EXAM LOCKER
University Edition · Technical Dossier
Confidential - Pre-tender technical dossier
University Edition

EXAM
LOCKER

Secure Examination Paper Distribution Platform

Technical Architecture & Implementation Guide

Designed for universities, colleges and private examination bodies
The paper becomes unreadable before it enters the network.
No single person can release a sealed paper alone.
01No printing presses.
02No transport trucks.
03No strong rooms.
04No single-person release.
AuthorAnimesh, FDIW
(Fraud Detection & Intelligence Wing)
Date21 July 2026
StackPHP 8.x / MySQL 8.x, libsodium cryptography, encrypted object storage
02Short summary

Exam Locker, in simple terms.

A plain-English overview of the entire platform in under two minutes.

Exam Locker is a secure digital system for sending university examination papers to exam centres without printing them early, transporting them in trucks, or storing them in strong rooms.

Think of it like a bank locker for question papers. The final paper is first given a special identity for each exam centre, then encrypted - turned into unreadable locked data - before it is uploaded. Even if someone steals the server or downloads the file early, they cannot read the questions.

The digital key needed to open each paper is divided among five trusted university custodians. Any three must approve the release, so no single administrator can unlock or leak a sealed paper alone. The paper becomes readable only shortly before the examination, and only on the authorised computer at the correct centre.

Each centre receives its own marked version. If a printed paper is photographed or leaked, its visible and hidden markings can help identify where it came from.

Every important action - uploading, approval, unlocking, printing, failed login attempts and closing the session - is recorded in a tamper-evident audit history. This helps investigators understand exactly who did what and when.

In simple terms, Exam Locker replaces printing presses, transport trunks and strong rooms with encryption, shared authority, controlled printing and a complete digital record.

03Executive visual summary

The entire system in one page.

Designed to be understood in under thirty seconds, without any knowledge of cryptography.
Every centre receives its own encrypted edition. One exam-session ceremony requires any 3 of 5 named custodians before the authorised centre client can reconstruct that edition's key.
1. CreateFinal approved paper
2. EncryptPer-centre edition
3. StoreCiphertext only
4. ApproveAny 3 of 5
5. ReleaseOne session ceremony
6. PrintOwn marked edition
7. RecordImmutable audit
A hacker steals only locked data.The platform stores encrypted files, not readable examination papers.
No custodian can release a paper alone.Any three of five pre-provisioned custodians must approve the exam-session ceremony.
A leaked copy points back to its centre.Every centre receives an edition carrying visible and forensic identity marks.
A secure digital chain replaces printing presses, transport trunks and strong rooms.
04Plain-English explanation

What is Exam Locker?

The non-technical explanation for university leadership, governing bodies and public decision-makers.
How papers move today
Bulk printing pressMany people see the paper days early.
Physical transportTrunks can be opened, copied and resealed.
Strong-room storageKeys, guards and insiders create more leak points.
Early centre accessA photograph can circulate before the exam begins.
How Exam Locker works
The paper is locked digitally.It becomes unreadable before it is uploaded.
Three officials must approve.No single administrator can release it alone.
The centre opens only its own edition.It is released shortly before the examination.
Every action is recorded.Investigators can see who did what and when.
Think of it as a bank locker for examination papers.

One key is not enough. The locker opens only during the permitted time window, and every opening is recorded. The difference is that the “locker” contains encrypted data, so stealing the server does not reveal the paper.

Explained in plain English for any non-technical reader.

05Threat model

Six ways an examination paper can be compromised.

The physical lifecycle creates three familiar leak surfaces. Digitisation removes them, but introduces centre, digital and quorum risks that must be designed explicitly.
V1Printing
V2Transport
V3Strong room
V4Centre insider
V5Digital attack
V6 - Quorum compromise

Three compromised custodian credentials or devices could satisfy the threshold. Compensating controls: independent reporting lines, device-bound credentials, approval-pattern anomaly detection, ceremony logging, rapid revocation and mandatory post-event review.

06Threat boundary

The complete threat surface.

