Virtualized browser based on ARM architecture and XC architecture

By designing a virtualized browser based on ARM architecture and XC architecture, using comprehensive independent research and development strategies and advanced technical means, the shortcomings of existing virtualized browsers in terms of security, compatibility, autonomous controllability and performance optimization are solved, and an efficient, secure and compatible virtualized browser system is achieved.

CN120066644APending Publication Date: 2025-05-30SAISI TECH (XIAN) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510092935.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing virtualized browsers have shortcomings in security, inter-architecture compatibility, autonomous controllability, resource management and performance optimization, especially in the ARM architecture, which fails to fully utilize its low-power characteristics, resulting in inefficiency in the system.

Method used

A virtualized browser based on ARM architecture and XC architecture is designed, and a comprehensive independent research and development strategy is adopted, including virtualization platform module, browser instance module, operating system module, sandbox module, encryption layer module, virtual resource manager module and management platform module. Through hardware-level security encryption measures, sandbox isolation mechanism, dynamic resource allocation and deep learning resource prediction model, cross-platform compatibility and efficient resource management are achieved.

Benefits of technology

It realizes high security, cross-platform compatibility, autonomous controllability and efficient resource management, improves the stability and performance of the system, ensures efficient operation on both ARM and X86 architectures, and is suitable for a variety of operating systems and devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066644A_ABST
    Figure CN120066644A_ABST
Patent Text Reader

Abstract

The invention discloses a virtualized browser based on ARM architecture and XC architecture, which relates to the technical field of virtualized browsers and comprises a virtualized platform module, a browser instance module, an operating system module, a sandbox module, an encryption layer module, a virtual resource manager module and a management platform module. According to the method, the risks of technology blocking, supply interruption and the like possibly caused by external technology limitation are effectively avoided, the sustainability and safety of technology development are ensured, key information infrastructures are completely and autonomously controlled on the browser application level, and the autonomous controllability is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of virtualized browsers, and more specifically, to a virtualized browser based on the ARM architecture and the XC architecture. Background Art

[0002] With the wide popularization of cloud computing, virtualization technology, and browser applications, virtualized browsers, as a new type of technology, have been applied in many fields. By isolating the operating environment of the browser from the main operating system, virtualized browsers enable each browser instance to run in an independent virtual machine or container, thereby improving the security and stability of the system. Virtualization technology creates multiple virtual environments, providing more efficient resource utilization while enhancing data isolation and cross-platform compatibility.

[0003] Currently, most virtualized browsers are based on the traditional X86 architecture and use a hypervisor or container technology to achieve isolation of browser instances. The hypervisor provides an independent operating environment through hardware virtualization support, while container technology achieves resource isolation and sharing through operating system-level virtualization. These technologies are mainly applied in scenarios such as data centers, large-scale cloud computing environments, and virtual desktops. In terms of processor architecture, the X86 architecture remains the mainstream, supporting high-performance computing capabilities and being compatible with most current operating systems and applications. At the same time, the ARM architecture, as a low-power, high-performance processor architecture that has emerged in recent years, has gradually been widely applied in mobile devices, embedded devices, and some low-power servers. To support the needs of multiple devices and platforms, virtualized browsers need to be able to migrate seamlessly and run compatibly between the X86 and ARM architectures.

[0004] Although existing virtualized browsers have achieved good application effects in some specific scenarios, there are still problems in multiple aspects, mainly including the following aspects:

[0005] 1) Insufficient security: Most current virtualized browsers rely on foreign technologies, especially in terms of security mechanisms at the hardware and operating system levels, there are security risks. For example, when vulnerabilities that may exist in virtualization technology are exploited by attackers, it may affect the security of the entire virtual environment. Since many technologies rely on external chips and operating systems, these technologies cannot fully ensure autonomy and controllability, which may lead to risks such as data leakage and privacy infringement.

[0006] 2) Poor compatibility between architectures: Most existing virtualized browsers are optimized for the X86 architecture and have weak support for the ARM architecture. Although some virtualization platforms have started to support the ARM architecture, due to differences in instruction sets, memory management methods, and hardware support between the ARM and X86 architectures, virtualized browsers still face significant challenges in cross-platform compatibility. Especially in terms of performance optimization and resource management under different architectures, it may lead to differences in operating efficiency and stability on different platforms.

[0007] 3) Lack of autonomy and controllability: Most existing virtualized browsers rely on foreign processor architectures and operating systems, resulting in insufficient technical autonomy and controllability. Especially in terms of security and information privacy, relying on external technologies may introduce uncontrollable risks. Although domestic substitution technologies have gradually made some progress, most alternative solutions have not been widely applied in the design and implementation of virtualized browsers.

