---
格式版本: 2
标题: "WebAssembly + Zephyr: A Two-Layer Isolation Model for Embedded Systems"
原文链接: "https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542"
发布日期: "2026-07-22"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:scrape:provider_published_at"
发布时间证据: "provider publishedAt: 2026-07-22"
发布时间校准原因: "规则确认唯一严格发布时间，来源 scrape:provider_published_at"
发布时间校准置信度: "high"
发布时间候选数量: 3
发布时间严格候选数量: 1
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-10T16:04:03+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-10T15:56:26+08:00"
入库时间: "2026-08-10T08:04:04.400Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://community.intel.com/t5/Blogs/ct-p/blogs"
匹配关键词:
  - "GPU"
  - "deployment"
  - "performance"
相关厂家:
  - "Intel"
  - "Microsoft"
  - "Google"
相关专家:
  []
内容类型: "网页"
抓取工具: "Jina Reader"
清洗工具: "Jina Reader Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 15
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "正文关于嵌入式系统隔离模型，与超节点/AI Rack/机柜级AI基础设施完全无关，无任何相关关键词或技术细节。"
AI质检模型: "deepseek-v4-flash"
AI质检时间: "2026-08-10T16:04:10+08:00"
AI主题相关性: 0
AI来源权威性: 15
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
采集批次: "2026年8月10日15点37分56秒"
采集批次ID: "20260810-153756-703"
去重键: "https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542"
---

Title: WebAssembly + Zephyr: A Two-Layer Isolation Model for Embedded Systems

URL Source: https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542

Published Time: 2026-07-22T08:50:53.935Z

Markdown Content:
hidden text to trigger **early**_load_ of fonts Продукция**Продукция**_Продукция_ Продукция Các sản phẩm**Các sản phẩm**_Các sản phẩm_ Các sản phẩm المنتجات**المنتجات**_المنتجات_ المنتجات מוצרים**מוצרים**_מוצרים_ מוצרים

[![Image 1: Intel logo - Return to the home page](https://www.intel.com/content/dam/logos/intel-header-logo.svg)](https://www.intel.com/content/www/us/en/homepage.html)

Toggle Navigation

1.   Products

[Products Home](https://www.intel.com/content/www/us/en/products/overview.html) 

[Processors](https://www.intel.com/content/www/us/en/products/details/processors.html)

    *   [Intel® Core™ Ultra Processors](https://www.intel.com/content/www/us/en/products/details/processors/core-ultra.html)
    *   [Intel® Core™ Processors](https://www.intel.com/content/www/us/en/products/details/processors/core.html)
    *   [Intel® Xeon® Processors](https://www.intel.com/content/www/us/en/products/details/processors/xeon/all.html)
    *   [Intel® Xeon® CPU Max Series](https://www.intel.com/content/www/us/en/products/details/processors/xeon/max-series.html)
    *   [Intel® Arc™ G-Series Processors](https://www.intel.com/content/www/us/en/products/details/processors/arc/g-series/handheld-gaming.html)
    *   [Intel Atom® Processors](https://www.intel.com/content/www/us/en/products/details/processors/atom.html)

[Select Systems & Devices](https://www.intel.com/content/www/us/en/products/systems-devices.html)

    *   [AI PCs Powered by Intel](https://www.intel.com/content/www/us/en/ai-pc/overview.html)
    *   [Gaming Systems](https://www.intel.com/content/www/us/en/gaming/serious-gaming.html)
    *   [Intel vPro® for Business](https://www.intel.com/content/www/us/en/architecture-and-technology/vpro/overview.html)
    *   [Intel® Arc™ Graphics](https://www.intel.com/content/www/us/en/products/details/discrete-gpus/arc.html)
    *   [Intel® Wi-Fi Products](https://www.intel.com/content/www/us/en/products/details/wireless.html)

[AI Accelerators](https://www.intel.com/content/www/us/en/products/docs/accelerator-engines/ai-engines.html)

    *   [Intel® Gaudi® AI Accelerators](https://www.intel.com/content/www/us/en/products/details/processors/ai-accelerators/gaudi.html)
    *   [Intel® Data Center GPU Flex Series](https://www.intel.com/content/www/us/en/products/details/discrete-gpus/data-center-gpu/flex-series.html)

[Network to Edge](https://www.intel.com/content/www/us/en/products/details/network-io.html)

    *   [Edge and Embedded Processors](https://www.intel.com/content/www/us/en/products/details/embedded-processors.html)
    *   [Intel® Ethernet Products](https://www.intel.com/content/www/us/en/products/details/ethernet.html)
    *   [Intel® Infrastructure Processing Unit (Intel® IPU)](https://www.intel.com/content/www/us/en/products/details/network-io/ipu.html)
    *   [Intel Robotics](https://www.intel.com/content/www/us/en/products/details/robotics.html)

