src/HOL/Auth/Guard/Proto.thy
author wenzelm
Tue, 10 Jul 2007 23:29:43 +0200
changeset 23719 ccd9cb15c062
parent 22426 1c38ca2496c4
child 23746 a455e69c31cc
permissions -rw-r--r--
more markup for inner and outer syntax; added enclose;
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     1
(******************************************************************************
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     2
date: april 2002
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     3
author: Frederic Blanqui
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     4
email: blanqui@lri.fr
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     5
webpage: http://www.lri.fr/~blanqui/
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     6
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     7
University of Cambridge, Computer Laboratory
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     8
William Gates Building, JJ Thomson Avenue
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
     9
Cambridge CB3 0FD, United Kingdom
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    10
******************************************************************************)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    11
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    12
header{*Other Protocol-Independent Results*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    13
16417
9bc16273c2d4 migrated theory headers to new format
haftmann
parents: 13601
diff changeset
    14
theory Proto imports Guard_Public begin
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    15
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    16
subsection{*protocols*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    17
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    18
types rule = "event set * event"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    19
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    20
abbreviation
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    21
  msg' :: "rule => msg" where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    22
  "msg' R == msg (snd R)"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    23
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    24
types proto = "rule set"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    25
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    26
constdefs wdef :: "proto => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    27
"wdef p == ALL R k. R:p --> Number k:parts {msg' R}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    28
--> Number k:parts (msg`(fst R))"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    29
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    30
subsection{*substitutions*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    31
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    32
record subs =
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    33
  agent   :: "agent => agent"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    34
  nonce :: "nat => nat"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    35
  nb    :: "nat => msg"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    36
  key   :: "key => key"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    37
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    38
consts apm :: "subs => msg => msg"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    39
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    40
primrec
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    41
"apm s (Agent A) = Agent (agent s A)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    42
"apm s (Nonce n) = Nonce (nonce s n)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    43
"apm s (Number n) = nb s n"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    44
"apm s (Key K) = Key (key s K)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    45
"apm s (Hash X) = Hash (apm s X)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    46
"apm s (Crypt K X) = (
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    47
if (EX A. K = pubK A) then Crypt (pubK (agent s (agt K))) (apm s X)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    48
else if (EX A. K = priK A) then Crypt (priK (agent s (agt K))) (apm s X)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    49
else Crypt (key s K) (apm s X))"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    50
"apm s {|X,Y|} = {|apm s X, apm s Y|}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    51
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    52
lemma apm_parts: "X:parts {Y} ==> apm s X:parts {apm s Y}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    53
apply (erule parts.induct, simp_all, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    54
apply (erule parts.Fst)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    55
apply (erule parts.Snd)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    56
by (erule parts.Body)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    57
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    58
lemma Nonce_apm [rule_format]: "Nonce n:parts {apm s X} ==>
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    59
(ALL k. Number k:parts {X} --> Nonce n ~:parts {nb s k}) -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    60
(EX k. Nonce k:parts {X} & nonce s k = n)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    61
by (induct X, simp_all, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    62
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    63
lemma wdef_Nonce: "[| Nonce n:parts {apm s X}; R:p; msg' R = X; wdef p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    64
Nonce n ~:parts (apm s `(msg `(fst R))) |] ==>
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    65
(EX k. Nonce k:parts {X} & nonce s k = n)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    66
apply (erule Nonce_apm, unfold wdef_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    67
apply (drule_tac x=R in spec, drule_tac x=k in spec, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    68
apply (drule_tac x=x in bspec, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    69
apply (drule_tac Y="msg x" and s=s in apm_parts, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    70
by (blast dest: parts_parts)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    71
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    72
consts ap :: "subs => event => event"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    73
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    74
primrec
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    75
"ap s (Says A B X) = Says (agent s A) (agent s B) (apm s X)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    76
"ap s (Gets A X) = Gets (agent s A) (apm s X)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    77
"ap s (Notes A X) = Notes (agent s A) (apm s X)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    78
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    79
abbreviation
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    80
  ap' :: "subs => rule => event" where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    81
  "ap' s R == ap s (snd R)"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    82
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    83
abbreviation
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    84
  apm' :: "subs => rule => msg" where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    85
  "apm' s R == apm s (msg' R)"
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    86
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    87
