SPKM3
Server has public keypair, which is not required on client
Similar to "one-sided" security services such as SSL, TLS, and as such, suffers from the same man-in-the middle attack
Client public kepairs are allowed – we plan to use client machine keypairs