FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT...

6
FINACLE SERVICES: API MANAGEMENT USING CA API GATEWAY

Transcript of FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT...

Page 1: FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT USING ... across development, test & production ... of other companies to the trademarks,

FINACLE SERVICES: API MANAGEMENT USING CA API GATEWAY

Page 2: FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT USING ... across development, test & production ... of other companies to the trademarks,

External Document © 2016 EdgeVerve Systems Limited

Executive Summary

Banks embarking on a digital

transformation in today’s connected

world need to thrive, compete and evolve.

To accelerate this transformation, Banks

need to bring systems together, innovate,

provide better customer experiences and

optimize cost. To optimize cost, increase

revenues and to improve customer

connect, Banks can unlock value of data

and drive innovation by exposing their

internal services to internal teams and

external partners in a seamless and

secured manner.

API management enables Banks to

leverage existing IT systems and

investments by exposing business

services as APIs. As an integral part of

API management solutions, API gateways

offer flexibility, performance and

security. By utilizing the features offered

by API gateway, banks can selectively

expose core banking services offered

by Finacle. CA API Gateway is one such

offering, built on the foundation of SOA

for exposing, securing and managing

backend applications, network systems or

infrastructure via APIs.

CA API Gateway can integrate with existing

IAM solutions in a plug and play manner

and is the best available solution for

enterprises looking to open up data and

services to partners, developers, mobile

apps, cloud services and smart devices. CA

API Gateway includes protocol bridging,

providing full translation between a variety

of protocols—from legacy to REST and

JSON—providing the bridge from legacy to

mobile, cloud, and social. CA API Gateway

can be configured to be PCI-DSS compliant,

and includes a built-in PKI engine, FIPS 140-

2 level encryption, a robust RBAC system,

and SAML support..

Integration approach

The Finacle core banking services are

exposed as APIs through the Finacle

Integration platform. When banks want

to expose these APIs to internal and

external teams, security validations and

access control checks needs to be taken

care of, in-addition to the validation of the

messages. CA API Gateway helps with the

Finacle and CA API management - Integration approach

• Central policy enforcement onoutgoing/ incoming tra�c

• Threat protection and security• Transformations• API monitoring/ management• API analytics• ESB-like web service mediation

Mobile banking App

REST

ful A

PI

GET P

UT P

OST D

ELET

E

DMZRESTful API

GET PUT POST DELETE

Financial institutions,B2B, etc.

¥

Finacleintegrator

CASA

Loans

CIF

l API

DELET

EE

Page 3: FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT USING ... across development, test & production ... of other companies to the trademarks,

External Document © 2016 EdgeVerve Systems Limited

complete API lifecycle and management,

including security, API design, publishing,

versioning, usage and performance.

If we consider the scenario of a bank

launching a new mobile app, the bank can

expose internal data assets and business

services as APIs, and then allow mobile app

developers access in order to build apps

at their own pace; a bank can expose APIs

to partners such as e-commerce websites

in order to process the online payments

with ease; or banks can potentially

outsource the data collection to third party

vendors with CA API Gateway to perform

validations and enforce security, thereby

focusing on the core aspects of its banking

operations.

Integration methodology & approach

• Finacleexposesseveralfinancial

and non-financial business services

through Finacle Integration platform.

These are XML based web services and

can be consumed using endpoints

such as SOAP and HTTP/S

• CAAPImanagementsolutionis

deployed on top of Finacle and

services are exposed to external

world in various modes such as SOAP

services or JSON/REST APIs.

• CRUDoperations(create,read,update

and delete) on the data are supported

through REST APIs exposed in the CA

API Gateway.

• Incaseofrequestssentbyconsumers,

JSON message is accepted from the

clients and JSON to Finacle XML

message format conversion happens

in the API management layer.

• Incaseofresponsessentto

consumers, the APIM layer converts

Finacle XML message to JSON output.

Deployment options

CA API gateway deploys in a variety

of form factors - hardware appliance,

virtual appliance, software & an Amazon

machine instance; easily scales and can be

deployed in a failover environment for high

availability.

Architecture diagram

Outside Partners / Divisions

External Developers

Mobile Apps Cloud Services Internet of Things

APIs/Web Services

Data

Identities

Page 4: FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT USING ... across development, test & production ... of other companies to the trademarks,

External Document © 2016 EdgeVerve Systems Limited

Key benefits• Bankscanadaptthisapproach

without any changes to Finacle

• APIMplatformprovidesdetailed

analytics and operational metrics,

which helps in analyzing how

services are utilized, how APIs

are performing and how APIs

are being used by developers.

These metrics can provide further

insight and help in identifying

new revenue opportunities.

