src/HOL/Auth/Guard/Guard_Yahalom.thy
author wenzelm
Wed, 14 Sep 2005 23:14:57 +0200
changeset 17394 a8c9ed3f9818
child 20768 1d478c2d621f
permissions -rw-r--r--
renamed Guard/NS_Public, Guard/OtwayRees, Guard/Yahalom.thy to avoid clash with plain Auth versions;
wenzelm@17394
     1
(******************************************************************************
wenzelm@17394
     2
date: march 2002
wenzelm@17394
     3
author: Frederic Blanqui
wenzelm@17394
     4
email: blanqui@lri.fr
wenzelm@17394
     5
webpage: http://www.lri.fr/~blanqui/
wenzelm@17394
     6
wenzelm@17394
     7
University of Cambridge, Computer Laboratory
wenzelm@17394
     8
William Gates Building, JJ Thomson Avenue
wenzelm@17394
     9
Cambridge CB3 0FD, United Kingdom
wenzelm@17394
    10
******************************************************************************)
wenzelm@17394
    11
wenzelm@17394
    12
header{*Yahalom Protocol*}
wenzelm@17394
    13
wenzelm@17394
    14
theory Guard_Yahalom imports Guard_Shared begin
wenzelm@17394
    15
wenzelm@17394
    16
subsection{*messages used in the protocol*}
wenzelm@17394
    17
wenzelm@17394
    18
syntax ya1 :: "agent => agent => nat => event"
wenzelm@17394
    19
wenzelm@17394
    20
translations "ya1 A B NA" => "Says A B {|Agent A, Nonce NA|}"
wenzelm@17394
    21
wenzelm@17394
    22
syntax ya1' :: "agent => agent => agent => nat => event"
wenzelm@17394
    23
wenzelm@17394
    24
translations "ya1' A' A B NA" => "Says A' B {|Agent A, Nonce NA|}"
wenzelm@17394
    25
wenzelm@17394
    26
syntax ya2 :: "agent => agent => nat => nat => event"
wenzelm@17394
    27
wenzelm@17394
    28
translations "ya2 A B NA NB"
wenzelm@17394
    29
=> "Says B Server {|Agent B, Ciph B {|Agent A, Nonce NA, Nonce NB|}|}"
wenzelm@17394
    30
wenzelm@17394
    31
syntax ya2' :: "agent => agent => agent => nat => nat => event"
wenzelm@17394
    32
wenzelm@17394
    33
translations "ya2' B' A B NA NB"
wenzelm@17394
    34
=> "Says B' Server {|Agent B, Ciph B {|Agent A, Nonce NA, Nonce NB|}|}"
wenzelm@17394
    35
wenzelm@17394
    36
syntax ya3 :: "agent => agent => nat => nat => key => event"
wenzelm@17394
    37
wenzelm@17394
    38
translations "ya3 A B NA NB K"
wenzelm@17394
    39
=> "Says Server A {|Ciph A {|Agent B, Key K, Nonce NA, Nonce NB|},
wenzelm@17394
    40
                    Ciph B {|Agent A, Key K|}|}"
wenzelm@17394
    41
wenzelm@17394
    42
syntax ya3':: "agent => msg => agent => agent => nat => nat => key => event"
wenzelm@17394
    43
wenzelm@17394
    44
translations "ya3' S Y A B NA NB K"
wenzelm@17394
    45
=> "Says S A {|Ciph A {|Agent B, Key K, Nonce NA, Nonce NB|}, Y|}"
wenzelm@17394
    46
wenzelm@17394
    47
syntax ya4 :: "agent => agent => nat => nat => msg => event"
wenzelm@17394
    48
wenzelm@17394
    49
translations "ya4 A B K NB Y" => "Says A B {|Y, Crypt K (Nonce NB)|}"
wenzelm@17394
    50
