1. A method in combination with a program operating on a computer, the method for authenticating the program to a resource on the computer and comprising:
retrieving, by the resource on the computer, a stored program security identifier (PSID) corresponding to the program, the stored PSID comprising information based on the program itself, an execution setting of the program, a first list of other programs that should not be operating on the computer, and any inputs and initializations that are provided to the program, whereby the stored PSID represents an approved set of conditions for operating the program in a trusted manner;
retrieving, by the resource on the computer, a set of instructions for constructing a second PSID, the set of instructions comprising an identifier of a first program that should not be operating on the computer;
determining, by the resource on the computer based at least in part on the identifier of the first program, that the first program is not operating on the computer from a local source;
constructing, by the resource on the computer, the second PSID according to the set of instructions, the second PSID comprising a second list of programs that should not be operating on the computer, the second list of programs that should not be operating on the computer comprising the identifier of the first program;
comparing, by the resource on the computer, the stored PSID and the second PSID to determine whether the stored PSID matches the second PSID;
if the stored PSID matches the second PSID, the resource on the computer concluding that the program operates in the trusted manner according to the approved set of conditions; and
if the stored PSID does not match the second PSID, the resource on the computer concluding that the program does not operate in the trusted manner according to the approved set of conditions.
2. The method of claim 1 wherein the program to be authenticated is hosted by a number of layers of other programs that ultimately rest upon hardware representative of the computer.
3. The method of claim 1 wherein the program to be authenticated is hosted by a number of layers of other programs that ultimately rest upon hardware representative of the computer, the method being performed by a program hosting the program to be authenticated and at a next layer toward the hardware.
4. The method of claim 1 comprising retrieving the stored PSID comprising information based on the program itself, such information including at least one of a digital certificate corresponding to the program and a manifold corresponding to the program.
5. The method of claim 1 comprising retrieving the stored PSID comprising information based on the execution setting of the program, such information including at least one of an identification of other programs directly or indirectly hosting the program to be authenticated, and other programs that should be operating on the computer.
6. The method of claim 1 comprising retrieving the stored PSID comprising information based on the inputs to the program, such information including at least one of an approved set of inputs for the program.
7. The method of claim 1 comprising retrieving the stored PSID comprising the information set forth as one of a list and a hash.
8. The method of claim 1 wherein the set of instructions further comprises a series of steps to be performed and an executable that performs such series of steps.
9. A method in combination with a program operating on a computer, the method for authenticating the program to a first resource on the computer, the program to be authenticated being hosted by a number of layers of hosting programs that ultimately rest upon hardware representative of the computer, the method comprising:
for each of the programs to be authenticated and the hosting program at each of some layers, establishing by a second resource on the computer a program security identifier (PSID) corresponding to the program, the established PSID including information based on the program itself, an execution setting of the program, a first list of other programs that should not be operating on the computer, and any inputs and initializations that are provided to the program, whereby the PSID represents an approved set of conditions for operating the program in a trusted manner;
combining by the second resource on the computer all of the established PSIDs to produce a composite PSID (CPSID) representing an overall security environment of the program to be authenticated;
delivering the produced CPSID from the second resource to the first resource, whereby the first resource reviews such delivered CPSID and determines based at least partially on such review whether to trust the program to be authenticated; and
delivering a set of instructions for constructing a second CPSID from the second resource to the first resource, wherein the set of instructions comprise an identification of each of the established PSIDs and a second set of instructions for constructing comparison PSIDs.
10. The method of claim 9 comprising establishing the PSID for a particular program by a hosting program at a next layer from the particular program toward the hardware.
11. The method of claim 9 wherein establishing the PSID for a particular program includes retrieving a stored PSID corresponding to the program, re-constructing the retrieved PSID based on the same information as obtained from local sources, and comparing the stored and reconstructed PSIDs to determine that a match exists.
12. The method of claim 11 comprising:
for each of the programs to be authenticated and the hosting program at each layer, establishing by the second resource on the computer a program security identifier (PSID) corresponding to the program, the stored PSID including information based on the program itself, an execution setting of the program, a second list of other programs that should not be operating on the computer, and any inputs and initializations that are provided to the program, whereby the stored PSID represents an approved set of conditions for operating the program in a trusted manner; and
combining by the second resource on the computer all of the established PSIDs to produce the CPSID representing an overall security environment of the program to be authenticated.
13. The method of claim 9 comprising combining all of the established PSIDs to produce a CPSID as one of an ordered list of the established PSIDs, a hash of the established PSIDs, and the result of a mathematical progression based on the established PSIDs.
14. The method of claim 9 comprising establishing the PSID for each program to include information based on the program itself, such information including at least one of a digital certificate corresponding to the program and a manifold corresponding to the program.
15. The method of claim 9 comprising establishing the PSID for each program to include information based on the execution setting of the program, such information including at least one of an identification of other programs directly or indirectly hosting the program to be authenticated, and other programs that should be operating on the computer.
16. The method of claim 9 comprising establishing the PSID for each program to include information based on the inputs to the program, such information including at least one of an approved set of inputs for the program.
17. The method of claim 9 wherein the hardware includes a trust module combining all of the established PSIDs to produce the CPSID and delivering the produced CPSID to the second resource.
18. The method of claim 9 wherein combining all of the established PSIDs to produce the CPSID comprises:
clearing a memory location designated to hold the CPSID;
receiving each established PSID for the CPSID in an ordered manner and, for each received PSID and in an iterative manner:
applying the received PSID to a function f that retrieves a current contents of the memory location;
combining the received PSID with the retrieved current contents of the memory location in a predetermined manner;
performing a mathematical operation on the combination to produce a result; and
placing the result of the operation into the memory location, such that upon processing all PSIDs the memory location contains the CPSID.
