SlideShare a Scribd company logo
1 of 11
A presentation of the Blue Cross and Blue Shield Association. All rights reserved.
BCBSA Mediation
Layer Architecture
August 09, 2012
Presentation at Intel / Gartner Webcast
Plamen Petrov
Chief Enterprise Architect
Blue Cross Blue Shield Association
A presentation of the Blue Cross and Blue Shield Association. All rights reserved.
12-131-V
2
Blue Plans have been leading the industry for 83 years
Cover 100M people –
1 in 3 Americans
Blue Plans contract with
96% of U.S. hospitals and
91% of all physicians
Blues committed to serving
local communities and national
customers
Blue Brand is #1 overall
brand equity in the health
insurance industry
Blues serve
85% of Fortune
100 Companies
The Blue Cross and Blue Shield System consists of 38 independently
operated Blue Cross and Blue Shield member companies, a Federal
Employee Program® and an Association, which serves the collective
needs of the Blue Cross and Blue Shield Plans.
Nationwide access. Local support.
A presentation of the Blue Cross and Blue Shield Association. All rights reserved.
12-131-V
3
BCBS Plan Members Access Many Services and Data Stores
Plan Member accesses services
provided by different entities and
data stored in many locations
Plan
Member
Local
BCBS Plan
BCBSA
Remote
BCBS Plan
Local
Hospital
Remote
Hospital
Consumer
Services
A presentation of the Blue Cross and Blue Shield Association. All rights reserved.
12-131-V
4
Service Brokering and Mediation Layer
Infrastructure
Services
BCBSA Mediation Layer
BluesNet
VPNs
Internet Organization
Organization
Organization
Blue Plan
Cloud Services
Organization
PlanConnexion
Cloud Services
Services Clients
Organization
Organization
BCBSA
Cloud Services
3rd Party Vendor
Cloud Services
Platform
Services
Master Data
Services
Architecture
Standards
Governance
Analytics
A presentation of the Blue Cross and Blue Shield Association. All rights reserved.
12-131-V
5
Mediation Services Platform
Mgt
API
Partner
API
Browser or Mobile
AuthN /Info Request
Medical Information
Service Provider Portal
BCBSA Plan A
• Web Server
• Mobile Tier
BCBS Plan B
Flat File
Services Mediation and
Integration Broker
Security Brokerage Technology EDI
Doctor Information
Peer Reviews, Awards
SOAP
JSON
XML
On-prem 3rd Party
Info Providers
• Web Server
• Mobile Tier
• SSL Termination
• Service Metering/Monitoring
• ID translation
• Data Transform
• Protocol Mediation
• Service Routing/Versioning
BCBS Plan C
• Web Server
• Mobile Tier
3rd Party Cloud
Info Providers
Service Mediation and Integration Brokerage
6
IT CSB TECHNOLOGY
ENABLEMENT
CONSIDERATIONS
Andy Thurai, Chief Architect, Intel
7
Mobile and API Service Growth a Driver for IT CSB
Other Internal CSB Deployments
• Online University
• Healthcare Claims Provider
• SI Delivering Composite Apps
• Telco Service Aggregator
*Source ProgrammableWeb
IT CSB
Platform
Extended Enterprise
Private & Public
Cloud Provider
Developer & Partner
Consumers
CSB Platforms offer way to automate & scale fine-grain service
brokering for composite and mobile apps used by IT
8
3rd Party CSBs &
Data Enrich Services
Partners
SaaS Applications
PaaS App Services
Departments 1-n
Developers &
Service Admins
Global Apps, IDM,
Middleware
Employee Apps
Devices
REST
HTTP
HTTP,
REST
HTTP,
REST/SOAP/
JSON
Id & Security
Broker
Service 1
PII Data
Tokenization
Service 2
API Mgt
Service 3
Orchestrate
VM/Services
Service 4
Dev Community
API Portal
Enterprise Departments/Developers
App to Cloud
Integration
Simplified, API
Exposed
Data
Integration
Service 5
Service/API Providers
On-prem Service
Broker
Sharing API Descriptions, Tools,
REST
JSON
Create Standardized
Apps that invoke
aggregated services
SOAP, JMS, DB,
FTP-any Calls
IT’s CSB Platform Simplifies Service Consumption
9
Security, Access,
Compliance
Developer Community
• Meter usage
• Throttle per SLAs
• API Analytics
• Configuration not code
• Discovery of aggregated
services from IT
• Meta data
• Edge threat protection
• Data Loss Protection
• Federated ID Brokering
• PCI PII Data Tokenization
App Service Gov &
Integration
• API management
• Policy creation & exe
• Legacy & SOA integration
• Orchestrate & transform
• Protocol translation
Service Gateway Fast Path to Operating as a CSB
IT CSB Operator
• Consistent policy enforcement for integration,
security, compliance across departments
Monetization/Charge Back
Vendor Mgt- Contracts, SLA, Tracking
Monitor Security Standards & Policies
Dev Support & Disaster Recovery
Move from Line of Business to “Enterprise
Controlled Consumption of Cloud Services
Responsibilities
& Enablement Tools
Value Added Custom “Glue” Code
COTs Core
CSB Platform
10
Security is Central for IT to Consume and Expose APIs
• Authentication: Enabled through
SSL/TLS, OAuth, SAML, Shared Secret
Mechanisms, Custom API Keys, Digital
Signature/PKI processing, Database
authentication rules
• Authorization: Enabled through XACML,
authorization decision points, coded in
policies, custom built rules
Trust - API Access Control Threat - Perimeter Defense
IdM
• Denial of Service Protection: Via app
security proxies and gateway capabilities
• Code Injection: Via pattern-based
scanning of SQL Injection, XSS, XML
threats, XPath injection
• Malware Detection: Via heuristics that
detect malware behavior
• A/V Scanning: Via signature based
scanning of MIME attachments
• Data Leak Prevention: Via network DLP
scanning for API calls
CSB platforms deliver these capabilities. Standards
based and independently certified
11
More: www.cloudsecurity.intel.com
Webinars
On-demand
• NIST & CSA CSB
• API Management
with ProgrammableWeb
• API DLP Security
• Meet Cloud API
White Paper
CSB Research & Case Study

