SlideShare a Scribd company logo
1 of 26
API Management for Enterprise Mobile Access
A Layer 7 Technologies Solution
 Matt McLarty, VP, Client Solutions, Layer 7 Technologies
Housekeeping
 Questions
 - Chat any questions you have and we’ll answer them at the end of this call

 Twitter                                                     facebook.com/layer7

 - Today’s event hashtag:
                                                              layer7.com/linkedin
   - #L7webinar
                                                              layer7.com/blogs
 - Follow us on Twitter as well:
   - @layer7
Agenda

                 • BYOD and the App Explosion
 “Bring Your     • Innovation through Consumerization
Own Device”



                 • Enterprise Mobility and the Mobile App Paradigm
  Enterprise
   Mobile        • Leveraging Enterprise Services and Assets
 Integration



                 • API Publication, Security and Monetization
Enterprise API   • Solutions and Case Studies from Layer 7 Technologies
Management
BYOD: Bring Your Own Device




                              Courtesy of Click Software
BYOD: iPad @ Work – from IDG Connect “iPad for Business Survey 2012”
The App Explosion




Courtesy of zendesk   Courtesy of [x]cube Labs
Pillars of an Enterprise Mobility Strategy*
                                               “By exposing
Business Drivers                               access … through
Hardware Ownership & Support                   a standardized
                                               mobile-friendly
Deployment, Provisioning & Management          enterprise
Enterprise Services Platform
                                               services layer,
                                               the cost of
Application Portfolio & Roadmap                innovation can
                                               be dramatically
Corporate Governance & Processes
                                               reduced.”
Security Standards & Audit Processes
                                                   * From “iPad in the
                                                        Enterprise”, N.
                                                Clevenger, Wiley 2011
Mobile App-to-Enterprise Service Integration
     • Existing enterprise                             • Re-use of API and
       services can create                               shared services
       and increase                                      infrastructure
       revenue

                             Increase       Cost
                             Revenue      Reduction




                             Quality of
                                          Compliance
                              Service


     • Leverages proven                                • Uses existing
       systems with                                      security policies
       enterprise SLA’s                                  and technologies
Mobile App-to-Enterprise Service Integration Challenges

   Mobile Devices
                                                         Enterprise Services
                                                                                   Data Services
                                    Network




 Proliferation of mobile        Composite services              Service API’s
                                                                                            Data privacy and
   devices increases              need API’s from         unavailable in mobile-
                                                                                            integrity must be
   message volumes               multiple providers,        friendly formats &
                                                                                          preserved end-to-end
      exponentially             requiring federation      protocols (REST, JSON)


        BYOD approach mixes           API’s must be reusable         How to access
        personal and business         across multiple mobile      business intelligence
          use, blurring the              and non-mobile           and Big Data in real-
         security perimeter                  platforms                    time
Enterprise Service Platform Evolution
 Web Apps and Web Services (2001-2010)




         Thin & Thick
            Client
                             Web Proxy          App Server      DB Server



 Mobile Apps and API’s (2011 and beyond)

          Mobile                                                                On-
          Apps                                                                 Prem


                                                                               Cloud
                        Mobile Access Gateway   API Server     Data Services
                                                             (Hadoop, RDBMS)
The Mobile Access Gateway

       Mobile Devices
                                                             Enterprise Services
                                                                               Real-time bridging from
                                                                                         SOAP, XML and legacy
s                                                                                      Data Services JSON
                                                                                         formats to REST,
                                      Network                                               mobile protocols
                               Optimized high scale
                               engine for compute-                                       Single logical gateway
                               intensive integration                                     cluster configurable to
                                    functions                                           handle mobile, web and
                                                                                               B2B traffic
     Proliferation of mobile       Composite services
                               App- and API-specific                Service API’s
                                                                                                Data privacy and
                                                                                           Existing enterprise
       devices increases             need API’s from
                                security handling—            unavailable in mobile-
       message volumes              multiple providers,         friendly formats &         access control andbe
                                                                                               integrity must
                                 including Oauth—                                           preserved end-to-end
                                                                                        crypto extended to App-
          exponentially            requiring federation
                               adapts the perimeter           protocols (REST, JSON)
                                                                                          API through Gateway

            BYOD approach mixesFederated security for reusable
                                         API’s must be                   How to accessEvent-aware integration
                                3rd party API’s, multiple mobile
            personal and business        across data                                    capability for real-time
                                                                      business intelligence
              use, blurring the aggregation for
                                            and non-mobile                               analytic data synthesis
                                                                      and Big Data in real-
                              composite API mashups
             security perimeter                 platforms                     time          and integration
The Mobile Access Gateway

