A security orchestration method, device, equipment, medium and product

By uniformly acquiring and parsing API requests through a gateway, and using pre-configured orchestration plugins for secure orchestration, the problem of flexible adaptation and operational complexity of API gateways in complex security scenarios is solved, achieving efficient, secure, and convenient transmission of API data.

CN120614211BActive Publication Date: 2025-10-28SHANGHAI PARAVIEW SOFTWARE CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511106348.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-08
Publication Date
2025-10-28
Estimated Expiration
2045-08-08

AI Technical Summary

Technical Problem

Existing API gateways lack flexibility in adapting to complex and ever-changing security requirements, resulting in high modification costs, increased operational complexity, and inconsistent encryption algorithms and chaotic signature verification rules due to decentralized processing, impacting system stability and performance.

Method used

API requests are uniformly obtained through a gateway, parsed according to pre-configured filtering conditions, and processed securely using pre-configured orchestration plugins to achieve unified and secure orchestration of API data.

Benefits of technology

Efficient processing is achieved through a unified gateway entry point, ensuring secure transmission of API data, reducing operational costs, and improving the convenience and adaptability of security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614211B_ABST
    Figure CN120614211B_ABST
Patent Text Reader

Abstract

This invention discloses a secure orchestration method, apparatus, device, medium, and product. The secure orchestration method includes: acquiring an Application Programming Interface (API) request and determining the target API to which the API request belongs; parsing the API request according to pre-configured filtering conditions of the target API to obtain a parsing result; and performing secure orchestration processing on the parsing result according to a pre-configured orchestration plugin corresponding to the target API to obtain target data. By using pre-configured filtering conditions and orchestration plugins corresponding to the API interface, secure orchestration processing of the API request is performed to obtain the target data. This achieves efficient processing at a unified gateway entry point, ensures secure transmission of API data, reduces operation and maintenance costs, and improves the convenience and adaptability of security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a secure orchestration method, apparatus, equipment, medium and product. Background Technology

[0002] In today's digital age, enterprises rely on a large number of Application Programming Interfaces (APIs) for internal system integration and external data exchange services. As a key channel for data flow, the security of APIs is of paramount importance.

[0003] Traditionally, secure operations on API data are often distributed across various business servers, with security processing performed before transmission to the API gateway. The API gateway, with its robust traffic control and plugin extension capabilities, can also provide secure processing for API data.

[0004] However, when faced with complex and ever-changing security requirements, existing methods have revealed many shortcomings. On the one hand, the flexibility of security processing at the API gateway is limited, and once business security policies are adjusted, the cost of modification is high and it is easy to affect the overall system stability. On the other hand, decentralized processing leads to a surge in operational complexity, with inconsistent encryption algorithms and chaotic signature verification rules between different modules. Additional data transfers and repeated verifications cause performance losses, making it difficult to meet the demands of efficient and secure modern API interaction. Summary of the Invention

[0005] This invention provides a secure orchestration method, apparatus, device, medium, and product to achieve unified secure orchestration of API data through a gateway, thereby improving the adaptability of security protection.

[0006] According to a first aspect of the present invention, a security orchestration method is provided, applied to a gateway, comprising:

[0007] Obtain the application programming interface (API) request and determine the target API to which the API request belongs;

[0008] The API request is parsed according to the pre-configured filtering conditions of the target API to obtain the parsing result;

[0009] The parsing results are securely orchestrated using the pre-configured orchestration plugin corresponding to the target API to obtain the target data.

[0010] According to a second aspect of the present invention, a security orchestration apparatus is provided, comprising:

[0011] The request acquisition module is used to acquire application programming interface (API) requests and determine the target API to which the API request belongs;

[0012] The result determination module is used to parse the API request according to the pre-configured filtering conditions of the target API and obtain the parsing result;

[0013] The data orchestration module is used to perform secure orchestration processing on the parsing results according to the pre-configured orchestration plugin corresponding to the target API, so as to obtain the target data.

