0078] Perform preliminary validation on the request format to ensure that the basic format is correct.

[0079] 2. Identity authentication stage:

[0080] Extract credential information from the request;

[0081] Perform identity verification according to the configured authentication method (such as API Key, JWT, etc.);

[0082] If the verification is successful, the next step will be entered; if it fails, the authentication error will be directly returned.

[0083] 3. Routing judgment stage:

[0084] Find matching routing rules based on the request path;

[0085] Determine the location and access method of the target service;

[0086] Get routing-related configuration information (such as timeout, retry strategy, etc.).

[0087] 4. Protocol conversion stage:

[0088] Convert the request format according to the interface specification of the target service;

[0089] Dealing with protocol differences between different types of APIs;

[0090] Make sure the request parameters meet the requirements of the target service.

[0091] 5. Request forwarding stage:

[0092] Establish a connection with the target service;

[0093] Send the converted request;

[0094] Wait for and receive a response from the target service.

[0095] 6. Response processing stage:

[0096] Format the response data uniformly;

[0097] Handle error conditions and generate standard error responses;

[0098] Return the final processing result to the caller.

[0099] The API gateway module uses an asynchronous processing mechanism to improve concurrent processing capabilities, implements full-link tracking of requests, supports a flexible protocol conversion plug-in mechanism, has a built-in complete error handling and retry mechanism, and provides detailed request processing logs.

[0100] 2. Multi-tenant management module

[0101] This embodiment adopts an advanced multi-tenant architecture design to achieve strict isolation of resources and data. The system supports multi-level organizational structures and can create independent team spaces, each of which has its own resource quotas and access rights. At the data storage level, a shared database architecture is adopted to distinguish the data of different tenants by tenant ID. The database table structure contains a tenant ID field, and all data query and modification operations will automatically add the tenant ID filter condition to ensure that tenants can only access their own data. The system uses SQL query parsing and dynamic injection of tenant IDs to ensure strict isolation of resource access for each tenant. SQL queries need to dynamically inject tenant identifiers to achieve transparent isolation. The specific steps are as follows:

[0102] 1) Intercept SQL queries and parse table structures.

[0103] 2) Dynamically inject tenant filter conditions into the WHERE clause.

[0104] 3) Execute the rewritten SQL query and return the result. The formula is as follows:

[0105] Q′=Q+"WHERE tenant_id=T"

[0106] Among them, Q represents the original query, Q′ represents the rewritten query, and T is the current tenant ID.

[0107] In terms of resource isolation, the system implements fine-grained resource quota management, and can set limits such as the number of API calls, storage space, and number of concurrent requests for each tenant. At the same time, the system also provides resource usage statistics and alarm functions. When a tenant's resource usage approaches the quota limit, an alarm notification will be automatically sent. In terms of permission control, the system implements a permission model based on RBAC (Role-Based Access Control), which can flexibly define roles and permissions to ensure that tenants can only access authorized resources. The system combines the RBAC and ABAC models to achieve fine-grained control of API access rights. The security of the API depends on efficient permission verification. Combine role permissions and dynamic attributes to achieve flexible access control. The specific steps are as follows:

[0108] 1) Query the user's roles and basic permissions.

[0109] 2) Extract dynamic attributes (such as time, IP address).

[0110] 3) Evaluate the dynamic policy and calculate the final permissions. The formula is as follows:

[0111] P=R∩S(A)

[0112] Among them, P represents the final permission set, R is the basic permission of the role, and S(A) is the calculation result of the dynamic attribute policy.

[0113] 4) Return the verification result.

[0114] In a specific implementation, the multi-tenant data isolation implementation adopts a shared database mode, and data isolation is achieved by automatically adding tenant ID conditions in SQL queries. Figure 3 shown.

[0115] Infrastructure Design:

[0116] 1) Data access layer encapsulation:

[0117] Design a unified data access base class;

[0118] Integrated database connection pool management mechanism;

[0119] Built-in tenant context manager.

