Actually it loks like (n+1)sec isn't perfect: a symmetric key is shared by all participants for a certain amount of time, until a participant joins or leaves or asks for re-keying. So you have a chunk of messages, with no upper bound on how many messages share the same symmetric key.