[0014] According to a third aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0015] At least one processor; and

[0016] A memory communicatively connected to the at least one processor; wherein,

[0017] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the secure orchestration method according to any embodiment of the present invention.

[0018] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the secure orchestration method described in any embodiment of the present invention.

[0019] According to a fifth aspect of the present invention, embodiments of the present invention also provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the secure orchestration method of any embodiment of the present invention.

[0020] The technical solution of this invention involves acquiring an Application Programming Interface (API) request and determining the target API to which the API request belongs; parsing the API request according to pre-configured filtering conditions of the target API to obtain a parsing result; and performing secure orchestration processing on the parsing result according to a pre-configured orchestration plugin corresponding to the target API to obtain target data. By using pre-configured filtering conditions and orchestration plugins corresponding to the API interface, secure orchestration processing of the API request is performed to obtain the target data. This achieves efficient processing at a unified gateway entry point, ensures secure transmission of API data, reduces operational costs, and improves the convenience and adaptability of security protection.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart of a secure orchestration method provided according to Embodiment 1 of the present invention;

[0024] Figure 2 This is an example interface diagram of a secure orchestration method provided according to Embodiment 1 of the present invention;

[0025] Figure 3 This is a schematic diagram of a security orchestration device according to Embodiment 2 of the present invention;

[0026] Figure 4 This is a schematic diagram of the structure of an electronic device that implements an embodiment of the present invention. Detailed Implementation

[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0029] Example 1

[0030] Figure 1 The flowchart illustrates a secure orchestration method provided in Embodiment 1 of the present invention. This embodiment is applicable to secure orchestration of different API requests. The method can be executed by a secure orchestration device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, this method is applied to a gateway and includes:

[0031] S110. Obtain the application programming interface (API) request and determine the target API to which the API request belongs.

[0032] In this embodiment, an API request can be understood as a request sent to the gateway through an API interface to obtain data or perform a specific operation. The target API can be understood as the API that sent the API request.

[0033] Specifically, the gateway's processor (hereinafter referred to as the processor) can obtain API requests initiated by external clients. The processor can first determine the target API that transmits the API request.

[0034] S120. Parse the API request according to the pre-configured filtering conditions of the target API to obtain the parsing result.

[0035] In this embodiment, the pre-configured filtering conditions can be understood as conditions used to determine the features to be encoded. Since the business characteristics, requirements and data sensitivity of different fields or different businesses are different, the content that the target API needs to be security orchestrated can be pre-set through the pre-configured filtering conditions.

[0036] Specifically, the processor can first determine the pre-configured filtering conditions corresponding to the target API. For example, the API can be bound to the pre-configured filtering conditions through binding, thereby triggering a fast parsing of the API request based on the pre-configured filtering conditions to obtain the parsing results. If certain data may not require security orchestration, then pre-configured filtering conditions can be omitted, indicating that security orchestration is not necessary.

[0037] S130. Perform secure orchestration processing on the parsed results according to the pre-configured orchestration plugin corresponding to the target API to obtain the target data.

[0038] In this embodiment, the pre-configured orchestration plugin can be understood as a pre-configured tool or component for automating the secure orchestration of the target API. The target data can be understood as the orchestrated data result.

[0039] Specifically, the processor can perform secure orchestration processing on the parsed results based on the pre-configured orchestration plugins bound to the target API. For example, the pre-configured orchestration plugins include steps such as encryption, encoding, and signature. The parsed results are processed sequentially using the configuration parameters and corresponding algorithms in the pre-configured orchestration plugins to obtain the securely orchestrated target data.

[0040] The technical solution of this invention involves acquiring an Application Programming Interface (API) request and determining the target API to which the request belongs; parsing the API request according to pre-configured filtering conditions of the target API to obtain the parsing result; and performing secure orchestration processing on the parsing result according to a pre-configured orchestration plugin corresponding to the target API to obtain the target data. By using pre-configured filtering conditions and orchestration plugins corresponding to the API interface to perform secure orchestration processing on the API request and obtain the target data, this achieves efficient processing at a unified gateway entry point, ensures secure transmission of API data, reduces operational costs, and improves the convenience and adaptability of security protection.