More Related Content

What's hot

Oil & Gas industry analysis- Final Project
Oil & Gas industry analysis- Final ProjectOil & Gas industry analysis- Final Project
Oil & Gas industry analysis- Final ProjectAlaa Sulaiman
 
Cost of Capital
Cost of CapitalCost of Capital
Cost of CapitalASAD ALI
 
Capital budgeting techniques
Capital budgeting techniquesCapital budgeting techniques
Capital budgeting techniquesVJTI Production
 
Statics distributions questions
Statics distributions questionsStatics distributions questions
Statics distributions questionsayeltuju
 
Financial Management: Risk and Rates of Return
Financial Management: Risk and Rates of ReturnFinancial Management: Risk and Rates of Return
Financial Management: Risk and Rates of Returnpetch243
 
Business Operational Excellence Strategy Powerpoint Presentation Slides
Business Operational Excellence Strategy Powerpoint Presentation SlidesBusiness Operational Excellence Strategy Powerpoint Presentation Slides
Business Operational Excellence Strategy Powerpoint Presentation SlidesSlideTeam
 
Time value of money
Time value of moneyTime value of money
Time value of moneyDeeAbsalom
 
Corporate Finance Powerpoint Presentation Slides
Corporate Finance Powerpoint Presentation SlidesCorporate Finance Powerpoint Presentation Slides
Corporate Finance Powerpoint Presentation SlidesSlideTeam
 
Business model and circular economy
Business model and circular economyBusiness model and circular economy
Business model and circular economyWiithaa
 
PT. Pertamina (persero)
PT. Pertamina (persero)PT. Pertamina (persero)
PT. Pertamina (persero)pangarso_adi
 
Managing Your Application Security Program with the ThreadFix Ecosystem
Managing Your Application Security Program with the ThreadFix EcosystemManaging Your Application Security Program with the ThreadFix Ecosystem
Managing Your Application Security Program with the ThreadFix EcosystemDenim Group
 

What's hot (12)

