Platform for 
Secure Digital 
Business 
Sachin Agarwal
70% of US population 
owns Smartphones
50 billion 
connected 
devices by 2020
Digital is disrupting the 
physical world with 
new business models
Why Digital? 
Customers are becoming 
increasingly wired – new touch 
points 
Digital is driving innovative new 
business models 
Integrated digital eco-systems 
offer valuable insights
Every Business is a Digital Business 
John Deere turns farm data and 
telemetry into a digital plan to 
optimize operations and increase 
yields/profits.
Get Visibility 
into Spend 
Manage expenses 
anytime, anywhere 
It’s all about 
automation
Key Aspects of Digital Enterprise Strategy 
• Create Digital eco-systems with APIs 
• Integrate data and applications to create a digital value 
chain 
• Analyze interactions to extract meaningful insights 
• Secure your digital interactions
The SOA Software Digital Business Platform
API MANAGEMENT
APIs Extend your Digital Ecosystems
Leverage Developers & Partners Ecosystems 
Tap into an 
extended eco-system 
of 
developers with 
APIs
Capture new Opportunities with APIs 
 Drive Innovation 
 Increase Reach 
 Support New Devices 
 Discover New Business Models 
 Increase Partner Network
APIs Foster Internal Innovation and Efficiency 
• Securely publish, share and use common services 
• Improve discoverability of internal services 
• Create internal communities to foster innovation
APIs: The Path to Digital Transformation
SOA Software API Management Platform 
• Community Manager 
• API Gateway 
• Lifecycle Manager 
for APIs
CLOUD INTEGRATION
The New Enterprise is Fragmented 
Cloud Platforms SaaS Applications Mobile & IoT Apps 
Data Services Packaged Apps Custom Apps
SaaS has leapt ahead 
72% 
2014 
*Source: North Bridge Venture Capital 
13% 
2011
Traditional Integration Approaches 
ESB are too heavy weight, 
long integration cycles 
Most Cloud Integration 
solutions still rely on ESB 
architecture 
Proprietary connectors 
don’t scale for
IFTTT is innovative, but not for Enterprise
What Connected Enterprises Need? 
• Integrate with growing number of Apps 
• Configure, no-code 
• Multi-channel focus 
• Ubiquitous access (API) 
• Multi-point 
• Configurable Orchestration & Transformation 
• Have Business, not your ESB drive your strategy
Integration Redefined 
Public APIs B2B APIs Internal APIs 
Cloud Integration Gateway
Cloud Integration Gateway 
 Gateway Architecture 
 API based Open connectors 
 Flexible Deployment 
 Declarative Policies 
 Multi-point Integration 
 Orchestrate and Transform 
 Publish as APIs 
 No IDEs or Eclipse plug-ins 
 Data and Policy Governance
SECURITY
A mobile app accessing your data has been compromised! 
How do you securely share APIs with an open developer community? 
Can you selectively revoke access for compromised Apps?
DIGITAL 
ENTERPRISE: 
 Securely share data 
 Make adoption easy 
 Make it SECURE
Securing the New Enterprise 
Digital is disrupting how and where information is accessed 
• Mobile and Social Apps 
don’t’ understand PKI, 
WS-Security, etc. 
• Focus on human 
readability, developer 
adoption
Realizing End-to-End Security 
Managing the 
User Experience 
Securing the 
App - PII, PHI 
Securing the Channel 
Enabling Easy Developer Access 
Securing the Backend
Understanding the Security Landscape 
Single Sign On MDM 
API Specific Security 
• Protocol specific threats 
• Key Management 
• OAuth 
• Monitoring 
• Licensing 
• Security Token Mediation 
ATP, Firewall, VPN etc.
