Revisiting a Proof of Security for the SM2 Key Exchange Protocol
Abstract
1. Introduction
2. Materials and Methods
2.1. Overview of the SM2 Key Exchange Protocol
2.2. Overview of the Bellare-Rogaway Model
2.2.1. Session Instances
2.2.2. Adversarial Capabilities and Queries
- Send : The adversary transmits a message m to the session instance . Upon receiving m, the instance processes it according to the protocol specification and returns the appropriate response. If the instance accepts a session key or terminates, this information is also revealed to .
- Reveal : If the session instance has already accepted a session key, then this query discloses that session key to . This models scenarios in which the adversary gains access to ephemeral keys retained in temporary storage.
- Corrupt : This query grants the adversary the complete internal state of user , including long-term private keys and any other sensitive parameters. It simulates situations such as insider threats or covert access to a user’s device.
- Test : This query is used to distinguish between a real session key and a randomly generated value. If currently holds a legitimate session key (and is considered “fresh,” as explained below), then a random bit b is chosen. If , the adversary receives the actual session key; if , the adversary receives a random value of the same length. The adversary’s objective is to guess whether the returned value is real or random.
2.2.3. Partnership and Freshness
2.2.4. Security Definition
- 1.
- When two uncorrupted parties complete matching sessions, they output the same session key.
- 2.
- The probability that guesses the bit b (i.e., outputs ) from the Test query correctly is no more than plus a negligible fraction, i.e., the advantage of in distinguishing the real key is quantified as:
3. Results
3.1. A Flaw of Yang’s Security Proof
3.2. A Brief Group Representation Attack
- 1.
- We define to be the set
- 2.
- For any expressed as and , where , we then specify the operations
3.3. A Formal Attack Based on the BR Model
3.3.1. Attack Goals and Setup
- Let represent the i-th session instance of user , and represent the j-th session instance of user .
- The adversary seeks to create a counterfeit session instance, denoted (or for convenience), which deceives into believing it is communicating with . As a result, will generate a session key that also learns or shares.
3.3.2. Attack Steps
- 1.
- Preparation: The adversary chooses a random integer . Using the public elliptic curve parameters and the public key A belonging to , plus the constant c, computes and sets as the ephemeral public key and sends it to the party with which it intends to establish a session.
- 2.
- Impersonation and Sending Messages (the Send query):
- calls to send a message to , impersonating the identity , along with the ephemeral public key .
- Upon receiving the above message, believes it has received a message from and proceeds according to the SM2 key exchange protocol.
- 3.
- Generating and Receiving Y (Response to the Send query):
- randomly chooses an ephemeral secret y, computes , and then responds via the query, sending Y back to the adversary .
- The adversary obtains Y and continues with the next step.
- 4.
- Session Key Computation at ’s Side:
- The instance uses its local secret (which, in the SM2 key exchange protocol, typically involves both a long-term key and an ephemeral random key) to computeGiven that and equals , we getTherefore,Z is then used by to derive the session key.
- 5.
- Adversary Shares the Same Session Key:
- Using the same and the received Y, the adversary computesIn the SM2 key exchange protocol, B is ’s public key or an identity-based parameter. By substituting , we can compute that the result matchesthus allowing to compute the exact same value Z as , through which can derive the same session key of .
- 6.
- Conclusion of the Attack: At this point, has successfully fooled into believing it is communicating with . The sessions (controlled by ) and share the same session key, completing the impersonation.
3.4. The Security of the SM2 Key Exchange Protocol in the Standard
| Algorithm 1 Conversion of a Field Element to an Integer |
| Input: An element of the field |
| Output: A non-negative integer x in the interval |
|
4. Discussion
4.1. Theoretical Analysis of the SM2 Key Exchange Protocol
4.2. Practical Security of the SM2 Key Exchange Protocol
4.3. Revision Suggestion of the SM2 Standard
5. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Blake-Wilson, S.; Menezes, A. Unknown key-share attacks on the station-to-station (STS) protocol. In Proceedings of the Public Key Cryptography; Springer: Berlin/Heidelberg, Germany, 1999; pp. 154–170. [Google Scholar] [CrossRef] [Scilit]
- Canetti, R.; Krawczyk, H. Security analysis of IKE’s signature-based key-exchange protocol. In Proceedings of the 22nd Annual International Cryptology Conference (CRYPTO 2002); Springer: Berlin/Heidelberg, Germany, 2002; pp. 143–161. [Google Scholar] [CrossRef] [Scilit]
- Dierks, T.; Rescorla, E. The Transport Layer Security (TLS) Protocol Version 1.2. Technical Report, IETF. 2008. Available online: https://www.rfc-editor.org/info/rfc5246 (accessed on 26 January 2026).
