上海讯联数据服务有限公司

Amazon Web Services Case Study: CardInfoLink

2022

Established in 2010, Shanghai CardInfoLink Data Service Co., Ltd. (“CardInfoLink”) specializes in domestic and cross-border payment processing and data services. Its businesses range from UnionPay card acquiring and international bank card acquiring and issuance processing, to overseas and innovative O2O payment processing services. CardInfoLink is headquartered in Shanghai, China, with one domestic branch and four overseas branches. Over half of its some 200 employees are engineers.

CardInfoLink, which received investment from Sequoia Capital in 2014, is the only third-party service provider in China that has established system and network connections with all six major international payment card organizations. With the boom of Internet Finance, CardInfoLink plans to further enhance its technologies and services and broaden its business to become a leading data processor in the Chinese payment industry, be able to process massive volume of transactions, and help its partners unlock the business potentials of various payment applications and users. It strives to be a vital part of China’s payment industry and a contributor to the payment infrastructures of the “Internet Plus” era.

Challenges

CardInfoLink has been positioned as a technology service provider from the day it was founded. Connecting payment card issuers and organizations with acquirers and merchants, CardInfoLink offers the underlying technologies that power the payment industry and help it run seamlessly. Over the years, CardInfoLink’s services have expanded from third-party and consolidated payment to mobile payment infrastructure, as business now also extends to the overseas market. Closely following the global footsteps of Alipay and WeChat Pay, CardInfoLink was among the first wave of payment service providers to offer international services, and indeed a leader in replicating domestic business models and success on the global stage.

Acquiring and payment processing lies at the core of CardInfoLink’s expanding overseas business and demands rock solid system stability. Moreover, customers’ recognition and acceptance of the underlying IT infrastructure is also a major factor of consideration. Previously, CardInfoLink mainly relied on IDC hosting services, complemented by public cloud services to support business growth in the domestic market. But taking IDC services overseas not only comes with disproportionally high system and management costs, but also severely limits resource and cost scalability as business expands. Moreover, in the scenarios such as flash sales or similarity, the hardware and network environment in the traditional IDC setup would be overstretched to maintain the level of stability. The impossible trinity of low maintenance, reasonable cost, and achievement of business objects under the IDC model makes this solution unsustainable.

Fundamentally, CardInfoLink needs an IT infrastructure that well-balances stability, scalability, and cost—delivering the committed SLA, easily expandable system features and performance, and supporting dynamic changes to the system cost structure to achieve optimal allocation of resources and expenses. Based on these criteria, CardInfoLink naturally set eyes on a public cloud service.

1061299140
kr_quotemark

With EVO Cloud, our core platform built with Amazon Web Services, CardInfoLink apps have achieved an overall availability of 99.95% and years of 0 security incident. Similarly, Amazon EKS’ managed container service, which powers our cloud-based DevOps system, has shortened our software iteration cycle from 4-6 weeks to 2 weeks.”

Jacky Zhang

CTO of Shanghai CardInfoLink Data Service Co., Ltd.

Why Amazon Web Services?

During the selection process, CardInfoLink carefully weighed the available options in terms of feasibility, cost, and compliance, deciding finally on Amazon Web Services as its preferred cloud service provider that would power its overseas business. In Jacky’s view, the following factors were the key drivers of this decision.

  • From a business perspective
  • CardInfoLink was particularly concerned about how smoothly its payment processing services can interface with the customers. AWS has a very high brand recognition among overseas banks, payment institutions, and large merchants. Furthermore, it fully meets the security and compliance requirements of different regions, industries, and customers, which credentials the end users can directly inherit. For example, AWS is certified as a PCI DSS Level 1 Service Provider and as in compliance with the relevant ISO/IEC standards. This means it is able to store, process, and transmit data in a secure, compliant manner and help ensure CardInfoLink’s security management program is fully consistent with industry standards.

  • Technology-wise
  • CardInfoLink’s top concerns were the complexity of building and managing its system on the cloud as well as system stability, performance, and security. In terms of the technology stack, AWS offers powerful and fully integrated service components, which can readily meet CardInfoLink’s existing and future usage needs and enable the quick implementation of customized solutions, delivering both architectural elasticity and flexibility. In terms of system stability, AWS helps ensure business continuity can meet the stated SLA, as it supports both multi-Availability Zone deployment within a single Region and cross-Regional disaster recovery. In addition, AWS holds a distinctive advantage in cross-regional collaboration and dynamic resource scaling, allowing CardInfoLink to better balance performance and cost.

  • In service support and experience
  • AWS’ command line interface (CLI) offers a smooth learning curve and high flexibility, and is highly compatible with the toolchain used internally at CardInfoLink, making it easy for its team to integrate the systems deployed internally and manage the related procedures and tools. Furthermore, AWS offers a wide array of technical documentations and implementation guides and a highly active community, allowing CardInfoLink to quickly find the answers to system architecture questions. In additional, AWS provided pragmatic and well-structured training to help CardInfoLink to quickly get started on system building.

    Moreover, AWS’ broad infrastructure coverage and consistent architecture and services permit CardInfoLink to deploy systems close to its customers’ location, at once meeting the regulatory requirements on local data residency and supporting lower-latency payment processing.

    Planning and implementation of the first AWS-powered system began in 2017 to support overseas acquiring and payment processing. Currently, CardInfoLink has established a SaaS-based payment processing system in several overseas regions. Its EVO Cloud, running on AWS, acts as a customer-facing payment processing gateway and acquiring platform, delivering payment processing services to both international bank card organizations like Visa and MasterCard as well as e-wallets including Alipay and WeChat Pay. The auxiliary payment services (e.g., account reconciliation and management) and value-added services, such as customized supply chain finance and marketing solutions are also supported. CardInfoLink also harnesses the power of AWS to build EVONET, its mobile payment infrastructure for the Asia-Pacific market, and cross-border clearing business, to expand the user base and help industries become more connected and accessible.

