\n
EXAM LOCKERUniversity Edition

The world’s most secure
examination vault.

Unreadable before the exam. Released only when three authorised custodians agree. Traceable after every print.

CertifyCircle Certified US Patent PendingMilitary Grade AES 256 bit Encryption

EXAMINATION DAY · RELEASE WINDOW09:29:58
BEFORE RELEASEUnreadable everywhere.
AFTER APPROVALOne centre. One edition.
UNIVERSITY EXAMINATIONFINAL PAPER
SEALEDCIPHERTEXTNO READABLE MASTER
CENTRE U-042KEY 42 · AEAD
ARegistrarAPPROVED
BControllerAPPROVED
CDeanAPPROVED
DObserverSTANDBY
ENomineeSTANDBY
THRESHOLD MET3 / 5Centre U-042 authorised for controlled print
01Encrypted before distributionNo readable paper enters the network.
02Collective release authorityNo one person can open it.
03Centre-specific accountabilityEvery copy retains its origin.
The physical leak chain disappears.
Noprinting press. Notransport truck. Nostrong room. Nomaster key.
What remains is a controlled digital ceremony.

Encrypted centre editions move safely. Three named people authorise release. The assigned centre opens only its own paper, only inside the time window.

The defining moment

Security is not a screen.
It is a ceremony.

ExamLocker is designed around one exact transition: from unreadable ciphertext to an authorised centre paper. Nothing is left to habit, memory or a single person.

01 · BEFORE

Nothing readable exists.

Every centre holds only its own encrypted edition. The network can move it, store it and verify it—but cannot read it.

01 · BEFORE

Nothing readable exists.

Every centre holds only its own encrypted edition. The network can move it, store it and verify it—but cannot read it.

02 · THE CEREMONY

Authority becomes collective.

Five named custodians are eligible. Any three must independently approve the same exam session, centre and release window.

03 · THE MOMENT

Exactly one centre can open.

The assigned client reconstructs only its own key, prints within the authorised window and turns every action into evidence.

EXAM SESSION09:29:58
U-042ENCRYPTED EDITIONAEAD · KEY 42 · SEALED
UNREADABLE
THRESHOLD0 / 3Paper remains sealed
09:29:58 · RELEASE CEREMONY CREATEDSESSION EL-2026-0721-AM
Security, made visible

Readable nowhere.
Ready exactly once.

ExamLocker turns a paper into centre-specific ciphertext before distribution begins. The network moves locked editions. The authorised centre reveals only its own.

FINAL PAPER
Approved source
ENCRYPTED AT SOURCE
U-042KEY 42
U-018KEY 18
U-027KEY 27
U-031KEY 31
U-009KEY 09
Isolated centre editions
01
FINAL PAPER
Approved sourceReadable only on the sealing device.
ENCRYPTED BEFORE DISTRIBUTION
02
Ciphertext onlyNo readable master paper enters the network.
ONE FRESH KEY PER CENTRE
03
U-009KEY 09
U-027KEY 27
U-031KEY 31
Isolated centre editionsEach centre can open only its own assigned copy.
01Encrypted before uploadThe readable paper never enters the platform.
02Isolated by centreA compromise cannot expose every edition.
03Released by ceremonyAny three of five custodians must agree.
Why it exists

The paper is vulnerable long before the exam.

For days, a traditional paper stays readable as it passes through printers, vehicles, vaults and people. ExamLocker removes that exposure before distribution begins.

Printed too earlyReadable copies exist days before the examination.
V1
Moved by handA sealed trunk can still be opened, copied and closed again.
V2
Protected by more peopleEvery key, guard and handoff adds another point of failure.
V3
Digital, without concentrated powerEndpoint, credential and quorum risks are controlled without creating one all-powerful administrator.
V4–V6

Lock it before it moves.

Create a different cryptographic key for every centre.
Divide release authority across five named custodians. Any three must agree.
Open only on the assigned centre client, within the authorised time window.
Turn every seal, approval, print and closure into verifiable evidence.
How it works

Locked from the start.
Ready at the right moment.

The paper remains encrypted through storage and delivery. It becomes readable only inside the authorised centre, shortly before printing.

