Specifying and building a formal secure Virtual Monitor Machine prototype | IEEE Conference Publication | IEEE Xplore