This paper surveys recent work on the design and analysis of key agreement protocols that are based on the intractability
of the Diffe-Hellman problem. The focus is on protocols that have been standardized, or are in the process of being standardized,
by organizations such as ANSI, IEEE, ISO/IEC, and NIST. The practical and provable security aspects of these protocols are
discussed.