[0008] 4) Resource management and performance optimization issues: In traditional virtualized browsers, resource allocation and management are often achieved through general virtualization platforms. This general solution cannot be fully optimized according to different architectures and hardware platforms. Especially in scenarios with high concurrency and high performance requirements, existing virtualized browsers may experience uneven resource allocation, performance bottlenecks, and system stability issues. For example, on low-power ARM architectures, existing virtualized browsers may not fully consider the balance between power consumption and processing capabilities, resulting in low system efficiency.

[0009] 5) Limitations of the technical path: Most existing technologies only target the X86 architecture and ignore support for the ARM architecture. This singularity of the technical path limits the application scenarios of virtualized browsers. Especially in scenarios with high requirements for low power consumption and high performance, such as embedded devices and mobile devices, the advantages of virtualization technology cannot be fully utilized.

[0010] Regarding the problems in the related technologies, no effective solutions have been proposed yet. Summary of the Invention

[0011] Regarding the problems in the related technologies, the present invention proposes a virtualized browser based on the ARM architecture and the XC architecture to overcome the above-mentioned technical problems existing in the existing related technologies.

[0012] The technical solution of the present invention is implemented as follows:

[0013] A virtualized browser based on the ARM architecture and the XC architecture, including: a virtualization platform module, a browser instance module, an operating system module, a sandbox module, an encryption layer module, a virtual resource manager module, and a management platform module, where;

[0014] The virtualization platform module is used to create virtual machines or containers on the host operating system and provide an independent running environment for the browser instance module;

[0015] The browser instance module is used to provide an actual running browser, and all user operations are processed through this browser instance module. Among them, each browser instance module runs independently in the virtualized environment and includes a browser kernel;

[0016] The operating system module is used to provide operating system support for the virtualization platform module and the browser instance module;

[0017] The sandbox module is used to isolate the browser instance module process and prevent the impact of malicious scripts or vulnerable extensions on the system;

[0018] The encryption layer module is used for the communication between the browser instance module and the external network to prevent data leakage or tampering;

[0019] The virtual resource manager module is used to allocate resources for the browser instance module, including CPU, memory, and disk space, and perform dynamic allocation according to the scheduling policy of the virtualization platform module;

[0020] The management platform module is used to provide a centralized user interface or API interface to manage the creation, scheduling, monitoring, and resource allocation of the browser instance module.

[0021] Furthermore, it includes the following steps:

[0022] Pre - perform environment initialization and virtualization platform module construction;

[0023] Create virtual machine or container instances;

[0024] Configure the browser kernel and environment;

[0025] Perform resource isolation and scheduling;

[0026] Perform security isolation using the sandbox mechanism;

[0027] Deploy and manage virtual browsers.

[0028] Furthermore, the pre - performing environment initialization and virtualization platform module construction includes: calibrating the virtualization platform module based on different hardware architectures. Among them, the virtualization platform module will create multiple virtual environments or containers on the host operating system to isolate the environments where browser instances run.

[0029] Furthermore, the creating of virtual machine or container instances includes the following steps:

[0030] Perform virtual machine configuration in advance, and allocate independent memory, CPU, and disk space for each virtual machine through the hypervisor;

[0031] Perform container configuration, use containerization technology to create multiple independent browser containers, and the containers share the kernel of the host operating system;

[0032] Perform incremental imaging, which is used to load only the necessary files for each instance, reduce resource occupancy, and at the same time support fast switching and live migration between instances.

[0033] Furthermore, the configuration of the browser kernel and environment includes the following steps:

[0034] Designate an open-source browser as the kernel and install and configure it in a virtual environment. Among them, each browser instance in the virtual environment will have its own configuration, cache, and data storage, which are not shared with other instances, and the plugins and extensions of the browser will also be managed independently.

[0035] Furthermore, the resource isolation and scheduling includes the following steps:

[0036] Perform resource management, and perform dynamic resource allocation through the virtualization platform module to ensure that each virtual browser instance obtains sufficient resources and does not interfere with the normal operation of other instances;

[0037] Perform performance monitoring and scheduling. The virtualization platform module monitors the performance of each virtualized browser instance in real time to ensure the stability of the system, and can automatically expand or contract virtual resources according to load changes.

[0038] Furthermore, the security isolation using the sandbox mechanism includes the following steps:

[0039] Designate the sandbox mechanism. Each browser instance module will run in a restricted environment, and the browser process, file system, and network are strictly isolated;

[0040] Perform data encryption and access control. All sensitive data in the browser is encrypted to avoid data leakage, and access operations are restricted by access control policies.

[0041] Furthermore, the deployment and management of the virtual browser include: providing a centralized management function through a graphical interface or API. Administrators can create, destroy, monitor, and view logs of virtual browser instances through the management platform, and the system can automatically expand virtual browser instances according to the load situation to ensure the stability of the system under high concurrency.

