SlideShare a Scribd company logo
1 of 27
Download to read offline
BASE24 is a product of ACI Worldwide, all copyrights acknowledged.
1Copyright comForte 2014
This part of the screen/slide are the so-called speaker notes
Viewing instructions: please see actual slide
Copyright comForte 2014 2
Copyright comForte 2014 3
In this presentation, we are assuming that we are a financial institution using BASE24 classic - and that we have no
plans to change that in the next few years. ((Side note: we might be looking at other options but we are aware that
fully migrating off BASE24 is a multi-year project))
That leaves us with a stable, yet old, unsecure and not-agile system. The word map above shows technologies and
components which are deeply entrenched into BASE24. All of the technologies are decades old and are *not* what
today is called ‘agile’.
4Copyright comForte 2014
Here are a few trends which are shaking up the financial industry (and others!)
5Copyright comForte 2014
This is what IBM is offering when it comes to modernizing “mainframe legacy applications”. Please note how they
have managed to integrate the mainframe into modern worlds but (1) running Linux partitions right on the
mainframe and (2) by providing “gateways” or “adaptors” running in this Linux component which enable the legacy
applications to take part in modernization initiatives.
Compare this with the way HP NonStop systems are typically NOT integrated into the Enterprise, more on this later
6Copyright comForte 2014
Simply put, we don’t have the tools for the job. Assume your NonStop BASE24 system is supposed to be integrated
in a new mobile app your business is developing:
- implement new functionality in TAL?  Not really an option
- How to provide a SOAP (or JSON/REST) wrapper around a ‘service’ provided by green screens?
7Copyright comForte 2014
Using modern tools is the answer – we’ll look in more details next
8Copyright comForte 2014
Copyright comForte 2014 9
A rock-solid and proven application to process POS and ATM transaction. Looks good from a high level – but how
correct is this picture?
10Copyright comForte 2014
As we typically run BASE24 classic very much in legacy mode, this is how it looks like from the C-level and business folks
perspective.
Let us not kid ourselves though – BASE24 is *not* integrated well into the Enterprise – also it severely lacks in certain areas of
compliance. That puts the application (and platform!) in danger of being replaced by something new.
Also, even if there are plans for replacement they typically involve a rather long schedule – can you afford to wait that long
given all the aforementioned business drivers?
The good news: as we’ll see, BASE24 (and other ‘legacy’ NonStop applications) can easily be
• SOA-enabled for better integrations
• secured for better PCI compliance
 But typically they are NOT
11Copyright comForte 2014
Further good news: typically the changes can be done with very little or even NO source code changes
12Copyright comForte 2014
Copyright comForte 2014 13
Here the business process is to add an ATM to a BASE24 system. The current process typically involves entering the
relevant data (description, IP address, ATM details) into a “green screen” user interface. That process is (1) manual
and laborious and (2) error prone.
14Copyright comForte 2014
In a SOA (Service Oriented Architecture) approach, the BASE24 system is presenting a service “Add ATM” (and
“INFO ATM <name>) to the integration layer. That service is then invoked from existing business
application/processes. The business benefits are:
- Streamlined operation
- “Live” view of all ATMs available for other applicatinos
- Reduction of manual, error-prone work
15Copyright comForte 2014
This presentation is not very technical by design – hence this slide only provides a short description of the
