Proving Memory Separation in a Microkernel by Code Level Verification | IEEE Conference Publication | IEEE Xplore