Abstract:One-round Diffie-Hellman key exchang e (OR-DHKE) protocols are considered to be unable to achieve perfect forward secrecy (PFS),so is identity-based OR-DHKE.Existing protocols in identity-based set provide only weak perfect forward secrecy (wPFS) at best.Based on the research on the PFS of Diffie-Hellman key exchange by Cremers et al.,this paper proposed a new identity-based authenticated key exch ange scheme with perfect forward secrecy.The article proposed firstly an identity-based OR-DHKE protocol with wPFS,named π0,and then employed the SIG transformation proposed by Cremers et al.to transform π0into an iden tity-based authenticated key exchange with PFS,named π1.Meanwhile,the article compared several main security models ,including CK,CK+,eCK and eCK-PFS,and defined a strong security model,ID-eCK-PFS,for identity-based au thenticated key exchange protocol. Under the ID-eCK-PFS model,the security of the protocols π0and π1were respectively deduced to solve the Decisional Bilinear Diffie-Hellman (DBDH) problem,and it didn′t use random or acle in the security games. Accordingly,the proposed protocol achieves perfect forward secrecy,and is provab le security in standard model.