Hybrid Cloud API Management via Local Proxy Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing API management systems face challenges in securing data transmissions and complying with security and compliance regulations, such as HIPAA and Gramm-Leach-Bliley Act, while also being resource-intensive and requiring local computing resources.
Innovation Solution
A hybrid cloud API management system is implemented, where a local API proxy is deployed in close proximity to backend data/services, cooperating with a remote API management server to manage APIs, reducing the need for local infrastructure and enhancing security and compliance by offloading processing and storage to the remote server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If API management service is implemented locally, then security and compliance control is improved, but resource consumption and infrastructure cost increase
Solution Approach 1:
The patent segments API management functionality into two parts: a lightweight local API proxy that handles security and compliance control, and a remote cloud-based API management service that handles resource-intensive operations. This segmentation allows security control to remain local while reducing local resource consumption by offloading other functions to the cloud.
Solution Approach 2:
The local API proxy acts as an intermediary between client applications and backend services. It enforces security and compliance policies locally while forwarding other management functions to the remote API management service, thus maintaining security control without requiring full local infrastructure.
2Device complexity
If third party provides API management service, then local infrastructure cost is reduced, but security and compliance control is compromised
Solution Approach 1:
The patent applies local quality by placing specific security and compliance control functions locally at the API proxy, while other API management functions remain remote. This ensures that sensitive security operations occur within the organization's controlled environment while still benefiting from cloud-based service management.
3Reliability
If local API proxy is deployed, then security control is improved, but network latency increases
Solution Approach 1:
The patent extracts resource-intensive API management functions from the local environment and places them in the cloud. The local API proxy retains only the essential security control functions, minimizing local processing and reducing network round-trips for non-critical operations.
4Adaptability or versatility
If full API management service is deployed locally, then complete control is achieved, but infrastructure cost and complexity increase
Solution Approach 1:
The remote API management service provides universal, multi-functional API management capabilities in the cloud. The local API proxy focuses on specific security and compliance functions, creating a division of labor that achieves comprehensive control without requiring the organization to maintain complex full-featured local infrastructure.
Data Source
AI summary
A method of serving an API request includes receiving the API request at a local API proxy deployed at a local deployment environment. The method includes utilizing the local API proxy to service the API request at the local deployment environment, establishing a connection with a remote API management server, and providing to the remote API management server, via the connection, at least metadata about the API request.


