Secure access method and system based on API interaction and storage medium
By adopting dynamic identity authentication and behavior analysis technology in API interaction, real-time monitoring and adjustment of user permissions, the problem of insufficient comprehensive API interaction security protection process and insufficient flexibility in fixed strategies in the existing technology is solved, and efficient dynamic identity authentication and cross-service global security protection are achieved.
Patent Information
- Application Number
- CN202411869218.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-05-23
AI Technical Summary
The existing technology has problems in API interactions such as complex rule matching and low computing efficiency, lack of dynamic attack protection mechanisms, limited data protection to a single service or gateway, insufficient flexibility of fixed policies and authorization mechanisms, and insufficient comprehensive API interaction security protection process.
A secure access method based on API interaction is adopted, including the user sending API requests and carrying an identity token, performing dynamic identity authentication and behavioral analysis. If there is abnormal behavior, the identity token will be revoked, user permissions will be restricted, or access will be terminated. The system uses dynamic token refresh and behavior analysis engine to monitor and analyze users' access behavior in real time and dynamically adjust users' API access permissions.
It realizes efficient dynamic identity authentication and permission management, prevents replay attacks and abnormal behaviors, provides global security protection across services and systems, adapts to the security needs of complex multi-level API interaction scenarios, and improves the security and response efficiency of the system.
Smart Images

Figure CN120030513A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and specifically relates to a secure access method, system and storage medium based on API interaction. Background Art
[0002] At present, although some progress has been made in API interaction and data security protection, the following problems still exist: ① Complex rule matching and computational efficiency issues: For example: the existing patent CN202310252588.9 discloses an interface interaction data security protection method based on AI high-speed regular matching, which ensures the security of API access based on AI and high-speed regular matching. However, due to the high complexity of AI models and regular matching, especially in high-concurrency scenarios, the matching process may cause excessive computing overhead, affecting the response speed and stability of the system. This technical solution mainly relies on rule matching and fails to effectively solve the performance bottleneck problem under high load.
[0003] ② Lack of protection mechanism against dynamic attacks: For example, the existing patent CN202410317974.6 discloses a data interaction method and device, which mainly improves authentication and data interaction under the microservice architecture, and emphasizes the security of load balancing and authentication through the API gateway. However, this solution does not fully consider effective protection measures against dynamic attacks (such as replay attacks and credential theft), and relies on static authentication certificates and policies, making it difficult to detect and respond to dynamically changing attack behaviors in a timely manner.
[0004] ③Data protection is limited to a single service or gateway: For example: the existing patent CN202210870632.8 discloses a method for constructing an API gateway through process-based service orchestration to achieve visual data processing. By constructing an API gateway through process-based service orchestration, visual processing of data and rapid format conversion are achieved, which can improve development efficiency and security. However, this solution focuses on the data processing capabilities of a single service or gateway, and does not delve into global security protection issues across services or systems. With the expansion of the API ecosystem, it is difficult to cope with security threats in complex multi-level and multi-system data interaction scenarios by relying solely on the security control of a single gateway.
[0005] ④Fixed policies and authorization mechanisms lack flexibility: For example, the existing patent CN202410317974.6 discloses a data interaction method and device, in which the microservice authentication mechanism improves the security of the microservice architecture to a certain extent, but it relies on fixed policies and authentication certificates, making it difficult to dynamically adjust user permissions and unable to adapt to rapidly changing user behaviors and access requirements. This fixed policy design is difficult to cope with diverse attack methods and changes in user behavior.
[0006] ⑤The API interaction security protection process is not comprehensive enough: For example, the existing patents CN202310252588.9 and CN202210870632.8 focus on certain specific links, such as the authentication of identity tokens and the process configuration of data processing, but lack comprehensive security protection for the entire API interaction process. When processing API requests, these solutions often only focus on security requirements at a certain level, making it difficult to achieve global and dynamic protection. Summary of the invention
[0007] The purpose of the present invention is to provide a secure access method, system and storage medium based on API interaction, aiming to solve the above-mentioned problems.
