API Throttling Profiles for Request Volume Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service provider companies face challenges in securely managing access to their data and logic through open APIs, including controlling the throttling amount and time period of requests from developer applications, while also ensuring secure and efficient billing mechanisms.

Innovation Solution

A computer-based method and system that utilizes a throttling profile stored within a memory device, including a throttling amount threshold and time period, to validate and manage the volume of request messages from developer applications accessing service applications through an open API platform, enabling both general and premium access with customizable billing options.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access to data is restricted to approved users only, then data security is improved, but the potential uses of the data are limited

Engineering Contradiction:
Improvedata securityVSAvoidpotential uses of data
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access rights into different categories (throttling levels) that can be independently configured. The system divides the access control mechanism into manageable segments where each developer application can be assigned specific throttling profiles, allowing selective data access while maintaining security. This segmentation enables the system to provide differentiated access levels without compromising overall data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the access control parameters by introducing throttling amounts and time periods as configurable parameters. Instead of a binary access restriction, the system uses adjustable parameters (throttling amount, throttling time period) to control data access. This allows the system to adapt access levels dynamically while maintaining security through controlled parameter modification rather than absolute restrictions.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If data access is provided to software developers through open API, then transaction volume and service versatility are improved, but control over the amount of access (throttling) becomes difficult

Engineering Contradiction:
Improvetransaction volumeVSAvoidcontrol over access amount
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing throttling profiles before developers actually access the data. The system pre-configures throttling parameters (throttling amount, throttling time period) for different developer applications before they make API calls. This advance setup simplifies ongoing access control by having the throttling logic already in place, eliminating the need for complex real-time control mechanisms during actual data access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer (the throttling mechanism within the API platform) between the developer applications and the underlying data storage system. This intermediary component handles the throttling control function, isolating the complexity of access management from the core data storage system. The intermediary absorbs the complexity of tracking and controlling access amounts while maintaining simple interfaces for both developers and the data layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If throttling amount and time period are increased to allow more developer access, then service versatility is improved, but data security and billing control are worsened

Engineering Contradiction:
Improvedeveloper access capabilityVSAvoiddata security and billing control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies dynamics by making the throttling parameters adjustable and adaptable rather than fixed. The system can dynamically configure throttling amounts and time periods based on the specific needs of different developer applications. This dynamic adjustment allows the system to optimize access levels for each developer while maintaining appropriate security and billing control, rather than using a one-size-fits-all approach that would compromise either accessibility or control.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8671385B2Methods and systems for throttling calls to a service application through an open API
Publication Date: 2014.03.11 MASTERCARD INT INC
  • US8671385B2 patent drawing
  • US8671385B2 patent drawing
  • US8671385B2 patent drawing

AI summary

A method and system for throttling a volume of request messages to a service application stored within a service provider (SP) computer system through an open application programming interface (API) platform is provided. The SP computer system is in communication with a memory device. The method includes storing a throttling profile for a developer application within the memory device wherein the throttling profile includes at least a throttling amount threshold and a throttling time period, receiving at the API platform a request message initiated by the developer application wherein the request message is included within a volume of request messages initiated by the developer application, identifying the request message as being associated with the developer application, retrieving the throttling profile for the developer application, and validating the volume of request messages as complying with the throttling profile.