Puncturable pseudorandom function.
This implementation and comments closely follows the one in libOTe.