Welcome!

Weblogic Authors: Yeshim Deniz, Elizabeth White, Michael Meiner, Michael Bushong, Avi Rosenthal

Related Topics: @CloudExpo, Containers Expo Blog

@CloudExpo: Article

Virtues of Service Virtualization in a Cloud

Service Virtualization is a crucial part of Federated SOA and cloud-based deployments

Virtualization Expo on Ulitzer

Service virtualization is the ability to create a virtual service from one or more predefined service files.  Service files are usually generated as a Web Service Description Language (WSDL, pronounced Wizdel, see tutorial for introduction to WSDL) file by service containers running business application developed in Java, .NET, PHP type programming languages. 

Service virtualization combines and slices business services deployed independent of the operating systems, programming language or hosting location. The services may be off-premise cloud services (SaaS, PaaS, IaaS)  or on-premise services deployed in a corporate data center. An intermediary cloud gateway sits between the producer and the consumer and aggregates the WSDLs. Based on policies enforced on the cloud gateway, only authorized operations are exposed to the consumers. A sample topology is as follows:

Service Virtualization Cloud Computing

 

In the virtualization diagram above, services A, B and C are deployed on-premise in the corporate data center whereas service D, E, and F are deployed off-premise at a cloud hosting provider such as Amazon EC2 or Rackspace.  The services produced are imported into a Cloud Gateway such as Forum Sentry, aggregated and then published to the consumers based on the credentials provided by the consumers at design-time. 

A new WSDL is generated by the Cloud Gateway that provides only those services that a consumer is entitled to see.  For example, in the diagram above, the internal consumer is provided a WSDL that only contains information related to services A-E, whereas the external consumer is provided a WSDL that contains only services B and F.  The consumers are not aware of whether the services are hosted on-premise in the Data Center or off-premise in the Cloud.

VIRTUES OF SERVICE VIRTUALIZATION

Security: The virtual WSDLs expose or hide operations extracted from imported source WSDLs selectively based on consumer authorization levels. The WSDL endpoints are cloaked with only intermediary's endpoints exposed.  Security is centeralized on the cloud gateway and decoupled from the business applications.  As services morph, the security policies can be controlled centrally.  Any security exposure can be rapidly remediated at the gateway without requiring immediate attention for "patching" a large number of services deployed across data centers and cloud providers.  Endpoint URL obfuscation that removes indications of  technology being deployed such as .jsp, .asmx, .php extensions provides a level of comfort to consumers by indicating a well integrated and standardized set of services.  Endpoint obfuscation also decreases techology-stack (Java, .NET, LAMP) specific attack vectors thereby reducing the attack surface area increased by exposing services.

Consistency: Virtualization provides the ability to select operations from multiple WSDLs and expose them to clients as a coherent single WSDL.  The alternate path to this technique is to provide multiple WSDLs generated by each container.  Typical containers take a class file or set of methods and generate a set of service definitions as a WSDL file.  Virtualization enables importing and aggregating such services generated from a variety of service container such as IBM WebSphere, WebLogic Server, Apache Axis, and .NET, selectively picking services that a consumer is authorized to see, and then generating a sub-set WSDL that only contains artifacts (XSD Schema, Message Definitions, Operation Names, Binding)  that a consumer is allowed to see.

Productivity:The main benefit of virtualization is the ability to mix and match operations without having to mannually copy and paste parts of the desired WSDLs into new WSDL files. It allows a corporations to generate a composite library of all supported operations and only expose the ones required for a particular consumer.  Service virtualization also provides a central location for service version management and service cataloguing.

Reliability: A service may be deployed redundantly on-premise and off-premise for capacity planning and management.  If an on-premise service is inundated with traffic, a cloud gateway can redirect traffic to off-premise cloud services.  In a catastrophic situation where either the data center or a cloud provider suffers an outage, a cloud gateway can provide fail-over capabilities.  A cloud gateway can also be used for failover across multi-cloud deployments.  As corporations migrate services to cloud providers, multi-cloud deployments that enable fault tolerance across clouds will become more prevalent.

Some of the challenges of Service Virtualization addressed by sophisticated Cloud Gateways, such as Forum Sentry include:

  • Protecting service endpoints through endpoint obfuscation.
  • Resolving different schemas that share the same namespace.
  • Reconciling incompatible constraints for elements that appear in multiple schemas.
  • Exposing the list of WSDLs that developers should be working on based on developer credentials. Although external trading partners typically require a single WSDL, internal developers work with multiple WSDLs. A list of WSDL needs to be retrieved from the cloud gateway to better manage developers working across multiple WSDLs.
  • Fault tolerance in multi-cloud deployments.

