Session 16545: Secure Hybrid Computing: z to Mobile Implementation plus Analytics

Similar documents
Hybrid Computing mit dem IBM zenterprise System. Matthias R. Bangert

Mainframe Optimization System z the Center of Enterprise Computing

IBM Cloud for VMware Solutions

Workload Thinking for zenterprise Fit for Purpose!

Linux on IBM Z. Operational efficiency and trustworthiness. Linux at its best. Highlights. IBM Systems Data Sheet

A platform that delivers superior business results, time and time again.

IBM z13 (z13) Highlights. Performance and Scale help improve client experience. IBM Systems Data Sheet

Enterprise X-Architecture 5th Generation And VMware Virtualization Solutions

IBM zenterprise System

IBM zenterprise System: What s New - Announcement Overview

Rickard Linck Client Technical Professional Core Database and Lifecycle Management Common Analytic Engine Cloud Data Servers On-Premise Data Servers

IBM Power Systems: Open innovation to put data to work Dexter Henderson Vice President IBM Power Systems

The zenterprise Unified Resource Manager IBM Corporation

Smarter Systems In Your Cloud Deployment

Agenda. This Session: Azure Networking Basics, On-prem connectivity options DEMO Create VNET/Gateway Cost-estimation for VNET/Gateways

Cloud on z Systems Solution Overview: IBM Cloud Manager with OpenStack

Exam C Foundations of IBM Cloud Reference Architecture V5

IBM Db2 Analytics Accelerator Version 7.1

Taking your next integration or BPM project to the cloud WebSphere Integration User Group, 12 July 2012 IBM Hursley

IBM C IBM z Systems Technical Support V6.

IBM zenterprise Blade Center Extension Top of Rack Switch (TOR)

EMC FORUM NEW YORK 2010

IBM zenterprise Unified Resource Manager Overview

Cisco Unified Data Center Strategy

Vendor: IBM. Exam Code: Exam Name: IBM System z Technical V5. Version: Demo

Smart Terminal Architecture with Secure Hosts A New Evolution in Smart Computing for an Enterprise. Analyst Briefing

Connect and Transform Your Digital Business with IBM

Exam : Title : IBM Cloud Computing Infrastructure Architect V1. Version : Demo

Exploiting IT Log Analytics to Find and Fix Problems Before They Become Outages

Change Data Capture - Migration Data Replication

Migrating Enterprise Applications to the Cloud Session 672. Leighton L. Nelson

VMware Virtual SAN Technology

A portfolio of hardware, software, and services for an enterprise-grade Linux operating environment. Marcel Mitran DE, CTO IBM LinuxONE

FUJITSU Backup as a Service Rapid Recovery Appliance

Leading-edge Technology on System z

Agenda. Future Sessions: Azure VMs, Backup/DR Strategies, Azure Networking, Storage, How to move

Mellanox InfiniBand Solutions Accelerate Oracle s Data Center and Cloud Solutions

Cloud Computing Introduction & Offerings from IBM

a.k.a. Introducing the IBM MQ Appliance

HPE SimpliVity. The new powerhouse in hyperconvergence. Boštjan Dolinar HPE. Maribor Lancom

Enterprise Networking Solutions, Inc.

C ibm IBM C Foundations of IBM Cloud Reference Architecture V5 Version 1.0

Practical Advice on Application Deployment: Making the Most of the zenterprise

Data Protection Modernization: Meeting the Challenges of a Changing IT Landscape

zenterprise The Ideal Platform For Smarter Computing Improving Service Delivery With Private Cloud Computing

BUILD BETTER MICROSOFT SQL SERVER SOLUTIONS Sales Conversation Card

CenturyLink for Microsoft

Hyperconverged Infrastructure Use Cases and Buyer s Guide

Systems and Technology. Rod Adkins Senior Vice President Systems and Technology Group

A Strategic View of Linux on System z from IBM

TRANSFORM YOUR APPLICATIONS

TOP REASONS TO CHOOSE DELL EMC OVER VEEAM

IBM Storage Solutions & Software Defined Infrastructure

Private Cloud Database Consolidation Name, Title

Lenovo Software Defined Infrastructure Solutions. Aleš Simončič Technical Sales Manager, Lenovo South East Europe

With Hyperconverged Infrastructure

DELL EMC DATA DOMAIN OPERATING SYSTEM

Hyper-Convergence De-mystified. Francis O Haire Group Technology Director

Transforming IT: From Silos To Services

Key Management in a System z Enterprise

Welcome to the Hybrid world. Why did we do it?

