Next Article in Journal
AI-Enabled System-of-Systems Decision Support: BIM-Integrated AI-LCA for Resilient and Sustainable Fiber-Reinforced Façade Design
Previous Article in Journal
Informing Design and Research Concerning Conversationally Explainable AI Systems by Collecting and Distilling Human Explanatory Dialogues
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Revisiting a Proof of Security for the SM2 Key Exchange Protocol

1
College of Information Engineering, Capital Normal University, Beijing 100048, China
2
Key Laboratory of Cyberspace Security, Ministry of Education of China, Zhengzhou 450002, China
3
Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100085, China
*
Author to whom correspondence should be addressed.
Information 2026, 17(2), 124; https://doi.org/10.3390/info17020124
Submission received: 5 January 2026 / Revised: 26 January 2026 / Accepted: 27 January 2026 / Published: 28 January 2026
(This article belongs to the Section Information Security and Privacy)

Abstract

The SM2 key exchange protocol, proposed by the Chinese State Cryptography Administration and adopted as a national standard, is extensively deployed in commercial applications across China. It has also been incorporated by global industrial organizations and integrated into numerous international products, such as TPM. Today, any cryptographic protocol aspiring to become widely adopted and standardized requires a rigorous security proof within a modern security model. Although Yang et al. claimed to have established such a proof for the SM2 key exchange protocol in the Bellare–Rogaway (BR) model, we show that their proof is flawed. Moreover, we present a group representation attack against the SM2 key exchange protocol, illustrating that the protocol cannot be proven secure in any contemporary security models. Our findings thus delineate the security boundary of the SM2 key exchange protocol.

1. Introduction

Authenticated key exchange (AKE) protocols [1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17] lie at the core of secure communications in modern cryptography. They enable two or more parties, who may have had no prior interaction or do not fully trust one another, to establish a shared secret key over an untrusted network. By ensuring both the authenticity of the participants and the confidentiality of the derived key, AKE protocols provide a foundation for numerous security services such as secure channels, password-based authentication, and multi-factor verification. Some research efforts focus on IoT scenarios by proposing lightweight AKE protocols tailored for IoT devices [18,19,20,21,22,23,24,25,26]. Meanwhile, with the advent of quantum computing, other works employ lattice-based methods to construct AKE protocols that resist quantum attacks [27,28,29,30,31].
The SM2 key exchange protocol was proposed by the Chinese State Cryptography Administration and incorporated into the Chinese national standard for the SM2 public key cryptographic algorithm [32,33,34]. This protocol is mandatory in various security applications used by Chinese government agencies and is also extensively adopted in commercial systems throughout China. Moreover, it has achieved international recognition, being standardized in industrial specifications such as Trusted Computing Group’s (TCG) TPM 2.0 specification [35], the Java Card specifications [36], and IETF drafts [37].
Because the applied-cryptography community and standard organizations regard formal analysis as indispensable for any cryptographic protocol aiming to be widely adopted and standardized, a rigorous evaluation of the SM2 key exchange protocol in modern AKE security models is urgently required. In response, Yang et al. [38] analyzed the SM2 key exchange protocol in the Bellare–Rogaway (BR) model [39], claiming that the protocol is secure under the elliptic curve discrete logarithm problem (ECDLP) assumption (Definition 1). However, we find that their proof reduces the compromise of a session key to the knowledge of the long-term and ephemeral private keys of the session’s owner or peer. Their reduction does not cover all the possible ways of computing the session key, and an adversary can compromise a session key through other means. Consequently, their security proof is flawed.
SM2 AKE is widely used and has been standardized by both Chinese cryptographic standards and international standards, demanding rigorous security proofs. However, we have found that a particular computational step (avf) in the SM2 key exchange protocol prevents it from being proven secure under modern AKE models. Therefore, the primary goal of this paper is to use rigorous modern AKE models to explain why the SM2 key exchange protocol cannot be proven. To this end, we propose a group representation attack on the SM2 key exchange protocol. Next, we analyze the elliptic curves employed in the SM2 standard and demonstrate that the specific curves in practical use can resist group representation attacks. Finally, by drawing on all current analyses of the SM2 key exchange protocol, we delineate the security boundary of the SM2 key exchange protocol and offer recommendations for revising the protocol to achieve higher security.

2. Materials and Methods

In this section, we first introduce the SM2 key exchange protocol and then present the Bellare–Rogaway model [39,40] used to analyze this protocol.