[0008] The present invention is mainly achieved through the following technical solutions: A secure access method based on API interaction, comprising the following steps: Step S1: The user sends an API request, and the request carries an identity token, wherein the identity token includes user identity information and access rights; Step S2: Receive API request and perform dynamic identity authentication; Step S3: If the validity period of the identity token is about to expire, the identity token is refreshed and sent to the user, and the user's access rights are updated at the same time; Step S4: The behavior analysis engine monitors and analyzes the user's access behavior in real time based on the point aggregation method. If there is abnormal behavior, the identity token is revoked, the user's rights are restricted, or the access is terminated.
[0009] In order to better implement the present invention, further, in the step S2, the received request is preliminarily screened according to any one of the strategies of current limiting, IP blacklist, and network firewall.
[0010] In order to better implement the present invention, further, step S2 includes the following steps: Step S21: First, perform identity token verification: verify the authenticity and validity period of the identity token; 1) Parse the identity token and confirm that it has not expired; 2) Then, verify the signature of the identity token to confirm that it has not been tampered with; 3) Extract user identity information and perform basic identity authentication; Step S22: Then, after the identity token verification is passed, dynamic behavior verification is performed; based on the visitor behavior data obtained in real time, multi-dimensional behavior analysis is performed, and if abnormal behavior is found, the user is required to re-authenticate; Step S23: Evaluate the credibility of the user's behavior based on the behavior data analysis. If the credibility is evaluated to be reduced, temporarily restrict the user's API access rights.
[0011] In order to better implement the present invention, further, in step S22, if there is one or more of the following: geographical location changes within the threshold time, the request identifier change frequency is higher than the set threshold, the fixed frequency of the request is abnormal, and the number of abnormal requests exceeds the threshold, the user is required to re-authenticate; in step S23, if the IP address changes or access is made during an abnormal time period, the user's access to sensitive data or functions is restricted.
[0012] In order to better implement the present invention, further, in step S3, when the user successfully logs in or passes identity authentication, an identity token containing user identity information, access rights and expiration time is generated and stored in a secure Cookie or HTTP header as an authentication credential for subsequent requests.
[0013] In order to better implement the present invention, further, in step S4, the data of the access behavior includes any one or more of device information, geographic location, access frequency, time period, request path, abnormal number, and constant frequency access.
[0014] In order to better implement the present invention, further, in step S4, if the number of requests sent within the threshold time exceeds the threshold or the frequency of IP address changes exceeds the threshold, the user authority is restricted.
[0015] In order to better implement the present invention, further, in step S4, if abnormal behavior or identity authentication failure is detected, the identity token of the user is revoked and the subsequent access request is rejected.
[0016] The present invention is mainly achieved through the following technical solutions: A secure access system based on API interaction, based on the above secure access method based on API interaction, including a user request layer, a security management layer, an API diversion layer and an API service layer; The user request layer is used to send a request, and the request carries an identity token as a verification credential for the user's identity; The security management layer includes: Identity authentication module: used to verify the identity token carried in the request to ensure the legality of the identity; Behavior analysis module: used to monitor and analyze user request behaviors in real time to prevent abnormal or malicious operations; Dynamic permission management module: used to dynamically adjust user permissions based on the behavior analysis results of the behavior analysis module; Token management module: used to manage the generation, refresh and revocation of identity tokens to ensure the security and timeliness of tokens; The API diversion layer includes: API diversion module: used to receive and forward requests to the corresponding API service; Current limiting and load balancing module: used to control the request rate to prevent system overload caused by too many requests, and distribute requests evenly to different service instances; The API service layer is used to execute different service logics according to requests and process API interfaces of specific business logics.
[0017] A computer-readable storage medium stores a computer program thereon, characterized in that when the program is executed by a processor, the above-mentioned secure access method based on API interaction is implemented.
