12.07.2015 Views

API Security with CA Layer 7 & CA SiteMinder - Layer 7 Technologies

API Security with CA Layer 7 & CA SiteMinder - Layer 7 Technologies

API Security with CA Layer 7 & CA SiteMinder - Layer 7 Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

DATA SHEET<strong>API</strong> <strong>Security</strong> <strong>with</strong> <strong>CA</strong> <strong>Layer</strong> 7and <strong>CA</strong> <strong>SiteMinder</strong> ®Unifying <strong>Security</strong> Across Web, <strong>API</strong>s & MobileGoing Beyond Web for Cloud & Mobile <strong>with</strong> <strong>API</strong>sEnterprises have traditionally exposed data and applications through internal services or carefullycontrolled Web-based applications. Now, the rise of mobile and cloud technologies is forcing enterprises toopen new channels. Programmable interfaces—or <strong>API</strong>s—are now fundamental to connecting mobile appsand cloud services <strong>with</strong> enterprise data and applications. <strong>API</strong>s enable new revenue models, prepare theenterprise for BYOD and expand the value of existing customer and partner relationships.Accessing enterprise data and applications from the cloud and mobile devices creates novel challengesaround application integration, security, service discovery, developer management, SLA enforcement anddata analytics.<strong>CA</strong> <strong>Layer</strong> 7 provides the industry’s leading <strong>API</strong> security and management platform. The <strong>CA</strong> <strong>Layer</strong> 7 <strong>API</strong><strong>Security</strong> & Management Suite empowers organizations to securely expose existing resources to mobileapps and cloud services via <strong>API</strong>s. <strong>CA</strong> <strong>Layer</strong> 7’s technology: enables organizations to leverage existingapplication investments through protocol adaptation; protects against external threats and inappropriateaccess; reaches new markets and third-party developer networks through an <strong>API</strong> developer portal.Key Benefits/Results<strong>CA</strong> <strong>Layer</strong> 7’s integration <strong>with</strong> <strong>CA</strong> <strong>SiteMinder</strong>allows you to:• Extend Internal SSO – Enable <strong>API</strong> accesscontrol using existing identity stores• Enable Mobile & BYOD – Expose OAuthand OpenID Connect mobile interfaces toenterprise data assets and bridge to internalidentities• Enforce Identity Policies – Dynamicallyenforce mediation policies based on identityattributes from <strong>SiteMinder</strong>The Role of Identity in <strong>API</strong> ManagementIdentity is a cornerstone of enterprise-grade <strong>API</strong> security and management. Mobileapplications, in particular, require a layered identity model in which the mobile end user,application developer and internal data access persona can each represent uniqueidentities that can be authenticated, authorized, mapped and managed.Identity defines these access rules but also forms the bedrock for defining enhanced userprofiles and available actions. Routing, versioning, traffic shaping, throttling andmediation decisions can all be made dynamically, based on the identities of the involvedparties, as well as contextual information about the transaction.Many enterprises have made investments in identity management solutions thatrepresent internal or Web-based identities for secure Single Sign-On (SSO). <strong>CA</strong> <strong>SiteMinder</strong>provides the secure, Internet-scale SSO and Web access management that organizationsneed in order to authenticate users and authorize access to Web applications/portals. Itenables the secure delivery of essential information and applications to enterpriseemployees, partners, suppliers and customers, via secure SSO.<strong>CA</strong> <strong>Layer</strong> 7 & <strong>CA</strong> <strong>SiteMinder</strong> Enable New Enterprise AccessThe combination of <strong>Layer</strong> 7 and <strong>CA</strong> <strong>SiteMinder</strong> enables an identity-centric <strong>API</strong> security andmanagement infrastructure for powerful mobile and cloud initiatives. Common use cases include:• Creating a unified security view across Web, <strong>API</strong>, mobile and cloud, using an existing<strong>SiteMinder</strong> framework• Exposing OAuth for mobile apps, bridging user tokens to <strong>SiteMinder</strong> identity tokens anddelegating authorization

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!