2.1. Overview of the SM2 Key Exchange Protocol

The notations used in this paper are summarized in Table 1, and the SM2 key exchange protocol is depicted in Figure 1. We particularly introduce the a v f ( ) function, which is important for our analysis of the protocol: the function receives an elliptic curve point X = ( x , y ) and returns x ¯ = 2 ω + ( x   &   ( 2 ω − 1 ) ) where ω = ⌈ ( ⌈ l o g 2 ( n ) ⌉ ) / 2 ⌉ − 1 and n is the order of the generator of the elliptic curve.
Definition 1.
[ECDLP Assumption] Let E be an elliptic curve defined over a finite field F q . The ECDLP assumption states that, given two randomly chosen points P , Q ∈ E ( F q ) , it is computationally infeasible to compute the integer l satisfying Q = l P .

2.2. Overview of the Bellare-Rogaway Model

The Bellare-Rogaway (BR) model is a well-established framework for analyzing and proving the security of key exchange protocols. By incorporating various types of queries to simulate adversarial capabilities, this model allows researchers to rigorously demonstrate whether a protocol can preserve session key confidentiality in the presence of a powerful attacker. We outline the key components of the BR model below.

2.2.1. Session Instances

In the BR model, each user in the system may initialize multiple session instances to replicate the possibility of concurrent executions in real-world scenarios. Let Π U i j represent the j-th session instance of user U i . Through these instances, an adversary can interact with ongoing or completed protocol runs, testing how well the protocol resists various attacks.

2.2.2. Adversarial Capabilities and Queries

An adversary M is assumed to have broad capabilities, modeled through specific types of queries:
  • Send ( Π U i j , m ) : The adversary transmits a message m to the session instance Π U i j . Upon receiving m, the instance processes it according to the protocol specification and returns the appropriate response. If the instance accepts a session key or terminates, this information is also revealed to M .
  • Reveal ( Π U i j ) : If the session instance Π U i j has already accepted a session key, then this query discloses that session key to M . This models scenarios in which the adversary gains access to ephemeral keys retained in temporary storage.
  • Corrupt ( U i ) : This query grants the adversary the complete internal state of user U i , including long-term private keys and any other sensitive parameters. It simulates situations such as insider threats or covert access to a user’s device.
  • Test ( Π U i j ) : This query is used to distinguish between a real session key and a randomly generated value. If  Π U i j currently holds a legitimate session key (and is considered “fresh,” as explained below), then a random bit b is chosen. If  b = 0 , the adversary receives the actual session key; if b = 1 , the adversary receives a random value of the same length. The adversary’s objective is to guess whether the returned value is real or random.

2.2.3. Partnership and Freshness

Partnership is defined such that two different session instances are considered partners if they hold the same session identifier (SID), agree on each other’s identities, and derive the same session key, without any other instance deriving that same key.
A session instance that has accepted a key is deemed fresh if neither it nor its partner instance has had its key revealed via a Reveal query and if neither of the two users involved has been compromised via a Corrupt query. Intuitively, freshness ensures that the key has not been exposed at either the session level or the user level.

2.2.4. Security Definition

Definition 2.
[Security of AKE] An AKE protocol is called secure if the following properties hold for any polynomial-time adversary M defined above:
1. 
When two uncorrupted parties complete matching sessions, they output the same session key.
2. 
The probability that M guesses the bit b (i.e., outputs b ′ = b ) from the Test query correctly is no more than 1 / 2 plus a negligible fraction, i.e., the advantage of M in distinguishing the real key is quantified as:
A d v M = Pr [ b ′ = b ] ≤ 1 / 2 + ϵ .

3. Results

In this section, we first reveal a flaw in the security analysis of Yang et al. [38], present a concrete group representation attack, and then provide a detailed description of the group representation attack in the BR model, illustrating why the SM2 AKE protocol cannot be rigorously proven secure under modern AKE models.

3.1. A Flaw of Yang’s Security Proof

The security analysis by Yang et al. reduces the compromise of a clean session key to the compromise of the long-term private keys and ephemeral private keys of the related parties. Suppose a party A ^ , whose public key is A = [ a ] G , establishes a session s with B ^ , whose public key is B = [ b ] G , and the session is denoted by ( A ^ , B ^ , X , Y ) where X is the outgoing ephemeral public key and Y the incoming ephemeral public key to the session. The argument of Yang et al. to prove the SM2 key exchange protocol is as follows: if an adversary M computes the session key of s, he must correctly guess the long-term private key a and the ephemeral private key x of the party A ^ or correctly guess the long-term private key b and the ephemeral private key y of the party B ^ . Since M does not know the private key of A, B, X, or Y, he can solve the ECDLP problem if he correctly computes any one of the values of a, b, x, or y.
The argument above is flawed, as  M can compute the session key of s without guessing the long-term or ephemeral private keys. For example, he can learn the session key of s by launching a key-replication attack [10] which forces the establishment of a controlled session s ′ that has the same key as the target session s. In general, a rigorous security proof must show that any method of computing the session key leads to a contradiction of some cryptographic assumption. However, the proof provided by Yang et al. does not meet this requirement because it does not address all possible ways of compromising the session key. In the following section, we construct a group representation attack that allows an adversary to impersonate a legitimate party, establish a session with another party, and compute the corresponding session key. Under modern AKE models, the above session established by the adversary is permitted to be treated as a controlled session, thereby enabling the adversary to obtain the session key of the target session. This indicates that the SM2 key exchange protocol cannot be proven secure in modern AKE models.