[0120] 2) Tenant information management:

[0121] Maintain tenant context information;

[0122] Provide a mechanism for obtaining and verifying tenant IDs;

[0123] Ensure the secure transmission of tenant information.

[0124] Data operation process:

[0125] 1) Query request processing:

[0126] Receive original SQL query request;

[0127] Get the current tenant ID from the tenant context;

[0128] Verify the validity of tenant information;

[0129] If no valid tenant information is found, the operation is terminated.

[0130] 2) SQL parsing conversion:

[0131] Parse the original SQL statement structure;

[0132] Extract key information such as table name and query conditions;

[0133] Analyze SQL statement types (SELECT / INSERT / UPDATE, etc.);

[0134] Determines where to insert the tenant filter criteria.

[0135] 3) Tenant condition injection:

[0136] Select the injection strategy based on the SQL type;

[0137] Add the tenant ID filter where appropriate;

[0138] Ensure tenant conditions are prioritized;

[0139] Handling multi-table associations.

[0140] 4) Query execution phase:

[0141] Get a database connection from the connection pool;

[0142] Execute SQL statements with tenant filtering;

[0143] Process the execution results and return;

[0144] Make sure the connection is released properly.

[0145] Specific application scenarios:

[0146] 1) User data query:

[0147] Receive department ID as query condition;

[0148] Automatically associate department information;

[0149] Inject tenant filtering to ensure data isolation;

[0150] Returns a list of users that meet the criteria.

[0151] 2) User data creation:

[0152] Receive basic user information;

[0153] Automatically inject the current tenant ID;

[0154] Execute data insertion operation;

[0155] Ensure that user data is correctly attributed.

[0156] This implementation achieves automatic isolation of tenant data through unified data access layer encapsulation, so that business code does not need to care about the specific implementation of tenant isolation. At the same time, through asynchronous processing and connection pool management, the performance and reliability of the system in multi-tenant scenarios are guaranteed.

[0157] The multi-tenant management module implements transparent tenant data isolation, supports asynchronous database operations, provides a unified SQL processing mechanism, and a complete exception handling mechanism.

[0158] 4. API Lifecycle Management Module

[0159] This embodiment implements a complete API lifecycle management function, covering all stages of API design, development, testing, release, operation and maintenance. In the API design stage, the system provides a visual API design tool that supports the OpenAPI specification and can intuitively define API request parameters, response formats, error codes and other information. The system automatically generates API documents and supports export in multiple formats.

[0160] In terms of version management, the system implements semantic version management, which can record the modification history of the API and support version rollback and comparison. When an incompatible modification occurs to the API, the system will automatically prompt and recommend a version upgrade. In terms of the release process, the system implements a strict release control mechanism, supports multi-environment deployment, and can set different release strategies. For example, grayscale release, A / B testing, etc. In terms of subscription management, the system provides a complete subscription approval process, which can set automatic or manual approval, and provides subscription status query and notification functions. This comprehensive lifecycle management greatly improves the efficiency of API development and maintenance.

[0161] 5. Consumer authority control module

[0162] This embodiment designs a multi-level security authentication mechanism to ensure the security of API calls. The system supports multiple authentication methods, including API Key, Basic Auth, JWT, OAuth2.0, and national secret algorithms. For different authentication methods, the system implements a unified authentication framework and can flexibly configure authentication rules. In terms of security auditing, the system implements complete audit log records, including detailed information on security events such as authentication failures and unauthorized access. The system supports real-time push of audit logs to external log systems to facilitate security analysis and tracing. In addition, the system also implements encrypted transmission of API calls and supports TLS / SSL protocols to ensure the security of data transmission.

[0163] In terms of access control, the system implements attribute-based access control (ABAC), which can formulate access policies based on multiple dimensions such as user identity, time, IP address, etc. The system also supports dynamic access control rules and can adjust access policies based on real-time monitoring data.

[0164] Ginseng Figure 4 As shown, in a specific implementation, permission control adopts a combination of RBAC (role-based access control) and ABAC (attribute-based access control):

[0165] Permission verification process:

[0166] 1) Role acquisition stage:

[0167] Receive user identification, resource information, and operation type;

[0168] Query all roles to which the user belongs;

[0169] Support scenarios where users have multiple roles at the same time.