wenzelm@17394
    51
syntax ya4' :: "agent => agent => nat => nat => msg => event"
wenzelm@17394
    52
wenzelm@17394
    53
translations "ya4' A' B K NB Y" => "Says A' B {|Y, Crypt K (Nonce NB)|}"
wenzelm@17394
    54
wenzelm@17394
    55
subsection{*definition of the protocol*}
wenzelm@17394
    56
wenzelm@17394
    57
consts ya :: "event list set"
wenzelm@17394
    58
wenzelm@17394
    59
inductive ya
wenzelm@17394
    60
intros
wenzelm@17394
    61
wenzelm@17394
    62
Nil: "[]:ya"
wenzelm@17394
    63
wenzelm@17394
    64
Fake: "[| evs:ya; X:synth (analz (spies evs)) |] ==> Says Spy B X # evs:ya"
wenzelm@17394
    65
wenzelm@17394
    66
YA1: "[| evs1:ya; Nonce NA ~:used evs1 |] ==> ya1 A B NA # evs1:ya"
wenzelm@17394
    67
wenzelm@17394
    68
YA2: "[| evs2:ya; ya1' A' A B NA:set evs2; Nonce NB ~:used evs2 |]
wenzelm@17394
    69
==> ya2 A B NA NB # evs2:ya"
wenzelm@17394
    70
wenzelm@17394
    71
YA3: "[| evs3:ya; ya2' B' A B NA NB:set evs3; Key K ~:used evs3 |]
wenzelm@17394
    72
==> ya3 A B NA NB K # evs3:ya"
wenzelm@17394
    73
wenzelm@17394
    74
YA4: "[| evs4:ya; ya1 A B NA:set evs4; ya3' S Y A B NA NB K:set evs4 |]
wenzelm@17394
    75
==> ya4 A B K NB Y # evs4:ya"
wenzelm@17394
    76
wenzelm@17394
    77
subsection{*declarations for tactics*}
wenzelm@17394
    78
wenzelm@17394
    79
declare knows_Spy_partsEs [elim]
wenzelm@17394
    80
declare Fake_parts_insert [THEN subsetD, dest]
wenzelm@17394
    81
declare initState.simps [simp del]
wenzelm@17394
    82
wenzelm@17394
    83
subsection{*general properties of ya*}
wenzelm@17394
    84
wenzelm@17394
    85
lemma ya_has_no_Gets: "evs:ya ==> ALL A X. Gets A X ~:set evs"
wenzelm@17394
    86
by (erule ya.induct, auto)
wenzelm@17394
    87
wenzelm@17394
    88
lemma ya_is_Gets_correct [iff]: "Gets_correct ya"
wenzelm@17394
    89
by (auto simp: Gets_correct_def dest: ya_has_no_Gets)
wenzelm@17394
    90
wenzelm@17394
    91
lemma ya_is_one_step [iff]: "one_step ya"
wenzelm@17394
    92
by (unfold one_step_def, clarify, ind_cases "ev#evs:ya", auto)
wenzelm@17394
    93
wenzelm@17394
    94
lemma ya_has_only_Says' [rule_format]: "evs:ya ==>
wenzelm@17394
    95
ev:set evs --> (EX A B X. ev=Says A B X)"
wenzelm@17394
    96
by (erule ya.induct, auto)
wenzelm@17394
    97
wenzelm@17394
    98
lemma ya_has_only_Says [iff]: "has_only_Says ya"
wenzelm@17394
    99
by (auto simp: has_only_Says_def dest: ya_has_only_Says')
wenzelm@17394
   100
wenzelm@17394
   101
lemma ya_is_regular [iff]: "regular ya"
wenzelm@17394
   102
apply (simp only: regular_def, clarify)
wenzelm@17394
   103
apply (erule ya.induct, simp_all add: initState.simps knows.simps)
wenzelm@17394
   104
by (auto dest: parts_sub)
wenzelm@17394
   105
wenzelm@17394
   106
subsection{*guardedness of KAB*}
wenzelm@17394
   107
wenzelm@17394
   108
lemma Guard_KAB [rule_format]: "[| evs:ya; A ~:bad; B ~:bad |] ==>
wenzelm@17394