3.2. A Brief Group Representation Attack

Here we present a concrete attack against the SM2 key exchange protocol: the group representation attack. This attack shows that the protocol cannot be proven secure in any security model, implying the incorrectness of the security proof of Yang et al. [38].
We begin by introducing an elliptic curve E that satisfies the following requirement: the binary representation of each point’s x-coordinate has its final ω bits fixed, where
ω = log 2 ( n ) 2 − 1 , n is the order of the generator of E .
Now let us consider another elliptic curve E ′ defined over a finite group F q ′ , where n is the order of the generator of E ′ . Denote the addition and multiplication operations in F q ′ by ‘+’ and ‘·’, respectively. Building upon F q ′ , we construct the algebraic structure ( F q , ⊕ , ⊗ ) as follows.
1.
We define F q to be the set
{ x : x = x ′ ‖ 0 ω , x ′ ∈ F q ′ } .
2.
For any x , y ∈ F q expressed as x = x ′ ‖ 0 ω and y = y ′ ‖ 0 ω , where x ′ , y ′ ∈ F q ′ , we then specify the operations
x ⊕ y = ( x ′ + y ′ ) ‖ 0 ω and x ⊗ y = ( x ′ · y ′ ) ‖ 0 ω .
It can be confirmed that ( F q , ⊕ , ⊗ ) forms a finite field. Because the representation of elements in F q has its ω least significant bits set to zero, every elliptic curve defined over F q automatically satisfies the intended property. Specifically, for the elliptic curve E defined on F q , the  a v f ( ) function yields a fixed value. Here we explain why, for any point X = ( x , y ) on the elliptic curve E, the value of x ¯ , or  a v f ( X ) , is a constant c.
x ¯ = a v f ( X ) = 2 ω + x & ( 2 ω − 1 ) ,
and then x ¯ simplifies to 2 ω , a constant denoted by c.
Based on the elliptic curve E, we propose a brief attack on the protocol in which an attacker M can impersonate a party A ^ to communicate with another party B ^ . M randomly chooses x * ∈ [ 1 , n ] and sends X * = [ 1 / c ] ( [ x * ] G − A ) to B ^ as the identity of A ^ . After receiving X * , B ^ responds with Y = [ y ] G and computes its unhashed value Z = [ h · t B ] ( A + [ x ¯ ] X * ) = [ h · t B ] ( A + [ c ] X * ) = [ h · t B ] ( [ x * ] G ) . Finally, M can compute the session key of B ^ by computing [ h · x * ] ( B + [ c ] Y ) = [ h · t B ] ( [ x * ] G ) which equals the unhashed value Z of B ^ . Thus, M successfully impersonates A ^ to B ^ .
Based on the above group representation attack, we claim that the SM2 key exchange protocol indeed cannot be proven secure under modern AKE models, for the following reasons. First, the aim of modern cryptography is to show, under certain mathematical assumptions, that an adversary with a given attack capabilities cannot break the protocol, thereby reducing the protocol’s security to the mathematical assumptions. In modern AKE models, no assumptions are made about the specific elliptic curves used by the protocol; instead, proofs employ pure mathematical elliptic curves. Consequently, the group representation attack we propose is admissible under all such model AKE models, meaning it is correct to conclude that the SM2 key exchange protocol cannot be proven secure in modern AKE models. One advantage of this proof paradigm is that if a protocol is proven secure within these models, it guarantees a very high level of security.

3.3. A Formal Attack Based on the BR Model

Below, we provide a formal description, grounded in the BR model, of the group representation attack. Specifically, we show how, through a series of query executions and message exchanges, the adversary can construct a counterfeit session s’ that shares the same session key as a target session. In the BR model, an adversary (denoted by M ) can interact with protocol session instances via the following queries: Send, Reveal, Corrupt, and Test. We provide a step-by-step account of how M can impersonate A ^ to B ^ in an SM2 key exchange setting, constructing a session s ′ that shares the same session key as the session it aims to attack.