abbreviation
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    88
  priK' :: "subs => agent => key" where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    89
  "priK' s A == priK (agent s A)"
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    90
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    91
abbreviation
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
    92
  pubK' :: "subs => agent => key" where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
    93
  "pubK' s A == pubK (agent s A)"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    94
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    95
subsection{*nonces generated by a rule*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    96
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    97
constdefs newn :: "rule => nat set"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    98
"newn R == {n. Nonce n:parts {msg (snd R)} & Nonce n ~:parts (msg`(fst R))}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
    99
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   100
lemma newn_parts: "n:newn R ==> Nonce (nonce s n):parts {apm' s R}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   101
by (auto simp: newn_def dest: apm_parts)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   102
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   103
subsection{*traces generated by a protocol*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   104
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   105
constdefs ok :: "event list => rule => subs => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   106
"ok evs R s == ((ALL x. x:fst R --> ap s x:set evs)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   107
& (ALL n. n:newn R --> Nonce (nonce s n) ~:used evs))"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   108
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   109
consts tr :: "proto => event list set"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   110
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   111
inductive "tr p" intros
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   112
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   113
Nil [intro]: "[]:tr p"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   114
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   115
Fake [intro]: "[| evsf:tr p; X:synth (analz (spies evsf)) |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   116
==> Says Spy B X # evsf:tr p"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   117
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   118
Proto [intro]: "[| evs:tr p; R:p; ok evs R s |] ==> ap' s R # evs:tr p"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   119
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   120
subsection{*general properties*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   121
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   122
lemma one_step_tr [iff]: "one_step (tr p)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   123
apply (unfold one_step_def, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   124
by (ind_cases "ev # evs:tr p", auto)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   125
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   126
constdefs has_only_Says' :: "proto => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   127
"has_only_Says' p == ALL R. R:p --> is_Says (snd R)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   128
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   129
lemma has_only_Says'D: "[| R:p; has_only_Says' p |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   130
==> (EX A B X. snd R = Says A B X)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   131
by (unfold has_only_Says'_def is_Says_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   132
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   133
lemma has_only_Says_tr [simp]: "has_only_Says' p ==> has_only_Says (tr p)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   134
apply (unfold has_only_Says_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   135
apply (rule allI, rule allI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   136
apply (erule tr.induct)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   137
apply (auto simp: has_only_Says'_def ok_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   138
by (drule_tac x=a in spec, auto simp: is_Says_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   139
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   140
lemma has_only_Says'_in_trD: "[| has_only_Says' p; list @ ev # evs1 \<in> tr p |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   141
==> (EX A B X. ev = Says A B X)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   142
by (drule has_only_Says_tr, auto)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   143
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   144
lemma ok_not_used: "[| Nonce n ~:used evs; ok evs R s;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   145
ALL x. x:fst R --> is_Says x |] ==> Nonce n ~:parts (apm s `(msg `(fst R)))"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   146
apply (unfold ok_def, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   147
apply (drule_tac x=x in spec, drule_tac x=x in spec)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   148
by (auto simp: is_Says_def dest: Says_imp_spies not_used_not_spied parts_parts)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   149
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   150
lemma ok_is_Says: "[| evs' @ ev # evs:tr p; ok evs R s; has_only_Says' p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   151
R:p; x:fst R |] ==> is_Says x"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   152
apply (unfold ok_def is_Says_def, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   153
apply (drule_tac x=x in spec, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   154
apply (subgoal_tac "one_step (tr p)")
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   155
apply (drule trunc, simp, drule one_step_Cons, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   156
apply (drule has_only_SaysD, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   157
by (clarify, case_tac x, auto)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   158
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   159
subsection{*types*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   160
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   161
types keyfun = "rule => subs => nat => event list => key set"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   162
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   163
types secfun = "rule => nat => subs => key set => msg"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   164
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   165
subsection{*introduction of a fresh guarded nonce*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   166
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   167
constdefs fresh :: "proto => rule => subs => nat => key set => event list
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   168
=> bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   169
"fresh p R s n Ks evs == (EX evs1 evs2. evs = evs2 @ ap' s R # evs1
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   170
& Nonce n ~:used evs1 & R:p & ok evs1 R s & Nonce n:parts {apm' s R}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   171
& apm' s R:guard n Ks)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   172
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   173
lemma freshD: "fresh p R s n Ks evs ==> (EX evs1 evs2.