technologies involved.
16Copyright comForte 2014
(This example is taken from the UK, other geographies might not have this requirement).
Today, customers in branch offices authenticate themselves via either a passport or a signature. In this example,
the business wants to authenticate bank customers in the branch using their debit card and Chip and PIN
technology. This is both easier for the end user as well as more convenient (no need to carry a passport or ID
document) and more secure.
Many BASE24 classic implementations already have Chip&PIN technology built-in, but not available as a service on
BASE24.
17Copyright comForte 2014
Here the technology involved is a bit more complex. But do not let this picture confuse you – interaction between multiple business applicationsof this complexity is perfectly
normal in modern IT environments. Here is a bit detail on how this would work:
BASE24 can provide a service via the integration layer to authenticatethe card (typically by converting it into a balance enquiry request at the integration layer). Pass or Fail is
returned to the requestorof the service
The implementation would be roughly as follows:
• A ew “Authenticatewith debit card” Application (let’s call it AWDCA) at branch is developed from scratch
• AWDCA has to be connected to the PeD ( PIN Encryption Device) via an internal network
• The AWDCA starts a transactionat the PeD (step 1)
• The customer swipes card, device does Offline PIN check. The PeD does *not* use offline PINverification but creates request for transaction
• Step 2: the PeD transactioncan be any transactioncode which is sent to the FEP layer at the bank which forwards it to the comforte service wrapper for BASE24(step 3). The
wrapper generates a BASE24 ISO Balance Inquiry request
• (still step 3, see next slide): the Integrationlayers sends request to CSL
• (still step 3, see next slide): CSL product receives WSDL and converts it into format readable by BASE24
• (still step 3, see next slide): CSL sends request into BASE24 and receives response
• (still step 3, see next slide): BASE24 sees normal balancy inquiry and treats it as coming from an ATM – doing Chip/EMV authorization as side effect
18Copyright comForte 2014
• (Step 4): Response is translatedinto “success”or “fail with error message” (balance inquiry result is tossed) and returned to AWDC
• The bank teller would simply use the new AWDCA and could now happily authenticate its customers.
Copyright comForte 2014 18
Note the similarity to slide #16
19Copyright comForte 2014
The last example is not about new business requirements but about being compliant with the PCI framework.
Out-of-the box, BASE24 classic can NOT comply with PCI 3.4, also BASE24 can NOT encrypt TCP/IP connections
between XPNET and ATMs or POS devices.
20Copyright comForte 2014
Greg Swedosh gave a good presentation about compliance at the NonStop technical Bootcamp 2014 – see
http://www.slideshare.net/thomasburg/you-may-be-compliant-but-are-you-really-secure
21Copyright comForte 2014
The following two comForte products improve compliance and security for BASE24 classic – again without any
source code changes:
• SecurData for protection of data at rest (PCI 3.4)
• SecurLib/SSL-AT for encryption of ATM or POS traffic
22Copyright comForte 2014
Copyright comForte 2014 23
We talked about how proper tools can help to move from an isolated, legacy BASE24 system to a service-enabled,
modern and secure BASE24 system – without requiring any source code changes
24Copyright comForte 2014
To keep BASE24/the NonStop relevant …
…It is about the business case!
… and about the application (BASE24 classic) and platform (HP NonStop) being perceived as flexible
25Copyright comForte 2014
Any questions please use http://comforte.com/company/contactform/
26Copyright comForte 2014