3.3.1. Attack Goals and Setup

  • Let Π A ^ i represent the i-th session instance of user A ^ , and  Π B ^ j represent the j-th session instance of user B ^ .
  • The adversary M seeks to create a counterfeit session instance, denoted Π A ^ i ′ (or s ′ for convenience), which deceives Π B ^ j into believing it is communicating with A ^ . As a result, Π B ^ j will generate a session key that M also learns or shares.

3.3.2. Attack Steps

1.
Preparation: The adversary M chooses a random integer x * ∈ [ 1 , n ] . Using the public elliptic curve parameters ( E , G ) and the public key A belonging to A ^ , plus the constant c, M computes X * = [ 1 / c ] [ x * ] G − A and sets X * as the ephemeral public key and sends it to the party with which it intends to establish a session.
2.
Impersonation and Sending Messages (the Send query):
  • M calls Send Π B ^ j , ( A ^ , X * ) to send a message to Π B ^ j , impersonating the identity A ^ , along with the ephemeral public key X * .
  • Upon receiving the above message, Π B ^ j believes it has received a message from A ^ and proceeds according to the SM2 key exchange protocol.
3.
Generating and Receiving Y (Response to the Send query):
  • Π B ^ j randomly chooses an ephemeral secret y, computes Y = [ y ] G , and then responds via the Send Π M ^ , Y query, sending Y back to the adversary M .
  • The adversary M obtains Y and continues with the next step.
4.
Session Key Computation at B ^ ’s Side:
  • The instance Π B ^ j uses its local secret t B (which, in the SM2 key exchange protocol, typically involves both a long-term key and an ephemeral random key) to compute
    Z = [ h · t B ] A + [ x ¯ ] X * .
    Given that X * = [ 1 / c ] [ x * ] G − A and [ x ¯ ] X * equals [ c ] X * , we get
    A + [ x ¯ ] X * = A + [ c ] [ 1 / c ] ( [ x * ] G − A ) = [ x * ] G .
    Therefore,
    Z = [ h · t B ] [ x * ] G .
    Z is then used by Π B ^ j to derive the session key.
5.
Adversary Shares the Same Session Key:
  • Using the same x * and the received Y, the adversary computes
    [ h · x * ] B + [ y ¯ ] Y = [ h · x * ] B + [ c ] Y .
    In the SM2 key exchange protocol, B is B ^ ’s public key or an identity-based parameter. By substituting Y = [ y ] G , we can compute that the result [ h · x * ] B + [ c ] Y matches
    [ h · t B ] [ x * ] G = Z ,
    thus allowing M to compute the exact same value Z as Π B ^ j , through which M can derive the same session key of Π B ^ j .
6.
Conclusion of the Attack: At this point, M has successfully fooled Π B ^ j into believing it is communicating with A ^ . The sessions Π A ^ i ′ (controlled by M ) and Π B ^ j share the same session key, completing the impersonation.
In summary, through a series of Send queries to manage the receipt of Y and construction of X * , the adversary M is able to compute the same session key as Π B ^ j . This results in a successful impersonation of A ^ in the SM2 key exchange protocol.

3.4. The Security of the SM2 Key Exchange Protocol in the Standard

We propose a group representation attack that uses a special elliptic curve on which the ω least significant bits of the point coordinates are fixed. In practice, however, the SM2 standard specifies the elliptic curves used in deployment. The SM2 standard mandates two types of elliptic curves E ( F q ) , one where q is an odd prime and another where q = 2 m , and it also constrains how elements of F q are represented as integers (Algorithm 1). Algorithm 1 shows that elements of F q have a one-to-one mapping to the interval ( 0 , q − 1 ) . Consequently, the  ω least significant bits of elliptic curve points are not fixed but are uniformly distributed over ( 0 , 2 ω − 1 ) . Therefore, the aforementioned group representation attack cannot be applied to the elliptic curves specified in the standard.
Algorithm 1 Conversion of a Field Element to an Integer
Input: An element α of the field GF ( q )
Output: A non-negative integer x in the interval [ 0 , q − 1 ]
   1:
if q is an odd prime:
   2:
    α is an integer in the interval [ 0 , q − 1 ] . Set x ← α .
   3:
else if  q = 2 m , then α must be a bitstring of length m.
   4:
Let s m − 1 , s m − 2 , … , s 1 , s 0 be the bits from left to right of α .
   5:
Set
x = ∑ i = 0 m − 1 2 i s i .
   6:
end if
   7:
return x

4. Discussion

In this section, we discuss the security boundaries of the SM2 key exchange protocol and ways to enhance its security, focusing on the theoretical analysis of the SM2 key exchange protocol, how practical elliptic curves resist group representation attacks, and proposed revisions to the SM2 standard.

