Verified seL4 on secure RISC-V processors

Prevention of Microarchitectural Covert Channels on an Open-Source 64-bit RISC-V Core

Time Protection: The Missing OS Abstraction

Time protection: The missing OS abstraction

The Jury Is In: Monolithic OS Design Is Flawed

Formal Semantics for C++ (2007)

Complx: A Verification Framework for Concurrent, Imperative Programs (2017)

L4 microkernels: The lessons from 20 years of research and deployment

Rust as a language for high performance GC implementation