[0041] Furthermore, based on the above embodiments, the steps for parsing API requests according to the pre-configured filtering conditions of the target API to obtain the parsing results can be refined as follows:

[0042] The request header structure in the API request is analyzed according to the pre-configured filtering conditions, and the data characteristics of the request body are scanned to determine the fields to be arranged; the fields to be arranged are used as the parsing results.

[0043] In this embodiment, the request header structure can be understood as the part used to convey additional information about the request, and may carry information related to the external client. The request body data characteristics can be understood as the features and attributes of the data that constitutes the request body. The fields to be orchestrated can be understood as the fields that undergo secure orchestration processing.

[0044] Specifically, the processor can analyze the request header structure in the API request according to the pre-configured filtering conditions and scan the data characteristics of the request body to determine the fields to be orchestrated. For example, the fields to be orchestrated can be the request method, request address, request headers and request parameters, etc. The processor can use the fields to be orchestrated as the parsing results.

[0045] Furthermore, based on the above embodiments, the steps of performing secure orchestration processing on the parsing results according to the pre-configured orchestration plugin corresponding to the target API to obtain the target data can be refined as follows:

[0046] The parsing results are securely orchestrated based on the algorithm in the pre-configured orchestration plugin corresponding to the target API to obtain intermediate results; the intermediate results are then replaced in the API request based on the position information in the pre-configured orchestration plugin to obtain the target data.

[0047] In this embodiment, the algorithm can be understood as an algorithm for secure orchestration processing, such as a signature algorithm, encoding algorithm, and encryption algorithm. Location information can be understood as the location replaced by the processed target data.

[0048] Specifically, the processor can perform secure orchestration processing on the parsed results according to the algorithm in the pre-configured orchestration plugin bound to the target API to obtain intermediate results; based on the position information in the pre-configured orchestration plugin, the intermediate results are replaced in the API request to obtain the target data.

[0049] Based on the above embodiments, the steps for securely orchestrating the parsing results according to the algorithm in the pre-configured orchestration plugin corresponding to the target API to obtain intermediate results can be refined as follows:

[0050] The parsing result is signed using the signature algorithm set in the pre-configured orchestration plugin, and the signed result is temporarily stored in a preset cache area. The signed result is then encoded using the encoding algorithm set in the pre-configured orchestration plugin, and the encoded result is temporarily stored in a preset cache area. Finally, the encoded result is encrypted using the encryption algorithm set in the pre-configured orchestration plugin to obtain an intermediate result.

[0051] In this embodiment, the signature algorithm set can be understood as a pre-configured set of signing algorithms, which can be one or more combined. The signing result can be understood as the result after signing. The preset buffer can be understood as a dedicated buffer pre-defined in memory, used to temporarily store temporary results during processing, such as intermediate values ​​for signature calculation, temporary results of encoding conversion, and encrypted ciphertext fragments. The encoding algorithm set can be understood as a pre-configured set of encoding algorithms, which can be one or more combined. The encoding result can be understood as the result after encoding. The encryption algorithm set can be understood as a pre-configured set of encryption algorithms.

[0052] Specifically, the processor can sign the parsed result based on the signature algorithm set in the pre-configured orchestration plugin, obtain the signed result, and temporarily store it in a preset cache. It can then encode the signed result based on the encoding algorithm set in the pre-configured orchestration plugin, obtain the encoded result, and temporarily store it in a preset cache. Finally, it can encrypt the encoded result based on the encryption algorithm set in the pre-configured orchestration plugin to obtain an intermediate result. The order of signing, encoding, and encryption can be set or reduced according to requirements; for example, it can include only signing, signing and encoding, or encoding and encryption, etc. The order and operation can be customized as needed.

