Contents. Overview 1 SENTINET



Similar documents
Contents Huntcliff, Suite 1350, Atlanta, Georgia, 30350, USA

Sentinet for BizTalk Server SENTINET

Sentinet for BizTalk Server SENTINET 3.1

Sentinet for Windows Azure SENTINET

Cloud Deployment Models

AquaLogic Service Bus

BEA AquaLogic Integrator Agile integration for the Enterprise Build, Connect, Re-use

Apigee Gateway Specifications

Part 2: The Neuron ESB

New Features in Neuron ESB 2.6

Increasing IT flexibility with IBM WebSphere ESB software.

SOA REFERENCE ARCHITECTURE: SERVICE TIER

Oracle SOA Suite: The Evaluation from 10g to 11g

Service Virtualization: Managing Change in a Service-Oriented Architecture

An Oracle White Paper October Maximize the Benefits of Oracle SOA Suite 11g with Oracle Service Bus

SERVICE ORIENTED ARCHITECTURE

Introduction to WebSphere Process Server and WebSphere Enterprise Service Bus

Developing Windows Azure and Web Services

This module provides an overview of service and cloud technologies using the Microsoft.NET Framework and the Windows Azure cloud.

Jitterbit Technical Overview : Microsoft Dynamics CRM

Increasing IT flexibility with IBM WebSphere ESB software.

The bridge to delivering digital applications across cloud, mobile and partner channels

API Management: Powered by SOA Software Dedicated Cloud

Tomáš Müller IT Architekt 21/04/2010 ČVUT FEL: SOA & Enterprise Service Bus IBM Corporation

Service-Oriented Architectures

Oracle Service Bus Examples and Tutorials

An enterprise- grade cloud management platform that enables on- demand, self- service IT operating models for Global 2000 enterprises

Managing SOA Security and Operations with SecureSpan

ORACLE MOBILE SUITE. Complete Mobile Development Solution. Cross Device Solution. Shared Services Infrastructure for Mobility

AquaLogic ESB Design and Integration (3 Days)

A standards-based approach to application integration

Pervasive Software + NetSuite = Seamless Cloud Business Processes

"An infrastructure that a company uses for integrating services in the application landscape."

Oracle SOA Suite Then and Now:

Nastel Technologies 48 South Service Road Melville, NY, USA Copyright 2014 Nastel Technologies, Inc.

A Survey Study on Monitoring Service for Grid

Jitterbit Technical Overview : Salesforce

MS 20487A Developing Windows Azure and Web Services

SONIC ESB 7. KEY CAPABILITIES > Connects, mediates and controls. KEY BENEFITS > Creates new processes using

IBM WebSphere ILOG Rules for.net

The Enterprise Service Bus: Making Service-Oriented Architecture Real

Ikasan ESB Reference Architecture Review

HP SOA Systinet software

Secure Identity Propagation Using WS- Trust, SAML2, and WS-Security 12 Apr 2011 IBM Impact

Enterprise IT is complex. Today, IT infrastructure spans the physical, the virtual and applications, and crosses public, private and hybrid clouds.

Avoiding Web Services Chaos with WebSphere Service Registry and Repository

CHAPTER 1 INTRODUCTION

ESB Features Comparison

IBM API Management Overview IBM Corporation

WebSphere Integration Solutions. IBM Day Minsk Anton Litvinov WebSphere Connectivity Professional Central Eastern Europe

Creating a Strong Security Infrastructure for Exposing JBoss Services

Using Layer 7 s API Gateway for vcloud Architectures How to achieve abstraction, security and management of vcloud APIs.

Redbook Overview Patterns: SOA Design with WebSphere Message Broker and WebSphere ESB

Ultimus Adaptive BPM Suite V8

Setting Up an AS4 System

MS 10978A Introduction to Azure for Developers

SCA-based Enterprise Service Bus WebSphere ESB

Extend and Enhance AD FS

Request for Information (RFI) Supply of information on an Enterprise Integration Solution to CSIR

