EP0803154B1

A mechanism for providing security to a dual decor command host system

Abstract

This record has no abstract on file.

EP0803154B1, drawing sheet 1
Sheet 1 of 26

Term

Term ended

Expired 12 September 2015, 11 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

16 claims: 1 independent, 15 dependent

  1. 1
    A host system having a memory organized into shared and host memory areas and a hardware platform including a plurality of input/output devices operatively connected for executing host system instructions and for emulating the execution of emulated system instructions by an emulator running as an application process on said host system, said emulator including a number of emulated system executive service components operating in said shared memory area comprising a listener module and a command handler unit operatively coupled together and an interpreter, an emulator monitor call unit EMCU and server facilities operating in said host memory area, said host system further including operating system facilities for providing a number of services for host programs, said operating system facilities being coupled to said plurality of input/output devices and to said EMCU, said host system further including validation means for allowing only trusted emulated system users to access host system facilities through a predetermined set of dual decor commands, said validation means comprising:user identity validation means included in said listener module, said user validation means in response to each emulated system user initiated login procedure verifying that the user has been given access to host facilities by generating a special monitor call for causing said EMCU to invoke predetermined ones of said host services for validating that the user is an authorized host system user and for causing the generation of a unique user description entry for each validated user to perform subsequent user level validations of said each emulated system user identity;a user table USTBL mechanism located in said host memory area, said USTBL mechanism having a number of locations for storing said unique user description entry generated by said EMCU;and, said server facilities including first server handler means including user security validation means, said security validation means in response to each input/output request generated by said command handler means in response to an emulated system user requesting access to said host facilities through one of said predetermined commands, performing a validation operation on said emulated system user by accessing said user table mechanism entry associated with said user requesting access to ascertain that said command was issued by a trusted user and would not compromise host system security and said first server handler means enabling execution of commands only when said validation operation confirms that the command was issued by a trusted user.