SlideShare a Scribd company logo
API Management for Enterprise Mobile Access
A Layer 7 Technologies Solution
 Matt McLarty, VP, Client Solutions, Layer 7 Technologies
Housekeeping
 Questions
 - Chat any questions you have and we’ll answer them at the end of this call

 Twitter                                                     facebook.com/layer7

 - Today’s event hashtag:
                                                              layer7.com/linkedin
   - #L7webinar
                                                              layer7.com/blogs
 - Follow us on Twitter as well:
   - @layer7
Agenda

                 • BYOD and the App Explosion
 “Bring Your     • Innovation through Consumerization
Own Device”



                 • Enterprise Mobility and the Mobile App Paradigm
  Enterprise
   Mobile        • Leveraging Enterprise Services and Assets
 Integration



                 • API Publication, Security and Monetization
Enterprise API   • Solutions and Case Studies from Layer 7 Technologies
Management
BYOD: Bring Your Own Device




                              Courtesy of Click Software
BYOD: iPad @ Work – from IDG Connect “iPad for Business Survey 2012”
The App Explosion




Courtesy of zendesk   Courtesy of [x]cube Labs
Pillars of an Enterprise Mobility Strategy*
                                               “By exposing
Business Drivers                               access … through
Hardware Ownership & Support                   a standardized
                                               mobile-friendly
Deployment, Provisioning & Management          enterprise
Enterprise Services Platform
                                               services
                                               layer, the cost of
Application Portfolio & Roadmap                innovation can
                                               be dramatically
Corporate Governance & Processes
                                               reduced.”
Security Standards & Audit Processes
                                                   * From “iPad in the
                                                        Enterprise”, N.
                                                Clevenger, Wiley 2011
Mobile App-to-Enterprise Service Integration
     • Existing enterprise                             • Re-use of API and
       services can create                               shared services
       and increase                                      infrastructure
       revenue

                             Increase       Cost
                             Revenue      Reduction




                             Quality of
                                          Compliance
                              Service


     • Leverages proven                                • Uses existing
       systems with                                      security policies
       enterprise SLA’s                                  and technologies
Mobile App-to-Enterprise Service Integration Challenges

   Mobile Devices
                                                         Enterprise Services
                                                                                   Data Services
                                   Network



                                Composite services
 Proliferation of mobile                                        Service API’s
                                  need API’s from                                           Data privacy and
   devices increases                                      unavailable in mobile-
                                     multiple                                               integrity must be
   message volumes                                          friendly formats &
                                providers, requiring                                      preserved end-to-end
      exponentially                                       protocols (REST, JSON)
                                    federation

        BYOD approach mixes           API’s must be reusable         How to access
        personal and business         across multiple mobile      business intelligence
          use, blurring the              and non-mobile           and Big Data in real-
         security perimeter                  platforms                    time
Enterprise Service Platform Evolution
 Web Apps and Web Services (2001-2010)




         Thin & Thick
            Client
                             Web Proxy          App Server      DB Server



 Mobile Apps and API’s (2011 and beyond)

          Mobile                                                                On-
          Apps                                                                 Prem


                                                                               Cloud
                        Mobile Access Gateway   API Server     Data Services
                                                             (Hadoop, RDBMS)
The Mobile Access Gateway

       Mobile Devices
                                                             Enterprise Services
                                                                               Real-time bridging from
                                                                                         SOAP, XML and legacy
s                                                                                      Data Services JSON
                                                                                         formats to REST,
                                      Network                                               mobile protocols
                               Optimized high scale
                               engine for compute-                                       Single logical gateway
                               intensive integration                                     cluster configurable to
                                    functions                                           handle mobile, web and
                                                                                               B2B traffic
     Proliferation of mobile       Composite services
                               App- and API-specific                Service API’s
                                                                                                Data privacy and
                                                                                           Existing enterprise
       devices increases             need API’s from
                                security handling—            unavailable in mobile-
       message volumes              multiple providers,         friendly formats &         access control andbe
                                                                                               integrity must
                                 including Oauth—                                           preserved end-to-end
                                                                                        crypto extended to App-
          exponentially            requiring federation
                               adapts the perimeter           protocols (REST, JSON)
                                                                                          API through Gateway

