Hi,
Thank you! I've added this as proposal 308. I'll be looking it over
with interest in the near future.
Thanks for adding this to the list of proposals.
One thing that helps me understand this kind of proposal is writing or examining a reference implementation for it, so I can see clearly what state is kept, which party does what, and so on. I did one for proposal 295 as https://github.com/nmathewson/prop295ref -- I hope I can get a reference implementation together for this one too, unless you're already on it.
A reference implementation would be nice and at the moment we are not working on that.
It would also be interesting to know what the ADL authors think of
this proposal too -- most of us at Tor aren't cryptographers ourselves.
Of course, all input is welcome.
Best wishes,
Jean Paul