Efficient One-round Key Exchange in the Standard Model

Colin Boyd, Yvonne Cliff, Juan M. Gonzalez Nieto, and Kenneth G. Paterson


We consider one-round identity-based key exchange protocols secure in the standard model. The security analysis uses the powerful security model of Canetti and Krawczyk and a natural extension of it to the ID-based setting. It is shown how KEMs can be used in a generic way to obtain two different protocol designs with progressively stronger security guarantees. A detailed analysis of the performance of the protocols is included; surprisingly, when instantiated with specific KEM constructions, the resulting protocols are competitive with the best previous schemes that have proofs only in the random oracle model.

Note: - Fixed definition of session id in Protocol 2 and added some informal discussion on why malleability attacks do not work against protocol 2 in Section 4. - Modified the second part of the proof of Protocol 2 to take into consideration the security of the randomness extractor and expander. - Numerous typos have been corrected.

This is the full version of the paper appearing at ACISP 2008
j gonzaleznieto @ qut edu au
2008-05-07
2008-01-07
