1461151762-fef80f3a-d4a8-42f4-94a7-66b80c4db8b1

1. An apparatus for securing a substrate in a processing system, comprising:
a support ring adapted to receive the substrate, the support ring having a seal engaging means formed on a surface therein;
a thrust plate assembly adapted to exert a securing force on the substrate to secure the substrate to the support ring; and
a sealing member attached to the thrust plate assembly, wherein the sealing member is adapted to exert a substantially radial sealing force against the seal engaging means.
2. The apparatus of claim 1, wherein the seal engaging means comprises an annular ring extending from the support ring and the sealing member is adapted to exert a substantially radial sealing force on an outer surface of the raised annular ring.
3. The apparatus of claim 2, wherein the sealing member comprises a body portion attached to the thrust plate assembly and wherein an annular portion extending from the body portion is adapted to engage the outer surface of the annular ring.
4. The apparatus of claim 3, wherein an inner surface of the sealing member where the annular portion extends from the body portion is substantially rounded to mate with a substantially rounded surface of the annular ring.
5. The apparatus of claim 3, wherein an outer diameter of the sealing member, measured to an outer surface of the annular portion, is less than 5 mm greater than an outer diameter of the annular ring.
6. The apparatus of claim 1, wherein the seal engaging means comprises an annular groove formed in a surface of the support ring and the sealing member is adapted to exert a substantially radial sealing force on an inner surface of the annular groove.
7. The apparatus of claim 1, further comprising a plurality of electrical contacts adapted to engage a plating surface of the substrate and the support ring comprises a contact ring.
8. The apparatus of claim 1, further comprising a plurality of electrical contacts adapted to engage a non-plating surface of the substrate.
9. The apparatus of claim 8, wherein the electrical contacts are attached to the thrust plate assembly.
10. The apparatus of claim 9, wherein the electrical contacts are attached to a conductive plate of the thrust plate assembly.
11. An apparatus for securing a substrate in a processing system, comprising:
a support ring adapted to receive the substrate, the support ring having an annular ring extending from a surface thereof;
a thrust plate assembly adapted to exert a securing force on the substrate to secure the substrate to the support ring;
a plurality of electrical contacts adapted to engage the substrate;
a first sealing member attached to the thrust plate assembly, wherein the first sealing member is adapted to exert a sealing force against the annular ring, wherein the sealing force is directed substantially radially inward towards a center of the support ring; and
a second sealing member attached to the support ring, the second sealing member adapted to engage a plating surface of the substrate.
12. The apparatus of claim 11, wherein the first and second sealing members form a cavity enclosing the electrical contacts.
13. The apparatus of claim 12, wherein the cavity is pressurized with a fluid.
14. The apparatus of claim 13, wherein the fluid is a gas.
15. The apparatus of claim 11, wherein the electrical contacts are adapted to engage a non-plating surface of the substrate.
16. The apparatus of claim 15, wherein the electrical contacts are adapted to engage the non-plating surface of the substrate at a substantially equal distance radially inward from an edge of the substrate as the second sealing member engages the plating surface of the substrate.
17. The apparatus of claim 11, wherein the first sealing member comprises a body portion attached to the thrust plate assembly and an annular portion extending from the body portion is adapted to engage an outer surface of the annular ring.
18. An apparatus for securing a substrate in a processing system, comprising:
a support ring adapted to receive the substrate;
a thrust plate assembly adapted to exert a securing force on the substrate to secure the substrate to the support ring;
a plurality of electrical contacts adapted to electrically contact a non-plating surface of the substrate; and
a sealing member attached to the substrate support member adapted to engage a plating surface of the substrate.
19. The apparatus of claim 18, wherein the electrical contacts are disposed on a surface of the thrust plate assembly.
20. The apparatus of claim 18, wherein the electrical contacts are adapted to engage the non-plating surface of the substrate at a substantially equal distance radially inward from an edge of the substrate as the sealing member engages the plating surface of the substrate.
21. The apparatus of claim 18, wherein the sealing member is adapted to engage the plating surface of the substrate within 2 mm of a beveled edge of the substrate.
