src/HOL/Auth/Guard/Guard_Shared.thy
author haftmann
Fri, 07 Dec 2007 15:07:59 +0100
changeset 25571 c9e39eafc7a0
parent 21404 eb85850d3eb7
child 35416 d8d7d1b785af
permissions -rw-r--r--
instantiation target rather than legacy instance
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     1
(******************************************************************************
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     2
date: march 2002
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     3
author: Frederic Blanqui
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     4
email: blanqui@lri.fr
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     5
webpage: http://www.lri.fr/~blanqui/
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     6
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     7
University of Cambridge, Computer Laboratory
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     8
William Gates Building, JJ Thomson Avenue
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     9
Cambridge CB3 0FD, United Kingdom
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    10
******************************************************************************)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    11
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    12
header{*lemmas on guarded messages for protocols with symmetric keys*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    13
16417
9bc16273c2d4 migrated theory headers to new format
haftmann
parents: 13601
diff changeset
    14
theory Guard_Shared imports Guard GuardK Shared begin
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    15
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    16
subsection{*Extensions to Theory @{text Shared}*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    17
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    18
declare initState.simps [simp del]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    19
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    20
subsubsection{*a little abbreviation*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    21
19363
667b5ea637dd refined 'abbreviation';
wenzelm
parents: 16417
diff changeset
    22
abbreviation
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 19363
diff changeset
    23
  Ciph :: "agent => msg => msg" where
19363
667b5ea637dd refined 'abbreviation';
wenzelm
parents: 16417
diff changeset
    24
  "Ciph A X == Crypt (shrK A) X"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    25
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    26
subsubsection{*agent associated to a key*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    27
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    28
constdefs agt :: "key => agent"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    29
"agt K == @A. K = shrK A"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    30
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    31
lemma agt_shrK [simp]: "agt (shrK A) = A"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    32
by (simp add: agt_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    33
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    34
subsubsection{*basic facts about @{term initState}*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    35
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    36
lemma no_Crypt_in_parts_init [simp]: "Crypt K X ~:parts (initState A)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    37
by (cases A, auto simp: initState.simps)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    38
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    39
lemma no_Crypt_in_analz_init [simp]: "Crypt K X ~:analz (initState A)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    40
by auto
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    41
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    42
lemma no_shrK_in_analz_init [simp]: "A ~:bad
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    43
==> Key (shrK A) ~:analz (initState Spy)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    44
by (auto simp: initState.simps)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    45
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    46
lemma shrK_notin_initState_Friend [simp]: "A ~= Friend C
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    47
==> Key (shrK A) ~: parts (initState (Friend C))"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    48
by (auto simp: initState.simps)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    49
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    50
lemma keyset_init [iff]: "keyset (initState A)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    51
by (cases A, auto simp: keyset_def initState.simps)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    52
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    53
subsubsection{*sets of symmetric keys*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    54
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    55
constdefs shrK_set :: "key set => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    56
"shrK_set Ks == ALL K. K:Ks --> (EX A. K = shrK A)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    57
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    58
lemma in_shrK_set: "[| shrK_set Ks; K:Ks |] ==> EX A. K = shrK A"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    59
by (simp add: shrK_set_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    60
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    61
lemma shrK_set1 [iff]: "shrK_set {shrK A}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    62
by (simp add: shrK_set_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    63
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    64
lemma shrK_set2 [iff]: "shrK_set {shrK A, shrK B}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    65
by (simp add: shrK_set_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    66
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    67
subsubsection{*sets of good keys*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    68
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    69
constdefs good :: "key set => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    70
"good Ks == ALL K. K:Ks --> agt K ~:bad"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    71
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    72
lemma in_good: "[| good Ks; K:Ks |] ==> agt K ~:bad"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    73
by (simp add: good_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    74
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    75
lemma good1 [simp]: "A ~:bad ==> good {shrK A}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    76
by (simp add: good_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    77
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    78
lemma good2 [simp]: "[| A ~:bad; B ~:bad |] ==> good {shrK A, shrK B}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    79
by (simp add: good_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    80
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    81
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    82
subsection{*Proofs About Guarded Messages*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    83
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    84
subsubsection{*small hack*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    85
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    86
lemma shrK_is_invKey_shrK: "shrK A = invKey (shrK A)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    87
by simp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    88
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    89
lemmas shrK_is_invKey_shrK_substI = shrK_is_invKey_shrK [THEN ssubst]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    90
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    91
lemmas invKey_invKey_substI = invKey [THEN ssubst]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    92
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    93
lemma "Nonce n:parts {X} ==> Crypt (shrK A) X:guard n {shrK A}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    94
apply (rule shrK_is_invKey_shrK_substI, rule invKey_invKey_substI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    95
by (rule Guard_Nonce, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    96
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    97