A credible system names where protection begins, what remains outside scope and how every leak vector is answered.
V0–V6 threat-response matrix · Complete lifecycle coverageSwipe horizontally
#Leak vectorTypical patternUniversity Edition response
V0Sealing-stage insider / compromised workstationReadable paper is copied before encryption or the sealing workstation is compromisedOutside the current cryptographic boundary. University controls apply before sealing; a controlled-authoring module is on the roadmap.
V1Printing press insiderPaper photographed during bulk printingCentral printing is eliminated.
V2Transport / logisticsSealed trunks opened and resealedPapers never travel physically.
V3Strong-room custodyLocker or treasury access collusionNo physical custody phase exists.
V4Centre insiderPaper opened or photographed earlyScheduled release, dual control and centre watermarking.
V5Digital compromiseServer breach or administrator abuseClient-side encryption, separated approvals and audit chain.
V6Quorum compromiseThree custodian credentials or devices are compromised or colludeIndependent reporting lines, device attestation, approval-pattern alerts, rapid revocation and evidence review.
Digitisation removes three physical leak surfaces - but it must not create a single powerful digital administrator.

Exam Locker therefore separates creation, approval, release and centre access. One compromised person is not enough to expose a paper.

Security boundary begins at sealing

Exam Locker protects the final approved paper from the moment the Sealing Officer encrypts it. From that point onward, the platform removes printing-press, transport and strong-room exposure.

Before sealing remains a university process

Drafting, moderation and committee circulation are outside this version's cryptographic boundary. Universities must control that stage through confidentiality policy, restricted access and documented approval. A controlled-authoring module may extend scope later.

07Before and after

What changes for a university.

The new system removes physical exposure while keeping the operating model simple for examination teams.
Traditional custody
×
Bulk printing
Readable papers exist days before the examination.
×
Physical transport
More custody points, seals and personnel.
×
Strong rooms
Access depends on physical keys and guards.
×
Single-person release authority
An insider may release or copy the paper.
×
Slow investigation
Leak source is difficult to prove.
Exam Locker
Encrypted at source
The paper is locked before any network transfer.
Digital delivery
No truck, trunk or courier custody.
Ciphertext storage
The cloud never stores a readable master.
Three-person approval
No single official can release it.
Evidence-ready audit
Every action is timestamped and traceable.
No printing presses. No transport trucks. No strong rooms. No single person can release a sealed examination paper alone.
08Authority model

Five custodians. Three required.

Five named custodians hold five distinct shares. Any three may form the fixed release quorum; no single custodian or administrator can reconstruct an edition key.
Controller of Examinations - A

Primary custodian. Holds one encrypted share and authorises the examination release ceremony.

University Security Officer - B

Primary custodian. Holds an independent share on a registered credential.

Independent Observer - C

Primary custodian. Holds an independent share and witnesses release.

Deputy Controller - D

Pre-provisioned alternate custodian with a distinct share created at sealing.

Alternate Observer - E

Pre-provisioned alternate custodian with a distinct share created at sealing.

Primary custodians: A - Controller of Examinations; B - University Security Officer; C - Independent Observer. Pre-provisioned alternates: D - Deputy Controller; E - Alternate Observer.
09Operational roles

Operations can run the system. They cannot read the paper.

Centre staff, investigators and the platform operator each receive only the access required for their role.
Paper Setter / Sealing Officer

Creates each centre-specific edition, encrypts it locally and never acts as a release custodian.

Centre Superintendent

Authenticates the assigned centre and conducts controlled printing. Does not hold a paper-key share.

Auditor / Investigator

Receives read-only custody records and verification exports for internal inquiry, police or appointed review.

Platform operator

Stores ciphertext and encrypted share capsules. It holds no custodian private key and cannot reconstruct any edition DEK.

Administrative access is not content access.

Managing users, centres or schedules never grants the ability to read an examination paper.

10Operational lifecycle

Nothing becomes readable until the last possible moment.

Every centre-specific edition has its own DEK. One exam-session quorum ceremony authorises the complete set of that session's centre capsules.
T-30 to
T-7 days
Seal every centre editionRender the centre identity first. Generate a fresh 256-bit DEK for each edition, encrypt it, split that edition DEK 3-of-5 and store five encrypted share capsules.
T-24h
Pre-deliver ciphertextEach centre downloads only its assigned encrypted bundle. No readable paper or reusable key is present.
T-45m
Readiness checkSuperintendent and Observer authenticate, verify the signed client and confirm the controlled printer.
T-30m
One quorum ceremony per exam sessionAny three of the five custodians approve once. Their signed release authorisation permits the platform to dispatch the already-prepared encrypted share capsules for every authorised centre edition in that session. Custodians do not perform one approval per centre.
T-29 to
T-5m
Controlled plaintext exposure windowThe signed centre client opens only its own three capsules, reconstructs only its own edition DEK in protected memory, decrypts and sends the marked edition to the controlled print service. This 24-minute window is monitored and fully logged.
T-0
Distribute and reconcilePrinted copy count is reconciled against candidate count; no other centre bundle can be opened with this edition DEK.
Post-exam
Attest and closeSurplus copies, client cleanup and session closure enter the custody chain.
11Safe release

No one releases a paper alone.

