ZKDF(zkey, label): PRK_h := HKDF-Extract("key-derivation", zkey) h := HKDF-Expand(PRK_h, label || "gns", 512 / 8) zkey' := (h mod L) * zkey return zkey'