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   174
evs = evs2 @ ap' s R # evs1 & Nonce n ~:used evs1 & R:p & ok evs1 R s
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   175
& Nonce n:parts {apm' s R} & apm' s R:guard n Ks)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   176
by (unfold fresh_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   177
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   178
lemma freshI [intro]: "[| Nonce n ~:used evs1; R:p; Nonce n:parts {apm' s R};
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   179
ok evs1 R s; apm' s R:guard n Ks |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   180
==> fresh p R s n Ks (list @ ap' s R # evs1)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   181
by (unfold fresh_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   182
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   183
lemma freshI': "[| Nonce n ~:used evs1; (l,r):p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   184
Nonce n:parts {apm s (msg r)}; ok evs1 (l,r) s; apm s (msg r):guard n Ks |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   185
==> fresh p (l,r) s n Ks (evs2 @ ap s r # evs1)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   186
by (drule freshI, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   187
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   188
lemma fresh_used: "[| fresh p R' s' n Ks evs; has_only_Says' p |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   189
==> Nonce n:used evs"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   190
apply (unfold fresh_def, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   191
apply (drule has_only_Says'D)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   192
by (auto intro: parts_used_app)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   193
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   194
lemma fresh_newn: "[| evs' @ ap' s R # evs:tr p; wdef p; has_only_Says' p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   195
Nonce n ~:used evs; R:p; ok evs R s; Nonce n:parts {apm' s R} |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   196
==> EX k. k:newn R & nonce s k = n"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   197
apply (drule wdef_Nonce, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   198
apply (frule ok_not_used, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   199
apply (clarify, erule ok_is_Says, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   200
apply (clarify, rule_tac x=k in exI, simp add: newn_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   201
apply (clarify, drule_tac Y="msg x" and s=s in apm_parts)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   202
apply (drule ok_not_used, simp+)
13601
fd3e3d6b37b2 Adapted to new simplifier.
berghofe
parents: 13508
diff changeset
   203
by (clarify, erule ok_is_Says, simp+)
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   204
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   205
lemma fresh_rule: "[| evs' @ ev # evs:tr p; wdef p; Nonce n ~:used evs;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   206
Nonce n:parts {msg ev} |] ==> EX R s. R:p & ap' s R = ev"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   207
apply (drule trunc, simp, ind_cases "ev # evs:tr p", simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   208
by (drule_tac x=X in in_sub, drule parts_sub, simp, simp, blast+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   209
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   210
lemma fresh_ruleD: "[| fresh p R' s' n Ks evs; keys R' s' n evs <= Ks; wdef p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   211
has_only_Says' p; evs:tr p; ALL R k s. nonce s k = n --> Nonce n:used evs -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   212
R:p --> k:newn R --> Nonce n:parts {apm' s R} --> apm' s R:guard n Ks -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   213
apm' s R:parts (spies evs) --> keys R s n evs <= Ks --> P |] ==> P"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   214
apply (frule fresh_used, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   215
apply (unfold fresh_def, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   216
apply (drule_tac x=R' in spec)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   217
apply (drule fresh_newn, simp+, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   218
apply (drule_tac x=k in spec)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   219
apply (drule_tac x=s' in spec)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   220
apply (subgoal_tac "apm' s' R':parts (spies (evs2 @ ap' s' R' # evs1))")
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   221
apply (case_tac R', drule has_only_Says'D, simp, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   222
apply (case_tac R', drule has_only_Says'D, simp, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   223
apply (rule_tac Y="apm s' X" in parts_parts, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   224
by (rule parts.Inj, rule Says_imp_spies, simp, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   225
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   226
subsection{*safe keys*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   227
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   228
constdefs safe :: "key set => msg set => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   229
"safe Ks G == ALL K. K:Ks --> Key K ~:analz G"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   230
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   231
lemma safeD [dest]: "[| safe Ks G; K:Ks |] ==> Key K ~:analz G"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   232
by (unfold safe_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   233
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   234
lemma safe_insert: "safe Ks (insert X G) ==> safe Ks G"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   235
by (unfold safe_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   236
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   237
lemma Guard_safe: "[| Guard n Ks G; safe Ks G |] ==> Nonce n ~:analz G"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   238
by (blast dest: Guard_invKey)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   239
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   240
subsection{*guardedness preservation*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   241
