Is the entropy from Q_plain
really needed? A reason for it would be that the client provides randomness with the nonce contained in Q_plain
, in the sense of a contributive key exchange. However, the client already contributes the HPKE ephemeral key.
If the Extract step should stay, I suggest changing the order of Q_plain
and odoh_secret
. The value odoh_secret
is of fixed size and uniformly random, and thus fits better as salt
to HKDF-Extract. If the first value is longer than a hash function block size, HMAC will do an additional hashing step: This seems easily possible for Q_plain.