22. The apparatus of claim 18, wherein the electrical contacts are attached to an electrically conductive plate attachable to a power supply for providing an electrical bias to the electrical contacts.
23. The apparatus of claim 18, further comprising another sealing member adapted to engage the non-plating surface of the substrate radially outward from the electrical contacts.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

What is claimed is:

1. A connector rod for connecting a vehicle steering mechanism to a vehicle wheel, said connector rod comprising;
a first end pivotally connectable to the vehicle steering mechanism to allow said connector rod to pivot in a first plane relative to the vehicle steering mechanism;
a second end adapted for connection to the vehicle wheel assembly;
a shaft portion interconnecting said first and second ends, said shaft portion being formed from a flexible material to allow said connector rod to deform in a second plane, approximately orthogonal to the first plane, in response to movement of said second end of said connector rod in the second plane.
2. The connector rod as set forth in claim 1, wherein said first end of said connector rod includes an aperture for receiving a support shaft of the vehicle steering mechanism, said aperture extending through said connector rod orthogonal to the first plane to allow said connector rod to pivot about the support shaft in the first plane.
3. The connector rod as set forth in claim 1, wherein said shaft portion is formed from a fiber reinforced compound.
4. The connector rod as set forth in claim 1, wherein said second end is cylindrical in shape and includes external threads for engaging a pivotal connection to the vehicle wheel assembly.
5. A vehicle steering assembly comprising;
a vehicle steering mechanism;
a wheel assembly including a pivotal wheel hub for supporting a wheel, a knuckle mounted to said hub, and a pivot arm extending outward from said knuckle;
a connector rod interconnecting said vehicle steering mechanism and said pivot arm for transmitting motion from said vehicle steering mechanism to said wheel assembly;
said connector rod including a first end pivotally connected to said vehicle steering mechanism to allow said connector rod to pivot in a first plane in relation to said vehicle steering mechanism, a second end pivotally connected to said pivot arm, and a shaft portion interconnecting said first and second ends;
said shaft portion being formed from a flexible material to allow said connector rod to deform in a second plane, approximately orthogonal to the first plane, in response to movement of said second end of said connector rod in the second plane.
6. The vehicle steering assembly as set forth in claim 5, wherein said vehicle steering mechanism includes a support shaft and said first end of said connector rod includes an aperture for receiving said support shaft, said support shaft being oriented orthogonal to the first plane to allow said connector rod to pivot about said support shaft in the first plane.
7. The vehicle steering assembly as set forth in claim 5, wherein said shaft portion of said connector rod is formed from a fiber reinforced compound.
8. The vehicle steering assembly as set forth in claim 5, wherein said second end of said connector rod is cylindrical in shape and includes external threads for engaging a connection to the vehicle wheel assembly.
9. The vehicle steering assembly as set forth in claim 8 including a ball joint disposed between and interconnecting said second end of said connector rod and said pivot arm to allow pivotal movement of said connector rod relative to said vehicle wheel assembly.
10. A connector rod for connecting a vehicle steering mechanism to a vehicle wheel assembly, said connector rod comprising;
a first end adapted for pivotal connection to the vehicle steering mechanism, whereby said connector rod is allowed to pivot in a first plane relative to the vehicle steering mechanism;
a second end adapted for connection to the vehicle wheel assembly;
a shaft portion interconnecting said first and second ends;
said first end including a radial spherical bearing disposed between said first end and the vehicle steering mechanism to allow said connector rod to pivot in a second plane, approximately orthogonal to the first plane, in response to horizontal movement of said second end of said connector rod in the second plane.
11. The connector rod as set forth in claim 10, wherein said first end of said connector rod includes an aperture for receiving a support shaft of the vehicle steering mechanism, said aperture extending through said connector rod orthogonal to the first plane to allow said connector rod to pivot about the support shaft in the first plane.
12. The connector rod as set forth in claim 10, wherein said second end is cylindrical in shape and includes external threads for engaging a pivotal connection to the vehicle wheel assembly.