[0053] For example, the pre-configured orchestration plugin includes signing, encoding, and encryption steps. First, it enters the signing step. The processor can extract content from the specified request header field based on the pre-configured orchestration plugin, calculate the signature value according to the pre-configured signing algorithm (e.g., HMAC-SHA256 signing algorithm, combined with the configuration key "sign_secret_key_1"), and store it in a dedicated cache. Then, it encodes according to the selected encoding algorithm (assuming base64 is selected). Finally, it encrypts according to the selected encryption algorithm (e.g., RSA encryption algorithm, combined with the configuration key "encrypt_secret_key_1"). The intermediate result obtained after encryption is replaced in the specified position of the API request according to the position information, such as placing it in a field of the message header or message body. It is then forwarded to the backend business service by the gateway processor, and the data validity is verified.

[0054] The beneficial effects of exercising power

[0055] As a first optional embodiment of this embodiment, based on the above embodiments, the configuration process of the pre-configured orchestration plugin includes:

[0056] In response to the security orchestration request of the registration API, at least three component functional modules are displayed through a visual configuration interface. These modules include a signature component, an encoding component, and an encryption component. The system receives orchestration information, location information, and parameter configuration information for each component functional module from the visual configuration interface. Based on the orchestration information, the system determines the processing order of each component functional module. Based on the parameter configuration information, the system determines the request data range and algorithm parameter information for each component functional module. Based on the processing order, location information, request data range, and detailed algorithm parameters, the system generates a pre-configured orchestration plugin for the registration API.

[0057] In this embodiment, the registration API can be understood as the API registered with the gateway. A security orchestration request can be understood as a request used to establish a pre-configured orchestration plugin. A visual configuration interface can be understood as an interface that displays configuration content in a visual form. Component functional modules can be understood as providing orchestration functionality in the form of components. Orchestration information can be understood as the included orchestration operations and their order, such as encryption followed by signing; or encoding followed by encryption; or signing followed by encoding and finally encryption, etc. Parameter configuration information can be understood as configuration content related to algorithm processing. Request data range can be understood as the processing range in the request, such as specific request header fields and request parameter fields. Algorithm parameter information can be understood as information related to algorithm parameters, such as keys, initialization vectors, and encoding format specifications, etc. Processing order can be understood as the application order of component functional modules.

[0058] Specifically, the processor can respond to security orchestration requests from external clients' registration APIs by displaying at least three component functional modules through a visual configuration interface. These modules include a signature component, an encoding component, and an encryption component. Each module corresponds to a rich algorithm library and parameter configuration items. For example, the signature component covers HMAC-SHA series algorithms (such as HMAC-SHA256, HMAC-SHA384, and HMAC-SHA512) and RSA signature algorithms. The encoding component includes common types such as Base64 encoding and Hex encoding. The encryption component supports mainstream encryption algorithms such as AES (different modes such as AES-CBC and AES-GCM) and RSA public key encryption. External client users can select the required functions and fill in the parameters according to their needs. The processor can receive orchestration information, location information, and parameter configuration information for each component functional module from the visual configuration interface. The processor can determine the processing order of each component's functional modules based on the orchestration information; determine the request data range and algorithm parameter information of the component's functional modules based on the parameter configuration information; generate a pre-configured orchestration plugin for the registered API based on the processing order, location information, request data range, and detailed algorithm parameters, and establish a binding relationship between the registered API and the pre-configured orchestration plugin so that the pre-configured orchestration plugin corresponding to the registered API can be directly called and the API can be published.

[0059] Furthermore, based on the above embodiments, the request data range and algorithm parameter information of the component functional modules are determined according to the parameter configuration information, including:

[0060] If the parameter configuration information belongs to the signature component functional module, the request data range and algorithm parameter information of the signature component functional module are determined. The algorithm parameter information includes at least one signature algorithm, a signature key, and the signature algorithm processing order. The request data range includes at least one of the request method, request address, request header, and request parameters. If the parameter configuration information belongs to the encoding component functional module, at least one encoding conversion algorithm and the encoding algorithm processing order of the encoding component module are determined as algorithm parameter information. If the parameter configuration information belongs to the encryption component functional module, the key corresponding to at least one encryption algorithm of the encryption component module and the encryption algorithm processing order are determined as algorithm parameter information.

