> But I am still interested in schemes for deriving a key amongst multiple parties using a middleman without the middleman knowing the key. It seems like a rather hard problem.
This is exactly what happens when your browser establishes an HTTPS connection. There are many middlemen between you and the web server, but it still manages to negotiate a shared symmetric key (the session key) that can be used for the bulk of the encryption.
The difference is that there is no certificate authority vouching for each participant in a video call's identity, so you would need to do independent identity verification if you want to ensure that the call is secure, which some people would do by reading the public keys of each participant aloud, and people verifying that everything matches what they see.