01CreateOne approved paper becomes a unique edition for each centre.
02EncryptA fresh key locks every edition before it leaves the sealing device.
03StoreThe platform keeps ciphertext. Never a readable master paper.
04ApproveAny three of five custodians authorise the exam session.
05ReleaseEncrypted capsules travel only to the assigned centre client.
06PrintThe client reconstructs one key in protected memory, then prints.
07RecordEvery action and exception becomes part of a tamper-evident history.
Shared authority

Five custodians.
Any three.
Never one.

No controller, administrator or operator can release a paper alone. Select three custodians to see the rule in action.

The threshold never drops. Fewer than three means a safe delay.
Exam-session releaseChoose three
Release window09:30–09:54
Threshold0 / 3
Assigned centreU-042
Choose any three custodiansOne or two approvals cannot open anything.
Operations platform

See the whole exam.
Not the paper.

Track every centre from readiness to closure—without exposing a single question to the controller or platform operator.

Morning examination

University Examination · 45 centres · 21 July 2026

LIVE STATUS
Centres prepared42/4542 of 45 ready
Release approvals0/3Window not open
Centres printing0Awaiting release
Issues to review1Printer readiness
Centre readinessView all centres
U-042 · North CampusReady240 copies
U-018 · City CollegeReady180 copies
U-027 · Science BlockWarning320 copies
U-031 · East CampusReady210 copies
U-009 · Law FacultyReady160 copies
Custody activityLive custody record
Bundle verified · U-042Signed client and printer confirmed · 08:14
Readiness warning · U-027Backup printer confirmation required · 08:12
Bundle downloaded · U-018Ciphertext integrity verified · 08:08
External digest publishedCustody chain checkpoint · 08:00
Security by design

Every centre isolated.
Every copy accountable.

Security is more than one lock. ExamLocker combines unique keys, attributable copies, expiring access and a custody history that can be verified later.

One centre. One key.

Opening one centre’s edition reveals nothing about another. There is no universal centre key.

45×centre-specific keys

Every copy carries its origin.

Visible and forensic marks identify the centre, while copy serials support physical reconciliation.

UNIVERSITY EXAMINATIONCENTRE U-042 · COPY 0187

History that resists rewriting.

Change or delete an event and the custody chain breaks from that point onward.

Access that expires.

Early requests, expired messages, reused nonces and centre mismatches are rejected and alerted.

24mauthorised release window

Alternates, ready in advance.

Deputy and alternate-observer shares are created at sealing. Nothing is copied or improvised on exam day.

2pre-provisioned alternates
08:00:00 DIGEST PUBLISHED 08:08:14 CIPHERTEXT VERIFIED · U-018 09:29:58 CEREMONY OPENED 09:30:04 APPROVAL 01 · SIGNED 09:30:11 APPROVAL 02 · SIGNED 09:30:18 APPROVAL 03 · THRESHOLD MET 09:30:19 CENTRE KEY RECONSTRUCTED · U-042 09:31:02 PRINT JOB 001 · 240 COPIES
Architecture

Built for universities.
Designed like critical infrastructure.

Deploy on standard cloud or university infrastructure, while the sensitive work stays protected by centre-side encryption, device-bound access and evidence-grade records.

University users
Sealing workstation

Creates centre editions and encrypts locally.

Approval portal

Collects any 3 of 5 custodian approvals.

Operations dashboard

Readiness, print and attestation status.

Exam Locker application core
PHP 8.x policy engine

Roles, session policy, release authorisation and workflow orchestration.

No readable paper anywhere on the platform
MySQL 8.x custody records

Users, centres, ceremonies, approvals, nonces, print counts and attestations.

Encrypted object storage

Centre bundles and encrypted share capsules only.

libsodium cryptography

AEAD encryption, digital signatures, hashing and key operations.

Exam centres
Authorised centre client

Device-bound session and local reconstruction.

Controlled print service

Direct print, copy count and spool cleanup.

Pre-authorised printer

Managed USB or approved local connection.

Pilot and rollout

Start small.
Prove everything.

01
Design the first exam

Map roles, name five custodians, register centre clients and configure the release window.

02
Test the unexpected

Rehearse cancellation, missing-custodian, network, printer, replay and incident scenarios.

03
Run. Verify. Improve.

Operate the live exam, export evidence, reconcile every copy and review every exception.

The complete technical story

For everyone who needs the details.

Explore the complete 24-section University Edition for technical, procurement, assurance and implementation review.

Standalone documentPrefer the complete dossier as its own publication?

