发明名称 ACCESSING PRIVILEGED OBJECTS IN A SERVER ENVIRONMENT
摘要 Accessing privileged objects in a server environment. A privileged object is associated with an application comprising at least one process resource and a corresponding semi-privileged instruction. The association is filed in an entity of an operating system kernel. A central processing unit (CPU) performs an authorization check if the semi-privileged instruction is issued and attempts to access the privileged object. The CPU executes the semi-privileged instruction and grants access to the privileged object if the operating system kernel has issued the semi-privileged instruction; or accesses the entity if a process resource of the application has issued the semi-privileged instruction to determine authorization of the process resource to access the privileged object. Upon positive authorization the CPU executes the semi-privileged instruction and grants access to the privileged object, and upon authorization failure denies execution of the semi-privileged instruction and performs a corresponding authorization check failure handling.
申请公布号 US2016036823(A1) 申请公布日期 2016.02.04
申请号 US201514874558 申请日期 2015.10.05
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BACHER Utz;BLASCHKA Frank;LUECK Einar;RAISCH Christoph
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A computer-implement method of accessing privileged objects in a server environment, the method comprising: associating one or more privileged objects with an application, the application comprising at least one process resource and a corresponding semi-privileged instruction, the associating providing an association; filing the association in an entity of an operating system kernel; based on the semi-privileged instruction being issued by a process resource of the at least one process resource and attempting to access the privileged object, performing an authorization check, the authorization check comprising accessing the entity to determine authorization of the process resource to access a privileged object; and performing processing based on performing the authorization check.
地址 Armonk NY US