Ok, CC'd! That said, here's a followup:

I was kind of confused why you cite RFC7748, but then go on to explain
things in terms of classical Diffie-Hellman.

As far as an ECC-based approach goes, I think something like the multiparty
Signal protocol[1] is a good starting point for how to solve the general
problem, and, as far as I can tell, addresses most of the concerns you
cited as a motivation.

The specific approach you detailed could be adapted to ECC as well.

[1] I'm not sure there's a more recent overview than this, which is
probably out-of-date: https://whispersystems.org/blog/private-groups/

