The present invention provides a generic technique to perform access
control check for data access and/or for doing an operation in a COM
based system comprised of multiple servers and having multiple users. A
unique user security context number is generated after validating the
user for a session, based on user entered authentication parameters. The
generation of the security context numbers and the fetching of the access
control information from storage medium is managed by a central security
server. The generated unique user security context number is then used
throughout the session to check for access permission for data access
and/or to perform an operation requested by the user during the session.