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   242
constdefs preserv :: "proto => keyfun => nat => key set => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   243
"preserv p keys n Ks == (ALL evs R' s' R s. evs:tr p -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   244
Guard n Ks (spies evs) --> safe Ks (spies evs) --> fresh p R' s' n Ks evs -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   245
keys R' s' n evs <= Ks --> R:p --> ok evs R s --> apm' s R:guard n Ks)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   246
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   247
lemma preservD: "[| preserv p keys n Ks; evs:tr p; Guard n Ks (spies evs);
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   248
safe Ks (spies evs); fresh p R' s' n Ks evs; R:p; ok evs R s;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   249
keys R' s' n evs <= Ks |] ==> apm' s R:guard n Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   250
by (unfold preserv_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   251
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   252
lemma preservD': "[| preserv p keys n Ks; evs:tr p; Guard n Ks (spies evs);
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   253
safe Ks (spies evs); fresh p R' s' n Ks evs; (l,Says A B X):p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   254
ok evs (l,Says A B X) s; keys R' s' n evs <= Ks |] ==> apm s X:guard n Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   255
by (drule preservD, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   256
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   257
subsection{*monotonic keyfun*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   258
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   259
constdefs monoton :: "proto => keyfun => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   260
"monoton p keys == ALL R' s' n ev evs. ev # evs:tr p -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   261
keys R' s' n evs <= keys R' s' n (ev # evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   262
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   263
lemma monotonD [dest]: "[| keys R' s' n (ev # evs) <= Ks; monoton p keys;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   264
ev # evs:tr p |] ==> keys R' s' n evs <= Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   265
by (unfold monoton_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   266
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   267
subsection{*guardedness theorem*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   268
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   269
lemma Guard_tr [rule_format]: "[| evs:tr p; has_only_Says' p;
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   270
preserv p keys n Ks; monoton p keys; Guard n Ks (initState Spy) |] ==>
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   271
safe Ks (spies evs) --> fresh p R' s' n Ks evs --> keys R' s' n evs <= Ks -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   272
Guard n Ks (spies evs)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   273
apply (erule tr.induct)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   274
(* Nil *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   275
apply simp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   276
(* Fake *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   277
apply (clarify, drule freshD, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   278
apply (case_tac evs2)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   279
(* evs2 = [] *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   280
apply (frule has_only_Says'D, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   281
apply (clarsimp, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   282
(* evs2 = aa # list *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   283
apply (clarsimp, rule conjI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   284
apply (blast dest: safe_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   285
(* X:guard n Ks *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   286
apply (rule in_synth_Guard, simp, rule Guard_analz)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   287
apply (blast dest: safe_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   288
apply (drule safe_insert, simp add: safe_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   289
(* Proto *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   290
apply (clarify, drule freshD, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   291
apply (case_tac evs2)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   292
(* evs2 = [] *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   293
apply (frule has_only_Says'D, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   294
apply (frule_tac R=R' in has_only_Says'D, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   295
apply (case_tac R', clarsimp, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   296
(* evs2 = ab # list *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   297
apply (frule has_only_Says'D, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   298
apply (clarsimp, rule conjI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   299
apply (drule Proto, simp+, blast dest: safe_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   300
(* apm s X:guard n Ks *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   301
apply (frule Proto, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   302
apply (erule preservD', simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   303
apply (blast dest: safe_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   304
apply (blast dest: safe_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   305
by (blast, simp, simp, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   306
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   307
subsection{*useful properties for guardedness*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   308
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   309
lemma newn_neq_used: "[| Nonce n:used evs; ok evs R s; k:newn R |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   310
==> n ~= nonce s k"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   311
by (auto simp: ok_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   312
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   313
