1. Amani , S. , Hixon , A. , Chen , Z. , Rizkallah , C. , Chubb , P. , O'Connor , L. , Beeren , J. , Nagashima , Y. , Lim , J. , Sewell , T. , Tuong , J. , Keller , G. , Murray , T. , Klein , G. , and Heiser , G. Cogent : Verifying high-assurance file system implementations. SIGPLAN Not. 51 , 4 (mar 2016), 175 -- 188 . Amani, S., Hixon, A., Chen, Z., Rizkallah, C., Chubb, P., O'Connor, L., Beeren, J., Nagashima, Y., Lim, J., Sewell, T., Tuong, J., Keller, G., Murray, T., Klein, G., and Heiser, G. Cogent: Verifying high-assurance file system implementations. SIGPLAN Not. 51, 4 (mar 2016), 175--188.
2. Arpaci-Dusseau , R. H. , and Arpaci-Dusseau , A. C. Operating Systems: Three Easy Pieces . Arpaci-Dusseau Books , 2018 . Arpaci-Dusseau, R. H., and Arpaci-Dusseau, A. C. Operating Systems: Three Easy Pieces. Arpaci-Dusseau Books, 2018.
3. Athalye , A. , Belay , A. , Kaashoek , M. F. , Morris , R. , and Zeldovich , N . Notary: A device for secure transaction approval . In Proceedings of the 27th ACM Symposium on Operating Systems Principles (SOSP 2019) (Hunstville, ON, Canada , Oct. 2019 ). Athalye, A., Belay, A., Kaashoek, M. F., Morris, R., and Zeldovich, N. Notary: A device for secure transaction approval. In Proceedings of the 27th ACM Symposium on Operating Systems Principles (SOSP 2019) (Hunstville, ON, Canada, Oct. 2019).
4. Baumann , A. , Barham , P. , Dagand , P.-E. , Harris , T. , Isaacs , R. , Peter , S. , Roscoe , T. , Schüpbach , A. , and Singhania , A . The multikernel: A new os architecture for scalable multicore systems . In Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles (New York, NY, USA, 2009), SOSP '09, Association for Computing Machinery , p. 29 -- 44 . Baumann, A., Barham, P., Dagand, P.-E., Harris, T., Isaacs, R., Peter, S., Roscoe, T., Schüpbach, A., and Singhania, A. The multikernel: A new os architecture for scalable multicore systems. In Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles (New York, NY, USA, 2009), SOSP '09, Association for Computing Machinery, p. 29--44.
5. Beringer , L. , Petcher , A. , Ye , K. Q. , and Appel , A. W . Verified correctness and security of openssl hmac . In Proceedings of the 24th USENIX Conference on Security Symposium (USA, 2015), SEC'15, USENIX Association , p. 207 -- 221 . Beringer, L., Petcher, A., Ye, K. Q., and Appel, A. W. Verified correctness and security of openssl hmac. In Proceedings of the 24th USENIX Conference on Security Symposium (USA, 2015), SEC'15, USENIX Association, p. 207--221.