Service-Oriented Architecture and Software Engineering

EBS SOA Integration Options

CISCO ACE XML GATEWAY TO FORUM SENTRY MIGRATION GUIDE

WHITE PAPER. Talend Enterprise ESB Technical Overview

ebay : How is it a hit

Vistara Lifecycle Management

The Way to SOA Concept, Architectural Components and Organization

Outlook. Corporate Research and Technologies, Munich, Germany. 20 th May 2010

The webmethods ESB. The Foundation of your SOA. Jean-Michel Ghyoot, Principal Solution Architect, March 28, 2013

MOC DEVELOPING WINDOWS AZURE AND WEB SERVICES

Principles and Foundations of Web Services: An Holistic View (Technologies, Business Drivers, Models, Architectures and Standards)

Securely Managing and Exposing Web Services & Applications

ORACLE SOA SUITE. Product Overview

Developing Windows Azure and Web Services

Introduction to Service Oriented Architecture (SOA)

Chapter 2 TOPOLOGY SELECTION. SYS-ED/ Computer Education Techniques, Inc.

Jitterbit Technical Overview : Microsoft Dynamics AX

WCF WINDOWS COMMUNICATION FOUNDATION OVERVIEW OF WCF, MICROSOFTS UNIFIED COMMUNICATION FRAMEWORK FOR.NET APPLICATIONS

JBOSS ENTERPRISE SOA PLATFORM AND JBOSS ENTERPRISE DATA SERVICES PLATFORM VALUE PROPOSITION AND DIFFERENTIATION

A Comprehensive Solution for API Management

Evaluating.NET-Based Enterprise Service Bus Solutions

LinuxWorld Conference & Expo Server Farms and XML Web Services

Motivation Definitions EAI Architectures Elements Integration Technologies. Part I. EAI: Foundations, Concepts, and Architectures

How To Create A C++ Web Service

IT Exam Training online / Bootcamp

Elastic Application Platform for Market Data Real-Time Analytics. for E-Commerce

Federal Enterprise Architecture and Service-Oriented Architecture

SOA Fundamentals For Java Developers. Alexander Ulanov, System Architect Odessa, 30 September 2008

Service Mediation. The Role of an Enterprise Service Bus in an SOA

JOURNAL OF OBJECT TECHNOLOGY

CloudCenter Full Lifecycle Management. An application-defined approach to deploying and managing applications in any datacenter or cloud environment

Securely. Mobilize Any Business Application. Rapidly. The Challenge KEY BENEFITS

CA Single Sign-On r12.x (CA SiteMinder) Implementation Proven Professional Exam

SIF 3: A NEW BEGINNING

Speed SOA development and time to value with IBM WebSphere Enterprise Service Bus Registry Edition

Cisco AON Secure File Transfer Extension Module

PUR1311/19. Request for Information (RFI) Provision of an Enterprise Service Bus. to the. European Bank for Reconstruction and Development

EAI OVERVIEW OF ENTERPRISE APPLICATION INTEGRATION CONCEPTS AND ARCHITECTURES. Enterprise Application Integration. Peter R. Egli INDIGOO.

SharePoint 2013 Business Connectivity Services Hybrid Overview

Introduction to UDDI: Important Features and Functional Concepts

Accelerate your SOA Projects through Service Simulation

Transcription:

Overview SENTINET

Overview 1 Contents Introduction... 3 Customer Benefits... 4 Development and Test... 4 Production and Operations... 5 Architecture... 5 Technology Stack... 8 Features Summary... 8 Sentinet Repository and design-time Governance... 8 Sentinet Runtime Management... 9 Protocols and Standards support... 9 Virtualization and Mediation... 9 Security... 10 Messages Processing and Transformations... 10 Routing... 11 Monitoring... 11 Service Level Agreements Management... 11 Alerting... 11 Testing... 12 Reporting... 12 Auditing... 12 Integration with Microsoft Azure cloud platform and Windows Server Service Bus... 12 Deployment Topologies... 12 System Requirements... 12 Services Virtualization and Mediation... 13 Communication and Security Mediation... 13 Authorization and Federated Security... 15 Routing and Versioning... 17 Services Aggregation... 18 Monitoring... 19 Service Agreements Management... 22 Alerting... 22

Overview 2 Auditing and Change Notifications... 23 Dependencies tracking and impact analysis... 23 Testing... 24