13. A vehicle steering assembly comprising;
a vehicle steering mechanism;
a wheel assembly including a pivotal wheel hub for supporting a wheel, a knuckle mounted to said hub, and a pivot arm extending outward from said knuckle;
a connector rod interconnecting said vehicle steering mechanism and said pivot arm for transmitting motion from said vehicle steering mechanism to said wheel assembly;
said connector rod including a first end pivotally connected to said vehicle steering mechanism to allow said connector rod to pivot in a first plane in relation to said vehicle steering mechanism, a second end pivotally connected to said pivot arm, and a shaft portion interconnecting said first and second ends;
said first end including a radial spherical bearing disposed between said first end and said vehicle steering mechanism to allow said connector rod to pivot in a second plane, approximately orthogonal to the first plane, in response to movement of said second end of said connector rod in the second plane.
14. The vehicle steering assembly as set forth in claim 13, wherein said vehicle steering mechanism includes a support shaft and said first end of said connector rod includes an aperture for receiving said support shaft, said support shaft being oriented orthogonal to the first plane to allow said connector rod to pivot about said support shaft in the first plane.
15. The vehicle steering assembly as set forth in claim 13, wherein said second end of said connector rod is cylindrical in shape and includes external threads for engaging a connection to the vehicle wheel assembly.
16. The vehicle steering assembly as set forth in claim 15 including a ball joint disposed between and interconnecting said second end of said connector rod and said pivot arm to allow pivotal movement of said connector rod relative to said vehicle wheel assembly.
17. A vehicle steering assembly comprising;
a vehicle steering mechanism;
a wheel assembly including a pivotal wheel hub for supporting a wheel, a knuckle mounted to said hub, and a pivot arm extending outward from said knuckle;
a connector rod interconnecting said vehicle steering mechanism and said pivot arm for transmitting linear motion from said vehicle steering mechanism through said connector rod to pivot said wheel assembly;
said connector rod including a first end connected to said vehicle steering mechanism, a second end pivotally connected to said pivot arm, and a shaft portion interconnecting said first and second ends;
said connector rod including a first mechanism to allow said connector rod to pivot in a first plane in relation to said vehicle steering mechanism in response to movement of said second end of said connector arm in the first plane, and a second mechanism to allow said connector rod to pivot in a second plane, approximately orthogonal to the first plane, in response to movement of said second end of said connector rod in the second plane.
18. The vehicle steering assembly as set forth in claim 17, wherein said first mechanism and said second mechanism are a common element disposed between and interconnecting said connector rod and said vehicle steering mechanism.

1461151749-ddc76c05-3d0d-4ae7-ba9e-b94764470c5b

1. An asset management system for managing a network asset communicably connectable to a computer network, said asset management system comprising:
storage means for storing management information of the network asset communicably connectable to the computer network, including network asset identifying information identifying the network asset and computer network node identifying information of the network asset identifying the network asset on the computer network to which the network asset is communicably connected;
determining means for determining sender and destination network address of information circulating over the computer network and for determining whether said information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed;
gathering means for gathering network asset management information, including network asset identifying information identifying the network asset being managed and computer network node identifying information of the network asset based upon the information circulating over the computer network, when determined by said determining means that the information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed; and
updating means for comparing the gathered network asset management information with the stored network asset management information and when the gathered network asset management information and the stored network asset management information are not same, updating the stored network asset management information with the gathered network asset management information.
2. An asset management system according to claim 1, wherein said management information includes information on a software asset executed by the asset.
3. An asset management system according to claim 1, wherein said management information includes information on a hardware asset constituting the asset.
4. An asset management system according to claim 2, wherein said management information includes information on a hardware asset constituting the asset.
5. An asset management system according to claim 1, wherein said management information includes information on classification as to whether the asset is a leased asset or not and, if it is, information on a lease expiration date of the asset, further comprising;
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
6. An asset management system according to claim 2, wherein said management information includes information on classification as to whether the asset is a leased asset or not and information on a lease expiration date of the asset, further comprising:
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
7. An asset management system according to claim 3, wherein said management information includes information on classification as to whether the asset is a leased asset or not and if it is, information on a lease expiration date of the asset, further comprising:
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
8. An asset management system according to claim 4, wherein said management information includes information on classification as to whether the asset is a leased asset or not and information on a lease expiration date of the asset, further comprising:
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
9. An asset management system according to claim 1, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
10. An asset management system according to claim 2, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
11. An asset management system according to claim 3, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
12. An asset management system according to claim 4, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
13. An asset management system according to claim 5, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
14. An asset management system according to claim 6, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
15. An asset management system according to claim 7, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
16. An asset management system according to claim 8, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
17. The asset management system according to claim 1, further comprising:
an asset management client connected at a position through which information circulating via the computer network passes; and
means for detecting that an asset not being managed is connected to the network and activating an alarm notification upon such detection.