   Mobile Devices
   Mobile Access                                     Enterprise Services
                                                         Service API’s Real-time bridging from
                                                     unavailable in mobile- SOAP, XML and legacy
    Gateway                                            friendly formats & Data Services JSON
                                                                            formats to REST,
                                                     protocols (REST, JSON)    mobile protocols
 Proliferation of mobile    Optimized high scale
   devices increases        engine for compute-      API’s must be reusable    Single logical gateway
   message volumes          intensive integration    across multiple mobile    cluster configurable to
      exponentially              functions              and non-mobile        handle mobile, web and
                                                            platforms                B2B traffic

 BYOD approach mixes        App- and API-specific                                Existing enterprise
 personal and business       security handling—        Data privacy and          access control and
   use, blurring the          including Oauth—         integrity must be      crypto extended to App-
  security perimeter        adapts the perimeter     preserved end-to-end       API through Gateway

  Composite services        Federated security for       How to access        Event-aware integration
    need API’s from          3rd party API’s, data    business intelligence    capability for real-time
   multiple providers,         aggregation for        and Big Data in real-    analytic data synthesis
  requiring federation     composite API mashups              time                and integration
Mobile App-to-Enterprise Integration Stakeholders

   App                                    Who is allowed to             API
 Developer                                use my API’s? Are            Owner
                       What API’s are     they being used?
                     available and how
                      can I use them?




        Mobile                                                                     On-
        Apps                                                                      Prem


                                                                                  Cloud
                 Mobile Access Gateway       API Server          Data Services
                                                               (Hadoop, RDBMS)



    IT                                                                   Info
                                           How is our data             Security
 Operator                                being protected and
                     What is changing?    access controlled?
                        Is everything
                     running smoothly?
Layer 7 API Management Suite
 API Proxy
 - Enterprise-grade Mobile Access Gateway

 API Portal
 - Developer on-boarding, support and resources
 - API metrics and reporting

 Enterprise Service Manager (ESM)
 - API migration, management and dashboarding

 Secure OAuth Toolkit
 - Support for 2 and 3-legged OAuth
API Management – How it All Works
                        Enterprise APIs



  1. Publish & Secure APIs                            2. Onboard Developers

                                                                                    Developer



   Security Architect


                   4. Close the Loop




                                                    3. Monetize your APIs


                                                                              IT Operator



                                          Business Manager/
                                             API Owner
Mobile Access Gateway – API Proxy
       Enterprise APIs



                              Feature/Function                          API Proxy
                              Credentialing                                 Y
                              Custom Assertion SDK                          Y
                              JDBC support                                  Y
                              SAML support                                 Full
                              Convert SOAP<->REST                           Y
                              WS* support                                   Y
                              XACML support                                 Y
   1. Publish & Secure APIs   MTOM support                                  Y
                              Transports supported           JMS, MQ, FTP(s), HTTP(s), raw TCP

                              Concurrent Assertion support                  Y
                              OAuth support                       1.0 and 2.0, HMAC, RSA
                              Rate Limiting                                 Y
                              Multiple Form Factors           Hardware, Software, VMware, AMI
Mobile Access Gateway – OAuth
• Plug in your ID providers, IAM, CA Siteminder,
  OAM, …
• Plug in any developer portal, api key
  management system
                                                   Layer 7 implements OAuth
     Layer 7 implements OAuth                      Resource Server for your REST
     Authorization Server                          services, APIs



Client application
     (REST client)                                              API Dev Portal or Client API Key store
                             1. Handshake
                             2. Service call



                              Handshake only
                              (optional)
     Resource owner
         (subscriber)                                            ID Provider
                                                                 For resource owner authentication
API Portal – Onboard and Manage Developers
      Enterprise APIs



                                    2. Onboard Developers




                         Feature/Function          API Portal
                         Developer Registration        Y
                         API Key Management            Y
                         API Explorer                  Y
                         API Rate Limiting             Y
                         API Reporting                 Y
                         Developer Support             Y
                         Fully-branded CMS             Y
                         Account Management            Y
ESM – API Migration and Lifecycle Management
 Automated dependency resolution when migrating policies between environments