• Providesafoundationfor

introducing new and innovative

services by aggregating existing

business services

• VariousaspectsofAPImanagement

like governance, monetization,

metering, security, etc. can be

well managed using the API

management layer without

impacting the data, security and

availability of the underlying Finacle

core banking system.

• APIrelatedoperationsaretakencare

by the CA API management solution

and the Finacle system focusses

only on providing the banking data,

thereby offering a clean and optimal

solution for the bank’s operations.

• Adaptabilitytowidelyusedforms

like REST services and JSON message

formats can be addressed without

worrying about the backend systems.

• UsingAPImanagementsolution,

we can maintain backward

compatibility by maintaining

multiple versions of API for each

service version.

• CAAPIGatewaycanactasatrusted

partner to Finacle for authenticating

theincomingrequestsagainstLDAP

/ IAM systems.

Throttling Prioritization Caching

Routing Traffic Control Transformation

Security

API – Enable The Data And Services

Composition Authentication Social SSO API Keys Entitlements

OAuth 1.x OAuth 2.0 OpenID Connect

Secure Access to the API

Token Service

Health Tracking

Workflow

Performance Global Staging

Reporting

Config Migration

Patch Management Policy Migration

Manage the API Lifecycle

Developer Enrollment

Manage the Developer Community

API Docs

Forums

API Explorer

Rankings Quotas

Plans

Analytics

Developer Enrollment

Functional overview

Page 5: FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT USING ... across development, test & production ... of other companies to the trademarks,

Key Features

• Security: Passed rigorous vulnerability

tests, and integrates with popular IAM

systems with support for OAuth, SAML

and RADIUS.

• Performance and Scale: Clustered

architecture allows application level

throttling, prioritization and linear

scalability across multiple gateways

with automatic failover.

• Manageability: Handles migrations

across development, test & production

with global management tools,

integrations with enterprise BI,

analytics and reporting tools.

• Flexibility: Multiple form factors/

deployment models with support for

a wide range of platforms. Provides

protocol bridging across legacy & new

systems, and includes content-based

routing.

• Extensibility: Plug-in framework to add

new transports and identity providers,

and deep integration with enterprise

management and BI products.

Page 6: FINACLE SERVICES: API MANAGEMENT USING CA API · PDF fileFINACLE SERVICES: API MANAGEMENT USING ... across development, test & production ... of other companies to the trademarks,

www.finacle.comFor more information, contact [email protected]

©2016 EdgeVerve Systems Limited, awholly owned subsidiaryof Infosys, Bangalore, India.All Rights Reserved.This documentation is the solepropertyof EdgeVerve Systems Limited (“EdgeVerve”).EdgeVerve believes the information in this document or page is accurate as of its publication date; such information is subject to change without notice. EdgeVerve acknowledges the proprietary rights of other companies to the trademarks, product names and such other intellectual property rights mentioned in this document. This document is not for general distribution and is meant for use solely by the person or entity that it has been specifically issued to and can be used for the sole purpose it is intended to be used for as communicated by EdgeVerve in writing. Except as expressly permitted by EdgeVerve in writing, neither this documentation nor any part of it may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, printing, photocopying, recording or otherwise, without the prior written permission of EdgeVerve and/ or any named intellectual property rights holders under this document.

About Infosys FinacleFinacle is the industry-leading universal banking solution from EdgeVerve Systems, a wholly owned subsidiary of Infosys. The solution helps financial institutions develop deeper connections with stakeholders, power continuous innovation and accelerate growth in the digital world. Today, Finacle is the choice of banks across 84 countries and serves over 547 million customers – nearly 16.5 percent of the world’s adult banked population.

Finaclesolutionsaddressthecorebanking,e-banking,mobilebanking,CRM,payments,treasury,origination,liquiditymanagement,Islamic banking, wealth management, and analytics needs of financial institutions worldwide. Assessment of the top 1000 world banks reveals that banks powered by Finacle enjoy 50 percent higher returns on assets, 30 percent higher returns on capital, and 8.1 percent points lesser costs to income than others.

About CACATechnologies(NASDAQ:CA)createssoftwarethatfuelstransformationforcompaniesandenablesthemtoseizetheopportunitiesofthe application economy. Software is at the heart of every business, in every industry. From planning to development to management and security, CA is working with companies worldwide to change the way we live, transact and communicate.

CA software and solutions help our customers drive enterprise-wide productivity, offer differentiated user experiences and open new growth opportunities. And we are able to deliver this value across multiple environments—mobile, private and public cloud, distributed and mainframe. Our goal is to be recognized by our customers as their critical partner in the new application economy. CA Technologies hasbeenrecognizedasavalueleaderbyindustryanalystsandhasbeenhailedasoneofthe“World’s100MostInnovativeCompanies”by Forbes, as well as one of the greenest companies in the United States by Newsweek®.