18. An asset management system according to claim 1, further comprising:
a communication log of each section storing data items including sender and destination addresses of information circulating over the network; and
means for detecting whether the addresses are those of an asset being managed and when an asset not being managed is detected alerting an administrator.
19. An asset management system according to claim 18, further comprising:
means for determining whether an asset has been transferred, automatically updating the contents of the asset registration and producing an alarm notification when the contents of the registration of the asset manager register master have been automatically updated.
20. An asset management system according to claim 1, further comprising:
a softwarehardware log connected at a position through which information circulating via the network passes; and
means for analyzing the log and automatically updating the content of the asset management register using the log.
21. An asset management system according to claim 1, further comprising:
a section asset master storing asset licenses; and
means for checking the licenses when it is determined that the software asset is one being managed.
22. An asset management system for managing a network asset communicably connectable to a computer network, said asset management system comprising:
a storage medium storing management information of the network asset communicably connectable to the computer network, including network asset information identifying the network asset and computer network node identifying information of the network asset to identify the network asset on a computer network to which the network asset is communicably connected;
a controller in communication with said storage medium, and performing processes comprising:
(i) determining sender and destination network address of information circulating over the computer network and determining whether said information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed;
(ii) gathering network asset management information, including network asset identifying information identifying the network asset being managed and computer network node identifying information of the network asset, based upon the information circulating over the computer network, when determined by said determining that the information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being manage; and
(iii) comparing the gathered network asset management information with the stored network asset management information and when the gathered network asset management information and the stored network asset management information are not same, updating the stored network asset management information with the gathered network asset management information.
23. An asset management system in which clients of network sections and a server are in communication by a computer network, the system comprising:
an asset management client in each network section to gather network asset management information of network assets communicably connectable to and belonging to each corresponding network section and
an asset management server in communication with each asset management client by the computer network to analyze the network asset management information gathered by each asset management client of each network section and to manage network assets of all the network sections wherein:
said asset management server comprises a storage medium for storing a master file registering network asset management information of the network assets, said network asset management information including network section identifying information identifying each network section, network asset identifying information identifying the network asset belonging to each network section and network section node identifying information identifying a connection node capable of connecting the asset at each section to the the network asset on the network section to which the network asset belongs,
said asset management client comprises a storage medium for storing, based upon sender and destination network address of information circulating over the computer network, in association with network section information identifying a belonging network section of said network asset management client, network asset management information of the network asset including network asset identifying information identifying the network asset belonging to the network section of said asset management client and network section node identifying information identifying the network asset on the network section to which the network asset belongs,
said asset management client further comprises a controller to perform a process comprising:
gathering, from the information circulating over the computer network, the network asset management information of each network asset belonging to each network section of each asset management client, network asset management information including information identifying the network asset, being managed, of the network section of said asset management client and network section node identifying information identifying a the network asset on the network section to which the network asset belongs, when determined that the information circulating over the computer network is information sent from the network asset, being managed, of the network section of said asset management client or information addressed to the network asset,

said asset management server further comprises a controller to perform a process comprising:
comparing the network asset management information of each network asset belonging to each network section gathered by the asset management client of each network section with the master file network asset management information, and
when the gathered network asset management information and the master file network asset management information are not same according to the comparing, updating the master file network asset management information with the gathered management information.
