Containerized system architecture based on Quhua embedded real-time operating system
By designing a containerized system architecture based on Ruihua embedded real-time operating system, the problem that the domestic Ruihua embedded real-time operating system lacks native containerization capabilities is solved, and safe isolation and real-time guarantees between containers are achieved, meeting the application needs in key security areas.
Patent Information
- Application Number
- CN202510048721.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-16
AI Technical Summary
The domestic Ruihua embedded real-time operating system lacks native containerization capabilities and is difficult to support lightweight containers, including real-time and secure isolation of container applications.
A containerized system architecture based on Ruihua embedded real-time operating system is designed, including privileged operating system kernels and non-privileged containers and container managers. This architecture provides resource management, secure isolation, real-time performance assurance and communication mechanisms through performance control groups, resource space, dual real-time scheduling, quick interrupt response and inter-container IPC modules.
It realizes safe isolation between containers, ensures the real-time nature of embedded real-time containers, and meets the requirements for operation and deployment of embedded containerized applications in key security fields.
Smart Images

Figure CN120010992A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of embedded operating systems, and in particular to an embedded real-time operating system architecture technology for implementing containerized application running support in an embedded real-time operating system. Background Art
[0002] As embedded real-time operating systems are increasingly used in various complex embedded systems, new architectures need to be studied to meet the integration, real-time and high security requirements of embedded basic software in safety-critical areas. In some complex embedded systems, the system must provide general system services to meet user requirements and ensure the normal operation of key systems. This inherently requires isolation between general systems and key real-time systems. Virtualization technology, isolation technology based on multi-core CPUs, and hardware-assisted isolation technology are usually used to isolate systems and provide secure partitioned operating environment technology. However, traditional virtualization technology will introduce high resource consumption and usually has poor real-time performance. As a lightweight implementation form of virtualization isolation technology, container technology can provide applications with a secure and unified isolated operating environment, flexible resource abstraction and allocation methods, and is gradually being promoted and applied in embedded systems. As a rapidly developing new service resource sharing and security assurance method, container technology has the advantages of better performance, lighter weight and faster speed than traditional virtual machines. In addition, containerization technology, which originated from the field of cloud native technology, can adapt well to the heterogeneous, dynamic, and complex environment in the cloud-edge-end environment. Embedded devices play an important role in the edge and end of cloud-edge-end integration. Container technology can shield device heterogeneity to form an elastic and scalable basic support architecture for cloud-edge-end integration. Therefore, support for containerization is also one of the important directions for the development of current embedded operating systems. The essence of a container is a process group. Containerization technology uses the process isolation function of the operating system layer to create multiple isolated containers on the operating system. It provides an independent lightweight virtual operating environment for applications, allowing applications and all their dependencies to be packaged in independent containers, thereby achieving portability and consistency across different environments.
[0003] The most important key functions for embedded real-time operating systems to support lightweight containers are real-time support for container applications and secure isolation between containers. Containerized embedded operating systems need to provide resource isolation, performance isolation, and real-time scheduling functions based on this. However, the current domestic Ruihua embedded real-time operating system lacks native containerization capabilities. Summary of the invention
[0004] In view of the problem that the current domestic Ruihua embedded real-time operating system lacks native containerization capabilities, a containerized system architecture based on Ruihua embedded real-time operating system is proposed. In view of the current requirements of embedded container computing for high performance and strong isolation, the Ruihua containerized embedded real-time operating system architecture design guarantees the resource abstraction and isolation faced by containers, and the real-time requirements of container process scheduling, providing native container real-time guarantees and deterministic deployment capabilities.
