API (Application Program Interface) data security implementation method and gateway

By inserting hidden characters into the API response data and combining symbol mapping tables, the problems of API data tampering and leaking traceability are solved, and data security and traceability are improved.

CN120200813APending Publication Date: 2025-06-24ANQING CITY DATA RESOURCES MANAGEMENT BUREAU +2
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510371477.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

API data is easily tampered with when text data is returned, or API modules are fake, resulting in response incorrect data return, causing customer privacy or network security issues, and data leakage cannot be traced.

Method used

Insert hidden characters in an invisible form in the API response data, and restore the sending source and receiving end of the response data in combination with the symbol map table in the server. The response data is isolated by verifying the composition and insertion position of the hidden characters to achieve data traceability.

Benefits of technology

Effectively prevent API from responding to data tampering, ensuring data integrity, and tracing the source of the leak when data is leaked, accurately locate the source of the leak, which is simple and easy to use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200813A_ABST
    Figure CN120200813A_ABST
Patent Text Reader

Abstract

The invention discloses an API (Application Program Interface) data security implementation method and a gateway, and relates to the technical field of data security. When response data is returned to an API request initiated by a client, a server is used for inserting hidden characters in the API response data in an invisible form; the hidden characters are used for restoring a sending source and a receiving end of the response data in combination with a symbol mapping table stored in the server; whether the API return response data goes wrong or not can be indicated by checking whether the hidden characters are inserted or not, and meanwhile, when the hidden characters are inserted in an invisible mode, tracing can be carried out when data are leaked, and a data leakage source is accurately positioned; the method is simple, effective, easy and practical.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data security, and specifically relates to an API data security implementation method and a gateway. Background Art

[0002] With the continuous development of Internet applications, APIs have become an important way for data interaction and function integration between applications. However, the widespread use of APIs has also brought new data security risks, including but not limited to unauthorized access, data leakage, API abuse, etc. Traditional network security measures, such as firewalls and intrusion detection systems, are difficult to effectively cope with attacks at the API interface level and data security.

[0003] For example, Chinese Patent CN117879906A provides an API data security event recognition method, device, electronic device and medium. When the API traffic to be analyzed matches the pre-acquired abnormal behavior recognition rules, at least one historical traffic log associated with the access entity information of the API traffic to be analyzed is obtained according to the access entity information of the API traffic to be analyzed; wherein, the abnormal behavior recognition rules are used to identify abnormal behaviors, and the abnormal behavior recognition rules include rules formed by combining feature tags of different dimensions; the recorded data of each historical traffic log is statistically analyzed to obtain a statistical analysis result; according to the statistical analysis result, an API data security event is output. Also, Chinese Patent CN117527412A discloses a data security monitoring method and device. When the risk value is higher than the risk threshold, it is determined that there is high-risk API data in the application program environment. Chinese Patent CN118760461A provides a method for API security management of an application program interface API and an API management platform for security management of data resources throughout the API life cycle.

[0004] However, when API data returns text data, first, the text data is very easy to be tampered with by others, or the API module is faked, resulting in incorrect response data being returned to the client, causing customer privacy or network security problems. Second, it is also a difficult problem that any client cannot trace the source after obtaining API data and causing data leakage. Based on this, a solution is provided. Summary of the Invention

[0005] The present invention aims to solve at least one of the technical problems existing in the prior art;

[0006] To this end, the present invention proposes an API data security implementation method, including the following steps:

[0007] When returning response data to an API request initiated by a client, the server is used to invisibly insert hidden characters into the API response data, and the hidden characters are used to restore the source and recipient of the response data in combination with a symbol mapping table stored in the server.

[0008] Furthermore, the hidden characters are formed by combining an identifier that maps the source identity information and an identifier that maps the recipient identity information.

[0009] Furthermore, the symbol mapping table contains a number of one-to-one corresponding identifiers and identity information.

[0010] Furthermore, the formation method of the hidden characters is as follows:

[0011] It is formed in the form that the identifier corresponding to the source identity information is in the front and the identifier corresponding to the recipient identity information is in the back.

[0012] Furthermore, the formation method of the hidden characters is as follows:

[0013] Arrange the corresponding identifiers before and after in descending order of the number of characters of the source identity information and the recipient identity information.