24. An asset management system for managing a network asset communicably connectable to a computer network, said asset management system comprising:
a storage unit to store management information of the network asset communicably connectable to the computer network, including network asset identifying information identifying the network asset and computer network node identifying information to identify the network asset on the computer network to which the network asset is communicably connected;
a determining unit sender and destination network address of information circulating over the computer network and for determining whether said information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed;
a gathering unit gathering network asset management information, including network asset identifying information identifying the network asset being managed and computer network node identifying information identifying of the network asset, based upon the information circulating over the computer network, when determined by said determining that the information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed; and
an updating unit to compare the gathered network asset management information with the stored network asset management information and to update the stored network asset management information according to the comparison.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A computing method, comprising:
running on a user computer a first operating environment for performing general-purpose operations and a second operating environment, which is configured exclusively for interacting with multiple servers in respective secure communication sessions and is separate from the first operating environment, wherein the second operating environment is isolated from the first operating environment and the first operating environment does not interact with the multiple servers in the secure communication sessions, the first operating environment including an operating system and second operating environment including an operating system separate from the operating system of the first operating environment, wherein in the protected communication session the second operating environment exchanges transaction data with a server via a security protocol, wherein general-purpose operations performed in the first operating environment do not affect operation of the second operating environment, and wherein running the second operating environment comprises verifying a trustworthiness of the second operating environment by communication between the second operating environment and a Central Management System (CMS) that is external to the user computer;
storing in the second operating environment multiple different server-specific credentials, each corresponding to one of the multiple servers, for authenticating a user of the user computer to each respective server, and a single set of master credentials for authenticating the user to the second operating environment; and
establishing a secure communication session between the user computer and at least one of the multiple servers under control of a program running in the second operating environment, by authenticating the user to the second operating environment using the master credentials and, responsively to successfully authenticating the user in the second operating environment, automatically selecting one of the server-specific credentials in the second operating environment corresponding to the one of the multiple servers and the second operating environment authenticating the user to the one server using the selected server-specific credentials.
2. The method according to claim 1, and comprising conducting the secure communication session with the given server responsively to successfully authenticating the user computer to the given server.
3. The method according to claim 1, wherein establishing the secure communication session comprises authenticating the user to the given server using the selected server-specific credentials only upon successfully verifying the trustworthiness of the second operating environment by the CMS.
4. The method according to claim 1, wherein storing the server-specific credentials comprises providing at least one of the server-specific credentials to the CMS, and sending at least one of the server-specific credentials from the CMS to the user computer for storage in the second operating environment.
5. The method according to claim 4, wherein providing at least one of the server-specific credentials further comprises providing a security policy of at least one of the servers to the CMS, and enforcing the security policy with respect to the second operating environment by the CMS.
6. The method according to claim 1, wherein storing the server-specific credentials comprises providing at least one of the server-specific credentials to the user computer independently of the CMS.
7. The method according to claim 1, wherein the master credentials are uniquely associated with the user computer, and wherein authenticating the user using the master credentials comprises verifying that the user computer matches the master credentials.
8. The method according to claim 1, wherein storing the server-specific credentials comprises encrypting the server-specific credentials, and wherein authenticating the user to the given server using the selected server-specific credentials comprises decrypting the selected credentials.
9. The method according to claim 1, wherein storing the master credentials comprises encrypting the master credentials, and wherein authenticating the user using the master credentials comprises decrypting the master credentials.
10. The method according to claim 1, wherein storing the server-specific credentials comprises storing a self-contained data element comprising one of the server-specific credentials and a software application that is to run in the second operating environment for communicating with a respective one of the servers.
11. The method according to claim 10, wherein the self-contained data element further comprises attributes of the software application.
12. The method according to claim 10, wherein the self-contained data element comprises the master credentials, the multiple server-specific credentials and respective multiple software applications for communicating with the servers.
13. The method according to claim 1, wherein establishing the secure communication session comprises, in response to successfully authenticating the user to the given server, causing a packet filter of the given server to allow packets arriving from the user computer to reach the given server.