The University Edition uses Shamir Secret Sharing with a fixed threshold of 3-of-5.
Five custodians exist. Any three may form the quorum. One or two reveal nothing useful.
Window opensConfigured release time reached
Any 3 custodiansApprove one exam-session ceremony
Capsules dispatchedOnly to assigned centre clients
Local reconstructionOne edition DEK in protected memory
Print and zeroNo reusable download link
No operator decryption

The server routes encrypted capsules but owns no custodian private credential.

Alternates already exist

An alternate owns a distinct share created before sealing. No share is copied on exam day.

No emergency downgrade

Fewer than three available custodians causes a safe delay; the threshold never drops.

12Key custody

How the key is split.

One isolated key per centre edition. Five encrypted shares. Any three named custodians may form the quorum.
3/5
One edition. One fresh DEK. Five encrypted shares.

A fresh 256-bit DEK is generated for every centre-specific edition. Each edition DEK is split into five shares. One 3-of-5 quorum ceremony per exam session authorises dispatch of the precomputed encrypted capsules for all authorised editions in that session - not one ceremony per centre.

DEK scope

A unique DEK is generated for every centre-specific edition. A centre that reconstructs its own DEK cannot decrypt another centre's bundle.

Exam-day scale

For 45 centres, sealing creates 45 DEKs and 225 encrypted share capsules. Custodians approve once per exam session; the approval authorises dispatch of the precomputed capsules for all listed editions.

One quorum ceremony. Many centre editions. No shared universal key.

This preserves operational practicality without weakening centre isolation or forensic attribution.

13Custody operations

No hidden master key. No improvised alternate.

Backup, revocation, recovery and operator boundaries are defined before sealing - not invented during an emergency.
Custody medium

Each share is encrypted to one custodian public key. The private credential remains device-bound or in a university-controlled secure credential store.

Backup

An encrypted recovery copy may exist in an offline institutional vault. Recovery requires identity re-verification, two-person authorisation and a logged ceremony. There is no universal master share.

Alternate

An alternate approver receives nothing at T-30. They already own a separate share created at sealing and may join the same 3-of-5 quorum.

Revocation

A custodian can be disabled before release. Suspected credential compromise after sealing requires re-sealing every affected edition with a fresh DEK and five new shares.

Operator boundary

The platform holds ciphertext, manifests and encrypted capsules only. It cannot open three capsules and never reconstructs an edition DEK.

Emergency rule. Availability must never weaken custody: an alternate can participate only through a distinct share provisioned before sealing.
14Attribution

A paper that identifies where it came from.

Centre identity is embedded before encryption. Claims are tied to documented test conditions, not assumed robustness.
Centre-specific paper
UNIVERSITY EXAMINATION
Course: Sample Paper · Session: Morning
CENTRE U-042
1. Answer all questions.
2. The examination duration is three hours.
3. Use the supplied answer booklet.
Centre U-042 · Session AMCopy 0187
Visible identity

Centre code and session information appear on every page, discouraging resale and anonymous circulation.

Forensic identity

Subtle, redundant page variations encode the centre identity and survive ordinary photographs and recompression after testing.

Copy serial

Physical copy numbers support reconciliation with candidate counts and surplus destruction.

Any plaintext available at a centre is already attributable to that centre.
Assurance boundary. Watermark detection must be validated against defined camera angles, rotation, cropping, blur, photocopying and messaging-app recompression. Detection confidence and false-positive rates are reported. Collusion using multiple centre editions is a separate attack class and must be included in testing; no blanket “survives every photograph” claim is made before evidence exists.
15Audit and evidence

A complete record of every action.

The platform helps prevent leaks and also helps the university prove what happened when an allegation arises.
SealManifest created
UploadCiphertext stored
ApproveThree signatures
UnlockCentre session
PrintCount recorded
AttestSession closed
Hash-chained event record
{ seq, timestamp_utc, actor_id, event_type,
payload_sha256, previous_hash, signature }

Changing or deleting a historical event breaks the chain from that point onward. Regular external digest copies make silent history rewriting detectable.

Complete chronology

Successful and failed actions are recorded in one ordered custody history.

Tamper evidence

Cryptographic links expose alteration, deletion or event reordering.

Evidence export

A verification package can be supplied to the university, police or an appointed inquiry.

16Failure modes

What happens when something goes wrong.

