Applying Formal Methods to a Certifiably Secure Software System | IEEE Journals & Magazine | IEEE Xplore