[0014] Furthermore, when the number of characters in the response data is even, it is combined in the form that the identifier corresponding to the source identity information is in the front and the identifier corresponding to the recipient identity information is in the back;

[0015] If it is not even, it is combined in the way that the positions of the above two identifiers are reversed.

[0016] Furthermore, the hidden characters determine the insertion position according to the maximum number of repeated characters in the response data.

[0017] Furthermore, when the maximum number of repetitions is even, obtain the numerical value of the units digit of the maximum number of repetitions, and insert the hidden characters after the character corresponding to the positive numerical value in the response data;

[0018] Otherwise, obtain the numerical value of the units digit of the maximum number of repetitions, and insert the hidden characters before the character corresponding to the positive reciprocal numerical value in the response data.

[0019] Furthermore, when the API is used to return the response data with hidden characters inserted to the client, the client with access permission can verify the composition and insertion position of the hidden characters, and isolate the response data when any one does not conform.

[0020] API data security gateway, and this gateway uses the aforementioned method to achieve API data security.

[0021] Compared with the prior art, the beneficial effects of the present invention are:

[0022] When the server returns response data for an API request initiated by the client, the server is used to insert hidden characters in an invisible form into the API response data. The hidden characters are used to restore the source and recipient of the response data in combination with the symbol mapping table stored in the server. By verifying whether the hidden characters are inserted, it can indicate whether there is a problem with the API returning response data. At the same time, by inserting hidden characters in an invisible form, it can also be used for tracing when data is leaked to accurately locate the source of the data leak. The present application is simple and effective and easy to use. Description of the Drawings

[0023] Figure 1 is a flowchart of the present invention;

[0024] Figure 2 is a diagram of the combination method of hidden characters of the present invention. Detailed Embodiments

[0025] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0026] Embodiment 1:

[0027] Please refer to Figure 1 , the present application provides an API data security implementation method, including the following steps:

[0028] First, the server receives an API request from the client through the front-end proxy module; each request is marked with a unique request ID for subsequent tracking;

[0029] Detect whether there is malicious behavior in the API request. Malicious behaviors mainly include behaviors such as SQL injection and cross-site scripting attacks. If malicious behavior is detected, the API request will be blocked and recorded in the alarm record;

[0030] Through account identification and the client IP, the system will call the permission control module for authorization verification according to the identity of the requestor and the API resources requested; only requests with access permissions can continue to be sent to the backend server; at the same time, the frequency and concurrency of requests within any time or a specified time period are restricted to ensure that each client does not exceed the preset access limit; once the request frequency exceeds the set threshold, the system will throttle or deny service to the request;

[0031] The API requests that have passed the security check will be forwarded to the corresponding backend API server for processing, and the responses returned by the backend server will enter the API data security gateway again;

[0032] After the response data returned by the server enters the API data security gateway, it will be traced and analyzed. The specific method of tracing and analysis is as follows:

[0033] After the response data is generated, if any acquisition process of the response data occurs, the object that obtains the corresponding response data will be automatically intercepted and marked as the receiving end. At the same time, its sending source will be obtained, and the sending source is referred to as the object that returns the response data;

[0034] A mapping table is established to lock the hidden characters from the identity information of the sending source and the receiving end. The specific method is as follows:

[0035] Here, after obtaining the identity information of the sending source and the receiving end, an identity identifier can be assigned to the two identity information. The identity identifier is unique and is a single character, and a symbol mapping table is constructed. The symbol mapping table contains several pieces of identity information and their corresponding identity identifiers, and the symbol mapping table is stored in the server; the identity information refers to the IP address of the corresponding user, or other representations that can identify the identities of the sending end and the receiving end; for the client, it can be an API Key, Token, user agent, IP address, device fingerprint, etc., and the server identity can be content such as an HTTPS certificate, APIGateway, load balancer, custom header field, etc.;

[0036] After obtaining the identity identifiers of the sending source and the receiving end, the two are combined in the order of the sending source identity identifier first and the receiving end identity identifier second to form a hidden character, and the hidden character is attached to the tail of the corresponding response data in the form of an invisible character. When data is leaked later, the hidden character can be used to call which sending source and a receiving end the leaked message comes from, facilitating the tracing of the leakage direction.