[0042] The beneficial effects of the present invention:

[0043] 1. The present invention fully adopts XC architecture technology, and all components from hardware to software are independently developed. This means that we have gotten rid of our dependence on foreign technology and have absolute autonomy at the technical level. Whether it is the core chip, virtualization platform, or browser kernel and related components, they can be customized and optimized according to their own needs, effectively avoiding the risks of technical blockade and supply interruption caused by external technical restrictions, ensuring the sustainability and security of technological development, and enabling key information infrastructure to achieve complete autonomous control at the browser application level, with significantly improved autonomous controllability.

[0044] 2. The security of the present invention reaches a new level. Through hardware-level security encryption measures, such as using the encryption module that comes with the XC architecture to encrypt data with high strength, it is ensured that during the data transmission and storage process, even in the face of external attacks, the data is difficult to be stolen or tampered with. In terms of the isolation mechanism in the virtualized environment, a strict isolation barrier is established between virtual machines and between browser instances and the host system to effectively prevent the lateral spread of malicious attacks within the system. Even if a browser instance is attacked, the impact can be strictly limited to the instance and cannot spread to other parts, which greatly enhances the overall security of the system and provides users with reliable data protection and a safe browsing environment.

[0045] 3. The present invention has excellent cross-platform compatibility. It supports two mainstream architectures, ARM and X86, as well as multiple operating systems such as Linux, Windows, and domestic operating systems. This allows users to use the virtualized browser smoothly and obtain a consistent user experience regardless of the type of device they use, whether it is a traditional X86 architecture desktop or notebook, or an emerging ARM architecture mobile device, embedded device, or a different operating system platform. This wide cross-platform compatibility breaks the limitations of hardware and operating systems, broadens the scope of application of the browser, and meets the diverse needs of users. Especially in enterprise-level applications, it can achieve seamless docking between different devices and systems and improve work efficiency.

[0046] 4. The resource management of the present invention is highly optimized. With the help of virtualized resource management strategies, the system can dynamically allocate resources in real time according to the actual needs of each browser instance. In low-load scenarios, the resource allocation to idle instances is automatically reduced to reduce system power consumption; in high-load conditions, more resources are quickly allocated to busy instances to ensure their efficient operation. This precise resource allocation method effectively improves resource utilization efficiency and avoids waste and idleness of resources. At the same time, by optimizing the resource scheduling algorithm, the overhead of system resource scheduling is reduced, the overall performance is further improved, unnecessary energy consumption is reduced, and operating costs are reduced, which can bring significant benefits to both individual users and large-scale enterprise deployments.

[0047] 5. The performance of the present invention is excellent and stable. On the ARM architecture, it makes full use of its low-power characteristics to optimize the browser, reduce background resource consumption, significantly improve the response speed while maintaining efficient operation, enabling timely feedback for user operations and providing a smoother browsing experience. On the X86 architecture, by combining its high computing performance and the advantages of multi-core processors, it greatly enhances the concurrent processing ability of the browser, enabling it to easily handle tasks such as multi-tab browsing, complex web page loading, and large data processing, ensuring stable operation of the system in high-concurrency scenarios without lag or crashes, and providing users with efficient and stable browsing services.

[0048] 6. The maintenance and management of the present invention are convenient and efficient. Through the centralized management platform provided by the system, with an intuitive graphical interface or a powerful API, administrators can easily manage virtual browser instances comprehensively. Whether it is creating new instances, destroying useless instances, or real-time monitoring of instance status and viewing detailed logs, all can be conveniently operated on a unified platform. In the face of system failures, it can quickly locate problems and automatically recover faulty instances, greatly shortening the system downtime and reducing maintenance costs. At the same time, the resource prediction model based on deep learning helps administrators plan resources in advance, optimize system performance, and ensure that the entire virtualized browser system is always in the best operating state.

[0049] 7. The present invention supports the development of the domestic ecological environment. It is optimized for domestic chips and operating systems and provides localized support libraries, which strongly promotes the development of the domestic software and hardware ecological environment. It plays an active role in the construction of the domestic independent and controllable information industry system, improves the market competitiveness of domestic chips and operating systems, promotes the wide application of domestic technologies in the browser field, provides important support for achieving independent innovation and security and controllability in the field of information technology, and helps to build a complete, secure, and reliable domestic information technology industrial chain. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0051] Figure 1 FIG. is a schematic diagram of the principle of a virtualized browser based on the ARM architecture and the XC architecture according to an embodiment of the present invention;

[0052] Figure 2 FIG. is a schematic diagram of the process of a virtualized browser based on the ARM architecture and the XC architecture according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present invention.

[0054] The present invention ensures that under the two major architecture systems of ARM and X86, the browser can have comprehensive independent and controllable capabilities, so as to effectively cope with the challenges in terms of security, controllability and performance in the current technology. This strategy realizes the complete isolation of the browser instance from its host operating system and the underlying hardware environment by constructing a virtualized browser environment. Running the browser on this carefully designed virtualization platform (such as a virtual machine or container environment) not only ensures the complete independence between the browser and the host system, but also greatly enhances the security protection level, running stability and overall performance of the browser.

[0055] According to an embodiment of the present invention, a virtualized browser based on the ARM architecture and the XC architecture is provided.

[0056] As Figure 1 - Figure 2 shown, the virtualized browser based on the ARM architecture and the XC architecture according to the embodiment of the present invention includes: a virtualization platform module 1, a browser instance module 2, an operating system module 3, a sandbox module 4, an encryption layer module 5, a virtual resource manager module 6 and a management platform module 7.

[0057] The virtualization platform module 1 is used to create a virtual machine or a container on the host operating system and provide an independent running environment for the browser instance module 2.

[0058] The browser instance module 2 is used to provide an actual running browser, and all user operations are processed through the browser instance module 2. Among them, each browser instance module 2 runs completely independently in the virtualized environment and has its own network, file system and browser kernel.

[0059] The operating system module 3 is used to provide operating system support for the virtualization platform module 1 and the browser instance module 2; among them, the operating system can be Linux, Windows or a domestic operating system, etc.

[0060] The sandbox module 4 is used to isolate the browser instance module 2 process and prevent the impact of malicious scripts or vulnerable extensions on the system.

[0061] In this technical solution, the sandbox module 4 ensures the complete isolation of the memory, file system, process, etc. between the browser instance module 2 and the host system.

[0062] An encryption layer module 5, which is used for communication between the browser instance module 2 and the external network to prevent data leakage or tampering;

[0063] A virtual resource manager module 6, which is used to allocate resources for the browser instance module 2, including CPU, memory, and disk space, and dynamically allocate them according to the scheduling policy of the virtualization platform module 1;

[0064] A management platform module 7, which is used to provide a centralized user interface or API interface to manage the creation, scheduling, monitoring, and resource allocation of the browser instance module 2;

[0065] In this technical solution, the virtualization platform module 1 is closely connected to the operating system module 3 and the browser instance module 2, providing functions such as hardware resource virtualization and dynamic allocation of memory and CPU. The browser instance module 2 interacts with the host operating system through the virtualization platform module 1. The operating system is the basis for the operation of the virtualization platform module 1, which provides hardware resource support for the virtualization platform module 1 and interacts with the browser instance module 2 through system calls and device drivers. The encryption layer module 5 is connected to the network module of the browser instance module 2 to ensure that all communications between the browser and the network are encrypted. The virtualization platform module 1 interacts with the virtualization platform module 1 and the operating system to ensure that the browser instance module 2 obtains the required resources. The management platform module 7 is connected to the virtualization platform module 1, the browser instance module 2, and the virtual resource manager module 6 for unified management and monitoring.

[0066] It includes the following steps:

[0067] Pre - perform environment initialization and build the virtualization platform module 1;

[0068] Specifically, the system will initialize the required hardware platform and select a suitable virtualization platform module 1 based on different hardware architectures such as X86 and ARM architectures. The virtualization platform module 1 will create multiple virtual environments or containers on the host operating system to run browser instances in these isolated environments.

[0069] In this technical solution, the XC domestic substitution solution is mainly implemented under domestic ARM chips and X86 architectures, supporting virtualization technologies through hardware virtualization extensions such as ARM's virtualization extension, X86's VT - x, AMD - V, etc. At the same time, select a suitable virtualization technology according to the architecture. For example, use KVM or QEMU on the X86 platform and use KVM or other adapted virtualization solutions on the ARM platform.

[0070] Create virtual machine or container instances;

[0071] In this technical solution, on the virtualization platform module 1, independent virtual machines VM or container instances are created. Each virtual machine or container instance will serve as an independent browser running environment, isolated from each other to prevent malicious code or browser failures from affecting the host system.

[0072] Specifically, for virtual machine configuration: Through a virtualization hypervisor such as QEMU / KVM, independent memory, CPU, disk space and other resources are allocated to each virtual machine.

[0073] For container configuration: Using containerization technologies such as Docker, LXC, etc., multiple independent browser containers are created. These containers share the kernel of the host operating system, but each container has an independent file system, network stack, etc.

[0074] At the same time, the incremental image technology is used in instance creation. Each instance only loads the necessary files, significantly reducing resource occupancy, and at the same time supporting fast switching and live migration between instances.

[0075] In addition, when applied, the incremental image technology has the following characteristics:

[0076] Including: On-demand loading mechanism. Through the on-demand loading mechanism, the incremental image technology only loads the necessary data required for the browser instance to run, rather than the complete image file. Using the initialization image as the basis, the differential part is dynamically loaded during runtime. This mechanism effectively reduces the startup time, significantly reduces storage and memory resource occupancy, and is especially suitable for large-scale instantiation scenarios.

[0077] Including: Multi-layer image structure. The incremental image adopts a hierarchical storage structure, modularizing common browser kernels, plugin extensions, user configurations, etc. into multiple independent image layers. The incremental part only records the changes of specific instances. The common layer of this structure can be shared by multiple instances, while the differential layer only stores instance-specific data, greatly saving storage space and increasing the image reuse rate.

[0078] Including: Real-time synchronization and hot update. It supports the real-time synchronization and hot update functions of the image. The incremental part can be dynamically updated without affecting the running browser instances. After the update, the new browser instances will automatically use the latest image version. This mechanism improves the flexibility and maintenance efficiency of the system, and at the same time reduces the downtime caused by image updates.

[0079] Including: Image caching and preheating technology. The incremental image combines caching and preheating technology to preload common browser configurations, extensions and user environments, so that the cached content can be directly reused when new instances are started. This technology can reduce startup latency, optimize the user experience, and is especially suitable for high-concurrency scenarios.

[0080] Including: differential synchronization and minimized storage optimization. The differential algorithm is adopted to record the changes during mirror update, and only the changed parts such as newly added plugins and modified configurations are stored. Through efficient snapshot management, only the minimized storage space is occupied. This mechanism can reduce the storage cost of mirror management and support fast instance switching and snapshot recovery.

[0081] Perform browser kernel and environment configuration;

[0082] In this technical solution, in each virtual machine or container, a browser kernel such as Chromium or Firefox is installed and configured. The browser instance module 2 realizes the personalized needs of different users by configuring independent user profiles, extensions, and plugins. Specifically as follows:

[0083] Among them, for the browser kernel: an open-source browser such as Chromium is selected as the kernel and installed and configured in the virtual environment. Each browser instance in the virtual environment will have its own configuration, cache, and data storage, and will not be shared with other instances.

[0084] Among them, for extensions and plugins: the plugins and extensions of the browser will also be independently managed to avoid mutual influence between different browser instances.

[0085] Perform resource isolation and scheduling;

[0086] In this technical solution, each virtualized browser instance independently obtains a certain amount of computing resources such as CPU, memory, and bandwidth, and is dynamically scheduled through the virtualization platform to ensure fair distribution of resources. It includes the following steps:

[0087] Perform resource management. Through the virtualization platform module 1, dynamic resource allocation is carried out to ensure that each virtual browser instance obtains sufficient resources and does not interfere with the normal operation of other instances.

[0088] Perform performance monitoring and scheduling. The virtualization platform module 1 monitors the performance of each virtualized browser instance in real time to ensure the stability of the system and can automatically expand or contract virtual resources according to load changes;

[0089] Among them, in terms of resource isolation, a dynamic isolation strategy is adopted, which dynamically adjusts the isolation parameters of instances by combining real-time monitoring data to adapt to changes in user requirements. This strategy can improve the flexibility of the system, avoid resource idleness or overload, support elastic expansion, and provide fast response capabilities for concurrent scenarios. In terms of resource scheduling, a resource prediction model is established based on deep learning. By analyzing historical data and current load conditions, a prediction model based on deep learning is adopted in resource scheduling to predict resource requirements, achieving precise resource allocation and energy consumption optimization. By analyzing the operation of historical data and the current load situation, future resource requirements are predicted. The inputs of the model include dynamic data such as user behavior, instance running status, and concurrent request volume. By establishing a deep learning model, the output prediction results of the model are used to adjust the resource allocation strategy in advance. This model can achieve precise allocation, dynamically adjust the resource ratio, and avoid over-allocation or insufficient resource allocation. This model continuously learns the usage patterns of users through a lifelong learning mechanism to adapt to changes in scenarios.

[0090] Among them, the resource prediction model stage includes the following steps:

[0091] Data collection is carried out in advance. According to the system monitoring tool, the obtained running status data includes CPU usage rate, memory occupancy rate, disk I / O, network bandwidth, etc., user behavior data such as the operation time distribution of users, request patterns, access frequencies, and external environment data such as system load peak-valley cycles, concurrent user numbers, and service request types.

[0092] Preprocess the data to complete data cleaning, filtering of invalid data, and handling of outliers.

[0093] Calibrate the model. Based on time series features, select the transform model, and use the self-attention mechanism to mine the global dependencies in the time series. The input of the model is multi-dimensional time series data, including the characteristics of historical resource usage rates and the current system load, and the output is the predicted future time resource requirements. In the model training stage, the mean squared error is selected as the loss function to measure the error between the predicted value and the true value. In the model training stage, the data is first split into a training set, a data set, and a test set. During the training process, the Adam optimizer is used to accelerate the convergence speed of the model, and at the same time, a learning rate decay mechanism is introduced to avoid overfitting. The prediction accuracy is calculated by comparing the relative error between the output prediction value and the actual value of the model. At the same time, the overall effect of the model is measured by verifying the energy consumption change after resource scheduling optimization.

[0094] Deploy the model. Deploy the trained model to the resource scheduling module, combine the actual monitoring data to predict resource requirements, and thus dynamically adjust the resources according to the prediction results.

[0095] With the above solution, a resource prediction model is adopted, which not only has accurate prediction: the deep learning model can capture complex time series features and is more accurate than traditional statistical methods; but also has strong adaptability: the model can continuously learn new data and adapt to the dynamic changes of user needs and load patterns. At the same time, it has real-time response: quickly predicts future resource requirements, completes allocation in advance, and avoids insufficient or over-allocation of system resources. In addition, it has high scalability: supports multiple hardware environments and different virtualization platforms such as ARM and X86 architectures

[0096] Perform security isolation using the sandbox mechanism;

[0097] In this technical solution, the virtualized browser isolates the browser instance module 2 from the host system through sandbox technology and security policies, ensuring that malicious websites, malicious codes, etc. cannot affect the entire system.

[0098] Calibrate the sandbox mechanism: Each browser instance module 2 will run in a restricted environment, and browser processes, file systems, networks, etc. are strictly isolated. Even if a certain browser instance module 2 is attacked, the attack cannot spread to the host operating system or other browser instances.

[0099] Perform data encryption and access control. All sensitive data in the browser, such as passwords, history records, etc., are encrypted to avoid data leakage. All access operations are restricted by strict access control policies.

[0100] With the above solution, it supports the deep integration of the hardware trusted execution environment TEE and the virtualization sandbox, further enhancing the system's anti-attack ability. The TEE of the trusted execution environment is a hardware trusted area isolated from the operating system, providing protection for the secure execution of code and data. Combining TEE with the virtual sandbox, sensitive operations are completed in TEE, while non-sensitive operations are still executed in the sandbox. TEE manages confidential data, while the sandbox isolates the execution of untrusted or third-party code. The implementation method is as follows: First, run the browser core module in TEE; the virtualization sandbox is used to isolate browser plugins, extensions, or run dynamic content; adopt dual-channel communication, and TEE and the sandbox perform data interaction through a secure channel to prevent information leakage.

[0101] Deploy and manage the virtual browser;

[0102] In this technical solution, to ensure the scalability and high availability of the virtual browser system, the system provides a management platform module 7, which can monitor the status of virtualized browser instances in real time and perform resource scheduling and fault recovery. Including:

[0103] Provide centralized management functions through a graphical interface or API. Administrators can create, destroy, monitor, view logs, etc. for virtual browser instances through the management platform. At the same time, according to the load situation, the system can automatically expand virtual browser instances to ensure the stability of the system under high concurrency. At the same time, for faulty instances, the system can automatically recover.

[0104] In addition, during application, the present invention realizes cross-platform support and optimization. Its virtualized browser can support different hardware architectures such as X86 and ARM, and operating systems such as Linux, Windows, and domestic operating systems, ensuring stable operation on multiple platforms. The platform optimizes virtualization performance for domestic chips, provides a localized support library, and significantly improves the operating efficiency of domestic systems. Specific implementation:

[0105] Realize hardware platform support: By adapting virtualization platforms for different hardware architectures, ensure that the virtual browser can run across platforms, supporting domestic chips such as the ARM architecture and the traditional X86 architecture.

[0106] Realize operating system support: The virtualized browser supports Linux, Windows, and domestic operating systems, etc., ensuring that users can use the virtualized browser in different operating system environments.

[0107] In the implementation of this technical solution, the implementation of the virtualized browser based on XC domestic substitution technology on the ARM architecture: On the ARM architecture, first, the XC processor provides hardware support for the virtualized browser, starts the virtualization technology, and loads the browser core. Utilizing the low-power consumption characteristics of ARM, the present invention optimizes the browser, reduces background resource consumption, and improves the response speed and stability of the browser. All data and network transmissions are encrypted through the hardware encryption module provided by the XC architecture to ensure user information security.

[0108] In addition, in the implementation, the implementation of the virtualized browser based on XC domestic substitution technology on the X86 architecture: On the X86 architecture, the present invention optimizes the virtualization environment through the XC architecture, combines the high computing performance of X86, makes full use of the advantages of multi-core processors, and improves the concurrent processing ability of the browser. The virtualized browser runs in an isolated virtual machine to ensure the independence of the operating system and the browser environment, and at the same time supports multi-user sessions and high-concurrency data processing.

[0109] In addition, during implementation, optimization in the domestic operating system environment: In the domestic operating system, the virtualized browser makes full use of the localized interfaces and features provided by the operating system. Through deep adaptation to the domestic operating system, the system call efficiency is further optimized, and unnecessary intermediate layer overhead is reduced. For example, in terms of file system access, the efficient file management module of the domestic operating system is directly called, which improves the reading and writing speed of the browser to local files. At the same time, in response to the security mechanisms of the domestic operating system, such as the built-in security protection module and permission management system, the virtualized browser is closely integrated with them to achieve more refined security policy configuration. During the use process, users can experience a smoother operation experience and a higher level of security guarantee, effectively promoting the coordinated development of the domestic information technology ecosystem.

[0110] In addition, during implementation, the performance in high-concurrency scenarios: In high-concurrency scenarios, such as the multi-person office environment of large enterprises or high-traffic Internet service platforms, this virtualized browser demonstrates excellent performance. When a large number of users simultaneously access multiple web pages and perform complex online operations such as real-time video conferencing and collaborative editing of documents by multiple people, the resource prediction model based on deep learning accurately estimates resource requirements, and the virtualization platform quickly allocates sufficient CPU, memory, and bandwidth resources to each browser instance. The dynamic isolation strategy ensures that each instance runs independently without interference, effectively avoiding performance degradation caused by resource competition. The incremental image technology enables fast instance startup and switching, greatly shortening the user waiting time. Through actual testing, in the case of thousands of concurrent users, the system can still maintain a stable response speed and low latency, ensuring the efficient continuity of business and providing a reliable solution for high-load application scenarios.

[0111] In summary, by means of the above technical solutions of the present invention, the following effects can be achieved:

[0112] 1. The present invention comprehensively adopts the XC architecture technology, and all components from hardware to software are independently developed. This means getting rid of the dependence on foreign technologies and having absolute autonomy at the technical level. Whether it is the core chip, virtualization platform, browser kernel, or related components, they can be customized and optimized according to their own needs, effectively avoiding risks such as technology blockade and supply interruption that may be caused by external technical restrictions, ensuring the sustainability and security of technology development, and enabling complete autonomous control of critical information infrastructure at the browser application level, with significantly improved autonomy and controllability.

[0113] 2. The security of the present invention reaches a new level. Through hardware-level security encryption measures, such as using the encryption module that comes with the XC architecture to encrypt data with high strength, it is ensured that during the data transmission and storage process, even in the face of external attacks, the data is difficult to be stolen or tampered with. In terms of the isolation mechanism in the virtualized environment, a strict isolation barrier is established between virtual machines and between browser instances and the host system to effectively prevent the lateral spread of malicious attacks within the system. Even if a browser instance is attacked, the impact can be strictly limited to the instance and cannot spread to other parts, which greatly enhances the overall security of the system and provides users with reliable data protection and a safe browsing environment.

[0114] 3. The present invention has excellent cross-platform compatibility. It supports two mainstream architectures, ARM and X86, as well as multiple operating systems such as Linux, Windows, and domestic operating systems. This allows users to use the virtualized browser smoothly and obtain a consistent user experience regardless of the type of device they use, whether it is a traditional X86 architecture desktop or notebook, or an emerging ARM architecture mobile device, embedded device, or a different operating system platform. This wide cross-platform compatibility breaks the limitations of hardware and operating systems, broadens the scope of application of the browser, and meets the diverse needs of users. Especially in enterprise-level applications, it can achieve seamless docking between different devices and systems and improve work efficiency.

[0115] 4. The resource management of the present invention is highly optimized. With the help of virtualized resource management strategies, the system can dynamically allocate resources in real time according to the actual needs of each browser instance. In low-load scenarios, the resource allocation to idle instances is automatically reduced to reduce system power consumption; in high-load conditions, more resources are quickly allocated to busy instances to ensure their efficient operation. This precise resource allocation method effectively improves resource utilization efficiency and avoids waste and idleness of resources. At the same time, by optimizing the resource scheduling algorithm, the overhead of system resource scheduling is reduced, the overall performance is further improved, unnecessary energy consumption is reduced, and operating costs are reduced, which can bring significant benefits to both individual users and large-scale enterprise deployments.

[0116] 5. The present invention has excellent and stable performance. On the ARM architecture, it makes full use of its low power consumption characteristics to optimize the browser and reduce the background resource consumption, so that the browser can significantly improve the response speed while maintaining efficient operation, and the user operation can get timely feedback, and the browsing experience is smoother. On the X86 architecture, combined with its high computing performance and multi-core processor advantages, the concurrent processing capability of the browser is greatly enhanced, and it can easily cope with tasks such as multi-tab browsing, complex web page loading, and large amounts of data processing, ensuring that the system still runs stably in high-concurrency scenarios without freezes or crashes, providing users with efficient and stable browsing services.

[0117] 6. The maintenance and management of the present invention are convenient and efficient. Through the centralized management platform provided by the system, and through an intuitive graphical interface or a powerful API, administrators can easily manage virtual browser instances comprehensively. Whether it is creating new instances, destroying useless instances, or monitoring the instance status in real time and viewing detailed logs, all can be conveniently operated on a unified platform. When dealing with system failures, it can quickly locate problems and automatically recover faulty instances, greatly shortening the system downtime and reducing the maintenance cost. At the same time, the resource prediction model based on deep learning helps administrators plan resources in advance, optimize system performance, and ensure that the entire virtualized browser system is always in the best operating state.

