🤖 AI Summary
This work presents the first three-round authenticated key exchange (AKE) protocol secure in the commitment model without relying on long-term secret key material. Building upon the MT authenticator framework, the authors design dedicated protocols tailored to key agreement (KA) and key encapsulation mechanism (KEM) primitives, respectively, and establish session key security via a game-based proof in the unauthenticated setting. Compared to existing four-round constructions, this approach reduces communication overhead by one round while achieving comparable security guarantees under standard models. The protocol also supports unilateral authentication, thereby offering enhanced efficiency and practicality without compromising security strength.
📝 Abstract
The commitment-based AKE model provides a formal security framework for key exchange protocols that avoid long-term cryptographic material, achieving authentication through a final out-of-band verification of session-derived values. Within this model, secure KA-based and KEM-based protocols were previously constructed via a commitment-based MT compiler, yielding optimized 4-pass protocols. In this work, we show that 3-pass protocols secure under this model exist for both primitives. These protocols are constructed ad hoc, following the core ideas of the commitment-based MT authenticator, and their SK security in the unauthenticated model is proved using the same game-based techniques, achieving bounds of the same form as those previously achieved. The resulting protocols provide one-way authentication in three message exchanges.