            BYOD approach mixesFederated security for reusable
                                         API’s must be                   How to accessEvent-aware integration
                                3rd party API’s, multiple mobile
            personal and business        across data                                    capability for real-time
                                                                      business intelligence
              use, blurring the aggregation for
                                            and non-mobile                               analytic data synthesis
                                                                      and Big Data in real-
                              composite API mashups
             security perimeter                 platforms                     time          and integration
The Mobile Access Gateway

   Mobile Devices
   Mobile Access                                     Enterprise Services
                                                         Service API’s Real-time bridging from
                                                     unavailable in mobile- SOAP, XML and legacy
    Gateway                                            friendly formats & Data Services JSON
                                                                            formats to REST,
                                                     protocols (REST, JSON)    mobile protocols
 Proliferation of mobile    Optimized high scale
   devices increases        engine for compute-      API’s must be reusable    Single logical gateway
   message volumes          intensive integration    across multiple mobile    cluster configurable to
      exponentially              functions              and non-mobile        handle mobile, web and
                                                            platforms                B2B traffic

 BYOD approach mixes        App- and API-specific                                Existing enterprise
 personal and business       security handling—        Data privacy and          access control and
   use, blurring the          including Oauth—         integrity must be      crypto extended to App-
  security perimeter        adapts the perimeter     preserved end-to-end       API through Gateway

  Composite services        Federated security for       How to access        Event-aware integration
    need API’s from          3rd party API’s, data    business intelligence    capability for real-time
   multiple providers,         aggregation for        and Big Data in real-    analytic data synthesis
  requiring federation     composite API mashups              time                and integration
Mobile App-to-Enterprise Integration Stakeholders

   App                                    Who is allowed to             API
 Developer                                use my API’s? Are            Owner
                       What API’s are     they being used?
                     available and how
                      can I use them?




        Mobile                                                                     On-
        Apps                                                                      Prem


                                                                                  Cloud
                 Mobile Access Gateway       API Server          Data Services
                                                               (Hadoop, RDBMS)



    IT                                                                   Info
                                           How is our data             Security
 Operator                                being protected and
                     What is changing?    access controlled?
                        Is everything
                     running smoothly?
Layer 7 API Management Suite
 API Proxy
 - Enterprise-grade Mobile Access Gateway

 API Portal
 - Developer on-boarding, support and resources
 - API metrics and reporting

 Enterprise Service Manager (ESM)
 - API migration, management and dashboarding

 Secure OAuth Toolkit
 - Support for 2 and 3-legged OAuth
API Management – How it All Works
                        Enterprise APIs



  1. Publish & Secure APIs                            2. Onboard Developers

                                                                                    Developer



   Security Architect


                   4. Close the Loop




                                                    3. Monetize your APIs


                                                                              IT Operator



                                          Business Manager/
                                             API Owner
Mobile Access Gateway – API Proxy
       Enterprise APIs



                              Feature/Function                          API Proxy
                              Credentialing                                 Y
                              Custom Assertion SDK                          Y
                              JDBC support                                  Y
                              SAML support                                 Full
                              Convert SOAP<->REST                           Y
                              WS* support                                   Y
                              XACML support                                 Y
   1. Publish & Secure APIs   MTOM support                                  Y
                              Transports supported           JMS, MQ, FTP(s), HTTP(s), raw TCP