More Related Content

What's hot

Introduction to Amazon Web Services
Introduction to Amazon Web ServicesIntroduction to Amazon Web Services
Introduction to Amazon Web ServicesAmazon Web Services
 
Open Banking via API Connect & DataPower
Open Banking via API Connect & DataPowerOpen Banking via API Connect & DataPower
Open Banking via API Connect & DataPowerIBM DataPower Gateway
 
Building APIs with Amazon API Gateway
Building APIs with Amazon API GatewayBuilding APIs with Amazon API Gateway
Building APIs with Amazon API GatewayAmazon Web Services
 
Virtualization in cloud computing ppt
Virtualization in cloud computing pptVirtualization in cloud computing ppt
Virtualization in cloud computing pptMehul Patel
 
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...Amazon Web Services
 
Dual write strategies for microservices
Dual write strategies for microservicesDual write strategies for microservices
Dual write strategies for microservicesBilgin Ibryam
 
3. CPU virtualization and scheduling
3. CPU virtualization and scheduling3. CPU virtualization and scheduling
3. CPU virtualization and schedulingHwanju Kim
 
Virtual Machine Concept
Virtual Machine ConceptVirtual Machine Concept
Virtual Machine Conceptfatimaanique1
 
Presentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyyPresentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyyTehmina Gulfam
 
Process Automation Forum April 2021 - Practical Process Automation
Process Automation Forum April 2021 - Practical Process AutomationProcess Automation Forum April 2021 - Practical Process Automation
Process Automation Forum April 2021 - Practical Process AutomationBernd Ruecker
 
Client Server Architecture
Client Server ArchitectureClient Server Architecture
Client Server Architecturesuks_87
 
Migration into a Cloud
Migration into a CloudMigration into a Cloud
Migration into a CloudDivya S
 
Virtualization VMWare technology
Virtualization VMWare technologyVirtualization VMWare technology
Virtualization VMWare technologysanjoysanyal
 
Cloud Architecture - Multi Cloud, Edge, On-Premise
Cloud Architecture - Multi Cloud, Edge, On-PremiseCloud Architecture - Multi Cloud, Edge, On-Premise
Cloud Architecture - Multi Cloud, Edge, On-PremiseAraf Karsh Hamid
 
Infrastructure as a Service ( IaaS)
Infrastructure as a Service ( IaaS)Infrastructure as a Service ( IaaS)
Infrastructure as a Service ( IaaS)Ravindra Dastikop
 
Virtual Machine provisioning and migration services
Virtual Machine provisioning and migration servicesVirtual Machine provisioning and migration services
Virtual Machine provisioning and migration servicesANUSUYA T K
 

What's hot (20)

Introduction to Amazon Web Services
Introduction to Amazon Web ServicesIntroduction to Amazon Web Services
Introduction to Amazon Web Services
 
Open Banking via API Connect & DataPower
Open Banking via API Connect & DataPowerOpen Banking via API Connect & DataPower
Open Banking via API Connect & DataPower
 
Building APIs with Amazon API Gateway
Building APIs with Amazon API GatewayBuilding APIs with Amazon API Gateway
Building APIs with Amazon API Gateway
 
Virtualization in cloud computing ppt
Virtualization in cloud computing pptVirtualization in cloud computing ppt
Virtualization in cloud computing ppt
 
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
 
Dual write strategies for microservices
Dual write strategies for microservicesDual write strategies for microservices
Dual write strategies for microservices
 
3. CPU virtualization and scheduling
3. CPU virtualization and scheduling3. CPU virtualization and scheduling
3. CPU virtualization and scheduling
 
Azure 101
Azure 101Azure 101
Azure 101
 
Virtual Machine Concept
Virtual Machine ConceptVirtual Machine Concept
Virtual Machine Concept
 
Presentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyyPresentation on backup and recoveryyyyyyyyyyyyy
Presentation on backup and recoveryyyyyyyyyyyyy
 
Cloud security
Cloud securityCloud security
Cloud security
 
Process Automation Forum April 2021 - Practical Process Automation
Process Automation Forum April 2021 - Practical Process AutomationProcess Automation Forum April 2021 - Practical Process Automation
Process Automation Forum April 2021 - Practical Process Automation
 
Client Server Architecture
Client Server ArchitectureClient Server Architecture
Client Server Architecture
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Servicios de Bases de Datos de AWS
Servicios de Bases de Datos de AWSServicios de Bases de Datos de AWS
Servicios de Bases de Datos de AWS
 
Migration into a Cloud
Migration into a CloudMigration into a Cloud
Migration into a Cloud
 
Virtualization VMWare technology
Virtualization VMWare technologyVirtualization VMWare technology
Virtualization VMWare technology
 
Cloud Architecture - Multi Cloud, Edge, On-Premise
Cloud Architecture - Multi Cloud, Edge, On-PremiseCloud Architecture - Multi Cloud, Edge, On-Premise
Cloud Architecture - Multi Cloud, Edge, On-Premise
 