subsubsection{*guardedness results on nonces*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    98
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    99
lemma guard_ciph [simp]: "shrK A:Ks ==> Ciph A X:guard n Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   100
by (rule Guard_Nonce, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   101
13523
079af5c90d1c avoid duplicate fact bindings;
wenzelm
parents: 13508
diff changeset
   102
lemma guardK_ciph [simp]: "shrK A:Ks ==> Ciph A X:guardK n Ks"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   103
by (rule Guard_Key, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   104
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   105
lemma Guard_init [iff]: "Guard n Ks (initState B)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   106
by (induct B, auto simp: Guard_def initState.simps)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   107
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   108
lemma Guard_knows_max': "Guard n Ks (knows_max' C evs)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   109
==> Guard n Ks (knows_max C evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   110
by (simp add: knows_max_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   111
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   112
lemma Nonce_not_used_Guard_spies [dest]: "Nonce n ~:used evs
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   113
==> Guard n Ks (spies evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   114
by (auto simp: Guard_def dest: not_used_not_known parts_sub)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   115
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   116
lemma Nonce_not_used_Guard [dest]: "[| evs:p; Nonce n ~:used evs;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   117
Gets_correct p; one_step p |] ==> Guard n Ks (knows (Friend C) evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   118
by (auto simp: Guard_def dest: known_used parts_trans)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   119
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   120
lemma Nonce_not_used_Guard_max [dest]: "[| evs:p; Nonce n ~:used evs;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   121
Gets_correct p; one_step p |] ==> Guard n Ks (knows_max (Friend C) evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   122
by (auto simp: Guard_def dest: known_max_used parts_trans)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   123
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   124
lemma Nonce_not_used_Guard_max' [dest]: "[| evs:p; Nonce n ~:used evs;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   125
Gets_correct p; one_step p |] ==> Guard n Ks (knows_max' (Friend C) evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   126
apply (rule_tac H="knows_max (Friend C) evs" in Guard_mono)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   127
by (auto simp: knows_max_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   128
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   129
subsubsection{*guardedness results on keys*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   130
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   131
lemma GuardK_init [simp]: "n ~:range shrK ==> GuardK n Ks (initState B)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   132
by (induct B, auto simp: GuardK_def initState.simps)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   133
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   134
lemma GuardK_knows_max': "[| GuardK n A (knows_max' C evs); n ~:range shrK |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   135
==> GuardK n A (knows_max C evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   136
by (simp add: knows_max_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   137
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   138
lemma Key_not_used_GuardK_spies [dest]: "Key n ~:used evs
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   139
==> GuardK n A (spies evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   140
by (auto simp: GuardK_def dest: not_used_not_known parts_sub)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   141
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   142
lemma Key_not_used_GuardK [dest]: "[| evs:p; Key n ~:used evs;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   143
Gets_correct p; one_step p |] ==> GuardK n A (knows (Friend C) evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   144
by (auto simp: GuardK_def dest: known_used parts_trans)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   145
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   146
lemma Key_not_used_GuardK_max [dest]: "[| evs:p; Key n ~:used evs;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   147
Gets_correct p; one_step p |] ==> GuardK n A (knows_max (Friend C) evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   148
by (auto simp: GuardK_def dest: known_max_used parts_trans)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   149
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   150
lemma Key_not_used_GuardK_max' [dest]: "[| evs:p; Key n ~:used evs;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   151
Gets_correct p; one_step p |] ==> GuardK n A (knows_max' (Friend C) evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   152
apply (rule_tac H="knows_max (Friend C) evs" in GuardK_mono)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   153
by (auto simp: knows_max_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   154
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   155
subsubsection{*regular protocols*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   156
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   157
constdefs regular :: "event list set => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   158
"regular p == ALL evs A. evs:p --> (Key (shrK A):parts (spies evs)) = (A:bad)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   159
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   160
lemma shrK_parts_iff_bad [simp]: "[| evs:p; regular p |] ==>
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   161
(Key (shrK A):parts (spies evs)) = (A:bad)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   162
by (auto simp: regular_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   163
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   164
lemma shrK_analz_iff_bad [simp]: "[| evs:p; regular p |] ==>
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   165
(Key (shrK A):analz (spies evs)) = (A:bad)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   166
by auto
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   167
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   168
lemma Guard_Nonce_analz: "[| Guard n Ks (spies evs); evs:p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   169
shrK_set Ks; good Ks; regular p |] ==> Nonce n ~:analz (spies evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   170
apply (clarify, simp only: knows_decomp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   171
apply (drule Guard_invKey_keyset, simp+, safe)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   172
apply (drule in_good, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   173
apply (drule in_shrK_set, simp+, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   174
apply (frule_tac A=A in shrK_analz_iff_bad)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   175
by (simp add: knows_decomp)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   176
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   177
lemma GuardK_Key_analz: "[| GuardK n Ks (spies evs); evs:p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   178
shrK_set Ks; good Ks; regular p; n ~:range shrK |] ==> Key n ~:analz (spies evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   179
apply (clarify, simp only: knows_decomp)
13601
fd3e3d6b37b2 Adapted to new simplifier.
berghofe
parents: 13523
diff changeset
   180
apply (drule GuardK_invKey_keyset, clarify, simp+, simp add: initState.simps)
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   181
apply clarify
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   182
apply (drule in_good, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   183
apply (drule in_shrK_set, simp+, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   184
apply (frule_tac A=A in shrK_analz_iff_bad)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   185
by (simp add: knows_decomp)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   186
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   187
end