- Aiello, W.; Bellovin, S.M.; Blaze, M.; Canetti, R.; Ioannidis, J.; Keromytis, A.D.; Reingold, O. Just fast keying: Key agreement in a hostile internet. ACM Trans. Inf. Syst. Secur. 2004, 7, 242–273. [Google Scholar] [CrossRef] [Scilit]
- Matsumoto, T.; Takashima, Y.; Imai, H. On seeking smart public-key-distribution systems. IEICE Trans. 1986, 69, 99–106. [Google Scholar]
- Menezes, A.; Qu, M.; Vanstone, S. Some new key agreement protocols providing implicit authentication. In Proceedings of the Second Workshop on Selected Areas in Cryptography (SAC 95), Ottawa, ON, Canada, 18–19 May 1995; pp. 22–35. [Google Scholar]
- NIST. KEA Algorithm Specifications. 1998. Available online: https://csrc.nist.gov/presentations/1998/skipjack-and-kea-algorithm-specifications (accessed on 26 January 2026).
- Law, L.; Menezes, A.; Qu, M.; Solinas, J.; Vanstone, S. An efficient protocol for authenticated key agreement. Des. Codes Cryptogr. 2003, 28, 119–134. [Google Scholar] [CrossRef] [Scilit]
- Jeong, I.R.; Katz, J.; Lee, D.H. One-round protocols for two-party authenticated key exchange. In Proceedings of the Applied Cryptography and Network Security; Springer: Berlin/Heidelberg, Germany, 2004; pp. 220–232. [Google Scholar] [CrossRef] [Scilit]
- Krawczyk, H. HMQV: A high-performance secure Diffie-Hellman protocol. In Proceedings of the Advances in Cryptology—CRYPTO 2005; Springer: Berlin/Heidelberg, Germany, 2005; pp. 546–566. [Google Scholar] [CrossRef] [Scilit]
- Lauter, K.; Mityagin, A. Security analysis of KEA authenticated key exchange protocol. In Proceedings of the Public Key Cryptography—PKC 2006; Springer: Berlin/Heidelberg, Germany, 2006; pp. 378–394. [Google Scholar] [CrossRef] [Scilit]
- LaMacchia, B.; Lauter, K.; Mityagin, A. Stronger security of authenticated key exchange. In Proceedings of the Provable Security; Springer: Berlin/Heidelberg, Germany, 2007; pp. 1–16. [Google Scholar] [CrossRef] [Scilit]
- Ustaoglu, B. Obtaining a secure and efficient key agreement protocol from (H)MQV and NAXOS. Des. Codes Cryptogr. 2008, 46, 329–342. [Google Scholar] [CrossRef] [Scilit]
- Gennaro, R.; Krawczyk, H.; Rabin, T. Okamoto-Tanaka revisited: Fully authenticated Diffie-Hellman with minimal overhead. In Proceedings of the Applied Cryptography and Network Security; Springer: Berlin/Heidelberg, Germany, 2010; pp. 309–328. [Google Scholar] [CrossRef] [Scilit]
- Xu, J.; Feng, D. Comments on the SM2 key exchange protocol. In Cryptology and Network Security; Springer: Berlin/Heidelberg, Germany, 2011; pp. 160–171. [Google Scholar] [CrossRef] [Scilit]
- Yao, A.C.; Zhao, Y. A New Family of Implicitly Authenticated Diffie-Hellman Protocols. Technical Report, Cryptology ePrint Archive. 2011. Available online: https://eprint.iacr.org/2011/035 (accessed on 26 January 2026).
