Defines functions the key manager must expose.
Decrypt sealed with instance's keys.
Delete key set for instance.
Check if the key set for instance exists and is valid.
Generate a new key pair and auth secret for instance.
Get PublicKeySet for instance. Encoded to be shared to the application server.