src/HOL/Predicate_Compile_Examples/Hotel_Example.thy
author nipkow
Mon, 13 Sep 2010 11:13:15 +0200
changeset 39302 d7728f65b353
parent 39200 bb93713b0925
child 39463 7ce0ed8dc4d6
permissions -rw-r--r--
renamed lemmas: ext_iff -> fun_eq_iff, set_ext_iff -> set_eq_iff, set_ext -> set_eqI
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     1
theory Hotel_Example
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     2
imports Predicate_Compile_Alternative_Defs Code_Prolog
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     3
begin
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     4
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     5
datatype guest = Guest0 | Guest1
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     6
datatype key = Key0 | Key1 | Key2 | Key3
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     7
datatype room = Room0
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     8
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
     9
types card = "key * key"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    10
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    11
datatype event =
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    12
   Check_in guest room card | Enter guest room card | Exit guest room
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    13
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    14
definition initk :: "room \<Rightarrow> key"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    15
  where "initk = (%r. Key0)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    16
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    17
declare initk_def[code_pred_def, code]
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    18
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    19
primrec owns :: "event list \<Rightarrow> room \<Rightarrow> guest option"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    20
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    21
  "owns [] r = None"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    22
| "owns (e#s) r = (case e of
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    23
    Check_in g r' c \<Rightarrow> if r' = r then Some g else owns s r |
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    24
    Enter g r' c \<Rightarrow> owns s r |
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    25
    Exit g r' \<Rightarrow> owns s r)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    26
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    27
primrec currk :: "event list \<Rightarrow> room \<Rightarrow> key"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    28
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    29
  "currk [] r = initk r"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    30
| "currk (e#s) r = (let k = currk s r in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    31
    case e of Check_in g r' (k1, k2) \<Rightarrow> if r' = r then k2 else k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    32
            | Enter g r' c \<Rightarrow> k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    33
            | Exit g r \<Rightarrow> k)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    34
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    35
primrec issued :: "event list \<Rightarrow> key set"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    36
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    37
  "issued [] = range initk"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    38
| "issued (e#s) = issued s \<union>
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    39
  (case e of Check_in g r (k1, k2) \<Rightarrow> {k2} | Enter g r c \<Rightarrow> {} | Exit g r \<Rightarrow> {})"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    40
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    41
primrec cards :: "event list \<Rightarrow> guest \<Rightarrow> card set"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    42
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    43
  "cards [] g = {}"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    44
| "cards (e#s) g = (let C = cards s g in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    45
                    case e of Check_in g' r c \<Rightarrow> if g' = g then insert c C
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    46
                                                else C
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    47
                            | Enter g r c \<Rightarrow> C
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    48
                            | Exit g r \<Rightarrow> C)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    49
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    50
primrec roomk :: "event list \<Rightarrow> room \<Rightarrow> key"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    51
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    52
  "roomk [] r = initk r"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    53
| "roomk (e#s) r = (let k = roomk s r in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    54
    case e of Check_in g r' c \<Rightarrow> k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    55
            | Enter g r' (x,y) \<Rightarrow> if r' = r (*& x = k*) then y else k
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    56
            | Exit g r \<Rightarrow> k)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    57
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    58
primrec isin :: "event list \<Rightarrow> room \<Rightarrow> guest set"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    59
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    60
  "isin [] r = {}"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    61
| "isin (e#s) r = (let G = isin s r in
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    62
                 case e of Check_in g r c \<Rightarrow> G
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    63
                 | Enter g r' c \<Rightarrow> if r' = r then {g} \<union> G else G
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    64
                 | Exit g r' \<Rightarrow> if r'=r then G - {g} else G)"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    65
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    66
primrec hotel :: "event list \<Rightarrow> bool"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    67
where
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    68
  "hotel []  = True"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    69
| "hotel (e # s) = (hotel s & (case e of
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    70
  Check_in g r (k,k') \<Rightarrow> k = currk s r \<and> k' \<notin> issued s |
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    71
  Enter g r (k,k') \<Rightarrow> (k,k') : cards s g & (roomk s r : {k, k'}) |
38734
e5508a74b11f changing hotel trace definition; adding simple handling of numerals on natural numbers
bulwahn
parents: 38733
diff changeset
    72
  Exit g r \<Rightarrow> g : isin s r))"
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    73
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    74
lemma issued_nil: "issued [] = {Key0}"
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    75
