API Gateway Stateless Identity Token for Microservice Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely accessing microservices due to the complexity and overhead of manually creating access rules based on multiple input parameters, often leading to missed parameters and cumbersome configuration.
Innovation Solution
A method and system that utilize machine learning techniques to validate and generate decision trees based on input parameters, IP addresses, and user credentials at an API gateway, creating a stateless identity token for secure access to microservices, thereby automating the access control process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If manual creation of access rules is used, then configuration flexibility is maintained, but configuration overhead and complexity increase significantly
Solution Approach 1:
The system performs self-service by automatically generating access rules through machine learning algorithms that process historical data and user behavior patterns. The rule generation module autonomously creates access control rules without requiring manual configuration, thereby reducing configuration overhead while maintaining security effectiveness.
Solution Approach 2:
The patent replaces the mechanical manual rule creation process with an automated machine learning-based system. The machine learning module analyzes historical access data and automatically generates optimized access rules, substituting human configuration efforts with intelligent automation that reduces complexity and overhead.
2Productivity
If manual rule creation is used, then control over access policies is maintained, but time consumption and productivity decrease
Solution Approach 1:
The system performs preliminary action by pre-processing historical access data and training machine learning models in advance. The rule generation module uses this pre-trained knowledge to quickly generate access rules for new users or scenarios, eliminating the need for time-consuming manual configuration while maintaining policy control.
Solution Approach 2:
The patent substitutes manual rule creation with automated machine learning systems that process data and generate rules instantly. This replacement dramatically reduces configuration time and improves productivity, as the system can handle multiple access control scenarios simultaneously without human intervention.
3Reliability
If comprehensive access control parameters are used, then security coverage is improved, but system complexity and difficulty of detection increase
Solution Approach 1:
The patent replaces manual parameter validation with automated machine learning systems that analyze and validate access parameters automatically. The machine learning module processes multiple parameters including user attributes, resource information, and access patterns, validating their consistency and generating comprehensive access rules without increasing operational complexity.
Solution Approach 2:
The system performs self-service validation by automatically analyzing input parameters and generating appropriate access rules. The rule generation module autonomously handles parameter validation and rule creation, maintaining comprehensive security coverage while reducing the complexity of manual parameter management and system configuration.
Data Source
AI summary
Disclosed is a system for allowing secure access to a microservice. An Application Programming Interface (API) gateway receives a request comprising a Uniform Resource Locator (URL) associated to the microservice. A set of input parameters indicating information about the user device and the microservice is identified from the URL. The system performs validation of input parameters, extraction of request patterns, tracking of IP address, and detection of user credentials to provide output parameters. A decision tree comprising rules is generated by using a supervised machine learning technique on the output parameters. Further, the API gateway creates a stateless identity token to encrypt the request. The stateless identity token is created based on the user credentials and at least one rule applicable to the request. Once the stateless identity token is created, the stateless identity token is verified to allow the secure access to the microservice.


