I’m surprised session cookies, and cookies in general, are not already encrypted? But I suspect this is a more clever scheme?