[Software](https://www.intel.com/content/www/us/en/software/software-overview.html)

    *   [oneAPI Unified Runtime](https://www.intel.com/content/www/us/en/developer/tools/oneapi/overview.html)
    *   [OpenVINO™ Toolkit](https://www.intel.com/content/www/us/en/developer/tools/openvino-toolkit/overview.html)
    *   [Intel® Trust Authority](https://www.intel.com/content/www/us/en/security/trust-authority.html)
    *   [Open Source Projects](https://www.intel.com/content/www/us/en/developer/topic-technology/open/project-catalog.html)
    *   [Intel® Developer Catalog](https://www.intel.com/content/www/us/en/developer/tools/software-catalog/overview.html)

2.   Support

 Drivers & Downloads  

    *   [Auto-update your Drivers](https://www.intel.com/content/www/us/en/support/detect.html)
    *   [Download Center](https://www.intel.com/content/www/us/en/download-center/home.html)

 Support For 

    *   [Products](https://www.intel.com/content/www/us/en/support.html)
    *   [Developers](https://www.intel.com/content/www/us/en/developer/get-help/overview.html)
    *   [Suppliers](https://www.intel.com/content/www/us/en/supplier/resources/self-help/intel-corporation-support.html)

 Resources 

    *   [Support Community](https://community.intel.com/)
    *   [Warranty Information](https://supporttickets.intel.com/s/warrantyinfo?language=en_US)
    *   [Contact Support](https://www.intel.com/content/www/us/en/support/contact-us.html)

3.   Solutions

 Industries  

    *   [Automotive](https://www.intel.com/content/www/us/en/automotive/overview.html)
    *   [Education](https://www.intel.com/content/www/us/en/education/intel-education.html)
    *   [Energy](https://www.intel.com/content/www/us/en/energy/energy-overview.html)
    *   [Financial Services](https://www.intel.com/content/www/us/en/financial-services-it/financial-services-overview.html)
    *   [Government](https://www.intel.com/content/www/us/en/government/public-sector-solutions-overview.html)
    *   [Healthcare & Life Sciences](https://www.intel.com/content/www/us/en/healthcare-it/healthcare-overview.html)
    *   [Manufacturing](https://www.intel.com/content/www/us/en/manufacturing/manufacturing-industrial-overview.html)
    *   [Retail](https://www.intel.com/content/www/us/en/retail/overview.html)
    *   [Telecommunications](https://www.intel.com/content/www/us/en/telecommunications/overview.html)
    *   [View all >](https://www.intel.com/content/www/us/en/industries/overview.html)

 Topics 

    *   [AI](https://www.intel.com/content/www/us/en/artificial-intelligence/overview.html)
    *   [Security](https://www.intel.com/content/www/us/en/security/overview.html)
    *   [Sustainability](https://www.intel.com/content/www/us/en/environment/sustainability.html)
    *   [View all >](https://www.intel.com/content/www/us/en/topics/overview.html)

 Resources 

    *   [Customer Case Studies](https://www.intel.com/content/www/us/en/customer-spotlight/overview.html)

4.   Developers

[Developers Home](https://www.intel.com/content/www/us/en/developer/overview.html) 

[Development Tools](https://www.intel.com/content/www/us/en/developer/tools/overview.html)

    *   [Software Catalog](https://www.intel.com/content/www/us/en/developer/tools/software-catalog/overview.html)
    *   [Download Center](https://www.intel.com/content/www/us/en/download-center/home.html)
    *   [Design Tools and Services](https://designintools.intel.com/)
    *   [Software Registration](https://registrationcenter.intel.com/en/)

[Topics & Technologies](https://www.intel.com/content/www/us/en/developer/topic-technology/overview.html)

    *   [Artificial Intelligence](https://www.intel.com/content/www/us/en/developer/topic-technology/artificial-intelligence/overview.html)
    *   [Client](https://www.intel.com/content/www/us/en/developer/topic-technology/client/overview.html)
    *   [Cloud](https://www.intel.com/content/www/us/en/developer/topic-technology/cloud/overview.html)
    *   [Game Development](https://www.intel.com/content/www/us/en/developer/topic-technology/gamedev/overview.html)
    *   [Edge, IoT & 5G](https://www.intel.com/content/www/us/en/developer/topic-technology/edge-5g/overview.html)
    *   [High Performance Computing (HPC)](https://www.intel.com/content/www/us/en/developer/topic-technology/high-performance-computing/overview.html)

[Resources & Documentation](https://www.intel.com/content/www/us/en/resources-documentation/developer.html)

    *   [Learn](https://www.intel.com/content/www/us/en/developer/learn/overview.html)
    *   [Communities & Events](https://www.intel.com/content/www/us/en/developer/community/overview.html)
    *   [Developer Programs](https://www.intel.com/content/www/us/en/developer/programs/overview.html)
    *   [Get Help](https://www.intel.com/content/www/us/en/developer/get-help/overview.html)

