The global and independent platform for the SAP community.

Hana Security - three scenarios

The topic of security is highly dependent on the particular use of Hana. The security concepts differ depending on the use case. The following are the most important security considerations and features per use case.
Thomas Kümmerle, Turnkey
November 2, 2015
2015
avatar
This text has been automatically translated from German to English.

Hana can be used as a database in a traditional architecture, another option is to use Hana as a platform, or to integrate Hana as a data mart in a BW landscape.

The three different scenarios have a direct influence on the Hana security concept.

First: Database in a traditional 3-tier architecture: In this scenario, the database located under the application server is replaced by Hana.

Second: Hana as a platform: In this scenario, the database is also replaced by Hana, but the applications are also provided on the Hana platform.

Third: Hana as a data mart in a BW landscape: In this deployment scenario, Hana is used in parallel with an existing database. The data can then be replicated from various source systems, for example from an SAP or third-party system, into the SAP Hana database.

Hana as a database

Hana has also introduced a new terminology to the topic of security. In Hana, a distinction is made between catalog roles and repository roles. Catalog roles contain runtime objects (schemas, tables, views and roles), while repository roles contain design-time objects (package, views, authorizations and roles).

Another feature is that repository roles - like any other object in the Hana Repository - are transportable, while this is not applicable to catalog roles.

The repository roles have the _SYS_REPO user as owner, while catalog roles have the developer as owner, which means that if the developer user is deleted, the content of the catalog roles is also deleted.

The roles in the Hana container for access authorizations are similar to those in Abap. The authorizations (privileges) are grouped in a structured manner in a role.

Roles in Hana are objects and access is controlled accordingly via the object privileges. However, roles can also contain other roles in addition to authorizations.

Hana as a platform

Security Model

The Hana Security Model provides for various authorization types (privilege types):

Object Privileges: Object privileges are used to control access to objects. In Hana, for example, these are tables/views, roles, stored procedures and synonyms. In the case of tables or views, the "Object Privileges" could be compared with the S_TABU_NAM object in the Abap world.

Analytic Privileges: Access to the Hana data model is controlled via the Analytic Privileges. While Object Privileges control access to the object (table, view), Analytic Privileges control access to specific data from the object at a granular level.

The counterpart to this in Abap would be the authorization object S_TABU_LIN, which can also be used to control access to certain rows accordingly. However, Analytic Privileges are intended for read-only access to the Hana information models (Attribute View, Analytic Views, Calculation Views).

Master data is modeled in a Hana attribute view and an attribute view can perform similar tasks to linked universes in SAP BO. A fact table with its associated attributes is modeled in a Hana Analytic View.

An Analytic View can be compared to an SAP-BO universe with exactly one fact table. The Hana Calculation Views are used to map multiple facts or calculated joins and allow the connection of multiple fact tables, comparable to SAP BO contexts in universes.

System Privileges: Access to the administrative functions is controlled via the system privileges.

Package Privileges: Packages are used in Hana to structure the repository content. Package privileges are used to control access to the package and all associated sub-packages. The structure of the packages is not specified by SAP and is left to the customer.

Application Privileges: Access to the Hana XS application and functionality is controlled via the application privileges. This controls, for example, which applications can be started and which functions and screens are displayed.

Roles - Good Practices: For the reasons already mentioned, priority should be given to repository roles when creating roles. SAP itself recommends the use of repository roles.

More and more, the integrated applications - which are delivered with Hana - are also being provided with predefined repository roles. In any case, the security requirements should be taken into account in good time during the design phase and the development process.

Subsequent adaptation can involve considerable effort. When designing the package structure, it is advisable to also consider the corresponding controls (package privileges), for example HR, Non-HR/Sensitive, Non-Sensitive.

Hana as a data mart

avatar
Thomas Kümmerle, Turnkey

Thomas Kümmerle is Managing Director at Turnkey Consulting Switzerland. He has many years of IT security experience in SAP ERP authorizations, Regulatory & Legal Compliance (SoD, SOX), SAP BI authorizations, Data Privacy and Protection.


Write a comment

Working on the SAP basis is crucial for successful S/4 conversion. 

This gives the Competence Center strategic importance for existing SAP customers. Regardless of the S/4 Hana operating model, topics such as Automation, Monitoring, Security, Application Lifecycle Management and Data Management the basis for S/4 operations.

For the second time, E3 magazine is organizing a summit for the SAP community in Salzburg to provide comprehensive information on all aspects of S/4 Hana groundwork.

Venue

FourSide Hotel Salzburg,
Trademark Collection by Wyndham
Am Messezentrum 2, 5020 Salzburg, Austria
+43-66-24355460

Event date

Wednesday, June 10, and
Thursday, June 11, 2026

Early Bird Ticket

Regular ticket

EUR 390 excl. VAT
available until 1.10.2025
EUR 590 excl. VAT

Venue

Hotel Hilton Heidelberg
Kurfürstenanlage 1
D-69115 Heidelberg

Event date

Wednesday, April 22 and
Thursday, April 23, 2026

Tickets

Regular ticket
EUR 590 excl. VAT
Subscribers to the E3 magazine
reduced with promocode STAbo26
EUR 390 excl. VAT
Students*
reduced with promocode STStud26.
Please send proof of studies by e-mail to office@b4bmedia.net.
EUR 290 excl. VAT
*The first 10 tickets are free of charge for students. Try your luck! 🍀
The event is organized by the E3 magazine of the publishing house B4Bmedia.net AG. The presentations will be accompanied by an exhibition of selected SAP partners. The ticket price includes attendance at all presentations of the Steampunk and BTP Summit 2026, a visit to the exhibition area, participation in the evening event and catering during the official program. The lecture program and the list of exhibitors and sponsors (SAP partners) will be published on this website in due course.