Overview 3 Introduction Nevatech Sentinet platform is a software middleware infrastructure that manages heterogeneous SOA and API services and applications deployed on-premises, in the cloud, or in hybrid environments. Sentinet provides customers integration architectures with design-time Governance and automated run-time API Management. All enterprise service applications face the same common infrastructural challenges services availability and accessibility, discovery, security, monitoring, auditing, service agreements and service level objectives management, alerting and many others. These common infrastructural challenges are typically not part of an organization s core business and can be addressed by middleware infrastructure tools and products that save time and resources. Development teams are enabled with faster time-tomarket delivery of their business solutions, while operations teams are equipped with tools and procedures to manage and maintain production systems in a consistent and predictable environment. The most effective and popular means of addressing common SOA and API infrastructure challenges is based on the concept of services virtualization or services brokerage. Services virtualization introduces the notion of the software agents or brokers that mediate communication between consumer and provider applications and implement dynamic, remote and non-invasive management of common infrastructure and operational tasks. Services virtualization is the only concept that enables SOA and API solutions with non-intrusive management and provides them with the real agility to adapt to continuous changes. Nevatech Sentinet software platform is the only market implementation of the services virtualization concept that is built entirely on the Microsoft platform and fully integrates with, and extends, Microsoft SOA offerings. Sentinet software platform is certified for Works for Windows 2008 R2 Server, Certified for Windows Server 2012/ 2012 R2 and Powered by Microsoft Azure. Sentinet supports and leverages industry standards and manages common infrastructure challenges for any heterogeneous SOA and API solutions, whether they are developed on the Microsoft platform or not. Sentinet is most beneficial to organizations that leverage a Microsoft platform to develop and operate their SOA and API solutions, and those organizations that have to integrate and mediate Microsoft and non-microsoft technologies as part of their SOA architectures. Sentinet is a unified middleware software infrastructure solution for on-premises, cloud and hybrid environments. It can operate in any of these diverse network configurations, and it can manage an organization s SOA and API solutions deployed and operated on-premises, in the cloud or in hybrid environments. Sentinet is the only middleware infrastructure that fully integrates with, and extends capabilities of the Microsoft Azure cloud platform. Sentinet provides organizations with connectivity and integrations across enterprise and cloud applications by enriching them with dynamic and remote manageability of security, access control, monitoring, alerting, SLAs management and automated testing. Sentinet provides organizations with design-time and run-time governance and automation. Using Sentinet, enterprises implementing service-based applications can realize the full potential of their flexible, standards-based systems.

Overview 4 Sentinet is: Powerful provides complete visibility and manageability of services, discovers problems and provides solutions. Non-intrusive no code or deployment configuration modifications are required for business services. Platform-independent fully supports Microsoft and non-microsoft based architectures. Microsoft focused - runs natively on, fully integrates with, and extends Microsoft on-premises and Microsoft Azure cloud platforms; provides powerful mediation capabilities between Microsoft and non-microsoft services and applications. Versatile can operate on-premises, in the cloud or in the hybrid environments; can manage onpremises or cloud business services. Flexible can be configured to perform a multitude of tasks for each system, service, or request. Secure supports various security standards and custom authentication/authorization schemes; fully supports interoperable and Microsoft-specific protocols and security standards. Extensible provides interoperable Web Services-based public API with multiple extensibility points; integrates with third party or custom management tools and products; customizable through standard Microsoft.NET extensibility points. Easy To Use Rich Internet Application graphical user interface is both powerful and intuitive. Supports variety of industry standards and protocols such as SOAP, REST, JSON, XML, WS-* specifications, HTTP, HTTPS, NET.TCP, MSMQ, Microsoft Azure Service Bus binary exchange. Customer Benefits Customer benefits span across all stages of customers SOA and API solutions life-cycle. Development and Test Sentinet enables development teams with faster time-to-market delivery of their SOA and API solutions by providing: Central SOA and APIs Repository with discoverable and reusable services and their metadata. Standardized and centralized policies enforcement that ensures developers adhere to policies and security models adapted for their projects and solutions. Effective and non-intrusive security policies models implementations. Effective and non-intrusive identities management. Effective and non-intrusive access control management. Effective and non-intrusive performance testing and performance impact analysis.

