Unified API Proxy for Multi-User Authentication and Endpoint Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing API management platforms require separate API proxies for each user with different client certifications, authentication, and authorization, leading to increased development, maintenance, and testing times, as well as higher infrastructure and computation resource needs.
Innovation Solution
A unified API proxy is defined to support multiple users with different client certifications, registered endpoints, and authentication tokens, allowing for granular control over security, rate limiting, and analytics, while maintaining a consistent interface to the backend service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate API proxies are created for each user with different client certifications and authentication, then security and authorization control are improved, but device complexity and development time increase
Solution Approach 1:
The patent implements a unified API proxy that serves multiple users with different client certifications and authentication methods through a single multi-functional proxy instance. The proxy evaluates requests against multiple endpoint definitions and user credentials, providing security and authorization control without requiring separate proxy instances for each user, thereby reducing device complexity while maintaining reliability
2Reliability
If separate API proxies are created for each user, then user-specific security control is improved, but development time and maintenance effort increase
Solution Approach 1:
The patent merges multiple user-specific security controls into a single unified API proxy that handles multiple users simultaneously. The proxy maintains separate endpoint definitions and authentication credentials for each user but processes all requests through one unified instance, eliminating the need to develop, deploy, and maintain separate proxy instances for each user, thereby reducing development and maintenance time while preserving user-specific security control
3Adaptability or versatility
If separate API proxies are used for multiple users, then authentication and authorization granularity is improved, but infrastructure resources increase
Solution Approach 1:
The unified API proxy implements multi-functionality by supporting multiple users with different authentication methods (client certificates, API keys, OAuth tokens) and authorization rules within a single proxy instance. This eliminates the need to provision separate infrastructure resources for each user while maintaining fine-grained authentication and authorization control through its multi-functional design
4Adaptability or versatility
If multiple separate API proxies are deployed, then user-specific endpoint control is improved, but system performance degrades
Solution Approach 1:
The patent combines multiple user-specific endpoint controls into a single unified API proxy that efficiently manages requests from multiple users. By consolidating endpoint evaluation and request routing logic into one proxy instance rather than distributing across multiple separate proxies, the system maintains flexible user-specific endpoint control while improving overall system performance through reduced infrastructure overhead and more efficient resource utilization
Data Source
AI summary
In some implementations, an application programming interface (API) management platform may receive, from a user equipment (UE), a request to a unified application programming interface (API) proxy that supports multiple users with different certifications, different sets of registered endpoints, different API keys, and different authentication tokens, wherein the request is associated with a user of the multiple users. The API management platform may perform an evaluation of the request based on a comparison of information indicated in the request and information associated with the user, wherein the request is accepted based on a validation of the request or the request is blocked based on an invalidation of the request.


