Refinement-Based Specification and Security Analysis of Separation Kernels | IEEE Journals & Magazine | IEEE Xplore