5.   Partners

[Intel® Partner Alliance](https://www.intel.com/content/www/us/en/partner-alliance/overview.html)

    *   [About Membership](https://www.intel.com/content/www/us/en/partner-alliance/membership/overview.html)
    *   [Already a Member? Login](https://www.intel.com/content/www/us/en/secure/partner-alliance/overview.html)
    *   [Get Help](https://www.intel.com/content/www/us/en/partner-alliance/help/overview.html)

[Intel® Partner Showcase](https://www.intel.com/content/www/us/en/partner/showcase/overview.html)

    *   [Partner Directory](https://www.intel.com/content/www/us/en/partner/showcase/partner-directory/overview.html)
    *   [Distributor Directory](https://www.intel.com/content/www/us/en/partner/showcase/partner-directory/distributor-select-region.html)

[Retail Partner Solutions](https://www.intel.com/content/www/us/en/secure/retail/partner-solutions/overview.html)

6.   Foundry

[Intel Foundry](https://www.intel.com/content/www/us/en/foundry/overview.html)

    *   [Process Technologies](https://www.intel.com/content/www/us/en/foundry/process.html)
    *   [Advanced Packaging & Test](https://www.intel.com/content/www/us/en/foundry/packaging.html)
    *   [Manufacturing](https://www.intel.com/content/www/us/en/foundry/manufacturing.html)
    *   [Accelerator Ecosystem Alliances](https://www.intel.com/content/www/us/en/foundry/accelerator.html)
    *   [Research](https://www.intel.com/content/www/us/en/foundry/research.html)
    *   [Shuttle](https://www.intel.com/content/www/us/en/foundry/manufacturing/shuttle.html)

7.   More +     

Sign In My Intel

[](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542)

 My Tools 

*   [](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542)?

Sign Out

English

## Select Your Language

*   [Bahasa Indonesia](https://www.intel.co.id/content/www/id/id/homepage.html)
*   [Deutsch](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=de)
*   [English](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=en)
*   [Español](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=es)
*   [Français](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=fr)
*   [Português](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=pt)

*   [Tiếng Việt](https://www.intel.vn/content/www/vn/vi/homepage.html)
*   [ไทย](https://www.thailand.intel.com/content/www/th/th/homepage.html)
*   [한국어](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=ko)
*   [日本語](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=ja)
*   [简体中文](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=zh-CN)
*   [繁體中文](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542?profile.language=zh-TW)

Toggle Search

Search< Close Search Panel Advanced Search

 close 

[Sign In](javascript:void();) to access restricted content 

### Using Intel.com Search

You can easily search the entire Intel.com site in several ways.

*    Brand Name: **Core i9**
*    Document Number: **123456**
*    Code Name: **Emerald Rapids**
*    Special Operators: **“Ice Lake”, Ice AND Lake, Ice OR Lake, Ice***

### Quick Links

You can also try the quick links below to see results for most popular searches.

*   [Product Information](https://www.intel.com/content/www/us/en/products/overview.html?wapkw=quicklink:products)
*   [Support](https://www.intel.com/content/www/us/en/support.html?wapkw=quicklink:support)
*   [Drivers & Software](https://downloadcenter.intel.com/?wapkw=quicklink:download-center)

### Recent Searches

[Sign In](javascript:void();) to access restricted content 

### Advanced Search

Find results with 

Show results from 

### Only search in

- [x]  Title - [x]  Description - [x] Content ID 

 Search 

[Sign in](javascript:void();) to access restricted content. 

The browser version you are using is not recommended for this site.

Please consider upgrading to the latest version of your browser by clicking one of the following links.

*   [Safari](https://support.apple.com/downloads/safari)
*   [Chrome](https://support.google.com/chrome/answer/95346?hl=en)
*   [Edge](https://www.microsoft.com/en-us/edge)
*   [Firefox](https://www.mozilla.org/en-US/firefox/new/)

 Browse 

*   [Support Community](https://community.intel.com/)
*   [About](https://community.intel.com/t5/About/bd-p/about-communities)
*   [Developer Software Forums](https://community.intel.com/t5/Developer-Software-Forums/ct-p/developer-software-forums)

    *   [Developer Software Forums](https://community.intel.com/t5/Developer-Software-Forums/ct-p/developer-software-forums)
    *   [Software Development Tools](https://community.intel.com/t5/Software-Development-Tools/ct-p/software-dev-tools)
    *   [Toolkits & SDKs](https://community.intel.com/t5/Toolkits-SDKs/ct-p/toolkits-sdks)
    *   [Software Development Topics](https://community.intel.com/t5/Software-Development-Topics/ct-p/software-dev-topics)
    *   [Software Development Technologies](https://community.intel.com/t5/Software-Development/ct-p/software-dev-technologies)
    *   [GPU Compute Software](https://community.intel.com/t5/GPU-Compute-Software/bd-p/gpu-compute-software)
    *   [Software Archive](https://community.intel.com/t5/Software-Archive/bd-p/software-archive)
    *   [Edge Software Catalog](https://community.intel.com/t5/Edge-Software-Catalog/bd-p/EdgeSoftwareCatalog)