Overview 5 Powerful and non-intrusive monitoring and message exchanges recording, auditing and troubleshooting. Consumer and provider applications parallel development enablement. Services and consumer applications automated testing. PKI keys and certificates management infrastructure. Extensibility at multiple levels and across a variety of management aspects. Production and Operations Sentinet enables operations team with tools and procedures to operate and maintain production systems in a consistent, reliable and predictable environment by providing: Better understanding of system behaviors. Services accessibility and high-availability management. Policies implementations that automate performance management. Security policies provisioning and security uphold. Remedy for exceptional conditions. Visibility and control without system reconfigurations or redeployments. Identities management and non-invasive access control. Integration with third party identity systems and Federated Security environments. Real-time monitoring that keeps enterprises appraised of applications behavior and their constituent components. Performance and impact analysis. Performance patterns and trends analysis. Service consumption patterns and trends analysis. Active and pro-active alerting. Root-case analysis and auditing. Service Level Agreement and Service Level Objectives management. Architecture Sentinet platform consists of four major components: 1. Sentinet Repository, an on-premises or cloud based MS SQL server database that provides centralized, hierarchical and secure storage for all SOA and API managed software assets, such as services, virtual services, security policies, metadata, authentication/authorization and access control rules, service agreements, identities and identity systems configurations, monitoring

Overview 6 data and auditing trails. Access to the Sentinet Repository is subject to strict security that includes data confidentiality, integrity, authentication and authorization control, and role-based access. Sentinet Repository is enabled with a multi-tenancy that allows partitioning of its content, its visibility and accessibility per specific Sentinet users and user groups. 2. Sentinet Management Services is an API of secure and interoperable SOAP and REST services that provide secure access to the Sentinet Repository. Sentinet Management Services application is used by the Sentinet users and administrators to remotely control the content of the Repository and to drive behavior of all their managed services and APIs. 3. Sentinet Nodes are high-performance, low-latency, scalable intermediary brokers that host dynamic virtual services designed and managed by Sentinet administrators using interactive Sentinet Administrative Console. Sentinet Nodes mediate communication between service consumers and service providers, and through that brokerage they enable integration solutions with multi-dimensional run-time management capabilities. Sentinet Nodes make outbound asynchronous connections to the Sentinet Management Services to dynamically configure themselves via light-weight heartbeat calls. Sentinet Nodes can be deployed as secure gateway proxies or as the agents embedded into application servers. Sentinet Nodes can be deployed within enterprise EAI internal infrastructure, or they can be distributed across on-premises and cloud environments forming a light-way ESB, a Virtual Service Bus of on-premises and Cloud Service Brokers. Sentinet Nodes enable managed services and APIs with agility and control of their connectivity, security, monitoring and auditing - all in a non-intrusive way. Sentinet virtual services hosted on the Sentinet Nodes create an SOA and APIs software reuse environment by allowing aggregation of multiple business services and APIs in a single service with fine-grained control of the aggregate service structure and accessibility. 4. Sentinet Administrative Console is a browser-based Rich Internet Application that enables Sentinet users and administrators with highly interactive, intuitive, secure and remote control of all the aspects of their integration solutions management.

Overview 7 Figure 1. Sentinet High-level Architecture overview.

Overview 8 Technology Stack Even though Sentinet is designed and built to manage heterogeneous services and applications, it is best suited for environments that host Microsoft services, or those that have to integrate Microsoft and non- Microsoft applications. Sentinet is built on top of Microsoft technology stacks and extends its capabilities. Figure 2. Sentinet technology and run-time platform stack. Sentinet is highly extendable through standard Microsoft.NET, WCF and WIF extensibility points, and thorough the Sentinet interoperable Web Services and native.net API interfaces. Features Summary Sentinet Repository and design-time Governance 1. Services discovery and secure access to services metadata. Unlike most of the UDDI-type of registries that provide only references to external metadata or incomplete services metadata, Sentinet Repository stores and provides access to the actual metadata with all associated attributes and artifacts. External links or entire documents can be attached to service description elements. 2. Dynamic metadata updates. Changes made to service definitions and artifacts automatically update relevant metadata by keeping it synchronized with real environment updates. 3. Support for documentation attachments. 4. Support for data schemas storage and retrieval. 5. Full Repository search capabilities. 6. Search and filter for message exchanges based on multiple criteria. 7. Message exchanges tracking. 8. Policies definitions through simple Microsoft WCF binding configurations. 9. Secure Repository access. Only authenticated and authorized users can access Repository.

