Nothing readable exists.
Every centre holds only its own encrypted edition. The network can move it, store it and verify it—but cannot read it.
\n
Skip to main contentUnreadable before the exam. Released only when three authorised custodians agree. Traceable after every print.
CertifyCircle Certified US Patent PendingMilitary Grade AES 256 bit Encryption
Encrypted centre editions move safely. Three named people authorise release. The assigned centre opens only its own paper, only inside the time window.
ExamLocker is designed around one exact transition: from unreadable ciphertext to an authorised centre paper. Nothing is left to habit, memory or a single person.
Every centre holds only its own encrypted edition. The network can move it, store it and verify it—but cannot read it.
Every centre holds only its own encrypted edition. The network can move it, store it and verify it—but cannot read it.
Five named custodians are eligible. Any three must independently approve the same exam session, centre and release window.
The assigned client reconstructs only its own key, prints within the authorised window and turns every action into evidence.
ExamLocker turns a paper into centre-specific ciphertext before distribution begins. The network moves locked editions. The authorised centre reveals only its own.
For days, a traditional paper stays readable as it passes through printers, vehicles, vaults and people. ExamLocker removes that exposure before distribution begins.
The paper remains encrypted through storage and delivery. It becomes readable only inside the authorised centre, shortly before printing.
No controller, administrator or operator can release a paper alone. Select three custodians to see the rule in action.
The threshold never drops. Fewer than three means a safe delay.Track every centre from readiness to closure—without exposing a single question to the controller or platform operator.
University Examination · 45 centres · 21 July 2026
Security is more than one lock. ExamLocker combines unique keys, attributable copies, expiring access and a custody history that can be verified later.
Opening one centre’s edition reveals nothing about another. There is no universal centre key.
Visible and forensic marks identify the centre, while copy serials support physical reconciliation.
Change or delete an event and the custody chain breaks from that point onward.
Early requests, expired messages, reused nonces and centre mismatches are rejected and alerted.
Deputy and alternate-observer shares are created at sealing. Nothing is copied or improvised on exam day.
Deploy on standard cloud or university infrastructure, while the sensitive work stays protected by centre-side encryption, device-bound access and evidence-grade records.
Creates centre editions and encrypts locally.
Collects any 3 of 5 custodian approvals.
Readiness, print and attestation status.
Roles, session policy, release authorisation and workflow orchestration.
No readable paper anywhere on the platformUsers, centres, ceremonies, approvals, nonces, print counts and attestations.
Centre bundles and encrypted share capsules only.
AEAD encryption, digital signatures, hashing and key operations.
Device-bound session and local reconstruction.
Direct print, copy count and spool cleanup.
Managed USB or approved local connection.
Map roles, name five custodians, register centre clients and configure the release window.
Rehearse cancellation, missing-custodian, network, printer, replay and incident scenarios.
Operate the live exam, export evidence, reconcile every copy and review every exception.
Explore the complete 24-section University Edition for technical, procurement, assurance and implementation review.
Open the full University Edition in a dedicated reader with its own table of contents, chapter navigation and responsive publication layout.
Designed to be understood in under thirty seconds, without any knowledge of cryptography.
The non-technical explanation for university leadership, governing bodies and public decision-makers.
One key is not enough. The locker opens only during the permitted time window, and every opening is recorded. The difference is that the “locker” contains encrypted data, so stealing the server does not reveal the paper.
Explained in plain English for any non-technical reader.
The physical lifecycle creates three familiar leak surfaces. Digitisation removes them, but introduces centre, digital and quorum risks that must be designed explicitly.
Three compromised custodian credentials or devices could satisfy the threshold. Compensating controls: independent reporting lines, device-bound credentials, approval-pattern anomaly detection, ceremony logging, rapid revocation and mandatory post-event review.
A credible system names where protection begins, what remains outside scope and how every leak vector is answered.
| # | Leak vector | Typical pattern | University Edition response |
|---|---|---|---|
| V0 | Sealing-stage insider / compromised workstation | Readable paper is copied before encryption or the sealing workstation is compromised | Outside the current cryptographic boundary. University controls apply before sealing; a controlled-authoring module is on the roadmap. |
| V1 | Printing press insider | Paper photographed during bulk printing | Central printing is eliminated. |
| V2 | Transport / logistics | Sealed trunks opened and resealed | Papers never travel physically. |
| V3 | Strong-room custody | Locker or treasury access collusion | No physical custody phase exists. |
| V4 | Centre insider | Paper opened or photographed early | Scheduled release, dual control and centre watermarking. |
| V5 | Digital compromise | Server breach or administrator abuse | Client-side encryption, separated approvals and audit chain. |
| V6 | Quorum compromise | Three custodian credentials or devices are compromised or collude | Independent reporting lines, device attestation, approval-pattern alerts, rapid revocation and evidence review. |
Exam Locker therefore separates creation, approval, release and centre access. One compromised person is not enough to expose a paper.