[0018] The beneficial effects of the present invention are as follows: (1) The present invention has an efficient dynamic identity authentication and permission management mechanism, which reduces the overhead of complex calculations and improves the response efficiency in high-concurrency scenarios while ensuring system security. The present invention has the function of detecting and protecting against replay attacks and abnormal behaviors, ensuring the security of API access in various attack scenarios, especially against dynamic threats. The present invention has global security protection capabilities across services and systems, and adapts to the security needs in complex multi-level API interaction scenarios. The present invention has a flexible dynamic permission adjustment mechanism, which adjusts API access rights in real time according to changes in user behavior, effectively enhancing the flexibility and adaptability of system security protection.
[0019] (2) The present invention effectively simplifies the computational complexity of permission management by introducing a dynamic token refresh mechanism and behavior-based permission control, and improves the response efficiency and stability of the system under high concurrency conditions. The present invention can monitor the user's access behavior in real time through dynamic identity authentication and behavior analysis mechanisms, and respond quickly to abnormal behaviors, thereby effectively preventing replay attacks and unauthorized access. The present invention provides global security protection capabilities across services and systems through a multi-level security protection mechanism combined with JWT's dynamic management, encryption verification and anomaly detection, further improving the security of the entire API ecosystem. The present invention's behavior-based dynamic permission adjustment mechanism can dynamically adjust the user's access rights based on the user's real-time behavior data (such as access frequency, device information, geographic location, etc.), thereby enhancing the adaptability to security requirements in complex scenarios. The present invention achieves all-round protection of API interactions from request to response through a complete dynamic identity authentication, token refresh, behavior monitoring and anomaly detection mechanism, and can effectively respond to complex and changing security threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 This is a principle block diagram of the secure access system based on API interaction of the present invention; Figure 2 This is a schematic diagram of the architecture of the secure access system based on API interaction of the present invention; Figure 3 It is a schematic diagram of the secure access system based on API interaction of the present invention; Figure 4 A flowchart of a secure access method based on API interaction according to the present invention; Figure 5 This is a flowchart of scenario 1 in Example 3. DETAILED DESCRIPTION
[0021] Embodiment 1: A secure access system based on API interaction, such as Figure 1 As shown, including: (1) User request layer: The user sends a request through a terminal device (such as a browser or mobile device), and the request carries a JWT token as a verification credential for the user's identity.
[0022] (2) Security management layer: This layer is the core of the entire system security and includes the following modules: 1) Identity authentication module: Verify the JWT token carried in the user request to ensure the legitimacy of the identity.
[0023] 2) Behavior analysis module: monitors and analyzes user request behaviors in real time to prevent abnormal or malicious operations.
[0024] 3) Dynamic permission management module: dynamically adjust user permissions based on behavior analysis results.
[0025] 4) Token management module: manages the generation, refresh and revocation of JWT tokens to ensure the security and timeliness of tokens.
[0026] (3) API diversion layer: 1) API diversion module: As the diversion module of the system, it is responsible for receiving and forwarding requests to the corresponding API services.
[0027] 2) Current limiting and load balancing module: controls the request rate to prevent excessive requests from causing system overload, and distributes requests evenly to different service instances.
[0028] (4) API service layer: API interface that handles specific business logic and executes different service logic based on the request. It includes multiple API services, such as API 1, API 2, etc., which handle different business logic respectively.
[0029] Preferably, if Figure 2 As shown, the system includes a presentation layer, a service layer and a data layer. The data layer includes a data storage module and a data access module, wherein the data access module includes units such as metadata, DAAS routing, data analysis and data sharing; the data storage module stores relational data, non-relational data and a file system, etc.