                                                                       cloud01LDAP
                                               prod01LDAP



              Development      Test (Enterprise)            Production (Cloud)
  dev01LDAP




                                                              3. Monetize your API’s
Example Scenario – Web Application Security




     Thin & Thick
        Client
                    Web Proxy      App Server            DB Server




                                  Policy Server          Directory
                                (e.g. SiteMinder)        (e.g. AD)




                                                    Monitoring & Logging
Example Scenario – Web Services Security




     Thin & Thick
        Client
                          Web Proxy              App Server            DB Server

        B2B
       Clients

                                                Policy Server          Directory
                                              (e.g. SiteMinder)        (e.g. AD)




                     Mobile Access Gateway
                    (L7 SecureSpan Gateway)
                                                 L7 Enterprise
                                               Service Manager    Monitoring & Logging
Example Scenario – API Management




     Thin & Thick
        Client
                          Web Proxy              App Server            DB Server

        B2B              L7 API Portal
       Clients

                                                Policy Server          Directory
                                              (e.g. SiteMinder)        (e.g. AD)
      Mobile
      Apps


                     Mobile Access Gateway
                    (L7 SecureSpan Gateway)
                                                 L7 Enterprise
                                               Service Manager    Monitoring & Logging
Case Study: API-Enabling Health Care
 Challenge: Reduce cost and delay in processing Medicaid member information by bringing
  the process online
 Solution: Mobile Access Gateway allows iPad application to securely connect to existing
  backend APIs; data routing, strict authN & authZ, comprehensive threat protection




 Results: Improved the provider’s health care coverage and member services, while
  increasing the effectiveness and efficiency of its Medicaid program
Case Study: Mobile-Enable Airline Services
 Challenge: Securely expose existing services to third party developers in order to expand
  their market reach
 Solution: The Layer 7 API Proxy allows the airline to securely expose and manage their APIs,
  while caching Sabre requests




 Results: Significantly grew market reach, while controlling costs associated with constantly
  pulling data from Sabre to service Developer requests
Case Study: Smart Grid Gateway
 Challenge: Migrate energy services to Smart Grid technology, leveraging the new capabilities
  offered by additional data and communication
 Solution: SOA, Web and API Security Gateway enables high volume meter data collection,
  assisted service and upcoming mobile self-service for enhanced client experience




 Results: Cost avoidance for higher volume meter traffic, improved customer service through
  real-time channels, improved service availability through proactive system monitoring
Conclusions

            Employees are         …and IT groups must
           bringing mobile        accommodate them
          devices to work en     without compromising
               masse…              security and SLA’s



            Mobile Apps are      …existing enterprise
             being built to     services can be used to
         improve productivity     quickly and reliably
           and reduce cost…       enable these apps


             Enterprise API
             Management           …through a Secure
                                Mobile Access Gateway,
           integrates Mobile    an API Portal, and open
          Apps and Enterprise          standards
               Services…

More Related Content

Viewers also liked

User Experience (UX) Design Process
User Experience (UX) Design ProcessUser Experience (UX) Design Process
User Experience (UX) Design ProcessJonathan Lupo
 
Managing Sensitive Information in an API and Microservices World
Managing Sensitive Information in an API and Microservices WorldManaging Sensitive Information in an API and Microservices World
Managing Sensitive Information in an API and Microservices WorldApigee | Google Cloud
 
A Lean Design Process for Creating Awesome UX
A Lean Design Process for Creating Awesome UXA Lean Design Process for Creating Awesome UX
A Lean Design Process for Creating Awesome UXAnnie Wang
 
10 Insightful Quotes On Designing A Better Customer Experience
10 Insightful Quotes On Designing A Better Customer Experience10 Insightful Quotes On Designing A Better Customer Experience
10 Insightful Quotes On Designing A Better Customer ExperienceYuan Wang
 
Design Thinking: The one thing that will transform the way you think
Design Thinking: The one thing that will transform the way you thinkDesign Thinking: The one thing that will transform the way you think
Design Thinking: The one thing that will transform the way you thinkDigital Surgeons
 
Lifecycle Manager and the Lifecycle API
Lifecycle Manager and the Lifecycle APILifecycle Manager and the Lifecycle API
Lifecycle Manager and the Lifecycle APIAkana
 
IDEO's design thinking.
IDEO's design thinking. IDEO's design thinking.
IDEO's design thinking. BeeCanvas
 

Viewers also liked (10)

API Governance in the Enterprise
API Governance in the EnterpriseAPI Governance in the Enterprise
API Governance in the Enterprise
 
