SlideShare une entreprise Scribd logo
1  sur  2
Télécharger pour lire hors ligne
Copyright © 2013 Layer 7 Technologies Inc. All rights reserved.  SecureSpan and the Layer 7 Technologies design mark are  
trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 
 
Securing Payment APIs Using Layer 7 
Provide Advanced Security & Authorization Mechanisms for Mobile Payments 
Mobility is changing the face of the 
payments ecosystem and predictions 
expect transaction volumes to increase 
tenfold by 2016. The API infrastructure 
supporting mobile payment products 
must incorporate advanced data 
integrity, security and scalability 
features to ensure the successful 
growth of the ecosystem.   
 
Learn More About Layer 7’s Mobile 
Payments Solution 
 Phone 
+1‐800‐681‐9377  
(toll free within North America)  
or +1‐604‐681‐9377 
 Email 
info@layer7.com 
 Web  
www.layer7.com 
 Facebook     
www.facebook.com/layer7 
 Twitter 
@layer7 
 
A look at the Mobile Payments Ecosystem	
With many new payment products coming to market and a variety of 
new technologies available, the mobile payment ecosystem was valued 
at approximately $170B in 2012. This was divided among well‐
established payment networks such as PayPal, closed‐loop services from 
Starbucks, digital wallet services from Visa (V.me) and NFC‐enabled 
mobile wallets like Isis. Despite the clear differences between these – 
and many more – products, each must ensure that every financial 
transaction is completed reliably and securely. This means having a 
scalable API architecture through which payments are processed. 
 
Using Layer 7 as a Secure Payments API Platform	
The Layer 7 API Management Suite offers a range of key features to 
enable a high‐capacity payment platform and supports all the technical 
and regulatory requirements that accompany this. Using the PCI‐DSS‐
compliant Layer 7 API Gateway technology, service providers can ensure 
all payment transactions are appropriately secured and – when 
necessary – encrypted, with additional data validation and verification 
controls in place to guarantee transactional integrity. 
 
Benefits	
Layer 7’s enterprise‐grade solution has been proven across several tier‐
one payment networks and financial institutions, helping to deliver 
scalable API infrastructure for a variety of payment products. The key 
benefits include: 
1. PCI‐DSS compliance for data security and end‐to‐end  
transport encryption 
2. Advanced OAuth tools to enable context‐based authorization 
and broker cloud‐based payment credentials 
3. Data validation and verification to ensure transactional integrity 
 
Copyright © 2013 Layer 7 Technologies Inc. All rights reserved.  SecureSpan and the Layer 7 Technologies design mark are  
trademarks of Layer 7 Technologies Inc. All other trademarks and copyrights are the property of their respective owners. 
 Key Features	
Traffic Management 
CoS Routing   Prioritize traffic based on class of service/quality of service preferences 
Service Availability 
Management 
 Manage routing to backend services, based on availability, latency or performance 
Reporting & Auditing 
 Generate configurable, out‐of‐the‐box reports to get insight into platform operations and 
service‐level performance and to support non‐repudiation 
Threat Protection 
Filter XML & REST/JSON 
Content for Mobile & Web 
 Validate and filter HTTP headers, parameters and form data  
 Identify and suppress leakage of sensitive information (e.g. credit card numbers) 
 Support REST, AJAX, XML, SOAP, POX and other XML‐based services  
Protect Transactional 
Integrity 
 Protect against identity spoofing and session hijacking, cluster wide  
 Assure integrity of communication, end to end  
Prevent XML/JSON Attack 
& Intrusion 
 Protect against: XML parsing; XDoS and OS attacks; SQL and malicious scripting language 
injection attacks; external entity attacks  
 Protect against XML content tampering and viruses in SOAP attachments  
Regulatory Compliance 
PCI‐DSS 
 PCI‐DSS installation and configuration guide makes it possible to configure and deploy the 
API Management Suite as part of a PCI‐compliant process 
Identity & Security 
Secure OAuth 
Implementation 
 Supports OAuth 1.0a, OAuth WRAP and OAuth 2.0  
 Provides sample two‐ and three‐legged OAuth implementations that can be configured  
to your needs 
Encryption 
 Support for TLS/SSL encryption over the wire  
 Support for a variety of cryptographic algorithms, including HMAC, RSA and SHA 
Form Factors 
Hardware   Active‐active clusterable, mirrored hot‐swappable drives, multi‐core 1U server 
Software    Solaris 10 for x86 and Niagara, SUSE Linux, Red Hat Linux 4.0/5.0  
Virtual & Cloud   VMware/ESX (VMware Ready Certified) 
To learn more about Layer 7, call us today at +1‐800‐681‐9377 (toll free within North America) or +1‐604‐681‐9377. 
You can also: email us at info@layer7.com; friend us on Facebook at facebook.com/layer7; visit us at layer7.com; 
follow us on Twitter (@layer7). 