Infrastructure as a Service ( IaaS)
Infrastructure as a Service ( IaaS)Infrastructure as a Service ( IaaS)
Infrastructure as a Service ( IaaS)
 
Virtual Machine provisioning and migration services
Virtual Machine provisioning and migration servicesVirtual Machine provisioning and migration services
Virtual Machine provisioning and migration services
 

Similar to BASE24 classic - modernization options

2014 11 data at rest protection for base24 - lessons learned in production
2014 11 data at rest protection for base24 - lessons learned in production2014 11 data at rest protection for base24 - lessons learned in production
2014 11 data at rest protection for base24 - lessons learned in productionThomas Burg
 
Modernize your AS400 - the future proof, low cost solution.
Modernize your AS400 - the future proof, low cost solution.Modernize your AS400 - the future proof, low cost solution.
Modernize your AS400 - the future proof, low cost solution.112Motion
 
Impact of platformization on your business processes and ERP Landscape
Impact of platformization on your business processes and ERP LandscapeImpact of platformization on your business processes and ERP Landscape
Impact of platformization on your business processes and ERP LandscapeJos Feyaerts
 
How to do a successful wms implementation overcome common pitfalls
How to do a successful wms implementation overcome common pitfallsHow to do a successful wms implementation overcome common pitfalls
How to do a successful wms implementation overcome common pitfallsJade Global
 
The attack on TARGET: how was it done - lessons learned for protecting HP Non...
The attack on TARGET: how was it done - lessons learned for protecting HP Non...The attack on TARGET: how was it done - lessons learned for protecting HP Non...
The attack on TARGET: how was it done - lessons learned for protecting HP Non...Thomas Burg
 
apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...
apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...
apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...apidays
 
6 Key Stages to CIF Self-Certified Status_v1.3 DR1115
6 Key Stages to CIF Self-Certified Status_v1.3 DR11156 Key Stages to CIF Self-Certified Status_v1.3 DR1115
6 Key Stages to CIF Self-Certified Status_v1.3 DR1115Jason Wyatt
 
B2B add on implementation scenarios po. part I inbound edi
B2B add on implementation scenarios po. part I inbound ediB2B add on implementation scenarios po. part I inbound edi
B2B add on implementation scenarios po. part I inbound ediRoberto Cantero Segovia
 
Salesforce.com & Raspberry Pi - Giant Clouds, Tiny Computers
Salesforce.com & Raspberry Pi - Giant Clouds, Tiny ComputersSalesforce.com & Raspberry Pi - Giant Clouds, Tiny Computers
Salesforce.com & Raspberry Pi - Giant Clouds, Tiny ComputersReidCarlberg
 
Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...
Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...
Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...CA Technologies
 
Platform Showcase: Making the Ultimate Live Demo, by Gabriel Michaud
Platform Showcase: Making the Ultimate Live Demo, by Gabriel MichaudPlatform Showcase: Making the Ultimate Live Demo, by Gabriel Michaud
Platform Showcase: Making the Ultimate Live Demo, by Gabriel MichaudAcumatica Cloud ERP
 
Placement of BPM runtime components in an SOA environment
Placement of BPM runtime components in an SOA environmentPlacement of BPM runtime components in an SOA environment
Placement of BPM runtime components in an SOA environmentKim Clark
 
Faster and more efficient processes by combining BPM and Mobile – yes we can!
Faster and more efficient processes by combining BPM and Mobile – yes we can!Faster and more efficient processes by combining BPM and Mobile – yes we can!
Faster and more efficient processes by combining BPM and Mobile – yes we can!Sebastian Faulhaber
 
A step by-step guide on i doc-ale between two sap servers
A step by-step guide on i doc-ale between two sap serversA step by-step guide on i doc-ale between two sap servers
A step by-step guide on i doc-ale between two sap serverskrishna RK
 
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...akquinet enterprise solutions GmbH
 