[0005] The technical solution of the present invention is:
[0006] A containerized system architecture based on Ruihua embedded real-time operating system includes the following functional modules: an operating system kernel running at a privileged level, a container running at a non-privileged level, and a container manager running at a non-privileged level, as follows:
[0007] The privileged operating system kernel adds some system extension modules for containerization based on the Ruihua embedded system kernel to provide the resource management mechanism, security isolation mechanism, container task real-time performance guarantee mechanism, device management allocation mechanism, and communication mechanism between containers required for containerization; specifically, it is reflected in the performance control group, resource space, secondary real-time scheduling, interruption fast response, and inter-container IPC module in the architecture design; the performance control group module manages the quota of resources allocated to each container through the configuration of the container; the resource space module encapsulates system resources into a variety of system resource objects, each of which defines several operation methods for container calls in the non-privileged level; the performance isolation support between containers is achieved by dividing the above system resource objects and binding them to the container; the secondary real-time scheduling module classifies and schedules real-time container applications and non-real-time container applications according to the real-time requirements of the container application, and schedules the tasks in the container at both the container layer and the task layer; the interruption fast response module provides a high-speed response mechanism for external device interrupts to real-time containers; the inter-container IPC module is to enhance the reliability of isolation between containers and the security of information flow between containers;
[0008] Containers running at the non-privileged level include application containers and system service containers. Application containers include real-time containers and non-real-time containers. Real-time containers run critical tasks. The functions of such containers are statically determined before deployment, including real-time applications and direct device drivers. The system kernel will allocate exclusive CPU, memory and device resources to real-time containers. The direct device driver inside the real-time container directly operates the exclusive device. Non-real-time containers run non-critical tasks, including non-real-time applications. Different containers can share system resources. The use of CPU, memory and device resources is allocated and scheduled on demand by the kernel and system containers. System service containers provide some common application services for user containers. System service containers include network protocol stack system service containers, file system system service containers, and device driver containers.
[0009] Container manager running at the non-privileged level: The non-privileged level is equipped with a container manager with a global view of the system. The container manager provides container deployment, container orchestration, health monitoring, and performance monitoring functions. It runs continuously in the system as a container daemon task, and performs corresponding container deployment and task orchestration scheduling according to the container configuration file provided by the user. During the container operation phase, it also continuously monitors the health and performance of the container, handles and reports container failures in a timely manner, and audits and analyzes the use of various resources to optimize the overall real-time and reliability of the system.
[0010] Furthermore, it includes the underlying hardware platform and the upper operating system software. The upper operating system software is divided into two layers: privileged level and non-privileged level, which respectively correspond to the different processor privilege levels at which this part of the software is running.
[0011] Furthermore, the resource space module encapsulates system resources into a variety of system resource objects, including task objects, memory objects, address space objects, device objects, interrupt objects, and communication objects.
[0012] Furthermore, in the resource space module, all tasks in the bound container can only use the bound system resources, which can be shared or further divided into fine-grained ways.
[0013] Furthermore, in the secondary real-time scheduling module, task layer scheduling refers to task scheduling in the native Ruihua embedded real-time operating system, while container layer scheduling refers to upper-layer container scheduling performed by this module based on native scheduling in units of containers.
[0014] Furthermore, the security of communication can be achieved based on the information security features provided by the processor. For example, the trusted execution environment mechanism of the ARM architecture-based processor can provide a container security service module to support the security control of information flow communication between containers. TrustZone-based container security enhancement can use this hardware isolation to achieve isolation between the container and the host environment.
[0015] Furthermore, in real-time containers, in order to ensure the real-time requirements of real-time containers, it supports running the drivers of some direct-pass devices directly in the container, that is, allowing the container to directly manage and exclusively use the device drivers. The device driver uses a fast interrupt response mechanism from the privileged level to obtain a more efficient interrupt processing process and more stable mission-critical performance.
[0016] Furthermore, when running in a non-privileged container, the functional requirements of the container in the embedded scenario are static. The required system service types can be determined before the entire system deployment phase begins. Users can choose to start a specific system service container based on their needs. User containers can use various system services provided by each system service container through cross-process communication between containers.
[0017] Furthermore, the deployment and operation process of container applications on Ruihua embedded real-time operating system is as follows:
[0018] During the container deployment phase, the container manager parses the container configuration file provided by the user to obtain the type, performance indicators, resource quota, and priority configuration information of the container to be created. It then calls the relevant interfaces provided by the kernel and specific function containers to register the above information to the corresponding performance control group and resource space, preparing for performance and resource isolation during container runtime.
[0019] After the preparation work is completed, the container manager will run the initial task of the target container based on the container image packaged by the user-developed application, thereby pulling up the container; during the container running stage, the container manager will continue to monitor the health status and performance status of each container; if a container fails during operation, the container manager will decide the handling method based on the priority information in its configuration information, including restarting the container, silently exiting, reporting an error and stopping other container operations; in addition, it will work with the kernel to accurately track the specific behavior of each task in each container, and based on this behavior audit information, it can further analyze the overall performance and health level of the container.