                              Concurrent Assertion support                  Y
                              OAuth support                       1.0 and 2.0, HMAC, RSA
                              Rate Limiting                                 Y
                              Multiple Form Factors           Hardware, Software, VMware, AMI
Mobile Access Gateway – OAuth
• Plug in your ID providers, IAM, CA
  Siteminder, OAM, …
• Plug in any developer portal, api key
  management system
                                                Layer 7 implements OAuth
     Layer 7 implements OAuth                   Resource Server for your REST
     Authorization Server                       services, APIs



Client application
     (REST client)                                           API Dev Portal or Client API Key store
                              1. Handshake
                              2. Service call



                              Handshake only
                              (optional)
     Resource owner
         (subscriber)                                         ID Provider
                                                              For resource owner authentication
API Portal – Onboard and Manage Developers
      Enterprise APIs



                                    2. Onboard Developers




                         Feature/Function          API Portal
                         Developer Registration        Y
                         API Key Management            Y
                         API Explorer                  Y
                         API Rate Limiting             Y
                         API Reporting                 Y
                         Developer Support             Y
                         Fully-branded CMS             Y
                         Account Management            Y
ESM – API Migration and Lifecycle Management
 Automated dependency resolution when migrating policies between environments


                                                                       cloud01LDAP
                                               prod01LDAP



              Development      Test (Enterprise)            Production (Cloud)
  dev01LDAP




                                                              3. Monetize your API’s
Example Scenario – Web Application Security




     Thin & Thick
        Client
                    Web Proxy      App Server            DB Server




                                  Policy Server          Directory
                                (e.g. SiteMinder)        (e.g. AD)




                                                    Monitoring & Logging
Example Scenario – Web Services Security




     Thin & Thick
        Client
                          Web Proxy              App Server            DB Server

        B2B
       Clients

                                                Policy Server          Directory
                                              (e.g. SiteMinder)        (e.g. AD)




                     Mobile Access Gateway
                    (L7 SecureSpan Gateway)
                                                 L7 Enterprise
                                               Service Manager    Monitoring & Logging
Example Scenario – API Management




     Thin & Thick
        Client
                          Web Proxy              App Server            DB Server

        B2B              L7 API Portal
       Clients

                                                Policy Server          Directory
                                              (e.g. SiteMinder)        (e.g. AD)
      Mobile
      Apps


                     Mobile Access Gateway
                    (L7 SecureSpan Gateway)
                                                 L7 Enterprise
                                               Service Manager    Monitoring & Logging
Case Study: API-Enabling Health Care
 Challenge: Reduce cost and delay in processing Medicaid member information by bringing
  the process online
 Solution: Mobile Access Gateway allows iPad application to securely connect to existing
  backend APIs; data routing, strict authN & authZ, comprehensive threat protection




 Results: Improved the provider’s health care coverage and member services, while
  increasing the effectiveness and efficiency of its Medicaid program
Case Study: Mobile-Enable Airline Services
 Challenge: Securely expose existing services to third party developers in order to expand
  their market reach
 Solution: The Layer 7 API Proxy allows the airline to securely expose and manage their APIs,
  while caching Sabre requests




 Results: Significantly grew market reach, while controlling costs associated with constantly
  pulling data from Sabre to service Developer requests
Case Study: Smart Grid Gateway
 Challenge: Migrate energy services to Smart Grid technology, leveraging the new capabilities
  offered by additional data and communication
 Solution: SOA, Web and API Security Gateway enables high volume meter data collection,
  assisted service and upcoming mobile self-service for enhanced client experience




 Results: Cost avoidance for higher volume meter traffic, improved customer service through
  real-time channels, improved service availability through proactive system monitoring
Conclusions

            Employees are         …and IT groups must
           bringing mobile        accommodate them
          devices to work en     without compromising
               masse…              security and SLA’s



            Mobile Apps are      …existing enterprise
             being built to     services can be used to
         improve productivity     quickly and reliably
           and reduce cost…       enable these apps


             Enterprise API
             Management           …through a Secure
                                Mobile Access Gateway,
           integrates Mobile    an API Portal, and open
          Apps and Enterprise          standards
               Services…

