Thanks for sharing.
Key exchange is out of scope, but committee should at least provide guidelines/best-practice.
For example, encourage key isolation (for a server implementation, it's maybe too convenient to use one key for all clients), key rotation&revocation.
I suggest adding brief clarifying language that:
- this specification is packet-format focused,
- Sender Identifier does not mandate a single key-management model, and
- future companion specs may define interoperable key exchange/onboarding without changing the encapsulation format.
------------------------------
Zaiming Shi
EMQ Technologies Co., LTD
------------------------------