IP Library Granted Patent US 9,444,629
Granted Patent B2
US 9,444,629 · App. 13/902,442 · Granted Sep 13, 2016

Dual layer transport security configuration

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,444,629
App. No.
13/902,442
Granted
Sep 13, 2016
Kind
B2
Abstract

A system includes a first computer processor that receives a data transmission from a second computer processor. The data transmission includes a client certificate authentication and a user-based authentication. If the incoming information cannot be authenticated by the client certificate in a first layer of the system landscape, then there is no further data transmission to a second layer. If the first layer can authenticate the client certificate authentication, the system landscape transmits the data transmission to the second layer. If the second layer cannot authenticate the user-based authentication, the system prevents the data transmission from being processed at the second layer. If the second layer can authenticate the user-based authentication, the system processes the data transmission at the second layer.

Claims (41)

1. A system comprising:

a first computer processor in a computer landscape performing the following operations:

receive a data transmission from a second computer processor via a data transmission network, wherein the data transmission comprises a client certificate authentication and a user-based authentication;

verify, at a first layer of the computer landscape, the client certificate authentication, wherein the first layer of the computer landscape comprises a network layer;

in response to determining at the first layer that the data transmission cannot be authenticated by the client certificate authentication, prevent the data transmission from being transmitted to a second layer of the computer landscape, wherein the second layer of the computer landscape comprises an application layer;

in response to determining that the data transmission is authenticated by the client certificate authentication, transmit the data transmission to the second layer of the computer landscape;

in response to receiving the data transmission at the second layer from the first layer, verify the user-based authentication at the second layer;

in response to determining at the second layer that the data transmission cannot be authenticated by the user-based authentication, prevent the data transmission from being processed at the second layer; and

in response to determining at the second layer that the data transmission is authenticated by the user-based authentication, process the data transmission at the second layer;

wherein the processing the data at the second layer comprises sending an acknowledgment from the first computer processor to the second computer processor acknowledging that the first computer processor has received the data transmission;

wherein the first computer processor transmits the payment instruction transmission to a third computer processor for processing by the third computer processor; and

wherein the computer landscape comprises a multi-layer network.

2. The system of claim 1 , wherein the client certificate authentication comprises an authentication for a particular client, the particular client comprising a plurality of users.

3. The system of claim 2 , wherein the particular client comprises a business organization.

4. The system of claim 1 , wherein the client certificate authentication comprises a client certificate that was previously electronically signed by a party receiving the data transmission.

5. The system of claim 1 , wherein the user-based authentication comprises an authentication for a particular individual user, and wherein the particular individual user is associated with a particular client.

6. The system of claim 1 , wherein the user-based authentication comprises a user-name and password.

7. The system of claim 1 , wherein the data transmission network comprises an Internet-based service.

8. A process comprising:

receiving into a computer landscape a data transmission from a data transmission network, wherein the data transmission comprises a client certificate authentication and a user-based authentication;

verifying, at a first layer of the computer landscape, the client certificate authentication, wherein the first layer of the computer landscape comprises a network layer;

in response to determining at the first layer that the data transmission cannot be authenticated by the client certificate authentication, preventing the data transmission from being transmitted to a second layer of the computer landscape, thereby reducing network traffic that enters into the application layer, wherein the second layer of the computer landscape comprises an application layer;

in response to determining that the data transmission is authenticated by the client certificate authentication, transmitting the data transmission to the second layer of the computer landscape;

in response to receiving the data transmission at the second layer from the first layer, verifying the user-based authentication at the second layer;

in response to determining at the second layer that the data transmission cannot be authenticated by the user-based authentication, preventing the data transmission from being processed at the second layer; and

in response to determining at the second layer that the data transmission is authenticated by the user-based authentication, processing the data transmission at the second layer;

wherein the processing the data at the second layer comprises sending an acknowledgment from the first computer processor to the second computer processor acknowledging that the first computer processor has received the data transmission;

wherein the first computer processor transmits the payment instruction transmission to a third computer processor for processing by the third computer processor; and

wherein the computer landscape comprises a multi-layer network.

9. The process of claim 8 , wherein the client-based authentication comprises a client certificate that was previously electronically signed by a party receiving the data transmission.

10. A computer readable storage device comprising instructions that when executed by a processor execute a process comprising:

receiving into a computer landscape a data transmission from a data transmission network, wherein the data transmission comprises a client certificate authentication and a user-based authentication;

verifying, at a first layer of the computer landscape, the client certificate authentication, wherein the first layer of the computer landscape comprises a network layer;

in response to determining at the first layer that the data transmission cannot be authenticated by the client certificate authentication, preventing the data transmission from being transmitted to a second layer of the computer landscape, wherein the second layer of the computer landscape comprises an application layer;

in response to determining that the data transmission is authenticated by the client certificate authentication, transmitting the data transmission to the second layer of the computer landscape;

in response to receiving the data transmission at the second layer from the first layer, verifying the user-based authentication at the second layer;

in response to determining at the second layer that the data transmission cannot be authenticated by the user-based authentication, preventing the data transmission from being processed at the second layer; and

in response to determining at the second layer that the data transmission is authenticated by the user-based authentication, processing the data transmission at the second layer;

wherein the processing the data at the second layer comprises sending an acknowledgment from a first computer processor to a second computer processor acknowledging that the first computer processor has received the data transmission;

wherein the first computer processor transmits the payment instruction transmission to a third computer processor for processing by the third computer processor; and

wherein the computer landscape comprises a multi-layer network.

Assignments (2)
CHANGE OF NAME Recorded Aug 26, 2014
From: SAP AG
To: SAP SE
Reel/Frame 033625/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2013
From: VISHAL, VIVEK
To: SAP AG
Reel/Frame 030484/0883 →