Return to Article Details Proof-Oriented Design of a Separation Kernel with Minimal Trusted Computing Base Download Download PDF