Exam Locker protects the final approved paper from the moment the Sealing Officer encrypts it. From that point onward, the platform removes printing-press, transport and strong-room exposure.
Drafting, moderation and committee circulation are outside this version's cryptographic boundary. Universities must control that stage through confidentiality policy, restricted access and documented approval. A controlled-authoring module may extend scope later.
The new system removes physical exposure while keeping the operating model simple for examination teams.
Five named custodians hold five distinct shares. Any three may form the fixed release quorum; no single custodian or administrator can reconstruct an edition key.
Primary custodian. Holds one encrypted share and authorises the examination release ceremony.
Primary custodian. Holds an independent share on a registered credential.
Primary custodian. Holds an independent share and witnesses release.
Pre-provisioned alternate custodian with a distinct share created at sealing.
Pre-provisioned alternate custodian with a distinct share created at sealing.
Centre staff, investigators and the platform operator each receive only the access required for their role.
Creates each centre-specific edition, encrypts it locally and never acts as a release custodian.
Authenticates the assigned centre and conducts controlled printing. Does not hold a paper-key share.
Receives read-only custody records and verification exports for internal inquiry, police or appointed review.
Stores ciphertext and encrypted share capsules. It holds no custodian private key and cannot reconstruct any edition DEK.
Managing users, centres or schedules never grants the ability to read an examination paper.
Every centre-specific edition has its own DEK. One exam-session quorum ceremony authorises the complete set of that session's centre capsules.
The University Edition uses Shamir Secret Sharing with a fixed threshold of 3-of-5.
The server routes encrypted capsules but owns no custodian private credential.
An alternate owns a distinct share created before sealing. No share is copied on exam day.
Fewer than three available custodians causes a safe delay; the threshold never drops.
One isolated key per centre edition. Five encrypted shares. Any three named custodians may form the quorum.
A fresh 256-bit DEK is generated for every centre-specific edition. Each edition DEK is split into five shares. One 3-of-5 quorum ceremony per exam session authorises dispatch of the precomputed encrypted capsules for all authorised editions in that session - not one ceremony per centre.
A unique DEK is generated for every centre-specific edition. A centre that reconstructs its own DEK cannot decrypt another centre's bundle.
For 45 centres, sealing creates 45 DEKs and 225 encrypted share capsules. Custodians approve once per exam session; the approval authorises dispatch of the precomputed capsules for all listed editions.
This preserves operational practicality without weakening centre isolation or forensic attribution.
Backup, revocation, recovery and operator boundaries are defined before sealing - not invented during an emergency.
Each share is encrypted to one custodian public key. The private credential remains device-bound or in a university-controlled secure credential store.
An encrypted recovery copy may exist in an offline institutional vault. Recovery requires identity re-verification, two-person authorisation and a logged ceremony. There is no universal master share.
An alternate approver receives nothing at T-30. They already own a separate share created at sealing and may join the same 3-of-5 quorum.
A custodian can be disabled before release. Suspected credential compromise after sealing requires re-sealing every affected edition with a fresh DEK and five new shares.
The platform holds ciphertext, manifests and encrypted capsules only. It cannot open three capsules and never reconstructs an edition DEK.
Centre identity is embedded before encryption. Claims are tied to documented test conditions, not assumed robustness.
Centre code and session information appear on every page, discouraging resale and anonymous circulation.
Subtle, redundant page variations encode the centre identity and survive ordinary photographs and recompression after testing.
Physical copy numbers support reconciliation with candidate counts and surplus destruction.
The platform helps prevent leaks and also helps the university prove what happened when an allegation arises.
Changing or deleting a historical event breaks the chain from that point onward. Regular external digest copies make silent history rewriting detectable.
Successful and failed actions are recorded in one ordered custody history.
Cryptographic links expose alteration, deletion or event reordering.
A verification package can be supplied to the university, police or an appointed inquiry.
Availability problems may delay printing, but they never weaken the custody rule.
Encrypted bundles are pre-delivered. Only the signed, short-lived release response requires live connectivity.
The session pauses safely and resumes under the same authorised centre identity after power returns.
No quorum release occurs. Replacement editions are sealed under fresh DEKs and new shares.
A pre-authorised backup printer may be selected. The change is observed, approved and recorded.
Any pre-provisioned alternate may join. Fewer than three available custodians causes a safe delay; no new share is issued.
The client rejects requests outside the window, expired messages, reused nonces or a centre/session mismatch and raises an alert.
From local reconstruction to completed printing, the signed client is the security boundary. Screen capture, memory extraction and modified-client resistance are endpoint controls and must be tested explicitly.
The examination controller sees readiness, release, printing and closure status without accessing the paper itself.
Sign-in, printer and bundle status.
Who has approved and when.
Expected versus produced copies.