by (auto simp add: initk_def)
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    76
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    77
lemmas issued_simps[code, code_pred_def] = issued_nil issued.simps(2)
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    78
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    79
declare Let_def[code_pred_inline]
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    80
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    81
lemma [code_pred_inline]: "insert == (%y A x. y = x | A x)"
39302
d7728f65b353 renamed lemmas: ext_iff -> fun_eq_iff, set_ext_iff -> set_eq_iff, set_ext -> set_eqI
nipkow
parents: 39200
diff changeset
    82
by (auto simp add: insert_iff[unfolded mem_def] fun_eq_iff intro!: eq_reflection)
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    83
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    84
lemma [code_pred_inline]: "(op -) == (%A B x. A x \<and> \<not> B x)"
39302
d7728f65b353 renamed lemmas: ext_iff -> fun_eq_iff, set_ext_iff -> set_eq_iff, set_ext -> set_eqI
nipkow
parents: 39200
diff changeset
    85
by (auto simp add: Diff_iff[unfolded mem_def] fun_eq_iff intro!: eq_reflection)
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    86
38950
62578950e748 storing options for prolog code generation in the theory
bulwahn
parents: 38949
diff changeset
    87
setup {* Code_Prolog.map_code_options (K
38949
1afa9e89c885 adapting example files to latest changes
bulwahn
parents: 38734
diff changeset
    88
  {ensure_groundness = true,
1afa9e89c885 adapting example files to latest changes
bulwahn
parents: 38734
diff changeset
    89
  limited_types = [],
1afa9e89c885 adapting example files to latest changes
bulwahn
parents: 38734
diff changeset
    90
  limited_predicates = [],
1afa9e89c885 adapting example files to latest changes
bulwahn
parents: 38734
diff changeset
    91
  replacing = [],
38963
b5d126d7be4b adapting and tuning example theories
bulwahn
parents: 38954
diff changeset
    92
  manual_reorder = [],
39189
d183bf90dabd adapting example files
bulwahn
parents: 38963
diff changeset
    93
  timeout = Time.fromSeconds 10,
38950
62578950e748 storing options for prolog code generation in the theory
bulwahn
parents: 38949
diff changeset
    94
  prolog_system = Code_Prolog.SWI_PROLOG}) *}
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    95
38734
e5508a74b11f changing hotel trace definition; adding simple handling of numerals on natural numbers
bulwahn
parents: 38733
diff changeset
    96
values 40 "{s. hotel s}"
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
    97
38731
2c8a595af43e invocation of values for prolog execution does not require invocation of code_pred anymore
bulwahn
parents: 38730
diff changeset
    98
38733
4b8fd91ea59a added quickcheck generator for prolog generation; first example of counterexample search with prolog for hotel key card system
bulwahn
parents: 38731
diff changeset
    99
setup {* Quickcheck.add_generator ("prolog", Code_Prolog.quickcheck) *}
4b8fd91ea59a added quickcheck generator for prolog generation; first example of counterexample search with prolog for hotel key card system
bulwahn
parents: 38731
diff changeset
   100
4b8fd91ea59a added quickcheck generator for prolog generation; first example of counterexample search with prolog for hotel key card system
bulwahn
parents: 38731
diff changeset
   101
lemma "\<lbrakk> hotel s; g \<in> isin s r \<rbrakk> \<Longrightarrow> owns s r = Some g"
4b8fd91ea59a added quickcheck generator for prolog generation; first example of counterexample search with prolog for hotel key card system
bulwahn
parents: 38731
diff changeset
   102
quickcheck[generator = code, iterations = 100000, report]
38949
1afa9e89c885 adapting example files to latest changes
bulwahn
parents: 38734
diff changeset
   103
quickcheck[generator = prolog, iterations = 1, expect = counterexample]
38733
4b8fd91ea59a added quickcheck generator for prolog generation; first example of counterexample search with prolog for hotel key card system
bulwahn
parents: 38731
diff changeset
   104
oops
4b8fd91ea59a added quickcheck generator for prolog generation; first example of counterexample search with prolog for hotel key card system
bulwahn
parents: 38731
diff changeset
   105
38731
2c8a595af43e invocation of values for prolog execution does not require invocation of code_pred anymore
bulwahn
parents: 38730
diff changeset
   106
38953
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   107
definition no_Check_in :: "event list \<Rightarrow> room \<Rightarrow> bool" where(*>*)
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   108
[code del]: "no_Check_in s r \<equiv> \<not>(\<exists>g c. Check_in g r c \<in> set s)"
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   109
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   110
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   111
definition feels_safe :: "event list \<Rightarrow> room \<Rightarrow> bool"
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   112
where
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   113
  "feels_safe s r = (\<exists>s\<^isub>1 s\<^isub>2 s\<^isub>3 g c c'.
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   114
   s = s\<^isub>3 @ [Enter g r c] @ s\<^isub>2 @ [Check_in g r c'] @ s\<^isub>1 \<and>
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   115
   no_Check_in (s\<^isub>3 @ s\<^isub>2) r \<and> isin (s\<^isub>2 @ [Check_in g r c] @ s\<^isub>1) r = {})"
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   116
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   117
setup {* Code_Prolog.map_code_options (K 
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   118
  {ensure_groundness = true,
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   119
   limited_types = [],
38963
b5d126d7be4b adapting and tuning example theories
bulwahn
parents: 38954
diff changeset
   120
   limited_predicates = [(["hotel"], 5)],
38953
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   121
   replacing = [(("hotel", "limited_hotel"), "quickcheck")],
38963
b5d126d7be4b adapting and tuning example theories
bulwahn
parents: 38954
diff changeset
   122
   manual_reorder = [],
39189
d183bf90dabd adapting example files
bulwahn
parents: 38963
diff changeset
   123
   timeout = Time.fromSeconds 10,
38953
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   124
   prolog_system = Code_Prolog.SWI_PROLOG}) *}
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   125
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   126
lemma
38954
80ce658600b0 changing order of premises generated when flattening functions in premises; adapting example for second attack for hotel key card system
bulwahn
parents: 38953
diff changeset
   127
  "hotel s ==> feels_safe s r ==> g \<in> isin s r ==> owns s r = Some g"
80ce658600b0 changing order of premises generated when flattening functions in premises; adapting example for second attack for hotel key card system
bulwahn
parents: 38953
diff changeset
   128
quickcheck[generator = prolog, iterations = 1, expect = counterexample]
38953
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   129
oops
0c38eb5fc4ca added further hotel key card attack in example file
bulwahn
parents: 38950
diff changeset
   130
38730
5bbdd9a9df62 adding hotel keycard example for prolog generation
bulwahn
parents:
diff changeset
   131
end