More Related Content

What's hot (18)

PPTX
IBM Worklight-Overview
IBM WebSphereIndia
 
PPTX
Compuware APM Solution
backfire_88
 
PDF
Magpie Smart Grid Software Engineering Offering
impodgirl
 
PDF
Identity in an API Economy KuppingerCole Webinar Sponsored by Layer 7
CA API Management
 
PDF
IBM Worklight - Technical Overview
IIC_Barcelona
 
PDF
Managing API Security in SaaS and Cloud
CA API Management
 
PDF
Managing API Security in SaaS and Cloud
CA API Management
 
PDF
What virtualization means to the branch office
Interop
 
PDF
BYOD Enterprise Mobility: Beauty & the Beast
CA API Management
 
PDF
Dev mobile apps ent it final
Heinrich Seeger
 
PPTX
Zytrix labs corporate_profile_e_india
Diwakar Singh
 
PDF
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
Jeremy Siewert
 
PDF
Navyug corporate presentation 2012
Navyug Infosolutions Pvt. Ltd.
 
PPTX
Web xpress enterprise mobility capability and solutions
WebXpress
 
PPTX
Soa
subhaprasad79
 
IBM Worklight-Overview
IBM WebSphereIndia
 
Compuware APM Solution
backfire_88
 
Magpie Smart Grid Software Engineering Offering
impodgirl
 
Identity in an API Economy KuppingerCole Webinar Sponsored by Layer 7
CA API Management
 
IBM Worklight - Technical Overview
IIC_Barcelona
 
Managing API Security in SaaS and Cloud
CA API Management
 
Managing API Security in SaaS and Cloud
CA API Management
 
What virtualization means to the branch office
Interop
 
BYOD Enterprise Mobility: Beauty & the Beast
CA API Management
 
Dev mobile apps ent it final
Heinrich Seeger
 
Zytrix labs corporate_profile_e_india
Diwakar Singh
 
Introduction to IBM Worklight: Building and connecting cross-platform mobile ...
Jeremy Siewert
 
Navyug corporate presentation 2012
Navyug Infosolutions Pvt. Ltd.
 
Web xpress enterprise mobility capability and solutions
WebXpress
 

Viewers also liked (6)

PPT
Layer 7: Identity Enabled SOA Governance
CA API Management
 
PPT
Layer 7: Automated SOA Policy Enforcement
CA API Management
 
PPTX
Supporting academic openness and funder compliance: a new institutional lic...
SPARC Europe
 
PPT
Layer 7: Getting Your SOA to Production Without Cost and Complexity
CA API Management
 
PDF
How to Choose A SOA Gateway from Layer 7
CA API Management
 
PPTX
CA API Gateway: Web API and Application Security
CA Technologies
 
Layer 7: Identity Enabled SOA Governance
CA API Management
 
Layer 7: Automated SOA Policy Enforcement
CA API Management
 
Supporting academic openness and funder compliance: a new institutional lic...
SPARC Europe
 
Layer 7: Getting Your SOA to Production Without Cost and Complexity
CA API Management
 
How to Choose A SOA Gateway from Layer 7
CA API Management
 
CA API Gateway: Web API and Application Security
CA Technologies
 
Ad

Similar to API Management for Enterprise Mobile Access a How-to Guide (20)

PDF
IBM Presentation for Mobile Developer Summit India
Leigh Williamson
 
PDF
Mobile Web and Apps World New Orleans- Session 9 Vordel Mobile APIManagement
NextVision Media
 
PDF
Re Inventing Enterprise IT around APIs and Apps
WSO2
 
PPT
Worklight nitin nm
Nitin Gaur
 
PPTX
Designing Enterprise Mobile Applications: Critical Success Factors
Perficient, Inc.
 