API Security 
1 Authentication & 
Authorization 
3 Message Security 
2 App Key Validation/ 
Licensing 
5 Content Filtering 
4 Threat Protection 
6 Rate Limiting 
Developers
SOA Software API Gateway 
Gateway 
Security 
Authentication 
Protection 
IAM Integration 
Encryption 
Mediation 
Quality of Service 
Paging/Caching 
Orchestration 
Scripting
Out-of-the-box Security Policies 
 OpenID Provider/Relying Party 
 OAuth 1.0a & 2.0 (all grant-types) 
 Developer/Partner Key Auth & Az 
 CORS Management 
 HTTP Basic-Auth 
 Mutual SSL based Authentication 
 SAML 1.1 & 2.0 (STS included) 
 WS-Trust 1.2 & 1.3 
 WS-Security Transport Binding 
 WS-Security Username Token 
 WS-Security Message Encryption/Signature 
 Integration with AD, SiteMinder, OAM, RSA, 
 Cookie-based Authentication 
 Denial of Service attack Prevention 
 SQL Injection Prevention 
 Virus Scanning 
 XML Schema Validation 
 Malicious Pattern Detection 
 SLA/Throttling by a Developer/Partner 
 Certificate (PKI) Management (CA Included)
ANALYTICS
Analytics 
Which Application, 
Channels or APIs 
are driving the most 
business?
Analytics 
 Ensure 99.99% uptime 
 Proactive Operations 
 Identify bottleneck 
 Prevent security breaches
Analytics for your Enterprise 
Business Analytics 
• Track product, 
customer and 
monetization trends 
• Identify new 
opportunities. 
Operational Analytics 
• Ensure operation 
excellence of your 
infrastructure 
• Analyze errors and 
response codes 
API Analytics 
• Identity top APIs by 
usage, monetization, 
app type etc. 
• Analyze API Licensing, 
monetization and fine-tune 
developer 
onboarding
Flexible Analytics Platform 
Intercept & 
Collect 
Store in Big 
Data Store 
Process & 
Map Reduce 
Enrich & 
Customize 
Analyze & 
Visualize
Analytics Manager 
API Gateway 
Community 
Manager 
Analytics 
Manager 
Data Set 
Dimensions 
Metrics 
Aggregation Rules 
Enrichment 
Map Reduce 
External Plugins 
R 
Import 
Capture 
Export 
Visualization 
Customize 
Export as Widgets 
Custom Plug-ins
Business Analytics
API Analytics
Operational Analytics
Analytics Framework 
 Policy based data collection 
 Out of the box reports and dashboards 
 Configure (no-code) to create custom visualizations 
 Embed charts in dash board 
 Import data from any external source 
 Export easily into any other analytics infrastructure
The SOA Software Digital Business Platform
Leader in Gartner MQ and Forrester Wave 
Gartner Application Services 
Governance MQ 2013 
The Gartner document is available upon request.*Gartner, Inc., Magic Quadrant for Application Services Governance 
by Paolo Malinverno, 
Daryl C. Plummer, Gordon Van Huizen, August 8th 2013. 
Forrester Wave: API 
Management, Q3 2014 
The Forrester Wave™ is copyrighted by Forrester Research, Inc. Forrester and Forrester Wave are 
trademarks of Forrester Research, Inc. The Forrester Wave is a graphical representation of Forrester's call 
on a market and is plotted using a detailed spreadsheet with exposed scores, weightings, and comments. 
Forrester does not endorse any vendor, product, or service depicted in the Forrester Wave. Information is 
based on best available resources. Opinions reflect judgment at the time and are subject to change.
Marquee Customers
PRODUCT OVERVIEW
APIs: The Path to Digital Transformation
Accelerate Digital Channels 
• Delight customers with an engaging 
experience on any channel or device, at any 
moment 
– Mobile-enable your enterprise, externalize 
your products and services as APIs, and stay 
ahead of consumer trends. 
– Accelerate time to market and reduce TCO 
by leveraging existing applications 
Capabilities 
• Orchestration 
• Mediation 
• Scripting 
• Caching/Paging 
• Security
Drive Partner Adoption 
• Engage business partners and get 
developers up and running quickly 
– Launch a secure online portal to quickly 
onboard business partners and establish 
interactive online social channels with them. 
