Solution Overview
Scenarios
During enterprise digital transformation, APIs have become the core channel for data exchange between service systems. Although APIs pose great convenience, they also expose data to risks such as unauthorized calling, excessive return of sensitive fields, and SQL injection. As a result, enterprise core data may be leaked through APIs. Typical use cases include:
- Open API data protection: When an enterprise opens APIs to partners or third parties, sensitive data (such as mobile numbers, ID card numbers, and bank card numbers) in API requests and responses must be automatically identified and masked to prevent sensitive data leakage through APIs.
- Data exchange management between internal systems: When enterprise internal systems share data via API calling, such behaviors need to be audited to identify abnormal access patterns, such as high-frequency pulling and calling by unauthorized users. In addition, sensitive fields in responses need to be dynamically masked.
- API compliance audit: Complies with laws and regulations such as Data Security Law and Personal Information Protection Law. It audits and records the transfer of sensitive data involved in APIs, and supports post-event tracing and compliance report generation.
- Data sharing security gateway: In data sharing scenarios, it functions as the security control layer on the API gateway. It performs policy verification, sensitive field masking, and access frequency control on cross-organization data requests to ensure that data is unreadable and secure but available for computing.
Solution Architecture
This topology adopts the hybrid deployment mode of bypass and serial connection. That is, the API data security protection and application server are in the same CIDR block (172.16.35.x), while the client PC is in a different CIDR block (172.16.212.x), and a switch is used for interconnection. After API requests are sent from the client PC, they are sent to the API data security protection through the switch for security check, and then forwarded to the application server for processing. The response data is returned to the client after security check.

| Component | Description | Example |
|---|---|---|
| Client PC | End user PC that initiates API access requests. | IP address: 172.16.212.65 |
| Switch | LAN switch, responsible for network interconnection between nodes. | - |
| API data security protection | Security protection component, which performs security processing such as checking, masking, and watermarking on API traffic. | IP address: 172.16.35.44 |
| Application server | Backend service application service, which processes API requests. | IP address: 172.16.35.53 |
Configuration Process
API data security protection provides comprehensive data security capabilities from asset management, rule configuration, to event processing. After you add the application system to be protected as a protected asset, you can configure multi-dimensional security policies to control API requests and responses in real time and mask sensitive data. Then, you can view alarms, audit logs, and trace data sources for post-event tracing and leakage locating. This ensures enterprise API data interaction security compliance throughout the process.
This solution provides you with an E2E API data security protection solution. The configuration procedure is as follows:
- Add an application asset: Add the application to be protected to the system.
- Configure rules: Manage API requests and responses in real time and mask sensitive data.
- Handle events.
- After the configuration, the system audits assets based on the audit policy and automatically generates audit logs and alarms.
- You can use the watermark source tracing function to trace data leakage events and locate related owners for accountability.
Resource and Cost Planning
The following table describes the resource and cost planning in this best practice.
| Resource | Description | Daily Fee |
|---|---|---|
| DSC | Professional edition:
| For details about billing, see Billing. |
| API data security protection | Yearly/Monthly billing | For details about billing, see Billing. |
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot