src/HOL/IOA/NTP/Impl.thy
author lcp
Tue, 25 Apr 1995 11:14:03 +0200
changeset 1072 0140ff702b23
parent 1051 4fcd0638e61d
child 1151 c820b3cc3df0
permissions -rw-r--r--
updated version
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
1051
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     1
(*  Title:      HOL/IOA/NTP/Impl.thy
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     2
    ID:         $Id$
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     3
    Author:     Tobias Nipkow & Konrad Slind
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     4
    Copyright   1994  TU Muenchen
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     5
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     6
The implementation
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     7
*)
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     8
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
     9
Impl = Sender + Receiver + Abschannel +
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    10
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    11
types 
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    12
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    13
'm impl_state 
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    14
= "'m sender_state * 'm receiver_state * 'm packet multiset * bool multiset"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    15
(*  sender_state   *  receiver_state   *    srch_state      * rsch_state *)
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    16
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    17
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    18
consts
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    19
 impl_ioa    :: "('m action, 'm impl_state)ioa"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    20
 sen         :: "'m impl_state => 'm sender_state"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    21
 rec         :: "'m impl_state => 'm receiver_state"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    22
 srch        :: "'m impl_state => 'm packet multiset"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    23
 rsch        :: "'m impl_state => bool multiset"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    24
 inv1, inv2, 
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    25
 inv3, inv4  :: "'m impl_state => bool"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    26
 hdr_sum     :: "'m packet multiset => bool => nat"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    27
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    28
defs
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    29
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    30
 impl_def
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    31
  "impl_ioa == (sender_ioa || receiver_ioa || srch_ioa || rsch_ioa)"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    32
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    33
 sen_def   "sen == fst"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    34
 rec_def   "rec == fst o snd"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    35
 srch_def "srch == fst o snd o snd"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    36
 rsch_def "rsch == snd o snd o snd"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    37
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    38
hdr_sum_def
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    39
   "hdr_sum M b == countm M (%pkt.hdr(pkt) = b)"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    40
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    41
(* Lemma 5.1 *)
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    42
inv1_def 
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    43
  "inv1(s) ==                                                                 \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    44
 \   (!b. count (rsent(rec s)) b = count (srcvd(sen s)) b + count (rsch s) b) \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    45
 \ & (!b. count (ssent(sen s)) b                                              \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    46
 \        = hdr_sum (rrcvd(rec s)) b + hdr_sum (srch s) b)"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    47
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    48
(* Lemma 5.2 *)
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    49
 inv2_def "inv2(s) ==                                                   \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    50
\  (rbit(rec(s)) = sbit(sen(s)) &                                       \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    51
\   ssending(sen(s)) &                                                  \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    52
\   count (rsent(rec s)) (~sbit(sen s)) <= count (ssent(sen s)) (~sbit(sen s)) &\
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    53
\   count (ssent(sen s)) (~sbit(sen s)) <= count (rsent(rec s)) (sbit(sen s)))  \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    54
\   |                                                                   \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    55
\  (rbit(rec(s)) = (~sbit(sen(s))) &                                    \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    56
\   rsending(rec(s)) &                                                  \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    57
\   count (ssent(sen s)) (~sbit(sen s)) <= count (rsent(rec s)) (sbit(sen s)) &\
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    58
\   count (rsent(rec s)) (sbit(sen s)) <= count (ssent(sen s)) (sbit(sen s)))"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    59
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    60
(* Lemma 5.3 *)
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    61
 inv3_def "inv3(s) ==                                                   \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    62
\   rbit(rec(s)) = sbit(sen(s))                                         \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    63
\   --> (!m. sq(sen(s))=[] | m ~= hd(sq(sen(s)))                        \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    64
\        -->  count (rrcvd(rec s)) (sbit(sen(s)),m)                     \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    65
\             + count (srch s) (sbit(sen(s)),m)                         \
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    66
\            <= count (rsent(rec s)) (~sbit(sen s)))"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    67
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    68
(* Lemma 5.4 *)
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    69
 inv4_def "inv4(s) == rbit(rec(s)) = (~sbit(sen(s))) --> sq(sen(s)) ~= []"
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    70
4fcd0638e61d Directory example is now called NTP
nipkow
parents:
diff changeset
    71
end