[0030] The present invention improves API security: The dynamic token refresh and behavior analysis technology of the present invention can effectively prevent credential theft, replay attacks and malicious requests, provide high-level security protection for various API-based systems, and reduce the probability of security incidents. The present invention improves user experience: By dynamically adjusting permissions and token refresh mechanisms, users can continuously and securely access system resources, avoid frequent re-authentication, and ensure efficient API interaction. The present invention has a wide range of market applications: The present invention is applicable to all application scenarios involving API interactions, especially in the fields of communications, finance, the Internet of Things, e-commerce, and SaaS platforms, and can help companies reduce risks and increase system reliability by improving the security and stability of APIs. The present invention enhances compliance: With the tightening of global data protection regulations, the security mechanism of the present invention can help companies meet data privacy and security compliance requirements, especially in API data transmission and access control.
[0031] Embodiment 2: A secure access method based on API interaction, which achieves all-round security protection for the API interaction process by introducing dynamic identity authentication, token management, behavior analysis and multi-level security protection mechanisms. It is particularly suitable for complex, cross-service or cross-system scenarios. Figure 4As shown, the specific steps include: (1) The user makes an API request, and the system receives and verifies their identity token. The system authenticates the user based on the token and the user's real-time access behavior data, and decides whether to grant access rights.
[0032] (2) When the token is about to expire, the system automatically refreshes the token and returns it to the user, ensuring the user's continued access.
[0033] (3) The system dynamically monitors user access behavior, adjusts user permissions and performs anomaly detection.
[0034] (4) If abnormal behavior is detected, the system immediately revokes the token, restricts user permissions, or terminates access to ensure the security of the system.
[0035] Preferably, in order to enhance the identity authentication of API visitors, the present invention proposes a dynamic identity authentication mechanism, which is not only based on conventional identity tokens (such as JWT), but also introduces dynamic verification based on behavioral analysis, and dynamically evaluates the credibility of user identity by combining the visitor's device information, geographic location, access frequency and other behavioral data. Through the dynamic identity authentication mechanism, this solution can prevent the credential from being stolen or replayed, and enhance the security of API access. The core steps of this mechanism include: 1) Identity token verification: Each API request carries an encrypted JWT token. The system first verifies the authenticity and validity of the token. The token contains user identity information and access rights.
[0036] 2) Dynamic behavior verification: While verifying the token, the system conducts multi-dimensional behavior analysis based on the visitor behavior data obtained in real time. If abnormal behavior is found (such as sudden geographic location changes, frequent changes in request identifiers, abnormal requests at a fixed frequency, a large number of abnormal (error) requests, etc.), the system will force the user to re-authenticate.
[0037] 3) Temporary permission adjustment: If behavioral analysis determines that the visitor's credibility has decreased (such as changes in IP address or visits during unusual time periods), the system will automatically adjust their access permissions to limit their access to sensitive data or functions.
[0038] Preferably, in view of the limited security of static token authentication in the prior art, the present invention implements a JWT token dynamic management and refresh mechanism to further enhance the security and flexibility of the token. The present invention ensures the timeliness and flexibility of API authentication through the dynamic management and refresh mechanism of JWT, avoiding the common problem of long-term validity of tokens. The specific process is as follows: 1) Token generation and storage: After a user successfully logs in or passes identity authentication, the system will generate a JWT token containing the user's identity information, permissions, and expiration time. The token will be stored in a secure cookie or HTTP header as an authentication credential for subsequent requests.
[0039] 2) Automatically refresh tokens: Use JWT tokens, which have a default validity period of a short period of time (such as 30 minutes). When the system detects that the user is continuously using the API and the token is about to expire, it will automatically generate and send a new token and update the user's access rights. This reduces the need for frequent re-login and the security risks caused by long-term token non-renewal.
[0040] 3) Token revocation mechanism: When abnormal user behavior or identity authentication failure is detected, the system will immediately revoke the user's JWT token and reject subsequent access requests, further improving the security of the system.