*   [Product Support Forums](https://community.intel.com/t5/Product-Support-Forums/ct-p/product-support-forums)

    *   [Product Support Forums](https://community.intel.com/t5/Product-Support-Forums/ct-p/product-support-forums)
    *   [Memory & Storage](https://community.intel.com/t5/Memory-Storage/ct-p/memory-storage)
    *   [Visual Computing](https://community.intel.com/t5/Visual-Computing/ct-p/visual-computing)
    *   [Embedded Products](https://community.intel.com/t5/Embedded-Products/ct-p/embedded-products)
    *   [Graphics](https://community.intel.com/t5/Graphics/bd-p/graphics)
    *   [Mobile and Desktop Processors](https://community.intel.com/t5/Mobile-and-Desktop-Processors/bd-p/processors)
    *   [Intel® Xeon® Processor and Server Products](https://community.intel.com/t5/Intel-Xeon-Processor-and-Server/bd-p/server-products)
    *   [Wireless](https://community.intel.com/t5/Wireless/bd-p/wireless)
    *   [Ethernet Products](https://community.intel.com/t5/Ethernet-Products/bd-p/ethernet-products)
    *   [Intel vPro® Platform](https://community.intel.com/t5/Intel-vPro-Platform/bd-p/vpro-platform)
    *   [Intel® QuickAssist Technology (Intel® QAT)](https://community.intel.com/t5/Intel-QuickAssist-Technology/bd-p/IntelQuickAssistTechnology)
    *   [Intel® Trusted Execution Technology (Intel® TXT)](https://community.intel.com/t5/Intel-Trusted-Execution/bd-p/trusted-execution-technology)
    *   [Thunderbolt™ Share](https://community.intel.com/t5/Thunderbolt-Share/bd-p/ThunderboltShare)
    *   [Intel® Gaudi® AI Accelerator](https://community.intel.com/t5/Intel-Gaudi-AI-Accelerator/bd-p/IntelGaudiAIAccelerator)

*   [Gaming Forums](https://community.intel.com/t5/Gaming-Forums/ct-p/gaming-community)

    *   [Gaming Forums](https://community.intel.com/t5/Gaming-Forums/ct-p/gaming-community)
    *   [Intel® Arc™ Discrete Graphics](https://community.intel.com/t5/Intel-Arc-Discrete-Graphics/bd-p/arc-graphics)
    *   [Gaming on Intel® Processors with Intel® Graphics](https://community.intel.com/t5/Gaming-on-Intel-Processors-with/bd-p/processors-with-intel-graphics)
    *   [Developing Games on Intel Graphics](https://community.intel.com/t5/Developing-Games-on-Intel/bd-p/developing-games-graphics)

*   [Blogs](https://community.intel.com/t5/Blogs/ct-p/blogs)

    *   [Blogs](https://community.intel.com/t5/Blogs/ct-p/blogs)
    *   [@Intel](https://community.intel.com/t5/Intel/ct-p/intel)
    *   [Products and Solutions](https://community.intel.com/t5/Products-and-Solutions/ct-p/products-solutions)
    *   [Tech Innovation](https://community.intel.com/t5/Tech-Innovation/ct-p/tech-innovation)
    *   [Thought Leadership](https://community.intel.com/t5/Thought-Leadership/ct-p/thought-leadership)
    *   [Intel Foundry](https://community.intel.com/t5/Intel-Foundry/ct-p/IntelFoundry)

*   [Private Forums](https://community.intel.com/t5/Private-Forums/ct-p/private-forums)

    *   [Private Forums](https://community.intel.com/t5/Private-Forums/ct-p/private-forums)
    *   [Intel oneAPI Toolkits Private Forums](https://community.intel.com/t5/Intel-oneAPI-Toolkits-Private/ct-p/oneapi-toolkits-private-forums)
    *   [Intel AI Software - Private Forums](https://community.intel.com/t5/Intel-AI-Software-Private-Forums/ct-p/IntelAISoftwarePrivateForums)
    *   [Intel® Connectivity Research Program (Private)](https://community.intel.com/t5/Intel-Connectivity-Research/cmp-p/grouphub%3Aconnectivity-research-program)
    *   [Intel-Habana Gaudi Technology Forum](https://community.intel.com/t5/Intel-Habana-Gaudi-Technology/cmp-p/grouphub%3Aintel-habana-gaudi-technology-forum)
    *   [HARP (Private Forum)](https://community.intel.com/t5/HARP-Private-Forum/cmp-p/grouphub%3Aharp)

[](https://community.intel.com/t5/help/faqpage)

 Client 

 Interact with Intel® product support specialists on client concerns and recommendations 

Success! Subscription added.

