Virtual Control Storage-curity measures in VM/370

Clement R. Attanasio · IBM Systems Journal · 1979

An experimental extension to VM/370 provides the virtual machine with a protected, fast-access execution and data domain. New capability in the form of a new instruction, whose meaning is defined by an arbitrary, protected program, is made available to the virtual machine. Protection is provided by basic, existing mechanisms in VM/370, namely virtual storage and virtual device management. Supervisor overhead required to support communication between a user and a server executing in vcs is minimized because the domain switch does not involve a virtual machine (task) switch, and because the interface provided is synchronous. The architecture of vcs is based on the concept of microcode which implements instructions for a machine architecture. When this concept is applied as a means of providing service to multiple users in a virtual machine environment, there are many interesting implications for the structure of the code that implements the service. The intention is to provide a system structure in which service can be provided in a way that avoids unnecessary invocation of function or duplication of function in server code and in the underlying control program.

Read the paper · More papers on PaperTik