Fujitsu World Tour 2018

IBM zenterprise Value for Business Workloads and Applications

Making System z the Center of Enterprise Computing

OFA Developer Workshop 2014

Transforming Data Protection with HPE: A Unified Backup and Recovery June 16, Copyright 2016 Vivit Worldwide

IBM MQ Hybrid Cloud Architectures

HCI mit VMware vsan Radikal einfach und vollständig in die SDDC Strategie integriert

Vision of the Software Defined Data Center (SDDC)

STORAGE CONSOLIDATION WITH IP STORAGE. David Dale, NetApp

IBM Power 9 надежная платформа для развертывания облаков. Ташкент. Юрий Кондратенко Cross-Brand Sales Specialist

Cloud Services. Infrastructure-as-a-Service

Smarter Business Agility with WebSphere DataPower Appliances Introduction

Copyright 2011, Oracle and/or its affiliates. All rights reserved.

Linux Platform Options Selecting Linux on IBM System z9 and zseries

2011 IBM Research Strategic Initiative: Workload Optimized Systems

L12. Linux Platform Options Selecting Linux on IBM System z9 and zseries. Jim Elliott San Francisco, CA. September 19-23, 2005

Azure Webinar. Resilient Solutions March Sander van den Hoven Principal Technical Evangelist Microsoft

The New Enterprise Data Center Summit. Session: zmr - consolidation with an affordable mainframe Speaker: Sreenath Chary Date: 19 th Nov 2008

Orchestrating the Cloud Infrastructure using Cisco Intelligent Automation for Cloud

IBM EXAM QUESTIONS & ANSWERS

IBM POWER SYSTEMS: YOUR UNFAIR ADVANTAGE

BUILD, MODERNIZE AND PROTECT WITH IBM CLOUD PRIVATE

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved. reserved. Insert Information Protection Policy Classification from Slide 8

Cloud offerings from IBM

Cloud Infrastructure and Operations Chapter 2B/8 Page Main concept from which Cloud Computing developed

Architecting Microsoft Azure Solutions (proposed exam 535)

CLOUD SECURITY: THE CHALLENGES FOR THE DATA CENTRE AND IT ENVIRONMENT NOVEMBER 2016

IBM TS4300 with IBM Spectrum Storage - The Perfect Match -

CASE STUDY: USING THE HYBRID CLOUD TO INCREASE CORPORATE VALUE AND ADAPT TO COMPETITIVE WORLD TRENDS

IBM dashdb Local. Using a software-defined environment in a private cloud to enable hybrid data warehousing. Evolving the data warehouse

Build an open hybrid cloud and paint it red and blue

Bart Willem Kris Vandermeulen Microsoft Belux

Dynamic Infrastructure: Building a Smarter Planet. Laura Voglino Vice President, Marketing System & Technology Group Growth Market

BUSINESS DATA LAKE FADI FAKHOURI, SR. SYSTEMS ENGINEER, ISILON SPECIALIST. Copyright 2016 EMC Corporation. All rights reserved.

IBM Data Virtualization Manager in Detail + Demo Atlanta DB2 User Group Meeting December 7, 2018

Automating the Software-Defined Data Center with vcloud Automation Center

Infrastructure modernization with Microsoft Azure

Enterprise Architectures The Pace Accelerates Camberley Bates Managing Partner & Analyst

Transform to Your Cloud

Transcription:

Session 16545: Secure Hybrid Computing: z to Mobile Implementation plus Analytics Zero Latency Enterprise (ZLE) for Cloud Analytics Mobile Social (CAMSS) with Need to Know and solid end to end Security Underpinning George Thompson, IBM Infrastructure Architect Jeff Beck, IBM IT Architect gthompsn@us.ibm.com jbeck1@us.ibm.com Insert Custom Session QR if Desired.

