Formally and Practically Relating the CK, CK-HMQV, and eCK Security Models for Authenticated Key Exchange
Cas J. F. Cremers · 2009
Many recent protocols for Authenticated Key Exchange have been proven correct in the CK, CK-HMQV, or eCK security models. The exact relation between the security models, and hence between the security guarantees provided by the protocols, is unclear. We show that the CK, CK-HMQV, and eCK security models are formally incomparable for a number of reasons. Second, we show that these models are also practically incomparable, by providing for each model attacks on existing protocols that are not considered by the other models. Our analysis exposes many subtleties of these models, some of which can even be generalized to reveal shortcomings in security proofs in related AKE security models.