4.1. Theoretical Analysis of the SM2 Key Exchange Protocol

From a theoretical perspective, the group representation attack discussed above indicates that the SM2 key exchange protocol cannot be rigorously proven secure under model AKE models, at least not without introducing additional assumptions about its internal mechanics. This attack exploits a structural loophole that bypasses the usual reliance on the elliptic curve discrete logarithm problem (ECDLP), highlighting a design gap which, under specially constructed scenarios, enables an adversary to replicate the shared secret key.

4.2. Practical Security of the SM2 Key Exchange Protocol

Although the SM2 key exchange protocol cannot be proven secure under modern AKE models, the analysis of the elliptic curves actually deployed in the SM2 standard (as discussed in Section 3.4) shows that the values of a v f ( ) on these real-world elliptic curves are not fixed but are instead approximately uniformly distributed. Moreover, Zhao et al. [41,42] conducted empirical measurements of a v f ( ) on the elliptic curves used in the SM2 standard, demonstrating that the entropy rate of a v f ( ) is close to 1 and essentially likes the behavior of a random number generator. This observation explains why in their security analysis, a v f ( ) is assumed as a secure cryptographic hash function. Under this assumption, the SM2 key exchange protocol can be proven secure in modern AKE models.
Therefore, the above analysis delineates the security boundary of the SM2 key exchange protocol. While it cannot be proven secure in the strictest theoretical sense, due to the potential for a group representation attack, its practical deployment may still be robust, as a v f ( ) provides sufficient randomness to withstand the group representation attack.

4.3. Revision Suggestion of the SM2 Standard

Although empirical measurements suggest that a v f ( ) for the elliptic curves used in the SM2 standard does provide some degree of randomness to resist the group representation attack, it still does not meet the security requirements of a cryptographic hash function. A cryptographic hash function must fulfill properties such as randomness and collision resistance [43], and the a v f ( ) in the SM2 standards currently does not attain these properties. Therefore, we still recommend replacing a v f ( ) with a cryptographically secure hash function in the SM2 standard. However, modifying the avf() function in the SM2 standard to a secure hash function, such as SM3 or SHA3, would impact the security standards or specifications that rely on the SM2 standard, as well as the corresponding products. Taking the trusted computing field as an example, this technology depends on the SM2 cryptographic algorithm. Therefore, changing the avf() function would require revising relevant trusted computing specifications, such as TCG’s TPM 2.0 Library specification [35]. At the same time, any trusted computing products relying on the TPM 2.0 specification, such as TPM 2.0 chips, would also need to be updated (e.g., through firmware updates) to support the revised SM2 cryptographic algorithm.

5. Conclusions

In this paper, we revisited the security of the SM2 key exchange protocol, a widely adopted protocol standardized in both Chinese and international standards. We demonstrated that the security proof put forward by Yang et al. [38] contains a critical flaw: it fails to account for all possible ways by which an adversary might compromise the session key. We presented a group representation attack, showing that an adversary can impersonate one party and derive the same session key. Our findings indicate that the SM2 key exchange protocol cannot be proven secure in modern AKE models. This theoretical limitation arises from the way the protocol uses the function a v f ( ) , which an adversary can exploit to undermine the secure properties that an AKE protocol should provide. Nonetheless, we also showed that in practice, the specific elliptic curves recommended by the SM2 standard significantly mitigate the feasibility of the group representation attack. Empirical measurements suggest that a v f ( ) exhibits essentially random behavior for these standard curves, making real-world exploitation difficult.
Based on this analysis, we conclude that although SM2 key exchange cannot be proven secure in a rigorous theoretical sense, exploiting its theoretical vulnerabilities requires highly contrived conditions that do not align well with the officially mandated elliptic curves. To further strengthen the protocol, we recommend replacing or upgrading a v f ( ) with a proper cryptographic hash function, thereby ensuring well-defined security properties such as collision resistance. By clarifying the boundaries between theory and practice, we provide a foundation for improving the design of the SM2 key exchange protocol and further affirm its practical robustness in current deployments.

Author Contributions

Conceptualization, Q.Z.; formal analysis and writing, Y.W.; methodology and review, S.Z. All authors have read and agreed to the published version of the manuscript.

Funding

This work was supported in part by the National Natural Science Foundation of China (62372311, 62272458, 62272323, 62272322, 62372312), and by the Open Foundation of Key Laboratory of Cyberspace Security, Ministry of Education of China (No. KLCS20240206).

