src/HOL/Auth/Shared.thy
author wenzelm
Fri, 05 Apr 2019 17:05:32 +0200
changeset 70067 9b34dbeb1103
parent 69597 ff784d5a5bfb
child 76287 cdc14f94c754
permissions -rw-r--r--
auxiliary operation for common uses of 'compile_generated_files';
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
37936
1e4c5015a72e updated some headers;
wenzelm
parents: 32631
diff changeset
     1
(*  Title:      HOL/Auth/Shared.thy
1934
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
     2
    Author:     Lawrence C Paulson, Cambridge University Computer Laboratory
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
     3
    Copyright   1996  University of Cambridge
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
     4
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
     5
Theory of Shared Keys (common to all symmetric-key protocols)
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
     6
3512
9dcb4daa15e8 Moving common declarations and proofs from theories "Shared"
paulson
parents: 3472
diff changeset
     7
Shared, long-term keys; initial states of agents
1934
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
     8
*)
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
     9
32631
2489e3c3562b common base for protocols with symmetric keys
haftmann
parents: 32149
diff changeset
    10
theory Shared
2489e3c3562b common base for protocols with symmetric keys
haftmann
parents: 32149
diff changeset
    11
imports Event All_Symmetric
2489e3c3562b common base for protocols with symmetric keys
haftmann
parents: 32149
diff changeset
    12
begin
1934
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
    13
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
    14
consts
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
    15
  shrK    :: "agent \<Rightarrow> key"  (*symmetric keys*)
14126
28824746d046 Tidying and replacement of some axioms by specifications
paulson
parents: 13956
diff changeset
    16
28824746d046 Tidying and replacement of some axioms by specifications
paulson
parents: 13956
diff changeset
    17
specification (shrK)
28824746d046 Tidying and replacement of some axioms by specifications
paulson
parents: 13956
diff changeset
    18
  inj_shrK: "inj shrK"
67443
3abf6a722518 standardized towards new-style formal comments: isabelle update_comments;
wenzelm
parents: 63648
diff changeset
    19
  \<comment> \<open>No two agents have the same long-term key\<close>
55416
dd7992d4a61a adapted theories to 'xxx_case' to 'case_xxx'
blanchet
parents: 53428
diff changeset
    20
   apply (rule exI [of _ "case_agent 0 (\<lambda>n. n + 2) 1"]) 
14126
28824746d046 Tidying and replacement of some axioms by specifications
paulson
parents: 13956
diff changeset
    21
   apply (simp add: inj_on_def split: agent.split) 
28824746d046 Tidying and replacement of some axioms by specifications
paulson
parents: 13956
diff changeset
    22
   done
1967
0ff58b41c037 "bad" set simplifies statements of many theorems
paulson
parents: 1965
diff changeset
    23
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
    24
text\<open>Server knows all long-term keys; other agents know only their own\<close>
39246
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    25
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    26
overloading
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    27
  initState \<equiv> initState
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    28
begin
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    29
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    30
primrec initState where
11104
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
    31
  initState_Server:  "initState Server     = Key ` range shrK"
39246
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    32
| initState_Friend:  "initState (Friend i) = {Key (shrK (Friend i))}"
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    33
| initState_Spy:     "initState Spy        = Key`shrK`bad"
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    34
9e58f0499f57 modernized primrec
haftmann
parents: 37936
diff changeset
    35
end
2032
1bbf1bdcaf56 Introduction of "lost" argument
paulson
parents: 2012
diff changeset
    36
1934
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
    37
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
    38
subsection\<open>Basic properties of shrK\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    39
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    40
(*Injectiveness: Agents' long-term keys are distinct.*)
18749
31c2af8b0c60 replacement of bool by a datatype (making problems first-order). More lemma names
paulson
parents: 17744
diff changeset
    41
lemmas shrK_injective = inj_shrK [THEN inj_eq]
31c2af8b0c60 replacement of bool by a datatype (making problems first-order). More lemma names
paulson
parents: 17744
diff changeset
    42
declare shrK_injective [iff]
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    43
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    44
lemma invKey_K [simp]: "invKey K = K"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    45
apply (insert isSym_keys)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    46
apply (simp add: symKeys_def) 
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    47
done
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    48
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    49
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    50
lemma analz_Decrypt' [dest]:
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    51
     "[| Crypt K X \<in> analz H;  Key K  \<in> analz H |] ==> X \<in> analz H"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    52
by auto
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    53
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
    54
text\<open>Now cancel the \<open>dest\<close> attribute given to
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
    55
 \<open>analz.Decrypt\<close> in its declaration.\<close>
14200
d8598e24f8fa Removal of the Key_supply axiom (affects many possbility proofs) and minor
paulson
parents: 14181
diff changeset
    56
declare analz.Decrypt [rule del]
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    57
69597
ff784d5a5bfb isabelle update -u control_cartouches;
wenzelm
parents: 67613
diff changeset
    58
text\<open>Rewrites should not refer to  \<^term>\<open>initState(Friend i)\<close> because
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
    59
  that expression is not in normal form.\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    60
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    61
lemma keysFor_parts_initState [simp]: "keysFor (parts (initState C)) = {}"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    62
apply (unfold keysFor_def)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    63
apply (induct_tac "C", auto)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    64
done
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    65
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    66
(*Specialized to shared-key model: no @{term invKey}*)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    67
lemma keysFor_parts_insert:
14983
2b5e9b80a8e5 avoid \...\;
wenzelm
parents: 14200
diff changeset
    68
     "[| K \<in> keysFor (parts (insert X G));  X \<in> synth (analz H) |]
39216
62332b382dba tidied using inductive_simps
paulson
parents: 37936
diff changeset
    69
      ==> K \<in> keysFor (parts (G \<union> H)) | Key K \<in> parts H"
41693
47532fe9e075 Introduction of metis calls and other cosmetic modifications.
paulson
parents: 39247
diff changeset
    70
by (metis invKey_K keysFor_parts_insert)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    71
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    72
lemma Crypt_imp_keysFor: "Crypt K X \<in> H ==> K \<in> keysFor H"
41693
47532fe9e075 Introduction of metis calls and other cosmetic modifications.
paulson
parents: 39247
diff changeset
    73
by (metis Crypt_imp_invKey_keysFor invKey_K)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    74
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    75
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
    76
subsection\<open>Function "knows"\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    77
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    78
(*Spy sees shared keys of agents!*)
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
    79
lemma Spy_knows_Spy_bad [intro!]: "A \<in> bad \<Longrightarrow> Key (shrK A) \<in> knows Spy evs"
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    80
apply (induct_tac "evs")
63648
f9f3006a5579 "split add" -> "split"
nipkow
parents: 61830
diff changeset
    81
apply (simp_all (no_asm_simp) add: imageI knows_Cons split: event.split)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    82
done
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    83
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    84
(*For case analysis on whether or not an agent is compromised*)
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
    85
lemma Crypt_Spy_analz_bad: "[| Crypt (shrK A) X \<in> analz (knows Spy evs);  A \<in> bad |]  
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    86
      ==> X \<in> analz (knows Spy evs)"
41693
47532fe9e075 Introduction of metis calls and other cosmetic modifications.
paulson
parents: 39247
diff changeset
    87
by (metis Spy_knows_Spy_bad analz.Inj analz_Decrypt')
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    88
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    89
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    90
(** Fresh keys never clash with long-term shared keys **)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    91
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    92
(*Agents see their own shared keys!*)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    93
lemma shrK_in_initState [iff]: "Key (shrK A) \<in> initState A"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    94
by (induct_tac "A", auto)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    95
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    96
lemma shrK_in_used [iff]: "Key (shrK A) \<in> used evs"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    97
by (rule initState_into_used, blast)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    98
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
    99
(*Used in parts_induct_tac and analz_Fake_tac to distinguish session keys
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   100
  from long-term shared keys*)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   101
lemma Key_not_used [simp]: "Key K \<notin> used evs ==> K \<notin> range shrK"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   102
by blast
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   103
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   104
lemma shrK_neq [simp]: "Key K \<notin> used evs ==> shrK B \<noteq> K"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   105
by blast
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   106
17744
3007c82f17ca theorems need names
paulson
parents: 16417
diff changeset
   107
lemmas shrK_sym_neq = shrK_neq [THEN not_sym]
3007c82f17ca theorems need names
paulson
parents: 16417
diff changeset
   108
declare shrK_sym_neq [simp]
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   109
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   110
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   111
subsection\<open>Fresh nonces\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   112
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   113
lemma Nonce_notin_initState [iff]: "Nonce N \<notin> parts (initState B)"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   114
by (induct_tac "B", auto)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   115
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   116
lemma Nonce_notin_used_empty [simp]: "Nonce N \<notin> used []"
41693
47532fe9e075 Introduction of metis calls and other cosmetic modifications.
paulson
parents: 39247
diff changeset
   117
by (simp add: used_Nil)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   118
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   119
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   120
subsection\<open>Supply fresh nonces for possibility theorems.\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   121
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   122
(*In any trace, there is an upper bound N on the greatest nonce in use.*)
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   123
lemma Nonce_supply_lemma: "\<exists>N. \<forall>n. N \<le> n \<longrightarrow> Nonce n \<notin> used evs"
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   124
apply (induct_tac "evs")
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   125
apply (rule_tac x = 0 in exI)
63648
f9f3006a5579 "split add" -> "split"
nipkow
parents: 61830
diff changeset
   126
apply (simp_all (no_asm_simp) add: used_Cons split: event.split)
41693
47532fe9e075 Introduction of metis calls and other cosmetic modifications.
paulson
parents: 39247
diff changeset
   127
apply (metis le_sup_iff msg_Nonce_supply)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   128
done
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   129
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   130
lemma Nonce_supply1: "\<exists>N. Nonce N \<notin> used evs"
41693
47532fe9e075 Introduction of metis calls and other cosmetic modifications.
paulson
parents: 39247
diff changeset
   131
by (metis Nonce_supply_lemma order_eq_iff)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   132
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   133
lemma Nonce_supply2: "\<exists>N N'. Nonce N \<notin> used evs \<and> Nonce N' \<notin> used evs' \<and> N \<noteq> N'"
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   134
apply (cut_tac evs = evs in Nonce_supply_lemma)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   135
apply (cut_tac evs = "evs'" in Nonce_supply_lemma, clarify)
41693
47532fe9e075 Introduction of metis calls and other cosmetic modifications.
paulson
parents: 39247
diff changeset
   136
apply (metis Suc_n_not_le_n nat_le_linear)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   137
done
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   138
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   139
lemma Nonce_supply3: "\<exists>N N' N''. Nonce N \<notin> used evs \<and> Nonce N' \<notin> used evs' \<and>  
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   140
                    Nonce N'' \<notin> used evs'' \<and> N \<noteq> N' \<and> N' \<noteq> N'' \<and> N \<noteq> N''"
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   141
apply (cut_tac evs = evs in Nonce_supply_lemma)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   142
apply (cut_tac evs = "evs'" in Nonce_supply_lemma)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   143
apply (cut_tac evs = "evs''" in Nonce_supply_lemma, clarify)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   144
apply (rule_tac x = N in exI)
14200
d8598e24f8fa Removal of the Key_supply axiom (affects many possbility proofs) and minor
paulson
parents: 14181
diff changeset
   145
apply (rule_tac x = "Suc (N+Na)" in exI)
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   146
apply (rule_tac x = "Suc (Suc (N+Na+Nb))" in exI)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   147
apply (simp (no_asm_simp) add: less_not_refl3 le_add1 le_add2 less_Suc_eq_le)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   148
done
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   149
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   150
lemma Nonce_supply: "Nonce (SOME N. Nonce N \<notin> used evs) \<notin> used evs"
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   151
apply (rule Nonce_supply_lemma [THEN exE])
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   152
apply (rule someI, blast)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   153
done
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   154
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   155
text\<open>Unlike the corresponding property of nonces, we cannot prove
69597
ff784d5a5bfb isabelle update -u control_cartouches;
wenzelm
parents: 67613
diff changeset
   156
    \<^term>\<open>finite KK ==> \<exists>K. K \<notin> KK \<and> Key K \<notin> used evs\<close>.
2516
4d68fbe6378b Now with Andy Gordon's treatment of freshness to replace newN/K
paulson
parents: 2451
diff changeset
   157
    We have infinitely many agents and there is nothing to stop their
14200
d8598e24f8fa Removal of the Key_supply axiom (affects many possbility proofs) and minor
paulson
parents: 14181
diff changeset
   158
    long-term keys from exhausting all the natural numbers.  Instead,
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   159
    possibility theorems must assume the existence of a few keys.\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   160
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   161
69597
ff784d5a5bfb isabelle update -u control_cartouches;
wenzelm
parents: 67613
diff changeset
   162
subsection\<open>Specialized Rewriting for Theorems About \<^term>\<open>analz\<close> and Image\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   163
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   164
lemma subset_Compl_range: "A \<subseteq> - (range shrK) \<Longrightarrow> shrK x \<notin> A"
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   165
by blast
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   166
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   167
lemma insert_Key_singleton: "insert (Key K) H = Key ` {K} \<union> H"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   168
by blast
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   169
13956
8fe7e12290e1 improved presentation of HOL/Auth theories
paulson
parents: 13926
diff changeset
   170
lemma insert_Key_image: "insert (Key K) (Key`KK \<union> C) = Key`(insert K KK) \<union> C"
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   171
by blast
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   172
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   173
(** Reverse the normal simplification of "image" to build up (not break down)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   174
    the set of keys.  Use analz_insert_eq with (Un_upper2 RS analz_mono) to
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   175
    erase occurrences of forwarded message components (X). **)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   176
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   177
lemmas analz_image_freshK_simps =
67443
3abf6a722518 standardized towards new-style formal comments: isabelle update_comments;
wenzelm
parents: 63648
diff changeset
   178
       simp_thms mem_simps \<comment> \<open>these two allow its use with \<open>only:\<close>\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   179
       disj_comms 
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   180
       image_insert [THEN sym] image_Un [THEN sym] empty_subsetI insert_subset
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   181
       analz_insert_eq Un_upper2 [THEN analz_mono, THEN [2] rev_subsetD]
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   182
       insert_Key_singleton subset_Compl_range
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   183
       Key_not_used insert_Key_image Un_assoc [THEN sym]
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   184
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   185
(*Lemma for the trivial direction of the if-and-only-if*)
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   186
lemma analz_image_freshK_lemma:
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   187
     "(Key K \<in> analz (Key`nE \<union> H)) \<longrightarrow> (K \<in> nE | Key K \<in> analz H)  ==>  
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   188
         (Key K \<in> analz (Key`nE \<union> H)) = (K \<in> nE | Key K \<in> analz H)"
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   189
by (blast intro: analz_mono [THEN [2] rev_subsetD])
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   190
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   191
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   192
subsection\<open>Tactics for possibility theorems\<close>
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   193
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   194
ML
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   195
\<open>
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   196
structure Shared =
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   197
struct
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   198
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   199
(*Omitting used_Says makes the tactic much faster: it leaves expressions
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   200
    such as  Nonce ?N \<notin> used evs that match Nonce_supply*)
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   201
fun possibility_tac ctxt =
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   202
   (REPEAT 
51717
9e7d1c139569 simplifier uses proper Proof.context instead of historic type simpset;
wenzelm
parents: 41693
diff changeset
   203
    (ALLGOALS (simp_tac (ctxt
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   204
          delsimps [@{thm used_Says}, @{thm used_Notes}, @{thm used_Gets}] 
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   205
          setSolver safe_solver))
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   206
     THEN
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   207
     REPEAT_FIRST (eq_assume_tac ORELSE' 
59498
50b60f501b05 proper context for resolve_tac, eresolve_tac, dresolve_tac, forward_tac etc.;
wenzelm
parents: 55416
diff changeset
   208
                   resolve_tac ctxt [refl, conjI, @{thm Nonce_supply}])))
