| - The new AKE protocol is secure (in the sense of Definition 2) if the DDH assumption holds for {} k???, where H is a TCR hash function family, ??F and ??F are PRF families and F is a ??PRF family with index {(I, f)} ???{}k, k???N, where I ??? {(V, W, d)|(V, W, d) ???2 ?? p} and f: (V, W, d) |??? Vr1+dr2W with (r1, r2) U??? p2.