Chemwatch products are developed based on a three-tier architecture. The high level system topology is as depicted in the picture below:
From the consumer perspective the structure looks like this:
Database layer
Chemwatch uses relational Oracle database. The data size is currently slightly over 0.5 Tb. It holds information on 300k reviewed and indexed chemicals (so called Chemwatch Golds) as well as on over 2 million other materials. The database is responsible for system state and process millions transactions per day. Its structure is optimized for performance and consistency. No duplicate information is stored; relations are built and resolved instead. This helped us to come up with a design schema capable to cope with high server side load generated by many clients (3500 active accounts with many users working under those).
Full text search is implemented using Oracle text capabilities. Database is fully Unicode compatible and can store and search information in over 40 languages.
The solution is scalable and can be adjusted using Amazon cloud which has near to infinite resources.
The data layer is represented by Oracle 11g database hosted in Amazon cloud (RDS extra large node). It holds all the data required for effective management of chemicals against different regulations used in different countries. All available performance and statistic tools are enabled on RDS to help us monitor database 24x7 and act on any deviation from the normal patterns.
Business logic
Chemwatch WebService represents a business layer of the three tier architecture. It is the backbone of the entire system topology. All the calculations and data processing are conducted in the WebService. It also supplies data and processes requests from front end applications providing output in 5 different formats (JSON, SOAP, CSV, ZIP, or XML).
WebService is absolutely stateless and implements SOA pattern. Its architectural role is to detach the front end from the database. It is developed with the concept of reversibility claiming that database implementation should be generic, so if there is a need to replace the database, it can be done quickly and efficiently.
The service provides different types of services to the end user applications, starting with authentication to document and report generation.
The service is entirely developed using .NET 4.5 framework. The solution corresponds to the latest performance and security standards. All the operations with client side are going through secure protocols (SSL). User access is tracked session-wisely.
Front end
Front end is represented by Chemwatch WebAppication, which depending on the subscription type comes into one of available packages: Backpack, ChemFFX, ChemGold, Cobra/Coshhpliant, SmartCobra, Chemritus, AuthorITe. etc.
Each client connects to a single WebService instance to request data and to save user input into the database. Basic calculations can be performed on the client side, but this is discouraged. Instead we have built a reusable library that holds all the client-side logic throughout all the products. This ensures that all Chemwatch products work in a consistent manner.
Web based clients are developed using .NET 4.0 Framework and work efficiently under different browsers such as: Internet Explorer 8.0 through latest, FireFox 3.6 through latest, Chrome 14 through latest, Safari S5.
SmartCobra for the iPhone and Android is created using mobile development frameworks.
Application Platform
Both Business layer and Front end run on IIS7.5 under Windows 2008 Server Datacenter Edition. Amazon is responsible for keeping those up to date and installing all the required security updates.You can learn more about WebService by watching video presentation:
http://www.chemwatch.net/marketing/presentations/webServ/video.
Integration capabilities
Web Service API 2.0 enables clients to create live data or document links to other application using:
- SOAP/WSDL
- REST (JSON, XML)
Any modern programming language has means to send and receive web requests (HTTP/HTTPS). This is all that is required to build connectivity to Chemwatch Web API 2.0.
API provides:
- 24x7 operation time
- High reliability (more than 99.9% uptime)
- Backwards compatibility
Operational considerations
System overview
Amazon cloud allows us to provide the high end level of data safety and disaster recovery. A separate instance of the database is maintained up to date with Master-Slave synchronization schema in a different geographical region. We can use that second instance at any time to recover data.
Amazon cloud also enables us to quickly scale the system to cope with increased load at runtime. A tailored balancing mechanism is used to enhance server capabilities automatically when required.
All the critical updates are installed by Amazon timely, maintaining the system in its current state and decreasing any risks associated with security vulnerabilities.
System topology
The server infrastructure which serves all clients consists of two application servers, both of which are located in two separate physical data centers in California, United States.
One server remains dormant and is only activated when there is either a traffic surge or the active server hardware is being overwhelmed.
Both application servers are pointing to a master Oracle database. This Master is synchronized one way to a low spec active Oracle database located in Tokyo. In addition to this database, there will be a dormant application server that can be activated should the need arise.
Based on our tests, California and Tokyo provide the best connection to the rest of the world including Europe and Australia.
Data Security
In the Cloud solution, user data stored is available only to the user and Chemwatch IT (to provide the support). Other customer cannot get an access to the other client’s information as it is protected by security login and password. To make sure no outside person can get hold of the user data we established a “white list” of IP addresses allowed to connect databases directly. In order to secure traffic we can enable SSL (MD5) /TLS (SHA-1) secure connection between Chemwatch and the client. Additionally we implement TLS secure connection on our server, so customer may use the power of SHA-1 hashing key to secure the traffic.
In the Bringing Cloud to the Ground (English) solution, all the data is saved within the local network and the customer is free to use their IT policies to secure the access (firewalls, security rules and policies, audits, etc.).