Correctness by construction: developing a commercial secure system
IEEE Software
A. Hall
The affordable application of formal methods to software engineering