Positive pay edi process in sap
Positive pay edi process in sapPositive pay edi process in sap
Positive pay edi process in sapRajeev Kumar
 
Cisco and The Applied Group Point of View
Cisco and The Applied Group Point of ViewCisco and The Applied Group Point of View
Cisco and The Applied Group Point of ViewDavid Barry
 
Kinh doanh so voi he thong bfo e business platform v2
Kinh doanh so voi he thong bfo e business platform v2Kinh doanh so voi he thong bfo e business platform v2
Kinh doanh so voi he thong bfo e business platform v2Hieutanda Nguyen Khac Hieu
 

Similar to BASE24 classic - modernization options (20)

2014 11 data at rest protection for base24 - lessons learned in production
2014 11 data at rest protection for base24 - lessons learned in production2014 11 data at rest protection for base24 - lessons learned in production
2014 11 data at rest protection for base24 - lessons learned in production
 
Modernize your AS400 - the future proof, low cost solution.
Modernize your AS400 - the future proof, low cost solution.Modernize your AS400 - the future proof, low cost solution.
Modernize your AS400 - the future proof, low cost solution.
 
Impact of platformization on your business processes and ERP Landscape
Impact of platformization on your business processes and ERP LandscapeImpact of platformization on your business processes and ERP Landscape
Impact of platformization on your business processes and ERP Landscape
 
BinionsIIa
BinionsIIaBinionsIIa
BinionsIIa
 
How to do a successful wms implementation overcome common pitfalls
How to do a successful wms implementation overcome common pitfallsHow to do a successful wms implementation overcome common pitfalls
How to do a successful wms implementation overcome common pitfalls
 
The attack on TARGET: how was it done - lessons learned for protecting HP Non...
The attack on TARGET: how was it done - lessons learned for protecting HP Non...The attack on TARGET: how was it done - lessons learned for protecting HP Non...
The attack on TARGET: how was it done - lessons learned for protecting HP Non...
 
Soa Test Methodology
Soa Test MethodologySoa Test Methodology
Soa Test Methodology
 
apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...
apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...
apidays LIVE Paris 2021 - EDI & API on One Integration Platform by Mir Mustha...
 
6 Key Stages to CIF Self-Certified Status_v1.3 DR1115
6 Key Stages to CIF Self-Certified Status_v1.3 DR11156 Key Stages to CIF Self-Certified Status_v1.3 DR1115
6 Key Stages to CIF Self-Certified Status_v1.3 DR1115
 
B2B add on implementation scenarios po. part I inbound edi
B2B add on implementation scenarios po. part I inbound ediB2B add on implementation scenarios po. part I inbound edi
B2B add on implementation scenarios po. part I inbound edi
 
Salesforce.com & Raspberry Pi - Giant Clouds, Tiny Computers
Salesforce.com & Raspberry Pi - Giant Clouds, Tiny ComputersSalesforce.com & Raspberry Pi - Giant Clouds, Tiny Computers
Salesforce.com & Raspberry Pi - Giant Clouds, Tiny Computers
 
Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...
Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...
Stop the Blame Game with Increased Visibility of your Mobile-to-Mainframe IT ...
 
Platform Showcase: Making the Ultimate Live Demo, by Gabriel Michaud
Platform Showcase: Making the Ultimate Live Demo, by Gabriel MichaudPlatform Showcase: Making the Ultimate Live Demo, by Gabriel Michaud
Platform Showcase: Making the Ultimate Live Demo, by Gabriel Michaud
 
Placement of BPM runtime components in an SOA environment
Placement of BPM runtime components in an SOA environmentPlacement of BPM runtime components in an SOA environment
Placement of BPM runtime components in an SOA environment
 
Faster and more efficient processes by combining BPM and Mobile – yes we can!
Faster and more efficient processes by combining BPM and Mobile – yes we can!Faster and more efficient processes by combining BPM and Mobile – yes we can!
Faster and more efficient processes by combining BPM and Mobile – yes we can!
 