Overview 9 10. Role-based Repository access. Sentinet Repository includes multi-tenancy and role-based access. 11. Support for standards-based policies and all Microsoft specific policies. 12. Policies automatic synchronization, implementation and enforcement. Sentinet Repository is an active repository. Changes made to the service definitions automatically propagate to the runtime environment ensuring automatic updates and no downtime of the production systems. 13. Service and consumer identities management and governance. 14. Built-in PKI and X.509 Certificates management infrastructure. 15. Service identities provisioning. 16. Sentinet Repository is a centralized storage for the runtime information such as real-time and historical monitoring, alerting, and SLA violations management. 17. Support for services and APIs versioning at design-time and run-time. 18. Services and Service Agreements life-cycle management. 19. Services and APIs access control and access rules management. 20. Systems state, compliance, and operational metrics reporting. 21. Repository export/import capabilities to automate services and APIs migration from development to staging and production environments. 22. Support for SOAP and REST services and APIs. 23. Access to Sentinet Repository via Secure and interoperable Web Service API. 24. Auditing and change notifications. 25. Dependencies tracking and impact analysis. Sentinet Runtime Management Protocols and Standards support Sentinet supports a wide range of standards, protocols and message formats. 1. SOAP, REST and REST to SOAP transformations. 2. All WS-* standards supported by Microsoft WCF technology. 3. XML, JSON, text, binary. 4. HTTP, HTTPS, NET.TCP, NET.MSMQ, MSMQ.FORMATNAME, NET.PIPE, SB (Microsoft Azure Service Bus, Windows Server Service Bus). 5. Authentication a. Windows Kerberos and NTLM b. Windows Group Membership c. Username/Password d. Basic Authentication e. X.509 Certificates f. SAML 1.1, 2.0 g. Federation with ADFS, Microsoft Azure ACS and custom STS Servers. 6. Identity Systems a. Sentinet Repository b. Windows Active Directory c. Extensibility for third party identity systems and custom identity systems. Virtualization and Mediation 1. Services virtualization using drag-and-drop graphical interface.

Overview 10 2. Mediation of transports, policies, message protocols, versions, and encodings. Examples: a. SOAP 1.1 and SOAP 1.2 b. Text, XML, JSON, MTOM, binary, custom message encodings. 3. Identities mapping and transformation. 4. Fine-grained virtualization. Virtualization of all, or only selected business service or API operations. 5. Aggregate virtualization. Aggregation of multiple business services and APIs by a single virtual service with fine grained control of the virtual API operations, endpoints and policies. 6. Bridging interoperable and non-interoperable communication protocols and security models. 7. Messages transformation. 8. Messages validation. 9. Support for interoperable and all Microsoft-specific communication transports. 10. Virtualization of SOAP Services and REST services (SOAP to REST conversion). Security 1. Support for industry standard interoperable and all Microsoft-specific, non-interoperable security models. 2. Support for industry standard and custom security tokens. 3. Support for security Federation and Single-Sign-On scenarios. 4. Support for WS-ReliableMessaging. 5. Support for WS-SecureConversation. 6. Support for and integration with industry standard and custom Security Token Services (STS). For example: Microsoft Azure Access Control Service, Microsoft Azure Active Directory and Microsoft ADFS 2.0 server. 7. Support for and integration with OAuth 2.0 and OpenID Connect security protocols. 8. Support for industry standard and custom authentication schemes. 9. Support for Claims based authentication/authorization and claims aware applications. 10. Support for Identities transformation and Identities pass-through. 11. Sentinet Authorization Engine that provides services and APIs with fine-grained and non-invasive run-time authorization at different service scopes such as service, service interface, service operation, or service endpoint. 12. Access Rules Graphical Designer with extensibility for custom Access Rules. Messages Processing and Transformations 1. Support for XSLT and XDT transformations 2. Support for conversions between XML and JSON formats 3. Support for REST application-level errors 4. Support for Regular Expression transformations 5. Support for string replace transformations 6. Support for HTTP headers processing 7. Support for SOAP headers processing 8. Support for Query Parameters processing 9. Support for Request URL processing and transformations 10. Support for Message Body Replacement transformations 11. Support for message Context Properties and conditional message tranformations 12. Support for Cross-Origin Resource Sharing (CORS) 13. Support for custom message processing components