User Experience (UX) Design Process
User Experience (UX) Design ProcessUser Experience (UX) Design Process
User Experience (UX) Design Process
 
Managing Sensitive Information in an API and Microservices World
Managing Sensitive Information in an API and Microservices WorldManaging Sensitive Information in an API and Microservices World
Managing Sensitive Information in an API and Microservices World
 
A Lean Design Process for Creating Awesome UX
A Lean Design Process for Creating Awesome UXA Lean Design Process for Creating Awesome UX
A Lean Design Process for Creating Awesome UX
 
RESTful API Design, Second Edition
RESTful API Design, Second EditionRESTful API Design, Second Edition
RESTful API Design, Second Edition
 
10 Insightful Quotes On Designing A Better Customer Experience
10 Insightful Quotes On Designing A Better Customer Experience10 Insightful Quotes On Designing A Better Customer Experience
10 Insightful Quotes On Designing A Better Customer Experience
 
Design Thinking: The one thing that will transform the way you think
Design Thinking: The one thing that will transform the way you thinkDesign Thinking: The one thing that will transform the way you think
Design Thinking: The one thing that will transform the way you think
 
Kickstarting Design Thinking
Kickstarting Design ThinkingKickstarting Design Thinking
Kickstarting Design Thinking
 
Lifecycle Manager and the Lifecycle API
Lifecycle Manager and the Lifecycle APILifecycle Manager and the Lifecycle API
Lifecycle Manager and the Lifecycle API
 
IDEO's design thinking.
IDEO's design thinking. IDEO's design thinking.
IDEO's design thinking.
 

More from CA API Management

Api architectures for the modern enterprise
Api architectures for the modern enterpriseApi architectures for the modern enterprise
Api architectures for the modern enterpriseCA API Management
 
Mastering Digital Channels with APIs
Mastering Digital Channels with APIsMastering Digital Channels with APIs
Mastering Digital Channels with APIsCA API Management
 
Takeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarTakeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarCA API Management
 
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...CA API Management
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...CA API Management
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...CA API Management
 
API Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataAPI Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataCA API Management
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...CA API Management
 
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...CA API Management
 
Enabling the Multi-Device Universe
Enabling the Multi-Device UniverseEnabling the Multi-Device Universe
Enabling the Multi-Device UniverseCA API Management
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...CA API Management
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...CA API Management
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...CA API Management
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinAdapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinCA API Management
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...CA API Management
 
5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer appsCA API Management
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...CA API Management
 
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...CA API Management
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...CA API Management
 
Using APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceUsing APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceCA API Management
 

More from CA API Management (20)

Api architectures for the modern enterprise
Api architectures for the modern enterpriseApi architectures for the modern enterprise
Api architectures for the modern enterprise
 
Mastering Digital Channels with APIs
Mastering Digital Channels with APIsMastering Digital Channels with APIs
Mastering Digital Channels with APIs
 
Takeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarTakeaways from API Security Breaches Webinar
Takeaways from API Security Breaches Webinar
 
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
 
API Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataAPI Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your Data
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
 
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
 
Enabling the Multi-Device Universe
Enabling the Multi-Device UniverseEnabling the Multi-Device Universe
Enabling the Multi-Device Universe
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinAdapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & Win
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
 
5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer apps
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
 
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
 
Using APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceUsing APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail Experience
 

Recently uploaded

AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 

Recently uploaded (20)

AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 

API Management for Enterprise Mobile Access a How-to guide

  • 1. API Management for Enterprise Mobile Access A Layer 7 Technologies Solution  Matt McLarty, VP, Client Solutions, Layer 7 Technologies
  • 2. Housekeeping  Questions - Chat any questions you have and we’ll answer them at the end of this call  Twitter facebook.com/layer7 - Today’s event hashtag: layer7.com/linkedin - #L7webinar layer7.com/blogs - Follow us on Twitter as well: - @layer7
  • 3. Agenda • BYOD and the App Explosion “Bring Your • Innovation through Consumerization Own Device” • Enterprise Mobility and the Mobile App Paradigm Enterprise Mobile • Leveraging Enterprise Services and Assets Integration • API Publication, Security and Monetization Enterprise API • Solutions and Case Studies from Layer 7 Technologies Management
  • 4. BYOD: Bring Your Own Device Courtesy of Click Software
  • 5. BYOD: iPad @ Work – from IDG Connect “iPad for Business Survey 2012”
  • 6. The App Explosion Courtesy of zendesk Courtesy of [x]cube Labs
  • 7. Pillars of an Enterprise Mobility Strategy*  “By exposing Business Drivers access … through Hardware Ownership & Support a standardized mobile-friendly Deployment, Provisioning & Management enterprise Enterprise Services Platform services layer, the cost of Application Portfolio & Roadmap innovation can be dramatically Corporate Governance & Processes reduced.” Security Standards & Audit Processes * From “iPad in the Enterprise”, N. Clevenger, Wiley 2011
  • 8. Mobile App-to-Enterprise Service Integration • Existing enterprise • Re-use of API and services can create shared services and increase infrastructure revenue Increase Cost Revenue Reduction Quality of Compliance Service • Leverages proven • Uses existing systems with security policies enterprise SLA’s and technologies
  • 9. Mobile App-to-Enterprise Service Integration Challenges Mobile Devices Enterprise Services Data Services Network Proliferation of mobile Composite services Service API’s Data privacy and devices increases need API’s from unavailable in mobile- integrity must be message volumes multiple providers, friendly formats & preserved end-to-end exponentially requiring federation protocols (REST, JSON) BYOD approach mixes API’s must be reusable How to access personal and business across multiple mobile business intelligence use, blurring the and non-mobile and Big Data in real- security perimeter platforms time
  • 10. Enterprise Service Platform Evolution  Web Apps and Web Services (2001-2010) Thin & Thick Client Web Proxy App Server DB Server  Mobile Apps and API’s (2011 and beyond) Mobile On- Apps Prem Cloud Mobile Access Gateway API Server Data Services (Hadoop, RDBMS)
  • 11. The Mobile Access Gateway Mobile Devices Enterprise Services Real-time bridging from SOAP, XML and legacy s Data Services JSON formats to REST, Network mobile protocols Optimized high scale engine for compute- Single logical gateway intensive integration cluster configurable to functions handle mobile, web and B2B traffic Proliferation of mobile Composite services App- and API-specific Service API’s Data privacy and Existing enterprise devices increases need API’s from security handling— unavailable in mobile- message volumes multiple providers, friendly formats & access control andbe integrity must including Oauth— preserved end-to-end crypto extended to App- exponentially requiring federation adapts the perimeter protocols (REST, JSON) API through Gateway BYOD approach mixesFederated security for reusable API’s must be How to accessEvent-aware integration 3rd party API’s, multiple mobile personal and business across data capability for real-time business intelligence use, blurring the aggregation for and non-mobile analytic data synthesis and Big Data in real- composite API mashups security perimeter platforms time and integration
  • 12. The Mobile Access Gateway Mobile Devices Mobile Access Enterprise Services Service API’s Real-time bridging from unavailable in mobile- SOAP, XML and legacy Gateway friendly formats & Data Services JSON formats to REST, protocols (REST, JSON) mobile protocols Proliferation of mobile Optimized high scale devices increases engine for compute- API’s must be reusable Single logical gateway message volumes intensive integration across multiple mobile cluster configurable to exponentially functions and non-mobile handle mobile, web and platforms B2B traffic BYOD approach mixes App- and API-specific Existing enterprise personal and business security handling— Data privacy and access control and use, blurring the including Oauth— integrity must be crypto extended to App- security perimeter adapts the perimeter preserved end-to-end API through Gateway Composite services Federated security for How to access Event-aware integration need API’s from 3rd party API’s, data business intelligence capability for real-time multiple providers, aggregation for and Big Data in real- analytic data synthesis requiring federation composite API mashups time and integration
  • 13. Mobile App-to-Enterprise Integration Stakeholders App Who is allowed to API Developer use my API’s? Are Owner What API’s are they being used? available and how can I use them? Mobile On- Apps Prem Cloud Mobile Access Gateway API Server Data Services (Hadoop, RDBMS) IT Info How is our data Security Operator being protected and What is changing? access controlled? Is everything running smoothly?
