Key control in key agreement protocols

Abstract
Certain key establishment protocols specified in an international standard and a draft international standard are considered. These protocols are all intended to provide joint key control, i.e. the protocols are designed to prevent either party choosing the key value. It is shown that this claim is suspect for most of the protocols concerned.