BIG API Security Gateway

Unified API access, authentication, rate limiting and protection — securing service-to-service traffic and data while reducing the exposure surface of digital business.

OVERVIEW

Product Overview

BIG API Security Gateway is a unified control platform deployed at the chokepoint of north-south traffic. With the spread of microservice architectures and open ecosystems, APIs have become the front line of digital business exposure. This product performs unified access, authentication, rate limiting and threat protection right on the path every API call must take, making each call trusted, controlled and auditable.

The product supports multiple authentication modes including OAuth / JWT / API Key together with fine-grained authorization, and builds in rate limiting, circuit breaking and API threat detection. It defends against API-layer attacks such as injection, privilege escalation and parameter abuse while automatically masking sensitive data. Full call logs flow into the situational awareness platform, with anomalous calls immediately triggering blocking and alerts — helping customers balance secure API openness with business growth.

CORE FEATURES

Core Features

Four capability modules covering security control across the full API lifecycle

01

Unified Access & Routing

Centralized management of API entry points and routing, with unified client intake and intelligent routing to standardize service calls.

02

Authentication & Authorization

Multiple authentication modes including OAuth / JWT / API Key, integrating identity verification, token issuance and fine-grained authorization.

03

Rate Limiting & Circuit Breaking

Traffic governance and circuit-breaking degradation mechanisms that withstand API abuse and traffic spikes to keep services stable.

04

API Threat Protection

Defends against API-layer attacks such as injection, privilege escalation and parameter abuse, automatically masking sensitive data and preventing scraping to protect data assets.

GATEWAY ARCHITECTURE

Product Architecture

A four-stage processing chain that makes every API call trusted, controlled and auditable

1

Access & Routing

Unified intake and intelligent routing of client requests

2

Authentication & Authorization

Identity verification, token issuance and fine-grained authorization

3

Rate Limiting & Protection

Rate limiting, circuit breaking and API threat detection with blocking

4

Audit & Observability

Full logs, metrics and distributed tracing

Closed-loop linkage: full API call logs flow into situational awareness, with anomalous calls immediately triggering blocking and alerts.
SCENARIOS & VALUE

Scenarios & Value

Microservice North-South Protection

Unified control of internal and external call entry points
  • Unified entry point and call standards
  • Effectively reduced attack surface
  • Fully auditable call logs

Open Platform / Ecosystem Onboarding

Securely opening APIs to partners
  • Secure partner onboarding
  • End-to-end call auditability
  • Tiered authorization for partners

Sensitive Endpoint Protection

Protecting sensitive endpoints from abuse
  • Privilege escalation and abuse blocked
  • Automatic masking of sensitive data
  • Masking and anti-scraping protect data assets
Reduced Exposure
Unified entry points for digital business
Effective Protection
Abuse and escalation blocked
Masking & Compliance
Sensitive data kept safe
End-to-End Audit
Full control over every call