lemma ok_Guard: "[| ok evs R s; Guard n Ks (spies evs); x:fst R; is_Says x |]
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   314
==> apm s (msg x):parts (spies evs) & apm s (msg x):guard n Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   315
apply (unfold ok_def is_Says_def, clarify)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   316
apply (drule_tac x="Says A B X" in spec, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   317
by (drule Says_imp_spies, auto intro: parts_parts)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   318
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   319
lemma ok_parts_not_new: "[| Y:parts (spies evs); Nonce (nonce s n):parts {Y};
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   320
ok evs R s |] ==> n ~:newn R"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   321
by (auto simp: ok_def dest: not_used_not_spied parts_parts)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   322
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   323
subsection{*unicity*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   324
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   325
constdefs uniq :: "proto => secfun => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   326
"uniq p secret == ALL evs R R' n n' Ks s s'. R:p --> R':p -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   327
n:newn R --> n':newn R' --> nonce s n = nonce s' n' -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   328
Nonce (nonce s n):parts {apm' s R} --> Nonce (nonce s n):parts {apm' s' R'} -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   329
apm' s R:guard (nonce s n) Ks --> apm' s' R':guard (nonce s n) Ks -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   330
evs:tr p --> Nonce (nonce s n) ~:analz (spies evs) -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   331
secret R n s Ks:parts (spies evs) --> secret R' n' s' Ks:parts (spies evs) -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   332
secret R n s Ks = secret R' n' s' Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   333
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   334
lemma uniqD: "[| uniq p secret; evs: tr p; R:p; R':p; n:newn R; n':newn R';
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   335
nonce s n = nonce s' n'; Nonce (nonce s n) ~:analz (spies evs);
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   336
Nonce (nonce s n):parts {apm' s R}; Nonce (nonce s n):parts {apm' s' R'};
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   337
secret R n s Ks:parts (spies evs); secret R' n' s' Ks:parts (spies evs);
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   338
apm' s R:guard (nonce s n) Ks; apm' s' R':guard (nonce s n) Ks |] ==>
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   339
secret R n s Ks = secret R' n' s' Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   340
by (unfold uniq_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   341
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   342
constdefs ord :: "proto => (rule => rule => bool) => bool"
22426
1c38ca2496c4 resolved name clashes
haftmann
parents: 21404
diff changeset
   343
"ord p inff == ALL R R'. R:p --> R':p --> ~ inff R R' --> inff R' R"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   344
22426
1c38ca2496c4 resolved name clashes
haftmann
parents: 21404
diff changeset
   345
lemma ordD: "[| ord p inff; ~ inff R R'; R:p; R':p |] ==> inff R' R"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   346
by (unfold ord_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   347
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   348
constdefs uniq' :: "proto => (rule => rule => bool) => secfun => bool"
22426
1c38ca2496c4 resolved name clashes
haftmann
parents: 21404
diff changeset
   349
"uniq' p inff secret == ALL evs R R' n n' Ks s s'. R:p --> R':p -->
1c38ca2496c4 resolved name clashes
haftmann
parents: 21404
diff changeset
   350
inff R R' --> n:newn R --> n':newn R' --> nonce s n = nonce s' n' -->
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   351
Nonce (nonce s n):parts {apm' s R} --> Nonce (nonce s n):parts {apm' s' R'} -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   352
apm' s R:guard (nonce s n) Ks --> apm' s' R':guard (nonce s n) Ks -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   353
evs:tr p --> Nonce (nonce s n) ~:analz (spies evs) -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   354
secret R n s Ks:parts (spies evs) --> secret R' n' s' Ks:parts (spies evs) -->
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   355
secret R n s Ks = secret R' n' s' Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   356
22426
1c38ca2496c4 resolved name clashes
haftmann
parents: 21404
diff changeset
   357
lemma uniq'D: "[| uniq' p inff secret; evs: tr p; inff R R'; R:p; R':p; n:newn R;
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   358
n':newn R'; nonce s n = nonce s' n'; Nonce (nonce s n) ~:analz (spies evs);
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   359
Nonce (nonce s n):parts {apm' s R}; Nonce (nonce s n):parts {apm' s' R'};
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   360
secret R n s Ks:parts (spies evs); secret R' n' s' Ks:parts (spies evs);
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   361
apm' s R:guard (nonce s n) Ks; apm' s' R':guard (nonce s n) Ks |] ==>
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   362
secret R n s Ks = secret R' n' s' Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   363
by (unfold uniq'_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   364
22426
1c38ca2496c4 resolved name clashes
haftmann
parents: 21404
diff changeset
   365
lemma uniq'_imp_uniq: "[| uniq' p inff secret; ord p inff |] ==> uniq p secret"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   366
apply (unfold uniq_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   367
apply (rule allI)+
22426
1c38ca2496c4 resolved name clashes
haftmann
parents: 21404
diff changeset
   368
apply (case_tac "inff R R'")
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   369
apply (blast dest: uniq'D)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   370
by (auto dest: ordD uniq'D intro: sym)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   371
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   372
subsection{*Needham-Schroeder-Lowe*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   373
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   374
constdefs