Availability problems may delay printing, but they never weaken the custody rule.
Internet failure

Encrypted bundles are pre-delivered. Only the signed, short-lived release response requires live connectivity.

Power failure

The session pauses safely and resumes under the same authorised centre identity after power returns.

Cancelled exam

No quorum release occurs. Replacement editions are sealed under fresh DEKs and new shares.

Printer problem

A pre-authorised backup printer may be selected. The change is observed, approved and recorded.

Missing custodian

Any pre-provisioned alternate may join. Fewer than three available custodians causes a safe delay; no new share is issued.

Early or replayed release

The client rejects requests outside the window, expired messages, reused nonces or a centre/session mismatch and raises an alert.

The 24-minute plaintext window is named, monitored and bounded.

From local reconstruction to completed printing, the signed client is the security boundary. Screen capture, memory extraction and modified-client resistance are endpoint controls and must be tested explicitly.

17Operations dashboard

One live view of every examination centre.

The examination controller sees readiness, release, printing and closure status without accessing the paper itself.
Downloaded42 of 45 centres
93%
Unlocked0 - release window not open
PrintingLive count appears centre by centre
AttestedPost-exam closures and copy reconciliation
AnomalyOne centre has a printer-readiness warning
Readiness

Sign-in, printer and bundle status.

Approvals

Who has approved and when.

Print counts

Expected versus produced copies.

Alerts

Early attempts, mismatches and failures.

18Technical architecture

A deployable university platform.

The design is intentionally practical: standard infrastructure, a secure centre client and a clear cryptographic boundary around readable content.
University users
Sealing workstationCreates centre editions and encrypts locally
Approval portalAny 3 of 5 custodian approvals
Operations dashboardReadiness, print and attestation status
Exam centres
Authorised clientDevice-bound centre session
Controlled print serviceDirect print with spool cleanup
Local printerPre-authorised USB or managed connection
Exam Locker application core
PHP 8.x
Application and policy engine
MySQL 8.x
Roles, ceremonies and custody records
Object storage
Encrypted paper bundles only
Cryptography
libsodium / AEAD and digital signatures
The University Edition requires no dedicated hardware security module.

It is deployable on standard cloud or university infrastructure, while preserving separation of duties, client-side encryption and evidence-grade logging.

Edition isolation. Object storage may contain many centre bundles, but each bundle uses a different DEK. The three released capsules delivered to Centre U-042 reconstruct only U-042's DEK.
19Data model

The records that make the system real.

The first nine tables define tenants, exams, isolated centre editions, manifests, centres, staff, custodians and encrypted share capsules.
boards

University tenant, governance and retention settings.

exams

Schedule, session, release window and status.

papers

Approved paper identity, version and sealing state.

paper_editions

Centre-specific ciphertext, edition ID and isolated DEK metadata.

manifests

SHA-256 hashes, sizes, nonce, algorithm and object references.

centers

Authorised locations, registered clients and printer policy.

center_staff

Superintendent, Observer and controlled-session assignments.

custodians

Five named share holders, credential state and reporting line.

share_capsules

Five encrypted Shamir-share capsules per centre edition.

20Evidence persistence

Every ceremony becomes verifiable evidence.

The remaining tables preserve quorum decisions, one-time release messages, centre operations, external anchors, alerts and exportable evidence.
approval_ceremonies

One session-level quorum ceremony and signed approvals.

release_messages

Signed, expiring, nonce-bound, one-time release responses.

unlock_sessions

Centre client, edition, staff, timestamps and consumption state.

print_jobs

Printer identity, copies requested, produced and reconciled.

attestations

Closure, surplus destruction and observer confirmation.

custody_events

Append-only hash-chained event chronology.

anchors

External digest witnesses that make silent history rewriting detectable.

alerts

Replay, early access, quorum anomalies, mismatches and failures.

audit_exports

Evidence bundle, verification result and recipient record.

Edition createdpaper_editions + manifests
Shares preparedshare_capsules x 5 per edition
Quorum approvedapproval_ceremonies + release_messages
Centre operatedunlock_sessions + print_jobs + attestations
Evidence anchoredcustody_events + anchors + audit_exports
The external-anchor claim now has a home.

The anchors table stores periodic chain-head digests, witness identifiers, timestamps and receipts. The audit_exports table records the exact evidence package and verification result supplied to an authorised reviewer.

21Implementation notes

The practical security baseline.