Open the full University Edition in a dedicated reader with its own table of contents, chapter navigation and responsive publication layout.

Open Technical Dossier
University Edition24-part technical architecture
Choose a chapter24 chapters
02The entire system in one page.Designed to be understood in under thirty seconds, without any knowledge of cryptography.
UNIVERSITY EDITION · CHAPTER 02

The entire system in one page.

Designed to be understood in under thirty seconds, without any knowledge of cryptography.

ExamLockerTECHNICAL DOSSIER
Every centre receives its own encrypted edition. One exam-session ceremony requires any 3 of 5 named custodians before the authorised centre client can reconstruct that edition's key.
1. CreateFinal approved paper
2. EncryptPer-centre edition
3. StoreCiphertext only
4. ApproveAny 3 of 5
5. ReleaseOne session ceremony
6. PrintOwn marked edition
7. RecordImmutable audit
A hacker steals only locked data.The platform stores encrypted files, not readable examination papers.
No custodian can release a paper alone.Any three of five pre-provisioned custodians must approve the exam-session ceremony.
A leaked copy points back to its centre.Every centre receives an edition carrying visible and forensic identity marks.
A secure digital chain replaces printing presses, transport trunks and strong rooms.
03What is Exam Locker?The non-technical explanation for university leadership, governing bodies and public decision-makers.
UNIVERSITY EDITION · CHAPTER 03

What is Exam Locker?

The non-technical explanation for university leadership, governing bodies and public decision-makers.

ExamLockerTECHNICAL DOSSIER
How papers move today
Bulk printing pressMany people see the paper days early.
Physical transportTrunks can be opened, copied and resealed.
Strong-room storageKeys, guards and insiders create more leak points.
Early centre accessA photograph can circulate before the exam begins.
How Exam Locker works
The paper is locked digitally.It becomes unreadable before it is uploaded.
Three officials must approve.No single administrator can release it alone.
The centre opens only its own edition.It is released shortly before the examination.
Every action is recorded.Investigators can see who did what and when.
Think of it as a bank locker for examination papers.

One key is not enough. The locker opens only during the permitted time window, and every opening is recorded. The difference is that the “locker” contains encrypted data, so stealing the server does not reveal the paper.

Explained in plain English for any non-technical reader.

04Six ways an examination paper can be compromised.The physical lifecycle creates three familiar leak surfaces. Digitisation removes them, but introduces centre, digital and quorum risks that must be designed explicitly.
UNIVERSITY EDITION · CHAPTER 04

Six ways an examination paper can be compromised.

The physical lifecycle creates three familiar leak surfaces. Digitisation removes them, but introduces centre, digital and quorum risks that must be designed explicitly.

ExamLockerTECHNICAL DOSSIER
V1Printing
V2Transport
V3Strong room
V4Centre insider
V5Digital attack
V6 - Quorum compromise

Three compromised custodian credentials or devices could satisfy the threshold. Compensating controls: independent reporting lines, device-bound credentials, approval-pattern anomaly detection, ceremony logging, rapid revocation and mandatory post-event review.

05The complete threat surface.A credible system names where protection begins, what remains outside scope and how every leak vector is answered.
UNIVERSITY EDITION · CHAPTER 05

The complete threat surface.

A credible system names where protection begins, what remains outside scope and how every leak vector is answered.

ExamLockerTECHNICAL DOSSIER
V0–V6 threat-response matrix · Complete lifecycle coverageSwipe horizontally
#Leak vectorTypical patternUniversity Edition response
V0Sealing-stage insider / compromised workstationReadable paper is copied before encryption or the sealing workstation is compromisedOutside the current cryptographic boundary. University controls apply before sealing; a controlled-authoring module is on the roadmap.
V1Printing press insiderPaper photographed during bulk printingCentral printing is eliminated.
V2Transport / logisticsSealed trunks opened and resealedPapers never travel physically.
V3Strong-room custodyLocker or treasury access collusionNo physical custody phase exists.
V4Centre insiderPaper opened or photographed earlyScheduled release, dual control and centre watermarking.
V5Digital compromiseServer breach or administrator abuseClient-side encryption, separated approvals and audit chain.
V6Quorum compromiseThree custodian credentials or devices are compromised or colludeIndependent reporting lines, device attestation, approval-pattern alerts, rapid revocation and evidence review.
Digitisation removes three physical leak surfaces - but it must not create a single powerful digital administrator.

Exam Locker therefore separates creation, approval, release and centre access. One compromised person is not enough to expose a paper.

Security boundary begins at sealing

Exam Locker protects the final approved paper from the moment the Sealing Officer encrypts it. From that point onward, the platform removes printing-press, transport and strong-room exposure.

Before sealing remains a university process

Drafting, moderation and committee circulation are outside this version's cryptographic boundary. Universities must control that stage through confidentiality policy, restricted access and documented approval. A controlled-authoring module may extend scope later.

06What changes for a university.The new system removes physical exposure while keeping the operating model simple for examination teams.
UNIVERSITY EDITION · CHAPTER 06

What changes for a university.

The new system removes physical exposure while keeping the operating model simple for examination teams.

ExamLockerTECHNICAL DOSSIER
Traditional custody
×
Bulk printing
Readable papers exist days before the examination.
×
Physical transport
More custody points, seals and personnel.
×
Strong rooms
Access depends on physical keys and guards.
×
Single-person release authority
An insider may release or copy the paper.
×
Slow investigation
Leak source is difficult to prove.
Exam Locker
Encrypted at source
The paper is locked before any network transfer.
Digital delivery
No truck, trunk or courier custody.
Ciphertext storage
The cloud never stores a readable master.
Three-person approval
No single official can release it.
Evidence-ready audit
Every action is timestamped and traceable.
No printing presses. No transport trucks. No strong rooms. No single person can release a sealed examination paper alone.
07Five custodians. Three required.Five named custodians hold five distinct shares. Any three may form the fixed release quorum; no single custodian or administrator can reconstruct an edition key.
UNIVERSITY EDITION · CHAPTER 07

Five custodians. Three required.

Five named custodians hold five distinct shares. Any three may form the fixed release quorum; no single custodian or administrator can reconstruct an edition key.

ExamLockerTECHNICAL DOSSIER
Controller of Examinations - A

Primary custodian. Holds one encrypted share and authorises the examination release ceremony.

University Security Officer - B

Primary custodian. Holds an independent share on a registered credential.

Independent Observer - C

Primary custodian. Holds an independent share and witnesses release.

Deputy Controller - D

Pre-provisioned alternate custodian with a distinct share created at sealing.

Alternate Observer - E

Pre-provisioned alternate custodian with a distinct share created at sealing.

Primary custodians: A - Controller of Examinations; B - University Security Officer; C - Independent Observer. Pre-provisioned alternates: D - Deputy Controller; E - Alternate Observer.
08Operations can run the system. They cannot read the paper.Centre staff, investigators and the platform operator each receive only the access required for their role.
UNIVERSITY EDITION · CHAPTER 08

Operations can run the system. They cannot read the paper.

Centre staff, investigators and the platform operator each receive only the access required for their role.

ExamLockerTECHNICAL DOSSIER
Paper Setter / Sealing Officer

Creates each centre-specific edition, encrypts it locally and never acts as a release custodian.

Centre Superintendent

Authenticates the assigned centre and conducts controlled printing. Does not hold a paper-key share.

Auditor / Investigator

Receives read-only custody records and verification exports for internal inquiry, police or appointed review.

Platform operator

Stores ciphertext and encrypted share capsules. It holds no custodian private key and cannot reconstruct any edition DEK.

Administrative access is not content access.

Managing users, centres or schedules never grants the ability to read an examination paper.

09Nothing becomes readable until the last possible moment.Every centre-specific edition has its own DEK. One exam-session quorum ceremony authorises the complete set of that session's centre capsules.
UNIVERSITY EDITION · CHAPTER 09

Nothing becomes readable until the last possible moment.

Every centre-specific edition has its own DEK. One exam-session quorum ceremony authorises the complete set of that session's centre capsules.