[0041] Preferably, the present invention proposes a behavior-based dynamic permission management mechanism to ensure flexible adjustment of API access rights and prevent users from abusing APIs after their permissions are elevated. In the present invention, the user's API access rights are not fixed, but dynamically adjusted according to their real-time behavior data. This mechanism can quickly respond to potential security threats based on the user's access pattern and improve the overall security of the system. It mainly includes the following steps: 1) Behavior Analysis Engine: Based on the point-of-use aggregation method, this engine monitors and analyzes user access behaviors in real time and identifies normal and abnormal behaviors. For example, it determines whether a user is a legitimate user or request based on parameters such as access frequency, time period, request path, abnormal number, and constant frequency access.
[0042] 2) Dynamic permission adjustment: When a user's behavior is abnormal (such as suddenly sending a large number of requests, frequent changes in IP addresses, etc.), the system will automatically reduce their permissions and restrict their access to some API interfaces or sensitive data. At the same time, if the user's behavior is restored to normal, the system will automatically restore their permissions. This proposal tentatively defines resource permission levels as low, medium, high, and special. When permission reduction is triggered, it is reduced to low by default. The default downgrade granularity and custom level can be modified through configuration.
[0043] 3) Multi-level permission control: The system divides permissions at multiple levels according to the user's identity and behavior, ensuring that users can only access functions related to their roles and behaviors, and preventing unauthorized operations. For example, low-trust users can only access basic data, while high-trust users can access sensitive data.
[0044] Preferably, in order to adapt to complex API interaction scenarios and achieve all-round protection from the network layer to the application layer, a multi-level security protection mechanism ensures that the system can cope with complex, cross-system API access security requirements and improve the overall system's defense capabilities. The multi-level security protection mechanism of the present invention mainly includes: 1) Network layer protection: By introducing the API diversion layer, all incoming API requests are initially screened, including current limiting, IP blacklist, network firewall and other strategies to prevent malicious traffic from entering the system.
[0045] 2) Application layer protection: At the application layer, multiple strategies such as authentication, token management, and behavior analysis of API requests are used to ensure user access security. The system will dynamically adjust strategies to implement stricter security protection for high-risk users.
[0046] 3) Anomaly detection and response: The system continuously monitors API access traffic and user behavior data. Once an anomaly is detected (such as DDoS attacks, replay attacks, etc.), it will immediately take corresponding emergency response measures, such as limiting traffic, terminating suspicious sessions, and enforcing identity verification.
[0047] The present invention is compatible with the existing API gateway and microservice architecture, and can work with common current limiting and identity authentication mechanisms. At the same time, the present technical solution provides an enhanced security layer for the existing system, which can effectively make up for the shortcomings of static permissions and fixed policies in the existing technology through behavior analysis and dynamic management.
[0048] The present invention not only enhances the security of API interaction, but also improves the availability and flexibility of the system in a high-concurrency and dynamic environment.
[0049] The present invention proposes a dynamic token refresh mechanism: based on user behavior and access status, the JWT token is refreshed in real time. Compared with traditional static tokens, the present invention adopts a dynamic token refresh mechanism, which can automatically update the JWT according to the frequency of user activities to prevent the credential from being invalid or maliciously used. The present invention performs dynamic permission adjustment based on behavior analysis: dynamically adjusts the user's API access rights by monitoring the user's access behavior. By analyzing the user's access behavior, the present invention can dynamically adjust permissions according to the access environment, device information, access frequency, etc., thereby improving the security of the API. The present invention proposes an encryption and signature verification mechanism: data encryption and signature verification are performed for each API interaction to ensure the integrity and legitimacy of the request. The present invention proposes an anomaly detection and protection mechanism: an anomaly detection system based on traffic analysis can automatically identify and block abnormal requests. The present invention not only encrypts and verifies the data, but also combines abnormal behavior detection and traffic analysis to provide multi-level security protection, which can cope with complex security threats. The present invention proposes an anti-replay attack mechanism: through request signature verification and timestamp management, the uniqueness of each request is ensured to prevent attackers from obtaining sensitive data through replay attacks.
[0050] Embodiment 3: A secure access method based on API interaction. The following takes a typical API access scenario as an example to provide security protection.
