首页|微服务架构下API网关属性授权策略研究

微服务架构下API网关属性授权策略研究

扫码查看
随着微服务架构的普及,API网关作为连接前端与后端服务的关键中间层,承担着访问控制、身份验证等多项安全职责。为了解决在网关层面对响应数据进行细粒度访问控制的问题,设计一种支持属性授权的API网关架构,并提出一种基于流式解析的属性授权控制策略。在网关启动阶段构建基于抽象语法树的路径匹配器,在运行阶段渐进式解析请求响应。实验证明,该方法相比现有方式未明显提升CPU负载,在内存占用和响应时间方面均有明显优势。
Research on API Gateway Attribute Authorization Strategy under Microservice Architecture
With the popularization of microservice architecture,API gateway serves as a key intermediate layer connecting front-end and back-end services,undertaking multiple security responsibilities such as access control and identity verification.To address the issue of fine-grained access control for response data at the gateway layer,an API gateway architecture that supports attribute authorization is designed,and an attribute authorization control strategy based on streaming parsing is proposed.It builds a path matcher based on an abstract syntax tree during the gateway startup phase,and gradually parses request responses during the runtime phase.Experimental results show that this method does not significantly improve CPU load compared to existing methods,and has significant advantages in memory usage and response time.

API Gatewaydata protectionattribute authorizationstreaming parsing

张礼庆

展开 >

上海市经济信息中心,上海 200050

API网关 数据保护 属性授权 流式解析

2024

现代信息科技
广东省电子学会

现代信息科技

ISSN:2096-4706
年,卷(期):2024.8(11)
  • 12