Q Tong, JC Guo, D Xiao, LM Yin, MY Zhu - researchgate.net
… methods to verify that the system satisfies the security invariants required by the specifications.
… ExpressOS is a new OS architecture that provides formally verified security invariants to …