1Bruijn, N.G. De, ‘Lambda calculus notation with nameless dummies, a tool for automatic formula manipulation, with application to the Church-Rosser theorem’, Indag. Math. 34 (1972) 381–392.
2Davey, B.A. and Priestley, H.A., Introduction to lattices and order (Cambridge University Press, 1990).
3Feferman, S. et al. , eds, Kurt Gödel: collected works, vol. II. (Oxford University Press, 1990).
4Gödel, Kurt, ‘The consistency of the axiom of choice and of the generalized continuum hypothesis’,  26–27; first published in Proc. Nat. Acad. Sci. USA (1938) 556–557.
5Gödel, Kurt, ‘The consistency of the axiom of choice and of the generalized continuum hypothesis with the axioms of set theory’,  33–101; first published by Princeton University Press, 1940.
6Gödel, Kurt, ‘Consistency proof for the generalized continuum hypothesis’,  27–32; first published in Proc. Nat. Acad. Sci. USA (1939) 220–224.
7Halmos, Paul R., Naive set theory (Van Nostrand, 1960).
8Kammüller, Florian, Wenzel, Markus and Paulson, Lawrence C. ‘Locales: a sectioning concept for Isabelle’, Theorem proving in higher order logics: TPHOLs '99, Lecture Notes in Comput. Sci. 1690 (ed. Bertot, Yves, Dowek, Gilles, Hirschowitz, André, Paulin, Christine and Théry, Laurent, Springer, 1999) 149–165.
9Kunen, Kenneth, Set theory: an introduction to independence proofs (North-Holland, 1980).
10Mendelson, E., Introduction to mathematical logic, 4th edn (Chapman and Hall, 1997).
11Nipkow, Tobias, Paulson, Lawrence C. and Wenzel, Markus, Isabelle⁄HOL: a proof assistant for higher-order logic, Lecture Notes in Comput. Sci. Tutorial 2283 (Springer, 2002).
12Paulson, Lawrence C., ‘The foundation of a generic theorem prover‘, J. Automat. Reasoning 5 (1989) 363–397.
13Paulson, Lawrence C., ‘Set theory for verification: I. From foundations to functions‘, J. Automat. Reasoning 11 (1993) 353–389.
14Paulson, Lawrence C., Isabelle: a generic theorem prover, Lecture Notes in Comput. Sci. 828 (Springer, 1994).
15Paulson, Lawrence C., ‘Set theory for verification: II. Induction and recursion’ J. Automat. Reasoning 15 (1995) 167–215.
16Paulson, Lawrence C., ‘Proving properties of security protocols by induction‘, 10th Computer Security Foundations Workshop (IEEE Computer Society Press, 1997) 70–83.
17Paulson, Lawrence C., ‘A fixedpoint approach to (co)inductive and (co)datatype definitions’, Proof, language, and interaction: essays in honor of Robin Milner (ed. Plotkin, Gordon, Stirling, Colin, and Tofte, Mads, MIT Press, 2000) 187–211.
18Paulson, Lawrence C., ‘The reflection theorem: a study in meta-theoretic reasoning’,  377–391.
19Paulson, Lawrence C. and Grąbczewski, Krzysztof, ‘Mechanizing set theory:cardinal arithmetic and the axiom of choice’, J. Automat. Reasoning 17 (1996) 291–323.
20Prawitz, Dag, ‘Ideas and results in proof theory‘, Second Scandinavian Logic Symposium (ed. Fenstad, J.E., North-Holland, 1971) 235’308.
21Strecker, Martin, ‘Formal verification of a Java compiler in Isabelle’,  63–77.
22Voronkov, Andrei, ed. Automated deduction – CADE-18 International Conference, Lecture Notes in Artificial Intelligence 2392 (Springer, 2002).