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   375
a :: agent "a == Friend 0"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   376
b :: agent "b == Friend 1"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   377
a' :: agent "a' == Friend 2"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   378
b' :: agent "b' == Friend 3"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   379
Na :: nat "Na == 0"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   380
Nb :: nat "Nb == 1"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   381
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   382
consts
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   383
ns :: proto
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   384
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   385
abbreviation
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   386
  ns1 :: rule where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   387
  "ns1 == ({}, Says a b (Crypt (pubK b) {|Nonce Na, Agent a|}))"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   388
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   389
abbreviation
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   390
  ns2 :: rule where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   391
  "ns2 == ({Says a' b (Crypt (pubK b) {|Nonce Na, Agent a|})},
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   392
    Says b a (Crypt (pubK a) {|Nonce Na, Nonce Nb, Agent b|}))"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   393
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   394
abbreviation
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   395
  ns3 :: rule where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   396
  "ns3 == ({Says a b (Crypt (pubK b) {|Nonce Na, Agent a|}),
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   397
    Says b' a (Crypt (pubK a) {|Nonce Na, Nonce Nb, Agent b|})},
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   398
    Says a b (Crypt (pubK b) (Nonce Nb)))"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   399
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   400
inductive ns intros
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   401
[iff]: "ns1:ns"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   402
[iff]: "ns2:ns"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   403
[iff]: "ns3:ns"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   404
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   405
abbreviation (input)
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   406
  ns3a :: event where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   407
  "ns3a == Says a b (Crypt (pubK b) {|Nonce Na, Agent a|})"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   408
21404
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   409
abbreviation (input)
eb85850d3eb7 more robust syntax for definition/abbreviation/notation;
wenzelm
parents: 20768
diff changeset
   410
  ns3b :: event where
20768
1d478c2d621f replaced syntax/translations by abbreviation;
wenzelm
parents: 16417
diff changeset
   411
  "ns3b == Says b' a (Crypt (pubK a) {|Nonce Na, Nonce Nb, Agent b|})"
13508
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   412
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   413
constdefs keys :: "keyfun"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   414
"keys R' s' n evs == {priK' s' a, priK' s' b}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   415
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   416
lemma "monoton ns keys"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   417
by (simp add: keys_def monoton_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   418
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   419
constdefs secret :: "secfun"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   420
"secret R n s Ks ==
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   421
(if R=ns1 then apm s (Crypt (pubK b) {|Nonce Na, Agent a|})
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   422
else if R=ns2 then apm s (Crypt (pubK a) {|Nonce Na, Nonce Nb, Agent b|})
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   423
else Number 0)"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   424
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   425
constdefs inf :: "rule => rule => bool"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   426
"inf R R' == (R=ns1 | (R=ns2 & R'~=ns1) | (R=ns3 & R'=ns3))"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   427
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   428
lemma inf_is_ord [iff]: "ord ns inf"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   429
apply (unfold ord_def inf_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   430
apply (rule allI)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   431
by (rule impI, erule ns.cases, simp_all)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   432
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   433
subsection{*general properties*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   434
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   435
lemma ns_has_only_Says' [iff]: "has_only_Says' ns"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   436
apply (unfold has_only_Says'_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   437
apply (rule allI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   438
by (erule ns.cases, auto)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   439
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   440
lemma newn_ns1 [iff]: "newn ns1 = {Na}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   441
by (simp add: newn_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   442
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   443
lemma newn_ns2 [iff]: "newn ns2 = {Nb}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   444
by (auto simp: newn_def Na_def Nb_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   445
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   446
lemma newn_ns3 [iff]: "newn ns3 = {}"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   447
by (auto simp: newn_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   448
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   449
lemma ns_wdef [iff]: "wdef ns"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   450
by (auto simp: wdef_def elim: ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   451