PDF
Mobile enterprise
Sura Gonzalez
 
PPTX
Beyond MDM: 5 Things You Must do to Secure Mobile Devices in the Enterprise
CA API Management
 
PDF
Gwc mobilefoundation-final-2
Dirk Nicol
 
PDF
Mobility Managment: Manage the growth of mobilization of the enterprise
Yugan Sikri
 
PDF
Ibm mobile strategy may2012 mark.cesario v1.0
Mark Cesario
 
PPT
IBM Pulse 2013 session - DevOps for Mobile Apps
Sanjeev Sharma
 
PPTX
Codestrong 2012 breakout session the role of cloud services in your next ge...
Axway Appcelerator
 
PPT
Inter connected enterprise trends & directions feb 19 2013
Sid Bhatia
 
PDF
Melbourne API Management Seminar
CA API Management
 
PDF
DevOps for Mobile - DevOpsDays, NY, 2013
Sanjeev Sharma
 
PDF
Cloud & The Mobile Stack
Subbu Ramanathan
 
PDF
Leverage An Intelligent Application Infrastructure for Competitive Advantage.
Eric D. Schabell
 
PPTX
Secure Big Data Analytics - Hadoop & Intel
Intel - API Security & Tokenization
 
PPTX
Enterprise mobility and cloud
Kamesh Pemmaraju
 
IBM Presentation for Mobile Developer Summit India
Leigh Williamson
 
Mobile Web and Apps World New Orleans- Session 9 Vordel Mobile APIManagement
NextVision Media
 
Re Inventing Enterprise IT around APIs and Apps
WSO2
 
Worklight nitin nm
Nitin Gaur
 
Designing Enterprise Mobile Applications: Critical Success Factors
Perficient, Inc.
 
Mobile enterprise
Sura Gonzalez
 
Beyond MDM: 5 Things You Must do to Secure Mobile Devices in the Enterprise
CA API Management
 
Gwc mobilefoundation-final-2
Dirk Nicol
 
Mobility Managment: Manage the growth of mobilization of the enterprise
Yugan Sikri
 
Ibm mobile strategy may2012 mark.cesario v1.0
Mark Cesario
 
IBM Pulse 2013 session - DevOps for Mobile Apps
Sanjeev Sharma
 
Codestrong 2012 breakout session the role of cloud services in your next ge...
Axway Appcelerator
 
Inter connected enterprise trends & directions feb 19 2013
Sid Bhatia
 
Melbourne API Management Seminar
CA API Management
 
DevOps for Mobile - DevOpsDays, NY, 2013
Sanjeev Sharma
 
Cloud & The Mobile Stack
Subbu Ramanathan
 
Leverage An Intelligent Application Infrastructure for Competitive Advantage.
Eric D. Schabell
 
Secure Big Data Analytics - Hadoop & Intel
Intel - API Security & Tokenization
 
Enterprise mobility and cloud
Kamesh Pemmaraju
 
Ad

More from CA API Management (20)

PDF
Api architectures for the modern enterprise
CA API Management
 
PDF
Mastering Digital Channels with APIs
CA API Management
 
PDF
Takeaways from API Security Breaches Webinar
CA API Management
 
PDF
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
CA API Management
 
PDF
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
CA API Management
 
PDF
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
CA API Management
 
PPTX
API Monetization: Unlock the Value of Your Data
CA API Management
 
PDF
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
CA API Management
 
PDF
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
CA API Management
 
PDF
Enabling the Multi-Device Universe
CA API Management
 
PDF
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
CA API Management
 
PDF
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
CA API Management
 
PPTX
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
CA API Management
 
PDF
Adapting to Digital Change: Use APIs to Delight Customers & Win
CA API Management
 
PPTX
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
CA API Management
 
PDF
5 steps end to end security consumer apps
CA API Management
 
PPTX
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
CA API Management
 
PDF
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
CA API Management
 
PPTX
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
CA API Management
 
PDF
Using APIs to Create an Omni-Channel Retail Experience
CA API Management
 
Api architectures for the modern enterprise
CA API Management
 
Mastering Digital Channels with APIs
CA API Management
 
Takeaways from API Security Breaches Webinar
CA API Management
 
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
CA API Management
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
CA API Management
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
CA API Management
 