Early attempts, mismatches and failures.
The design is intentionally practical: standard infrastructure, a secure centre client and a clear cryptographic boundary around readable content.
It is deployable on standard cloud or university infrastructure, while preserving separation of duties, client-side encryption and evidence-grade logging.
The first nine tables define tenants, exams, isolated centre editions, manifests, centres, staff, custodians and encrypted share capsules.
boardsUniversity tenant, governance and retention settings.
examsSchedule, session, release window and status.
papersApproved paper identity, version and sealing state.
paper_editionsCentre-specific ciphertext, edition ID and isolated DEK metadata.
manifestsSHA-256 hashes, sizes, nonce, algorithm and object references.
centersAuthorised locations, registered clients and printer policy.
center_staffSuperintendent, Observer and controlled-session assignments.
custodiansFive named share holders, credential state and reporting line.
share_capsulesFive encrypted Shamir-share capsules per centre edition.
The remaining tables preserve quorum decisions, one-time release messages, centre operations, external anchors, alerts and exportable evidence.
approval_ceremoniesOne session-level quorum ceremony and signed approvals.
release_messagesSigned, expiring, nonce-bound, one-time release responses.
unlock_sessionsCentre client, edition, staff, timestamps and consumption state.
print_jobsPrinter identity, copies requested, produced and reconciled.
attestationsClosure, surplus destruction and observer confirmation.
custody_eventsAppend-only hash-chained event chronology.
anchorsExternal digest witnesses that make silent history rewriting detectable.
alertsReplay, early access, quorum anomalies, mismatches and failures.
audit_exportsEvidence bundle, verification result and recipient record.
The anchors table stores periodic chain-head digests, witness identifiers, timestamps and receipts. The audit_exports table records the exact evidence package and verification result supplied to an authorised reviewer.
A single defined cryptographic profile for the university pilot.
AES-256-GCM is the mandatory paper-encryption algorithm for this final edition. A fresh random 256-bit DEK and unique 96-bit nonce are generated for every centre-specific edition. Algorithm agility may be designed internally, but the tender baseline is not written as “either/or.”
Each edition DEK is split with Shamir Secret Sharing, threshold 3-of-5. Each share is encrypted to one named custodian public key. The platform stores encrypted capsules only.
Every release response is digitally signed and bound to exam_id, paper_id, edition_id, centre_id, session_id, release_window, nonce and expiry. The centre client records one-time consumption and rejects replay.
A signed Electron/Tauri or native kiosk client is the security-bearing endpoint. A browser prototype may validate workflow, but is not presented as equivalent security.
Persistent OS spooling is disabled where supported. Temporary material uses an encrypted volume or memory-backed storage, followed by verified cleanup and printer-cache handling.
Custodian credentials are device-bound or held in a university-controlled secure credential store. Recovery, revocation and alternate activation follow the dedicated key-custody page.
Exam Locker protects paper-based examinations that still require centre-side printing. It complements computer-based testing rather than pretending every examination can become CBT.
CBT requires devices, reliable power and connectivity, accessibility arrangements, secure test-delivery software and operational change at every seat. Many descriptive, diagrammatic, open-book or institution-specific examinations still require paper.
It preserves the familiar paper examination while eliminating bulk pre-printing, physical transport and strong-room custody. Universities can adopt it without redesigning the examination itself.
Independent testing, documented controls and operating evidence convert architecture claims into procurement confidence.
Commission independent application, infrastructure and source-code assessment through an appropriately empanelled information-security auditing organisation before production use.
Evaluate independent software testing, security assessment and product-certification options appropriate to the deployment and procurement context.
Map hosting, identity, logging, incident response, data retention and government-cloud requirements where applicable to the institution or funding authority.
Assess legal applicability with counsel. The Act addresses unfair means in defined public examinations; a university must determine whether its examination and authority fall within the statutory definitions.
The pilot should produce a threat model, secure-development evidence, independent test reports, incident procedures, retention policy and an auditable operating manual.
A tightly scoped university pilot converts architecture claims into operational evidence.
Map roles, provision five custodians, register centre clients, define recovery and configure the examination session.
Run cancellation, missing-custodian, network failure, printer failure, replay and incident-response exercises.
Conduct the live examination, export evidence, measure watermark recovery and document every exception.
Authorise a university discovery and pilot-design workshop to define the first examination, participating centres, named custodians, success metrics, implementation responsibilities and commercial proposal.
Practical enough to pilot. Precise enough to audit.
The platform holds ciphertext and encrypted capsules, not examination content.
Every centre-specific edition uses a fresh DEK. One centre cannot open another centre's bundle.
A fixed 3-of-5 quorum is required; alternate custodians are pre-provisioned.
Approve the pilot-design workshop and select the first university examination for controlled implementation.
One centre-specific edition. Three independent approvals. One controlled print window. A permanent record of what happened.