  • 14. Layer 7 API Management Suite  API Proxy - Enterprise-grade Mobile Access Gateway  API Portal - Developer on-boarding, support and resources - API metrics and reporting  Enterprise Service Manager (ESM) - API migration, management and dashboarding  Secure OAuth Toolkit - Support for 2 and 3-legged OAuth
  • 15. API Management – How it All Works Enterprise APIs 1. Publish & Secure APIs 2. Onboard Developers Developer Security Architect 4. Close the Loop 3. Monetize your APIs IT Operator Business Manager/ API Owner
  • 16. Mobile Access Gateway – API Proxy Enterprise APIs Feature/Function API Proxy Credentialing Y Custom Assertion SDK Y JDBC support Y SAML support Full Convert SOAP<->REST Y WS* support Y XACML support Y 1. Publish & Secure APIs MTOM support Y Transports supported JMS, MQ, FTP(s), HTTP(s), raw TCP Concurrent Assertion support Y OAuth support 1.0 and 2.0, HMAC, RSA Rate Limiting Y Multiple Form Factors Hardware, Software, VMware, AMI
  • 17. Mobile Access Gateway – OAuth • Plug in your ID providers, IAM, CA Siteminder, OAM, … • Plug in any developer portal, api key management system Layer 7 implements OAuth Layer 7 implements OAuth Resource Server for your REST Authorization Server services, APIs Client application (REST client) API Dev Portal or Client API Key store 1. Handshake 2. Service call Handshake only (optional) Resource owner (subscriber) ID Provider For resource owner authentication
  • 18. API Portal – Onboard and Manage Developers Enterprise APIs 2. Onboard Developers Feature/Function API Portal Developer Registration Y API Key Management Y API Explorer Y API Rate Limiting Y API Reporting Y Developer Support Y Fully-branded CMS Y Account Management Y
  • 19. ESM – API Migration and Lifecycle Management  Automated dependency resolution when migrating policies between environments cloud01LDAP prod01LDAP Development Test (Enterprise) Production (Cloud) dev01LDAP 3. Monetize your API’s
  • 20. Example Scenario – Web Application Security Thin & Thick Client Web Proxy App Server DB Server Policy Server Directory (e.g. SiteMinder) (e.g. AD) Monitoring & Logging
  • 21. Example Scenario – Web Services Security Thin & Thick Client Web Proxy App Server DB Server B2B Clients Policy Server Directory (e.g. SiteMinder) (e.g. AD) Mobile Access Gateway (L7 SecureSpan Gateway) L7 Enterprise Service Manager Monitoring & Logging
  • 22. Example Scenario – API Management Thin & Thick Client Web Proxy App Server DB Server B2B L7 API Portal Clients Policy Server Directory (e.g. SiteMinder) (e.g. AD) Mobile Apps Mobile Access Gateway (L7 SecureSpan Gateway) L7 Enterprise Service Manager Monitoring & Logging
  • 23. Case Study: API-Enabling Health Care  Challenge: Reduce cost and delay in processing Medicaid member information by bringing the process online  Solution: Mobile Access Gateway allows iPad application to securely connect to existing backend APIs; data routing, strict authN & authZ, comprehensive threat protection  Results: Improved the provider’s health care coverage and member services, while increasing the effectiveness and efficiency of its Medicaid program
  • 24. Case Study: Mobile-Enable Airline Services  Challenge: Securely expose existing services to third party developers in order to expand their market reach  Solution: The Layer 7 API Proxy allows the airline to securely expose and manage their APIs, while caching Sabre requests  Results: Significantly grew market reach, while controlling costs associated with constantly pulling data from Sabre to service Developer requests
  • 25. Case Study: Smart Grid Gateway  Challenge: Migrate energy services to Smart Grid technology, leveraging the new capabilities offered by additional data and communication  Solution: SOA, Web and API Security Gateway enables high volume meter data collection, assisted service and upcoming mobile self-service for enhanced client experience  Results: Cost avoidance for higher volume meter traffic, improved customer service through real-time channels, improved service availability through proactive system monitoring
  • 26. Conclusions Employees are …and IT groups must bringing mobile accommodate them devices to work en without compromising masse… security and SLA’s Mobile Apps are …existing enterprise being built to services can be used to improve productivity quickly and reliably and reduce cost… enable these apps Enterprise API Management …through a Secure Mobile Access Gateway, integrates Mobile an API Portal, and open Apps and Enterprise standards Services…

Editor's Notes

  1. Technical/security architects work with the Layer 7 Gateway to create policy that secures their enterprise APIsWeb administrators work with the Layer 7 API Portal to customize the look and feel; create API documentation and resources; etc, enabling developers to quickly understand how to work with the APIs and build out an applicationBusiness Managers and API Owners tasked with monetizing their APIs (or expand their market reach) create business rules around who can use which APIs in what waysThose business rules created on the API Portal are written down to the Layer 7 Gateway and enforced at runtime to ensure proper API interaction
  2. Enterprise Service Manager also provides operational reporting and dashboarding