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   452
subsection{*guardedness for NSL*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   453
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   454
lemma "uniq ns secret ==> preserv ns keys n Ks"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   455
apply (unfold preserv_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   456
apply (rule allI)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   457
apply (rule impI, rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   458
apply (erule fresh_ruleD, simp, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   459
apply (rule allI)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   460
apply (rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   461
apply (erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   462
(* fresh with NS1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   463
apply (rule impI, rule impI, rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   464
apply (erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   465
(* NS1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   466
apply clarsimp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   467
apply (frule newn_neq_used, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   468
apply (rule No_Nonce, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   469
(* NS2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   470
apply clarsimp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   471
apply (frule newn_neq_used, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   472
apply (case_tac "nonce sa Na = nonce s Na")
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   473
apply (frule Guard_safe, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   474
apply (frule Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   475
apply (frule ok_Guard, simp, simp, simp, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   476
apply (frule_tac K="pubK' s b" in Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   477
apply (frule_tac R=ns1 and R'=ns1 and Ks=Ks and s=sa and s'=s in uniqD, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   478
apply (simp add: secret_def, simp add: secret_def, force, force)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   479
apply (simp add: secret_def keys_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   480
apply (rule No_Nonce, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   481
(* NS3 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   482
apply clarsimp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   483
apply (case_tac "nonce sa Na = nonce s Nb")
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   484
apply (frule Guard_safe, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   485
apply (frule Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   486
apply (frule_tac x=ns3b in ok_Guard, simp, simp, simp, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   487
apply (frule_tac K="pubK' s a" in Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   488
apply (frule_tac R=ns1 and R'=ns2 and Ks=Ks and s=sa and s'=s in uniqD, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   489
apply (simp add: secret_def, simp add: secret_def, force, force)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   490
apply (simp add: secret_def, rule No_Nonce, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   491
(* fresh with NS2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   492
apply (rule impI, rule impI, rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   493
apply (erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   494
(* NS1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   495
apply clarsimp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   496
apply (frule newn_neq_used, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   497
apply (rule No_Nonce, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   498
(* NS2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   499
apply clarsimp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   500
apply (frule newn_neq_used, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   501
apply (case_tac "nonce sa Nb = nonce s Na")
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   502
apply (frule Guard_safe, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   503
apply (frule Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   504
apply (frule ok_Guard, simp, simp, simp, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   505
apply (frule_tac K="pubK' s b" in Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   506
apply (frule_tac R=ns2 and R'=ns1 and Ks=Ks and s=sa and s'=s in uniqD, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   507
apply (simp add: secret_def, simp add: secret_def, force, force)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   508
apply (simp add: secret_def, rule No_Nonce, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   509
(* NS3 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   510
apply clarsimp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   511
apply (case_tac "nonce sa Nb = nonce s Nb")
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   512
apply (frule Guard_safe, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   513
apply (frule Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   514
apply (frule_tac x=ns3b in ok_Guard, simp, simp, simp, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   515
apply (frule_tac K="pubK' s a" in Crypt_guard_invKey, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   516
apply (frule_tac R=ns2 and R'=ns2 and Ks=Ks and s=sa and s'=s in uniqD, simp+)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   517
apply (simp add: secret_def, simp add: secret_def, force, force)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   518
apply (simp add: secret_def keys_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   519
apply (rule No_Nonce, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   520
(* fresh with NS3 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   521
by simp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   522
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   523
subsection{*unicity for NSL*}
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   524
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   525
lemma "uniq' ns inf secret"
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   526