API Monetization: Unlock the Value of Your Data
CA API Management
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
CA API Management
 
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
CA API Management
 
Enabling the Multi-Device Universe
CA API Management
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
CA API Management
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
CA API Management
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
CA API Management
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
CA API Management
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
CA API Management
 
5 steps end to end security consumer apps
CA API Management
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
CA API Management
 
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
CA API Management
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
CA API Management
 
Using APIs to Create an Omni-Channel Retail Experience
CA API Management
 

Recently uploaded (20)

PDF
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
PDF
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
PDF
Smart Air Quality Monitoring with Serrax AQM190 LITE
SERRAX TECHNOLOGIES LLP
 
PDF
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
PPT
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
PDF
Blockchain Transactions Explained For Everyone
CIFDAQ
 
PPTX
Q2 Leading a Tableau User Group - Onboarding
lward7
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
LLMs.txt: Easily Control How AI Crawls Your Site
Keploy
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
PDF
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
PDF
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
PDF
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PDF
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
PDF
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
Smart Air Quality Monitoring with Serrax AQM190 LITE
SERRAX TECHNOLOGIES LLP
 
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
Blockchain Transactions Explained For Everyone
CIFDAQ
 
Q2 Leading a Tableau User Group - Onboarding
lward7
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
LLMs.txt: Easily Control How AI Crawls Your Site
Keploy
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
Fl Studio 24.2.2 Build 4597 Crack for Windows Free Download 2025
faizk77g
 
