HPKE produces a shaed secret known to both initiator and responder.
An AEAD key and nonce are then derived from this secret. This change
derives an additional exporter secret from the secret. It also
introduces a Export() API, akin to that of TLS, for computing values
using this exporter secret.
HPKE produces a shaed secret known to both initiator and responder. An AEAD key and nonce are then derived from this secret. This change derives an additional exporter secret from the secret. It also introduces a Export() API, akin to that of TLS, for computing values using this exporter secret.