    CardInfoLink uses the following Amazon Web Services: Amazon Elastic Compute Cloud (Amazon EC2), Amazon Simple Storage Service (Amazon S3), Amazon Elastic File System (Amazon EFS), Amazon Virtual Private Cloud (Amazon VPC), Elastic Load Balancing, Amazon ElastiCache, Amazon Elastic Kubernetes Service (Amazon EKS), Amazon Relational Database Service (Amazon RDS), Amazon Transfer Family, Amazon API Gateway, Amazon Simple Email Service (SES), Amazon Simple Notification Service (Amazon SNS), Amazon PrivateLink, Amazon CloudWatch, Amazon CloudTrail, Amazon WAF, Amazon Shield, Amazon Key Management Service (Amazon KMS), and Amazon Global Accelerator.

讯联数据基于亚马逊云科技的系统架构示意图
CardInfoLink Architecture on Amazon Web Services

Benefits

From third-party payment to aggregate payment and then to mobile payment infrastructure, CardInfoLink has now deployed its EVO Cloud service on AWS. Overseas business now encompasses WeChat Pay and Alipay as well as local wallets such as WeChat HK, Grab Pay in Singapore, and NTT Docomo in Japan. Currently CardInfoLink has business in more than 30 countries and regions worldwide through its regional offices and teams in Hong Kong, Tokyo, and Singapore, providing integrated technical solutions to the mainstream acquiring banks and third-party payment companies around the world.

Jacky said what the benefit CardInfoLink using AWS are in the following ways:

First, AWS has significantly reduced the complexity of system monitoring and cross-regional network connections, and hence the upkeep burden of its system and network hardware environment. For instance, the combination of Amazon EC2’s AMI lifecycle management function with CardInfoLink’s proprietary, MongoDB Oplog-based incremental backup feature helps control the company’s backup resources and costs and enables periodic full backup plus incremental backup. With VPC Peering, Amazon PrivateLink, and CloudWatch, CardInfoLink is able to build fast, secure cross-regional networks, reducing latency from seconds to the millisecond-level for more efficient coordination of resources.

Second, it comes with significant cost optimizations, enabling faster launch-to-profitability cycle for product and service innovations. For the hardware cost component, AWS allows CardInfoLink to dynamically scale resources, and hence system cost, with business volume, which prevents large-scale hardware investment. For the upkeep and staff cost component, AWS makes it possible for CardInfoLink to reassign team from traditional maintenance tasks to innovation and site reliability engineering (SRE) activities. Notably, the cloud-based DevOps system, based on the fusion of Amazon EKS and ElastiCache with the CI/CD (continuous integration/continuous delivery) pipeline, has shortened software iteration cycle from 4-6 weeks to 2 weeks.

Third, AWS delivers security, stability, and system performance to drive sustainable business growth. At the system level, Amazon WAF and Amazon Shield offer essential protection against common threats such as DDoS, and their penetration tests and vulnerability scans help CardInfoLink keep its application platform free of security incident for many years in a row. At the data-level, static and dynamic data encryption is performed at every stage such as storage and transmission, while TLS is enabled for databases. Amazon KMS helps CardInfoLink to manage production environment keys and stay compliant. With AWS, CardInfoLink applications have achieved an overall availability of 99.95%, winning over customers and market shares.

CardInfoLink was also impressed by AWS’ expandability. During one “Double 11 Shopping festival”, EVO Cloud’s transaction per second (TPS) surged more than ten-fold. Thanks to traffic control strategies and auto scaling, the platform handled the traffic spike with aplomb.
CardInfoLink plans to further enrich its online service offerings such as customized marketing systems and risk identification and control. In particular, AWS’ powerful Lake House Architecture and big data-powered machine learning and analytics all have much to offer. The containerization of system services is another major upcoming project. “Whether its cloud-based solutions or local architectures based on the customers’ own resource pools, AWS can help CardInfoLink meet customer needs through a sensible approach and continue to break new ground,” Jacky concluded.


Established in 2010, Shanghai CardInfoLink Data Service Co., Ltd. (“CardInfoLink”) specializes in domestic and cross-border payment processing and data services. Its businesses range from UnionPay card acquiring and international bank card acquiring and issuance processing, to overseas and innovative O2O payment processing services.

Why Choose AWS

  • Robust security and compliance guarantees and broad market recognition
  • An optimal balance of system stability,  performance, operation cost and business goals
  • Smooth learning curve and consistent technology architecture and services

AWS Services Used

Amazon WAF

Amazon WAF is a web application firewall that helps protect your web applications or APIs against common web exploits and bots that may affect availability, compromise security, or consume excessive resources. 

Learn More >>

Amazon ElastiCache

Amazon ElastiCache is a web service that makes it easy to deploy, operate, and scale an in-memory data store or cache in the cloud. 

 

Learn More >>

Amazon EKS

Amazon Elastic Kubernetes Service (Amazon EKS) makes it easy to deploy, manage, and scale containerized applications using Kubernetes on Amazon Web Services.

Learn More >>

Amazon RDS

Amazon Relational Database Service (Amazon RDS) makes it easy to set up, operate, and scale a relational database in the cloud. 

 

Learn More >>


Get Started

Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Contact our experts and start your own AWS journey today.