- Yao, A.C.; Zhao, Y. OAKE: A new family of implicitly authenticated diffie-hellman protocols. In Proceedings of the the 20th ACM SIGSAC Conference on Computer and Communications Security (CCS), Berlin, Germany, 4–8 November 2013; ACM: New York, NY, USA, 2013; pp. 1113–1128. [Google Scholar] [CrossRef] [Scilit]
- Rabiah, A.B.; Ramakrishnan, K.; Liri, E.; Kar, K. A lightweight authentication and key exchange protocol for IoT. IEEE Trans. Wirel. Commun. 2023, 22, 7862–7872. [Google Scholar] [CrossRef] [Scilit]
- Jia, X.; He, D.; Li, L.; Choo, K.K.R. Signature-based three-factor authenticated key exchange for internet of things applications. Multimed. Tools Appl. 2018, 77, 18355–18382. [Google Scholar] [CrossRef] [Scilit]
- Khelf, R.; Ghoualmi-Zine, N.; Ahmim, M. TAKE-IoT: Tiny authenticated key exchange protocol for the internet of things. Int. J. Embed. Real-Time Commun. Syst. 2020, 11, 1–21. [Google Scholar] [CrossRef] [Scilit]
- Simsek, I. Authentication, authorization, access control, and key exchange in Internet of Things. ACM Trans. Internet Things 2024, 5, 1–30. [Google Scholar] [CrossRef] [Scilit]
- Peivandizadeh, A.; Y. Adarbah, H.; Molavi, B.; Mohajerzadeh, A.; H. Al-Badi, A. A secure key exchange and authentication scheme for securing communications in the Internet of Things environment. Future Internet 2024, 16, 357. [Google Scholar] [CrossRef] [Scilit]
- Arias-Jimenez, A.; Gallego-Madrid, J.; Sanchez-Gomez, J.; Marin-Perez, R. Lightweight authenticated key exchange for low-power IoT networks using EDHOC. Internet Things 2025, 31, 101539. [Google Scholar] [CrossRef] [Scilit]
- Fan, C.I.; Lai, C.I.; Medhane, D.V. Cake-puf: A collaborative authentication and key exchange protocol based on physically unclonable functions for industrial internet of things. IEEE Internet Things J. 2024, 11, 39709–39720. [Google Scholar] [CrossRef] [Scilit]
- Sarkar, P.; Nag, A. Lattice-based device-to-device authentication and key exchange protocol for IoT system. Int. J. Inf. Technol. 2024, 16, 4167–4179. [Google Scholar] [CrossRef] [Scilit]
- Mishra, R.; Mishra, A. Current research on Internet of Things (IoT) security protocols: A survey. Comput. Secur. 2025, 151, 104310. [Google Scholar] [CrossRef] [Scilit]
- Snook, M. Quantum Resistant Authenticated Key Exchange from Ideal Lattices. Ph.D Thesis, University of Cincinnati, Cincinnati, OH, USA, 2016. [Google Scholar]
- Garcia, C.R.; Rommel, S.; Takarabt, S.; Olmos, J.J.V.; Guilley, S.; Nguyen, P.; Monroy, I.T. Quantum-resistant transport layer security. Comput. Commun. 2024, 213, 345–358. [Google Scholar] [CrossRef] [Scilit]
- Xia, T.; Wang, M.; He, J.; Yang, G.; Fan, L.; Wei, G. A quantum-resistant identity authentication and key agreement scheme for uav networks based on kyber algorithm. Drones 2024, 8, 359. [Google Scholar] [CrossRef] [Scilit]
- Lu, S.; Li, X. Quantum-resistant lightweight authentication and key agreement protocol for fog-based microgrids. IEEE Access 2021, 9, 27588–27600. [Google Scholar] [CrossRef] [Scilit]
- Wang, W.; Tan, S.F. Quantum Resistant Authentication and Key Agreement Protocol (AKA) for Autonomous Vehichle. In Proceedings of the 5th International Conference on Neural Networks, Information and Communication Engineering (NNICE), Guangzhou, China, 10–12 January 2025; IEEE: Piscataway, NJ, USA, 2025; pp. 1011–1016. [Google Scholar] [CrossRef] [Scilit]
- GB/T 35276-2017; Information Security Technology—SM2 Cryptographic Algorithm Usage Specification. Standardization Administration of the People’s Republic of China: Beijing, China, 2017.
- GB/T 32918.1-2016; Information Security Technology—Public Key Cryptographic Algorithm SM2 Based on Elliptic Curves—Part 1: General. Standardization Administration of the People’s Republic of China: Beijing, China, 2016.