   109
ya3 A B NA NB K:set evs --> GuardK K {shrK A,shrK B} (spies evs)" 
wenzelm@17394
   110
apply (erule ya.induct)
wenzelm@17394
   111
(* Nil *)
wenzelm@17394
   112
apply simp_all
wenzelm@17394
   113
(* Fake *)
wenzelm@17394
   114
apply (clarify, erule in_synth_GuardK, erule GuardK_analz, simp)
wenzelm@17394
   115
(* YA1 *)
wenzelm@17394
   116
(* YA2 *)
wenzelm@17394
   117
apply safe
wenzelm@17394
   118
apply (blast dest: Says_imp_spies)
wenzelm@17394
   119
(* YA3 *)
wenzelm@17394
   120
apply blast
wenzelm@17394
   121
apply (drule_tac A=Server in Key_neq, simp+, rule No_Key, simp)
wenzelm@17394
   122
apply (drule_tac A=Server in Key_neq, simp+, rule No_Key, simp)
wenzelm@17394
   123
(* YA4 *)
wenzelm@17394
   124
apply (blast dest: Says_imp_spies in_GuardK_kparts)
wenzelm@17394
   125
by blast
wenzelm@17394
   126
wenzelm@17394
   127
subsection{*session keys are not symmetric keys*}
wenzelm@17394
   128
wenzelm@17394
   129
lemma KAB_isnt_shrK [rule_format]: "evs:ya ==>
wenzelm@17394
   130
ya3 A B NA NB K:set evs --> K ~:range shrK"
wenzelm@17394
   131
by (erule ya.induct, auto)
wenzelm@17394
   132
wenzelm@17394
   133
lemma ya3_shrK: "evs:ya ==> ya3 A B NA NB (shrK C) ~:set evs"
wenzelm@17394
   134
by (blast dest: KAB_isnt_shrK)
wenzelm@17394
   135
wenzelm@17394
   136
subsection{*ya2' implies ya1'*}
wenzelm@17394
   137
wenzelm@17394
   138
lemma ya2'_parts_imp_ya1'_parts [rule_format]:
wenzelm@17394
   139
     "[| evs:ya; B ~:bad |] ==>
wenzelm@17394
   140
      Ciph B {|Agent A, Nonce NA, Nonce NB|}:parts (spies evs) -->
wenzelm@17394
   141
      {|Agent A, Nonce NA|}:spies evs"
wenzelm@17394
   142
by (erule ya.induct, auto dest: Says_imp_spies intro: parts_parts)
wenzelm@17394
   143
wenzelm@17394
   144
lemma ya2'_imp_ya1'_parts: "[| ya2' B' A B NA NB:set evs; evs:ya; B ~:bad |]
wenzelm@17394
   145
==> {|Agent A, Nonce NA|}:spies evs"
wenzelm@17394
   146
by (blast dest: Says_imp_spies ya2'_parts_imp_ya1'_parts)
wenzelm@17394
   147
wenzelm@17394
   148
subsection{*uniqueness of NB*}
wenzelm@17394
   149
wenzelm@17394
   150
lemma NB_is_uniq_in_ya2'_parts [rule_format]: "[| evs:ya; B ~:bad; B' ~:bad |] ==>
wenzelm@17394
   151
Ciph B {|Agent A, Nonce NA, Nonce NB|}:parts (spies evs) -->
wenzelm@17394
   152
Ciph B' {|Agent A', Nonce NA', Nonce NB|}:parts (spies evs) -->
wenzelm@17394
   153
A=A' & B=B' & NA=NA'"
wenzelm@17394
   154
apply (erule ya.induct, simp_all, clarify)
wenzelm@17394
   155
apply (drule Crypt_synth_insert, simp+)
wenzelm@17394
   156
apply (drule Crypt_synth_insert, simp+, safe)
wenzelm@17394
   157
apply (drule not_used_parts_false, simp+)+
wenzelm@17394
   158
by (drule Says_not_parts, simp+)+
wenzelm@17394
   159
wenzelm@17394
   160
lemma NB_is_uniq_in_ya2': "[| ya2' C A B NA NB:set evs;
wenzelm@17394
   161
ya2' C' A' B' NA' NB:set evs; evs:ya; B ~:bad; B' ~:bad |]
wenzelm@17394