[0037] Embodiment 2:

[0038] As Embodiment 2 of the present application, this embodiment provides a different way of combining hidden characters. The specific method is as follows:

[0039] Mark the identity information of the sending source as the sending information, mark the identity information of the receiving end as the receiving information, obtain the number of characters of the sending information and the receiving information, and place the corresponding identity identifiers of the sending source and the receiving end in the front and back in the order from largest to smallest number of characters.

[0040] Embodiment 3:

[0041] As Embodiment 3 of the present application, as Figure 2As shown in the figure, on the basis of Embodiment 1, this embodiment is real-time. The difference is that a different hidden character combination method is provided in this application. The specific method is as follows:

[0042] Obtain the number of characters with the same number in the response data, and mark it as the determined number. When the determined number is even, at this time, combine the identity identifier corresponding to the sending source first and the identity identifier corresponding to the receiving end second to obtain the hidden character. When the determined number is not even, at this time, automatically combine the identity identifier corresponding to the receiving end first and the identity identifier corresponding to the sending source second to obtain the hidden character.

[0043] Embodiment 4:

[0044] As Embodiment 4 of this application, this embodiment is carried out on the basis of any one of Embodiments 1, 2, and 3. The difference is that after obtaining the hidden character in this application, the following steps will be performed, specifically:

[0045] Obtain the number of repetitions of any character that appears repeatedly in the response data, and mark the largest value of the number of repetitions as the determined number. When the determined number is even, at this time, obtain the units digit of the determined number and mark it as the sequential insertion value; if the determined number is not even, at this time, mark the units digit of the determined number as the reverse insertion value;

[0046] When generating the sequential insertion value, automatically insert the corresponding hidden character after the character corresponding to the value of the sequential insertion value starting from the first character of the response data;

[0047] When generating the reverse insertion value, automatically insert the corresponding hidden character before the character corresponding to the value of the sequential insertion value starting from the last character of the response data.

[0048] Embodiment 5:

[0049] As Embodiment 5 of this application, this embodiment is carried out on the basis of any one of Embodiments 1 to 5. The difference is that after generating the response data with the hidden character inserted, when the API is used to send the response data back to the client, at this time, the regular client, or the client with access permission, will verify the response data according to the preset parsing rules. The parsing rules are specifically as follows:

[0050] First, it is necessary to identify whether there is a hidden character in the response data. When there is no hidden character, the response data will be automatically isolated and stored in a secure sandbox or other secure environment, indicating that the data returned by the API in the server at this time may be counterfeited. The data at this time is highly suspicious and requires the user to further process it later and select whether to delete the corresponding data;

[0051] Of course, if there are hidden characters at this time, they also need to be verified according to the different solutions in Embodiment 2, Embodiment 3, and Embodiment 4; the hidden characters identified here can be recognized by the authorized client itself, will not be displayed to the user, and will not prompt the user that there are hidden characters to prevent the hidden characters from being tampered with;

[0052] When this embodiment is implemented on the basis of Embodiment 2, the identity information of the local client needs to be obtained. Since the local client is the receiving end at this time, its identity information is the received information. Then, two identity identifiers are obtained from the hidden characters, and two corresponding identity information are obtained from the symbol mapping table; the two identity information are compared with the received information. If both identity information are inconsistent with the received information, the response data will be automatically isolated for the user to perform subsequent processing. Otherwise, the inconsistent identity information is the sent information. Automatically obtain the number of characters of the sent information and the received information, and confirm whether there is an incorrect order of the two identity identifiers according to the order of the two character numbers. If so, it also means that there is a problem with the corresponding response data and needs to be processed. Otherwise, it is not necessary;

[0053] If this embodiment is implemented on the basis of Embodiment 3, the identity information of the local client needs to be obtained. Since the local client is the receiving end at this time, its identity information is the received information. Then, two identity identifiers are obtained from the hidden characters, and two corresponding identity information are obtained from the symbol mapping table; the two identity information are compared with the received information. If both identity information are inconsistent with the received information, the response data will be automatically isolated for the user to perform subsequent processing. Otherwise, the inconsistent identity information is the sent information. When the number of characters of the response data is detected to be even, if the identity identifier corresponding to the sent information is not in front and the identity identifier corresponding to the received information is not behind, it means that there is a problem with the response data. When the number of characters of the response data is not even, if the identity identifier corresponding to the received information is not in front and the identity identifier corresponding to the sent information is not behind, it means that there is a problem with the response data;

