摘要:Certificateless authenticated key agreement (CL-AKA) protocols neither suffer from a heavy certificate managementburden nor have the key escrow problem. Recently, many CL-AKA protocols have been proposed. However, manyof them need expensive bilinear pairings, which cannot be suitable for low-power devices such as sensors or mobile devices.To be implemented in practice, some pairing-free CL-AKA protocols have been built, however, very few of these pairing-freeCL-AKA protocols can be secure in the eCK model. In this paper, we present a pairing-free CL-AKA protocol and providea full proof of its security in the eCK model. Compared with the existing CL-AKA protocols, our protocol is more secure,practical and suitable for low-power devices.