   162
==> A=A' & B=B' & NA=NA'"
wenzelm@17394
   163
by (drule NB_is_uniq_in_ya2'_parts, auto dest: Says_imp_spies)
wenzelm@17394
   164
wenzelm@17394
   165
subsection{*ya3' implies ya2'*}
wenzelm@17394
   166
wenzelm@17394
   167
lemma ya3'_parts_imp_ya2'_parts [rule_format]: "[| evs:ya; A ~:bad |] ==>
wenzelm@17394
   168
Ciph A {|Agent B, Key K, Nonce NA, Nonce NB|}:parts (spies evs)
wenzelm@17394
   169
--> Ciph B {|Agent A, Nonce NA, Nonce NB|}:parts (spies evs)"
wenzelm@17394
   170
apply (erule ya.induct, simp_all)
wenzelm@17394
   171
apply (clarify, drule Crypt_synth_insert, simp+)
wenzelm@17394
   172
apply (blast intro: parts_sub, blast)
wenzelm@17394
   173
by (auto dest: Says_imp_spies parts_parts)
wenzelm@17394
   174
wenzelm@17394
   175
lemma ya3'_parts_imp_ya2' [rule_format]: "[| evs:ya; A ~:bad |] ==>
wenzelm@17394
   176
Ciph A {|Agent B, Key K, Nonce NA, Nonce NB|}:parts (spies evs)
wenzelm@17394
   177
--> (EX B'. ya2' B' A B NA NB:set evs)"
wenzelm@17394
   178
apply (erule ya.induct, simp_all, safe)
wenzelm@17394
   179
apply (drule Crypt_synth_insert, simp+)
wenzelm@17394
   180
apply (drule Crypt_synth_insert, simp+, blast)
wenzelm@17394
   181
apply blast
wenzelm@17394
   182
apply blast
wenzelm@17394
   183
by (auto dest: Says_imp_spies2 parts_parts)
wenzelm@17394
   184
wenzelm@17394
   185
lemma ya3'_imp_ya2': "[| ya3' S Y A B NA NB K:set evs; evs:ya; A ~:bad |]
wenzelm@17394
   186
==> (EX B'. ya2' B' A B NA NB:set evs)"
wenzelm@17394
   187
by (drule ya3'_parts_imp_ya2', auto dest: Says_imp_spies)
wenzelm@17394
   188
wenzelm@17394
   189
subsection{*ya3' implies ya3*}
wenzelm@17394
   190
wenzelm@17394
   191
lemma ya3'_parts_imp_ya3 [rule_format]: "[| evs:ya; A ~:bad |] ==>
wenzelm@17394
   192
Ciph A {|Agent B, Key K, Nonce NA, Nonce NB|}:parts(spies evs)
wenzelm@17394
   193
--> ya3 A B NA NB K:set evs"
wenzelm@17394
   194
apply (erule ya.induct, simp_all, safe)
wenzelm@17394
   195
apply (drule Crypt_synth_insert, simp+)
wenzelm@17394
   196
by (blast dest: Says_imp_spies2 parts_parts)
wenzelm@17394
   197
wenzelm@17394
   198
lemma ya3'_imp_ya3: "[| ya3' S Y A B NA NB K:set evs; evs:ya; A ~:bad |]
wenzelm@17394
   199
==> ya3 A B NA NB K:set evs"
wenzelm@17394
   200
by (blast dest: Says_imp_spies ya3'_parts_imp_ya3)
wenzelm@17394
   201
wenzelm@17394
   202
subsection{*guardedness of NB*}
wenzelm@17394
   203
wenzelm@17394
   204
constdefs ya_keys :: "agent => agent => nat => nat => event list => key set"
wenzelm@17394
   205
"ya_keys A B NA NB evs == {shrK A,shrK B} Un {K. ya3 A B NA NB K:set evs}"
wenzelm@17394
   206
wenzelm@17394
   207
lemma Guard_NB [rule_format]: "[| evs:ya; A ~:bad; B ~:bad |] ==>
wenzelm@17394
   208
ya2 A B NA NB:set evs --> Guard NB (ya_keys A B NA NB evs) (spies evs)"
wenzelm@17394
   209
apply (erule ya.induct)
wenzelm@17394
   210
(* Nil *)
wenzelm@17394
   211