A single defined cryptographic profile for the university pilot.
Encryption profile

AES-256-GCM is the mandatory paper-encryption algorithm for this final edition. A fresh random 256-bit DEK and unique 96-bit nonce are generated for every centre-specific edition. Algorithm agility may be designed internally, but the tender baseline is not written as “either/or.”

Key handling

Each edition DEK is split with Shamir Secret Sharing, threshold 3-of-5. Each share is encrypted to one named custodian public key. The platform stores encrypted capsules only.

Release message

Every release response is digitally signed and bound to exam_id, paper_id, edition_id, centre_id, session_id, release_window, nonce and expiry. The centre client records one-time consumption and rejects replay.

Signed client

A signed Electron/Tauri or native kiosk client is the security-bearing endpoint. A browser prototype may validate workflow, but is not presented as equivalent security.

Controlled printing

Persistent OS spooling is disabled where supported. Temporary material uses an encrypted volume or memory-backed storage, followed by verified cleanup and printer-cache handling.

Identity and custody

Custodian credentials are device-bound or held in a university-controlled secure credential store. Recovery, revocation and alternate activation follow the dedicated key-custody page.

Security claims attach to a precise profile: per-edition keys, 3-of-5 custody, signed one-time release messages and a controlled endpoint.
22Institutional fit

Why not simply use CBT?

Exam Locker protects paper-based examinations that still require centre-side printing. It complements computer-based testing rather than pretending every examination can become CBT.
Why not simply use CBT?

CBT requires devices, reliable power and connectivity, accessibility arrangements, secure test-delivery software and operational change at every seat. Many descriptive, diagrammatic, open-book or institution-specific examinations still require paper.

Where Exam Locker fits

It preserves the familiar paper examination while eliminating bulk pre-printing, physical transport and strong-room custody. Universities can adopt it without redesigning the examination itself.

23Assurance programme

Compliance must be earned.

Independent testing, documented controls and operating evidence convert architecture claims into procurement confidence.

CERT-In security audit

Commission independent application, infrastructure and source-code assessment through an appropriately empanelled information-security auditing organisation before production use.

STQC assurance path

Evaluate independent software testing, security assessment and product-certification options appropriate to the deployment and procurement context.

MeitY-aligned controls

Map hosting, identity, logging, incident response, data retention and government-cloud requirements where applicable to the institution or funding authority.

Public Examinations Act, 2024

Assess legal applicability with counsel. The Act addresses unfair means in defined public examinations; a university must determine whether its examination and authority fall within the statutory definitions.

Compliance is a verification programme, not a logo on a page.

The pilot should produce a threat model, secure-development evidence, independent test reports, incident procedures, retention policy and an auditable operating manual.

Official reference framework: CERT-In (national cyber-security agency and empanelled auditor ecosystem); STQC, Ministry of Electronics & Information Technology (software testing, assessment and certification services); The Public Examinations (Prevention of Unfair Means) Act, 2024, India Code. Applicability and certification scope require formal assessment.
24Pilot and rollout

Pilot. Prove. Audit. Scale.

A tightly scoped university pilot converts architecture claims into operational evidence.
Start with one real examination, a controlled set of centres and measurable acceptance criteria.
ScopeOne university, one examination family, 3-5 centres and a defined candidate volume.
DurationEight to twelve weeks including integration, rehearsal, live operation and post-exam review.
EvidenceIndependent security test, custody verification, print reconciliation and watermark performance report.
DecisionScale only after the university accepts the operational and security results.
01
Design and integrate

Map roles, provision five custodians, register centre clients, define recovery and configure the examination session.

02
Rehearse and test

Run cancellation, missing-custodian, network failure, printer failure, replay and incident-response exercises.

03
Operate and review

Conduct the live examination, export evidence, measure watermark recovery and document every exception.

Proposed next step

Authorise a university discovery and pilot-design workshop to define the first examination, participating centres, named custodians, success metrics, implementation responsibilities and commercial proposal.

Deliverable: signed pilot scope and implementation plan
25Closing position

A university-ready security model.

Practical enough to pilot. Precise enough to audit.
Secure the paper before it enters the network. Give every centre its own key. Require three independent custodians. Record everything.
No readable paper in storage

The platform holds ciphertext and encrypted capsules, not examination content.

No universal centre key

Every centre-specific edition uses a fresh DEK. One centre cannot open another centre's bundle.

No single-person release

A fixed 3-of-5 quorum is required; alternate custodians are pre-provisioned.

We cannot leak your readable paper because we do not store it. If a centre copy escapes, it already carries that centre's identity.

Move from dossier to pilot.

Approve the pilot-design workshop and select the first university examination for controlled implementation.