Exchange. Though general one-round GKE satisfying advanced security properties such as
forward secrecy and maximal-exposure-resilience (MEX-resilience) is not known, it can be
efficiently constructed with the help of pairings in the 3KE case. In this paper, we introduce
the first one-round 3KE which is MEX-resilient in the standard model, though existing one-
round 3KE schemes are proved in the random oracle model (ROM), or not MEX-resilient …