apply (simp_all add: ya_keys_def)
wenzelm@17394
   212
(* Fake *)
wenzelm@17394
   213
apply safe
wenzelm@17394
   214
apply (erule in_synth_Guard, erule Guard_analz, simp, clarify)
wenzelm@17394
   215
apply (frule_tac B=B in Guard_KAB, simp+)
wenzelm@17394
   216
apply (drule_tac p=ya in GuardK_Key_analz, simp+)
wenzelm@17394
   217
apply (blast dest: KAB_isnt_shrK, simp)
wenzelm@17394
   218
(* YA1 *)
wenzelm@17394
   219
apply (drule_tac n=NB in Nonce_neq, simp+, rule No_Nonce, simp)
wenzelm@17394
   220
(* YA2 *)
wenzelm@17394
   221
apply blast
wenzelm@17394
   222
apply (drule Says_imp_spies)
wenzelm@17394
   223
apply (drule_tac n=NB in Nonce_neq, simp+)
wenzelm@17394
   224
apply (drule_tac n'=NAa in in_Guard_kparts_neq, simp+)
wenzelm@17394
   225
apply (rule No_Nonce, simp)
wenzelm@17394
   226
(* YA3 *)
wenzelm@17394
   227
apply (rule Guard_extand, simp, blast)
wenzelm@17394
   228
apply (case_tac "NAa=NB", clarify)
wenzelm@17394
   229
apply (frule Says_imp_spies)
wenzelm@17394
   230
apply (frule in_Guard_kparts_Crypt, simp+, blast, simp+)
wenzelm@17394
   231
apply (frule_tac A=A and B=B and NA=NA and NB=NB and C=Ba in ya3_shrK, simp)
wenzelm@17394
   232
apply (drule ya2'_imp_ya1'_parts, simp, blast, blast)
wenzelm@17394
   233
apply (case_tac "NBa=NB", clarify)
wenzelm@17394
   234
apply (frule Says_imp_spies)
wenzelm@17394
   235
apply (frule in_Guard_kparts_Crypt, simp+, blast, simp+)
wenzelm@17394
   236
apply (frule_tac A=A and B=B and NA=NA and NB=NB and C=Ba in ya3_shrK, simp)
wenzelm@17394
   237
apply (drule NB_is_uniq_in_ya2', simp+, blast, simp+)
wenzelm@17394
   238
apply (simp add: No_Nonce, blast)
wenzelm@17394
   239
(* YA4 *)
wenzelm@17394
   240
apply (blast dest: Says_imp_spies)
wenzelm@17394
   241
apply (case_tac "NBa=NB", clarify)
wenzelm@17394
   242
apply (frule_tac A=S in Says_imp_spies)
wenzelm@17394
   243
apply (frule in_Guard_kparts_Crypt, simp+)
wenzelm@17394
   244
apply (blast dest: Says_imp_spies)
wenzelm@17394
   245
apply (case_tac "NBa=NB", clarify)
wenzelm@17394
   246
apply (frule_tac A=S in Says_imp_spies)
wenzelm@17394
   247
apply (frule in_Guard_kparts_Crypt, simp+, blast, simp+)
wenzelm@17394
   248
apply (frule_tac A=A and B=B and NA=NA and NB=NB and C=Aa in ya3_shrK, simp)
wenzelm@17394
   249
apply (frule ya3'_imp_ya2', simp+, blast, clarify)
wenzelm@17394
   250
apply (frule_tac A=B' in Says_imp_spies)
wenzelm@17394
   251
apply (rotate_tac -1, frule in_Guard_kparts_Crypt, simp+, blast, simp+)
wenzelm@17394
   252
apply (frule_tac A=A and B=B and NA=NA and NB=NB and C=Ba in ya3_shrK, simp)
wenzelm@17394
   253
apply (drule NB_is_uniq_in_ya2', simp+, blast, clarify)
wenzelm@17394
   254
apply (drule ya3'_imp_ya3, simp+)
wenzelm@17394
   255
apply (simp add: Guard_Nonce)
wenzelm@17394
   256
apply (simp add: No_Nonce)
wenzelm@17394
   257
done
wenzelm@17394
   258
wenzelm@17394
   259
end