– Drive partner adoption with updated 
documentation and developer community. 
Connect with developers, inspire them, and 
drive your API usage. 
Capabilities 
• Portal 
• Social 
• Documentation 
• Groups 
• Search
Monetize Digital Assets 
• Package, market and license your 
assets to maximize revenue 
– Transform any application, service or 
asset into elegant and simple APIs. 
– Productize you data, create customized 
packages and tailored plans, and license 
them accordingly. 
Capabilities 
• Licensing 
• Rate Limiting 
• Provisioning 
• Documentation
Analyze your Business 
• Get instant insights into your business and 
optimize the delivery and value of APIs 
– Maximize your revenue by gaining complete 
visibility into how your partners and 
customers leverage your data. 
– Monitor activity for a specific partner, app or 
developer and evaluate their impact on your 
business. 
Capabilities 
• Business Analytics 
• Operational 
Insights 
• App and Developer 
Metrics
An Unified API & SOA Platform 
API Producers API Consumers 
Transform 
& Secure 
Dev. 
Publish Monetize 
Adoption 
API 
SOAP to REST 
Mobile- 
Optimization 
OAuth 
Mediation 
Analytics API Documentation 
Applications 
and Services 
Apps
API Platform Capabilities 
Platform 
Licensing 
Quota Mgmt. 
Partner Mgmt. 
PCI Compliance 
Provisioning 
Policy Mgmt. 
Monitoring 
OAuth 
Federation 
Analytics 
Lifecycle 
API/Services 
Application 
User 
Compliance 
Integrations 
Gateway 
Security 
Authentication 
Protection 
IAM Integration 
Encryption 
Mediation 
Quality of Service 
Paging/Caching 
Orchestration 
Scripting 
API Portal 
Search 
Documentation 
Groups 
Social
The Unified SOA & API Platform 
Analytics 
Developer Engagement 
Gateway Services 
Service Integration 
Lifecycle Management
Flexible Deployment Model
API Resources and API University 
• Resource Center 
– http://resource.soa.com/ 
• Follow us on: 
www.facebook.com/soasoftware 
www.linkedin.com/company/soasoftware 
@soasoftwareinc

Platform for Secure Digital Business

  • 1.
    Platform for SecureDigital Business Sachin Agarwal
  • 2.
    70% of USpopulation owns Smartphones
  • 3.
    50 billion connected devices by 2020
  • 4.
    Digital is disruptingthe physical world with new business models
  • 5.
    Why Digital? Customersare becoming increasingly wired – new touch points Digital is driving innovative new business models Integrated digital eco-systems offer valuable insights
  • 6.
    Every Business isa Digital Business John Deere turns farm data and telemetry into a digital plan to optimize operations and increase yields/profits.
  • 8.
    Get Visibility intoSpend Manage expenses anytime, anywhere It’s all about automation
  • 9.
    Key Aspects ofDigital Enterprise Strategy • Create Digital eco-systems with APIs • Integrate data and applications to create a digital value chain • Analyze interactions to extract meaningful insights • Secure your digital interactions
  • 10.
    The SOA SoftwareDigital Business Platform
  • 11.
  • 12.
    APIs Extend yourDigital Ecosystems
  • 13.
    Leverage Developers &Partners Ecosystems Tap into an extended eco-system of developers with APIs
  • 14.
    Capture new Opportunitieswith APIs  Drive Innovation  Increase Reach  Support New Devices  Discover New Business Models  Increase Partner Network
  • 15.
    APIs Foster InternalInnovation and Efficiency • Securely publish, share and use common services • Improve discoverability of internal services • Create internal communities to foster innovation
  • 16.
    APIs: The Pathto Digital Transformation
  • 17.
    SOA Software APIManagement Platform • Community Manager • API Gateway • Lifecycle Manager for APIs
  • 18.
