src/HOL/Predicate_Compile_Examples/Hotel_Example.thy
author blanchet
Thu, 10 Oct 2013 08:23:57 +0200
changeset 54096 8ab8794410cd
parent 53015 a1119cf551e8
child 58249 180f1b3508ed
permissions -rw-r--r--
repaired confusion between the stated and effective fact filter -- the mismatch could result in "Match" exceptions
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     1
theory Hotel_Example
40104
82873a6f2b81 splitting Hotel Key card example into specification and the two tests for counter example generation
bulwahn
parents: 39799
diff changeset
     2
imports Main
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     3
begin
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     4
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     5
datatype guest = Guest0 | Guest1
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     6
datatype key = Key0 | Key1 | Key2 | Key3
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     7
datatype room = Room0
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     8
42463
f270e3e18be5 modernized specifications;
wenzelm
parents: 40104
diff changeset
     9
type_synonym card = "key * key"
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    10
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    11
datatype event =
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    12
   Check_in guest room card | Enter guest room card | Exit guest room
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    13
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    14
definition initk :: "room \<Rightarrow> key"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    15
  where "initk = (%r. Key0)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    16
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    17
declare initk_def[code_pred_def, code]
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    18
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    19
primrec owns :: "event list \<Rightarrow> room \<Rightarrow> guest option"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    20
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    21
  "owns [] r = None"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    22
| "owns (e#s) r = (case e of
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    23
    Check_in g r' c \<Rightarrow> if r' = r then Some g else owns s r |
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    24
    Enter g r' c \<Rightarrow> owns s r |
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    25
    Exit g r' \<Rightarrow> owns s r)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    26
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    27
primrec currk :: "event list \<Rightarrow> room \<Rightarrow> key"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    28
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    29
  "currk [] r = initk r"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    30
| "currk (e#s) r = (let k = currk s r in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    31
    case e of Check_in g r' (k1, k2) \<Rightarrow> if r' = r then k2 else k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    32
            | Enter g r' c \<Rightarrow> k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    33
            | Exit g r \<Rightarrow> k)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    34
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    35
primrec issued :: "event list \<Rightarrow> key set"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    36
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    37
  "issued [] = range initk"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    38
| "issued (e#s) = issued s \<union>
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    39
  (case e of Check_in g r (k1, k2) \<Rightarrow> {k2} | Enter g r c \<Rightarrow> {} | Exit g r \<Rightarrow> {})"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    40
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    41
primrec cards :: "event list \<Rightarrow> guest \<Rightarrow> card set"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    42
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    43
  "cards [] g = {}"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    44
| "cards (e#s) g = (let C = cards s g in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    45
                    case e of Check_in g' r c \<Rightarrow> if g' = g then insert c C
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    46
                                                else C
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    47
                            | Enter g r c \<Rightarrow> C
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    48
                            | Exit g r \<Rightarrow> C)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    49
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    50
primrec roomk :: "event list \<Rightarrow> room \<Rightarrow> key"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    51
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    52
  "roomk [] r = initk r"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    53
| "roomk (e#s) r = (let k = roomk s r in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    54
    case e of Check_in g r' c \<Rightarrow> k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    55
            | Enter g r' (x,y) \<Rightarrow> if r' = r (*& x = k*) then y else k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    56
            | Exit g r \<Rightarrow> k)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    57
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    58
primrec isin :: "event list \<Rightarrow> room \<Rightarrow> guest set"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    59
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    60
  "isin [] r = {}"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    61
| "isin (e#s) r = (let G = isin s r in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    62
                 case e of Check_in g r c \<Rightarrow> G
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    63
                 | Enter g r' c \<Rightarrow> if r' = r then {g} \<union> G else G
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    64
                 | Exit g r' \<Rightarrow> if r'=r then G - {g} else G)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    65
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    66
primrec hotel :: "event list \<Rightarrow> bool"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    67
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    68
  "hotel []  = True"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    69
| "hotel (e # s) = (hotel s & (case e of
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    70
  Check_in g r (k,k') \<Rightarrow> k = currk s r \<and> k' \<notin> issued s |
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    71
  Enter g r (k,k') \<Rightarrow> (k,k') : cards s g & (roomk s r : {k, k'}) |
38734
e5508a74b11f changing hotel trace definition; adding simple handling of numerals on natural numbers
bulwahn
parents: 38733
diff changeset
    72
  Exit g r \<Rightarrow> g : isin s r))"
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    73
38953
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
    74
definition no_Check_in :: "event list \<Rightarrow> room \<Rightarrow> bool" where(*>*)
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
    75
[code del]: "no_Check_in s r \<equiv> \<not>(\<exists>g c. Check_in g r c \<in> set s)"
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
    76
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
    77
definition feels_safe :: "event list \<Rightarrow> room \<Rightarrow> bool"
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
    78
where
53015
a1119cf551e8 standardized symbols via "isabelle update_sub_sup", excluding src/Pure and src/Tools/WWW_Find;
wenzelm
parents: 42463
diff changeset
    79
  "feels_safe s r = (\<exists>s\<^sub>1 s\<^sub>2 s\<^sub>3 g c c'.
a1119cf551e8 standardized symbols via "isabelle update_sub_sup", excluding src/Pure and src/Tools/WWW_Find;
wenzelm
parents: 42463
diff changeset
    80
   s = s\<^sub>3 @ [Enter g r c] @ s\<^sub>2 @ [Check_in g r c'] @ s\<^sub>1 \<and>
a1119cf551e8 standardized symbols via "isabelle update_sub_sup", excluding src/Pure and src/Tools/WWW_Find;
wenzelm
parents: 42463
diff changeset
    81
   no_Check_in (s\<^sub>3 @ s\<^sub>2) r \<and> isin (s\<^sub>2 @ [Check_in g r c] @ s\<^sub>1) r = {})"
38953
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
    82
39799
fdbea66eae4b finding the counterexample with different options (manually limited precisely, manually limited global, automatically limited global)
bulwahn
parents: 39463
diff changeset
    83
40104
82873a6f2b81 splitting Hotel Key card example into specification and the two tests for counter example generation
bulwahn
parents: 39799
diff changeset
    84
section {* Some setup *}
39799
fdbea66eae4b finding the counterexample with different options (manually limited precisely, manually limited global, automatically limited global)
bulwahn
parents: 39463
diff changeset
    85
40104
82873a6f2b81 splitting Hotel Key card example into specification and the two tests for counter example generation
bulwahn
parents: 39799
diff changeset
    86
lemma issued_nil: "issued [] = {Key0}"
82873a6f2b81 splitting Hotel Key card example into specification and the two tests for counter example generation
bulwahn
parents: 39799
diff changeset
    87
by (auto simp add: initk_def)
39799
fdbea66eae4b finding the counterexample with different options (manually limited precisely, manually limited global, automatically limited global)
bulwahn
parents: 39463
diff changeset
    88
40104
82873a6f2b81 splitting Hotel Key card example into specification and the two tests for counter example generation
bulwahn
parents: 39799
diff changeset
    89
lemmas issued_simps[code, code_pred_def] = issued_nil issued.simps(2)
39799
fdbea66eae4b finding the counterexample with different options (manually limited precisely, manually limited global, automatically limited global)
bulwahn
parents: 39463
diff changeset
    90
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    91
end