SAP HANA Cloud Integration CUSTOMER

Similar documents
How-To Guide SAP Cloud for Customer Document Version: How to Configure SAP HCI basic authentication for SAP Cloud for Customer

Data Integration using Integration Gateway. SAP Mobile Platform 3.0 SP02

Integration capabilities of SAP S/4HANA to SAP Cloud Solutions

How-To Guide SAP NetWeaver Document Version: How To Guide - Configure SSL in ABAP System

Integration Capabilities of SAP S/4HANA to SAP Cloud Solutions

How to Extend SAP Cloud for Customer - SAP On- Premise Pre-Packaged Integration Content (PI/HCI)

PUBLIC Connecting a Customer System to SAP HCI

How-To Guide SAP Cloud for Customer Document Version: How to replicate marketing attributes from SAP CRM to SAP Cloud for Customer

Getting Started with the License Administration Workbench 2.0 (LAW 2.0)

R49 Using SAP Payment Engine for payment transactions. Process Diagram

SAP ERP E-Commerce and SAP CRM Web Channel Enablement versions available on the market

Software and Delivery Requirements

Transform HR into a Best-Run Business Best People and Talent: Gain a Trusted Partner in the Business Transformation Services Group

How-To Guide SAP Cloud for Customer Document Version: How to Perform Initial Load of data from SAP ERP to SAP Cloud for Customer

Managing a Hybrid Model Integration of SAP HCM with SuccessFactors BizX Talent Management. Bianka Woelke SAP HCM Product Management

SEPA in SAP CRM. Application Innovation, CRM & Service Industries. Customer

Upgrade: SAP Mobile Platform Server for Windows SAP Mobile Platform 3.0 SP02

Real-Time Reconciliation of Invoice and Goods Receipts powered by SAP HANA. Stefan Karl, Finance Solutions, SAP ASUG Presentation, May 2013

Cut Costs and Improve Agility by Simplifying and Automating Common System Administration Tasks

Unlock the Value of Your Microsoft and SAP Software Investments

Partner Certification to Operate SAP Solutions and SAP Software Environments

Installation Guide: Agentry Device Clients SAP Mobile Platform 2.3

Landscape Design and Integration. SAP Mobile Platform 3.0 SP02

SAP / SERVIEW Roadshow SAP Solution Manager macht ITIL möglich! David Birkenbach / ITSM Solution Management

SAP Business One mobile app for Android Version 1.0.x November 2013

SFSF EC to 3 rd party payroll Integration Software and Delivery Requirements

Using SAP Logon Tickets for Single Sign on to Microsoft based web applications

PUBLIC Operations Guide

SBOP Analysis 2.1, edition for Microsoft Office Additional PAM Information

Start Anywhere and Go Everywhere with Cloud Services for HR

SAP ERP EMPLOYEE INTERACTION CENTER

Power Smart Business Operations with Real-Time Process Intelligence

Protect Your Connected Business Systems by Identifying and Analyzing Threats

SAP Cloud for Customer integration with SAP ERP: Software and Delivery Requirements

Business-Driven, Compliant Identity Management

SAP HANA Enterprise Cloud

Simplify and Secure Cloud Access to Critical Business Data

Ariba Procure-to-Pay Integration rapiddeployment

Contents. About this Support Package / Patch...5. To install the EPM Add-in for Microsoft Office Support Package 15 / Patch XX...

Mobile app for Android Version 1.2.x, December 2015

Streamline Processes and Gain Business Insights in the Cloud

SAP Mobile Documents. December, 2015

A Cloud-Based Foundation for Enterprise Mobility

Performance Best Practices Guide for SAP NetWeaver Portal 7.3

Transform Invoice Management with a Hybrid of Cloud and On-Premise Software

Mobile app for Android Version 1.0.x, January 2014

SAP HANA virtualized Technology Roadmap. Arne Arnold, SAP HANA Product Management September, 2014

SAP HANA Live & SAP BW Data Integration A Case Study

Certificate SAP INTEGRATION CERTIFICATION

SAP Document Center. May Public

Securing Enterprise Mobility for Greater Competitive Advantage

SAP NetWeaver Identity Management Identity Services Configuration Guide

Automotive Consulting Solution. CHEP - EDI- Container Data

An End-to-End Population Health Management for High Risk Patients

Roadmap from On-Premise to Cloud based Integration solutions from SAP

SAP HANA SPS 09 - What s New? HANA IM Services: SDI and SDQ

How To Make Your Software More Secure

Installing and Configuring the HANA Cloud Connector for On-premise OData Access

SAP BusinessObjects Cloud

Single Sign-On between SAP Portal and SuccessFactors

SAP HANA Cloud Platform

T-Systems: Operate Complex IT Landscapes Efficiently with SAP Landscape Virtualization Management