  • 19.
    The New Enterpriseis Fragmented Cloud Platforms SaaS Applications Mobile & IoT Apps Data Services Packaged Apps Custom Apps
  • 20.
    SaaS has leaptahead 72% 2014 *Source: North Bridge Venture Capital 13% 2011
  • 21.
    Traditional Integration Approaches ESB are too heavy weight, long integration cycles Most Cloud Integration solutions still rely on ESB architecture Proprietary connectors don’t scale for
  • 22.
    IFTTT is innovative,but not for Enterprise
  • 23.
    What Connected EnterprisesNeed? • Integrate with growing number of Apps • Configure, no-code • Multi-channel focus • Ubiquitous access (API) • Multi-point • Configurable Orchestration & Transformation • Have Business, not your ESB drive your strategy
  • 24.
    Integration Redefined PublicAPIs B2B APIs Internal APIs Cloud Integration Gateway
  • 25.
    Cloud Integration Gateway  Gateway Architecture  API based Open connectors  Flexible Deployment  Declarative Policies  Multi-point Integration  Orchestrate and Transform  Publish as APIs  No IDEs or Eclipse plug-ins  Data and Policy Governance
  • 26.
  • 27.
    A mobile appaccessing your data has been compromised! How do you securely share APIs with an open developer community? Can you selectively revoke access for compromised Apps?
  • 28.
    DIGITAL ENTERPRISE: Securely share data  Make adoption easy  Make it SECURE
  • 29.
    Securing the NewEnterprise Digital is disrupting how and where information is accessed • Mobile and Social Apps don’t’ understand PKI, WS-Security, etc. • Focus on human readability, developer adoption
  • 30.
    Realizing End-to-End Security Managing the User Experience Securing the App - PII, PHI Securing the Channel Enabling Easy Developer Access Securing the Backend
  • 31.
    Understanding the SecurityLandscape Single Sign On MDM API Specific Security • Protocol specific threats • Key Management • OAuth • Monitoring • Licensing • Security Token Mediation ATP, Firewall, VPN etc.
  • 32.
    API Security 1Authentication & Authorization 3 Message Security 2 App Key Validation/ Licensing 5 Content Filtering 4 Threat Protection 6 Rate Limiting Developers
  • 33.
    SOA Software APIGateway Gateway Security Authentication Protection IAM Integration Encryption Mediation Quality of Service Paging/Caching Orchestration Scripting
  • 34.
    Out-of-the-box Security Policies  OpenID Provider/Relying Party  OAuth 1.0a & 2.0 (all grant-types)  Developer/Partner Key Auth & Az  CORS Management  HTTP Basic-Auth  Mutual SSL based Authentication  SAML 1.1 & 2.0 (STS included)  WS-Trust 1.2 & 1.3  WS-Security Transport Binding  WS-Security Username Token  WS-Security Message Encryption/Signature  Integration with AD, SiteMinder, OAM, RSA,  Cookie-based Authentication  Denial of Service attack Prevention  SQL Injection Prevention  Virus Scanning  XML Schema Validation  Malicious Pattern Detection  SLA/Throttling by a Developer/Partner  Certificate (PKI) Management (CA Included)
  • 35.
  • 36.
    Analytics Which Application, Channels or APIs are driving the most business?
  • 37.
    Analytics  Ensure99.99% uptime  Proactive Operations  Identify bottleneck  Prevent security breaches
  • 38.
    Analytics for yourEnterprise Business Analytics • Track product, customer and monetization trends • Identify new opportunities. Operational Analytics • Ensure operation excellence of your infrastructure • Analyze errors and response codes API Analytics • Identity top APIs by usage, monetization, app type etc. • Analyze API Licensing, monetization and fine-tune developer onboarding
  • 39.
    Flexible Analytics Platform Intercept & Collect Store in Big Data Store Process & Map Reduce Enrich & Customize Analyze & Visualize
  • 40.