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Blake-Wilson, S.; Menezes, A. Unknown key-share attacks on the station-to-station (STS) protocol. In Proceedings of the Public Key Cryptography; Springer: Berlin/Heidelberg, Germany, 1999; pp. 154–170. [Google Scholar] [CrossRef] [Scilit]
  2. Canetti, R.; Krawczyk, H. Security analysis of IKE’s signature-based key-exchange protocol. In Proceedings of the 22nd Annual International Cryptology Conference (CRYPTO 2002); Springer: Berlin/Heidelberg, Germany, 2002; pp. 143–161. [Google Scholar] [CrossRef] [Scilit]
  3. Dierks, T.; Rescorla, E. The Transport Layer Security (TLS) Protocol Version 1.2. Technical Report, IETF. 2008. Available online: https://www.rfc-editor.org/info/rfc5246 (accessed on 26 January 2026).
  4. Aiello, W.; Bellovin, S.M.; Blaze, M.; Canetti, R.; Ioannidis, J.; Keromytis, A.D.; Reingold, O. Just fast keying: Key agreement in a hostile internet. ACM Trans. Inf. Syst. Secur. 2004, 7, 242–273. [Google Scholar] [CrossRef] [Scilit]
  5. Matsumoto, T.; Takashima, Y.; Imai, H. On seeking smart public-key-distribution systems. IEICE Trans. 1986, 69, 99–106. [Google Scholar]
  6. Menezes, A.; Qu, M.; Vanstone, S. Some new key agreement protocols providing implicit authentication. In Proceedings of the Second Workshop on Selected Areas in Cryptography (SAC 95), Ottawa, ON, Canada, 18–19 May 1995; pp. 22–35. [Google Scholar]
  7. NIST. KEA Algorithm Specifications. 1998. Available online: https://csrc.nist.gov/presentations/1998/skipjack-and-kea-algorithm-specifications (accessed on 26 January 2026).
  8. Law, L.; Menezes, A.; Qu, M.; Solinas, J.; Vanstone, S. An efficient protocol for authenticated key agreement. Des. Codes Cryptogr. 2003, 28, 119–134. [Google Scholar] [CrossRef] [Scilit]
  9. Jeong, I.R.; Katz, J.; Lee, D.H. One-round protocols for two-party authenticated key exchange. In Proceedings of the Applied Cryptography and Network Security; Springer: Berlin/Heidelberg, Germany, 2004; pp. 220–232. [Google Scholar] [CrossRef] [Scilit]
  10. Krawczyk, H. HMQV: A high-performance secure Diffie-Hellman protocol. In Proceedings of the Advances in Cryptology—CRYPTO 2005; Springer: Berlin/Heidelberg, Germany, 2005; pp. 546–566. [Google Scholar] [CrossRef] [Scilit]
  11. Lauter, K.; Mityagin, A. Security analysis of KEA authenticated key exchange protocol. In Proceedings of the Public Key Cryptography—PKC 2006; Springer: Berlin/Heidelberg, Germany, 2006; pp. 378–394. [Google Scholar] [CrossRef] [Scilit]
  12. LaMacchia, B.; Lauter, K.; Mityagin, A. Stronger security of authenticated key exchange. In Proceedings of the Provable Security; Springer: Berlin/Heidelberg, Germany, 2007; pp. 1–16. [Google Scholar] [CrossRef] [Scilit]
  13. Ustaoglu, B. Obtaining a secure and efficient key agreement protocol from (H)MQV and NAXOS. Des. Codes Cryptogr. 2008, 46, 329–342. [Google Scholar] [CrossRef] [Scilit]
  14. Gennaro, R.; Krawczyk, H.; Rabin, T. Okamoto-Tanaka revisited: Fully authenticated Diffie-Hellman with minimal overhead. In Proceedings of the Applied Cryptography and Network Security; Springer: Berlin/Heidelberg, Germany, 2010; pp. 309–328. [Google Scholar] [CrossRef] [Scilit]
  15. Xu, J.; Feng, D. Comments on the SM2 key exchange protocol. In Cryptology and Network Security; Springer: Berlin/Heidelberg, Germany, 2011; pp. 160–171. [Google Scholar] [CrossRef] [Scilit]
  16. Yao, A.C.; Zhao, Y. A New Family of Implicitly Authenticated Diffie-Hellman Protocols. Technical Report, Cryptology ePrint Archive. 2011. Available online: https://eprint.iacr.org/2011/035 (accessed on 26 January 2026).
  17. Yao, A.C.; Zhao, Y. OAKE: A new family of implicitly authenticated diffie-hellman protocols. In Proceedings of the the 20th ACM SIGSAC Conference on Computer and Communications Security (CCS), Berlin, Germany, 4–8 November 2013; ACM: New York, NY, USA, 2013; pp. 1113–1128. [Google Scholar] [CrossRef] [Scilit]