[0170] 2) Permission information acquisition stage:

[0171] Traverse all roles of the user;

[0172] Prioritize obtaining the role permission list from the cache;

[0173] Load from database when cache misses;

[0174] Merges the permission lists of all roles.

[0175] 3) Basic permission verification stage:

[0176] Build permission check key value (resource type: operation);

[0177] Check whether the user has basic operation permissions;

[0178] Access is directly denied when permissions are insufficient.

[0179] 4) Access policy acquisition phase:

[0180] Get strategy based on resource type and identity;

[0181] Supports fine-grained control at the resource level;

[0182] The access policies for different resources can be configured dynamically.

[0183] 5) Dynamic strategy evaluation phase:

[0184] Constructing a policy evaluation context;

[0185] Contains user information, resource information, and operation type;

[0186] Record access time, IP address, user agent and other environmental information;

[0187] Evaluate all applicable access policies.

[0188] Core components:

[0189] Permission controller, including:

[0190] Role Manager: responsible for the mapping relationship between users and roles;

[0191] Policy Manager: Responsible for the management and evaluation of access policies.

[0192] Permission cache: optimizes permission query performance.

[0193] The consumer permission control module implements an extensible permission model, supports multi-dimensional access control, has an optimized cache management mechanism, a complete exception handling process, and flexible policy configuration capabilities.

[0194] 6. Observability Analysis Module

[0195] This embodiment implements a full range of API observability analysis functions, including monitoring, logging, and tracing. In terms of monitoring, the system collects a wealth of indicator data, including key indicators such as API call volume, response time, and error rate, and supports custom monitoring indicators. The system uses a time series database to store monitoring data and supports flexible query and analysis.

[0196] In terms of log management, the system implements structured log collection, supports multiple log storage solutions, and enables easy log retrieval and analysis.

[0197] In terms of call chain tracking, the system implements a distributed tracking function that can record the complete chain of API calls, including the processing time and exception information of each node. The system records the processing process of each request through a distributed call chain and analyzes performance bottlenecks. The transparency of the API call chain helps to discover performance problems, and distributed tracking can record the call relationship between multiple nodes. The specific steps are as follows:

[0198] 1) Generate a unique tracking ID for each request.

[0199] 2) Attach the parent node ID when requesting forwarding.

[0200] 3) Record the processing time of each node. The formula is as follows:

[0201]

[0202] Where Ttotal represents the total response time of the request, Ti represents the processing time of node i, and n represents the number of nodes involved in the request chain. 4) Summarize the call chain data and generate a performance report.

[0203] In addition, the system supports exporting tracking data to professional APM tools for in-depth analysis. These observability features help users quickly discover and locate problems and improve the maintainability of the system.

[0204] 7. Performance monitoring module

[0205] In a specific implementation, performance monitoring uses distributed tracing and multi-dimensional indicator collection to achieve all-round performance monitoring. This includes:

[0206] Data collection process:

[0207] 1) Basic information extraction stage:

[0208] Record service ID and API path information;

[0209] Get the request method and status code;

[0210] Calculate request processing time;

[0211] Record the client IP address;

[0212] Generates a unique identifier for the request.

[0213] 2) Performance indicator collection stage:

[0214] API call basic indicator collection:

[0215] Count the number of requests;

[0216] Record the number of errors;

[0217] Measure the response time.

[0218] Resource usage indicator collection:

[0219] Monitor memory usage;

[0220] Track CPU usage;

[0221] Count the number of connections.

[0222] Business indicator collection:

[0223] Calculate the request data size;

[0224] Statistics response data size.

[0225] 3) Call chain tracing stage:

[0226] Generate a global tracking identifier;

[0227] Record the current calling node information;

[0228] Associate parent node call information;

[0229] Add service and API tags;

[0230] Build a complete call chain.