    Analytics Manager APIGateway Community Manager Analytics Manager Data Set Dimensions Metrics Aggregation Rules Enrichment Map Reduce External Plugins R Import Capture Export Visualization Customize Export as Widgets Custom Plug-ins
  • 41.
  • 42.
  • 43.
  • 44.
    Analytics Framework Policy based data collection  Out of the box reports and dashboards  Configure (no-code) to create custom visualizations  Embed charts in dash board  Import data from any external source  Export easily into any other analytics infrastructure
  • 45.
    The SOA SoftwareDigital Business Platform
  • 46.
    Leader in GartnerMQ and Forrester Wave Gartner Application Services Governance MQ 2013 The Gartner document is available upon request.*Gartner, Inc., Magic Quadrant for Application Services Governance by Paolo Malinverno, Daryl C. Plummer, Gordon Van Huizen, August 8th 2013. Forrester Wave: API Management, Q3 2014 The Forrester Wave™ is copyrighted by Forrester Research, Inc. Forrester and Forrester Wave are trademarks of Forrester Research, Inc. The Forrester Wave is a graphical representation of Forrester's call on a market and is plotted using a detailed spreadsheet with exposed scores, weightings, and comments. Forrester does not endorse any vendor, product, or service depicted in the Forrester Wave. Information is based on best available resources. Opinions reflect judgment at the time and are subject to change.
  • 47.
  • 48.
  • 49.
    APIs: The Pathto Digital Transformation
  • 50.
    Accelerate Digital Channels • Delight customers with an engaging experience on any channel or device, at any moment – Mobile-enable your enterprise, externalize your products and services as APIs, and stay ahead of consumer trends. – Accelerate time to market and reduce TCO by leveraging existing applications Capabilities • Orchestration • Mediation • Scripting • Caching/Paging • Security
  • 51.
    Drive Partner Adoption • Engage business partners and get developers up and running quickly – Launch a secure online portal to quickly onboard business partners and establish interactive online social channels with them. – Drive partner adoption with updated documentation and developer community. Connect with developers, inspire them, and drive your API usage. Capabilities • Portal • Social • Documentation • Groups • Search
  • 52.
    Monetize Digital Assets • Package, market and license your assets to maximize revenue – Transform any application, service or asset into elegant and simple APIs. – Productize you data, create customized packages and tailored plans, and license them accordingly. Capabilities • Licensing • Rate Limiting • Provisioning • Documentation
  • 53.
    Analyze your Business • Get instant insights into your business and optimize the delivery and value of APIs – Maximize your revenue by gaining complete visibility into how your partners and customers leverage your data. – Monitor activity for a specific partner, app or developer and evaluate their impact on your business. Capabilities • Business Analytics • Operational Insights • App and Developer Metrics
  • 54.
    An Unified API& SOA Platform API Producers API Consumers Transform & Secure Dev. Publish Monetize Adoption API SOAP to REST Mobile- Optimization OAuth Mediation Analytics API Documentation Applications and Services Apps
  • 55.
    API Platform Capabilities Platform Licensing Quota Mgmt. Partner Mgmt. PCI Compliance Provisioning Policy Mgmt. Monitoring OAuth Federation Analytics Lifecycle API/Services Application User Compliance Integrations Gateway Security Authentication Protection IAM Integration Encryption Mediation Quality of Service Paging/Caching Orchestration Scripting API Portal Search Documentation Groups Social
  • 56.
    The Unified SOA& API Platform Analytics Developer Engagement Gateway Services Service Integration Lifecycle Management
  • 57.
  • 58.
    API Resources andAPI University • Resource Center – http://resource.soa.com/ • Follow us on: www.facebook.com/soasoftware www.linkedin.com/company/soasoftware @soasoftwareinc

Editor's Notes

  • #6 customers are becoming increasingly wired and tech-savvy the realignment of, or new investment in, technology and business models to more effectively engage digital customers at every touchpoint in the customer experience lifecycle