ExamLockerTECHNICAL DOSSIER
T-30 to
T-7 days
Seal every centre editionRender the centre identity first. Generate a fresh 256-bit DEK for each edition, encrypt it, split that edition DEK 3-of-5 and store five encrypted share capsules.
T-24h
Pre-deliver ciphertextEach centre downloads only its assigned encrypted bundle. No readable paper or reusable key is present.
T-45m
Readiness checkSuperintendent and Observer authenticate, verify the signed client and confirm the controlled printer.
T-30m
One quorum ceremony per exam sessionAny three of the five custodians approve once. Their signed release authorisation permits the platform to dispatch the already-prepared encrypted share capsules for every authorised centre edition in that session. Custodians do not perform one approval per centre.
T-29 to
T-5m
Controlled plaintext exposure windowThe signed centre client opens only its own three capsules, reconstructs only its own edition DEK in protected memory, decrypts and sends the marked edition to the controlled print service. This 24-minute window is monitored and fully logged.
T-0
Distribute and reconcilePrinted copy count is reconciled against candidate count; no other centre bundle can be opened with this edition DEK.
Post-exam
Attest and closeSurplus copies, client cleanup and session closure enter the custody chain.
10No one releases a paper alone.The University Edition uses Shamir Secret Sharing with a fixed threshold of 3-of-5.
UNIVERSITY EDITION · CHAPTER 10

No one releases a paper alone.

The University Edition uses Shamir Secret Sharing with a fixed threshold of 3-of-5.

ExamLockerTECHNICAL DOSSIER
Five custodians exist. Any three may form the quorum. One or two reveal nothing useful.
Window opensConfigured release time reached
Any 3 custodiansApprove one exam-session ceremony
Capsules dispatchedOnly to assigned centre clients
Local reconstructionOne edition DEK in protected memory
Print and zeroNo reusable download link
No operator decryption

The server routes encrypted capsules but owns no custodian private credential.

Alternates already exist

An alternate owns a distinct share created before sealing. No share is copied on exam day.

No emergency downgrade

Fewer than three available custodians causes a safe delay; the threshold never drops.

11How the key is split.One isolated key per centre edition. Five encrypted shares. Any three named custodians may form the quorum.
UNIVERSITY EDITION · CHAPTER 11

How the key is split.

One isolated key per centre edition. Five encrypted shares. Any three named custodians may form the quorum.

ExamLockerTECHNICAL DOSSIER
3/5
One edition. One fresh DEK. Five encrypted shares.

A fresh 256-bit DEK is generated for every centre-specific edition. Each edition DEK is split into five shares. One 3-of-5 quorum ceremony per exam session authorises dispatch of the precomputed encrypted capsules for all authorised editions in that session - not one ceremony per centre.

DEK scope

A unique DEK is generated for every centre-specific edition. A centre that reconstructs its own DEK cannot decrypt another centre's bundle.

Exam-day scale

For 45 centres, sealing creates 45 DEKs and 225 encrypted share capsules. Custodians approve once per exam session; the approval authorises dispatch of the precomputed capsules for all listed editions.

One quorum ceremony. Many centre editions. No shared universal key.

This preserves operational practicality without weakening centre isolation or forensic attribution.

12No hidden master key. No improvised alternate.Backup, revocation, recovery and operator boundaries are defined before sealing - not invented during an emergency.
UNIVERSITY EDITION · CHAPTER 12

No hidden master key. No improvised alternate.

Backup, revocation, recovery and operator boundaries are defined before sealing - not invented during an emergency.

ExamLockerTECHNICAL DOSSIER
Custody medium

Each share is encrypted to one custodian public key. The private credential remains device-bound or in a university-controlled secure credential store.

Backup

An encrypted recovery copy may exist in an offline institutional vault. Recovery requires identity re-verification, two-person authorisation and a logged ceremony. There is no universal master share.

Alternate

An alternate approver receives nothing at T-30. They already own a separate share created at sealing and may join the same 3-of-5 quorum.

Revocation

A custodian can be disabled before release. Suspected credential compromise after sealing requires re-sealing every affected edition with a fresh DEK and five new shares.

Operator boundary

The platform holds ciphertext, manifests and encrypted capsules only. It cannot open three capsules and never reconstructs an edition DEK.

Emergency rule. Availability must never weaken custody: an alternate can participate only through a distinct share provisioned before sealing.
13A paper that identifies where it came from.Centre identity is embedded before encryption. Claims are tied to documented test conditions, not assumed robustness.
UNIVERSITY EDITION · CHAPTER 13

A paper that identifies where it came from.

Centre identity is embedded before encryption. Claims are tied to documented test conditions, not assumed robustness.

