WAAP Client API Hash Handshake for Malicious Client Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing integrated web security solutions fail to comprehensively protect web environments against API attacks, such as hacking and data breaches, due to vulnerabilities in API communication, leading to increased security incidents and operational costs.

Innovation Solution

A WAAP-based security system that integrates web application and API protection, utilizing a hash verification tool to register, store, and verify API identifiers and hashes, perform security handshakes, and manage session regeneration to ensure secure API communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrated web security solutions with API protection are introduced, then security coverage against API attacks is improved, but device complexity and implementation burden increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidimplementation burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines web application firewall (WAF) functions with API security protection into a single integrated security device. The device simultaneously handles HTTP/HTTPS traffic inspection and API request validation, merging previously separate security functions into one unified system that reduces implementation complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security device is designed to perform multiple functions including web application firewall operations, API security protection, bot mitigation, and DDoS defense within a single platform. This multi-functional approach allows organizations to deploy one universal security solution rather than multiple separate tools, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If hash verification tool is deployed for API security, then API attack detection capability is improved, but system resource consumption increases

Engineering Contradiction:
ImproveAPI attack detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-registering API specifications, endpoints, and authentication methods in the hash verification tool before actual API traffic arrives. This advance preparation creates ready-to-use verification rules that enable rapid real-time validation without requiring intensive computational resources during live traffic processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex manual API security verification processes with automated hash-based validation mechanisms. Instead of requiring intricate rule-based inspection of each API request, the system uses cryptographic hash verification to efficiently authenticate API endpoints and parameters, significantly reducing computational overhead.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive API security verification is performed, then security against data breaches is improved, but processing time for legitimate requests increases

Engineering Contradiction:
Improveprotection against data breachesVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security verification process applies different levels of inspection to different parts of API traffic. Critical authentication parameters and sensitive data fields receive rigorous hash verification, while non-critical request elements undergo lighter validation. This differentiated approach maintains strong security against data breaches while minimizing processing time for legitimate requests.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4708769A1WAAP-based security system and method for client API security
Publication Date: 2026.03.11 PENTA SECURITY SYST INC
  • EP4708769A1 patent drawingFigure 1~2
  • EP4708769A1 patent drawingFigure 3
  • EP4708769A1 patent drawingFigure 4~5

AI summary

Disclosed is a security method for client application programming interface (API) security that is performed by a security device including a service provider and a hash verification tool. The security method may comprise: registering, by the service provider, the API in the hash verification tool; storing, by the hash verification tool, the API, an identifier (ID) of the API, and a hash; and transmitting, by the hash verification tool, the ID and the hash to the service provider.