+
+Key derivation
+--------------
+
+We're using `HKDF <https://ia.cr/2010/264>`_ to extract the AES key
+and iv from the $G_t$ element.
+
+Encryption Mode
+---------------
+
+Ciphertext is `AES128` in `GCM` mode with 12 bit IV and 16 bit
+tag. The ciphertext-format is as follows::
+
+ compress(s) | compress(cx) | c
+ enc(4 byte len(ptxt) | ptxt | 0 padding) | tag