Workstation–Mainframe Integration With On-Demand Encrypted Links
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IBM mainframe systems with z/OS version 2.4 and prior lack secure communication between Logical PARtitions (LPARs) and workstations, suffer from limited functionality after the deprecation of WSA, and face challenges in managing encrypted traffic and display limitations, particularly with tools like Excel and Word, leading to inefficiencies and loss of ISPF programming capabilities.
Innovation Solution
The Workstation Integrations for z Systems Enhanced (WIZE) system provides secure, encrypted connections using AES-256 encryption and TLS 1.2, offloads work to zAAP processors, and enables easy conversion of workflows with on-demand command-duration connections, allowing tools like Excel and Word to be used on workstations, and provides comprehensive help documentation in binary format.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If WSA is used for communication between workstation and mainframe, then basic connectivity is established, but communication traffic is unencrypted and insecure
Solution Approach 1:
The patent introduces an intermediary security layer that establishes encrypted tunnels between the workstation and mainframe. This intermediary mechanism implements TLS 1.2 encryption without requiring changes to the existing WSA communication protocol, thereby maintaining compatibility while enhancing security. The intermediary security layer handles encryption/decryption of traffic, resolving the contradiction between securing communication and maintaining device complexity at acceptable levels.
2Adaptability or versatility
If z/OS version 2.5 is implemented, then system updates are achieved, but WSA functionality and ISPF APIs are deprecated and disabled
Solution Approach 1:
The patent implements preliminary action by capturing and preserving WSA functionality and ISPF API capabilities before they are deprecated in z/OS 2.5. The system maintains these functionalities through virtualization and emulation layers that allow legacy applications to continue operating on the updated OS version. This preliminary preservation approach enables organizations to upgrade to z/OS 2.5 while maintaining productivity and avoiding loss of ISPF programming capabilities.
3Ease of operation
If help panels are displayed in mainframe terminal interface, then user guidance is provided, but screen capacity constraints limit detailed documentation display
Solution Approach 1:
The patent resolves this contradiction by transitioning help documentation from the two-dimensional constrained terminal screen to the multi-dimensional capabilities of the workstation display. Help panels are rendered in the workstation's graphical user interface environment, which provides substantially larger display area and supports rich formatting, hyperlinks, and interactive elements. This dimensional transition from terminal screen to workstation display eliminates the area constraints while maintaining ease of operation through familiar GUI interfaces.
4Productivity
If mainframe general processors handle all work, then processing capacity is sufficient, but bandwidth consumption and processing costs increase
Solution Approach 1:
The patent applies segmentation by dividing processing work between the mainframe and the workstation based on capability and efficiency considerations. Complex computational tasks that can be performed independently are offloaded to the workstation, reducing mainframe bandwidth consumption and processing load. The mainframe retains responsibility for core functions requiring its specialized capabilities, while the workstation handles peripheral processing tasks. This segmented approach maintains overall processing capacity while reducing energy loss and bandwidth consumption on the mainframe.
Data Source
AI summary
Improved, secure, encrypted communications between workstations and servers are disclosed along with extended and enhanced functionality for IBM's z/Architecture mainframes. On-demand connections are opened by the mainframe when a command is executed and closed in real-time after the command execution is complete and work results from the workstation are received. Connect-back port instructions and mainframe allow/deny lists for IP addresses provide additional security. Optimized and extended menus and submenus are presented in user interfaces and trigger functions. Binary help files for available commands can be stored on mainframes.