SuccessFactors Global Human Capital Management (HCM) Academy and Admin Training Schedule (Q3 Q4 2014)

White Paper. SAP NetWeaver Landscape Virtualization Management on VCE Vblock System 300 Family

SAP Project Portfolio Monitoring Rapid- Deployment Solution: Software Requirements

Elevate Your Customer Engagement Strategy with Cloud Services

Remote Connectivity Infrastructure

SAP Audit Management A Preview

How-to-Guide: SAP Web Dispatcher for Fiori Applications

Migration and Upgrade Paths to SAP Process Orchestration. Udo Paltzer Product Owner SAP Process Integration, SAP HANA Cloud Integration

SAP-Managed Migration to SAP Business Suite powered by SAP HANA in the Cloud

SAP Sales and Operations Planning

Sending Additional Files from SAP Netweaver PI to third Party System

Driving Transformation with Less Budget The Value of SAP Enterprise Support

Formulate Winning Sales and Operations Strategies Through Integrated Planning

CUSTOMER Presentation of SAP Predictive Analytics

Cloud Single Sign-On and On-Premise Identity Federation with SAP NetWeaver Cloud White Paper

Protect Your Customers and Brands with Multichannel Two-Factor Authentication

MLP: Simpler Processes and Improved Usability with SAP Customer Relationship Management

Configuring Java IDoc Adapter (IDoc_AAE) in Process Integration. : SAP Labs India Pvt.Ltd

SAP Business ByDesign and SAP ERP. SAP Business ByDesign for Subsidiaries Overview of Functional and Technical Integration with Headquarters SAP ERP

SAP Learning Hub: Your Competitive Advantage for a Career in SAP Solutions

SAP BusinessObjects Design Studio Document Version: What's New Guide: SAP BusinessObjects Design Studio

Optimize Revenue for High-Volume Service Providers with Pricing Simulation

SAP Best Practices for SAP Mobile Secure Cloud Configuration March 2015

Certification Guide Network Connectivity for SAP on Premise and Cloud Solutions Integration

SAP BusinessObjects Business Intelligence 4.1 One Strategy for Enterprise BI. May 2013

Real-Time Analytics: Integrating Social Media Insights with Traditional Data

Price and Revenue Management - Manual Price Changes. SAP Best Practices for Retail

SAP MII for Manufacturing rapid-deployment solution: Software Requirements

Transcription:

CUSTOMER

Table of Contents 1 Introduction.... 3 2 from a Bird s Eye Perspective....4 3 Integration Capabilities....5 4 Connectivity Options....7 5 Using Predefined Integration Content....8 6 Security.... 9 6.1 Transport Level Security....9 6.2 Message Level Security....9 6.2.1 Message Level Security Based on PKCS#7/CMS Enveloped Data and Signed Data....10 6.3 Tenant Isolation....10 2 2013 SAP AG or an SAP affiliate company. All rights reserved. Table of Contents

1 Introduction This document provides an overview of the process integration-related capabilities of SAP HANA Cloud Integration - Application Edition. Introduction 2013 SAP AG or an SAP affiliate company. All rights reserved. 3

