There exists a secure protocol(Diffie-Hellman) with 2 modular exponentiation operations for negotiating a key with no authentication. There exists a secure protocol(SPEKE, SRP, EKE..) with 2 exponentiations for negotiating a key with mutual authentication. Doesn't this suggest the existence of a 2 exponentiation protocol for authenticating only one side? Does one exist? It would be an improvement over what's now used with three exponentiations by the server.