Oil & Gas industry analysis- Final Project
Oil & Gas industry analysis- Final ProjectOil & Gas industry analysis- Final Project
Oil & Gas industry analysis- Final Project
 
Cost of Capital
Cost of CapitalCost of Capital
Cost of Capital
 
Profil PT Astra International, Tbk
Profil PT Astra International, TbkProfil PT Astra International, Tbk
Profil PT Astra International, Tbk
 
Capital budgeting techniques
Capital budgeting techniquesCapital budgeting techniques
Capital budgeting techniques
 
Statics distributions questions
Statics distributions questionsStatics distributions questions
Statics distributions questions
 
Financial Management: Risk and Rates of Return
Financial Management: Risk and Rates of ReturnFinancial Management: Risk and Rates of Return
Financial Management: Risk and Rates of Return
 
Business Operational Excellence Strategy Powerpoint Presentation Slides
Business Operational Excellence Strategy Powerpoint Presentation SlidesBusiness Operational Excellence Strategy Powerpoint Presentation Slides
Business Operational Excellence Strategy Powerpoint Presentation Slides
 
Time value of money
Time value of moneyTime value of money
Time value of money
 
Corporate Finance Powerpoint Presentation Slides
Corporate Finance Powerpoint Presentation SlidesCorporate Finance Powerpoint Presentation Slides
Corporate Finance Powerpoint Presentation Slides
 
Business model and circular economy
Business model and circular economyBusiness model and circular economy
Business model and circular economy
 
PT. Pertamina (persero)
PT. Pertamina (persero)PT. Pertamina (persero)
PT. Pertamina (persero)
 
Managing Your Application Security Program with the ThreadFix Ecosystem
Managing Your Application Security Program with the ThreadFix EcosystemManaging Your Application Security Program with the ThreadFix Ecosystem
Managing Your Application Security Program with the ThreadFix Ecosystem
 

Viewers also liked

J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015
J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015
J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015ir_stjude
 
Pandora fest Presentation
Pandora fest PresentationPandora fest Presentation
Pandora fest Presentationguestd26feb
 
Engineering college PPT
Engineering college PPTEngineering college PPT
Engineering college PPTTheTrojan
 
Sample PPT from College
Sample PPT from CollegeSample PPT from College
Sample PPT from Collegemeridian2327
 

Viewers also liked (6)

J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015
J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015
J.P. Morgan 33rd Annual Healthcare Conference Presentation 2015
 
Pandora fest Presentation
Pandora fest PresentationPandora fest Presentation
Pandora fest Presentation
 
Engineering college PPT
Engineering college PPTEngineering college PPT
Engineering college PPT
 
Sample PPT from College
Sample PPT from CollegeSample PPT from College
Sample PPT from College
 
Ppt for national conference
Ppt for national conferencePpt for national conference
Ppt for national conference
 
Solar Mobile Charger PPT
Solar Mobile Charger PPTSolar Mobile Charger PPT
Solar Mobile Charger PPT
 

Similar to BCBS & Mediation Layer Architecture

Smart Contracts and Blockchain: Separating Hype from Reality
Smart Contracts and Blockchain: Separating Hype from RealitySmart Contracts and Blockchain: Separating Hype from Reality
Smart Contracts and Blockchain: Separating Hype from RealityApttus
 
AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...
AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...
AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...AppDynamics
 
AWS最新區塊鏈服務與應用
AWS最新區塊鏈服務與應用AWS最新區塊鏈服務與應用
AWS最新區塊鏈服務與應用Amazon Web Services
 
Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / ExostarPistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / ExostarPistoia Alliance
 
Migrate existing web services and build native microservices in bluemix
Migrate existing web services and build native microservices in bluemixMigrate existing web services and build native microservices in bluemix
Migrate existing web services and build native microservices in bluemixJoel Thimsen
 
Atsc Corporate Capabilities Briefing Final Tech Services
Atsc Corporate Capabilities Briefing Final   Tech ServicesAtsc Corporate Capabilities Briefing Final   Tech Services
Atsc Corporate Capabilities Briefing Final Tech Servicesacaraffa
 
