A financial institution is implementing a new secure messaging system. The primary requirement is that if the long-term private key of a recipient is compromised, an attacker should not be able to decrypt past messages that were sent to that recipient. Which cryptographic property must the key exchange protocol implement to meet this requirement?