http://i3xi5qxvbrngh3g6o7czwjfxwjzigook7zxzjmgwg5b7xnjcn5hzciad.onion/proposals/269-hybrid-handshake.html
The server responds with an ephemeral DH public key and an
encapsulation of a random secret under the client's ephemeral KEM key. The
two parties then derive a shared secret from: 1) the static-ephemeral DH
share, 2) the ephemeral-ephemeral DH share, 3) the encapsulated secret, 4)
the transcript of their communication.
2.2 Notation
Public, non-secret, values are denoted in UPPER CASE.