Would it be possible to give the key provider the option to specify the encryption key and protocols instead of just the KEK?