Service Virtualization is a crucial part of Federated SOA and cloud-based deployments. The vices of free-for-all operations can quickly result in chaos.  Highly distributed enviroments that require automated interaction with suppliers and customers as well as external service providers (SaaS, PaaS, IaaS) can only be controlled through cloud gateways that provide strong service virtualization.

More Stories By Mamoon Yunus

Mamoon Yunus is an industry-honored CEO and visionary in Web Services-based technologies. As the founder of Forum Systems, he pioneered XML Security Gateways & Firewalls and was granted a patent for XML Gateway Appliances. He has spearheaded Forum's direction and strategy for eight generations of award-winning XML Security products. Prior to Forum Systems, Yunus was a Global Systems Engineer for webMethods (NASD: WEBM) where he developed XML-based business integration and architecture plans for Global 2000 companies such as GE, Pepsi, Siemens, and Mass Mutual. He has held various high-level executive positions at Informix (acquired by IBM) and Cambridge Technology Group.

He holds two Graduate Degrees in Engineering from MIT and a BSME from Georgia Institute of Technology. InfoWorld recognized Yunus as one of four "Up and coming CTOs to watch in 2004." He is a sought-after speaker at industry conferences such as RSA, Gartner, Web Services Edge, CSI, Network Interop, and Microsoft TechEd. Yunus has the distinction of showcasing Forum Systems' entrepreneurial leadership as a case study at the MIT Sloan School of Management. He has also been featured on CNBC as Terry Bradshaw's "Pick of the Week."

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
Discussions of cloud computing have evolved in recent years from a focus on specific types of cloud, to a world of hybrid cloud, and to a world dominated by the APIs that make today's multi-cloud environments and hybrid clouds possible. In this Power Panel at 17th Cloud Expo, moderated by Conference Chair Roger Strukhoff, panelists addressed the importance of customers being able to use the specific technologies they need, through environments and ecosystems that expose their APIs to make true ...
"Space Monkey by Vivent Smart Home is a product that is a distributed cloud-based edge storage network. Vivent Smart Home, our parent company, is a smart home provider that places a lot of hard drives across homes in North America," explained JT Olds, Director of Engineering, and Brandon Crowfeather, Product Manager, at Vivint Smart Home, in this SYS-CON.tv interview at @ThingsExpo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
We are seeing a major migration of enterprises applications to the cloud. As cloud and business use of real time applications accelerate, legacy networks are no longer able to architecturally support cloud adoption and deliver the performance and security required by highly distributed enterprises. These outdated solutions have become more costly and complicated to implement, install, manage, and maintain.SD-WAN offers unlimited capabilities for accessing the benefits of the cloud and Internet. ...
In an era of historic innovation fueled by unprecedented access to data and technology, the low cost and risk of entering new markets has leveled the playing field for business. Today, any ambitious innovator can easily introduce a new application or product that can reinvent business models and transform the client experience. In their Day 2 Keynote at 19th Cloud Expo, Mercer Rowe, IBM Vice President of Strategic Alliances, and Raejeanne Skillern, Intel Vice President of Data Center Group and G...
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.
DXWorldEXPO LLC announced today that "IoT Now" was named media sponsor of CloudEXPO | DXWorldEXPO 2018 New York, which will take place on November 11-13, 2018 in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
The current age of digital transformation means that IT organizations must adapt their toolset to cover all digital experiences, beyond just the end users’. Today’s businesses can no longer focus solely on the digital interactions they manage with employees or customers; they must now contend with non-traditional factors. Whether it's the power of brand to make or break a company, the need to monitor across all locations 24/7, or the ability to proactively resolve issues, companies must adapt to...
"IBM is really all in on blockchain. We take a look at sort of the history of blockchain ledger technologies. It started out with bitcoin, Ethereum, and IBM evaluated these particular blockchain technologies and found they were anonymous and permissionless and that many companies were looking for permissioned blockchain," stated René Bostic, Technical VP of the IBM Cloud Unit in North America, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Conventi...
Founded in 2000, Chetu Inc. is a global provider of customized software development solutions and IT staff augmentation services for software technology providers. By providing clients with unparalleled niche technology expertise and industry experience, Chetu has become the premiere long-term, back-end software development partner for start-ups, SMBs, and Fortune 500 companies. Chetu is headquartered in Plantation, Florida, with thirteen offices throughout the U.S. and abroad.
René Bostic is the Technical VP of the IBM Cloud Unit in North America. Enjoying her career with IBM during the modern millennial technological era, she is an expert in cloud computing, DevOps and emerging cloud technologies such as Blockchain. Her strengths and core competencies include a proven record of accomplishments in consensus building at all levels to assess, plan, and implement enterprise and cloud computing solutions. René is a member of the Society of Women Engineers (SWE) and a m...