SlideShare a Scribd company logo
Manage Your Mesh 
Securing Public Cloud IoT APIs, and 
Building Private Mesh Trust Domains and 
Enclaves of Privacy to Integrate a Mesh of 
“Things” with Integrity & Availability 
ryan.bagnulo@soa.com 
Twitter: @iryanb
APIs are for any “Thing” 
and they don’t always belong on the Internet 
IoT Mesh
Wiring Things to Arduinos 
D1: 2.6 Volt RED LED 
& 330 Ohm Resistor 
A0: 3V Volt Motor & 
330 Ohm Resistor
Tinkering With Things 
Turn on Buzzer 
Turn on Motor
Programming Things – Protect the Flash API
The First Step to Managing your Mesh is with an API Gateway 
Gateway 
Security 
Authentication 
Protection 
IAM Integration 
Encryption 
Mediation 
Quality of Service 
Paging/Caching 
Orchestration 
Scripting 
Public IoT Mesh 
Private Mesh 
ProTip: 
Customer Premise 
Equipment such as a WiFi 
Router or Cableboxshould 
filter API traffic with an 
embedded gateway
Logical Mesh Management Architecture 
Private Mesh 
https://iot.mymesh.net/ 
mynet/status 
or 
https://skynet.im/status 
https://p0st3r.broker.soa.com/v1/skynet/status 
Public IoT Mesh
Use Gateways in the Cloud & Privately 
Private Mesh 
“Badge Readers” 
Private Mesh 
“Department X” 
Public Mesh
Public, Private, Hybrid
API Policy Configuration Templates 
Operational Policies 
o API Consumer Application Security Policy 
o API DDoS & Malicious Code Protection 
o Aggregate Policy 
o Authentication Policy 
o Authorization Policy 
o ICAP Antivirus Integration Policy 
o Cache Policy 
o HTTP Security Policy 
o OAuth Security Policy 
o Paging Policy 
o Pipeline Policy 
o WS-Security Asymmetric Binding Policy 
o WS-Security Message Policy 
o WS-Security Supporting Tokens Policy 
o WS-Security Symmetric Binding Policy 
o WS-Security Transport Binding Policy 
o WS-Addressing Policy 
o WS-Auditing SOAP Message Policy 
o WS-Auditing SOAP Service Policy 
o WS-Auditing Service Policy 
o WS-Auditing Transaction Tracking Policy 
o XML Policy 
Quality Of Service Policies 
o Bandwidth Quota Policy 
o Concurrency Quota Policy 
o Script Policy 
o Service Level Enforcement Policy 
o Service Level Policy 
o Throughput Quota Policy 
o Timeout Policy 
Compliance Policies 
o Aggregate 
o Script 
o WSI BP 
o XQuery
Design Complex Process Orchestrations 
Execute JavaScript on the API Gateway to Modify Request 
and Response Data and to invoke APIs with Branching 
conditions for Content Based Routing and API Response 
Aggregation
Monitor the Mesh
Manage Mobile App Access To Your 
Mesh with a Developer Portal 
• A social developer engagement 
platform 
• Integrated API documentation 
• App access provisioning and 
monitoring 
• Integrated discussion and newsfeeds 
• Trouble ticket management 
• Search with full content indexing 
• API and App privacy and group 
management – essential for B2B and 
partner APIs 
• Federation to enable new business 
models
Multisite Meshes 
Internet Zero Trust (I0T) Architecture 
IoT Mesh 
IoT Mesh 
IoT Mesh
Demo / Q&A
Restrict IoT API Operations with Scope Mappings
Manage Acceptance of API Legal Agreements
Quickly Test API OAuth Client App Integration
Verify Public Scope Tokens Cannot Access 
Private Scoped Operations
Enforce SLAs to Throttle Requests Per Minute
Manage IoT API Documentation with Swagger
Generate Self-Service IoT API Usage Reports
Generate Self-Service IoT API Usage Reports
Generate Self-Service IoT API Usage Reports
Generate Self-Service IoT API Usage Reports
Generate Self-Service IoT API Usage Reports
View Alerts and Participate in Discussion Boards

More Related Content

What's hot (20)

PPTX
London Adapt or Die: Securing your APIs the Right Way!
Apigee | Google Cloud
 
PPTX
Powering Internal API Communities
Akana
 
PPTX
Enterprise API Adoption Patterns
Akana
 
PDF
How Apigee Api Management Platform Helps with Digital Excellence
Ram Kumar
 
PPTX
Open api in enterprise
Guru Lakshmeekar B
 
PPTX
API Frenzy: API Strategy 101
Akana
 
PDF
Intel Mashery API Management Solution
David Gevorkyan
 
PPTX
Deep-Dive: Secure API Management
Apigee | Google Cloud
 
PDF
Redefine Omni-Channel Retailing - Harness the Power of APIs
Apigee | Google Cloud
 
