Derives a 32-byte AES-256 key from PRF output.
32-byte key suitable for AES-256-GCM
32-byte PRF output from the authenticator
Purpose string for domain separation (default: backup encryption)