Correctness by construction: developing a commercial secure system
IEEE Software
R. Chapman
The affordable application of formal methods to software engineering