PDF
Be My API How to Implement an API Strategy Everyone will Love
CA API Management
 
PPTX
Adapt or Die Sydney - API Security
Apigee | Google Cloud
 
PDF
London Adapt or Die: Opening Keynot
Apigee | Google Cloud
 
PPTX
API Management
Roger van de Kimmenade
 
PDF
Azure api management
JoTechies
 
PPT
API Strategy Presentation
Lawrence Coburn
 
PPTX
A New Breed of Technical Leaders: The 101 to Defining Your API Business Stra...
Akana
 
PDF
WSO2Con EU 2015: Towards a Winning API Strategy
WSO2
 
PPTX
API Design Best Practices & Tech Talk : API Craft Meetup @ Apigee
Anil Sagar
 
PPTX
API Services: Building State-of-the-Art APIs
Apigee | Google Cloud
 
PPTX
API Management in Digital Transformation
Aditya Thatte
 
London Adapt or Die: Securing your APIs the Right Way!
Apigee | Google Cloud
 
Powering Internal API Communities
Akana
 
Enterprise API Adoption Patterns
Akana
 
How Apigee Api Management Platform Helps with Digital Excellence
Ram Kumar
 
Open api in enterprise
Guru Lakshmeekar B
 
API Frenzy: API Strategy 101
Akana
 
Intel Mashery API Management Solution
David Gevorkyan
 
Deep-Dive: Secure API Management
Apigee | Google Cloud
 
Redefine Omni-Channel Retailing - Harness the Power of APIs
Apigee | Google Cloud
 
Be My API How to Implement an API Strategy Everyone will Love
CA API Management
 
Adapt or Die Sydney - API Security
Apigee | Google Cloud
 
London Adapt or Die: Opening Keynot
Apigee | Google Cloud
 
API Management
Roger van de Kimmenade
 
Azure api management
JoTechies
 
API Strategy Presentation
Lawrence Coburn
 
A New Breed of Technical Leaders: The 101 to Defining Your API Business Stra...
Akana
 
WSO2Con EU 2015: Towards a Winning API Strategy
WSO2
 
API Design Best Practices & Tech Talk : API Craft Meetup @ Apigee
Anil Sagar
 
API Services: Building State-of-the-Art APIs
Apigee | Google Cloud
 
API Management in Digital Transformation
Aditya Thatte
 

Viewers also liked (17)

PDF
API Description Languages
Akana
 
PPTX
API Description Languages: Which is the Right One for Me?
Akana
 
PPT
Java findamentals1
Todor Kolev
 
PPT
JAVA Tutorial- Do's and Don'ts of Java programming
Keshav Kumar
 
PDF
Caixa Empreender Award | Mesh App (BGI)
Caixa Geral Depósitos
 
PPTX
Lamdba micro service using Amazon Api Gateway
Mike Becker
 
PPTX
Module 10 - Session 2 ICTs and environmental observation 20110223
Richard Labelle
 
PPTX
Are APIs and SOA Converging?
Akana
 
PPTX
Best Practices: The Role of API Management
Akana
 
PDF
HP Wearables and IoT - Our Story - Christine Hawkins
WithTheBest
 
PDF
AI Then & Now
Narrative Science
 
PDF
IoT the driver of Business Innovation: better products, new services and...
Eurotech
 
PPTX
The Business Value for Internal APIs in the Enterprise
Akana
 
PDF
Outlook on Artificial Intelligence in the Enterprise 2016
Narrative Science
 
PPTX
The internet of things the next technology revolution
usman sarwar
 
PDF
Customer Segmentation: Design and Delivery (Webinar)
CGAP
 
PDF
Iot 1906 - approaches for building applications with the IBM IoT cloud
PeterNiblett
 
API Description Languages
Akana
 
API Description Languages: Which is the Right One for Me?
Akana
 
Java findamentals1
Todor Kolev
 
JAVA Tutorial- Do's and Don'ts of Java programming
Keshav Kumar
 
Caixa Empreender Award | Mesh App (BGI)
Caixa Geral Depósitos
 
Lamdba micro service using Amazon Api Gateway
Mike Becker
 
Module 10 - Session 2 ICTs and environmental observation 20110223
Richard Labelle
 