- GB/T 32918.3-2016; Information Security Technology—Public Key Cryptographic Algorithm SM2 Based on Elliptic Curves—Part 3: Key Exchange Protocol. Standardization Administration of the People’s Republic of China: Beijing, China, 2016.
- TCG. Trusted Platform Module Library Part 1: Architecture. Family 2.0, Level 00 Revision 01.38. 2016. Available online: https://trustedcomputinggroup.org/wp-content/uploads/TPM-Rev-2.0-Part-1-Architecture-01.38.pdf (accessed on 26 January 2026).
- ORACLE. Java Card Platform, Version 3.1. 2019. Available online: https://docs.oracle.com/en/java/javacard/3.1/specnotes/index.html (accessed on 26 January 2026).
- Internet Engineering Task Force. SM2 Digital Signature Algorithm. 2014. Available online: https://tools.ietf.org/id/draft-shen-sm2-ecdsa-02.txt (accessed on 26 January 2026).
- Yang, A.; Nam, J.; Kim, M.; Choo, K.K.R. Provably-Secure (Chinese Government) SM2 and Simplified SM2 Key Exchange Protocols. Sci. World J. 2014, 2014, 825984. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Bellare, M.; Rogaway, P. Entity authentication and key distribution. In Proceedings of the 13th Annual International Cryptology Conference on Advances in Cryptology (CRYPTO); Springer: Berlin/Heidelberg, Germany, 1993; pp. 232–249. [Google Scholar] [CrossRef] [Scilit]
- Bellare, M.; Rogaway, P. Provably secure session key distribution: The three party case. In Proceedings of the 27th Annual ACM Symposium on Theory of Computing, Las Vegas, NV, USA, 29 May–1 June 1995; ACM: New York, NY, USA, 1995; pp. 57–66. [Google Scholar] [CrossRef] [Scilit]
- Zhao, S.; Zhang, Q. A Unified Security Analysis of Two-phase Key Exchange Protocols in TPM 2.0. In Proceedings of the International Conference on Trust and Trustworthy Computing; Springer: Berlin/Heidelberg, Germany, 2015; pp. 40–57. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Q.; Zhao, S. A comprehensive formal security analysis and revision of the two-phase key exchange primitive of TPM 2.0. Comput. Netw. 2020, 179, 107369. [Google Scholar] [CrossRef] [Scilit]
- Preneel, B. Cryptographic hash functions. Eur. Trans. Telecommun. 1994, 5, 431–448. [Google Scholar] [CrossRef] [Scilit]

| Notation | Definition |
|---|---|
| , | Identities of two communicating parties |
| A,B | The parties and ’s long-term public keys |
| a,b | The parties and ’s long-term private keys |
| In a finite field of size q, we denote addition by + and multiplication by ·. However, the multiplication symbol · can be omitted. | |
| All points that lie on the elliptic curve E defined over | |
| G | The generator of an elliptic curve |
| The total count of points lying on the elliptic curve E | |
| h | Let h denotes the co-factor, determined by , where n is the order of the generator G |
| A key derivation function whose input is specified by and whose output length is | |
| Combining the contents of two strings s and t in a sequential manner | |
| An n-bit sequence made up entirely of zeroes | |
| The ceiling of an integer i | |
| The collection of all integer values x that satisfy | |
| & | A logical bit-by-bit conjunction that yields 1 only when both corresponding bits are 1. |
| An operation defined by repeatedly adding an elliptic-curve point to itself a specified integer number of times, |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Zhang, Q.; Wang, Y.; Zhao, S. Revisiting a Proof of Security for the SM2 Key Exchange Protocol. Information 2026, 17, 124. https://doi.org/10.3390/info17020124
Zhang Q, Wang Y, Zhao S. Revisiting a Proof of Security for the SM2 Key Exchange Protocol. Information. 2026; 17(2):124. https://doi.org/10.3390/info17020124
Chicago/Turabian StyleZhang, Qianying, Yuting Wang, and Shijun Zhao. 2026. "Revisiting a Proof of Security for the SM2 Key Exchange Protocol" Information 17, no. 2: 124. https://doi.org/10.3390/info17020124
APA StyleZhang, Q., Wang, Y., & Zhao, S. (2026). Revisiting a Proof of Security for the SM2 Key Exchange Protocol. Information, 17(2), 124. https://doi.org/10.3390/info17020124