Success! Subscription removed.

Sorry, you must verify to complete this action. Please click the verification link in your email. You may re-send via your [profile](https://community.intel.com/t5/user/myprofilepage/tab/personal-profile:email).

*   [Intel Community](https://community.intel.com/)

*   [Blogs](https://community.intel.com/t5/Blogs/ct-p/blogs)

*   [Tech Innovation](https://community.intel.com/t5/Tech-Innovation/ct-p/tech-innovation)

*   [Client](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/bg-p/blog-client)

*   WebAssembly + Zephyr: A Two-Layer Isolation Model for Embedded Systems

54 Discussions

# WebAssembly + Zephyr: A Two-Layer Isolation Model for Embedded Systems

[Subscribe](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542)

[Article Options](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542# "Show option menu")

*   [Subscribe to RSS Feed](https://community.intel.com/cipcp26785/rss/message?board.id=blog-client&message.id=171)

*   Mark as New
*   Mark as Read

*   Bookmark
*   Subscribe

*   [Printer Friendly Page](https://community.intel.com/t5/blogs/blogarticleprintpage/blog-id/blog-client/article-id/171)
*   [Report Inappropriate Content](https://community.intel.com/t5/notifications/notifymoderatorpage/message-uid/1754542)

![Image 2: WebAssembly + Zephyr: A Two-Layer Isolation Model for Embedded Systems](https://community.intel.com/t5/image/serverpage/image-id/73450i8CFBB382CB6EEE2B/image-size/large?v=v2&px=999&whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright)

![Image 3: Belem](https://community.intel.com/t5/image/serverpage/avatar-name/intelgreeninverse-11/avatar-theme/candy/avatar-collection/Intel_Customer/avatar-display-size/message/version/2?xdesc=1.0)

[Belem](https://community.intel.com/t5/user/viewprofilepage/user-id/133071)

 Employee 

‎07-22-2026 01:50 AM

1 0 266

## Why Combine Zephyr with WebAssembly?

Embedded devices often face a difficult trade-off. The core firmware must remain stable, while application logic may need to change more frequently.

Combining Zephyr User Mode with WebAssembly provides a lightweight way to add flexible application logic without exposing the core system to unnecessary risk. Together, they enable a practical architecture that separates platform firmware from updateable application logic.

### Zephyr User Mode

Zephyr User Mode provides hardware-backed isolation between application code and the operating system.

User code runs with restricted access to memory and kernel resources. User threads can only access authorized memory regions and approved kernel services. If a user thread performs an illegal memory access, the fault can be contained without bringing down the entire system.

For a WebAssembly-based design, this means the WebAssembly runtime itself can execute inside a Zephyr user thread, creating a protection boundary between the runtime and the rest of the system.

### WebAssembly

WebAssembly is a portable binary format designed for safe and efficient execution.

A Wasm module executes inside a sandbox with its own linear memory and cannot directly access host memory. Interaction with the surrounding system occurs only through explicitly exposed host functions.

These characteristics make WebAssembly a good fit for application logic that is:

*   Frequently updated
*   Developed by multiple teams
*   Less trusted than core firmware
*   Shared across multiple products

By separating application logic from platform-specific firmware, WebAssembly allows business logic to evolve independently of the underlying system.

### WAMR

WebAssembly modules do not run directly on Zephyr. They require a runtime responsible for loading modules, managing execution, validating memory accesses, and providing host-function support.

**WebAssembly Micro Runtime (WAMR)** is a lightweight WebAssembly runtime designed for resource-constrained systems. WAMR is widely used in embedded environments and provides integration support for Zephyr.

WAMR performs the core runtime functions required to execute Wasm modules while maintaining the sandbox boundary that separates module code from native firmware.

In a typical deployment, WAMR loads and executes Wasm modules, validates accesses to module memory, and enforces the interface between Wasm code and native firmware through host APIs.

### A Two-Layer Isolation Model

Together, Zephyr User Mode and WAMR create a two-layer isolation model:

*   **Zephyr User Mode** isolates the runtime thread from the rest of the system.
*   The **WAMR sandbox** isolates Wasm modules running inside that thread.

![Image 4: figure1_0.8.png](https://community.intel.com/t5/image/serverpage/image-id/73446iD1EDFB03EF25520A/image-size/large?v=v2&px=999&whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright)

### Application Logic Is Decoupled from Firmware

Business logic can be packaged as Wasm modules. The firmware only needs to expose a stable set of host APIs, allowing application logic to evolve independently from the core firmware.

This separation reduces coupling between application development and firmware release cycles. It also makes it easier to customize products without modifying platform code.

### Runtime and System Isolation

The WAMR sandbox does not allow a Wasm module to invoke arbitrary Zephyr services directly.

Instead, all interactions with the operating system must pass through explicitly exposed host APIs implemented by native firmware. This host API boundary limits the set of system capabilities that a module can access and provides a clear interface between Wasm code and the underlying platform.

Host functions execute within the WAMR runtime thread and remain subject to Zephyr User Mode restrictions. Access to kernel services continues to follow Zephyr's userspace model. Operations on kernel objects are performed through system calls, and a user thread may access only those kernel objects for which permission has been explicitly granted.

As a result, even when a Wasm module invokes a host API, access to system resources is still controlled by Zephyr's userspace protection mechanisms. A module cannot bypass the host API boundary, and the runtime thread cannot access kernel objects or privileged resources that have not been authorized.

#### Memory Isolation

The Wasm sandbox is built on top of memory already assigned to the user-mode runtime thread.

A Wasm module executes within its own linear memory, while the WAMR runtime executes within memory regions that belong to the runtime thread's memory domain. The module cannot directly reference native addresses or arbitrary memory owned by the system.

When the runtime accesses module memory, it does so through validated offsets within the module's linear memory rather than through unrestricted native pointers. This ensures that module memory accesses remain confined to the sandbox.

At the next level, Zephyr User Mode restricts the runtime thread itself to the memory partitions assigned to its memory domain. Any native access outside the authorized memory domain is blocked by the underlying MPU or MMU and handled by Zephyr's userspace protection mechanisms.

Together, the linear-memory sandbox and the user-mode memory domain create a layered memory-isolation model that protects both the runtime and the rest of the system.

#### Fault Containment

Faults are isolated at multiple levels.

Within the WAMR sandbox, modules execute inside their own linear memory. Invalid memory accesses, runtime exceptions, and other module-level faults can be detected and contained by the runtime. Interaction with the host occurs only through explicitly exposed host APIs.

If a fault occurs in native code running inside the user-mode runtime thread, Zephyr User Mode provides an additional layer of protection by restricting access to authorized memory and kernel resources.

Together, these mechanisms help prevent application-level failures from affecting the kernel or unrelated system components.

## WebAssembly vs. Zephyr Loadable Extensions

A natural question is:

Why use WebAssembly instead of Zephyr’s own loadable extension mechanism?

Zephyr supports **Loadable Extensions (LLEXT)**, which allow native code to be loaded into a running system. Both LLEXT and WebAssembly provide a way to extend functionality without rebuilding the entire firmware, but they target different requirements.

![Image 5: figure2_0.5.png](https://community.intel.com/t5/image/serverpage/image-id/73447iD90210F098BB532A/image-size/large?v=v2&px=999&whitelist-exif-data=Orientation%2CResolution%2COriginalDefaultFinalSize%2CCopyright)

### Zephyr Loadable Extensions

LLEXT executes native code.

Because extensions run directly on the target system, they can deliver near-native performance and integrate closely with Zephyr services.

However, they are tied to a specific architecture and system configuration, and software defects can have a broader impact on the system.

### WebAssembly

WebAssembly executes inside a runtime sandbox.

Instead of directly accessing system resources, modules interact with the system through approved host APIs exposed by the firmware. This introduces some runtime overhead, but it also provides stronger isolation and a portable module format.

### Choosing Between Them

**Requirement****Better Fit**
Maximum performance LLEXT or native firmware
Strong isolation WebAssembly
Untrusted code WebAssembly
Frequent logic updates WebAssembly
Hard real-time code LLEXT or native firmware

In short, LLEXT is often the better choice when the code is trusted and maximum performance is required.

WebAssembly is often the better choice when isolation, portability, and independent updates are the primary goals.

The two approaches are not mutually exclusive. A system can use native code for low-level and time-critical functionality while using WebAssembly for higher-level application logic that benefits from stronger isolation.

## Conclusion

WebAssembly is most valuable when application logic needs to be updated independently, developed by different teams, or isolated from the core firmware.

Combined with Zephyr User Mode and a lightweight runtime such as WAMR, it provides a practical balance between flexibility and fault isolation for embedded systems. The runtime executes inside a user-mode thread, while Wasm modules execute inside the runtime sandbox, creating a layered defense against software faults.

The approach comes with costs. Running a Wasm runtime requires additional code space, memory, and execution overhead compared to native execution. Runtime memory, module instances, execution stacks, and Wasm linear memory must all be considered during system design.

WebAssembly is therefore best suited to application logic that benefits from isolation and independent updates rather than hard real-time or hardware-facing functionality.

A useful rule is:

*   Keep time-critical and hardware-facing code native.
*   Put updateable, less trusted, or product-specific logic in Wasm.

This approach is not a replacement for native firmware. Device drivers, interrupt handlers, and hard real-time control loops should remain native.

For embedded systems that need both flexibility and reliability, the combination of Zephyr User Mode, WAMR, and WebAssembly offers a useful middle ground: more dynamic than fixed firmware, safer than unrestricted native plugins, and practical on resource-constrained devices.

[1 Kudo](https://community.intel.com/t5/kudos/messagepage/board-id/blog-client/message-id/171/tab/all-users "Click here to see who gave kudos to this post.")

[](https://community.intel.com/t5/blogs/v2/blogarticlepage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/1754542?t:ac=blog-id/blog-client/article-id/171&t:cp=kudos/contributions/tapletcontributionspage "Click here to give kudos to this post.")

[](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542)

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

*   [Comment](https://community.intel.com/plugins/common/feature/samlss/doauth/post?lang=en&redirectreason=permissiondenied&referer=https%3A%2F%2Fcommunity.intel.com%2Ft5%2FBlogs%2FTech-Innovation%2FClient%2FWebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded%2Fpost%2F1754542%23comment-on-this)

[Top](https://community.intel.com/t5/Blogs/Tech-Innovation/Client/WebAssembly-Zephyr-A-Two-Layer-Isolation-Model-for-Embedded/post/1754542)

**Community support is provided Monday to Friday. Other contact methods are available [here](https://www.intel.com/content/www/us/en/support/contact-us.html).**

Intel does not verify all solutions, including but not limited to any file transfers that may appear in this community. Accordingly, Intel disclaims all express and implied warranties, including without limitation, the implied warranties of merchantability, fitness for a particular purpose, and non-infringement, as well as any warranty arising from course of performance, course of dealing, or usage in trade.

*   [Company Overview](https://www.intel.com/content/www/us/en/company-overview/company-overview.html)
*   [Contact Intel](https://www.intel.com/content/www/us/en/support/contact-us.html)
*   [Newsroom](https://newsroom.intel.com/)
*   [Investors](https://www.intc.com/)
*   [Careers](https://www.intel.com/content/www/us/en/jobs/life-at-intel.html)
*   [Corporate Responsibility](https://www.intel.com/content/www/us/en/corporate-responsibility/corporate-responsibility.html)
*   [Inclusion](https://www.intel.com/content/www/us/en/inclusion/inclusion-at-intel.html)
*   [Public Policy](https://www.intel.com/content/www/us/en/company-overview/public-policy.html)

*   [](https://www.facebook.com/Intel)
*   [](https://twitter.com/intel)
*   [](https://www.linkedin.com/company/intel-corporation)
*   [](https://www.youtube.com/user/channelintel?sub_confirmation=1)
*   [](https://www.instagram.com/intel/)

*   © Intel Corporation
*   [Terms of Use](https://www.intel.com/content/www/us/en/legal/terms-of-use.html)
*   [*Trademarks](https://www.intel.com/content/www/us/en/legal/trademarks.html)
*   [Cookies](https://www.intel.com/content/www/us/en/privacy/intel-cookie-notice.html)
*   [Privacy](https://www.intel.com/content/www/us/en/privacy/intel-privacy-notice.html)
*   [Supply Chain Transparency](https://www.intel.com/content/www/us/en/corporate-responsibility/statement-combating-modern-slavery.html)
*   [Site Map](https://www.intel.com/content/www/us/en/siteindex.html)
*   [Recycling](https://www.intel.com/content/www/us/en/support/articles/000098122/services.html)
*   [Your Privacy Choices](https://community.intel.com/#)
*   [Notice at Collection](https://www.intel.com/content/www/us/en/privacy/privacy-residents-certain-states.html)

Intel technologies may require enabled hardware, software or service activation. // No product or component can be absolutely secure. // Your costs and results may vary. //Performance varies by use, configuration, and other factors. Learn more at [intel.com/performanceindex](https://edc.intel.com/content/www/us/en/products/performance/benchmarks/overview/). // See our complete legal [Notices and Disclaimers](https://edc.intel.com/content/www/us/en/products/performance/benchmarks/overview/#GUID-26B0C71C-25E9-477D-9007-52FCA56EE18C). //Intel is committed to respecting human rights and avoiding causing or contributing to adverse impacts on human rights. See Intel’s [Global Human Rights Principles](https://www.intel.com/content/www/us/en/policy/policy-human-rights.html). Intel’s products and software are intended only to be used in applications that do not cause or contribute to adverse impacts on human rights.

[![Image 6: Intel Footer Logo](https://www.intel.com/content/dam/logos/intel-footer-logo.svg)](https://www.intel.com/content/www/us/en/homepage.html "Intel Footer Logo")

![Image 7: Company Logo](https://cdn.cookielaw.org/logos/215b83c1-e050-4276-906c-e65481a36156/3d79bec9-e414-4424-8212-f86375d1bced/916d880d-81ed-4f4e-88bd-83aeaf6af358/logo-classicblue-3000px-OneTrust.png)

## Manage Cookies Settings

## Manage Cookies Settings

*   ### Information We Collect 
*   ### Strictly Necessary Cookies 
*   ### Analytics 
*   ### Functional 
*   ### Ad Targeting 
*   ### Data Transfer 
*   ### Data Sharing 

#### Information We Collect

Intel values your privacy. Our Sites use Cookies and Similar Technologies on this website to improve your online experience, to analyze site usage, and to show tailored advertising to you. This consent management tool will help you understand what information is being collected and give you control over how it is being used. 

**Information Our Partners Collect**

 Details of the vendors that we use to improve your overall web browsing experience are provided in the tool. They use Cookies and Similar Technologies to connect you with your social networks and tailor advertising to better match your interests. 

**Your Choices**

 You can manage your cookie settings by visiting the Analytics, Functional, and Ad Targeting tabs on the left. 

[Intel Privacy Notice](https://www.intel.com/content/www/us/en/privacy/intel-privacy-notice.html)

[Intel Cookie Notice](https://www.intel.com/content/www/us/en/privacy/intel-cookie-notice.html)

#### Strictly Necessary Cookies

Always Active

These technologies are necessary for the Intel experience to function and cannot be switched off in our systems. The technology is usually only set in response to actions made by the device owner which amount to a request for services, such as setting privacy preferences, logging in, filling in forms, maintaining secure login areas, maintaining state across pages (remembering items in a shopping basket), and server load balancing. The device owner can set their preference to block or alert Intel about these technologies, but some parts of the Intel experience will not work. These technologies do not store any personally identifiable information.

Cookies Details

#### Analytics

- [x] Analytics Active

These technologies allow Intel to count device visits and traffic sources, so Intel can measure and improve the performance of our experiences. The technology helps Intel to know which experiences are the most and least popular and see how device owners interact with the experience. All information these technologies collect is aggregated. If the device owner does not allow these technologies, then Intel will not know when the device owner visited or how the device owner interacted with our experiences.

Cookies Details

#### Functional

- [x] Functional Active

These technologies enable the Intel experience to provide enhanced functionality and personalization. The technology may be set by Intel or by third-party providers whose services Intel have added to our experiences. If the device owner does not allow these technologies, then some or all of these services may not function properly for the device owner.

Cookies Details

#### Ad Targeting and sharing choices

- [x] Ad Targeting and sharing choices Active

Inactive/Active

**Inactive** means Intel will not collect and Share my device information for Ad Targeting uses.

**Active** means Intel may collect and Share my device information for Ad Targeting uses.

If you visit an Intel Site or service using a device with a United States IP address and a privacy-preference signal enabled (e.g., [Do Not Track](http://www.allaboutdnt.com/), [Global Privacy Control](https://globalprivacycontrol.org/)), Intel will not collect device information for the purpose of Ad Targeting uses.

If you visit an Intel Site or service using a device with a United States IP address, you have not enabled a privacy-preference signal, and your Ad Targeting and Sharing Choices are set to Active, Intel may collect device information for the purpose of Ad Targeting uses.

If you have more than one device, you will need to configure all devices with your privacy-preferences.

These technologies may be set through our Intel experience or by our advertising partners. The technology may be used to build a profile of the device owner’s interests and show the device owner relevant advertisements on other experiences. The technology does not store directly personal information on the device, but the technology is based on uniquely identifying the device. If the device owner does not allow these technologies, then the device owner will experience less targeted advertising.

Cookies Details

#### Data Transfer

- [x] Data Transfer Inactive

You consent to allowing Intel to transfer your personal information outside of China for processing based upon Intel's [Privacy](https://community.intel.com/content/www/cn/zh/privacy/intel-privacy-notice.html) and [Cookies](https://community.intel.com/content/www/cn/zh/privacy/intel-cookie-notice.html) notices as well as the [Intel Privacy Notice Supplement for Users in China](https://www.intel.com/content/dam/www/public/cn/zh/documents/corporate-information/china-supplement-to-global-privacy-notice.pdf).

Cookies Details

#### Data Sharing

- [x] Data Sharing Inactive

You consent to Intel sharing your personal information with Intel's affiliates, Intel's partners, and Intel-authorized third-party personal information processors.

Cookies Details

### Cookie List

Consent Leg.Interest

- [x] checkbox label label

- [x] checkbox label label

- [x] checkbox label label

Clear
*   - [x] checkbox label label 

Apply Cancel

Confirm My Choices

All Inactive All Active

[![Image 8: Powered by Onetrust](https://cdn.cookielaw.org/logos/static/powered_by_logo.svg)](https://www.onetrust.com/solutions/consent-and-preferences/?utm_source=cmp&utm_medium=cmpbanner)
