Effective management of access and services

Centralization of integrations at the University of Aveiro

ABOUT THIS SUCCESS STORY

The University of Aveiro faced challenges in managing a complex application ecosystem with multiple integrations and a lack of standardization. Xpand IT’s solution, using the WSO2 platform, centralized management, improved traceability, security, and agility, making it easier to create new services and enhancing problem-solving efficiency.

SCOPE OF THE SOLUTION

  • Centralization of integrations

  • Traceability and security

  • Agility in service creation

  • WSO2

Challenge: application ecosystem management

The University of Aveiro (UA) manages a diversified application ecosystem, which offers a wide and differentiated set of services to its different stakeholders. Countless digital services need to be implemented and maintained for students, teachers, staff, potential candidates, alumni and even other universities to interact with the UA. These vary according to the type of access, the physical location and the level of security required for the operation in question.

As many of these implementations are carried out by different teams, managing all the resulting scenarios in a non-standardized model quickly became complex and unscalable. The need for the correct identification of all the dependencies discovered limitations and reduced the speed of detecting incidents and the necessary evolution of the basic system.

Therefore, three main objectives were defined:

Management and implementation

Streamline all these management process and the implementation of new integrations with the UA.

Visibility and traceability

Promote visibility and traceability for more efficient problem resolution.

Facilitating development

Facilitate the development and adoption of new services.

Solution: access and service management with WSO2

To achieve the proposed objectives, a middleware strategy was defined, based on the implementation of a consolidated platform, and capable of offering the robustness and agility required by the University of Aveiro. The solution had 4 stages:

Systems integration: Given the heterogeneity of the systems involved, this component seeks to abstract and facilitate the creation of integrations between them. Through it, it is possible to mediate and transform the entire communication process between the various systems, taking the diversity and specificity of the protocols and message formats noted by each one into account.

Grupo de jovens estudantes reunidos em torno de uma mesa, colaborando em projetos num portátil, rodeados de cadernos e material de estudo, representando aprendizagem e inovação académica.

API management: An API manager makes it possible to catalogue and expose all relevant APIs, in an organized and documented way; segment, give visibility and guarantee authorized access to services based on the profile of the respective consumer; and provide metrics and streamline the adoption of services by users and entities internal and external to the UA.

Access security: The security of services and applications is now centrally managed by an IAM (identity and access management) component. This component is responsible for authentication and access authorisation, as well as the federation of users in third-party systems (e.g., Shibollet), ensuring the application of security policies defined for each case through industry standard protocols.

Training and governance: The solution included training actions directed at the management, and the configuration of the solution and implementation of new integrations. This allows an easier adoption of the technology as well as the joint definition of governance policies and processes for the creation and management of APIs and services.

Benefits: efficient incident response and governance strategy

A fast, efficient response to incidents

and other technical problems, through standardized and centralized alert and traceability mechanisms.

The enforcement of security and auditability policies

in the access to services by different applications and entities, according to their authorization levels.

The governance of services and APIs

by defining procedures for the correct implementation and documentation of artifacts.

Quality and agility

in the creation and availability of new services and APIs for internal and external consumption, promoting self-service.

"Through this project, the UA wanted to find an agile, secure, reliable solution for its application ecosystem. The goal was a solution capable of responding to the needs of integration and internal and external interoperability, at the information systems level. Xpand-IT has met expectations and has provided technical support across the board, from design, to operation, to complex integration scenarios."

Cláudio Teixeira
Director of Information and Communication Technology Services, University of Aveiro

Technologies

About University of Aveiro

Headquarters: Aveiro, Portugal

Founded in 1973

Misson and values

  • Creation and sharing of knowledge, engaging the entire community through education, research, and cooperation with the surrounding environment.

Type of solution

  • Project focused on access and service management at UA;
  • Improved interoperability between UA and its users (teachers, students, partners);
  • Ensuring effective incident response and enforcement of security policies.

Read more

We believe in partnerships that deliver results

This success story shows what’s possible when collaboration happens. Shall we talk?