Nuprl Lemma : ses-legal-thread-has*-signature

s:SES
  (SecurityAxioms
   (∀es:EO+(Info). ∀A:Id. ∀thr:Thread.
        ((Legal(thr)@A ∧ noncelike-signatures(s;es;thr))
         (∀sg:E(Sign). ∀e:Act.
              (e ∈ thr
               has* signature(sg)
               (∃e':E. ((e' <loc e) ∧ Action(e') ∧ e' has* signature(sg) ∧ e' ∈ thr)) ∨ (e sg ∈ E) 
                 supposing ∀e':E
                             ((e' < e)
                              Action(e')
                              e' has* signature(sg)
                              ((loc(e') A ∈ Id) ∧ (¬↑e' ∈b Send))))))))


Proof




Definitions occuring in Statement :  noncelike-signatures: noncelike-signatures(s;es;thr) ses-legal-thread: Legal(thr)@A ses-thread-member: e ∈ thr ses-thread: Thread ses-axioms: SecurityAxioms event-has*: has* a ses-act: Act ses-action: Action(e) ses-sig: signature(e) ses-sign: Sign ses-send: Send ses-info: Info security-event-structure: SES es-E-interface: E(X) in-eclass: e ∈b X event-ordering+: EO+(Info) es-locl: (e <loc e') es-causl: (e < e') es-loc: loc(e) es-E: E Id: Id assert: b uimplies: supposing a all: x:A. B[x] exists: x:A. B[x] not: ¬A implies:  Q or: P ∨ Q and: P ∧ Q equal: t ∈ T
Lemmas :  sq_stable_from_decidable ses-action_wf decidable__ses-action assert_wf in-eclass_wf ses-send_wf es-interface-subtype_rel2 es-E_wf event-ordering+_subtype top_wf subtype_top sdata_wf event-has*_wf ses-sig_wf es-causl_wf all_wf es-loc_wf not_wf ses-thread-member_wf ses-act_wf es-E-interface_wf ses-sign_wf ses-legal-thread_wf noncelike-signatures_wf ses-thread_wf Id_wf event-ordering+_wf ses-info_wf ses-axioms_wf security-event-structure_wf es-causl-swellfnd less_than_transitivity1 less_than_irreflexivity int_seg_wf decidable__equal_int subtype_rel-int_seg false_wf le_weakening subtract_wf int_seg_properties le_wf nat_wf zero-le-nat lelt_wf event-has_wf infix_ap_wf rel_exp_wf ses-info-flow_wf le_weakening2 decidable__le not-le-2 less-iff-le condition-implies-le minus-one-mul zero-add minus-add minus-minus add-associates add-swap add-commutes add_functionality_wrt_le add-zero le-add-cancel or_wf exists_wf es-locl_wf equal_wf set_wf less_than_wf primrec-wf2 es-le_wf int_seg_subtype-nat decidable__lt not-equal-2 le-add-cancel-alt sq_stable__le add-mul-special zero-mul ses-legal-thread-has-atom event-has*-iff subtype_rel_dep_function member-useable-atoms ses-rcv_wf es-causl_transitivity2 es-causle_weakening_locl ses-act-has-atom ses-encrypt_wf encryption-key_wf ses-decrypt_wf ses-verify_wf ses-new_wf bool_wf eqtt_to_assert l_member_wf squash_wf true_wf list_wf sdata-atoms_wf iff_weakening_equal ses-useable-atoms_wf eqff_to_assert assert_elim bfalse_wf and_wf bnot_wf btrue_neq_bfalse bool_cases_sqequal subtype_base_sq bool_subtype_base ses-legal-thread-decrypt ses-used-atoms_wf decidable__or decidable__l_member decidable__atom_equal_1 member-used-atoms encryption-key-atoms_wf ses-encryption-key_wf ses-signed_wf ses-verify-sig_wf ses-verify-signed_wf ses-cipher_wf ses-decryption-key_wf eclass-val_wf es-causl_weakening es-locl_transitivity2 es-le_weakening sq_stable__l_member ses-crypt_wf ses-decrypted_wf rel_exp_iff rel_star_wf class-value-has_wf free-from-atom_wf event-has*-transitive-encrypt atom1_subtype_base ses-cipher-unique ses-flow-axiom-ordering int_subtype_base event-has_functionality member_wf ses-info-flow-exp_functionality le-add-cancel2 decidable__es-E-equal es-le-self

Latex:
\mforall{}s:SES
    (SecurityAxioms
    {}\mRightarrow{}  (\mforall{}es:EO+(Info).  \mforall{}A:Id.  \mforall{}thr:Thread.
                ((Legal(thr)@A  \mwedge{}  noncelike-signatures(s;es;thr))
                {}\mRightarrow{}  (\mforall{}sg:E(Sign).  \mforall{}e:Act.
                            (e  \mmember{}  thr
                            {}\mRightarrow{}  e  has*  signature(sg)
                            {}\mRightarrow{}  (\mexists{}e':E.  ((e'  <loc  e)  \mwedge{}  Action(e')  \mwedge{}  e'  has*  signature(sg)  \mwedge{}  e'  \mmember{}  thr))  \mvee{}  (e  =  sg) 
                                  supposing  \mforall{}e':E
                                                          ((e'  <  e)
                                                          {}\mRightarrow{}  Action(e')
                                                          {}\mRightarrow{}  e'  has*  signature(sg)
                                                          {}\mRightarrow{}  ((loc(e')  =  A)  \mwedge{}  (\mneg{}\muparrow{}e'  \mmember{}\msubb{}  Send))))))))



Date html generated: 2015_07_23-PM-00_13_30
Last ObjectModification: 2015_02_04-PM-03_50_21

Home Index