Are APIs and SOA Converging?
Akana
 
Best Practices: The Role of API Management
Akana
 
HP Wearables and IoT - Our Story - Christine Hawkins
WithTheBest
 
AI Then & Now
Narrative Science
 
IoT the driver of Business Innovation: better products, new services and...
Eurotech
 
The Business Value for Internal APIs in the Enterprise
Akana
 
Outlook on Artificial Intelligence in the Enterprise 2016
Narrative Science
 
The internet of things the next technology revolution
usman sarwar
 
Customer Segmentation: Design and Delivery (Webinar)
CGAP
 
Iot 1906 - approaches for building applications with the IBM IoT cloud
PeterNiblett
 
Ad

Similar to Manage Your Mesh (20)

PPTX
Manage Your Mesh
Akana
 
PDF
[Workshop] API-driven Integration
WSO2
 
PPTX
API Gateways are going through an identity crisis
Christian Posta
 
PDF
API, Integration, and SOA Convergence
Kasun Indrasiri
 
PDF
What's new in API Connect and DataPower - 2019
IBM DataPower Gateway
 
PPTX
Gateway/APIC security
Shiu-Fun Poon
 
PDF
2016 06 - design your api management strategy - axway - Api Management
SmartWave
 
PDF
APIConnect Security Best Practice
Shiu-Fun Poon
 
PDF
IoT - Unit 1 Chapter 1 (Introduction to Embedded Systems) - PPT.pdf
dipakraut82
 
PDF
IoT material revised edition
pavan penugonda
 
PDF
Chapter-1_embedded syustem iot.pdf
JohnMcClaine2
 
PDF
Chapter-1.pdf
ssuser01a3d0
 
PDF
unit 3.pdf
KavithaK23
 
PPT
IOT UNIT 1B.ppt
madhavanmohan1
 
PPTX
chapter-1_iot.pptx
RAHULRAJ438202
 
PDF
Agile integration activation: get hands on with ap-is
Judy Breedlove
 
PPTX
unit1-iot introduction,logical design ,physical design
thirupathireddy80
 
PPTX
Rapid Mobile App to API Integration
Akana
 
PPTX
1427264023243345TGFGBBGHGJKU6Y767GGGBGGH
arcse1
 
PDF
[WSO2Con EU 2018] Blockchain in the Business API Ecosystem - API Consumption ...
WSO2
 
Manage Your Mesh
Akana
 
[Workshop] API-driven Integration
WSO2
 
API Gateways are going through an identity crisis
Christian Posta
 
API, Integration, and SOA Convergence
Kasun Indrasiri
 
What's new in API Connect and DataPower - 2019
IBM DataPower Gateway
 
Gateway/APIC security
Shiu-Fun Poon
 
2016 06 - design your api management strategy - axway - Api Management
SmartWave
 
APIConnect Security Best Practice
Shiu-Fun Poon
 
IoT - Unit 1 Chapter 1 (Introduction to Embedded Systems) - PPT.pdf
dipakraut82
 
IoT material revised edition
pavan penugonda
 
Chapter-1_embedded syustem iot.pdf
JohnMcClaine2
 
Chapter-1.pdf
ssuser01a3d0
 
unit 3.pdf
KavithaK23
 
IOT UNIT 1B.ppt
madhavanmohan1
 
chapter-1_iot.pptx
RAHULRAJ438202
 
Agile integration activation: get hands on with ap-is
Judy Breedlove
 
unit1-iot introduction,logical design ,physical design
thirupathireddy80
 
Rapid Mobile App to API Integration
Akana
 
1427264023243345TGFGBBGHGJKU6Y767GGGBGGH
arcse1
 
[WSO2Con EU 2018] Blockchain in the Business API Ecosystem - API Consumption ...
WSO2
 
Ad

More from Akana (16)

PPTX
Lifecycle Manager and the Lifecycle API
Akana
 
PPTX
Intermediary for Microsoft: Product Overview and Demo
Akana
 
PPTX
API Security: Securing Digital Channels and Mobile Apps Against Hacks
Akana
 
PPTX
Driving Business Partner Adoption with APIs
Akana
 
PPTX
Jumping Ahead with Enterprise APIs
Akana
 
PPTX
API and SOA: Two Sides of the Same Coin?
Akana
 
PPTX
The Datacenter API
Akana
 
PPTX
Turbo Charge DataPower to Reach Your SOA Goals
Akana
 
PPTX
The API Economy is Here: Facebook, Twitter, Netflix and Your IT Enterprise
Akana
 