2 from a Bird s Eye Perspective This document provides an overview of the process integration capabilities of. is a platform hosted in the SAP HANA Cloud. It facilitates the integration of business processes spanning different companies, organizations, or departments within an organization. It supports endto-end process integration across cloud-based and on-premise applications (cloud-cloud and cloud-on-premise integration). It also provides data integration capabilities that allow you to efficiently and securely move data between onpremise systems and the cloud. Note This document provides an overview of the process integration-related capabilities of SAP HANA Cloud Integration. comprises the following key features: Core runtime for processing, transformation, and routing of messages to be exchanged between the involved participants Message processing at runtime is performed by a cluster of virtual machines running on SAP HANA Cloud. Here, the platform ensures that data related to different customers connected to SAP HANA Cloud Integration is isolated. This is important, for example, when using for businessto-business scenarios. Out-of-the-box connectivity support (IDoc, SFTP, SOAP/HTTPS) Security features such as content encryption and certificate-based communication Customers who want to use have to first set up the connection between their backend systems and SAP HANA Cloud. This process referred to as the onboarding process involves a tight and coordinated cooperation of experts at SAP and on customer's side. SAP provides continuous guidance and support during the whole onboarding process. The current version of is available for customers and partners as an Application Edition, especially for a dedicated set of SAP OnDemand solutions (SAP Customer OnDemand, SuccessFactors BizX, SAP Financial Services Network). Upon purchase, predefined, ready-to-use prepackaged integration content can be made available by SAP without the immediate need for additional hardware or integration skills on the customer s side. This drastically reduces integration project lead times and lowers resource consumption significantly. For reasons of simplicity, we refer to all kinds of parties, back-end systems, or applications that exchange messages with each other using under the generalized term participant. offers full flexibility in how participants can exchange messages by the following: Leveraging preconfigured integration patterns. These integration patterns provide different options for configuring the data flow between participants, for example, by using routing rules. Using various connectivity options. This covers a set of adapters (or endpoint types) that allow participants to connect with different communication protocols to. 4 2013 SAP AG or an SAP affiliate company. All rights reserved. from a Bird s Eye Perspective

3 Integration Capabilities This section summarizes various ways in which participants exchange messages with each other when running an integration scenario based on. The following figure illustrates an example of the routing capability, where a message from one participant is forwarded by to three different receivers. The following table summarizes all integration patterns supported by. Integration Capability Routing Description Forwards (routes) a message to one or more receivers. also supports routing that depends on the content of the message (contentbased routing). For example, detects that a message has a particular field value, and forwards it to the specific receiver participant that handles requests from the sender participant. Mapping Transforms (maps) sender into receiver data structures. In scenarios spanning different application systems or different organizations and enterprises, it is very likely Integration Capabilities 2013 SAP AG or an SAP affiliate company. All rights reserved. 5

Integration Capability Description that the structure of the data exchanged between two participants will differ on both sides of a connection due to business-related reasons. To enable a seamless exchange of data, the data structures on both sides of a connection have to be transformed (or: mapped) into each other. allows structural mapping of XML documents. You can re-use existing on-premise content (service interfaces / message mappings / operation mappings / XSLT based mappings) from an SAP Enterprise Services Repository (EHP 1 for SAP NetWeaver 7.3). Value mappings allow you to map different representations of an object to each other. Value mappings are useful when performing a dynamic value lookup of an object that has different representations in different contexts. In value mappings, you map these different representations of an object to each other by setting mapping rules in a value mapping table. Note For example: You can use a value mappingto map a Merchant ID to a Customer ID, where Merchant ID is an external application representation of a customer, while Customer ID is an internal SAP representation. Content enricher Content filter Encoder/decoder (Base64) Splitter Extends the message content with additional information (constant, xpath, header, expression). Filters information by extracting a specific node from the incoming message. Encodes message content using an encoding scheme. This function is useful where secure content transfer over the network is required. Breaks down a composite message into multiple individual messages and sends them to a receiver. 6 2013 SAP AG or an SAP affiliate company. All rights reserved. Integration Capabilities

4 Connectivity Options Various connectivity options also referred to as adapters allow you to connect to different kinds of technical communication protocols. The following table summarizes all adapters provided by. Connectivity Option SFTP client adapter Description Enables you to connect an SFTP server to SAP HANA Cloud Integration (which acts as a client). This enables you to use Secure Shell File Transfer Protocol (SSH File Transfer Protocol, abbreviated to SFTP). This option is particularly useful for secure communication between and non-sap system environments. The following versions are supported: SSH version 2 (as specified at http:// tools.ietf.org/html/rfc4251) SSH File Transfer Protocol (SFTP) version 3 or higher IDoc (IDoc SOAP) adapter Enables you to set up reliable communication of IDoc XML documents via SOAP/HTTPS with enabled back ends of the SAP Business Suite. This option allows integration with on-premise SAP back-end systems in customers' corporate networks. SOAP adapter Enables you to exchange SOAP messages between remote clients or Web service servers and SAP HANA Cloud Integration. Connectivity Options 2013 SAP AG or an SAP affiliate company. All rights reserved. 7

