Stateful RFC 6979 HMAC-DRBG nonce generator.
Implements the deterministic nonce procedure of RFC 6979 Section 3.2. Keeping the DRBG state between candidates is what enables step h's retry rule: when a candidate k yields r = 0 or s = 0, signing must continue with the next DRBG output, not restart the sequence.