ExamLockerTECHNICAL DOSSIER
Centre-specific paper
UNIVERSITY EXAMINATION
Course: Sample Paper · Session: Morning
CENTRE U-042
1. Answer all questions.
2. The examination duration is three hours.
3. Use the supplied answer booklet.
Visible identity

Centre code and session information appear on every page, discouraging resale and anonymous circulation.

Forensic identity

Subtle, redundant page variations encode the centre identity and survive ordinary photographs and recompression after testing.

Copy serial

Physical copy numbers support reconciliation with candidate counts and surplus destruction.

Any plaintext available at a centre is already attributable to that centre.
Assurance boundary. Watermark detection must be validated against defined camera angles, rotation, cropping, blur, photocopying and messaging-app recompression. Detection confidence and false-positive rates are reported. Collusion using multiple centre editions is a separate attack class and must be included in testing; no blanket “survives every photograph” claim is made before evidence exists.
14A complete record of every action.The platform helps prevent leaks and also helps the university prove what happened when an allegation arises.
UNIVERSITY EDITION · CHAPTER 14

A complete record of every action.

The platform helps prevent leaks and also helps the university prove what happened when an allegation arises.

ExamLockerTECHNICAL DOSSIER
SealManifest created
UploadCiphertext stored
ApproveThree signatures
UnlockCentre session
PrintCount recorded
AttestSession closed
Hash-chained event record
{ seq, timestamp_utc, actor_id, event_type,
payload_sha256, previous_hash, signature }

Changing or deleting a historical event breaks the chain from that point onward. Regular external digest copies make silent history rewriting detectable.

Complete chronology

Successful and failed actions are recorded in one ordered custody history.

Tamper evidence

Cryptographic links expose alteration, deletion or event reordering.

Evidence export

A verification package can be supplied to the university, police or an appointed inquiry.

15What happens when something goes wrong.Availability problems may delay printing, but they never weaken the custody rule.
UNIVERSITY EDITION · CHAPTER 15

What happens when something goes wrong.

Availability problems may delay printing, but they never weaken the custody rule.

ExamLockerTECHNICAL DOSSIER
Internet failure

Encrypted bundles are pre-delivered. Only the signed, short-lived release response requires live connectivity.

Power failure

The session pauses safely and resumes under the same authorised centre identity after power returns.

Cancelled exam

No quorum release occurs. Replacement editions are sealed under fresh DEKs and new shares.

Printer problem

A pre-authorised backup printer may be selected. The change is observed, approved and recorded.

Missing custodian

Any pre-provisioned alternate may join. Fewer than three available custodians causes a safe delay; no new share is issued.

Early or replayed release

The client rejects requests outside the window, expired messages, reused nonces or a centre/session mismatch and raises an alert.

The 24-minute plaintext window is named, monitored and bounded.

From local reconstruction to completed printing, the signed client is the security boundary. Screen capture, memory extraction and modified-client resistance are endpoint controls and must be tested explicitly.

16One live view of every examination centre.The examination controller sees readiness, release, printing and closure status without accessing the paper itself.
UNIVERSITY EDITION · CHAPTER 16

One live view of every examination centre.

The examination controller sees readiness, release, printing and closure status without accessing the paper itself.

ExamLockerTECHNICAL DOSSIER
Downloaded42 of 45 centres
93%
Unlocked0 - release window not open
PrintingLive count appears centre by centre
AttestedPost-exam closures and copy reconciliation
AnomalyOne centre has a printer-readiness warning
Readiness

Sign-in, printer and bundle status.

Approvals

Who has approved and when.

Print counts

Expected versus produced copies.

Alerts

Early attempts, mismatches and failures.

17A deployable university platform.The design is intentionally practical: standard infrastructure, a secure centre client and a clear cryptographic boundary around readable content.
UNIVERSITY EDITION · CHAPTER 17

A deployable university platform.

The design is intentionally practical: standard infrastructure, a secure centre client and a clear cryptographic boundary around readable content.

ExamLockerTECHNICAL DOSSIER
University users
Sealing workstationCreates centre editions and encrypts locally
Approval portalAny 3 of 5 custodian approvals
Operations dashboardReadiness, print and attestation status
Exam centres
Authorised clientDevice-bound centre session
Controlled print serviceDirect print with spool cleanup
Local printerPre-authorised USB or managed connection
Exam Locker application core
PHP 8.x
Application and policy engine
MySQL 8.x
Roles, ceremonies and custody records
Object storage
Encrypted paper bundles only
Cryptography
libsodium / AEAD and digital signatures
The University Edition requires no dedicated hardware security module.

