On Security Model of One-Round Authenticated Key Exchange
Haibo Tian · 2013
Considering one-round AKE, Cremers and Feltz at ESORICS 2012 defined a security model with perfect forward secrecy (PFS). However, in that model Boyd and and Nieto's general attack about PFS is unworkable. This paper extends their model to capture the general attack and shows that a compiled one-round AKE protocol does not achieve the PFS in the extended model. It suggests to withstand the general attack by extra assumptions.