[0020] The beneficial effects of the present invention are:
[0021] The Ruihua containerized embedded real-time operating system designed by the present invention realizes secure isolation between containers by using lightweight embedded real-time operating system extensions, and ensures the real-time performance of embedded real-time containers by utilizing a secondary real-time scheduling algorithm, device driver pass-through, and rapid interrupt response, thereby ensuring the priority of mission-critical tasks and the strong real-time performance of critical tasks, and meeting the requirements for the operation and deployment of embedded containerized applications in security-critical fields. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is the architecture diagram of the Ruihua containerized embedded real-time operating system of the present invention. DETAILED DESCRIPTION
[0023] The present invention is described in detail below in conjunction with the accompanying drawings and specific embodiments. This embodiment is implemented based on the technical solution of the present invention, and provides a detailed implementation method and specific operation process, but the protection scope of the present invention is not limited to the following embodiments.
[0024] Aiming at the requirement of extremely high reliability and stability for real-time containers of key tasks in embedded real-time scenarios, the present invention designs a new containerized embedded real-time operating system architecture, provides containerized application deployment and operation capabilities, and provides real-time performance guarantee of containers and resource isolation control between containers.
[0025] like Figure 1 The following is the architecture diagram of Ruihua embedded real-time operating system. The architecture diagram is mainly divided into two parts: the underlying hardware platform and the upper operating system software. The upper operating system software is divided into two layers: privileged level and non-privileged level, which correspond to the different processor privilege levels at which this part of the software runs. The underlying hardware does not belong to the architecture design of this operating system. It is only drawn in the figure to better illustrate the architecture design of the upper software.
[0026] The containerized embedded real-time operating system architecture designed by the present invention includes the following functional modules:
[0027] 1. Operating system kernel running at privileged level:
[0028] The privileged operating system kernel mainly adds some system extension modules for containerization based on the Ruihua embedded system kernel to provide the resource management mechanism, security isolation mechanism, container task real-time performance guarantee mechanism, device management allocation mechanism, and communication mechanism between containers required for containerization. Specifically, it is reflected in the performance control group, resource space, secondary real-time scheduling, interrupt fast response, and inter-container IPC module in the architecture design.
[0029] The resource space module encapsulates system resources into a variety of system resource objects, including task objects, memory objects, address space objects, device objects, interrupt objects, communication objects, etc. Each object defines several operation methods for non-privileged container calls. Performance isolation between containers is supported by dividing and binding the above system resource objects to containers. All tasks in the bound container can only use the bound system resources, which can be shared or further divided in fine-grained manner, avoiding mutual performance interference between containers.
[0030] The performance control group module manages the quotas of memory, CPU time, I / O and other resources allocated to each container through container configuration.
[0031] The secondary real-time scheduling module classifies and schedules real-time container applications and non-real-time container applications according to the real-time requirements of container applications, and schedules tasks in containers at both the container layer and the task layer to ensure the real-time performance of the container system. Task layer scheduling refers to task scheduling in the native Ruihua embedded real-time operating system, while container layer scheduling refers to upper-layer container scheduling by this module based on native scheduling in units of containers to ensure the real-time performance of applications in real-time containers.
[0032] The interruption fast response module provides a high-speed response mechanism for external device interruptions to real-time containers, ensuring the real-time requirements of real-time containers.
[0033] In order to enhance the reliability of isolation between containers and the security of information flow between containers, the inter-container IPC module can realize the security protection of communication based on the information security features provided by the processor. For example, the trusted execution environment (TrustZone) mechanism of the processor based on the ARM architecture provides a container security service module to support the security control of information flow communication between containers. Compared with traditional software-based security isolation technologies such as namespaces, control groups, container network isolation, and storage isolation, this container security isolation solution is based on hardware security extension technology and provides a hardware-level isolation mechanism. TrustZone-based container security enhancement can use this hardware isolation to achieve isolation between containers and host environments, ensuring that applications and data inside containers cannot be accessed or tampered with by unauthorized host environments, and can provide a more powerful security protection mechanism to improve the security and credibility of the container environment.