A step by-step guide on i doc-ale between two sap servers
A step by-step guide on i doc-ale between two sap serversA step by-step guide on i doc-ale between two sap servers
A step by-step guide on i doc-ale between two sap servers
 
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
Fiori and S/4 authorizations: What are the biggest challenges, and where do t...
 
Positive pay edi process in sap
Positive pay edi process in sapPositive pay edi process in sap
Positive pay edi process in sap
 
Cisco and The Applied Group Point of View
Cisco and The Applied Group Point of ViewCisco and The Applied Group Point of View
Cisco and The Applied Group Point of View
 
Kinh doanh so voi he thong bfo e business platform v2
Kinh doanh so voi he thong bfo e business platform v2Kinh doanh so voi he thong bfo e business platform v2
Kinh doanh so voi he thong bfo e business platform v2
 

More from Thomas Burg

HPE NonStop GTUG Berlin - 'Yuma' Workshop
HPE NonStop GTUG Berlin - 'Yuma' Workshop HPE NonStop GTUG Berlin - 'Yuma' Workshop
HPE NonStop GTUG Berlin - 'Yuma' Workshop Thomas Burg
 
Comparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RACComparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RACThomas Burg
 
HP NonStop applications: Modernization from the Ground-up and the User-in
HP NonStop applications: Modernization from the Ground-up and the User-inHP NonStop applications: Modernization from the Ground-up and the User-in
HP NonStop applications: Modernization from the Ground-up and the User-inThomas Burg
 
You may be compliant, but are you really secure?
You may be compliant, but are you really secure?You may be compliant, but are you really secure?
You may be compliant, but are you really secure?Thomas Burg
 
The attack against target - how was it done and how has it changed the securi...
The attack against target - how was it done and how has it changed the securi...The attack against target - how was it done and how has it changed the securi...
The attack against target - how was it done and how has it changed the securi...Thomas Burg
 
comForte CSL: a messaging middleware framework for HP NonStop
comForte CSL: a messaging middleware framework for HP NonStopcomForte CSL: a messaging middleware framework for HP NonStop
comForte CSL: a messaging middleware framework for HP NonStopThomas Burg
 
2014 02 comForte SecurTape product
2014 02 comForte SecurTape product2014 02 comForte SecurTape product
2014 02 comForte SecurTape productThomas Burg
 
From Russia with Love - modern tools used in Cyber Attacks
From Russia with Love - modern tools used in Cyber AttacksFrom Russia with Love - modern tools used in Cyber Attacks
From Russia with Love - modern tools used in Cyber AttacksThomas Burg
 
The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...
The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...
The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...Thomas Burg
 
Survival of the Fittest: Modernize your NonStop applications today
Survival of the Fittest: Modernize your NonStop applications todaySurvival of the Fittest: Modernize your NonStop applications today
Survival of the Fittest: Modernize your NonStop applications todayThomas Burg
 

More from Thomas Burg (10)

HPE NonStop GTUG Berlin - 'Yuma' Workshop
HPE NonStop GTUG Berlin - 'Yuma' Workshop HPE NonStop GTUG Berlin - 'Yuma' Workshop
HPE NonStop GTUG Berlin - 'Yuma' Workshop
 
Comparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RACComparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RAC
 
HP NonStop applications: Modernization from the Ground-up and the User-in
HP NonStop applications: Modernization from the Ground-up and the User-inHP NonStop applications: Modernization from the Ground-up and the User-in
HP NonStop applications: Modernization from the Ground-up and the User-in
 
You may be compliant, but are you really secure?
You may be compliant, but are you really secure?You may be compliant, but are you really secure?
You may be compliant, but are you really secure?
 