[0051] Scenario 1: Figure 3 and Figure 5 As shown, dynamic identity authentication and behavior analysis are performed: (1) User request API: The user initiates an API request to the system through a browser or client, carrying a JWT identity token. The token contains the user's basic identity information and expiration time.
[0052] (2) Identity token verification: The system's security management layer first enters the identity authentication module to verify the JWT token, including: a. Parse the identity token and confirm that it has not expired; b. Verify the signature of the identity token to confirm that it has not been tampered with; c. Extract user identity information and perform basic identity authentication; d. If the verification is successful, a token indicating successful authorization will be returned.
[0053] (3) Behavior analysis and dynamic adjustment: After identity authentication, the behavior analysis module will analyze the user's access behavior, mainly considering the following data: ① The user’s IP address; ②User requests resources; ③Users’ historical access behavior; ④ Type of API accessed and request time; ⑤The user's request path; ⑥The number of abnormal user requests; ⑦Users request access at a constant frequency.
[0054] If the user's behavior conforms to the normal pattern, the system will allow access. If abnormal behavior is found, such as high access frequency, frequent changes in IP address, etc., the system will trigger dynamic permission management and temporarily restrict the user's API access rights.
[0055] (4) Access the resource server with the token and output a securely encrypted message.
[0056] Scenario 2: Dynamic refresh and revocation of JWT tokens: Token refresh mechanism: The user's JWT token has a short validity period (such as 30 minutes). When the system detects that the user's token is about to expire and its behavior is still normal, the system automatically generates a new token and returns it to the user through the response. The new token has an updated validity period, and the user can continue to access the system without re-login.
[0057] Token revocation mechanism: If the user's behavior analysis results show that he has performed abnormal operations, such as forging his identity or attempting to unauthorized access to sensitive data, the system will immediately revoke the user's JWT token and terminate his subsequent API requests. This operation can effectively prevent credential abuse and malicious attacks.
[0058] Scenario 3: Multi-level security protection: Pre-filter layer protection: At the application layer, the system ensures that each user's API request undergoes strict security review through multiple mechanisms such as identity authentication, behavior analysis, and dynamic adjustment of permissions. In high-risk scenarios, such as access to sensitive data, the system will further enhance verification measures and require users to enter additional authentication information to ensure the legitimacy of the visitor.
[0059] Network layer protection: The system sets up an API diversion layer and a security management layer at the network entrance, which has functions such as current limiting, IP blacklist, and flow control. Abnormal traffic and attack requests will be automatically rejected to ensure that malicious traffic cannot enter.
[0060] Scenario 4: Security assurance for the entire API access process: Authentication and permission control: The security management layer verifies the JWT token through the identity authentication module and determines the credibility of the user's behavior through the behavior analysis module. If the verification is successful, the system decides whether to allow the user to access the API based on the user's permissions.
[0061] Access control and emergency response: The system dynamically adjusts user permissions in the permission control module to prevent abnormal users from accessing sensitive data. When user behavior is abnormal, the system will trigger an emergency response to terminate suspicious sessions, revoke tokens, and block access to ensure the security of API services.
[0062] Request reception and processing: When a user sends an API request, the system receives it through the API distribution layer and forwards the request to the API service layer.
[0063] Scenario 5: Adaptability and scalability: The present invention can be seamlessly integrated with existing microservice architectures, API gateways and other systems, and has strong adaptability. By introducing a behavior analysis engine and a dynamic permission management mechanism, the solution has the ability to flexibly expand and can adjust security policies according to specific scenarios to adapt to different access requirements and risk levels.
[0064] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Any simple modification or equivalent change made to the above embodiment based on the technical essence of the present invention shall fall within the protection scope of the present invention.