PPTX
Using APIs
Akana
 
PPTX
Using APIs for better Business Partnerships
Akana
 
PPTX
API Security: Does My Business Need OAuth?
Akana
 
PPTX
API Management - A Transformation
Akana
 
PPTX
A Peek Into The Future of Mobile-Enabled Health Care
Akana
 
PPTX
Unified Security for Mobile, APIs and the Web
Akana
 
PPTX
API Frenzy: The Implications and Planning for a Successful API Strategy
Akana
 
Lifecycle Manager and the Lifecycle API
Akana
 
Intermediary for Microsoft: Product Overview and Demo
Akana
 
API Security: Securing Digital Channels and Mobile Apps Against Hacks
Akana
 
Driving Business Partner Adoption with APIs
Akana
 
Jumping Ahead with Enterprise APIs
Akana
 
API and SOA: Two Sides of the Same Coin?
Akana
 
The Datacenter API
Akana
 
Turbo Charge DataPower to Reach Your SOA Goals
Akana
 
The API Economy is Here: Facebook, Twitter, Netflix and Your IT Enterprise
Akana
 
Using APIs
Akana
 
Using APIs for better Business Partnerships
Akana
 
API Security: Does My Business Need OAuth?
Akana
 
API Management - A Transformation
Akana
 
A Peek Into The Future of Mobile-Enabled Health Care
Akana
 
Unified Security for Mobile, APIs and the Web
Akana
 
API Frenzy: The Implications and Planning for a Successful API Strategy
Akana
 

Recently uploaded (20)

PDF
Latest Scam Shocking the USA in 2025.pdf
onlinescamreport4
 
PPTX
办理方法西班牙假毕业证蒙德拉贡大学成绩单MULetter文凭样本
xxxihn4u
 
PPTX
The Latest Scam Shocking the USA in 2025.pptx
onlinescamreport4
 
PPTX
AI at Your Side: Boost Impact Without Losing the Human Touch (SXSW 2026 Meet ...
maytaldahan
 
PDF
Data Protection & Resilience in Focus.pdf
AmyPoblete3
 
PPTX
Different Generation Of Computers .pptx
divcoder9507
 
PPTX
B2B_Ecommerce_Internship_Simranpreet.pptx
LipakshiJindal
 
PPT
1965 INDO PAK WAR which Pak will never forget.ppt
sanjaychief112
 
PPTX
How tech helps people in the modern era.
upadhyayaryan154
 
PPTX
dns domain name system history work.pptx
MUHAMMADKAVISHSHABAN
 
PPTX
Pengenalan perangkat Jaringan komputer pada teknik jaringan komputer dan tele...
Prayudha3
 
DOCX
An_Operating_System by chidi kingsley wo
kingsleywokocha4
 
PPT
Introduction to dns domain name syst.ppt
MUHAMMADKAVISHSHABAN
 
PDF
LOGENVIDAD DANNYFGRETRRTTRRRTRRRRRRRRR.pdf
juan456ytpro
 
PPTX
Perkembangan Perangkat jaringan komputer dan telekomunikasi 3.pptx
Prayudha3
 
PPTX
原版北不列颠哥伦比亚大学毕业证文凭UNBC成绩单2025年新版在线制作学位证书
e7nw4o4
 
PPTX
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
PPTX
Artificial-Intelligence-in-Daily-Life (2).pptx
nidhigoswami335
 
PDF
LB# 820-1889_051-7370_C000.schematic.pdf
matheusalbuquerqueco3
 
PDF
GEO Strategy 2025: Complete Presentation Deck for AI-Powered Customer Acquisi...
Zam Man
 
Latest Scam Shocking the USA in 2025.pdf
onlinescamreport4
 
办理方法西班牙假毕业证蒙德拉贡大学成绩单MULetter文凭样本
xxxihn4u
 
The Latest Scam Shocking the USA in 2025.pptx
onlinescamreport4
 
AI at Your Side: Boost Impact Without Losing the Human Touch (SXSW 2026 Meet ...
maytaldahan
 
Data Protection & Resilience in Focus.pdf
AmyPoblete3
 
Different Generation Of Computers .pptx
divcoder9507
 
B2B_Ecommerce_Internship_Simranpreet.pptx
LipakshiJindal
 
1965 INDO PAK WAR which Pak will never forget.ppt
sanjaychief112
 
How tech helps people in the modern era.
upadhyayaryan154
 
dns domain name system history work.pptx
MUHAMMADKAVISHSHABAN
 
Pengenalan perangkat Jaringan komputer pada teknik jaringan komputer dan tele...
Prayudha3
 