It is deployable on standard cloud or university infrastructure, while preserving separation of duties, client-side encryption and evidence-grade logging.

Edition isolation. Object storage may contain many centre bundles, but each bundle uses a different DEK. The three released capsules delivered to Centre U-042 reconstruct only U-042's DEK.
18The records that make the system real.The first nine tables define tenants, exams, isolated centre editions, manifests, centres, staff, custodians and encrypted share capsules.
UNIVERSITY EDITION · CHAPTER 18

The records that make the system real.

The first nine tables define tenants, exams, isolated centre editions, manifests, centres, staff, custodians and encrypted share capsules.

ExamLockerTECHNICAL DOSSIER
boards

University tenant, governance and retention settings.

exams

Schedule, session, release window and status.

papers

Approved paper identity, version and sealing state.

paper_editions

Centre-specific ciphertext, edition ID and isolated DEK metadata.

manifests

SHA-256 hashes, sizes, nonce, algorithm and object references.

centers

Authorised locations, registered clients and printer policy.

center_staff

Superintendent, Observer and controlled-session assignments.

custodians

Five named share holders, credential state and reporting line.

share_capsules

Five encrypted Shamir-share capsules per centre edition.

19Every ceremony becomes verifiable evidence.The remaining tables preserve quorum decisions, one-time release messages, centre operations, external anchors, alerts and exportable evidence.
UNIVERSITY EDITION · CHAPTER 19

Every ceremony becomes verifiable evidence.

The remaining tables preserve quorum decisions, one-time release messages, centre operations, external anchors, alerts and exportable evidence.

ExamLockerTECHNICAL DOSSIER
approval_ceremonies

One session-level quorum ceremony and signed approvals.

release_messages

Signed, expiring, nonce-bound, one-time release responses.

unlock_sessions

Centre client, edition, staff, timestamps and consumption state.

print_jobs

Printer identity, copies requested, produced and reconciled.

attestations

Closure, surplus destruction and observer confirmation.

custody_events

Append-only hash-chained event chronology.

anchors

External digest witnesses that make silent history rewriting detectable.

alerts

Replay, early access, quorum anomalies, mismatches and failures.

audit_exports

Evidence bundle, verification result and recipient record.

Edition createdpaper_editions + manifests
Shares preparedshare_capsules x 5 per edition
Quorum approvedapproval_ceremonies + release_messages
Centre operatedunlock_sessions + print_jobs + attestations
Evidence anchoredcustody_events + anchors + audit_exports
The external-anchor claim now has a home.

The anchors table stores periodic chain-head digests, witness identifiers, timestamps and receipts. The audit_exports table records the exact evidence package and verification result supplied to an authorised reviewer.

20The practical security baseline.A single defined cryptographic profile for the university pilot.
UNIVERSITY EDITION · CHAPTER 20

The practical security baseline.

A single defined cryptographic profile for the university pilot.

ExamLockerTECHNICAL DOSSIER
Encryption profile

AES-256-GCM is the mandatory paper-encryption algorithm for this final edition. A fresh random 256-bit DEK and unique 96-bit nonce are generated for every centre-specific edition. Algorithm agility may be designed internally, but the tender baseline is not written as “either/or.”

Key handling

Each edition DEK is split with Shamir Secret Sharing, threshold 3-of-5. Each share is encrypted to one named custodian public key. The platform stores encrypted capsules only.

Release message

Every release response is digitally signed and bound to exam_id, paper_id, edition_id, centre_id, session_id, release_window, nonce and expiry. The centre client records one-time consumption and rejects replay.

Signed client

A signed Electron/Tauri or native kiosk client is the security-bearing endpoint. A browser prototype may validate workflow, but is not presented as equivalent security.

Controlled printing

Persistent OS spooling is disabled where supported. Temporary material uses an encrypted volume or memory-backed storage, followed by verified cleanup and printer-cache handling.

Identity and custody

Custodian credentials are device-bound or held in a university-controlled secure credential store. Recovery, revocation and alternate activation follow the dedicated key-custody page.

