TLS uses certificate authorities and a public key infrastructure to ensure the authenticity of a peer. Is authenticity also something PSP provides, or is it focused on confidentiality and integrity?
> each NIC has two 256-bit AES keys, called master keys, not shared with any hosts including its own, or with any other NICs. The master keys are "critical security parameters",which are kept ephemerally in on-NIC RAM, and must not be stored on any persistent medium.
I take that to mean you do the asymmetric key stuff outside of PSP, then the symmetric key stuff is offloaded to PSP. Assuming you send a lot of data per connection, the symmetric key part will be much larger, so the expensive part is offloaded.