New Model of Hybrid Computing Move the application to the data (no longer Client Server Model) System of Record (large database for transactional access with all data types) for OLTP, ANALYTICS, WAREHOUSE, COGNITIVE, BIG DATA This is still the primary ingest mechanism but Real Time Single Version of Truth for all access solutions System of Engagement is the new access method Social, multimedia, multiple data sources Data can be presented on a need to know basis Only what user is allowed to see May not know that some data will even exist Don t move data to the end user Hotel California Show them the results via distributed presentation Limits data loss/theft at the end user level It can be moved closer via managed replica s or proxy servers

New Model of Hybrid Computing The System (operating system and database) becomes responsible for security of the data The security administrator and database administrator can collaborate to define and implement the compartments for data isolation Applications wouldn t need to modify database calls to include WHERE security processing logic as the System will handle that This can reduce development costs as mistakes may be eliminated Built in EAL5+ Security RACF, PKI, H/W Cryptography, SSL/TLS, ICSF, MLS Communications architecture is critical success VPN and IPSec is critical Shared authentication is mandatory Registration and enrollment, audit, access control

Hybrid heterogeneous delivery eliminates boundaries for CAMSS with advanced scale, availability, performance, RAS & zero latency Advanced Virtualization for Cloud, scalability, resource sharing, cost take-out Advanced Accelerators including specialty engines, WLM, SDE Advanced Server CPU Memory Network and I/O.eliminate latency and increase performance ((CPU 5.5 GHz Specialty Engines SMT & Multi Tenancy Execution, HPC,Four Level Cache, Transactional Memory on Chip, Flash, RDMA, ROCE, Hipersockets, OSA, SAPs, CAPI, FGPA)) Advanced Cloud and Interoperability between ALL Clouds Advanced Development - Open Source and Traditional Access operability for engagement Advanced Mobile and Web engagement Advanced Analytics with Advanced Data Management ECM Archival Advanced Social Media solutions modeling tracking dissemination Advanced Ingest Streams for Standard and Social ingest Advanced Security EAL5+ with solid end to end deployment Advanced Storage extreme bandwidth: Flash, zedc Advanced Resiliency Scalability, HA, Backup/Recovery, DR, RAS, CBU, COD, P/U Outage Advanced Infrastructure flexibility for Agile development Dev/Ops BlueMix, SoftLayer, etc. Advanced Middleware solutions providing services to client software applications

Need to Know DB2 Labeled Security REQUIREMENT: Original View Data shared between people/organizations with different "need to know" Original View: Suppliers could see each other s data They could collude and cheat the manufacturer on price Or lower their prices to compete against each other Supplier 1 Supplier 2 Supplier 3 System Record Manufacturing System Supplier Data All Suppliers see all info Implementing Labeled Security: Additional security information gathered from suppliers during sign on Result is suppliers could only see their data Manufacturing employees see all data No applications were changed Supplier 1 MLS View Unique IP @ + Userid Suppliers only see their data MLS POC Demo Link: https://www.youtube.com/watch?v=qjbjtaim Src Supplier 2 Supplier 3 System Record Manufacturing System Single DB

Technical Components a sample list Input device System(s) of Engagement Softlayer WAS ispatial MQ Raytheon TCS ME4Sure IBM Apple Managed Replica Proxy VDI Outsourced or Branch Office PCs, Call Centers Developer Desktops Remote / Laptop Users DB2 Oracle WAS Linux z/vm IDAA Secure MQ RACF: PKI, MLS Veristorm zdoop System of Record Insert Update Analytics Power HPC AIX GPFS Watson Streams Big Insights Infosphere Analytics Cognos SPSS Social

IT Management Trends are changing Silo-ed operations Scale Out Application Growth Global Business Responsibilities Governance Risk and Compliance Business Continuity Privacy Lean and Green X86, RISC IT Operations Global IT operations Legacy IT operations Application Architects Next Gen Applications Hybrid IT Operations Hybrid Bladecenter Virtual Clients IT Operations Hybrid Application Sandbox Application Architects

