Methods and apparatus for constructing a secure and flexible operating system
Inventors
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
The present disclosure provides methods and apparatus for constructing a secure and flexible operating system. The presently disclosed system executes different user applications in different operating systems on different virtual machines. Each user application communicates with other processes via the hypertext transfer protocol (HTTP). In particular, each user application's user interface is implemented in a web browser that is running in its own operating system on its own virtual machine, and each user application interacts with the user interface by exchanging HTTP messages between the virtual machines.
Core Innovation
The invention relates to constructing a secure and flexible operating system by installing a microkernel on a computing device and executing a first user application in a first operating system of a first virtual machine on the microkernel. A second different user application is executed in a second different operating system of a second different virtual machine on the microkernel. The microkernel provides a separated execution environment for different user applications across different virtual machines and operating systems.
The invention further executes a first embedded web browser in a third different virtual machine on the microkernel. A first message associated with the first user application is sent from the first virtual machine to the third virtual machine using hypertext transfer protocol (HTTP), where the first message includes information for generating a first display. The first display is generated via a user interface in the first embedded web browser in the third different virtual machine based on the information included in the first message.
In addition, a second different message associated with the second user application is sent from the second virtual machine to the third virtual machine using HTTP, where the second message includes information for generating a second display. The second display is generated via the user interface in the first embedded web browser in the third different virtual machine based on the information included in the second message. Dependent aspects specify using a microkernel security primitive to restrict HTTP communication and constraining where a scripting language is executed relative to the embedded web browser.
Claims Coverage
The independent claims provide five complementary coverage points built around a secure and flexible operating system constructed using a microkernel, separated virtual machines, an embedded web browser, and HTTP messaging that carries display-generation information. Each independent claim includes the same core inventive architecture and data flow.
Microkernel-based separated virtual machine execution for multiple user applications
A method of constructing a secure and flexible operating system by installing a microkernel on a computing device; executing a first user application in a first operating system of a first virtual machine on the microkernel; and executing a second different user application in a second different operating system of a second different virtual machine on the microkernel.
Embedded web browser virtual machine for generating displays
Executing a first embedded web browser in a third different virtual machine on the microkernel; and generating, via a user interface in the first embedded web browser in the third different virtual machine, a first display based on information included in an HTTP message associated with the first user application.
HTTP message-based display generation coordination across virtual machines
Sending a first message associated with the first user application from the first virtual machine to the third virtual machine using hypertext transfer protocol (HTTP), wherein the first message includes information for generating a first display; sending a second different message associated with the second user application from the second virtual machine to the third virtual machine using HTTP, wherein the second message includes information for generating a second display; and generating, via the user interface in the first embedded web browser in the third different virtual machine, the second display based on information included in the second message.
Computing device with microkernel, virtual machines, embedded web browser, and HTTP display generation
A computing device including a secure and flexible operating system, comprising instructions to operate a microkernel on the computing device; execute a first user application and a second different user application in respective operating systems of respective virtual machines on the microkernel; execute a first embedded web browser in a third different virtual machine on the microkernel; send messages associated with the user applications to the third different virtual machine using HTTP where each message includes information for generating displays; and generate the displays via a user interface in the embedded web browser.
Computer-readable memory device for microkernel and HTTP display generation architecture
A computer readable memory device storing instructions to cause a computing device to operate a microkernel; execute a first user application and a second different user application in respective operating systems of respective virtual machines on the microkernel; execute a first embedded web browser in a third different virtual machine on the microkernel; send messages associated with the user applications using HTTP where each message includes information for generating a display; and generate the displays via the user interface in the first embedded web browser.
Across the independent claims, the coverage is centered on a secure and flexible operating system using a microkernel to run different user applications in separate virtual machines and operating systems, while coordinating user-interface display generation through an embedded web browser in a separate virtual machine. Display content is generated in the embedded web browser based on information carried by HTTP messages sent from the application virtual machines, with dependent refinements adding microkernel security restriction of HTTP communication and constraining scripting-language execution relative to the embedded web browser.
Stated Advantages
Not explicitly described in patent.
Documented Applications
Not explicitly described in patent.
Interested in licensing this patent?