[0034] 2. Run in a non-privileged container
[0035] The purpose of the containerized operating system designed by the present invention is to provide an operating environment support for asset management isolation and real-time scheduling support for application containers. All application containers can be real-time containers or non-real-time containers, and they all run at the non-privileged level of the system. Real-time containers run critical tasks. The functions of such containers are statically determined before deployment, mainly including real-time applications and direct device drivers. Their workload is streamlined and has extremely high requirements for real-time performance. Therefore, the functional components required for real-time tasks will be concentrated in the real-time container through a highly cohesive construction method. The system kernel will allocate exclusive CPU, memory and device resources to the real-time container to avoid interference from other tasks in the system. The direct device driver inside the real-time container directly operates the exclusive device to provide low-latency interaction. In order to ensure the real-time requirements of the real-time container, it supports the direct operation of some direct device drivers in the container (that is, the container directly manages and exclusively enjoys the device driver). The device driver adopts a fast interrupt response mechanism from the privileged level to obtain a more efficient interrupt processing process and a more stable critical task performance.
[0036] Non-real-time containers run non-critical tasks. They usually provide richer and more logically complex functions, mainly including non-real-time applications. They do not have high requirements for real-time performance, and different containers can share system resources. The use of CPU, memory, and device resources is allocated and scheduled on demand by the kernel and system containers.
[0037] In addition to user application containers, this architecture design also designs system service containers to provide some commonly used application services for user containers. System service containers include network protocol stack system service containers, file system service containers, device driver containers, etc. The functional requirements of containers in embedded scenarios are static. The types of system services required can be determined before the entire system deployment phase begins. Users can choose to start specific system service containers based on their needs. User containers (including real-time and non-real-time containers) can use various system services provided by each system service container through inter-process communication (IPC) between containers. Since these system services run at a non-privileged level, any errors generated in the container will not harm the operating system kernel in the privileged state.
[0038] 3. A container manager running at a non-privileged level.
[0039] The non-privileged level is designed with a container manager that has a global view of the system. The container manager provides container deployment, container orchestration, health monitoring, and performance monitoring functions. It runs continuously in the system as a container daemon task, performs corresponding container deployment and task orchestration scheduling according to the container configuration file provided by the user, and continuously monitors the health and performance of the container during the container operation phase, handles and reports container failures in a timely manner, and audits and analyzes the use of various resources to optimize the overall real-time and reliability of the system.
[0040] The deployment and operation process of container applications on Ruihua containerized embedded real-time operating system is as follows:
[0041] During the container deployment phase, the container manager parses the container configuration file provided by the user to obtain configuration information such as the type, performance indicators, resource quotas, and priorities of the container to be created. It then calls the kernel and related interfaces provided by specific functional containers to register the above information with the corresponding performance control group and resource space, in preparation for performance and resource isolation during container runtime.
[0042] After the preparation is completed, the container manager will run the initial task of the target container based on the container image packaged by the user-developed application, thereby pulling up the container. During the container operation phase, the container manager will continue to monitor the health and performance status of each container. If a container fails during operation, the container manager will decide how to handle it based on the priority and other information in its configuration information, such as restarting the container, exiting silently, reporting an error and stopping other containers. In addition, it will work with the kernel to accurately track the specific behavior of each task in each container, and based on these behavioral audit information, the overall performance and health level of the container can be further analyzed.
[0043] The above-mentioned embodiment only expresses one implementation mode of the present invention, and its description is relatively specific and detailed, but it cannot be understood as limiting the scope of the invention patent. It should be pointed out that for ordinary technicians in this field, several modifications and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be based on the attached claims.
Claims
1. A containerized system architecture based on Ruihua embedded real-time operating system, characterized in that: It includes the following functional modules: operating system kernel running at privileged level, container running at non-privileged level, and container manager running at non-privileged level, as follows: The privileged operating system kernel adds some system extension modules for containerization based on the Ruihua embedded system kernel to provide the resource management mechanism, security isolation mechanism, container task real-time performance guarantee mechanism, device management allocation mechanism, and communication mechanism between containers required for containerization; specifically, it is reflected in the performance control group, resource space, secondary real-time scheduling, interruption fast response, and inter-container IPC module in the architecture design; the performance control group module manages the quota of resources allocated to each container through the configuration of the container; the resource space module encapsulates system resources into a variety of system resource objects, each of which defines several operation methods for container calls in the non-privileged level; the performance isolation support between containers is achieved by dividing the above system resource objects and binding them to the container; the secondary real-time scheduling module classifies and schedules real-time container applications and non-real-time container applications according to the real-time requirements of the container application, and schedules the tasks in the container at both the container layer and the task layer; the interruption fast response module provides a high-speed response mechanism for external device interrupts to real-time containers; the inter-container IPC module is to enhance the reliability of isolation between containers and the security of information flow between containers; Containers running at the non-privileged level include application containers and system service containers. Application containers include real-time containers and non-real-time containers. Real-time containers run critical tasks. The functions of such containers are statically determined before deployment, including real-time applications and direct device drivers. The system kernel will allocate exclusive CPU, memory and device resources to real-time containers. The direct device driver inside the real-time container directly operates the exclusive device. Non-real-time containers run non-critical tasks, including non-real-time applications. Different containers can share system resources. The use of CPU, memory and device resources is allocated and scheduled on demand by the kernel and system containers. System service containers provide some common application services for user containers. System service containers include network protocol stack system service containers, file system system service containers, and device driver containers. Container manager running at the non-privileged level: The non-privileged level is equipped with a container manager with a global view of the system. The container manager provides container deployment, container orchestration, health monitoring, and performance monitoring functions. It runs continuously in the system as a container daemon task, and performs corresponding container deployment and task orchestration scheduling according to the container configuration file provided by the user. During the container operation phase, it also continuously monitors the health and performance of the container, handles and reports container failures in a timely manner, and audits and analyzes the use of various resources to optimize the overall real-time and reliability of the system.
