Security models play an important role in analyzing the security of key exchange protocols. In which the security models CK [1], CK_HMQV [2], and eCK [3] are most commonly used. In [4], C.J.F Cremers pointed out that the security in these three models cannot be reduced together, i.e., a protocol that achieves security in any of the above models is not guaranteed that it will secure in the others. In addition, this work also points to several issues related to proving security for some of the protocols in these models, namely session matching. On the basis of [4], in this article, the security in the model  [2] was compared to the AKE security [8]. Besides, the report will point out a problem related to the implementation of Lemongrass-3 [9, 10], which achieves AKE security and then offer a solution to the problem.


