Prototypes Nordlys AdvokaterP6 · Client portal
The server

What the portal’s server holds

Every row the server stores for the portal, read from it every 2 seconds. It holds public keys, ciphertext and keys wrapped for one reader each. None of it opens a document.

Public keys

NameRoleKey idPublic key

Documents

NameVersionStoredCiphertext

Wrapped keys

DocumentReaderVersionWrapped key

What happened

WhenWhoWhat
How Nordlys Advokater is built
  1. The adviser and the client each have a key pair. The server keeps only the public halves.
  2. Each document is encrypted with its own random key. That key is then wrapped once for each reader, with the reader’s public key.
  3. To share, the adviser wraps the document key for the client. To remove access, the adviser encrypts the document again with a new key and wraps it only for the readers who stay. A key the client kept opens nothing on the server after that.
  4. Data on the server is deleted after 7 days.