Overview 11 Routing 1. Dynamic messages routing to different business services, service versions APIs and service endpoints. 2. Built-in load-balancer with fault tolerance. 3. Priority-based routing. 4. Multicast and publish/subscribe routing. 5. Custom routing (content-based, schedule-based, identity-based, geography-based, etc.). Monitoring 1. Real-time and historical transactions monitoring. 2. Messages recording at different message-processing stages such as wire-level monitoring, message transformation monitoring, encrypted and decrypted messages monitoring, protocol bridging monitoring. 3. Errors and business SOAP Faults monitoring. 4. Search for message exchanges by a. Date and time b. Transaction status c. Client IP Address d. Access Rule e. Service Operation f. Request Content g. Response Content 5. Service and APIs performance monitoring. 6. Service and APIs traffic volumes monitoring. 7. Service Level Agreements and Service Level Objectives violations monitoring. 8. Monitoring group of services. 9. Monitoring group of Service Agreements. Service Level Agreements Management 1. Service Level Agreements can cover multiple services and APIs. 2. Service Level Agreements can cover multiple service and API scopes: a. Service scope b. Interface scope c. Operation scope d. Endpoint scope 3. Service Level Agreements per consumer or consumer groups. 4. Service Level Agreements monitored against multiple service metrics such as traffic volume, service availability and performance metrics. 5. Service Level Agreements per specific service access rules. 6. Service Level Agreements per specific time schedules. Alerting 1. Alerts on expiring consumer and service applications X.509 certificates. 2. Alerts on SLA violations, service traffic volumes, service availability and performance metrics. 3. Built-in alert notification targets such as user emails and custom Windows Events. 4. Alerts extensibility via custom alert handlers. For example, send alerts to Microsoft System Center Operations Manager or send SMS messages.

Overview 12 Testing 1. Virtual services testing. 2. Security models testing. 3. Performance implications testing. 4. Auto-generated test responses and fault messages. 5. Service response patterns testing. 6. Pro-active development testing. 7. On-premises and cloud testing. Reporting 1. Reports of the most active, most failed, or least performing services within different time intervals. 2. Reports of the service consumption, performance and availability details. 3. Reports of the service consumptions filtered by Access Rules. 4. Reports for service groups. 5. Reports extensibility via Sentinet interoperable Web Service API. Auditing 1. Auditing of service and API changes. 2. Audit of any Repository object changes. 3. Audit of the Sentinet user sessions. Integration with Microsoft Azure cloud platform and Windows Server Service Bus 1. Integrates with and extends Microsoft Azure Service Bus relay capabilities. 2. Integrates with Microsoft Azure Service Bus asynchronous messaging with support for Queues, Topics and Subscriptions. 3. Integrates with Windows Server Service Bus asynchronous messaging. 4. Integrates with and extends Microsoft Azure Access Control service capabilities. Deployment Topologies 1. Sentinet Node can be deployed as security gateway proxy or as a stand-alone network intermediary. 2. Sentinet Node can be deployed as the agent embedded in the application server. 3. Sentinet fully supports high-availability and redundant deployment topologies. 4. Sentinet Nodes can be deployed within internal EAI/B2B infrastructures, and in the cloud environments. 5. Microsoft Azure deployment topologies include Sentinet Node deployments as native Microsoft Cloud Services Web Roles, sites and Azure Virtual Machines. System Requirements 1. Windows Server 2012, 2012 (R2), Windows Server 2008, 2008 (R2) in production. 2. Can be installed on Windows 7 or Windows 8 for non-production environments. 3..NET 4.5 Framework 4. IIS Server 8.0, 7.5 or 7.0. 5. Microsoft SQL Server 2014, 2012, 2008, 2005 or SQL Azure Database.

