Updated on 2026-09-30 GMT+08:00

Solution Overview

Scenarios

During enterprise digital transformation, APIs have become the core channel for data exchange between service systems. Although APIs pose great convenience, they also expose data to risks such as unauthorized calling, excessive return of sensitive fields, and SQL injection. As a result, enterprise core data may be leaked through APIs. Typical use cases include:

  • Open API data protection: When an enterprise opens APIs to partners or third parties, sensitive data (such as mobile numbers, ID card numbers, and bank card numbers) in API requests and responses must be automatically identified and masked to prevent sensitive data leakage through APIs.
  • Data exchange management between internal systems: When enterprise internal systems share data via API calling, such behaviors need to be audited to identify abnormal access patterns, such as high-frequency pulling and calling by unauthorized users. In addition, sensitive fields in responses need to be dynamically masked.
  • API compliance audit: Complies with laws and regulations such as Data Security Law and Personal Information Protection Law. It audits and records the transfer of sensitive data involved in APIs, and supports post-event tracing and compliance report generation.
  • Data sharing security gateway: In data sharing scenarios, it functions as the security control layer on the API gateway. It performs policy verification, sensitive field masking, and access frequency control on cross-organization data requests to ensure that data is unreadable and secure but available for computing.

Solution Architecture

This topology adopts the hybrid deployment mode of bypass and serial connection. That is, the API data security protection and application server are in the same CIDR block (172.16.35.x), while the client PC is in a different CIDR block (172.16.212.x), and a switch is used for interconnection. After API requests are sent from the client PC, they are sent to the API data security protection through the switch for security check, and then forwarded to the application server for processing. The response data is returned to the client after security check.

Figure 1 Solution architecture

Table 1 Components

Component

Description

Example

Client PC

End user PC that initiates API access requests.

IP address: 172.16.212.65

Switch

LAN switch, responsible for network interconnection between nodes.

-

API data security protection

Security protection component, which performs security processing such as checking, masking, and watermarking on API traffic.

IP address: 172.16.35.44

Application server

Backend service application service, which processes API requests.

IP address: 172.16.35.53

Configuration Process

API data security protection provides comprehensive data security capabilities from asset management, rule configuration, to event processing. After you add the application system to be protected as a protected asset, you can configure multi-dimensional security policies to control API requests and responses in real time and mask sensitive data. Then, you can view alarms, audit logs, and trace data sources for post-event tracing and leakage locating. This ensures enterprise API data interaction security compliance throughout the process.

Figure 2 Usage process

This solution provides you with an E2E API data security protection solution. The configuration procedure is as follows:

  1. Add an application asset: Add the application to be protected to the system.
  2. Configure rules: Manage API requests and responses in real time and mask sensitive data.
    1. Configure an allowlist.
    2. Configure a denylist.
    3. Configure masking rules.
    4. Configure watermark rules.
  3. Handle events.
    1. After the configuration, the system audits assets based on the audit policy and automatically generates audit logs and alarms.
    2. You can use the watermark source tracing function to trace data leakage events and locate related owners for accountability.

Resource and Cost Planning

The following table describes the resource and cost planning in this best practice.

Table 2 Resource and cost planning

Resource

Description

Daily Fee

DSC

Professional edition:

  • Billing mode: Yearly/Monthly
  • Number of supported databases: 2
  • OBS volume that can be added: 100 GB
  • Number of supported API calls: 1 million

For details about billing, see Billing.

API data security protection

Yearly/Monthly billing

For details about billing, see Billing.