Formal construction of provably secure systems with Cartesiana | IEEE Conference Publication | IEEE Xplore