Overview 13 Services Virtualization and Mediation When business services are exposed through Sentinet Nodes, they become more accessible to consumer applications. Business services can be developed and deployed with the unified and most effective communications and security implementations, while ultimately exposed to consumer applications using requirements driven by the service s external accessibilities and security models. Consumer or Consumer Application 2 Transport, Security, Protocol, etc. Consumer or Consumer Application 3 Transport, Security, Protocol, etc. Sentinet Node 1 Internal Consumer or Consumer Application 4 Transport, Security, Protocol, etc. Service Figure 3. Service virtualization. Figure 4 shows a business service that is developed, tested and deployed with a unified and optimized internal communications and security implementation (1). Once the service is virtualized through the Sentinet Node, it is exposed to consumer applications through dynamic endpoints hosted on the Sentinet Node using variety of managed communication and security models (2), (3), (4), etc. Consumer applications are decoupled from the business service endpoints location and internal communication and security requirements. Consumers can retrieve virtual service metadata using Sentinet Administrative console or from the optional metadata endpoints that can be remotely opened on the Sentinet Node. Communication and Security Mediation In this sample scenario Microsoft WCF service is deployed with performance-optimized net.tcp transport. WCF binary message encoder is used to provide the smallest message sizes payloads during messages transmission. Windows integrated security is used for optimal performance and strong authentication (1). Both net.tcp transport and binary message encoder are not interoperable and cannot be used by external consumer application that can only support interoperable http(s) transport with standard text message encoder and interoperable transport level security (2), figure 5. A virtual service hosted on the Sentinet Node enables consumer application with the service accessibility by mediating transport and security requirement.

Overview 14 Virtual Service hosted on Sentinet Node Consumer or Consumer Application 2 External 1 Internal Service https:// Text encoder Basic Http Transport security net.tcp:// Binary encoder Windows Integrated Security Figure 4. Communication and Security Mediation. If a new consumer application needs to access business service, and that new consumer application has different supported transport and security capabilities, then Sentinet Node is dynamically configured with additional virtual service endpoints to mediate new transport and security requirements to the same business service implementation. https:// Text encoder Basic Http Transport security Consumer or Consumer Application 2 External Virtual Service hosted on Sentinet Node 1 Internal Consumer or Consumer Application 3 External Service net.tcp:// Binary encoder Windows Integrated Security http:// Text encoder Basic Http Message-level security Figure 5. Multiple virtual endpoints. Consider another hypothetical scenario, when a customer organization makes its mobile application available for its consumers community. Mobile application is designed to make calls to a customer proprietary REST API, as well as it makes use of the public Microsoft Bing Search API. Sentinet will manage both APIs, but most importantly it will leverage organization s private account with Microsoft Bing service to give its mobile applications access to Microsoft Bing Search API. Each mobile application consumer will use his own personal security key that is issued to him by the mobile application provider. Sentinet will authenticate consumers based on their personal security keys and authorize application s access to Microsoft Bing Search API by using privately held Microsoft Bing Primary Account Key.

Overview 15 Note that Microsoft Bing Primary Account Key will be securely stored with the Sentinet Node, while it is not known to, or even distributed to thousands of mobile application installations. Mobile applications do not have dependency on the public Bing API location and even syntax requirements. If public API endpoints or API syntax changes, Sentinet will mediate these changes without affecting existing mobile applications. Consumer with mobile device Consumer with mobile device Personal Security Key 1 Personal Security Key 2 Microsoft Primary Account Key Microsoft Bing Public API... Personal Security Key N Sentinet Node Personal Security Key X Customer Proprietary REST API Consumer with mobile device Figure 6. Mediating security and aggregating REST APIs. Authorization and Federated Security Service authorization logic is often hardcoded in the business service implementation which makes it difficult to scale authorization rules through services, and to promote services through different life cycles and environments. Sentinet provides a highly flexible run-time Authorization Engine and an interactive design-time Access Rules Designer. The authorization Engine executes at the Sentinet Nodes where it enforces custom authorizations rules designed by the Sentinet administrators. Business services can now delegate ultimate authentication and authorization decisions to the Sentinet virtual services, while authenticating and authorizing only trusted Sentinet Nodes.

Overview 16 Consumer Authentication and Authorization is moved out from the service implementation, and delegated to the virtual service Consumer or Consumer Application Trust Service Virtual Service hosted on the Sentinet Node Figure 7. Scalable and non-invasive authorization rules and access control. Sentinet Authorization and Access Control rules are managed declaratively using rich graphical user interface and Access Control Designer. Administrators can control authorized identities, access time schedules, allowed throughput, and content-based access rules. Developers can extend Sentinet Authorization Engine with custom Access Control rules and integrate them in the Sentinet Administrative Console application. Figure 8. Graphical Access Rule Designer.