[0118] 7. The present invention supports the development of the domestic ecological environment. It is optimized for domestic chips and operating systems and provides localized support libraries, which strongly promotes the development of the domestic software and hardware ecological environment. It plays an active role in the construction of the domestic self-controlled information industry system, improves the market competitiveness of domestic chips and operating systems, promotes the wide application of domestic technologies in the browser field, provides an important support for achieving independent innovation and security control in the field of information technology, and helps to build a complete, secure and reliable domestic information technology industry chain.

[0119] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Those skilled in the art will easily think of other implementation schemes of the present disclosure after considering the disclosure in the specification and the embodiments. This application aims to cover any variations, uses or adaptive changes of the present disclosure, and these variations, uses or adaptive changes follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the claims.

[0120] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A virtualized browser based on ARM architecture and XC architecture, characterized in that: include: A virtualization platform module (1), a browser instance module (2), an operating system module (3), a sandbox module (4), an encryption layer module (5), a virtual resource manager module (6) and a management platform module (7), wherein; The virtualization platform module (1) is used to create a virtual machine or container on the host operating system to provide an independent operating environment for the browser instance module (2); The browser instance module (2) is used to provide an actual running browser, and all user operations are processed by the browser instance module (2), wherein each browser instance module (2) runs independently in a virtualized environment and includes a browser kernel; The operating system module (3) is used to provide operating system support for the virtualization platform module (1) and the browser instance module (2); The sandbox module (4) is used to isolate the browser instance module (2) process to prevent malicious scripts or vulnerability extensions from affecting the system; The encryption layer module (5) is used for communication between the browser instance module (2) and the external network to prevent data leakage or tampering; The virtual resource manager module (6) is used to allocate resources of the browser instance module (2), including CPU, memory and disk space, and dynamically allocate them according to the scheduling policy of the virtualization platform module (1); The management platform module (7) is used to provide a centralized user interface or API interface to manage the creation, scheduling, monitoring and resource allocation of the browser instance module (2).

2. The virtualized browser based on ARM architecture and XC architecture according to claim 1, characterized in that: The following steps are involved: Initialize the environment and build the virtualization platform module (1) in advance; Create a virtual machine or container instance; Configure the browser kernel and environment; Perform resource isolation and scheduling; Use sandbox mechanism for security isolation; Deploy and manage virtual browsers.

3. The virtualized browser based on ARM architecture and XC architecture according to claim 2, characterized in that: The pre-initialization of the environment and the construction of the virtualization platform module (1) include: calibrating the virtualization platform module (1) based on different hardware architectures, wherein the virtualization platform module (1) creates multiple virtual environments or containers on the host operating system for running browser instances in isolated environments.

4. The virtualized browser based on ARM architecture and XC architecture according to claim 2, characterized in that: The step of creating a virtual machine or container instance includes the following steps: Pre-configure virtual machines and allocate independent memory, CPU and disk space to each virtual machine through the virtualization management program; Perform container configuration and use containerization technology to create multiple independent browser containers that share the kernel of the host operating system. Incremental mirroring is used to load only necessary files for each instance, reducing resource usage while supporting fast switching and hot migration between instances.

5. The virtualized browser based on ARM architecture and XC architecture according to claim 2, characterized in that: The browser kernel and environment configuration includes the following steps: The open source browser is used as the kernel and installed and configured in the virtual environment. Each browser instance in the virtual environment will have its own configuration, cache, and data storage, which are not shared with other instances, and the browser plug-ins and extensions will also be managed independently.

6. The virtualized browser based on ARM architecture and XC architecture according to claim 2, characterized in that: The resource isolation and scheduling includes the following steps: Perform resource management and dynamically allocate resources through the virtualization platform module (1) to ensure that each virtual browser instance obtains sufficient resources without interfering with the normal operation of other instances; To perform performance monitoring and scheduling, the virtualization platform module (1) monitors the performance of each virtualized browser instance in real time to ensure the stability of the system and can automatically expand or shrink virtual resources according to load changes.

7. The virtualized browser based on ARM architecture and XC architecture according to claim 2, characterized in that: The method of using a sandbox mechanism for security isolation includes the following steps: The sandbox mechanism is defined, where each browser instance module (2) runs in a restricted environment, and the browser process, file system, and network are strictly isolated; Data encryption and access control are performed. All sensitive data in the browser is encrypted to avoid data leakage, and access operations are restricted by access control policies.

8. The virtualized browser based on ARM architecture and XC architecture according to claim 2, characterized in that: The deployment and management of virtual browsers include: providing centralized management functions through a graphical interface or API, and administrators can create, destroy, monitor and view logs of virtual browser instances through a management platform. According to the load conditions, the system can automatically expand virtual browser instances to ensure the stability of the system under high concurrency conditions.

Citation Information

Cited By

  • Multi-webpage application automatic execution method and system based on virtual browser isolation

    CN121561212A