5 Using Predefined Integration Content allows the participating organizations to develop, deploy, and consume services in a standardized manner. SAP provides a predefined set of integration content that covers most of the integration needs for a particular scenario. Customers can use the predefined integration contentto implement their integration scenarios with less time and effort. To accomplish this, however, customers need to register with SAP HANA Cloud Integration and complete the onboarding process as recommended by SAP. Customers can re-use existing on-premise content (message mappings / operation mappings / XSLT based mappings) from an SAP Enterprise Services Repository (EHP 1 for SAP NetWeaver 7.3). Note In the current version of, content is adjusted by SAP only (based on customer requirements). 8 2013 SAP AG or an SAP affiliate company. All rights reserved. Using Predefined Integration Content

6 Security 6.1 Transport Level Security The chosen connectivity option (adapter) and transport protocol determine the transport level security. Table 1: Adapter Transport Protocol Transport Level Security SFTP client adapter SSH SFTP (Secure Shell File Transfer Protocol) IDoc (IDoc SOAP) adapter HTTP HTTPS (SSL) SOAP adapter HTTP HTTPS (SSL) Secure data transfer with SFTP is based on a combination of symmetric and asymmetric keys. Symmetric (session) keys are used to encrypt and decrypt data within a session. Asymmetric key pairs (on the client and server side) are used to encrypt and decrypt the session keys. When asymmetric key pairs are used, SFTP also ensures that only authorized public keys are used by the involved participants. Supports SSL-based transport level security (X.509 certificate-based authentication and authorization). Supports SSL-based transport level security (X.509 certificate-based authentication and authorization). 6.2 Message Level Security You have the following option to configure message level security. Security 2013 SAP AG or an SAP affiliate company. All rights reserved. 9

Table 2: Transport Protocol Transport Level Security Message Level Security SSH HTTP SFTP HTTPS PKCS#7/CMS Enveloped Data and Signed Data Encryption/decryption of message content Signing/verifying messages 6.2.1 Message Level Security Based on PKCS#7/CMS Enveloped Data and Signed Data In addition to security at the transport protocol level, security can also be configured at the message level, based on PKCS#7/CMS Enveloped Data and Signed Data. The CMS specification can be found at: http://tools.ietf.org/ html/rfc5652 Note This option can be implemented independently of and on top of the applied transport level security. This option supports the following use cases: Signing and verifying a message Encrypting and decrypting the content of a message Note Digitally signing a message within is based on the CMS type Signed Data. Digitally encrypting or decrypting the content of a message is based on the CMS type Enveloped Data. can be configured so that messages are decrypted and re-encrypted by SAP HANA Cloud Integration on their way between the sender and receiver participants. The same applies to signing and verifying signatures. This can be useful if the services and the recipient do not have a direct communication channel, but can only communicate using an untrusted intermediary. 6.3 Tenant Isolation At runtime, processes the data that is exchanged between the involved participants on a cluster of different virtual machines hosted in the SAP cloud. Note 10 2013 SAP AG or an SAP affiliate company. All rights reserved. Security

A virtual machine (VM) is a software implementation of a machine that executes a program like a physical machine. is designed so that the involved virtual machines are strictly separated from each other with regard to the related participants. In other words, separate resources ( memory, CPU, and file system) of the cloud-based integration platform are allocated to each participant although all participants might share the same hardware. In addition, each tenant uses a separate database schema, which guarantees that the data of the different participants is strictly separated. This separation is also referred to as tenant isolation. The following figure illustrates this concept for two participants communicating with each other using SAP HANA Cloud Integration. Security 2013 SAP AG or an SAP affiliate company. All rights reserved. 11

www.sap.com/contactsap 2013 SAP AG or an SAP affiliate company. All rights reserved. No part of this publication may be reproduced or transmitted in any form or for any purpose without the express permission of SAP AG. The information contained herein may be changed without prior notice. Some software products marketed by SAP AG and its distributors contain proprietary software components of other software vendors. National product specifications may vary. These materials are provided by SAP AG and its affiliated companies ("SAP Group") for informational purposes only, without representation or warranty of any kind, and SAP Group shall not be liable for errors or omissions with respect to the materials. The only warranties for SAP Group products and services are those that are set forth in the express warranty statements accompanying such products and services, if any. Nothing herein should be construed as constituting an additional warranty. SAP and other SAP products and services mentioned herein as well as their respective logos are trademarks or registered trademarks of SAP AG in Germany and other countries. Please see http://www.sap.com/corporate-en/legal/copyright/ index.epx for additional trademark information and notices.