View a markdown version of this page

Open Banking on AWS: Services and operations - Open Banking on AWS

Open Banking on AWS: Services and operations

Publication date: September 7, 2021 (Diagram history)

With this architecture, you can implement Open Banking API microservices, manage identity, and monitor security posture. The solution uses Amazon Elastic Container Service with AWS Fargate for containerized services, Amazon DynamoDB for consent storage, and Amazon GuardDuty for threat detection.

Open Banking services and operations diagram

Reference architecture diagram showing Open Banking microservices, identity, and security by using Amazon ECS, AWS Fargate, DynamoDB, and Amazon GuardDuty.

The following steps describe the services and operational components for this architecture:

  1. Connect securely between VPCs and services hosted on AWS or on-premises by using AWS PrivateLink.

  2. Implement Open Banking API specifications for Account Information and Payments services by using multiple container-based microservices hosted on Amazon ECS with AWS Fargate. Cache customer account information by using Amazon ElastiCache. Host webhooks for payment status in this layer.

  3. Store consumer consents, aggregated data, and API performance metrics in DynamoDB.

  4. Hold a copy of the system of record in Amazon RDS. Synchronize data in near real time from the bank core system.

  5. Implement the identity provider (IdP) for OAuth 2.0 in a separate AWS account so that other workloads in the bank can consume it securely.

  6. Provide a separate developer sandbox for the third party to integrate with the bank AWS environment and build their products.

  7. Monitor for malicious activity and unauthorized behavior by using GuardDuty. Get a comprehensive view of security alerts and security posture across AWS accounts by using AWS Security Hub CSPM.

  8. Collect logs from all services in Amazon Simple Storage Service. Analyze and monitor logs by using Amazon OpenSearch Service.

  9. Manage configuration by using AWS Systems Manager. Deploy environments by using AWS CloudFormation. Use Amazon EventBridge, Amazon Simple Queue Service, and Amazon Simple Notification Service for notification capability between services.

Further reading

For additional information, see the following resources:

Diagram history

To receive updates about this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

September 7, 2021

Initial publication

Reference architecture diagram first published.

September 7, 2021

Initial publication

Reference architecture diagram first published.

September 7, 2021

RSS subscription requirement

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.