The specification-based testing of a trusted kernel: MK++ | IEEE Conference Publication | IEEE Xplore