By analyzing security and performance deficiencies of IKEv2 and JFK in the large-scale deployment of IPSec applications,the paper proposes a lightweight key exchange protocol(LKE)in order to reduce the number of messages and the cost of computing resources effectively.LKE solves the coexistence of both anti-DoS attack and perfect forward secrecy by classical puzzle and two round asynchronous exchanges.It is shown by simulation that LKE strongly accommodates communication with limited bandwidth and exceeds I...