Cloud Foundry - How Service broker integrates with AppDirect to provide catal...
Cloud Foundry - How Service broker integrates with AppDirect to provide catal...Cloud Foundry - How Service broker integrates with AppDirect to provide catal...
Cloud Foundry - How Service broker integrates with AppDirect to provide catal...Nima Badiey
 
Platform for Secure Digital Business
Platform for Secure Digital BusinessPlatform for Secure Digital Business
Platform for Secure Digital BusinessAkana
 
Internet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco SystemsInternet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco SystemsAndreas Mai
 
Cloud 12 08 V2
Cloud 12 08 V2Cloud 12 08 V2
Cloud 12 08 V2Pini Cohen
 
Hadoop and Financial Services
Hadoop and Financial ServicesHadoop and Financial Services
Hadoop and Financial ServicesCloudera, Inc.
 
Create B2B Exchanges with Cisco Connected Processes: an overview
Create B2B Exchanges with Cisco Connected Processes: an overviewCreate B2B Exchanges with Cisco Connected Processes: an overview
Create B2B Exchanges with Cisco Connected Processes: an overviewCisco DevNet
 
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Standards Customer Council
 
Trust Your Supplier - trust your product in the supply chain
Trust Your Supplier - trust your product in the supply chain Trust Your Supplier - trust your product in the supply chain
Trust Your Supplier - trust your product in the supply chain Mohan Venkataraman
 
Introducing Cloudera DataFlow (CDF) 2.13.19
Introducing Cloudera DataFlow (CDF) 2.13.19Introducing Cloudera DataFlow (CDF) 2.13.19
Introducing Cloudera DataFlow (CDF) 2.13.19Cloudera, Inc.
 
CA Security - Deloitte IAM Summit - Vasu
CA Security - Deloitte IAM Summit  - VasuCA Security - Deloitte IAM Summit  - Vasu
CA Security - Deloitte IAM Summit - VasuVasu Surabhi
 
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...apidays
 
Cloud Options for a Modern Architecture
Cloud Options for a Modern ArchitectureCloud Options for a Modern Architecture
Cloud Options for a Modern ArchitectureProlifics
 
Steve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud ComputingSteve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud ComputingMauricio Godoy
 

Similar to BCBS & Mediation Layer Architecture (20)

Smart Contracts and Blockchain: Separating Hype from Reality
Smart Contracts and Blockchain: Separating Hype from RealitySmart Contracts and Blockchain: Separating Hype from Reality
Smart Contracts and Blockchain: Separating Hype from Reality
 
AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...
AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...
AppSphere 15 - Mining the World’s Largest Healthcare Data Warehouse while Ens...
 
AWS最新區塊鏈服務與應用
AWS最新區塊鏈服務與應用AWS最新區塊鏈服務與應用
AWS最新區塊鏈服務與應用
 
Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / ExostarPistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
Pistoia Alliance European Conference 2015 - Stuart Robertson / Exostar
 
Migrate existing web services and build native microservices in bluemix
Migrate existing web services and build native microservices in bluemixMigrate existing web services and build native microservices in bluemix
Migrate existing web services and build native microservices in bluemix
 
Atsc Corporate Capabilities Briefing Final Tech Services
Atsc Corporate Capabilities Briefing Final   Tech ServicesAtsc Corporate Capabilities Briefing Final   Tech Services
Atsc Corporate Capabilities Briefing Final Tech Services
 
Cloud Foundry - How Service broker integrates with AppDirect to provide catal...
Cloud Foundry - How Service broker integrates with AppDirect to provide catal...Cloud Foundry - How Service broker integrates with AppDirect to provide catal...
Cloud Foundry - How Service broker integrates with AppDirect to provide catal...
 
