Visible to the public Verifying a Separation Kernel for a Cryptographic Device: A Status Report