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 

API Management for Enterprise Mobile Access a How-to Guide

  • 1. API Management for Enterprise Mobile Access A Layer 7 Technologies Solution  Matt McLarty, VP, Client Solutions, Layer 7 Technologies
  • 2. Housekeeping  Questions - Chat any questions you have and we’ll answer them at the end of this call  Twitter facebook.com/layer7 - Today’s event hashtag: layer7.com/linkedin - #L7webinar layer7.com/blogs - Follow us on Twitter as well: - @layer7
  • 3. Agenda • BYOD and the App Explosion “Bring Your • Innovation through Consumerization Own Device” • Enterprise Mobility and the Mobile App Paradigm Enterprise Mobile • Leveraging Enterprise Services and Assets Integration • API Publication, Security and Monetization Enterprise API • Solutions and Case Studies from Layer 7 Technologies Management
  • 4. BYOD: Bring Your Own Device Courtesy of Click Software
  • 5. BYOD: iPad @ Work – from IDG Connect “iPad for Business Survey 2012”
  • 6. The App Explosion Courtesy of zendesk Courtesy of [x]cube Labs
  • 7. Pillars of an Enterprise Mobility Strategy*  “By exposing Business Drivers access … through Hardware Ownership & Support a standardized mobile-friendly Deployment, Provisioning & Management enterprise Enterprise Services Platform services layer, the cost of Application Portfolio & Roadmap innovation can be dramatically Corporate Governance & Processes reduced.” Security Standards & Audit Processes * From “iPad in the Enterprise”, N. Clevenger, Wiley 2011
  • 8. Mobile App-to-Enterprise Service Integration • Existing enterprise • Re-use of API and services can create shared services and increase infrastructure revenue Increase Cost Revenue Reduction Quality of Compliance Service • Leverages proven • Uses existing systems with security policies enterprise SLA’s and technologies
  • 9. Mobile App-to-Enterprise Service Integration Challenges Mobile Devices Enterprise Services Data Services Network Composite services Proliferation of mobile Service API’s need API’s from Data privacy and devices increases unavailable in mobile- multiple integrity must be message volumes friendly formats & providers, requiring preserved end-to-end exponentially protocols (REST, JSON) federation BYOD approach mixes API’s must be reusable How to access personal and business across multiple mobile business intelligence use, blurring the and non-mobile and Big Data in real- security perimeter platforms time
  • 10. Enterprise Service Platform Evolution  Web Apps and Web Services (2001-2010) Thin & Thick Client Web Proxy App Server DB Server  Mobile Apps and API’s (2011 and beyond) Mobile On- Apps Prem Cloud Mobile Access Gateway API Server Data Services (Hadoop, RDBMS)
  • 11. The Mobile Access Gateway Mobile Devices Enterprise Services Real-time bridging from SOAP, XML and legacy s Data Services JSON formats to REST, Network mobile protocols Optimized high scale engine for compute- Single logical gateway intensive integration cluster configurable to functions handle mobile, web and B2B traffic Proliferation of mobile Composite services App- and API-specific Service API’s Data privacy and Existing enterprise devices increases need API’s from security handling— unavailable in mobile- message volumes multiple providers, friendly formats & access control andbe integrity must including Oauth— preserved end-to-end crypto extended to App- exponentially requiring federation adapts the perimeter protocols (REST, JSON) API through Gateway BYOD approach mixesFederated security for reusable API’s must be How to accessEvent-aware integration 3rd party API’s, multiple mobile personal and business across data capability for real-time business intelligence use, blurring the aggregation for and non-mobile analytic data synthesis and Big Data in real- composite API mashups security perimeter platforms time and integration
  • 12. The Mobile Access Gateway Mobile Devices Mobile Access Enterprise Services Service API’s Real-time bridging from unavailable in mobile- SOAP, XML and legacy Gateway friendly formats & Data Services JSON formats to REST, protocols (REST, JSON) mobile protocols Proliferation of mobile Optimized high scale devices increases engine for compute- API’s must be reusable Single logical gateway message volumes intensive integration across multiple mobile cluster configurable to exponentially functions and non-mobile handle mobile, web and platforms B2B traffic BYOD approach mixes App- and API-specific Existing enterprise personal and business security handling— Data privacy and access control and use, blurring the including Oauth— integrity must be crypto extended to App- security perimeter adapts the perimeter preserved end-to-end API through Gateway Composite services Federated security for How to access Event-aware integration need API’s from 3rd party API’s, data business intelligence capability for real-time multiple providers, aggregation for and Big Data in real- analytic data synthesis requiring federation composite API mashups time and integration
  • 13. Mobile App-to-Enterprise Integration Stakeholders App Who is allowed to API Developer use my API’s? Are Owner What API’s are they being used? available and how can I use them? Mobile On- Apps Prem Cloud Mobile Access Gateway API Server Data Services (Hadoop, RDBMS) IT Info How is our data Security Operator being protected and What is changing? access controlled? Is everything running smoothly?