  18. Rabiah, A.B.; Ramakrishnan, K.; Liri, E.; Kar, K. A lightweight authentication and key exchange protocol for IoT. IEEE Trans. Wirel. Commun. 2023, 22, 7862–7872. [Google Scholar] [CrossRef] [Scilit]
  19. Jia, X.; He, D.; Li, L.; Choo, K.K.R. Signature-based three-factor authenticated key exchange for internet of things applications. Multimed. Tools Appl. 2018, 77, 18355–18382. [Google Scholar] [CrossRef] [Scilit]
  20. Khelf, R.; Ghoualmi-Zine, N.; Ahmim, M. TAKE-IoT: Tiny authenticated key exchange protocol for the internet of things. Int. J. Embed. Real-Time Commun. Syst. 2020, 11, 1–21. [Google Scholar] [CrossRef] [Scilit]
  21. Simsek, I. Authentication, authorization, access control, and key exchange in Internet of Things. ACM Trans. Internet Things 2024, 5, 1–30. [Google Scholar] [CrossRef] [Scilit]
  22. Peivandizadeh, A.; Y. Adarbah, H.; Molavi, B.; Mohajerzadeh, A.; H. Al-Badi, A. A secure key exchange and authentication scheme for securing communications in the Internet of Things environment. Future Internet 2024, 16, 357. [Google Scholar] [CrossRef] [Scilit]
  23. Arias-Jimenez, A.; Gallego-Madrid, J.; Sanchez-Gomez, J.; Marin-Perez, R. Lightweight authenticated key exchange for low-power IoT networks using EDHOC. Internet Things 2025, 31, 101539. [Google Scholar] [CrossRef] [Scilit]
  24. Fan, C.I.; Lai, C.I.; Medhane, D.V. Cake-puf: A collaborative authentication and key exchange protocol based on physically unclonable functions for industrial internet of things. IEEE Internet Things J. 2024, 11, 39709–39720. [Google Scholar] [CrossRef] [Scilit]
  25. Sarkar, P.; Nag, A. Lattice-based device-to-device authentication and key exchange protocol for IoT system. Int. J. Inf. Technol. 2024, 16, 4167–4179. [Google Scholar] [CrossRef] [Scilit]
  26. Mishra, R.; Mishra, A. Current research on Internet of Things (IoT) security protocols: A survey. Comput. Secur. 2025, 151, 104310. [Google Scholar] [CrossRef] [Scilit]
  27. Snook, M. Quantum Resistant Authenticated Key Exchange from Ideal Lattices. Ph.D Thesis, University of Cincinnati, Cincinnati, OH, USA, 2016. [Google Scholar]
  28. Garcia, C.R.; Rommel, S.; Takarabt, S.; Olmos, J.J.V.; Guilley, S.; Nguyen, P.; Monroy, I.T. Quantum-resistant transport layer security. Comput. Commun. 2024, 213, 345–358. [Google Scholar] [CrossRef] [Scilit]
  29. Xia, T.; Wang, M.; He, J.; Yang, G.; Fan, L.; Wei, G. A quantum-resistant identity authentication and key agreement scheme for uav networks based on kyber algorithm. Drones 2024, 8, 359. [Google Scholar] [CrossRef] [Scilit]
  30. Lu, S.; Li, X. Quantum-resistant lightweight authentication and key agreement protocol for fog-based microgrids. IEEE Access 2021, 9, 27588–27600. [Google Scholar] [CrossRef] [Scilit]
  31. Wang, W.; Tan, S.F. Quantum Resistant Authentication and Key Agreement Protocol (AKA) for Autonomous Vehichle. In Proceedings of the 5th International Conference on Neural Networks, Information and Communication Engineering (NNICE), Guangzhou, China, 10–12 January 2025; IEEE: Piscataway, NJ, USA, 2025; pp. 1011–1016. [Google Scholar] [CrossRef] [Scilit]
  32. GB/T 35276-2017; Information Security Technology—SM2 Cryptographic Algorithm Usage Specification. Standardization Administration of the People’s Republic of China: Beijing, China, 2017.
  33. GB/T 32918.1-2016; Information Security Technology—Public Key Cryptographic Algorithm SM2 Based on Elliptic Curves—Part 1: General. Standardization Administration of the People’s Republic of China: Beijing, China, 2016.
  34. GB/T 32918.3-2016; Information Security Technology—Public Key Cryptographic Algorithm SM2 Based on Elliptic Curves—Part 3: Key Exchange Protocol. Standardization Administration of the People’s Republic of China: Beijing, China, 2016.
  35. TCG. Trusted Platform Module Library Part 1: Architecture. Family 2.0, Level 00 Revision 01.38. 2016. Available online: https://trustedcomputinggroup.org/wp-content/uploads/TPM-Rev-2.0-Part-1-Architecture-01.38.pdf (accessed on 26 January 2026).