[0231] 4) Data persistence stage:

[0232] Asynchronously store performance indicator data;

[0233] Save call chain tracking information;

[0234] Record API call details;

[0235] Ensure data persistence and reliability.

[0236] Performance report generation process:

[0237] 1) Data query stage:

[0238] Receive query condition parameters;

[0239] Query raw data from the time series database;

[0240] Support multi-dimensional data filtering.

[0241] 2) Index calculation stage:

[0242] Throughput statistics:

[0243] Calculate the total number of requests;

[0244] Analyze the average TPS;

[0245] Statistics of peak TPS.

[0246] Response time analysis:

[0247] Calculate average response time;

[0248] Statistics of 95% response time;

[0249] Statistics of 99% response time.

[0250] Error rate analysis:

[0251] Calculate the overall error rate;

[0252] Analyze the error distribution.

[0253] Resource usage analysis:

[0254] Statistics of average memory usage;

[0255] Analyze CPU usage trends.

[0256] Exception handling mechanism:

[0257] 1) Monitoring data collection exception handling:

[0258] Record error logs;

[0259] Ensure that the main process is not affected;

[0260] Support data compensation mechanism.

[0261] 2) Report generation exception handling:

[0262] Record the cause of the error in detail;

[0263] Support retry mechanism;

[0264] Provide downgrade options.

[0265] This performance monitoring module uses asynchronous processing to improve performance, implements distributed tracking capabilities, supports multi-dimensional indicator collection, has an efficient data storage solution, and a flexible report generation mechanism.

[0266] The present invention has the following technical effects:

[0267] 1. Provide a unified API management platform to reduce management costs.

[0268] 2. Support multi-tenant isolation to improve system security.

[0269] 3. Realize API full life cycle management and improve development efficiency.

[0270] 4. Provide comprehensive monitoring and analysis capabilities to ensure system stability.

[0271] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. It should be pointed out that a person skilled in the art can make several improvements and modifications without departing from the technical principles of the present invention, and these improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A platform that supports users to publish and manage infinitely scalable APIs, characterized by: include: API gateway module, which is used to receive and forward API requests. Based on the weighted round-robin load balancing strategy, it dynamically adjusts the request routing according to the node weight and current load status, and evenly distributes the requests to the backend service nodes. Multi-tenant management module, which is used to create independent team spaces, assign independent resource quotas and access permissions to each team space, and ensure that resources between different teams are isolated from each other; API lifecycle management module, used for API design, version management, release management, and subscription management; The consumer permission control module is used to manage API access rights, implement fine-grained access control, adopt a multi-level security authentication mechanism to ensure the security of API calls, and support multiple authentication methods; The observability analysis module is used to conduct comprehensive API observability analysis from three dimensions: monitoring, logging, and call chain tracing.

2. The API platform supporting user publishing and management and infinite scalability according to claim 1, characterized in that: The API gateway module supports unified management of REST API and AI API; for AI API, the API gateway module automatically handles interface differences among different AI vendors and converts requests into a standard format; the API gateway module adopts an asynchronous non-blocking design pattern, handles concurrent requests through a coroutine pool, and improves response speed through multi-level caching; the API gateway module supports a flexible plug-in mechanism, and achieves on-demand expansion of functions by dynamically loading security authentication, current limiting and circuit breaking, and logging plug-ins in the request processing process.

3. The API platform supporting user publishing and management and infinitely scalable according to claim 2, characterized in that: The load balancing strategy based on weighted polling dynamically adjusts the request routing according to the node weight and the current load status to evenly distribute the requests to the backend service nodes, including: 1) Initialize the weight and status of the backend service node; 2) Calculate the weight ratio of each node. The formula is as follows: Among them, Wi represents the weight ratio of the i-th node, indicating the proportion of requests assigned to this node; Ci represents the performance score of node i, quantifying the node processing capacity; n represents the total number of backend service nodes; 3) Dynamically adjust weights based on real-time load; 4) Allocate traffic by weight and monitor the status of nodes.

