Tock Embedded Operating System
Security critical devices
Security critical devices, like TPMs and USB authentication fobs, are
actually multiprogramming environments running applications written by
different people. Tock guarantees that untrusted components can’t leak
secrets even if they are buggy or crash....
Read more at tockos.org