发明名称 System for determining the rights of object access for a server process by combining them with the rights of the client process
摘要 In a multitasking, multiuser computer system, a server process temporarily impersonates the characteristics of a client process when the client process preforms a remote procedure call on the server process. Each process has an identifier list with a plurality of identifiers that characterize the process. The server process generates a new identifier list which is either the same as the client process's list, or is the union of the server's and the client's lists. Each object in the system can have an access control list which defines the identifiers that a process must have in order to access the object. The operation system has access checking software for enabling a selected process access to a specified object when the identifiers for the process match the list of identifiers in the access control list of the specified object. The server can therefore access all objects accessible to the client while the server is working for the client. The server can restore its original identifier list after completing the services that it performs for the client.
申请公布号 US5321841(A) 申请公布日期 1994.06.14
申请号 US19930011293 申请日期 1993.01.29
申请人 DIGITAL EQUIPMENT CORPORATION 发明人 EAST, JEFFREY A.;WALKER, JAMES J.;JENNESS, STEVEN M.;OZUR, MARK C.;KELLY, JR., JAMES W.
分类号 G06F9/46;(IPC1-7):G06F13/14 主分类号 G06F9/46
代理机构 代理人
主权项
地址