An_Operating_System by chidi kingsley wo
kingsleywokocha4
 
Introduction to dns domain name syst.ppt
MUHAMMADKAVISHSHABAN
 
LOGENVIDAD DANNYFGRETRRTTRRRTRRRRRRRRR.pdf
juan456ytpro
 
Perkembangan Perangkat jaringan komputer dan telekomunikasi 3.pptx
Prayudha3
 
原版北不列颠哥伦比亚大学毕业证文凭UNBC成绩单2025年新版在线制作学位证书
e7nw4o4
 
The Internet of Things (IoT) refers to a vast network of interconnected devic...
chethana8182
 
Artificial-Intelligence-in-Daily-Life (2).pptx
nidhigoswami335
 
LB# 820-1889_051-7370_C000.schematic.pdf
matheusalbuquerqueco3
 
GEO Strategy 2025: Complete Presentation Deck for AI-Powered Customer Acquisi...
Zam Man
 

Manage Your Mesh

  • 1. Manage Your Mesh Securing Public Cloud IoT APIs, and Building Private Mesh Trust Domains and Enclaves of Privacy to Integrate a Mesh of “Things” with Integrity & Availability [email protected] Twitter: @iryanb
  • 2. APIs are for any “Thing” and they don’t always belong on the Internet IoT Mesh
  • 3. Wiring Things to Arduinos D1: 2.6 Volt RED LED & 330 Ohm Resistor A0: 3V Volt Motor & 330 Ohm Resistor
  • 4. Tinkering With Things Turn on Buzzer Turn on Motor
  • 5. Programming Things – Protect the Flash API
  • 6. The First Step to Managing your Mesh is with an API Gateway Gateway Security Authentication Protection IAM Integration Encryption Mediation Quality of Service Paging/Caching Orchestration Scripting Public IoT Mesh Private Mesh ProTip: Customer Premise Equipment such as a WiFi Router or Cableboxshould filter API traffic with an embedded gateway
  • 7. Logical Mesh Management Architecture Private Mesh https://iot.mymesh.net/ mynet/status or https://skynet.im/status https://p0st3r.broker.soa.com/v1/skynet/status Public IoT Mesh
  • 8. Use Gateways in the Cloud & Privately Private Mesh “Badge Readers” Private Mesh “Department X” Public Mesh
  • 10. API Policy Configuration Templates Operational Policies o API Consumer Application Security Policy o API DDoS & Malicious Code Protection o Aggregate Policy o Authentication Policy o Authorization Policy o ICAP Antivirus Integration Policy o Cache Policy o HTTP Security Policy o OAuth Security Policy o Paging Policy o Pipeline Policy o WS-Security Asymmetric Binding Policy o WS-Security Message Policy o WS-Security Supporting Tokens Policy o WS-Security Symmetric Binding Policy o WS-Security Transport Binding Policy o WS-Addressing Policy o WS-Auditing SOAP Message Policy o WS-Auditing SOAP Service Policy o WS-Auditing Service Policy o WS-Auditing Transaction Tracking Policy o XML Policy Quality Of Service Policies o Bandwidth Quota Policy o Concurrency Quota Policy o Script Policy o Service Level Enforcement Policy o Service Level Policy o Throughput Quota Policy o Timeout Policy Compliance Policies o Aggregate o Script o WSI BP o XQuery
  • 11. Design Complex Process Orchestrations Execute JavaScript on the API Gateway to Modify Request and Response Data and to invoke APIs with Branching conditions for Content Based Routing and API Response Aggregation
  • 13. Manage Mobile App Access To Your Mesh with a Developer Portal • A social developer engagement platform • Integrated API documentation • App access provisioning and monitoring • Integrated discussion and newsfeeds • Trouble ticket management • Search with full content indexing • API and App privacy and group management – essential for B2B and partner APIs • Federation to enable new business models
  • 14. Multisite Meshes Internet Zero Trust (I0T) Architecture IoT Mesh IoT Mesh IoT Mesh
  • 16. Restrict IoT API Operations with Scope Mappings
  • 17. Manage Acceptance of API Legal Agreements
  • 18. Quickly Test API OAuth Client App Integration
  • 19. Verify Public Scope Tokens Cannot Access Private Scoped Operations
  • 20. Enforce SLAs to Throttle Requests Per Minute
  • 21. Manage IoT API Documentation with Swagger
  • 22. Generate Self-Service IoT API Usage Reports
  • 23. Generate Self-Service IoT API Usage Reports
  • 24. Generate Self-Service IoT API Usage Reports
  • 25. Generate Self-Service IoT API Usage Reports
  • 26. Generate Self-Service IoT API Usage Reports
  • 27. View Alerts and Participate in Discussion Boards