Overview 17 Sentinet Authorization Engine supports and extends industry standard Security Token Services (STS), including native support and integration with Microsoft Active Directory Federation Services (ADFS) and Microsoft Azure Access Control Service (ACS). Figure 9. Access Control Designer. Routing and Versioning Sentinet provides flexible support for messages routing and services versioning. Not only can Sentinet Nodes be clustered and load-balanced, but they can also execute as load-balancers by routing messages to different business service deployments. Messages can be routed based on a variety of routing rules and criteria such as weighted round-robin, fail-over priority based routing, multi-cast, content based, schedule-based, identity-based or any other custom routing rule. Sentinet Nodes can route messages to different service versions using either endpoints-based or content-based mapping rules.

Overview 18 Figure 10. Sentinet messages Router configuration. Services Aggregation Sentinet allows easy aggregation of multiple business services and APIs within a single virtual service. Services aggregation gives the benefit of software assets reuse. Services implemented as different APIs with different locations, communications and policy requirements, can be exposed to the ultimate consumer applications via unified and standard communication protocols and policies. Sentinet Virtual Service Designer helps to build aggregated virtual services using intuitive drag-and-drop user interface and graphical wizards. Figure 11. Virtual service Designer. Drag-and-drop services to construct an aggregate virtual service.

Overview 19 Monitoring Monitoring APIs and services is not a second-level concern. There is no management and cost control without visibility. Sentinet Administrators can see who is using their business services, when, and how. Sentinet provides extensive message exchanges monitoring, tracking, recording and aggregated statistics that help administrators to analyze current systems states and trends. Using real-time and historical monitoring users can predict services future use, scalability, and performance degradations so that service level agreements are continuously maintained. Figure 12. Real-time monitoring.

Overview 20 Figure 13. Individual Messages Monitoring and Tracking. Figure 14. XML messages recording.

Overview 21 Figure 15. JSON messages recording. Figure 16. Historical Monitoring and Reporting.

Overview 22 Service Agreements Management Sentinet Service Level Agreements (SLA) and Service Level Objectives (SLO) management helps organizations and IT operations to understand and implement best practices for monitoring, diagnostics and reporting in order to maintain reliable and scalable applications. Degradations in IT Service delivery can be costly and damaging to business. Organizations are implementing strict Service Level Agreements to ensure high standards of IT service. Sentinet SLA management infrastructure helps organizations to create, monitor and respond actively and pro-actively on SLAs and operational requirements violations in any type of on-premises or cloud environment. Service Agreements can be validated against multiple performance, service availability and traffic volume metrics, and can cover multiple services at different service scopes filtered by access control rules. Sentinet SLAs manage relationships between service consumers and service providers, and enable administrators with complete visibility and operational performance of their services. SOA administrators can define different SLAs for the same service or group of services, and monitor and alert on SLA violations per individual consumer or group of consumers. Figure 17. Monitoring Service Agreement Violations. Alerting Sentinet provides a powerful and extendable Alerting System that can generate and handle alerts for expiring X.509 certificates, SLAs and operational metrics violations. Alerts can be configured against individual SLAs, with individual frequency generation and more than one Alert Action. Each Alert Action can handle generated alerts differently (for example: Send email, or Send SMS or Text Message). Sentinet Alerting System can be integrated with third party and industry standard Operations and Management Systems (for example: Microsoft SCOM).

Overview 23 Auditing and Change Notifications Sentinet provides complete auditing and change notifications for all SOA and API Repository objects. Figure 18. Repository Auditing. Dependencies tracking and impact analysis Sentinet provides Repository objects dependencies tracking and impact analysis that helps developers and operations to identify impact of their services and API changes on other services and API.

Overview 24 Figure 19. Dependencies diagram. Testing Sentinet provides non-intrusive automated testing and service-mockup capabilities. These features make developers more productive by allowing them to create both parallel and isolated development and test processes. Developers and administrators can test their services performance and security even before services concrete implementations are available. Sentinet helps to simulate and predict production systems behaviors before they are deployed in real environments.

Overview 25 Figure 20. Sample Response Test Messages.