The attack against target - how was it done and how has it changed the securi...
The attack against target - how was it done and how has it changed the securi...The attack against target - how was it done and how has it changed the securi...
The attack against target - how was it done and how has it changed the securi...
 
comForte CSL: a messaging middleware framework for HP NonStop
comForte CSL: a messaging middleware framework for HP NonStopcomForte CSL: a messaging middleware framework for HP NonStop
comForte CSL: a messaging middleware framework for HP NonStop
 
2014 02 comForte SecurTape product
2014 02 comForte SecurTape product2014 02 comForte SecurTape product
2014 02 comForte SecurTape product
 
From Russia with Love - modern tools used in Cyber Attacks
From Russia with Love - modern tools used in Cyber AttacksFrom Russia with Love - modern tools used in Cyber Attacks
From Russia with Love - modern tools used in Cyber Attacks
 
The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...
The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...
The Verizon 2012/2013 Data Breach Investigations Reports - Lessons Learned fo...
 
Survival of the Fittest: Modernize your NonStop applications today
Survival of the Fittest: Modernize your NonStop applications todaySurvival of the Fittest: Modernize your NonStop applications today
Survival of the Fittest: Modernize your NonStop applications today
 

Recently uploaded

Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 

Recently uploaded (20)

Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 

BASE24 classic - modernization options

  • 1. BASE24 is a product of ACI Worldwide, all copyrights acknowledged. 1Copyright comForte 2014
  • 2. This part of the screen/slide are the so-called speaker notes Viewing instructions: please see actual slide Copyright comForte 2014 2
  • 4. In this presentation, we are assuming that we are a financial institution using BASE24 classic - and that we have no plans to change that in the next few years. ((Side note: we might be looking at other options but we are aware that fully migrating off BASE24 is a multi-year project)) That leaves us with a stable, yet old, unsecure and not-agile system. The word map above shows technologies and components which are deeply entrenched into BASE24. All of the technologies are decades old and are *not* what today is called ‘agile’. 4Copyright comForte 2014
  • 5. Here are a few trends which are shaking up the financial industry (and others!) 5Copyright comForte 2014
  • 6. This is what IBM is offering when it comes to modernizing “mainframe legacy applications”. Please note how they have managed to integrate the mainframe into modern worlds but (1) running Linux partitions right on the mainframe and (2) by providing “gateways” or “adaptors” running in this Linux component which enable the legacy applications to take part in modernization initiatives. Compare this with the way HP NonStop systems are typically NOT integrated into the Enterprise, more on this later 6Copyright comForte 2014
  • 7. Simply put, we don’t have the tools for the job. Assume your NonStop BASE24 system is supposed to be integrated in a new mobile app your business is developing: - implement new functionality in TAL?  Not really an option - How to provide a SOAP (or JSON/REST) wrapper around a ‘service’ provided by green screens? 7Copyright comForte 2014
  • 8. Using modern tools is the answer – we’ll look in more details next 8Copyright comForte 2014
  • 10. A rock-solid and proven application to process POS and ATM transaction. Looks good from a high level – but how correct is this picture? 10Copyright comForte 2014
  • 11. As we typically run BASE24 classic very much in legacy mode, this is how it looks like from the C-level and business folks perspective. Let us not kid ourselves though – BASE24 is *not* integrated well into the Enterprise – also it severely lacks in certain areas of compliance. That puts the application (and platform!) in danger of being replaced by something new. Also, even if there are plans for replacement they typically involve a rather long schedule – can you afford to wait that long given all the aforementioned business drivers? The good news: as we’ll see, BASE24 (and other ‘legacy’ NonStop applications) can easily be • SOA-enabled for better integrations • secured for better PCI compliance  But typically they are NOT 11Copyright comForte 2014
  • 12. Further good news: typically the changes can be done with very little or even NO source code changes 12Copyright comForte 2014
