nBased
on a set of inference rules that model a satisfiability relation S sat P
n
nExample: parallel rule
n
nForall i. (Si sat (R precedes T))
n(|||i Si ) sat (R precedes T)
n
nProperties of the
inference system:
nSemiautomatic (invariant needed for recursive
definitions)
nSound and relatively complete
nAll the properties
of the Yahalom protocol seen in previous lecture
can be easily verified using this system (see proofs in the book of Ryan and Schneider)