Contenu connexe

En vedette

Daum APIs: A to Z - API Meetup 2014
Daum APIs: A to Z  - API Meetup 2014Daum APIs: A to Z  - API Meetup 2014
Daum APIs: A to Z - API Meetup 2014
Channy Yun
 
API Management architect presentation
API Management architect presentationAPI Management architect presentation
API Management architect presentation
sflynn073
 

En vedette (18)

Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
 
Designing & Implementing Hypermedia APIs – Mike Amundsen, Principal API Archi...
Designing & Implementing Hypermedia APIs – Mike Amundsen, Principal API Archi...Designing & Implementing Hypermedia APIs – Mike Amundsen, Principal API Archi...
Designing & Implementing Hypermedia APIs – Mike Amundsen, Principal API Archi...
 
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
 
APIs for biz dev 2.0 - Which business model to win in the API Economy?
APIs for biz dev 2.0 - Which business model to win in the API Economy?APIs for biz dev 2.0 - Which business model to win in the API Economy?
APIs for biz dev 2.0 - Which business model to win in the API Economy?
 
RESTful Web APIs – Mike Amundsen, Principal API Architect, Layer 7
RESTful Web APIs – Mike Amundsen, Principal API Architect, Layer 7RESTful Web APIs – Mike Amundsen, Principal API Architect, Layer 7
RESTful Web APIs – Mike Amundsen, Principal API Architect, Layer 7
 
Introducing Swagger
Introducing SwaggerIntroducing Swagger
Introducing Swagger
 
Daum APIs: A to Z - API Meetup 2014
Daum APIs: A to Z  - API Meetup 2014Daum APIs: A to Z  - API Meetup 2014
Daum APIs: A to Z - API Meetup 2014
 
API Security and Management Best Practices
API Security and Management Best PracticesAPI Security and Management Best Practices
API Security and Management Best Practices
 
Swagger - make your API accessible
Swagger - make your API accessibleSwagger - make your API accessible
Swagger - make your API accessible
 
Definitive Guide to API Management
Definitive Guide to API ManagementDefinitive Guide to API Management
Definitive Guide to API Management
 
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
 
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
 
API Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your DataAPI Monetization: Unlock the Value of Your Data
API Monetization: Unlock the Value of Your Data
 
Mastering Digital Channels with APIs
Mastering Digital Channels with APIsMastering Digital Channels with APIs
Mastering Digital Channels with APIs
 
Best Practices for API Management
Best Practices for API Management Best Practices for API Management
Best Practices for API Management
 
Open API and API Management - Introduction and Comparison of Products: TIBCO ...
Open API and API Management - Introduction and Comparison of Products: TIBCO ...Open API and API Management - Introduction and Comparison of Products: TIBCO ...
Open API and API Management - Introduction and Comparison of Products: TIBCO ...
 
Takeaways from API Security Breaches Webinar
Takeaways from API Security Breaches WebinarTakeaways from API Security Breaches Webinar
Takeaways from API Security Breaches Webinar
 
API Management architect presentation
API Management architect presentationAPI Management architect presentation
API Management architect presentation
 

Plus de CA API Management

5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer apps
CA API Management
 

Plus de CA API Management (20)

Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
 
Enabling the Multi-Device Universe
Enabling the Multi-Device UniverseEnabling the Multi-Device Universe
Enabling the Multi-Device Universe
 
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
 
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
 
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
 
Adapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & WinAdapting to Digital Change: Use APIs to Delight Customers & Win
Adapting to Digital Change: Use APIs to Delight Customers & Win
 
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
 
5 steps end to end security consumer apps
5 steps end to end security consumer apps5 steps end to end security consumer apps
5 steps end to end security consumer apps
 
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
 
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...Gartner AADI Summit Sydney 2014   Implementing the Layer 7 API Management Pla...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
 
Using APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail ExperienceUsing APIs to Create an Omni-Channel Retail Experience
Using APIs to Create an Omni-Channel Retail Experience
 
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
 Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ... Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
 
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
 
The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...
The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...
The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architec...
 
Is there an API in that (IoT)?
Is there an API in that (IoT)?Is there an API in that (IoT)?
Is there an API in that (IoT)?
 
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
 
Your New Digital Business & APIs
Your New Digital Business & APIs Your New Digital Business & APIs
Your New Digital Business & APIs
 
Mapping the API Landscape - Mike Amundsen, Director of API Architecture
Mapping the API Landscape - Mike Amundsen, Director of API ArchitectureMapping the API Landscape - Mike Amundsen, Director of API Architecture
Mapping the API Landscape - Mike Amundsen, Director of API Architecture
 
Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...
Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...
Lean API Strategy - Holger Reinhardt, Snr Principal Business Unit Strategy, L...
 
Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...
Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...
Your Journey to Agility using APIs - Tyson Whitten, Director of Solutions Mar...
 

Securing Payment APIs Using Layer 7