2. According to claim 1, the containerized system architecture based on Ruihua embedded real-time operating system is characterized in that: It includes the underlying hardware platform and the upper-level operating system software. The upper-level operating system software is divided into two layers: privileged level and non-privileged level, which correspond to the different processor privilege levels at which this part of the software is running.
3. According to claim 1, the containerized system architecture based on Ruihua embedded real-time operating system is characterized in that: The resource space module encapsulates system resources into a variety of system resource objects, including task objects, memory objects, address space objects, device objects, interrupt objects, and communication objects.
4. According to claim 1, the containerized system architecture based on Ruihua embedded real-time operating system is characterized in that: In the resource space module, all tasks in the bound container can only use the bound system resources, which can be shared or further divided into fine-grained ways.
5. The containerized system architecture based on Ruihua embedded real-time operating system according to claim 1 is characterized in that: In the secondary real-time scheduling module, task layer scheduling refers to the task scheduling in the native Ruihua embedded real-time operating system, while container layer scheduling refers to the upper-layer container scheduling performed by this module based on the native scheduling in units of containers.
6. The containerized system architecture based on Ruihua embedded real-time operating system according to claim 1 is characterized in that: The security of communication can be achieved based on the information security features provided by the processor. For example, the trusted execution environment mechanism of the ARM architecture-based processor can provide a container security service module to support the security control of information flow communication between containers. TrustZone-based container security enhancement can use this hardware isolation to achieve isolation between the container and the host environment.
7. The containerized system architecture based on Ruihua embedded real-time operating system according to claim 1 is characterized in that: In real-time containers, in order to ensure the real-time requirements of real-time containers, it is supported to directly run the drivers of some direct-pass devices in the container, that is, the container directly manages and exclusively uses the device drivers. The device driver uses a fast interrupt response mechanism from the privileged level to obtain a more efficient interrupt processing process and more stable mission-critical performance.
8. The containerized system architecture based on Ruihua embedded real-time operating system according to claim 1 is characterized in that: Running in a non-privileged container, the functional requirements of the container in the embedded scenario are static. The required system service types can be determined before the entire system deployment phase begins. Users can choose to start a specific system service container based on their needs. User containers can use various system services provided by each system service container through cross-process communication between containers.
9. The containerized system architecture based on Ruihua embedded real-time operating system according to claim 1 is characterized in that: The deployment and operation process of container applications on Ruihua embedded real-time operating system is as follows: During the container deployment phase, the container manager parses the container configuration file provided by the user to obtain the type, performance indicators, resource quota, and priority configuration information of the container to be created. It then calls the relevant interfaces provided by the kernel and specific function containers to register the above information to the corresponding performance control group and resource space, preparing for performance and resource isolation during container runtime. After the preparation is completed, the container manager will run the initial task of the target container based on the container image packaged by the user's application, thereby pulling up the container; During the container operation phase, the container manager will continuously monitor the health and performance status of each container. If a container fails during operation, the container manager will decide on the handling method based on the priority information in its configuration information, including restarting the container, exiting silently, reporting an error, and stopping other container operations. In addition, it will work with the kernel to accurately track the specific behavior of each task in each container. Based on this behavior audit information, the overall performance and health level of the container can be further analyzed.
Citation Information
Cited By
Containerized system architecture based on reworks embedded real-time operating system
WO2026148808A1