[0061] In this embodiment, the signature algorithm processing order can be understood as the execution order of different algorithms when multiple preceding algorithms are used. The encoding algorithm processing order can be understood as the execution order of different algorithms when multiple encoding algorithms are used. The encryption algorithm processing order can be understood as the execution order of different algorithms when multiple encryption algorithms are used. The key can be understood as the character sequence used to encrypt and decrypt data; different encryption algorithms or signature algorithms can have different keys.

[0062] Specifically, in response to parameter configuration information belonging to the signature component functional module, the request data range and algorithm parameter information of the signature component functional module are determined. Since one or more algorithms can be selected for signing as needed, the algorithm parameter information includes at least one signature algorithm, a signature key, and the processing order of the signature algorithms. The request data range includes at least one of the request method, request address, request header, and request parameters. In response to parameter configuration information belonging to the encoding component functional module, at least one encoding conversion algorithm and the encoding algorithm processing order of the encoding component module are determined as algorithm parameter information. In response to parameter configuration information belonging to the encryption component functional module, the key corresponding to at least one encryption algorithm and the encryption algorithm processing order of the encryption component module are determined as algorithm parameter information.

[0063] The first optional embodiment of this embodiment allows for the free configuration of orchestration, signing, encoding, and encryption processes for different registration APIs through a visual configuration interface. This enables users to flexibly customize and combine security orchestration operation sequences and detailed parameter configurations based on different needs such as business characteristics, compliance requirements, and data sensitivity. It also automatically generates pre-configured orchestration plugins for different APIs, fully leveraging the advantages of the gateway architecture and its plug-in extensibility to improve the accuracy of system security protection.

[0064] For example, to facilitate understanding of the configuration process, a visual configuration interface will be used as an example. Figure 2 This is an example interface diagram of a secure orchestration method provided in Embodiment 1 of the present invention. Figure 2As shown, the signature processing section includes four fields: request method, request address, request header, and request parameters. Users can select the appropriate field and input its content. The signature algorithm can be chosen based on requirements; the image shows two algorithms, but more can be combined. For each algorithm, the same or different keys can be set to enrich the encryption methods and improve the encryption effect. Similarly, multiple encoding algorithms can be combined; for example, the image shows selecting base64 and hex algorithms sequentially. All provided encoding algorithms can be selected from the dropdown menu in the lower right corner, allowing for arbitrary combinations to enhance encoding performance and meet personalized requirements. The encryption component module provides various encryption algorithms. Users can add encryption algorithms and corresponding keys to meet different encryption needs for different API interfaces. The image shows selectable encryption algorithms: rsa2Encrypt, aes128, and aes192, each with its own key. Different keys can be set to implement different encryption algorithms. After selecting and filling in all the information, users can click the "Generate" button. The processor will automatically generate the execution code corresponding to the API and the configured orchestration plugin based on the selected algorithm and corresponding parameter configuration information. The generated code can be displayed visually. After generating the code, users can also fill in the location where the processed data will be entered in the location processing section. They can select the message header and message body, and enter the field names corresponding to the locations to be filled in the message body and message header. By clicking the "OK" control, the final pre-configured orchestration plugin is generated, bound to the registered API, and the API is published.

[0065] Example 2

[0066] Figure 3 This is a schematic diagram of a secure orchestration device provided in Embodiment 2 of the present invention. Figure 3 As shown, the device includes:

[0067] Request acquisition module 31 is used to acquire application programming interface (API) requests and determine the target API to which the API request belongs;

[0068] Result determination module 32 is used to parse the API request according to the pre-configured filtering conditions of the target API and obtain the parsing result;

[0069] The data orchestration module 33 is used to perform secure orchestration processing on the parsing results according to the pre-configured orchestration plugin corresponding to the target API to obtain the target data.

[0070] Furthermore, the result determination module 32 is specifically used for:

[0071] Analyze the request header structure in the API request according to the pre-configured filtering conditions and scan the data characteristics of the request body to determine the fields to be arranged.

[0072] The field to be arranged is used as the parsing result.