  • 14. Here the business process is to add an ATM to a BASE24 system. The current process typically involves entering the relevant data (description, IP address, ATM details) into a “green screen” user interface. That process is (1) manual and laborious and (2) error prone. 14Copyright comForte 2014
  • 15. In a SOA (Service Oriented Architecture) approach, the BASE24 system is presenting a service “Add ATM” (and “INFO ATM <name>) to the integration layer. That service is then invoked from existing business application/processes. The business benefits are: - Streamlined operation - “Live” view of all ATMs available for other applicatinos - Reduction of manual, error-prone work 15Copyright comForte 2014
  • 16. This presentation is not very technical by design – hence this slide only provides a short description of the technologies involved. 16Copyright comForte 2014
  • 17. (This example is taken from the UK, other geographies might not have this requirement). Today, customers in branch offices authenticate themselves via either a passport or a signature. In this example, the business wants to authenticate bank customers in the branch using their debit card and Chip and PIN technology. This is both easier for the end user as well as more convenient (no need to carry a passport or ID document) and more secure. Many BASE24 classic implementations already have Chip&PIN technology built-in, but not available as a service on BASE24. 17Copyright comForte 2014
  • 18. Here the technology involved is a bit more complex. But do not let this picture confuse you – interaction between multiple business applicationsof this complexity is perfectly normal in modern IT environments. Here is a bit detail on how this would work: BASE24 can provide a service via the integration layer to authenticatethe card (typically by converting it into a balance enquiry request at the integration layer). Pass or Fail is returned to the requestorof the service The implementation would be roughly as follows: • A ew “Authenticatewith debit card” Application (let’s call it AWDCA) at branch is developed from scratch • AWDCA has to be connected to the PeD ( PIN Encryption Device) via an internal network • The AWDCA starts a transactionat the PeD (step 1) • The customer swipes card, device does Offline PIN check. The PeD does *not* use offline PINverification but creates request for transaction • Step 2: the PeD transactioncan be any transactioncode which is sent to the FEP layer at the bank which forwards it to the comforte service wrapper for BASE24(step 3). The wrapper generates a BASE24 ISO Balance Inquiry request • (still step 3, see next slide): the Integrationlayers sends request to CSL • (still step 3, see next slide): CSL product receives WSDL and converts it into format readable by BASE24 • (still step 3, see next slide): CSL sends request into BASE24 and receives response • (still step 3, see next slide): BASE24 sees normal balancy inquiry and treats it as coming from an ATM – doing Chip/EMV authorization as side effect 18Copyright comForte 2014
  • 19. • (Step 4): Response is translatedinto “success”or “fail with error message” (balance inquiry result is tossed) and returned to AWDC • The bank teller would simply use the new AWDCA and could now happily authenticate its customers. Copyright comForte 2014 18
  • 20. Note the similarity to slide #16 19Copyright comForte 2014
  • 21. The last example is not about new business requirements but about being compliant with the PCI framework. Out-of-the box, BASE24 classic can NOT comply with PCI 3.4, also BASE24 can NOT encrypt TCP/IP connections between XPNET and ATMs or POS devices. 20Copyright comForte 2014
  • 22. Greg Swedosh gave a good presentation about compliance at the NonStop technical Bootcamp 2014 – see http://www.slideshare.net/thomasburg/you-may-be-compliant-but-are-you-really-secure 21Copyright comForte 2014
  • 23. The following two comForte products improve compliance and security for BASE24 classic – again without any source code changes: • SecurData for protection of data at rest (PCI 3.4) • SecurLib/SSL-AT for encryption of ATM or POS traffic 22Copyright comForte 2014
  • 25. We talked about how proper tools can help to move from an isolated, legacy BASE24 system to a service-enabled, modern and secure BASE24 system – without requiring any source code changes 24Copyright comForte 2014
  • 26. To keep BASE24/the NonStop relevant … …It is about the business case! … and about the application (BASE24 classic) and platform (HP NonStop) being perceived as flexible 25Copyright comForte 2014
  • 27. Any questions please use http://comforte.com/company/contactform/ 26Copyright comForte 2014