19. The method of claim 18 comprising combining the received PSID with the retrieved current contents of the memory location by concatenation.
20. The method of claim 18 comprising performing a hash function on the combination to produce the result.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. A computer implemented method comprising:
determining an absolute energy break-even time for a first low power state with respect to a current state of a system;
determining a relative energy break-even time for the first low power state with respect to a second low power state based on at least in part the absolute energy break-even time; and
selecting an operating state for the system based on at least in part the relative energy break-even time.
2. The method of claim 1, further including using a power consumption associated with the first low power state and a power consumption associated with the second low power state to determine the relative energy break-even time.
3. The method of claim 1, wherein the second low power state is shallower and has a shorter exit latency than the first low power state.
4. The method of claim 3, further including selecting the second low power state as the operating state if a projected idleness duration is less than the relative energy break-even time for the first low power state.
5. The method of claim 4, wherein the projected idleness duration is greater than the absolute energy break-even time for the first low power state.
6. The method of claim 1, further including:
detecting a first break event from a first event source;
detecting a second break event from a second event source; and
coordinating issuance of the first and second break events to the system based on at least in part the relative energy break-even time.
7. The method of claim 6, wherein coordination of the issuance of the first and second break events includes a determination of a holding time based on at least in part the relative energy break-even time, and a deference of at least one of the first and second break events based on at least in part the holding time.
8. A non-transitory computer readable storage medium comprising a set of instructions which, if executed by a processor, cause a computer to:
determine an absolute energy break-even time for a first low power state with respect to a current state of a system;
determine a relative energy break-even time for the first low power state with respect to a second low power state based on at least in part the absolute energy break-even time; and
select an operating state for the system based on at least in part the relative energy break-even time.
9. The medium of claim 8, wherein the instructions, if executed, cause a computer to further use a power consumption associated with the first low power state and a power consumption associated with the second low power state to determine the relative energy break-even time.
10. The medium of claim 8, wherein the second low power state is to be shallower and is to have a shorter exit latency than the first low power state.
11. The medium of claim 10, wherein the instructions, if executed, cause a computer to select the second low power state as the operating state if a projected idleness duration is less than the relative energy break-even time for the first low power state.
12. The medium of claim 11, wherein the projected idleness duration is to be greater than the absolute energy break-even time for the first low power state.
13. The medium of claim 8, wherein the instructions, if executed, cause a computer to:
detect a first break event from a first event source;
detect a second break event from a second event source; and
coordinate issuance of the first and second break events to the system based on at least in part the relative energy break-even time.
14. The medium of claim 13, wherein coordination of the issuance of the first and second break events is to include a determination of a holding time based on at least in part the relative energy break-even time, and a deference of at least one of the first and second break events based on at least in part the holding time.
15. An apparatus comprising:
logic to,
determine an absolute energy break-even time for a first low power state with respect to a current state of a system,
determine a relative energy break-even time for the first low power state with respect to a second low power state based on at least in part the absolute energy break-even time, and
select an operating state for the system based on at least in part the relative energy break-even time.
16. The apparatus of claim 15, wherein the logic is to further use a power consumption associated with the first low power state and a power consumption associated with the second low power state to determine the relative energy break-even time.
17. The apparatus of claim 15, wherein the second low power state is to be shallower and is to have a shorter exit latency than the first low power state.
18. The apparatus of claim 17, wherein the logic is to select the second low power state as the operating state if a projected idleness duration is less than the relative energy break-even time for the first low power state.
19. The apparatus of claim 18, wherein the projected idleness duration is to be greater than the absolute energy break-even time for the first low power state.
20. The apparatus of claim 15, wherein the logic is to,
detect a first break event from a first event source,
detect a second break event from a second event source, and
coordinate issuance of the first and second break events to the system based on at least in part the relative energy break-even time.
21. The apparatus of claim 20, wherein coordination of the issuance of the first and second break events is to include a determination of a holding time based on at least in part the relative energy break-even time, and a deference of at least one of the first and second break events based on at least in part the holding time.
22. The apparatus of claim 15, wherein the first and second low power states are to include at least one of a platform state, a processor state and a device state.
23. A platform comprising:
a processor; and
logic to,
determine an absolute energy break-even time for a first low power state with respect to a current state of the processor,
determine a relative energy break-even time for the first low power state with respect to a second low power state based on at least in part the absolute energy break-even time, and
select an operating state for the processor based on at least in part the relative energy break-even time.
24. The platform of claim 23, wherein the logic is to further use a power consumption associated with the first low power state and a power consumption associated with the second low power state to determine the relative energy break-even time.
25. The platform of claim 23, wherein the second low power state is to be shallower and is to have a shorter exit latency than the first low power state.
26. The platform of claim 25, wherein the logic is to select the second low power state as the operating state if a projected idleness duration is less than the relative energy break-even time for the first low power state.
27. The platform of claim 26, wherein the projected idleness duration is to be greater than the absolute energy break-even time for the first low power state.
28. The platform of claim 23, wherein the logic is to,
detect a first break event from a first event source,
detect a second break event from a second event source, and
coordinate issuance of the first and second break events to the processor based on at least in part the relative energy break-even time.
29. The platform of claim 28, wherein coordination of the issuance of the first and second break events is to include a determination of a holding time based on at least in part the relative energy break-even time, and a deference of at least one of the first and second break events based on at least in part the holding time.