[0073] Furthermore, the data orchestration module 33 includes:

[0074] The first determining unit is used to perform secure orchestration processing on the parsing result according to the algorithm in the pre-configured orchestration plugin corresponding to the target API to obtain an intermediate result;

[0075] The second determining unit is used to replace the intermediate results in the API request based on the position information in the pre-configured orchestration plugin to obtain the target data.

[0076] The technical solution of this invention involves acquiring an Application Programming Interface (API) request and determining the target API to which the API request belongs; parsing the API request according to pre-configured filtering conditions of the target API to obtain a parsing result; and performing secure orchestration processing on the parsing result according to a pre-configured orchestration plugin corresponding to the target API to obtain target data. By using pre-configured filtering conditions and orchestration plugins corresponding to the API interface, secure orchestration processing of the API request is performed to obtain the target data. This achieves efficient processing at a unified gateway entry point, ensures secure transmission of API data, reduces operational costs, and improves the convenience and adaptability of security protection.

[0077] Specifically, the first determining unit is used for:

[0078] The parsing result is signed based on the signature algorithm set in the pre-configured orchestration plugin, and the signed result is temporarily stored in a preset cache area.

[0079] The signature result is encoded based on the encoding algorithm set in the pre-configured orchestration plugin, and the encoded result is temporarily stored in the preset cache area;

[0080] The encoding result is encrypted based on the set of encryption algorithms in the pre-configured orchestration plugin to obtain an intermediate result.

[0081] Optionally, the device further includes a plug-in configuration module.

[0082] The plugin configuration module includes:

[0083] The interface display unit is used to respond to the security orchestration request of the registration API and display at least three component functional modules through a visual configuration interactive interface. The component functional modules include a signature component functional module, an encoding component functional module, and an encryption component functional module.

[0084] The information receiving unit is used to receive the arrangement information, position information and parameter configuration information of each component functional module fed back by the visual configuration interaction interface;

[0085] The third determining unit is used to determine the processing order of each component functional module based on the arrangement information;

[0086] The fourth determining unit is used to determine the request data range and algorithm parameter information of the component functional module based on the parameter configuration information.

[0087] The fifth determining unit is used to generate the pre-configured orchestration plugin for the registration API based on the processing order, location information, the range of each request data, and the detailed algorithm parameters.

[0088] Specifically, the fourth determining unit is used for:

[0089] In response to the parameter configuration information belonging to the signature component functional module, the request data range and algorithm parameter information of the signature component functional module are determined. The algorithm parameter information includes at least one signature algorithm, signature key and signature algorithm processing order. The request data range includes at least one of request method, request address, request header and request parameters.

[0090] In response to the parameter configuration information belonging to the encoding component functional module, at least one encoding conversion algorithm and the encoding algorithm processing order of the encoding component module are determined as the algorithm parameter information;

[0091] In response to the parameter configuration information belonging to the encryption component functional module, the key corresponding to at least one encryption algorithm of the encryption component module and the encryption algorithm processing order are determined as the algorithm parameter information.

[0092] The secure orchestration device provided in the embodiments of the present invention can execute the secure orchestration method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.

[0093] Example 3

[0094] Figure 4A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0095] like Figure 4 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded from storage unit 48 into the RAM 43. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0096] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0097] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as security orchestration methods.

[0098] In some embodiments, the secure orchestration method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the secure orchestration method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the secure orchestration method by any other suitable means (e.g., by means of firmware).

[0099] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0100] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0101] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0102] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0103] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0104] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0105] In one embodiment, the present invention further includes a computer program product, which includes a computer program that, when executed by a processor, implements the secure orchestration method of any embodiment of the present invention.