Platform for Secure Digital Business
Platform for Secure Digital BusinessPlatform for Secure Digital Business
Platform for Secure Digital Business
 
Internet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco SystemsInternet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco Systems
 
Cloud 12 08 V2
Cloud 12 08 V2Cloud 12 08 V2
Cloud 12 08 V2
 
Hadoop and Financial Services
Hadoop and Financial ServicesHadoop and Financial Services
Hadoop and Financial Services
 
Create B2B Exchanges with Cisco Connected Processes: an overview
Create B2B Exchanges with Cisco Connected Processes: an overviewCreate B2B Exchanges with Cisco Connected Processes: an overview
Create B2B Exchanges with Cisco Connected Processes: an overview
 
Cloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud ServicesCloud Customer Architecture for Securing Workloads on Cloud Services
Cloud Customer Architecture for Securing Workloads on Cloud Services
 
Trust Your Supplier - trust your product in the supply chain
Trust Your Supplier - trust your product in the supply chain Trust Your Supplier - trust your product in the supply chain
Trust Your Supplier - trust your product in the supply chain
 
Introducing Cloudera DataFlow (CDF) 2.13.19
Introducing Cloudera DataFlow (CDF) 2.13.19Introducing Cloudera DataFlow (CDF) 2.13.19
Introducing Cloudera DataFlow (CDF) 2.13.19
 
CA Security - Deloitte IAM Summit - Vasu
CA Security - Deloitte IAM Summit  - VasuCA Security - Deloitte IAM Summit  - Vasu
CA Security - Deloitte IAM Summit - Vasu
 
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
APIsecure 2023 - Approaching Multicloud API Security USing Metacloud, David L...
 
CA API Gateway
CA API GatewayCA API Gateway
CA API Gateway
 
Cloud Options for a Modern Architecture
Cloud Options for a Modern ArchitectureCloud Options for a Modern Architecture
Cloud Options for a Modern Architecture
 
Steve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud ComputingSteve Mills - Dispelling the Vapor Around Cloud Computing
Steve Mills - Dispelling the Vapor Around Cloud Computing
 

Recently uploaded

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxBkGupta21
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 

Recently uploaded (20)

Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptx
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 

