API Compliance Auditing via Virtual Environment Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for enforcing API use compliance, especially in virtual environments, are inadequate in detecting and addressing misuse such as trademark and copyright abuses, reverse engineering, and unauthorized data usage, as they lack robust and scalable solutions for auditing API usage outside the API owner's system.

Innovation Solution

Implementing DevCom technology for automatic auditing of API usage compliance by intercepting and parsing data streams, identifying non-compliant characteristics, and generating certificates of authority, which allows for the detection and reporting of misuse within virtual environments, enabling compliance monitoring across all API usage scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual compliance management methods are used for API usage outside the API owner's system, then implementation simplicity is maintained, but detection capability and compliance enforcement effectiveness deteriorate

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a virtual environment as an intermediary system between the API owner's system and external applications. This virtual environment captures and analyzes data streams from applications using the API, enabling compliance detection without requiring direct integration into the API owner's core system. The virtual environment acts as a mediator that observes API usage patterns and identifies non-compliant behavior through data stream analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive auditing of API usage is implemented to detect all forms of misuse, then compliance detection accuracy improves, but computational resources and processing time increase

Engineering Contradiction:
Improvecompliance detection accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the necessary compliance-relevant information from data streams rather than analyzing entire data sets. The system identifies and extracts specific characteristics such as trademark usage patterns, copyright violations, and unauthorized API calls from the flowing data streams. This selective extraction approach maintains high detection accuracy while significantly reducing computational overhead compared to comprehensive analysis of all data.

Inventive Principle:
Principle #2Taking out (Extraction)

3Speed

If real-time monitoring and analysis of data streams is performed to identify non-compliant behavior, then response time to compliance violations improves, but system processing load increases

Engineering Contradiction:
Improveresponse timeVSAvoidprocessing load
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the virtual environment with compliance rules, detection algorithms, and analysis frameworks before monitoring begins. The system prepares detection mechanisms in advance, so when data streams flow through the virtual environment, compliance violations can be identified immediately without requiring complex real-time computation. The heavy lifting of rule configuration and algorithm preparation is done beforehand, reducing real-time processing demands.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10324826B2Developer channel compliance
Publication Date: 2019.06.18 FOCUS IP INC
  • US10324826B2 patent drawing
  • US10324826B2 patent drawing
  • US10324826B2 patent drawing

AI summary

Novel tools and techniques might provide for implementing application programming interface (“API”) use compliance, and, in some cases, by implementing application auditing for API use compliance within virtual environments in which target APIs are executed. In some embodiments, a method might comprise identifying misuse of an application programming interface (“API”) that is used in a developer channel, by intercepting data streams between the API and one or more computing systems, parsing the intercepted data streams, and determining whether the API is use non-compliant, based at least in part on identifying use non-compliant characteristics in the parsed data streams.