[0106] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0107] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0108] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A secure orchestration method, characterized in that, Applied to gateways, including: Obtain the application programming interface (API) request and determine the target API to which the API request belongs; The API request is parsed according to the pre-configured filtering conditions of the target API to obtain the parsing result; The parsing results are securely orchestrated using the pre-configured orchestration plugin corresponding to the target API to obtain the target data. The configuration process of the pre-configured orchestration plugin includes: In response to the security orchestration request of the registration API, at least three component functional modules are displayed through a visual configuration interface, including a signature component functional module, an encoding component functional module, and an encryption component functional module; Receive the arrangement information, position information and parameter configuration information of each component's functional module from the visual configuration interaction interface; Based on the arrangement information, determine the processing order of each component's functional module; Based on the parameter configuration information, determine the request data range and algorithm parameter information of the component functional module; The pre-configured orchestration plugin for the registration API is generated based on the processing order, location information, the range of each request data, and the algorithm parameter information.

2. The method according to claim 1, characterized in that, The step of determining the request data range and algorithm parameter information of the component functional module based on the parameter configuration information includes: In response to the parameter configuration information belonging to the signature component functional module, the request data range and algorithm parameter information of the signature component functional module are determined. The algorithm parameter information includes at least one signature algorithm, signature key and signature algorithm processing order. The request data range includes at least one of request method, request address, request header and request parameters. In response to the parameter configuration information belonging to the encoding component functional module, at least one encoding conversion algorithm and the encoding algorithm processing order of the encoding component functional module are determined as the algorithm parameter information; In response to the parameter configuration information belonging to the encryption component functional module, the key corresponding to at least one encryption algorithm of the encryption component functional module and the encryption algorithm processing order are determined as the algorithm parameter information.

3. The method according to claim 1, characterized in that, The step of parsing the API request according to the pre-configured filtering conditions of the target API to obtain the parsing result includes: Analyze the request header structure in the API request according to the pre-configured filtering conditions and scan the data characteristics of the request body to determine the fields to be arranged. The field to be arranged is used as the parsing result.

4. The method according to claim 1, characterized in that, The step of performing secure orchestration processing on the parsed results according to the pre-configured orchestration plugin corresponding to the target API to obtain the target data includes: The parsing results are securely orchestrated according to the algorithm in the pre-configured orchestration plugin corresponding to the target API to obtain intermediate results; The intermediate results are replaced in the API request based on the position information in the pre-configured orchestration plugin to obtain the target data.

5. The method according to claim 4, characterized in that, The intermediate result is obtained by performing secure orchestration processing on the parsed result according to the algorithm in the pre-configured orchestration plugin corresponding to the target API, including: The parsing result is signed based on the signature algorithm set in the pre-configured orchestration plugin, and the signed result is temporarily stored in a preset cache area. The signature result is encoded based on the encoding algorithm set in the pre-configured orchestration plugin, and the encoded result is temporarily stored in the preset cache area; The encoding result is encrypted based on the set of encryption algorithms in the pre-configured orchestration plugin to obtain an intermediate result.

6. A safety scheduling device, characterized in that, include: The request acquisition module is used to acquire application programming interface (API) requests and determine the target API to which the API request belongs; The result determination module is used to parse the API request according to the pre-configured filtering conditions of the target API and obtain the parsing result; The data orchestration module is used to perform secure orchestration processing on the parsing results according to the pre-configured orchestration plugin corresponding to the target API to obtain the target data; The device further includes: a plug-in configuration module; The plugin configuration module includes: The interface display unit is used to respond to the security orchestration request of the registration API and display at least three component functional modules through a visual configuration interaction interface. The component functional modules include a signature component functional module, an encoding component functional module, and an encryption component functional module. The information receiving unit is used to receive the arrangement information, position information and parameter configuration information of each component functional module fed back by the visual configuration interaction interface; The third determining unit is used to determine the processing order of each component functional module based on the arrangement information; The fourth determining unit is used to determine the request data range and algorithm parameter information of the component functional module based on the parameter configuration information. The fifth determining unit is used to generate the pre-configured orchestration plugin for the registration API based on the processing order, location information, the range of each request data, and the algorithm parameter information.

7. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the secure orchestration method according to any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the secure orchestration method according to any one of claims 1-5.

9. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the secure orchestration method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Centralized system for a hardware security module for access to encryption keys

    US20200177383A1

  • Processing and archiving encrypted data at shared storage locations

    US20250021490A1