BCBS & Mediation Layer Architecture

  • 1. A presentation of the Blue Cross and Blue Shield Association. All rights reserved. BCBSA Mediation Layer Architecture August 09, 2012 Presentation at Intel / Gartner Webcast Plamen Petrov Chief Enterprise Architect Blue Cross Blue Shield Association
  • 2. A presentation of the Blue Cross and Blue Shield Association. All rights reserved. 12-131-V 2 Blue Plans have been leading the industry for 83 years Cover 100M people – 1 in 3 Americans Blue Plans contract with 96% of U.S. hospitals and 91% of all physicians Blues committed to serving local communities and national customers Blue Brand is #1 overall brand equity in the health insurance industry Blues serve 85% of Fortune 100 Companies The Blue Cross and Blue Shield System consists of 38 independently operated Blue Cross and Blue Shield member companies, a Federal Employee Program® and an Association, which serves the collective needs of the Blue Cross and Blue Shield Plans. Nationwide access. Local support.
  • 3. A presentation of the Blue Cross and Blue Shield Association. All rights reserved. 12-131-V 3 BCBS Plan Members Access Many Services and Data Stores Plan Member accesses services provided by different entities and data stored in many locations Plan Member Local BCBS Plan BCBSA Remote BCBS Plan Local Hospital Remote Hospital Consumer Services
  • 4. A presentation of the Blue Cross and Blue Shield Association. All rights reserved. 12-131-V 4 Service Brokering and Mediation Layer Infrastructure Services BCBSA Mediation Layer BluesNet VPNs Internet Organization Organization Organization Blue Plan Cloud Services Organization PlanConnexion Cloud Services Services Clients Organization Organization BCBSA Cloud Services 3rd Party Vendor Cloud Services Platform Services Master Data Services Architecture Standards Governance Analytics
  • 5. A presentation of the Blue Cross and Blue Shield Association. All rights reserved. 12-131-V 5 Mediation Services Platform Mgt API Partner API Browser or Mobile AuthN /Info Request Medical Information Service Provider Portal BCBSA Plan A • Web Server • Mobile Tier BCBS Plan B Flat File Services Mediation and Integration Broker Security Brokerage Technology EDI Doctor Information Peer Reviews, Awards SOAP JSON XML On-prem 3rd Party Info Providers • Web Server • Mobile Tier • SSL Termination • Service Metering/Monitoring • ID translation • Data Transform • Protocol Mediation • Service Routing/Versioning BCBS Plan C • Web Server • Mobile Tier 3rd Party Cloud Info Providers Service Mediation and Integration Brokerage
  • 6. 6 IT CSB TECHNOLOGY ENABLEMENT CONSIDERATIONS Andy Thurai, Chief Architect, Intel
  • 7. 7 Mobile and API Service Growth a Driver for IT CSB Other Internal CSB Deployments • Online University • Healthcare Claims Provider • SI Delivering Composite Apps • Telco Service Aggregator *Source ProgrammableWeb IT CSB Platform Extended Enterprise Private & Public Cloud Provider Developer & Partner Consumers CSB Platforms offer way to automate & scale fine-grain service brokering for composite and mobile apps used by IT
  • 8. 8 3rd Party CSBs & Data Enrich Services Partners SaaS Applications PaaS App Services Departments 1-n Developers & Service Admins Global Apps, IDM, Middleware Employee Apps Devices REST HTTP HTTP, REST HTTP, REST/SOAP/ JSON Id & Security Broker Service 1 PII Data Tokenization Service 2 API Mgt Service 3 Orchestrate VM/Services Service 4 Dev Community API Portal Enterprise Departments/Developers App to Cloud Integration Simplified, API Exposed Data Integration Service 5 Service/API Providers On-prem Service Broker Sharing API Descriptions, Tools, REST JSON Create Standardized Apps that invoke aggregated services SOAP, JMS, DB, FTP-any Calls IT’s CSB Platform Simplifies Service Consumption
  • 9. 9 Security, Access, Compliance Developer Community • Meter usage • Throttle per SLAs • API Analytics • Configuration not code • Discovery of aggregated services from IT • Meta data • Edge threat protection • Data Loss Protection • Federated ID Brokering • PCI PII Data Tokenization App Service Gov & Integration • API management • Policy creation & exe • Legacy & SOA integration • Orchestrate & transform • Protocol translation Service Gateway Fast Path to Operating as a CSB IT CSB Operator • Consistent policy enforcement for integration, security, compliance across departments Monetization/Charge Back Vendor Mgt- Contracts, SLA, Tracking Monitor Security Standards & Policies Dev Support & Disaster Recovery Move from Line of Business to “Enterprise Controlled Consumption of Cloud Services Responsibilities & Enablement Tools Value Added Custom “Glue” Code COTs Core CSB Platform
  • 10. 10 Security is Central for IT to Consume and Expose APIs • Authentication: Enabled through SSL/TLS, OAuth, SAML, Shared Secret Mechanisms, Custom API Keys, Digital Signature/PKI processing, Database authentication rules • Authorization: Enabled through XACML, authorization decision points, coded in policies, custom built rules Trust - API Access Control Threat - Perimeter Defense IdM • Denial of Service Protection: Via app security proxies and gateway capabilities • Code Injection: Via pattern-based scanning of SQL Injection, XSS, XML threats, XPath injection • Malware Detection: Via heuristics that detect malware behavior • A/V Scanning: Via signature based scanning of MIME attachments • Data Leak Prevention: Via network DLP scanning for API calls CSB platforms deliver these capabilities. Standards based and independently certified
  • 11. 11 More: www.cloudsecurity.intel.com Webinars On-demand • NIST & CSA CSB • API Management with ProgrammableWeb • API DLP Security • Meet Cloud API White Paper CSB Research & Case Study

Editor's Notes

  1. Lets drill into the broker platform a little deeper. Today off the shelf CSB technology enablement platforms exist to build host and deliver the broker service layer. This is typically a multi-tenant architecture that can service departmental needs. For the consuming department this may involve identity SSO or credential mapping for users to access SaaS provider apps, tokenizing or encrypting sensitive PII personal data to meet regulatory compliance concerns before pushing data and content to cloud provider platforms, proxing internal application API with enterprise class security before allowing consumption by partners, orchestration of VMs and services to deliver composite applications, or even to add value added services like moving large volumes of Big Data workloads for analytics. Its clear the cloud API plays an increasingly pivotal role in authentication, integration, security, and data integration for the CSB layer.