Security claims attach to a precise profile: per-edition keys, 3-of-5 custody, signed one-time release messages and a controlled endpoint.
21Why not simply use CBT?Exam Locker protects paper-based examinations that still require centre-side printing. It complements computer-based testing rather than pretending every examination can become CBT.
UNIVERSITY EDITION · CHAPTER 21

Why not simply use CBT?

Exam Locker protects paper-based examinations that still require centre-side printing. It complements computer-based testing rather than pretending every examination can become CBT.

ExamLockerTECHNICAL DOSSIER
Why not simply use CBT?

CBT requires devices, reliable power and connectivity, accessibility arrangements, secure test-delivery software and operational change at every seat. Many descriptive, diagrammatic, open-book or institution-specific examinations still require paper.

Where Exam Locker fits

It preserves the familiar paper examination while eliminating bulk pre-printing, physical transport and strong-room custody. Universities can adopt it without redesigning the examination itself.

22Compliance must be earned.Independent testing, documented controls and operating evidence convert architecture claims into procurement confidence.
UNIVERSITY EDITION · CHAPTER 22

Compliance must be earned.

Independent testing, documented controls and operating evidence convert architecture claims into procurement confidence.

ExamLockerTECHNICAL DOSSIER

CERT-In security audit

Commission independent application, infrastructure and source-code assessment through an appropriately empanelled information-security auditing organisation before production use.

STQC assurance path

Evaluate independent software testing, security assessment and product-certification options appropriate to the deployment and procurement context.

MeitY-aligned controls

Map hosting, identity, logging, incident response, data retention and government-cloud requirements where applicable to the institution or funding authority.

Public Examinations Act, 2024

Assess legal applicability with counsel. The Act addresses unfair means in defined public examinations; a university must determine whether its examination and authority fall within the statutory definitions.

Compliance is a verification programme, not a logo on a page.

The pilot should produce a threat model, secure-development evidence, independent test reports, incident procedures, retention policy and an auditable operating manual.

Official reference framework: CERT-In (national cyber-security agency and empanelled auditor ecosystem); STQC, Ministry of Electronics & Information Technology (software testing, assessment and certification services); The Public Examinations (Prevention of Unfair Means) Act, 2024, India Code. Applicability and certification scope require formal assessment.
23Pilot. Prove. Audit. Scale.A tightly scoped university pilot converts architecture claims into operational evidence.
UNIVERSITY EDITION · CHAPTER 23

Pilot. Prove. Audit. Scale.

A tightly scoped university pilot converts architecture claims into operational evidence.

ExamLockerTECHNICAL DOSSIER
Start with one real examination, a controlled set of centres and measurable acceptance criteria.
ScopeOne university, one examination family, 3-5 centres and a defined candidate volume.
DurationEight to twelve weeks including integration, rehearsal, live operation and post-exam review.
EvidenceIndependent security test, custody verification, print reconciliation and watermark performance report.
DecisionScale only after the university accepts the operational and security results.
01
Design and integrate

Map roles, provision five custodians, register centre clients, define recovery and configure the examination session.

02
Rehearse and test

Run cancellation, missing-custodian, network failure, printer failure, replay and incident-response exercises.

03
Operate and review

Conduct the live examination, export evidence, measure watermark recovery and document every exception.

Proposed next step

Authorise a university discovery and pilot-design workshop to define the first examination, participating centres, named custodians, success metrics, implementation responsibilities and commercial proposal.

Deliverable: signed pilot scope and implementation plan
24A university-ready security model.Practical enough to pilot. Precise enough to audit.
UNIVERSITY EDITION · CHAPTER 24

A university-ready security model.

Practical enough to pilot. Precise enough to audit.

ExamLockerTECHNICAL DOSSIER
Secure the paper before it enters the network. Give every centre its own key. Require three independent custodians. Record everything.
No readable paper in storage

The platform holds ciphertext and encrypted capsules, not examination content.

No universal centre key

Every centre-specific edition uses a fresh DEK. One centre cannot open another centre's bundle.

No single-person release

A fixed 3-of-5 quorum is required; alternate custodians are pre-provisioned.

We cannot leak your readable paper because we do not store it. If a centre copy escapes, it already carries that centre's identity.

Move from dossier to pilot.

Approve the pilot-design workshop and select the first university examination for controlled implementation.

Protect the examination

Keep the paper sealed.
Until the right moment.

One centre-specific edition. Three independent approvals. One controlled print window. A permanent record of what happened.

Talk to us