[0054] If this embodiment is implemented on the basis of Embodiment 4, the number of repetitions of any repeatedly occurring characters in the response data needs to be obtained, and the largest value of the number of repetitions is marked as the determined number. When the determined number is even, the units digit of the determined number is obtained and marked as the sequential insertion value; when the determined number is not even, the units digit of the determined number is marked as the reverse insertion value;

[0055] When the sequential insertion value is generated, automatically check whether the hidden character is inserted after the character corresponding to the value of the sequential insertion value starting from the first character of the response data;

[0056] When generating reverse insertion values, automatically check whether hidden characters are inserted after the character where the value corresponding to the reverse insertion value is located, starting from the last character of the response data;

[0057] If any of the conditions is not met, it still indicates that there is a problem with the corresponding response data.

[0058] Embodiment Six:

[0059] Certainly, as Embodiment Six of the present application, this embodiment is used to implement the integration of the aforementioned five embodiments. If there are any mutually parallel technical solutions, one solution is randomly selected for implementation.

[0060] Certainly, the present application also provides an API data security gateway, which realizes API data security through the technical solutions disclosed in the aforementioned six embodiments.

[0061] Some of the data in the above formula are calculated by removing the dimension and taking their numerical values. The formula is obtained by software simulation of a large amount of collected data to get a formula closest to the actual situation; the preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.

[0062] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. API data security implementation method, characterized in that: The steps include: When returning response data to an API request initiated by a client, the server is used to insert hidden characters in the API response data in an invisible form. The hidden characters are used to restore the sending source and receiving end of the response data in combination with a symbol mapping table stored in the server.

2. The API data security implementation method according to claim 1, characterized in that: The hidden character is formed by combining an identity identifier that maps the identity information of the sending source and an identity identifier that maps the identity information of the receiving end.

3. The API data security implementation method according to claim 2, characterized in that: The symbol mapping table contains a number of one-to-one corresponding identity identifiers and identity information.

4. The API data security implementation method according to claim 2, characterized in that: The hidden characters are formed as follows: It is composed in the form of the identity identifier corresponding to the identity information of the sending source being in front and the identity identifier corresponding to the identity information of the receiving end being in the back.

5. The API data security implementation method according to claim 2, characterized in that: The hidden characters are formed as follows: The corresponding identity identifiers are arranged in front and back according to the order of the number of characters of the identity information of the sending source and the identity information of the receiving end from large to small.

6. The API data security implementation method according to claim 2, characterized in that: When the number of characters in the response data is an even number, the identity identifier corresponding to the identity information of the sending source is placed in front, and the identity identifier corresponding to the identity information of the receiving end is placed in the back; If it is not an even number, it is formed by reversing the positions of the two above-mentioned identity identifiers.

7. The API data security implementation method according to claim 6, characterized in that: The hidden character is inserted at a position determined by the maximum number of repetitions of the characters in the response data.

8. The API data security implementation method according to claim 7, characterized in that: When the maximum number of repetitions is an even number, the value of the single digit of the maximum number of repetitions is obtained, and the hidden character is inserted after the character corresponding to the positive value of the response data; Otherwise, obtain the value of the maximum number of repetitions, and insert the hidden character before the character corresponding to the positive and negative values ​​of the response data.

9. The API data security implementation method according to claim 1, characterized in that: When the API is used to transmit the response data of the inserted hidden characters back to the client, the client with access rights can verify the composition and insertion position of the hidden characters, and isolate the response data when any one of them does not meet the requirements. 10.API data security gateway, characterized by: The gateway implements API data security using the method described in any one of claims 1-9.

Citation Information

Patent Citations

  • Data security monitoring method and device

    CN117527412A

  • API (Application Program Interface) data security event identification method and device, electronic equipment and medium

    CN117879906A

  • Application program interface security management method and API management platform

    CN118760461A

  • Data label traceability technology for Web layer

    CN114257449A

  • Universal text watermarking method and device

    CN114708133A