Claims
1. A secure access method based on API interaction, characterized in that: The following steps are involved: Step S1: The user sends an API request, and the request carries an identity token, wherein the identity token includes user identity information and access rights; Step S2: Receive API request and perform dynamic identity authentication; Step S3: If the validity period of the identity token is about to expire, the identity token is refreshed and sent to the user, and the user's access rights are updated at the same time; Step S4: The behavior analysis engine monitors and analyzes the user's access behavior in real time based on the point aggregation method. If there is abnormal behavior, the identity token is revoked, the user's rights are restricted, or the access is terminated.
2. According to the secure access method based on API interaction according to claim 1, it is characterized in that: In step S2, the received request is preliminarily screened according to any one of the strategies of current limiting, IP blacklist, and network firewall.
3. A secure access method based on API interaction according to claim 1 or 2, characterized in that: The step S2 comprises the following steps: Step S21: First, perform identity token verification: verify the authenticity and validity period of the identity token; Parse the identity token and confirm that it has not expired; Then, verify the signature of the identity token to confirm that it has not been tampered with; Extract user identity information and perform basic authentication; Step S22: Then, after the identity token verification is passed, dynamic behavior verification is performed; based on the visitor behavior data obtained in real time, multi-dimensional behavior analysis is performed, and if abnormal behavior is found, the user is required to re-authenticate; Step S23: Evaluate the credibility of the user's behavior based on the behavior data analysis. If the credibility is evaluated to be low, temporarily restrict the user's API access rights.
4. According to the secure access method based on API interaction of claim 3, it is characterized in that: In step S22, if there is one or more of the following: geographical location changes within the threshold time, request identifier change frequency is higher than the set threshold, fixed frequency of requests is abnormal, and the number of abnormal requests exceeds the threshold, the user is required to re-authenticate. In step S23, if the IP address changes or access is made during an abnormal time period, the user's access to sensitive data or functions is restricted.
5. According to the secure access method based on API interaction according to claim 1, it is characterized in that: In step S3, when the user successfully logs in or passes identity authentication, an identity token containing user identity information, access rights and expiration time is generated and stored in a secure Cookie or HTTP header as an authentication credential for subsequent requests.
6. According to the secure access method based on API interaction of claim 1, it is characterized in that: In step S4, the access behavior data includes any one or more of device information, geographic location, access frequency, time period, request path, abnormal number, and constant frequency access.
7. A secure access method based on API interaction according to claim 6, characterized in that: In step S4, if the number of requests sent within the threshold time exceeds the threshold or the frequency of IP address changes exceeds the threshold, the user authority is restricted.
8. The secure access method based on API interaction according to claim 6, characterized in that: In step S4, if abnormal behavior or identity authentication failure is detected, the user's identity token is revoked and the user's subsequent access request is rejected.
9. A secure access system based on API interaction, based on the secure access method based on API interaction according to any one of claims 1 to 8, characterized in that: Includes user request layer, security management layer, API diversion layer and API service layer; The user request layer is used to send a request, and the request carries an identity token as a verification credential for the user's identity; The security management layer includes: Identity authentication module: used to verify the identity token carried in the request to ensure the legality of the identity; Behavior analysis module: used to monitor and analyze user request behaviors in real time to prevent abnormal or malicious operations; Dynamic permission management module: used to dynamically adjust user permissions based on the behavior analysis results of the behavior analysis module; Token management module: used to manage the generation, refresh and revocation of identity tokens to ensure the security and timeliness of tokens; The API diversion layer includes: API diversion module: used to receive and forward requests to the corresponding API service; Current limiting and load balancing module: used to control the request rate to prevent system overload caused by too many requests, and distribute requests evenly to different service instances; The API service layer is used to execute different service logics according to requests and process API interfaces of specific business logics.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the secure access method based on API interaction described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Method for realizing visual data processing by constructing API (Application Program Interface) gateway through process service orchestration
CN115277817A
Interface interaction data security protection method based on AI high-speed regular matching
CN116260650A
Data interaction method and device
CN118199974A
Cited By
Security event early warning and response method based on operator-level network
CN120710781A
Authentication method for calling API (Application Program Interface) by large model and related device
CN121283639A