14. A user computer, comprising:
an network interface device, which is operative to communicate with multiple servers over a communication network; and
a hardware processor, which is coupled to run a first operating environment, which is configured to perform general-purpose operations, and a second operating environment, which is configured exclusively for interacting with the multiple servers in respective protected communication sessions and is separate from the first operating environment,
wherein the second operating environment is isolated from the first operating environment and the first operating environment does not interact with the multiple servers in the secure communication sessions, the first operating environment including an operating system and second operating environment including an operating system separate from the operating system of the first operating environment,
wherein in the protected communication session the second operating environment exchanges transaction data with a server via a security protocol,
wherein general-purpose operations performed in the first operating environment do not affect operation of the second operating environment, and
wherein running the second operating environment comprises verifying a trustworthiness of the second operating environment by communication between the second operating environment and a Central Management System (CMS) that is external to the user computer,

the hardware processor configured to store in the second operating environment multiple different server-specific credentials, each corresponding to one of the multiple servers, for authenticating a user of the user computer to each respective server and a single set of master credentials for authenticating the user to the second operating environment, and
the hardware processor configured to establish a secure communication session between the user computer and at least one of the multiple servers under control of a program running in the second operating environment, by authenticating the user to the second operating environment using the master credentials and, responsively to successfully authenticating the user in the second operating environment, automatically selecting, one of the server-specific credentials in the second operating environment corresponding to the one of the multiple servers and the second operating environment authenticating the user to the one server using the selected server-specific credentials.
15. The user computer according to claim 14, wherein the processor is coupled to conduct the secure communication session with the given server responsively to successfully authenticating the user computer to the given server.
16. The user computer according to claim 14, wherein the processor is coupled to authenticate the user to the given server using the selected server-specific credentials only when the trustworthiness of the second operating environment is successfully verified by the CMS.
17. The user computer according to claim 14, wherein the processor is coupled to receive at least one of the server-specific credentials from the CMS, and to store received at least one of the server-specific credentials in the second operating environment.
18. The user computer according to claim 14, wherein the processor is coupled to store at least one of the server-specific credentials independently of the CMS.
19. The user computer according to claim 14, wherein the master credentials are uniquely associated with the user computer, and wherein the processor is coupled to authenticate the user using the master credentials by verifying that the user computer matches the master credentials.
20. The user computer according to claim 14, wherein the processor is coupled to encrypt the stored server-specific credentials, and to decrypt the selected credentials so as to authenticate the user to the given server.
21. The user computer according to claim 14, wherein the processor is coupled to encrypt the stored master credentials, and to decrypt the master credentials so as to authenticate the user.
22. The user computer according to claim 14, wherein the processor is coupled to store a self-contained data element comprising one of the server-specific credentials and a software application that is to run in the second operating environment for communicating with a respective one of the servers.
23. The user computer according to claim 22, wherein the self-contained data element further comprises attributes of the software application.
24. The user computer according to claim 22, wherein the self-contained data element comprises the master credentials, the multiple server-specific credentials and respective multiple software applications for communicating with the servers.
25. A computer software product for use in a user computer, the computer software product comprising a non-transitory computer-readable storage medium, storing executable instructions, which instructions, when executed by the user computer, cause the user computer to perform operations including,
communicating with multiple servers over a communication network, to run a first operating environment for performing general-purpose operations and a second operating environment, which is configured exclusively for interacting with the multiple servers in respective secure communication sessions and is separate from the first operating environment,
wherein where the second operating environment is isolated from the first operating environment and the first operating environment does not interact with the multiple servers in the secure communication sessions, the first operating environment including an operating system and second operating environment including an operating system separate from the operating system of the first operating environment,
wherein in the protected communication session the second operating environment exchanges transaction data with a server via a security protocol,
wherein general-purpose operations performed in the first operating environment do not affect operation of the second operating environment, and
wherein running the second operating environment comprises verifying a trustworthiness of the second operating environment by communication between the second operating environment and a Central Management System (CMS) that is external to the user computer,

storing in the second operating environment multiple different server-specific credentials, each corresponding to one of the multiple servers, for authenticating a user of the user computer to each respective server and a single set of master credentials for authenticating the user to the second operating environment, and
establishing a secure communication session between the user computer and at least one of the multiple servers under control of a program running in the second operating environment, by authenticating the user to the second operating environment using the master credentials and, responsively to successfully authenticating the user in the second operating environment, automatically selecting one of the server-specific credentials in the second operating environment corresponding to the one of the multiple servers and the second operating environment authenticating the user to the one server using the selected server-specific credentials.