4. The API platform supporting user publishing and management and infinitely scalable according to claim 1, characterized in that: The multi-tenant management module is specifically used for: In terms of data storage, a shared database architecture is adopted to distinguish the data of different tenants by tenant ID. The tenant ID is parsed and dynamically injected through SQL query to ensure strict isolation of resource access for each tenant. In terms of resource isolation, fine-grained resource quota management is used to set limits for each tenant, including the number of API calls, storage space, and the number of concurrent requests. Resource usage statistics and alarm functions are also provided. When a tenant's resource usage approaches the quota limit, an alarm notification is automatically sent. In terms of permission control, roles and permissions are flexibly defined based on the RBAC permission model to ensure that tenants can only access authorized resources, and by combining the RBAC and ABAC models, fine-grained control of API access rights can be achieved.

5. The API platform supporting user publishing and management and infinitely scalable according to claim 1, characterized in that: The API lifecycle management module is specifically used for: In terms of API design, it provides a visual API design tool that supports the OpenAPI specification, supports intuitive definition of API request parameters, response format, error code information, automatically generates API documents, and supports export in multiple formats; In terms of version management, semantic version management is implemented, which supports recording API modification history, version rollback and comparison, and automatically prompts and recommends version upgrades when incompatible API modifications occur. In terms of release management, a strict release control mechanism is implemented, multi-environment deployment is supported, and different release strategies can be set; In terms of subscription management, it provides a complete subscription approval process, supports automatic or manual approval, and provides subscription status query and notification functions.

6. The API platform supporting user publishing and management and infinite scalability according to claim 1, characterized in that: The consumer rights control module is specifically used for: Through attribute-based access control, access policies are formulated based on multiple dimensions including user identity, time, and IP address: Support dynamic access control rules and adjust access policies based on real-time monitoring data; Implement complete audit log records, including detailed information on security events such as authentication failures and unauthorized access; Supports real-time push of audit logs to external log systems for security analysis and tracing; Realize encrypted transmission of API calls, support TLS / SSL protocol, and ensure the security of data transmission.

7. The API platform supporting user publishing and management and infinite scalability according to claim 1, characterized in that: The observability analysis module is specifically used for: In terms of monitoring, it collects multiple indicator data, including API call volume, response time, and error rate, and supports custom monitoring indicators. It uses a time series database to store monitoring data and supports flexible query and analysis. In terms of log management, structured log collection is implemented, multiple log storage solutions are supported, and log retrieval and analysis are facilitated; In terms of call chain tracing, the distributed call chain is used to record the processing process of each request, record the complete link of the API call, including the processing time and exception information of each node, and analyze the performance bottleneck. The specific process is as follows: 1) Generate a unique tracking ID for each request; 2) Attach the parent node ID when requesting forwarding; 3) Record the processing time of each node. The formula is as follows: Where Ttotal represents the total response time of the request, Ti represents the processing time of node i, and n represents the number of nodes involved in the request link. 4) Summarize call chain data and generate performance reports.

8. The API platform supporting user publishing and management and infinitely scalable according to claim 7, characterized in that: In terms of call chain tracing, it also supports exporting tracing data to professional APM tools for in-depth analysis.

9. The API platform supporting user publishing and management and infinitely scalable according to claim 1, characterized in that: Also includes: The performance monitoring module is used to implement all-round performance monitoring by using distributed tracing and multi-dimensional indicator collection.

Citation Information

Patent Citations

  • Open API full-life-cycle management method based on micro-service

    CN111181727A

  • Distributed gateway system

    CN113923251A

  • Open API (Application Program Interface) integration and management method and computer equipment

    CN114979103A

  • Data security isolation and sharing framework implementation method for multiple tenants

    CN116760639A

  • Data isolation method under SAAS platform

    CN117879902A

Cited By

  • Central authority service device, authority management method, device, equipment and medium

    CN120358084A

  • Central authority service device, authority management method, device, equipment and medium

    CN120358084B

  • AI gateway multi-level cache synchronization method and system oriented to high-concurrency API service

    CN120528975A

  • Intelligent service management system supporting multi-tenant data isolation and resource quota

    CN122179210A