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   209
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   210
(*For harder protocols (such as Recur) where we have to set up some
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   211
  nonces and keys initially*)
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   212
fun basic_possibility_tac ctxt =
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   213
    REPEAT 
51717
9e7d1c139569 simplifier uses proper Proof.context instead of historic type simpset;
wenzelm
parents: 41693
diff changeset
   214
    (ALLGOALS (asm_simp_tac (ctxt setSolver safe_solver))
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   215
     THEN
59498
50b60f501b05 proper context for resolve_tac, eresolve_tac, dresolve_tac, forward_tac etc.;
wenzelm
parents: 55416
diff changeset
   216
     REPEAT_FIRST (resolve_tac ctxt [refl, conjI]))
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   217
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   218
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   219
val analz_image_freshK_ss =
51717
9e7d1c139569 simplifier uses proper Proof.context instead of historic type simpset;
wenzelm
parents: 41693
diff changeset
   220
  simpset_of
69597
ff784d5a5bfb isabelle update -u control_cartouches;
wenzelm
parents: 67613
diff changeset
   221
   (\<^context> delsimps [image_insert, image_Un]
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   222
      delsimps [@{thm imp_disjL}]    (*reduces blow-up*)
51717
9e7d1c139569 simplifier uses proper Proof.context instead of historic type simpset;
wenzelm
parents: 41693
diff changeset
   223
      addsimps @{thms analz_image_freshK_simps})
24122
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   224
fc7f857d33c8 tuned ML bindings (for multithreading);
wenzelm
parents: 23894
diff changeset
   225
end
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   226
\<close>
13926
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   227
6e62e5357a10 converting more HOL-Auth to new-style theories
paulson
parents: 13907
diff changeset
   228
11104
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   229
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   230
(*Lets blast_tac perform this step without needing the simplifier*)
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   231
lemma invKey_shrK_iff [iff]:
11270
a315a3862bb4 better treatment of methods: uses Method.ctxt_args to refer to current
paulson
parents: 11230
diff changeset
   232
     "(Key (invKey K) \<in> X) = (Key K \<in> X)"
13507
febb8e5d2a9d tidying of Isar scripts
paulson
parents: 12415
diff changeset
   233
by auto
11104
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   234
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   235
(*Specialized methods*)
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   236
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   237
method_setup analz_freshK = \<open>
30549
d2d7874648bd simplified method setup;
wenzelm
parents: 30510
diff changeset
   238
    Scan.succeed (fn ctxt =>
30510
4120fc59dd85 unified type Proof.method and pervasive METHOD combinators;
wenzelm
parents: 24122
diff changeset
   239
     (SIMPLE_METHOD
59498
50b60f501b05 proper context for resolve_tac, eresolve_tac, dresolve_tac, forward_tac etc.;
wenzelm
parents: 55416
diff changeset
   240
      (EVERY [REPEAT_FIRST (resolve_tac ctxt [allI, ballI, impI]),
60754
02924903a6fd prefer tactics with explicit context;
wenzelm
parents: 59498
diff changeset
   241
          REPEAT_FIRST (resolve_tac ctxt @{thms analz_image_freshK_lemma}),
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   242
          ALLGOALS (asm_simp_tac (put_simpset Shared.analz_image_freshK_ss ctxt))])))\<close>
11104
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   243
    "for proving the Session Key Compromise theorem"
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   244
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   245
method_setup possibility = \<open>
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   246
    Scan.succeed (fn ctxt => SIMPLE_METHOD (Shared.possibility_tac ctxt))\<close>
23894
1a4167d761ac tactics: avoid dynamic reference to accidental theory context (via ML_Context.the_context etc.);
wenzelm
parents: 21588
diff changeset
   247
    "for proving possibility theorems"
1a4167d761ac tactics: avoid dynamic reference to accidental theory context (via ML_Context.the_context etc.);
wenzelm
parents: 21588
diff changeset
   248
61830
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   249
method_setup basic_possibility = \<open>
4f5ab843cf5b isabelle update_cartouches -c -t;
wenzelm
parents: 60754
diff changeset
   250
    Scan.succeed (fn ctxt => SIMPLE_METHOD (Shared.basic_possibility_tac ctxt))\<close>
11104
f2024fed9f0c partial conversion to Isar script style
paulson
parents: 10833
diff changeset
   251
    "for proving possibility theorems"
2516
4d68fbe6378b Now with Andy Gordon's treatment of freshness to replace newN/K
paulson
parents: 2451
diff changeset
   252
67613
ce654b0e6d69 more symbols;
wenzelm
parents: 67443
diff changeset
   253
lemma knows_subset_knows_Cons: "knows A evs \<subseteq> knows A (e # evs)"
53428
3083c611ec40 use case_of_simps
noschinl
parents: 51717
diff changeset
   254
by (cases e) (auto simp: knows_Cons)
12415
74977582a585 Slightly generalized the agents' knowledge theorems
paulson
parents: 11270
diff changeset
   255
1934
58573e7041b4 Separation of theory Event into two parts:
paulson
parents:
diff changeset
   256
end