  36. ORACLE. Java Card Platform, Version 3.1. 2019. Available online: https://docs.oracle.com/en/java/javacard/3.1/specnotes/index.html (accessed on 26 January 2026).
  37. Internet Engineering Task Force. SM2 Digital Signature Algorithm. 2014. Available online: https://tools.ietf.org/id/draft-shen-sm2-ecdsa-02.txt (accessed on 26 January 2026).
  38. Yang, A.; Nam, J.; Kim, M.; Choo, K.K.R. Provably-Secure (Chinese Government) SM2 and Simplified SM2 Key Exchange Protocols. Sci. World J. 2014, 2014, 825984. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  39. Bellare, M.; Rogaway, P. Entity authentication and key distribution. In Proceedings of the 13th Annual International Cryptology Conference on Advances in Cryptology (CRYPTO); Springer: Berlin/Heidelberg, Germany, 1993; pp. 232–249. [Google Scholar] [CrossRef] [Scilit]
  40. Bellare, M.; Rogaway, P. Provably secure session key distribution: The three party case. In Proceedings of the 27th Annual ACM Symposium on Theory of Computing, Las Vegas, NV, USA, 29 May–1 June 1995; ACM: New York, NY, USA, 1995; pp. 57–66. [Google Scholar] [CrossRef] [Scilit]
  41. Zhao, S.; Zhang, Q. A Unified Security Analysis of Two-phase Key Exchange Protocols in TPM 2.0. In Proceedings of the International Conference on Trust and Trustworthy Computing; Springer: Berlin/Heidelberg, Germany, 2015; pp. 40–57. [Google Scholar] [CrossRef] [Scilit]
  42. Zhang, Q.; Zhao, S. A comprehensive formal security analysis and revision of the two-phase key exchange primitive of TPM 2.0. Comput. Netw. 2020, 179, 107369. [Google Scholar] [CrossRef] [Scilit]
  43. Preneel, B. Cryptographic hash functions. Eur. Trans. Telecommun. 1994, 5, 431–448. [Google Scholar] [CrossRef] [Scilit]
Figure 1. The SM2 key exchange protocol.
Figure 1. The SM2 key exchange protocol.
Information 17 00124 g001
Table 1. Notations and Definitions.
Table 1. Notations and Definitions.
NotationDefinition
A ^ , B ^ Identities of two communicating parties
A,BThe parties A ^ and B ^ ’s long-term public keys
a,bThe parties A ^ and B ^ ’s long-term private keys
( F q , + , · ) In a finite field of size q, we denote addition by + and multiplication by ·. However, the multiplication symbol · can be omitted.
E ( F q ) All points that lie on the elliptic curve E defined over F q
GThe generator of an elliptic curve
# E ( F q ) The total count of points lying on the elliptic curve E
hLet h denotes the co-factor, determined by # E ( F q ) / n , where n is the order of the generator G
K D F ( p a r , k l e n ) A key derivation function whose input is specified by p a r and whose output length is k l e n
s | | t Combining the contents of two strings s and t in a sequential manner
0 n An n-bit sequence made up entirely of zeroes
⌈ i ⌉ The ceiling of an integer i
[ i , j ] The collection of all integer values x that satisfy i ≤ x ≤ j
&A logical bit-by-bit conjunction that yields 1 only when both corresponding bits are 1.
[ k ] P An operation defined by repeatedly adding an elliptic-curve point to itself a specified integer number of times, [ k ] P = P + P + ⋯ + P ︸ k
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Zhang, Q.; Wang, Y.; Zhao, S. Revisiting a Proof of Security for the SM2 Key Exchange Protocol. Information 2026, 17, 124. https://doi.org/10.3390/info17020124

AMA Style

Zhang Q, Wang Y, Zhao S. Revisiting a Proof of Security for the SM2 Key Exchange Protocol. Information. 2026; 17(2):124. https://doi.org/10.3390/info17020124

Chicago/Turabian Style

Zhang, Qianying, Yuting Wang, and Shijun Zhao. 2026. "Revisiting a Proof of Security for the SM2 Key Exchange Protocol" Information 17, no. 2: 124. https://doi.org/10.3390/info17020124

APA Style

Zhang, Q., Wang, Y., & Zhao, S. (2026). Revisiting a Proof of Security for the SM2 Key Exchange Protocol. Information, 17(2), 124. https://doi.org/10.3390/info17020124

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop