> I would like to have a "container" for each instance of an untrusted application.

You might like to look at Bromium (bromium.com), founded by a bunch of ex-Xen folks. I think they were doing something like this for the enterprise.

