Formalizing Correct-by-Construction Casper in Coq | IEEE Conference Publication | IEEE Xplore