YD/T 4678-2024 in English
VALIDTechnical requirements for access application of enterprise-level SaaS platform based on open instant messaging basic service capabilities
- Issued on:2024-03-29
- Implemented on:2024-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$262.00
| Standard No: | YD/T 4678-2024 |
| Document status: | VALID |
| Title in English: | Technical requirements for access application of enterprise-level SaaS platform based on open instant messaging basic service capabilities |
| Title in Chinese: | 基于即时通信基础服务能力开放的企业级SaaS平台接入应用技术要求 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2024-03-29 |
| Implemented on: | 2024-07-01 |
| ICS Classification: | 35.100.30-Network layer |
| Chinese Classification: | L79-Opening and system interconnection of computer |
| Professional Classification: | YD-Telecommunication |
Introduction
Analysis of the core framework of technical standards
| Dimensions | Traditional enterprise applications | Requirements of this standard |
|---|---|---|
| Integration method | Customized private protocol | Standardized open API |
| Identity authentication | Independent account system | Uniform login-free mechanism |
| Security control | Single point protection | Five-layer defense system |
In-depth analysis of system architecture
In the three-tier entity architecture defined by the standard, the enterprise-level SAAS platform serves as the capability hub, which is implemented through 6 types of core interfaces:
- The server-to-server capability call interface (Class II) supports 200+ enterprise-level APIs
- The client interaction interface (Class III) includes 15 standard call specifications for front-end components
- The data channel between the server and the client (Class I) requires end-to-end encryption
Key interface technical specifications
Log-free interface implementation solution
The Ticket+Nonce+Timestamp triple verification mechanism is adopted, and the token validity period is strictly limited to 2 hours, involving:
- Enterprise identity verification (corpId binding)
- Dynamic signature calculation (SHA-256 algorithm)
- Temporary authorization code generation (one-time use)
Key points for security protection implementation
| Security level | Technical requirements | Implementation case |
|---|---|---|
| Data security | National secret SM4 encrypted transmission | AES-256 storage of address book fields |
| Host security | Webshell detection rate ≥ 99.9% | Alibaba Cloud Knight Protection Solution |
Analysis of standard evolution trend
Compared with the 2018 trial version, this draft for approval adds:
- Smart office interface group (attendance/sign-in management)
- Data embedding specification (user behavior tracking)
- Service window access mode (B2B2C scenario)
Implementation case of a financial group
Through standardized interface transformation, its CRM system integration cycle was shortened from 3 months to 2 weeks, and the single sign-on success rate was increased to 99.97%

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

YD/T 4713-2024 in English
Industrial Internet Security Testing and Assessment Environment Reference Architecture
2024-03-29