apply (unfold uniq'_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   527
apply (rule allI)+
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   528
apply (rule impI, erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   529
(* R = ns1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   530
apply (rule impI, erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   531
(* R' = ns1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   532
apply (rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   533
apply (rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   534
apply (rule impI, erule tr.induct)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   535
(* Nil *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   536
apply (simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   537
(* Fake *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   538
apply (clarify, simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   539
apply (drule notin_analz_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   540
apply (drule Crypt_insert_synth, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   541
apply (drule Crypt_insert_synth, simp, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   542
(* Proto *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   543
apply (erule_tac P="ok evsa Ra sa" in rev_mp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   544
apply (erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   545
(* ns1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   546
apply (clarify, simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   547
apply (erule disjE, erule disjE, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   548
apply (drule ok_parts_not_new, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   549
apply (clarify, drule ok_parts_not_new, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   550
(* ns2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   551
apply (simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   552
(* ns3 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   553
apply (simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   554
(* R' = ns2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   555
apply (rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   556
apply (rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   557
apply (rule impI, erule tr.induct)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   558
(* Nil *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   559
apply (simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   560
(* Fake *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   561
apply (clarify, simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   562
apply (drule notin_analz_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   563
apply (drule Crypt_insert_synth, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   564
apply (drule_tac n="nonce s' Nb" in Crypt_insert_synth, simp, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   565
(* Proto *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   566
apply (erule_tac P="ok evsa Ra sa" in rev_mp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   567
apply (erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   568
(* ns1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   569
apply (clarify, simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   570
apply (drule_tac s=sa and n=Na in ok_parts_not_new, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   571
(* ns2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   572
apply (clarify, simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   573
apply (drule_tac s=sa and n=Nb in ok_parts_not_new, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   574
(* ns3 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   575
apply (simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   576
(* R' = ns3 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   577
apply simp
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   578
(* R = ns2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   579
apply (rule impI, erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   580
(* R' = ns1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   581
apply (simp only: inf_def, blast)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   582
(* R' = ns2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   583
apply (rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   584
apply (rule impI, rule impI, rule impI, rule impI)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   585
apply (rule impI, erule tr.induct)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   586
(* Nil *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   587
apply (simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   588
(* Fake *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   589
apply (clarify, simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   590
apply (drule notin_analz_insert)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   591
apply (drule_tac n="nonce s' Nb" in Crypt_insert_synth, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   592
apply (drule_tac n="nonce s' Nb" in Crypt_insert_synth, simp, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   593
(* Proto *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   594
apply (erule_tac P="ok evsa Ra sa" in rev_mp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   595
apply (erule ns.cases)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   596
(* ns1 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   597
apply (simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   598
(* ns2 *)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   599
apply (clarify, simp add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   600
apply (erule disjE, erule disjE, clarsimp, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   601
apply (drule_tac s=sa and n=Nb in ok_parts_not_new, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   602
apply (erule disjE, clarsimp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   603
apply (drule_tac s=sa and n=Nb in ok_parts_not_new, simp, simp, simp)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   604
by (simp_all add: secret_def)
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   605
890d736b93a5 Frederic Blanqui's new "guard" examples
paulson
parents:
diff changeset
   606
end