API Gateway Authentication for Secure Cross-Application Calling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing interface calling methods between application programs incur high costs due to key encryption and suffer from poor stability and security, especially when network or physical faults occur.
Innovation Solution
A cloud server provides an ecosystem service market that manages interface calls between applications, performing authentication, resource monitoring, and capacity expansion, while reducing costs and enhancing security through identity verification and ecosystem analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If key encryption is used to ensure security in interface calling between application programs, then security is improved, but interface opening costs increase
Solution Approach 1:
The patent introduces a gateway as an intermediary component that manages encryption keys and authentication. The gateway acts as a mediator between application programs, handling the complex key management and authentication processes centrally, thereby reducing the interface opening costs for individual applications while maintaining security through the intermediary's key encryption mechanisms.
2Reliability
If key encryption is used for interface calling, then security is improved, but stability deteriorates when network or physical faults occur
Solution Approach 1:
The patent implements a fault detection mechanism where the gateway monitors the status of application programs and interface calls. When network or physical faults are detected, the gateway can identify the fault source and adjust the calling process accordingly, providing feedback control that maintains system stability despite the presence of encryption overhead and potential fault conditions.
3Productivity
If application programs directly call each other through interfaces, then calling efficiency is improved, but security and stability deteriorate
Solution Approach 1:
The gateway serves as a necessary intermediary that enables efficient interface calling while maintaining security and stability. It provides centralized key management, authentication, and fault detection capabilities, allowing application programs to call interfaces efficiently without directly implementing complex security protocols, thus resolving the contradiction between calling efficiency and security/stability.
4Reliability
If a centralized ecosystem service market is introduced to manage interface calls, then security and stability are improved, but system complexity increases
Solution Approach 1:
The gateway is designed as a universal component that performs multiple functions including key management, authentication, fault detection, and interface call routing. By consolidating these diverse functions into a single multi-functional gateway, the system achieves improved security and stability without proportionally increasing overall system complexity, as the gateway handles multiple responsibilities that would otherwise require separate components.
Data Source
AI summary
A cloud server hosts an ecosystem service market, where the ecosystem service market is configured to provide a service for calling an application programming interface (API) between different applications such as a first application and a second application. The cloud server receives, through the ecosystem service market, an interface calling request sent by the first application, where the interface calling request carries an identity of the first application. The interface calling request is used to call an API of the second application, and the identity is an identifier allocated by the ecosystem service market. The cloud server performs, through the ecosystem service market, authentication on the identity that is of the first application. Upon success of the authentication, the cloud server calls the API of the second application through the ecosystem service market.