  • 14. Layer 7 API Management Suite  API Proxy - Enterprise-grade Mobile Access Gateway  API Portal - Developer on-boarding, support and resources - API metrics and reporting  Enterprise Service Manager (ESM) - API migration, management and dashboarding  Secure OAuth Toolkit - Support for 2 and 3-legged OAuth
  • 15. API Management – How it All Works Enterprise APIs 1. Publish & Secure APIs 2. Onboard Developers Developer Security Architect 4. Close the Loop 3. Monetize your APIs IT Operator Business Manager/ API Owner
  • 16. Mobile Access Gateway – API Proxy Enterprise APIs Feature/Function API Proxy Credentialing Y Custom Assertion SDK Y JDBC support Y SAML support Full Convert SOAP<->REST Y WS* support Y XACML support Y 1. Publish & Secure APIs MTOM support Y Transports supported JMS, MQ, FTP(s), HTTP(s), raw TCP Concurrent Assertion support Y OAuth support 1.0 and 2.0, HMAC, RSA Rate Limiting Y Multiple Form Factors Hardware, Software, VMware, AMI
  • 17. Mobile Access Gateway – OAuth • Plug in your ID providers, IAM, CA Siteminder, OAM, … • Plug in any developer portal, api key management system Layer 7 implements OAuth Layer 7 implements OAuth Resource Server for your REST Authorization Server services, APIs Client application (REST client) API Dev Portal or Client API Key store 1. Handshake 2. Service call Handshake only (optional) Resource owner (subscriber) ID Provider For resource owner authentication
  • 18. API Portal – Onboard and Manage Developers Enterprise APIs 2. Onboard Developers Feature/Function API Portal Developer Registration Y API Key Management Y API Explorer Y API Rate Limiting Y API Reporting Y Developer Support Y Fully-branded CMS Y Account Management Y
  • 19. ESM – API Migration and Lifecycle Management  Automated dependency resolution when migrating policies between environments cloud01LDAP prod01LDAP Development Test (Enterprise) Production (Cloud) dev01LDAP 3. Monetize your API’s
  • 20. Example Scenario – Web Application Security Thin & Thick Client Web Proxy App Server DB Server Policy Server Directory (e.g. SiteMinder) (e.g. AD) Monitoring & Logging
  • 21. Example Scenario – Web Services Security Thin & Thick Client Web Proxy App Server DB Server B2B Clients Policy Server Directory (e.g. SiteMinder) (e.g. AD) Mobile Access Gateway (L7 SecureSpan Gateway) L7 Enterprise Service Manager Monitoring & Logging
  • 22. Example Scenario – API Management Thin & Thick Client Web Proxy App Server DB Server B2B L7 API Portal Clients Policy Server Directory (e.g. SiteMinder) (e.g. AD) Mobile Apps Mobile Access Gateway (L7 SecureSpan Gateway) L7 Enterprise Service Manager Monitoring & Logging
  • 23. Case Study: API-Enabling Health Care  Challenge: Reduce cost and delay in processing Medicaid member information by bringing the process online  Solution: Mobile Access Gateway allows iPad application to securely connect to existing backend APIs; data routing, strict authN & authZ, comprehensive threat protection  Results: Improved the provider’s health care coverage and member services, while increasing the effectiveness and efficiency of its Medicaid program
  • 24. Case Study: Mobile-Enable Airline Services  Challenge: Securely expose existing services to third party developers in order to expand their market reach  Solution: The Layer 7 API Proxy allows the airline to securely expose and manage their APIs, while caching Sabre requests  Results: Significantly grew market reach, while controlling costs associated with constantly pulling data from Sabre to service Developer requests
  • 25. Case Study: Smart Grid Gateway  Challenge: Migrate energy services to Smart Grid technology, leveraging the new capabilities offered by additional data and communication  Solution: SOA, Web and API Security Gateway enables high volume meter data collection, assisted service and upcoming mobile self-service for enhanced client experience  Results: Cost avoidance for higher volume meter traffic, improved customer service through real-time channels, improved service availability through proactive system monitoring
  • 26. Conclusions Employees are …and IT groups must bringing mobile accommodate them devices to work en without compromising masse… security and SLA’s Mobile Apps are …existing enterprise being built to services can be used to improve productivity quickly and reliably and reduce cost… enable these apps Enterprise API Management …through a Secure Mobile Access Gateway, integrates Mobile an API Portal, and open Apps and Enterprise standards Services…

Editor's Notes

  • #16: Technical/security architects work with the Layer 7 Gateway to create policy that secures their enterprise APIsWeb administrators work with the Layer 7 API Portal to customize the look and feel; create API documentation and resources; etc, enabling developers to quickly understand how to work with the APIs and build out an applicationBusiness Managers and API Owners tasked with monetizing their APIs (or expand their market reach) create business rules around who can use which APIs in what waysThose business rules created on the API Portal are written down to the Layer 7 Gateway and enforced at runtime to ensure proper API interaction
  • #20: Enterprise Service Manager also provides operational reporting and dashboarding