Global IT Opportunities CLOUD DELIVERY Business resilience The vault Business Process Integration Infrastructure Simplification Virtualization Hybrid Server consolidation Help fail over (Disaster Recover) other servers data Enterprise data protected; simplifying Compliance Leveraging web services for application and database access Manpower, energy, floor space savings Many server images in a single machine Hybrid Client consolidation Faster/cheaper recovery for desktop systems Enterprise data protected; simplifying Compliance Leveraging web services for multi channel transformation and applications Manpower, energy, floor space savings Many client images in a single machine Appl Development Target Deployment platform Target Development platform The Hybrid Server and Client are weapons, use them wisely Cultivating growth opportunities while taking out costs

VPN tunnel Hybrid Cloud Enterprise Architecture: Overview (System z and SoftLayer) SoftLayer Hybrid Architecture provides best of both worlds WAS Load Balance WAS Secure Transactions combined with the dynamic of Cloud Internet On-Prem Data Center Systems Record DB2 10

Cloud Application Service Infrastructure ( CASI ) "CASI" is a hybrid hardware infrastructure designed to allow for the deployment of applications using a Fit-for-Purpose architecture approach. "CASI" infrastructure consists of: z Systems (z/os and RedHat Linux on z Systems) Power Systems (AIX) System x via zbx (Windows and RedHat Linux on x86) WebSphere DataPower via zbx Netezza (Data Warehousing) 10GbE Layer 3 switches Developed by the Agency Enterprise Server Division (AESD) The multiple hardware platforms allow for the deployment of application components based on an applications specific requirements: Most applications are 3-tiered: HTTP web server -> Application server -> Database Example: HTTP server/x86 specific components on x86 Windows or Linux -> Application server (WAS) on Power Systems -> Oracle or DB2 Database on Linux on z Systems 10GbE L3 switches allow for private data communication between all "CASI" systems without the need for routing or firewalls (i.e. Layer 2 networking), or a single router hop between systems (Layer 3 networking). "CASI" leverages existing Disaster Recovery infrastructure via GDPS/XRC to provide recovery for new and existing applications.

"CASI" currently supports: All major hardware architectures X86, s390x, RISC Run application components on native hardware architecture Reduced need to rewrite code for easier application porting High-speed, private 10GbE network Co-locates application to data sources Eliminates need for firewalls within "CASI" infrastructure z/vm, PowerVM, KVM hypervisors DR solution via GDPS/XRC Most CASI applications End-user piece of mind Quick deployment of virtual servers and hardware resources All "CASI" platforms are 100% virtualized Most "CASI" client requests fulfilled within hours or a few days

2/27/2015 13

AESD s "CASI" service started with existing Mainframe and Power Systems infrastructure 2004-2005: Evaluated Linux on z Systems using IFLs Advertised new Linux on z Systems service to end users throughout the agency Ability to host database and web service applications with various SLA s: Production and DEV environments Provided disaster recovery for hosted applications Limitations: Applications must be certified to run on Linux on z Systems or Power Systems Limited bandwidth and IP addresses

2/27/2015 15

IBM Announces zenterprise in July 2010 zenterprise 196 zenterprise BladeCenter Extension (zbx) Ability to host native x86 applications on blades Tightly integrated with z Systems security and long-standing operational policies Communication between zbx and z CEC occur over secure, private high-speed network (IEDN) Mainframe viewed as a Fit-for-Purpose cloud server 2011: AESD acquires zbx and x86 blades to expand "CASI" capabilities: Multi-tier applications across "CASI" platforms for enhanced qualities of services End-user applications communicate fast and securely over zenterprise IEDN network Limitations: Private, high-speed networking limited only to zenterprise, not external platforms (i.e. Power Systems)

2/27/2015 17

Future AESD outlook for CASI Implement Layer 3 switches to provide 10GbE network backbone across all "CASI" platforms Provide private VLANs to end-users that expand across platforms Limit amount of public IP addresses required for applications Ability to host hundreds or more applications Expand service offerings using hardware appliances and software solutions Consider multi-vendor hardware offerings Architecture designed to be open

2/27/2015 19

THANK YOU George Thompson IBM Infrastructure Architect gthompsn@us.ibm.com Jeff Beck IBM Client IT Architect jbeck1@us.ibm.com